Security-first, zero-dependency document processing in Rust.
Bounded parsers, explicit loss reports, deterministic writers, and hardened sanitization.
Málthorp is a security-first, no_std-first Rust ecosystem for reading, inspecting, validating, editing, sanitizing, converting, and writing document formats. Every document is treated as untrusted: allocations and work must be bounded, parser operations must be accountable, and every lossy conversion must be reported.
Version 0.1.0 is the repository foundation. It establishes crate boundaries, toolchain policy, security policy, specification provenance, and verification gates. It does not yet parse documents and must not be used as if the planned 1.0 guarantees were already implemented.
- Zero third-party Cargo dependencies.
- no_std public libraries, with alloc only behind an explicit feature.
- Rust 1.90.0 minimum for all public crates.
- Rust 1.97.1 for current development and the private CLI.
- Production code forbids unsafe code.
- No network access, external resource loading, shell commands, or runtime plugins in library behavior.
- Source files remain at or below 500 lines; generated specification tables are separately identified and reviewed.
- Official specifications are pinned before format behavior is implemented.
- Small release milestones, each ending in an exact-commit pentest.
| Crate | Format or role | 1.0 target |
|---|---|---|
| malthorp | Facade | Detection, inspection, conversion, editing, sanitization |
| malthorp-core | Foundation | I/O traits, limits, diagnostics, semantic IR, transactions |
| malthorp-text | Text foundation | UTF encodings, line handling, Unicode and code-page data |
| malthorp-txt | Plain text | Read, write, transcode, inspect, edit |
| malthorp-csv | CSV and TSV | Streaming read/write, inspect, sanitize, edit |
| malthorp-markdown | CommonMark 0.31.2 | Parse, write, inspect, sanitize, edit |
| malthorp-xml | XML 1.0 | Secure streaming parser, native model, writer |
| malthorp-rtf | RTF 1.9.1 | Rich-text read/write/edit and object sanitization |
HTML, SVG, IDML, EPUB, FB2, XPS, ODT, DOCX, PDF, and legacy DOC remain post-1.0 work. See the release plan for the staged sequence.
The public libraries are tested across every stable release currently present between the MSRV and current toolchain. The CLI deliberately supports only the current pinned stable toolchain.
| Rust | Public crates | malthorp-cli |
|---|---|---|
| 1.90.0 | Supported (MSRV) | Not supported |
| 1.91.0, 1.91.1 | Supported | Not supported |
| 1.92.0 | Supported | Not supported |
| 1.93.0, 1.93.1 | Supported | Not supported |
| 1.94.0, 1.94.1 | Supported | Not supported |
| 1.95.0 | Supported | Not supported |
| 1.96.0, 1.96.1 | Supported | Not supported |
| 1.97.0 | Supported | Not supported |
| 1.97.1 | Supported (current) | Supported |
The exact policy and commands are in MSRV.md.
| Feature | Default | Purpose |
|---|---|---|
| alloc | yes | Enables future owned document models and editing |
| txt | yes | Enables the plain-text format crate |
| csv | no | Enables CSV and TSV |
| markdown | no | Enables CommonMark |
| xml | no | Enables XML |
| rtf | no | Enables RTF |
| all-formats | no | Enables all formats targeted for 1.0 |
The bootstrap contains crate boundaries only; enabling a format feature does not yet imply parser availability.
Public crates avoid operating-system APIs and are designed for Linux, Windows, the BSDs, macOS, Android, iOS, WebAssembly, embedded no_std consumers, and a future Aesynx target. The CLI release matrix will cover Linux, Windows, macOS, and BSD targets as each packaging milestone is reached. No OS support claim is made until the corresponding CI or release evidence exists.
Use the pinned toolchain and run the local gate:
scripts/checks.shRun the complete public-crate Rust matrix when preparing a release:
scripts/check-rust-version-matrix.shThe networked current-version check is intentionally separate from ordinary offline-capable builds:
scripts/check_latest_tools.shGitHub should use CodeQL default setup. This repository intentionally does not contain an advanced CodeQL workflow.
- Architecture
- Implementation Plan
- Release Plan
- Specification Sources
- Threat Model
- Resource Limits
- Platform Support
- Unsupported Features
Málthorp is pre-implementation software. There has been no independent audit, and no parser is production-ready. Security findings should be reported privately according to SECURITY.md.
Licensed under either the Apache License, Version 2.0 or the MIT License, at your option. Specification copies retain their publishers' own notices and are not relicensed as Málthorp software.