Skip to content

Build the missing EQL 3.0.6 GitHub release and image, and fix the release.yml race #1035

Description

@auxesis

EQL 3.0.6 reached npm and crates.io from stack on 2 October 2026, but its GitHub release and Docker image were never built. This issue builds them, and fixes the two faults in release.yml that skipped them. Do it after the cutover of the stack crates import, so that stack main does not move on freeze day.

The release published every package, but skipped the EQL assets

Version Packages PR #938 merged at 07:27 UTC on 2 October 2026. Its Release JS run, 36978691809, published 15 npm packages, all with provenance that names cipherstash/stack and release.yml. Release eql-bindings published eql-bindings 3.0.6 to crates.io.

Three jobs in the Release JS run were skipped:

  • Build and attach the EQL SQL release, which creates the eql-3.0.6 tag and GitHub release with the SQL assets;
  • Build and attach the EQL docs bundle;
  • Dispatch the Postgres + EQL image build, which builds ghcr.io/cipherstash/postgres-eql for 3.0.6.

So there is no eql-3.0.6 tag, no GitHub release with the SQL and docs, and no 3.0.6 image. stash eql install is not affected, because it reads the SQL from the @cipherstash/eql npm package.

Two faults caused it

  1. changeset publish races the FFI publish. The publish-ffi job published all seven @cipherstash/protect-ffi packages at 0.33.0. npm answered that each one "may take a few minutes to become available". About a minute later, the release job's changeset publish could not yet see the wrapper or the musl package, so it tried to publish them again. npm refused both with E402 Payment Required, because changeset publish uses restricted access for them. Nothing was published twice, but the release job failed.

    The publish-auth job has the same shape. Since ci: arm publishing for @cipherstash/auth and the stack-* crates #1009 merged on 2 October 2026, it publishes the seven @cipherstash/auth packages with npm publish. The release job, which needs it, then runs changeset publish over the same packages. So an auth release can fail in the same way.

  2. The EQL jobs depend on the release job succeeding. They run only when the release job's eql_published output is true. A step after changeset publish sets that output from publishedPackages. When changeset publish fails, that step never runs. A re-run cannot fix it either: a re-run finds nothing left to publish, so eql_published stays false.

Fix both in release.yml

  • Wait for the FFI and auth packages before changeset publish. Poll npm until every version in the published.txt of publish-ffi and of publish-auth is visible, with a timeout. Then changeset publish skips them as already published.
  • Work out eql_published from the registry and the tags, not from this run. Treat EQL as needing its assets when @cipherstash/eql at the tree's version is on npm, but the eql-<version> tag does not exist. Compute it in a step that runs even when changeset publish fails.

With the second change, the next push to main after the fix builds the missing 3.0.6 release and image by itself.

Done when

  • The fix merges to main, with tests that cover a failed changeset publish, an already-published EQL version, and the wait for both the FFI and the auth packages.
  • The eql-3.0.6 tag and GitHub release exist, with the SQL and docs assets.
  • ghcr.io/cipherstash/postgres-eql has its 3.0.6 tags.
  • A check of the eql-3.0.6 release against the EQL plan's "verify at one version V" item passes: the npm tarball, the crate, the SQL and docs assets and the image tags all name 3.0.6.

Fixed by #1026

#1026 merged on 3 October 2026. It fixed both faults, and a third that it found:

  • The release job now waits for npm to list every package that publish-ffi and publish-auth published, before changeset publish runs.
  • A new eql-assets job decides from npm and the git tags whether EQL needs its assets. It runs even when changeset publish fails.
  • The EQL asset jobs had a hidden success() condition, which skipped them whenever any job up their needs: chain was skipped. They now use !cancelled() and check results explicitly.

The release run on #1026's merge built the missing assets at 23e9af3f, the commit that published 3.0.6:

  • the eql-3.0.6 tag and GitHub release, with cipherstash-encrypt.sql, cipherstash-encrypt-uninstall.sql and both docs bundles;
  • ghcr.io/cipherstash/postgres-eql with tags 14-3.0.6, 15-3.0.6, 16-3.0.6 and 17-3.0.6, plus 17, 3.0.6 and latest.

On 2 October 2026, the auth packages hit the same race: in the release of @cipherstash/auth 0.44.1, changeset publish got E402 on three of them. No package was lost.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    SDKbugSomething isn't workinggithub-actionsPull request modifies GitHub Actions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions