Extract drive unlock behind pluggable Unlocker seam
libfreemkv must stay firmware-clean for crates.io. Move ALL drive-unlock
knowledge — firmware blobs, WRITE_BUFFER/MODE SELECT upload, unlock CDBs,
the MT1959 variant-A/B handshake, the 800 KB profiles.json database, and
the DriveProfile parsing — out into the freemkv-unlock-ld crate.
libfreemkv now keeps only the seam:
- Unlocker trait (name/matches/unlock) + a process-wide ordered registry
(register_unlocker / route_unlock) in src/unlock.rs
- Drive::init() walks the registry; the first unlocker whose matches(id)
is true runs unlock(scsi, id); if none match the drive is left in
stock mode and the host-cert AACS handshake (the OEM route) carries
the disc.
The unlocker issues its own CDBs through the public ScsiTransport::execute,
so libfreemkv knows nothing about how unlocking happens.
Removed:
- profiles.json
- src/platform/mt1959/{mod,variant_a,variant_b}.rs
- src/profile.rs (DriveProfile, ProfilesFile, find_by_drive_id, ...)
- the PlatformDriver trait
Because the Unlocker seam reports only success/failure (no extended-access
marker), VID acquisition is now always via the cert-based handshake; the
per-drive OEM-VID-CDB shortcut and Drive::is_unlocked() (now const false)
are removed/neutralized. Disc-speed calibration moved into the unlocker's
unlock(); Drive::probe_disc() is a no-op.
git grep over src/ is firmware-blob/profiles/WRITE_BUFFER/mt1959-free.
All tests pass on Rust 1.86 (precommit green).
This commit is contained in:
+7
-8
@@ -1113,8 +1113,8 @@ impl KeyOrigin {
|
||||
|
||||
/// AACS host credentials for the live-drive authenticated handshake.
|
||||
///
|
||||
/// Optional and source-agnostic: an unlocked / LibreDrive drive uses the OEM
|
||||
/// Volume-ID path and needs none, and an ISO scan has no handshake at all. The
|
||||
/// Optional and source-agnostic: an ISO scan has no handshake at all, and a
|
||||
/// live drive without supplied credentials simply skips cert auth. The
|
||||
/// caller supplies the host cert(s) from wherever it likes — today the keydb's
|
||||
/// `host_certs()`, tomorrow a cert file or built-in. Decoupled from the key
|
||||
/// source: a locked drive needs the cert to unlock even when the decryption key
|
||||
@@ -1133,8 +1133,8 @@ pub struct DriveCredentials {
|
||||
/// authenticated handshake.
|
||||
#[derive(Default)]
|
||||
pub struct ScanOptions {
|
||||
/// Host credentials for the live-drive AACS handshake. `None` for an
|
||||
/// unlocked / LibreDrive drive (OEM Volume-ID path) and for ISO scans.
|
||||
/// Host credentials for the live-drive AACS handshake. `None` for ISO
|
||||
/// scans, or a live drive where cert auth should be skipped.
|
||||
pub credentials: Option<DriveCredentials>,
|
||||
/// Optional cooperative-cancellation token. When set, long scan-time
|
||||
/// loops (notably the CSS known-plaintext crack, which can scan up to
|
||||
@@ -1226,10 +1226,9 @@ impl Disc {
|
||||
/// The session must be open and unlocked (`Drive::open` handles this).
|
||||
/// All disc reads use standard READ(10) via UDF — no vendor SCSI commands.
|
||||
pub fn scan(session: &mut Drive, opts: &ScanOptions) -> Result<Self> {
|
||||
// AACS handshake (Blu-ray/UHD). Routes through Disc::read_vid,
|
||||
// which prefers the per-drive OEM CDB path when the drive is
|
||||
// in the extended-access state and falls back to cert-based
|
||||
// mutual auth otherwise.
|
||||
// AACS handshake (Blu-ray/UHD). Acquires the Volume ID via the
|
||||
// cert-based mutual-auth handshake (the OEM route); drive unlock
|
||||
// itself runs separately behind the pluggable `Unlocker` seam.
|
||||
tracing::info!(target: "freemkv::scan", "phase: AACS handshake");
|
||||
let (handshake, handshake_error) = Self::do_handshake(session, opts);
|
||||
tracing::info!(target: "freemkv::scan", handshake = handshake.is_some(), "phase: handshake done");
|
||||
|
||||
Reference in New Issue
Block a user