hashicorp/terraform · error

failed to compute checksum for

Error message

failed to compute checksum for %s: %s

What it means

Thrown by archiveHashAuthentication.AuthenticatePackage when PackageHashLegacyZipSHA(archiveLocation) returns an error reading or hashing the archive. The wrapped %s is the underlying error — usually an I/O failure opening/reading the archive or a zip-struct read error. The location did type-assert to PackageLocalArchive, so the file exists as an archive but its contents cannot be hashed.

Solutions

  1. Delete the cached archive file and re-run init to re-download a complete package.
  2. Check read permissions and that no other process (AV, backup, another terraform run) holds the file.
  3. Verify the archive is a valid zip (unzip -t or equivalent) and non-empty; if not, re-fetch.
  4. Confirm the download path has enough disk space to write the full archive.
Defensive patterns

Strategy: try-catch

Try / catch

result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "failed to compute checksum") {
    // archive unreadable: re-download
    _ = os.Remove(archivePath)
}
return result, err

Prevention

When it happens

Trigger: AuthenticatePackage on a PackageLocalArchive whose file is unreadable (permission denied, removed mid-operation, locked by another process) or whose zip structure is unreadable by the legacy-zip hasher. Triggered at package_authentication.go:309-311.

Common situations: The downloaded .zip is truncated (interrupted download); AV/EDR on Windows locks the file; permissions changed after staging; the archive is corrupt or zero-length; concurrent processes reading/deleting the cache.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/c1663d8e83e0c36e. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:311

//
// NewPackageHashAuthentication is preferable to use when possible because
// it uses the newer hashing scheme (implemented by function PackageHash) that
// can work with both packed and unpacked provider packages.
func NewArchiveChecksumAuthentication(platform Platform, wantSHA256Sum [sha256.Size]byte) PackageAuthentication {
	return archiveHashAuthentication{platform, wantSHA256Sum}
}

func (a archiveHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
	archiveLocation, ok := localLocation.(PackageLocalArchive)
	if !ok {
		// A source should not use this authentication type for non-archive
		// locations.
		return nil, fmt.Errorf("cannot check archive hash for non-archive location %s", localLocation)
	}

	gotHash, err := PackageHashLegacyZipSHA(archiveLocation)
	if err != nil {
		return nil, fmt.Errorf("failed to compute checksum for %s: %s", archiveLocation, err)
	}
	wantHash := HashLegacyZipSHAFromSHA(a.WantSHA256Sum)
	if gotHash != wantHash {
		return nil, fmt.Errorf("archive has incorrect checksum %s (expected %s)", gotHash, wantHash)
	}
	return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}

func (a archiveHashAuthentication) AcceptableHashes() []Hash {
	return []Hash{HashLegacyZipSHAFromSHA(a.WantSHA256Sum)}
}

type matchingChecksumAuthentication struct {
	Document      []byte
	Filename      string
	WantSHA256Sum [sha256.Size]byte
}

View on GitHub (pinned to d32a084675)