Skip to main content
Author:

Michał Górny

License:

2-clause BSD license

Introduction

gemato provides a reference implementation of the full-tree Manifest checks as specified in GLEP 74 [1]. Originally focused on verifying the integrity and authenticity of the Gentoo ebuild repository, the tool can be used as a generic checksumming tool for any directory trees.

Usage

Verification

The basic purpose of gemato is to verify a directory tree against Manifest files. In order to do that, run the gemato verify tool against the requested directory:

gemato verify /var/db/repos/gentoo

The tool will automatically locate the top-level Manifest (if any) and check the specified directory recursively. If a subdirectory of the Manifest tree is specified, only the specified leaf is checked.

Creating new Manifest tree

Creating a new Manifest tree can be accomplished using the gemato create command against the top directory of the new Manifest tree:

gemato create -p ebuild /var/db/repos/gentoo

Note that for the create command you always need to specify either a profile (via -p) or at least a hash set (via -H).

Updating existing Manifests

The gemato update command is provided to update an existing Manifest tree:

gemato update -p ebuild /var/db/repos/gentoo

Alike create, update also requires specifying a profile (-p) or a hash set (-H). The command locates the appropriate top-level Manifest and updates the specified directory recursively. If a subdirectory of the Manifest tree is specified, the entries for the specified leaf and respective Manifest files are updated.

Utility commands

gemato provides a few other utility commands that provide access to its crypto backend. These are:

gemato hash -H <hashes> [<path>...]

Print hashes of the specified files in Manifest-like format.

gemato openpgp-verify [-K <key>] [<path>...]

Check OpenPGP cleartext signatures embedded in the specified files.

gemato openpgp-verify-detached [-K <key>] <sig-file> <data-file>

Verify the specified data file against a detached OpenPGP signature.

Requirements

gemato is written in Python and compatible with implementations of Python 3.9+. gemato is currently tested against CPython 3.9 through 3.11 and PyPy3. gemato core depends only on standard Python library modules.

Additionally, OpenPGP requires system install of GnuPG 2.2+ and requests Python module. Tests require pytest, and responses for mocking.

References and footnotes

Metadata

Release files for gemato 20.14

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gemato 20.14
File Size Uploaded
gemato-20.14.tar.gz 96.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gemato 20.14
File Interpreter ABI Platform
gemato-20.14-py3-none-any.whl Python 3 none any Details

Total release size: 149.1 kB

Release files / gemato-20.14.tar.gz

Download URL gemato-20.14.tar.gz
Size 96.4 kB
Tags Source
SHA-256 checksum
How to use checksums
8ce33adbc11fb5f4f8def3df0ce91c7b051d9674169155d59a2eeae50ad7bac4
BLAKE2b-256 checksum
How to use checksums
561c7969b02e4c6b8beae1ba26356a414ae0caed66fc1b942a84978fe8cb0eef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.15.0rc2

Release files / gemato-20.14-py3-none-any.whl

Download URL gemato-20.14-py3-none-any.whl
Size 52.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
619c4bb7a279385e9b5b0a71350468fc2a3933a9dfc842f4cf0cb28084b32e8b
BLAKE2b-256 checksum
How to use checksums
9370074348c9383bb8d56bcdacfbb305f027441509d3ec443e7ae91293e61342
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.15.0rc2

Release history Release notifications | RSS feed

20.15

2 release files

This release

20.14 This release

2 release files

20.13

2 release files

20.12

2 release files

20.11

2 release files

20.10

2 release files

20.9

2 release files

20.8

2 release files

20.7

2 release files

20.6

2 release files

20.5

2 release files

20.4

2 release files

20.3

2 release files

20.2

2 release files

20.1

2 release files

20.0

2 release files

19.0

2 release files

18.0

2 release files

17.0

2 release files

16.2

2 release files

16.1

2 release files

16.0

2 release files

15.2

2 release files

15.1

2 release files

15.0

2 release files

14.5

2 release files

14.4

2 release files

14.3

2 release files

14.2

2 release files

14.1

2 release files

14.0

2 release files

13.1

2 release files

13.0

2 release files

12.2

2 release files

12.1

2 release files

12.0

2 release files

11.2

2 release files

11.1

2 release files

11.0

2 release files

10.3

2 release files

10.2

2 release files

10.1

2 release files

10.0

2 release files

9.3

2 release files

9.2

2 release files

9.1

2 release files

9.0

2 release files

8

1 release file

7

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page