zupt/vendor/vuptsdk/include/zuptsdk_easy.h
Cristian Cezar Moisés 51fa068f50 sdk: integrate libvuptsdk (renamed libzuptsdk); decouple --pq-box
libvuptsdk (git.securityops.co/cristiancmoises/libvuptsdk) is the renamed
libzuptsdk: only the .so filename/SONAME changed (libzuptsdk.so.2 ->
libvuptsdk.so.2); the C API (zuptsdk_* symbols, zuptsdk.h) is unchanged.

- Rename vendor/zuptsdk -> vendor/vuptsdk with libvuptsdk's headers.
- Makefile WITH_SDK=1 now links -lvuptsdk (+ its transitive libcrypto/libargon2
  deps via SDK_DEPLIBS) instead of -lzuptsdk, and installs libvuptsdk.so.*.
- DECOUPLE --pq-box: it needs the SEPARATE libpqvaptvupt, which libvuptsdk does
  NOT provide, so gate it behind a new WITH_PQBOX=1 (was folded into WITH_SDK).
  zupt_crypto_pqbox.c now keys on ZUPT_WITH_PQBOX; WITH_SDK=1 alone builds and
  links cleanly with just libvuptsdk and enables --pq-sdk + Argon2id.
- Banner/help renamed libzuptsdk -> libvuptsdk; the machine-readable 'Build:'
  line lists --pq-box only under WITH_PQBOX. GUI _get_caps matches on 'vuptsdk'.

Validated on Guix: WITH_SDK=1 links libvuptsdk + libcrypto + libargon2, runs,
banner 'Build: full (libvuptsdk: Argon2id, --pq-sdk available)', keygen --sdk +
--pq-sdk encrypt/decrypt byte-exact roundtrip. Default source-only build
unchanged (make check 16/16).
2026-07-12 14:47:40 -03:00

89 lines
3.4 KiB
C

/*
* vuptsdk easy.h — high-level API for drop-in encryption.
* SPDX-License-Identifier: AGPL-3.0-or-later
*
* Goal: 3 lines of code to encrypt/decrypt anything in any language.
* No context management, no parameter tuning, secure defaults.
*/
#ifndef ZUPTSDK_EASY_H
#define ZUPTSDK_EASY_H
#include "zuptsdk.h"
#ifdef __cplusplus
extern "C" {
#endif
/* ─── String/buffer encryption (PQ pubkey) ─── */
/** Encrypt with recipient pubkey file path. Returns alloc'd combined
* blob (header || ciphertext) ready to store/transmit. */
int zuptsdk_easy_encrypt(const char *recipient_pubkey_path,
const uint8_t *plaintext, size_t plaintext_sz,
uint8_t **blob_out, size_t *blob_sz);
/** Decrypt blob with recipient privkey file path. */
int zuptsdk_easy_decrypt(const char *recipient_privkey_path,
const uint8_t *blob, size_t blob_sz,
uint8_t **plaintext_out, size_t *plaintext_sz);
/* ─── Password-based encryption ─── */
/** Encrypt with password (Argon2id, MODERATE preset by default). */
int zuptsdk_easy_encrypt_password(const char *password,
const uint8_t *plaintext, size_t plaintext_sz,
uint8_t **blob_out, size_t *blob_sz);
int zuptsdk_easy_decrypt_password(const char *password,
const uint8_t *blob, size_t blob_sz,
uint8_t **plaintext_out, size_t *plaintext_sz);
/* ─── Field-level encryption (for DB columns, JSON fields) ─── */
/** Encrypt small fields with a 32-byte key. Returns base64-encoded
* string (alloc'd, NUL-terminated, free with zuptsdk_free).
* Suitable for DB columns, JSON fields, env vars. */
int zuptsdk_easy_encrypt_field(const uint8_t key[32],
const char *plaintext,
char **b64_out);
int zuptsdk_easy_decrypt_field(const uint8_t key[32],
const char *b64_input,
char **plaintext_out);
/* ─── File encryption with progress ─── */
typedef void (*zuptsdk_easy_progress_t)(uint64_t bytes_done,
uint64_t bytes_total,
void *userdata);
int zuptsdk_easy_encrypt_file(const char *recipient_pubkey_path,
const char *input_path,
const char *output_path,
zuptsdk_easy_progress_t cb, void *userdata);
int zuptsdk_easy_decrypt_file(const char *recipient_privkey_path,
const char *input_path,
const char *output_path,
zuptsdk_easy_progress_t cb, void *userdata);
/* ─── Keypair generation ─── */
/** Generate keypair and save to two paths. Convenience wrapper. */
int zuptsdk_easy_keygen(const char *pubkey_out_path,
const char *privkey_out_path);
/** Derive a deterministic 32-byte key from a password via Argon2id.
* For field encryption, derive key once at startup, reuse for many fields. */
int zuptsdk_easy_derive_key(const char *password,
const uint8_t salt[16],
uint8_t key_out[32]);
/* ─── Random salt generation ─── */
int zuptsdk_easy_random_salt(uint8_t out[16]);
#ifdef __cplusplus
}
#endif
#endif