pub fn strip_bytes(data: &[u8], options: &StripOptions) -> Result<Stripped>Expand description
Produce a sanitised copy of data in memory, verified before it is returned.
The output is re-inspected here, and metadata that survived the strip fails the whole
operation. That check is the reason this function exists rather than callers using a
handler directly: it converts an entire class of handler bug — one that removes less than
it reports — from a silent leak into a loud refusal (docs/ARCHITECTURE.md §1 stage 5).
What it cannot do is find metadata the inspector does not know to look for. It makes the
tool internally consistent, not omniscient, and docs/THREAT_MODEL.md §4.8 says so to
users in those words.
§Errors
StryptError::VerificationFailed if anything survived; otherwise the handler’s errors.