https://bugzilla.redhat.com/show_bug.cgi?id=1885495 --- Comment #16 from Carl George 🤠 <carl@xxxxxxxxxx> --- I ran fedora-review on this, and it found another issue. - Sources used to build the package match the upstream source, as provided in the spec URL. Note: Upstream MD5sum check error, diff is in /home/carl/packaging/other/qatengine/copr-build-1767717/review- qatengine/diff.txt See: https://docs.fedoraproject.org/en-US/packaging-guidelines/SourceURL/ Source checksums ---------------- https://github.com/intel/QAT_Engine/archive/v0.6.1/qatengine-0.6.1.tar.gz : CHECKSUM(SHA256) this package : a63d4dd5f58a0856af8ff578f763cf489e85f7266ce703270171c895d6aa20f5 CHECKSUM(SHA256) upstream package : 8a738339f7743e1bd81ce58496c4b2ad6ec26c0124e70ef4f42ab1aadeaf57c7 diff -r also reports differences Did someone force push in the upstream repo? Please do another copr build with the actual upstream tarball. The tarball that is used in Fedora should be the unmodified sources available from upstream [0]. [0] https://docs.fedoraproject.org/en-US/packaging-guidelines/SourceURL/ -- You are receiving this mail because: You are on the CC list for the bug. You are always notified about changes to this product and component _______________________________________________ package-review mailing list -- package-review@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to package-review-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-review@xxxxxxxxxxxxxxxxxxxxxxx