[Bug 1014265] New: Zypper: "unblock" a package with bad digest has no effect
http://bugzilla.suse.com/show_bug.cgi?id=1014265 Bug ID: 1014265 Summary: Zypper: "unblock" a package with bad digest has no effect Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.2 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Basesystem Assignee: bnc-team-screening@forge.provo.novell.com Reporter: hguo@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- When user attempts to install a package with bad digest, zypper says: ================= Warning: Digest verification failed for file 'xxxxx' [xxxxx.rpm] expected aaaaa but got bbbbb Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise. However if you made certain that the file with checksum 'aaaa..' is secure, correct and should be used within this operation, enter the first 4 characters of the checksum to unblock using this file on your own risk. Empty input will discard the file. ======================== By answering the checksum back to zypper, it should proceed to install the package, however it isn't happening: ======================== Unblock or discard? [aaaa/? shows all options] (discard): aaaa Package xxxxxx seems to be corrupted during transfer. Do you want to retry retrieval? Abort, retry, ignore? [a/r/i] (a): i Installation has completed with error. ======================== Previously zypper would proceed to install the package given the digest value is answered. This is a regression. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Howard Guo
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Chenzi Cao
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Michael Andres
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c1
--- Comment #1 from Michael Andres
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c2
Michael Andres
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c3
--- Comment #3 from Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c4
--- Comment #4 from Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c5
--- Comment #5 from Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c6
--- Comment #6 from Swamp Workflow Management
http://bugzilla.suse.com/show_bug.cgi?id=1014265
http://bugzilla.suse.com/show_bug.cgi?id=1014265#c7
--- Comment #7 from Swamp Workflow Management
participants (1)
-
bugzilla_noreply@novell.com