dotnet/aspnetcore · error · Exception

Could not find checksum for

Error message

Could not find checksum for {path} in Release file.

What it means

Raised by parse_release_file when the Release file's SHA256 checksum stanza has no entry for the requested relative path (e.g. main/binary-amd64/Packages.gz). The function iterates the regex matches and only returns an entry whose path equals the requested one and whose checksum is 64 hex chars long; falling through means the path is not listed.

Solutions

  1. Verify the --arch value is valid for the suite and mirror (open {mirror}/dists/{suite}/Release in a browser and check the SHA256 stanza actually lists the path the script prints).
  2. Confirm the --suite string matches the dists/ directory name on the mirror exactly (case-sensitive, including -backports, -updates suffixes).
  3. Use the matching mirror for the architecture — Debian ports architectures (loong64, riscv64 etc.) live on ftp.debian.org/debian-ports, not the main archive.
  4. If 'universe' is the problem, point to a mirror that carries it (Ubuntu) or accept that the missing-index path returns None at fetch_and_decompress:110 instead of reaching this throw.

Example fix

# before
python3 install-debs.py --mirror http://deb.debian.org/debian --suite trixie --arch loong64 \
  --rootfsdir rootfs --force-check-gpg --keyring k.gpg libc6
# 'Could not find checksum for main/binary-loong64/Packages.gz in Release file.'

# after: ports mirror for ports arch
python3 install-debs.py --mirror http://ftp.debian.org/debian-ports --suite trixie --arch loong64 \
  --rootfsdir rootfs --force-check-gpg --keyring /usr/share/keyrings/debian-ports-archive-keyring.gpg libc6
Defensive patterns

Strategy: validation

Validate before calling

# Confirm the Release file actually lists the path install-debs.py will request:
path="main/binary-$ARCH/Packages.gz"
curl -fsS "$MIRROR/dists/$SUITE/Release" | awk -v p=$path '$1 ~ /^[0-9a-f]{64}$/ && $3==p {print "found:", $1; found=1} END{if(!found) exit 1}'

Prevention

When it happens

Trigger: parse_release_file(release_file_content, path) loops over re.findall matches of the SHA256 stanza; if none has entry[2] == path, it raises. The path is built as f'{component}/binary-{arch}/Packages.gz' in fetch_and_decompress, so an arch or component that the Release file does not cover will not be listed.

Common situations: Wrong --arch for the suite (e.g. arm64 against a ports mirror that uses a different path layout, or loong64 not present at all); --suite that does not include 'universe' but the script always tries both 'main' and 'universe'; Release file from a different mirror/suite than the Packages.gz; Release file format change adding/remove stanzas; component renamed (e.g. old Debian 'main' vs ports-specific layouts).

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/909ff41c913822a3. Report an issue: GitHub.

Appendix: source

Thrown at eng/common/cross/install-debs.py:154

        print("Signature verified successfully.")

        with open(release_file.name) as f:
            return f.read()

def parse_release_file(content, path):
    """Parses the Release file and returns sha256 checksum of the specified path."""

    # data looks like this:
    # <checksum>  <size>  <path>
    matches = re.findall(r'^ (\S*) +(\S*) +(\S*)$', content, re.MULTILINE)

    for entry in matches:
        # the file has both md5 and sha256 checksums, we want sha256 which has a length of 64
        if entry[2] == path and len(entry[0]) == 64:
            return entry[0]

    raise Exception(f"Could not find checksum for {path} in Release file.")

def parse_debian_version(version):
    """Parse a Debian package version into epoch, upstream version, and revision."""
    match = re.match(r'^(?:(\d+):)?([^-]+)(?:-(.+))?$', version)
    if not match:
        raise ValueError(f"Invalid Debian version format: {version}")
    epoch, upstream, revision = match.groups()
    return int(epoch) if epoch else 0, upstream, revision or ""

def compare_upstream_version(v1, v2):
    """Compare upstream or revision parts using Debian rules."""
    def tokenize(version):
        tokens = re.split(r'([0-9]+|[A-Za-z]+)', version)
        return [int(x) if x.isdigit() else x for x in tokens if x]

    tokens1 = tokenize(v1)
    tokens2 = tokenize(v2)

View on GitHub (pinned to 3600ca084e)