Skip to content

Tracking: implement ADR-0002, new value kinds and EQL v4 for Stack Encrypt #1145

Description

@coderdan

Background

Stack Encrypt is our Rust encryption engine; the Go SDK runs it. EQL (Encrypt
Query Language) is the SQL we install into a customer's Postgres so it can
store and search encrypted values. Every value Stack Encrypt handles is encoded
three ways: as a ciphertext, as an equality term (a keyed hash for =) and as
an order term (for <, > and sorting). ADR-0002 (#1139)
decides how each encoding works for each kind of value, and how EQL keeps
columns written by Stack Encrypt apart from columns written by
cipherstash-client, the engine behind the TypeScript SDK.

Problem

Stack Encrypt can write one of EQL's 51 column types, TextEq. Numbers, dates,
timestamps and decimals are blocked because their byte formats were never
decided, and the three encodings disagree about which kinds of value exist.
Separately, a Stack Encrypt query against a column cipherstash-client wrote
returns no rows, silently, because Postgres cannot tell the two apart.

Proposal

The work spans four repositories and has a fixed release order: crates.io
releases must land before the crates that build on them.

  1. ore.rs: variable-length orderable encoding (orderable-bytes has no variable-length encoding — text and bytes can't share the order layer ore.rs#94). Chained block ORE for text
    (Tracking: review and release chained block ORE (ore v2) so text can use block ORE ore.rs#95) is not on the critical path.
  2. cipherstash-suite: cllw-ore typed impls behind a default-on feature, and a
    bytes-level entry point (tracked in New vitaminc-ore crate: one order encoding per kind, with block ORE, CLLW ORE and CLLW OPE as pluggable schemes vitaminc#374; that repo has no issues).
  3. vitaminc 0.6.0: aead-value 0.6: rename FfiValue to Value, make it Clone and non_exhaustive, move transport's framing tags vitaminc#371, aead-value 0.6: add 8-, 16- and 128-bit integers, Date, Timestamp and Decimal as value kinds vitaminc#372, vitaminc-prf: equality terms for the new kinds, floats and decimal, from one canonical form per kind vitaminc#373, New vitaminc-ore crate: one order encoding per kind, with block ORE, CLLW ORE and CLLW OPE as pluggable schemes vitaminc#374, Bindings: encode the new value kinds from JavaScript and Go (BigInt to 128 bits, Date, narrow integers) vitaminc#375, and the conformance rule in
    aead-value: a cross-language conformance corpus for the FFI transport codec vitaminc#332.
  4. stack-encrypt breaking release (stack-encrypt: delete dynamic::Value and Scalar, derive terms through vitaminc, add block ORE, drop Bool order terms #1140), then published to crates.io.
  5. EQL: EQL: write the same SQL out as eql_v3 and eql_v4, so Stack Encrypt columns are their own Postgres types #1141 can start now. @cipherstash/eql 4.0: ship the v3 and v4 bundles together and move Stack Encrypt's targets to v4 #1142 needs stack-encrypt: delete dynamic::Value and Scalar, derive terms through vitaminc, add block ORE, drop Bool order terms #1140 on crates.io. stash eql install can't install EQL v4 — add --eql-version 3|4|all #1143 follows @cipherstash/eql 4.0: ship the v3 and v4 bundles together and move Stack Encrypt's targets to v4 #1142.
  6. Go SDK (Go SDK: int16 is widened to Int32, and there's no way to encrypt a date, timestamp, decimal or 128-bit integer #1144), before the Go SDK ships, because it changes how int16 is
    encrypted.

Using canonical order bytes as the equality input needs written sign-off
before cipherstash/vitaminc#373 merges.

Critical path: cipherstash/ore.rs#94 → cipherstash/vitaminc#374 → vitaminc 0.6.0 → #1140 → #1142 → #1144.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions