dotnet/efcore · error · Exception

Could not find checksum for

Error message

Could not find checksum for {path} in Release file.

What it means

Raised by parse_release_file when no SHA256 entry (a line matching '^ (\S*) +(\S*) +(\S*)$' whose first field is 64 chars and whose path field equals {path}) is found in the Release file. It means the Release file the mirror served does not list a checksum for the requested Packages.gz path.

Solutions

  1. curl -s {mirror}/dists/{suite}/Release and grep for the exact path ({component}/binary-{arch}/Packages.gz) to see whether it is listed.
  2. Correct --arch and --suite to a combination the mirror actually publishes.
  3. If the mirror only has 'main', patch the hardcoded component list ['main','universe'] in download_package_index_parallel to drop the missing component.
  4. Switch to a mirror that publishes the full component set for your suite.

Example fix

// before
for component in ["main", "universe"]:  # hardcoded; 'universe' absent on Debian ports mirrors

// after
for component in ["main"]:  # only iterate components the mirror actually publishes
Defensive patterns

Strategy: validation

Validate before calling

# preflight: confirm the Release file lists a SHA256 for every path we will request
import urllib.request
rel = urllib.request.urlopen(f"{mirror}/dists/{suite}/Release").read().decode()
for component in ["main", "universe"]:
    path = f"{component}/binary-{arch}/Packages.gz"
    if not any(line.rstrip().endswith(path) and len(line.split()[0]) == 64 for line in rel.splitlines() if line.startswith(" ")):
        print(f"WARNING: Release has no SHA256 for {path}; this suite/component/arch will fail")

Prevention

When it happens

Trigger: check_sig is on; parse_release_file is asked for {component}/binary-{arch}/Packages.gz but the Release file contains no SHA256 line for that exact path.

Common situations: The arch is not published for that suite (e.g. loong64 missing), the component does not exist on that mirror (the code hardcodes both main and universe, but Debian ports mirrors often only have main), a suite name typo, or a Release file format change that breaks the leading-space regex.

Related errors


AI-assisted analysis of dotnet/efcore@3a2006ef56 (2026-08-11). Data as JSON: /api/errors/82efd039d5052a9a. Report an issue: GitHub.

Appendix: source

Thrown at eng/common/cross/install-debs.py:154

        print("Signature verified successfully.")

        with open(release_file.name) as f:
            return f.read()

def parse_release_file(content, path):
    """Parses the Release file and returns sha256 checksum of the specified path."""

    # data looks like this:
    # <checksum>  <size>  <path>
    matches = re.findall(r'^ (\S*) +(\S*) +(\S*)$', content, re.MULTILINE)

    for entry in matches:
        # the file has both md5 and sha256 checksums, we want sha256 which has a length of 64
        if entry[2] == path and len(entry[0]) == 64:
            return entry[0]

    raise Exception(f"Could not find checksum for {path} in Release file.")

def parse_debian_version(version):
    """Parse a Debian package version into epoch, upstream version, and revision."""
    match = re.match(r'^(?:(\d+):)?([^-]+)(?:-(.+))?$', version)
    if not match:
        raise ValueError(f"Invalid Debian version format: {version}")
    epoch, upstream, revision = match.groups()
    return int(epoch) if epoch else 0, upstream, revision or ""

def compare_upstream_version(v1, v2):
    """Compare upstream or revision parts using Debian rules."""
    def tokenize(version):
        tokens = re.split(r'([0-9]+|[A-Za-z]+)', version)
        return [int(x) if x.isdigit() else x for x in tokens if x]

    tokens1 = tokenize(v1)
    tokens2 = tokenize(v2)

View on GitHub (pinned to 3a2006ef56)