Skip to content

Sync testing with main - #29

Merged
TheZeekA merged 23 commits into
testingfrom
main
Sep 24, 2026
Merged

TheZeekA merged 23 commits into
testingfrom
main

Conversation

@TheZeekA

Copy link
Copy Markdown
Owner

Brings testing up to date with main after the v1.52 merge (#28). testing has no commits that aren't already in main, so this is a pure catch-up with no content changes.

TheZeekA and others added 23 commits August 2, 2026 08:30
ZeeCrypt v1.50: Windows-only rebrand + Picocrypt security audit fixes
Sync testing into main: latest screenshot, README note, and stale asset cleanup
zeecrypt-logo.png and zeecrypt.png were added to main independently of
the testing branch's history (separate upload events), so merging
testing's later deletion of these same files never propagated. They
were superseded by zeecrypt-logo-scaled.png.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Remove stray pre-rebrand logo images from main
Add MSI installer for Windows releases
Pin WiX Toolset to v5 in the release build
Fix invalid XML comment in installer.wxs
Fix second literal -- in installer.wxs comment
Fix broken installer download link in README
Add SECURITY, CONTRIBUTING, Code of Conduct, and PR template
Add Explorer right-click integration
Add version display and manual update checker
Release v1.51: Explorer context menu and update checker
Fix MSI installer: per-machine install, x64 path, completion dialog
Update README screenshot to v1.51
Document Explorer integration and update checker in README Features
Simplify Windows build pipeline: replace Resource Hacker with go-winres
Security:
- Derive the header-MAC subkey after the keyfile key is mixed in. For
  keyfile-only volumes it depended only on argon2id("", salt), so the
  header could be forged; since the data MAC doesn't cover the nonce,
  a forged nonce decrypted "successfully" to garbage. Breaking change
  for keyfile volumes from v1.50/1.51, which are recognized (never
  accepted) and pointed at v1.51. Password-only volumes are unaffected.
- broken() deleted outputFile instead of outputFile.incomplete, leaving
  unauthenticated plaintext behind and deleting a file the user chose
  to overwrite.
- Failed/cancelled deniable decrypts left the unwrapped .tmp (which has
  a readable header) next to the volume. Temp inputs are now tracked
  and removed by removeTempInput(), which only deletes files work()
  created and refuses to clobber an existing *.tmp.

Fixes:
- RS repair pass re-ran recombine/unwrap: crashed on deniable volumes,
  always failed on split ones. work(prepared bool) skips preparation.
- Crashes on an invalid PKCS#7 byte, a <136-byte RS tail, a too-short
  deniable file, and a deniable keyfile volume opened without keyfiles.
- Split cleanup used the wrong chunk names and globbed with
  metacharacter-unsafe paths.
- Enter could start a second work() mid-operation; the update modal
  and applyUpdate could exit mid-operation.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Drive onDrop()/work() the way the UI does, without a window: round
trips across every option, tampering and corruption, RS repair on
deniable/split volumes, temp-file cleanup on failure and cancel, the
keyfile header forgery, and compatibility with v1.51 volumes checked
in under testdata/legacy-v1.51. Each bug test was confirmed to fail
against v1.51.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
v1.52: decryption cleanup, RS repair, keyfile header MAC fix + headless tests
@TheZeekA
TheZeekA merged commit dd8fc8c into testing Sep 24, 2026
5 checks passed
TheZeekA added a commit that referenced this pull request Sep 24, 2026
Merge pull request #29 from TheZeekA/main
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant