Repository navigation
Commit 1670ebd
committed
feat(golang)!: the generated API replaces the value and record calls
The Go SDK is now what the plan builder design describes: a struct's stash
tags are the declaration, stashgen writes the encrypted type and its
functions, and a program calls users.Encrypt, users.Decrypt and
users.Fields. Everything the old package offered beside that is removed,
not deprecated — it was never released: Cipher.Encrypt/Decrypt and the
Element forms, Client.Decrypt, EncryptRecord(s)/DecryptRecord(s),
EncryptedRecord, EncryptedField, Cipher.Term, RecordOption, WithPlan,
ExtendContext, WithGuest, TermKind, Plan, FieldPlan, NewPlan, PlanFromTags
and every run-time tag reader, the plan package and plantest, factstest,
Context/Label and their constructors, and the four Sealed* storage types.
What replaces them, and why it has the shape it has:
- encrypt.Cipher.Extend appends the caller's parts to every field's
context in every call through the cipher, so the write, the query and
the read cannot use different ones. encrypt.Ciphertext is the frozen
stack-encrypt leaf, the one storage type: every sealed field is one
leaf. Index is Equality, Ore, Ope, Match() and JSON(); the term types
stay. Decrypter is what a generated Decrypt takes: *Cipher refuses a
foreign keyset's row before any key is retrieved, *Client opens each
row under the keyset that sealed it.
- The record path (Cipher.Seal, Cipher.Open, Client.Open, Cipher.Derive)
takes the internal record types, so only generated code reaches it.
internal/record is the data form of a declaration as dynamic::record
reads it: a field's context is its label (context segments + identity)
nested under each extension part, "type" is the wire kind, outputs are
c/eq/match/ore/ope. Both gensupport (running) and stashgen (checking)
lower to it, so the generator checks the plan the program will run.
- encrypt/gensupport is the real library behind generated code: Declare
and the verb methods carry the field's wire kind, which stashgen picks
from the Go type (int8..int32 travel as int32, int/int64 as int64, the
unsigned likewise, []byte as bytes); Codec.Encrypt/Decrypt send a slice
as one guest call and one ZeroKMS request; Field[T] seals one value and
derives the field's terms; Get converts within a kind's family and
refuses the rest, so a value that opens to another type is an error.
- Passthrough fields stay on the host. The FFI codec cannot carry every
Go type a program stores beside a ciphertext (time.Time, gorm.DeletedAt,
any driver.Valuer), and nothing the engine does to a passthrough value
is observable, so the plan the engine sees has the sealed fields only
and the generated Seal reads passthrough values back from the Record.
The plan says passthrough crosses; this is the deviation, recorded here
and in the record package's doc.
- An opaque struct crosses as one JSON document, declared bytes, because
the engine seals a composite FfiValue as a tree of leaves and an opaque
struct is one column. Its fields are what JSON carries; the generator
refuses a nested struct inside one for now.
- stashgen.GuestEngine is the embedded guest: encrypt.NewChecker
instantiates it with no credentials and asks se_plan_check one field at
a time, so a refusal names the field, then for the whole plan. The
engine produces no EQL type in this build (se_targets is empty), so
encrypt_into is refused with "EQL types are not available yet".
The guest loses se_encrypt, se_decrypt and the element exports (ADR-0007
as amended: every value crosses under a declaration) and gains
se_plan_check and se_targets. A `deterministic-kms` feature builds a TEST
guest whose keys derive from a seed — the DeterministicSource of
stack-encrypt's tests/common, copied — so the Go tests open the records
Rust sealed in tests/fixtures/record_lowering.json through the generated
testusers package and derive the same term bytes, and run round trips,
foreign-keyset refusal, tampering and the ORE/OPE ordering properties
with no ZeroKMS. The hermetic tests replace the old live ordering tests;
the live suite keeps the real round trips through generated code. The
test build's import gate requires no transport import: with no ZeroKMS
client in it, the linker drops the host module.
Generated *_stash.go files are committed (internal/testusers, example),
and tests-golang.yml runs `go generate ./...` and fails on a diff. The
stashgen goldens and the stub SDK follow the new signatures; the stub
agreement test now covers encrypt too and compares signatures without
parameter names. The example is rewritten to the eight steps; the
explicit-credentials example, which only showed the removed API, is
gone with its task.
Claude-Session: https://claude.ai/code/session_01V3WFXwax4J3uecpFEJ6yHc1 parent c16ea7b commit 1670ebd
93 files changed
Lines changed: 5322 additions & 8502 deletions
File tree
- .github/workflows
- languages/golang
- auth
- cmd/stashgen
- encrypt
- example
- explicit
- gensupport
- guest
- src
- tests
- internal/testusers
- plan
- plantest
- testdata/TestPolicies
- wasm
- internal
- factstest
- record
- stashgen
- testdata
- cases
- accounts
- contacts
- embedded
- foreign
- orders
- users
- stubsdk/encrypt
- gensupport
- scripts/__tests__
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | | - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
13 | 15 | | |
14 | 16 | | |
15 | 17 | | |
| |||
144 | 146 | | |
145 | 147 | | |
146 | 148 | | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
147 | 157 | | |
148 | 158 | | |
149 | 159 | | |
| |||
155 | 165 | | |
156 | 166 | | |
157 | 167 | | |
158 | | - | |
| 168 | + | |
159 | 169 | | |
160 | 170 | | |
161 | 171 | | |
| |||
166 | 176 | | |
167 | 177 | | |
168 | 178 | | |
| 179 | + | |
| 180 | + | |
169 | 181 | | |
170 | 182 | | |
171 | 183 | | |
| |||
183 | 195 | | |
184 | 196 | | |
185 | 197 | | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
186 | 209 | | |
187 | 210 | | |
188 | 211 | | |
| |||
256 | 279 | | |
257 | 280 | | |
258 | 281 | | |
259 | | - | |
| 282 | + | |
260 | 283 | | |
261 | 284 | | |
262 | 285 | | |
| |||
320 | 343 | | |
321 | 344 | | |
322 | 345 | | |
323 | | - | |
| 346 | + | |
324 | 347 | | |
325 | 348 | | |
326 | 349 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
92 | 92 | | |
93 | 93 | | |
94 | 94 | | |
95 | | - | |
| 95 | + | |
96 | 96 | | |
97 | 97 | | |
98 | 98 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
72 | | - | |
| 72 | + | |
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
119 | | - | |
| 119 | + | |
120 | 120 | | |
121 | | - | |
| 121 | + | |
122 | 122 | | |
123 | 123 | | |
124 | 124 | | |
| |||
176 | 176 | | |
177 | 177 | | |
178 | 178 | | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
179 | 185 | | |
180 | 186 | | |
181 | | - | |
182 | | - | |
183 | | - | |
| 187 | + | |
| 188 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
11 | 12 | | |
12 | 13 | | |
13 | 14 | | |
| |||
117 | 118 | | |
118 | 119 | | |
119 | 120 | | |
120 | | - | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
121 | 130 | | |
122 | 131 | | |
123 | 132 | | |
124 | | - | |
| 133 | + | |
125 | 134 | | |
126 | | - | |
| 135 | + | |
127 | 136 | | |
128 | 137 | | |
129 | 138 | | |
130 | | - | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
131 | 147 | | |
132 | 148 | | |
133 | 149 | | |
| |||
0 commit comments