feat: initial wipe implementation - block device safety, HDD overwrite, NVMe/secure-discard, verification

This commit is contained in:
changchichung
2026-09-01 10:56:53 +08:00
commit 5470eb0e8d
40 changed files with 5767 additions and 0 deletions
+24
View File
@@ -0,0 +1,24 @@
# Changelog
All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [0.1.0] - 2026-09-01
### Added
- Initial release of `wipe`
- Block device validation (`/dev` symlink resolution, block device checks)
- `lsblk --json` inspection with sysfs fallback
- Partition and mount discovery, nested mount handling
- Safety checks: whole-disk confirmation, mounted/swap detection, holder/dependency (LVM/dm-crypt/mdraid/multipath), running system protection
- HDD overwrite engine: zero, ones, alternating, random (ChaCha20 deterministic stream)
- Progress reporting via `indicatif`, ETA, throughput
- `sync` / `--no-sync`, deterministic verification (`OVERWRITE_VERIFIED`)
- SSD/NVMe backends: `secure-discard` (`blkdiscard --secure`), `nvme-sanitize`/`nvme-crypto` via `nvme-cli` with capability (`SANICAP`) and `SSTAT` monitoring
- CLI: `--passes`, `--method`, `--yes`, `--whole-disk`, `--unmount`, `--force`, `--dry-run`, `--verify`, `--buffer-size`, `--json`, `--verbose`
- JSON output with error codes (0-15)
- SIGINT handling (exit 15, `WIPE INTERRUPTED`)
- Loop device integration tests and unit tests
- CI (`cargo fmt`, `check`, `test`, `clippy`, `build`), release workflow, Dockerfile, Makefile