Skip to content

Commit 4539acb

Browse files
committed
feat(eql): derive text equality targets
Use Stack Encrypt declarations and native readers for TextEq and TextEqQuery. The stored identifier supplies context; Vitamin C owns plaintext encoding and equality input. Encode only encrypted output. Exercise canonical cross-opening, validation before KMS, batching, query-only operation and PostgreSQL equality/index use. Registry CI requires the unpublished suite crates and a refreshed registry lock. Refs cipherstash/cipherstash-suite#2215
1 parent 013e3ff commit 4539acb

117 files changed

Lines changed: 1500 additions & 166 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
'@cipherstash/eql': minor
3+
---
4+
5+
**Rust `TextEq` and `TextEqQuery` support Stack Encrypt's target-directed API behind the `stack-encrypt` feature.** The stored table and column identifier supplies the encryption context; native ciphertext and equality terms are transcoded into EQL payloads while Vitamin C owns plaintext encoding. This is a new producer profile with exact string equality, independent of existing cipherstash-client ciphertext and terms. Query operands carry no recoverable ciphertext.

‎.github/workflows/test-eql.yml‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -520,6 +520,18 @@ jobs:
520520
github.event_name != 'pull_request'
521521
|| needs.changes.outputs.relevant == 'true'
522522
runs-on: blacksmith-16vcpu-ubuntu-2204
523+
services:
524+
encryption-postgres:
525+
image: postgres:17
526+
env:
527+
POSTGRES_PASSWORD: postgres
528+
ports:
529+
- 7433:5432
530+
options: >-
531+
--health-cmd pg_isready
532+
--health-interval 10s
533+
--health-timeout 5s
534+
--health-retries 5
523535
steps:
524536
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
525537
with:
@@ -549,6 +561,24 @@ jobs:
549561
rustup component add --toolchain "${active_rust_toolchain}" rustfmt clippy
550562
mise run test:crates
551563
564+
# Registry builds require the unpublished Stack Encrypt crates from
565+
# cipherstash-suite#2215 to be published before this change merges.
566+
- name: Test Rust text equality with PostgreSQL
567+
env:
568+
PGPASSWORD: postgres
569+
EQL_TEST_DATABASE_URL: "host=localhost port=7433 user=postgres password=postgres dbname=postgres"
570+
run: |
571+
cargo test --locked -p eql-bindings --features stack-encrypt
572+
cargo test --locked -p eql-encryption-tests
573+
cargo clippy --locked -p eql-bindings -p eql-encryption-tests --all-features --all-targets -- -D warnings
574+
psql -h localhost -p 7433 -U postgres -d postgres -v ON_ERROR_STOP=1 -f crates/eql-bindings/sql/cipherstash-encrypt.sql
575+
cargo test --locked -p eql-encryption-tests --test text_eq -- --ignored
576+
577+
- name: Compile Rust text equality for WASI without HTTP
578+
run: |
579+
rustup target add wasm32-wasip1
580+
cargo check --locked -p eql-bindings --features stack-encrypt --target wasm32-wasip1
581+
552582
# Freshness gate for the eql-types codegen output: regenerate the
553583
# TypeScript bindings and JSON Schemas and fail if the checked-in
554584
# copies differ. Reuses the toolchain from the step above.

0 commit comments

Comments
 (0)