pkgcheck
Integrity checker for Slackware Linux: verifies that the files recorded by each package
in /var/log/packages/ really exist on the system.
- Bulk extraction of
FILE LIST:sections with ripgrep in a single pass. - Parallel verification with
ThreadPoolExecutor(broken symbolic links count as present:os.lstatis used). - Distinguishes missing files, backup-only (
.bak/.orig) and no access (requires root), as well as.newconfigs pending review. - Decodes the octal escapes (
\NNN) Slackware uses for names with non-ASCII bytes and discards sections after the FILE LIST (e.g.REQUIRES:). - Excludes install scripts (
install/) and pseudo-filesystems (dev/,sys/, …). - Reports files with verification errors too (JSON
files_errors/ERRORSlog section). - Live progress and report with rich; summary + breakdown per package.
- Automatic log in
/var/log/pkgcheck/pkgcheck-<date>.log(.jsonwith--json). - Internationalized interface (7 languages) with automatic OS locale detection.
Requirements
- Python 3.12+
- uv
- ripgrep (
rg) in thePATH
Getting started
uv sync # creates .venv and installs the project and its dependencies
uv run pkgcheck --version
It can also be run as a module: uv run python -m pkgcheck.
Usage
sudo uv run pkgcheck # analyzes /var/log/packages and writes the log
sudo uv run pkgcheck --json # writes the log in JSON format (.json)
uv run pkgcheck --no-elevate --json # without root: only prints the JSON to stdout
uv run pkgcheck --workers 16 # adjusts the parallelism
uv run pkgcheck --packages-dir /mnt/root/var/log/packages
Root privileges
Some protected files (e.g. /var/spool/atjobs, /root) can only be checked with root
privileges. If the process is not running as root:
- In an interactive terminal you are asked whether to re-run with sudo.
--elevatere-runs withsudowithout asking.--no-elevate(or--quiet, or non-interactive output) verifies only what is accessible and warns.
Install scripts and pseudo-filesystems
Entries under install/ (install/doinst.sh, install/slack-desc,
install/douninst.sh, install/slack-required) are metadata that Slackware does not
leave on disk, so they are excluded from the analysis and shown as an informational
counter.
The pseudo-filesystems (dev/, sys/, proc/, run/, tmp/ and var/run/) are also
not tracked: their entries (e.g. the device nodes of the devs package) are dynamic and
do not persist. More prefixes can be added with --exclude.
Pending new configs (.new)
Slackware records configs with the .new suffix in FILE LIST (e.g.
etc/ssl/openssl.cnf.new). On install, the package script renames the file to the
name without suffix (.new → ``); if that file already existed on the system, it keeps
the .new suffix and it is left pending review by the user.
pkgcheck honors this semantics:
foo.conf.newrecorded andfoo.confpresent → installed correctly (not reported).foo.conf.newpresent on disk → reported as pending review (the new version awaits your decision).foo.conf.newrecorded but with no trace → missing.
The suffix is adjusted with --new-suffix (default .new). The detail appears in the
report (key files_pending_new in JSON) and in the console tree.
Backup-only files
If a recorded path does not exist but a backup-suffix variant (.bak or .orig) does,
it is reported as backup-only instead of missing. The set of suffixes is adjusted with
--backup-suffixes. The per-package detail appears in the report (key files_backup in
JSON), not in the console tree.
Automatic log
Each run writes a log in /var/log/pkgcheck/ (the directory is created if it does not
exist) with the convention:
pkgcheck-dd-mm-yyyy-hh-mm-ss.log # plain text (default)
pkgcheck-dd-mm-yyyy-hh-mm-ss.json # with --json
- Requires root privileges: the default run uses
sudo, so the log is saved automatically. If it cannot be written, a warning is shown and the analysis continues. - With
--no-elevate(or non-interactive output without root) no file is saved: the result is only shown on screen (rich in text mode; with--jsononly the JSON document is printed to stdout). - With
--json, progress and process messages go to stderr (scan phases, progress bar and completion line), so stdout is reserved for the JSON document (no-elevate) or the confirmation of the saved log (root). In text mode progress is shown in the console itself. - If two runs collide on the same second, a numeric suffix is added
(
pkgcheck-<date>-1.log,-2, ...).
The JSON document includes a timestamp (ISO 8601), generator, version, summary
and the per-package indexes missing, files_backup, files_pending_new, no_access
and files_errors. These keys are stable and never localized.
Internationalization
The interface, the help and the text log are localized according to the operating system
language. Supported languages: en (base), es, pt, fr, de, zh (Simplified
Chinese) and ja.
Precedence for choosing the language:
--lang {en,es,pt,fr,de,zh,ja}PKGCHECK_LANGenvironment variable- OS locale (
LC_ALL,LC_MESSAGESorLANG) - English (default)
Translations live in src/pkgcheck/locales/{lang}.json (English → language mapping). To
add a new language, create locales/xx.json with the same keys translated; if a key is
missing, the English text is shown. The report JSON keys (missing, files_backup, ...)
are not localized: they are the stable API.
Arguments
| Argument | Description |
|---|---|
--packages-dir |
Directory with the records (default /var/log/packages). |
--workers N |
Verification threads (default: auto). |
--json |
Writes the log in JSON format (.json) instead of text. |
--max-rows N |
Limits the per-package console breakdown. |
--exclude PREFIX |
Additional prefix to exclude (repeatable or comma-separated). |
--backup-suffixes |
Backup suffixes detected as backup-only (default .bak,.orig). |
--new-suffix |
New-config suffix pending review (default .new). |
--lang LANG |
Interface language (en,es,pt,fr,de,zh,ja); detects the OS language. |
--quiet |
Hides progress and breakdown; only prints the summary. |
--elevate |
Re-runs with sudo if root privileges are not available. |
--no-elevate |
Does not ask for root privileges; only verifies what is accessible. |
--version |
Shows the version. |
Code quality
uv run ruff check
uv run ruff format --check
Ruff configuration in pyproject.toml: target-version = "py312" and rules
E, F, W, I, UP, B, SIM, C4, RET, ARG, RUF.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file slackware_pkgcheck-0.1.0.tar.gz.
File metadata
- Download URL: slackware_pkgcheck-0.1.0.tar.gz
- Upload date:
- Size: 29.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.12.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e8919d37f76b9e4a811223813a568369d9ca7e94df7bdeba027aa85556f9b48a
|
|
| MD5 |
5595c1ccddc9e037ae80234c67c3c4fd
|
|
| BLAKE2b-256 |
eaf3b0520c32af0e26bc9f30b3c0a76cd2123aa3285f01e0195cb7fa43873dbe
|
File details
Details for the file slackware_pkgcheck-0.1.0-py3-none-any.whl.
File metadata
- Download URL: slackware_pkgcheck-0.1.0-py3-none-any.whl
- Upload date:
- Size: 35.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.12.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
38d74744a8ced457a7b6377c1feeb1f843940bd79ec98cc10a81b8bccfd04e1f
|
|
| MD5 |
7e786ab59fb7dad70c69d122e55305e1
|
|
| BLAKE2b-256 |
d805eaf16c96432ac18f2a1c2343d6e0bc0a1fcb320aed8bd455f3102ba84a6b
|