Background
EQL's SQL installs data types (domains such as eql_v3_text_eq, kept in the
public schema) and the functions that compare them (in the disposable
eql_v3 and eql_v3_internal schemas, per ADR-0001). Each domain checks the
payload's version field: VALUE->>'v' = '3'.
Problem
Stack Encrypt and cipherstash-client both write the same eql_v3_* domains,
but their search terms never match each other. A Go query against a column
the TypeScript SDK wrote returns no rows, and nothing warns. ADR-0002 (#1139)
separates them as EQL v4: identical SQL, but distinct Postgres types, so a
mismatched query fails when it is planned.
Proposal
- Replace the literal schema name and version in the hand-written
packages/eql/src/v3/** SQL with build-time placeholders, as eql-codegen's
templates already do ({{ schema }}). This covers about 24k lines that
mention eql_v3, and VALUE->>'v' = '3' in every domain check.
- Have the build write out
eql_v3 (version 3) and eql_v4 (version 4),
each with its own release manifest and digests.
- Keep ADR-0001's split:
public.eql_v4_* data domains survive reinstall,
and eql_v4 and eql_v4_internal stay disposable.
- Run the SQLx suites against both. Add a test that an
eql_v4 query term
can't be compared with an eql_v3 column.
This can start now; it depends on nothing in vitaminc.
Background
EQL's SQL installs data types (domains such as
eql_v3_text_eq, kept in thepublicschema) and the functions that compare them (in the disposableeql_v3andeql_v3_internalschemas, per ADR-0001). Each domain checks thepayload's version field:
VALUE->>'v' = '3'.Problem
Stack Encrypt and cipherstash-client both write the same
eql_v3_*domains,but their search terms never match each other. A Go query against a column
the TypeScript SDK wrote returns no rows, and nothing warns. ADR-0002 (#1139)
separates them as EQL v4: identical SQL, but distinct Postgres types, so a
mismatched query fails when it is planned.
Proposal
packages/eql/src/v3/**SQL with build-time placeholders, as eql-codegen'stemplates already do (
{{ schema }}). This covers about 24k lines thatmention
eql_v3, andVALUE->>'v' = '3'in every domain check.eql_v3(version3) andeql_v4(version4),each with its own release manifest and digests.
public.eql_v4_*data domains survive reinstall,and
eql_v4andeql_v4_internalstay disposable.eql_v4query termcan't be compared with an
eql_v3column.This can start now; it depends on nothing in vitaminc.