Repository navigation
feat(golang)!: the Go SDK: stash tags, stashgen and generated Encrypt/Decrypt #1094
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
+16,970
−9,489
Open
Changes from all commits
Commits
Show all changes
25 commits
Select commit
Hold shift + click to select a range
5cca158
feat(golang): stashgen generator library and encrypt/gensupport
coderdan 16546c3
feat(golang): stashgen command, refusal tests and the stub contract c…
coderdan dc9e348
feat(golang): declarations from a policy, and protosource
coderdan fc591d8
refactor(golang)!: rename stackencrypt to encrypt and stackauth to auth
coderdan 2c635ef
feat(golang)!: the generated API replaces the value and record calls
coderdan 35680fa
fix(golang): every field type the generator accepts round-trips
coderdan b127482
fix(golang): a term the engine cannot derive names its field and index
coderdan 4f93d35
fix(golang): the deterministic test guest lives under testdata, out o…
coderdan b51efd6
fix(golang): Get reads every type the generator accepts, and a model …
coderdan b9348c1
fix(golang): se_targets entries are read whole against the agreed wir…
coderdan 6e3e9ef
test(golang): the refusals hold against the embedded engine, not only…
coderdan 54618a2
test(golang): residency on every pull request, and the fixture test f…
coderdan 65039a3
refactor(golang): one DeterministicSource, protoc-gen-go's GoName, an…
coderdan d7a2dd8
chore(stack-kms): DeterministicSource debugs opaquely; stack-encrypt …
coderdan 2eeb79c
fix(golang)!: index-only fields and nil interface passthroughs round-…
coderdan af1b266
chore(golang): mark stashgen output as linguist-generated
auxesis 811b70b
chore(golang): keep generated *_stash.go files expanded in review
auxesis 5f0c393
fix(golang): Decrypt errors hold no plaintext and wrap ErrEncoding
coderdan 0c5417e
fix(golang): docs say what this build does; -redact covers %#v
coderdan 8a63d8e
fix(golang): a field added to an embedded struct stops the build; CI …
coderdan bbcf03e
fix(golang)!: the policy path checks names and takes its output as a …
coderdan d7e7f81
refactor(golang)!: names that do not repeat their package, in Go's sp…
coderdan d680c27
docs(stack-encrypt): drop the Go plan.Custom note, the package is rem…
coderdan 8903021
fix(golang): parseTarget refuses an unknown kind or index
coderdan 8619046
docs(golang): say what the SDK does not protect, and fix the example'…
coderdan File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,10 @@ | ||
| # stashgen's golden test expectations. Marked `linguist-generated` so GitHub | ||
| # collapses them in pull-request and commit diffs by default and excludes them | ||
| # from repository language statistics. This is a GitHub display hint only: | ||
| # nothing about Git, CI, or the build changes. | ||
| # | ||
| # The generated *_stash.go files are deliberately NOT marked. They are the | ||
| # committed record of which fields are encrypted, with which indexes and under | ||
| # which context, so a change to them must stay expanded for the reviewer to | ||
| # read (docs/sdk-design-principles.md, Go principle 10). | ||
| *.golden linguist-generated |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10 changes: 5 additions & 5 deletions
10
languages/golang/stackauth/clientkey.go → languages/golang/auth/clientkey.go
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,12 +1,12 @@ | ||
| package stackauth | ||
| package auth | ||
|
|
||
| import "github.com/cipherstash/stack/languages/golang/internal/guest" | ||
|
|
||
| // ClientKey is the ZeroKMS client key as [ProfileStore.SecretKey] reads it | ||
| // out of secretkey.json: opaque (it prints a redaction under every verb and | ||
| // hands its bytes to no caller) and wiped once consumed. It is the same | ||
| // type as stackencrypt.ClientKey, by identity, so a key read here goes | ||
| // straight into stackencrypt.NewCredentials. This package does not import | ||
| // stackencrypt: a binary that only wants the profile does not carry the | ||
| // crypto guest. (stackencrypt imports this one, for AutoCredentials.) | ||
| // type as encrypt.ClientKey, by identity, so a key read here goes | ||
| // straight into encrypt.NewCredentials. This package does not import | ||
| // encrypt: a binary that only wants the profile does not carry the | ||
| // crypto guest. (encrypt imports this one, for AutoCredentials.) | ||
| type ClientKey = guest.ClientKey |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fix in a follow-up: this step does not find a generated file that was never committed.
Impact: Go10 says "CI fails when one is out of date."
git diffignores untracked files. If a developer adds a//go:generateline and does not commit its output, this step passes. The build fails only if other code uses the missing file.Evidence:
git diff --exit-code -- ., which compares tracked files only.languages/golang/encrypt/README.md:66,languages/golang/cmd/stashgen/README.md:55andlanguages/golang/encrypt/doc.go:45.Fix: Also fail on an untracked file, here and in the three recipes:
Found by 1 model: claude
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed in d4dc295. The CI step now also fails on untracked files under
languages/golangand prints them, and the three recipes addtest -z "$(git status --porcelain)".