hashicorp/terraform · error
the cached package for
Error message
the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file
What it means
When MatchesAnyHash completes successfully but returns matched == false, the cached provider package hashes do not match any checksum recorded in the dependency lock file. This is a deliberate integrity failure: Terraform treats the package as untrusted because it differs from what was locked. reportError installs a stub factory so the error surfaces again if the provider is actually used.
Solutions
- If the package was intentionally replaced, run terraform init -upgrade (or terraform providers lock) to regenerate the lock hashes for the current package.
- If the package is suspect, delete .terraform/providers/<provider>/<version> and re-run terraform init to fetch the original.
- Ensure all platforms needed are represented in the lock file: terraform providers lock -platform=linux_amd64 -platform=darwin_arm64 ...
- Verify the registry/mirror URL is the trusted origin configured when the lock was first generated.
Example fix
# before: checksum mismatch after replacing provider # after: regenerate lock hashes terraform providers lock -platform=$(go env GOOS)_$(go env GOARCH) git add .terraform.lock.hcl
Defensive patterns
Strategy: validation
Validate before calling
// Verify package hashes match the lock before delegating to Terraform.
matched, err := cached.MatchesAnyHash(lock.PreferredHashes())
if err == nil && !matched {
return fmt.Errorf("integrity check failed for %s; regenerate lock or re-fetch", provider)
} Prevention
- Generate lock hashes for all target platforms with terraform providers lock.
- Never replace provider binaries under the cache without updating the lock file.
- Treat a sudden checksum mismatch as a possible supply-chain incident and investigate before re-locking.
When it happens
Trigger: lock.PreferredHashes() is non-empty, cached.MatchesAnyHash returns (false, nil). The package bytes differ from every h1:/zh: hash in the lock file — e.g. the archive was replaced, re-packed, or comes from an unverified mirror.
Common situations: Manually replacing a provider binary for debugging and forgetting to update the lock; pulling a different build of the same version from a mirror; lock file generated on a different platform with only zh: hashes and the local package yields h1: only; supply-chain tampering or a corrupted download.
Related errors
- downloaded archive does not match the release checksum
- failed to verify checksum of
- Failed to convert provider version to Go version
- failed to read dependency lock file
- Provider download blocked due to policy violations. Please…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/da1bce115ca6e0f8.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/meta_providers.go:420
reportError(fmt.Errorf(
"there is no package for %s %s cached in %s",
provider, version, cacheDir.BasePath(),
))
continue
}
// The cached package must match one of the checksums recorded in
// the lock file, if any.
if allowedHashes := lock.PreferredHashes(); len(allowedHashes) != 0 {
matched, err := cached.MatchesAnyHash(allowedHashes)
if err != nil {
reportError(fmt.Errorf(
"failed to verify checksum of %s %s package cached in in %s: %s",
provider, version, cacheDir.BasePath(), err,
))
continue
}
if !matched {
reportError(fmt.Errorf(
"the cached package for %s %s (in %s) does not match any of the checksums recorded in the dependency lock file",
provider, version, cacheDir.BasePath(),
))
continue
}
}
factories[provider] = providerFactory(cached)
}
for provider, localDir := range devOverrideProviders {
factories[provider] = devOverrideProviderFactory(provider, localDir)
}
for provider, reattach := range unmanagedProviders {
factories[provider] = unmanagedProviderFactory(provider, reattach)
}
if m.testingOverrides != nil {
// Allow tests, where testingOverrides is set, to see test providers in locks
for provider, factory := range m.testingOverrides.Providers {
factories[provider] = factoryView on GitHub (pinned to d32a084675)