0.27.5 (step 2, Phase 1): expose AACS inputs (uk_ro, mkb) on AacsState

scan now stashes the raw Unit_Key_RO.inf + MKB bytes on AacsState (via
resolve_vid_only, the disable_keydb path), so an external key-resolver can
derive unit keys from a resolved VUK without re-reading the disc — the
foundation for moving lookup/derivation out of libfreemkv. Additive: the keydb
path is untouched, all existing constructors default the new fields empty.
584 lib tests green. Builds on the KeyOrigin rename + the Key/decrypt_with API.
This commit is contained in:
MattJackson
2026-06-04 13:20:27 -07:00
parent d94a4d3444
commit 8bc1de6c9b
3 changed files with 22 additions and 5 deletions
+9 -3
View File
@@ -465,6 +465,8 @@ impl Disc {
unit_keys: resolved.unit_keys,
read_data_key,
volume_id,
uk_ro: Vec::new(),
mkb: Vec::new(),
})
}
@@ -527,6 +529,8 @@ impl Disc {
unit_keys: vec![(1, unit_key)],
read_data_key: handshake.and_then(|h| h.read_data_key),
volume_id: handshake.map(|h| h.volume_id).unwrap_or([0u8; 16]),
uk_ro: Vec::new(),
mkb: Vec::new(),
})
}
@@ -563,12 +567,12 @@ impl Disc {
None => 1,
};
// MKB_RO is the correctly-sized copy; avoid reading the padded RW region.
let mkb_ver = udf_fs
let mkb_bytes = udf_fs
.read_file(reader, "/AACS/MKB_RO.inf")
.or_else(|_| udf_fs.read_file(reader, "/AACS/MKB_RW.inf"))
.ok()
.as_deref()
.and_then(aacs::mkb_version);
.unwrap_or_default();
let mkb_ver = aacs::mkb_version(&mkb_bytes);
tracing::warn!(
target: "freemkv::disc",
@@ -590,6 +594,8 @@ impl Disc {
unit_keys: vec![],
read_data_key: handshake.and_then(|h| h.read_data_key),
volume_id: handshake.map(|h| h.volume_id).unwrap_or([0u8; 16]),
uk_ro: uk_ro_data,
mkb: mkb_bytes,
})
}
}
+12 -1
View File
@@ -893,6 +893,13 @@ pub struct AacsState {
pub read_data_key: Option<[u8; 16]>,
/// Volume ID (16 bytes) -- from SCSI handshake
pub volume_id: [u8; 16],
/// Raw `Unit_Key_RO.inf` bytes (encrypted unit keys + CPS map). Stashed at
/// scan so an external resolver (key-resolver) can derive the unit keys
/// from a VUK without re-reading the disc. Empty when not captured.
pub uk_ro: Vec<u8>,
/// Raw MKB bytes (`MKB_RO.inf`). Stashed at scan so an external resolver can
/// walk it (device/processing key → media key). Empty when not captured.
pub mkb: Vec<u8>,
}
/// How AACS keys were resolved. Variants are ordered root-of-trust →
@@ -1555,7 +1562,9 @@ impl Disc {
unit_keys: keys,
read_data_key: None,
volume_id: [0u8; 16],
});
uk_ro: Vec::new(),
mkb: Vec::new(),
});
// The prior resolution error (e.g. KeydbLoad) is now moot — we have
// the decryption key. Clear it so callers don't treat the disc as
// keyless on the stale error.
@@ -2833,6 +2842,8 @@ mod tests {
unit_keys,
read_data_key: None,
volume_id: [0u8; 16],
uk_ro: Vec::new(),
mkb: Vec::new(),
}
}