Expand description
Detection and removal of hidden identifying metadata from files.
§Status
Phase 1 — in progress. Format detection, the report types, and the typed error set exist, along with the PDF and JPEG handlers. PNG and WebP are still to land, each with its own fuzz target and seed corpus (scope locked by ADR-0005). A format with no handler is reported as unsupported and is never passed through untouched.
§Invariants
These are project invariants, not style preferences. Each has an ADR in
docs/DECISIONS.md, and code violating them should not be merged:
- No network access, ever, in any code path. No dependency that opens a socket may appear in this crate’s tree, including transitively. (ADR-0004)
- No
unsafe. Enforced byunsafe_code = "forbid"at the workspace level. (ADR-0007) - No panics on untrusted input. Every failure is a typed
Result. Malformed input is expected input, not an exceptional condition. (ADR-0006) - No CLI concerns. This crate returns structured data; it never formats output for humans, reads argv, prints, or exits. Front-ends render. (ADR-0003)
- Fail closed. Never emit partially-sanitised output, and never report success for a file that was not actually processed.
Re-exports§
pub use detect::Format;pub use detect::detect;pub use error::IoAction;pub use error::MalformedDetail;pub use error::ResourceLimit;pub use error::Result;pub use error::StryptError;pub use error::UnsupportedKind;pub use formats::MetadataHandler;pub use formats::ParseLimits;pub use formats::StripOptions;pub use formats::Stripped;pub use io::AtomicWrite;pub use io::Limits;pub use io::Overwrite;pub use io::Permissions;pub use pipeline::inspect_bytes;pub use pipeline::inspect_file;pub use pipeline::strip_bytes;pub use pipeline::strip_file;pub use report::Finding;pub use report::InspectOptions;pub use report::MetadataKind;pub use report::MetadataReport;pub use report::MetadataValue;pub use report::Note;pub use report::Retained;pub use report::RetentionReason;pub use report::Sensitivity;pub use report::StripReport;
Modules§
- detect
- Format detection by content sniffing.
- error
- Typed errors.
- formats
- Format handlers.
- io
- Bounded reading and atomic writing.
- panic_
guard - Containment for panics raised inside third-party parsers.
- pipeline
- The end-to-end operations front-ends call.
- registry
- Dispatch from a detected format to its handler.
- report
- Structured results.
Functions§
- version
- The crate version, for front-ends to report.