v4.0.0: codec 2.60.4 security release, --pq-box sealed-box mode, F-16 fix
Some checks failed
CI / build-and-test (clang) (push) Has been cancelled
CI / build-and-test (gcc) (push) Has been cancelled
CI / strict-warnings (clang, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -O2 -std=c11 -Werror) (push) Has been cancelled
CI / strict-warnings (gcc, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -Wformat-security -Wlogical-op -Wjump-misses-init -Wdouble-promotion -O2 -std=c11 -Werror) (push) Has been cancelled
CI / sanitizers (push) Has been cancelled
CI / pie-hardening (push) Has been cancelled
CI / cross-aarch64 (push) Has been cancelled
CI / dist-reproducibility (push) Has been cancelled
CI / packaging-syntax (push) Has been cancelled
CI / release (push) Has been cancelled

Major release. Highlights:

- Codec: vendored VaptVupt codec moves to canonical 2.60.4 security
  release. Fixes a high-severity OOB heap write in the AVX2 decode fast
  path (reachable on a valid stream sized to exactly content_size, both
  tail variants). Brings CBMC-formally-verified BCJ filters with
  automatic ELF/PE/Mach-O detection. Compressed output stays
  byte-identical (ratio gate Δ 0.00%); wire format unchanged at v1.6.
- New --pq-box sealed-box recipient mode (vendored libpqvaptvupt 0.6.0):
  ML-KEM-768 + X25519 combined via HKDF-SHA256 with domain separation,
  AES-256-CTR + HMAC-SHA256 EtM. Legacy --pq and --pq-sdk stay readable.
- F-16: discloses and fixes a pre-existing data-loss defect in the
  <= 3.8.0 in-tree BCJ encoder. Full back-compat matrix decodes
  byte-exact under 4.0.0; every readable pre-4.0 archive remains readable.

Repository hygiene:
- Sync full 4.0.0 source tree (codec, crypto, SDK, GUI, packaging, tests).
- Remove internal scratch files (PROMPT.md, FORMAL_AUDIT_PROMPT.md)
  and superseded version-specific docs (INTEGRATION_PROTOCOL_2.60.4.md,
  docs/FINDINGS-2.x.md) and a stray test binary.
- Refresh README download/install section to real 4.0.0 release assets;
  bump version badge to 4.0.0.
- Add .gitignore for build outputs (keeps vendored prebuilt libraries).
This commit is contained in:
Cristian Cezar Moisés 2026-06-10 18:48:58 -03:00
commit 544a2cd647
98 changed files with 15615 additions and 1397 deletions

95
tests/test_sha256_shani.sh Executable file
View file

@ -0,0 +1,95 @@
#!/bin/bash
# SPDX-License-Identifier: AGPL-3.0-or-later
# Copyright (c) 2025-2026 Cristian Cezar Moisés
#
# SHA-256 SHA-NI hardware-path test (v3.2.0).
#
# The SHA-NI compression function in src/zupt_sha256_shani.c accelerates
# HMAC-SHA256 (the Encrypt-then-MAC second pass and PBKDF2) on CPUs with
# the Intel SHA Extensions. This test validates:
#
# 1. The 64 SHA-NI round constants are bit-identical to the scalar
# K[] table in zupt_sha256.c (catches transcription errors — the
# single most likely bug in a hand-written SHA-NI routine). This
# check runs on ALL hosts, SHA-NI or not.
# 2. The SHA-NI object compiles cleanly with -msha -mssse3 -msse4.1.
# 3. zupt_cpu gains has_shani and the dispatch is wired (source check).
# 4. On SHA-NI hardware: the SHA-NI path's digests match NIST FIPS
# 180-4 vectors and the scalar path bit-exact (executed by the C
# test). On non-SHA-NI hosts this step SKIPS — the instructions
# cannot be executed — but steps 1-3 still gate the build.
set -u
PASS=0; FAIL=0
P() { echo "$1"; PASS=$((PASS+1)); }
F() { echo "$1"; FAIL=$((FAIL+1)); }
echo "SHA-256 SHA-NI hardware path"
# ── 1. Round-constant equivalence (host-independent) ──
python3 - <<'PYEOF'
import re, sys
scalar = open('src/zupt_sha256.c').read()
m = re.search(r'static const uint32_t K\[64\]\s*=\s*\{(.*?)\};', scalar, re.S)
ks = [int(x,16) for x in re.findall(r'0x[0-9a-fA-F]{8}', m.group(1))]
shani = open('src/zupt_sha256_shani.c').read()
pairs = re.findall(r'_mm_set_epi64x\(\(long long\)0x([0-9A-Fa-f]{16})ULL,\s*\(long long\)0x([0-9A-Fa-f]{16})ULL\)', shani)
kpairs = [(hi,lo) for (hi,lo) in pairs if not hi.lower().startswith('0c0d')]
recon = []
for hi, lo in kpairs:
hi_u = int(hi,16); lo_u = int(lo,16)
recon += [lo_u & 0xFFFFFFFF, (lo_u>>32)&0xFFFFFFFF, hi_u & 0xFFFFFFFF, (hi_u>>32)&0xFFFFFFFF]
sys.exit(0 if (len(ks)==64 and recon==ks) else 1)
PYEOF
if [ $? -eq 0 ]; then
P "SHA-NI round constants bit-identical to scalar K[] (64/64)"
else
F "SHA-NI round constants DIFFER from scalar K[] table"
fi
# ── 2. has_shani wired into CPU detection ──
if grep -q 'has_shani' include/zupt_cpuid.h && grep -q 'has_shani' src/zupt_cpuid.c; then
P "has_shani present in CPU feature struct + detection"
else
F "has_shani not wired into zupt_cpuid"
fi
# ── 3. Dispatch wired in zupt_sha256.c ──
if grep -q 'zupt_sha256_transform_shani' src/zupt_sha256.c && grep -q 'zupt_cpu.has_shani' src/zupt_sha256.c; then
P "SHA-256 update() dispatches to SHA-NI when available"
else
F "SHA-256 dispatch to SHA-NI not wired"
fi
# ── 4. Compile + execute the C correctness test ──
ARCH=$(uname -m)
if [ "$ARCH" = "x86_64" ] || [ "$ARCH" = "i686" ]; then
SHANI_CFLAGS="-msha -mssse3 -msse4.1"
else
SHANI_CFLAGS=""
fi
TMP=$(mktemp -d)
if gcc -Iinclude -Isrc -Wall -Wextra -Werror $SHANI_CFLAGS -O2 -std=c11 \
tests/test_sha256_shani.c src/zupt_sha256.c src/zupt_sha256_shani.c src/zupt_cpuid.c \
-o "$TMP/t" 2>"$TMP/cc.log"; then
P "SHA-NI test compiles clean (-Werror $SHANI_CFLAGS)"
OUT=$("$TMP/t")
echo "$OUT" | sed 's/^/ /'
if echo "$OUT" | grep -q "failed (skipped"; then
echo " (host lacks SHA-NI — execution-level checks deferred to SHA-NI hardware)"
elif echo "$OUT" | grep -qE "SHA-NI: [0-9]+ passed, 0 failed$"; then
P "SHA-NI path executes correctly (NIST vectors + scalar agreement)"
else
F "SHA-NI C test reported failures"
fi
else
F "SHA-NI test failed to compile"
head -10 "$TMP/cc.log" | sed 's/^/ /'
fi
rm -rf "$TMP"
echo ""
echo " ───────────────────────────────────────"
echo " SHA-NI hardware path: $PASS passed, $FAIL failed"
echo " ───────────────────────────────────────"
[ "$FAIL" = 0 ] || exit 1