hashicorp/terraform · error

failed to verify checksum of

Error message

failed to verify checksum of %s %s package cached in in %s: %s

What it means

After locating a cached provider package, providerFactoriesFromLocks verifies it against lock.PreferredHashes via cached.MatchesAnyHash. If MatchesAnyHash itself returns an error (as opposed to a clean false), the verification could not complete — typically an I/O error reading the package files or computing hashes — and this error is recorded. Note the message contains a typo ('cached in in') in the source.

Solutions

  1. Inspect the trailing %s (the inner err) for the exact I/O or hash failure, then fix that root cause (permissions, disk space).
  2. Remove the affected provider directory under .terraform/providers/<provider>/<version>/ and re-run terraform init to re-extract cleanly.
  3. Ensure the user running Terraform owns and can read the entire cache tree (chown -R if needed).
  4. If TF_PLUGIN_CACHE_DIR is on a network/overlay share, move it to a local fast volume.

Example fix

# before: hash verification I/O error
# after: clear and re-fetch
rm -rf .terraform/providers/registry.terraform.io/hashicorp/aws/5.0.1
terraform init
Defensive patterns

Strategy: retry

Validate before calling

// Pre-check readability of the package dir before Terraform verifies hashes.
info, err := os.Stat(pkgDir)
if err != nil || !info.IsDir() {
    return fmt.Errorf("provider package unreadable at %s: %w", pkgDir, err)
}

Try / catch

// Transient I/O hash errors are often resolved by re-fetching once.
if errors.Is(err, syscall.EIO) || strings.Contains(err.Error(), "hash") {
    _ = os.RemoveAll(pkgDir)
    return runTerraform("init") // single retry after clearing
}

Prevention

When it happens

Trigger: cached.MatchesAnyHash(allowedHashes) returns a non-nil err while lock.PreferredHashes() is non-empty. Causes include file permission errors reading the unpacked package, missing files inside the package directory, or a hashing algorithm the runtime cannot compute.

Common situations: Permissions changed on .terraform/providers after a sudo/role switch; antivirus or container overlay filesystem locking package files; partially-extracted archive left by an interrupted init; filesystem corruption on the cache volume.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/274079e8d7c7e252. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/meta_providers.go:413

			// loops below, for dev overrides etc.
			continue
		}

		version := lock.Version()
		cached := cacheDir.ProviderVersion(provider, version)
		if cached == nil {
			reportError(fmt.Errorf(
				"there is no package for %s %s cached in %s",
				provider, version, cacheDir.BasePath(),
			))
			continue
		}
		// The cached package must match one of the checksums recorded in
		// the lock file, if any.
		if allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {
			matched, err := cached.MatchesAnyHash(allowedHashes)
			if err != nil {
				reportError(fmt.Errorf(
					"failed to verify checksum of %s %s package cached in in %s: %s",
					provider, version, cacheDir.BasePath(), err,
				))
				continue
			}
			if !matched {
				reportError(fmt.Errorf(
					"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file",
					provider, version, cacheDir.BasePath(),
				))
				continue
			}
		}
		factories[provider] = providerFactory(cached)
	}
	for provider, localDir := range devOverrideProviders {
		factories[provider] = devOverrideProviderFactory(provider, localDir)
	}

View on GitHub (pinned to d32a084675)