Skip to content

stack-encrypt: delete dynamic::Value and Scalar, derive terms through vitaminc, add block ORE, drop Bool order terms #1140

Description

@coderdan

Background

stack-encrypt's dynamic module is the path bindings use: values arrive as
vitaminc Values whose type is known only at runtime.

Problem

  1. Two types restate vitaminc's vocabulary. dynamic::Value wraps
    FfiValue only to add Clone. dynamic::term::Scalar (term.rs:196)
    mirrors FfiValue's variants one for one, to pick a Rust type for the term
    crates, and copies text out of Protected to do it.
  2. Bool has order terms (term.rs:444, 467; allowed by kind.rs:62-68).
    With two possible values, an order term tells anyone with the column which
    rows are true.
  3. No block ORE, so TextOrdOre and TextSearchOre stay refused (stashgen refuses TextOrdOre and TextSearchOre — EQL stores block ORE terms and the engine derives CLLW ORE #1132).
  4. TextEq doesn't normalise text, so café written in two Unicode forms
    gives two different hashes.

Proposal

  1. Bump the vitaminc pins to 0.6.0:
    • in the root Cargo.toml, both Go guests, eql-bindings and
      packages/eql/tests/encryption;
    • follow the Value rename;
    • follow the transport tag move in stack-guest-abi and the guests.
  2. Delete dynamic::Value and Scalar. dynamic::term takes &Value and
    calls vitaminc-prf and vitaminc-ore. admits keeps only rules that
    belong to stack, such as Match taking text only.
  3. Remove Bool order terms. Add a block ORE term kind beside CLLW ORE and
    OPE. Remove the direct cllw-ore dependency.
  4. Normalise TextEq to NFC. No stored data depends on the old form.
  5. Breaking: a ! commit and a CHANGELOG Unreleased entry, then publish to
    crates.io before @cipherstash/eql 4.0: ship the v3 and v4 bundles together and move Stack Encrypt's targets to v4 #1142 uses the new API (cargo publish builds
    eql-bindings against the registry).

Needs vitaminc 0.6.0. Decided in ADR-0002 (#1139). Related: #1063, #1132.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SDKenhancementNew feature or requestrustPull requests that update Rust code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions