Files
DRMLibre/crates
JMR-devandClaude Opus 4.8 01334d31d0 Fix panic-on-malformed-input defects found in code review
Harden the decryptors against corrupt/edge-case input so a single bad file
errors cleanly instead of panicking (and, in a batch, aborting the whole run):

* ADEPT EPUB: the content-decrypt guard was `len < 16` but then sliced off the
  16-byte pad block before reading the trailing pad length; a one-block (16-byte)
  ciphertext left an empty slice and panicked on `.last().unwrap()`. Guard is
  now `len <= 16`.
* MOBI: validate the section table before indexing it — require >= 2 sections
  and reject a record count that exceeds the section count, preventing
  out-of-bounds panics on `section_offsets[1]` / `section_bounds(i)`.
* MOBI: `trailing_size` now uses saturating/checked subtraction, and the caller
  clamps the trailing size to the record length, so a corrupt trailing-size
  encoding can't underflow.
* MOBI: `normalize_pids` slices PIDs by characters, not bytes, so a non-ASCII
  `--pid` can't panic on a non-char-boundary.
* CLI: wrap the per-file decrypt in `catch_unwind` so any future panic is
  contained to that file rather than aborting a multi-file run.

Adds 5 regression tests (one per fix). 46 lib tests pass; clippy + fmt clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 19:57:52 -05:00
..