jdx/mise · error
could not resolve the configured checksum for
Error message
could not resolve the configured checksum for {} on {} What it means
An HTTP-backend checksum source was configured (checksum URL/manifest) but produced no checksum for this specific platform target. When lockfile generation is enabled, mise treats this as a hard error rather than silently writing an unverified url-only lockfile entry, because the resulting lockfile could not pin integrity for that artifact.
Solutions
- Fix the checksum_file/checksum_url pattern so it matches the target asset's name in the manifest
- Verify the checksum URL is reachable and lists an entry for this platform's artifact
- Disable generate_lockfiles (or set lockfile=false) if you accept an unverified url-only entry — note the warning this emits
Example fix
// before (mise.toml) checksum_file = "SHA256SUMS" # asset missing from this file // after checksum_file = "SHA256SUMS-linux-x64" # or pattern matching the target asset
Defensive patterns
Strategy: validation
Validate before calling
// bash: confirm the checksum manifest actually lists the target asset before install
curl -fsSL "$CHECKSUM_URL" | grep -q "${ASSET_NAME}$" || { echo 'checksum manifest missing asset'; exit 1; } Prevention
- Verify the checksum_file/checksum_url pattern matches every platform's asset name
- Test installs on all target platforms, not just the one used to author the config
- Monitor checksum-host availability; prefer checksum files bundled in the release
When it happens
Trigger: Installing an HTTP-backend tool where opts.checksum_url_for_target(target) returns Some but resolution yields checksum == None (manifest lacks the target's filename, SHASUMS naming mismatch, checksum file unreachable), with generate_lockfiles enabled.
Common situations: Upstream publishes SHASUMS files that don't include this platform's asset name; checksum_file pattern doesn't match the asset; checksum host is down or URL changed.
Related errors
- expected exactly one Hex OTP build record for
- Invalid checksum
- Invalid checksum
- Invalid lockfile checksum for precompiled Erlang/OTP
- invalid lockfile format for tool
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/5e61c5bb4a7b223d.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/http.rs:1173
// entry that is miscounted as a successful platform (see #7113).
let Some(url) = self.lock_url_for_target(&opts, tv, target) else {
return Err(crate::errors::Error::UnsupportedTarget(format!(
"no URL configured for {} on {}; skipping",
self.ba.full(),
target.to_key()
))
.into());
};
let checksum = self.resolve_lock_checksum(&opts, tv, target, &url).await;
// A checksum source was configured but produced nothing for this target
// (manifest miss, SHASUMS naming mismatch, unreachable file, ...). The
// url-only entry is still written, but surface it so it isn't a silent
// drop of checksum verification.
if checksum.is_none() && opts.checksum_url_for_target(target).is_some() {
if Settings::get().generate_lockfiles() {
eyre::bail!(
"could not resolve the configured checksum for {} on {}",
self.ba.full(),
target.to_key()
);
}
warn!(
"could not resolve a checksum for {} on {}; locking the URL without checksum verification",
self.ba.full(),
target.to_key()
);
}
Ok(PlatformInfo {
url: Some(url),
checksum,
..Default::default()
})
}View on GitHub (pinned to 533346cc37)