1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
[]
= "strypt-core"
= "Detection and removal of hidden identifying metadata from files"
= true
= true
= true
= true
= true
= true
= true
= true
= ["parser-implementations", "multimedia::images"]
# The integration tests read fixtures from `corpus/`, which lives at the workspace root and is
# therefore not packageable. Shipping tests that cannot run would be worse than shipping none.
= ["tests/"]
[]
# Not enabled by default and never by a front-end. Opens a hidden door to the internal ZIP
# parser so it can be fuzzed on its own, per ADR-0028. See `src/fuzzing.rs`.
= []
[]
# Typed errors. `anyhow` must never appear here: callers have to distinguish "unsupported
# format" from "corrupt file" from "I/O error", and a boxed error erases exactly that
# (ADR-0008, ADR-0018).
= { = true }
# PDF object model. See ADR-0018 for the evaluation against `oxidize-pdf` and for the
# honest accounting of what this dependency costs in transitive surface.
= { = true }
# The ZIP container layer's decompressor and checksum (ADR-0028). Both were already in the
# resolved graph transitively; declaring them makes what strypt actually calls visible in the
# manifest, which is what ADR-0008 asks for.
= { = true }
= { = true }
[]
# The OOXML integration tests read strypt's own output back with a second, independent ZIP
# reader written in the test file (`tests/ooxml.rs`). Verifying the output with the code that
# produced it would only prove the parser agrees with itself. `flate2` is already a dependency
# of this crate (ADR-0028), so this adds nothing to the tree.
= { = true }
# Lints are specified explicitly here rather than inherited, because Cargo does not permit a
# crate to both inherit `workspace.lints` and override them. The workspace set is repeated
# below, plus the panic-freedom lints that apply to this crate only.
[]
= "forbid"
= "warn"
# Panic-freedom in the parsing path (ADR-0006). These are denied here and NOT in strypt-cli,
# because the boundary that matters is "code reachable from untrusted bytes". Scope any
# necessary exception to the specific site with a comment explaining why it cannot be
# reached by hostile input — never blanket-allow at crate level, which defeats the purpose.
[]
= { = "deny", = -1 }
= { = "warn", = -1 }
= "deny"
= "deny"
= "deny"
= "deny"
= "deny"
= "deny"
= "deny"