Commit Graph
4 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 15592b84c8 Make legacy-cgi a runtime dependency
erdr2pml (eReader/.pdb support) imports the stdlib `cgi` module at
runtime, which was removed in Python 3.13. Having legacy-cgi only in the
dev group meant eReader decryption would break on a 3.13+ runtime that
installed just the main dependencies. Move it to the main dependency
group, scoped with a `python >= 3.13` marker so it is installed only
where the stdlib module is gone (3.8-3.12 keep using the stdlib `cgi`).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:15:36 -05:00
JMR-devandClaude Opus 4.8 9b93b5b789 Add legacy-cgi dev dep and expand erdr2pml tests
erdr2pml imports the stdlib `cgi` module, removed in Python 3.13, so its
tests were skipped on modern interpreters. Add the `legacy-cgi` backport
as a dev dependency so the module imports, and flesh out its tests:
deXOR involution, fixKey known vector / length, cleanPML high-ASCII
escaping, and sanitizeFileName separator/colon/control-char/angle-bracket
handling. The skip guard is kept as a safety net for environments without
the backport.

Suite is now 44 passing, 0 skipped.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:13:26 -05:00
JMR-devandClaude Opus 4.8 ba96df081f Add pytest suite for both plugins
Add a pytest suite covering the pure logic of the DeDRM and Obok plugins.
Because the plugins normally run inside calibre and use intra-package
imports, tests/dedrm_test_utils.py sets up an import shim (plugin dirs on
sys.path, a minimal calibre stub, and a synthetic `dedrm` package) so the
modules can be imported and exercised standalone.

Coverage:
  - alfcrypto: PC1 and Topaz cipher round-trips, PBKDF2 vs hashlib.
  - kgenpids / kindlepid: PID encoding, bit-field extraction, device-PID
    and serial-PID known vectors, CRC32.
  - mobidedrm: PC1 round-trip, trailing-data sizing, bad-key handling.
  - ineptpdf / ineptepub: nunpack and PKCS7 unpad.
  - topazextract: encoded number/string parsing, plus a regression test
    that a malicious header tag ("../../evil") cannot escape the output
    directory (covers the path-traversal fix).
  - obok: unpad, hash-key table, SafeUnbuffered str/bytes handling.
  - utilities / argv_utils: uStrCmp normalisation, unicode_argv.
  - erdr2pml: deXOR/sanitiseFileName, skipped on Python 3.13+ where the
    module's `cgi` import is unavailable.

Run with `poetry install` then `poetry run pytest`. 36 pass, 2 skip on
Python 3.13+.

Note: this surfaced two dead-code modules that are broken on Python 3
(aescbc's pure-Python AES and kgenpids.decode, neither on a live path,
since the real crypto goes through pycryptodome); left as-is here.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:08:03 -05:00
JMR-devandClaude Opus 4.8 815c621f01 Manage dependencies with Poetry; drop abandoned pycrypto
Add a Poetry manifest (pyproject.toml) and lock file to manage the
development / standalone-CLI environment for the plugins. The plugins
themselves run inside calibre's bundled Python, so the project is set to
package-mode = false and the manifest documents the real third-party
dependency set rather than building a distributable package.

Declared dependencies:
  - pycryptodomex (>=3.20): maintained crypto library exposing the
    `Cryptodome` namespace that every crypto import already prefers. This
    replaces the abandoned pycrypto (unmaintained since 2014,
    CVE-2013-7459), which is no longer needed and is not declared.
  - lxml (>=5.0): EPUB/PDF/ADEPT XML handling.
  - apsw (>=3.46): optional `nook` group, only used by
    ignoblekeyWindowsStore.py for Nook Windows Store key extraction.

calibre/calibre_lzma/PyQt are supplied by the calibre runtime and the
Python <3.3 lzma fallbacks (backports.lzma, pylzma) are unnecessary on
the supported Python 3.8+ range, so none are declared.

Also update the stale PyCrypto install instructions in
ignoblekeyGenPassHash.py to point at the maintained pycryptodomex.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:27:43 -05:00