hashicorp/terraform · error
failed to compute checksum for
Error message
failed to compute checksum for %s: %s
What it means
Thrown by archiveHashAuthentication.AuthenticatePackage when PackageHashLegacyZipSHA(archiveLocation) returns an error reading or hashing the archive. The wrapped %s is the underlying error — usually an I/O failure opening/reading the archive or a zip-struct read error. The location did type-assert to PackageLocalArchive, so the file exists as an archive but its contents cannot be hashed.
Solutions
- Delete the cached archive file and re-run init to re-download a complete package.
- Check read permissions and that no other process (AV, backup, another terraform run) holds the file.
- Verify the archive is a valid zip (unzip -t or equivalent) and non-empty; if not, re-fetch.
- Confirm the download path has enough disk space to write the full archive.
Defensive patterns
Strategy: try-catch
Try / catch
result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "failed to compute checksum") {
// archive unreadable: re-download
_ = os.Remove(archivePath)
}
return result, err Prevention
- Verify downloads complete (non-empty, valid zip) before staging.
- Keep the cache on a writable, unlocked path with enough disk.
- Re-fetch on any archive read error rather than retrying the same bytes.
When it happens
Trigger: AuthenticatePackage on a PackageLocalArchive whose file is unreadable (permission denied, removed mid-operation, locked by another process) or whose zip structure is unreadable by the legacy-zip hasher. Triggered at package_authentication.go:309-311.
Common situations: The downloaded .zip is truncated (interrupted download); AV/EDR on Windows locks the file; permissions changed after staging; the archive is corrupt or zero-length; concurrent processes reading/deleting the cache.
Related errors
- failed to verify provider package checksums
- archive has incorrect checksum
- can not read private key from
- can't read
- cannot check archive hash for non-archive location
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/c1663d8e83e0c36e.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:311
//
// NewPackageHashAuthentication is preferable to use when possible because
// it uses the newer hashing scheme (implemented by function PackageHash) that
// can work with both packed and unpacked provider packages.
func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
return archiveHashAuthentication{platform, wantSHA256Sum}
}
func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
archiveLocation, ok := localLocation.(PackageLocalArchive)
if !ok {
// A source should not use this authentication type for non-archive
// locations.
return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
}
gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
if err != nil {
return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
}
wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
if gotHash != wantHash {
return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
}
return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}
func (a archiveHashAuthentication) AcceptableHashes() []Hash {
return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}
type matchingChecksumAuthentication struct {
Document []byte
Filename string
WantSHA256Sum [sha256.Size]byte
}
View on GitHub (pinned to d32a084675)