Problem with Repos'Leap 16

Hi,
I have been trying to update my system with myrlyn and the problem is I get errors on the following repo’s:

This problem started yesterday late afternoon and I keep getting the same issues
Testing what is going on with

zypper refresh 

I get:

Refreshing service 'NVIDIA'.
Refreshing service 'openSUSE'.
Repository 'repo-non-free (16.0)' is up to date.                                                                                                                                             
Looking for gpg keys in repository Dev_tools.
  gpgkey=https://download.opensuse.org/repositories/devel:/tools/16.0/repodata/repomd.xml.key
Retrieving repository 'Dev_tools' metadata -----------------------------------------------------------------------------------------------------------------------------------------------[\]
Warning: Digest verification failed for file 'e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz'
[/var/tmp/zypp.tmp/AP_0xW6uJ5u/repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz]

  expected e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663
  but got  48a985e73e0caff38abef60e06a854ad038366c7713b195220b17b0489722e1a70900afd6666393a07dcd086b22a9ba1a28724521edde193bdc6588dbc97bb09

Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.

However if you made certain that the file with checksum '48a9..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.

Is this happening to anyone else ?

boven:~ # zypper ref
Looking for gpg keys in repository Main (Non-OSS).
  gpgkey=http://download.opensuse.org/distribution/leap/16.0/repo/non-oss/x86_64/repodata/repomd.xml.key
Retrieving repository 'Main (Non-OSS)' metadata .........................................................................................................................................................................................................................[done]
Building repository 'Main (Non-OSS)' cache ..............................................................................................................................................................................................................................[done]
Repository 'open264 codecs' is up to date.                                                                                                                                                                                                                                     
Looking for gpg keys in repository Main (OSS).
  gpgkey=http://download.opensuse.org/distribution/leap/16.0/repo/oss/x86_64/repodata/repomd.xml.key
Retrieving repository 'Main (OSS)' metadata .............................................................................................................................................................................................................................[done]
Building repository 'Main (OSS)' cache ..................................................................................................................................................................................................................................[done]
All repositories have been refreshed.
boven:~ # date
Sat Aug 29 13:56:39 CEST 2026
boven:~ # 

This issue persists in TW repos as well.

download.opensuse.org is a redirector,

Maybe you see more if you search for the time, you have updated:

grep -i "2026-08-29 16:03" /var/log/zypper.log | less

But this a long output

To cleanly work with present meta data do:

sudo zypper clean -a
sudo zypper ref -f
sudo zypper up

and see if the issue persists. At least, one person today reported it helped.

Maybe you see more if you search for the time, you have updated:

The problem is that I used Myrlyn the previous day, not zypper, and I did not update since it was actually not possible. I thought it was a problem with servers tho I did not check on the Opensuse service status site.
When I search on previous dates on the file /var/log/zypp/history i have some updated available on 2026-08-27 among those I remember gpredict.
On the /var/log/zypper.log file i can not find any record with a date other then 20206-08-29 (today).
but the mistakes are the same … wrong sha256 checkums on files.
example :

2026-08-29 13:52:01 <1> (53431) [ZYPP_MEDIA_CURL] request.cc(~NetworkRequestPrivate):86 0x56537c043010 curl_easy_cleanup
2026-08-29 13:52:01 <1> (53431) [zypp::media++] MediaHandler.cc(provideFile):977 provideFile([1]./repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz{1.7 MiB|sha512-e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663|})
2026-08-29 13:52:01 <2> (53431) [zypp] checksumwf.cc(operator()):80 File /var/tmp/zypp.tmp/AP_0xYdQtxz/repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz has wrong checksum sha512-48a985e73e0caff38abef60e06a854ad038366c7713b195220b17b0489722e1a70900afd6666393a07dcd086b22a9ba1a28724521edde193bdc6588dbc97bb09 (expected sha512-e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663)
sudo zypper clean -a
sudo zypper ref -f
sudo zypper up

and see if the issue persists. At least, one person today reported it helped.

tried that just now in my did not work. same results.

Then, give it a day and try again.

I’ve used a bit more verbosity on zypper:

sudo zypper -vvv ref -f

and the result came out :

Specified repositories: 
Forcing raw metadata refresh
Retrieving: https://download.nvidia.com/opensuse/leap/16.0/repodata/repomd.xml ........................................................................................................[done]
Looking for gpg keys in repository repo-non-free (16.0).
  gpgkey=https://download.nvidia.com/opensuse/leap/16.0/repodata/repomd.xml.key
Retrieving: https://download.nvidia.com/opensuse/leap/16.0/repodata/repomd.xml.key ....................................................................................................[done]
Retrieving: https://download.nvidia.com/opensuse/leap/16.0/repodata/repomd.xml.asc ..........................................................................................[done (836 B/s)]
  Repository:       repo-non-free (16.0)
  Key Fingerprint:  2FB0 3195 DECD 4949 2BD1 C17A B1D0 D788 DB27 FD5A
  Key Name:         NVIDIA Linux Driver Team <linux-bugs@nvidia.com>
  Key Algorithm:    RSA 4096
  Key Created:      Thu 14 Apr 2022 11:04:01 PM WEST
  Key Expires:      (does not expire)
  Rpm Name:         gpg-pubkey-db27fd5a-62589a51
Retrieving: https://download.nvidia.com/opensuse/leap/16.0/repodata/b5b40cc6fe94921741ec1e67d847753fac4755f9e8f1d50d453699b9c4a1cbdb-primary.xml.gz ...................................[done]
Retrieving: https://download.nvidia.com/opensuse/leap/16.0/repodata/susedata.xml.gz ...................................................................................................[done]
Retrieving repository 'repo-non-free (16.0)' metadata .................................................................................................................................[done]
Forcing building of repository cache
Building repository 'repo-non-free (16.0)' cache ......................................................................................................................................[done]
Forcing raw metadata refresh
Retrieving: https://download.opensuse.org/repositories/devel:/tools/16.0/repodata/repomd.xml ..........................................................................................[done]
Looking for gpg keys in repository Dev_tools.
  gpgkey=https://download.opensuse.org/repositories/devel:/tools/16.0/repodata/repomd.xml.key
Retrieving: https://download.opensuse.org/repositories/devel:/tools/16.0/repodata/repomd.xml.key ..........................................................................[done (2.4 KiB/s)]
Retrieving: https://download.opensuse.org/repositories/devel:/tools/16.0/repodata/repomd.xml.asc ............................................................................[done (827 B/s)]
  Repository:       Dev_tools
  Key Fingerprint:  CB3E D75A C0E1 FE7B 52F5 58E2 0FD0 7641 6330 7D5D
  Key Name:         devel:tools OBS Project <devel:tools@build.opensuse.org>
  Key Algorithm:    RSA 4096
  Key Created:      Tue 03 Feb 2026 08:38:47 AM WET
  Key Expires:      Thu 13 Apr 2028 09:38:47 AM WEST
  Rpm Name:         gpg-pubkey-63307d5d-6981b417
Retrieving: https://ftp.rnl.tecnico.ulisboa.pt/pub/opensuse/repositories/devel:/tools/16.0/repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9[done]

Warning: Digest verification failed for file 'e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz'
[/var/tmp/zypp.tmp/AP_0xud31g8/repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663-filelists-ext.xml.gz]

  expected e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9422e07da8584a4122819761d529c88b940b46d7970663
  but got  905833d7d796b8ab43e2bdb05add5d6f780c8f25e9a1251bf62ae82d6e18b8e1526d2f5d3f189488de86504c7c15289fe3e74494ac51244a74895d7873382c89

Accepting packages with wrong checksums can lead to a corrupted system and in extreme cases even to a system compromise.

However if you made certain that the file with checksum '9058..' is secure, correct
and should be used within this operation, enter the first 4 characters of the checksum
to unblock using this file on your own risk. Empty input will discard the file.

Unblock or discard? [9058/...? shows all options] (discard):

I can see the mirror used is :

Retrieving: https://ftp.rnl.tecnico.ulisboa.pt/pub/opensuse/repositories/devel:/tools/16.0/repodata/e61fb599267b87214ae49250f1ca711ae4707a67f5dfea7413e6b9d5a11316eec8d870e825bbf59bab9[done]

So this can be indeed a synchronization issue … no worries … I will try tomorrow … or better Monday …
Thanks.

1 Like

I’m having the same problem with Tumbleweed repo’s.
I’ll try tomorrow.

You are hitting this broken mirror
https://ftp.rnl.tecnico.ulisboa.pt/pub/opensuse/repositories/
I open it in a browser, click the directories, it stay on the same page, just adding directory/ to the end of url.

Indeed that is the case and I thought it was just a synchronization issue … I will wait until Monday during the weekend no one will fix it.

You can append ?AVOID_COUNTRY=pt to the baseurl of the repo at the moment