nyx / verify.py
Devansh Batham
Document TypeSafe compatibility and benchmark performance
7519c08
Raw History Blame Contribute Delete
1.18 kB
#!/usr/bin/env python3
"""Fail-closed integrity check for the nyx package."""
from __future__ import annotations
import hashlib
import json
from pathlib import Path
ROOT = Path(__file__).resolve().parent
def digest(path: Path) -> str:
checksum = hashlib.sha256()
with path.open("rb") as stream:
for block in iter(lambda: stream.read(8 * 1024 * 1024), b""):
checksum.update(block)
return checksum.hexdigest()
manifest = json.loads((ROOT / "release-manifest.json").read_text())
if manifest.get("repository") != "devanshbatham/nyx":
raise SystemExit("Unexpected repository identity")
for name, metadata in manifest["files"].items():
path = ROOT / name
if not path.is_file() or path.is_symlink():
raise SystemExit(f"Missing or unsafe release file: {name}")
if path.stat().st_size != metadata["bytes"]:
raise SystemExit(f"Size mismatch: {name}")
if digest(path) != metadata["sha256"]:
raise SystemExit(f"SHA-256 mismatch: {name}")
print(json.dumps({
"verified": True,
"files": len(manifest["files"]),
"total_bytes": manifest["total_bytes"],
"repository": manifest["repository"],
}))