gemato – Gentoo Manifest Tool
- Author:
Michał Górny
- License:
2-clause BSD license
Introduction
gemato provides a reference implementation of the full-tree Manifest checks as specified in GLEP 74 [1]. Originally focused on verifying the integrity and authenticity of the Gentoo ebuild repository, the tool can be used as a generic checksumming tool for any directory trees.
Usage
Verification
The basic purpose of gemato is to verify a directory tree against Manifest files. In order to do that, run the gemato verify tool against the requested directory:
gemato verify /var/db/repos/gentoo
The tool will automatically locate the top-level Manifest (if any) and check the specified directory recursively. If a subdirectory of the Manifest tree is specified, only the specified leaf is checked.
Creating new Manifest tree
Creating a new Manifest tree can be accomplished using the gemato create command against the top directory of the new Manifest tree:
gemato create -p ebuild /var/db/repos/gentoo
Note that for the create command you always need to specify either a profile (via -p) or at least a hash set (via -H).
Updating existing Manifests
The gemato update command is provided to update an existing Manifest tree:
gemato update -p ebuild /var/db/repos/gentoo
Alike create, update also requires specifying a profile (-p) or a hash set (-H). The command locates the appropriate top-level Manifest and updates the specified directory recursively. If a subdirectory of the Manifest tree is specified, the entries for the specified leaf and respective Manifest files are updated.
Utility commands
gemato provides a few other utility commands that provide access to its crypto backend. These are:
- gemato hash -H <hashes> [<path>...]
Print hashes of the specified files in Manifest-like format.
- gemato openpgp-verify [-K <key>] [<path>...]
Check OpenPGP cleartext signatures embedded in the specified files.
- gemato openpgp-verify-detached [-K <key>] <sig-file> <data-file>
Verify the specified data file against a detached OpenPGP signature.
Requirements
gemato is written in Python and compatible with implementations of Python 3.9+. gemato is currently tested against CPython 3.9 through 3.11 and PyPy3. gemato core depends only on standard Python library modules.
Additionally, OpenPGP requires system install of GnuPG 2.2+ and requests Python module. Tests require pytest, and responses for mocking.
References and footnotes
Metadata
Release files for gemato 20.15
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gemato-20.15.tar.gz | 96.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gemato-20.15-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 149.4 kB
Release files / gemato-20.15.tar.gz
| Download URL | gemato-20.15.tar.gz |
|---|---|
| Size | 96.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
67ce56ab9b41f2c298e8621d9077352b6560a09859a790cb875cbe7d5d1f36e0
|
|
BLAKE2b-256 checksum How to use checksums |
9e7516922c14c831e4cec0c5ab1838205fcc1862cb010f83eaaace1a67c4d474
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.15.0rc2
|
Release files / gemato-20.15-py3-none-any.whl
| Download URL | gemato-20.15-py3-none-any.whl |
|---|---|
| Size | 52.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ccd96c572dd05e3120505d9e11c4a6cae6e8d7bb6774ff9dd9d49ba5bb05f8fc
|
|
BLAKE2b-256 checksum How to use checksums |
6110fc08597a94a5a12bf105c51ec926e21a6ea86e93a73c5db095f7eba92401
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.15.0rc2
|