Commit Graph
3 Commits
Author SHA1 Message Date
JMR-devandClaude Opus 4.8 d407298be4 Update tests for shared helpers and fix test nits
- Cover the new utilities helpers (unpad, crc32, checksumPid type
  preservation, pidFromSerial, safe_join) and drop the now-redundant
  per-module crc32 tests.
- Rename test_unpad_removes_pkcs7_padding to reflect that unpad only
  trusts the trailing pad-length byte rather than validating PKCS#7.
- Replace the KOBO_HASH_KEYS change-detector with a test that documents
  the intentional value pin and checks the ASCII-salt contract.
- Note kgenpids' hybrid import in the test-loader docstring.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-24 09:18:01 -05:00
JMR-devandClaude Opus 4.8 d6418996dd Harden tests flagged in code review
Strengthen weak-assertion / false-confidence tests:

  - test_alfcrypto: replace the tautological ctx_init determinism check
    with an independent golden vector, and add a golden Topaz decrypt
    vector that does not rely on the test's own inverse helper (so a
    systematic cipher bug is caught, not just round-trip symmetry). Pin
    the PC1 bad-key assertion to match="Bad key length", and load
    alfcrypto via the dedrm package so the test exercises the same module
    object that topazextract/mobidedrm import.
  - test_mobidedrm: pin the PC1 bad-key assertion to the guard message.
  - test_topazextract: make the path-traversal regression rely on the
    depth-independent positive oracle (the sanitised file must land inside
    outdir, which fails against the pre-fix code) plus an exact-contents
    check, instead of brittle parent-path negatives.
  - test_erdr2pml: narrow the import skip to only the missing-cgi case so
    a genuinely broken module fails loudly instead of silently skipping.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:35:21 -05:00
JMR-devandClaude Opus 4.8 ba96df081f Add pytest suite for both plugins
Add a pytest suite covering the pure logic of the DeDRM and Obok plugins.
Because the plugins normally run inside calibre and use intra-package
imports, tests/dedrm_test_utils.py sets up an import shim (plugin dirs on
sys.path, a minimal calibre stub, and a synthetic `dedrm` package) so the
modules can be imported and exercised standalone.

Coverage:
  - alfcrypto: PC1 and Topaz cipher round-trips, PBKDF2 vs hashlib.
  - kgenpids / kindlepid: PID encoding, bit-field extraction, device-PID
    and serial-PID known vectors, CRC32.
  - mobidedrm: PC1 round-trip, trailing-data sizing, bad-key handling.
  - ineptpdf / ineptepub: nunpack and PKCS7 unpad.
  - topazextract: encoded number/string parsing, plus a regression test
    that a malicious header tag ("../../evil") cannot escape the output
    directory (covers the path-traversal fix).
  - obok: unpad, hash-key table, SafeUnbuffered str/bytes handling.
  - utilities / argv_utils: uStrCmp normalisation, unicode_argv.
  - erdr2pml: deXOR/sanitiseFileName, skipped on Python 3.13+ where the
    module's `cgi` import is unavailable.

Run with `poetry install` then `poetry run pytest`. 36 pass, 2 skip on
Python 3.13+.

Note: this surfaced two dead-code modules that are broken on Python 3
(aescbc's pure-Python AES and kgenpids.decode, neither on a live path,
since the real crypto goes through pycryptodome); left as-is here.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 20:08:03 -05:00