scuttle/CHANGELOG.md

113 lines
7.3 KiB
Markdown
Executable File
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# scuttle — Changelog
## v0.4.0 — Verification + Audit Exporters + Signing + Firmware Erase (2026-08-04)
Fourth tagged release. Combines the v0.5 (Verification and Audit) and v0.6 (Firmware Erase) milestones from `docs/MANIFEST.md` §15.
### Added
#### v0.5 Layer 6 — Extended Verification (`scuttle-verify`)
- **Spot verification** (`verify_static_pattern_spot`): reads N% of blocks at pseudorandom offsets and compares against the expected pattern. Default 5%.
- **Block verification** (`verify_static_pattern_blocks`): reads fixed-size blocks (e.g. 1 MiB) for large devices where sector-by-sector is too slow.
- **Statistical verification** (`compute_statistics`, `verify_statistical`):
- Shannon entropy (bits per byte, 0.08.0).
- Chi-square statistic for uniform distribution (256 buckets).
- Chi-square p-value (Wilson-Hilferty approximation, 255 degrees of freedom).
- Byte frequency max deviation.
- **Failure mapping** (`FailedRange`): tracks LBA start/end + expected/actual hex for each mismatch.
- `VerifyResult` now carries `failed_ranges: Vec<FailedRange>` and `stats: Option<StatisticalResult>`.
- 5 new unit tests (statistics on zeros, statistics on random, spot verify pass, spot verify mismatch, block verify).
#### v0.5 Layer 7 — Audit Exporters + Merkle Tree (`scuttle-audit`)
- **XML exporter** (`to_xml`): well-formed XML with sorted keys, CDATA-escaped text.
- **CSV exporter** (`to_csv`): single-row flat format with all key fields.
- **HTML exporter** (`to_html`): self-contained HTML page with embedded CSS, styled result (green/red), and a `<pre>` block with the full JSON.
- **YAML exporter** (`to_yaml`): via serde_yaml.
- **Merkle tree** (`MerkleTree`): builds a SHA-256 Merkle tree over per-block hashes of the wiped device. Supports `from_leaves` and `from_data`. Pads to power-of-two.
- **NIST SP 800-88 compliance report** (`ComplianceReport`): maps the audit record's NIST class (Clear/Purge/Destroy) to compliance evidence. Serializable to JSON.
- `VerifyResultJson` now carries `stats: Option<StatisticalResultJson>`.
- 9 new unit tests (Merkle single/two/three/from_data, XML/CSV/HTML/YAML export, compliance report).
#### v0.5 Layer 7 — Signing (`scuttle-signing`)
- **`scuttle-signing` crate**: Ed25519 digital signatures for audit records.
- `sign_ed25519(record, key)``SignatureResult` (algorithm, signature_hex, key_fingerprint, signed_payload_hash).
- `verify_ed25519_with_key(record, sig, public_key)``bool`.
- `load_ed25519_key(path)` — load a 32-byte seed from file.
- `generate_ed25519_keypair()` — for testing.
- `key_fingerprint(public_key)` — SHA-256 of the public key, hex-encoded.
- `SignerBackend` trait + `Ed25519Signer`, `OpenPgpSigner` (stub), `X509Signer` (stub).
- `SignatureJson` for embedding in the audit record.
- 8 unit tests (sign+verify roundtrip, wrong-key failure, signature changes with record, OpenPGP/X.509 stubs return NotImplemented, signer backend trait, key load rejects wrong length, key load 32 bytes).
#### v0.6 Layer 9 — Firmware Erase (`scuttle-firmware`)
- **`scuttle-firmware` crate**: firmware-level sanitization commands.
- **ATA Secure Erase** (`ata_secure_erase`, `ata_secure_erase_enhanced`): via `hdparm --security-erase` / `--security-erase-enhanced`. Includes `ata_detect_secure_erase` and `ata_set_security_password`.
- **NVMe Sanitize** (`nvme_sanitize`): supports Block Erase, Crypto Erase, Overwrite actions via `nvme-cli`. Includes `nvme_sanitize_status` polling (up to 1 hour timeout).
- **NVMe Format NVM** (`nvme_format`): format namespace with block size + secure erase setting (None / UserDataErase / CryptographicErase).
- **SCSI Sanitize** (`scsi_sanitize`): via `sg_sanitize --overwrite`.
- **SCSI Format Unit** (`scsi_format`): via `sg_format --format --six`.
- **TRIM** (`trim_discard`): direct `ioctl(BLKDISCARD)` over the entire device.
- **FITRIM** (`fitrim`): direct `ioctl(FITRIM)` on a mounted filesystem.
- **HPA/DCO detect + disable** (`detect_hpa_dco`, `disable_hpa`, `disable_dco`): via `hdparm -N` and `hdparm --dco-identify` / `--dco-restore`.
- **High-level dispatch** (`run_firmware_erase`): takes a `PurgeMethod` + device path, runs the right command, returns `FirmwareResult`.
- Tools are detected at runtime; if absent, returns `FirmwareError::ToolNotFound`.
- 8 unit tests (which() finds known binaries, HPA/DCO parse helpers, ATA detect returns gracefully without hdparm).
#### v0.6 Policy engine integration (`scuttle-policy`)
- `WipePlan` now carries `firmware_erase: Option<PurgeMethod>`.
- SSD policies set `firmware_erase = AtaSecureErase` (or `AtaSecureEraseEnhanced` if supported) for Purge/Enterprise/Forensic/Government/AirGap/Paranoid intents.
- NVMe policies set `firmware_erase = NvmeSanitizeCrypto` for the same intents.
- PMEM policy sets `firmware_erase = PmemCryptoErase` (returns Unsupported at runtime since ndctl integration is deferred to v0.7).
- HDD / virtual / freespace policies leave `firmware_erase = None`.
- 5 new tests verify the firmware_erase field is set correctly.
#### v0.6 Core wipe engine integration (`scuttle-core`)
- `JobOptions` now carries `firmware_erase: Option<PurgeMethod>`.
- The wipe engine invokes `scuttle_firmware::run_firmware_erase` BEFORE the overwrite passes.
- Firmware erase failures are logged and recorded in `audit.notes` but do NOT abort the wipe — the overwrite passes still run as belt-and-braces.
#### CLI integration
- `--certificate` now accepts: `none`, `json`, `pdf`, `xml`, `csv`, `html`, `yaml`, `both` (json+pdf), `all` (all 6 formats).
- CLI overrides for `--rounds`, `--verify`, `--certificate`, `--noblank` are now correctly re-applied after the policy engine runs (previously the policy engine's profile defaults would overwrite CLI overrides).
### Tests
- **105 tests total** (was 70 in v0.3):
- 5 new in `scuttle-verify` (spot/block/statistical).
- 9 new in `scuttle-audit` (exporters + Merkle + compliance).
- 8 new in `scuttle-signing` (Ed25519 sign/verify + stubs).
- 8 new in `scuttle-firmware` (parse helpers + which).
- 5 new in `scuttle-policy` (firmware_erase field).
### Known limitations
- Firmware erase requires `hdparm`, `nvme-cli`, and `sg3_utils` to be installed. If absent, the function returns `ToolNotFound` and the wipe continues with overwrite-only.
- PMEM crypto-erase requires `ndctl` (deferred to v0.7).
- OpenPGP and X.509 signing are stubs (deferred to v2.0).
- The Merkle tree is built but not yet signed or bound into the audit record (the signing happens over the canonical JSON, not the Merkle root — full Merkle-root signing arrives in v0.7).
---
## v0.3.0 — Modern Providers + Profiles/Policies + Freespace Mode (2026-08-04)
See git history for full v0.3.0 changelog. Summary: 5 modern PRNGs (BLAKE3-XOF, XChaCha20, SHAKE128, SHAKE256, Salsa20); Layer 16 benchmark framework; v0.4 modern profile TOML schema with policy_map + constraints; policy engine with 20 built-in policies; 11 modern profiles; `--freespace-only` mode; fixed MT19937 + ISAAC-64 KAT bugs.
---
## v0.2.0 — Legacy Compatibility (2026-08-04)
See git history. Summary: legacy profiles, legacy flag compatibility, PDF certificate exporter, nwipe symlink support.
---
## v0.1.0 — Architectural Bootstrap (2026-08-04)
See git history. Summary: Layers 1-7 + 13 implemented from scratch in Rust; 24 tests passing.