13 Commits
Author SHA1 Message Date
harald aa65d96434 feat(sync): add rsync-like sync command with dry-run and bump version to v0.5.0 2026-09-16 10:40:38 +02:00
harald 46f976b353 feat(cross-platform): add QUICKSTART.md, live crash test, and platform abstraction module 2026-09-10 16:31:57 +02:00
harald 70d03df676 fix(security): implement P3 high-entropy carrier default and P5 manifest capacity guard 2026-09-09 21:33:01 +02:00
harald 771c08ff0f fix(security): implement P1 loopback session token, P2 AAD filename binding, and P4 memory zeroization 2026-09-09 21:24:07 +02:00
harald 98bfac718f fix(core): resolve all 12 adversarial review findings
- Zeroize passwords in CLI prompts, handlers, and mount authentication
- Preserve carrier_node_id when recovering Slot 0 via recovery key
- Add --slot parameter to restore-header for targeted slot recovery
- Implement online_backup and restore_from_backup using SQLite Online Backup API
- Expose 'sanctum backup' and 'sanctum restore' CLI subcommands
- Fix inactivity auto-lock by removing touch() from PROPFIND metadata/read_dir
- Support O_APPEND by setting file cursor to file size on handle creation
- Prevent data loss by implementing Drop for CarrierFile to flush dirty blocks
- Optimize CSPRNG padding to only fill unwritten slack space
- Batch carrier initialization in 500-block transactions to prevent UI/CLI freeze
- Enforce 64-byte savings threshold for LZ4 compression
- Add WebClient service diagnostic hint for Windows net use mount errors
- Add unit and integration tests covering all new features
2026-09-09 21:02:21 +02:00
harald 030ce6a1e5 feat(security): implement Phase 2 Modell A (Steganografischer Alibi-Carrier für Plausible Deniability) 2026-09-09 20:22:00 +02:00
harald b8e4dcb614 feat(security): implement Phase 1 of Plausible Deniability hardening 2026-09-09 19:55:34 +02:00
harald 1e6854e9f5 feat(anti-forensics): implement incremental auto-vacuum, chunk shredding, and plausible deniability 2026-09-08 10:46:24 +02:00
harald 2cb065c8c0 feat(opsec): implement inactivity auto-lock, session lock detection, and anti-leak shield 2026-09-08 10:14:31 +02:00
harald 1c8a860184 feat(recovery): implement header backup/restore, BIP-39 recovery key, and integrity verification 2026-09-08 09:49:08 +02:00
harald 2d14c64c3e feat(compression): implement transparent LZ4 chunk compression with V1 backwards compatibility 2026-09-07 21:59:42 +02:00
harald a9c3dd25a3 feat(cli): add passwd command for instant master password changes 2026-09-07 17:29:50 +02:00
harald 9115596763 Initial commit: Sanctum encrypted single-file container for Windows 2026-09-07 15:40:58 +02:00