zupt/THIRD-PARTY-NOTICES.md
Cristian Cezar Moisés 4874010d0e v4.1.0: source-only build, multithreaded-encryption fix, security hardening
Build from source with no vendored binaries:
- Remove prebuilt libzuptsdk.so / libpqvaptvupt.so (and a stray .pyc). The
  default build needs only a C compiler + make; it links no external library
  and installs no .so. The libzuptsdk-backed modes (Argon2id KDF, --pq-sdk,
  --pq-box) are gated behind an opt-in `make WITH_SDK=1`. The default password
  KDF is PBKDF2-SHA256 and --pq (native ML-KEM-768 + X25519) is the built-in PQ
  mode. openSUSE/RPM/deb/AUR/Homebrew/Nix recipes bumped to 4.1.0; the openSUSE
  spec now builds source-only (%files ships no .so, %build/%install WITH_SDK=0).

Fix: multithreaded encrypted archives were unextractable on the native AEAD
path. The parallel compress/decompress workers skipped the F-09 frame-preface
AAD that the serial path and the archive's AAD_PREFACE flag bind into every
block MAC, so each multithreaded block failed authentication. The workers now
bind the preface via a shared serializer; output is byte-identical across
thread counts and interoperates with single-threaded archives (also fixes
`--kdf pbkdf2 -t N` in any build).

Security hardening (crafted-archive memory safety + crypto):
- LZH raw code-length stack overflow + huff_lut OOB write
- overflow-safe bounds in parse_index and solid-mode extract (heap OOB read)
- SEQ decoder safe-zone heap overflow (litlen+matchlen reserve)
- require the per-block ENCRYPTED flag on encrypted archives (plaintext forgery)
- cap archive-supplied PBKDF2 iteration count (KDF-amplification DoS)
- non-elidable secret wipe in the SDK path; restored disk images created 0600

Docs: remove AUDIT.md / BENCHMARKS.md / ROADMAP.md; trim marketing/AI-styled
text and correct KDF/PQ facts across README, SECURITY, INSTALL, DISTRIBUTION,
THREAT_MODEL, THIRD-PARTY-NOTICES, the man page, and packaging READMEs. Wire
format v1.6 unchanged.
2026-07-07 19:45:37 -03:00

4.6 KiB

THIRD-PARTY NOTICES

This document records VaptVupt's runtime dependencies and build-time tools. If you redistribute VaptVupt, you must preserve this attribution document along with the LICENSE file.


Licensing

Note on VaptVupt LZ codec licensing: the VaptVupt LZ codec (src/vv_.c, src/vaptvupt_api.c, include/vaptvupt.h) is licensed GPL-3.0-or-later (not AGPL like the rest of the project) so that, with sufficient maturity, it can be considered for upstreaming into the Linux or BSD kernels, which require GPL-compatible licenses. The author retains the right to dual-license the codec under other terms for commercial use; contact sac@securityops.co for inquiries.

The rest of the project (vaptvupt CLI, Jasmin source, GUI) is licensed AGPL-3.0-or-later. Commercial licenses (relief from the AGPL network-use clause) are available; contact sac@securityops.co.


Build-time tool (not redistributed)

jasminc — the Jasmin language compiler

The constant-time cryptographic primitives in jasmin/.jazz are compiled to native assembly (jasmin/.s) using the external jasminc compiler. The jasminc tool is not bundled with VaptVupt; the AGPL .jazz source files and their AGPL-licensed .s assembly output are bundled.

Upstream: https://github.com/jasmin-lang/jasmin License: MIT (the compiler itself; not relevant to VaptVupt's licensing) Used by: VaptVupt's build system, only when re-generating jasmin/.s from jasmin/.jazz (most users won't need to do this — pre-built .s files ship in this repo).


Runtime system libraries (linked from the OS, never bundled)

These are standard system libraries provided by the operating system's package manager (apt, dnf, pacman, etc.). They are dynamically linked at runtime and are NOT redistributed as part of VaptVupt.

libargon2 — Argon2id password hashing function (RFC 9106)

Required only for: the optional make WITH_SDK=1 build. The default build uses native PBKDF2-SHA256 and does not link libargon2. Linked at runtime: libargon2.so.1 Version expected: 1.0+ (Debian/Ubuntu: libargon2-1) Upstream: https://github.com/P-H-C/phc-winner-argon2 License: Apache-2.0 OR CC0-1.0 (dual) Copyright: (c) 2015 The Argon2 Authors Used by: Argon2id password-derived encryption mode

OpenSSL libcrypto — AES, SHA-256, AES-NI hardware backends

Linked at runtime: libcrypto.so.3 Version expected: 3.0+ Upstream: https://www.openssl.org License: Apache-2.0 Copyright: (c) 1998-2026 The OpenSSL Project Used by: AES-256-CTR, SHA-256, hardware-accelerated paths


Compatibility with public standards

Where VaptVupt implements public standards, it does so independently from any reference implementation. Other projects in the post-quantum hybrid encryption space (libsodium, age, Tink, rustls, etc.) were referenced as prior art during design, but no code was copied from any external project. Standards followed:

  • FIPS 197 (AES)
  • FIPS 202 (Keccak / SHA-3)
  • FIPS 203 (ML-KEM)
  • RFC 5297 (AES-SIV)
  • RFC 5869 (HKDF)
  • RFC 7748 (X25519)
  • RFC 8032 (Ed25519)
  • RFC 8439 (ChaCha20-Poly1305)
  • RFC 9106 (Argon2)
  • RFC 9180 (HPKE)

Reporting attribution issues

If you believe VaptVupt redistributes code from a project not listed here, or if attribution information is incomplete, please email:

sac@securityops.co

with the subject "[third-party]" and details of the issue.


License summary

VaptVupt CLI, Jasmin source, GUI: AGPL-3.0-or-later VaptVupt LZ codec: GPL-3.0-or-later Commercial license (any component): contact sac@securityops.co

Project home: https://git.securityops.co/cristiancmoises/vaptvupt