Home / Alt manpages / sum(1)

  • sum(1)
  • User command
  • linux

Use sum to Compare File Checksums and Block Counts

You will calculate the checksum and block count for one or more files, choose between the default BSD algorithm and the System V variant, and make a comparison that does not accidentally mix their output formats. Allow about ten minutes if the files are already on the machine. You need a shell and GNU coreutils; ordinary files in your working area do not need elevated privileges.

1. Check the installed command

This guide describes GNU coreutils sum 9.4, installed here as package coreutils version 9.4-3ubuntu6.3. Check your own binary before putting its output into a script, because another implementation or release may differ.

$ command -v sum
/usr/bin/sum
$ sum --version | head -n 1
sum (GNU coreutils) 9.4

The local manual page calls sum a checksum and block-counting utility. It accepts zero or more file names. With no file name, or with -, it reads standard input.

Checkpoint

If command -v sum finds nothing, install or enable the package through your normal distribution process. Do not add sudo to an otherwise ordinary checksum command.

2. Calculate the default BSD result

Run sum with a file path to get the default result:

$ sum /path/to/archive.tar
08288     1 /path/to/archive.tar

The first field is a 16-bit BSD checksum. The second is the number of 1 KiB blocks used by the file, rounded up for a partial final block. The file name is printed so that output for several inputs can be distinguished.

For a quick reproducible test, make a small file in a temporary directory and calculate it:

$ printf 'abc\n' > /tmp/sum-example.txt
$ sum /tmp/sum-example.txt
08288     1 /tmp/sum-example.txt

Shell redirection creates or replaces /tmp/sum-example.txt. That is harmless for this new example name, but > truncates an existing file before sum runs. Use a destination you have checked, or use >> only when appending is genuinely intended.

3. Select the System V format when required

Use -s or its long spelling --sysv for the System V algorithm:

$ sum --sysv /tmp/sum-example.txt
304 1 /tmp/sum-example.txt
$ sum -s /tmp/sum-example.txt
304 1 /tmp/sum-example.txt

This variant uses 512-byte blocks. Its checksum is not directly comparable with the default BSD checksum, even for the same file. Agree the option, input bytes and output interpretation before comparing two results. A report that says only "the sum is 304" is incomplete without the algorithm and block size.

The checksum is a compact compatibility check, not a modern cryptographic integrity proof. Different files can produce the same 16-bit value. Use a cryptographic digest tool, such as a separately approved SHA-256 workflow, when the result must resist deliberate collisions or identify an untrusted download.

4. Read several files in one command

Pass multiple paths to produce one result per file:

$ sum /path/to/part-a /path/to/part-b
08288     1 /path/to/part-a
16500     1 /path/to/part-b

sum reads each named file independently. It does not concatenate them before calculating one combined value. Keep the algorithm consistent when comparing a set later:

$ sum -s /path/to/part-a /path/to/part-b
304 1 /path/to/part-a
12345 1 /path/to/part-b

The checksum values above are illustrative output shapes, not values to copy into a real verification record. Run the command against your actual files and save the complete line, including the algorithm choice used to create it.

5. Use standard input safely

When there is no file argument, sum waits for standard input. The terminating newline is part of the bytes being summed, so these two commands produce different inputs:

$ printf 'hello\n' | sum
36979     1
$ printf 'hello' | sum
46037     1

A pipe has no file name to print. Use - when you want to make the standard-input choice visible in a command or a log:

$ printf 'hello\n' | sum -
36979     1 -
$ printf 'hello\n' | sum --sysv -
542 1 -

Quote or otherwise control the producer command when exact bytes matter. A text editor, command substitution or line-ending conversion can change the input without making the checksum command itself fail.

6. Verify a result without overwriting anything

sum prints calculations; it does not provide a checksum-file comparison mode in this interface. To check a stored result, rerun the same command and compare its complete output with your trusted record:

$ sum --sysv /path/to/archive.tar
304 1 /path/to/archive.tar
$ printf 'sum matches only if the recorded algorithm and bytes are the same\n'
sum matches only if the recorded algorithm and bytes are the same

For a manual check, compare the printed fields and file name. Do not treat a matching checksum as proof that a file came from a particular person or was not deliberately changed. Also check that the file path names the file you meant to read, particularly in scripts that process directories containing spaces or unexpected names.

If a file cannot be opened, sum reports the error and continues to any later operands where possible. The useful recovery is to correct the path or read permission and rerun. Do not make a whole directory world-readable just to calculate a checksum. If access is genuinely restricted, ask the file owner or use the existing administrative procedure; only then consider a command such as sudo sum /path/to/protected-file.

7. Keep scripts explicit

Use the long option in a script when the algorithm matters, and write the output to a new report file only after choosing a safe destination. For example:

$ report=/tmp/archive-sum.txt
$ test ! -e "$report" || { printf 'Refusing to replace %s\n' "$report" >&2; exit 1; }
$ sum --sysv /path/to/archive.tar > "$report"
$ cat "$report"
304 1 /path/to/archive.tar

The test guard prevents this example from replacing an existing report. If the command fails before writing a complete report, inspect the file before using it as evidence. For an important record, write to a new temporary path and rename it into place only after checking the command status and contents. Do not delete an older record until the replacement has been reviewed.

Done means

  • You confirmed which sum implementation and version is installed.
  • You know whether each result used BSD with 1 KiB blocks or System V with 512-byte blocks.
  • You included the newline and other byte-producing details when standard input mattered.
  • You compared complete output lines for the intended files instead of comparing bare checksum numbers.
  • You kept in mind that a 16-bit checksum is not a cryptographic integrity guarantee.
  • You avoided overwriting source files and existing reports during testing.