hashicorp/terraform · error

the cached package for

Error message

the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file

What it means

When MatchesAnyHash completes successfully but returns matched == false, the cached provider package hashes do not match any checksum recorded in the dependency lock file. This is a deliberate integrity failure: Terraform treats the package as untrusted because it differs from what was locked. reportError installs a stub factory so the error surfaces again if the provider is actually used.

Solutions

  1. If the package was intentionally replaced, run terraform init -upgrade (or terraform providers lock) to regenerate the lock hashes for the current package.
  2. If the package is suspect, delete .terraform/providers/<provider>/<version> and re-run terraform init to fetch the original.
  3. Ensure all platforms needed are represented in the lock file: terraform providers lock -platform=linux_amd64 -platform=darwin_arm64 ...
  4. Verify the registry/mirror URL is the trusted origin configured when the lock was first generated.

Example fix

# before: checksum mismatch after replacing provider
# after: regenerate lock hashes
terraform providers lock -platform=$(go env GOOS)_$(go env GOARCH)
git add .terraform.lock.hcl
Defensive patterns

Strategy: validation

Validate before calling

// Verify package hashes match the lock before delegating to Terraform.
matched, err := cached.MatchesAnyHash(lock.PreferredHashes())
if err == nil && !matched {
    return fmt.Errorf("integrity check failed for %s; regenerate lock or re-fetch", provider)
}

Prevention

When it happens

Trigger: lock.PreferredHashes() is non-empty, cached.MatchesAnyHash returns (false, nil). The package bytes differ from every h1:/zh: hash in the lock file — e.g. the archive was replaced, re-packed, or comes from an unverified mirror.

Common situations: Manually replacing a provider binary for debugging and forgetting to update the lock; pulling a different build of the same version from a mirror; lock file generated on a different platform with only zh: hashes and the local package yields h1: only; supply-chain tampering or a corrupted download.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/da1bce115ca6e0f8. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/meta_providers.go:420

			reportError(fmt.Errorf(
				"there is no package for %s %s cached in %s",
				provider, version, cacheDir.BasePath(),
			))
			continue
		}
		// The cached package must match one of the checksums recorded in
		// the lock file, if any.
		if allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {
			matched, err := cached.MatchesAnyHash(allowedHashes)
			if err != nil {
				reportError(fmt.Errorf(
					"failed to verify checksum of %s %s package cached in in %s: %s",
					provider, version, cacheDir.BasePath(), err,
				))
				continue
			}
			if !matched {
				reportError(fmt.Errorf(
					"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file",
					provider, version, cacheDir.BasePath(),
				))
				continue
			}
		}
		factories[provider] = providerFactory(cached)
	}
	for provider, localDir := range devOverrideProviders {
		factories[provider] = devOverrideProviderFactory(provider, localDir)
	}
	for provider, reattach := range unmanagedProviders {
		factories[provider] = unmanagedProviderFactory(provider, reattach)
	}
	if m.testingOverrides != nil {
		// Allow tests, where testingOverrides is set, to see test providers in locks
		for provider, factory := range m.testingOverrides.Providers {
			factories[provider] = factory

View on GitHub (pinned to d32a084675)