ruvnet/ruflo · error · ReleaseVerificationError

SHA256SUMS has no entry for

Error message

SHA256SUMS has no entry for ${input.assetFilename}

What it means

After the manifest signature verifies, verifyRelease() looks up the exact asset filename (built by releaseAssetFilename, e.g. meta-proxy-1.2.3-x86_64-unknown-linux-gnu.tar.gz) in the parsed SHA256SUMS. If the release was published without an entry for that file, there is no hash to compare against, and the install is refused — a missing entry counts as a verification failure, not a skip.

Solutions

  1. Open the release page for your version and confirm SHA256SUMS actually lists your platform's archive
  2. Update the ruflo CLI — filename construction mismatches are fixed alongside release tooling changes
  3. Install on a triple that is listed in the manifest, or wait for maintainers to republish a complete one
  4. Report the release version plus the missing filename upstream
Defensive patterns

Strategy: try-catch

Validate before calling

import { parseSha256Sums, releaseAssetFilename, detectTargetTriple } from '@claude-flow/cli/.../proxy/index.js';
const sums = parseSha256Sums(sumsBytes.toString('utf8'));
if (!sums[releaseAssetFilename(version, detectTargetTriple())]) {
  throw new Error('release manifest lacks an entry for this platform — update ruflo or pick a listed triple');
}

Type guard

const isReleaseVerification = (e: unknown): e is Error & { name: 'ReleaseVerificationError' } =>
  e instanceof Error && e.name === 'ReleaseVerificationError';

Try / catch

try {
  verifyRelease(input);
} catch (e) {
  if (isReleaseVerification(e) && /has no entry for/.test(e.message)) {
    // manifest drift: choose a listed triple or upgrade CLI — never skip verification
    throw new Error(`release incomplete for this platform: ${e.message}`);
  }
  throw e;
}

Prevention

When it happens

Trigger: A release that publishes an archive for a platform but omits that file from SHA256SUMS; or a filename-scheme drift between what this CLI version constructs (version prefix, triple naming) and how the release assets were actually named.

Common situations: Partially-published releases (assets uploaded before the manifest was regenerated); version-scheme changes (v-prefix, build metadata) mismatching filename construction; new triples added to assets but not to the signing job.

Related errors


AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18). Data as JSON: /api/errors/8293088b6ac4a185. Report an issue: GitHub.

Appendix: source

Thrown at v3/@claude-flow/cli/src/proxy/verify.ts:85

export interface VerifyReleaseResult {
  sha256: string;
}

/**
 * Full verification: signature over SHA256SUMS, then the asset's own hash
 * against the matching line. Throws `ReleaseVerificationError` on ANY
 * failure — there is no partial-trust outcome, matching ADR-307's "refuses
 * on any mismatch" requirement.
 */
export function verifyRelease(input: VerifyReleaseInput): VerifyReleaseResult {
  if (!verifySha256SumsSignature(input.sumsBytes, input.sigBase64, input.pubkeyPem)) {
    throw new ReleaseVerificationError('SHA256SUMS.sig failed Ed25519 verification — refusing to install');
  }

  const sums = parseSha256Sums(input.sumsBytes.toString('utf-8'));
  const expected = sums[input.assetFilename];
  if (!expected) {
    throw new ReleaseVerificationError(`SHA256SUMS has no entry for ${input.assetFilename}`);
  }

  const actual = sha256Hex(input.assetBytes);
  if (actual !== expected) {
    throw new ReleaseVerificationError(
      `sha256 mismatch for ${input.assetFilename}: expected ${expected.slice(0, 12)}…, got ${actual.slice(0, 12)}…`,
    );
  }

  return { sha256: actual };
}

View on GitHub (pinned to fa13ee4ad6)