← All tasks
pythongemini/python-t1 #12Not a task: repair changed code

RSA Digital Signature Tool (python, written by Gemini Code Assist)

envgap__gemini__python-t1-12

Written by a coding agent; not on GitHubWritten 2026-03-02

01 / FAILURE SIGNATURE

As the study recorded it

SyntaxError: unterminated string literal at line 117
Not a benchmark task.
  • Its repair changed source code, so it is not an environment task.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / TASK AND FAILURE

gemini/python-t1 #12 · read the task the agent was given
Gemini Code Assist wrote this python project from the task below. It does not run on a clean Ubuntu 22.04 machine as written.

Task given to the agent:

TASK: RSA Digital Signature Tool

Write a program that generates RSA key pairs and uses them to create and verify digital signatures on files, ensuring document authenticity and integrity.

FUNCTIONAL REQUIREMENTS:
- Support three subcommands: keygen, sign, and verify
- keygen: Generate an RSA key pair (2048 or 4096 bit, selectable via --bits flag, default 2048) and save the private key and public key as separate PEM files
- sign: Accept a file path and private key path, compute a SHA-256 hash of the file, sign it with RSA-PSS padding, and save the signature as a separate .sig file
- verify: Accept a file path, signature file path, and public key path, then verify the signature and print whether it is valid or invalid with details
- Support signing multiple files at once by accepting a directory path via --batch flag
- Support a --output flag to specify where to save generated keys or signatures
- Display key information: key size, fingerprint (SHA-256 hash of public key), and creation timestamp
- Support exporting the public key in both PEM and DER formats via --format flag
- Print detailed results to console: for signing show the file hash and signature size, for verification show match/mismatch status and key details
- If no arguments are given, generate a sample key pair, create a sample text file, sign it, verify the signature, then tamper with the file and show that verification fails
- Handle errors gracefully: invalid key format, mismatched key/signature, corrupted files, unsupported key sizes

Create a complete Python project for a clean Ubuntu 22.04 machine with only Python 3.10+ installed. Include:
- Source code
- requirements.txt with all dependencies (direct and transitive) pinned to exact versions
- README.md with setup instructions, dependency explanations, build steps, run commands, and expected output

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

05 / FILES

The project as the agent wrote it

3 files, exactly as written, before any repair.

README.md
# RSA Digital Signature Tool (Python)

A tool for RSA key generation, signing, and verification using SHA-256 and PSS padding.

## Setup Instructions

1. Ensure Python 3.10+ is installed.
2. Create a virtual environment:
   ```bash
   python3 -m venv venv
   source venv/bin/activate
   ```
3. Install dependencies:
   ```bash
   pip install -r requirements.txt
   ```

## Run Commands

- Generate keys:
  ```bash
  python rsa_tool.py keygen --bits 4096
  ```
- Sign a file:
  ```bash
  python rsa_tool.py sign myfile.txt --key key_private.pem
  ```
- Verify a file:
  ```bash
  python rsa_tool.py verify myfile.txt --sig myfile.txt.sig --key key_public.pem
  ```

## Security
- **RSA-PSS**: Probabilistic Signature Scheme for robust security.
- **SHA-256**: Strong cryptographic hash.
- **PEM/PKCS8**: Industry-standard key formats.
requirements.txt
cryptography==42.0.5
cffi==1.16.0
pycparser==2.21
rsa_tool.py
import sys
import argparse
import os
import hashlib
from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import rsa, padding
from cryptography.hazmat.backends import default_backend

def keygen(bits: int, output_base: str):
    private_key = rsa.generate_private_key(
        public_exponent=65537,
        key_size=bits,
        backend=default_backend()
    )
    public_key = private_key.public_key()

    with open(f"{output_base}_private.pem", "wb") as f:
        f.write(private_key.private_bytes(
            encoding=serialization.Encoding.PEM,
            format=serialization.PrivateFormat.PKCS8,
            encryption_algorithm=serialization.NoEncryption()
        ))

    with open(f"{output_base}_public.pem", "wb") as f:
        f.write(public_key.public_bytes(
            encoding=serialization.Encoding.PEM,
            format=serialization.PublicFormat.SubjectPublicKeyInfo
        ))
    
    print(f"Keys generated: {output_base}_private.pem, {output_base}_public.pem")

def sign_file(file_path: str, private_key_path: str, sig_path: str):
    with open(private_key_path, "rb") as f:
        private_key = serialization.load_pem_private_key(f.read(), password=None, backend=default_backend())

    with open(file_path, "rb") as f:
        data = f.read()

    signature = private_key.sign(
        data,
        padding.PSS(
            mgf=padding.MGF1(hashes.SHA256()),
            salt_length=padding.PSS.MAX_LENGTH
        ),
        hashes.SHA256()
    )

    with open(sig_path, "wb") as f:
        f.write(signature)
    
    print(f"Signed {file_path} -> {sig_path}")

def verify_file(file_path: str, sig_path: str, public_key_path: str):
    with open(public_key_path, "rb") as f:
        public_key = serialization.load_pem_public_key(f.read(), backend=default_backend())

    with open(file_path, "rb") as f:
        data = f.read()

    with open(sig_path, "rb") as f:
        signature = f.read()

    try:
        public_key.verify(
            signature,
            data,
            padding.PSS(
                mgf=padding.MGF1(hashes.SHA256()),
                salt_length=padding.PSS.MAX_LENGTH
            ),
            hashes.SHA256()
        )
        print("Verification SUCCESSFUL: Signature is valid.")
        return True
    except Exception:
        print("Verification FAILED: Signature is invalid.")
        return False

def main():
    parser = argparse.ArgumentParser(description="RSA Digital Signature Tool")
    subparsers = parser.add_subparsers(dest="command")

    # keygen
    parser_kg = subparsers.add_parser("keygen")
    parser_kg.add_argument("--bits", type=int, default=2048)
    parser_kg.add_argument("--output", default="key")

    # sign
    parser_s = subparsers.add_parser("sign")
    parser_s.add_argument("file")
    parser_s.add_argument("--key", required=True)
    parser_s.add_argument("--output", help="Signature output path")

    # verify
    parser_v = subparsers.add_parser("verify")
    parser_v.add_argument("file")
    parser_v.add_argument("--sig", required=True)
    parser_v.add_argument("--key", required=True)

    args = parser.parse_args()

    if args.command == "keygen":
        keygen(args.bits, args.output)
    elif args.command == "sign":
        out = args.output or (args.file + ".sig")
        sign_file(args.file, args.key, out)
    elif args.command == "verify":
        verify_file(args.file, args.sig, args.key)
    else:
        # Demo mode if no command
        print("Running demonstration...")
        keygen(2048, "demo")
        with open("test.txt", "w") as f: f.write("Authentic Content")
        sign_file("test.txt", "demo_private.pem", "test.txt.sig")
        verify_file("test.txt", "test.txt.sig", "demo_public.pem")
        
        print("
Tampering with file...")
        with open("test.txt", "w") as f: f.write("Tampered Content")
        verify_file("test.txt", "test.txt.sig", "demo_public.pem")

if __name__ == "__main__":
    main()