← All tasks
javagemini/java-t1 #12Not a task: repair changed code

RSA Digital Signature Tool (java, written by Gemini Code Assist)

envgap__gemini__java-t1-12

Written by a coding agent; not on GitHubWritten 2026-03-02

01 / FAILURE SIGNATURE

As the study recorded it

Unclosed string literals (6 broken strings)
Not a benchmark task.
  • Its repair changed source code, so it is not an environment task.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / TASK AND FAILURE

gemini/java-t1 #12 · read the task the agent was given
Gemini Code Assist wrote this java project from the task below. It does not run on a clean Ubuntu 22.04 machine as written.

Task given to the agent:

TASK: RSA Digital Signature Tool

Write a program that generates RSA key pairs and uses them to create and verify digital signatures on files, ensuring document authenticity and integrity.

FUNCTIONAL REQUIREMENTS:
- Support three subcommands: keygen, sign, and verify
- keygen: Generate an RSA key pair (2048 or 4096 bit, selectable via --bits flag, default 2048) and save the private key and public key as separate PEM files
- sign: Accept a file path and private key path, compute a SHA-256 hash of the file, sign it with RSA-PSS padding, and save the signature as a separate .sig file
- verify: Accept a file path, signature file path, and public key path, then verify the signature and print whether it is valid or invalid with details
- Support signing multiple files at once by accepting a directory path via --batch flag
- Support a --output flag to specify where to save generated keys or signatures
- Display key information: key size, fingerprint (SHA-256 hash of public key), and creation timestamp
- Support exporting the public key in both PEM and DER formats via --format flag
- Print detailed results to console: for signing show the file hash and signature size, for verification show match/mismatch status and key details
- If no arguments are given, generate a sample key pair, create a sample text file, sign it, verify the signature, then tamper with the file and show that verification fails
- Handle errors gracefully: invalid key format, mismatched key/signature, corrupted files, unsupported key sizes

Create a complete Java project for a clean Ubuntu 22.04 machine with only JDK 17+ installed. Include:
- Source code
- pom.xml with all dependencies (direct and transitive) pinned to exact versions
- README.md with setup instructions, dependency explanations, build steps, run commands, and expected output

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

05 / FILES

The project as the agent wrote it

3 files, exactly as written, before any repair.

pom.xml
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>

    <groupId>com.rsatool</groupId>
    <artifactId>rsa-signature-tool</artifactId>
    <version>1.0-SNAPSHOT</version>

    <properties>
        <maven.compiler.source>17</maven.compiler.source>
        <maven.compiler.target>17</maven.compiler.target>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
    </properties>

    <dependencies>
        <!-- Built-in security libraries used -->
    </dependencies>

    <build>
        <plugins>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-shade-plugin</artifactId>
                <version>3.5.1</version>
                <executions>
                    <execution>
                        <phase>package</phase>
                        <goals>
                            <goal>shade</goal>
                        </goals>
                        <configuration>
                            <transformers>
                                <transformer implementation="org.apache.maven.plugins.shade.resource.ManifestResourceTransformer">
                                    <mainClass>com.rsatool.RsaSignatureTool</mainClass>
                                </transformer>
                            </transformers>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
        </plugins>
    </build>
</project>
README.md
# RSA Digital Signature Tool (Java)

A tool for RSA key generation, signing, and verification.

## Setup Instructions

1. Ensure JDK 17+ and Maven are installed.
2. Build the project:
   ```bash
   mvn clean package
   ```

## Run Commands

- Generate keys:
  ```bash
  java -jar target/rsa-signature-tool-1.0-SNAPSHOT.jar keygen
  ```
- Sign a file:
  ```bash
  java -jar target/rsa-signature-tool-1.0-SNAPSHOT.jar sign data.txt key_private.pem
  ```
- Verify a file:
  ```bash
  java -jar target/rsa-signature-tool-1.0-SNAPSHOT.jar verify data.txt data.txt.sig key_public.pem
  ```
src/main/java/com/rsatool/RsaSignatureTool.java
package com.rsatool;

import java.io.File;
import java.io.FileOutputStream;
import java.nio.file.Files;
import java.security.*;
import java.security.spec.PKCS8EncodedKeySpec;
import java.security.spec.X509EncodedKeySpec;
import java.util.Base64;

public class RsaSignatureTool {

    public static void main(String[] args) {
        if (args.length < 1) {
            System.out.println("Usage: java -jar rsa-tool.jar <keygen|sign|verify> ...");
            return;
        }

        String command = args[0];
        try {
            if (command.equalsIgnoreCase("keygen")) {
                generateKeys("key");
            } else if (command.equalsIgnoreCase("sign") && args.length >= 3) {
                sign(new File(args[1]), new File(args[2]));
            } else if (command.equalsIgnoreCase("verify") && args.length >= 4) {
                verify(new File(args[1]), new File(args[2]), new File(args[3]));
            }
        } catch (Exception e) {
            e.printStackTrace();
        }
    }

    private static void generateKeys(String base) throws Exception {
        KeyPairGenerator generator = KeyPairGenerator.getInstance("RSA");
        generator.initialize(2048);
        KeyPair pair = generator.generateKeyPair();

        try (FileOutputStream out = new FileOutputStream(base + "_private.pem")) {
            out.write("-----BEGIN PRIVATE KEY-----
".getBytes());
            out.write(Base64.getMimeEncoder().encode(pair.getPrivate().getEncoded()));
            out.write("
-----END PRIVATE KEY-----".getBytes());
        }
        try (FileOutputStream out = new FileOutputStream(base + "_public.pem")) {
            out.write("-----BEGIN PUBLIC KEY-----
".getBytes());
            out.write(Base64.getMimeEncoder().encode(pair.getPublic().getEncoded()));
            out.write("
-----END PUBLIC KEY-----".getBytes());
        }
        System.out.println("Keys generated: " + base + "_private.pem and " + base + "_public.pem");
    }

    private static void sign(File file, File keyFile) throws Exception {
        byte[] keyBytes = Files.readAllBytes(keyFile.toPath());
        String pem = new String(keyBytes).replace("-----BEGIN PRIVATE KEY-----", "")
                                         .replace("-----END PRIVATE KEY-----", "")
                                         .replaceAll("\s", "");
        PKCS8EncodedKeySpec spec = new PKCS8EncodedKeySpec(Base64.getDecoder().decode(pem));
        PrivateKey key = KeyFactory.getInstance("RSA").generatePrivate(spec);

        Signature sig = Signature.getInstance("SHA256withRSA");
        sig.initSign(key);
        sig.update(Files.readAllBytes(file.toPath()));
        byte[] signature = sig.sign();

        Files.write(new File(file.getPath() + ".sig").toPath(), signature);
        System.out.println("Signed: " + file.getPath() + ".sig");
    }

    private static void verify(File file, File sigFile, File keyFile) throws Exception {
        byte[] keyBytes = Files.readAllBytes(keyFile.toPath());
        String pem = new String(keyBytes).replace("-----BEGIN PUBLIC KEY-----", "")
                                         .replace("-----END PUBLIC KEY-----", "")
                                         .replaceAll("\s", "");
        X509EncodedKeySpec spec = new X509EncodedKeySpec(Base64.getDecoder().decode(pem));
        PublicKey key = KeyFactory.getInstance("RSA").generatePublic(spec);

        Signature sig = Signature.getInstance("SHA256withRSA");
        sig.initVerify(key);
        sig.update(Files.readAllBytes(file.toPath()));
        
        boolean valid = sig.verify(Files.readAllBytes(sigFile.toPath()));
        System.out.println("Verification " + (valid ? "SUCCESSFUL" : "FAILED"));
    }
}