MattJackson
bac2e39ee5
AACS 100%: device key tree, MKB SCSI read, AACS2 detection, STN streams
...
- Device key subset-difference tree: aesg3 key derivation, v_mask calc,
tree traversal from device key to processing key to media key
- MKB SCSI read: REPORT DISC STRUCTURE 0x83 with multi-pack support
- resolve_keys now has 4 paths:
1. disc hash → KEYDB → VUK
2. KEYDB media key + VID → VUK
3. MKB + processing keys → media key → VUK
4. MKB + device keys → processing key → media key → VUK
- setup_aacs reads MKB from drive (not just from file)
- AACS 2.0 detection: drive cert type 0x11 detected, falls back to
AACS 1.0 handshake (P-256 crypto path prepared but not yet built)
- STN table parsing in mpls.rs: video format/rate, audio format/rate/lang,
subtitle lang, coding type — all streamed into Disc title streams
- 31 tests passing
2026-04-07 11:19:34 -07:00
MattJackson
9825db82aa
AACS complete: Unit_Key_RO.inf parser, disc hash, MKB processing, resolve chain
...
- Unit_Key_RO.inf: proper parser matching libaacs format (uk_pos, stride,
AACS1 48-byte / AACS2 64-byte key spacing, title→CPS unit mapping)
- Disc hash: SHA1 of Unit_Key_RO.inf for KEYDB lookup
- MKB processing: processing keys + subdiff records + cvalues → media key
(verify media key record with 12-byte zero check)
- Content Certificate parser: detect AACS version + bus encryption flag
- resolve_keys(): full 3-path chain:
1. disc hash → KEYDB → VUK (fast, 99% of discs)
2. KEYDB media key + VID → VUK
3. MKB + processing keys → media key → VUK
- setup_aacs() now reads Unit_Key_RO.inf + Content Cert from disc via UDF
- 31 tests passing
2026-04-07 11:13:20 -07:00
MattJackson
985d00f0a4
AACS 2.0 full pipeline: handshake, bus key, decrypt, transparent API
...
- aacs.rs: content decryption (AES-CBC aligned units, bus decrypt, VUK
derivation, unit key decrypt). 11 tests including synthetic roundtrip.
- aacs_handshake.rs: SCSI authentication (ECDH on AACS 160-bit curve,
ECDSA sign/verify, AES-CMAC, bus key derivation, read_data_key).
14 tests including EC order, ECDH shared secret, cert verification.
- disc.rs: transparent API — Disc::scan() detects AACS, authenticates,
derives keys internally. ContentReader decrypts on the fly. App never
sees AACS details.
- error.rs: AacsError (E7000) variant
BF v12 complete: 284 unique matches from 8 AWS instances.
2026-04-06 20:40:52 -07:00
MattJackson
117a7823d6
Library disc API: Disc, Title, Stream with typed codec/hdr/color
...
Clean public API for disc scanning. CLI should only display,
never parse binary formats directly.
Disc::scan() → titles → streams with:
codec (Hevc/TrueHd/Ac3/Pgs/etc), pid, language,
resolution, frame_rate, channels, hdr, color_space,
secondary flag, label
2026-04-06 15:47:07 -07:00
MattJackson
7db4606038
Add disc format parsers: UDF, MPLS, CLPI
...
- udf.rs: read files from Blu-ray disc filesystem
- mpls.rs: parse playlists → titles with clips and timestamps
- clpi.rs: parse clip info → EP map with coarse/fine SPN entries
- disc.rs: high-level title scanning, sector extent mapping
- drive.rs: add read_disc() for unencrypted reads, scsi_execute()
- error.rs: add E6000 DiscError
Stage 1 of freemkv rip: identify titles and their sector ranges.
2026-04-06 14:27:48 -07:00