2021-03-07 18:00:25

by Ronald Warsow

[permalink] [raw]
Subject: stable kernel checksumming fails

hello

getting stable kernels with this script:

https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/tree/get-verified-tarball


fails since the last 2 (?) stable releases with (last lines):

...

+ /usr/bin/curl -L -o
/home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/linux-5.11.4.tar.xz
https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.11.4.tar.xz
% Total % Received % Xferd Average Speed Time Time Time
Current
Dload Upload Total Spent Left
Speed
100 112M 100 112M 0 0 5757k 0 0:00:19 0:00:19 --:--:--
5938k

pushd ${TMPDIR} >/dev/null
+ pushd /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
echo "Verifying checksum on linux-${VER}.tar.xz"
+ echo 'Verifying checksum on linux-5.11.4.tar.xz'
Verifying checksum on linux-5.11.4.tar.xz
if ! ${SHA256SUMBIN} -c ${SHACHECK}; then
echo "FAILED to verify the downloaded tarball checksum"
popd >/dev/null
rm -rf ${TMPDIR}
exit 1
fi
+ /usr/bin/sha256sum -c
/home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt
/usr/bin/sha256sum:
/home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt:
no properly formatted SHA256 checksum lines found
+ echo 'FAILED to verify the downloaded tarball checksum'
FAILED to verify the downloaded tarball checksum
+ popd
+ rm -rf /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
+ exit 1


checksumming the downloaded kernel manually gives an "Okay" though.


is this just me (on Fedora 33) ?


--
regards

Ronald


2021-03-07 21:32:52

by Greg Kroah-Hartman

[permalink] [raw]
Subject: Re: stable kernel checksumming fails

On Sun, Mar 07, 2021 at 03:10:49PM +0100, Ronald Warsow wrote:
> hello
>
> getting stable kernels with this script:
>
> https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/tree/get-verified-tarball
>
>
> fails since the last 2 (?) stable releases with (last lines):
>
> ...
>
> + /usr/bin/curl -L -o
> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/linux-5.11.4.tar.xz
> https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.11.4.tar.xz
> % Total % Received % Xferd Average Speed Time Time Time
> Current
> Dload Upload Total Spent Left
> Speed
> 100 112M 100 112M 0 0 5757k 0 0:00:19 0:00:19 --:--:--
> 5938k
>
> pushd ${TMPDIR} >/dev/null
> + pushd /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
> echo "Verifying checksum on linux-${VER}.tar.xz"
> + echo 'Verifying checksum on linux-5.11.4.tar.xz'
> Verifying checksum on linux-5.11.4.tar.xz
> if ! ${SHA256SUMBIN} -c ${SHACHECK}; then
> echo "FAILED to verify the downloaded tarball checksum"
> popd >/dev/null
> rm -rf ${TMPDIR}
> exit 1
> fi
> + /usr/bin/sha256sum -c
> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt
> /usr/bin/sha256sum:
> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt:
> no properly formatted SHA256 checksum lines found
> + echo 'FAILED to verify the downloaded tarball checksum'
> FAILED to verify the downloaded tarball checksum
> + popd
> + rm -rf /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
> + exit 1
>
>
> checksumming the downloaded kernel manually gives an "Okay" though.
>
>
> is this just me (on Fedora 33) ?

Fails for me on Arch:

Verifying checksum on linux-5.11.4.tar.xz
/usr/bin/sha256sum: /home/gregkh/Downloads/linux-tarball-verify.gZo313NCk.untrusted/sha256sums.txt: no properly formatted SHA256 checksum lines found
FAILED to verify the downloaded tarball checksum


Konstantin, anything change recently?

2021-03-08 02:28:22

by Konstantin Ryabitsev

[permalink] [raw]
Subject: Re: stable kernel checksumming fails

On Sun, Mar 07, 2021 at 03:45:15PM +0100, Greg KH wrote:
> > checksumming the downloaded kernel manually gives an "Okay" though.
> >
> >
> > is this just me (on Fedora 33) ?
>
> Fails for me on Arch:
>
> Verifying checksum on linux-5.11.4.tar.xz
> /usr/bin/sha256sum: /home/gregkh/Downloads/linux-tarball-verify.gZo313NCk.untrusted/sha256sums.txt: no properly formatted SHA256 checksum lines found
> FAILED to verify the downloaded tarball checksum
>
>
> Konstantin, anything change recently?

I think it's just cache invalidation problems. I've committed a tiny change to
the script that always grabs that file from the origin servers instead of
going via the CDN.

https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/commit/?id=71e570c5f090b5740e323f98504bf38592785b49

This should sidestep the problem.

-K

2021-03-08 02:32:17

by Greg Kroah-Hartman

[permalink] [raw]
Subject: Re: stable kernel checksumming fails

On Sun, Mar 07, 2021 at 10:43:54AM -0500, Konstantin Ryabitsev wrote:
> On Sun, Mar 07, 2021 at 03:45:15PM +0100, Greg KH wrote:
> > > checksumming the downloaded kernel manually gives an "Okay" though.
> > >
> > >
> > > is this just me (on Fedora 33) ?
> >
> > Fails for me on Arch:
> >
> > Verifying checksum on linux-5.11.4.tar.xz
> > /usr/bin/sha256sum: /home/gregkh/Downloads/linux-tarball-verify.gZo313NCk.untrusted/sha256sums.txt: no properly formatted SHA256 checksum lines found
> > FAILED to verify the downloaded tarball checksum
> >
> >
> > Konstantin, anything change recently?
>
> I think it's just cache invalidation problems. I've committed a tiny change to
> the script that always grabs that file from the origin servers instead of
> going via the CDN.
>
> https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/commit/?id=71e570c5f090b5740e323f98504bf38592785b49
>
> This should sidestep the problem.
>
> -K

Nice, fixed it for me, thanks!

Ronald, does it now work for you too?

greg k-h

2021-03-08 08:06:49

by Ronald Warsow

[permalink] [raw]
Subject: Re: stable kernel checksumming fails

On 07.03.21 16:48, Greg KH wrote:
> On Sun, Mar 07, 2021 at 10:43:54AM -0500, Konstantin Ryabitsev wrote:
>> On Sun, Mar 07, 2021 at 03:45:15PM +0100, Greg KH wrote:
>>>> checksumming the downloaded kernel manually gives an "Okay" though.
>>>>
...
>>
>> I think it's just cache invalidation problems. I've committed a tiny change to
>> the script that always grabs that file from the origin servers instead of
>> going via the CDN.
>>
>> https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/commit/?id=71e570c5f090b5740e323f98504bf38592785b49
>>
>> This should sidestep the problem.
>>
>> -K
>
> Nice, fixed it for me, thanks!
>
> Ronald, does it now work for you too?
>
> greg k-h
>

yes, all is fine again.

thanks all !

--
regards

Ronald

2021-03-08 08:31:23

by Bhaskar Chowdhury

[permalink] [raw]
Subject: Re: stable kernel checksumming fails

On 15:45 Sun 07 Mar 2021, Greg KH wrote:
>On Sun, Mar 07, 2021 at 03:10:49PM +0100, Ronald Warsow wrote:
>> hello
>>
>> getting stable kernels with this script:
>>
>> https://git.kernel.org/pub/scm/linux/kernel/git/mricon/korg-helpers.git/tree/get-verified-tarball
>>
>>
>> fails since the last 2 (?) stable releases with (last lines):
>>
>> ...
>>
>> + /usr/bin/curl -L -o
>> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/linux-5.11.4.tar.xz
>> https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.11.4.tar.xz
>> % Total % Received % Xferd Average Speed Time Time Time
>> Current
>> Dload Upload Total Spent Left
>> Speed
>> 100 112M 100 112M 0 0 5757k 0 0:00:19 0:00:19 --:--:--
>> 5938k
>>
>> pushd ${TMPDIR} >/dev/null
>> + pushd /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
>> echo "Verifying checksum on linux-${VER}.tar.xz"
>> + echo 'Verifying checksum on linux-5.11.4.tar.xz'
>> Verifying checksum on linux-5.11.4.tar.xz
>> if ! ${SHA256SUMBIN} -c ${SHACHECK}; then
>> echo "FAILED to verify the downloaded tarball checksum"
>> popd >/dev/null
>> rm -rf ${TMPDIR}
>> exit 1
>> fi
>> + /usr/bin/sha256sum -c
>> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt
>> /usr/bin/sha256sum:
>> /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted/sha256sums.txt:
>> no properly formatted SHA256 checksum lines found
>> + echo 'FAILED to verify the downloaded tarball checksum'
>> FAILED to verify the downloaded tarball checksum
>> + popd
>> + rm -rf /home/ron/Downloads/linux-tarball-verify.1GiZid5WT.untrusted
>> + exit 1
>>
>>
>> checksumming the downloaded kernel manually gives an "Okay" though.
>>
>>
>> is this just me (on Fedora 33) ?
>
>Fails for me on Arch:
>
>Verifying checksum on linux-5.11.4.tar.xz
>/usr/bin/sha256sum: /home/gregkh/Downloads/linux-tarball-verify.gZo313NCk.untrusted/sha256sums.txt: no properly formatted SHA256 checksum lines found
>FAILED to verify the downloaded tarball checksum
>
I can confirm it works alright with me on OpenSuse Tumbleweed and Slackware
...yet to test on others....Debian....Arch and Gentoo ...
>

Oh btw ...sometimes I got that specific error because of lack of dns
propogation to dns stuff in some reason...


>Konstantin, anything change recently?
>


Attachments:
(No filename) (2.37 kB)
signature.asc (499.00 B)
Download all attachments