Security hardening and v2 vault format finalization release.
Changed
- Finalized the shared v2 encrypted vault/export envelope.
- Standardized current vault/export writes around
Lockroot_VAULT/Lockroot_EXPORT, Argon2id, and AES-256-GCM. - Clarified legacy migration behavior across Android, iOS, macOS, Windows, and Linux.
- Updated README, security notes, threat model, crypto notes, and vault format documentation.
Security
- Hardened vault unlock, save, and migration paths.
- Added compatible legacy migration behavior where the platform can decrypt the old vault format.
- Improved desktop vault/export handling around the newer shared envelope shape.
- Clarified that wrong passwords, tampered ciphertext, and tampered envelope metadata fail authentication.
Testing
- Updated Android vault codec and repository tests.
- Added desktop smoke coverage for v2 vault/export behavior.
- Verified Android release unit tests, Windows release build, Linux release build, and desktop smoke tests.