diff --git a/DISTRIBUTION.md b/DISTRIBUTION.md index 6f92b6b..ac7f904 100644 --- a/DISTRIBUTION.md +++ b/DISTRIBUTION.md @@ -10,7 +10,7 @@ Every packaging recipe expects an upstream tarball `vaptvupt-VERSION.tar.gz` pro ```sh make dist -# → /tmp/vaptvupt-4.2.0.tar.gz +# → /tmp/vaptvupt-4.2.1.tar.gz ``` Re-running `make dist` on the same source tree produces an identical sha256 (verified by `tests/test_dist_reproducible.sh`, wired into `make test`). This lets distros pin a stable hash in their recipes. @@ -56,13 +56,13 @@ Maintainer flow: ```sh # 1. Produce the upstream tarball make dist -# → /tmp/vaptvupt-4.2.0.tar.gz +# → /tmp/vaptvupt-4.2.1.tar.gz # 2. Upload to a stable URL (e.g. git.securityops.co releases) # 3. Update packaging/aur/PKGBUILD: -# - Set pkgver=4.2.0 -# - Set sha256sums=("$(sha256sum /tmp/vaptvupt-4.2.0.tar.gz | awk '{print $1}')") +# - Set pkgver=4.2.1 +# - Set sha256sums=("$(sha256sum /tmp/vaptvupt-4.2.1.tar.gz | awk '{print $1}')") # 4. Generate .SRCINFO cd packaging/aur && makepkg --printsrcinfo > .SRCINFO @@ -73,7 +73,7 @@ makepkg -s # 6. Push to AUR git clone ssh://aur@aur.archlinux.org/vaptvupt.git aur-vaptvupt cp packaging/aur/PKGBUILD packaging/aur/.SRCINFO aur-vaptvupt/ -cd aur-vaptvupt && git add -A && git commit -m "v4.2.0" && git push +cd aur-vaptvupt && git add -A && git commit -m "v4.2.1" && git push ``` User install: @@ -117,10 +117,10 @@ The `packaging/debian/` tree is a Debian source-package layout. Maintainer flow: # 1. Produce the upstream tarball with the standard Debian # orig.tar.gz naming convention: make dist -cp /tmp/vaptvupt-4.2.0.tar.gz /tmp/vaptvupt_4.2.0.orig.tar.gz +cp /tmp/vaptvupt-4.2.1.tar.gz /tmp/vaptvupt_4.2.1.orig.tar.gz # 2. Unpack and overlay the debian/ tree: -cd /tmp && tar xzf vaptvupt_4.2.0.orig.tar.gz && cd vaptvupt-4.2.0 +cd /tmp && tar xzf vaptvupt_4.2.1.orig.tar.gz && cd vaptvupt-4.2.1 cp -a /path/to/vaptvupt/packaging/debian ./debian # 3. Build the source package: @@ -128,7 +128,7 @@ dpkg-buildpackage -S -us -uc # source-only dpkg-buildpackage -b -us -uc # binary # 4. Lint: -lintian vaptvupt_4.2.0-1_*.deb +lintian vaptvupt_4.2.1-1_*.deb # 5. Submit via the standard Debian mentors process: # https://mentors.debian.net/intro-maintainers/ @@ -145,7 +145,7 @@ sudo apt install vaptvupt ```sh # 1. Produce the tarball make dist -cp /tmp/vaptvupt-4.2.0.tar.gz ~/rpmbuild/SOURCES/ +cp /tmp/vaptvupt-4.2.1.tar.gz ~/rpmbuild/SOURCES/ # 2. Drop the .spec into the SPECS directory: cp packaging/rpm/vaptvupt.spec ~/rpmbuild/SPECS/ @@ -154,7 +154,7 @@ cp packaging/rpm/vaptvupt.spec ~/rpmbuild/SPECS/ cd ~/rpmbuild && rpmbuild -ba SPECS/vaptvupt.spec # 4. Lint: -rpmlint RPMS/x86_64/vaptvupt-4.2.0-1.fc*.rpm +rpmlint RPMS/x86_64/vaptvupt-4.2.1-1.fc*.rpm # 5. Submit via the Fedora new-package review process: # https://docs.fedoraproject.org/en-US/package-maintainers/Package_Review_Process/ @@ -177,7 +177,7 @@ The `packaging/opensuse/` tree carries an RPM `.spec` suited to the Open Build S make dist # 2. In an OBS package checkout (osc), stage the sources and spec: -cp /tmp/vaptvupt-4.2.0.tar.gz . +cp /tmp/vaptvupt-4.2.1.tar.gz . cp /path/to/vaptvupt/packaging/opensuse/vaptvupt.spec . # 3. Build locally against a target repository: @@ -230,7 +230,7 @@ nix build github:cristiancmoises/vaptvupt#vaptvupt nix run github:cristiancmoises/vaptvupt#vaptvupt -- version # 2. To consume from another flake: -# inputs.vaptvupt.url = "github:cristiancmoises/vaptvupt?ref=v4.2.0"; +# inputs.vaptvupt.url = "github:cristiancmoises/vaptvupt?ref=v4.2.1"; # packages.x86_64-linux.default = inputs.vaptvupt.packages.x86_64-linux.vaptvupt; # 3. To submit to nixpkgs (https://github.com/NixOS/nixpkgs): diff --git a/INSTALL.md b/INSTALL.md index 3ff4778..7c99e01 100644 --- a/INSTALL.md +++ b/INSTALL.md @@ -5,13 +5,13 @@ If you're seeing the error: ``` vaptvupt-gui depende de python3-pyqt6 | python3-pyside6; porém: Pacote python3-pyqt6 não está instalado. -vaptvupt-gui depende de vaptvupt (>= 4.2.0); porém: +vaptvupt-gui depende de vaptvupt (>= 4.2.1); porém: Versão de vaptvupt no sistema é 2.1.7-1. ``` This is correct behavior. The `vaptvupt-gui` deb requires: - Python 3 with **PyQt6** or **PySide6** (the GUI toolkit) -- The **vaptvupt CLI 4.2.0** or newer +- The **vaptvupt CLI 4.2.1** or newer ## The fastest fix — one command (Linux Mint, Ubuntu, Debian) @@ -33,8 +33,8 @@ the right order. sudo apt update sudo apt install -y python3-pyqt6 -# 2. Upgrade vaptvupt CLI to 4.2.0 -sudo dpkg -i vaptvupt_4.2.0_amd64.deb +# 2. Upgrade vaptvupt CLI to 4.2.1 +sudo dpkg -i vaptvupt_4.2.1_amd64.deb # 3. Install the GUI sudo dpkg -i vaptvupt-gui_1.3.0_all.deb @@ -50,7 +50,7 @@ sudo apt --fix-broken install ```bash sudo dnf install -y python3-pyqt6 -sudo dnf install -y vaptvupt-4.2.0-1.x86_64.rpm vaptvupt-gui-1.3.0-1.noarch.rpm +sudo dnf install -y vaptvupt-4.2.1-1.x86_64.rpm vaptvupt-gui-1.3.0-1.noarch.rpm ``` (Or build the RPM from the SRPM tarball with `rpmbuild -bb SPECS/vaptvupt.spec`) @@ -98,7 +98,7 @@ Qt6 inside the deb because: - Bundling would make the deb 80 MB+ instead of 35 KB - Distribution-managed Qt gets security updates automatically -## Why does the GUI need vaptvupt 4.2.0? +## Why does the GUI need vaptvupt 4.2.1? The GUI calls `vaptvupt --pq` and `vaptvupt keygen` for native post-quantum encryption (ML-KEM-768 + X25519, in-tree implementation). @@ -108,7 +108,7 @@ fail against them. ## After installing — verify ```bash -vaptvupt version # should show: 4.2.0 +vaptvupt version # should show: 4.2.1 vaptvupt-gui # should launch the GUI window ``` @@ -178,8 +178,8 @@ sudo zypper install gcc make # openSUSE ### Build VaptVupt itself ```bash -tar -xzf vaptvupt-4.2.0-source.tar.gz -cd vaptvupt-4.2.0 +tar -xzf vaptvupt-4.2.1-source.tar.gz +cd vaptvupt-4.2.1 make # build the `./vaptvupt` binary sudo make install # install to /usr/local/bin (override with PREFIX=/usr) diff --git a/README.md b/README.md index 9e567bb..c2e94d4 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,14 @@ License: AGPL-3.0-or-later (dual-licensed AGPL + commercial). > command is preserved as a symlink to `vaptvupt` for one major version > cycle. -## What's new in 4.2.0 +## What's new in 4.2.1 / 4.2.0 + +- **4.2.1 (patch):** `vaptvupt info` now correctly reports the post-quantum + mode — a `--pq-only` archive reads "ML-KEM-768 only, no classical layer" + instead of being mislabelled as hybrid. Reader-side only; no wire-format + change, and existing 4.2.0 archives are relabelled with no re-encryption. + +The 4.2.0 feature set (all included in 4.2.1): - **Full (pure) post-quantum mode — `--pq-only`.** ML-KEM-768 (FIPS 203) as the *sole* key-establishment mechanism, with no classical X25519 component. @@ -43,11 +50,11 @@ License: AGPL-3.0-or-later (dual-licensed AGPL + commercial). > **F-16 (data loss):** archives created by **≤ 3.8.0** at `-l 8`/`-l 9` > whose inputs included x86/ELF/PE executables may be **undecodable by any > version** (write-time defect in the old in-tree BCJ encoder). Re-create -> such archives with 4.2.0 and verify extraction before deleting source +> such archives with 4.2.1 and verify extraction before deleting source > data. Details in [CHANGELOG.md](CHANGELOG.md). -Binaries for the CLI (4.2.0) and GUI (1.3.0) are on the -[release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v4.2.0). +Binaries for the CLI (4.2.1) and GUI (1.3.0) are on the +[release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v4.2.1). --- @@ -122,18 +129,18 @@ Argon2id KDF. ### Pre-built packages Assets are published on the -[v4.2.0 release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v4.2.0) +[v4.2.1 release page](https://git.securityops.co/cristiancmoises/vaptvupt/releases/tag/v4.2.1) and verifiable against the published `SHA256SUMS.txt`. -**Command-line tool (`vaptvupt` 4.2.0):** +**Command-line tool (`vaptvupt` 4.2.1):** | Format | File | Distros | |---|---|---| -| Debian/Ubuntu | `vaptvupt_4.2.0_amd64.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ | -| RPM | `vaptvupt-4.2.0-1.x86_64.rpm` | Fedora 38+, RHEL 9+, openSUSE, AlmaLinux, Rocky, other RPM-based distributions | -| AppDir tarball | `vaptvupt-4.2.0-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run, no FUSE) | -| Source tarball | `vaptvupt-4.2.0.tar.gz` | Build from source on any platform | -| openSUSE OBS | `vaptvupt-4.2.0-opensuse-obs.tar.gz` | Open Build Service source bundle | +| Debian/Ubuntu | `vaptvupt_4.2.1_amd64.deb` | Debian 11+, Ubuntu 22.04+, Mint 21+ | +| RPM | `vaptvupt-4.2.1-1.x86_64.rpm` | Fedora 38+, RHEL 9+, openSUSE, AlmaLinux, Rocky, other RPM-based distributions | +| AppDir tarball | `vaptvupt-4.2.1-x86_64.AppDir.tar.gz` | Any glibc 2.28+ (extract & run, no FUSE) | +| Source tarball | `vaptvupt-4.2.1.tar.gz` | Build from source on any platform | +| openSUSE OBS | `vaptvupt-4.2.1-opensuse-obs.tar.gz` | Open Build Service source bundle | **Graphical front-end (`vaptvupt-gui` 1.3.0):** @@ -149,17 +156,17 @@ and verifiable against the published `SHA256SUMS.txt`. sha256sum -c SHA256SUMS.txt # Debian / Ubuntu / Mint -sudo dpkg -i vaptvupt_4.2.0_amd64.deb +sudo dpkg -i vaptvupt_4.2.1_amd64.deb sudo apt-get install -f # resolve any missing deps # Fedora / RHEL / openSUSE / AlmaLinux / Rocky and other RPM-based distros -sudo rpm -i vaptvupt-4.2.0-1.x86_64.rpm +sudo rpm -i vaptvupt-4.2.1-1.x86_64.rpm # or -sudo dnf install ./vaptvupt-4.2.0-1.x86_64.rpm +sudo dnf install ./vaptvupt-4.2.1-1.x86_64.rpm # AppDir tarball (no install, no FUSE required) -tar xzf vaptvupt-4.2.0-x86_64.AppDir.tar.gz -./vaptvupt-4.2.0-x86_64.AppDir/AppRun --help +tar xzf vaptvupt-4.2.1-x86_64.AppDir.tar.gz +./vaptvupt-4.2.1-x86_64.AppDir/AppRun --help # GUI AppImage (single executable) chmod +x VaptVupt-GUI-1.3.0-x86_64.AppImage @@ -169,10 +176,10 @@ chmod +x VaptVupt-GUI-1.3.0-x86_64.AppImage ### Building from SRPM (Fedora / RHEL / RPM-based distributions) ```bash -tar xzf vaptvupt-4.2.0.srpm.tar.gz +tar xzf vaptvupt-4.2.1.srpm.tar.gz cd ~/rpmbuild # or use rpmbuild --define "_topdir $(pwd)" rpmbuild -bb SPECS/vaptvupt.spec -sudo rpm -i RPMS/x86_64/vaptvupt-4.2.0-1.*.rpm +sudo rpm -i RPMS/x86_64/vaptvupt-4.2.1-1.*.rpm ``` ### Basic usage @@ -672,6 +679,7 @@ VaptVupt archives require VaptVupt v2.0+. | v4.0.0 | Codec 2.60.4 security release (OOB heap write fixed in AVX2 decode fast path), `--pq-box` sealed-box mode, F-16 data-loss disclosure + fix (old in-tree BCJ encoder), CBMC-verified BCJ filters with auto ELF/PE/Mach-O detection, SHA-NI acceleration. Wire format v1.6 | | v4.1.0 | Source-only tree (prebuilt libzuptsdk/libpqvaptvupt removed); default build needs only a C compiler + make; native `--pq` is the default PQ mode; `--pq-sdk`/`--pq-box`/Argon2id gated behind `make WITH_SDK=1`. Wire format stays v1.6 | | v4.2.0 | Full (pure) post-quantum mode `--pq-only` (ML-KEM-768 only, envelope 0x06); critical fix for AES-CTR keystream reuse under `--dedup` (fresh random per-block nonce); clearer SDK keygen guidance. Wire format stays v1.6 | +| v4.2.1 | `vaptvupt info` now reports the real post-quantum mode (`--pq-only` no longer mislabelled as hybrid); reader-side only, no wire-format change | See [CHANGELOG.md](CHANGELOG.md) for detailed per-version changes. diff --git a/SECURITY.md b/SECURITY.md index 8383305..c104113 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,4 +1,4 @@ -# Security Policy — VaptVupt 4.2.0 +# Security Policy — VaptVupt 4.2.1 ## Reporting Vulnerabilities diff --git a/THREAT_MODEL.md b/THREAT_MODEL.md index a497b1a..393d753 100644 --- a/THREAT_MODEL.md +++ b/THREAT_MODEL.md @@ -323,6 +323,6 @@ normally. ## Document version This threat model covers archive format v1.6 as shipped in VaptVupt -4.2.0. It is part of the source tree (`THREAT_MODEL.md`) and +4.2.1. It is part of the source tree (`THREAT_MODEL.md`) and versioned with the project; this section will be updated as the format evolves. diff --git a/gui/README.md b/gui/README.md index ae32def..7d9bdef 100644 --- a/gui/README.md +++ b/gui/README.md @@ -116,7 +116,7 @@ The GUI calls the vaptvupt CLI binary — all cryptography runs in native C, not ## Credits -- **vaptvupt** v4.2.0 — Cristian Cezar Moisés ([github](https://git.securityops.co/cristiancmoises/vaptvupt)) +- **vaptvupt** v4.2.1 — Cristian Cezar Moisés ([github](https://git.securityops.co/cristiancmoises/vaptvupt)) ## License diff --git a/packaging/aur/PKGBUILD b/packaging/aur/PKGBUILD index bb66ca0..d0e2066 100644 --- a/packaging/aur/PKGBUILD +++ b/packaging/aur/PKGBUILD @@ -11,7 +11,7 @@ # zupt-VERSION.tar.gz alongside the PKGBUILD. pkgname=vaptvupt -pkgver=4.2.0 +pkgver=4.2.1 pkgrel=1 provides=('zupt') replaces=('zupt') diff --git a/packaging/build-appimage.sh b/packaging/build-appimage.sh index 357aa20..9b710d1 100755 --- a/packaging/build-appimage.sh +++ b/packaging/build-appimage.sh @@ -6,7 +6,7 @@ set -e cd "$(dirname "$0")/.." -VERSION="${VERSION:-4.2.0}" +VERSION="${VERSION:-4.2.1}" ARCH="${ARCH:-x86_64}" PKGNAME="vaptvupt" LEGACY="zupt" diff --git a/packaging/debian/changelog b/packaging/debian/changelog index 49769b3..b6b2252 100644 --- a/packaging/debian/changelog +++ b/packaging/debian/changelog @@ -1,3 +1,16 @@ +vaptvupt (4.2.1-1) UNRELEASED; urgency=medium + + * Fix: `vaptvupt info` mislabelled full post-quantum (--pq-only, enc_type + 0x06) archives as "PQ Hybrid (ML-KEM-768 + X25519)". Full-PQ archives + set the generic ZUPT_FLAG_PQ_HYBRID header flag, but info only checked + that flag. info now reads the real enc_type from the encryption-header + block and reports the actual mode ("ML-KEM-768 only, no classical + layer" for --pq-only; hybrid / SDK-v2 / sealed-box otherwise). + Reader-side only — no wire-format change; existing 4.2.0 archives are + relabelled with no re-encryption. + + -- Cristian Cezar Moisés Fri, 10 Jul 2026 12:00:00 +0000 + vaptvupt (4.2.0-1) UNRELEASED; urgency=high * New native full (pure) post-quantum mode --pq-only: ML-KEM-768 (FIPS diff --git a/packaging/homebrew/vaptvupt.rb b/packaging/homebrew/vaptvupt.rb index 88bb44d..b5cd21a 100644 --- a/packaging/homebrew/vaptvupt.rb +++ b/packaging/homebrew/vaptvupt.rb @@ -23,8 +23,8 @@ class Vaptvupt < Formula desc "Post-quantum backup compression utility (ML-KEM-768 + AES-256-CTR + HMAC-SHA256)" homepage "https://git.securityops.co/cristiancmoises/zupt" - url "https://git.securityops.co/cristiancmoises/zupt/releases/download/v4.2.0/vaptvupt-4.2.0.tar.gz" - version "4.2.0" + url "https://git.securityops.co/cristiancmoises/zupt/releases/download/v4.2.1/vaptvupt-4.2.1.tar.gz" + version "4.2.1" sha256 "REPLACE_WITH_SHA256_OF_RELEASE_TARBALL" license "AGPL-3.0-or-later" diff --git a/packaging/nix/flake.nix b/packaging/nix/flake.nix index ab46dcb..efb3bc8 100644 --- a/packaging/nix/flake.nix +++ b/packaging/nix/flake.nix @@ -33,7 +33,7 @@ zupt = pkgs.stdenv.mkDerivation { pname = "vaptvupt"; - version = "4.2.0"; + version = "4.2.1"; # When publishing, replace this with `fetchurl` against the # release tarball. For local development the flake assumes it diff --git a/packaging/opensuse/README.md b/packaging/opensuse/README.md index 34aa636..d37ad13 100644 --- a/packaging/opensuse/README.md +++ b/packaging/opensuse/README.md @@ -1,12 +1,12 @@ # openSUSE Build Service update for `home:cabelo:innovators/vaptvupt` -This directory contains the three files needed to build vaptvupt `4.2.0` +This directory contains the three files needed to build vaptvupt `4.2.1` in OBS: | File | Purpose | |---------------|-------------------------------------------------------------------------| -| `_service` | `revision` pinned to `v4.2.0`. Format unchanged (still `tar_scm`). | -| `vaptvupt.spec` | `Version: 4.2.0`. `License: AGPL-3.0-or-later`. `%check` calls `make check`. | +| `_service` | `revision` pinned to `v4.2.1`. Format unchanged (still `tar_scm`). | +| `vaptvupt.spec` | `Version: 4.2.1`. `License: AGPL-3.0-or-later`. `%check` calls `make check`. | | `vaptvupt.changes`| Changelog for the 4.x series. Older history preserved verbatim. | ## Spec notes @@ -58,22 +58,22 @@ cp /path/to/vaptvupt-source/packaging/opensuse/_service . cp /path/to/vaptvupt-source/packaging/opensuse/vaptvupt.spec . cp /path/to/vaptvupt-source/packaging/opensuse/vaptvupt.changes . -# 3. Trigger the service locally to fetch v4.2.0 from GitHub +# 3. Trigger the service locally to fetch v4.2.1 from GitHub osc service runall -# Produces vaptvupt-4.2.0.tar.gz in the current directory. +# Produces vaptvupt-4.2.1.tar.gz in the current directory. # 4. (Optional) Local build to verify before committing osc build openSUSE_Tumbleweed x86_64 # 5. Commit upstream -osc status # confirm vaptvupt-4.2.0.tar.gz is staged alongside the +osc status # confirm vaptvupt-4.2.1.tar.gz is staged alongside the # three text files -osc commit -m "Update to 4.2.0" +osc commit -m "Update to 4.2.1" ``` ## Notes for future updates -* The `_service` `revision` is pinned to `v4.2.0`. To track a new +* The `_service` `revision` is pinned to `v4.2.1`. To track a new release, edit that one line and re-run `osc service runall`. * The spec's `Version:` field is hard-coded — when you bump `_service` `revision`, also bump `Version:` to match. diff --git a/packaging/opensuse/_service b/packaging/opensuse/_service index 18125a2..4453127 100644 --- a/packaging/opensuse/_service +++ b/packaging/opensuse/_service @@ -2,7 +2,7 @@ https://github.com/cristiancmoises/zupt git - v4.2.0 + v4.2.1 @PARENT_TAG@ v(.*) enable diff --git a/packaging/opensuse/vaptvupt.changes b/packaging/opensuse/vaptvupt.changes index c3e3261..eff6eeb 100644 --- a/packaging/opensuse/vaptvupt.changes +++ b/packaging/opensuse/vaptvupt.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Fri Jul 10 12:00:00 UTC 2026 - Alessandro de Oliveira Faria + +- Update to 4.2.1: + * Fix: "vaptvupt info" mislabelled full post-quantum (--pq-only) + archives as "PQ Hybrid (ML-KEM-768 + X25519)". info now reads the + real enc_type from the encryption-header block and reports the + actual mode ("ML-KEM-768 only, no classical layer" for --pq-only). + Reader-side only; no wire-format change, existing 4.2.0 archives are + relabelled with no re-encryption. + ------------------------------------------------------------------- Thu Jul 9 12:00:00 UTC 2026 - Alessandro de Oliveira Faria diff --git a/packaging/opensuse/vaptvupt.spec b/packaging/opensuse/vaptvupt.spec index b55b2b8..5cdb1a5 100644 --- a/packaging/opensuse/vaptvupt.spec +++ b/packaging/opensuse/vaptvupt.spec @@ -19,7 +19,7 @@ Name: vaptvupt -Version: 4.2.0 +Version: 4.2.1 Release: 0 Summary: Post-quantum backup compression with AES-256 + ML-KEM-768 hybrid encryption License: AGPL-3.0-or-later diff --git a/packaging/rpm/vaptvupt.spec b/packaging/rpm/vaptvupt.spec index ecd8a58..8610191 100644 --- a/packaging/rpm/vaptvupt.spec +++ b/packaging/rpm/vaptvupt.spec @@ -20,7 +20,7 @@ # in the base. Name: vaptvupt -Version: 4.2.0 +Version: 4.2.1 Release: 1%{?dist} Summary: Post-quantum backup compression utility (AES-256 + ML-KEM-768 + Argon2id, formerly Zupt) @@ -107,6 +107,12 @@ and optional encrypted comments. %endif %changelog +* Fri Jul 10 2026 Cristian Cezar Moisés - 4.2.1-1 +- Fix: "vaptvupt info" mislabelled full post-quantum (--pq-only) archives as + "PQ Hybrid (ML-KEM-768 + X25519)". info now reads the real enc_type from the + encryption-header block and reports the actual mode ("ML-KEM-768 only, no + classical layer" for --pq-only). Reader-side only; no wire-format change. + * Thu Jul 09 2026 Cristian Cezar Moisés - 4.2.0-1 - New native full (pure) post-quantum mode --pq-only: ML-KEM-768 as the sole KEM, no classical X25519 (envelope 0x06). For "PQ-only" compliance