dotnet/aspnetcore · error · Exception
Could not find checksum for
Error message
Could not find checksum for {path} in Release file. What it means
Raised by parse_release_file when the Release file's SHA256 checksum stanza has no entry for the requested relative path (e.g. main/binary-amd64/Packages.gz). The function iterates the regex matches and only returns an entry whose path equals the requested one and whose checksum is 64 hex chars long; falling through means the path is not listed.
Solutions
- Verify the --arch value is valid for the suite and mirror (open {mirror}/dists/{suite}/Release in a browser and check the SHA256 stanza actually lists the path the script prints).
- Confirm the --suite string matches the dists/ directory name on the mirror exactly (case-sensitive, including -backports, -updates suffixes).
- Use the matching mirror for the architecture — Debian ports architectures (loong64, riscv64 etc.) live on ftp.debian.org/debian-ports, not the main archive.
- If 'universe' is the problem, point to a mirror that carries it (Ubuntu) or accept that the missing-index path returns None at fetch_and_decompress:110 instead of reaching this throw.
Example fix
# before python3 install-debs.py --mirror http://deb.debian.org/debian --suite trixie --arch loong64 \ --rootfsdir rootfs --force-check-gpg --keyring k.gpg libc6 # 'Could not find checksum for main/binary-loong64/Packages.gz in Release file.' # after: ports mirror for ports arch python3 install-debs.py --mirror http://ftp.debian.org/debian-ports --suite trixie --arch loong64 \ --rootfsdir rootfs --force-check-gpg --keyring /usr/share/keyrings/debian-ports-archive-keyring.gpg libc6
Defensive patterns
Strategy: validation
Validate before calling
# Confirm the Release file actually lists the path install-debs.py will request:
path="main/binary-$ARCH/Packages.gz"
curl -fsS "$MIRROR/dists/$SUITE/Release" | awk -v p=$path '$1 ~ /^[0-9a-f]{64}$/ && $3==p {print "found:", $1; found=1} END{if(!found) exit 1}' Prevention
- Verify --arch exists under {mirror}/dists/{suite}/ before the run.
- Use debian-ports mirror for ports architectures (loong64, riscv64 etc.).
- Match --suite exactly to the dists/ directory name, including -backports/-updates suffixes.
When it happens
Trigger: parse_release_file(release_file_content, path) loops over re.findall matches of the SHA256 stanza; if none has entry[2] == path, it raises. The path is built as f'{component}/binary-{arch}/Packages.gz' in fetch_and_decompress, so an arch or component that the Release file does not cover will not be listed.
Common situations: Wrong --arch for the suite (e.g. arm64 against a ports mirror that uses a different path layout, or loong64 not present at all); --suite that does not include 'universe' but the script always tries both 'main' and 'universe'; Release file from a different mirror/suite than the Packages.gz; Release file format change adding/remove stanzas; component renamed (e.g. old Debian 'main' vs ports-specific layouts).
Related errors
- SHA256 mismatch for : expected , got
- SHA256 mismatch for : expected , got
- Could not find 'data.tar.*' in
- Failed to download after attempts.
- Failed to download , Status Code
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/909ff41c913822a3.
Report an issue: GitHub.
Appendix: source
Thrown at eng/common/cross/install-debs.py:154
print("Signature verified successfully.")
with open(release_file.name) as f:
return f.read()
def parse_release_file(content, path):
"""Parses the Release file and returns sha256 checksum of the specified path."""
# data looks like this:
# <checksum> <size> <path>
matches = re.findall(r'^ (\S*) +(\S*) +(\S*)$', content, re.MULTILINE)
for entry in matches:
# the file has both md5 and sha256 checksums, we want sha256 which has a length of 64
if entry[2] == path and len(entry[0]) == 64:
return entry[0]
raise Exception(f"Could not find checksum for {path} in Release file.")
def parse_debian_version(version):
"""Parse a Debian package version into epoch, upstream version, and revision."""
match = re.match(r'^(?:(\d+):)?([^-]+)(?:-(.+))?$', version)
if not match:
raise ValueError(f"Invalid Debian version format: {version}")
epoch, upstream, revision = match.groups()
return int(epoch) if epoch else 0, upstream, revision or ""
def compare_upstream_version(v1, v2):
"""Compare upstream or revision parts using Debian rules."""
def tokenize(version):
tokens = re.split(r'([0-9]+|[A-Za-z]+)', version)
return [int(x) if x.isdigit() else x for x in tokens if x]
tokens1 = tokenize(v1)
tokens2 = tokenize(v2)
View on GitHub (pinned to 3600ca084e)