1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
//! Detection and removal of hidden identifying metadata from files.
//!
//! # Status
//!
//! **Phase 1 complete (2026-08-22); Phase 2 complete (2026-09-05); Phase 3 — hardening — open
//! since 2026-09-05 with nothing delivered yet.** JPEG, PNG, WebP, PDF, TIFF,
//! GIF, HEIF, AVIF, SVG, JPEG XL, FLAC, WAV, MP3, Ogg, MP4, M4A, Office Open XML, and
//! `OpenDocument` are handled, each with its own fuzz target and seed corpus, and each standing on
//! a clean sustained fuzz run. A format with no handler is reported as unsupported and is never
//! passed through untouched.
//!
//! What is *not* claimed: no tool guarantees total metadata removal, and the recorded
//! per-format limitations in `docs/THREAT_MODEL.md` are real. Read them before relying on this.
//!
//! # Invariants
//!
//! These are project invariants, not style preferences. Each has an ADR in
//! `docs/DECISIONS.md`, and code violating them should not be merged:
//!
//! - **No network access, ever, in any code path.** No dependency that opens a socket may
//! appear in this crate's tree, including transitively. (ADR-0004)
//! - **No `unsafe`.** Enforced by `unsafe_code = "forbid"` at the workspace level. (ADR-0007)
//! - **No panics on untrusted input.** Every failure is a typed `Result`. Malformed input is
//! *expected* input, not an exceptional condition. (ADR-0006)
//! - **No CLI concerns.** This crate returns structured data; it never formats output for
//! humans, reads argv, prints, or exits. Front-ends render. (ADR-0003)
//! - **Fail closed.** Never emit partially-sanitised output, and never report success for a
//! file that was not actually processed.
// Behind a non-default feature, and not part of the public API: it exists so the ZIP container
// layer can be fuzzed directly, which ADR-0028 requires and which reaching it only through the
// OOXML handler would not achieve.
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
pub use ;
/// The crate version, for front-ends to report.
pub const