Commit Graph
18 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 bb96fe90ac Deduplicate PID/unpad helpers and generalize the Topaz path fix
Move the copies of unpad, crc32, checksumPid and pidFromSerial that were
scattered across the plugin into utilities.py, and add a shared safe_join
that generalizes the Topaz extraction path-traversal fix.

- unpad: adobekey, ineptepub and ineptpdf import the shared helper. The
  four bare-script key tools keep their local copies since they run
  without a package context.
- checksumPid is type-preserving (bytes for kgenpids/kindlepid, str for
  mobidedrm) so every call site keeps its exact behavior.
- kgenpids falls back to an absolute import because it is imported
  top-level by the worker modules.
- topazextract.extractFiles uses safe_join; genbook is unchanged as it
  only handles already-sanitized names.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 09:17:48 -05:00
JMR-devandClaude Opus 4.8 838700fbec Remove Python 2 compatibility shims
The plugins target calibre 5/6 (Python 3) and the Poetry environment
pins Python >=3.8, so the Python 2 fallbacks are dead code. This removes
them throughout both plugins (behaviour on Python 3 is unchanged):

  - Drop all `from __future__` imports.
  - Collapse `if sys.version_info[0] == 2: ... else: ...` blocks to their
    Python 3 branch (ineptpdf, mobidedrm, kindlekey, kgenpids, alfcrypto,
    erdr2pml, ineptepub, obok, and the various unpad() helpers, etc.).
  - Replace `_winreg` import fallbacks with plain `import winreg`, and
    delete the py2-only adobekey_winreg_unicode module (now unreferenced).
  - Drop py2 name shims: `unicode`/`unichr`, `.iteritems()`,
    `from StringIO import StringIO`, `htmlentitydefs` fallback, and the
    Windows CommandLineToArgvW dance in unicode_argv (py3 sys.argv is
    already Unicode on every platform).
  - Remove the "Calibre < 5" (py2) bugfix block from the compat header.

Verified: every .py file in both plugins still byte-compiles.

Scope: the maintained DeDRM_plugin and Obok_plugin only. The archival
standalone scripts under Other_Tools/ are left as historical snapshots.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:42:33 -05:00
JMR-devandClaude Opus 4.8 768d49094c Fix path traversal in Topaz extraction (arbitrary file write)
The Topaz header record "tag" is read verbatim from the untrusted book
file by bookReadString() and then used unsanitized to build the output
filename in extractFiles(). A crafted tag such as "../../foo" let a
malicious .azw/Topaz file write attacker-controlled bytes outside the
extraction directory. The payload content requires no book key, since an
unencrypted record with compressedLength == 0 is returned raw.

Strip the record name to its basename before joining it to destdir so
traversal sequences (../, /, \) can no longer escape, and add an
abspath-based containment check as defense in depth.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:21:42 -05:00
NoDRM 53996cf49c More Python2 fixes 2023-08-03 20:45:06 +02:00
NoDRM f86cff285b Fix python2 issues in Kindle and Nook code (#355) 2023-06-24 09:53:55 +02:00
NoDRM a0bb84fbfc Move unicode_argv to its own file 2022-08-06 20:19:18 +02:00
NoDRM de23b5c221 Move SafeUnbuffered to own Python file 2022-08-06 20:09:30 +02:00
Aldo Bleeker 5ace15e912 Python 3 fixes 2021-12-29 12:18:06 +00:00
NoDRM b11aadcca6 Bugfixes in standalone code for Calibre < 5 / Python 2 2021-12-29 11:39:48 +01:00
NoDRM dbf4b54026 Begin work on standalone version
Now the plugin ZIP file (DeDRM_plugin.zip) can be run with a normal
Python interpreter as if it were a Python file (try
`python3 DeDRM_plugin.zip --help`). This way I can begin building a
standalone version (that can run without Calibre) without having to
duplicate a ton of code.
2021-12-29 09:26:29 +01:00
NoDRM 9c40b3ce5a Cleanup 2021-12-29 09:14:35 +01:00
NoDRM 90910ab106 Add back Python2 support (ADEPT) 2021-11-16 11:09:03 +01:00
Apprentice Harper 939cdbb0c9 More fixes for Amazon books, fixing identity checks, started on Topaz. 2020-10-16 13:58:59 +01:00
Apprentice Harper 781268e17e More general changes, and get mobidedrm and kindlekey to work on Mac. 2020-10-14 16:23:49 +01:00
Apprentice Harper e31752e334 Mostly Mac fixes. mobidedrm.py now works, and k4mobidedrm for at least some input. kindlekey.py should be working too. But lots more changes and testing to do. 2020-10-04 20:36:12 +01:00
Apprentice Harper de50a02af9 More generic 3.0 changes, to be tested. 2020-09-27 11:54:49 +01:00
Apprentice Harper afa4ac5716 Starting on Version 7.0 using the work done by others. Completely untested. I will be testing things, but I thought I'd get this base version up for others to give pull requests.
THIS IS ON THE MASTER BRANCH. The Master branch will be Python 3.0 from now on. While Python 2.7 support will not be deliberately broken, all efforts should now focus on Python 3.0 compatibility.

I can see a lot of work has been done. There's more to do. I've bumped the version number of everything I came across to the next major number for Python 3.0 compatibility indication.

Thanks everyone. I hope to update here at least once a week until we have a stable 7.0 release for calibre 5.0
2020-09-26 21:22:47 +01:00
Apprentice Harper 92bf51bc8f Remove stand-alone apps. Only support the two plugins. 2020-02-16 10:12:25 +00:00