Three root causes were causing failures on non-x86_64-Linux platforms:
Single SHA256 per package: the pinned fallback checksum in
formatted_packages.py was a single value computed for linux-x86_64 only.
Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced
different binaries with different digests, so verification always failed
on those platforms when the fetch_latest resolver was unavailable.
Fix: replace the single sha256 field with a sha256_map dict keyed by
"{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct
pinned digests for all four supported platforms for both Go 1.26.3 and
Firecracker 1.15.1, fetched from official sources.
Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase
hex, but checksums returned by external APIs could be uppercase.
_verify() compared them without normalising case, causing false mismatches.
Fix: new resolved_sha256 property always returns a lowercased digest;
_resolve_latest() also lowercases the dynamically-fetched sha before
storing it.
Firecracker not skipped on macOS: _resolve_latest_firecracker() returns
None on macOS (firecracker is Linux-only), causing a fallback to the
pinned linux binary URL with a linux-only checksum map entry. The download
and verification would both fail misleadingly.
Fix: explicit early-continue guard in install_custom_packages() when
name == "firecracker" and IS_MACOS.
Three root causes were causing failures on non-x86_64-Linux platforms:
1. Single SHA256 per package: the pinned fallback checksum in
formatted_packages.py was a single value computed for linux-x86_64 only.
Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced
different binaries with different digests, so verification always failed
on those platforms when the fetch_latest resolver was unavailable.
Fix: replace the single `sha256` field with a `sha256_map` dict keyed by
"{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct
pinned digests for all four supported platforms for both Go 1.26.3 and
Firecracker 1.15.1, fetched from official sources.
2. Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase
hex, but checksums returned by external APIs could be uppercase.
_verify() compared them without normalising case, causing false mismatches.
Fix: new resolved_sha256 property always returns a lowercased digest;
_resolve_latest() also lowercases the dynamically-fetched sha before
storing it.
3. Firecracker not skipped on macOS: _resolve_latest_firecracker() returns
None on macOS (firecracker is Linux-only), causing a fallback to the
pinned linux binary URL with a linux-only checksum map entry. The download
and verification would both fail misleadingly.
Fix: explicit early-continue guard in install_custom_packages() when
name == "firecracker" and IS_MACOS.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Three root causes were causing failures on non-x86_64-Linux platforms:
Single SHA256 per package: the pinned fallback checksum in
formatted_packages.py was a single value computed for linux-x86_64 only.
Downloads on linux-aarch64, macos-x86_64, and macos-aarch64 produced
different binaries with different digests, so verification always failed
on those platforms when the fetch_latest resolver was unavailable.
Fix: replace the single
sha256field with asha256_mapdict keyed by"{os}-{arch}" (e.g. "linux-aarch64", "macos-arm64"). Added the correct
pinned digests for all four supported platforms for both Go 1.26.3 and
Firecracker 1.15.1, fetched from official sources.
Case-sensitive SHA256 comparison: _sha256_of() always returns lowercase
hex, but checksums returned by external APIs could be uppercase.
_verify() compared them without normalising case, causing false mismatches.
Fix: new resolved_sha256 property always returns a lowercased digest;
_resolve_latest() also lowercases the dynamically-fetched sha before
storing it.
Firecracker not skipped on macOS: _resolve_latest_firecracker() returns
None on macOS (firecracker is Linux-only), causing a fallback to the
pinned linux binary URL with a linux-only checksum map entry. The download
and verification would both fail misleadingly.
Fix: explicit early-continue guard in install_custom_packages() when
name == "firecracker" and IS_MACOS.