hashicorp/terraform · error · ErrQueryFailed

registry response includes invalid SHA256 hash

Error message

registry response includes invalid SHA256 hash %q: %s

What it means

Thrown when the registry's shasum field is not exactly sha256.Size*2 (64) hex characters long. Note: the error formats the nil err variable (a latent bug — the message prints '%!s(<nil>)'), so the real diagnostic is the length mismatch, not the appended err.

Solutions

  1. Report the malformed shasum field to the registry operator
  2. If self-hosting, return the provider archive's SHA256 as a 64-char lowercase hex string
  3. Verify the registry endpoint returns the documented single-hash shasum (not the SHA256SUMS file body)
Defensive patterns

Strategy: validation

Validate before calling

// Confirm the shasum is exactly 64 hex characters.
if len(body.SHA256Sum) != sha256.Size*2 {
    return fmt.Errorf("registry shasum has wrong length %d (want %d): %q",
        len(body.SHA256Sum), sha256.Size*2, body.SHA256Sum)
}

Type guard

func IsSHA256HexLength(s string) bool {
    return len(s) == sha256.Size*2
}

Try / catch

if len(body.SHA256Sum) != sha256.Size*2 {
    return fmt.Errorf("registry returned a malformed shasum (length): %q", body.SHA256Sum)
}

Prevention

When it happens

Trigger: len(body.SHA256Sum) != 64 — empty, too short, too long, or a non-hex-padded value.

Common situations: Registry omits the shasum field (empty string); returns a base64-encoded digest instead of hex; truncates the digest; schema regression returning the full checksums document instead of a single hash.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/ff007913ee75892c. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_client.go:308

	}

	ret := PackageMeta{
		Provider:         provider,
		Version:          version,
		ProtocolVersions: protoVersions,
		TargetPlatform: Platform{
			OS:   body.OS,
			Arch: body.Arch,
		},
		Filename: body.Filename,
		Location: PackageHTTPURL(downloadURL.String()),
		// "Authentication" is populated below
	}

	if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
		)
	}

	var checksum [sha256.Size]byte
	_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
		)
	}

	shasumsURL, err := url.Parse(body.SHA256SumsURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
	}
	shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
	if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {

View on GitHub (pinned to d32a084675)