← All tasks
pythongemini/python-t1 #13Not a task: repair changed code

HMAC File Integrity Checker (python, written by Gemini Code Assist)

envgap__gemini__python-t1-13

Written by a coding agent; not on GitHubWritten 2026-03-02

01 / FAILURE SIGNATURE

As the study recorded it

SyntaxError: unterminated string literal at line 74
Not a benchmark task.
  • Its repair changed source code, so it is not an environment task.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / TASK AND FAILURE

gemini/python-t1 #13 · read the task the agent was given
Gemini Code Assist wrote this python project from the task below. It does not run on a clean Ubuntu 22.04 machine as written.

Task given to the agent:

TASK: HMAC File Integrity Checker

Write a program that computes and verifies HMAC-based integrity checksums for files and directories, creating a manifest of checksums that can later be used to detect unauthorized modifications.

FUNCTIONAL REQUIREMENTS:
- Accept a file or directory path, a secret key, and a mode (generate or verify) as command-line arguments
- Support multiple hash algorithms selectable via --algorithm flag: SHA-256 (default), SHA-384, SHA-512, SHA3-256
- generate mode: Compute HMAC for each file and save a manifest file containing file paths, HMAC values, file sizes, and timestamps
- verify mode: Read the manifest, recompute HMACs, and report which files are unchanged, modified, added (present but not in manifest), or missing (in manifest but deleted)
- For directories, recursively process all files and support --exclude flag with glob patterns to skip files (e.g., --exclude "*.log,*.tmp")
- Support a --output flag for the manifest file path (default: integrity_manifest.json)
- Print a colored summary to console showing verification results: passed files in green, modified in red, missing in yellow, new files in blue
- Compute a master HMAC over the entire manifest to detect tampering of the manifest file itself
- Support incremental updates: when generating with an existing manifest, only recompute HMACs for files whose modification time has changed via --incremental flag
- If no arguments are given, generate sample files in a temporary directory, create an integrity manifest, modify one file, delete another, add a new file, then run verification to demonstrate all detection capabilities
- Handle binary and text files correctly, permission errors gracefully

Create a complete Python project for a clean Ubuntu 22.04 machine with only Python 3.10+ installed. Include:
- Source code
- requirements.txt with all dependencies (direct and transitive) pinned to exact versions
- README.md with setup instructions, dependency explanations, build steps, run commands, and expected output

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

05 / FILES

The project as the agent wrote it

3 files, exactly as written, before any repair.

integrity_checker.py
import os
import sys
import hmac
import hashlib
import json
import argparse
import glob
from colorama import Fore, Style, init

init(autoreset=True)

def compute_hmac(file_path, key, algorithm='sha256'):
    h = hmac.new(key.encode(), digestmod=algorithm)
    with open(file_path, 'rb') as f:
        while chunk := f.read(8192):
            h.update(chunk)
    return h.hexdigest()

def generate_manifest(path, key, algo, output, exclude):
    manifest = {"files": {}, "algorithm": algo}
    files = []
    if os.path.isfile(path):
        files = [path]
    else:
        for root, _, filenames in os.walk(path):
            for f in filenames:
                full_path = os.path.join(root, f)
                if not any(glob.fnmatch.fnmatch(f, pattern) for pattern in exclude):
                    files.append(full_path)

    for f_path in files:
        print(f"Processing {f_path}...")
        manifest["files"][f_path] = {
            "hmac": compute_hmac(f_path, key, algo),
            "size": os.path.getsize(f_path),
            "mtime": os.path.getmtime(f_path)
        }

    # Master HMAC
    manifest_data = json.dumps(manifest["files"], sort_keys=True)
    manifest["master_hmac"] = hmac.new(key.encode(), manifest_data.encode(), digestmod=algo).hexdigest()

    with open(output, 'w') as f:
        json.dump(manifest, f, indent=4)
    print(f"{Fore.GREEN}Manifest saved to {output}")

def verify_manifest(manifest_path, key):
    with open(manifest_path, 'r') as f:
        manifest = json.load(f)
    
    algo = manifest["algorithm"]
    stored_files = manifest["files"]
    
    # Verify Master HMAC
    manifest_data = json.dumps(stored_files, sort_keys=True)
    current_master = hmac.new(key.encode(), manifest_data.encode(), digestmod=algo).hexdigest()
    if current_master != manifest["master_hmac"]:
        print(f"{Fore.RED}CRITICAL: Manifest file has been tampered with!")
        return

    results = {"unchanged": [], "modified": [], "added": [], "missing": []}
    
    # Check existing and missing
    for f_path, info in stored_files.items():
        if not os.path.exists(f_path):
            results["missing"].append(f_path)
        else:
            current_hmac = compute_hmac(f_path, key, algo)
            if current_hmac == info["hmac"]:
                results["unchanged"].append(f_path)
            else:
                results["modified"].append(f_path)

    print("
VERIFICATION REPORT")
    print("=" * 40)
    for f in results["unchanged"]: print(f"{Fore.GREEN}[PASS] {f}")
    for f in results["modified"]: print(f"{Fore.RED}[MODIFIED] {f}")
    for f in results["missing"]: print(f"{Fore.YELLOW}[MISSING] {f}")

def main():
    parser = argparse.ArgumentParser(description="HMAC File Integrity Checker")
    parser.add_argument("mode", choices=['generate', 'verify'])
    parser.add_argument("path", help="File or directory to process")
    parser.add_argument("key", help="Secret key for HMAC")
    parser.add_argument("--algorithm", default="sha256")
    parser.add_argument("--output", default="integrity_manifest.json")
    parser.add_argument("--exclude", default="")

    args = parser.parse_args()
    exclude_list = args.exclude.split(',') if args.exclude else []

    if args.mode == 'generate':
        generate_manifest(args.path, args.key, args.algorithm, args.output, exclude_list)
    else:
        verify_manifest(args.output, args.key)

if __name__ == "__main__":
    main()
README.md
# HMAC File Integrity Checker (Python)

A tool for detecting unauthorized file modifications using HMAC.

## Setup Instructions

1. Ensure Python 3.10+ is installed.
2. Create a virtual environment:
   ```bash
   python3 -m venv venv
   source venv/bin/activate
   ```
3. Install dependencies:
   ```bash
   pip install -r requirements.txt
   ```

## Run Commands

- **Generate Manifest**:
  ```bash
  python integrity_checker.py generate ./target_dir mysecretkey
  ```
- **Verify Integrity**:
  ```bash
  python integrity_checker.py verify ./target_dir mysecretkey
  ```

## Output
- Console: Color-coded report of changed/missing files.
- File: `integrity_manifest.json` containing HMACs and metadata.
requirements.txt
colorama==0.4.6