Skip to content

Let a disc prove it is still what you burned - #104

Merged
lazardjokovic merged 1 commit into
mainfrom
feature/checksum-manifest
Oct 2, 2026
Merged

lazardjokovic merged 1 commit into
mainfrom
feature/checksum-manifest

Conversation

@lazardjokovic

Copy link
Copy Markdown
Owner

Closes item 2 of #98.

to be able to restore it back to it's original bin / exe structure, matching the original hash values

The structure half already worked

Before writing anything I measured whether a disc restores identically, because that decided what the feature needed to be:

Disc Files recovered with names intact Bytes identical
UDF only 5 of 5 yes
With ISO9660 and Joliet for Windows XP 5 of 5 yes

That included a 112-character filename, longer than Joliet's limit, which survives because IMAPI writes long names into the ISO9660 tree and 7-Zip reads the UDF one. So nothing was broken. What was missing was any way to prove it, which is the one thing a disc cannot tell you about itself.

What the disc gains

A third checkbox on the row that already offers Linux naming and XP readability:

Also make the disc:  [ ] named on Linux  [ ] readable on Windows XP and older  [ ] checksummed

It writes checksums.sha256 at the disc root, one line per file:

# DiscWright checksum list for HOLLOW KNIGHT
# 7 files, SHA-256, sha256sum format.
#
# To check a copy, from the folder holding these files:
#   sha256sum -c checksums.sha256
...
39a9971a976312384611cd72148998f216266bcedac9805a53622171799ac06c *setup_hollow_knight_(64bit).exe

Nothing from DiscWright is needed to read it, which rather matters for a file whose whole job is to still be useful in twenty years. sha256sum -c checks it directly, and for a Windows machine with nothing installed the header prints a PowerShell loop that does the same thing.

It covers the menu and the icon as well as the games, so a disc verifies whole and a game restored out of it still has its own lines to check against.

Two things only the real tools showed

CRLF silently broke the format

The first version used CRLF like every other file DiscWright writes. sha256sum -c takes the carriage return as part of the filename:

sha256sum: 'AUTORUN/menu.hta'$'\r': No such file or directory
AUTORUN/menu.hta: FAILED open or read

Every line reported as a missing file. It writes LF now, and a test pins it. Reading the output would never have shown this; running the checker did.

The instructions in the header are tested, not assumed

The file prints a PowerShell loop for machines without coreutils. That loop was run exactly as printed, including against a file corrupted by one byte:

OK    AUTORUN/menu.hta
FAIL  Extras/manual.pdf
OK    setup_game_(64bit)_(89718).exe

Shipping verification instructions that do not work would be worse than shipping none.

Cost, measured

About 204 MB/s on this machine, one pass over the data:

Medium Full disc
CD ~3 s
DVD ~23 s
DVD-9 ~42 s
Blu-ray 25 GB ~2 min
Blu-ray 100 GB ~8 min

It cannot be folded into the staging copy to make it free: when source and output share a volume the build hard-links its files and never reads them.

Off by default, like the two beside it, on the principle already written into this file: what every disc carries is not a decision to make on somebody's behalf.

Tests

  • the hash matches what Get-FileHash computes, rather than agreeing with the code that wrote it
  • sha256sum -c accepts the file, checked with the real tool
  • lines end with a newline alone, the thing that broke the format
  • a file changed by one byte is caught
  • a real disc built with the box ticked carries it, and one built without does not
  • every file on the built disc is listed, and the hashes match what is sitting there
  • the name is reserved, so extra content cannot overwrite it
  • the answer survives saving and reopening a project, and an older project reads back as off
Suite Result Where it ran
Logic 702 passed, 0 failed, 0 skipped my machine, via tests\Invoke-Tests.ps1
Window 112 passed, 0 failed the Windows test VM, not the desktop

The window suite matters here because the row gained a control and the icon preview moved to make room; the layout test that checks for overlapping controls passes.

Project schema goes to 11. Absent in anything older, which reads back as off, so reopening an old project and rebuilding produces the disc it produced before.

🤖 Generated with Claude Code

Asked for as being able to restore a disc back to its original bin and
exe structure, matching the original hash values.

The structure half already worked. A disc built here, extracted again,
comes back byte for byte with its names intact, under both filesystem
options, including a 112-character name. That was measured before any
of this was written, because it decided what the feature had to be.
What was missing was any way to prove it, which is the one thing a
disc cannot tell you about itself.

A third checkbox on the row that already offers Linux naming and XP
readability writes checksums.sha256 at the disc root: one line per
file, SHA-256, in the format sha256sum uses, so nothing from
DiscWright is needed to read it. That matters for a file whose whole
job is to still be useful in twenty years. The header carries a
PowerShell loop that does the same job on a machine with nothing
installed, and that loop was run as printed, against a file corrupted
by one byte, rather than written and assumed.

Lines end with a newline alone, unlike every other file this writes.
sha256sum -c takes a carriage return as part of the filename and
reports every line as a missing file. A test pins it, because only the
real tool showed it.

Off by default, like the two beside it, on the principle already
written down here: what every disc carries is not a decision to make
on somebody's behalf. The cost is one pass over the data, about three
seconds for a CD and eight minutes for a filled Blu-ray, and it cannot
be folded into the staging copy because a same-volume build hard-links
its files and never reads them.

It covers the menu and the icon as well as the games, so a disc
verifies whole and a game restored out of it still has its own lines.

Project schema goes to 11. Absent in anything older, which reads back
as off, so reopening an old project and rebuilding produces the disc
it produced before.

Refs #98.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@lazardjokovic
lazardjokovic merged commit 5cfa27e into main Oct 2, 2026
3 checks passed
@lazardjokovic
lazardjokovic deleted the feature/checksum-manifest branch October 2, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant