strypt_core/lib.rs
1//! Detection and removal of hidden identifying metadata from files.
2//!
3//! # Status
4//!
5//! **Phase 1 complete (2026-08-22); Phase 2 complete (2026-09-05); Phase 3 — hardening — open
6//! since 2026-09-05 with nothing delivered yet.** JPEG, PNG, WebP, PDF, TIFF,
7//! GIF, HEIF, AVIF, SVG, JPEG XL, FLAC, WAV, MP3, Ogg, MP4, M4A, Office Open XML, and
8//! `OpenDocument` are handled, each with its own fuzz target and seed corpus, and each standing on
9//! a clean sustained fuzz run. A format with no handler is reported as unsupported and is never
10//! passed through untouched.
11//!
12//! What is *not* claimed: no tool guarantees total metadata removal, and the recorded
13//! per-format limitations in `docs/THREAT_MODEL.md` are real. Read them before relying on this.
14//!
15//! # Invariants
16//!
17//! These are project invariants, not style preferences. Each has an ADR in
18//! `docs/DECISIONS.md`, and code violating them should not be merged:
19//!
20//! - **No network access, ever, in any code path.** No dependency that opens a socket may
21//! appear in this crate's tree, including transitively. (ADR-0004)
22//! - **No `unsafe`.** Enforced by `unsafe_code = "forbid"` at the workspace level. (ADR-0007)
23//! - **No panics on untrusted input.** Every failure is a typed `Result`. Malformed input is
24//! *expected* input, not an exceptional condition. (ADR-0006)
25//! - **No CLI concerns.** This crate returns structured data; it never formats output for
26//! humans, reads argv, prints, or exits. Front-ends render. (ADR-0003)
27//! - **Fail closed.** Never emit partially-sanitised output, and never report success for a
28//! file that was not actually processed.
29
30mod bytes;
31mod container;
32pub mod detect;
33pub mod error;
34pub mod formats;
35// Behind a non-default feature, and not part of the public API: it exists so the ZIP container
36// layer can be fuzzed directly, which ADR-0028 requires and which reaching it only through the
37// OOXML handler would not achieve.
38#[cfg(feature = "fuzzing")]
39#[doc(hidden)]
40pub mod fuzzing;
41pub mod io;
42pub mod panic_guard;
43pub mod pipeline;
44pub mod registry;
45pub mod report;
46pub mod walk;
47
48pub use detect::{Format, detect};
49pub use error::{IoAction, MalformedDetail, ResourceLimit, Result, StryptError, UnsupportedKind};
50pub use formats::{MetadataHandler, ParseLimits, StripOptions, Stripped};
51pub use io::{AtomicWrite, Limits, Overwrite, Permissions, stripped_path};
52pub use pipeline::{inspect_bytes, inspect_file, strip_bytes, strip_bytes_to_file, strip_file};
53pub use report::{
54 Finding, InspectOptions, MetadataKind, MetadataReport, MetadataValue, Note, Retained,
55 RetentionReason, Sensitivity, StripReport,
56};
57pub use walk::{Skip, Skipped, Walk, walk};
58
59/// The crate version, for front-ends to report.
60#[must_use]
61pub const fn version() -> &'static str {
62 env!("CARGO_PKG_VERSION")
63}
64
65#[cfg(test)]
66mod tests {
67 use super::*;
68
69 #[test]
70 fn version_is_reported() {
71 assert!(!version().is_empty());
72 }
73}