pub trait MetadataHandler: Send + Sync {
// Required methods
fn name(&self) -> &'static str;
fn format(&self) -> Format;
fn inspect(
&self,
input: &[u8],
options: &InspectOptions,
) -> Result<MetadataReport>;
fn strip(&self, input: &[u8], options: &StripOptions) -> Result<Stripped>;
}Expand description
Detection, reporting, and removal for one file format.
Implementations sit directly on attacker-controlled bytes and must uphold the invariants
in docs/ARCHITECTURE.md §3: inspect never mutates, nothing panics, failure is total
rather than partial, resources are bounded, the payload is preserved, and anything strip
claims to remove is something inspect can detect — without which the verification pass
would be checking nothing.
Required Methods§
Sourcefn name(&self) -> &'static str
fn name(&self) -> &'static str
Stable identifier, matching Format::id.
Sourcefn inspect(
&self,
input: &[u8],
options: &InspectOptions,
) -> Result<MetadataReport>
fn inspect( &self, input: &[u8], options: &InspectOptions, ) -> Result<MetadataReport>
Report what metadata the file contains, without modifying anything.
An unparseable region is a crate::report::Note, not necessarily an error: a file
strypt only partly understands is still worth telling the user about, provided the
report says plainly which part was not understood.
§Errors
Returns an error when the file’s structure is unusable, or when a parse ceiling is hit.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".