[Bug 934751] New: Bad checksum on repository
http://bugzilla.opensuse.org/show_bug.cgi?id=934751 Bug ID: 934751 Summary: Bad checksum on repository Classification: openSUSE Product: openSUSE Distribution Version: 13.2 Hardware: x86-64 OS: openSUSE 13.2 Status: NEW Severity: Normal Priority: P5 - None Component: Maintenance Assignee: bnc-team-screening@forge.provo.novell.com Reporter: jamesrome@alum.mit.edu QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Retrieving repository 'openSUSE:13.2:Update' metadata -----------------------------------------------------------------------------------------------------[|] Warning: Digest verification failed for file '03f8cec0b5ba52d39c90891a512c6d2ca7d7b125aa1bed572372463bcbe37c5f-appdata.xml.gz' [/var/cache/zypp/raw/openSUSE:13.2:UpdateqhyOCY/repodata/03f8cec0b5ba52d39c90891a512c6d2ca7d7b125aa1bed572372463bcbe37c5f-appdata.xml.gz] expected 4b7b13246a375b856bfaff1f019ca731f289408604329e47135520637217e549 but got e6c5988694e984d4674f01930765d016f384d5c5d33b2655ec3f397e23e47ab0 Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c1
Bernhard Wiedemann
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c2
--- Comment #2 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c5
--- Comment #5 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c6
--- Comment #6 from Michael Andres
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c7
--- Comment #7 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c8
--- Comment #8 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c9
--- Comment #9 from Michael Andres
/var/cache/zypp/raw/openSUSE:13.2:Update@@@@@@/repodata
and not accidentally from the original repo (without the @@@@@@)
/var/cache/zypp/raw/openSUSE:13.2:Update/repodata
I'm asking because the attached file has the correct checksum (4b7b1324) -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c10
--- Comment #10 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c11
--- Comment #11 from Michael Andres
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c12
--- Comment #12 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c13
--- Comment #13 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c14
--- Comment #14 from Michael Andres
[http://download.opensuse.org/ports/update/13.2/repodata/repomd.xml] <data type="appdata"> <location href="repodata/03f8cec0b5ba52d39c90891a512c6d2ca7d7b125aa1bed572372463bcbe37c5f-appdata.xml.gz" /> <checksum type="sha256">33949d687153a3ab9e5e39713a1768690fa6c672df9cbc30e28af69414f95c6c</checksum> <timestamp>1435145552</timestamp> <size>568279</size> <open-checksum type="sha256">fa03e49e929bd234f5c8a49971f215482fb99a4b30820092ac3694bd39f37231</open-checksum> </data>
Same here. Checksumm is 4df95663ea6. Looks like the file has changed, but not the filename. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c15
Michael Andres
[http://gd.tuwien.ac.at/opsys/linux/opensuse/ports/update/13.2] <data type="appdata"> <location href="repodata/03f8cec0b5ba52d39c90891a512c6d2ca7d7b125aa1bed572372463bcbe37c5f-appdata.xml.gz" /> <checksum type="sha256">4df95663ea673827c548aaeeebddbf34d8566edd08b58ca052a5cd6c96cbf509</checksum> <timestamp>1434989566</timestamp> <size>568279</size> <open-checksum type="sha256">fa03e49e929bd234f5c8a49971f215482fb99a4b30820092ac3694bd39f37231</open-checksum> </data>
I always thought the funny checksum-like string in front of the file name (03f8cec0b5ba52...-appdata.xml.gz) should change whenever the content changes; in order to avoid such a name clash? -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c16
--- Comment #16 from Adrian Schröter
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c17
--- Comment #17 from Adrian Schröter
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c18
--- Comment #18 from Adrian Schröter
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c19
Michael Andres
[http://gd.tuwien.ac.at/opsys/linux/opensuse/ports/update/13.2] <data type="appdata"> <location href="repodata/03f8cec0b5ba52d39c90891a512c6d2ca7d7b125aa1bed572372463bcbe37c5f-appdata.xml.gz" /> <checksum type="sha256">78dab2d5caaf2b5f27e045cf3cd67656a5558500a02d224ba13b4b9f374e3550</checksum> <timestamp>1435167125</timestamp> <size>568279</size> <open-checksum type="sha256">fa03e49e929bd234f5c8a49971f215482fb99a4b30820092ac3694bd39f37231</open-checksum> </data>
Mirrors got new metadata (from 1435167125 Wed Jun 24 19:32:05 2015), new checksums but the filename is still the same (03f8cec0b5ba52...-appdata.xml.gz). I'll assign it to you as a reminder. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c20
--- Comment #20 from James Rome
http://bugzilla.opensuse.org/show_bug.cgi?id=934751
http://bugzilla.opensuse.org/show_bug.cgi?id=934751#c21
Karl Cheng
participants (1)
-
bugzilla_noreply@novell.com