Skip to content

Releases: thepictishbeast/cinder

Cinder v0.2.0-dev — full free-RAM overwrite, background service, schedules, icon

Choose a tag to compare

@thepictishbeast thepictishbeast released this 12 Aug 11:25

What changed

Free-RAM overwrite is no longer capped. It used to stop at a small
fraction of what was free — three causes, all fixed:

  • the native scrub gave up at the first refused allocation; it now
    backs off (64 MiB → 256 KiB) and only stops when the allocator refuses
    the smallest chunk,
  • the app sized the job from one stale availMem snapshot minus a fat
    margin; there is no up-front budget now — it re-reads the kernel's live
    MemAvailable between blocks against a keep-free floor,
  • it ran on a plain background thread, so Android's low-memory killer
    reaped it early; it now runs in a foreground service.

Runs in the background. Start a wipe and leave the app — it keeps
going, with a notification showing live progress and a Stop action.

Real feedback. Live bytes, throughput and elapsed time while it runs;
a finishing report with how much was overwritten, why it stopped
(memory ceiling / keep-free floor / stopped), how many blocks it held,
and free RAM and storage before → after.

Scheduled wipes. Daily or weekly, free RAM and/or free space. Timing
is inexact so Android can batch it, the schedule survives a reboot, and a
run is skipped (with the reason recorded) below 30% battery when not
charging.

An actual app icon — an ember on charcoal, drawn as vector XML with
an adaptive icon, a monochrome/themed layer, and a fallback for older
Android.

Why it asks for no storage permission is now explained in the app:
the document picker is the consent step for shredding a file or folder,
and free-space/RAM wiping needs no grant because it writes into Cinder's
own storage and its own memory. The only new prompt is notifications, so
a background wipe stays visible and stoppable.

Command line: cinder dirty-ram --all [--keep-free BYTES].

Honest limits (unchanged)

Overwriting is best-effort on flash — the controller may keep old copies
in remapped cells. A factory reset (crypto-erase) is the only device-wide
guarantee. RAM clears completely on power-off.

Verification

19 tests pass, clippy clean, and the built APK was checked for the icon,
service, receivers and permissions. Not yet run on real hardware —
the build host's emulator does not boot, so the on-device suite still
needs a phone. Debug-signed preview build.

Cinder v0.1.1-dev (audited)

Pre-release

Choose a tag to compare

@thepictishbeast thepictishbeast released this 07 Aug 08:48

Cinder v0.1.1-dev — audited build.

New / fixed

  • Audit + proofs shipped: docs/PROOFS.md (deletion + free-space/RAM preservation, all test-backed) and docs/AUDIT.md (findings + graceful-failure across devices).
  • RAM scrub now claims ~all free RAM (reads availMem, minus a safety margin) instead of a fixed 128 MB. On a phone the CPU/GPU/tensor chip share one physical RAM pool, so this also overwrites the free GPU/NPU memory — no driver needed.
  • Fix: clean up a leftover scratch dir on launch if a free-space wipe was interrupted.

Proven (16 unit tests)

  • Deletion overwrites the original bytes (no plaintext fragment survives).
  • Free-space wipe leaves every existing file byte-for-byte identical.
  • RAM scrub only touches its own memory.

Honest limits (unchanged)

Overwriting is best-effort on flash; a factory reset is the only device-wide guarantee. RAM/VRAM is volatile — a reboot clears it. Debug-signed dev preview; SAF file/folder flows want an on-device tap-through.

Cinder v0.1.0-dev

Cinder v0.1.0-dev Pre-release
Pre-release

Choose a tag to compare

@thepictishbeast thepictishbeast released this 06 Aug 23:43

Cinder v0.1.0-dev — honest, best-effort secure erase for Android. Fully offline, FOSS (AGPL-3.0).

What it does

  • Shred a file / a folder — overwrite with random + fsync, then delete (folder shred is recursive and symlink-safe).
  • Wipe free space — fill free space with random then delete it; force-TRIM the freed blocks if you're rooted.
  • Scrub RAM — overwrite the reassignable RAM the OS hands the app.
  • Factory-reset guidance — points you at the one guaranteed erase.

The honest part (why this isn't a placebo)

On phone flash, overwriting is best-effort: the controller can keep the original bytes in a cell the overwrite never touched (NIST SP 800-88 prefers cryptographic erase). The only device-wide guarantee is a factory reset (destroys the encryption key). Scrubbing free RAM can't beat a reboot; forcing TRIM needs root. Every action in the app says so, up front.

Verified

Rust core: 13 unit tests. Builds for all 4 ABIs (arm64-v8a, armeabi-v7a, x86, x86_64). Runtime-checked on an emulator: the app launches and its native code runs on-device.

⚠️ This is a dev preview, debug-signed build for testing (not a signed release). Sideload or add via Obtainium (include-prereleases ON). The SAF file/folder picker flows still want real-device tap-through.