Version fields, changelogs (rpm/deb/openSUSE), and download references
across README/INSTALL/DISTRIBUTION/gui-README bumped to 4.2.1 for the
info-label point release. GUI stays 1.3.0. No code change here.
The CLI AppImage no longer bundles libzuptsdk/libpqvaptvupt (removed in
the 4.1.0 source-only switch); the binary links only libc/libm/pthread
from the host. Drop the vendored-library install and the LD_LIBRARY_PATH
in AppRun, and default VERSION to 4.2.0.
- 2026-07-09 is a Thursday; fix the weekday in the rpm, debian, and
openSUSE 4.2.0 changelog entries (was "Wed").
- packaging/rpm/vaptvupt.spec: drop the stale vendored-library install
and %files entries (the libraries were removed in 4.1.0's source-only
switch), build with WITH_SDK=0, and list the actual vaptvupt binary
and shell completions. Mirrors the already-source-only openSUSE spec.
Add a native full post-quantum encryption mode and fix a critical
keystream-reuse bug in deduplicated encrypted archives.
Full post-quantum mode (--pq-only)
- New envelope type 0x06 (ZUPT_ENC_PQ_ONLY): ML-KEM-768 (FIPS 203) as
the sole key-establishment mechanism, with no classical X25519
component. Archive key = SHA3-512(ml_ss || ml_ct || "ZUPT-PQ-ONLY-v1").
- For compliance postures that require a single NIST-standardised PQ
primitive with no classical KEM in the envelope (CNSA 2.0-style
"PQ-only"). Hybrid --pq stays the recommended default; --pq-only has
no classical fallback, so a break of ML-KEM-768 alone breaks it.
- keygen --pq-only / keygen --pub --pq-only (ZPQK magic, 1200B pub /
3600B priv; not interchangeable with hybrid --pq keys). Wrong or
tampered ciphertext is rejected via ML-KEM FO implicit rejection plus
the HMAC-SHA256 Encrypt-then-MAC envelope. In-tree, default build.
Security (critical): AES-256-CTR keystream reuse under --dedup
- Dedup assigns block sequence 0 to every data block (the sentinel that
keeps cross-file dedup references authenticating consistently). The
per-block nonce was base_nonce XOR block_seq, so under --dedup every
block collapsed to the same nonce, reusing the CTR keystream across
distinct plaintexts (a many-time-pad). Each block now uses a fresh
random 128-bit nonce stored in the block prefix and bound into the
block MAC; block_seq is still bound as MAC AAD. Regression test:
tests/test_dedup_nonce.sh. Re-encrypt any --dedup encrypted archives
written by <= 4.1.0.
Other
- keygen --sdk / --box on a source-only build now fails with a clear
message pointing to native --pq / --pq-only (or a WITH_SDK=1 build).
- Documentation: README, SECURITY, THREAT_MODEL, man page, CHANGELOG,
and all packaging recipes updated for the new mode and the security
fix; version bumped to 4.2.0. Wire format v1.6 unchanged (0x06 is
additive).
Validation: make check 16/16, quick suite 11/11 (incl. PQ-only),
dedup-nonce regression (all block nonces distinct), cppcheck clean.
Build from source with no vendored binaries:
- Remove prebuilt libzuptsdk.so / libpqvaptvupt.so (and a stray .pyc). The
default build needs only a C compiler + make; it links no external library
and installs no .so. The libzuptsdk-backed modes (Argon2id KDF, --pq-sdk,
--pq-box) are gated behind an opt-in `make WITH_SDK=1`. The default password
KDF is PBKDF2-SHA256 and --pq (native ML-KEM-768 + X25519) is the built-in PQ
mode. openSUSE/RPM/deb/AUR/Homebrew/Nix recipes bumped to 4.1.0; the openSUSE
spec now builds source-only (%files ships no .so, %build/%install WITH_SDK=0).
Fix: multithreaded encrypted archives were unextractable on the native AEAD
path. The parallel compress/decompress workers skipped the F-09 frame-preface
AAD that the serial path and the archive's AAD_PREFACE flag bind into every
block MAC, so each multithreaded block failed authentication. The workers now
bind the preface via a shared serializer; output is byte-identical across
thread counts and interoperates with single-threaded archives (also fixes
`--kdf pbkdf2 -t N` in any build).
Security hardening (crafted-archive memory safety + crypto):
- LZH raw code-length stack overflow + huff_lut OOB write
- overflow-safe bounds in parse_index and solid-mode extract (heap OOB read)
- SEQ decoder safe-zone heap overflow (litlen+matchlen reserve)
- require the per-block ENCRYPTED flag on encrypted archives (plaintext forgery)
- cap archive-supplied PBKDF2 iteration count (KDF-amplification DoS)
- non-elidable secret wipe in the SDK path; restored disk images created 0600
Docs: remove AUDIT.md / BENCHMARKS.md / ROADMAP.md; trim marketing/AI-styled
text and correct KDF/PQ facts across README, SECURITY, INSTALL, DISTRIBUTION,
THREAT_MODEL, THIRD-PARTY-NOTICES, the man page, and packaging READMEs. Wire
format v1.6 unchanged.
Major release. Highlights:
- Codec: vendored VaptVupt codec moves to canonical 2.60.4 security
release. Fixes a high-severity OOB heap write in the AVX2 decode fast
path (reachable on a valid stream sized to exactly content_size, both
tail variants). Brings CBMC-formally-verified BCJ filters with
automatic ELF/PE/Mach-O detection. Compressed output stays
byte-identical (ratio gate Δ 0.00%); wire format unchanged at v1.6.
- New --pq-box sealed-box recipient mode (vendored libpqvaptvupt 0.6.0):
ML-KEM-768 + X25519 combined via HKDF-SHA256 with domain separation,
AES-256-CTR + HMAC-SHA256 EtM. Legacy --pq and --pq-sdk stay readable.
- F-16: discloses and fixes a pre-existing data-loss defect in the
<= 3.8.0 in-tree BCJ encoder. Full back-compat matrix decodes
byte-exact under 4.0.0; every readable pre-4.0 archive remains readable.
Repository hygiene:
- Sync full 4.0.0 source tree (codec, crypto, SDK, GUI, packaging, tests).
- Remove internal scratch files (PROMPT.md, FORMAL_AUDIT_PROMPT.md)
and superseded version-specific docs (INTEGRATION_PROTOCOL_2.60.4.md,
docs/FINDINGS-2.x.md) and a stray test binary.
- Refresh README download/install section to real 4.0.0 release assets;
bump version badge to 4.0.0.
- Add .gitignore for build outputs (keeps vendored prebuilt libraries).