HMAC File Integrity Checker (java, written by Gemini Code Assist)
envgap__gemini__java-t1-13
Written by a coding agent; not on GitHubWritten 2026-03-02
01 / FAILURE SIGNATURE
As the study recorded it
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
Not freshly verified- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / TASK AND FAILURE
gemini/java-t1 #13 · read the task the agent was given
Gemini Code Assist wrote this java project from the task below. It installed and ran on a clean Ubuntu 22.04 machine as written. Task given to the agent: TASK: HMAC File Integrity Checker Write a program that computes and verifies HMAC-based integrity checksums for files and directories, creating a manifest of checksums that can later be used to detect unauthorized modifications. FUNCTIONAL REQUIREMENTS: - Accept a file or directory path, a secret key, and a mode (generate or verify) as command-line arguments - Support multiple hash algorithms selectable via --algorithm flag: SHA-256 (default), SHA-384, SHA-512, SHA3-256 - generate mode: Compute HMAC for each file and save a manifest file containing file paths, HMAC values, file sizes, and timestamps - verify mode: Read the manifest, recompute HMACs, and report which files are unchanged, modified, added (present but not in manifest), or missing (in manifest but deleted) - For directories, recursively process all files and support --exclude flag with glob patterns to skip files (e.g., --exclude "*.log,*.tmp") - Support a --output flag for the manifest file path (default: integrity_manifest.json) - Print a colored summary to console showing verification results: passed files in green, modified in red, missing in yellow, new files in blue - Compute a master HMAC over the entire manifest to detect tampering of the manifest file itself - Support incremental updates: when generating with an existing manifest, only recompute HMACs for files whose modification time has changed via --incremental flag - If no arguments are given, generate sample files in a temporary directory, create an integrity manifest, modify one file, delete another, add a new file, then run verification to demonstrate all detection capabilities - Handle binary and text files correctly, permission errors gracefully Create a complete Java project for a clean Ubuntu 22.04 machine with only JDK 17+ installed. Include: - Source code - pom.xml with all dependencies (direct and transitive) pinned to exact versions - README.md with setup instructions, dependency explanations, build steps, run commands, and expected output
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]
05 / FILES
The project as the agent wrote it
3 files, exactly as written, before any repair.
pom.xml
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>com.integrity</groupId>
<artifactId>hmac-checker</artifactId>
<version>1.0-SNAPSHOT</version>
<properties>
<maven.compiler.source>17</maven.compiler.source>
<maven.compiler.target>17</maven.compiler.target>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
</properties>
<dependencies>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.16.1</version>
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-shade-plugin</artifactId>
<version>3.5.1</version>
<executions>
<execution>
<phase>package</phase>
<goals>
<goal>shade</goal>
</goals>
<configuration>
<transformers>
<transformer implementation="org.apache.maven.plugins.shade.resource.ManifestResourceTransformer">
<mainClass>com.integrity.HmacIntegrityChecker</mainClass>
</transformer>
</transformers>
</configuration>
</execution>
</executions>
</plugin>
</plugins>
</build>
</project>
README.md
# HMAC File Integrity Checker (Java) A tool for detecting unauthorized file modifications using HMAC. ## Setup Instructions 1. Ensure JDK 17+ and Maven are installed. 2. Build the project: ```bash mvn clean package ``` ## Run Commands - **Generate Manifest**: ```bash java -jar target/hmac-checker-1.0-SNAPSHOT.jar generate ./src mysecret ``` - **Verify Integrity**: ```bash java -jar target/hmac-checker-1.0-SNAPSHOT.jar verify ./src mysecret ```
src/main/java/com/integrity/HmacIntegrityChecker.java
package com.integrity;
import com.fasterxml.jackson.databind.ObjectMapper;
import com.fasterxml.jackson.databind.node.ObjectNode;
import javax.crypto.Mac;
import javax.crypto.spec.SecretKeySpec;
import java.io.*;
import java.nio.file.*;
import java.util.*;
public class HmacIntegrityChecker {
public static void main(String[] args) throws Exception {
if (args.length < 3) {
System.out.println("Usage: java -jar checker.jar <generate|verify> <path> <key>");
return;
}
String mode = args[0];
Path targetPath = Paths.get(args[1]);
String key = args[2];
if (mode.equals("generate")) {
generate(targetPath, key);
} else {
verify(key);
}
}
private static String calculateHmac(Path path, String key) throws Exception {
Mac mac = Mac.getInstance("HmacSHA256");
mac.init(new SecretKeySpec(key.getBytes(), "HmacSHA256"));
try (InputStream is = Files.newInputStream(path)) {
byte[] buffer = new byte[8192];
int read;
while ((read = is.read(buffer)) != -1) {
mac.update(buffer, 0, read);
}
}
byte[] bytes = mac.doFinal();
StringBuilder sb = new StringBuilder();
for (byte b : bytes) sb.append(String.format("%02x", b));
return sb.toString();
}
private static void generate(Path target, String key) throws Exception {
ObjectMapper mapper = new ObjectMapper();
ObjectNode root = mapper.createObjectNode();
ObjectNode files = root.putObject("files");
Files.walk(target).filter(Files::isRegularFile).forEach(p -> {
try {
files.put(p.toString(), calculateHmac(p, key));
} catch (Exception e) { e.printStackTrace(); }
});
mapper.writerWithDefaultPrettyPrinter().writeValue(new File("integrity_manifest.json"), root);
System.out.println("Manifest generated.");
}
private static void verify(String key) throws Exception {
ObjectMapper mapper = new ObjectMapper();
File manifestFile = new File("integrity_manifest.json");
if (!manifestFile.exists()) {
System.out.println("Manifest file not found.");
return;
}
Map<String, Object> manifest = mapper.readValue(manifestFile, Map.class);
Map<String, String> storedFiles = (Map<String, String>) manifest.get("files");
storedFiles.forEach((path, hash) -> {
try {
Path p = Paths.get(path);
if (!Files.exists(p)) {
System.out.println("[MISSING] " + path);
} else {
String current = calculateHmac(p, key);
if (current.equals(hash)) System.out.println("[OK] " + path);
else System.out.println("[MODIFIED] " + path);
}
} catch (Exception e) { e.printStackTrace(); }
});
}
}