`make fmt` now runs prettier over the Markdown files after the Go formatters, and `make fmt-check` fails when prettier would change one. `package.json`, `yarn.lock`, `.prettierrc` and `.prettierignore` are the `sneak/prompts` copies at `dd4027b`, except for `"private": true` in `package.json` in place of the licence field. Both scripts find yarn the way that repo's scripts do. `script/bootstrap` installs prettier with `yarn install --frozen-lockfile`. When the yarn those scripts would run is not 1.22.22, it installs yarn through corepack under node 22.17.0: the node on `PATH` if it has that version, otherwise one installed through nvm from a hash-checked archive. `README.md` and `TODO.md` are reformatted once. Model: opus-5-5
attrsum is a Go 1.22 command-line utility that adds, updates, verifies, and clears per-file file content checksums stored in extended attributes (xattrs) on macOS (APFS) and Linux, released under the WTFPL v2.
Original release 2025-05-08.
Current version 1.0 (2025-05-08).
Getting Started — Quick Build
# prerequisites: Go 1.22+
git clone https://git.eeqj.de/sneak/attrsum.git
cd attrsum
go build -o attrsum .
Install
go install git.eeqj.de/sneak/attrsum@latest # into GOPATH/bin or $(go env GOBIN)
Semantic Versioning 2.0.0 is used for tags.
Usage
# add checksum & timestamp xattrs to every regular file under one or more paths
attrsum sum add DIR1 DIR2 file.txt
# update checksum only when file mtime is newer than stored sumtime
attrsum sum update DIR1 DIR2
# verify checksums, stop on first error
attrsum check DIR1 DIR2
# verify every file, reporting each result, keep going after errors
attrsum -v check --continue DIR1 DIR2
# remove checksum & timestamp xattrs
attrsum clear DIR1 DIR2
# read paths from stdin (use - as argument)
find /data -name "*.jpg" | attrsum sum add -
# quiet mode (suppress progress bar and summary)
attrsum -q sum add DIR
| xattr key | meaning |
|---|---|
user.berlin.sneak.app.attrsum.checksum |
base-58 multihash (sha2-256) |
user.berlin.sneak.app.attrsum.sumtime |
RFC 3339 timestamp of checksum |
Flags:
-v, --verbose— per-file log output-q, --quiet— suppress all output except errors (no progress bar or summary)--exclude PATTERN— skip paths matching rsync/Doublestar glob--exclude-dotfiles— skip any path component that starts with.
All commands display a progress bar with ETA and print a summary report to
stderr on completion (unless --quiet is specified).
attrsum never follows symlinks and skips non-regular files (sockets,
devices, …).
Why?
Apple APFS and Linux ext3/ext4 store no per-file content checksums, so
silent data corruption can pass unnoticed. attrsum keeps a portable checksum
inside each file’s xattrs, providing integrity verification that travels
with the file itself—no external database required. Now you can trust a USB
stick didn't eat your data.
TODO
Future improvements under consideration:
- Dry-run mode (
--dry-run,-n) — show what would be done without making changes - JSON output (
--json) — machine-readable output for scripting and integration - Parallel processing (
-j N) — use multiple goroutines for faster checksumming on large trees - Exit code documentation — formalize and document exit codes for scripting
Contributing
- Author & maintainer: sneak – sneak@sneak.berlin
- Issues / PRs: https://git.eeqj.de/sneak/attrsum/
- Code must pass
make check, which runs the tests and golangci-lint as phases of theDockerfile(Docker is required) and checks formatting withgofmt -sand goimports for Go and prettier for Markdown.make bootstrapinstalls goimports and prettier, andmake fmtfixes what the check reports. - No CLA; contributions are under WTFPL v2.
Community & Support
Bug tracker and wiki are in the Gitea repo linked above.
No formal Code of Conduct; be excellent to each other.
License
Everything is permitted. See WTFPL v2.