siyuan-note/siyuan · warning

checksum manifest is unavailable

Error message

checksum manifest is unavailable

What it means

getGitHubManifestChecksum locates the SHA256SUMS.txt asset on the selected GitHub release and requires it to exist, be in 'uploaded' state, and have a browser download URL. If the manifest asset is missing, still 'uploading', or lacks a URL, it cannot verify the package checksum and returns this error. The caller (getGitHubUpdateRelease) logs a warning and degrades gracefully — the release is still returned without a checksum.

Solutions

  1. Wait a few minutes and retry the update check until the release's assets finish uploading (state becomes 'uploaded')
  2. Verify on the GitHub release page that SHA256SUMS.txt is attached; if missing, await a maintainer fix or download the installer manually without checksum verification
  3. If asset.Digest (sha256 of the package) is present on the package asset, the manifest path is skipped entirely — newer releases with digests avoid this error
  4. This is non-fatal in-kernel: the update flow continues with no checksum, but manual verification is recommended before installing
Defensive patterns

Strategy: fallback

Validate before calling

asset := findGitHubReleaseAsset(release, "SHA256SUMS.txt")
manifestReady := asset != nil && asset.State == "uploaded" && asset.BrowserDownloadURL != ""

Type guard

func manifestReady(a *githubReleaseAsset) bool {
    return a != nil && a.State == "uploaded" && a.BrowserDownloadURL != ""
}

Try / catch

checksum, err := getGitHubManifestChecksum(ctx, release, pkg)
if err != nil {
    logging.LogWarnf("checksum unavailable: %s", err) // proceed without checksum, as getGitHubUpdateRelease does
}

Prevention

When it happens

Trigger: Update check on a non-stable channel when the selected release lacks a SHA256SUMS.txt asset entirely, the asset's API state is not 'uploaded' (e.g. 'started' during publish), or browser_download_url is empty.

Common situations: Checking for updates seconds/minutes after a new release is published while GitHub is still uploading assets; maintainer forgot to attach SHA256SUMS.txt; GitHub asset upload partially failed.

Understand the failure class

Background: 'Could not be found', 'does not exist', 'not found in database': the resource-not-found family when an ID, slug, key, or URI lookup comes back empty — this error's family across 20 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/2dd48caf6e827b78. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/updater_release.go:366

			return ""
		}
	}
	return ""
}

func findGitHubReleaseAsset(release *githubRelease, name string) *githubReleaseAsset {
	for _, asset := range release.Assets {
		if nil != asset && name == asset.Name {
			return asset
		}
	}
	return nil
}

func getGitHubManifestChecksum(ctx context.Context, release *githubRelease, pkgName string) (string, error) {
	manifestAsset := findGitHubReleaseAsset(release, "SHA256SUMS.txt")
	if nil == manifestAsset || "uploaded" != manifestAsset.State || "" == manifestAsset.BrowserDownloadURL {
		return "", errors.New("checksum manifest is unavailable")
	}
	manifestDigest := normalizeSHA256(manifestAsset.Digest)
	manifestCacheKey := ""
	if "" != manifestDigest {
		manifestCacheKey = manifestAsset.BrowserDownloadURL + "#" + manifestDigest
	}
	if "" != manifestCacheKey {
		cached, ok := githubManifestCache.Load(manifestCacheKey)
		if ok {
			if checksum := parseChecksumManifest(cached.(string), pkgName); "" != checksum {
				return checksum, nil
			}
			return "", errors.New("package checksum is unavailable")
		}
	}

	response, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)
	if err != nil {

View on GitHub (pinned to 9f775e8a12)