partsieve

    OOXML capability audit and verified rebuild; restricted Word and spreadsheet profiles

    ooxml
    xlsx
    docx
    vba
    audit
    verified-rebuild
    Download zip
    Author
    Version
    0.2.0-spike
    License
    Apache-2.0
    Last updated
    14 hours ago
    Downloads
    5

    #zlhahaha/partsieve

    See README.md for the implemented spike, commands, limits, evidence, and unsupported features. The first prototype version is 0.1.0-spike.

    SieveError

    pub(all) suberror SieveError {
    Refused(String)
    Incomplete(String)
    Invalid(String)
    } derive(
    Debug
    )

    Assessment

    pub(all) struct Assessment {
    schema : String
    input_hash : String?
    findings : Array[CapabilityFinding]
    coverage : Coverage
    decision : Decision
    graph : PackageGraph?
    } derive(Eq, ToJson,
    Debug
    )

    Assessment::equal

    fn Assessment::equal(Assessment, Assessment) -> Bool

    Assessment::not_equal

    fn Assessment::not_equal(x : Assessment, y : Assessment) -> Bool

    Assessment::to_json

    fn Assessment::to_json(Assessment) -> Json

    Audit

    pub(all) struct Audit {
    schema : String
    input_hash : String
    format : String
    main_part : String
    coverage : String
    profile : String
    checked_rules : Array[String]
    limitations : Array[String]
    parts : Array[PartRecord]
    relationships : Array[Relationship]
    findings : Array[Finding]
    } derive(Eq, ToJson,
    Debug
    )

    Audit::equal

    fn Audit::equal(Audit, Audit) -> Bool

    Audit::not_equal

    fn Audit::not_equal(x : Audit, y : Audit) -> Bool

    Audit::to_json

    fn Audit::to_json(Audit) -> Json

    Audit::to_repr

    Capability

    pub(all) enum Capability {
    Vba
    HttpHyperlink
    RemoteTemplate
    ExternalResource
    ExternalData
    Ole
    ActiveX
    UnknownExternalRelationship
    UnknownPotentiallyActiveExtension
    } derive(Eq,
    Debug
    )

    Capability::equal

    fn Capability::equal(Capability, Capability) -> Bool

    Capability::not_equal

    fn Capability::not_equal(x : Capability, y : Capability) -> Bool

    Capability::to_json

    fn Capability::to_json(self : Capability) -> Json

    CapabilityFinding

    pub(all) struct CapabilityFinding {
    rule_id : String
    capability : Capability
    source : String
    part : String
    certainty : Certainty
    rebuild_support : RebuildSupport
    evidence : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    CapabilityFinding::equal

    CapabilityFinding::not_equal

    fn CapabilityFinding::not_equal(x : CapabilityFinding, y : CapabilityFinding) -> Bool

    CapabilityFinding::to_json

    Certainty

    pub(all) enum Certainty {
    Declared
    Uncertain
    } derive(Eq,
    Debug
    )

    Certainty::equal

    fn Certainty::equal(Certainty, Certainty) -> Bool

    Certainty::not_equal

    fn Certainty::not_equal(x : Certainty, y : Certainty) -> Bool

    Certainty::to_json

    fn Certainty::to_json(self : Certainty) -> Json

    CheckState

    pub(all) enum CheckState {
    Checked
    NotChecked
    IncompleteCheck
    Opaque
    } derive(Eq,
    Debug
    )

    CheckState::equal

    fn CheckState::equal(CheckState, CheckState) -> Bool

    CheckState::not_equal

    fn CheckState::not_equal(x : CheckState, y : CheckState) -> Bool

    CheckState::to_json

    fn CheckState::to_json(self : CheckState) -> Json

    CheckedOperation

    pub(all) struct CheckedOperation {
    operation_id : String
    kind : PlanOperationKind
    part : String
    source : String
    relationship_id : String
    rule_id : String
    decision_id : String
    before_hash : String
    expected_after_hash : String?
    depends_on : Array[String]
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    CheckedOperation::equal

    CheckedOperation::not_equal

    fn CheckedOperation::not_equal(x : CheckedOperation, y : CheckedOperation) -> Bool

    CheckedOperation::to_json

    ContentTypeIndex

    pub(all) struct ContentTypeIndex {
    content_type : String
    parts : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    ContentTypeIndex::equal

    ContentTypeIndex::not_equal

    fn ContentTypeIndex::not_equal(x : ContentTypeIndex, y : ContentTypeIndex) -> Bool

    ContentTypeIndex::to_json

    ContractDisposition

    pub(all) struct ContractDisposition {
    part : String
    classification : PreservationKind
    before_hash : String
    after_hash : String?
    decision_id : String?
    rule_id : String?
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    ContractDisposition::equal

    ContractDisposition::not_equal

    ContractDisposition::to_json

    Coverage

    pub(all) struct Coverage {
    declared_profile : String
    rules : Array[RuleCoverage]
    checked_rules : Array[String]
    unchecked_features : Array[String]
    parse_complete : Bool
    parse_error : String?
    } derive(Eq, ToJson,
    Debug
    )

    Coverage::equal

    fn Coverage::equal(Coverage, Coverage) -> Bool

    Coverage::not_equal

    fn Coverage::not_equal(x : Coverage, y : Coverage) -> Bool

    Coverage::to_json

    fn Coverage::to_json(Coverage) -> Json

    Coverage::to_repr

    Decision

    pub(all) struct Decision {
    result : ResultStatus
    rebuild_allowed : Bool
    profile : String
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    Decision::equal

    fn Decision::equal(Decision, Decision) -> Bool

    Decision::not_equal

    fn Decision::not_equal(x : Decision, y : Decision) -> Bool

    Decision::to_json

    fn Decision::to_json(Decision) -> Json

    Decision::to_repr

    Disposition

    pub(all) struct Disposition {
    part : String
    classification : String
    before_hash : String
    after_hash : String?
    } derive(Eq, ToJson,
    Debug
    )

    Disposition::equal

    fn Disposition::equal(Disposition, Disposition) -> Bool

    Disposition::not_equal

    fn Disposition::not_equal(x : Disposition, y : Disposition) -> Bool

    Disposition::to_json

    fn Disposition::to_json(Disposition) -> Json

    Finding

    pub(all) struct Finding {
    rule : String
    capability : String
    part : String
    evidence : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    Finding::equal

    fn Finding::equal(Finding, Finding) -> Bool

    Finding::not_equal

    fn Finding::not_equal(x : Finding, y : Finding) -> Bool

    Finding::to_json

    fn Finding::to_json(Finding) -> Json

    Finding::to_repr

    GraphNode

    pub(all) struct GraphNode {
    part : String
    inbound : Array[Int]
    outbound : Array[Int]
    xml_references : Array[Int]
    reachable : Bool
    } derive(Eq, ToJson,
    Debug
    )

    GraphNode::equal

    fn GraphNode::equal(GraphNode, GraphNode) -> Bool

    GraphNode::not_equal

    fn GraphNode::not_equal(x : GraphNode, y : GraphNode) -> Bool

    GraphNode::to_json

    fn GraphNode::to_json(GraphNode) -> Json

    ImplicitReference

    pub(all) struct ImplicitReference {
    source : String
    relationship_index : Int
    semantics : String
    } derive(Eq, ToJson,
    Debug
    )

    ImplicitReference::equal

    ImplicitReference::not_equal

    fn ImplicitReference::not_equal(x : ImplicitReference, y : ImplicitReference) -> Bool

    ImplicitReference::to_json

    Limits

    pub(all) struct Limits {
    input_bytes : Int
    entry_bytes : Int
    total_bytes : Int
    entries : Int
    xml_bytes : Int
    xml_depth : Int
    xml_nodes : Int
    xml_attributes : Int
    output_bytes : Int
    } derive(Eq, ToJson,
    Debug
    )

    Limits::default

    fn Limits::default() -> Limits

    Limits::equal

    fn Limits::equal(Limits, Limits) -> Bool

    Limits::not_equal

    fn Limits::not_equal(x : Limits, y : Limits) -> Bool

    Limits::to_json

    fn Limits::to_json(Limits) -> Json

    Limits::to_repr

    Operation

    pub(all) struct Operation {
    kind : String
    part : String
    relationship_id : String
    rule : String
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    Operation::equal

    fn Operation::equal(Operation, Operation) -> Bool

    Operation::not_equal

    fn Operation::not_equal(x : Operation, y : Operation) -> Bool

    Operation::to_json

    fn Operation::to_json(Operation) -> Json

    PackageGraph

    pub(all) struct PackageGraph {
    schema : String
    root : String
    parts : Array[PartRecord]
    relationships : Array[Relationship]
    xml_references : Array[XmlReference]
    implicit_references : Array[ImplicitReference]
    nodes : Array[GraphNode]
    content_types : Array[ContentTypeIndex]
    reachable : Array[String]
    orphan_candidates : Array[String]
    coverage_gaps : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    PackageGraph::equal

    PackageGraph::not_equal

    fn PackageGraph::not_equal(x : PackageGraph, y : PackageGraph) -> Bool

    PackageGraph::to_json

    PartRecord

    pub(all) struct PartRecord {
    name : String
    content_type : String
    sha256 : String
    } derive(Eq, ToJson,
    Debug
    )

    PartRecord::equal

    fn PartRecord::equal(PartRecord, PartRecord) -> Bool

    PartRecord::not_equal

    fn PartRecord::not_equal(x : PartRecord, y : PartRecord) -> Bool

    PartRecord::to_json

    fn PartRecord::to_json(PartRecord) -> Json

    PlanOperationKind

    pub(all) enum PlanOperationKind {
    RemovePart
    RemoveRelationship
    RewriteSourceXml
    RewriteRelationshipPart
    RewriteContentTypes
    ChangeMainContentType
    } derive(Eq,
    Debug
    )

    PlanOperationKind::equal

    PlanOperationKind::not_equal

    fn PlanOperationKind::not_equal(x : PlanOperationKind, y : PlanOperationKind) -> Bool

    PlanOperationKind::to_json

    PolicyAction

    pub(all) enum PolicyAction {
    AllowAction
    RemoveAction
    RefuseAction
    } derive(Eq,
    Debug
    )

    PolicyAction::equal

    PolicyAction::not_equal

    fn PolicyAction::not_equal(x : PolicyAction, y : PolicyAction) -> Bool

    PolicyAction::to_json

    fn PolicyAction::to_json(self : PolicyAction) -> Json

    PolicyDecision

    pub(all) struct PolicyDecision {
    decision_id : String
    finding_index : Int?
    action : PolicyAction
    rule_id : String
    part : String
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    PolicyDecision::equal

    PolicyDecision::not_equal

    fn PolicyDecision::not_equal(x : PolicyDecision, y : PolicyDecision) -> Bool

    PolicyDecision::to_json

    PreparedPlan

    pub(all) struct PreparedPlan {
    schema : String
    tool : String
    rules : String
    input_hash : String
    input_format : String
    output_format : String
    policy : String
    profile : String
    limits : Limits
    preconditions : Array[PartRecord]
    findings : Array[CapabilityFinding]
    decisions : Array[PolicyDecision]
    operations : Array[CheckedOperation]
    controlled_removals : Array[String]
    orphan_candidates : Array[String]
    coverage : Coverage
    gate : Decision
    unavailable_handlers : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    PreparedPlan::equal

    PreparedPlan::not_equal

    fn PreparedPlan::not_equal(x : PreparedPlan, y : PreparedPlan) -> Bool

    PreparedPlan::to_json

    Presence

    pub(all) enum Presence {
    Present
    Absent
    Unknown
    } derive(Eq,
    Debug
    )

    Presence::equal

    fn Presence::equal(Presence, Presence) -> Bool

    Presence::not_equal

    fn Presence::not_equal(x : Presence, y : Presence) -> Bool

    Presence::to_json

    fn Presence::to_json(self : Presence) -> Json

    Presence::to_repr

    PreservationKind

    pub(all) enum PreservationKind {
    BytePreservedKind
    SemanticallyRewrittenKind
    RemovedByPolicyKind
    RegeneratedMetadataKind
    } derive(Eq,
    Debug
    )

    PreservationKind::equal

    PreservationKind::not_equal

    fn PreservationKind::not_equal(x : PreservationKind, y : PreservationKind) -> Bool

    PreservationKind::to_json

    fn PreservationKind::to_json(self : PreservationKind) -> Json

    RebuildSupport

    pub(all) enum RebuildSupport {
    Supported
    NotSupported
    } derive(Eq,
    Debug
    )

    RebuildSupport::equal

    RebuildSupport::not_equal

    fn RebuildSupport::not_equal(x : RebuildSupport, y : RebuildSupport) -> Bool

    RebuildSupport::to_json

    fn RebuildSupport::to_json(self : RebuildSupport) -> Json

    Rebuilt

    pub(all) struct Rebuilt {
    bytes : Bytes
    receipt : Receipt
    }

    Receipt

    pub(all) struct Receipt {
    schema : String
    tool : String
    rules : String
    policy : String
    profile : String
    input_hash : String
    output_hash : String
    input_size : Int
    output_size : Int
    input_format : String
    output_format : String
    limits : Limits
    audit : Audit
    plan : RewritePlan
    dispositions : Array[Disposition]
    structure : String
    preservation : String
    independent_validation : String
    limitations : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    Receipt::equal

    fn Receipt::equal(Receipt, Receipt) -> Bool

    Receipt::not_equal

    fn Receipt::not_equal(x : Receipt, y : Receipt) -> Bool

    Receipt::to_json

    fn Receipt::to_json(Receipt) -> Json

    Receipt::to_repr

    Relationship

    pub(all) struct Relationship {
    source : String
    id : String
    kind : String
    target : String
    resolved : String
    external : Bool
    } derive(Eq, ToJson,
    Debug
    )

    Relationship::equal

    Relationship::not_equal

    fn Relationship::not_equal(x : Relationship, y : Relationship) -> Bool

    Relationship::to_json

    ResultStatus

    pub(all) enum ResultStatus {
    Pass
    Fail
    IncompleteResult
    Unsupported
    } derive(Eq,
    Debug
    )

    ResultStatus::equal

    ResultStatus::not_equal

    fn ResultStatus::not_equal(x : ResultStatus, y : ResultStatus) -> Bool

    ResultStatus::to_json

    fn ResultStatus::to_json(self : ResultStatus) -> Json

    RewritePlan

    pub(all) struct RewritePlan {
    schema : String
    input_hash : String
    policy : String
    profile : String
    operations : Array[Operation]
    } derive(Eq, ToJson,
    Debug
    )

    RewritePlan::equal

    fn RewritePlan::equal(RewritePlan, RewritePlan) -> Bool

    RewritePlan::not_equal

    fn RewritePlan::not_equal(x : RewritePlan, y : RewritePlan) -> Bool

    RewritePlan::to_json

    fn RewritePlan::to_json(RewritePlan) -> Json

    RuleCoverage

    pub(all) struct RuleCoverage {
    rule_id : String
    capability : Capability
    state : CheckState
    presence : Presence
    rebuild_support : RebuildSupport
    reason : String
    } derive(Eq, ToJson,
    Debug
    )

    RuleCoverage::equal

    RuleCoverage::not_equal

    fn RuleCoverage::not_equal(x : RuleCoverage, y : RuleCoverage) -> Bool

    RuleCoverage::to_json

    VerificationCheck

    pub(all) struct VerificationCheck {
    check_id : String
    state : CheckState
    result : ResultStatus?
    detail : String
    } derive(Eq, ToJson,
    Debug
    )

    VerificationCheck::equal

    VerificationCheck::not_equal

    fn VerificationCheck::not_equal(x : VerificationCheck, y : VerificationCheck) -> Bool

    VerificationCheck::to_json

    VerifiedRebuilt

    pub(all) struct VerifiedRebuilt {
    bytes : Bytes
    receipt : VerifiedReceipt
    }

    VerifiedReceipt

    pub(all) struct VerifiedReceipt {
    schema : String
    tool : String
    rules : String
    policy : String
    profile : String
    input_hash : String
    output_hash : String
    input_size : Int
    output_size : Int
    input_format : String
    output_format : String
    limits : Limits
    input_coverage : Coverage
    output_coverage : Coverage
    findings : Array[CapabilityFinding]
    output_findings : Array[CapabilityFinding]
    decisions : Array[PolicyDecision]
    allowed_capabilities : Array[CapabilityFinding]
    plan : PreparedPlan
    dispositions : Array[ContractDisposition]
    checks : Array[VerificationCheck]
    result : ResultStatus
    independent_validation : CheckState
    independent_tools : Array[String]
    limitations : Array[String]
    } derive(Eq, ToJson,
    Debug
    )

    VerifiedReceipt::equal

    VerifiedReceipt::not_equal

    fn VerifiedReceipt::not_equal(x : VerifiedReceipt, y : VerifiedReceipt) -> Bool

    VerifiedReceipt::to_json

    XmlReference

    pub(all) struct XmlReference {
    source : String
    element_index : Int
    depth : Int
    element_namespace : String
    element_name : String
    attribute_name : String
    relationship_id : String
    relationship_index : Int
    } derive(Eq, ToJson,
    Debug
    )

    XmlReference::equal

    XmlReference::not_equal

    fn XmlReference::not_equal(x : XmlReference, y : XmlReference) -> Bool

    XmlReference::to_json

    assess

    fn assess(input : Bytes, limits? : Limits) -> Assessment

    audit

    fn audit(input : Bytes, limits? : Limits) -> Audit raise

    digest

    fn digest(bytes : BytesView) -> String

    inspect_graph

    fn inspect_graph(input : Bytes, limits? : Limits) -> PackageGraph raise

    plan

    fn plan(input : Bytes, limits? : Limits) -> RewritePlan raise

    prepare

    fn prepare(input : Bytes, limits? : Limits) -> PreparedPlan raise

    rebuild

    fn rebuild(input : Bytes, limits? : Limits) -> Rebuilt raise

    rebuild_verified

    fn rebuild_verified(input : Bytes, limits? : Limits) -> VerifiedRebuilt raise

    rebuild_verified_with_plan

    fn rebuild_verified_with_plan(input : Bytes, supplied : Json, limits? : Limits) -> VerifiedRebuilt raise

    rebuild_with_plan

    fn rebuild_with_plan(input : Bytes, supplied : Json, limits? : Limits) -> Rebuilt raise

    resolve_target

    fn resolve_target(source : String, target : String) -> String raise

    verify

    fn verify(output : Bytes, original : Bytes, limits? : Limits) -> Receipt raise

    verify_contract

    fn verify_contract(output : Bytes, original : Bytes, limits? : Limits) -> VerifiedReceipt raise