Skip to main content
puodziukas.dev›CASES/ARTIFACT VERSIONING/
CASE STUDY - DATA INTEGRITY - BACKUP VERIFICATION

Byte-Identical
Verification at Scale

SHA-256 checksum manifest - 541,774 files - 0 divergence - GPG-signed - home lab
Reproducibility is usually a convention: a README says which data produced a result, and everyone trusts it. Here it is a checksum pass. A full drive copy, with that file count verified byte-for-byte against a GPG-signed SHA-256 manifest. Home lab, code available on request.

Why Convention Is Not Enough

A large file migration is only as trustworthy as the answer to "did every byte survive the copy." When that answer lives in a file count or a progress bar, it drifts silently: a file truncates, a copy stalls, and nobody notices until something reads back wrong. A checksum manifest removes the ambiguity. Every file's SHA-256 digest is recorded before the copy and checked again after, so there is no such thing as a silent divergence.

This case is that discipline run at full-corpus scale on a home-lab drive migration: not a claim of a data-versioning platform, just the checksum-verify mechanism, GPG-signed and re-run until the result is 0 divergent files.

The Two Properties

PROPERTY 01
Signed manifest
The full file set is captured in a manifest and GPG-signed. The signature attests; it never seals, an owner is never locked out.
Provenance you can hand to an auditor: who produced this file set, and proof it has not drifted since.
PROPERTY 02
Byte-identical verification
Every file was duplicated and every one verified byte-for-byte against its source SHA-256 digest. 0 divergent files.
A checksum verify pass is the oracle. Reproducibility is not asserted in prose, it is an exit code.
# Byte-identical verification (home lab) manifest = gpg_sign(sha256_all(source_files)) # signs, never seals verify: for f in all_files: assert sha256(f) == manifest[f.path] # 0 divergent

Why This Matters For A Team

A platform or data team migrating a large file set needs to answer "did anything silently corrupt" without hand-waving. A GPG-signed checksum manifest makes that answer a verify command instead of a promise. The manifest signs rather than seals, so it never becomes a lockout risk for the owner. Reproducibility becomes an exit code.

PROOF
+GPG-signed manifest, Attests provenance to an auditor; signs, never seals, no owner lockout
+0 divergence, Every file verified byte-identical against its source digest
+Home lab, private, Code available on request
Work with me

reproducibility discipline - Remote - open to mid-level and senior IC roles

RELATED CASES
Eval & Release Gate