zupt/INSTALL.md
Cristian Cezar Moisés 124958aea9 v4.2.0: full (pure) post-quantum mode + critical dedup nonce fix
Add a native full post-quantum encryption mode and fix a critical
keystream-reuse bug in deduplicated encrypted archives.

Full post-quantum mode (--pq-only)
- New envelope type 0x06 (ZUPT_ENC_PQ_ONLY): ML-KEM-768 (FIPS 203) as
  the sole key-establishment mechanism, with no classical X25519
  component. Archive key = SHA3-512(ml_ss || ml_ct || "ZUPT-PQ-ONLY-v1").
- For compliance postures that require a single NIST-standardised PQ
  primitive with no classical KEM in the envelope (CNSA 2.0-style
  "PQ-only"). Hybrid --pq stays the recommended default; --pq-only has
  no classical fallback, so a break of ML-KEM-768 alone breaks it.
- keygen --pq-only / keygen --pub --pq-only (ZPQK magic, 1200B pub /
  3600B priv; not interchangeable with hybrid --pq keys). Wrong or
  tampered ciphertext is rejected via ML-KEM FO implicit rejection plus
  the HMAC-SHA256 Encrypt-then-MAC envelope. In-tree, default build.

Security (critical): AES-256-CTR keystream reuse under --dedup
- Dedup assigns block sequence 0 to every data block (the sentinel that
  keeps cross-file dedup references authenticating consistently). The
  per-block nonce was base_nonce XOR block_seq, so under --dedup every
  block collapsed to the same nonce, reusing the CTR keystream across
  distinct plaintexts (a many-time-pad). Each block now uses a fresh
  random 128-bit nonce stored in the block prefix and bound into the
  block MAC; block_seq is still bound as MAC AAD. Regression test:
  tests/test_dedup_nonce.sh. Re-encrypt any --dedup encrypted archives
  written by <= 4.1.0.

Other
- keygen --sdk / --box on a source-only build now fails with a clear
  message pointing to native --pq / --pq-only (or a WITH_SDK=1 build).
- Documentation: README, SECURITY, THREAT_MODEL, man page, CHANGELOG,
  and all packaging recipes updated for the new mode and the security
  fix; version bumped to 4.2.0. Wire format v1.6 unchanged (0x06 is
  additive).

Validation: make check 16/16, quick suite 11/11 (incl. PQ-only),
dedup-nonce regression (all block nonces distinct), cppcheck clean.
2026-07-09 21:15:14 -03:00

6.4 KiB

VaptVupt + VaptVupt GUI — Install Guide for Linux

If you're seeing the error:

vaptvupt-gui depende de python3-pyqt6 | python3-pyside6; porém:
  Pacote python3-pyqt6 não está instalado.
vaptvupt-gui depende de vaptvupt (>= 4.2.0); porém:
  Versão de vaptvupt no sistema é 2.1.7-1.

This is correct behavior. The vaptvupt-gui deb requires:

  • Python 3 with PyQt6 or PySide6 (the GUI toolkit)
  • The vaptvupt CLI 4.2.0 or newer

The fastest fix — one command (Linux Mint, Ubuntu, Debian)

Put all the downloaded files in the same folder, then:

sudo bash install-zupt-gui.sh

This script auto-detects your distribution and installs everything in the right order.

Manual fix — three commands (if you prefer)

Linux Mint / Ubuntu / Debian / Pop!_OS

# 1. Install the Qt6 Python binding
sudo apt update
sudo apt install -y python3-pyqt6

# 2. Upgrade vaptvupt CLI to 4.2.0
sudo dpkg -i vaptvupt_4.2.0_amd64.deb

# 3. Install the GUI
sudo dpkg -i vaptvupt-gui_1.3.0_all.deb

If step 3 still complains about deps, run:

sudo apt --fix-broken install

Fedora / RHEL / Rocky / AlmaLinux

sudo dnf install -y python3-pyqt6
sudo dnf install -y vaptvupt-4.2.0-1.x86_64.rpm vaptvupt-gui-1.3.0-1.noarch.rpm

(Or build the RPM from the SRPM tarball with rpmbuild -bb SPECS/vaptvupt.spec)

openSUSE Leap / Tumbleweed

sudo zypper install python3-pyqt6
# Build the RPM from the source tarball — see the SRPM .tar.gz

Arch Linux / Manjaro / EndeavourOS

sudo pacman -S python-pyqt6
# Build vaptvupt from the source tarball

Anything else (or no apt/dnf/pacman handy)

Use the AppImage — no install needed:

tar xzf VaptVupt-GUI-1.3.0-x86_64.AppDir.tar.gz
cd vaptvupt-gui.AppDir
./AppRun

The AppImage still needs Python 3 + Qt6 binding on the host. For a fully standalone executable with no Python dependency, use a future PyInstaller-built version (not in this release).

Why does the GUI need Qt6?

The VaptVupt GUI is written in Python, using either PyQt6 or PySide6 (it auto-detects whichever is installed). These are bindings to the Qt 6 graphical toolkit — they're how the GUI draws windows, buttons, and dialogs.

PyQt6 is in the default repositories of major Linux distributions, so installing it is one apt/dnf/zypper/pacman command away. We don't bundle Qt6 inside the deb because:

  • It's already on most modern systems
  • Bundling would make the deb 80 MB+ instead of 35 KB
  • Distribution-managed Qt gets security updates automatically

Why does the GUI need vaptvupt 4.2.0?

The GUI calls vaptvupt --pq and vaptvupt keygen for native post-quantum encryption (ML-KEM-768 + X25519, in-tree implementation). Older CLI versions lack these flags, so the GUI's compress/extract will fail against them.

After installing — verify

vaptvupt version       # should show: 4.2.0
vaptvupt-gui           # should launch the GUI window

If the GUI window still doesn't appear

# Run from terminal to see error messages
vaptvupt-gui

# If you see "ImportError: No module named 'PyQt6'":
#   The GUI fell back through both PyQt6 and PySide6 imports.
#   Re-check: python3 -c 'import PyQt6.QtWidgets'

# If you see "DISPLAY not set":
#   You're on SSH without X forwarding. Use ssh -X or run locally.

# If you see "qt.qpa.plugin: Could not load the Qt platform plugin":
#   Missing Qt platform plugin. On Mint/Ubuntu:
#   sudo apt install qt6-qpa-plugins

Reporting issues

If you've tried the above and vaptvupt-gui still won't work, open an issue at https://git.securityops.co/cristiancmoises/vaptvupt/issues with:

  1. Output of lsb_release -a (or cat /etc/os-release)
  2. Output of python3 --version
  3. Output of python3 -c 'import PyQt6; print(PyQt6.__version__)' 2>&1
  4. Output of vaptvupt version
  5. Output of vaptvupt-gui (the error message it printed to terminal)

Building from source

If you want to build VaptVupt from the source tarball instead of installing the pre-built .deb / .rpm packages, you'll need only a C compiler and make. The default build has NO external crypto dependency and installs no shared library.

Build dependencies (default build)

Component Why needed
gcc ≥ 7 or clang ≥ 10 C11 compiler
make build driver
libm, pthread math and threading (part of the standard C library/toolchain)

The default build uses PBKDF2-SHA256 (600k iterations) for password KDF and the in-tree native --pq mode (ML-KEM-768 + X25519) for post-quantum encryption. No libzuptsdk, no OpenSSL, no libargon2 is required.

Install build dependencies (Debian/Ubuntu/Mint)

sudo apt install build-essential

Install build dependencies (Fedora/RHEL/openSUSE)

sudo dnf install gcc make        # Fedora/RHEL
sudo zypper install gcc make     # openSUSE

Build VaptVupt itself

tar -xzf vaptvupt-4.2.0-source.tar.gz
cd vaptvupt-4.2.0

make                 # build the `./vaptvupt` binary
sudo make install    # install to /usr/local/bin (override with PREFIX=/usr)

./vaptvupt version       # verify

The make step takes 10-30 seconds. The build emits the binary as ./vaptvupt. The default install prefix is /usr/local; override with PREFIX=/usr for system-wide install.

Run the test suite

make test

Covers roundtrip, multi-file, cross-block, dedup property, path-traversal, argument-order, and block-swap regression. Each suite reports its own pass/fail count.

Cross-compilation

VaptVupt builds on x86_64, aarch64, armhf, ppc64le, s390x, and riscv64. To cross-compile:

make CC=aarch64-linux-gnu-gcc      # for AArch64
make CC=arm-linux-gnueabihf-gcc    # for ARMv7 (Raspberry Pi 32-bit)

The Makefile auto-detects target architecture via $(CC) -dumpmachine and selects the appropriate SIMD flags (NEON on AArch64, SSE4/AVX2 on x86_64).

Optional: WITH_SDK=1 build

The SDK-backed modes — --pq-sdk, --pq-box (sealed-box), and the Argon2id KDF — are optional. They are not in the default build and require building against the separately distributed libzuptsdk / libpqvaptvupt libraries:

make WITH_SDK=1

This build additionally needs the SDK development package and its runtime dependencies (OpenSSL libcrypto, libargon2), which ship with the SDK distribution. Without WITH_SDK=1, the --pq-sdk and --pq-box flags are unavailable; use the native --pq mode instead.