hashicorp/terraform · error

failed to verify provider package checksums

Error message

failed to verify provider package checksums: %s

What it means

Thrown by packageHashAuthentication.AuthenticatePackage when PackageMatchesAnyHash returns a non-nil error while trying to compute/compare the package's hash against RequiredHashes. The wrapped %s is the underlying error — typically an I/O failure reading the staged package, a corrupt zip, or a hashing computation error. This is an infrastructure/read failure, not a mismatch verdict.

Solutions

  1. Clear the provider plugin cache (remove .terraform/providers/<host>/<ns>/<type>/<version>/) and re-run init to re-download cleanly.
  2. Check read permissions and file ownership on the plugin directory, especially after running as a different user or root.
  3. On Windows, exclude the cache path from AV/EDR on-access scanning, or stop the process holding the file.
  4. Verify disk space and that the download completed (re-run with a fresh download).
Defensive patterns

Strategy: try-catch

Try / catch

result, err := auth.AuthenticatePackage(loc)
if err != nil {
    if strings.Contains(err.Error(), "failed to verify provider package checksums") {
        // underlying I/O / hashing failure: clear the cache and retry once
        _ = os.RemoveAll(providerCacheDir)
    }
    return result, err
}

Prevention

When it happens

Trigger: AuthenticatePackage is called on a local package whose files cannot be read (permission denied, missing file, broken symlink), or whose zip/archive cannot be walked during hash computation. PackageMatchesAnyHash localLocation read returns err at multi_source.go... package_authentication.go:250-252.

Common situations: The provider cache dir got partially deleted or had permissions changed; antivirus/EDR locking the unzipped plugin files on Windows; a truncated download left in the cache; a manually placed provider dir missing files; out-of-disk during extraction.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/9bb36b5fd2145d5a. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:252

	requiredHashes := PreferredHashes(validHashes)
	return packageHashAuthentication{
		RequiredHashes: requiredHashes,
		AllHashes:      validHashes,
		Platform:       platform,
	}
}

func (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
	if len(a.RequiredHashes) == 0 {
		// Indicates that none of the hashes given to
		// NewPackageHashAuthentication were considered to be usable by this
		// version of Terraform.
		return nil, fmt.Errorf("this version of Terraform does not support any of the checksum formats given for this provider")
	}

	matches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)
	if err != nil {
		return nil, fmt.Errorf("failed to verify provider package checksums: %s", err)
	}

	if matches {
		return &PackageAuthenticationResult{result: verifiedChecksum}, nil
	}
	if len(a.RequiredHashes) == 1 {
		return nil, fmt.Errorf("provider package doesn't match the expected checksum %q", a.RequiredHashes[0].String())
	}
	// It's non-ideal that this doesn't actually list the expected checksums,
	// but in the many-checksum case the message would get pretty unweildy.
	// In practice today we typically use this authenticator only with a
	// single hash returned from a network mirror, so the better message
	// above will prevail in that case. Maybe we'll improve on this somehow
	// if the future introduction of a new hash scheme causes there to more
	// commonly be multiple hashes.
	return nil, fmt.Errorf("provider package doesn't match the any of the expected checksums")
}

View on GitHub (pinned to d32a084675)