Skip to content

Pod install error verification checksum was incorrect at boost (1.83.0) #42109

Description

@truongngodang

Description

[!] Error installing boost
Verification checksum was incorrect, expected 6478edfe2f3305127cffe8caf73ea0176c53769f4bf1585be237eb30798c3b8e, got 5e89103d9b70bba5c91a794126b169cb67654be2051f90cf7c22ba6893ede0ff

Steps to reproduce

  1. cd ios & pod install

React Native Version

0.73.1

Affected Platforms

Build - MacOS

Output of npx react-native info

System:
  OS: macOS 14.2.1
  CPU: (8) arm64 Apple M1 Pro
  Memory: 73.77 MB / 16.00 GB
  Shell:
    version: "5.9"
    path: /bin/zsh
Binaries:
  Node:
    version: 21.5.0
    path: /opt/homebrew/bin/node
  Yarn:
    version: 1.22.21
    path: /opt/homebrew/bin/yarn
  npm:
    version: 10.2.4
    path: /opt/homebrew/bin/npm
  Watchman: Not Found
Managers:
  CocoaPods:
    version: 1.14.3
    path: /opt/homebrew/bin/pod
SDKs:
  iOS SDK:
    Platforms:
      - DriverKit 23.2
      - iOS 17.2
      - macOS 14.2
      - tvOS 17.2
      - watchOS 10.2
  Android SDK: Not Found
IDEs:
  Android Studio: 2023.1 AI-231.9392.1.2311.11076708
  Xcode:
    version: 15.1/15C65
    path: /usr/bin/xcodebuild
Languages:
  Java:
    version: 17.0.9
    path: /opt/homebrew/opt/openjdk@17/bin/javac
  Ruby:
    version: 2.6.10
    path: /usr/bin/ruby
npmPackages:
  "@react-native-community/cli": Not Found
  react:
    installed: 18.2.0
    wanted: 18.2.0
  react-native:
    installed: 0.73.1
    wanted: 0.73.1
  react-native-macos: Not Found
npmGlobalPackages:
  "*react-native*": Not Found
Android:
  hermesEnabled: true
  newArchEnabled: false
iOS:
  hermesEnabled: Not found
  newArchEnabled: false

Stacktrace or Logs

[!] Error installing boost
Verification checksum was incorrect, expected 6478edfe2f3305127cffe8caf73ea0176c53769f4bf1585be237eb30798c3b8e, got 5e89103d9b70bba5c91a794126b169cb67654be2051f90cf7c22ba6893ede0ff

Reproducer

none

Screenshots and Videos

No response

Activity

  1. github-actions commented on Dec 31, 2023

    @github-actions
    ⚠️ Missing Reproducible Example
    ℹ️ We could not detect a reproducible example in your issue report. Please provide either:
    • If your bug is UI related: a Snack
    • If your bug is build/update related: use our Reproducer Template. A reproducer needs to be in a GitHub repository under your username.
  2. dantonio1401 commented on Dec 31, 2023

    @dantonio1401

    Having the same issue

  3. deeeed commented on Dec 31, 2023

    @deeeed

    +1

  4. InquestApp-Admin commented on Dec 31, 2023

    @InquestApp-Admin

    same issue. started tonight

  5. deeeed commented on Dec 31, 2023

    @deeeed

    The issue seems to be on jfrog.io, the download links are dead https://boostorg.jfrog.io/artifactory/main/release/1.76.0/source/boost_1_76_0.tar.gz

    It seems to be the only mirror according to:
    https://www.boost.org/users/history/version_1_76_0.html

  6. Artem-Kalugin commented on Dec 31, 2023

    @Artem-Kalugin

    The issue seems to be on jfrog.io, the download links are dead https://boostorg.jfrog.io/artifactory/main/release/1.76.0/source/boost_1_76_0.tar.gz

    It seems to be the only mirror according to: https://www.boost.org/users/history/version_1_76_0.html

    And even there links dont work, rederecting to dead site

  7. kdn0325 commented on Dec 31, 2023

    @kdn0325

    We found a temporary solution until the issue is resolved

    move to

    node_modules/react-native/third-party-podspecs/boost.podspec

    spec.source = { :http => 'https://boostorg.jfrog.io/artifactory/main/release/1.83.0/source/boost_1_83_0.tar.bz2',
    :sha256 => '6478edfe2f3305127cffe8caf73ea0176c53769f4bf1585be237eb30798c3b8e' }
    

    change to

    spec.source = { :http => 'https://sourceforge.net/projects/boost/files/boost/1.83.0/boost_1_83_0.tar.bz2',
    :sha256 => '6478edfe2f3305127cffe8caf73ea0176c53769f4bf1585be237eb30798c3b8e' }
    
  8. kimyoungjae96 commented on Dec 31, 2023

    @kimyoungjae96

    I solved it with this.

  9. netanelz-amdocs commented on Dec 31, 2023

    @netanelz-amdocs

    @cortinico do you plan to fix it so we would not need to patch it? Any ETA?

    I solved it with this.

  10. Jonathanide1 commented on Jan 1, 2024

    @Jonathanide1

    Same issue.

  11. Yeasirarafat53 commented on Jan 1, 2024

    @Yeasirarafat53

    same issue

  12. ronCohen2 commented on Jan 1, 2024

    @ronCohen2

    same issue

  13. 44 remaining items

  14. r-guerin0 commented on Jan 8, 2024

    @r-guerin0

    Also having the issue (running react-native@0.72.4)

  15. ts-ign0re commented on Jan 8, 2024

    @ts-ign0re

    The same case.

    Happy New Year You All Guys!

  16. prateekuttreja2020 commented on Jan 8, 2024

    @prateekuttreja2020
    • Facing the same issue... Running on React native 0.72.8, Boost 1.76.0

    Error installing boost
    Verification checksum was incorrect, expected f0397ba6e982c4450f27bf32a2a83292aba035b827a5623a14636ea583318c41, got 5e89103d9b70bba5c91a794126b169cb67654be2051f90cf7c22ba6893ede0ff

  17. louisiscoding commented on Jan 8, 2024

    @louisiscoding

    Same issue as @prateekuttreja2020 . Running on React Native 0.70. Boost 1.76.0

  18. dimitris4 commented on Jan 8, 2024

    @dimitris4

    same issue, react native v. 0.72.6 - only happens in the CI/CD pipeline though..

  19. prashantkamboj commented on Jan 8, 2024

    @prashantkamboj

    Same issue with me but why this issue is closed ?

  20. lluis-sancho commented on Jan 8, 2024

    @lluis-sancho

    Same error here. (0.71.6)

  21. cipolleschi commented on Jan 8, 2024

    @cipolleschi
    Contributor

    Hi everyone. We are extremely sorry for the disruption. As I mention already, we don't own the service where Boost is hosted, so this is not a part of our infra where we can intervene directly.

    We are working on a solution to avoid this problem in the future, so bear with us for now.
    From your reports, I can see that the version affected are:

    • 0.70
    • 0.71
    • 0.72
    • 0.73

    Please bear in mind that 0.70 is not supported anymore. We might consider to make a new release for the sake of this change, but that's still up for discussion.

    Please, stop adding comment like "+1" or "I'm affected too", because this just adds noise to the issue and doesn't make us work faster.

    @prashantkamboj the issue is closed because the exact same incident happened around New Year's Eve and then the infra recovered the 1st of January, so we closed the issue.
    Now, a week after, it is presenting again.

    Workaround

    To unblock yourself, you can apply the changes highlighted by this PR: https://github.com/facebook/react-native/pull/42118/files

    For 0.72 and 0.73, these changes should be straight forward, as they are already in the monorepo setup, so the files path matches with the one of the PR.

    For 0.70 and 0.71, we are not in the monorepo. To get the right path, remove the package/react-native from the two files paths.
    So, the paths are:

    • For the build.gradle.kts: <your_project>/node_modules/react-native/ReactAndroid/build.gradle.kts
    • For the boost.podspec: <your_project>/node_modules/react-native/third-party-podspecs/boost.podspec
  22. binarybaba commented on Jan 8, 2024

    @binarybaba

    for those with boost@1.76

    spec.source = { :http => 'https://archives.boost.io/release/1.76.0/source/boost_1_76_0.tar.gz',
                      :sha256 => '7bd7ddceec1a1dfdcbdb3e609b60d01739c38390a5f956385a12f3122049f0ca' }
    

    Quick way to find out: download the file and run sha256sum <filename>

  23. sindhusingh commented on Jan 8, 2024

    @sindhusingh

    for those with boost@1.76

    spec.source = { :http => 'https://archives.boost.io/release/1.76.0/source/boost_1_76_0.tar.gz',
                      :sha256 => '7bd7ddceec1a1dfdcbdb3e609b60d01739c38390a5f956385a12f3122049f0ca' }
    

    Quick way to find out: download the file and run sha256sum <filename>

    Excellent! The temporary solution, as mentioned by others earlier, is effective. However, the issue is that we need to apply this solution every time we install fresh packages. Even creating a patch for these changes doesn't work seamlessly. I'm still in search of a permanent fix.

  24. D-Cabs commented on Jan 8, 2024

    @D-Cabs

    Hi!
    React V. 0.70.5 question. Im a bit unsure what to do as remove "package/react-native" from the path.

    .../node_modules/react-native/ReactAndroid/build.gradle has

        src("https://archives.boost.io/release/${BOOST_VERSION.replace("_", ".")}/source/boost_${BOOST_VERSION}.tar.gz")
        onlyIfNewer(true)
        overwrite(false)
        dest(new File(downloadsDir, "boost_${BOOST_VERSION}.tar.gz"))
    

    And .../node_modules/react-native/third-party-podspecs

      spec.name = 'boost'
      spec.version = '1.76.0'
      spec.license = { :type => 'Boost Software License', :file => "LICENSE_1_0.txt" }
      spec.homepage = 'http://www.boost.org'
      spec.summary = 'Boost provides free peer-reviewed portable C++ source libraries.'
      spec.authors = 'Rene Rivera'
      spec.source = { :http => 'https://boostorg.jfrog.io/artifactory/main/release/1.76.0/source/boost_1_76_0.tar.bz2',
                      :sha256 => 'f0397ba6e982c4450f27bf32a2a83292aba035b827a5623a14636ea583318c41'}
    

    I am unsure what to change like @cipolleschi mentioned.

    Could somebody point me on what to change as issue is critical for me at the moment.

  25. matteodanelli commented on Jan 8, 2024

    @matteodanelli

    Hi! React V. 0.70.5 question. Im a bit unsure what to do as remove "package/react-native" from the path.

    .../node_modules/react-native/ReactAndroid/build.gradle has

    task downloadBoost(dependsOn: createNativeDepsDirectories, type: Download) { src("https://archives.boost.io/release/${BOOST_VERSION.replace("_", ".")}/source/boost_${BOOST_VERSION}.tar.gz") onlyIfNewer(true) overwrite(false) dest(new File(downloadsDir, "boost_${BOOST_VERSION}.tar.gz")) }

    And .../node_modules/react-native/third-party-podspecs

    Pod::Spec.new do |spec| spec.name = 'boost' spec.version = '1.76.0' spec.license = { :type => 'Boost Software License', :file => "LICENSE_1_0.txt" } spec.homepage = 'http://www.boost.org' spec.summary = 'Boost provides free peer-reviewed portable C++ source libraries.' spec.authors = 'Rene Rivera' spec.source = { :http => 'https://boostorg.jfrog.io/artifactory/main/release/1.76.0/source/boost_1_76_0.tar.bz2', :sha256 => 'f0397ba6e982c4450f27bf32a2a83292aba035b827a5623a14636ea583318c41' }

    I am unsure what to change like @cipolleschi mentioned.

    Could somebody point me on what to change as issue is critical for me at the moment.

    You could check this. Maybe it helps

  26. abdymm commented on Jan 8, 2024

    @abdymm

    Could somebody point me on what to change as issue is critical for me at the moment.

    i guess you need to do the patch package by changing the source url

  27. cipolleschi commented on Jan 8, 2024

    @cipolleschi
    Contributor

    We have an official workaround and a pinned issue: #42180.
    I'm locking this conversation.

  28. locked and limited conversation to collaborators on Jan 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions