v5.0.0: version bump, audit fixes, documentation overhaul

Version bumped to 5.0.0 across include/zupt.h, all packaging recipes, man
page, and docs.

Audit fixes (pre-5.0.0 review):
- src/zupt_format.c: overflow-safe bound in the solid-mode `test` path
  (off+sz could wrap and drive an OOB read in zupt_xxh64 on a crafted archive;
  the extract path was already hardened, the test path was not).
- gui: run_async now marshals the completion callback onto the GUI thread with
  QueuedConnection (a bare functor connected DirectConnection and touched
  widgets off the worker thread); Extract auto-detect note survives the log
  clear via a new `info` param.
- .github/workflows/ci.yml: trigger on `master` (was main/develop, so CI never
  ran); `make dist` tarball is vaptvupt-*.tar.gz not zupt-*; the ASAN PQ
  round-trip uses native --pq (was --pq-sdk, which fails on the source-only
  build and blocked the release job).

Documentation:
- New AUDIT.md (methodology, FIPS 203 conformance validation, findings, repro).
- CHANGELOG 5.0.0 entry covers the FIPS 203 conformance fix + BREAKING note and
  the GUI/CLI/security/packaging work.
- README "What's new in 5.0.0", download tables (incl. Windows/macOS/BSD +
  portable GUI), version-history row.
- SECURITY.md + THREAT_MODEL.md: ML-KEM-768 documented as FIPS 203, validated
  byte-for-byte against OpenSSL 3.5.
- Accuracy fixes: man page (--kdf default is PBKDF2 on source-only; codec
  2.60.4), rpm %description, debian control/copyright, homebrew header
  (no vendored library on source-only builds).

make check 16/16 (FIPS 203 conformance 3/3, all distro-safe checks).
This commit is contained in:
Cristian Cezar Moisés 2026-07-10 17:22:02 -03:00
commit 5050570b23
24 changed files with 356 additions and 139 deletions

View file

@ -5,13 +5,13 @@ If you're seeing the error:
```
vaptvupt-gui depende de python3-pyqt6 | python3-pyside6; porém:
Pacote python3-pyqt6 não está instalado.
vaptvupt-gui depende de vaptvupt (>= 4.2.1); porém:
vaptvupt-gui depende de vaptvupt (>= 5.0.0); porém:
Versão de vaptvupt no sistema é 2.1.7-1.
```
This is correct behavior. The `vaptvupt-gui` deb requires:
- Python 3 with **PyQt6** or **PySide6** (the GUI toolkit)
- The **vaptvupt CLI 4.2.1** or newer
- The **vaptvupt CLI 5.0.0** or newer
## The fastest fix — one command (Linux Mint, Ubuntu, Debian)
@ -33,8 +33,8 @@ the right order.
sudo apt update
sudo apt install -y python3-pyqt6
# 2. Upgrade vaptvupt CLI to 4.2.1
sudo dpkg -i vaptvupt_4.2.1_amd64.deb
# 2. Upgrade vaptvupt CLI to 5.0.0
sudo dpkg -i vaptvupt_5.0.0_amd64.deb
# 3. Install the GUI
sudo dpkg -i vaptvupt-gui_1.3.0_all.deb
@ -50,7 +50,7 @@ sudo apt --fix-broken install
```bash
sudo dnf install -y python3-pyqt6
sudo dnf install -y vaptvupt-4.2.1-1.x86_64.rpm vaptvupt-gui-1.3.0-1.noarch.rpm
sudo dnf install -y vaptvupt-5.0.0-1.x86_64.rpm vaptvupt-gui-1.3.0-1.noarch.rpm
```
(Or build the RPM from the SRPM tarball with `rpmbuild -bb SPECS/vaptvupt.spec`)
@ -98,7 +98,7 @@ Qt6 inside the deb because:
- Bundling would make the deb 80 MB+ instead of 35 KB
- Distribution-managed Qt gets security updates automatically
## Why does the GUI need vaptvupt 4.2.1?
## Why does the GUI need vaptvupt 5.0.0?
The GUI calls `vaptvupt --pq` and `vaptvupt keygen` for native
post-quantum encryption (ML-KEM-768 + X25519, in-tree implementation).
@ -108,7 +108,7 @@ fail against them.
## After installing — verify
```bash
vaptvupt version # should show: 4.2.1
vaptvupt version # should show: 5.0.0
vaptvupt-gui # should launch the GUI window
```
@ -178,8 +178,8 @@ sudo zypper install gcc make # openSUSE
### Build VaptVupt itself
```bash
tar -xzf vaptvupt-4.2.1-source.tar.gz
cd vaptvupt-4.2.1
tar -xzf vaptvupt-5.0.0-source.tar.gz
cd vaptvupt-5.0.0
make # build the `./vaptvupt` binary
sudo make install # install to /usr/local/bin (override with PREFIX=/usr)