Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1872 commits
Select commit Hold shift + click to select a range
5f593ee
fix(docs): skip name-dropped CREATE FUNCTION mis-parses
coderdan Jul 6, 2026
d79b672
feat(eql-bindings): v3 scalar query-operand bindings (CIP-3432)
freshtonic Jul 7, 2026
9c62e8c
chore: gitignore .claude session dir
freshtonic Jul 7, 2026
2cdc89c
feat(eql v3 sql): generate public.<name>_query operand domains (CIP-3…
freshtonic Jul 7, 2026
080d752
feat(eql v3 sql): generate query operators binding storage↔query doma…
freshtonic Jul 7, 2026
4b56102
test(eql v3): fresh-encryption conformance for scalar query operands …
freshtonic Jul 7, 2026
b4bcdb6
docs(changelog): scalar query-operand surface (CIP-3432)
freshtonic Jul 7, 2026
b925e26
test(eql v3): add query operators/wrappers to the public surface gold…
freshtonic Jul 7, 2026
1fe7167
test(eql v3): cover every scalar query-operand domain in the matrix (…
freshtonic Jul 7, 2026
9a89fc9
style(eql-codegen): rustfmt the query render functions (CIP-3432)
freshtonic Jul 7, 2026
13e1a3d
test(eql v3): matrix planner_metadata counts the query operators (CIP…
freshtonic Jul 7, 2026
f677e9a
docs(eql v3): address review — query-twin blocker rationale + cast no…
freshtonic Jul 7, 2026
e517fab
Merge pull request #373 from cipherstash/james/cip-3432-eql-v3-query-…
freshtonic Jul 7, 2026
c8a93db
fix(v3): install SEM btree operator classes conditionally (Supabase /…
coderdan Jul 7, 2026
51fbf68
docs(changelog): link the conditional-opclass fix to #375
coderdan Jul 7, 2026
85c2178
feat(v3): COMMENT ON DOMAIN for every encrypted domain type
coderdan Jul 7, 2026
1d2c35d
docs(changelog): add entry for domain-type comments (#377)
coderdan Jul 7, 2026
00cec62
refactor(v3): make domain-type comments terse (one-line in type pickers)
coderdan Jul 7, 2026
fbf32b7
Merge pull request #377 from cipherstash/dan/v3-domain-comments
coderdan Jul 7, 2026
2fa8730
Merge pull request #375 from cipherstash/dan/v3-supabase-conditional-…
coderdan Jul 7, 2026
24bd6f4
feat(eql v3)!: query-operand domains renamed to the query_<name> pref…
freshtonic Jul 7, 2026
c6f5e01
test(eql v3): make the operator-equivalents structural scan non-vacuous
freshtonic Jul 7, 2026
39aee45
feat(eql v3)!: move query-operand domains into the eql_v3 schema (CIP…
freshtonic Jul 8, 2026
6a2ac33
Merge pull request #379 from cipherstash/james/cip-3442-query-domain-…
freshtonic Jul 8, 2026
457f3a7
feat(typescript): scaffold @cipherstash/eql package
tobyhede Jul 7, 2026
0ee038a
feat(typescript): generate npm package types and schemas
tobyhede Jul 7, 2026
35c2188
feat(release): bundle exact SQL in language bindings
tobyhede Jul 7, 2026
0b1599f
ci(release): publish TypeScript bindings to npm
tobyhede Jul 7, 2026
53e23dc
ci(release): resolve language binding targets
tobyhede Jul 7, 2026
a282a3a
ci(release): pin selected language binding packages
tobyhede Jul 7, 2026
2ee4439
ci(release): publish all language bindings from coordinator
tobyhede Jul 7, 2026
f589fbb
chore(release): add language-specific release wrappers
tobyhede Jul 7, 2026
c0dd84a
test(typescript): cover generated EQL package surface
tobyhede Jul 7, 2026
f2240bc
docs(release): describe language binding releases
tobyhede Jul 7, 2026
093202c
docs(release): align runbook, CLAUDE.md, and changelog with language-…
tobyhede Jul 7, 2026
e0a236b
ci(release): harden release-typescript workflow (injection, retry-saf…
tobyhede Jul 7, 2026
2ca76a8
feat(release): adopt changesets as the lockstep version source
tobyhede Jul 7, 2026
cd303db
ci(release): changesets release.yml (npm+SQL+docs); release-plz publi…
tobyhede Jul 7, 2026
221b638
ci(release): guard package workflow caches
tobyhede Jul 8, 2026
4190365
fix(release): publish npm prereleases with dist tag
tobyhede Jul 8, 2026
2e9cd6f
ci(release): unify prerelease entrypoint
tobyhede Jul 8, 2026
42123b3
ci(release): consolidate to a single release.yml process
tobyhede Jul 8, 2026
7d20b43
docs(release): replace alpha runbook with comprehensive release doc
tobyhede Jul 8, 2026
25d0bd6
ci(release): harden Multitudes notify and pin image dispatch to the r…
tobyhede Jul 8, 2026
b8df5e4
docs: make Changesets the canonical changelog + version owner
tobyhede Jul 8, 2026
b8d796b
docs(changelog): backfill pending [Unreleased] entries into changesets
tobyhede Jul 8, 2026
da4039d
chore(rebase): reconcile with eql_v3 (query-operand domains + changelog)
tobyhede Jul 8, 2026
25a2001
fix(ci): drop the pnpm dependency from the generated-output gates
freshtonic Jul 8, 2026
13c4a81
docs(claude): note that regenerating committed generated code is a de…
tobyhede Jul 8, 2026
792c78d
fix(release): address review findings — publish guards, marker tighte…
freshtonic Jul 8, 2026
56e67e2
Merge pull request #374 from cipherstash/eql-language-bindings-release
freshtonic Jul 8, 2026
b5c586f
chore(release): eql 3.0.0-alpha.3
freshtonic Jul 8, 2026
7239f91
chore(release): eql 3.0.0-alpha.3 — retry (fix crate-publish dispatch)
freshtonic Jul 8, 2026
07cb738
ci: register release-plz.yml on the default branch (dispatch stub)
freshtonic Jul 8, 2026
3c55825
Merge pull request #383 from cipherstash/james/register-release-plz-w…
freshtonic Jul 8, 2026
cb20b74
chore(release): eql 3.0.0-alpha.3 — retry (trusted publishing configu…
freshtonic Jul 8, 2026
4301cff
chore(release): eql 3.0.0-alpha.3 — retry (fix npm PATH shadowing + b…
freshtonic Jul 8, 2026
e079f6b
chore(release): eql 3.0.0-alpha.3 — retry (API tag creation)
freshtonic Jul 8, 2026
a758894
feat(release): npm prereleases publish under 'latest' until 3.0.0 GA
freshtonic Jul 8, 2026
d71a221
fix(docs): suppress Doxygen auto-linking of `text` in jsonb selector …
coderdan Jul 8, 2026
ca91f1a
Merge pull request #372 from cipherstash/fix/doxygen-schema-name-misp…
coderdan Jul 8, 2026
275c582
Merge pull request #385 from cipherstash/fix/jsonb-warning-doxygen-au…
coderdan Jul 8, 2026
99dc436
feat(install): disable ORE-backed domains loudly on non-superuser ins…
freshtonic Jul 9, 2026
e1e0d0e
fix(install): add the poison constraints NOT VALID + review polish (C…
freshtonic Jul 9, 2026
5ea1271
Merge pull request #388 from cipherstash/james/cip-3468-do-not-instal…
freshtonic Jul 9, 2026
56aa46c
feat(types)!: prefix all public EQL v3 types with eql_v3_ (CIP-3472)
freshtonic Jul 9, 2026
60bc2fe
feat(jsonb)!: switch SteVec ordering from CLLW-ORE (oc) to CLLW-OPE (op)
freshtonic Jul 9, 2026
36e5d7a
style(tests): cargo fmt after ord_ope_term migration
freshtonic Jul 9, 2026
1fd50ed
style(bindings): cargo fmt
freshtonic Jul 9, 2026
a8d9405
test,docs: adopt the eql_v3_-prefixed public type names everywhere (C…
freshtonic Jul 9, 2026
9e3a7d5
docs: review polish — changelog-safe U-004 link, U-003 spacing, gramm…
freshtonic Jul 9, 2026
ce01677
Merge pull request #390 from cipherstash/james/cip-3469-switch-jsonbs…
freshtonic Jul 9, 2026
e88701d
Merge origin/eql_v3 (SteVec CLLW-OPE #390, ore_fallback CIP-3468) int…
freshtonic Jul 9, 2026
baeeea6
chore(release): eql 3.0.0-alpha.4
coderdan Jul 9, 2026
03d97ce
fix(test): norm() must match raw format_type output, not source names
freshtonic Jul 9, 2026
4d1f19c
Merge pull request #391 from cipherstash/james/cip-3472-prefix-all-pu…
freshtonic Jul 9, 2026
e8971ed
feat(v3)!: back the `_ord` domains with CLLW-OPE instead of block-ORE
tobyhede Jul 9, 2026
6cb7279
test(ci): run float_special in CI, gated by self-expiring known-failu…
tobyhede Jul 9, 2026
3561ef5
refactor(v3)!: name the ordering extractors after their domain, not t…
tobyhede Jul 9, 2026
efbe94a
feat(v3)!: back `text_search` with CLLW-OPE; add `text_search_ore`
tobyhede Jul 9, 2026
031d484
fix(ci): update the D4 smoke test for the ord_term/ord_term_ore extra…
freshtonic Jul 9, 2026
4f9086d
test(ore-fallback): poison probes target _ord_ore — _ord is OPE and n…
freshtonic Jul 9, 2026
cbd3850
chore(bindings): reconcile the OpeCllw doc after the rebase; drop res…
freshtonic Jul 9, 2026
e9a0400
fix(rebase): restore resolutions clobbered by later-commit replays
freshtonic Jul 9, 2026
9cf3e3e
fix(test): the _ord query-operand test must encrypt with OPE, not ORE
tobyhede Jul 9, 2026
bf79607
test(jsonb-entry): pin the ord-extractor override as load-bearing
tobyhede Jul 9, 2026
415f1bd
docs: correct claims the CLLW-OPE migration falsified
tobyhede Jul 9, 2026
49d4169
fix(test): the jsonb_entry placeholder must carry `op`, not the remov…
tobyhede Jul 9, 2026
c68e669
docs(crates): SteVec orders by `op` (CLLW-OPE), not `oc` (CLLW-ORE)
tobyhede Jul 9, 2026
06b8f6e
test(ci): run v3_scalar_query_operand_tests in the e2e job
freshtonic Jul 9, 2026
b5bed80
fix(ci): known-failures gate must report an unreferenced marker, not …
freshtonic Jul 9, 2026
ad58637
test(float): pin `=` on `_ord` splitting ±0.0, coupled to #387
freshtonic Jul 9, 2026
d8c7d01
Merge pull request #389 from cipherstash/default-ord-is-ore
freshtonic Jul 9, 2026
6d7e87c
Merge branch 'main' into eql_v3
coderdan Jul 9, 2026
a22184a
chore(release): exit changesets pre-mode so `main` can cut 3.0.0
freshtonic Jul 9, 2026
297daf0
Merge pull request #392 from cipherstash/eql_v3
freshtonic Jul 9, 2026
a35410d
Version Packages
github-actions[bot] Jul 9, 2026
e28cf1d
ci(release-plz): send a User-Agent to the crates.io API
freshtonic Jul 9, 2026
f54ba1f
Merge pull request #393 from cipherstash/changeset-release/main
freshtonic Jul 9, 2026
4119c42
Merge pull request #394 from cipherstash/ci/crates-io-user-agent
freshtonic Jul 9, 2026
a8ec17c
feat(eql_v3): add storage-only public.eql_v3_json; rename JSON family…
tobyhede Jul 14, 2026
6aa8b96
fix: apply CodeRabbit auto-fixes
tobyhede Jul 15, 2026
5890243
fix: correct stale TOC anchor for json-support querying section
tobyhede Jul 15, 2026
89a1da5
test(json): extract real-ciphertext storage fixture + suite from PR #397
tobyhede Jul 15, 2026
e73f6f6
test(json): storage-only eql_v3_json domain — real-ciphertext matrix …
tobyhede Jul 15, 2026
a51c1f4
test(json): isolate storage-reject payload + fix identity in clean-in…
tobyhede Jul 15, 2026
bd8af9d
docs(codegen): fix stale jsonb→json binding refs; generalize mixed-fa…
tobyhede Jul 15, 2026
920ce73
style: rustfmt v3_json_storage_tests
tobyhede Jul 15, 2026
3d342d7
chore(changeset): json storage/rename is a patch (3.0.1)
tobyhede Jul 15, 2026
d4ff8c6
chore(release): open eql-3.0.1 release batching branch
tobyhede Jul 16, 2026
30b2550
Merge pull request #398 from cipherstash/feat/eql-v3-json-storage-and…
tobyhede Jul 16, 2026
18d58e7
feat(eql_v3)!: rename text bloom fuzzy match to `@@` / `eql_v3.matches`
tobyhede Jul 15, 2026
36b9843
refactor(eql-codegen): model operator symbol as OpSymbol enum
tobyhede Jul 15, 2026
f6d5b5e
Merge pull request #406 from cipherstash/eql-v3-rename-text-match-ope…
tobyhede Jul 16, 2026
0aa9f6a
Merge pull request #408 from cipherstash/refactor/eql-codegen-opsymbo…
tobyhede Jul 16, 2026
e0db50c
ci(release): allow prereleases from any non-main branch
tobyhede Jul 16, 2026
e7790ab
chore(release): eql 3.0.1-alpha.0
tobyhede Jul 16, 2026
0d87403
docs(eql_v3): fix stale/inverted CLLW-OPE migration comments (CIP-3490)
freshtonic Jul 14, 2026
4623cab
test(eql_v3): close CLLW-OPE migration coverage gaps (CIP-3491)
freshtonic Jul 14, 2026
fa31d49
ci(splinter): drop 10 stale ore_cllw allowlist rows, add unused-row c…
freshtonic Jul 14, 2026
8cfcdd9
Merge pull request #399 from cipherstash/james/cip-3490-cllw-ope-migr…
freshtonic Jul 16, 2026
49ef541
ci(known-failures): close four fail-open / false-positive paths (CIP-…
freshtonic Jul 14, 2026
bbd4d18
Merge pull request #402 from cipherstash/james/cip-3489-splintersh-10…
freshtonic Jul 16, 2026
87e5aae
Merge pull request #401 from cipherstash/james/cip-3488-harden-the-kn…
freshtonic Jul 16, 2026
f60a564
feat(eql_v3): split json_entry eq_term into eq_entry_term (coalesce) …
tobyhede Jul 16, 2026
48857b2
feat(eql_v3): generate json_entry <-> query_<T>_eq/_ord/_ord_ope cros…
tobyhede Jul 16, 2026
bee1d3f
test(eql_v3): allow json_entry x query_<T> cross-type operators; rege…
tobyhede Jul 16, 2026
7530108
test(eql_v3): json_entry cross-type structural equivalence + ord inde…
tobyhede Jul 16, 2026
ce40706
fix(eql_v3): equality on encrypted JSON via query_<T>_ord (op); drop …
tobyhede Jul 16, 2026
aabfd94
test(eql_v3): surface guard asserts equality via query_<T>_ord + no _…
tobyhede Jul 16, 2026
af1ed4f
test(eql_v3): op-based equality correctness for json_entry cross-type…
tobyhede Jul 16, 2026
bd54115
docs(eql_v3): document json_entry selector-with-constraint queries vi…
tobyhede Jul 16, 2026
9c1b5e3
fix(eql_v3): text json_entry cross-type gets all six operators via or…
tobyhede Jul 16, 2026
8215394
refactor(eql-codegen): derive the json_entry cross surface from the c…
tobyhede Jul 16, 2026
b255a15
test(eql_v3): use real fixture ciphertext for the inert hm in the tex…
tobyhede Jul 16, 2026
4890ec1
style(rust): clean rustfmt and clippy across the workspace
tobyhede Jul 16, 2026
1bedb8c
test(ci): gate doc anchors and the known-failure parser, and fix what…
tobyhede Jul 16, 2026
36c95be
test(ci): raise max_locks_per_transaction for the test Postgres
tobyhede Jul 17, 2026
cfb03bc
test(sqlx): pin the new json_entry cross-type operator surface test
tobyhede Jul 17, 2026
140407e
test(eql_v3): close the json_entry cross-type e2e gap with fresh quer…
tobyhede Jul 17, 2026
d7049da
test(eql_v3): fix SEL_HELLO_OP, which named $.number, and pin text or…
tobyhede Jul 17, 2026
8b4e3cc
style(sqlx): rustfmt the json_entry query-operand e2e tests
freshtonic Jul 17, 2026
fa9a7f2
fix(eql_v3): block json_entry text equality, which returned false pos…
tobyhede Jul 17, 2026
44fb90b
fix(eql_v3): block json_entry equality for bigint and numeric (f64 le…
tobyhede Jul 17, 2026
755b4ea
docs: update renamed JSON domains in Supabase guide
tobyhede Jul 17, 2026
b762f6d
style: format JSON cross-type operator changes
tobyhede Jul 17, 2026
aacb4a5
test(sqlx): size the test Postgres lock table for concurrent uninstalls
freshtonic Jul 17, 2026
1f27727
fix(eql_v3): drop temporal operands from the json_entry cross surface…
coderdan Jul 17, 2026
dee77c5
test(eql_v3): range oracles at a median pivot, unserved-pair raise co…
coderdan Jul 17, 2026
5a57908
docs(upgrading): U-009 — the uninstaller can exceed Postgres's defaul…
coderdan Jul 17, 2026
0afdfa2
Merge pull request #409 from cipherstash/eql-3.0.1
freshtonic Jul 17, 2026
e58adc6
Version Packages
github-actions[bot] Jul 17, 2026
2833f3d
Merge pull request #411 from cipherstash/changeset-release/main
coderdan Jul 17, 2026
66cbb61
feat(v3): SteVec value-inclusive selectors + envelope wire format
coderdan Jul 18, 2026
4964ec2
chore: use cipherstash-client 0.42
coderdan Jul 19, 2026
4346f4c
docs: remove stale v2 surface reference
coderdan Jul 19, 2026
ad94b8b
test: update SteVec v3 CI fixtures
coderdan Jul 19, 2026
713c1bb
test: align SteVec fixtures with client 0.42
coderdan Jul 19, 2026
4aa408b
fix v3 SteVec containment semantics
coderdan Jul 19, 2026
1627b42
fix: align SteVec containment CI coverage
coderdan Jul 19, 2026
1c41d9a
fix: block lossy JSON entry equality
coderdan Jul 19, 2026
f6a8240
fix: close SteVec validation and test gaps
coderdan Jul 20, 2026
884c41f
Allowlist the JSON OPE term extractor
coderdan Jul 20, 2026
d9118c2
Merge pull request #413 from cipherstash/dan/eql-value-selectors
coderdan Jul 20, 2026
cd66ff7
Merge main into JSON entry cross-type operators
coderdan Jul 20, 2026
95ae8c2
Merge pull request #410 from cipherstash/eql-v3-json-entry-cross-type…
coderdan Jul 20, 2026
3ae5178
Version Packages
github-actions[bot] Jul 20, 2026
fabb417
Release EQL 3.0.2
coderdan Jul 20, 2026
045dcc8
Regenerate 3.0.2 release assets
coderdan Jul 20, 2026
52e8cdb
Merge pull request #414 from cipherstash/changeset-release/main
coderdan Jul 20, 2026
e085cf8
Fix release image workflow dispatch
coderdan Jul 20, 2026
73b81da
docs: equality on ordering domains splits on term injectivity
coderdan Jul 23, 2026
031eb47
Merge pull request #418 from cipherstash/docs/database-indexes-ord-eq…
coderdan Jul 23, 2026
dbd8b7c
docs: fix errors and gaps surfaced by a full documentation audit
coderdan Jul 23, 2026
ce132f4
docs: RDS-proper supports the ORE operator class — production-confirmed
coderdan Jul 23, 2026
620714f
fix(v3): guard empty-bloom needle in eql_v3.matches (CIP-3606)
freshtonic Jul 23, 2026
c424e2e
build: harden v3 dep ordering (LC_ALL=C sort, cross-platform cycle ga…
tobyhede Jul 8, 2026
7cf5f40
codegen: emit deterministic topo-ordered manifest for the generated S…
tobyhede Jul 8, 2026
0cb8c63
build: order generated surface from codegen manifest; tsort now a who…
tobyhede Jul 8, 2026
0eabc47
build: add referenced-vs-defined symbol cross-check over the installe…
tobyhede Jul 8, 2026
76fcdc2
ci/docs: gate symbol-order + build-ordering helpers; document codegen…
tobyhede Jul 8, 2026
3455561
build: address review — fail-loud strip_require_lines (propagate grep…
tobyhede Jul 8, 2026
0e72905
style: cargo fmt + silence clippy::type_complexity in property test s…
tobyhede Jul 9, 2026
a7651be
build: teach the symbol-order checker the eql_v3 CREATE DOMAIN form
tobyhede Jul 9, 2026
965dce2
build: order the whole v3 surface from one walk, not two enumerations
tobyhede Jul 9, 2026
fccd712
build: harden the symbol-order gate and correct the ordering diagnostics
tobyhede Jul 9, 2026
8b5a116
test: gate the installer against the order, not just the order agains…
tobyhede Jul 9, 2026
fb7c096
build: drop the one-shot monolith reorder-only check
tobyhede Jul 9, 2026
e8b261b
build: address review — invalidate the build cache on gate edits, fai…
tobyhede Jul 17, 2026
2fd6bd3
build: report what the symbol gate cannot resolve; reject self-edges;…
tobyhede Jul 17, 2026
f9de116
build: describe the query-domain schema split without a private track…
tobyhede Jul 24, 2026
73e412d
Merge pull request #382 from cipherstash/build-ordering-refactor
tobyhede Jul 24, 2026
1e4329f
feat(eql_v3): add grouped_value aggregate
freshtonic Jul 27, 2026
874326f
test(splinter): allowlist eql_v3.grouped_value search_path finding
freshtonic Jul 27, 2026
88dae68
docs(eql_v3): reframe grouped_value docs for users; add DISTINCT test
freshtonic Jul 27, 2026
5e9a649
docs(eql_v3): tighten grouped_value docs per review
freshtonic Jul 27, 2026
cb47ede
Merge pull request #423 from cipherstash/james/cip-3657-re-create-gro…
freshtonic Jul 27, 2026
132c762
fix(ci): scrub private tracker ids and fix rustfmt
freshtonic Jul 27, 2026
6a6a0f4
Merge pull request #421 from cipherstash/james/cip-3606-an-empty-bloo…
freshtonic Jul 27, 2026
c5e3935
Merge pull request #415 from cipherstash/fix/release-image-dispatch-repo
coderdan Jul 27, 2026
7e5e42c
docs: address review feedback on the audit fixes
coderdan Jul 27, 2026
e0cdd9d
docs: JSON is a mixed catalog family; note the _ord shorthand
coderdan Jul 27, 2026
79e0569
Merge pull request #419 from cipherstash/docs/audit-fixes
coderdan Jul 27, 2026
58d9696
chore(release): bump grouped_value changeset to patch
coderdan Jul 27, 2026
62f85b0
Merge pull request #426 from cipherstash/fix/grouped-value-patch-bump
coderdan Jul 27, 2026
1154673
Version Packages
github-actions[bot] Jul 27, 2026
d57a2da
Merge pull request #424 from cipherstash/changeset-release/main
coderdan Jul 27, 2026
c8ee10f
fix(docs): recover symbols the manifest extraction was silently dropping
coderdan Jul 28, 2026
8653d06
fix(docs): keep filtered line numbers stable and stop publishing a tr…
coderdan Jul 28, 2026
d5a2e17
Merge pull request #427 from cipherstash/docs/manifest-extraction-fixes
coderdan Jul 28, 2026
c5967c5
Version Packages
github-actions[bot] Jul 28, 2026
f878f9a
Merge pull request #429 from cipherstash/changeset-release/main
coderdan Jul 28, 2026
2cfadb0
test(v3): property tests for the empty-bloom needle guard (CIP-3665)
freshtonic Aug 4, 2026
4c2bb92
feat(json)!: rename eql_v3.ste_vec_contains to eql_v3.jsonb_document_…
freshtonic Aug 4, 2026
efaa0b1
docs(reference): document eq_term/ord_term for SELECT DISTINCT + ORDE…
freshtonic Aug 4, 2026
4e74bfb
fix(test): rename ste_vec_contains splinter allowlist row to jsonb_do…
freshtonic Aug 4, 2026
63af028
chore(release): regenerate bundled installer SQL for jsonb_document_c…
freshtonic Aug 4, 2026
1a40413
chore(tests): drop private tracker identifiers from public test files…
freshtonic Aug 4, 2026
c4f8e48
Merge pull request #433 from cipherstash/james/cip-3677-document-sele…
freshtonic Aug 5, 2026
a4e8cbf
Merge pull request #432 from cipherstash/james/cip-3353-consolidate-s…
freshtonic Aug 5, 2026
ab6806d
test(v3): append full-length seed before selecting the substring prefix
freshtonic Aug 5, 2026
aab1d12
Merge pull request #431 from cipherstash/james/cip-3665-property-test…
freshtonic Aug 5, 2026
6d664eb
docs(plans): EQL monorepo absorption plan
tobyhede Aug 13, 2026
39c75d6
docs(plans): resolve the EQL absorption's three open decisions
tobyhede Aug 13, 2026
ae463e3
docs(plans): record the path-dep build probe as verified
tobyhede Aug 13, 2026
e54aa5b
Add 'packages/eql/' from commit 'aab1d12d6b078abb62b4eb9b89fb1cbcf51d…
tobyhede Aug 13, 2026
ed66a44
chore(eql): delete duplicated and dead files from the import
tobyhede Aug 13, 2026
f56cb6f
docs(plans): move the Biome reflow behind the ignore entries
tobyhede Aug 13, 2026
f29fdfb
chore(biome): exclude the imported EQL generated surfaces
tobyhede Aug 13, 2026
57dd5bf
style(eql): reflow the imported tree under Biome 2.5.2
tobyhede Aug 13, 2026
8fda740
feat(eql): wire the subtree into the pnpm workspace and turbo graph
tobyhede Aug 13, 2026
f8946ce
docs(plans): record the Phase 2 verification results, including two t…
tobyhede Aug 13, 2026
3830f06
ci(eql): run the SQLx suite from the root workflow directory
tobyhede Aug 13, 2026
e614cf7
ci(eql): port the bench and macro-expand workflows to the root
tobyhede Aug 13, 2026
7f93728
test(eql): assert every cargo check EQL owns is reached by a root wor…
tobyhede Aug 13, 2026
3e905da
chore(deps): monitor the EQL Cargo workspace with Dependabot
tobyhede Aug 13, 2026
98b0fef
docs(plans): record Phase 4, and move two items to Phase 5
tobyhede Aug 13, 2026
7a9604c
feat(eql): resolve eql-bindings from the tree, not from crates.io
tobyhede Aug 13, 2026
e275b09
test(eql): fail the build if EQL resolves from a registry
tobyhede Aug 13, 2026
d153f7c
docs(plans): record Phase 3, and split its one half-runnable box
tobyhede Aug 13, 2026
6009ad9
fix(eql): let the two checkout-less jobs out of the EQL working direc…
tobyhede Aug 13, 2026
43020cf
fix(eql): build @cipherstash/eql before prisma-next typechecks agains…
tobyhede Aug 13, 2026
102cbcc
docs(plans): record the EQL build-structure verification
tobyhede Aug 13, 2026
497a43d
test(ci): guard bare pnpm steps on the package graph, not on turbo's …
tobyhede Aug 13, 2026
9467cc5
fix(eql): re-pin the workspace-keyed SteVec selector, and guard its s…
tobyhede Aug 13, 2026
da14133
fix(eql): re-pin SEL_HELLO_OP to this repo's CI workspace
tobyhede Aug 13, 2026
d0ba95a
docs(plans): record that workspace:^ moved consumers to EQL's unrelea…
tobyhede Aug 13, 2026
9b1c44d
feat(eql)!: bump to 4.0.0, and refuse to package SQL under the wrong …
tobyhede Aug 13, 2026
23079d7
fix(eql): release the rename as 3.0.5, not 4.0.0
tobyhede Aug 13, 2026
ea9e140
feat(stack-prisma): bake eql-3.0.5, and re-emit the baseline to keep …
tobyhede Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
42 changes: 42 additions & 0 deletions .changeset/eql-3-0-5-migration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
'@cipherstash/stack-prisma': minor
---

Move the bundled EQL v3 migrations to **eql-3.0.5**, which renames the SQL
function `eql_v3.ste_vec_contains` to `eql_v3.jsonb_document_contains`. The
operators are unchanged (`@>` / `<@` on `public.eql_v3_json_search` behave
exactly as before) — only callers that invoke the function **by name** are
affected, which in practice means Supabase / PostgREST, since PostgREST calls
functions rather than operators.

Two artefacts carry the new bundle:

- A new upgrade edge, `20260814T0000_upgrade_eql_v3_3_0_5`, carrying the
invariant `cipherstash:upgrade-eql-v3-bundle-3.0.5-v1`. Databases already
running an earlier bundle re-install through this edge on the next
`prisma-next migrate`, exactly as they did for 3.0.2 and 3.0.4.
- The baseline install migration `20260601T0100_install_eql_v3_bundle`, whose
baked bundle moves to 3.0.5 and which gains a fourth no-SQL carrier op for
the new invariant. Fresh databases therefore land on 3.0.5 from the single
all-additive genesis edge, keeping `db init` (additive-only policy) working.

**Action required.** The baseline's bytes — and so its `migrationHash` — have
changed. If your project already has a `migrations/cipherstash/` directory
generated against `@cipherstash/stack-prisma@1.0.0`, delete that directory and
re-run `prisma-next migration plan` (or `migrate`); the seed phase regenerates
it byte-identical to the shipped artefacts. Your database keeps its markers, so
already-applied invariants are not re-run — the only new work is the 3.0.5
upgrade edge.

**Why the baseline was re-emitted rather than left frozen.** These artefacts are
content-addressed and normally append-only: an EQL bump ships as a new upgrade
directory and published directories are never rewritten. That rule cannot be
followed here without a second `from: null` genesis edge, because no upgrade
edge can ever be walked by `db init` — every upgrade edge is a self-edge, and
the integrity checker requires a self-edge to carry a `data`-class op, which
`db init`'s additive-only policy refuses. A fresh database must therefore
collect every head-ref invariant from the genesis edge it walks. The
append-only alternative would duplicate the full ~2.6 MB bundle into a new
genesis edge on every EQL release, permanently; re-emitting was taken instead
while 1.0.0 was two weeks old with negligible adoption, and is a decision to be
re-argued on adoption numbers rather than repeated by default.
9 changes: 9 additions & 0 deletions .changeset/supabase-skill-eql-305.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
'stash': patch
---

Update the bundled agent skills for eql-3.0.5. `skills/stash-supabase`
re-states the PostgREST query-domain limitations against 3.0.5 (unchanged in
substance — the typed `eql_v3.query_*` operand requirement still stands), and
`skills/stash-postgres` drops a claim that the CLI pins `@cipherstash/eql` to
an exact version, which stopped being true when EQL moved in-tree.
6 changes: 6 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,9 @@
self-hosted-runner:
labels:
- blacksmith-4vcpu-ubuntu-2404
# Every job in the imported EQL suite. Sixteen of them, and the size is
# deliberate upstream: the sharded SQLx matrix compiles the full Rust
# dependency tree, so the runner is chosen for the compile rather than for
# the tests. Kept as its own label rather than renamed to the 4vcpu one —
# rehoming those jobs is a cost decision, not a lint fix.
- blacksmith-16vcpu-ubuntu-2204
63 changes: 63 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,69 @@ updates:
update-types:
- version-update:semver-major

# ── Cargo (packages/eql — the second Rust workspace) ───────────
# The EQL subtree brought a second Cargo workspace: five members
# (crates/eql-{domains,codegen,tests-macros,bindings} plus tests/sqlx) and
# its own Cargo.lock. It needs its own entry because Dependabot's cargo
# `directory:` is a single workspace root, not a glob — the protect-ffi entry
# above cannot reach it. The lockfile-to-ecosystem check in
# e2e/tests/supply-chain.e2e.test.ts asserts coverage per ECOSYSTEM, so it
# was already satisfied by that entry and would NOT have caught this gap;
# the symptom would simply have been that no PR ever arrived.
- package-ecosystem: cargo
# The workspace root, where Cargo.toml and Cargo.lock live. Not `/`, and
# not a crate directory — same trap as the protect-ffi entry documents.
directory: /packages/eql
# Monthly, matching protect-ffi and for the same reason: validating a
# Cargo.lock bump here means the sharded SQLx matrix in test-eql.yml, which
# compiles the full dependency tree and runs against live Postgres with
# CipherStash credentials. Security fixes are unaffected — those are driven
# by alerts, not by `schedule`.
#
# No `day:`, for the reason recorded above: it applies to `interval: weekly`
# and would be configuration that does nothing.
schedule:
interval: monthly
cooldown:
default-days: 7
open-pull-requests-limit: 3
labels:
- dependencies
- supply-chain
commit-message:
prefix: "chore"
include: scope
groups:
cargo-minor-patch:
patterns:
- "*"
update-types:
- minor
- patch
ignore:
# `cipherstash-client = "=0.42.0"` in tests/sqlx/Cargo.toml — the SAME
# exact pin, at the SAME version, as packages/protect-ffi. That is not a
# coincidence and it is the reason the subtree was imported: the two now
# share one release train, and a Dependabot PR that moved one workspace
# and not the other would reintroduce precisely the skew the absorption
# removed. Bump both, manually, in step with the npm catalog.
#
# Same caveat as above: `ignore` suppresses security PRs too. osv-scanner
# is the compensating control and already reaches this lockfile
# (`--recursive ./`).
- dependency-name: "cipherstash-client"
- dependency-name: "cts-common"
- dependency-name: "stack-auth"
- dependency-name: "stack-profile"
# Published from this workspace by release-plz. A Dependabot PR proposing
# a registry version for a crate we release here would fight the lockstep
# version hook (scripts/sync-lockstep-versions.mjs).
- dependency-name: "eql-bindings"
# Major bumps are reviewed and applied manually, not by Dependabot.
- dependency-name: "*"
update-types:
- version-update:semver-major

# ── GitHub Actions ─────────────────────────────────────────────
- package-ecosystem: github-actions
directory: /
Expand Down
119 changes: 119 additions & 0 deletions .github/workflows/bench-eql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,119 @@
name: "Bench EQL"

# Ported from cipherstash/encrypt-query-language with the subtree. See
# `.github/workflows/test-eql.yml` for the full account of what the move costs;
# this file needed the same four path rewrites plus two changes of its own,
# noted at the steps that carry them.
#
# Runs the slow benchmark / regression / scale SQLx tests gated behind the
# `bench` cargo feature. Not on pull requests — those use the fast `test-eql`
# workflow.
# Triggers:
# - push to main (catches regressions before release)
# - nightly schedule (additional smoke)
# - manual workflow_dispatch (PR triage)
on:
push:
branches:
- main
# Repo-root relative, so every entry gained the subtree prefix. Unprefixed,
# `src/**/*.sql` and `tests/sqlx/**/*` match nothing under this repository's
# root and the bench would simply stop running on pushes — silently, since
# a workflow that never triggers reports nothing at all.
paths:
- ".github/workflows/bench-eql.yml"
- "packages/eql/src/**/*.sql"
- "packages/eql/tests/sqlx/**/*"
- "packages/eql/tasks/**/*"
- "packages/eql/crates/**"
- "packages/eql/Cargo.toml"
- "packages/eql/Cargo.lock"

schedule:
# 02:00 UTC daily
- cron: "0 2 * * *"

workflow_dispatch:

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
MISE_VERBOSE: "1"

permissions:
contents: read

defaults:
run:
shell: bash {0}
# Every `run:` here is written against the EQL root.
working-directory: packages/eql

jobs:
bench:
name: "Bench EQL (Postgres 17)"
runs-on: blacksmith-16vcpu-ubuntu-2204
timeout-minutes: 60

env:
POSTGRES_VERSION: "17"

steps:
# SHA-pinned, where upstream used floating major tags. The rest of the
# imported suite already pins by SHA; a mutable tag on a job that holds
# live CipherStash credentials means the code running there can change
# without a commit here. Same three pins as test-eql.yml — keep them in
# step. (checkout moves v4 -> v6 with this, matching that file.)
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false

# Fast pre-flight: fail in seconds if a secret was rotated or cleared,
# before the rust-cache restore and a bench run budgeted at 60 minutes.
# This is a scheduled job, so nobody is watching it start — the difference
# between failing here and failing in `test:bench` is a legible nightly
# failure versus "Auth strategy error: Not authenticated" an hour in.
- uses: ./.github/actions/require-cs-secrets
with:
workspace-crn: ${{ vars.CS_WORKSPACE_CRN }}
client-id: ${{ vars.CS_CLIENT_ID }}
client-key: ${{ secrets.CS_CLIENT_KEY }}
client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }}

- uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4
with:
version: 2026.4.0
install: true
cache: true
# mise reads config from cwd and its PARENTS, so an action running at
# the repo root never sees packages/eql/mise.toml.
working_directory: packages/eql

- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
workspaces: packages/eql
shared-key: sqlx-tests

- name: Setup database
run: |
mise run postgres:up postgres-${POSTGRES_VERSION} --extra-args "--detach --wait"

- name: Run bench tests
# CS_* scoped to THIS step only (least privilege): test:bench -> test:sqlx:prep
# -> fixture:generate:all encrypts via cipherstash-client and needs BOTH a
# ZeroKMS auth credential (CS_CLIENT_ACCESS_KEY + CS_WORKSPACE_CRN) AND a client
# key (CS_CLIENT_ID + CS_CLIENT_KEY); without them it fails "Auth strategy error:
# Not authenticated". Kept off job scope so checkout/mise/rust-cache actions
# never see them.
#
# CS_WORKSPACE_CRN and CS_CLIENT_ID read from `vars.`, not `secrets.` —
# this repo keeps the two non-sensitive ones there. Reading them from
# `secrets.` yields the empty string rather than an error.
env:
CS_CLIENT_ACCESS_KEY: ${{ secrets.CS_CLIENT_ACCESS_KEY }}
CS_WORKSPACE_CRN: ${{ vars.CS_WORKSPACE_CRN }}
CS_CLIENT_ID: ${{ vars.CS_CLIENT_ID }}
CS_CLIENT_KEY: ${{ secrets.CS_CLIENT_KEY }}
run: |
export active_rust_toolchain=$(rustup show active-toolchain | cut -d' ' -f1)
rustup component add --toolchain ${active_rust_toolchain} rustfmt clippy
mise run --output prefix test:bench --postgres ${POSTGRES_VERSION}
6 changes: 3 additions & 3 deletions .github/workflows/fta-v3.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,10 +82,10 @@ jobs:
# reflow trips this step without a real complexity increase, re-measure
# (`npx fta src --format table`) before assuming the code got worse.
- name: Analyze stack (eql/v3) complexity
run: pnpm --filter @cipherstash/stack run analyze:complexity
run: pnpm exec turbo run analyze:complexity --filter @cipherstash/stack

- name: Analyze stack-drizzle complexity
run: pnpm --filter @cipherstash/stack-drizzle run analyze:complexity
run: pnpm exec turbo run analyze:complexity --filter @cipherstash/stack-drizzle

- name: Analyze stack-supabase complexity
run: pnpm --filter @cipherstash/stack-supabase run analyze:complexity
run: pnpm exec turbo run analyze:complexity --filter @cipherstash/stack-supabase
95 changes: 95 additions & 0 deletions .github/workflows/macro-expand-eql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,95 @@
name: "Macro expand EQL"

# Ported from cipherstash/encrypt-query-language with the subtree. See
# `.github/workflows/test-eql.yml` for what the move costs (three path rewrites
# here) and `scripts/__tests__/eql-suite-ci.test.mjs` for why a workflow left in
# `packages/eql/.github/` runs nowhere.
#
# Regenerates the matrix `cargo expand` snapshots (one per reachable
# `scalar_matrix!` arm: integer = [eq, ord], text = [eq, ord, search], boolean =
# [storage]) and fails if any has drifted from its committed copy. This is a
# body-level fidelity backstop for the matrix macros — the name-inventory
# snapshot (test-eql.yml `matrix-coverage` job) catches add/remove of whole
# arms; this catches changes *inside* the generated bodies.
#
# Non-blocking by design: it is NOT a required PR check. `cargo expand` needs a
# nightly toolchain, so it is isolated off the PR path.
# - nightly schedule (the backstop that flags a forgotten local regen)
# - manual workflow_dispatch
#
# GAP (intended): there is no `pull_request` trigger, so a change that only
# touches macro *bodies* (no arm add/remove) can merge without ever running
# here and will first surface as a red nightly run afterwards. Accept this — the
# expand lane needs nightly and stays off the PR critical path by design.
#
# The pinned nightly date lives in ONE place: the `cargo +nightly-...` invocation
# in the `test:matrix:expand` mise task. The install step below DERIVES the date
# from mise.toml (grep), so there is nothing to keep in lockstep — bump it once in
# mise.toml. The snapshot then only moves when the macro moves, not when nightly
# reformats its expansion.
on:
schedule:
# 03:00 UTC daily
- cron: "0 3 * * *"

workflow_dispatch:

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
MISE_VERBOSE: "1"

defaults:
run:
shell: bash {0}
# Every `run:` here is written against the EQL root: `mise.toml` for the
# nightly grep, and `tests/sqlx/snapshots` for the drift diff.
working-directory: packages/eql

permissions:
contents: read

jobs:
macro-expand:
name: "Macro expand drift (nightly)"
runs-on: blacksmith-16vcpu-ubuntu-2204
timeout-minutes: 30

steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false

- uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4
with:
version: 2026.4.0
install: true
cache: true
working_directory: packages/eql

- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
workspaces: packages/eql/tests/sqlx
shared-key: sqlx-tests

# Derive the pinned nightly date from mise.toml (single source of truth —
# the `cargo +nightly-...` invocation in the `test:matrix:expand` task) so
# there is nothing to bump in lockstep here. cargo-expand is likewise pinned
# once in mise.toml's [tools] (`cargo:cargo-expand`) and installed by the
# mise-action step above, so its version is single-sourced too — no
# hardcoded version lives in this workflow. It drives the rustfmt pass, so
# an unpinned version could drift the snapshot even with a frozen macro +
# nightly. The snapshot then only moves when the macro moves.
- name: Install pinned nightly toolchain
run: |
NIGHTLY=$(grep -oE 'nightly-[0-9]{4}-[0-9]{2}-[0-9]{2}' mise.toml | head -1)
test -n "$NIGHTLY" || { echo "could not find pinned nightly in mise.toml"; exit 1; }
rustup toolchain install "$NIGHTLY" --profile minimal --component rustfmt

- name: Regenerate and verify the matrix expansion snapshots
run: |
mise run test:matrix:expand
git diff --exit-code -- \
tests/sqlx/snapshots/integer_expanded.rs \
tests/sqlx/snapshots/text_expanded.rs \
tests/sqlx/snapshots/boolean_expanded.rs \
|| { echo "Expansion snapshot stale — run 'mise run test:matrix:expand' (needs the pinned nightly) and commit."; exit 1; }
2 changes: 1 addition & 1 deletion .github/workflows/prisma-next-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -149,7 +149,7 @@ jobs:
run: pnpm exec turbo run build --filter @cipherstash/stack-prisma

- name: Emit example contract
run: pnpm --filter @cipherstash/prisma-example emit
run: pnpm exec turbo run emit --filter @cipherstash/prisma-example

- name: Start E2E Postgres container
working-directory: examples/prisma
Expand Down
9 changes: 9 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,15 @@ jobs:
uses: changesets/action@v1.9.0
with:
publish: pnpm run release
# LOAD-BEARING, and it fails OPEN if removed. Without `version:` the
# action runs its own built-in `changeset version` and never invokes
# the root `version` script — so `scripts/sync-lockstep-versions.mjs`
# would not run, npm would bump while
# packages/eql/crates/eql-bindings/Cargo.toml and the bundled SQL
# assets kept the old version, and the first symptom would be a
# published crate disagreeing with the SQL bundle it ships.
# Asserted by scripts/__tests__/release-version-hook.test.mjs.
version: pnpm run version
commitMode: 'github-api'
env:
# No NPM_TOKEN — publishing authenticates via npm OIDC trusted
Expand Down
Loading
Loading