{"record":{"id":"909ff41c913822a3","repo":"dotnet/aspnetcore","slug":"could-not-find-checksum-for-path-in-release-file","errorCode":null,"errorMessage":"Could not find checksum for {path} in Release file.","messagePattern":"Could not find checksum for (.+?) in Release file\\.","errorType":"exception","errorClass":"Exception","httpStatus":null,"severity":"error","filePath":"eng/common/cross/install-debs.py","lineNumber":154,"sourceCode":"\n        print(\"Signature verified successfully.\")\n\n        with open(release_file.name) as f:\n            return f.read()\n\ndef parse_release_file(content, path):\n    \"\"\"Parses the Release file and returns sha256 checksum of the specified path.\"\"\"\n\n    # data looks like this:\n    # <checksum>  <size>  <path>\n    matches = re.findall(r'^ (\\S*) +(\\S*) +(\\S*)$', content, re.MULTILINE)\n\n    for entry in matches:\n        # the file has both md5 and sha256 checksums, we want sha256 which has a length of 64\n        if entry[2] == path and len(entry[0]) == 64:\n            return entry[0]\n\n    raise Exception(f\"Could not find checksum for {path} in Release file.\")\n\ndef parse_debian_version(version):\n    \"\"\"Parse a Debian package version into epoch, upstream version, and revision.\"\"\"\n    match = re.match(r'^(?:(\\d+):)?([^-]+)(?:-(.+))?$', version)\n    if not match:\n        raise ValueError(f\"Invalid Debian version format: {version}\")\n    epoch, upstream, revision = match.groups()\n    return int(epoch) if epoch else 0, upstream, revision or \"\"\n\ndef compare_upstream_version(v1, v2):\n    \"\"\"Compare upstream or revision parts using Debian rules.\"\"\"\n    def tokenize(version):\n        tokens = re.split(r'([0-9]+|[A-Za-z]+)', version)\n        return [int(x) if x.isdigit() else x for x in tokens if x]\n\n    tokens1 = tokenize(v1)\n    tokens2 = tokenize(v2)\n","sourceCodeStart":136,"sourceCodeEnd":172,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/eng/common/cross/install-debs.py#L136-L172","documentation":"Raised by parse_release_file when the Release file's SHA256 checksum stanza has no entry for the requested relative path (e.g. main/binary-amd64/Packages.gz). The function iterates the regex matches and only returns an entry whose path equals the requested one and whose checksum is 64 hex chars long; falling through means the path is not listed.","triggerScenarios":"parse_release_file(release_file_content, path) loops over re.findall matches of the SHA256 stanza; if none has entry[2] == path, it raises. The path is built as f'{component}/binary-{arch}/Packages.gz' in fetch_and_decompress, so an arch or component that the Release file does not cover will not be listed.","commonSituations":"Wrong --arch for the suite (e.g. arm64 against a ports mirror that uses a different path layout, or loong64 not present at all); --suite that does not include 'universe' but the script always tries both 'main' and 'universe'; Release file from a different mirror/suite than the Packages.gz; Release file format change adding/remove stanzas; component renamed (e.g. old Debian 'main' vs ports-specific layouts).","solutions":["Verify the --arch value is valid for the suite and mirror (open {mirror}/dists/{suite}/Release in a browser and check the SHA256 stanza actually lists the path the script prints).","Confirm the --suite string matches the dists/ directory name on the mirror exactly (case-sensitive, including -backports, -updates suffixes).","Use the matching mirror for the architecture — Debian ports architectures (loong64, riscv64 etc.) live on ftp.debian.org/debian-ports, not the main archive.","If 'universe' is the problem, point to a mirror that carries it (Ubuntu) or accept that the missing-index path returns None at fetch_and_decompress:110 instead of reaching this throw."],"exampleFix":"# before\npython3 install-debs.py --mirror http://deb.debian.org/debian --suite trixie --arch loong64 \\\n  --rootfsdir rootfs --force-check-gpg --keyring k.gpg libc6\n# 'Could not find checksum for main/binary-loong64/Packages.gz in Release file.'\n\n# after: ports mirror for ports arch\npython3 install-debs.py --mirror http://ftp.debian.org/debian-ports --suite trixie --arch loong64 \\\n  --rootfsdir rootfs --force-check-gpg --keyring /usr/share/keyrings/debian-ports-archive-keyring.gpg libc6","handlingStrategy":"validation","validationCode":"# Confirm the Release file actually lists the path install-debs.py will request:\npath=\"main/binary-$ARCH/Packages.gz\"\ncurl -fsS \"$MIRROR/dists/$SUITE/Release\" | awk -v p=$path '$1 ~ /^[0-9a-f]{64}$/ && $3==p {print \"found:\", $1; found=1} END{if(!found) exit 1}'","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify --arch exists under {mirror}/dists/{suite}/ before the run.","Use debian-ports mirror for ports architectures (loong64, riscv64 etc.).","Match --suite exactly to the dists/ directory name, including -backports/-updates suffixes."],"tags":["python","debian","release-file","checksum","config","cross-build"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}