Repository navigation
Releases: thepictishbeast/cinder
Release list
Cinder v0.2.0-dev — full free-RAM overwrite, background service, schedules, icon
What changed
Free-RAM overwrite is no longer capped. It used to stop at a small
fraction of what was free — three causes, all fixed:
- the native scrub gave up at the first refused allocation; it now
backs off (64 MiB → 256 KiB) and only stops when the allocator refuses
the smallest chunk, - the app sized the job from one stale
availMemsnapshot minus a fat
margin; there is no up-front budget now — it re-reads the kernel's live
MemAvailablebetween blocks against a keep-free floor, - it ran on a plain background thread, so Android's low-memory killer
reaped it early; it now runs in a foreground service.
Runs in the background. Start a wipe and leave the app — it keeps
going, with a notification showing live progress and a Stop action.
Real feedback. Live bytes, throughput and elapsed time while it runs;
a finishing report with how much was overwritten, why it stopped
(memory ceiling / keep-free floor / stopped), how many blocks it held,
and free RAM and storage before → after.
Scheduled wipes. Daily or weekly, free RAM and/or free space. Timing
is inexact so Android can batch it, the schedule survives a reboot, and a
run is skipped (with the reason recorded) below 30% battery when not
charging.
An actual app icon — an ember on charcoal, drawn as vector XML with
an adaptive icon, a monochrome/themed layer, and a fallback for older
Android.
Why it asks for no storage permission is now explained in the app:
the document picker is the consent step for shredding a file or folder,
and free-space/RAM wiping needs no grant because it writes into Cinder's
own storage and its own memory. The only new prompt is notifications, so
a background wipe stays visible and stoppable.
Command line: cinder dirty-ram --all [--keep-free BYTES].
Honest limits (unchanged)
Overwriting is best-effort on flash — the controller may keep old copies
in remapped cells. A factory reset (crypto-erase) is the only device-wide
guarantee. RAM clears completely on power-off.
Verification
19 tests pass, clippy clean, and the built APK was checked for the icon,
service, receivers and permissions. Not yet run on real hardware —
the build host's emulator does not boot, so the on-device suite still
needs a phone. Debug-signed preview build.
Cinder v0.1.1-dev (audited)
Cinder v0.1.1-dev — audited build.
New / fixed
- Audit + proofs shipped:
docs/PROOFS.md(deletion + free-space/RAM preservation, all test-backed) anddocs/AUDIT.md(findings + graceful-failure across devices). - RAM scrub now claims ~all free RAM (reads
availMem, minus a safety margin) instead of a fixed 128 MB. On a phone the CPU/GPU/tensor chip share one physical RAM pool, so this also overwrites the free GPU/NPU memory — no driver needed. - Fix: clean up a leftover scratch dir on launch if a free-space wipe was interrupted.
Proven (16 unit tests)
- Deletion overwrites the original bytes (no plaintext fragment survives).
- Free-space wipe leaves every existing file byte-for-byte identical.
- RAM scrub only touches its own memory.
Honest limits (unchanged)
Overwriting is best-effort on flash; a factory reset is the only device-wide guarantee. RAM/VRAM is volatile — a reboot clears it. Debug-signed dev preview; SAF file/folder flows want an on-device tap-through.
Cinder v0.1.0-dev
Cinder v0.1.0-dev — honest, best-effort secure erase for Android. Fully offline, FOSS (AGPL-3.0).
What it does
- Shred a file / a folder — overwrite with random + fsync, then delete (folder shred is recursive and symlink-safe).
- Wipe free space — fill free space with random then delete it; force-TRIM the freed blocks if you're rooted.
- Scrub RAM — overwrite the reassignable RAM the OS hands the app.
- Factory-reset guidance — points you at the one guaranteed erase.
The honest part (why this isn't a placebo)
On phone flash, overwriting is best-effort: the controller can keep the original bytes in a cell the overwrite never touched (NIST SP 800-88 prefers cryptographic erase). The only device-wide guarantee is a factory reset (destroys the encryption key). Scrubbing free RAM can't beat a reboot; forcing TRIM needs root. Every action in the app says so, up front.
Verified
Rust core: 13 unit tests. Builds for all 4 ABIs (arm64-v8a, armeabi-v7a, x86, x86_64). Runtime-checked on an emulator: the app launches and its native code runs on-device.
⚠️ This is a dev preview, debug-signed build for testing (not a signed release). Sideload or add via Obtainium (include-prereleases ON). The SAF file/folder picker flows still want real-device tap-through.