Verify a review packet
A review packet lists every file it covered with a SHA-256. Drop the packet and the files, and see whether what you hold is what was reviewed.
Your content never leaves the browser.
1Packet or manifest
No packet loaded.
2Source files
No files loaded.
How the check works
Read the file list
Every packet has a Files section: one row per file with its label, byte size, line count and SHA-256. A manifest JSON carries the same rows.
Hash the files again
Each file you drop is read as UTF-8 text and hashed in this tab with Web Crypto, the same way the workbench hashed it.
Compare row by row
Every listed file gets one result. Files you dropped that the packet does not list are named underneath.
Results
| Result | Meaning | What to do |
|---|---|---|
| Match | MeaningThe file hashes to the value in the manifest. | What to doNothing. The review covered this exact file. |
| Matches after line-ending normalisation | MeaningThe content is the same; one side has CRLF line endings and the other LF. | What to doNothing to fix in the code. Check out with the same line endings if you need the raw hash to agree. |
| Mismatch | MeaningA file with that name was supplied and its content differs. | What to doCheck out the commit the review was run on, or run the review again on the current file. |
| Missing | MeaningNo supplied file has that name or that hash. | What to doDrop the missing file, or the folder that holds it. |
Why line endings get their own result
Git on Windows checks files out with CRLF line endings when core.autocrlf is on. The same commit then hashes to a different value on two machines, and a plain comparison calls it a mismatch.
The verifier hashes each file three ways: as supplied, with CRLF replaced by LF, and with LF replaced by CRLF. A file that only matches after the swap is reported on its own line, with the direction, so a line-ending difference is never mistaken for a changed file.
Check one hash by hand
The hash in a packet is a plain SHA-256 of the file. Any tool gives the same value.
# Linux
sha256sum src/Vault.sol
# macOS
shasum -a 256 src/Vault.sol
# Windows PowerShell
Get-FileHash -Algorithm SHA256 src\Vault.sol
Questions
Are my files uploaded?
No. The page reads each file with the browser’s file API and hashes it with Web Crypto. It makes no request with a file name, a hash or any content. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it.
What does a match prove?
That the bytes you hold are the bytes the review was run on, to the last character. It is a statement about the files. Whether the review’s conclusions hold is a separate question, answered by the code and the proof.
Where does a packet come from?
The workbench writes one for every finished review: the verdict, the context you gave, the file list with a SHA-256 per file, and the review itself. A manifest is the same file list as JSON, as returned by the review API and the MCP server.
No packet yet
Run a review in the workbench. The packet it saves carries the verdict, the evidence you gave and the hash of every file, ready to attach to a submission.