Repository navigation
Documents the parallel-column exit - #121
Merged
Merged
Conversation
The migrate-from-cloak guide gains a second exit beside the in-place one: a <field>_encrypted column per encrypted field, written by the host's changeset beside the old one, backfilled by a plan that reads the old column through its legacy type and writes into: the new one, verified over the new column, then read, then the old column and the legacy library dropped. Steps 0 to 8 are numbered for a rehearsal to assert; the in-place steps keep every word. The tip already carries the shape: into: is honoured by the pass, verify/2 and the census for a legacy encrypted source, so no lib/ code changes, no record changes and no changelog fragment. The guide says why the shape needs no reverse plan: the pass never writes the old column, which stays current until the drop. A new fixture migration adds the three _encrypted columns to the runbook table, and a new test file runs the plan against it. Refs: ece-cwg6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The migrate-from-cloak guide gains a second exit, "The other exit: a parallel column", beside the in-place walk (which keeps every word; the diff removes no line of the guide). A host adds a
<field>_encryptedbinary column beside each encrypted one, its schema declares both fields (the old on the legacy type, the new on this package's type with nolegacy:), and its changeset writes both. A plan reads each old column through its legacy type and writesinto:the new one (from:the legacy type,to:this package's type,into:the new column,scope_from,source_authenticated:). Reads stay on the old column through the backfill and the verification, one deploy cuts reads over as a step of its own, and only then do the old columns and the legacy library go. The steps are numbered 0 to 8 so a rehearsal can assert each one.The guide also says:
column:, because the declared context column is derived from the field name.No code change
The shape runs on the package as it is:
Encryptor.Ecto.Migrator.pass!/5takes the target column frominto:,verify/2goes through the same pass, andEncryptor.Ecto.Migrator.Census'srewrite_queries/2reads theinto:column. So there is no change underlib/, no Note on ADR-0002, no changelog fragment (documentation and test fixtures are excluded), and the plan field options are unchanged. Ruled by the operator, 2026-09-29: a recipe, with code only where the tip showed a gap; none was shown.Tests
test/encryptor/ecto/runbook_parallel_test.exsruns the parallel plan against the runbook's integrations table, which a new fixture migration (Encryptor.Ecto.TestMigrationRunbookParallel, added toTestRepo's migration list; no existing migration edited) gives three_encryptedcolumns. The tests show: the dual write writing both formats; the pass leaving every old column byte for byte and writing the new one in this package's format, a NULL source leaving its pair NULL; a dual-written row countedalready_targetand not rewritten;verify/2red before the pass and{:ok, _}after it over the new columns; the census reading the new column; the new columns readable under the old field names with thecolumn:pin, the old columns still readable through the legacy schema, and the cut-over schema reading every row after the old columns are dropped. Each test carries its sabotage note.Provenance
ParallelIntegration,CutOverIntegration,ParallelMigration) are added toEncryptor.Ecto.TestRunbookbeside the in-place ones; the in-place walk inrunbook_test.exsis untouched.Review
Own in-turn review (no
lib/change, so no cold pass): I re-read the diff against the bead's description, acceptance and notes, and checked each guide claim against the code by anchor:pass!/5setstarget_columnfrominto:and builds the target's params for it;Keyset.swap_query/5compares only the target column (unchanged/3); a NULL source row counts:null(Pass.row/4);Census.rewrite_queries/2reads theinto:column and itsintegrity/2emitssource_non_null,target_non_nullandtarget_empty;Encryptor.Ecto.Binary'sderive_column/1derives the context column from the field name, and a field-levelcolumn:pin wins over it. The in-place steps keep every word (zero removed lines in the guide).Gate
mix qualityon the rebased head: Format, Compile (warnings as errors), Doc links, Dependencies, Credo, Docs, Dialyzer and Tests (875 of 875 passed, 95.3% coverage) all passed; Doctor, Gettext and Sobelow skipped as not installed.Refs: ece-cwg6