4 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 2cdefbe45c Update rand to 0.10 with a rand_core 0.6 compatibility shim
Bump the `rand` dev-dependency to the latest (0.10), which exposes rand_core
0.10, while the latest `rsa` (0.9) still requires an rand_core 0.6 RNG for key
generation. Bridge the skew with a small, test-only adapter instead of pinning
rand back.

* Add `rand_core_06 = { package = "rand_core", version = "0.6" }` so the shim
  can implement the old traits (cargo unifies it with the rand_core 0.6 that
  rsa already uses).
* `RandCompat<R>` wraps a modern RNG and re-implements rand_core 0.6's RngCore
  + CryptoRng over it, delegating to rand_core 0.10's infallible methods.
  Implementing both satisfies rand_core 0.6's blanket CryptoRngCore impl, which
  is exactly the bound rsa keygen requires.
* The CryptoRng bound is preserved (only wraps RNGs still marked
  cryptographically secure), so the randomness is not weakened — it is purely a
  trait-version shim. Tests now use `RandCompat(rand::rng())`.

46 tests pass (incl. the RSA-based EPUB roundtrips that exercise the shim);
clippy + rustfmt clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 20:44:22 -05:00
JMR-devandClaude Opus 4.8 259bb4d6fa Update dependencies to latest versions
Bump dependency requirements to their current latest and migrate the code for
the breaking API changes; refresh Cargo.lock for the rest.

Notable version bumps:
* zip 2 -> 8, quick-xml 0.37 -> 0.40, toml 0.8 -> 1
* windows 0.58 -> 0.62, winreg 0.52 -> 0.56
* RustCrypto: aes 0.8 -> 0.9, cbc 0.1 -> 0.2, sha1/sha2 0.10 -> 0.11,
  md-5 0.10 -> 0.11, ctr 0.9 -> 0.10, hmac 0.12 -> 0.13, pbkdf2 0.12 -> 0.13

Code migrations:
* quick-xml 0.40: BytesText::unescape() -> xml10_content();
  Attribute::unescape_value() -> normalized_value(XmlVersion::Implicit1_0)
* windows 0.62: LocalFree now takes Option<HLOCAL>
* cipher 0.5 (aes 0.9 / cbc 0.2): BlockEncryptMut/BlockDecryptMut ->
  BlockModeEncrypt/BlockModeDecrypt; encrypt_padded_mut/decrypt_padded_mut ->
  encrypt_padded/decrypt_padded

Held back deliberately: rand stays 0.8 because the latest rsa (0.9) still needs
an rand_core 0.6 RNG for keygen, which rand 0.9+ no longer provides. rsa pinning
the older RustCrypto generation also leaves a couple of duplicate transitive
versions (digest 0.10/0.11, crypto-common 0.1/0.2) — harmless.

Verified: 46 tests pass, clippy + rustfmt clean, and a real ADEPT EPUB still
decrypts end-to-end (DPAPI key extraction + RSA/AES) to a valid DRM-free file.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 20:27:43 -05:00
JMR-devandClaude Opus 4.8 2dcfcf5631 Add Windows Adobe key auto-extraction (phase 3, part 1)
On Windows, recover the Adobe ADEPT user key from an installed/activated
Adobe Digital Editions and use it automatically, so ADEPT EPUBs decrypt
with no --key argument. Ported from adobekey.py:

* Build the DPAPI entropy byte-for-byte: system-volume serial number,
  CPUID leaf-0 vendor (EBX|EDX|ECX) and leaf-1 signature, and the ADE
  username, packed as ">I12s3s13s".
* CryptUnprotectData (DPAPI) recovers the key-encryption-key from the
  HKCU\Software\Adobe\Adept\Device "key" value, then each per-credential
  privateLicenseKey under ...\Activation is AES-128-CBC decrypted and the
  DER RSA key taken from byte 26 onward.

Decryption now lazily auto-extracts and retries when no supplied key fits,
and newly found keys are written back to the TOML config so later runs are
offline. Uses the `windows` (DPAPI/volume info) and `winreg` crates behind
cfg(windows); pure-Rust crypto unchanged.

Verified end-to-end on a real ADEPT EPUB: the key was extracted from the
local ADE and the book decrypted to a valid, DRM-free EPUB (rights.xml and
encryption.xml removed, content readable).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 18:48:37 -05:00
JMR-devandClaude Opus 4.8 409473b8f3 Initial release: ADEPT EPUB and Kindle MOBI DRM removal (phases 0-2)
DRMLibre is a standalone, single-binary Rust CLI that removes DRM from
Amazon Kindle and Adobe Digital Editions ebooks. The decryption logic is
ported from DeDRM_tools (GPLv3); this project is GPL-3.0-or-later.

This commit covers the first three milestones of the plan:

* Phase 0 - workspace scaffold (drmlibre-core engine + drmlibre-cli),
  native TOML config, magic-byte/zip-content format detection, and the
  remove/passhash/config CLI surface with atomic output handling.
* Phase 1 - Adobe ADEPT EPUB: RSA (PKCS#1 v1.5) and PassHash book-key
  unwrap, RMSDK>=10 hardening, AES-128-CBC content decryption, and IETF/
  Adobe font de-obfuscation. Verified end-to-end with a real RSA key.
* Phase 2 - Kindle MOBI/AZW/AZW3: PC1 cipher, type-1 and type-2 DRM,
  serial->PID derivation, EXTH header patches, and trailing-data handling.
  Verified end-to-end and against the upstream golden vectors.

All crypto is pure Rust (RustCrypto), so the release binary has no
third-party runtime dependencies. 42 tests pass; clippy and rustfmt clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 18:38:03 -05:00