Verify Files with sha224sum

sha224sum writes a SHA-224 digest for a file, then a later check tells you whether the bytes still match. The examples use GNU coreutils 9.4, the version installed on the reference system.

1. Check the installed command

Confirm that your shell will run the GNU utility described here:

$ sha224sum --version
sha224sum (GNU coreutils) 9.4

Your version may differ. The core workflow is stable, but keep the local help and manpage beside scripts that depend on less common options. SHA-224 produces a 224-bit digest, displayed as 56 hexadecimal characters.

Checkpoint: If sha224sum is not found, stop and install the package through your normal distribution process. Do not copy a checksum binary from an untrusted download.

2. Calculate a digest without changing the file

Replace /path/to/important-file with a real readable path:

$ sha224sum /path/to/important-file
daf94d95cc268c8155076850c8ff30304408f3284888d2c5d41ff7e6  /path/to/important-file

The exact digest depends on the file. The final field is the file name. With no file argument, or with -, the command reads standard input:

$ printf '%s\n' 'alpha' 'beta' | sha224sum
daf94d95cc268c8155070c8ff30304408f3284888d2c5d41ff7e6  -

Input must be exact. A changed byte, line ending or trailing newline changes the digest. Quote paths containing spaces or shell metacharacters. The command reads its input; it does not rewrite it.

3. Save a verification record

Run the calculation once and redirect standard output to a new checksum file:

$ sha224sum /path/to/important-file > /path/to/important-file.sha224
$ cat /path/to/important-file.sha224
daf94d95cc268c8155070c8ff30304408f3284888d2c5d41ff7e6  /path/to/important-file

Shell redirection truncates an existing destination before sha224sum starts. That is a destructive overwrite. Pick a new name, or preserve the old record first:

$ cp --preserve=all /path/to/important-file.sha224 /path/to/important-file.sha224.bak
$ sha224sum /path/to/important-file > /path/to/important-file.sha224.new
$ mv /path/to/important-file.sha224.new /path/to/important-file.sha224

The last command replaces the old record only after the new calculation succeeds. If the calculation fails, leave the original record in place and inspect the error. Remove the backup only after you have checked the new record; deletion is irreversible.

4. Verify the file later

Ask --check to read the record and recalculate the named file:

$ sha224sum --check /path/to/important-file.sha224
/path/to/important-file: OK

An OK result means the current bytes match the recorded digest. It does not establish that the record itself came from a trusted source. Keep the checksum record separate from the file when you need an independent comparison.

For a script or quiet health check, use --status. It prints nothing, so inspect the exit status:

$ sha224sum --status /path/to/important-file.sha224
$ printf 'status=%s\n' "$?"
status=0

Do not treat empty output from --status as a failure. Status zero means every checked file matched; a non-zero status means the check failed or the checksum input was not usable.

5. Test a mismatch safely

Do not edit an important file merely to test an alert. Make a disposable copy, create its record, then alter the copy:

$ cp /path/to/important-file /tmp/important-file.test
$ sha224sum /tmp/important-file.test > /tmp/important-file.test.sha224
$ printf '%s\n' 'test change' >> /tmp/important-file.test
$ sha224sum --check /tmp/important-file.test.sha224
/tmp/important-file.test: FAILED
sha224sum: WARNING: 1 computed checksum did NOT match

The warning and exit status are the useful signals. Restore the disposable copy by removing both files when you have finished testing. Never use a broad recursive deletion command for cleanup; name only the temporary paths you created.

6. Avoid mode and filename traps

Options such as --quiet, --ignore-missing, --strict and --warn only matter when checking records. Read their local help before adding them to automation.

Done means