{"record":{"id":"82efd039d5052a9a","repo":"dotnet/efcore","slug":"could-not-find-checksum-for-path-in-release-file","errorCode":null,"errorMessage":"Could not find checksum for {path} in Release file.","messagePattern":"Could not find checksum for (.+?) in Release file\\.","errorType":"exception","errorClass":"Exception","httpStatus":null,"severity":"error","filePath":"eng/common/cross/install-debs.py","lineNumber":154,"sourceCode":"\n        print(\"Signature verified successfully.\")\n\n        with open(release_file.name) as f:\n            return f.read()\n\ndef parse_release_file(content, path):\n    \"\"\"Parses the Release file and returns sha256 checksum of the specified path.\"\"\"\n\n    # data looks like this:\n    # <checksum>  <size>  <path>\n    matches = re.findall(r'^ (\\S*) +(\\S*) +(\\S*)$', content, re.MULTILINE)\n\n    for entry in matches:\n        # the file has both md5 and sha256 checksums, we want sha256 which has a length of 64\n        if entry[2] == path and len(entry[0]) == 64:\n            return entry[0]\n\n    raise Exception(f\"Could not find checksum for {path} in Release file.\")\n\ndef parse_debian_version(version):\n    \"\"\"Parse a Debian package version into epoch, upstream version, and revision.\"\"\"\n    match = re.match(r'^(?:(\\d+):)?([^-]+)(?:-(.+))?$', version)\n    if not match:\n        raise ValueError(f\"Invalid Debian version format: {version}\")\n    epoch, upstream, revision = match.groups()\n    return int(epoch) if epoch else 0, upstream, revision or \"\"\n\ndef compare_upstream_version(v1, v2):\n    \"\"\"Compare upstream or revision parts using Debian rules.\"\"\"\n    def tokenize(version):\n        tokens = re.split(r'([0-9]+|[A-Za-z]+)', version)\n        return [int(x) if x.isdigit() else x for x in tokens if x]\n\n    tokens1 = tokenize(v1)\n    tokens2 = tokenize(v2)\n","sourceCodeStart":136,"sourceCodeEnd":172,"githubUrl":"https://github.com/dotnet/efcore/blob/3a2006ef569de08368d59db5e1468aa8f407e4f8/eng/common/cross/install-debs.py#L136-L172","documentation":"Raised by parse_release_file when no SHA256 entry (a line matching '^ (\\S*) +(\\S*) +(\\S*)$' whose first field is 64 chars and whose path field equals {path}) is found in the Release file. It means the Release file the mirror served does not list a checksum for the requested Packages.gz path.","triggerScenarios":"check_sig is on; parse_release_file is asked for {component}/binary-{arch}/Packages.gz but the Release file contains no SHA256 line for that exact path.","commonSituations":"The arch is not published for that suite (e.g. loong64 missing), the component does not exist on that mirror (the code hardcodes both main and universe, but Debian ports mirrors often only have main), a suite name typo, or a Release file format change that breaks the leading-space regex.","solutions":["curl -s {mirror}/dists/{suite}/Release and grep for the exact path ({component}/binary-{arch}/Packages.gz) to see whether it is listed.","Correct --arch and --suite to a combination the mirror actually publishes.","If the mirror only has 'main', patch the hardcoded component list ['main','universe'] in download_package_index_parallel to drop the missing component.","Switch to a mirror that publishes the full component set for your suite."],"exampleFix":"// before\nfor component in [\"main\", \"universe\"]:  # hardcoded; 'universe' absent on Debian ports mirrors\n\n// after\nfor component in [\"main\"]:  # only iterate components the mirror actually publishes","handlingStrategy":"validation","validationCode":"# preflight: confirm the Release file lists a SHA256 for every path we will request\nimport urllib.request\nrel = urllib.request.urlopen(f\"{mirror}/dists/{suite}/Release\").read().decode()\nfor component in [\"main\", \"universe\"]:\n    path = f\"{component}/binary-{arch}/Packages.gz\"\n    if not any(line.rstrip().endswith(path) and len(line.split()[0]) == 64 for line in rel.splitlines() if line.startswith(\" \")):\n        print(f\"WARNING: Release has no SHA256 for {path}; this suite/component/arch will fail\")","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Confirm the suite actually publishes the requested arch and components before running.","Patch the hardcoded component list to match what the mirror serves.","Avoid typos in --suite; suite names are case- and spelling-sensitive."],"tags":["gpg","release-file","mirror","configuration"],"backgroundTag":null,"analyzedSha":"3a2006ef569de08368d59db5e1468aa8f407e4f8","analyzedAt":"2026-08-11T23:42:04.146Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}