Expand description
MP3.
The third tranche of Phase 2’s fourth group (ADR-0037), and the one format in this project that is not a container at all. There is no header describing the file, no index, no chunk list: an MP3 is a run of self-describing MPEG audio frames, and every piece of metadata it carries was glued to one end or the other by a tagger. An ID3v2 tag at the head; ID3v1, APE, and Lyrics3 at the tail; frames in between (ADR-0040 — required reading before touching this handler).
§Edited by deletion at both ends, never re-encoded
The tags are dropped whole and the frames are copied verbatim, so a file with no tags comes back byte-identical — GIF’s, JPEG XL’s, FLAC’s and WAV’s property. Nothing here decodes audio and nothing rewrites a field: unlike every other format strypt handles, an MP3 has no length, offset, or flag anywhere that removal could invalidate, because nothing in it points at anything else.
§The output is what is left, not what was kept
There is no allow-list here because there is nothing to allow-list: the frames are the payload
and everything that is not a frame goes. That makes the boundary the whole of the safety
argument, which is why [super::tags] refuses a tag length rather than clamping it, and why
this module demands a real frame header where the tags stop (§2.4.2.3 of ISO/IEC 11172-3). A
tag that lied about its length would otherwise take audio with it, or leave metadata behind as
“audio”.
§What stays, and it is measured rather than assumed
A VBR header — Xing, Info, or VBRI — is a real MPEG frame that decoders decode as silence,
and the LAME extension inside it names the encoder and its settings. It is a software
fingerprint, it stays, and the report says so: it is inside the encoded stream, which
ADR-0037 commits this group to never entering, and removing it would break VBR seeking and
gapless playback. mat2 leaves it too (docs/THREAT_MODEL.md §7.15).
Structs§
- Mp3Handler
- Removal of metadata from MP3 audio.