Ray's Knowledge Base

A pinned archive checksum fails when a dependency's tag now comes from another repository

PitfallVerified 29 Sep 2026Holds anywhere
Pitfall. The symptom, what causes it, and the fix that was run and seen to work.

Symptom#

Every wheel job stops at the dependency fetch step with a SHA-256 mismatch for one dependency, right after its source URL moved to another host, with the same tag name (v0.0.8).

Cause#

A tag name is not a commit. The same tag in the new repository (github.com/llnl-asr/cpp-logger) pointed at a different commit (31753df) than in the old internal GitLab, so the archive and its hash differ.

Fix#

Build the archive locally from the new source, check that its hash equals the "actual" hash CI printed, and put that hash in the manifest (dependency/source/manifest.txt in dftracer, commit fa09659); then run the verifier (scripts/wheel/fetch_deps.sh --verify). Confirm the new tag holds the same code as the old one, or pin a commit instead of a tag.

Evidence#

dftracer PR 388 CI: the local archive hash equalled CI's actual hash 234f78f6…483b, and fetch_deps.sh --verify passed for all 5 dependencies. Whether the GitHub v0.0.8 holds the same code as the GitLab tag was not checked.