Commit Graph
16 Commits
Author SHA1 Message Date
Matthew Jackson 4f6029e4d4 1.3.2: carry UnitKey.variant_number (all sources emit 0)
Construct unit keys via UnitKey::new; ordinary content is variant 0. Inherits libfreemkv 1.3.2. No behaviour change.
2026-07-10 14:00:28 -07:00
Matthew Jackson d21857d92e test: use example.test placeholder host, not .invalid
leak-guard bans the .invalid TLD (grouped with private .internal/.local/etc);
example.test is the RFC 6761 reserved test TLD — equally unreachable, not on
the ban list — so the leak-guard CI check passes.
2026-07-10 08:52:57 -07:00
Matthew Jackson 3bc8969c5f keydb/online: resolve off aacs::derive + types, drop boil wrappers
leak-guard / leak-guard (push) Failing after 5s
libfreemkv deleted the aacs::boil veneer, so switch the resolve path to the
raw primitives: derive_media_key_from_{pk,dk}, derive_vuk, decrypt_unit_key
from aacs::derive, and the newtypes from aacs::types. Add a local uks_from_vuk
helper composing decrypt_unit_key. No behaviour change; fmt/clippy/test green
on Rust 1.86.
2026-07-05 12:09:50 -07:00
Matthew Jackson 34e2d3a0e8 1.2.0: route online/keydb hex parsing through libfreemkv::hex (one parser) 2026-06-28 22:12:07 -07:00
Matthew Jackson 4eb53b0c93 1.1.1: align online MKB cap with libfreemkv read cap (64 MiB) + log over-cap
The online source dropped any MKB over 10 MiB while libfreemkv's reader
captures up to 64 MiB — an MKB in that band was silently un-forwardable
(no key, no surfaced cause). Match the cap and log when it is exceeded.
2026-06-28 21:12:57 -07:00
Matthew Jackson 6805ad22d4 AACS: own keydb parser + 100% parse + get_uk derivation
- Relocate keydb.cfg parser into keydb_format.rs (libfreemkv no longer knows
  keydb); add 100% parse (mkb_version/volume_size/is_uhd, revoked_at_mkb) +
  helper API (get_uk/get_uks/get_vid/host_certs(mkb)).
- KeydbSource/OnlineSource/MultiSource -> get_uk(ctx); MultiSource host_certs
  union; KAT-proven derivation parity. NumberedUnitKey alias. clippy clean.
2026-06-26 12:19:24 -07:00
Matthew Jackson a287e165bd keysources: label() on keydb/online sources; neutral path in the XDG test 2026-06-23 09:09:06 -07:00
Matthew Jackson 6f164ca355 v1.0.0-rc.3.1: online key-service auth header + cross-OS keydb search paths (paths.rs) 2026-06-22 18:09:48 -07:00
Matthew Jackson bde416604e keysources: expose host certs through KeySource trait
- KeydbSource implements KeySource::host_certs(), delegating to the
  inherent host_certs() — surfaces the | HC | / | HC2 | certs already
  parsed from keydb.cfg by libfreemkv's parser, so the OEM cert route
  collects them across the keysource layer. No new parsing.
- OnlineSource::host_certs() is a no-op stub: returns empty with zero
  network access (no client fetch, no server endpoint). Online host-cert
  serving is deferred. TODO(owner) marker left in place.

Tests: trait host_certs returns the keydb HC row; empty when keydb
missing; online host_certs is an empty no-op without network.
2026-06-22 11:23:46 -07:00
Matthew Jackson 0139ba6f1b rc2: SSRF parity, bounded DNS, strict hex parse, over-cap MKB error signaling 2026-06-22 08:47:52 -07:00
Matthew Jackson 3957ac70c1 v1.0.0-rc.1
key sources (keydb/online/mapfile), overflow-safe LBA
2026-06-21 21:06:07 -07:00
MattJackson 68a2e51bf7 v0.30.0: OnlineSource forwards the disc title to the key service
OnlineSource::query() now includes the disc's volume_label (UDF/ISO volume id)
as a plain-text `title` field in the /decode POST, so the key service can build
a disc_hash → title catalog from real rips. Depends on libfreemkv 0.30.
2026-06-06 09:05:48 -07:00
MattJackson da5bd08d3f sources: stateful one-key-at-a-time providers, UK-first keydb, shared resolve loop
Each source implements next_key (a cursor over its candidates) instead of
returning them all at once. The keydb hands its per-disc candidates out
UK-first (UK > VK > MK > DK) so a stale/wrong VUK never pre-empts a good UK in
the same entry; online and mapfile are one-shot. MultiSource composes sources
in the caller's chosen order and resolve_and_apply drives the
next_key -> decrypt_with loop, stopping at the first key that decrypts.
read_sample_units moves here so the CLI and autorip share one content sampler.
2026-06-05 09:23:17 -07:00
MattJackson c6f1ec1fcc OnlineSource: minimal client; POST to the configured URL verbatim
Drop unused tracing dep. The endpoint URL is taken from config as-is, so a
change on the service side is a config change, not a code change.
2026-06-04 15:33:34 -07:00
MattJackson 0e65237ce7 OnlineSource::needs_samples() = true (validates against ciphertext) 2026-06-04 14:45:49 -07:00
MattJackson 681e7a0295 Add OnlineSource and MapfileSource
OnlineSource: the remote key-service client (moved out of autorip), posting the
disc's Unit_Key_RO.inf + MKB + Volume ID + encrypted content samples to the
service and returning the resolved unit key as a terminal Key::Unit candidate.
Kept out of libfreemkv so the library stays network-free. Source-internal
failures (unreachable / status / parse) are logged and surface as "no
candidate" so the next source is tried.

MapfileSource: reads a rip mapfile's persisted unit keys (the resume / deferred-
mux fast path) and offers them as a Key::Unit candidate. Keyed by mapfile path.

DiscInputs gained an app-populated `samples` field for sources that validate
against ciphertext server-side (OnlineSource); local sources ignore it.
2026-06-04 14:42:02 -07:00