ruvnet/ruflo · error · ReleaseVerificationError
SHA256SUMS has no entry for
Error message
SHA256SUMS has no entry for ${input.assetFilename} What it means
After the manifest signature verifies, verifyRelease() looks up the exact asset filename (built by releaseAssetFilename, e.g. meta-proxy-1.2.3-x86_64-unknown-linux-gnu.tar.gz) in the parsed SHA256SUMS. If the release was published without an entry for that file, there is no hash to compare against, and the install is refused — a missing entry counts as a verification failure, not a skip.
Solutions
- Open the release page for your version and confirm SHA256SUMS actually lists your platform's archive
- Update the ruflo CLI — filename construction mismatches are fixed alongside release tooling changes
- Install on a triple that is listed in the manifest, or wait for maintainers to republish a complete one
- Report the release version plus the missing filename upstream
Defensive patterns
Strategy: try-catch
Validate before calling
import { parseSha256Sums, releaseAssetFilename, detectTargetTriple } from '@claude-flow/cli/.../proxy/index.js';
const sums = parseSha256Sums(sumsBytes.toString('utf8'));
if (!sums[releaseAssetFilename(version, detectTargetTriple())]) {
throw new Error('release manifest lacks an entry for this platform — update ruflo or pick a listed triple');
} Type guard
const isReleaseVerification = (e: unknown): e is Error & { name: 'ReleaseVerificationError' } =>
e instanceof Error && e.name === 'ReleaseVerificationError'; Try / catch
try {
verifyRelease(input);
} catch (e) {
if (isReleaseVerification(e) && /has no entry for/.test(e.message)) {
// manifest drift: choose a listed triple or upgrade CLI — never skip verification
throw new Error(`release incomplete for this platform: ${e.message}`);
}
throw e;
} Prevention
- Smoke-test installs on all five triples in release CI
- Upgrade CLI and proxy releases together
- Treat missing manifest entries as release-tooling bugs, not user error
When it happens
Trigger: A release that publishes an archive for a platform but omits that file from SHA256SUMS; or a filename-scheme drift between what this CLI version constructs (version prefix, triple naming) and how the release assets were actually named.
Common situations: Partially-published releases (assets uploaded before the manifest was regenerated); version-scheme changes (v-prefix, build metadata) mismatching filename construction; new triples added to assets but not to the signing job.
Related errors
- extracted binary path failed validation
- SHA256SUMS.sig failed Ed25519 verification — refusing to…
- AI budget file is a symlink (refusing)
- AI job registry is a symlink (refusing)
- AIDefence failed to load
AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18).
Data as JSON: /api/errors/8293088b6ac4a185.
Report an issue: GitHub.
Appendix: source
Thrown at v3/@claude-flow/cli/src/proxy/verify.ts:85
export interface VerifyReleaseResult {
sha256: string;
}
/**
* Full verification: signature over SHA256SUMS, then the asset's own hash
* against the matching line. Throws `ReleaseVerificationError` on ANY
* failure — there is no partial-trust outcome, matching ADR-307's "refuses
* on any mismatch" requirement.
*/
export function verifyRelease(input: VerifyReleaseInput): VerifyReleaseResult {
if (!verifySha256SumsSignature(input.sumsBytes, input.sigBase64, input.pubkeyPem)) {
throw new ReleaseVerificationError('SHA256SUMS.sig failed Ed25519 verification — refusing to install');
}
const sums = parseSha256Sums(input.sumsBytes.toString('utf-8'));
const expected = sums[input.assetFilename];
if (!expected) {
throw new ReleaseVerificationError(`SHA256SUMS has no entry for ${input.assetFilename}`);
}
const actual = sha256Hex(input.assetBytes);
if (actual !== expected) {
throw new ReleaseVerificationError(
`sha256 mismatch for ${input.assetFilename}: expected ${expected.slice(0, 12)}…, got ${actual.slice(0, 12)}…`,
);
}
return { sha256: actual };
}
View on GitHub (pinned to fa13ee4ad6)