Skip to content

Correct downloaded bytes fail when checksums are out of source order

scope: generic · severity: trap · confidence: proven · subsystem: packaging

Symptom — A freshly downloaded source fails its checksum, while fetching that same URL independently produces the expected hash.

Cause — abuild’s default_fetch compares sources and checksums in list order. The filenames written beside checksum values do not drive that pairing. In the Taimen firmware recipe, the first extra firmware source was compared against board-2.json’s checksum because that line appeared second.

What to do — Keep checksum entries in exactly the same order as source. Run pmbootstrap checksum after changing sources, then review the resulting order. Do not weaken checksum verification or assume the CDN corrupted a file before comparing the downloaded bytes independently.