Add a native full post-quantum encryption mode and fix a critical keystream-reuse bug in deduplicated encrypted archives. Full post-quantum mode (--pq-only) - New envelope type 0x06 (ZUPT_ENC_PQ_ONLY): ML-KEM-768 (FIPS 203) as the sole key-establishment mechanism, with no classical X25519 component. Archive key = SHA3-512(ml_ss || ml_ct || "ZUPT-PQ-ONLY-v1"). - For compliance postures that require a single NIST-standardised PQ primitive with no classical KEM in the envelope (CNSA 2.0-style "PQ-only"). Hybrid --pq stays the recommended default; --pq-only has no classical fallback, so a break of ML-KEM-768 alone breaks it. - keygen --pq-only / keygen --pub --pq-only (ZPQK magic, 1200B pub / 3600B priv; not interchangeable with hybrid --pq keys). Wrong or tampered ciphertext is rejected via ML-KEM FO implicit rejection plus the HMAC-SHA256 Encrypt-then-MAC envelope. In-tree, default build. Security (critical): AES-256-CTR keystream reuse under --dedup - Dedup assigns block sequence 0 to every data block (the sentinel that keeps cross-file dedup references authenticating consistently). The per-block nonce was base_nonce XOR block_seq, so under --dedup every block collapsed to the same nonce, reusing the CTR keystream across distinct plaintexts (a many-time-pad). Each block now uses a fresh random 128-bit nonce stored in the block prefix and bound into the block MAC; block_seq is still bound as MAC AAD. Regression test: tests/test_dedup_nonce.sh. Re-encrypt any --dedup encrypted archives written by <= 4.1.0. Other - keygen --sdk / --box on a source-only build now fails with a clear message pointing to native --pq / --pq-only (or a WITH_SDK=1 build). - Documentation: README, SECURITY, THREAT_MODEL, man page, CHANGELOG, and all packaging recipes updated for the new mode and the security fix; version bumped to 4.2.0. Wire format v1.6 unchanged (0x06 is additive). Validation: make check 16/16, quick suite 11/11 (incl. PQ-only), dedup-nonce regression (all block nonces distinct), cppcheck clean.
3.8 KiB
openSUSE Build Service update for home:cabelo:innovators/vaptvupt
This directory contains the three files needed to build vaptvupt 4.2.0
in OBS:
| File | Purpose |
|---|---|
_service |
revision pinned to v4.2.0. Format unchanged (still tar_scm). |
vaptvupt.spec |
Version: 4.2.0. License: AGPL-3.0-or-later. %check calls make check. |
vaptvupt.changes |
Changelog for the 4.x series. Older history preserved verbatim. |
Spec notes
-
License —
AGPL-3.0-or-later(dual-licensed AGPL-3.0-or-later- commercial).
-
No BuildRequires beyond the toolchain — the default build needs only
gcc gzip make(pluslibm/pthreadfrom glibc). There are no system library BuildRequires. The repository is source-only: the previously vendoredlibzuptsdk.soandlibpqvaptvupt.sohave been removed from the tree,%buildand%installrun withWITH_SDK=0, and%filesno longer lists any.so. The package installs no shared library. Do not add system crypto BuildRequires.The optional SDK modes (
--pq-sdk,--pq-box) and the Argon2id KDF require an upstreammake WITH_SDK=1build linked against the separately distributedlibzuptsdk/libpqvaptvuptlibraries. They are not part of this package. -
%checktarget — the s390x branch falls back totest-vectors; other architectures runmake check. This exercises the HMAC tamper detection, archive-integrity trailer, byte-level integrity preface AAD, default-KDF, auth-fail, and encrypted-comment suites, the NIST/RFC vectors (SHA-256, SHA-3, ML-KEM-768, AES-256-CTR, HMAC, X25519, PBKDF2), and the path-traversal, argument-order, and block-swap regressions.The default password KDF is PBKDF2-SHA256 (600k iterations). Argon2id test vectors run only in a
WITH_SDK=1build and are not checked here. -
URLs — the
URL:field points at the canonical project URLhttps://git.securityops.co/cristiancmoises/vaptvupt. The_servicefile still fetches from GitHub (https://github.com/cristiancmoises/vaptvupt), which is what the existingtar_scmconfiguration uses in OBS.
How to apply
# 1. Check out the package
osc checkout home:cabelo:innovators vaptvupt
cd home:cabelo:innovators/vaptvupt
# 2. Drop the new files in (assuming this README is at
# /path/to/vaptvupt-source/packaging/opensuse/README.md)
cp /path/to/vaptvupt-source/packaging/opensuse/_service .
cp /path/to/vaptvupt-source/packaging/opensuse/vaptvupt.spec .
cp /path/to/vaptvupt-source/packaging/opensuse/vaptvupt.changes .
# 3. Trigger the service locally to fetch v4.2.0 from GitHub
osc service runall
# Produces vaptvupt-4.2.0.tar.gz in the current directory.
# 4. (Optional) Local build to verify before committing
osc build openSUSE_Tumbleweed x86_64
# 5. Commit upstream
osc status # confirm vaptvupt-4.2.0.tar.gz is staged alongside the
# three text files
osc commit -m "Update to 4.2.0"
Notes for future updates
- The
_servicerevisionis pinned tov4.2.0. To track a new release, edit that one line and re-runosc service runall. - The spec's
Version:field is hard-coded — when you bump_servicerevision, also bumpVersion:to match. BuildRequiresis intentionally minimal (gcc gzip make). vaptvupt has no external library dependencies in the default build; do not add system crypto BuildRequires.
Reporting issues
- Upstream bugs: https://git.securityops.co/cristiancmoises/vaptvupt
- openSUSE packaging bugs: https://bugs.opensuse.org/
- Cabelo's OBS project: https://build.opensuse.org/project/show/home:cabelo:innovators