hash mismatch

Bug #1767533 reported by Bernd Späth on 2018-04-28
38
This bug affects 6 people
Affects Status Importance Assigned to Milestone
virtualbox (Ubuntu)
Undecided
Unassigned

Bug Description

Trying to install the package virtualbox-ext-pack 5.2.10-3 produces the following error message:

Hash mismatch Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack: expected 8c31bc1d0337e6668e0d9140defc6deaf265087f855783dd09b873a064a70703, or wrong accept-license key

I manually downloaded Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack to find verify it has the same sha256 sum: 5eef217dbe0a8e8caf383ea8db83344517af0f9093041b5345c8468a427b327b as the file downloaded by the installer script.

Unlike the installer script I chose to use https for the download.
As the certificate seemed to be valid, I am more or less sure, I at least got the version the legit owner of the CN www.virtualbox.org seems to offer.

Investigating the problem further I found out, there seems to have been an update of the extension pack from version 5.2.10-122088 to 5.2.10-122406 just yesterday.

Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122088.vbox-extpack 16-Apr-2018 11:18 19M
Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122406.vbox-extpack 27-Apr-2018 15:31 19M

Downloading the older 122088 release I was able to verify this one produces the sha256 checksum named above.
Most probably the "file" named Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack is just a symlink that Oracle changed from the older 122088 version to point the newer 122406 version.

Which would mean the variable hash on line 5 of the postinst script would have to be updated to the checksum of the newer version as well.

Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in virtualbox (Ubuntu):
status: New → Confirmed
Robert Moucha (robert-moucha) wrote :

According to http://download.virtualbox.org/virtualbox/5.2.10/SHA256SUMS file, checksum 5eef217dbe0a8e8caf383ea8db83344517af0f9093041b5345c8468a427b327b matches both "Oracle_VM_VirtualBox_Extension_Pack-5.2.10-122406.vbox-extpack" and "Oracle_VM_VirtualBox_Extension_Pack-5.2.10.vbox-extpack". So reporter's
assumption is correct.

Hello Bernd, or anyone else affected,

Accepted virtualbox-ext-pack into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.2.10-3ubuntu18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed verification-needed-bionic
Łukasz Zemczak (sil2100) wrote :

Hello Bernd, or anyone else affected,

Accepted virtualbox-ext-pack into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.2.18-1~ubuntu18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping!

N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers