dropbear-openipc: name the hash file so buildroot reads it - #2456
Merged
Merged
Conversation
Buildroot resolves a package's checksums to <RAWNAME>.hash, which for this package is dropbear-openipc.hash. The file shipped as dropbear.hash and was therefore never opened: check-hash printed "WARNING: no hash file for dropbear-2022.82.tar.bz2" and returned 0, so the tarball was fetched from sources.buildroot.net over plain HTTP and built with no integrity check at all. BR2_DOWNLOAD_FORCE_CHECK_HASHES is off, so nothing ever failed and the gap stayed invisible -- the .hash file is present in the tree and looks right, which is exactly why this survived review. The contents were already correct, all four hashes verifying against the released tarball, so this is a rename and verification simply starts working. Found while reviewing #2449, which had introduced the same mistake in a new package.
openipc-ai
requested review from
cronyx,
flyrouter and
viktorxda
as code owners
September 19, 2026 13:15
PR Summary by QodoEnable Dropbear OpenIPC checksum verification
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #2450.
Problem
general/package/dropbear-openipc/ships its checksums asdropbear.hash, named after the upstream project. Buildroot resolves a package's hash file to<RAWNAME>.hash(package/pkg-generic.mk:512), which for this package isdropbear-openipc.hash— so the file we ship is never opened. Buildroot will say so itself:Neither of those exists.
support/download/check-hashthen warns and returns success, and we do not setBR2_DOWNLOAD_FORCE_CHECK_HASHES, so the tarball is fetched fromhttp://sources.buildroot.net/dropbearover plain HTTP and built with no integrity check. Dropbear is the SSH daemon on every image that enables it, and the threeLICENSEhashes are equally dead, solegal-infoloses its check too.This is not a claim about the mirror. The point is that we ship a file whose only purpose is verification, it looks correct in review, and it does nothing.
Every other
.hashin the tree is named correctly (libjpeg-openipc,webrtc-audio-processing-openipc,legacy/gst1-plugins-bad-openipc); this was the only one left. #2449 had introduced a second instance, fixed there before merge.Hardware tested on
Not applicable, and I want to be explicit rather than leave it blank. This renames a checksum file. It changes nothing Buildroot fetches, compiles or installs — the dropbear tarball and every byte of the resulting image are identical — it only decides whether the download is verified on the way in. There is no camera-observable behaviour to exercise.
The risk it does carry is the opposite one: these hashes have never been read, so nothing had ever proven them correct, and a wrong entry would turn a silent no-check into a hard build failure on 100 boards. So I verified all four against the released tarball before renaming, and the evidence below is that check rather than a board.
Evidence
All four entries verify against the real tarball:
The three licence hashes also match Buildroot's own current
package/dropbear/dropbear.hash(for 2024.85) — those files have not changed upstream, which is an independent corroboration.Running Buildroot's own
support/download/check-hashagainst the real tarball, before and after:Before:
After:
And it now actually catches a bad download — one byte flipped in the tarball:
Selector and self-test:
The full matrix is the right answer here even for a rename: if a hash were wrong, every board that builds dropbear would fail, so every board should prove it does not.
Scope
general/package/all-patches/linux/general/overlay/or in a sharedload_<vendor>script hardcodes a value specific to my boardDROPBEAR_OPENIPC_SITEis Buildroot'ssources.buildroot.netmirror rather than an OpenIPC repository. That is pre-existing and untouched here — no*_SITEor*_VERSIONchanges in this diff — but I am not going to tick a box asserting something this PR did not establish.)LD_PRELOAD, and no binaries that cannot be rebuilt from source