Skip to main content

gemato – Gentoo Manifest Tool

Author:

Michał Górny

License:

2-clause BSD license

Introduction

gemato provides a reference implementation of the full-tree Manifest checks as specified in GLEP 74 [1]. Originally focused on verifying the integrity and authenticity of the Gentoo ebuild repository, the tool can be used as a generic checksumming tool for any directory trees.

Usage

Verification

The basic purpose of gemato is to verify a directory tree against Manifest files. In order to do that, run the gemato verify tool against the requested directory:

gemato verify /var/db/repos/gentoo

The tool will automatically locate the top-level Manifest (if any) and check the specified directory recursively. If a subdirectory of the Manifest tree is specified, only the specified leaf is checked.

Creating new Manifest tree

Creating a new Manifest tree can be accomplished using the gemato create command against the top directory of the new Manifest tree:

gemato create -p ebuild /var/db/repos/gentoo

Note that for the create command you always need to specify either a profile (via -p) or at least a hash set (via -H).

Updating existing Manifests

The gemato update command is provided to update an existing Manifest tree:

gemato update -p ebuild /var/db/repos/gentoo

Alike create, update also requires specifying a profile (-p) or a hash set (-H). The command locates the appropriate top-level Manifest and updates the specified directory recursively. If a subdirectory of the Manifest tree is specified, the entries for the specified leaf and respective Manifest files are updated.

Utility commands

gemato provides a few other utility commands that provide access to its crypto backend. These are:

gemato hash -H <hashes> [<path>...]

Print hashes of the specified files in Manifest-like format.

gemato openpgp-verify [-K <key>] [<path>...]

Check OpenPGP cleartext signatures embedded in the specified files.

gemato openpgp-verify-detached [-K <key>] <sig-file> <data-file>

Verify the specified data file against a detached OpenPGP signature.

Requirements

gemato is written in Python and compatible with implementations of Python 3.9+. gemato is currently tested against CPython 3.9 through 3.11 and PyPy3. gemato core depends only on standard Python library modules.

Additionally, OpenPGP requires system install of GnuPG 2.2+ and requests Python module. Tests require pytest, and responses for mocking.

References and footnotes

Metadata

Release files for gemato 20.15

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gemato 20.15
File Size Uploaded
gemato-20.15.tar.gz 96.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gemato 20.15
File Interpreter ABI Platform
gemato-20.15-py3-none-any.whl Python 3 none any Details

Total release size: 149.4 kB

Release files / gemato-20.15.tar.gz

Download URL gemato-20.15.tar.gz
Size 96.5 kB
Tags Source
SHA-256 checksum
How to use checksums
67ce56ab9b41f2c298e8621d9077352b6560a09859a790cb875cbe7d5d1f36e0
BLAKE2b-256 checksum
How to use checksums
9e7516922c14c831e4cec0c5ab1838205fcc1862cb010f83eaaace1a67c4d474
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.15.0rc2

Release files / gemato-20.15-py3-none-any.whl

Download URL gemato-20.15-py3-none-any.whl
Size 52.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ccd96c572dd05e3120505d9e11c4a6cae6e8d7bb6774ff9dd9d49ba5bb05f8fc
BLAKE2b-256 checksum
How to use checksums
6110fc08597a94a5a12bf105c51ec926e21a6ea86e93a73c5db095f7eba92401
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.15.0rc2

Release history Release notifications | RSS feed

This release

20.15 This release

2 release files

20.14

2 release files

20.13

2 release files

20.12

2 release files

20.11

2 release files

20.10

2 release files

20.9

2 release files

20.8

2 release files

20.7

2 release files

20.6

2 release files

20.5

2 release files

20.4

2 release files

20.3

2 release files

20.2

2 release files

20.1

2 release files

20.0

2 release files

19.0

2 release files

18.0

2 release files

17.0

2 release files

16.2

2 release files

16.1

2 release files

16.0

2 release files

15.2

2 release files

15.1

2 release files

15.0

2 release files

14.5

2 release files

14.4

2 release files

14.3

2 release files

14.2

2 release files

14.1

2 release files

14.0

2 release files

13.1

2 release files

13.0

2 release files

12.2

2 release files

12.1

2 release files

12.0

2 release files

11.2

2 release files

11.1

2 release files

11.0

2 release files

10.3

2 release files

10.2

2 release files

10.1

2 release files

10.0

2 release files

9.3

2 release files

9.2

2 release files

9.1

2 release files

9.0

2 release files

8

1 release file

7

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page