Re: [bitbake-devel][PATCH] fetch: Upgrade shown checksum to SHA-512

Richard Purdie <[email protected]>
Newsgroups org.openembedded.lists.bitbake-devel
Message-ID <097843c651961a6f5156b4e6febfd3f9910e7a73.camel@linuxfoundation.org>
On Wed, 2026-05-13 at 08:46 -0600, Joshua Watt via lists.openembedded.org wrote:
> Regulatory standards for Software Bill of Materials like BSI TR-03183
> [1] are requiring SHA 512 as the minimum checksum for validation.
> Upgrade the checksum suggested by the bitbake fetcher to align with this
> requirement.
> 
> Note that the checker has allowed SHA 512 as the checksum for some time
> now, this only changes the checksum that is suggested by tooling.
> 
> [1]: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html
> 
> Signed-off-by: Joshua Watt <[email protected]>
> ---
>  lib/bb/fetch2/__init__.py | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/lib/bb/fetch2/__init__.py b/lib/bb/fetch2/__init__.py
> index f7d5dfe9a..1e78c4fda 100644
> --- a/lib/bb/fetch2/__init__.py
> +++ b/lib/bb/fetch2/__init__.py
> @@ -35,7 +35,7 @@ _revisions_cache = bb.checksum.RevisionsCache()
>  logger = logging.getLogger("BitBake.Fetcher")
>  
>  CHECKSUM_LIST = [ "goh1", "md5", "sha256", "sha1", "sha384", "sha512" ]
> -SHOWN_CHECKSUM_LIST = ["sha256"]
> +SHOWN_CHECKSUM_LIST = ["sha256", "sha512"]
>  
>  class BBFetchException(Exception):
>      """Class all fetch exceptions inherit from"""
> 

This change will need a tweak to one of the devtool tests:

devtool.DevtoolUpgradeTests.test_devtool_upgrade_drop_md5sum

https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/3720
https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/3853

Cheers,

Richard
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.