dotnet/efcore · critical · Exception
SHA256 mismatch for : expected , got
Error message
SHA256 mismatch for {path}: expected {packages_sha}, got {sha256} What it means
Raised by fetch_and_decompress when --force-check-gpg is on: the SHA256 of the downloaded Packages.gz does not equal the SHA256 recorded for that path in the signed Release file. It means two files the mirror must serve consistently are out of agreement, i.e. a package-index integrity failure.
Solutions
- Use a different official mirror, or a snapshot mirror pinned to a single instant (e.g. snapshot.debian.org) where Release and Packages.gz are guaranteed consistent.
- Wait and re-run if the mirror appears to be mid-sync.
- Manually curl both files, sha256sum them, and compare to the Release SHA256 line to identify which side is wrong.
- Only as a last resort and if you accept the risk, drop --force-check-gpg (the script suggests --skipsigcheck in build-rootfs.sh).
Example fix
// before --mirror http://deb.debian.org/debian-ports --force-check-gpg --keyring ... // after # pin a single consistent instant of the archive --mirror http://snapshot.debian.org/archive/debian-ports/20260101T000000Z --force-check-gpg --keyring ...
Defensive patterns
Strategy: retry
Validate before calling
# preflight: verify Release and Packages.gz agree on one suite before the full run
import urllib.request, gzip, hashlib
def check(mirror, suite, path):
rel = urllib.request.urlopen(f"{mirror}/dists/{suite}/Release").read().decode()
pkg = urllib.request.urlopen(f"{mirror}/dists/{suite}/{path}").read()
expected = next(l.split()[0] for l in rel.splitlines() if l.endswith(path) and len(l.split()[0])==64)
return hashlib.sha256(pkg).hexdigest() == expected
# assert check(args.mirror, args.suite[0], 'main/binary-amd64/Packages.gz') Try / catch
try:
asyncio.run(download_package_index_parallel(mirror, arch, suites, True, keyring))
except Exception as e:
if "SHA256 mismatch for" in str(e):
# Release/Packages disagreement -> switch to a snapshot mirror and retry
raise SystemExit(f"index integrity failure, use a snapshot mirror: {e}")
raise Prevention
- Use snapshot mirrors pinned to a single instant so Release and Packages.gz cannot disagree.
- Avoid running during a mirror's publish window.
- Do not disable --force-check-gpg just to bypass this; it hides real integrity problems.
When it happens
Trigger: check_sig is true; the bytes of {mirror}/dists/{suite}/{component}/binary-{arch}/Packages.gz hash to a value different from the SHA256 entry parse_release_file extracted from {mirror}/dists/{suite}/Release.
Common situations: Mirror mid-publish (Release updated but Packages.gz not yet propagated, or the reverse), a CDN layering violation serving mixed versions, a transparent proxy caching one file but not the other, or (rarely) a compromised mirror.
Related errors
- SHA256 mismatch for : expected , got
- Could not find checksum for
- Signature verification failed
- Could not find 'data.tar.*' in
- Failed to download , Status Code
AI-assisted analysis of dotnet/efcore@3a2006ef56 (2026-08-11).
Data as JSON: /api/errors/d109f8cfda562305.
Report an issue: GitHub.
Appendix: source
Thrown at eng/common/cross/install-debs.py:105
"""Fetch and decompress the Packages.gz file."""
path = f"{component}/binary-{arch}/Packages.gz"
url = f"{mirror}/dists/{suite}/{path}"
async with session.get(url) as response:
if response.status == 200:
compressed_data = await response.read()
decompressed_data = gzip.decompress(compressed_data).decode('utf-8')
print(f"Downloaded index: {url}")
if check_sig:
# Verify the package index against the sha256 recorded in the Release file
release_file_content = await fetch_release_file(session, mirror, suite, keyring)
packages_sha = parse_release_file(release_file_content, path)
sha256 = hashlib.sha256(compressed_data).hexdigest()
if sha256 != packages_sha:
raise Exception(f"SHA256 mismatch for {path}: expected {packages_sha}, got {sha256}")
print(f"Checksum verified for {path}")
return decompressed_data
else:
print(f"Skipped index: {url} (doesn't exist)")
return None
async def fetch_release_file(session, mirror, suite, keyring):
"""Fetch Release and Release.gpg files and verify the signature."""
release_url = f"{mirror}/dists/{suite}/Release"
release_gpg_url = f"{mirror}/dists/{suite}/Release.gpg"
with tempfile.NamedTemporaryFile() as release_file, tempfile.NamedTemporaryFile() as release_gpg_file:
await download_file(session, release_url, release_file.name)
await download_file(session, release_gpg_url, release_gpg_file.name)
print("Verifying signature of Release with Release.gpg.")View on GitHub (pinned to 3a2006ef56)