jdx/mise · error
the stamp for packslip
Error message
the stamp for packslip:{project}@{} from {} records no sha256 for {}, so nothing says the manifest is the one that host reviewed What it means
A stamp (record of a host having reviewed a packslip manifest) exists but records no sha256 digest. Without the digest nothing ties the stamp's review claim to a specific file, so mise refuses to treat the stamped URL as reviewed content.
Solutions
- Regenerate the stamp so it records the sha256 of the exact reviewed manifest
- Remove the stamp so mise falls back to requiring the original vendor release asset
- Fix whatever stamping host/tool wrote the digest-less stamp to include sha256
Example fix
null
Defensive patterns
Strategy: validation
Validate before calling
// before accepting a stamp, require the digest field
if let Some(stamp) = &stamp {
assert!(stamp.digest.is_some(), "stamp must record sha256");
} Type guard
null
Try / catch
null
Prevention
- Always emit the sha256 when generating stamps
- Validate stamp files after any stamping-tool migration
- Treat digest-less stamps as invalid at write time, not install time
When it happens
Trigger: verified_release (called from candidate_exclusion/resolve_lock_info) receives Some(stamp) whose stamp.digest is None while consulting the vendor for withdrawals and the digest pin.
Common situations: A mirror host generated a stamp without computing the manifest digest; a hand-written or tool-migrated stamp entry omits the digest field; the stamp format was extended and older stamps predate digests.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
Related errors
- packslip: @ : manifest digest differs from signed list
- packslip: @ : manifest digest differs from signed list
- brew-cask: : cask metadata has no sha256
- cached OCI layer digest mismatch
- packslip: @ : verified manifest project/version differs…
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/21ee3ff49aaa1a20.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/packslip.rs:896
/// any target platform, while latest-version selection uses the same policy
/// path to decide whether a candidate is eligible.
async fn verified_release(
&self,
project: &str,
tv: &ToolVersion,
pin: &Pin,
opts: &PackslipOptions<'_>,
stamp: Option<&crate::packslip_stamps::Stamp>,
) -> Result<(Statement, packslip::Verified)> {
use sha2::{Digest, Sha256};
// With a stamp in hand the manifest is already named, so the vendor is
// asked only for withdrawals and its digest pin. Requiring the original
// release asset here would refuse a stamped mirror that install accepts.
let (url, vendor_digest) = match stamp {
Some(stamp) => {
if stamp.digest.is_none() {
bail!(
"the stamp for packslip:{project}@{} from {} records no sha256 for {}, so nothing says the manifest is the one that host reviewed",
tv.version,
stamp.host,
stamp.entry.packslip
);
}
(
stamp.entry.packslip.clone(),
self.vendor_entry(project, tv, pin, opts)
.await?
.and_then(|vendor| vendor.digest),
)
}
None => {
let vendor = self.locate_bundle(project, tv, pin, opts).await?;
(vendor.url, vendor.digest)
}
};View on GitHub (pinned to 533346cc37)