Bug 1888

Summary: SRC_URI checksum is now required
Product: [Documentation] Reference Reporter: Darren Hart <dvhart>
Component: handbookAssignee: Scott Rifenbark <srifenbark>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: poky.doc.watcher, poky.watcher, richard.purdie, sgw
Version: unspecified   
Target Milestone: 1.2 M3   
Hardware: x86   
OS: Multiple   
URL: http://git.yoctoproject.org/cgit.cgi/yocto-docs/commit/?id=a1991f0b6f32a0a296ae4d115a834ed61042720b
Whiteboard: 2-april-2012: resolved/fixed
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: ---

Description Darren Hart 2012-01-09 12:25:32 UTC
The Makefile recipe example does not include a SRC_URI checksum, without it, the recipe do_fetch command will fail. The do_fetch log will report something along the lines of:

WARNING: Fetcher failure for URL: 'http://iweb.dl.sourceforge.net/project/generalembedded/Downloads/Utility/phub_util_mac.tar.bz2'. No checksum specified for /toph/yocto/downloads/phub_util_mac.tar.bz2, please add at least one to the recipe:
SRC_URI[md5sum] = "f148f0a515ffa264ca5723df48cb7011"
SRC_URI[sha256sum] = "201818aa0540ecc7bec840fb993058eae5927a89a55ebbf57780c795ff200753"

(NOTE: These checksums are not for the example in the recipe)
Comment 1 Scott Rifenbark 2012-01-09 13:07:25 UTC
What is the suggested documentation fix here?
Comment 2 Richard Purdie 2012-03-29 12:30:57 UTC
Add the lines:

SRC_URI[md5sum] = "f148f0a515ffa264ca5723df48cb7011"
SRC_URI[sha256sum] =
"201818aa0540ecc7bec840fb993058eae5927a89a55ebbf57780c795ff200753"

to the example.
Comment 3 Darren Hart 2012-03-29 14:52:06 UTC
Doh, I thought I had addressed this. Thanks RP.
Comment 4 Scott Rifenbark 2012-03-29 15:30:33 UTC
I need to verify if this is the example you want the lines added to.  The bug does not specify the manual.  If this is the example, where do I put the lines Richard suggests?

----------------------

In the following example, mtd-utils is a makefile-based package:

     DESCRIPTION = "Tools for managing memory technology devices."
     SECTION = "base"
     DEPENDS = "zlib lzo e2fsprogs util-linux"
     HOMEPAGE = "http://www.linux-mtd.infradead.org/"
     LICENSE = "GPLv2"
     LIC_FILES_CHKSUM = "file://COPYING;md5=0636e73ff0215e8d672dc4c32c317bb3 \
                         file://include/common.h;beginline=1;endline=17;md5=ba05b07912a44ea2bf81ce409380049c"

     SRC_URI = "git://git.infradead.org/mtd-utils.git;protocol=git;tag=v${PV}"

     S = "${WORKDIR}/git/"

     EXTRA_OEMAKE = "'CC=${CC}' 'CFLAGS=${CFLAGS} -I${S}/include -DWITHOUT_XATTR' \
                     'BUILDDIR=${S}'"

     do_install () {
             oe_runmake install DESTDIR=${D} SBINDIR=${sbindir} MANDIR=${mandir} \
                                INCLUDEDIR=${includedir}
             install -d ${D}${includedir}/mtd/
             for f in ${S}/include/mtd/*.h; do
                     install -m 0644 $f ${D}${includedir}/mtd/
             done
     }
Comment 5 Richard Purdie 2012-03-29 16:05:44 UTC
Darren, looking at this I don't understand it. Can you provide a link to the document which needs fixing? I can't find anything requesting phub_util_mac.tar.bz2 be downloaded...
Comment 6 Darren Hart 2012-03-30 19:13:07 UTC
This was just an example. I followed those instructions to add a new recipe for the phub_util_mac tool (it doesn't exist in our repositories). The instructions do not mention the required SRC_URI checksum lines.

The docs, it turns out, are using a git SRC_URI, which I believe requires a SRCREV="..." line. While tarball SRC_URIs require a SRC_URI[md5sum]="".
Comment 7 Darren Hart 2012-03-30 19:55:29 UTC
This is what I'd recommend:

To the existing example recipe, update it to match the one in the current sources:

replace:
SRC_URI = "git://git.infradead.org/mtd-utils.git;protocol=git;tag=v${PV}"

with:
SRC_URI = "git://git.infradead.org/mtd-utils.git;protocol=git;tag=995cfe51b0a3cf32f381c140bf72b21bf91cef1b"

You can see the entire file here:
http://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta/recipes-devtools/mtd/mtd-utils_1.4.9.bb

Using a named tag breaks working offline, so we shouldn't do that in example documentation. Apparently a SRCREV is not required here.

In the text describing the recipe, consider adding something like this:

"""
If your sources are available as a tarball instead of a git repository, you will need to provide the URL to the tarball as well as an md5 or sha256 sum of the download. For example:

SRC_URI="ftp://ftp.infradead.org/pub/mtd-utils/mtd-utils-1.4.9.tar.bz2"
SRC_URI[md5sum]="82b8e714b90674896570968f70ca778b"

You can generate the md5 or sha1 sums by using the md5sum or sha256sum commands with the target file as the only argument. For example:

$ md5sum mtd-utils-1.4.9.tar.bz2 
82b8e714b90674896570968f70ca778b  mtd-utils-1.4.9.tar.bz2
"""

Richard, do you agree with all the above?
Comment 8 Richard Purdie 2012-03-30 21:19:17 UTC
Yes, sounds reasonable to me.
Comment 9 Scott Rifenbark 2012-04-02 22:07:43 UTC
Implemented Darren's suggestions.  There might need to be some tweaking depending on his review.  New section can be found at http://www.yoctoproject.org/docs/latest/dev-manual/dev-manual.html#usingpoky-extend-addpkg-makefile

Scott