hashicorp/terraform · error
registry response includes invalid SHASUMS URL
Error message
registry response includes invalid SHASUMS URL: %s
What it means
Thrown when the registry's shasums_url field cannot be parsed as a URL. This URL points to the SHA256SUMS file used for checksum authentication.
Solutions
- Report the malformed shasums_url to the registry operator
- If self-hosting, publish shasums_url as an absolute http(s) URL
- Verify the registry endpoint returns the documented field
Defensive patterns
Strategy: validation
Validate before calling
if _, err := url.Parse(body.SHA256SumsURL); err != nil {
return fmt.Errorf("registry shasums_url is unparseable: %w", err)
} Type guard
func IsParseableURL(s string) bool {
_, err := url.Parse(s)
return err == nil
} Try / catch
shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return fmt.Errorf("registry returned an invalid SHASUMS URL: %w", err)
} Prevention
- Publish shasums_url as an absolute http(s) URL on the registry
- Sanitize response fields of control characters
When it happens
Trigger: url.Parse(body.SHA256SumsURL) returned a non-nil error (control characters, unparseable scheme, etc.).
Common situations: Registry returns a malformed shasums_url; field corruption in transit; a mirror rewriting the field incorrectly; empty or whitespace value with invalid structure.
Related errors
- registry response includes invalid SHASUMS signature URL
- registry response includes invalid SHASUMS URL: must use…
- registry response includes invalid download URL
- registry response includes invalid download URL: must use…
- failed to retrieve authentication checksums for provider
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/d2271aeb87c82781.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_client.go:323
if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
)
}
var checksum [sha256.Size]byte
_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
)
}
shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
}
shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
}
document, err := c.getFile(shasumsURL)
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
)
}
signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
}
signatureURL = resp.Request.URL.ResolveReference(signatureURL)
if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {View on GitHub (pinned to d32a084675)