wipe
Secure block device wipe and hardware erase orchestration for Linux — a safer, stricter alternative to shred for whole-disk operations.
Warning: This tool performs irreversible destructive operations. Always verify the target device with
--dry-runfirst.
Features
- Strict destructive-operation safety:
/devvalidation, symlink escape prevention, whole-disk confirmation, mount/swap/holder checks, running system protection - HDD overwrite:
zero,ones,alternating,random(ChaCha20 deterministic stream, per-chunk unique, verifiable) - SSD/NVMe hardware erase:
secure-discard(blkdiscard --secure),nvme-sanitize(block erase),nvme-crypto(crypto erase) vianvme-cli - Progress, ETA, throughput, sync control,
--verify(OVERWRITE_VERIFIED) - Human and JSON output, typed exit codes (0-15), SIGINT-safe
Installation
cargo install --path .
Or build release binary:
cargo build --release
# binary at target/release/wipe
Build
cargo build --release
Basic Usage
# Dry run first!
sudo wipe /dev/sdb --whole-disk --dry-run
# Wipe HDD (1 pass zero overwrite, sync)
sudo wipe /dev/sdb --whole-disk
# Multiple passes
sudo wipe /dev/sdb --whole-disk --passes 3
# With verify
sudo wipe /dev/sdb --whole-disk --verify
# JSON output
sudo wipe /dev/sdb --whole-disk --json --yes
Methods
# Auto (HDD -> zero, SSD/NVMe -> require explicit method)
sudo wipe /dev/sdb --whole-disk --method auto
# Explicit overwrite methods
sudo wipe /dev/sdb --whole-disk --method zero
sudo wipe /dev/sdb --whole-disk --method random
sudo wipe /dev/sdb --whole-disk --method ones
sudo wipe /dev/sdb --whole-disk --method alternating
# SSD / NVMe hardware erase
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-sanitize
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-crypto
sudo wipe /dev/sda --whole-disk --method secure-discard
autowill not silently fallback from hardware erase to overwrite on SSD/NVMe; it returns an error requiring explicit--method.- NVMe sanitize is asynchronous;
wipepollsnvme sanitize-log(SSTAT) every second.
Common Options
| Option | Description |
|---|---|
-n, --passes <N> |
HDD overwrite passes (default 1) |
-m, --method <METHOD> |
auto (default), zero, random, ones, alternating, secure-discard, nvme-sanitize, nvme-crypto |
-y, --yes |
Skip interactive WIPE confirmation (does NOT bypass system-disk protection) |
--whole-disk |
Explicitly allow whole-disk wipe |
--unmount |
Auto unmount filesystems / swapoff |
--force |
Override non-system safety checks (never bypasses running system device) |
--dry-run |
No data modification; shows device, partitions, mounts, method, passes |
--verify |
Read-back verification after overwrite |
--no-sync |
Skip final sync |
--buffer-size <SIZE> |
e.g. 64M (default), 16M, 32M, 128M |
--json |
Machine-readable output |
-v, --verbose |
Verbose logging |
Exit codes: 0 success, 1 generic, 2 invalid args, 3 perm denied, 4 not found, 5 not block device, 6 mounted, 7 dependency, 8 running system, 9 unsupported method, 10 capability unavailable, 11 unmount failed, 12 overwrite failed, 13 verification failed, 14 external command failed, 15 interrupted.
Dry Run Example
sudo wipe /dev/sdb --whole-disk --dry-run
Device
Path /dev/sdb
Type HDD
Size 3.64 TiB
Model ST4000...
Serial XXXXX
Rotational yes
Partitions
/dev/sdb1
/dev/sdb2
Mounted
/data
Action
unmount /data
Method
zero overwrite
Passes
1
Estimated operation
destructive: YES
DRY RUN
No data will be modified.
JSON Example
Success:
{
"device": "/dev/sdb",
"type": "hdd",
"size": 4000787030016,
"method": "zero",
"passes": 3,
"verification": true,
"result": "overwrite_verified",
"success": true
}
Error:
{
"device": "/dev/sda",
"success": false,
"error": {
"code": "RUNNING_SYSTEM_DEVICE",
"message": "target device contains the running system"
}
}
SSD / NVMe vs HDD
- HDD (
ROTA=1):zerooverwrite is the default forauto. Use--passesfor multiple passes. - SSD (
ROTA=0, SATA): Prefersecure-discardif supported; otherwise explicitzerooverwrite with the caveat that logical overwrite ≠ NAND erasure. - NVMe: Check
nvme id-ctrlSANICAP(bit 0 crypto, bit 1 block, bit 2 overwrite). Usenvme-sanitize/nvme-cryptofor controller-level erase.autorequires explicit method for SSD/NVMe to avoid silent fallback.
Safety Notes
See SECURITY.md. Logical verification (OVERWRITE_VERIFIED) confirms the LBA range reads back as written, but does not prove forensic irrecoverability for remapped sectors or NAND cells.
Development
make fmt
make check
make test
make lint
make build
make verify
# Loop device integration (needs sudo)
sudo ./scripts/loop-test.sh
./scripts/verify.sh
License
MIT