hashicorp/terraform · error · ErrQueryFailed
registry response includes invalid SHA256 hash
Error message
registry response includes invalid SHA256 hash %q: %s
What it means
Thrown when the registry's shasum field is not exactly sha256.Size*2 (64) hex characters long. Note: the error formats the nil err variable (a latent bug — the message prints '%!s(<nil>)'), so the real diagnostic is the length mismatch, not the appended err.
Solutions
- Report the malformed shasum field to the registry operator
- If self-hosting, return the provider archive's SHA256 as a 64-char lowercase hex string
- Verify the registry endpoint returns the documented single-hash shasum (not the SHA256SUMS file body)
Defensive patterns
Strategy: validation
Validate before calling
// Confirm the shasum is exactly 64 hex characters.
if len(body.SHA256Sum) != sha256.Size*2 {
return fmt.Errorf("registry shasum has wrong length %d (want %d): %q",
len(body.SHA256Sum), sha256.Size*2, body.SHA256Sum)
} Type guard
func IsSHA256HexLength(s string) bool {
return len(s) == sha256.Size*2
} Try / catch
if len(body.SHA256Sum) != sha256.Size*2 {
return fmt.Errorf("registry returned a malformed shasum (length): %q", body.SHA256Sum)
} Prevention
- Registries must return shasum as a 64-char lowercase hex digest
- Do not return base64 or the full SHA256SUMS file body in the shasum field
When it happens
Trigger: len(body.SHA256Sum) != 64 — empty, too short, too long, or a non-hex-padded value.
Common situations: Registry omits the shasum field (empty string); returns a base64-encoded digest instead of hex; truncates the digest; schema regression returning the full checksums document instead of a single hash.
Related errors
- registry response includes invalid download URL
- registry response includes invalid download URL: must use…
- registry response includes invalid SHASUMS signature URL
- registry response includes invalid SHASUMS URL: must use…
- registry response includes invalid SHASUMS URL
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/ff007913ee75892c.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_client.go:308
}
ret := PackageMeta{
Provider: provider,
Version: version,
ProtocolVersions: protoVersions,
TargetPlatform: Platform{
OS: body.OS,
Arch: body.Arch,
},
Filename: body.Filename,
Location: PackageHTTPURL(downloadURL.String()),
// "Authentication" is populated below
}
if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
)
}
var checksum [sha256.Size]byte
_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
)
}
shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
}
shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {View on GitHub (pinned to d32a084675)