Skip to content

rsmm.sdk.repo

Distribution: repo.json schema + SHA256/Ed25519 sign + verify.

Open spec. No central host. Anyone can publish a repo.json at a URL of their choice; users add it with rsmm repo add <url>.

Signing is optional but recommended. We use Ed25519 from cryptography when available and fall back to “unsigned mode” otherwise. Keys live in ~/.rsmm/keys/:

<id>.pub # base64 Ed25519 public key
<id>.key # base64 Ed25519 private key (mode 0600)
repo.sha256_file(path: 'Path') -> 'str'

Hex SHA256 of a file, streamed (no full-file buffering).

The integrity primitive behind repo.json manifests and :func:sign_file / :func:verify_file.

repo.sign_file(path: 'Path', private_key_path: 'Path') -> 'str'

Return base64 Ed25519 signature of path’s SHA256 digest.

Signing the digest (not the whole file) lets verifiers stream-hash without buffering the file.

repo.verify_file(path: 'Path', sig_b64: 'str', public_key_path: 'Path') -> 'bool'

Verify a base64 Ed25519 signature over path’s SHA256 digest.

Returns True if sig_b64 (from :func:sign_file) matches under public_key_path, False otherwise — a malformed signature is simply one that does not verify. Raises RepoError only for a malformed or unreadable public key.

Verification must not depend on cryptography: the CLI ships frozen with no runtime dependencies, so every released build lacked it and this raised on every call — which rsmm update then read as “verify skipped” and installed the archive without checking the signature at all. Without the package it uses the stdlib Ed25519 verifier the signed loader channel already relies on (:mod:rsmm.engine.minisign).