Deduplicate PID/unpad helpers and generalize the Topaz path fix

Move the copies of unpad, crc32, checksumPid and pidFromSerial that were
scattered across the plugin into utilities.py, and add a shared safe_join
that generalizes the Topaz extraction path-traversal fix.

- unpad: adobekey, ineptepub and ineptpdf import the shared helper. The
  four bare-script key tools keep their local copies since they run
  without a package context.
- checksumPid is type-preserving (bytes for kgenpids/kindlepid, str for
  mobidedrm) so every call site keeps its exact behavior.
- kgenpids falls back to an absolute import because it is imported
  top-level by the worker modules.
- topazextract.extractFiles uses safe_join; genbook is unchanged as it
  only handles already-sanitized names.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-24 09:17:48 -05:00
co-authored by Claude Opus 4.8
parent 1ca134f5c3
commit bb96fe90ac
8 changed files with 101 additions and 126 deletions
+1 -23
View File
@@ -78,14 +78,13 @@ __version__ = "1.1"
import sys
import os
import struct
import binascii
#@@CALIBRE_COMPAT_CODE@@
from .alfcrypto import Pukall_Cipher
from .utilities import SafeUnbuffered
from .utilities import SafeUnbuffered, checksumPid
from .argv_utils import unicode_argv
@@ -105,27 +104,6 @@ def PC1(key, src, decryption=True):
except:
raise
letters = b'ABCDEFGHIJKLMNPQRSTUVWXYZ123456789'
def crc32(s):
return (~binascii.crc32(s,-1))&0xFFFFFFFF
def checksumPid(s):
s = s.encode()
crc = crc32(s)
crc = crc ^ (crc >> 16)
res = s
l = len(letters)
for i in (0,1):
b = crc & 0xff
pos = (b // l) ^ (b % l)
res += bytes(bytearray([letters[pos%l]]))
crc >>= 8
return res.decode()
# expects bytearray
def getSizeOfTrailingDataEntries(ptr, size, flags):
def getSizeOfTrailingDataEntry(ptr, size):