Skip to content

Commit da14133

Browse files
committed
fix(eql): re-pin SEL_HELLO_OP to this repo's CI workspace
b325a0c7… -> 6f1db3bd…, the second and last of the workspace-keyed SteVec selectors. The new drift guard reported the candidates instead of choosing one, so the leaf is identified rather than guessed: at 16 * len + 20 hex chars all six op-carrying leaves reconcile against the fixture's known documents — $.empty 20, $.accented 84/180/196 (three lengths, not four, because the café/cafe collision pair shares one), $.nested.deep 148 for "constant", $.number and $.large a fixed-width 132, and $.hello alone spanning 132/148 for world-1..9 vs world-10. --no-fail-fast paid for itself immediately: the run reported all seven remaining failures at once (695/671/655 tests per shard, shard 1 fully green) and every one is a SEL_HELLO_OP consumer, so this is expected to be the last of it rather than the next round of one.
1 parent 9467cc5 commit da14133

2 files changed

Lines changed: 18 additions & 2 deletions

File tree

‎docs/plans/2026-08-13-eql-monorepo-absorption.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,9 @@ There is also a convention mismatch. EQL reads all four values from `secrets`; t
149149
The finding above treats the credentials as a wiring problem. They are also an *identity* problem, which the first credentialed run found and this plan had not anticipated: `vars.CS_WORKSPACE_CRN` here names a different CipherStash workspace than the one EQL was developed against. Two pinned SteVec selectors are MACs of (column context, JSONPath) **under the workspace keyset**, so they re-pin on the move even though no Rust, no SQL and no fixture logic changed:
150150

151151
- `tests/sqlx/src/fixtures/v3_doc_integer.rs::SELECTOR` — `fce8be75…` → `606a4a44…`, reported identically by two independent runs.
152-
- `tests/sqlx/src/fixtures/v3_ste_vec.rs::SEL_HELLO_OP` — same keying, value not yet observed.
152+
- `tests/sqlx/src/fixtures/v3_ste_vec.rs::SEL_HELLO_OP` — `b325a0c7…` → `6f1db3bd…`, identified from the new guard's report.
153+
154+
The identification is over-determined rather than rule-matched, which is the standard a silent mis-pin deserves. The guard printed all six `op`-carrying leaves, and at `16 * len + 20` hex chars every one reconciles against the fixture's known documents: `$.empty` 20, `$.accented` 84/180/196 — three lengths rather than four, because the `café`/`cafe` collision pair the fixture exists to carry shares one — `$.nested.deep` 148 for `"constant"`, `$.number` and `$.large` a fixed-width 132, and `$.hello` alone spanning 132/148 for `world-1..9` vs `world-10`.
153155

154156
This is a known, accepted property rather than a defect: the module comment says supporting multiple workspaces "would require runtime selector resolution, which the static `ScalarType::column_expr()` seam cannot do — out of scope here." The consequence to record is that **these pins are now coupled to this repo's CI workspace**, so rotating `CS_WORKSPACE_CRN` re-pins them again, and a contributor running the suite against their own workspace will see the drift message and must not commit their local value.
155157

‎packages/eql/tests/sqlx/src/fixtures/v3_ste_vec.rs‎

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,21 @@ const NAME: &str = "v3_ste_vec";
4848
/// `op` is `8 * (len + 1) + 1` bits, so `$.hello` is 132 hex chars for
4949
/// `"world-1"`..`"world-9"` and 148 for `"world-10"`, while `$.number` is a
5050
/// fixed-width 65-bit number term — 132 on every row.
51-
pub const SEL_HELLO_OP: &str = "b325a0c77b130af97b805c12ff853ab3";
51+
///
52+
/// **Pinned to this repo's CI workspace** (`vars.CS_WORKSPACE_CRN`). The value
53+
/// below replaced `b325a0c77b130af97b805c12ff853ab3` when the suite moved here
54+
/// from `cipherstash/encrypt-query-language`: a different workspace means a
55+
/// different keyset, so the MAC re-pinned with no Rust, SQL or fixture change.
56+
/// `v3_jsonb_sel_hello_op_matches_fixture` is the drift guard; it reports the
57+
/// live candidates rather than choosing, so the leaf is identified by the
58+
/// length rule above, not guessed. Against that workspace the fixture's six
59+
/// `op`-carrying leaves separate cleanly at `16 * len + 20` hex chars —
60+
/// `$.empty` 20, `$.accented` 84/180/196 (three lengths, not four: the
61+
/// `café`/`cafe` collision pair shares one), `$.nested.deep` 148,
62+
/// `$.number` and `$.large` a fixed 132, and `$.hello` alone spanning 132/148.
63+
/// A contributor running against their own workspace will see the guard fire
64+
/// and should NOT commit their local value.
65+
pub const SEL_HELLO_OP: &str = "6f1db3bd70058dc4dab95cc692599b12";
5266

5367
/// The canonical `payload` column type — the `public.eql_v3_json_search` DOMAIN, so the
5468
/// domain CHECK runs when the fixture loads.

0 commit comments

Comments
 (0)