Files
general-scripts-and-system-…/Windows-Scripts/checksum.ps1
T
2026-09-25 15:16:30 -06:00

376 lines
15 KiB
PowerShell

[CmdletBinding(DefaultParameterSetName='Generate')]
param(
# File(s) or wildcard pattern to compute checksum for
[Parameter(Position = 0, ParameterSetName = 'Generate', ValueFromPipeline = $true)]
[Parameter(Position = 0, ParameterSetName = 'Match', ValueFromPipeline = $true)]
[string[]]$FilePath,
# Output file to save generated checksums (-o mode)
[Parameter(Mandatory = $false, ParameterSetName = 'Generate')]
[Alias('o', '-outfile')]
[string]$OutFile,
# File containing checksums to verify (-c mode)
[Parameter(Mandatory = $false, ParameterSetName = 'Verify')]
[Alias('c', '-check')]
[string]$Check,
# Direct checksum hash string to match against (-m mode)
[Parameter(Mandatory = $true, ParameterSetName = 'Match')]
[Alias('m', '-match')]
[string]$Match,
# Hashing algorithm to use (Defaults to SHA256)
[Parameter(Mandatory = $false)]
[Alias('a', 'algo', '-algo', '-algorithm')]
[ValidateSet('SHA1', 'SHA256', 'SHA384', 'SHA512', 'MD5')]
[string]$Algorithm,
# Recursive flag (-r, -recursive, --recursive)
[Parameter(Mandatory = $false)]
[Alias('r', 'recursive', '-recursive')]
[switch]$Recursive,
# Help flag (-h, -Help, --Help, --H)
[Parameter(Mandatory = $false)]
[Alias('h', '-h', '-help')]
[switch]$Help
)
begin {
function Show-Help {
@'
NAME
checksum - Compute and verify message digests / file checksums
SYNOPSIS
.\checksum.ps1 [-FilePath] <string[]> [-OutFile <string>] [-Algorithm <string>] [-Recursive]
.\checksum.ps1 [-FilePath] <string[]> -Match <string> [-Algorithm <string>] [-Recursive]
.\checksum.ps1 -Check <string> [-Algorithm <string>] [-Recursive]
.\checksum.ps1 -Help
DESCRIPTION
Computes or verifies checksums using various cryptographic algorithms.
Outputs hash values in standard Linux utility format (<hash> <filename>).
Ignores checksum files (.md5, .sha1, .sha256, .sha384, .sha512) unless explicitly passed.
NOTE: All flags and parameters are completely case-insensitive
(e.g., -r, -R, --Recursive, and --recursive are treated identically).
PARAMETERS
-FilePath <string[]>
Specifies the path to one or more files to hash. Accepts wildcards (*).
-o, -OutFile, --OutFile <string>
Specifies an output file to save the checksum results to.
If passed as an empty string (e.g. -o ""), the file is auto-named:
- If input has a wildcard (*), outputs to 'checksums.<algo>'
- If no wildcard is used, outputs to '<filename>.<algo>' per file.
When combined with -r and *, it auto-generates checksum files
inside the current working directory and each subdirectory recursively.
-r, -Recursive, --Recursive <switch>
Recursively generate or verify checksums in subdirectories.
-c, -Check, --Check <string>
Read checksums from the specified file and verify them against files on disk.
If -r is used, searches for the specified filename recursively in subdirectories.
-m, -Match, --Match <string>
Compare the computed hash of the target file(s) against a specific hash string.
-a, -Algorithm, --Algorithm, -Algo, --Algo <string>
Specifies the cryptographic hash algorithm to use.
Supported values: SHA1, SHA256 (default), SHA384, SHA512, MD5.
If omitted in -c or -m mode, the algorithm is auto-detected by hash length.
-h, -Help, --Help, --H <switch>
Display this help message.
EXAMPLES
1. Compute SHA256 checksum for a single file:
.\checksum.ps1 myfile.iso
2. Compute checksums for all files and write to a file while showing output:
.\checksum.ps1 * --OutFile checksums.sha256
3. Auto-generate per-directory checksum files recursively for all files:
.\checksum.ps1 * -r -o ""
4. Verify checksums from verification files recursively:
.\checksum.ps1 --Check checksums.sha256 --Recursive
'@
}
# Helper function to auto-detect hash algorithm based on string character length
function Get-AlgorithmFromHashLength {
param([string]$HashString)
switch ($HashString.Trim().Length) {
32 { return 'MD5' }
40 { return 'SHA1' }
64 { return 'SHA256' }
96 { return 'SHA384' }
128 { return 'SHA512' }
default {
Write-Error "checksum: Could not auto-detect algorithm for hash length $($HashString.Length). Please specify -Algorithm."
return $null
}
}
}
}
process {
# Match help arguments passed either as switch (-h, -Help) or positional string ('help', 'h', '--help', etc.)
$isHelpRequested =$Help.IsPresent -or (
$FilePath -and$FilePath.Count -eq 1 -and (
$FilePath[0] -match '^(?i)[-/]{0,2}(h\vert{}help)$'
)
)
if ($isHelpRequested) {
Show-Help
return
}
# Normalize explicit algorithm input if provided
if (-not [string]::IsNullOrWhiteSpace($Algorithm)) {
$Algorithm =$Algorithm.ToUpper()
}
# --- ITEM GATHERING (Generate & Match Modes) ---
if ($PSCmdlet.ParameterSetName -in @('Generate', 'Match')) {
if (-not $FilePath -or$FilePath.Count -eq 0) {
Write-Error "checksum: Missing file path parameter. Use -Help for usage."
return
}
$allItems = @()$isWildcardGlobal = $false$skipExtensions = @('.md5', '.sha1', '.sha256', '.sha384', '.sha512')
foreach ($pathEntry in$FilePath) {
$isWildcard = ($pathEntry -match '\*')
if ($isWildcard) { $isWildcardGlobal =$true }
$resolvedItems = @()
if ($Recursive) {
$resolvedItems = Get-ChildItem -Path$pathEntry -Recurse -File -ErrorAction SilentlyContinue
} else {
if ($isWildcard -or ($pathEntry -match '\?')) {
$resolvedItems = Get-ChildItem -Path$pathEntry -File -ErrorAction SilentlyContinue
} else {
$resolvedItems = Get-Item -Path$pathEntry -ErrorAction SilentlyContinue
}
}
if (-not $resolvedItems) {
Write-Error "checksum: $pathEntry`: No such file or directory"
continue
}
$explicitFileFound = $false
if ((-not $isWildcard) -and (Test-Path -Path $pathEntry -PathType Leaf)) {
$explicitFileFound = $true
}
foreach ($item in $resolvedItems) {
if ($item.PSIsContainer) { continue }
# Feature 1: Skip checksum extension files unless they were named explicitly
if (-not $explicitFileFound) {
if ($skipExtensions -contains $item.Extension.ToLower()) {
continue
}
}
$allItems += $item
}
}
}
# --- DIRECT MATCH MODE (-m / -Match) ---
if ($PSCmdlet.ParameterSetName -eq 'Match') {
if ([string]::IsNullOrWhiteSpace($Algorithm)) {
$Algorithm = Get-AlgorithmFromHashLength -HashString $Match
if (-not $Algorithm) { return }
Write-Verbose "Auto-detected algorithm: $Algorithm"
}
$expectedHash = $Match.Trim().ToLower()
foreach ($item in $allItems) {
$actualHash = (Get-FileHash -Path $item.FullName -Algorithm $Algorithm).Hash.ToLower()
$targetFile = Resolve-Path -Path $item.FullName -Relative
if ($targetFile.StartsWith(".\")) { $targetFile = $targetFile.Substring(2) }
if ($actualHash -eq $expectedHash) {
Write-Host "${targetFile}: " -NoNewline
Write-Host "OK" -ForegroundColor Green
} else {
Write-Host "${targetFile}: " -NoNewline
Write-Host "FAILED" -ForegroundColor Red
}
}
}
# --- VERIFICATION MODE (-c / -Check) ---
elseif ($PSCmdlet.ParameterSetName -eq 'Verify') {
$checkFiles = @()
if ($Recursive) {
# Find all files matching the name of $Check recursively
$checkFileName = Split-Path $Check -Leaf
$checkFiles = Get-ChildItem -Path .\ -Filter $checkFileName -Recurse -File -ErrorAction SilentlyContinue
} else {
if (Test-Path -Path $Check -PathType Leaf) {
$checkFiles = @(Get-Item -Path $Check)
}
}
if (-not $checkFiles -or $checkFiles.Count -eq 0) {
Write-Error "checksum: $Check`: No such file or directory"
return
}
foreach ($cf in$checkFiles) {
$lines = Get-Content -Path$cf.FullName
$baseDir =$cf.DirectoryName
$fileAlgo =$Algorithm
if ([string]::IsNullOrWhiteSpace($fileAlgo)) {
foreach ($line in$lines) {
if ([string]::IsNullOrWhiteSpace($line) -or$line.StartsWith("#")) { continue }
if ($line -match '^([a-fA-F0-9]+)\s+') {
$fileAlgo = Get-AlgorithmFromHashLength -HashString$Matches[1]
if ($fileAlgo) { Write-Verbose "Auto-detected algorithm: $fileAlgo in $($cf.Name)" }
break
}
}
if ([string]::IsNullOrWhiteSpace($fileAlgo)) {$fileAlgo = 'SHA256' }
}
foreach ($line in$lines) {
if ([string]::IsNullOrWhiteSpace($line) -or$line.StartsWith("#")) { continue }
if ($line -match '^([a-fA-F0-9]+)\s+[* ]?(.*)$') {
$expectedHash =$Matches[1].ToLower()
$targetFile =$Matches[2].Trim().TrimStart('*')
# Resolve path relative to where the check file currently resides
$targetFullPath = Join-Path -Path $baseDir -ChildPath$targetFile
if (Test-Path -Path $targetFullPath -PathType Leaf) {$actualHash = (Get-FileHash -Path $targetFullPath -Algorithm$fileAlgo).Hash.ToLower()
$displayPath = Resolve-Path -Path$targetFullPath -Relative
if ($displayPath.StartsWith(".\")) { $displayPath =$displayPath.Substring(2) }
if ($actualHash -eq$expectedHash) {
Write-Host "${displayPath}: " -NoNewline
Write-Host "OK" -ForegroundColor Green
} else {
Write-Host "${displayPath}: " -NoNewline
Write-Host "FAILED" -ForegroundColor Red
}
} else {
# Format missing path nicely
$displayPath =$targetFile
if ($baseDir -ne (Get-Location).Path) {$displayPath = Join-Path -Path (Resolve-Path -Path $baseDir -Relative) -ChildPath$targetFile
if ($displayPath.StartsWith(".\")) { $displayPath =$displayPath.Substring(2) }
}
Write-Host "${displayPath}: " -NoNewline
Write-Host "FAILED open or read" -ForegroundColor Red
}
} else {
Write-Warning "checksum: improperly formatted line in $($cf.Name):$line"
}
}
}
}
# --- GENERATION MODE ---
else {
if ([string]::IsNullOrWhiteSpace($Algorithm)) {$Algorithm = 'SHA256'
}
# Check if -o / -OutFile parameter was explicitly invoked
$wantOutFile =$PSBoundParameters.ContainsKey('OutFile')
$outFilename =$OutFile
if ($wantOutFile) {
# Feature 2 & 3: Recursive, Wildcard + Passed output flag splits hashes strictly into localized directory files
if ($Recursive -and$isWildcardGlobal) {
$groupedItems =$allItems | Group-Object DirectoryName
foreach ($group in$groupedItems) {
$dirPath =$group.Name
$filesInDir =$group.Group
if ([string]::IsNullOrWhiteSpace($outFilename)) {
$currentOutFile = Join-Path -Path$dirPath -ChildPath "checksums.$($Algorithm.ToLower())"
} else {
$currentOutFile = Join-Path -Path $dirPath -ChildPath$outFilename
}
# Clear existing file before iterating
$null = New-Item -Path$currentOutFile -ItemType File -Force
foreach ($item in $filesInDir) {$hash = (Get-FileHash -Path $item.FullName -Algorithm$Algorithm).Hash.ToLower()
$relativePath =$item.Name # Localization relies purely on internal filenames
$outputLine = "$hash$relativePath"
Add-Content -Path $currentOutFile -Value$outputLine
Write-Output $outputLine
}
}
}
# Non-localized standard generation (Singular master file, or Per-file auto naming)
else {
$singleOutFile =$null
# Check for standard auto naming rules
if ([string]::IsNullOrWhiteSpace($outFilename)) {
if ($isWildcardGlobal) {$singleOutFile = "checksums.$($Algorithm.ToLower())"
}
} else {
$singleOutFile =$outFilename
}
# Clear master file if consolidating to one file
if ($singleOutFile) {
$null = New-Item -Path$singleOutFile -ItemType File -Force
}
foreach ($item in $allItems) {$hash = (Get-FileHash -Path $item.FullName -Algorithm$Algorithm).Hash.ToLower()
$relativePath = Resolve-Path -Path$item.FullName -Relative
if ($relativePath.StartsWith(".\")) {
$relativePath =$relativePath.Substring(2)
}
$outputLine = "$hash$relativePath"
if ($singleOutFile) {
Add-Content -Path $singleOutFile -Value$outputLine
} else {
# Single-file auto naming (<filename>.<algo>)
$currentOutFile = "$($item.FullName).$($Algorithm.ToLower())"
$null = New-Item -Path$currentOutFile -ItemType File -Force
Add-Content -Path $currentOutFile -Value$outputLine
}
Write-Output $outputLine
}
}
}
# Standard fallback if no -o was invoked: Stream perfectly to console
else {
foreach ($item in $allItems) {$hash = (Get-FileHash -Path $item.FullName -Algorithm$Algorithm).Hash.ToLower()
$relativePath = Resolve-Path -Path$item.FullName -Relative
if ($relativePath.StartsWith(".\")) {
$relativePath =$relativePath.Substring(2)
}
$outputLine = "$hash$relativePath"
Write-Output $outputLine
}
}
}
}
end {}