GNU bug report logs - #40017
hplip-3.20.2 source tarball hash mismatch

Previous Next

Package: guix;

Reported by: Mark H Weaver <mhw <at> netris.org>

Date: Tue, 10 Mar 2020 18:30:02 UTC

Severity: normal

Done: Tobias Geerinckx-Rice <me <at> tobias.gr>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Tobias Geerinckx-Rice <me <at> tobias.gr>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#40017: closed (hplip-3.20.2 source tarball hash mismatch)
Date: Tue, 10 Mar 2020 21:05:02 +0000
[Message part 1 (text/plain, inline)]
Your message dated Tue, 10 Mar 2020 22:05:03 +0100
with message-id <87blp3j4zk.fsf <at> nckx>
and subject line Re: hplip-3.20.2 source tarball hash mismatch
has caused the debbugs.gnu.org bug report #40017,
regarding hplip-3.20.2 source tarball hash mismatch
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
40017: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=40017
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Mark H Weaver <mhw <at> netris.org>
To: bug-guix <at> gnu.org
Cc: Tobias Geerinckx-Rice <me <at> tobias.gr>
Subject: hplip-3.20.2 source tarball hash mismatch
Date: Tue, 10 Mar 2020 14:28:45 -0400
The following commit updated hplip to 3.20.2, but the actual hash of the
source tarball does not match the expected hash in the commit.

     Thanks,
       Mark

--8<---------------cut here---------------start------------->8---
commit ed2d015d293fb0ffa3e47f98f1db625b91420d94
Author: Tobias Geerinckx-Rice <me <at> tobias.gr>
Date:   Sat Mar 7 01:34:19 2020 +0100

  gnu: hplip: Update to 3.20.2.
  
  * gnu/packages/cups.scm (hplip): Update to 3.20.2.
--8<---------------cut here---------------end--------------->8---


--8<---------------cut here---------------start------------->8---
building /gnu/store/2gdh5gd2bx4f91v7vikpq7gq6vcil1bl-hplip-3.20.2.tar.gz.drv...

Starting download of /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz
From http://downloads.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz...
following redirection to `https://phoenixnap.dl.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz'...
downloading from http://downloads.sourceforge.net/project/hplip/hplip/3.20.2/hplip-3.20.2.tar.gz...
 hplip-3.20.2.tar.gz  24.5MiB                  1.0MiB/s 00:24 [##################] 100.0%
sha256 hash mismatch for /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz:
  expected hash: 1hkiyj29vzmz14cy68g94i617ymxinzvjvcsfdd78kcbd1s9vi4h
  actual hash:   00vcbpnp478l2v61mlxb4kr6q3gzkxspm4lwfky39f6ck72pqxb7
hash mismatch for store item '/gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz'
build of /gnu/store/2gdh5gd2bx4f91v7vikpq7gq6vcil1bl-hplip-3.20.2.tar.gz.drv failed
--8<---------------cut here---------------end--------------->8---


[Message part 3 (message/rfc822, inline)]
From: Tobias Geerinckx-Rice <me <at> tobias.gr>
To: Mark H Weaver <mhw <at> netris.org>
Cc: 40017-done <at> debbugs.gnu.org
Subject: Re: hplip-3.20.2 source tarball hash mismatch
Date: Tue, 10 Mar 2020 22:05:03 +0100
[Message part 4 (text/plain, inline)]
Mark,

Mark H Weaver 写道:
> The following commit updated hplip to 3.20.2, but the actual 
> hash of the
> source tarball does not match the expected hash in the commit.

[…]

> sha256 hash mismatch for 
> /gnu/store/xnqrxpngp4505228zib9zp8b5n7v4ri6-hplip-3.20.2.tar.gz:
>   expected hash: 
>   1hkiyj29vzmz14cy68g94i617ymxinzvjvcsfdd78kcbd1s9vi4h
>   actual hash: 
>   00vcbpnp478l2v61mlxb4kr6q3gzkxspm4lwfky39f6ck72pqxb7

Thanks.  This happens, although I wish it would stop.

The differences are: timestamps, differing .ppd.gz file order in 
.inc files, and a modified pre-compiled binary (locatedriver). 
Luckily, the latter is snippeted out, leaving only harmless 
changes AFAICT.

Here's the original diff, although the list will probably scrub 
it:

[hplipdiff.lz (application/octet-stream, attachment)]
[Message part 6 (text/plain, inline)]
The world would be a better place if $big_hosters didn't allow 
rewriting tarballs in-place.  But then people would upload their 
privkeys and cry.

Fixed with 6048241f10210c79925ca40b75c8697d2b2a5848.

Kind regards,

T G-R
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 5 years and 70 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.