File Manifest Verifier
Check a received bundle against the file list and SHA-256 digests supplied by its sender. This tool validates the expected document first, then hashes selected files incrementally and reports matched, changed, missing, unexpected or indeterminate paths. A reference manifest can also be generated, but generation alone does not verify a received bundle.
Key features
- Strict v1 JSON schema with duplicate-key and duplicate-path rejection
- Exact relative paths, file sizes and SHA-256 content comparisons
- Separate missing, unexpected and unreadable-file outcomes
- Sequential 256 KiB reads with cancellation and no partial success
- Complete CSV/JSON reports and an optional new reference manifest
- Explicit folder-root handling and a real byte-change example
How to use
- Paste or select an expected JSON manifest in this tool’s documented v1 format.
- Select actual files or a folder and review the paths; choose whether to remove the selected folder’s root name.
- Run verification and wait for every readable file to finish. Canceling discards the run.
- Review all five outcomes, including any read failures. Filters affect the preview only.
- Download the complete report, or separately generate a new reference from readable actual files.
Use cases
- Check that a transferred research-data bundle has every expected file
- Locate a one-byte change after a handoff or backup copy
- Prepare a reference manifest before sharing a small asset bundle
Frequently asked questions
Which manifest formats are supported?
Only this tool’s strict JSON format: format teck-tani-file-manifest, version 1, algorithm SHA-256, pathRule relative-posix-exact and files containing exactly path, size and sha256. Unknown fields, duplicate keys and paths, wrong digest lengths and unsupported algorithms are rejected. Integers must be nonnegative decimal literals, without exponent or fractional notation. Common checksum text formats are not imported.
How are file paths compared?
Paths are relative POSIX-style strings, compared exactly with case and Unicode code points preserved. Folder selection can remove exactly one root segment; flat file selection has only file names. No case folding, Unicode normalization or path guessing occurs. Absolute paths, backslashes, colons, dot segments, empty segments, control/bidirectional-control characters, unpaired surrogates and edge spaces are rejected. Paths have at most 512 Unicode characters and each segment at most 255.
What do the five verification outcomes mean?
Matched means path, byte size and SHA-256 all agree. Changed means an expected file differs in size or digest. Missing means no selected file has that path. Unexpected means a readable selected file is absent from the expectation. Indeterminate means its bytes could not be read completely; this takes precedence over unexpected. A read failure never counts as matched, and cancellation returns no report.
What are the limits and memory behavior?
At most 200 files per expected or actual set, 256 MiB per file, 1 GiB per set, and 256 KiB of UTF-8 manifest JSON. Hashing reads one 256 KiB slice at a time and yields between slices. The current browser read must settle before cancellation finishes; no second job starts in the meantime. Empty files are hashed correctly. Empty expected and actual sets match vacuously; that does not confirm any content. JSON-encoded path strings are limited to 200 KiB combined so a generated compact reference remains importable.
Does a match prove authenticity or safety?
No. It establishes consistency with the supplied manifest, whose source you must trust separately. The tool does not validate digital signatures, scan for malware, inspect archives, detect omitted empty folders or verify filesystem permissions, symbolic links or modification dates. It compares selected file bytes and paths, not two complete folder snapshots.
What do exports and reference generation include?
Reports contain every path even when the table is filtered. CSV uses UTF-8 BOM, CRLF and quoted fields; formula-shaped strings receive an apostrophe. JSON preserves original path strings. A new reference contains readable actual files only, including unexpected files and excluding missing expected files; it is unavailable if any read fails. Creating it does not overwrite the supplied expectation or establish a trusted publisher.
Privacy
Selected file contents, paths, hashes and reports are processed in page memory. This tool does not send them over the network or automatically store them. Choose downloads explicitly and treat the exported file names and hashes as potentially sensitive. Leaving the page discards unsaved results.
Comments & questions