Hello everyone / Bonjour à tous,

On a fresh Yunohost install, I tried to install TTRSS using the web interface (Home > Applications > Install > Reading > Tiny Tiny RSS Install).
This operation failed, with error message “ynh_die ‘–message=Corrupt source’”
Here is the full log : TTRSS install log - Yunohost paste

I looked at existing topics, and it seems like this Dec '19 topic is similar. It could be on my side (wrong configuration), or on the Yunohost app side.

What would be the preferred course of action to fix this issue on myside, or to help fixing it in the app ?

Looking at it seems like the expected sha256 for the source file is a5f2aae2b566a0d06a7dd6d7d9d39695c09c77e3b4fc76ca2a49c041499b30d5, whereas calculating it I found cb5a39a61f6319734606f06fafbb0eb60aa488cdc911ec84ee6738da533124cb

> Get-FileHash .\tt-rss-9d3c79498368fa99cfde684c759a1c40825aaaa9.tar.gz -Algorithm SHA256 | Format-List

Algorithm : SHA256
Hash      : CB5A39A61F6319734606F06FAFBB0EB60AA488CDC911EC84EE6738DA533124CB

I can write in English or French as needed.
Thank you very much !

My YunoHost server

Hardware: Kimsufi dedicated server
YunoHost version: 4.1.8 (stable)
I have access to my server : Through the webadmin
Are you in a special context or did you perform some particular tweaking on your YunoHost instance ? : no

It’s a bit odd because this hash has been set like 7 months ago according to the git history

Our automatic tests found no obvious issue about this, and the last one ran ~2 weeks ago

It’s pretty puzzling because this is the archive from a specific commit hash (9d3c7949) on the git repository from ttrss … I see no reason why the archive content would have changed without the commit hash also changing.

One explanation could be that somebody like an attacker that got access to the git forge manually tweaked the archive content on the server (it wouldn’t be the first time we saw this, that’s why those checksums are important)


Created a topic on their support forum to check with the team: Did the archive on got updated somehow ?! - Development - Tiny Tiny RSS: Community


