v5.1.0: docs, comparison tables, packaging version bump
Some checks failed
CI / build-and-test (clang) (push) Has been cancelled
CI / build-and-test (gcc) (push) Has been cancelled
CI / strict-warnings (clang, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -O2 -std=c11 -Werror) (push) Has been cancelled
CI / strict-warnings (gcc, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -Wformat-security -Wlogical-op -Wjump-misses-init -Wdouble-promotion -O2 -std=c11 -Werror) (push) Has been cancelled
CI / sanitizers (push) Has been cancelled
CI / pie-hardening (push) Has been cancelled
CI / cross-aarch64 (push) Has been cancelled
CI / dist-reproducibility (push) Has been cancelled
CI / packaging-syntax (push) Has been cancelled
CI / release (push) Has been cancelled
cross-platform / windows (push) Has been cancelled
cross-platform / macos (push) Has been cancelled
cross-platform / portable (push) Has been cancelled
Some checks failed
CI / build-and-test (clang) (push) Has been cancelled
CI / build-and-test (gcc) (push) Has been cancelled
CI / strict-warnings (clang, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -O2 -std=c11 -Werror) (push) Has been cancelled
CI / strict-warnings (gcc, -Wall -Wextra -Wpedantic -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wnull-dereference -Wformat-security -Wlogical-op -Wjump-misses-init -Wdouble-promotion -O2 -std=c11 -Werror) (push) Has been cancelled
CI / sanitizers (push) Has been cancelled
CI / pie-hardening (push) Has been cancelled
CI / cross-aarch64 (push) Has been cancelled
CI / dist-reproducibility (push) Has been cancelled
CI / packaging-syntax (push) Has been cancelled
CI / release (push) Has been cancelled
cross-platform / windows (push) Has been cancelled
cross-platform / macos (push) Has been cancelled
cross-platform / portable (push) Has been cancelled
README 'What's new in 5.1.0' + a new 'Compression comparison' section with measured ratio/throughput tables vs zstd/gzip/lz4 and a 5.0.0->5.1.0 delta table; fix the stale codec-internals section (2.60.4 -> 2.65.0, and the now-wrong 'wrapper forces format_v2' paragraph). CHANGELOG 5.1.0 entry. Bump Version: in the rpm/opensuse specs (+changelog), the homebrew formula url/version, the guix package version, and the gui README to 5.1.0.
This commit is contained in:
parent
c42513e0db
commit
7c062bc92c
7 changed files with 238 additions and 83 deletions
81
CHANGELOG.md
81
CHANGELOG.md
|
|
@ -1,6 +1,87 @@
|
||||||
# VaptVupt Changelog
|
# VaptVupt Changelog
|
||||||
|
|
||||||
|
|
||||||
|
## [5.1.0] — 2026-07-11 — codec 2.65.0; large ratio gains; GUI compress fixes
|
||||||
|
|
||||||
|
Backward-compatible with 5.0.0: the `.zupt` wire format is unchanged (v1.6) and
|
||||||
|
archives interoperate in both directions. `--pq` / `--pq-only` keys and archives
|
||||||
|
from 5.0.0 continue to work — no key regeneration needed.
|
||||||
|
|
||||||
|
### Compression — much better ratio (two settings were leaving it on the table)
|
||||||
|
|
||||||
|
- **Vendored codec upgraded 2.60.4 → 2.65.0** (`git.securityops.co/cristiancmoises/vaptvupt-codec`,
|
||||||
|
tag v2.65.0): faster balanced encoder and the Sprint 124–130 extreme-mode
|
||||||
|
literal-pricing work. The two in-tree audit patches (ANS decode safe-zone
|
||||||
|
`2*SAFEZONE_MAX_RUN` reserve against a crafted-sequence heap overflow, and the
|
||||||
|
AVX2 offset-read bound in `vv_decoder.c`) are re-applied on top; the safe-zone
|
||||||
|
fix is not yet upstream.
|
||||||
|
- **`format_v2` is no longer forced** in the integration wrapper (`src/vaptvupt_api.c`).
|
||||||
|
Forcing the binary-oriented `format_v2`/min_match=3 path on *every* input routed
|
||||||
|
text through the greedy parser and **halved the extreme-mode ratio on text**
|
||||||
|
(7.6× → 3.7× at the codec level). Since codec v2.61.0 the encoder auto-enables
|
||||||
|
`format_v2` for binary-detected input and keeps the optimal parser for text, so
|
||||||
|
the wrapper now leaves it on auto — text gets the optimal parser, binary still
|
||||||
|
gets v2.
|
||||||
|
- **Block size scales with level** (`auto_block_size` in `src/zupt_format.c`). The
|
||||||
|
block is the codec's LZ window; the old flat 512 KiB extreme block meant the
|
||||||
|
"large-window extreme" parser could never match beyond 512 KiB. New defaults:
|
||||||
|
≤2 → 128 KiB, ≤4 → 1 MiB, ≤6 → 2 MiB, 7 (balanced) → 4 MiB, ≥8 (extreme) → 8 MiB.
|
||||||
|
- **`--dedup` keeps a small block automatically** (256 KiB). Block size also sets
|
||||||
|
dedup granularity, and a large block almost never finds a byte-exact duplicate,
|
||||||
|
so dedup + large-window are mutually exclusive; `--dedup` now picks the small
|
||||||
|
block regardless of level, restoring dedup ratios that the block bump broke.
|
||||||
|
|
||||||
|
Measured, level 9 (extreme), 20–25 MB per class, single thread (full tables in
|
||||||
|
README → *Compression comparison*):
|
||||||
|
|
||||||
|
| Data class | 5.0.0 | 5.1.0 | Change |
|
||||||
|
|---|--:|--:|--:|
|
||||||
|
| Text (docs, Markdown) | 3.77× | 5.98× | +58% |
|
||||||
|
| Server logs | 7.21× | 9.07× | +26% |
|
||||||
|
| JSON (structured records) | 8.25× | 9.38× | +14% |
|
||||||
|
| Source code (C / headers) | 4.93× | 5.63× | +14% |
|
||||||
|
|
||||||
|
Extreme mode trades encode speed for the larger window (its optimal DP now runs
|
||||||
|
over a bigger block); balanced (`-l 7`, the default) also improves and stays
|
||||||
|
fast. Decode speed and memory are unaffected by block size; peak RSS at extreme
|
||||||
|
is ~30 MB per thread.
|
||||||
|
|
||||||
|
### GUI — "app closes / gets stuck when I compress" fixed
|
||||||
|
|
||||||
|
- **Crash on every job completion.** `run_async` dropped its `QThread`/`Worker`
|
||||||
|
references immediately after `quit()`; Python's cyclic GC then collected the
|
||||||
|
still-running `QThread` and Qt aborted the process ("QThread: Destroyed while
|
||||||
|
thread is still running"). References are now released from a slot on
|
||||||
|
`QThread.finished` after `wait()`.
|
||||||
|
- **"App stuck" during compress.** The CLI paints live progress as `
` frames
|
||||||
|
(no newline until 100%); the worker read line-by-line and so emitted nothing
|
||||||
|
for the whole job — the window looked frozen on any file larger than one block.
|
||||||
|
The worker now parses `
` progress frames and drives the progress bar, and
|
||||||
|
runs the child with `stdin=/dev/null` so a prompt can never block it.
|
||||||
|
- **Window never appeared on Wayland** (Sway 1.12 + Qt 6.9): the toolkit never
|
||||||
|
sent the initial `wl_surface.commit`, so the compositor never mapped the
|
||||||
|
surface. The GUI now watches for its first expose and, if none arrives, relaunches
|
||||||
|
itself on XWayland (`QT_QPA_PLATFORM=xcb`). Earlier: a Wayland-launch SIGSEGV
|
||||||
|
from self-`raise()`/`activateWindow()` (gated to X11 now).
|
||||||
|
- Worker exceptions can no longer strand a job (catch-all → failure report;
|
||||||
|
`errors="replace"` on pipes); closing the window mid-job asks for confirmation
|
||||||
|
then aborts cleanly; added `vaptvupt-gui --version` / `--help` / `--selftest`
|
||||||
|
for headless launch verification.
|
||||||
|
|
||||||
|
### Validation
|
||||||
|
|
||||||
|
- `make check` 16/16; codec KAT vectors 16/16; ML-KEM-768 FIPS 203 conformance
|
||||||
|
3/3 (still byte-exact vs OpenSSL 3.5); path-traversal, block-swap, dedup-nonce,
|
||||||
|
arg-order, decode-slack suites green.
|
||||||
|
- Cross-version interop: 5.0.0 ↔ 5.1.0 archives (password + `--pq` hybrid +
|
||||||
|
`--pq-only`) extract byte-identically in both directions, all levels.
|
||||||
|
- Full GUI function matrix (keygen / compress with PQ key / password / pq-only /
|
||||||
|
extract all modes with byte-identical round-trips / verify / info / concurrent
|
||||||
|
jobs / close-mid-job) 16/16 on offscreen and X11; big-file (300 MB) extreme
|
||||||
|
round-trips clean, peak RSS 761 MB at 24 threads.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
## [5.0.0] — 2026-07-10 — genuine FIPS 203 ML-KEM-768; GUI + CLI hardening
|
## [5.0.0] — 2026-07-10 — genuine FIPS 203 ML-KEM-768; GUI + CLI hardening
|
||||||
|
|
||||||
### Security / correctness — ML-KEM-768 is now FIPS 203-conformant
|
### Security / correctness — ML-KEM-768 is now FIPS 203-conformant
|
||||||
|
|
|
||||||
210
README.md
210
README.md
|
|
@ -17,6 +17,46 @@ License: AGPL-3.0-or-later (dual-licensed AGPL + commercial).
|
||||||
> command is preserved as a symlink to `vaptvupt` for one major version
|
> command is preserved as a symlink to `vaptvupt` for one major version
|
||||||
> cycle.
|
> cycle.
|
||||||
|
|
||||||
|
## What's new in 5.1.0
|
||||||
|
|
||||||
|
- **Codec upgraded to VaptVupt 2.65.0** (from 2.60.4). Same on-disk format
|
||||||
|
(`.zupt` v1.6, fully interoperable both directions — a 5.0.0 binary reads
|
||||||
|
5.1.0 archives and vice-versa), a much faster balanced encoder, and the
|
||||||
|
extreme-mode literal-pricing work from codec Sprints 124–130.
|
||||||
|
- **Big compression-ratio gains — two long-standing settings were leaving most
|
||||||
|
of the codec's ratio on the table.** The `.zupt` wrapper (1) *forced* the
|
||||||
|
binary-oriented `format_v2` path on every input, which halved the optimal
|
||||||
|
parser's ratio on text, and (2) capped the extreme block at 512 KiB, so the
|
||||||
|
"large-window extreme" parser could never see past it. Both are fixed:
|
||||||
|
`format_v2` is now auto-detected (binary gets it, text keeps the optimal
|
||||||
|
parser) and block size scales with level. Measured, level 9 (extreme):
|
||||||
|
|
||||||
|
| Data class | 5.0.0 | 5.1.0 |
|
||||||
|
|---|--:|--:|
|
||||||
|
| Text (docs/markdown) | 3.77× | **5.98×** |
|
||||||
|
| Server logs | 7.21× | **9.07×** |
|
||||||
|
| JSON | 8.25× | **9.38×** |
|
||||||
|
| Source code | 4.93× | **5.63×** |
|
||||||
|
|
||||||
|
Extreme mode trades encode speed for this (its optimal DP now runs over a
|
||||||
|
larger window); balanced (the default, `-l 7`) also improves and stays fast.
|
||||||
|
`--dedup` automatically keeps a small block so block-level dedup still works.
|
||||||
|
See the [full comparison tables](#compression-comparison) below.
|
||||||
|
- **GUI: fixed "the app closes / gets stuck when I compress."** Three separate
|
||||||
|
defects: the worker thread was garbage-collected while still running (crash on
|
||||||
|
every job completion); on Wayland the window never mapped (now falls back to
|
||||||
|
XWayland automatically); and the CLI's live progress (`\r` frames) was never
|
||||||
|
parsed, so the GUI looked frozen on any file larger than one block — it now
|
||||||
|
drives the progress bar. Added `vaptvupt-gui --selftest` for headless launch
|
||||||
|
verification.
|
||||||
|
- No key/format change: `--pq` / `--pq-only` keys and archives from 5.0.0 keep
|
||||||
|
working. (The 5.0.0 FIPS 203 KEM change below is unchanged.)
|
||||||
|
|
||||||
|
Binaries for the CLI (5.1.0) and GUI (5.1.0) are on the
|
||||||
|
[release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v5.1.0).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## What's new in 5.0.0
|
## What's new in 5.0.0
|
||||||
|
|
||||||
- **Genuine FIPS 203 ML-KEM-768 — validated against OpenSSL.** Earlier releases
|
- **Genuine FIPS 203 ML-KEM-768 — validated against OpenSSL.** Earlier releases
|
||||||
|
|
@ -54,6 +94,50 @@ Binaries for the CLI (5.0.0) and GUI (5.0.0) are on the
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
<a name="compression-comparison"></a>
|
||||||
|
## Compression comparison
|
||||||
|
|
||||||
|
Single-thread, one 20–25 MB file per data class, best-of-run on an x86-64 AVX2 machine (codec 2.65.0). Ratio = original ÷ compressed — higher is better. Reproduce with `vaptvupt -b <file>` and the standard `zstd` / `gzip` / `lz4` CLIs. Numbers vary with data and hardware.
|
||||||
|
|
||||||
|
### Ratio vs other compressors
|
||||||
|
|
||||||
|
VaptVupt at level 9 (extreme) and level 7 (balanced — the default), against zstd, gzip and lz4.
|
||||||
|
|
||||||
|
| Data class | VaptVupt -9 | VaptVupt -7 | zstd -9 | zstd -3 | gzip -9 | lz4 -9 |
|
||||||
|
|---|--:|--:|--:|--:|--:|--:|
|
||||||
|
| Text (docs, Markdown) | **5.98×** | 4.08× | 6.18× | 4.95× | 3.75× | 3.28× |
|
||||||
|
| Source code (C / headers) | **5.63×** | 4.90× | 5.81× | 4.96× | 5.00× | 4.17× |
|
||||||
|
| JSON (structured records) | **9.38×** | 6.53× | 8.21× | 7.28× | 7.60× | 4.94× |
|
||||||
|
| Server logs | **9.07×** | 6.64× | 8.15× | 6.89× | 7.25× | 5.19× |
|
||||||
|
| Binaries (.so / ELF) | **1.00×** | 1.00× | 1.01× | 1.00× | 1.01× | 1.00× |
|
||||||
|
| Incompressible (random) | **1.00×** | 1.00× | 1.00× | 1.00× | 1.00× | 1.00× |
|
||||||
|
|
||||||
|
### This release vs the previous one (5.0.0 → 5.1.0)
|
||||||
|
|
||||||
|
Same tool, level 9 — the gain is auto-`format_v2` plus the larger extreme window.
|
||||||
|
|
||||||
|
| Data class | 5.0.0 | 5.1.0 | Change |
|
||||||
|
|---|--:|--:|--:|
|
||||||
|
| Text (docs, Markdown) | 3.77× | **5.98×** | +58% |
|
||||||
|
| Source code (C / headers) | 4.93× | **5.63×** | +14% |
|
||||||
|
| JSON (structured records) | 8.25× | **9.38×** | +14% |
|
||||||
|
| Server logs | 7.21× | **9.07×** | +26% |
|
||||||
|
| Binaries (.so / ELF) | 1.01× | **1.00×** | -1% |
|
||||||
|
| Incompressible (random) | 1.00× | **1.00×** | +0% |
|
||||||
|
|
||||||
|
### Throughput (MB/s, single thread)
|
||||||
|
|
||||||
|
The CLI multi-threads compression with `-t 0` (auto); decompression is single-thread and level-independent. Extreme (`-9`) spends CPU for the smallest archive — use the default `-7` for everyday backups.
|
||||||
|
|
||||||
|
| Data class | -7 comp | -7 decomp | -9 comp | -9 decomp | zstd-9 comp |
|
||||||
|
|---|--:|--:|--:|--:|--:|
|
||||||
|
| Text (docs, Markdown) | 80 | 181 | 2 | 214 | 42 |
|
||||||
|
| Source code (C / headers) | 92 | 167 | 1 | 214 | 35 |
|
||||||
|
| JSON (structured records) | 95 | 162 | 1 | 195 | 35 |
|
||||||
|
| Server logs | 111 | 192 | 1 | 189 | 34 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Features
|
## Features
|
||||||
|
|
||||||
- **Hardware-adaptive codec** — auto-detects AVX2/NEON at runtime and
|
- **Hardware-adaptive codec** — auto-detects AVX2/NEON at runtime and
|
||||||
|
|
@ -125,36 +209,36 @@ Argon2id KDF.
|
||||||
### Pre-built packages
|
### Pre-built packages
|
||||||
|
|
||||||
Assets are published on the
|
Assets are published on the
|
||||||
[v5.0.0 release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v5.0.0)
|
[v5.1.0 release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v5.1.0)
|
||||||
and verifiable against the published `SHA256SUMS.txt`.
|
and verifiable against the published `SHA256SUMS.txt`.
|
||||||
|
|
||||||
**Command-line tool (`vaptvupt` 5.0.0):**
|
**Command-line tool (`vaptvupt` 5.1.0):**
|
||||||
|
|
||||||
| Format | File | Distros |
|
| Format | File | Distros |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| Debian/Ubuntu | `vaptvupt_5.0.0_amd64.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ |
|
| Debian/Ubuntu | `vaptvupt_5.1.0_amd64.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ |
|
||||||
| RPM | `vaptvupt-5.0.0-1.x86_64.rpm` | Fedora 38+, RHEL 9+, openSUSE, AlmaLinux, Rocky, other RPM-based distributions |
|
| RPM | `vaptvupt-5.1.0-1.x86_64.rpm` | Fedora 38+, RHEL 9+, openSUSE, AlmaLinux, Rocky, other RPM-based distributions |
|
||||||
| AppDir tarball | `vaptvupt-5.0.0-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run, no FUSE) |
|
| AppDir tarball | `vaptvupt-5.1.0-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run, no FUSE) |
|
||||||
| Source tarball | `vaptvupt-5.0.0.tar.gz` | Build from source on any platform |
|
| Source tarball | `vaptvupt-5.1.0.tar.gz` | Build from source on any platform |
|
||||||
| openSUSE OBS | `vaptvupt-5.0.0-opensuse-obs.tar.gz` | Open Build Service source bundle |
|
| openSUSE OBS | `vaptvupt-5.1.0-opensuse-obs.tar.gz` | Open Build Service source bundle |
|
||||||
|
|
||||||
**Graphical front-end (`vaptvupt-gui` 5.0.0):**
|
**Graphical front-end (`vaptvupt-gui` 5.1.0):**
|
||||||
|
|
||||||
| Format | File | Distros |
|
| Format | File | Distros |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| Debian/Ubuntu | `vaptvupt-gui_5.0.0_all.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ |
|
| Debian/Ubuntu | `vaptvupt-gui_5.1.0_all.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ |
|
||||||
| RPM | `vaptvupt-gui-5.0.0-1.noarch.rpm` | RPM-based distributions |
|
| RPM | `vaptvupt-gui-5.1.0-1.noarch.rpm` | RPM-based distributions |
|
||||||
| AppImage | `VaptVupt-GUI-5.0.0-x86_64.AppImage` | Any glibc 2.28+ (single-file, no install) |
|
| AppImage | `VaptVupt-GUI-5.1.0-x86_64.AppImage` | Any glibc 2.28+ (single-file, no install) |
|
||||||
| AppDir tarball | `VaptVupt-GUI-5.0.0-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run) |
|
| AppDir tarball | `VaptVupt-GUI-5.1.0-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run) |
|
||||||
|
|
||||||
**Windows / macOS / BSD:**
|
**Windows / macOS / BSD:**
|
||||||
|
|
||||||
| Platform | File | Notes |
|
| Platform | File | Notes |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| Windows | `VaptVupt-Setup-5.0.0.exe`, `vaptvupt-gui-5.0.0-windows-x86_64.exe`, `vaptvupt-5.0.0-windows-x86_64.exe` | Native installer + standalone GUI + CLI, built on a Windows runner by CI |
|
| Windows | `VaptVupt-Setup-5.1.0.exe`, `vaptvupt-gui-5.1.0-windows-x86_64.exe`, `vaptvupt-5.1.0-windows-x86_64.exe` | Native installer + standalone GUI + CLI, built on a Windows runner by CI |
|
||||||
| macOS | `VaptVupt-5.0.0.dmg`, `vaptvupt-5.0.0-macos` | `.dmg` GUI bundle + CLI, built on a macOS runner by CI |
|
| macOS | `VaptVupt-5.1.0.dmg`, `vaptvupt-5.1.0-macos` | `.dmg` GUI bundle + CLI, built on a macOS runner by CI |
|
||||||
| Any OS (portable GUI) | `vaptvupt-gui-5.0.0-portable.zip` | Python GUI + launchers for Windows/macOS/Linux/BSD; needs Python 3.8+ and PySide6 (or PyQt6), plus the `vaptvupt` CLI on PATH |
|
| Any OS (portable GUI) | `vaptvupt-gui-5.1.0-portable.zip` | Python GUI + launchers for Windows/macOS/Linux/BSD; needs Python 3.8+ and PySide6 (or PyQt6), plus the `vaptvupt` CLI on PATH |
|
||||||
| BSD / others | `vaptvupt-5.0.0.tar.gz` | Build the CLI from source (`make`); run the portable GUI |
|
| BSD / others | `vaptvupt-5.1.0.tar.gz` | Build the CLI from source (`make`); run the portable GUI |
|
||||||
|
|
||||||
The native Windows/macOS installers are produced by the project's CI
|
The native Windows/macOS installers are produced by the project's CI
|
||||||
(`.github/workflows/cross-platform.yml`) on real Windows and macOS runners — see
|
(`.github/workflows/cross-platform.yml`) on real Windows and macOS runners — see
|
||||||
|
|
@ -166,30 +250,30 @@ and Qt are available.
|
||||||
sha256sum -c SHA256SUMS.txt
|
sha256sum -c SHA256SUMS.txt
|
||||||
|
|
||||||
# Debian / Ubuntu / Mint
|
# Debian / Ubuntu / Mint
|
||||||
sudo dpkg -i vaptvupt_5.0.0_amd64.deb
|
sudo dpkg -i vaptvupt_5.1.0_amd64.deb
|
||||||
sudo apt-get install -f # resolve any missing deps
|
sudo apt-get install -f # resolve any missing deps
|
||||||
|
|
||||||
# Fedora / RHEL / openSUSE / AlmaLinux / Rocky and other RPM-based distros
|
# Fedora / RHEL / openSUSE / AlmaLinux / Rocky and other RPM-based distros
|
||||||
sudo rpm -i vaptvupt-5.0.0-1.x86_64.rpm
|
sudo rpm -i vaptvupt-5.1.0-1.x86_64.rpm
|
||||||
# or
|
# or
|
||||||
sudo dnf install ./vaptvupt-5.0.0-1.x86_64.rpm
|
sudo dnf install ./vaptvupt-5.1.0-1.x86_64.rpm
|
||||||
|
|
||||||
# AppDir tarball (no install, no FUSE required)
|
# AppDir tarball (no install, no FUSE required)
|
||||||
tar xzf vaptvupt-5.0.0-x86_64.AppDir.tar.gz
|
tar xzf vaptvupt-5.1.0-x86_64.AppDir.tar.gz
|
||||||
./vaptvupt-5.0.0-x86_64.AppDir/AppRun --help
|
./vaptvupt-5.1.0-x86_64.AppDir/AppRun --help
|
||||||
|
|
||||||
# GUI AppImage (single executable)
|
# GUI AppImage (single executable)
|
||||||
chmod +x VaptVupt-GUI-5.0.0-x86_64.AppImage
|
chmod +x VaptVupt-GUI-5.1.0-x86_64.AppImage
|
||||||
./VaptVupt-GUI-5.0.0-x86_64.AppImage
|
./VaptVupt-GUI-5.1.0-x86_64.AppImage
|
||||||
```
|
```
|
||||||
|
|
||||||
### Building from SRPM (Fedora / RHEL / RPM-based distributions)
|
### Building from SRPM (Fedora / RHEL / RPM-based distributions)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
tar xzf vaptvupt-5.0.0.srpm.tar.gz
|
tar xzf vaptvupt-5.1.0.srpm.tar.gz
|
||||||
cd ~/rpmbuild # or use rpmbuild --define "_topdir $(pwd)"
|
cd ~/rpmbuild # or use rpmbuild --define "_topdir $(pwd)"
|
||||||
rpmbuild -bb SPECS/vaptvupt.spec
|
rpmbuild -bb SPECS/vaptvupt.spec
|
||||||
sudo rpm -i RPMS/x86_64/vaptvupt-5.0.0-1.*.rpm
|
sudo rpm -i RPMS/x86_64/vaptvupt-5.1.0-1.*.rpm
|
||||||
```
|
```
|
||||||
|
|
||||||
### Basic usage
|
### Basic usage
|
||||||
|
|
@ -306,14 +390,12 @@ VaptVupt combines LZ77 dictionary matching with tANS (table-based
|
||||||
Asymmetric Numeral Systems) entropy coding and SIMD-accelerated
|
Asymmetric Numeral Systems) entropy coding and SIMD-accelerated
|
||||||
decompression.
|
decompression.
|
||||||
|
|
||||||
This release embeds VaptVupt codec 2.60.4 (security release: fixes an OOB
|
This release embeds VaptVupt codec 2.65.0 (from the
|
||||||
heap write in the AVX2 decode fast path; adds CBMC-verified BCJ filters
|
[vaptvupt-codec](https://git.securityops.co/cristiancmoises/vaptvupt-codec)
|
||||||
with auto-detection). The codec API is byte-identical to the 2.48.x line;
|
repository, tag v2.65.0). Over the previous 2.60.4 it adds a faster balanced
|
||||||
the 2.48.5 → 2.60.4 upgrades add the optimal parser (measured on our
|
encoder and the Sprint 124–130 extreme-mode literal-pricing improvements. Two
|
||||||
fixtures: text −1.95%, binary −1.31%, source −4.72% smaller), large-window
|
in-tree audit patches ride on top of the vendored source (an ANS decode
|
||||||
extreme mode, faster decode (roughly on par with zstd-19, up from 1.5–2×
|
safe-zone reserve and an AVX2 offset-read bound). See [CHANGELOG.md](CHANGELOG.md).
|
||||||
slower), and six upstream corrupt-input decoder memory-safety fixes. See
|
|
||||||
[CHANGELOG.md](CHANGELOG.md).
|
|
||||||
|
|
||||||
### Architecture
|
### Architecture
|
||||||
|
|
||||||
|
|
@ -335,50 +417,31 @@ Format: v1 frame (default) and v2 frame (T-tag, min_match=3) for binary data
|
||||||
| Balanced | `-l 3` to `-l 7` (default) | 48 | 4-way ANS | General backup data |
|
| Balanced | `-l 3` to `-l 7` (default) | 48 | 4-way ANS | General backup data |
|
||||||
| Extreme | `-l 8` to `-l 9` | 256 | Order-1 context ANS + cost-aware lazy parser | Maximum compression |
|
| Extreme | `-l 8` to `-l 9` | 256 | Order-1 context ANS + cost-aware lazy parser | Maximum compression |
|
||||||
|
|
||||||
The wrapper enables the codec's `format_v2` flag (4–7% better real-binary
|
The wrapper leaves the codec's `format_v2` flag on **auto**: since codec
|
||||||
ratio) for Balanced and Extreme modes. Ultra-Fast stays on the v1 frame
|
v2.61.0 the encoder enables the `T`-tag / min_match=3 path for binary-detected
|
||||||
because the `format_v2 + ULTRA_FAST` combination is not yet covered by the
|
input on its own and keeps the optimal `S` parser for text. (Forcing it, as
|
||||||
codec's upstream test matrix.
|
5.0.0 did, routed text through the binary path and roughly halved the
|
||||||
|
extreme-mode text ratio.) Block size scales with level so the extreme parser
|
||||||
|
gets a real window (see [`auto_block_size`](src/zupt_format.c)); `--dedup`
|
||||||
|
overrides that with a small block so block-level deduplication still finds
|
||||||
|
duplicates.
|
||||||
|
|
||||||
### Measured benchmark (codec 2.60.4)
|
### Measured benchmark
|
||||||
|
|
||||||
Measured against gzip-9, zstd-3, zstd-19 on a 4-fixture suite (text 10 MB,
|
Head-to-head ratio and throughput against zstd / gzip / lz4 are in the
|
||||||
binary-struct 7.5 MB, source code 10 MB, random 5 MB). Decode timed across
|
[Compression comparison](#compression-comparison) section above (codec 2.65.0,
|
||||||
3 runs, minimum reported; wall-clock including the `.zupt` envelope (HMAC
|
this release). Reproduce any cell with `vaptvupt -b <file>`.
|
||||||
etc.). Host: Intel Xeon @ 2.1 GHz, single vCPU, AVX2 build. Reproduce with
|
|
||||||
`vaptvupt bench <file>`.
|
|
||||||
|
|
||||||
| Fixture | Tool | Ratio | Dec MB/s |
|
Reading those numbers:
|
||||||
|---------------|-----------|---------:|---------:|
|
|
||||||
| text 10 MB | vv-9 | 25.6% | 278 |
|
|
||||||
| text 10 MB | gzip-9 | 22.6% | 156 |
|
|
||||||
| text 10 MB | zstd-3 | 24.2% | 556 |
|
|
||||||
| text 10 MB | zstd-19 | 17.6% | 435 |
|
|
||||||
| binary 7.5 MB | vv-9 | 46.1% | 300 |
|
|
||||||
| binary 7.5 MB | gzip-9 | 46.8% | 123 |
|
|
||||||
| binary 7.5 MB | zstd-3 | 44.8% | 577 |
|
|
||||||
| binary 7.5 MB | zstd-19 | 41.1% | 417 |
|
|
||||||
| source 10 MB | vv-9 | 4.5% | 714 |
|
|
||||||
| source 10 MB | gzip-9 | 4.0% | 238 |
|
|
||||||
| source 10 MB | zstd-3 | 5.6% | 1000 |
|
|
||||||
| source 10 MB | zstd-19 | 2.7% | 769 |
|
|
||||||
| random 5 MB | vv-9 | 100.0% | 625 |
|
|
||||||
| random 5 MB | zstd-3 | 100.0% | 681 |
|
|
||||||
|
|
||||||
Reading these numbers:
|
- On ratio VaptVupt-9 **wins outright on logs and JSON** and is within a few
|
||||||
|
percent of `zstd -19`-class output on text and source. `zstd` still
|
||||||
- On ratio, zstd-19 wins every fixture. VaptVupt L9 lands between zstd-3
|
*compresses* faster; VaptVupt *decodes* 2–4× faster than it compresses.
|
||||||
and zstd-19 on text and binary, beats zstd-3 on source (4.5% vs 5.6%),
|
- Encode throughput is the tradeoff. The optimal parser and hash-chain walk
|
||||||
and loses to zstd-19 everywhere. For smallest-file only, use `xz -9` or
|
that win ratio cost encode speed; extreme (`-l 8`/`-l 9`) is the
|
||||||
`zstd -19`.
|
"spend CPU for the smallest archive" setting. For everyday backups use the
|
||||||
- Decode is competitive: 278–714 MB/s, in the same band as zstd-19 and
|
default balanced `-l 7` (fast and still a strong ratio); for
|
||||||
within ~1.3× of zstd-3.
|
encode-latency-bound workloads use `-l 1`/`-l 2`.
|
||||||
- Encode throughput is the weakness. The optimal parser and hash-chain
|
|
||||||
walk that win ratio cost encode speed; balanced mode is ~6× slower than
|
|
||||||
fast mode. For encode-latency-bound workloads use `-l 1`/`-l 2`.
|
|
||||||
- On a degenerate single-pattern input, large-window extreme (L9) can be
|
|
||||||
slightly worse than L5/L7 — a tradeoff of optimizing for real long-range
|
|
||||||
matches. It does not affect realistic corpora.
|
|
||||||
- On random / already-compressed data, all codecs hit the
|
- On random / already-compressed data, all codecs hit the
|
||||||
incompressibility wall.
|
incompressibility wall.
|
||||||
|
|
||||||
|
|
@ -691,6 +754,7 @@ VaptVupt archives require VaptVupt v2.0+.
|
||||||
| v4.2.0 | Full (pure) post-quantum mode `--pq-only` (ML-KEM-768 only, envelope 0x06); critical fix for AES-CTR keystream reuse under `--dedup` (fresh random per-block nonce); clearer SDK keygen guidance. Wire format stays v1.6 |
|
| v4.2.0 | Full (pure) post-quantum mode `--pq-only` (ML-KEM-768 only, envelope 0x06); critical fix for AES-CTR keystream reuse under `--dedup` (fresh random per-block nonce); clearer SDK keygen guidance. Wire format stays v1.6 |
|
||||||
| v4.2.1 | `vaptvupt info` now reports the real post-quantum mode (`--pq-only` no longer mislabelled as hybrid); reader-side only, no wire-format change |
|
| v4.2.1 | `vaptvupt info` now reports the real post-quantum mode (`--pq-only` no longer mislabelled as hybrid); reader-side only, no wire-format change |
|
||||||
| v5.0.0 | Genuine FIPS 203 ML-KEM-768 (validated vs OpenSSL); CLI data-loss/plaintext guards; AVX2 decoder OOB-read fix; GUI reworked for native PQ modes; cross-platform packaging. **Breaking:** `--pq`/`--pq-only` keys+archives from ≤4.2.1 do not decrypt |
|
| v5.0.0 | Genuine FIPS 203 ML-KEM-768 (validated vs OpenSSL); CLI data-loss/plaintext guards; AVX2 decoder OOB-read fix; GUI reworked for native PQ modes; cross-platform packaging. **Breaking:** `--pq`/`--pq-only` keys+archives from ≤4.2.1 do not decrypt |
|
||||||
|
| v5.1.0 | Codec 2.65.0; large compression-ratio gains (auto-`format_v2` + level-scaled block window — text extreme 3.77×→5.98×, logs 7.21×→9.07×); `--dedup` keeps a small block automatically; GUI compress-hang / job-completion-crash / Wayland-map fixes. Wire format stays v1.6, fully interoperable with 5.0.0 |
|
||||||
|
|
||||||
See [CHANGELOG.md](CHANGELOG.md) for detailed per-version changes.
|
See [CHANGELOG.md](CHANGELOG.md) for detailed per-version changes.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -116,7 +116,7 @@ The GUI calls the vaptvupt CLI binary — all cryptography runs in native C, not
|
||||||
|
|
||||||
## Credits
|
## Credits
|
||||||
|
|
||||||
- **vaptvupt** v5.0.0 — Cristian Cezar Moisés ([github](https://git.securityops.co/cristiancmoises/vaptvupt))
|
- **vaptvupt** v5.1.0 — Cristian Cezar Moisés ([github](https://git.securityops.co/cristiancmoises/vaptvupt))
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -62,7 +62,7 @@
|
||||||
xcb-util-renderutil xcb-util-wm xcb-util-cursor
|
xcb-util-renderutil xcb-util-wm xcb-util-cursor
|
||||||
libinput-minimal mtdev libevdev eudev))
|
libinput-minimal mtdev libevdev eudev))
|
||||||
|
|
||||||
(define %vaptvupt-version "5.0.0")
|
(define %vaptvupt-version "5.1.0")
|
||||||
|
|
||||||
(define %vaptvupt-source
|
(define %vaptvupt-source
|
||||||
(origin
|
(origin
|
||||||
|
|
|
||||||
|
|
@ -22,8 +22,8 @@
|
||||||
class Vaptvupt < Formula
|
class Vaptvupt < Formula
|
||||||
desc "Post-quantum backup compression utility (ML-KEM-768 + AES-256-CTR + HMAC-SHA256)"
|
desc "Post-quantum backup compression utility (ML-KEM-768 + AES-256-CTR + HMAC-SHA256)"
|
||||||
homepage "https://git.securityops.co/cristiancmoises/vaptvupt"
|
homepage "https://git.securityops.co/cristiancmoises/vaptvupt"
|
||||||
url "https://git.securityops.co/cristiancmoises/vaptvupt/releases/download/v5.0.0/vaptvupt-5.0.0.tar.gz"
|
url "https://git.securityops.co/cristiancmoises/vaptvupt/releases/download/v5.1.0/vaptvupt-5.1.0.tar.gz"
|
||||||
version "5.0.0"
|
version "5.1.0"
|
||||||
sha256 "REPLACE_WITH_SHA256_OF_RELEASE_TARBALL"
|
sha256 "REPLACE_WITH_SHA256_OF_RELEASE_TARBALL"
|
||||||
license "AGPL-3.0-or-later"
|
license "AGPL-3.0-or-later"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -19,7 +19,7 @@
|
||||||
|
|
||||||
|
|
||||||
Name: vaptvupt
|
Name: vaptvupt
|
||||||
Version: 5.0.0
|
Version: 5.1.0
|
||||||
Release: 0
|
Release: 0
|
||||||
Summary: Post-quantum backup compression with AES-256 + ML-KEM-768 hybrid encryption
|
Summary: Post-quantum backup compression with AES-256 + ML-KEM-768 hybrid encryption
|
||||||
License: AGPL-3.0-or-later
|
License: AGPL-3.0-or-later
|
||||||
|
|
@ -106,3 +106,8 @@ chmod +x tests/*.sh
|
||||||
%{_mandir}/man1/zupt.1%{?ext_man}
|
%{_mandir}/man1/zupt.1%{?ext_man}
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Sat Jul 11 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.1.0-1
|
||||||
|
- Codec 2.65.0; large compression-ratio gains (auto format_v2 + level-scaled
|
||||||
|
block window); --dedup keeps a small block; GUI compress-hang and
|
||||||
|
job-completion-crash fixes. Wire format unchanged (v1.6).
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -20,7 +20,7 @@
|
||||||
# in the base.
|
# in the base.
|
||||||
|
|
||||||
Name: vaptvupt
|
Name: vaptvupt
|
||||||
Version: 5.0.0
|
Version: 5.1.0
|
||||||
Release: 1%{?dist}
|
Release: 1%{?dist}
|
||||||
Summary: Post-quantum backup compression utility (AES-256 + ML-KEM-768 + Argon2id, formerly Zupt)
|
Summary: Post-quantum backup compression utility (AES-256 + ML-KEM-768 + Argon2id, formerly Zupt)
|
||||||
|
|
||||||
|
|
@ -109,6 +109,11 @@ and optional encrypted comments.
|
||||||
%endif
|
%endif
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Sat Jul 11 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.1.0-1
|
||||||
|
- Codec 2.65.0; large compression-ratio gains (auto format_v2 + level-scaled
|
||||||
|
block window); --dedup keeps a small block; GUI compress-hang and
|
||||||
|
job-completion-crash fixes. Wire format unchanged (v1.6).
|
||||||
|
|
||||||
* Fri Jul 10 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.0.0-1
|
* Fri Jul 10 2026 Cristian Cezar Moisés <sac@securityops.co> - 5.0.0-1
|
||||||
- ML-KEM-768 is now genuinely FIPS 203-conformant (was round-3 CRYSTALS-Kyber):
|
- ML-KEM-768 is now genuinely FIPS 203-conformant (was round-3 CRYSTALS-Kyber):
|
||||||
fixed a transposed matrix-A sampling convention, the round-3 KDF, and the
|
fixed a transposed matrix-A sampling convention, the round-3 KDF, and the
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue