Skip to content

EQL: write the same SQL out as eql_v3 and eql_v4, so Stack Encrypt columns are their own Postgres types #1141

Description

@coderdan

Background

EQL's SQL installs data types (domains such as eql_v3_text_eq, kept in the
public schema) and the functions that compare them (in the disposable
eql_v3 and eql_v3_internal schemas, per ADR-0001). Each domain checks the
payload's version field: VALUE->>'v' = '3'.

Problem

Stack Encrypt and cipherstash-client both write the same eql_v3_* domains,
but their search terms never match each other. A Go query against a column
the TypeScript SDK wrote returns no rows, and nothing warns. ADR-0002 (#1139)
separates them as EQL v4: identical SQL, but distinct Postgres types, so a
mismatched query fails when it is planned.

Proposal

  1. Replace the literal schema name and version in the hand-written
    packages/eql/src/v3/** SQL with build-time placeholders, as eql-codegen's
    templates already do ({{ schema }}). This covers about 24k lines that
    mention eql_v3, and VALUE->>'v' = '3' in every domain check.
  2. Have the build write out eql_v3 (version 3) and eql_v4 (version 4),
    each with its own release manifest and digests.
  3. Keep ADR-0001's split: public.eql_v4_* data domains survive reinstall,
    and eql_v4 and eql_v4_internal stay disposable.
  4. Run the SQLx suites against both. Add a test that an eql_v4 query term
    can't be compared with an eql_v3 column.

This can start now; it depends on nothing in vitaminc.

Metadata

Metadata

Assignees

Labels

SDKenhancementNew feature or requestrustPull requests that update Rust code

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions