zupt/gui/README.md
Cristian Cezar Moisés 5050570b23 v5.0.0: version bump, audit fixes, documentation overhaul
Version bumped to 5.0.0 across include/zupt.h, all packaging recipes, man
page, and docs.

Audit fixes (pre-5.0.0 review):
- src/zupt_format.c: overflow-safe bound in the solid-mode `test` path
  (off+sz could wrap and drive an OOB read in zupt_xxh64 on a crafted archive;
  the extract path was already hardened, the test path was not).
- gui: run_async now marshals the completion callback onto the GUI thread with
  QueuedConnection (a bare functor connected DirectConnection and touched
  widgets off the worker thread); Extract auto-detect note survives the log
  clear via a new `info` param.
- .github/workflows/ci.yml: trigger on `master` (was main/develop, so CI never
  ran); `make dist` tarball is vaptvupt-*.tar.gz not zupt-*; the ASAN PQ
  round-trip uses native --pq (was --pq-sdk, which fails on the source-only
  build and blocked the release job).

Documentation:
- New AUDIT.md (methodology, FIPS 203 conformance validation, findings, repro).
- CHANGELOG 5.0.0 entry covers the FIPS 203 conformance fix + BREAKING note and
  the GUI/CLI/security/packaging work.
- README "What's new in 5.0.0", download tables (incl. Windows/macOS/BSD +
  portable GUI), version-history row.
- SECURITY.md + THREAT_MODEL.md: ML-KEM-768 documented as FIPS 203, validated
  byte-for-byte against OpenSSL 3.5.
- Accuracy fixes: man page (--kdf default is PBKDF2 on source-only; codec
  2.60.4), rpm %description, debian control/copyright, homebrew header
  (no vendored library on source-only builds).

make check 16/16 (FIPS 203 conformance 3/3, all distro-safe checks).
2026-07-10 17:22:02 -03:00

3.2 KiB

VaptVupt GUI

Desktop application for vaptvupt backup compression with ML-KEM-768 + X25519 post-quantum hybrid encryption.

Works on GNU/Linux, BSD, macOS, and Windows.

Install

tar xzf vaptvupt-gui.tar.gz && cd vaptvupt-gui
./vaptvupt-gui                      # auto-creates venv, installs PySide6
./install.sh --user              # adds right-click menu integration

Windows

Option A — Installer (recommended):

Download VaptVuptGUI-1.3.0-Setup.exe and run it. Installs to Program Files, adds Start Menu shortcut, desktop shortcut, right-click context menus, and .zupt file association. Includes uninstaller.

Option B — Build from source:

cd packaging\windows
build-windows.bat

Requires Python 3.9+, NSIS 3.x, and a compiled vaptvupt.exe.

Option C — Run directly:

pip install PySide6
python src\zupt_gui.py

macOS / BSD

pip3 install PySide6
python3 src/zupt_gui.py

AppImage (universal Linux)

chmod +x VaptVupt-GUI-1.3.0-x86_64.AppImage
./VaptVupt-GUI-1.3.0-x86_64.AppImage

Flatpak

flatpak-builder --install build packaging/flatpak/dev.zupt.gui.yml
flatpak run dev.zupt.gui

Features

Tab Function
Keys Generate ML-KEM-768 + X25519 hybrid keypairs
Compress All codecs, levels 1-9, dedup, solid, password, PQ keys
Extract Decrypt and extract .zupt archives
Verify Check block checksums, view archive metadata
Disk Full-disk backup and restore
About Version, cryptographic stack, credits

All tabs support drag-and-drop. Drop a .zupt file anywhere on the window to extract it. Drop any other file to compress it.

System Integration

Linux (Nemo / Cinnamon)

After ./install.sh --user:

  • Right-click any file: Compress with VaptVupt
  • Right-click .zupt file: Extract with VaptVupt
  • Double-click .zupt: opens in VaptVupt GUI

Windows (after installer)

  • Right-click any file: Compress with VaptVupt
  • Right-click any folder: Compress with VaptVupt
  • Double-click .zupt: opens in VaptVupt GUI
  • Right-click .zupt: Verify Integrity

Architecture

VaptVupt GUI (PySide6, Python)
    |
    |-- subprocess.Popen() with streaming stderr
    |
    v
vaptvupt CLI (Pure C11 binary)
    ML-KEM-768 + X25519 + AES-256-CTR
    VaptVupt / LZHP / Store codecs
    Block deduplication, full-disk backup

The GUI calls the vaptvupt CLI binary — all cryptography runs in native C, not Python.

Packaging

Platform Format Tool
Any pip pip install .
Debian/Ubuntu/Mint .deb packaging/deb/control
Fedora/RHEL .rpm rpmbuild -ba packaging/rpm/vaptvupt.spec
Universal Linux .AppImage packaging/appimage/build-appimage.sh
Sandboxed Linux .flatpak packaging/flatpak/dev.zupt.gui.yml
Windows .exe installer packaging/windows/build-windows.bat
Windows NSIS .exe packaging/windows/zupt-installer.nsi

Credits

  • vaptvupt v5.0.0 — Cristian Cezar Moisés (github)

License

AGPL-3.0-or-later