CheckSignatures calculates sha1 signatures for files in rootDir and compare them with signatures found at "sha1sum.txt" in the same directory. It'll return an error if one of the signatures don't match
(rootDir string)
Source from the content-addressed store, hash-verified