Skip to content

Prepares the 0.7.0 release, pinning encryptor 0.6.0 - #126

Merged
johnnyt merged 2 commits into
mainfrom
ece-h9qm-release-0-7-0
Sep 30, 2026
Merged

johnnyt merged 2 commits into
mainfrom
ece-h9qm-release-0-7-0

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Release prep for encryptor_ecto 0.7.0, with the exact encryptor pin moved to 0.6.0, the version now on Hex. Held for the operator's merge; the tag follows the merge, and the publish is the operator's.

Version word: 0.7.0

A minor, not a patch, because the promoted section opens with a bold Breaking heading. The fragments that chose it: ece-h9qm (Breaking: the encryptor 0.6.0 pin and the GCP row's refusal term) and ece-xmb (Breaking: a reverse plan over a legacy-declaring type must declare source_authenticated:); ece-woy (Added: the optional root vault beside :gcp_kms) would choose a minor on its own too. ece-3bg is Fixed.

Commits

  1. Pins encryptor 0.6.0 and its GCP refusal term. mix.exs moves {:encryptor, "== 0.5.0"} to {:encryptor, "== 0.6.0"}; mix.lock moves the encryptor entry and nothing else. In 0.6.0, Encryptor.Provider.GcpKms answers a Decrypt that Cloud KMS refuses with HTTP 400 or 404 as {:invalid_key_descriptor, {:kms_refused, status}}; a 403, a throttle, a server error and an unreachable service keep {:key_unavailable, selector}. The key store returns a GCP row's answer unrelabelled (the delegating clause of Encryptor.Ecto.KeyStore's unwrap_row/4, unchanged here), so its own answer for such a row changes with the pin. No lib/ code changes; what follows the term:
    • the two tests that asserted {:key_unavailable, selector} for the fake's 400 now assert {:invalid_key_descriptor, {:kms_refused, 400}}: "provision, write, read, destroy the version, delete the row" (key_store_gcp_shred_repo_test.exs) and "a row moved to another scope fails closed, in the provider's own term" (key_store_repo_test.exs), with their comments; one existing sabotage note's quoted term follows;
    • the KeyStore moduledoc's GCP passage names both terms;
    • the GCP KMS guide: the "What your application sees" middle row, the paragraph under it, and the permanent-refusal section (now "Which refusals are permanent"), rewritten for 0.6.0;
    • ADR-0005: one dated foot Note reading Amendment A5's refused-Decrypt row at the 0.6.0 pin; it decides nothing and removes no line;
    • changelog.d/ece-h9qm.md: two Breaking lines, the exact pin (with 0.6.0's refusal of unknown vault options) and the changed answer. Breaking per the README's pre-1.0 rule, which puts a change to the error vocabulary under a bold Breaking heading.
  2. Prepares the 0.7.0 release. @version moves to 0.7.0; the fragments on main plus this PR's are promoted into ## [0.7.0] - 2026-09-30 (Breaking: ece-h9qm, ece-xmb; Added: ece-woy; Fixed: ece-3bg) and deleted, so changelog.d/ holds only its README. Every bullet carries over verbatim, and the Added bullet gains one sentence, from the cold review of the optional-root-vault change: a :gcp_kms that is not a keyword list, in a store with no root vault, is now refused as {:invalid_config, :gcp_kms, :not_a_keyword_list} where it was refused as {:missing_config, [:provider, :root_vault]} (KeyStore's root_vault/1 passes a non-nil :gcp_kms through, and gcp_kms/2 refuses it). The README install snippet and the Cloak exit guide's step 2 snippet move to {:encryptor_ecto, "~> 0.7.0"}; the CHANGELOG's changelog.d/ link points at v0.7.0. No published CHANGELOG section is edited.

Provenance

Two threading edits the pin forced, beyond the file list above:

  • the GCP KMS guide's restore-window paragraph said the 0.5.0 moduledoc gives the default destruction window as 24 hours; the 0.6.0 moduledoc gives 30 days, as Cloud KMS's reference does, and the paragraph now says so;
  • the two-vaults guide's shred step said "With encryptor 0.5.0 a read of the shredded agreement already fails when the delete commits"; it now names 0.6.0, where the same holds (0.6.0's Encryptor.Vault documents a whole-scope shred as immediate because the provider is asked ahead of the cache).

No other break from 0.6.0 showed: the full gate is green on the new pin, and no vault this package or its tests start uses an option 0.6.0 refuses.

New members of a closed vocabulary since v0.6.0

  • {:invalid_key_descriptor, {:no_root_vault, "engine_message"}}, from KeyStore's unwrap_row/4 (the ece-woy fragment).
  • {:invalid_key_descriptor, {:kms_refused, status}} for a GCP row, passed through from encryptor 0.6.0 (the ece-h9qm fragment).
  • {:invalid_config, :gcp_kms, :not_a_keyword_list} is not new, but is newly the answer for a store with no root vault (the added sentence above).
  • One new compile refusal, not a term: a plan field whose from: type declares legacy: and that lacks source_authenticated: (the ece-xmb fragment).

All four are in the 0.7.0 section.

Checks

Full mix quality on the head, quoted whole:

Running quality checks...

✓ Format: No changes needed (310ms)
✓ Compile: dev + test compiled (warnings as errors) (401ms)

Running analysis stages in parallel...

○ Doctor: skipped (:doctor not installed)
○ Gettext: skipped (:gettext not installed)
○ Sobelow: skipped (:sobelow not installed)
✓ Doc links: 12 links checked (15ms)
✓ Dependencies: No unused dependencies (492ms)
✓ Credo: No issues (1.3s)
✓ Docs: No warnings (1.4s)
✓ Dialyzer: No warnings (2.0s)
✓ Tests: 891 of 891 passed, 95.3% coverage (3.5s)

✓ All quality checks passed!

The database arm ran (no skip message). The same gate is green at the first commit. Sabotage of the two changed tests: relabelling the GCP clause's failure to {:invalid_key_descriptor, :unwrap_failed} turned both red on the assertion; resolving the scope's keys through decryption_keys/2 inside shred/3 turned the shred assertion red on the new term, which the edited sabotage note now quotes. Both restored byte-equal.

encryptor 0.6.0 is on Hex, and mix.exs moves its exact pin from
== 0.5.0 to == 0.6.0; mix.lock moves the encryptor entry and nothing
else.

In 0.6.0 Encryptor.Provider.GcpKms answers a Decrypt that Cloud KMS
refuses with HTTP 400 or 404 as {:invalid_key_descriptor,
{:kms_refused, status}}, where it answered {:key_unavailable,
selector}; a 403 and an unreachable service keep the old term. The
key store passes a GCP row's answer through unrelabelled, so its own
answer for such a row changes with the pin. No lib/ code changes:

- the two tests that asserted the old term for the fake's 400 (a
  destroyed version, a row moved to another scope) assert the new
  one, and a sabotage note's quoted term follows;
- the KeyStore moduledoc's GCP passage names both terms;
- the GCP guide's "What your application sees" row, the paragraph
  under it, and the permanent-refusal section are rewritten for
  0.6.0, and the restore window reads 0.6.0's 30-day default;
- the two-vaults guide's shred step names the pinned 0.6.0;
- a dated foot Note on ADR-0005 reads Amendment A5's refused-Decrypt
  row at the new pin, deciding nothing;
- changelog.d/ece-h9qm.md carries two Breaking lines: the exact pin
  with its refused unknown vault options, and the changed answer.

Full mix quality green on this tree, database arm included.

Refs: ece-h9qm
A MINOR rather than a patch because the section opens with a bold
Breaking heading: the package requires encryptor 0.6.0 exactly, a GCP
row's refused Decrypt answers the permanent kms_refused term, and a
reverse plan over a legacy-declaring type must declare
source_authenticated:. Added carries the key store's optional root
vault beside :gcp_kms; Fixed carries shred/3's re-check under P3.

@Version moves to 0.7.0. The four fragments on main are promoted into
`## [0.7.0] - 2026-09-30` and deleted in this commit, grouped and
ordered Breaking, Added, Fixed per changelog.d/README's at-release
paragraph. Every bullet carries over verbatim, and the Added bullet
gains one sentence: a :gcp_kms that is not a keyword list, in a store
with no root vault, is now refused as {:invalid_config, :gcp_kms,
:not_a_keyword_list} where it was refused as {:missing_config,
[:provider, :root_vault]}. changelog.d/ holds only its README again.

The README install snippet and the Cloak exit guide's step 2 snippet
move to `{:encryptor_ecto, "~> 0.7.0"}`, the exact-minor form; the
CHANGELOG's changelog.d/ link points at v0.7.0. The encryptor pin is
already == 0.6.0, moved in the commit before this one.

There is no tag and no publish here.

Refs: ece-h9qm
@johnnyt
johnnyt merged commit 1fcb204 into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the ece-h9qm-release-0-7-0 branch September 30, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant