# sha256 of every committed file that ends up in front of a visitor.
#
# Generated by build/update-checksums.sh, which is the only thing that writes
# it. No build and no hook ever rewrites this file: one that a build could
# refresh would bless whatever it found, and an unexpected change here is
# supposed to stop somebody rather than be tidied away. Regenerating is a
# command a person runs, and the diff is the evidence they meant it.
#
# Everything fetched is already content-addressed where it is fetched: the wallet
# and its Python dependencies by build/build-wallet-zip.sh, the Pyodide runtime
# by build/fetch-assets.sh. This file is the other half, the files that live in
# the repository and are served or packaged as they are. Without it "you can read
# all of it" is a claim about a moving target; with it, a change to any of them
# is a line in a diff that somebody had to write on purpose.
#
# Check them from the repository root with any of:
#
#     sha256sum -c build/checksums.txt          # the hashes below
#     ./build/fetch-assets.sh --check           # and that nothing is missing from them
#     ./build/update-checksums.sh --check       # and that this file is what it would be
#
# When a change to one of these files is deliberate, regenerate this file in the
# same commit as the change:
#
#     ./build/update-checksums.sh
#
# Both directions are checked, because they are the same mistake: a file that
# changed and a file that was added and listed nowhere both reach a visitor
# unannounced. build/build-wallet-zip.sh asks both questions of the packaged
# directories below before it stages either into a zip, and refuses to package a
# file that is not listed here at all.

# Served as they stand. src/web is the page, its scripts and its icons; src/shims
# is the Python the page fetches at boot and writes into Pyodide's filesystem,
# including the shim that hands back a decoded QR payload. Verifying a wallet zip
# says nothing about any of them, and they are the code that decides what the
# wallet is shown.
#
# jsQR 1.4.0, Apache-2.0, is the file published as dist/jsQR.js in the npm
# package jsqr@1.4.0, unmodified. To confirm that independently, and not just
# that it matches the src/web/jsQR.js line below:
#
#     curl -sL https://registry.npmjs.org/jsqr/-/jsqr-1.4.0.tgz | tar xzO package/dist/jsQR.js | sha256sum

a7b7fa32b1d3da4ac565bc691ebcae2c7bf47c3d239df6e2709ad079527bf565  src/shims/browser_camera.py
b165ba562b357879fc9b0b478dca9589bb05e4cb4d6f456e93694dc29a16a966  src/shims/browser_display.py
dd33f4aba83577f8fb7866d2f84972aac1b167fd1f523b8035969373c91c9c10  src/shims/browser_hd.py
2e1b0500e002f33684e9187a9c3d2752f526ce6e78f0e02feea238e92c0dee5b  src/shims/browser_qr.py
52ade09ad344a558d0ecb38f8cd1232a1caf8bce55048401b28c089583717009  src/shims/browser_touch.py
0243ccf633097906b763839cd4b2d9f92fccd042bac1fd11ee7be60f31e78687  src/web/apple-touch-icon.png
0493f209d15abeb168ca8c8b705247f9fe4616e34c8dfee0925ae75f3d1c0635  src/web/doom-boot.js
1ebb8267bb112587c9739a7f30fd9197c3e0137a0fcd4677f6a8677b6fa307f5  src/web/icon-192.png
2c740b578143c67bbca1f950c33fe62d2a06fd22d5c0a7adf58348dc648e09bf  src/web/icon-512.png
6cd07baa5239a1ab031a811b0ed9d0da47c159c79f626583de466b428038004e  src/web/index.html
fc3651512dcb372f3c417da35407ce1cbe32479b7467543e8163cd2466465266  src/web/jikkey-card-photo.png
605dfba849b63cc639556f0190e316408bff921523fe389ceb608edc6f5110e7  src/web/jikkey-i18n.js
332bee8eaed568d8b950c42056cd0f7f0addfcec09cb217811ada743ee257cc6  src/web/jikkey-logo.png
c8f97ed75e4b51bae3ce24259802164af8cc878ffd1f52ec0155573f8f590080  src/web/jikkey-logo.svg
292c783acb0e91675aa43c6cad221bca66c86b858e10c08b143c020e426d8a99  src/web/jikkey-suede-bright.png
fbb9f16f8aa6307606dc5e98c756c05a7490049289f2d2658bd063ee92ed9f27  src/web/jikkey-suede.svg
6f89d3a97c4a5c81273863f1558679fd6b98906e6cde577f00a2b8ac85b5df3a  src/web/jikkey-theme.css
bc40c8a15196236b2314db0856f72ca0b49980cd5413b8c852a7349f5fee0859  src/web/jsQR.js
38f848ed6ad5c56b1d5bdd3b73498dba9c0b9e56b0d22afb9415b9f9cb3dc618  src/web/manifest.json
75d7bbeb31dfd951e2d2dcd768f0c42e54faaf10d4fd23f1fa4c50e99abbdc10  src/web/qr-encode.js
db254ff250af0d3afef5d746f69aaa19bfeac64d7158cbcfc86937573d7e9aaa  src/web/seedsigner-device.js
ebdba8ffca304f3637c6633d84a460f1887516a752ca7b8a80cecc7d6c5a4a08  src/web/signet-coordinator.js
a19eabc9ae72b414b4d7dcc38d2b035cc818b81e8e7dfc3fb09a4d7fce8c3ca7  src/web/sw.js
7b4b618d5bf889defaf7fcbdf962c43b9ad3b34ce7c5537d4a1200269ce62127  src/web/ur-decode.js
84390fe70e248b64dc088bc94436709e4a9c9cc435a4990822939d2f3873045e  src/web/wallet-camera.js
e832c8795b3fe082f8420509902847ad5ecd31a11334007db8bec2bad97038e8  src/web/wallet-cards.js
7f5142f956927707d5e282447a1ca7df8b71b0a702176f0a6a9c25f8a0f39807  src/web/wallet-coordinator.js
e4584eb2db70e77da71d5e33a2859173bf24fd0c6104f14f322a61b0464459c3  src/web/wallet-isolation.js
c5ec241be3e6bebb8bf7bda5734b08a91d93dfb75ac3f18794d00f6f259ae933  src/web/wallet-touch.js
ebee89297750a166d7374a704abc9c3e9ef60403b4514c6e26fa0911862e3523  src/web/wallet-track.js
d06e33018e9211ceccc97da162d3dbe06878bdc8dd63ff05b8fe73439f886921  src/web/wallet-tutorial.js
8157055fe5f076760971a6e1a87a474c1f1ffbaa8943d593897b6e5a6da9875a  src/web/wallet-worker.js
be388f901b20de73fc3404eb1f66d32f3aafc8855fed526b63370ca5f1efb3a4  src/web/wallet.html

# The stand-in packages, which build/build-wallet-zip.sh copies out of the working
# tree and into a wallet zip whole. Every other input to that zip is pinned by a
# commit sha or an artifact sha256, so these were the one way its bytes could move
# without anything saying so: edit the simulated card, get a different zip, and
# the only evidence was the hash it no longer matched. Both directories in full,
# not just the files that happen to be staged, because a file added to one of them
# lands in the zip too.

0ed612d6aa1b9e48593fa195a41df9470b81375ea8d5bb135466a1fc0e390a53  src/fakes/README.md
75b3b90df8552bb53df7d7e424483b2c79ceb3bd38f971a2ada2f136780ca9ae  src/fakes/RPi/GPIO.py
38b94626c551a058fb31654e0bf3f425c29aaed19a76fb89ffb161c51ae03c8e  src/fakes/RPi/__init__.py
eb888cf20bca98fd12ea8585357a0bcfc161c00d14496a31f53411784ee3cb88  src/fakes/pyzbar/__init__.py
f5ba36b26dfdfe8a67fae80f6194cad107a71734d891d6213977af5ffc75369c  src/fakes/pyzbar/pyzbar.py
5d9307b2e463c9a3911db9cd071709d00cd3dd6965fa48077cbcafdef9edb177  src/smartcard/CardConnectionObserver.py
1a08f3f4de8b5f35cfdc920445a58fe5685edf302f440aefdb634b215d519059  src/smartcard/CardMonitoring.py
9e40ac4e858b5c4183b74e95b414597714b59872765cf7620f8b4c465fda7985  src/smartcard/CardRequest.py
3f09616591e0c4d0a722251b89a02ffad2c500a4283a7f5acd737d8df008a5bf  src/smartcard/CardType.py
b35e337248b6467bd4da3b3ab17a87bf5c01b45363a1027302838e801ae1d6e0  src/smartcard/Exceptions.py
c96aecaab78ee04ce687e97368638c5030124df143a420491d1baadbeccaf182  src/smartcard/System.py
c6074f00c409fdfb352de57aba1cc9ee07288ad41bcb8cacc72227a32b8bd5db  src/smartcard/__init__.py
99a4a391f1ecc3da5f0ae55e354cf02a1519ea2cbd2652a1a834f48b741500e3  src/smartcard/simulated_card.py
d90db283c8febb151f4031007ecaff3a01e4c42dab51e27ca6f7b63e5d882ec5  src/smartcard/sw/SWExceptions.py
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855  src/smartcard/sw/__init__.py
76c5c4752c0784b1491c021730145d7b3611847aaf65281c2fc8c297e9e6b00c  src/smartcard/util.py
