hashicorp/terraform · error

registry response includes invalid SHASUMS URL

Error message

registry response includes invalid SHASUMS URL: %s

What it means

Thrown when the registry's shasums_url field cannot be parsed as a URL. This URL points to the SHA256SUMS file used for checksum authentication.

Solutions

  1. Report the malformed shasums_url to the registry operator
  2. If self-hosting, publish shasums_url as an absolute http(s) URL
  3. Verify the registry endpoint returns the documented field
Defensive patterns

Strategy: validation

Validate before calling

if _, err := url.Parse(body.SHA256SumsURL); err != nil {
    return fmt.Errorf("registry shasums_url is unparseable: %w", err)
}

Type guard

func IsParseableURL(s string) bool {
    _, err := url.Parse(s)
    return err == nil
}

Try / catch

shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
    return fmt.Errorf("registry returned an invalid SHASUMS URL: %w", err)
}

Prevention

When it happens

Trigger: url.Parse(body.SHA256SumsURL) returned a non-nil error (control characters, unparseable scheme, etc.).

Common situations: Registry returns a malformed shasums_url; field corruption in transit; a mirror rewriting the field incorrectly; empty or whitespace value with invalid structure.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/d2271aeb87c82781. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_client.go:323

	if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
		)
	}

	var checksum [sha256.Size]byte
	_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
		)
	}

	shasumsURL, err := url.Parse(body.SHA256SumsURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
	}
	shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
	if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
	}
	document, err := c.getFile(shasumsURL)
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
		)
	}
	signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
	}
	signatureURL = resp.Request.URL.ResolveReference(signatureURL)
	if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {

View on GitHub (pinned to d32a084675)