GNU bug report logs - #40017
hplip-3.20.2 source tarball hash mismatch

Previous Next

Package: guix;

Reported by: Mark H Weaver <mhw <at> netris.org>

Date: Tue, 10 Mar 2020 18:30:02 UTC

Severity: normal

Done: Tobias Geerinckx-Rice <me <at> tobias.gr>

Bug is archived. No further changes may be made.

To add a comment to this bug, you must first unarchive it, by sending
a message to control AT debbugs.gnu.org, with unarchive 40017 in the body.
You can then email your comments to 40017 AT debbugs.gnu.org in the normal way.

Toggle the display of automated, internal messages from the tracker.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to bug-guix <at> gnu.org:
bug#40017; Package guix. (Tue, 10 Mar 2020 18:30:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mark H Weaver <mhw <at> netris.org>:
New bug report received and forwarded. Copy sent to bug-guix <at> gnu.org. (Tue, 10 Mar 2020 18:30:02 GMT) Full text and rfc822 format available.

Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):

From: Mark H Weaver <mhw <at> netris.org>
To: bug-guix <at> gnu.org
Cc: Tobias Geerinckx-Rice <me <at> tobias.gr>
Subject: hplip-3.20.2 source tarball hash mismatch
Date: Tue, 10 Mar 2020 14:28:45 -0400
The following commit updated hplip to 3.20.2, but the actual hash of the
source tarball does not match the expected hash in the commit.

     Thanks,
       Mark

--8<---------------cut here---------------start------------->8---
commit ed2d015d293fb0ffa3e47f98f1db625b91420d94
Author: Tobias Geerinckx-Rice <me <at> tobias.gr>
Date:   Sat Mar 7 01:34:19 2020 +0100

  gnu: hplip: Update to 3.20.2.
  
  * gnu/packages/cups.scm (hplip): Update to 3.20.2.
--8<---------------cut here---------------end--------------->8---


--8<---------------cut here---------------start------------->8---
building /gnu/store/2gdh5gd2bx4f91v7vikpq7gq6vcil1bl-hplip-3.20.2.tar.gz.drv...

Starting download of /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz
From http://downloads.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz...
following redirection to `https://phoenixnap.dl.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz'...
downloading from http://downloads.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz...
 hplip-3.20.2.tar.gz  24.5MiB                  1.0MiB/s 00:24 [##################] 100.0%
sha256 hash mismatch for /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz:
  expected hash: 1hkiyj29vzmz14cy68g94i617ymxinzvjvcsfdd78kcbd1s9vi4h
  actual hash:   00vcbpnp478l2v61mlxb4kr6q3gzkxspm4lwfky39f6ck72pqxb7
hash mismatch for store item '/gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz'
build of /gnu/store/2gdh5gd2bx4f91v7vikpq7gq6vcil1bl-hplip-3.20.2.tar.gz.drv failed
--8<---------------cut here---------------end--------------->8---




Reply sent to Tobias Geerinckx-Rice <me <at> tobias.gr>:
You have taken responsibility. (Tue, 10 Mar 2020 21:05:02 GMT) Full text and rfc822 format available.

Notification sent to Mark H Weaver <mhw <at> netris.org>:
bug acknowledged by developer. (Tue, 10 Mar 2020 21:05:02 GMT) Full text and rfc822 format available.

Message #10 received at 40017-done <at> debbugs.gnu.org (full text, mbox):

From: Tobias Geerinckx-Rice <me <at> tobias.gr>
To: Mark H Weaver <mhw <at> netris.org>
Cc: 40017-done <at> debbugs.gnu.org
Subject: Re: hplip-3.20.2 source tarball hash mismatch
Date: Tue, 10 Mar 2020 22:05:03 +0100
[Message part 1 (text/plain, inline)]
Mark,

Mark H Weaver 写道:
> The following commit updated hplip to 3.20.2, but the actual 
> hash of the
> source tarball does not match the expected hash in the commit.

[…]

> sha256 hash mismatch for 
> /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz:
>   expected hash: 
>   1hkiyj29vzmz14cy68g94i617ymxinzvjvcsfdd78kcbd1s9vi4h
>   actual hash: 
>   00vcbpnp478l2v61mlxb4kr6q3gzkxspm4lwfky39f6ck72pqxb7

Thanks.  This happens, although I wish it would stop.

The differences are: timestamps, differing .ppd.gz file order in 
.inc files, and a modified pre-compiled binary (locatedriver). 
Luckily, the latter is snippeted out, leaving only harmless 
changes AFAICT.

Here's the original diff, although the list will probably scrub 
it:

[hplipdiff.lz (application/octet-stream, attachment)]
[Message part 3 (text/plain, inline)]
The world would be a better place if $big_hosters didn't allow 
rewriting tarballs in-place.  But then people would upload their 
privkeys and cry.

Fixed with 6048241f10210c79925ca40b75c8697d2b2a5848.

Kind regards,

T G-R
[signature.asc (application/pgp-signature, inline)]

bug archived. Request was from Debbugs Internal Request <help-debbugs <at> gnu.org> to internal_control <at> debbugs.gnu.org. (Wed, 08 Apr 2020 11:24:05 GMT) Full text and rfc822 format available.

This bug report was last modified 4 years and 17 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.