Commit Graph
235 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 1ca134f5c3 Remove dead pure-Python AES implementation
aescbc.py provided a pure-Python Rijndael/AES-CBC fallback consumed only
by alfcrypto.AES_CBC, whose sole caller (kindlekey's macOS
CryptUnprotectData) never assigns self.crp and so raised AttributeError
before reaching it. The live crypto path uses Cryptodome, so delete the
dead module and the unused wrapper.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 09:17:37 -05:00
JMR-devandClaude Opus 4.8 ae2231727f Fix Python 3 correctness bugs found in code review
Fix str/bytes and leftover-py2 defects across the plugin, several on live
decryption paths:

  - erdr2pml.py: getText() footnote/sidebar handling mixed a bytes
    accumulator with str literals and called ord() on a bytes element,
    crashing on eReader/.pdb books that contain footnotes or sidebars.
  - ion.py: readdecimal() did `[ord(x) for x in self.read(...)]` over
    bytes (ord(int)), crashing KFX decryption on Ion DECIMAL values;
    printlob() had the same ord()-over-bytes in its debug path.
  - zipfilerugged.py: `isinstance(file, unicode)` raised NameError when a
    file-like object (not a path string) was passed to the ZipFile.
  - utilities.py: SafeUnbuffered.write referenced the undefined `unicode`
    (same fix already applied to the obok copy).
  - ineptpdf.py: ord(bookkey[0]) over an int in an error-diagnostic print.
  - epubfontdecrypt.py: removed a dead py2 itertools.izip fallback.
  - convert2xml.py: escapestr did bytes.replace(str, ...).
  - kgenpids.py: decode() built a str result then += bytes.

Cleanups from the earlier shim removal: drop now-unused `import sys`
(alfcrypto, utilities, kgenpids); unicode_argv returns list(sys.argv) so
callers can't mutate the process-global sys.argv.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:35:11 -05:00
JMR-devandClaude Opus 4.8 38dedea32b Fix invalid string escape sequences
Python 3.12+ emits SyntaxWarning for unrecognised backslash escapes (and
these will eventually become SyntaxErrors). Convert the affected string
literals to raw strings so the escapes are explicit:

  - scriptinterface.py: filename filter regexes (\.der, \.b64, ...).
  - obok.py: MAC-address detection regexes (\s, \-) and the title
    sanitiser ([^\s\w]).
  - flatxml2svg.py: the emitted JavaScript snippet contains \? and \d but
    also a trailing newline, so the regex part is made a raw string and
    the "\n" is concatenated separately.

All changes are value-preserving (an unrecognised escape already evaluated
to the backslash plus the character); verified the emitted JS string and
the compiled regexes are unchanged, and that both plugins now compile with
zero SyntaxWarnings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 19:52:56 -05:00
JMR-devandClaude Opus 4.8 838700fbec Remove Python 2 compatibility shims
The plugins target calibre 5/6 (Python 3) and the Poetry environment
pins Python >=3.8, so the Python 2 fallbacks are dead code. This removes
them throughout both plugins (behaviour on Python 3 is unchanged):

  - Drop all `from __future__` imports.
  - Collapse `if sys.version_info[0] == 2: ... else: ...` blocks to their
    Python 3 branch (ineptpdf, mobidedrm, kindlekey, kgenpids, alfcrypto,
    erdr2pml, ineptepub, obok, and the various unpad() helpers, etc.).
  - Replace `_winreg` import fallbacks with plain `import winreg`, and
    delete the py2-only adobekey_winreg_unicode module (now unreferenced).
  - Drop py2 name shims: `unicode`/`unichr`, `.iteritems()`,
    `from StringIO import StringIO`, `htmlentitydefs` fallback, and the
    Windows CommandLineToArgvW dance in unicode_argv (py3 sys.argv is
    already Unicode on every platform).
  - Remove the "Calibre < 5" (py2) bugfix block from the compat header.

Verified: every .py file in both plugins still byte-compiles.

Scope: the maintained DeDRM_plugin and Obok_plugin only. The archival
standalone scripts under Other_Tools/ are left as historical snapshots.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:42:33 -05:00
JMR-devandClaude Opus 4.8 815c621f01 Manage dependencies with Poetry; drop abandoned pycrypto
Add a Poetry manifest (pyproject.toml) and lock file to manage the
development / standalone-CLI environment for the plugins. The plugins
themselves run inside calibre's bundled Python, so the project is set to
package-mode = false and the manifest documents the real third-party
dependency set rather than building a distributable package.

Declared dependencies:
  - pycryptodomex (>=3.20): maintained crypto library exposing the
    `Cryptodome` namespace that every crypto import already prefers. This
    replaces the abandoned pycrypto (unmaintained since 2014,
    CVE-2013-7459), which is no longer needed and is not declared.
  - lxml (>=5.0): EPUB/PDF/ADEPT XML handling.
  - apsw (>=3.46): optional `nook` group, only used by
    ignoblekeyWindowsStore.py for Nook Windows Store key extraction.

calibre/calibre_lzma/PyQt are supplied by the calibre runtime and the
Python <3.3 lzma fallbacks (backports.lzma, pylzma) are unnecessary on
the supported Python 3.8+ range, so none are declared.

Also update the stale PyCrypto install instructions in
ignoblekeyGenPassHash.py to point at the maintained pycryptodomex.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:27:43 -05:00
JMR-devandClaude Opus 4.8 768d49094c Fix path traversal in Topaz extraction (arbitrary file write)
The Topaz header record "tag" is read verbatim from the untrusted book
file by bookReadString() and then used unsanitized to build the output
filename in extractFiles(). A crafted tag such as "../../foo" let a
malicious .azw/Topaz file write attacker-controlled bytes outside the
extraction directory. The payload content requires no book key, since an
unencrypted record with compressedLength == 0 is returned raw.

Strip the record name to its basename before joining it to destdir so
traversal sequences (../, /, \) can no longer escape, and add an
abspath-based containment check as defense in depth.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:21:42 -05:00
NoDRM 7379b45319 Remove future import from ion.py 2024-11-10 20:15:33 +01:00
NoDRM bde82fd7ab Fix python2 support for ion.py 2024-11-10 16:10:29 +01:00
NoDRM de3d91f5e5 Don't repack EPUB if nothing has changed 2024-11-10 15:21:09 +01:00
NoDRM c5ee327a60 Add note about key import/export for K4PC in the help file (fixes #663) 2024-11-10 14:44:57 +01:00
NoDRM 815d86efe0 Update changelog 2024-11-10 14:36:27 +01:00
Ben Combee 05fff5217b Fix crash using bare sha1 symbol
Use sha1 from hashlib, as it isn't imported globally, fixed crash trying to decrypt a eReader PDB file
2024-11-10 13:10:11 +00:00
Martin Rys 34c4c067e8 DeDRM ion: Correctly throw last exception if decrypt fails 2024-11-10 13:09:45 +00:00
Martin Rys 195ea69537 DeDRM ion: Clean out errorneous whitespace and UTF8 definition from python 2 times 2024-11-10 13:09:45 +00:00
NoDRM bf2471e65b Update kfxdedrm as suggested in #440 2023-12-21 12:35:11 +01:00
NoDRM 5492dcdbf4 More FileOpen fixes 2023-12-21 11:57:39 +01:00
NoDRM 737d5e7f1e Bunch of updates for the FileOpen script 2023-12-03 10:45:09 +01:00
NoDRM e4e5808894 Fix file lock issue in androidkindlekey.py 2023-12-03 10:42:41 +01:00
NoDRM ef67dbd204 Fix more Py2/Py3 stuff 2023-08-06 15:49:52 +02:00
NoDRM 10b6caf9f5 Enable autorelease into 2nd repo 2023-08-03 21:53:16 +02:00
NoDRM 53996cf49c More Python2 fixes 2023-08-03 20:45:06 +02:00
NoDRM d388ae72fd More Py2 fixes 2023-08-03 20:14:33 +02:00
NoDRM bc089ee46d More Python2 bugfixes 2023-08-03 20:01:38 +02:00
NoDRM e509b7d520 Fix python2 issues in kgenpids and kindlekey 2023-08-03 11:26:05 +02:00
NoDRM e82d2b5c9c Fix PDF decryption for 256-bit AES with V=5 2023-08-02 18:13:42 +02:00
NoDRM 7f6dd84389 Fix PDF decryption of ancient 40-bit RC4 with R=2 2023-08-02 16:55:41 +02:00
NoDRM b9bad26d4b Prepare release candidate v10.0.9 2023-08-02 07:39:35 +02:00
NoDRM 2a1413297e Add warning to the standalone code 2023-08-02 07:30:39 +02:00
Satsuoni abc5de018e Added several more scramble functions to Kindle decrypt 2023-06-25 16:38:55 +02:00
NoDRMandSatsuoni 133e67fa03 Added fix for padding being correct on accident
Co-authored-by: Satsuoni <satsuoni@hotmail.com>
2023-06-25 16:27:31 +02:00
NoDRM f86cff285b Fix python2 issues in Kindle and Nook code (#355) 2023-06-24 09:53:55 +02:00
NoDRM a553a71f45 Fix font decryption with multiple IDs (#347) 2023-06-23 19:44:24 +02:00
740b46546f Try to add support for new K4PC
Co-authored-by: Andrew Innes <andrew.c12@gmail.com>
Co-authored-by: Satsuoni <satsuoni@hotmail.com>
2023-06-23 19:30:06 +02:00
NoDRM fb8b003444 Support for Adobe's 'aes128-cbc-uncompressed' encryption (see #242) 2023-01-06 14:32:25 +01:00
NoDRM 3c12806f38 Fix issue with remaining data in encryption.xml 2023-01-06 14:29:56 +01:00
NoDRM a711954323 PDF: Ignore invalid objid in non-strict mode, fixes #233 2022-12-29 19:52:08 +01:00
NoDRM a30405bebf Fix Python3 bug in stylexml2css.py, fixes #232 2022-12-23 10:44:45 +01:00
NoDRM 901a6c091d Fix exception in error logging in ineptpdf 2022-12-23 10:42:25 +01:00
NoDRM 06df18bea3 Strip whitespace from Kindle serials (#158) 2022-10-19 16:39:39 +02:00
NoDRM 06648eeb1c Add support for empty arrays (<>) in PDF objects. Fixes #183. 2022-10-17 17:13:41 +02:00
NoDRM eb45c71fd9 Cleanup 2022-09-10 11:44:55 +02:00
NoDRM 2d4c5d2c4b Fix key import sometimes generating corrupted keys.
Should fix #145, #134, #119, #116, #115, #109 and maybe others.
2022-09-10 11:42:59 +02:00
NoDRM 88b0966961 Fix tons of PDF-related issues 2022-08-07 15:58:01 +02:00
NoDRM 52cf3faa59 Fix DeACSM import for PDF files 2022-08-07 09:31:49 +02:00
NoDRM b12e567c5f Cleanup / SafeUnbuffered bugfix 2022-08-07 09:30:24 +02:00
NoDRM ca6d30b2d9 More stuff I missed 2022-08-06 20:25:07 +02:00
NoDRM dfa247bf88 Cleanup 2022-08-06 20:19:36 +02:00
NoDRM a0bb84fbfc Move unicode_argv to its own file 2022-08-06 20:19:18 +02:00
NoDRM 410e086d08 Remove AlfCrypto libraries and perform everything in Python
The old AlfCrypto DLL, SO and DYLIB files are ancient,
I don't have the systems to recompile them all, they
cause issues on ARM Macs, and I doubt with all the Python
improvements over the last years that they have a significant
performance advantage. And even if that's the case, nobody is
importing hundreds of DRM books at the same time so it shouldn't
hurt if some decryptions might take a bit longer.
2022-08-06 20:13:19 +02:00
NoDRM de23b5c221 Move SafeUnbuffered to own Python file 2022-08-06 20:09:30 +02:00