clawbot 2d996df335
check / check (push) Successful in 2m33s
Run lint and tests as phases of the Dockerfile (closes #5)
The Dockerfile gets a lint phase on the pinned golangci-lint v2.12.2
image and a test phase on the Debian Go image. The tests run as an
unprivileged user, because root reads a file with mode 0000 and the
permission test then fails. The build stage copies a file from each
phase, so no build finishes unless both pass, and it no longer runs
make check. script/lint and script/test each build their phase,
uncached and tagged; script/cibuild bootstraps, runs script/check, then
builds the image. script/bootstrap no longer installs golangci-lint.
README.md and TODO.md describe the new setup.

Model: opus-5-5
2026-10-06 04:32:11 +00:00
2025-05-08 13:26:05 -07:00

attrsum is a Go 1.22 command-line utility that adds, updates, verifies, and clears per-file file content checksums stored in extended attributes (xattrs) on macOS (APFS) and Linux, released under the WTFPL v2.

Original release 2025-05-08.

Current version 1.0 (2025-05-08).


Getting Started — Quick Build

# prerequisites: Go 1.22+
git clone https://git.eeqj.de/sneak/attrsum.git
cd attrsum
go build -o attrsum .

Install

go install git.eeqj.de/sneak/attrsum@latest   # into GOPATH/bin or $(go env GOBIN)

Semantic Versioning 2.0.0 is used for tags.


Usage

# add checksum & timestamp xattrs to every regular file under one or more paths
attrsum sum add DIR1 DIR2 file.txt

# update checksum only when file mtime is newer than stored sumtime
attrsum sum update DIR1 DIR2

# verify checksums, stop on first error
attrsum check DIR1 DIR2

# verify every file, reporting each result, keep going after errors
attrsum -v check --continue DIR1 DIR2

# remove checksum & timestamp xattrs
attrsum clear DIR1 DIR2

# read paths from stdin (use - as argument)
find /data -name "*.jpg" | attrsum sum add -

# quiet mode (suppress progress bar and summary)
attrsum -q sum add DIR
xattr key meaning
user.berlin.sneak.app.attrsum.checksum base-58 multihash (sha2-256)
user.berlin.sneak.app.attrsum.sumtime RFC 3339 timestamp of checksum

Flags:

  • -v, --verbose — per-file log output
  • -q, --quiet — suppress all output except errors (no progress bar or summary)
  • --exclude PATTERN — skip paths matching rsync/Doublestar glob
  • --exclude-dotfiles — skip any path component that starts with .

All commands display a progress bar with ETA and print a summary report to stderr on completion (unless --quiet is specified).

attrsum never follows symlinks and skips non-regular files (sockets, devices, …).


Why?

Apple APFS and Linux ext3/ext4 store no per-file content checksums, so silent data corruption can pass unnoticed. attrsum keeps a portable checksum inside each file’s xattrs, providing integrity verification that travels with the file itself—no external database required. Now you can trust a USB stick didn't eat your data.


TODO

Future improvements under consideration:

  • Dry-run mode (--dry-run, -n) — show what would be done without making changes
  • JSON output (--json) — machine-readable output for scripting and integration
  • Parallel processing (-j N) — use multiple goroutines for faster checksumming on large trees
  • Exit code documentation — formalize and document exit codes for scripting

Contributing

  • Author & maintainer: sneak – sneak@sneak.berlin
  • Issues / PRs: https://git.eeqj.de/sneak/attrsum/
  • Code must pass make check, which runs the tests and golangci-lint as phases of the Dockerfile (Docker is required) and checks formatting with gofmt.
  • No CLA; contributions are under WTFPL v2.

Community & Support

Bug tracker and wiki are in the Gitea repo linked above.

No formal Code of Conduct; be excellent to each other.


License

Everything is permitted. See WTFPL v2.

S
Description
No description provided
Readme
278 KiB
Languages
Go 74.9%
Shell 18.1%
Dockerfile 4.3%
Makefile 2.7%