Build from source with no vendored binaries: - Remove prebuilt libzuptsdk.so / libpqvaptvupt.so (and a stray .pyc). The default build needs only a C compiler + make; it links no external library and installs no .so. The libzuptsdk-backed modes (Argon2id KDF, --pq-sdk, --pq-box) are gated behind an opt-in `make WITH_SDK=1`. The default password KDF is PBKDF2-SHA256 and --pq (native ML-KEM-768 + X25519) is the built-in PQ mode. openSUSE/RPM/deb/AUR/Homebrew/Nix recipes bumped to 4.1.0; the openSUSE spec now builds source-only (%files ships no .so, %build/%install WITH_SDK=0). Fix: multithreaded encrypted archives were unextractable on the native AEAD path. The parallel compress/decompress workers skipped the F-09 frame-preface AAD that the serial path and the archive's AAD_PREFACE flag bind into every block MAC, so each multithreaded block failed authentication. The workers now bind the preface via a shared serializer; output is byte-identical across thread counts and interoperates with single-threaded archives (also fixes `--kdf pbkdf2 -t N` in any build). Security hardening (crafted-archive memory safety + crypto): - LZH raw code-length stack overflow + huff_lut OOB write - overflow-safe bounds in parse_index and solid-mode extract (heap OOB read) - SEQ decoder safe-zone heap overflow (litlen+matchlen reserve) - require the per-block ENCRYPTED flag on encrypted archives (plaintext forgery) - cap archive-supplied PBKDF2 iteration count (KDF-amplification DoS) - non-elidable secret wipe in the SDK path; restored disk images created 0600 Docs: remove AUDIT.md / BENCHMARKS.md / ROADMAP.md; trim marketing/AI-styled text and correct KDF/PQ facts across README, SECURITY, INSTALL, DISTRIBUTION, THREAT_MODEL, THIRD-PARTY-NOTICES, the man page, and packaging READMEs. Wire format v1.6 unchanged.
110 lines
4.6 KiB
Markdown
110 lines
4.6 KiB
Markdown
THIRD-PARTY NOTICES
|
|
===================
|
|
|
|
This document records VaptVupt's runtime dependencies and build-time
|
|
tools. If you redistribute VaptVupt, you must preserve this attribution
|
|
document along with the LICENSE file.
|
|
|
|
-------------------------------------------------------------------------
|
|
Licensing
|
|
-------------------------------------------------------------------------
|
|
|
|
**Note on VaptVupt LZ codec licensing**: the VaptVupt LZ codec
|
|
(src/vv_*.c, src/vaptvupt_api.c, include/vaptvupt*.h) is licensed
|
|
GPL-3.0-or-later (not AGPL like the rest of the project) so that, with
|
|
sufficient maturity, it can be considered for upstreaming into the Linux
|
|
or BSD kernels, which require GPL-compatible licenses. The author retains
|
|
the right to dual-license the codec under other terms for commercial use;
|
|
contact sac@securityops.co for inquiries.
|
|
|
|
The rest of the project (vaptvupt CLI, Jasmin source, GUI) is licensed
|
|
AGPL-3.0-or-later. Commercial licenses (relief from the AGPL network-use
|
|
clause) are available; contact sac@securityops.co.
|
|
|
|
-------------------------------------------------------------------------
|
|
Build-time tool (not redistributed)
|
|
-------------------------------------------------------------------------
|
|
|
|
**jasminc** — the Jasmin language compiler
|
|
|
|
The constant-time cryptographic primitives in jasmin/*.jazz are
|
|
compiled to native assembly (jasmin/*.s) using the external `jasminc`
|
|
compiler. The jasminc tool is not bundled with VaptVupt; the AGPL .jazz
|
|
source files and their AGPL-licensed .s assembly output are bundled.
|
|
|
|
Upstream: https://github.com/jasmin-lang/jasmin
|
|
License: MIT (the compiler itself; not relevant to VaptVupt's licensing)
|
|
Used by: VaptVupt's build system, only when re-generating jasmin/*.s
|
|
from jasmin/*.jazz (most users won't need to do this —
|
|
pre-built .s files ship in this repo).
|
|
|
|
-------------------------------------------------------------------------
|
|
Runtime system libraries (linked from the OS, never bundled)
|
|
-------------------------------------------------------------------------
|
|
|
|
These are standard system libraries provided by the operating system's
|
|
package manager (apt, dnf, pacman, etc.). They are dynamically linked
|
|
at runtime and are NOT redistributed as part of VaptVupt.
|
|
|
|
**libargon2** — Argon2id password hashing function (RFC 9106)
|
|
|
|
Required only for: the optional `make WITH_SDK=1` build. The default
|
|
build uses native PBKDF2-SHA256 and does not link
|
|
libargon2.
|
|
Linked at runtime: libargon2.so.1
|
|
Version expected: 1.0+ (Debian/Ubuntu: libargon2-1)
|
|
Upstream: https://github.com/P-H-C/phc-winner-argon2
|
|
License: Apache-2.0 OR CC0-1.0 (dual)
|
|
Copyright: (c) 2015 The Argon2 Authors
|
|
Used by: Argon2id password-derived encryption mode
|
|
|
|
**OpenSSL libcrypto** — AES, SHA-256, AES-NI hardware backends
|
|
|
|
Linked at runtime: libcrypto.so.3
|
|
Version expected: 3.0+
|
|
Upstream: https://www.openssl.org
|
|
License: Apache-2.0
|
|
Copyright: (c) 1998-2026 The OpenSSL Project
|
|
Used by: AES-256-CTR, SHA-256, hardware-accelerated paths
|
|
|
|
-------------------------------------------------------------------------
|
|
Compatibility with public standards
|
|
-------------------------------------------------------------------------
|
|
|
|
Where VaptVupt implements public standards, it does so independently from
|
|
any reference implementation. Other projects in the post-quantum hybrid
|
|
encryption space (libsodium, age, Tink, rustls, etc.) were referenced as
|
|
prior art during design, but no code was copied from any external
|
|
project. Standards followed:
|
|
|
|
- FIPS 197 (AES)
|
|
- FIPS 202 (Keccak / SHA-3)
|
|
- FIPS 203 (ML-KEM)
|
|
- RFC 5297 (AES-SIV)
|
|
- RFC 5869 (HKDF)
|
|
- RFC 7748 (X25519)
|
|
- RFC 8032 (Ed25519)
|
|
- RFC 8439 (ChaCha20-Poly1305)
|
|
- RFC 9106 (Argon2)
|
|
- RFC 9180 (HPKE)
|
|
|
|
-------------------------------------------------------------------------
|
|
Reporting attribution issues
|
|
-------------------------------------------------------------------------
|
|
|
|
If you believe VaptVupt redistributes code from a project not listed here,
|
|
or if attribution information is incomplete, please email:
|
|
|
|
sac@securityops.co
|
|
|
|
with the subject "[third-party]" and details of the issue.
|
|
|
|
-------------------------------------------------------------------------
|
|
License summary
|
|
-------------------------------------------------------------------------
|
|
|
|
VaptVupt CLI, Jasmin source, GUI: AGPL-3.0-or-later
|
|
VaptVupt LZ codec: GPL-3.0-or-later
|
|
Commercial license (any component): contact sac@securityops.co
|
|
|
|
Project home: https://git.securityops.co/cristiancmoises/vaptvupt
|