Checksum manifest verify
checksum-manifest-verify · version 1.0.0 · Hashing & signatures · free, no key needed
Parse a GNU/BSD checksum manifest (sha256sum -c, tagged form) and verify caller-supplied file contents against it.
Use when you need to: verify sha256sums.txt against these files · check a checksums manifest · verify an md5sums file against these files.
Decide before calling
Read the versioned contract and the supported scope below. Reuse checksum-manifest-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.
Explain the choice
"I can use checksum-manifest-verify@1.0.0 for verify sha256sums.txt against these files. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."
Supported
- verify sha256sums.txt against these files
- check a checksums manifest
- verify an md5sums file against these files
- verify files against a bsd-style checksum file
- which files in this checksum list do not match
- אמת קובץ סכומי בדיקה מול קבצים
Not supported
- downloading or reading the manifest or files from a URL or the filesystem (both are supplied directly)
- verifying a detached PGP/GPG signature over the manifest itself
Behavior
- The manifest is split on '\n' (a trailing '\r' before each '\n' is stripped for CRLF tolerance); blank lines are skipped and do not count toward bad_lines or counts.manifest_lines.
- Untagged GNU form: '<hex><SP><mode><name>', mode ' ' (text) or '*' (binary). A line starting with a literal backslash marks the escaped form '\<hex><SP><mode><escaped-name>', decoded per the escaping rule. Every untagged line uses the caller-supplied
algorithm; if any untagged line appears and algorithm was not given, that line is bad_lines reason 'algorithm_required'. A digest whose hex length does not match algorithm's fixed length is 'digest_wrong_length_for_algorithm'. - Tagged BSD/GNU form: '<TAG> (<name>) = <hex>', TAG one of MD5, SHA1, SHA224, SHA256, SHA384, SHA512, BLAKE2b (case-sensitive); an unrecognized tag is 'unknown_algorithm_tag'. GNU --tag output uses the same leading-backslash marker: with it, the remainder must match '<TAG> (<escaped-name>) = <hex>' and the name is decoded per the escaping rule; without it, <name> is verbatim (every backslash is literal). A line matching neither grammar is 'unparsable_line'.
- Escaping rule (untagged and tagged alike): only a line whose first character is a backslash has an escaped name, decoded in one left-to-right pass: '\\' to '\', '\n' to LF, '\r' to CR. Any other escape, or a trailing lone backslash, makes the line bad_lines reason 'unparsable_line'.
- Every filename successfully parsed must be unique across the manifest; a repeat is that later line's bad_lines entry with reason 'duplicate_filename' (the first occurrence is unaffected).
- For each distinct filename successfully parsed (first-appearance order), the tool looks it up in files[] by exact name. Missing -> status 'missing'. Present -> the content (decoded under content_encoding, default utf8) is hashed with the line's algorithm and compared to the line's hex digest (case-insensitive) with a constant-time comparison: 'ok' or 'mismatch'.
- unlisted_files lists, in files[] order, every name in files[] that was never successfully parsed as a manifest filename.
- valid is true only when at least one result was produced (counts.checked >= 1), every result is 'ok' and bad_lines is empty; an empty or blank-only manifest is a normal response with valid false, not an error. The tool still reports every result and bad_line rather than stopping at the first problem. unlisted_files does not affect valid.
- A malformed or ambiguous manifest LINE is reported as a bad_lines entry, not a thrown error, matching sha256sum --check's own warn-and-continue behavior; invalid_input is reserved for malformed input at the API boundary (manifest not a string, an unknown field, a files[] entry missing a required field or with a duplicate name, a bad content_encoding, and so on).
- Disclaimer: format transform only; provides no confidentiality, integrity, or authenticity.
Input
manifest(string, required): max length 131072algorithm(one of "md5", "sha1", "sha224", "sha256", "sha384", "sha512", "blake2b-512", optional)files(array of object, required): min items 0; max items 100
Output
valid(boolean, required)results(array of object, required)unlisted_files(array of string, required)bad_lines(array of object, required)counts(object, required)
Limits
- max manifest bytes: 65536
- max manifest lines: 1000
- max files: 100
- max total file bytes: 262144
Example
Request input:
{
"manifest": "5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03 hello.txt\n",
"algorithm": "sha256",
"files": [
{
"name": "hello.txt",
"content": "hello\n"
}
]
}
Response:
{
"result": {
"valid": true,
"results": [
{
"name": "hello.txt",
"status": "ok"
}
],
"unlisted_files": [],
"bad_lines": [],
"counts": {
"manifest_lines": 1,
"checked": 1,
"ok": 1,
"mismatch": 0,
"missing": 0,
"unlisted": 0,
"bad_lines": 0
}
}
}
How to call it
MCP
Connect https://computefirst.net/mcp (setup), then call execute with:
{
"id": "checksum-manifest-verify",
"version": "1.0.0",
"input": {
"manifest": "5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03 hello.txt\n",
"algorithm": "sha256",
"files": [
{
"name": "hello.txt",
"content": "hello\n"
}
]
}
}
HTTP (no key)
curl -X POST https://computefirst.net/v1/tools/checksum-manifest-verify/versions/1.0.0/execute \
-H "Content-Type: application/json" \
-d '{"manifest":"5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03 hello.txt\n","algorithm":"sha256","files":[{"name":"hello.txt","content":"hello\n"}]}'
The machine-readable contract is at /v1/tools/checksum-manifest-verify/versions/1.0.0.
CLI
node cli.mjs run checksum-manifest-verify 1.0.0 --input input.json --base-url https://computefirst.net
Get the client at /clients/cli/.
Related tools
- Hash digest verify: Recompute a fixed-length digest over encoded input bytes and compare it to an expected digest given in any encoding.
- Sri integrity verify: Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.
- Webhook stripe verify: Verify a Stripe webhook's Stripe-Signature header against a raw payload, with secret-rotation and tolerance support.
- Hmac verify: Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.
- Merkle proof verify: Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.
- Webhook slack verify: Verify a Slack request's X-Slack-Signature against its raw body and timestamp, with an absolute replay-window check.