siyuan-note/siyuan · critical
verify checksum failed, download install package
Error message
verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]
What it means
After downloading an install package, downloadInstallPkg computes the SHA-256 of the saved file and compares it with the checksum published in the release metadata. On mismatch it returns this error, logs it, and deletes the corrupted/tampered download so a bad package is never installed.
Solutions
- Retry the update — the bad file was removed, and a fresh download usually fixes transient corruption
- Check network/proxy stability or switch networks for large package downloads
- If using a mirror, verify it serves the exact release asset bytes
- If it persists, verify the publisher's checksum actually matches the uploaded asset and report the broken release
Defensive patterns
Strategy: retry
Try / catch
if err := downloadInstallPkg(pkgURL, checksum); err != nil {
if strings.Contains(err.Error(), "verify checksum failed") {
scheduleRetry(15 * time.Minute) // 重新下载
return
}
logging.LogErrorf("install package download failed: %s", err)
} Prevention
- Verify network/proxy stability for large downloads
- Compare the downloaded file's SHA-256 with the published checksum manually when a mirror is involved
- Keep temp-disk healthy; ensure releases re-publish checksums when assets change
When it happens
Trigger: A completed download's file hash differs from the release checksum — interrupted/corrupted transfer, a CDN serving a stale or different asset, or the published checksum not matching the uploaded asset.
Common situations: Unstable network or proxy truncating large downloads; update mirror out of sync with the release; publisher re-uploading an asset without updating the checksum; disk corruption in the temp directory.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- : [ ] checksum is unavailable
- download failed:
- errUpdatePackageUnavailable
- get bazaar package failed
- update package URL or checksum is empty
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/3b60ca3d6a38b535.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/updater.go:175
logging.LogInfof("downloading install package [%s]", pkgURL)
client := req.C().SetTLSHandshakeTimeout(7 * time.Second).SetTimeout(10 * time.Minute).DisableInsecureSkipVerify().SetUserAgent(util.UserAgent)
callback := func(info req.DownloadInfo) {
progress := fmt.Sprintf("%.2f%%", float64(info.DownloadedSize)/float64(info.Response.ContentLength)*100.0)
// logging.LogDebugf("downloading install package [%s %s]", pkgURL, progress)
util.PushStatusBar(fmt.Sprintf(Conf.Language(133), progress))
}
_, err = client.R().SetOutputFile(savePath).SetDownloadCallbackWithInterval(callback, 1*time.Second).Get(pkgURL)
if err != nil {
logging.LogErrorf("download install package [%s] failed: %s", pkgURL, err)
if removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {
logging.LogErrorf("remove incomplete install package [%s] failed: %s", savePath, removeErr)
}
return
}
localChecksum, _ := sha256Hash(savePath)
if checksum != localChecksum {
err = fmt.Errorf("verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]", pkgURL, checksum, savePath, localChecksum)
logging.LogError(err.Error())
if removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {
logging.LogErrorf("remove invalid install package [%s] failed: %s", savePath, removeErr)
}
return
}
logging.LogInfof("downloaded install package [%s] to [%s]", pkgURL, savePath)
util.PushStatusBar(Conf.Language(62))
return
}
func sha256Hash(filename string) (ret string, err error) {
file, err := os.Open(filename)
if err != nil {
return
}
defer file.Close()
View on GitHub (pinned to 9f775e8a12)