Release v0.5.0 - #14
Merged
Merged
Conversation
Sync with the internal repository. Changes since the last sync (v0.4.1): * Seed-only ciphertext: drop the PUBLICKEY seed mode. Only the UNIFORM a-part can be reconstructed from a seed without the encryption key, so the public-key variant is removed from CipherSeedMode, Encryptor and the serialization format. * Serialization: add a 2 GiB size guard on both serialize and deserialize. FlatBuffers' internal size counter is a uint32 that only asserts in debug builds, so oversized buffers silently corrupted in release. * SeedGenerator: serialize Gen()/Reseed() behind a mutex, make Reseed() honor its documented empty-optional behavior, and stop evaluating Gen() eagerly through value_or() at the Encryptor/KeyGenerator call sites. * OmpUtils: make the saved thread count thread_local and add an OMP thread limit guard. * Install: fix find_package(deb) on a default (static) install by making the alea/flatbuffers find_dependency calls conditional, install the generated headers flat next to the headers that include them, and add the per-project include root to the install interface. Skip BLAKE3's broken subproject install rules. * Warnings: add set_deb_no_warnings() and apply it to the flatbuffers targets so a consumer's global warning flags don't surface warnings we don't own. * Restore the DEB_ARCH cache variable, which CMakePresets.json already referenced but CMakeLists.txt no longer declared. * .clang-tidy: fix the "ccpcoreguidelines-*" typo that disabled that check group. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
juny2400
approved these changes
Sep 18, 2026
gnuykeat
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Syncs the public repository with the internal one. Base for this diff is the tree merged as #13 ("General optimize"); everything below landed internally after that.
Seed-only ciphertext: drop the PUBLICKEY seed mode
Only the
UNIFORMa-part can be regenerated from a seed alone. The public-key variant needed the encryption key to reconstructa, which defeats the purpose and made the deserialized ciphertext unusable without extra context.CipherSeedMode::PUBLICKEY, the matchingEncryptorT::completeCiphertext()overload and the corresponding serialization path are removed.examples/SeedOnlyCiphertext.cppand the EnDec tests are updated accordingly.Serialization size guard (2 GiB)
FlatBuffers' internal size counter is a
uint32guarded only by an assert that compiles out in release builds, so a buffer past ~4 GiB silently wrapped and produced corrupt output. Bothserializeanddeserializenow reject anything above a 2 GiB bound up front with a clear error. Covered by new cases inSerialize-test.cpp.SeedGenerator thread safety
Gen()andReseed()mutated the singleton's RNG state with no synchronization. Both are now serialized behind a file-local mutex (GetInstance()'s magic-static initialization was already safe; the state was not).Reseed()documented "when empty a random seed is chosen" but calledseed.value()and threwstd::bad_optional_access. The constructor'srandom_deviceseeding is factored intomakeEntropySeed()and shared, so the documented behavior now holds.seed.value_or(SeedGenerator::Gen())evaluatedGen()unconditionally, so a caller supplying a deterministic seed still advanced the singleton. TheEncryptorandKeyGeneratorcall sites select lazily now.OpenMP
The saved thread count in
OmpUtilswas a function-levelstatic int, so concurrent scopes clobbered each other's saved value; it isthread_localnow. Adds a thread-limit guard inOmpUtils.hpp.Install / packaging
find_package(deb)failed on a default (static) install:debConfig.cmake.inunconditionally requiredaleaandflatbuffers, which a static build links throughBUILD_INTERFACEand bakes intolibdeb.a, so neither package is present. Thosefind_dependencycalls are now conditional onDEB_INSTALL_ALEA/DEB_INSTALL_FLATBUFFERS.DEB_SERIALIZE_APIputs flatbuffers into the public include graph (installedSerialize.hpp→DebFBType.h→<flatbuffers/flatbuffers.h>), soDEB_INSTALL_FLATBUFFERSis forced on whenever we install at all.generated/level, and${CMAKE_INSTALL_INCLUDEDIR}/${PROJECT_NAME}is added to the install interface to mirror the build interface.libblake3.pcinto its own binary dir but installs it from the top-level one, socmake --installfailed on a file that was never there. Its install rules are skipped for the duration of that subdirectory.Warnings
New
set_deb_no_warnings()helper, applied to the flatbuffers targets, plusINTERFACE_SYSTEM_INCLUDE_DIRECTORIESonflatbuffers. A consumer project with global warning flags (add_compile_options(-Wall ...)) leaked them into everyadd_subdirectory(), surfacing warnings from dependencies we neither own nor can fix.Drift fixes picked up along the way
Two items that were lost in an earlier sync rather than being new work, flagged here so they are easy to drop if you would rather they landed separately:
CMakePresets.jsonsets"DEB_ARCH": "x86-64-v3"for the benchmark preset, butCMakeLists.txtno longer declared or usedDEB_ARCH, so the preset was a no-op. The cache variable and the-marchplumbing are restored..clang-tidyhadccpcoreguidelines-*(typo), which silently disabled that whole check group. Fixed tocppcoreguidelines-*.Project version is bumped to 0.5.0.
Testing
cmake --preset ci+cmake --build --preset cibuilds clean with no warnings, andctest --preset all-testpasses 6/6 (Operation, EnDecryption, KeyGen, NTT, U32, Serialize) on Linux / GCC 14.3 / OpenMP.🤖 Generated with Claude Code