1.2.0: mux loss-concealment read path (P3/Edit-2, A2 NULL-TS fill)
Decrypt-verify is a RIP gate, not a MUX gate. On the mux read path an undecryptable content unit must never abort the mux: - DecryptingSectorSource gains tolerate_decrypt_loss(): when set, an undecryptable in-content unit is tallied, overwritten with valid NULL TS packets (PID 0x1FFF) via aacs::fill_null_ts_unit, logged loud with its LBA, and the read returns Ok — the stream keeps flowing. The rip paths keep the fail-loud DECRYPT_VERIFY_READ decorator (re-read off the disc); only the mux opts in. - Wire it into both mux read paths: the file-backed highway (build_iso_pipeline) and the inline DiscStream. - NULL-TS fill keeps the demuxer byte-synced on the 192-byte stride; the lost video/audio PID packets surface as a CC gap the TS assembler already drops a partial PES on (the B1 foundation). Ciphertext is never passed downstream either way. - Fix stale resolve_vid_only no-cert test: default is UHD (audit #4). Tests: conceal-as-NULL-TS, fill well-formedness, fail-loud still holds.
This commit is contained in:
+2
-2
@@ -45,8 +45,8 @@ pub use trace::{KeyNode, KeyOutcome, KeyStep, ResolutionTrace, UnlockOutcome, Un
|
||||
pub use decrypt::{
|
||||
ALIGNED_UNIT_LEN, ALIGNED_UNIT_SECTORS, UnitKeyResult, aacs_unit_encrypted,
|
||||
aacs_unit_needs_decrypt, decrypt_bus, decrypt_unit, decrypt_unit_checked, decrypt_unit_full,
|
||||
decrypt_unit_try_keys, is_unit_aligned, ts_packet_total, ts_sync_count, ts_sync_destroyed,
|
||||
unit_is_clean_ps, unit_is_clean_ts, unit_key_validates,
|
||||
decrypt_unit_try_keys, fill_null_ts_unit, is_unit_aligned, ts_packet_total, ts_sync_count,
|
||||
ts_sync_destroyed, unit_is_clean_ps, unit_is_clean_ts, unit_key_validates,
|
||||
};
|
||||
// `probe` is a reproduction-harness helper (see keys.rs), not part of the
|
||||
// documented 1.0 surface; keep it reachable but off the rendered docs so we
|
||||
|
||||
Reference in New Issue
Block a user