Prepares the 0.7.0 release, pinning encryptor 0.6.0 - #126
Merged
Merged
Conversation
encryptor 0.6.0 is on Hex, and mix.exs moves its exact pin from
== 0.5.0 to == 0.6.0; mix.lock moves the encryptor entry and nothing
else.
In 0.6.0 Encryptor.Provider.GcpKms answers a Decrypt that Cloud KMS
refuses with HTTP 400 or 404 as {:invalid_key_descriptor,
{:kms_refused, status}}, where it answered {:key_unavailable,
selector}; a 403 and an unreachable service keep the old term. The
key store passes a GCP row's answer through unrelabelled, so its own
answer for such a row changes with the pin. No lib/ code changes:
- the two tests that asserted the old term for the fake's 400 (a
destroyed version, a row moved to another scope) assert the new
one, and a sabotage note's quoted term follows;
- the KeyStore moduledoc's GCP passage names both terms;
- the GCP guide's "What your application sees" row, the paragraph
under it, and the permanent-refusal section are rewritten for
0.6.0, and the restore window reads 0.6.0's 30-day default;
- the two-vaults guide's shred step names the pinned 0.6.0;
- a dated foot Note on ADR-0005 reads Amendment A5's refused-Decrypt
row at the new pin, deciding nothing;
- changelog.d/ece-h9qm.md carries two Breaking lines: the exact pin
with its refused unknown vault options, and the changed answer.
Full mix quality green on this tree, database arm included.
Refs: ece-h9qm
A MINOR rather than a patch because the section opens with a bold Breaking heading: the package requires encryptor 0.6.0 exactly, a GCP row's refused Decrypt answers the permanent kms_refused term, and a reverse plan over a legacy-declaring type must declare source_authenticated:. Added carries the key store's optional root vault beside :gcp_kms; Fixed carries shred/3's re-check under P3. @Version moves to 0.7.0. The four fragments on main are promoted into `## [0.7.0] - 2026-09-30` and deleted in this commit, grouped and ordered Breaking, Added, Fixed per changelog.d/README's at-release paragraph. Every bullet carries over verbatim, and the Added bullet gains one sentence: a :gcp_kms that is not a keyword list, in a store with no root vault, is now refused as {:invalid_config, :gcp_kms, :not_a_keyword_list} where it was refused as {:missing_config, [:provider, :root_vault]}. changelog.d/ holds only its README again. The README install snippet and the Cloak exit guide's step 2 snippet move to `{:encryptor_ecto, "~> 0.7.0"}`, the exact-minor form; the CHANGELOG's changelog.d/ link points at v0.7.0. The encryptor pin is already == 0.6.0, moved in the commit before this one. There is no tag and no publish here. Refs: ece-h9qm
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release prep for
encryptor_ecto0.7.0, with the exactencryptorpin moved to 0.6.0, the version now on Hex. Held for the operator's merge; the tag follows the merge, and the publish is the operator's.Version word: 0.7.0
A minor, not a patch, because the promoted section opens with a bold Breaking heading. The fragments that chose it:
ece-h9qm(Breaking: theencryptor0.6.0 pin and the GCP row's refusal term) andece-xmb(Breaking: a reverse plan over a legacy-declaring type must declaresource_authenticated:);ece-woy(Added: the optional root vault beside:gcp_kms) would choose a minor on its own too.ece-3bgis Fixed.Commits
mix.exsmoves{:encryptor, "== 0.5.0"}to{:encryptor, "== 0.6.0"};mix.lockmoves theencryptorentry and nothing else. In 0.6.0,Encryptor.Provider.GcpKmsanswers aDecryptthat Cloud KMS refuses with HTTP 400 or 404 as{:invalid_key_descriptor, {:kms_refused, status}}; a 403, a throttle, a server error and an unreachable service keep{:key_unavailable, selector}. The key store returns a GCP row's answer unrelabelled (the delegating clause ofEncryptor.Ecto.KeyStore'sunwrap_row/4, unchanged here), so its own answer for such a row changes with the pin. Nolib/code changes; what follows the term:{:key_unavailable, selector}for the fake's 400 now assert{:invalid_key_descriptor, {:kms_refused, 400}}: "provision, write, read, destroy the version, delete the row" (key_store_gcp_shred_repo_test.exs) and "a row moved to another scope fails closed, in the provider's own term" (key_store_repo_test.exs), with their comments; one existing sabotage note's quoted term follows;KeyStoremoduledoc's GCP passage names both terms;Decryptrow at the 0.6.0 pin; it decides nothing and removes no line;changelog.d/ece-h9qm.md: two Breaking lines, the exact pin (with 0.6.0's refusal of unknown vault options) and the changed answer. Breaking per the README's pre-1.0 rule, which puts a change to the error vocabulary under a bold Breaking heading.@versionmoves to 0.7.0; the fragments on main plus this PR's are promoted into## [0.7.0] - 2026-09-30(Breaking:ece-h9qm,ece-xmb; Added:ece-woy; Fixed:ece-3bg) and deleted, sochangelog.d/holds only its README. Every bullet carries over verbatim, and the Added bullet gains one sentence, from the cold review of the optional-root-vault change: a:gcp_kmsthat is not a keyword list, in a store with no root vault, is now refused as{:invalid_config, :gcp_kms, :not_a_keyword_list}where it was refused as{:missing_config, [:provider, :root_vault]}(KeyStore'sroot_vault/1passes a non-nil:gcp_kmsthrough, andgcp_kms/2refuses it). The README install snippet and the Cloak exit guide's step 2 snippet move to{:encryptor_ecto, "~> 0.7.0"}; the CHANGELOG'schangelog.d/link points atv0.7.0. No published CHANGELOG section is edited.Provenance
Two threading edits the pin forced, beyond the file list above:
encryptor0.5.0 a read of the shredded agreement already fails when the delete commits"; it now names 0.6.0, where the same holds (0.6.0'sEncryptor.Vaultdocuments a whole-scope shred as immediate because the provider is asked ahead of the cache).No other break from 0.6.0 showed: the full gate is green on the new pin, and no vault this package or its tests start uses an option 0.6.0 refuses.
New members of a closed vocabulary since v0.6.0
{:invalid_key_descriptor, {:no_root_vault, "engine_message"}}, fromKeyStore'sunwrap_row/4(theece-woyfragment).{:invalid_key_descriptor, {:kms_refused, status}}for a GCP row, passed through fromencryptor0.6.0 (theece-h9qmfragment).{:invalid_config, :gcp_kms, :not_a_keyword_list}is not new, but is newly the answer for a store with no root vault (the added sentence above).from:type declareslegacy:and that lackssource_authenticated:(theece-xmbfragment).All four are in the 0.7.0 section.
Checks
Full
mix qualityon the head, quoted whole:The database arm ran (no skip message). The same gate is green at the first commit. Sabotage of the two changed tests: relabelling the GCP clause's failure to
{:invalid_key_descriptor, :unwrap_failed}turned both red on the assertion; resolving the scope's keys throughdecryption_keys/2insideshred/3turned the shred assertion red on the new term, which the edited sabotage note now quotes. Both restored byte-equal.