hashicorp/terraform · error
failed to verify checksum of
Error message
failed to verify checksum of %s %s package cached in in %s: %s
What it means
After locating a cached provider package, providerFactoriesFromLocks verifies it against lock.PreferredHashes via cached.MatchesAnyHash. If MatchesAnyHash itself returns an error (as opposed to a clean false), the verification could not complete — typically an I/O error reading the package files or computing hashes — and this error is recorded. Note the message contains a typo ('cached in in') in the source.
Solutions
- Inspect the trailing %s (the inner err) for the exact I/O or hash failure, then fix that root cause (permissions, disk space).
- Remove the affected provider directory under .terraform/providers/<provider>/<version>/ and re-run terraform init to re-extract cleanly.
- Ensure the user running Terraform owns and can read the entire cache tree (chown -R if needed).
- If TF_PLUGIN_CACHE_DIR is on a network/overlay share, move it to a local fast volume.
Example fix
# before: hash verification I/O error # after: clear and re-fetch rm -rf .terraform/providers/registry.terraform.io/hashicorp/aws/5.0.1 terraform init
Defensive patterns
Strategy: retry
Validate before calling
// Pre-check readability of the package dir before Terraform verifies hashes.
info, err := os.Stat(pkgDir)
if err != nil || !info.IsDir() {
return fmt.Errorf("provider package unreadable at %s: %w", pkgDir, err)
} Try / catch
// Transient I/O hash errors are often resolved by re-fetching once.
if errors.Is(err, syscall.EIO) || strings.Contains(err.Error(), "hash") {
_ = os.RemoveAll(pkgDir)
return runTerraform("init") // single retry after clearing
} Prevention
- Keep the cache on a reliable local filesystem, not a flaky network mount.
- Avoid running Terraform as different users against the same cache (permissions drift).
- Periodically verify cache integrity in CI.
When it happens
Trigger: cached.MatchesAnyHash(allowedHashes) returns a non-nil err while lock.PreferredHashes() is non-empty. Causes include file permission errors reading the unpacked package, missing files inside the package directory, or a hashing algorithm the runtime cannot compute.
Common situations: Permissions changed on .terraform/providers after a sudo/role switch; antivirus or container overlay filesystem locking package files; partially-extracted archive left by an interrupted init; filesystem corruption on the cache volume.
Related errors
- the cached package for
- there is no package for
- Failed to convert provider version to Go version
- failed to read dependency lock file
- action schema not found for action
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/274079e8d7c7e252.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/meta_providers.go:413
// loops below, for dev overrides etc.
continue
}
version := lock.Version()
cached := cacheDir.ProviderVersion(provider, version)
if cached == nil {
reportError(fmt.Errorf(
"there is no package for %s %s cached in %s",
provider, version, cacheDir.BasePath(),
))
continue
}
// The cached package must match one of the checksums recorded in
// the lock file, if any.
if allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {
matched, err := cached.MatchesAnyHash(allowedHashes)
if err != nil {
reportError(fmt.Errorf(
"failed to verify checksum of %s %s package cached in in %s: %s",
provider, version, cacheDir.BasePath(), err,
))
continue
}
if !matched {
reportError(fmt.Errorf(
"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file",
provider, version, cacheDir.BasePath(),
))
continue
}
}
factories[provider] = providerFactory(cached)
}
for provider, localDir := range devOverrideProviders {
factories[provider] = devOverrideProviderFactory(provider, localDir)
}View on GitHub (pinned to d32a084675)