siyuan-note/siyuan · warning
checksum manifest is unavailable
Error message
checksum manifest is unavailable
What it means
getGitHubManifestChecksum locates the SHA256SUMS.txt asset on the selected GitHub release and requires it to exist, be in 'uploaded' state, and have a browser download URL. If the manifest asset is missing, still 'uploading', or lacks a URL, it cannot verify the package checksum and returns this error. The caller (getGitHubUpdateRelease) logs a warning and degrades gracefully — the release is still returned without a checksum.
Solutions
- Wait a few minutes and retry the update check until the release's assets finish uploading (state becomes 'uploaded')
- Verify on the GitHub release page that SHA256SUMS.txt is attached; if missing, await a maintainer fix or download the installer manually without checksum verification
- If asset.Digest (sha256 of the package) is present on the package asset, the manifest path is skipped entirely — newer releases with digests avoid this error
- This is non-fatal in-kernel: the update flow continues with no checksum, but manual verification is recommended before installing
Defensive patterns
Strategy: fallback
Validate before calling
asset := findGitHubReleaseAsset(release, "SHA256SUMS.txt") manifestReady := asset != nil && asset.State == "uploaded" && asset.BrowserDownloadURL != ""
Type guard
func manifestReady(a *githubReleaseAsset) bool {
return a != nil && a.State == "uploaded" && a.BrowserDownloadURL != ""
} Try / catch
checksum, err := getGitHubManifestChecksum(ctx, release, pkg)
if err != nil {
logging.LogWarnf("checksum unavailable: %s", err) // proceed without checksum, as getGitHubUpdateRelease does
} Prevention
- Wait a few minutes after a release announcement before checking updates so assets finish uploading
- Prefer releases whose package assets carry a digest field; they skip the manifest path entirely
- Never auto-install with an empty checksum; prompt the user to verify manually
- Check the release page lists SHA256SUMS.txt before automating installs
When it happens
Trigger: Update check on a non-stable channel when the selected release lacks a SHA256SUMS.txt asset entirely, the asset's API state is not 'uploaded' (e.g. 'started' during publish), or browser_download_url is empty.
Common situations: Checking for updates seconds/minutes after a new release is published while GitHub is still uploading assets; maintainer forgot to attach SHA256SUMS.txt; GitHub asset upload partially failed.
Understand the failure class
Background: 'Could not be found', 'does not exist', 'not found in database': the resource-not-found family when an ID, slug, key, or URI lookup comes back empty — this error's family across 20 libraries.
Related errors
- checksum manifest digest mismatch
- checksum manifest is too large
- checksum manifest response is empty
- errUpdatePackageUnavailable
- get GitHub releases failed
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/2dd48caf6e827b78.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/updater_release.go:366
return ""
}
}
return ""
}
func findGitHubReleaseAsset(release *githubRelease, name string) *githubReleaseAsset {
for _, asset := range release.Assets {
if nil != asset && name == asset.Name {
return asset
}
}
return nil
}
func getGitHubManifestChecksum(ctx context.Context, release *githubRelease, pkgName string) (string, error) {
manifestAsset := findGitHubReleaseAsset(release, "SHA256SUMS.txt")
if nil == manifestAsset || "uploaded" != manifestAsset.State || "" == manifestAsset.BrowserDownloadURL {
return "", errors.New("checksum manifest is unavailable")
}
manifestDigest := normalizeSHA256(manifestAsset.Digest)
manifestCacheKey := ""
if "" != manifestDigest {
manifestCacheKey = manifestAsset.BrowserDownloadURL + "#" + manifestDigest
}
if "" != manifestCacheKey {
cached, ok := githubManifestCache.Load(manifestCacheKey)
if ok {
if checksum := parseChecksumManifest(cached.(string), pkgName); "" != checksum {
return checksum, nil
}
return "", errors.New("package checksum is unavailable")
}
}
response, err := httpclient.NewCloudRequest30s().SetContext(ctx).Get(manifestAsset.BrowserDownloadURL)
if err != nil {View on GitHub (pinned to 9f775e8a12)