JMR-devandClaude Opus 4.8 01334d31d0 Fix panic-on-malformed-input defects found in code review
Harden the decryptors against corrupt/edge-case input so a single bad file
errors cleanly instead of panicking (and, in a batch, aborting the whole run):

* ADEPT EPUB: the content-decrypt guard was `len < 16` but then sliced off the
  16-byte pad block before reading the trailing pad length; a one-block (16-byte)
  ciphertext left an empty slice and panicked on `.last().unwrap()`. Guard is
  now `len <= 16`.
* MOBI: validate the section table before indexing it — require >= 2 sections
  and reject a record count that exceeds the section count, preventing
  out-of-bounds panics on `section_offsets[1]` / `section_bounds(i)`.
* MOBI: `trailing_size` now uses saturating/checked subtraction, and the caller
  clamps the trailing size to the record length, so a corrupt trailing-size
  encoding can't underflow.
* MOBI: `normalize_pids` slices PIDs by characters, not bytes, so a non-ASCII
  `--pid` can't panic on a non-char-boundary.
* CLI: wrap the per-file decrypt in `catch_unwind` so any future panic is
  contained to that file rather than aborting a multi-file run.

Adds 5 regression tests (one per fix). 46 lib tests pass; clippy + fmt clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 19:57:52 -05:00

DRMLibre

A standalone, single-binary command-line tool (written in Rust, no runtime dependencies) for removing DRM from Amazon Kindle and Adobe Digital Editions ebooks. The decryption logic is ported from DeDRM_tools; DRMLibre is therefore licensed GPL-3.0-or-later. See CREDITS.md.

Use DRMLibre only on books you own, to exercise your own rights (format shifting, backup, accessibility). Respect the law in your jurisdiction.

Status

Under active development. Supported / planned formats:

Capability Status
Adobe ADEPT EPUB (+ hardening, B&N PassHash, font de-obfuscation) ✅ done
Kindle MOBI / AZW / AZW3 ✅ done
Adobe key auto-extraction from installed ADE (Windows, DPAPI) ✅ done
Kindle-for-PC key (.kinf) / Android / macOS auto-extraction planned
Kindle KFX-ZIP planned
Adobe PDF, Kindle Topaz, eReader, Kobo, LCP out of scope

On Windows with Adobe Digital Editions activated, ADEPT EPUBs decrypt with no extra arguments — the key is extracted from the local install and cached in the config for later offline use.

Usage

drmlibre remove <files...> [options]   # remove DRM
drmlibre passhash ...                   # generate/extract Adobe/B&N PassHashes
drmlibre config                         # summarize keys in the config file

Common remove options: -o/--output, --outputdir, -f/--force, --overwrite, --serial, --pid, --key, --passphrase, --android-backup, --config (default ./drmlibre.toml).

Examples:

# Adobe EPUB, using an exported Adobe key:
drmlibre remove "My Book.epub" --key adobe.der -o "My Book (no DRM).epub"

# Kindle eInk book, using the device serial:
drmlibre remove "My Book.azw" --serial 0123456789ABCDEF

Architecture

A Cargo workspace:

  • crates/drmlibre-core — the UI-agnostic engine (format detection, key management, decryptors). No printing or process exits; everything is a Result and progress goes through tracing. This is what a future GUI links.
  • crates/drmlibre-cli — the drmlibre binary (argument parsing, file I/O policy, exit codes).

Building

cargo build --release      # binary at target/release/drmlibre
cargo test                 # run the test suite
S
Description
Standalone single-binary Rust CLI to remove DRM from Amazon Kindle and Adobe Digital Editions ebooks (GPLv3).
Readme GPL-3.0
130 KiB
Languages
Rust 100%