Bump the `rand` dev-dependency to the latest (0.10), which exposes rand_core
0.10, while the latest `rsa` (0.9) still requires an rand_core 0.6 RNG for key
generation. Bridge the skew with a small, test-only adapter instead of pinning
rand back.
* Add `rand_core_06 = { package = "rand_core", version = "0.6" }` so the shim
can implement the old traits (cargo unifies it with the rand_core 0.6 that
rsa already uses).
* `RandCompat<R>` wraps a modern RNG and re-implements rand_core 0.6's RngCore
+ CryptoRng over it, delegating to rand_core 0.10's infallible methods.
Implementing both satisfies rand_core 0.6's blanket CryptoRngCore impl, which
is exactly the bound rsa keygen requires.
* The CryptoRng bound is preserved (only wraps RNGs still marked
cryptographically secure), so the randomness is not weakened — it is purely a
trait-version shim. Tests now use `RandCompat(rand::rng())`.
46 tests pass (incl. the RSA-based EPUB roundtrips that exercise the shim);
clippy + rustfmt clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the floating `stable` channel with the exact current latest stable
(1.96.0, which also matches the crate's rust-version/MSRV) so builds are
reproducible and `clippy -D warnings` can't break from an unrelated toolchain
bump.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Update each action to its current latest release and pin to the full commit
SHA (supply-chain hardening), with the version in a trailing comment:
* actions/checkout v4 -> v7.0.0
* Swatinem/rust-cache v2 -> v2.9.1
* actions/upload-artifact v4 -> v7.0.1
* actions/download-artifact v4 -> v8.0.1
* softprops/action-gh-release v2 -> v3.0.1
* dtolnay/rust-toolchain pinned to master @ 2026-06-20 (no tagged
releases); add explicit `toolchain: stable` since the channel can no
longer be inferred from the @ref once pinned to a SHA.
Verified upload-artifact v7 (zips by default) and download-artifact v8
interoperate, and that every input still exists in the new majors.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* ci.yml: on pull requests to main, runs on windows-latest and macos-latest;
checks formatting, runs clippy (warnings denied), and runs the unit tests
(`cargo test --workspace`).
* release.yml: manual workflow_dispatch (tag + optional prerelease inputs);
builds release binaries for Windows (x86_64) and macOS (aarch64 + x86_64),
then publishes them to GitHub Releases with auto-generated notes.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Harden the decryptors against corrupt/edge-case input so a single bad file
errors cleanly instead of panicking (and, in a batch, aborting the whole run):
* ADEPT EPUB: the content-decrypt guard was `len < 16` but then sliced off the
16-byte pad block before reading the trailing pad length; a one-block (16-byte)
ciphertext left an empty slice and panicked on `.last().unwrap()`. Guard is
now `len <= 16`.
* MOBI: validate the section table before indexing it — require >= 2 sections
and reject a record count that exceeds the section count, preventing
out-of-bounds panics on `section_offsets[1]` / `section_bounds(i)`.
* MOBI: `trailing_size` now uses saturating/checked subtraction, and the caller
clamps the trailing size to the record length, so a corrupt trailing-size
encoding can't underflow.
* MOBI: `normalize_pids` slices PIDs by characters, not bytes, so a non-ASCII
`--pid` can't panic on a non-char-boundary.
* CLI: wrap the per-file decrypt in `catch_unwind` so any future panic is
contained to that file rather than aborting a multi-file run.
Adds 5 regression tests (one per fix). 46 lib tests pass; clippy + fmt clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>