hashicorp/terraform · error

provider package doesn't match the any of the expected…

Error message

provider package doesn't match the any of the expected checksums

What it means

Thrown by packageHashAuthentication.AuthenticatePackage when there are two or more RequiredHashes and the package matched none of them. This is the multi-hash mismatch path at package_authentication.go:261-268 (note the message typo 'match the any of the expected'). The error does not enumerate the expected hashes, so diagnosis requires inspecting the lock file / AllHashes directly.

Solutions

  1. Remove the cached package directory and re-run init to re-download against the current registry hashes.
  2. Regenerate the lock file (terraform init -upgrade) so hashes match the currently published package bytes.
  3. Compare the actual package hash (compute it locally) against each entry in the lock file to identify which scheme/version drifted.
  4. If running across platforms, ensure the lock file has hashes for the target platform's package, not just one platform.
Defensive patterns

Strategy: try-catch

Try / catch

result, err := auth.AuthenticatePackage(loc)
if err != nil && strings.Contains(err.Error(), "doesn't match the any of the expected checksums") {
    // multi-hash mismatch: log AllHashes for diagnosis, then re-fetch
    return result, err
}

Prevention

When it happens

Trigger: AuthenticatePackage with len(RequiredHashes) > 1 where PackageMatchesAnyHash returned false. Typical with the standard registry flow where multiple zh:/h1: hashes are acceptable but the local package matches none.

Common situations: Package repackaged upstream while the lock file still lists old hashes; cross-platform lock file used on a platform whose cached package was built differently; a stale CI cache; tampered or partially overwritten package files.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/9216ec851abfc726. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/package_authentication.go:268

	matches, err := PackageMatchesAnyHash(localLocation, a.RequiredHashes)
	if err != nil {
		return nil, fmt.Errorf("failed to verify provider package checksums: %s", err)
	}

	if matches {
		return &PackageAuthenticationResult{result: verifiedChecksum}, nil
	}
	if len(a.RequiredHashes) == 1 {
		return nil, fmt.Errorf("provider package doesn't match the expected checksum %q", a.RequiredHashes[0].String())
	}
	// It's non-ideal that this doesn't actually list the expected checksums,
	// but in the many-checksum case the message would get pretty unweildy.
	// In practice today we typically use this authenticator only with a
	// single hash returned from a network mirror, so the better message
	// above will prevail in that case. Maybe we'll improve on this somehow
	// if the future introduction of a new hash scheme causes there to more
	// commonly be multiple hashes.
	return nil, fmt.Errorf("provider package doesn't match the any of the expected checksums")
}

func (a packageHashAuthentication) AcceptableHashes() []Hash {
	// In this case we include even hashes the current version of Terraform
	// doesn't prefer, because this result is used for building a lock file
	// and so it's helpful to include older hash formats that other Terraform
	// versions might need in order to do authentication successfully.
	return a.AllHashes
}

type archiveHashAuthentication struct {
	Platform      Platform
	WantSHA256Sum [sha256.Size]byte
}

// NewArchiveChecksumAuthentication returns a PackageAuthentication
// implementation that checks that the original distribution archive matches
// the given hash.

View on GitHub (pinned to d32a084675)