Repository navigation
Conversation
ADR-0002 separates the two producers of EQL payloads by Postgres type: cipherstash-client's terms stay in eql_v3, Stack Encrypt's move to eql_v4, and both come from one SQL source. This is the first step of #1141: the source stops naming its schemas and payload version literally. Every file under src/v3, the version template, the search_path pin script and the uninstaller now write {{prefix}} where they wrote eql_v3, and {{eql_version}} in the 90 domain CHECKs that compared VALUE->>'v' to '3'. eql-codegen emits the same placeholders for the generated surface; the Rust bindings keep the literal eql_v3_ prefix because they describe v3 payloads. A new `eql-codegen render <3|4> <out> <file>...` substitutes them. It refuses an unknown or unterminated placeholder and any literal eql_v3 or eql_v4, since a literal name would render the same for both versions and let the v4 bundle reach into v3. build.sh renders the ordered surface into build/render/eql_v3/ and runs the symbol-order and installer-completeness gates on the rendered files. The docs tooling reads rendered SQL too. Only v3 is rendered here. The installer and uninstaller it builds are byte-identical to the ones built before this change. Refs #1141
|
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
EQL (Encrypt Query Language) is the SQL we install into a customer's Postgres so it can store and search encrypted values. ADR-0002 (#1139) decides that one SQL source should be installed under two names:
eql_v3for payloads written by cipherstash-client (the TypeScript SDK's engine) andeql_v4for payloads written by Stack Encrypt. Postgres then refuses to compare a query of one with a column of the other, instead of silently returning no rows.This PR is the first step: the SQL source stops naming its schemas and payload version literally, so it can be written out as either version. Nothing a customer installs changes. The v3 installer and uninstaller this branch builds are byte-identical to the ones
mainbuilds.Changes
packages/eql/src/v3, plus the version template, the search_path pin script and the uninstaller, writes{{prefix}}where it wroteeql_v3(about 24k sites), and{{eql_version}}in the 90 domain CHECKs that comparedVALUE->>'v'to'3'.eql_v3_prefix, because they describe v3 payloads.eql-codegen render <3|4> <out> <file>...: new. It substitutes the placeholders, and refuses an unknown or unterminated placeholder and any literaleql_v3/eql_v4. A literal name would render the same for both versions, so the v4 bundle would quietly reach into v3.tasks/build.shrenders the ordered surface intobuild/render/eql_v3/(gitignored), runs the symbol-order and installer-completeness gates on the rendered files, and assemblesrelease/from them.docs:validate:documented-sqlruns psql over the rendered tree, and the Doxygen filter renderseql_v3names, so the generated reference is unchanged.packages/eql/AGENTS.mdgains a "Schema and version placeholders" section. The scalar-type reference shows extension SQL with placeholders.Verification
release/cipherstash-encrypt.sql,release/cipherstash-encrypt-uninstall.sqlandsrc/deps-ordered-v3.txt: compared withcmpagainst a build of the base commit. All three are byte-identical.test:crates(eql-codegen 150 unit tests, including 8 new render tests),codegen:parity,types:check,typescript:check,test:schemas:parity,test:self_contained_v3,test:symbol_order_v3,test:symbol_order_selftest,test:installer_complete,test:build_ordering_helpers,test:doc-anchors,test:matrix:inventory,test:matrix:catalog-coverage,test:public_identifiers,release:prepare-bindings-assets.test, and rootpnpm run test:scripts(71 files, 1296 tests).docs:validate:documented-sql,test:surface:snapshot, splinter and the clean-install smoke test. All need Postgres, and Docker wasn't running.test:docs_v3_grepalso wasn't run, because it needs bash 4 and this Mac has bash 3. I edited its one source grep and checked that grep by hand. The installer is byte-identical, so the database suites see the same SQL; CI runs them.Related
Refs #1141. Stacked on #1139 (the ADR). The next two PRs in the stack:
eql_v4bundle, with a gate that noeql_v3name survives in it, and a test that aneql_v4query term can't be compared with aneql_v3column.Review notes
The 290 SQL files are a mechanical rewrite. Review
crates/eql-codegen/src/render.rs,tasks/build.shand the codegen const changes. The SQL diff is covered by the byte-identical check.https://claude.ai/code/session_01CA4pFfaN4DPNSTLnJVNxsu