hash mismatch

Bug #1767533 reported by Bernd Späth
38
This bug affects 6 people
Affects Status Importance Assigned to Milestone
virtualbox (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Trying to install the package virtualbox-ext-pack 5.2.10-3 produces the following error message:

Hash mismatch Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack: expected 8c31bc1d0337e6668e0d9140defc6deaf265087f855783dd09b873a064a70703, or wrong accept-license key

I manually downloaded Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack to find verify it has the same sha256 sum: 5eef217dbe0a8e8caf383ea8db83344517af0f9093041b5345c8468a427b327b as the file downloaded by the installer script.

Unlike the installer script I chose to use https for the download.
As the certificate seemed to be valid, I am more or less sure, I at least got the version the legit owner of the CN www.virtualbox.org seems to offer.

Investigating the problem further I found out, there seems to have been an update of the extension pack from version 5.2.10-122088 to 5.2.10-122406 just yesterday.

Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122088.vbox-extpack 16-Apr-2018 11:18 19M
Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122406.vbox-extpack 27-Apr-2018 15:31 19M

Downloading the older 122088 release I was able to verify this one produces the sha256 checksum named above.
Most probably the "file" named Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack is just a symlink that Oracle changed from the older 122088 version to point the newer 122406 version.

Which would mean the variable hash on line 5 of the postinst script would have to be updated to the checksum of the newer version as well.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in virtualbox (Ubuntu):
status: New → Confirmed
Revision history for this message
Robert Moucha (robert-moucha) wrote :

According to http://download.virtualbox.org/virtualbox/5.2.10/SHA256SUMS file, checksum 5eef217dbe0a8e8caf383ea8db83344517af0f9093041b5345c8468a427b327b matches both "Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122406.vbox-extpack" and "Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack". So reporter's
assumption is correct.

Revision history for this message
Marian Rainer-Harbach (marianrh) wrote :
Revision history for this message
Timo Aaltonen (tjaalton) wrote : Please test proposed package

Hello Bernd, or anyone else affected,

Accepted virtualbox-ext-pack into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.2.10-3ubuntu18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed verification-needed-bionic
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Bernd, or anyone else affected,

Accepted virtualbox-ext-pack into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.2.18-1~ubuntu18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping!

N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.