Expert Review Checklist
Use this checklist to attack HVCE v4 as a hostile reviewer.
Compression claims
- Verify that all ratio claims are corpus-specific.
- Confirm that random/encrypted/already-compressed data claims are not entropy-violating.
- Compare against 7-Zip, WinRAR, WinZip, zstd, brotli, xz, lzip, lrzip, paq/zpaq, cmix, and domain-specific codecs where appropriate.
- Measure both compressed size and total cost: compression time, decompression time, RAM, external dictionaries, model files, side information, and metadata.
Correctness
- Run
python hvce.py test. - Run
python -m pytest -q. - Fuzz random file trees.
- Fuzz archive corruption with and without recovery records.
- Verify safe path extraction against absolute paths and
..attacks. - Verify encrypted archives reject wrong passwords before attempting extraction.
Security
- Audit ChaCha20 block function against known test vectors.
- Audit HMAC coverage.
- Audit KDF iteration handling and salt/nonce uniqueness.
- Confirm no unauthenticated metadata leaks in password mode except public encryption parameters.
- Consider replacing the Python crypto path with a bindings-backed audited library in production.
Metadata
- Test Linux permissions/timestamps.
- Test Windows file attributes.
- Test symlink policy.
- Test Unicode paths.
- Test very long paths.
Performance
- Benchmark on SSD/NVMe.
- Benchmark many tiny files.
- Benchmark large single files.
- Benchmark already-compressed media.
- Benchmark versioned backups/checkpoints.
- Benchmark synthetic and real office folders.
- Benchmark source trees and scientific arrays.
Production blockers
- Native Rust/C core.
- Streaming archive writer/reader for huge files without full memory buffering.
- Signed Windows installer.
- Long-term fuzz corpus.
- Independent crypto review.
- More metadata coverage: ACLs, ADS, xattrs, resource forks.