<!-- Same check, but reached only after a stale cache entry was already
discarded and re-downloaded once: a mismatch here is not the stale
cache biting us a second time, it means the release itself changed
or the pin is wrong, so say that plainly instead of leaving it to
read like the plain case above. -->
<failmessage="Digest mismatch for @{asset} even after discarding a stale cached copy and re-downloading fresh: expected @{sha256}, got ${@{asset}.actual}. This is not a stale-cache symptom -- the pinned digest or the released asset itself needs checking.">