Add a native full post-quantum encryption mode and fix a critical
keystream-reuse bug in deduplicated encrypted archives.
Full post-quantum mode (--pq-only)
- New envelope type 0x06 (ZUPT_ENC_PQ_ONLY): ML-KEM-768 (FIPS 203) as
the sole key-establishment mechanism, with no classical X25519
component. Archive key = SHA3-512(ml_ss || ml_ct || "ZUPT-PQ-ONLY-v1").
- For compliance postures that require a single NIST-standardised PQ
primitive with no classical KEM in the envelope (CNSA 2.0-style
"PQ-only"). Hybrid --pq stays the recommended default; --pq-only has
no classical fallback, so a break of ML-KEM-768 alone breaks it.
- keygen --pq-only / keygen --pub --pq-only (ZPQK magic, 1200B pub /
3600B priv; not interchangeable with hybrid --pq keys). Wrong or
tampered ciphertext is rejected via ML-KEM FO implicit rejection plus
the HMAC-SHA256 Encrypt-then-MAC envelope. In-tree, default build.
Security (critical): AES-256-CTR keystream reuse under --dedup
- Dedup assigns block sequence 0 to every data block (the sentinel that
keeps cross-file dedup references authenticating consistently). The
per-block nonce was base_nonce XOR block_seq, so under --dedup every
block collapsed to the same nonce, reusing the CTR keystream across
distinct plaintexts (a many-time-pad). Each block now uses a fresh
random 128-bit nonce stored in the block prefix and bound into the
block MAC; block_seq is still bound as MAC AAD. Regression test:
tests/test_dedup_nonce.sh. Re-encrypt any --dedup encrypted archives
written by <= 4.1.0.
Other
- keygen --sdk / --box on a source-only build now fails with a clear
message pointing to native --pq / --pq-only (or a WITH_SDK=1 build).
- Documentation: README, SECURITY, THREAT_MODEL, man page, CHANGELOG,
and all packaging recipes updated for the new mode and the security
fix; version bumped to 4.2.0. Wire format v1.6 unchanged (0x06 is
additive).
Validation: make check 16/16, quick suite 11/11 (incl. PQ-only),
dedup-nonce regression (all block nonces distinct), cppcheck clean.
Build from source with no vendored binaries:
- Remove prebuilt libzuptsdk.so / libpqvaptvupt.so (and a stray .pyc). The
default build needs only a C compiler + make; it links no external library
and installs no .so. The libzuptsdk-backed modes (Argon2id KDF, --pq-sdk,
--pq-box) are gated behind an opt-in `make WITH_SDK=1`. The default password
KDF is PBKDF2-SHA256 and --pq (native ML-KEM-768 + X25519) is the built-in PQ
mode. openSUSE/RPM/deb/AUR/Homebrew/Nix recipes bumped to 4.1.0; the openSUSE
spec now builds source-only (%files ships no .so, %build/%install WITH_SDK=0).
Fix: multithreaded encrypted archives were unextractable on the native AEAD
path. The parallel compress/decompress workers skipped the F-09 frame-preface
AAD that the serial path and the archive's AAD_PREFACE flag bind into every
block MAC, so each multithreaded block failed authentication. The workers now
bind the preface via a shared serializer; output is byte-identical across
thread counts and interoperates with single-threaded archives (also fixes
`--kdf pbkdf2 -t N` in any build).
Security hardening (crafted-archive memory safety + crypto):
- LZH raw code-length stack overflow + huff_lut OOB write
- overflow-safe bounds in parse_index and solid-mode extract (heap OOB read)
- SEQ decoder safe-zone heap overflow (litlen+matchlen reserve)
- require the per-block ENCRYPTED flag on encrypted archives (plaintext forgery)
- cap archive-supplied PBKDF2 iteration count (KDF-amplification DoS)
- non-elidable secret wipe in the SDK path; restored disk images created 0600
Docs: remove AUDIT.md / BENCHMARKS.md / ROADMAP.md; trim marketing/AI-styled
text and correct KDF/PQ facts across README, SECURITY, INSTALL, DISTRIBUTION,
THREAT_MODEL, THIRD-PARTY-NOTICES, the man page, and packaging READMEs. Wire
format v1.6 unchanged.