Skip to main content

MetadataHandler

Trait MetadataHandler 

Source
pub trait MetadataHandler: Send + Sync {
    // Required methods
    fn name(&self) -> &'static str;
    fn format(&self) -> Format;
    fn inspect(
        &self,
        input: &[u8],
        options: &InspectOptions,
    ) -> Result<MetadataReport>;
    fn strip(&self, input: &[u8], options: &StripOptions) -> Result<Stripped>;
}
Expand description

Detection, reporting, and removal for one file format.

Implementations sit directly on attacker-controlled bytes and must uphold the invariants in docs/ARCHITECTURE.md §3: inspect never mutates, nothing panics, failure is total rather than partial, resources are bounded, the payload is preserved, and anything strip claims to remove is something inspect can detect — without which the verification pass would be checking nothing.

Required Methods§

Source

fn name(&self) -> &'static str

Stable identifier, matching Format::id.

Source

fn format(&self) -> Format

The format this handler is responsible for.

Source

fn inspect( &self, input: &[u8], options: &InspectOptions, ) -> Result<MetadataReport>

Report what metadata the file contains, without modifying anything.

An unparseable region is a crate::report::Note, not necessarily an error: a file strypt only partly understands is still worth telling the user about, provided the report says plainly which part was not understood.

§Errors

Returns an error when the file’s structure is unusable, or when a parse ceiling is hit.

Source

fn strip(&self, input: &[u8], options: &StripOptions) -> Result<Stripped>

Produce a sanitised copy.

§Errors

Returns an error rather than partially-sanitised bytes. There is no half-success.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§