Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
44 changes: 22 additions & 22 deletions .github/actions/build-ffi-binding/action.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Build the protect-ffi binding
description: >-
Compile `packages/protect-ffi` into the artifacts its JS consumers load at
Compile `languages/typescript/packages/protect-ffi` into the artifacts its JS consumers load at
runtime — `lib/` (tsc), `index.node` (cargo), and optionally `dist/wasm/**`
(wasm-pack) — then prove they load.

Expand Down Expand Up @@ -47,7 +47,7 @@ runs:
id: cache-native
uses: actions/cache@v4
with:
path: packages/protect-ffi/index.node
path: languages/typescript/packages/protect-ffi/index.node
# package.json and mise.toml are in the key because they are build
# INPUTS, not just metadata: `build:native` is `cargo-build` plus a
# `postcargo-build` hook (`neon dist < cargo.log`), both defined in
Expand All @@ -56,7 +56,7 @@ runs:
# the build step below and the job proceeds on a stale index.node.
#
# The last two are NOT in this package. `crates/protect-ffi/Cargo.toml`
# carries `eql-bindings = { path = "../../../eql/crates/eql-bindings" }`
# carries `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`
# — an in-tree path dependency that compiles into `index.node` and into
# the wasm build below. A path dep has no registry checksum, so a
# source-only edit there moves NOTHING this key would otherwise hash:
Expand All @@ -82,11 +82,11 @@ runs:
# that way) would make it a compile input with no other trace.
key: >-
ffi-native-${{ runner.os }}-${{ runner.arch }}-${{
hashFiles('packages/protect-ffi/crates/**',
'packages/protect-ffi/Cargo.toml',
'packages/protect-ffi/Cargo.lock',
'packages/protect-ffi/package.json',
'packages/protect-ffi/mise.toml',
hashFiles('languages/typescript/packages/protect-ffi/crates/**',
'languages/typescript/packages/protect-ffi/Cargo.toml',
'languages/typescript/packages/protect-ffi/Cargo.lock',
'languages/typescript/packages/protect-ffi/package.json',
'languages/typescript/packages/protect-ffi/mise.toml',
'packages/eql/crates/**',
'packages/eql/Cargo.toml') }}

Expand All @@ -109,7 +109,7 @@ runs:

# Unlike index.node, this path is NOT purely generated. `dist/wasm` holds
# wasm-pack's output alongside three declaration files that are tracked in
# git — see packages/protect-ffi/.gitignore for why they have to be. A
# git — see languages/typescript/packages/protect-ffi/.gitignore for why they have to be. A
# restore untars over the checkout, so with a key hashed from the Rust
# inputs alone, an entry saved before a `.d.ts` edit silently reverts that
# edit: no diff, no log line, and the next `tsc` against wasm-inline
Expand Down Expand Up @@ -139,7 +139,7 @@ runs:
id: cache-wasm
uses: actions/cache@v4
with:
path: packages/protect-ffi/dist/wasm
path: languages/typescript/packages/protect-ffi/dist/wasm
# The last five are the same build-input argument as on the native key,
# and `build:wasm` is the longer pipeline of the two: wasm-pack, then
# `tsc -p tsconfig.wasm-errors.json`, then a `postbuild:wasm` hook
Expand Down Expand Up @@ -173,19 +173,19 @@ runs:
# same missing input.
key: >-
ffi-wasm-${{ runner.os }}-${{
hashFiles('packages/protect-ffi/crates/**',
'packages/protect-ffi/Cargo.toml',
'packages/protect-ffi/Cargo.lock',
hashFiles('languages/typescript/packages/protect-ffi/crates/**',
'languages/typescript/packages/protect-ffi/Cargo.toml',
'languages/typescript/packages/protect-ffi/Cargo.lock',
'packages/eql/crates/**',
'packages/eql/Cargo.toml',
'packages/protect-ffi/dist/wasm/*.d.ts',
'packages/protect-ffi/src/errors.ts',
'packages/protect-ffi/package.json',
'packages/protect-ffi/mise.toml',
'packages/protect-ffi/tsconfig.wasm-errors.json',
'packages/protect-ffi/scripts/inline-wasm.mjs') }}
'languages/typescript/packages/protect-ffi/dist/wasm/*.d.ts',
'languages/typescript/packages/protect-ffi/src/errors.ts',
'languages/typescript/packages/protect-ffi/package.json',
'languages/typescript/packages/protect-ffi/mise.toml',
'languages/typescript/packages/protect-ffi/tsconfig.wasm-errors.json',
'languages/typescript/packages/protect-ffi/scripts/inline-wasm.mjs') }}

# mise carries the pinned wasm-pack (see packages/protect-ffi/mise.toml)
# mise carries the pinned wasm-pack (see languages/typescript/packages/protect-ffi/mise.toml)
# and, run from that directory, trusts the nested config — a bare `mise`
# call elsewhere refuses it with "Config files are not trusted", which
# reads as a toolchain problem rather than a trust one.
Expand All @@ -210,7 +210,7 @@ runs:
with:
install: true
install_args: aqua:wasm-bindgen/wasm-pack
working_directory: packages/protect-ffi
working_directory: languages/typescript/packages/protect-ffi

# `--all-targets` in the Rust lint means all target KINDS, not platforms;
# wasm32 has to be installed explicitly before anything can build for it.
Expand All @@ -230,7 +230,7 @@ runs:
# deep in a credentialed suite. Fail here instead, naming the artifact.
- name: Verify the binding loads
shell: bash
working-directory: packages/protect-ffi
working-directory: languages/typescript/packages/protect-ffi
env:
WANT_WASM: ${{ inputs.wasm }}
run: |
Expand Down
6 changes: 3 additions & 3 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ updates:
update-types:
- version-update:semver-major

# ── Cargo (packages/protect-ffi — one of two Rust workspaces) ───
# ── Cargo (languages/typescript/packages/protect-ffi — one of two Rust workspaces) ───
# Absorbing protect-ffi brought a 494-crate Cargo.lock in-tree. osv-scanner
# already sees it — `--recursive ./` walks the tree and extracts every
# lockfile it recognises — so known advisories were visible from day one, but
Expand All @@ -76,7 +76,7 @@ updates:
# A misaimed directory fails silently: Dependabot records "no manifest
# found" on a log page nobody visits, and the symptom is simply that no PR
# ever arrives. The e2e test asserts this path holds a Cargo.toml.
directory: /packages/protect-ffi
directory: /languages/typescript/packages/protect-ffi
# Monthly, where npm and actions are weekly. The deviation is about
# validation cost, not risk appetite: a Cargo.lock bump is checked by
# tests-rust.yml — one Blacksmith job, 45-minute timeout, cargo test +
Expand Down Expand Up @@ -190,7 +190,7 @@ updates:
- patch
ignore:
# `cipherstash-client = "=0.42.0"` in tests/sqlx/Cargo.toml — the SAME
# exact pin, at the SAME version, as packages/protect-ffi. That is not a
# exact pin, at the SAME version, as languages/typescript/packages/protect-ffi. That is not a
# coincidence and it is the reason the subtree was imported: the two now
# share one release train, and a Dependabot PR that moved one workspace
# and not the other would reintroduce precisely the skew the absorption
Expand Down
22 changes: 11 additions & 11 deletions .github/workflows/_build-ffi-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@ jobs:
- name: Install node-gyp
run: npm install -g node-gyp

# zig + cargo-zigbuild, pinned in packages/protect-ffi/mise.toml. Only the
# zig + cargo-zigbuild, pinned in languages/typescript/packages/protect-ffi/mise.toml. Only the
# gnu platforms use them, so the four others skip this rather than
# compiling cargo-zigbuild from source on runners that never call it.
#
Expand All @@ -175,14 +175,14 @@ jobs:
with:
install: true
install_args: zig cargo:cargo-zigbuild
working_directory: packages/protect-ffi
working_directory: languages/typescript/packages/protect-ffi
cache: false

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Build binding
working-directory: packages/protect-ffi
working-directory: languages/typescript/packages/protect-ffi
env:
CARGO_BUILD_TARGET: ${{ matrix.cfg.target }}
NEON_BUILD_PLATFORM: ${{ matrix.cfg.platform }}
Expand Down Expand Up @@ -247,7 +247,7 @@ jobs:
fi

- name: Place the binding in its platform package
working-directory: packages/protect-ffi
working-directory: languages/typescript/packages/protect-ffi
env:
PLATFORM: ${{ matrix.cfg.platform }}
BUILD_LOG: ${{ matrix.cfg.log }}
Expand Down Expand Up @@ -280,8 +280,8 @@ jobs:
run: |
set -euo pipefail
mkdir -p ffi-dist
pnpm --dir "packages/protect-ffi/platforms/${PLATFORM}" pack
mv "packages/protect-ffi/platforms/${PLATFORM}"/*.tgz ffi-dist/
pnpm --dir "languages/typescript/packages/protect-ffi/platforms/${PLATFORM}" pack
mv "languages/typescript/packages/protect-ffi/platforms/${PLATFORM}"/*.tgz ffi-dist/
ls ffi-dist

- name: Verify the tarball is the platform package, not the wrapper
Expand Down Expand Up @@ -348,7 +348,7 @@ jobs:
- name: Install node-gyp
run: npm install -g node-gyp

# wasm-pack, pinned in packages/protect-ffi/mise.toml — `build:wasm`
# wasm-pack, pinned in languages/typescript/packages/protect-ffi/mise.toml — `build:wasm`
# shells out to it and nothing else supplies it. `install_args` narrows
# this to wasm-pack alone: a bare `mise install` would also build
# cargo-zigbuild from source, which this job never calls. The argument is
Expand All @@ -359,7 +359,7 @@ jobs:
with:
install: true
install_args: aqua:wasm-bindgen/wasm-pack
working_directory: packages/protect-ffi
working_directory: languages/typescript/packages/protect-ffi
cache: false

# `--all-targets` in the Rust lint means all target KINDS, not platforms;
Expand All @@ -374,15 +374,15 @@ jobs:
# tracked; the runtime .js and .wasm are generated here. Without this the
# published `./wasm` and `./wasm-inline` entries resolve to nothing.
- name: Build WASM
working-directory: packages/protect-ffi
working-directory: languages/typescript/packages/protect-ffi
run: pnpm run build:wasm

- name: Pack the wrapper
run: |
set -euo pipefail
mkdir -p ffi-dist
pnpm --dir packages/protect-ffi pack
mv packages/protect-ffi/*.tgz ffi-dist/
pnpm --dir languages/typescript/packages/protect-ffi pack
mv languages/typescript/packages/protect-ffi/*.tgz ffi-dist/

- name: Verify the wrapper tarball
run: |
Expand Down
20 changes: 10 additions & 10 deletions .github/workflows/fta-v3.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,24 +12,24 @@ on:
branches:
- 'main'
paths:
- 'packages/stack/src/eql/v3/**'
- 'packages/stack-drizzle/**'
- 'packages/stack-supabase/**'
- 'languages/typescript/packages/stack/src/eql/v3/**'
- 'languages/typescript/packages/stack-drizzle/**'
- 'languages/typescript/packages/stack-supabase/**'
# Shared match-index defaults live outside src/eql/v3 but shape every
# emitted v3 match block (load-bearing `k`/`m` ciphertext params), so edits
# here must trigger the v3 gate too.
- 'packages/stack/src/schema/match-defaults.ts'
- 'packages/stack/package.json'
- 'languages/typescript/packages/stack/src/schema/match-defaults.ts'
- 'languages/typescript/packages/stack/package.json'
- '.github/workflows/fta-v3.yml'
pull_request:
branches:
- "**"
paths:
- 'packages/stack/src/eql/v3/**'
- 'packages/stack-drizzle/**'
- 'packages/stack-supabase/**'
- 'packages/stack/src/schema/match-defaults.ts'
- 'packages/stack/package.json'
- 'languages/typescript/packages/stack/src/eql/v3/**'
- 'languages/typescript/packages/stack-drizzle/**'
- 'languages/typescript/packages/stack-supabase/**'
- 'languages/typescript/packages/stack/src/schema/match-defaults.ts'
- 'languages/typescript/packages/stack/package.json'
- '.github/workflows/fta-v3.yml'

permissions:
Expand Down
Loading
Loading