M7 PHP Crypto releases and integrity

Current status

Version 0.3.0 is a verified development candidate, not a confirmed public release. The candidate source archive and its two sidecars have passed integrity and reproducibility checks. Final reviewed source tagging, release generation and public availability verification remain pending. There are no verified public download links on this page yet.

Acceptance recorded on 2026-09-20 UTC covers macOS arm64, PHP 8.4.4 NTS/module API 20240924 and OpenSSL 3.6.3, against an exact verified M7 C Crypto 0.3.0 candidate. All six PHPT cases passed without failures, warnings or skips; independent Node encryption interoperability and native leak checks passed. Stress coverage included signing (1000 cycles), generation (three cycles per profile), and encryption (1000 cycles). These results apply to the tested candidate, not an arbitrary later source snapshot.

Linux 0.3.0 acceptance, additional PHP versions, ZTS and a precompiled binary distribution have not been established by that run. The source's PHP 8.4+ header gate does not expand the tested matrix. Lower-version PHP support is later work and does not block ordinary Identity SDK releases.

Distribution contract

Each version has three files:

m7-php-crypto-<version>.tar.gz
m7-php-crypto-<version>.tar.gz.sha256
m7-php-crypto-<version>.tar.gz.manifest.json

The planned public path is https://m7.org/downloads/m7-php-crypto/<version>/. It is not evidence of current availability. Link all three exact files only after their public bytes match the reviewed final bundle. Published versions are immutable; changed contents require a new version.

The archive contains one versioned source root, MANIFEST.json and CHECKSUMS.sha256. The JSON sidecar matches the embedded manifest byte for byte, and the SHA-256 sidecar covers the compressed archive. Source version, extension header, changelog, archive name/root, manifest and annotated m7-php-crypto-v<version> tag must agree for a final release. The manifest records source commit, normalized epoch, dependencies and payload hashes.

Follow checksum-first installation. C remains a separate artifact: a PHP release must record and test its exact C archive digest as well as the minimum C 0.3+ requirement. Source integrity checks do not replace native runtime and platform verification. Checksums do not authenticate the publisher; use a trusted distribution channel.

A development candidate, final local release, website-staged bundle, installed module and verified public release are distinct states. Initial bundles contain source to compile, not a module usable across PHP ABIs or platforms.

Changes by source version

Source version Main change Availability meaning
0.3.0 Adds encrypt/decrypt with C 0.3+ RSA-OAEP-256; adds immutable source-release tooling Current verified development candidate
0.2.0 Adds key generation and PEM export Historical source milestone; not a current public download claim
0.1.0 Establishes native key import, signing and verification Historical source milestone; not a current public download claim

Current public documentation describes 0.3.0 and is maintained separately from immutable archives. Later documentation corrections do not replace an existing archive. Read the shipped changelog for the selected bundle. The package uses MTL-10; its LICENSE.md is included.

Return to M7 PHP Crypto.