hashicorp/terraform · error
failed to verify provider package checksums
Error message
failed to verify provider package checksums: %s
What it means
Thrown by packageHashAuthentication.AuthenticatePackage when PackageMatchesAnyHash returns a non-nil error while trying to compute/compare the package's hash against RequiredHashes. The wrapped %s is the underlying error — typically an I/O failure reading the staged package, a corrupt zip, or a hashing computation error. This is an infrastructure/read failure, not a mismatch verdict.
Solutions
- Clear the provider plugin cache (remove .terraform/providers/<host>/<ns>/<type>/<version>/) and re-run init to re-download cleanly.
- Check read permissions and file ownership on the plugin directory, especially after running as a different user or root.
- On Windows, exclude the cache path from AV/EDR on-access scanning, or stop the process holding the file.
- Verify disk space and that the download completed (re-run with a fresh download).
Defensive patterns
Strategy: try-catch
Try / catch
result, err := auth.AuthenticatePackage(loc)
if err != nil {
if strings.Contains(err.Error(), "failed to verify provider package checksums") {
// underlying I/O / hashing failure: clear the cache and retry once
_ = os.RemoveAll(providerCacheDir)
}
return result, err
} Prevention
- Treat the provider cache as disposable; delete and re-download on I/O errors.
- Run init in a clean CI workspace to avoid stale/locked caches.
- On Windows, exclude the plugin cache from on-access AV scanning.
When it happens
Trigger: AuthenticatePackage is called on a local package whose files cannot be read (permission denied, missing file, broken symlink), or whose zip/archive cannot be walked during hash computation. PackageMatchesAnyHash localLocation read returns err at multi_source.go... package_authentication.go:250-252.
Common situations: The provider cache dir got partially deleted or had permissions changed; antivirus/EDR locking the unzipped plugin files on Windows; a truncated download left in the cache; a manually placed provider dir missing files; out-of-disk during extraction.
Related errors
- failed to compute checksum for
- archive has incorrect checksum
- can not read private key from
- can't read
- provider package doesn't match the any of the expected…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/9bb36b5fd2145d5a.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/package_authentication.go:252
requiredHashes := PreferredHashes(validHashes)
return packageHashAuthentication{
RequiredHashes: requiredHashes,
AllHashes: validHashes,
Platform: platform,
}
}
func (a packageHashAuthentication) AuthenticatePackage(localLocation PackageLocation) (*PackageAuthenticationResult, error) {
if len(a.RequiredHashes) == 0 {
// Indicates that none of the hashes given to
// NewPackageHashAuthentication were considered to be usable by this
// version of Terraform.
return nil, fmt.Errorf("this version of Terraform does not support any of the checksum formats given for this provider")
}
matches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)
if err != nil {
return nil, fmt.Errorf("failed to verify provider package checksums: %s", err)
}
if matches {
return &PackageAuthenticationResult{result: verifiedChecksum}, nil
}
if len(a.RequiredHashes) == 1 {
return nil, fmt.Errorf("provider package doesn't match the expected checksum %q", a.RequiredHashes[0].String())
}
// It's non-ideal that this doesn't actually list the expected checksums,
// but in the many-checksum case the message would get pretty unweildy.
// In practice today we typically use this authenticator only with a
// single hash returned from a network mirror, so the better message
// above will prevail in that case. Maybe we'll improve on this somehow
// if the future introduction of a new hash scheme causes there to more
// commonly be multiple hashes.
return nil, fmt.Errorf("provider package doesn't match the any of the expected checksums")
}
View on GitHub (pinned to d32a084675)