Fix custom package checksum verification for Mac and Linux arm64 #6

Merged
JMR-dev merged 1 commits from claude/custom-packages-checksum-yf1cS into main 2026-05-22 17:52:08 +00:00
JMR-dev commented 2026-05-22 17:51:26 +00:00 (Migrated from github.com)

Three root causes were causing failures on non-x86_64-Linux platforms:

  1. Single SHA256 per package: the pinned fallback checksum in
    formatted_packages.py was a single value computed for linux-x86_64 only.
    Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced
    different binaries with different digests, so verification always failed
    on those platforms when the fetch_latest resolver was unavailable.

    Fix: replace the single sha256 field with a sha256_map dict keyed by
    "{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct
    pinned digests for all four supported platforms for both Go 1.26.3 and
    Firecracker 1.15.1, fetched from official sources.

  2. Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase
    hex, but checksums returned by external APIs could be uppercase.
    _verify() compared them without normalising case, causing false mismatches.

    Fix: new resolved_sha256 property always returns a lowercased digest;
    _resolve_latest() also lowercases the dynamically-fetched sha before
    storing it.

  3. Firecracker not skipped on macOS: _resolve_latest_firecracker() returns
    None on macOS (firecracker is Linux-only), causing a fallback to the
    pinned linux binary URL with a linux-only checksum map entry. The download
    and verification would both fail misleadingly.

    Fix: explicit early-continue guard in install_custom_packages() when
    name == "firecracker" and IS_MACOS.

Three root causes were causing failures on non-x86_64-Linux platforms: 1. Single SHA256 per package: the pinned fallback checksum in formatted_packages.py was a single value computed for linux-x86_64 only. Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced different binaries with different digests, so verification always failed on those platforms when the fetch_latest resolver was unavailable. Fix: replace the single `sha256` field with a `sha256_map` dict keyed by "{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct pinned digests for all four supported platforms for both Go 1.26.3 and Firecracker 1.15.1, fetched from official sources. 2. Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase hex, but checksums returned by external APIs could be uppercase. _verify() compared them without normalising case, causing false mismatches. Fix: new resolved_sha256 property always returns a lowercased digest; _resolve_latest() also lowercases the dynamically-fetched sha before storing it. 3. Firecracker not skipped on macOS: _resolve_latest_firecracker() returns None on macOS (firecracker is Linux-only), causing a fallback to the pinned linux binary URL with a linux-only checksum map entry. The download and verification would both fail misleadingly. Fix: explicit early-continue guard in install_custom_packages() when name == "firecracker" and IS_MACOS.
Sign in to join this conversation.