Tried to search forum for anything covering this but I don’t see anything which makes me think its a me problem. Getting this while running zypper dup, not really sure how to proceed. Any help greatly appreciated.
Warning: Digest verification failed for file 'libmbedcrypto16-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xDfw1rl/x86_64/libmbedcrypto16-3.6.6-1.1.x86_64.rpm]
expected 1f38d255dd5b5fc29242262a704a610be1df33b24c7630b561428a5e503fa8dbe15018bd9464c2dd63acd6c9c40205f2220881faf2b52a11e2459ce11e88593f
but got 0b1c7738ad8db1d66aa0c42002ffb2fda23804b5ecea536d543a056e2eeb3154f4c02eb0ec8d9ebe6cb6ca0c14cd4955a7526e7b66e9bb89914a1df1c64a4414
Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.
However if you made certain that the file with checksum '0b1c..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.
Just plain old zypper dup. After over 2.5 GB of downloads, we end with the following.
Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64 (Main Repository (OSS)) (128/857), 617.1 KiB
Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64.rpm ...........................................................................................[done (544.0 KiB/s)]
Warning: Digest verification failed for file 'libmbedcrypto16-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xT3Qpz3/x86_64/libmbedcrypto16-3.6.6-1.1.x86_64.rpm]
expected 1f38d255dd5b5fc29242262a704a610be1df33b24c7630b561428a5e503fa8dbe15018bd9464c2dd63acd6c9c40205f2220881faf2b52a11e2459ce11e88593f
but got 0b1c7738ad8db1d66aa0c42002ffb2fda23804b5ecea536d543a056e2eeb3154f4c02eb0ec8d9ebe6cb6ca0c14cd4955a7526e7b66e9bb89914a1df1c64a4414
Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.
However if you made certain that the file with checksum '0b1c..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.
Unblock or discard? [0b1c/...? shows all options] (discard):
I chose to discard. Retrying produced the same.
Because of the size of the download, I’d rather not zypper clean, but I did run zypper -vv refresh just now:
Verbosity: 3
Initializing Target
Specified repositories:
Checking whether to refresh metadata for Main Update Repository
Retrieving: https://download.opensuse.org/update/tumbleweed/repodata/repomd.xml ..............................................................[done (3.5 KiB/s)]
Repository 'Main Update Repository' is up to date.
Checking whether to refresh metadata for Main Repository (NON-OSS)
Retrieving: https://download.opensuse.org/tumbleweed/repo/non-oss/repodata/repomd.xml .......................................................[done (12.4 KiB/s)]
Repository 'Main Repository (NON-OSS)' is up to date.
Checking whether to refresh metadata for Main Repository (OSS)
Retrieving: https://download.opensuse.org/tumbleweed/repo/oss/repodata/repomd.xml ...........................................................[done (13.8 KiB/s)]
Repository 'Main Repository (OSS)' is up to date.
Skipping disabled repository 'Packman Repository'
Checking whether to refresh metadata for libdvdcss repository
Retrieving: https://opensuse-guide.org/repo/openSUSE_Tumbleweed/repodata/repomd.xml ..........................................................[done (3.0 KiB/s)]
Repository 'libdvdcss repository' is up to date.
Checking whether to refresh metadata for multimedia:apps
Retrieving: https://download.opensuse.org/repositories/multimedia:/apps/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:apps' is up to date.
Checking whether to refresh metadata for multimedia:proaudio
Retrieving: https://download.opensuse.org/repositories/multimedia:/proaudio/openSUSE_Tumbleweed/repodata/repomd.xml ..........................[done (2.9 KiB/s)]
Repository 'multimedia:proaudio' is up to date.
Checking whether to refresh metadata for multimedia:apps
Retrieving: https://download.opensuse.org/repositories/multimedia:/apps/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:apps' is up to date.
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/repositories/openSUSE:/Tumbleweed/standard/repodata/repomd.xml .....................................[done (2.6 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for network:im:signal
Retrieving: https://download.opensuse.org/repositories/network:/im:/signal/openSUSE_Tumbleweed/repodata/repomd.xml ...........................[done (2.6 KiB/s)]
Repository 'network:im:signal' is up to date.
Skipping disabled repository 'openSUSE:Tumbleweed'
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/tumbleweed/repo/oss/repodata/repomd.xml ...........................................................[done (13.8 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for openSUSE:Tumbleweed
Retrieving: https://download.opensuse.org/repositories/openSUSE:/Tumbleweed/standard/repodata/repomd.xml .....................................[done (2.6 KiB/s)]
Repository 'openSUSE:Tumbleweed' is up to date.
Checking whether to refresh metadata for multimedia:libs
Retrieving: https://download.opensuse.org/repositories/multimedia:/libs/openSUSE_Tumbleweed/repodata/repomd.xml ..............................[done (2.9 KiB/s)]
Repository 'multimedia:libs' is up to date.
Checking whether to refresh metadata for microsoft-edge
Retrieving: https://packages.microsoft.com/yumrepos/edge-stable/repodata/repomd.xml ..........................................................[done (1.5 KiB/s)]
Repository 'microsoft-edge' is up to date.
Skipping disabled repository 'openSUSE-20230714-0'
Checking whether to refresh metadata for packman-essentials
Retrieving: https://ftp.gwdg.de/pub/linux/misc/packman/suse/openSUSE_Tumbleweed/Essentials/repodata/repomd.xml ...............................[done (1.3 KiB/s)]
Repository 'packman-essentials' is up to date.
Skipping disabled repository 'openSUSE-Tumbleweed-Debug'
Checking whether to refresh metadata for Open H.264 Codec (openSUSE Tumbleweed)
Retrieving: http://codecs.opensuse.org/openh264/openSUSE_Tumbleweed/repodata/repomd.xml ......................................................[done (2.9 KiB/s)]
Repository 'Open H.264 Codec (openSUSE Tumbleweed)' is up to date.
Skipping disabled repository 'openSUSE-Tumbleweed-Source'
Checking whether to refresh metadata for spotify-easyrpm
Repository 'spotify-easyrpm' is up to date.
Checking whether to refresh metadata for vscode
Retrieving: https://packages.microsoft.com/yumrepos/vscode/repodata/repomd.xml ...........................................................................[done]
Repository 'vscode' is up to date.
Checking whether to refresh metadata for Windsurf Repository
Retrieving: https://windsurf-stable.codeiumdata.com/wVxQEIWkwPUEAGf3/yum/repo/repodata/repomd.xml ........................................................[done]
Repository 'Windsurf Repository' is up to date.
All repositories have been refreshed.
Running zypper dup after that reloads the cache as expected, tries to retrieve libmbedcrypto16-3.6.6-1.1.x86_64.rpm, and fails with the checksum error as before.
The presumably-corrupted package doesn’t get that far. If the digest verification fails, the file doesn’t make it into cache. It will be re-downloaded each attempt.
However, I’m now under the belief that the rpm file itself may be fine. I’ve downloaded it manually from two mirrors (mirror.sfo12.us.leaseweb.net and mirrors.edge.kernel.org) and they both return identical files. Running rpm --checksigon both reports “digests signatures OK”.
I also deleted everything in /var/cache/zypp/raw/download.opensuse.org-oss and /var/cache/zypp/solv/download.opensuse.org-oss to force metadata to be redownloaded, but it didn’t change the final outcome.
I’m currently in the process of dusting off my ancient, moth-eaten sysadmin hat to dig into this more.
By the way, in case it’s helpful, the sha256sum of the libmbedcrypto16-3.6.6-1.1.x86_64.rpm file I’m receiving is e56a6b8c74d074fd4ec76ff5decb488d7214614ae39cd6a0fb014f45a0f78b1c.
# zypper in libmbedcrypto16
Loading repository data...
Reading installed packages...
Resolving package dependencies...
The following NEW package is going to be installed:
libmbedcrypto16
1 new package to install.
Package download size: 617.1 KiB
Package install size change:
| 651.6 KiB required by packages that will be installed
651.6 KiB | - 0 B released by packages that will be removed
Backend: classic_rpmtrans
Continue? [y/n/v/...? shows all options] (y):
Preloading: libmbedcrypto16-3.6.6-1.1.x86_64.rpm [done]
Preload finished. [success (7.8 KiB/s) ] ....................................................................................[done]
Retrieving: libmbedcrypto16-3.6.6-1.1.x86_64 (openSUSE Tumbleweed OSS) (1/1), 617.1 KiB
Checking for file conflicts: ................................................................................................[done]
(1/1) Installing: libmbedcrypto16-3.6.6-1.1.x86_64 ..........................................................................[done]
Running post-transaction scripts ............................................................................................[done]
#
Would you mind sharing the sha256 of the rpm it just downloaded? Presumably the command would be find /var/cache/zypp/packages/ -name libmbedcrypto16-3.6.6-1.1.x86_64.rpm | xargs sha256sum.
Do you know if there’s a way to discover which mirror your system used?
i just wanted to add something, it happened to me too, but it’s a different package: libmbedx509-7-3.6.6-1.1.x86_64.rpm:
Warning: Digest verification failed for file 'libmbedx509-7-3.6.6-1.1.x86_64.rpm'
[/var/tmp/zypp.tmp/AP_0xh2AiqN/x86_64/libmbedx509-7-3.6.6-1.1.x86_64.rpm]
expected a0b4b9680a01dd1c3a145c0907531dd354261f9b459bf20bdb893fc6865bcaa1d59c3ea26f1b008bb103dac5df75a2eb1e833d05a8ece008948656a410fdc791
but got b253435e6f81c1eeb3de994e12202b4a2cce37d719eb95651165f3666f7516e0a42e38d9e1afb78d28af1262f1e653927c00de781d154d36bfdd59054366a161
Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.
However if you made certain that the file with checksum 'b253..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.
Unblock or discard? [b253/...? shows all options] (discard): ?
I temporarily swapped the “Main Repository (OSS)” repo URL from https://download.opensuse.org/tumbleweed/repo/oss/ to https://mirrors.edge.kernel.org/opensuse/tumbleweed/repo/oss/ and everything downloaded and installed fine.
Specifically, I used YaST’s Software Repositories to do this and then just ran zypper dup again.
One of the mirrors to which download.opensuse.org is redirecting seems to have some serious sync problems. Repo software that has the potential to offer a file of one checksum but to declare a manifest for a different checksum, just because of sync delays, is a very bad design. I can imagine something like that being abused for a supply chain attack, especially if users get used to accepting these checksum errors.
Anyway, things are okay now. I’m going to switch my repo back to download.opensuse.org and hope I don’t have to look up this topic again in the near future.