Expand description
Detection and removal of hidden identifying metadata from files.
§Status
Phase 1 complete (2026-08-22); Phase 2 complete (2026-09-05); Phase 3 — hardening — open
since 2026-09-05 with nothing delivered yet. JPEG, PNG, WebP, PDF, TIFF,
GIF, HEIF, AVIF, SVG, JPEG XL, FLAC, WAV, MP3, Ogg, MP4, M4A, Office Open XML, and
OpenDocument are handled, each with its own fuzz target and seed corpus, and each standing on
a clean sustained fuzz run. A format with no handler is reported as unsupported and is never
passed through untouched.
What is not claimed: no tool guarantees total metadata removal, and the recorded
per-format limitations in docs/THREAT_MODEL.md are real. Read them before relying on this.
§Invariants
These are project invariants, not style preferences. Each has an ADR in
docs/DECISIONS.md, and code violating them should not be merged:
- No network access, ever, in any code path. No dependency that opens a socket may appear in this crate’s tree, including transitively. (ADR-0004)
- No
unsafe. Enforced byunsafe_code = "forbid"at the workspace level. (ADR-0007) - No panics on untrusted input. Every failure is a typed
Result. Malformed input is expected input, not an exceptional condition. (ADR-0006) - No CLI concerns. This crate returns structured data; it never formats output for humans, reads argv, prints, or exits. Front-ends render. (ADR-0003)
- Fail closed. Never emit partially-sanitised output, and never report success for a file that was not actually processed.
Re-exports§
pub use detect::Format;pub use detect::detect;pub use error::IoAction;pub use error::MalformedDetail;pub use error::ResourceLimit;pub use error::Result;pub use error::StryptError;pub use error::UnsupportedKind;pub use formats::MetadataHandler;pub use formats::ParseLimits;pub use formats::StripOptions;pub use formats::Stripped;pub use io::AtomicWrite;pub use io::Limits;pub use io::Overwrite;pub use io::Permissions;pub use io::stripped_path;pub use pipeline::inspect_bytes;pub use pipeline::inspect_file;pub use pipeline::strip_bytes;pub use pipeline::strip_bytes_to_file;pub use pipeline::strip_file;pub use report::Finding;pub use report::InspectOptions;pub use report::MetadataKind;pub use report::MetadataReport;pub use report::MetadataValue;pub use report::Note;pub use report::Retained;pub use report::RetentionReason;pub use report::Sensitivity;pub use report::StripReport;pub use walk::Skip;pub use walk::Skipped;pub use walk::Walk;pub use walk::walk;
Modules§
- detect
- Format detection by content sniffing.
- error
- Typed errors.
- formats
- Format handlers.
- io
- Bounded reading and atomic writing.
- panic_
guard - Containment for panics raised inside third-party parsers.
- pipeline
- The end-to-end operations front-ends call.
- registry
- Dispatch from a detected format to its handler.
- report
- Structured results.
- walk
- Expanding a folder into the files a batch processes, shared so every front-end descends alike.
Functions§
- version
- The crate version, for front-ends to report.