siyuan-note/siyuan · critical

verify checksum failed, download install package

Error message

verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]

What it means

After downloading an install package, downloadInstallPkg computes the SHA-256 of the saved file and compares it with the checksum published in the release metadata. On mismatch it returns this error, logs it, and deletes the corrupted/tampered download so a bad package is never installed.

Solutions

  1. Retry the update — the bad file was removed, and a fresh download usually fixes transient corruption
  2. Check network/proxy stability or switch networks for large package downloads
  3. If using a mirror, verify it serves the exact release asset bytes
  4. If it persists, verify the publisher's checksum actually matches the uploaded asset and report the broken release
Defensive patterns

Strategy: retry

Try / catch

if err := downloadInstallPkg(pkgURL, checksum); err != nil {
    if strings.Contains(err.Error(), "verify checksum failed") {
        scheduleRetry(15 * time.Minute) // 重新下载
        return
    }
    logging.LogErrorf("install package download failed: %s", err)
}

Prevention

When it happens

Trigger: A completed download's file hash differs from the release checksum — interrupted/corrupted transfer, a CDN serving a stale or different asset, or the published checksum not matching the uploaded asset.

Common situations: Unstable network or proxy truncating large downloads; update mirror out of sync with the release; publisher re-uploading an asset without updating the checksum; disk corruption in the temp directory.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/3b60ca3d6a38b535. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/updater.go:175

	logging.LogInfof("downloading install package [%s]", pkgURL)
	client := req.C().SetTLSHandshakeTimeout(7 * time.Second).SetTimeout(10 * time.Minute).DisableInsecureSkipVerify().SetUserAgent(util.UserAgent)
	callback := func(info req.DownloadInfo) {
		progress := fmt.Sprintf("%.2f%%", float64(info.DownloadedSize)/float64(info.Response.ContentLength)*100.0)
		// logging.LogDebugf("downloading install package [%s %s]", pkgURL, progress)
		util.PushStatusBar(fmt.Sprintf(Conf.Language(133), progress))
	}
	_, err = client.R().SetOutputFile(savePath).SetDownloadCallbackWithInterval(callback, 1*time.Second).Get(pkgURL)
	if err != nil {
		logging.LogErrorf("download install package [%s] failed: %s", pkgURL, err)
		if removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {
			logging.LogErrorf("remove incomplete install package [%s] failed: %s", savePath, removeErr)
		}
		return
	}

	localChecksum, _ := sha256Hash(savePath)
	if checksum != localChecksum {
		err = fmt.Errorf("verify checksum failed, download install package [%s] checksum [%s] not equal to downloaded [%s] checksum [%s]", pkgURL, checksum, savePath, localChecksum)
		logging.LogError(err.Error())
		if removeErr := os.Remove(savePath); nil != removeErr && !os.IsNotExist(removeErr) {
			logging.LogErrorf("remove invalid install package [%s] failed: %s", savePath, removeErr)
		}
		return
	}
	logging.LogInfof("downloaded install package [%s] to [%s]", pkgURL, savePath)
	util.PushStatusBar(Conf.Language(62))
	return
}

func sha256Hash(filename string) (ret string, err error) {
	file, err := os.Open(filename)
	if err != nil {
		return
	}
	defer file.Close()

View on GitHub (pinned to 9f775e8a12)