jdx/mise · error

the stamp for packslip

Error message

the stamp for packslip:{project}@{} from {} records no sha256 for {}, so nothing says the manifest is the one that host reviewed

What it means

A stamp (record of a host having reviewed a packslip manifest) exists but records no sha256 digest. Without the digest nothing ties the stamp's review claim to a specific file, so mise refuses to treat the stamped URL as reviewed content.

Solutions

  1. Regenerate the stamp so it records the sha256 of the exact reviewed manifest
  2. Remove the stamp so mise falls back to requiring the original vendor release asset
  3. Fix whatever stamping host/tool wrote the digest-less stamp to include sha256

Example fix

null
Defensive patterns

Strategy: validation

Validate before calling

// before accepting a stamp, require the digest field
if let Some(stamp) = &stamp {
    assert!(stamp.digest.is_some(), "stamp must record sha256");
}

Type guard

null

Try / catch

null

Prevention

When it happens

Trigger: verified_release (called from candidate_exclusion/resolve_lock_info) receives Some(stamp) whose stamp.digest is None while consulting the vendor for withdrawals and the digest pin.

Common situations: A mirror host generated a stamp without computing the manifest digest; a hand-written or tool-migrated stamp entry omits the digest field; the stamp format was extended and older stamps predate digests.

Understand the failure class

Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/21ee3ff49aaa1a20. Report an issue: GitHub.

Appendix: source

Thrown at src/backend/packslip.rs:896

    /// any target platform, while latest-version selection uses the same policy
    /// path to decide whether a candidate is eligible.
    async fn verified_release(
        &self,
        project: &str,
        tv: &ToolVersion,
        pin: &Pin,
        opts: &PackslipOptions<'_>,
        stamp: Option<&crate::packslip_stamps::Stamp>,
    ) -> Result<(Statement, packslip::Verified)> {
        use sha2::{Digest, Sha256};

        // With a stamp in hand the manifest is already named, so the vendor is
        // asked only for withdrawals and its digest pin. Requiring the original
        // release asset here would refuse a stamped mirror that install accepts.
        let (url, vendor_digest) = match stamp {
            Some(stamp) => {
                if stamp.digest.is_none() {
                    bail!(
                        "the stamp for packslip:{project}@{} from {} records no sha256 for {}, so nothing says the manifest is the one that host reviewed",
                        tv.version,
                        stamp.host,
                        stamp.entry.packslip
                    );
                }
                (
                    stamp.entry.packslip.clone(),
                    self.vendor_entry(project, tv, pin, opts)
                        .await?
                        .and_then(|vendor| vendor.digest),
                )
            }
            None => {
                let vendor = self.locate_bundle(project, tv, pin, opts).await?;
                (vendor.url, vendor.digest)
            }
        };

View on GitHub (pinned to 533346cc37)