Version Packages - #938
Version Packages#938
Conversation
77d81a8 to
e796adc
Compare
e796adc to
935828a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Requesting changes — not because the generated diff is wrong (mechanically it's correct, see below), but because merging it in the repo's current state produces a fully blocked release, and one required pre-merge step for the FFI half hasn't happened. This review is the checklist for whoever drives the release.
Why merge-now fails
-
@cipherstash/eqlis bumped to 3.0.6, but it is still a frozen publisher.scripts/release-gate.mjson live main still carries the@cipherstash/eqlentry inFROZEN_PUBLISHERS, npm has only up to 3.0.5, and the gate exits non-zero when a frozen package's committed version is missing from the registry. Merging this PR therefore fails thegatejob and skipsreleaseentirely — nothing ships, including@cipherstash/protect-ffi0.32.1 and@cipherstash/stack-prisma1.2.0. Note that no CI ran onchangeset-release/mainat all ("no checks reported"), so nothing surfaced this on the PR; the failure would arrive post-merge.Two ways out, both preceding the merge:
- Do the Phase-5 cutover first: delete the
@cipherstash/eqlentries fromFROZEN_PUBLISHERSandFROZEN_ARTEFACT_DIGESTS(they must go together —release-gate.test.mjspins that), update the three documentsfrozen-publisher-docs.test.mjsholds (AGENTS.md, SECURITY.md's publishing note, the gate map itself), and confirm the two cutover prerequisites AGENTS.md says no workflow can assert: theGPG_PRIVATE_KEYsecret for release-plz, and write access toghcr.io/cipherstash/postgres-eql. That arms the whole five-artefact EQL pipeline, which is presumably the intent given.changeset/eql-repoint-manifests-to-stack.mdis in this release. - Or defer the EQL release: pull the EQL changesets from main and let the bot regenerate this PR without the 3.0.6 bump.
- Do the Phase-5 cutover first: delete the
-
Seven FFI packages move to 0.32.1, and
ffi-preflight.ymlhas not been dispatched against this branch. AGENTS.md requires the preflight dry run against the Version Packages branch before merging a release that moves an FFI version (there is no--dry-runonchangeset publish; the preflight is the only rehearsal). The last preflight runs are from 19 Aug on other branches — and the most recent one on main failed. Dispatch it againstchangeset-release/mainand get it green before merging.
What I verified is right in the diff
- The EQL lockstep held: crate
eql-bindings→ 3.0.6,COMMENT ON SCHEMA eql_v3 IS '3.0.6'stamped in both copies of the install bundle, bothrelease-manifest.jsonfiles, andsrc/generated/release-manifest.tsall move together —sync-lockstep-versions.mjsran as designed, and theeql-sql-asset-freshnessinvariants hold in this tree. - All seven protect-ffi packages move in lockstep to 0.32.1; the platform packages match the wrapper.
- No parked
.md.deferredchangesets are being consumed; the changesets folded in match what was pending on main.
Once the frozen-publisher question is resolved one way or the other and a green ffi-preflight exists for this branch, I'm happy to re-review — the generated content itself is sound.
f54b74a to
543943a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-reviewed after the bot regenerated the branch (543943a, now folding in the changesets from #948/#951-family merges). Both blockers from my previous review are unchanged and still stand: (1) @cipherstash/eql is still bumped to 3.0.6 while live main's FROZEN_PUBLISHERS still freezes it and npm stops at 3.0.5 — merging fails the release gate and ships nothing; do the Phase-5 cutover first or defer the EQL changesets. (2) Seven FFI packages still move with no ffi-preflight.yml run against this branch (latest preflight runs are 19 Aug, and the last one on main failed). The generated lockstep content itself remains mechanically correct. Full checklist in my previous review.
8cddd8a to
8741d7a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Refreshing the block over the latest regeneration (8741d7a): both conditions are still unchanged — @cipherstash/eql is still in FROZEN_PUBLISHERS on live main while this PR bumps it to 3.0.6 (npm still stops at 3.0.5, so merge fails the release gate and nothing ships), and ffi-preflight.yml has still never run against this branch while seven FFI packages move. Checklist in my first review on this PR stands verbatim.
748a145 to
b4d25b9
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Covering the latest regeneration: conditions unchanged — @cipherstash/eql still frozen in FROZEN_PUBLISHERS on live main while this PR bumps it to 3.0.6 (npm latest is still 3.0.5), and ffi-preflight.yml has still never run against this branch. My original checklist on this PR stands.
b4d25b9 to
03f2df2
Compare
5de45d7 to
50c053a
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-review of the latest regeneration (50c053a, base 6a92634 = current main). The two blockers from my first review on this PR are still open.
-
EQL is still frozen. On current main,
scripts/release-gate.mjsstill has@cipherstash/eqlinFROZEN_PUBLISHERS(and inFROZEN_ARTEFACT_DIGESTS). This PR bumps EQL to 3.0.6. The gate fails for a frozen package whose committed version is not on npm. If you merge now, thegatejob fails andreleasedoes not run. Then nothing ships, including@cipherstash/protect-ffi0.33.0. Do the Phase-5 cutover first, or remove the EQL changesets from main. (I did not query npm again in this pass. The last check showed 3.0.5 as the newest version. The 3.0.6 changelog entry says trusted publishing is already repointed. That does not change the gate, because the gate reads the map, not npm's trust configuration.) -
No
ffi-preflight.ymlrun on this branch. Seven FFI packages now move to 0.33.0. The most recent preflight runs are from 19 Aug, onmain, and the last one failed. Dispatch the preflight againstchangeset-release/mainand make sure that it passes before you merge.
New in this regeneration (not blocking, but it makes item 2 more important): the version hook's cargo update --package eql-bindings changed the lock more than necessary. packages/protect-ffi/Cargo.lock now resolves windows-sys to older versions for four Windows-only transitive edges: errno and rustls-platform-verifier 0.61.2 → 0.52.0, socket2 0.61.2 → 0.60.2, and winapi-util 0.61.2 → 0.48.0. Each crate's declared range allows this, so it is probably harmless. But it is a real change to what win32-x64-msvc compiles, and no changeset describes it. It also contradicts the refreshCargoLock docstring in scripts/sync-lockstep-versions.mjs, which says that the re-resolution was "byte-identical … windows-sys edges included". The mise rust = latest toolchain is the likely cause. The preflight is the only rehearsal that builds the Windows binary from this lock, so please run it before you merge.
The rest of the generated content is still mechanically correct. The EQL lockstep holds: the crate, both release manifests, the generated TS manifest, and both install-bundle copies all show 3.0.6. All seven FFI packages move together.
973e7b8 to
c5f1be5
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-review of the latest regeneration (c5f1be5, base e239a73 = current main). Since 50c053a, the only release-specific change is one new stash changelog entry (24f7b2c, the stash-postgres signed-range recipe). That entry is correct. The two blockers from my first review on this PR are still open.
-
EQL is still frozen. On current main,
scripts/release-gate.mjsstill has@cipherstash/eqlinFROZEN_PUBLISHERSandFROZEN_ARTEFACT_DIGESTS. This PR bumps EQL to 3.0.6. I checked npm again today:latestis still 3.0.5. If you merge now, thegatejob fails andreleasedoes not run, so nothing ships (including@cipherstash/protect-ffi0.33.0). Do the Phase-5 cutover first, or remove the EQL changesets from main. -
No
ffi-preflight.ymlrun on this branch. Seven FFI packages move to 0.33.0. The most recent preflight run is still from 19 Aug, onmain, and it failed. Dispatch the preflight againstchangeset-release/mainand make sure that it passes before you merge.
The windows-sys re-resolution in packages/protect-ffi/Cargo.lock that I reported last time is still in this diff (errno and rustls-platform-verifier → 0.52.0, socket2 → 0.60.2, winapi-util → 0.48.0). It is not a blocker by itself, but only the preflight builds the Windows binary from this lock.
The rest of the generated content is still mechanically correct. The EQL lockstep holds at 3.0.6, and all seven FFI packages move together.
c5f1be5 to
77560f9
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-review of the latest regeneration (77560f9, base 6970d22 = current main). One of the two blockers from my first review is now closed. One is still open.
Closed: the FFI preflight. ffi-preflight.yml run 36922288394 (dispatched 2026-10-01 with ref: changeset-release/main) passed. Its checkout resolved to 77560f94, which is this head commit, and it packed @cipherstash/protect-ffi@0.33.0. All six platform builds, the WASM + wrapper tarball job, and the install smoke test are green. The win32-x64-msvc build used this branch's packages/protect-ffi/Cargo.lock, so the windows-sys re-resolution that I reported before (errno and rustls-platform-verifier → 0.52.0, socket2 → 0.60.2, winapi-util → 0.48.0) now compiles in a real rehearsal. I do not consider it a risk for this release any more.
Still open: EQL is still frozen. On current main (6970d220), scripts/release-gate.mjs still has @cipherstash/eql in FROZEN_PUBLISHERS and FROZEN_ARTEFACT_DIGESTS. This PR bumps EQL to 3.0.6. The gate fails for a frozen package whose committed version is not on npm. If you merge now, the gate job fails and release does not run, so nothing ships, including @cipherstash/protect-ffi 0.33.0. Do the Phase-5 cutover first, or remove the EQL changesets from main. (I did not query npm again in this pass. My check on 2026-10-01 showed 3.0.5 as latest. The upstream repository is archived, so nothing can publish 3.0.6 from there.)
New in this regeneration (not blocking): #998 ("let the lockstep bump leave an unchanged version alone") is now in the base. The EQL lockstep still holds at 3.0.6: the crate, both Cargo.lock entries, both release manifests, the generated TS manifest, and both install-bundle copies agree. The @cipherstash/eql CHANGELOG also has formatting changes in the existing hand-entered 3.0.5 entry (*every* → _every_, plus one blank line). These come from the changelog formatter. They are cosmetic and do not change the text.
The rest of the generated content is still mechanically correct. When the frozen-publisher item is resolved, I will approve.
77560f9 to
ebca637
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-review of the latest regeneration (ebca637, base fd5d865 = main after #974). The one blocker from my previous review is still open.
Still open: EQL is still frozen. On fd5d865d, scripts/release-gate.mjs still has @cipherstash/eql in FROZEN_PUBLISHERS and FROZEN_ARTEFACT_DIGESTS. This PR bumps EQL to 3.0.6. The gate fails for a frozen package whose committed version is not on npm. If you merge now, the gate job fails and release does not run, so nothing ships, including @cipherstash/protect-ffi 0.33.0. Do the Phase-5 cutover first, or remove the EQL changesets from main. (I did not query npm again in this pass. My check on 2026-10-01 showed 3.0.5 as latest.)
What changed since 77560f9: only the 3311039 changeset from #974 (.changeset/claude-review-oidc-guidance.md, stash and @cipherstash/wizard patch). The bot added it correctly to the stash and @cipherstash/wizard CHANGELOGs and to the @cipherstash/e2e dependency list. The versions do not move, because both packages already had a minor bump to 1.2.0. Nothing under packages/protect-ffi or packages/eql changed, so the green ffi-preflight.yml run 36922288394 on 77560f9 still covers the FFI content of this head.
The rest of the generated content is still mechanically correct. When the frozen-publisher item is resolved, I will approve.
ebca637 to
7d49eeb
Compare
freshtonic
left a comment
There was a problem hiding this comment.
Re-review of the latest regeneration (7d49eeb, base 823f42d = main after #999). The last blocker is closed. I approve.
Closed: EQL is no longer frozen. #999 (876038ef, the Phase-5 cutover) made FROZEN_PUBLISHERS and FROZEN_ARTEFACT_DIGESTS in scripts/release-gate.mjs empty. Thus the gate does not stop on @cipherstash/eql@3.0.6 when it is not on npm, and scripts/eql-pipeline-armed.mjs now arms the EQL publish jobs. The two prerequisites that a workflow cannot assert are recorded as done in the plan: GPG_PRIVATE_KEY is in the repository secrets (I checked the list), and the plan records Write access for cipherstash/stack on ghcr.io/cipherstash/postgres-eql.
No change to the release content since ebca637. git diff ebca6377 7d49eebc shows the same nine files as the base update from #999, and none of them is a generated release file. Nothing under packages/protect-ffi changed, so the green ffi-preflight.yml run 36922288394 still applies to the FFI content of this head. The EQL lockstep still holds at 3.0.6, and all seven FFI packages move together to 0.33.0.
After the merge (not blocking): this is the first EQL release from this repository. The plan says that it has no record of the versioned dry run for the repointed trusted publishing. Thus, examine the release run closely, and make sure that all five artefacts are present at 3.0.6: the npm tarball, the eql-bindings crate, the eql-3.0.6 GitHub release with the SQL and docs assets, and the postgres-eql image tags. Also, the "cutover needs two more things" paragraph in AGENTS.md still says that the GHCR package is "still linked to cipherstash/encrypt-query-language". That is not part of this PR, but it is now out of date.
c6eb8be to
1c0ad54
Compare
The Version Packages PR (#938) takes @cipherstash/eql 3.0.5 -> 3.0.6, and its Run Tests jobs fail the lockstep test in test/v3/migration-v3.test.ts: no published migration bakes the 3.0.6 install SQL, 9b6dab78. This lands that migration on main ahead of #938, mirroring ba37039. 3.0.6 differs from 3.0.5 only in its version stamp: `SELECT '3.0.6'` in eql_v3.version(), `COMMENT ON SCHEMA eql_v3 IS '3.0.6'`, and one `--!` doc comment the build template substitutes the same version into. The SQL is #938's (7d49eeb), byte for byte. - New self-edge 20261002T0000_upgrade_eql_v3_3_0_6 carrying cipherstash:upgrade-eql-v3-bundle-3.0.6-v1, modelled on the 3.0.5 edge, with a schema-comment postcheck for the other half of the stamp. migrationHash b16c9fc5, baked SQL 9b6dab78. - The baseline re-emitted by its own migration.ts (the emitter keeps createdAt): it bakes 3.0.6 and gains a fourth carrier op, so a fresh `db init` still collects every head-ref invariant from the one additive genesis edge. migrationHash bad30c9b -> 2fdc7caf, baked SQL accde003 -> 9b6dab78. The 3.0.2, 3.0.4 and 3.0.5 edges keep their frozen digests. - Head ref, constants, control descriptor, and the example's vendored copy. Re-emitting rather than adding a second `from: null` genesis edge was re-argued, as the 3.0.5 record asked, and came out the same way: @cipherstash/stack-prisma had 144 npm downloads in September 2026 (52 in the last week), fewer than the ~253/month at which the 3.0.5 re-emit was judged a small blast radius; and 3.0.6 changes only the version stamp, so a second genesis edge would add a permanent 2.6 MB copy for no change in behaviour. Once adoption is real, the second genesis edge is the right shape. What this rewrites was never published. The npm tarballs show 1.0.0 shipping baseline sha256:fc495f7f, and 1.1.0 and 1.1.1 shipping 1030654387, all baking eql-3.0.4 and carrying only the 3.0.2 and 3.0.4 edges; bad30c9b and the 3.0.5 edge (8c47bd1d) reached main on 21 August, after 1.1.1. npm consumers therefore see one baseline change, 1030654387 -> 2fdc7caf, in 1.2.0. The 3.0.5 changeset said otherwise by omission, and listed only 1.0.0 and 1.1.0; it now says the action is shared with the 3.0.6 entry and taken once. The 3.0.5 edge is kept. So a 1.1.x database upgrading to 1.2.0 walks the 3.0.5 and then the 3.0.6 self-edge and installs the bundle twice - a time cost, not a correctness problem. It stays because the frozen-history guard treats committed edges as published, and a database built from main may already have walked it. The 3.0.6 changeset and the migration header say so. The eqlVersion marker accepts 3.0.5 and 3.0.6 for one cycle, because main sits between this merge and #938's. Narrow it once #938 merges. Tests: the 3.0.6 edge's shape; both edges baking the 3.0.6 stamp, with every version postcheck reading 3.0.6; the stale-vendored paths walking both edges; and a database already at 3.0.5 walking only the 3.0.6 edge. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
The live migration suite only ever applied the installed @cipherstash/eql's SQL, so no carrier op's or upgrade edge's postcheck ever ran against a database. Those postchecks compare against literals interpolated at emit time (`eql_v3.version() = '3.0.6'`), so one that never matches what its own edge installs fails every customer apply while every offline test stays green. Two cases now apply the descriptor's baked SQL the runner's way: execute, then postchecks, one transaction per plan. - db init: the genesis edge alone, on an empty eql_v3, satisfies every one of its postchecks. - migrate: a 1.1.x database walks the 3.0.5 then the 3.0.6 edge. It starts from the 3.0.4 edge's bytes, which are the 1.1.x baseline's (both pin 63104a81). Each edge is asserted NOT pre-satisfied first, because the runner skips an op whose postchecks already hold, so the double install the 3.0.6 changeset warns about is shown to be real. The end state then satisfies the genesis edge's postchecks. Ops are typed by extending the framework's MigrationPlanOperation, as stale-vendored-space.test.ts does, so the descriptor's ops narrow to them without a cast across unrelated types. The byte-identity case stays, and is red by construction between this branch merging and #938 doing so. The baseline then bakes 3.0.6 while the installed package is still 3.0.5. The comment there and DEVELOPING.md say so. Verified against ghcr.io/cipherstash/postgres-eql:17-2.3.1. On this branch 6 of 7 pass; byte-identity fails, and its diff is exactly the two stamp lines. With #938's EQL files applied all 7 pass. Two mutants fail as they should. Dropping the 3.0.6 edge from the walk gives "expected '3.0.5' to be '3.0.6'". A 3.0.5 bundle checked against the genesis postchecks fails the 3.0.4 carrier's version check. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
1c0ad54 to
9f5a6b7
Compare
…kills The skills ship inside the stash tarball and nothing rewrites their version literals, so the release-train test requires the stash-cli skill to pin the stash version being released. Move the stash-cli one-shot install and the two stash-edge @cipherstash/stack imports from 1.1.1 to 1.2.0, as the 1.1.1 Version Packages PR (#928) did for its release. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
npm already has @cipherstash/nextjs 4.2.0 and 4.3.0. Both were published by hand on 10 December 2025, without provenance, as republishes of 4.1.0's source, and neither version was ever recorded in this repository. changeset publish skips a version that npm already has, so 4.2.0 would have shipped none of this release's changes. 4.2.0 also has no dist/, so it cannot be imported. npm resolves ^4.1.x to 4.3.0 today. Release as 4.4.0, the next minor above every published 4.x version. Against 4.3.0, the public API change is additive: an optional authCode on GetCtsTokenResponse. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
The skills ship inside the stash tarball, and nothing rewrites the version pins in them. People moved them by hand in each Version Packages PR: #928 and #938 did, and #1020 did not, because no CI ran on it. main then failed release-train.test.ts until #1029. scripts/sync-skill-pins.mjs now runs from the root `version` script, right after `changeset version`. It rewrites every exact pin of a release-train package in skills/ to the stable version in the tree, so each Version Packages PR carries the pins with the versions they name. The packages are the changesets `fixed` group that holds `stash`, which a test holds equal to the CLI's RELEASE_TRAIN_MANIFESTS. Run on main's stale pins, the script makes exactly the change in #1029. Refs: CIP-4285 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
The skills ship inside the stash tarball, and nothing rewrites the version pins in them. People moved them by hand in each Version Packages PR: #928 and #938 did, and #1020 did not, because no CI ran on it. main then failed release-train.test.ts until #1029. scripts/sync-skill-pins.mjs now runs from the root `version` script, right after `changeset version`. It rewrites every exact pin of a release-train package in skills/ to the stable version in the tree, so each Version Packages PR carries the pins with the versions they name. The packages are the changesets `fixed` group that holds `stash`, which a test holds equal to the CLI's RELEASE_TRAIN_MANIFESTS. Run on main's stale pins, the script makes exactly the change in #1029. Refs: CIP-4285 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
stash@1.2.0
@cipherstash/nextjs@4.2.0
@cipherstash/protect-ffi@0.33.0
@cipherstash/stack@1.2.0
@cipherstash/stack-prisma@1.2.0
@cipherstash/eql@3.0.6
@cipherstash/stack-drizzle@1.2.0
@cipherstash/stack-supabase@1.2.0
@cipherstash/wizard@1.2.0
@cipherstash/protect-ffi-darwin-arm64@0.33.0
@cipherstash/protect-ffi-darwin-x64@0.33.0
@cipherstash/protect-ffi-linux-arm64-gnu@0.33.0
@cipherstash/protect-ffi-linux-x64-gnu@0.33.0
@cipherstash/protect-ffi-linux-x64-musl@0.33.0
@cipherstash/protect-ffi-win32-x64-msvc@0.33.0
@cipherstash/e2e@0.0.6
@cipherstash/basic-example@1.2.17
@cipherstash/prisma-example@0.1.3
@cipherstash/bench@0.0.8
@cipherstash/ffi-integration-tests@1.0.1
@cipherstash/test-kit@0.0.4