Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
823 commits
Select commit Hold shift + click to select a range
8d870b1
fix(stack-encrypt): a row is implemented for `()` alone; a `from` fie…
coderdan Aug 29, 2026
3d7a5b3
fix(stack-encrypt): restore the decrypt-context bound; gate the _with…
coderdan Aug 31, 2026
07db41f
docs(stack-encrypt): the design doc names the derives that shipped
coderdan Sep 1, 2026
57a1f18
fix(stack-encrypt): address review on the context-parameter PR
coderdan Sep 1, 2026
e286459
feat(stack-encrypt-derive): `#[stash(row = User)]` infers each field'…
coderdan Aug 29, 2026
473bd7a
feat(stack-encrypt-derive): a row's context prefix is explicit, and `…
coderdan Aug 31, 2026
882ecec
docs(stack-encrypt): design doc and RFC follow the explicit row context
coderdan Aug 31, 2026
c02729a
docs(stack-encrypt): the bridge snippet uses the supplied-context cho…
coderdan Sep 1, 2026
62d8dfc
test(stack-encrypt): the nested-row retrieve count is exact
coderdan Sep 1, 2026
6afac7e
Merge pull request cipherstash/cipherstash-suite#2164 from cipherstas…
coderdan Sep 1, 2026
085b7f7
feat(stack-kms)!: build stack-auth, stack-kms and stack-encrypt for W…
coderdan Aug 27, 2026
37d8e47
refactor(stack-auth): replace crate-wide no-http allow(dead_code) wit…
claude Aug 28, 2026
3cab1ea
fix(stack): address review findings on the http feature split
claude Aug 28, 2026
ee92fad
ci(wasi): pin the no-http test/doc shape; drop unneeded http from cts…
claude Aug 28, 2026
8a38d53
fix(stack): address Copilot review on error Display strings
coderdan Aug 31, 2026
29b6d12
fix(stack-encrypt): make the no-http test gate actually HTTP-free; fi…
coderdan Aug 31, 2026
a0f23d8
docs(stack-auth): correct stale StaticTokenStrategy comments in Cargo…
coderdan Aug 31, 2026
c278732
fix(stack-kms): ConnectionInit's Display no longer repeats its source
coderdan Sep 1, 2026
d0c438b
feat(stack-encrypt): freeze the byte formats the crate owns (phase 2)
claude Aug 28, 2026
33419fa
docs(stack-encrypt): table and nesting diagram for the sealed-leaf by…
claude Aug 28, 2026
8950a74
fix(stack-encrypt): address phase-2 review findings on the frozen byt…
coderdan Aug 29, 2026
f4fec2a
fix(stack-encrypt): structured term decode errors and consistent term…
coderdan Aug 29, 2026
975d9fa
fix(stack-encrypt): review follow-ups on the frozen byte formats
coderdan Aug 31, 2026
6a981c2
fix(stack-encrypt): reject oversized key tags on the seal path
coderdan Aug 31, 2026
586d177
docs(stack-encrypt): make the cipher module public so its docs render
coderdan Aug 31, 2026
27ad2cf
Merge pull request cipherstash/cipherstash-suite#2160 from cipherstas…
coderdan Sep 1, 2026
d9f4c9f
feat(stack-encrypt): expose pending-tree batching and the CLLW term t…
claude Aug 28, 2026
67105b0
feat(wasi): stack-encrypt guest module for the Go/wazero binding (pha…
claude Aug 28, 2026
d6503e5
refactor(stack-kms): share ZeroKMS response classification across tra…
coderdan Aug 31, 2026
76a0605
feat(stack-kms): accept hex or base64 client key material
coderdan Aug 31, 2026
946bbd8
feat(stack-encrypt): expose is_degenerate_aad for FFI front-ends
coderdan Aug 31, 2026
166b113
fix(wasi): correct guest error statuses and reclaim host buffers first
coderdan Aug 31, 2026
4461bb3
fix(wasi): accept every documented client-key encoding in guest config
coderdan Aug 31, 2026
aa211b9
fix(wasi): refuse degenerate contexts, size output buffers exactly
coderdan Aug 31, 2026
23cfcb6
Merge pull request cipherstash/cipherstash-suite#2153 from cipherstas…
coderdan Sep 1, 2026
435c5a0
fix(wasi): reject passthrough nodes in record ciphertext slots
coderdan Sep 1, 2026
e3765a5
feat(stack-auth): classify credential rejections where the variants live
coderdan Sep 1, 2026
8970413
fix(wasi): harden the guest's host-boundary parsing
coderdan Sep 1, 2026
7362511
docs(stack-encrypt): state the context contract on the cipher-directe…
coderdan Sep 1, 2026
b79f268
fix(wasi): count zero-length buffers instead of keying them by pointer
coderdan Sep 1, 2026
93990f4
fix(stack-kms): mark the classify response structs non_exhaustive
coderdan Sep 1, 2026
1c71647
ci(wasi): gate the guest crate and assert its import surface
coderdan Sep 2, 2026
7ea876e
fix(wasi): wipe the plaintext operand on the ORE/OPE term paths
coderdan Sep 2, 2026
428d83f
test(stack-kms): fuzz the client-key material decoder
coderdan Sep 2, 2026
f90d677
Merge pull request cipherstash/cipherstash-suite#2162 from cipherstas…
coderdan Sep 2, 2026
f0883b3
feat(stack-encrypt)!: vitaminc 0.2.0, `NonEmpty<T>` contexts, `struct…
coderdan Sep 8, 2026
5f68d3b
chore(zerokms-protocol): version 0.12.30, a patch bump for the descri…
claude Sep 8, 2026
b6b46e2
Merge pull request cipherstash/cipherstash-suite#2194 from cipherstas…
coderdan Sep 8, 2026
c6a3c54
ci: run the full suite on root Cargo.toml/Cargo.lock changes
tobyhede Sep 7, 2026
6c0f8a1
Merge pull request cipherstash/cipherstash-suite#2177 from cipherstas…
tobyhede Sep 9, 2026
a7e960b
feat(cts)!: move CTS to vitaminc 0.3.0 and drop the git pins
coderdan Sep 7, 2026
e68a08a
Merge pull request cipherstash/cipherstash-suite#2183 from cipherstas…
coderdan Sep 10, 2026
93c43b6
feat(wasi): plan and term contexts are structured, so a plan can spel…
coderdan Sep 10, 2026
95708af
refactor(wasi): borrow plan contexts per use; say which Rust context …
coderdan Sep 11, 2026
e2e3bff
docs(wasi): name every scalar a probe context may be; carry the secur…
coderdan Sep 11, 2026
427fe41
docs(wasi): make the guest's rustdoc build clean on both targets, and…
coderdan Sep 11, 2026
f8c84d4
docs(wasi): state the codec's nesting bound where the context grammar…
coderdan Sep 11, 2026
3e4f64e
Merge pull request cipherstash/cipherstash-suite#2210 from cipherstas…
coderdan Sep 12, 2026
e8a42ce
build(deps)!: vitaminc 0.4.0; the guest's plan context is `AadPiece` …
coderdan Sep 12, 2026
c9e7d21
feat(stack-encrypt)!: multi-keyset `StackCipher`, `KeysetCipher` for …
coderdan Sep 12, 2026
ceca2f0
fix(stack-encrypt): a keyset name is a lookup with a window, and no a…
coderdan Sep 12, 2026
3c30a60
fix(stack-encrypt): a name binding follows the later lookup, is stric…
coderdan Sep 12, 2026
bbcc1b2
fix(stack-encrypt): an answer older than the one a keyset holds is dr…
coderdan Sep 12, 2026
e743eb5
fix(stack-encrypt)!: seal `CipherScope`
coderdan Sep 12, 2026
9ee94d8
fix(stack-encrypt): eviction leaves a watermark, so an older answer c…
coderdan Sep 12, 2026
0f4bbfd
fix(stack-encrypt): the watermark eviction leaves is the entry's, not…
coderdan Sep 12, 2026
ac4f958
fix(stack-encrypt)!: two ciphers over one keyset merge; `Error` is no…
coderdan Sep 12, 2026
ef117d3
fix(stack-encrypt): a lookup whose answer lost is answered with the o…
coderdan Sep 12, 2026
b0e2668
docs(stack-encrypt): drop a redundant explicit link target that rustd…
coderdan Sep 12, 2026
23c2e53
fix(stack-encrypt): a losing lookup's answer is decided before its in…
coderdan Sep 13, 2026
53accce
fix(stack-encrypt): a name ZeroKMS says is unbound orders like any an…
coderdan Sep 13, 2026
d293be8
test(stack-encrypt): a name ZeroKMS refuses, end to end — the race, i…
coderdan Sep 13, 2026
f8da8e2
feat(stack-auth): a workspace CRN is reachable without reaching for c…
coderdan Sep 13, 2026
a118060
feat(stack-encrypt)!: the default keyset is the client's, and only th…
coderdan Sep 13, 2026
3438596
docs(stack-encrypt): where credentials come from, and a `&str` that n…
coderdan Sep 13, 2026
fd0b1bc
feat(stack-encrypt)!: a leaf's AAD is derived, never supplied
coderdan Sep 13, 2026
07fb2a2
fix(stack-encrypt-guest)!: the plaintext a host hands over outlives t…
coderdan Sep 14, 2026
8675635
Merge pull request cipherstash/cipherstash-suite#2211 from cipherstas…
coderdan Sep 18, 2026
bec2922
feat(wasi)!: one cipher per instance, keysets selected per call; the …
coderdan Sep 12, 2026
6edfb13
fix(wasi): validate every input before the cipher is consulted; init …
coderdan Sep 12, 2026
61d9f44
fix(stack-encrypt-guest): validate term and record inputs against the…
coderdan Sep 12, 2026
968a663
fix(stack-encrypt-guest): wipe_all allocates nothing; config and plan…
coderdan Sep 12, 2026
aabc8e0
docs(stack-encrypt-guest): shutdown speaks for the cipher calls only,…
coderdan Sep 13, 2026
1b64c77
docs(stack-encrypt-guest): a value open counts its requests like a re…
coderdan Sep 13, 2026
fe17d68
Merge pull request cipherstash/cipherstash-suite#2212 from cipherstas…
coderdan Sep 20, 2026
76a4e70
feat(stack-encrypt): Go module over the WASI guest (CIP-4022)
coderdan Sep 12, 2026
0692efa
feat(stack-encrypt): order ORE and OPE terms in Go
coderdan Sep 12, 2026
52565ab
test(stack-encrypt): property-test Go term ordering against plaintext…
coderdan Sep 12, 2026
38d8b05
fix(stack-encrypt): run the Go guest on the host CSPRNG and clocks
coderdan Sep 12, 2026
961ee65
fix(stack-encrypt): make Go record decoding lossless, nullable-aware …
coderdan Sep 12, 2026
ea3da1e
fix(stack-encrypt): bound and wipe the Go host transport; survive int…
coderdan Sep 12, 2026
25af1b9
fix(stack-encrypt): a partial response is wiped, and an interrupted c…
coderdan Sep 13, 2026
e6f0f14
fix(stack-encrypt): an empty part is refused where it is made, the de…
coderdan Sep 13, 2026
360a1d7
fix(stack-encrypt): wipe the request body when the transport closes i…
claude Sep 13, 2026
f5a772e
feat(stack-encrypt)!: a client does not name its own default keyset
coderdan Sep 14, 2026
e748c5f
feat(stack-encrypt)!: the Go keyset API is the Rust one
coderdan Sep 18, 2026
1cb4643
Merge pull request cipherstash/cipherstash-suite#2214 from cipherstas…
coderdan Sep 20, 2026
7db88f6
docs: record declarative encryption targets
coderdan Sep 12, 2026
72d347d
feat(stack-encrypt)!: declare target operations
coderdan Sep 13, 2026
e9f3d7e
refactor(stack-encrypt): a declaration's errors are typed, its contex…
coderdan Sep 17, 2026
0505537
docs(stack-encrypt-derive): show a field in your own storage format, …
coderdan Sep 17, 2026
ebd4912
fix(stack-encrypt): a decryption holds its local failure, so a column…
claude Sep 17, 2026
71db1b2
feat(stack-encrypt-derive): a ciphertext-only record declares `contex…
claude Sep 17, 2026
d44bdbb
docs(stack-encrypt): say what `ExpectedContext`'s default does and do…
claude Sep 17, 2026
df73957
docs(stack-encrypt-derive): the lead example names its destination on…
claude Sep 17, 2026
9518118
Merge pull request cipherstash/cipherstash-suite#2215 from cipherstas…
coderdan Sep 20, 2026
b04e794
docs(stack-encrypt): ADR-0004 — a context reaches its operations by b…
coderdan Sep 14, 2026
3e1b402
feat(stack-encrypt)!: a context reaches its operations by being threa…
coderdan Sep 17, 2026
28b420d
feat(stack-encrypt)!: a data-key request renders its own descriptor f…
coderdan Sep 17, 2026
3d34c1f
docs(stack-encrypt): the term methods are the query path, and the sto…
coderdan Sep 17, 2026
bc7c7b3
test(stack-encrypt): pin what ADR-0004 claims, on hand-written trees …
coderdan Sep 17, 2026
7190306
docs(stack-encrypt): ADR-0004 is accepted, and says what it left out
coderdan Sep 17, 2026
3ff867c
fix(stack-encrypt): a data-key request needs only the AEAD encoding o…
coderdan Sep 17, 2026
4845078
docs(stack-encrypt): ADR-0004 says what the type parameter does not r…
coderdan Sep 17, 2026
d388761
docs(stack-encrypt): a request binds its descriptor to its own contex…
coderdan Sep 17, 2026
70c64a8
feat(stack-encrypt): a dynamic façade for contexts and index terms
coderdan Sep 14, 2026
85254e1
feat(stack-encrypt): record plans in the library, not in each binding
coderdan Sep 14, 2026
0e84f10
docs(stack-encrypt): the dynamic module's public items carry their ow…
coderdan Sep 14, 2026
08d432e
fix(wasi)!: every ZeroKMS request says who it is
coderdan Sep 14, 2026
3b21c74
docs(go): a runnable example over the developer profile
coderdan Sep 14, 2026
fd62062
refactor(wasi): the user-agent names the library, not the shim
coderdan Sep 14, 2026
f268ed5
docs(go): the example follows the profile's token instead of pinning one
coderdan Sep 14, 2026
4eca152
test(stack-encrypt): the derive diagnostics are recorded with every f…
coderdan Sep 18, 2026
ec7a253
docs(wasi): the guest's doc links follow the context parser into the …
coderdan Sep 18, 2026
1925824
refactor(stack-encrypt): the dynamic scope is named for what it is
coderdan Sep 18, 2026
1f61ce2
test(stack-encrypt): the dynamic module is tested where it lives
coderdan Sep 18, 2026
6089fb5
fix(wasi): a library invariant failing is not the caller's fault
coderdan Sep 18, 2026
534f41e
fix(stack-encrypt): a plan refuses a field or key given twice
coderdan Sep 18, 2026
7af383f
fix(go): the example checks the workspace id before it becomes a path
coderdan Sep 18, 2026
cb0afd8
fix(wasi): an unclassified dynamic error is ours, not the caller's
coderdan Sep 18, 2026
ab2868a
fix(stack-encrypt): a plan is one value with its invariants, not a slice
coderdan Sep 18, 2026
c3e35bd
docs(stack-encrypt): the user-agent doc spells the product token as sent
coderdan Sep 18, 2026
7834a78
fix(stack-encrypt): a record names each field, and its ciphertext, ex…
coderdan Sep 18, 2026
381fb4f
docs(go): the example and the plan follow the keyset API rename
coderdan Sep 18, 2026
d59ad8c
feat(go): a record plan is a value, not only a tag
coderdan Sep 17, 2026
dbd4bb9
feat(stack-encrypt)!: the Go guest's memory is locked, non-dumpable a…
coderdan Sep 20, 2026
7d7ad6c
fix(stack-encrypt): guest memory outlives a call that wazero closes m…
coderdan Sep 20, 2026
6eed5e9
refactor(stack-encrypt): one mapped memory over platform primitives; …
coderdan Sep 20, 2026
7e8ff98
fix(go): a plan refuses an index kind given twice, and a nil type
coderdan Sep 20, 2026
e732b04
refactor(go)!: a plan's field is a FieldPlan with Terms, validated once
coderdan Sep 20, 2026
225519f
fix(go): a plan refuses a Go field planned twice, whatever its record…
claude Sep 20, 2026
d5eea6d
Merge pull request cipherstash/cipherstash-suite#2230 from cipherstas…
coderdan Sep 20, 2026
53d5801
docs(stack-encrypt): ADR-0005, a separate credential guest for the pr…
coderdan Sep 20, 2026
c578f81
feat(stack-profile): the crate builds for wasm32-wasip1, and names th…
coderdan Sep 20, 2026
856f34b
feat(stack-auth)!: an HTTP transport trait mirroring the guest's host…
coderdan Sep 20, 2026
ced50d1
fix(stack-auth): test modules keep a literal `cfg(test)` so the CRAP …
coderdan Sep 20, 2026
1dafe3c
ci(go): the Go binding runs on macOS and Windows against the guest Li…
coderdan Sep 20, 2026
a3f131a
ci(go): say what the platform jobs prove today, and what they are the…
coderdan Sep 20, 2026
505eb4e
fix(stack-auth)!: the wire types print nothing secret, wipe their hea…
coderdan Sep 20, 2026
ce9f342
fix(stack-encrypt): a refused strict growth is the call's failure, no…
coderdan Sep 20, 2026
f44f027
fix(stack-encrypt): a guest trap closes the client; the lock refusal …
coderdan Sep 20, 2026
07fae27
Merge branch 'main' into dan/cip-4111-go-guest-memory
coderdan Sep 20, 2026
4e198ec
fix(stack-encrypt): the example's Close takes no context
coderdan Sep 20, 2026
d1d594f
fix(stack-encrypt): the strict-growth tests skip on a host with no re…
coderdan Sep 20, 2026
ba16144
docs(stack-encrypt): ADR-0005 matches the transport trait as landed, …
coderdan Sep 21, 2026
64345b4
ci(go): the version pin read fails by name when empty, and the commen…
coderdan Sep 21, 2026
b31db96
fix(stack-encrypt): instantiation is bracketed by enter and exit like…
coderdan Sep 21, 2026
5218276
test(stack-encrypt): the host-clock check tolerates Windows timer skew
coderdan Sep 21, 2026
dd640d2
Merge pull request cipherstash/cipherstash-suite#2240 from cipherstas…
coderdan Sep 21, 2026
32d7594
Merge remote-tracking branch 'origin/main' into dan/cip-4111-go-guest…
coderdan Sep 21, 2026
9629eaa
Merge pull request cipherstash/cipherstash-suite#2237 from cipherstas…
coderdan Sep 21, 2026
21ab9c6
Merge pull request cipherstash/cipherstash-suite#2238 from cipherstas…
coderdan Sep 21, 2026
1b5f76e
Merge pull request cipherstash/cipherstash-suite#2239 from cipherstas…
coderdan Sep 21, 2026
6894ab5
chore(deps): bump Rust toolchain to 1.94.1
tobyhede Sep 21, 2026
3d0d46f
feat(stack)!: move the suite to vitaminc 0.5.0
coderdan Sep 22, 2026
db40c9c
refactor(stack-encrypt): IntoContext bounds; restate descriptor invar…
coderdan Sep 22, 2026
329abf4
feat(stack-guest-abi): share the guest ABI plumbing as a workspace crate
coderdan Sep 22, 2026
54eb214
fix(stack-guest-abi): answer review on the shared ABI crate
coderdan Sep 22, 2026
09e4a29
fix(stack-guest-abi): declare the transport's deps for wasm32 only
coderdan Sep 22, 2026
cc9a7bd
feat(go): one module at bindings/go, with internal/guest for what bot…
coderdan Sep 22, 2026
1e6ff91
fix(go): answer review on internal/guest
coderdan Sep 22, 2026
921af24
feat(go): Config.ClientKey is an opaque, wiped type, not a string
coderdan Sep 22, 2026
5f1b0ef
fix(go): answer review on the consumed client key
coderdan Sep 22, 2026
587af1d
feat(go): the credential guest and stackauth, the profile half of ADR…
coderdan Sep 22, 2026
358c739
fix(go): answer review on the credential guest and stackauth
coderdan Sep 22, 2026
7f9fd38
test(go): the refused-growth test pins the report unchanged, not locked
coderdan Sep 22, 2026
e6b40eb
fix(stack-guest-abi): key the buffer registry by pointer and gate it …
coderdan Sep 23, 2026
a850bc0
test(stack-encrypt): fuzz the leaf and index-term byte decoders
coderdan Sep 23, 2026
1b71f9e
test(stack-encrypt): gate the crate on the CRAP metric
coderdan Sep 23, 2026
66fd8d9
test(stack-guest-abi): drive the buffer registry against a model
coderdan Sep 23, 2026
ea56421
test(stack-encrypt): fuzz the stored-record preflight against a model
coderdan Sep 23, 2026
91ce93f
chore(mise): per-crate rustdoc gates for the stack crates, fanned out…
coderdan Sep 23, 2026
a9e7d7b
ci: mutation-testing gate for stack-auth and stack-encrypt (cargo-mut…
coderdan Sep 23, 2026
501928f
Merge pull request cipherstash/cipherstash-suite#2256 from cipherstas…
coderdan Sep 23, 2026
d9e2492
Merge pull request cipherstash/cipherstash-suite#2255 from cipherstas…
coderdan Sep 23, 2026
d2098a3
Merge pull request cipherstash/cipherstash-suite#2253 from cipherstas…
coderdan Sep 23, 2026
82a254c
Merge pull request cipherstash/cipherstash-suite#2246 from cipherstas…
tobyhede Sep 28, 2026
6ad8407
test(stack-encrypt): update UI snapshots for Rust 1.94.1 diagnostics
tobyhede Sep 29, 2026
fb14197
Merge pull request cipherstash/cipherstash-suite#2270 from cipherstas…
tobyhede Sep 29, 2026
7845690
test(stack): pin mutation regression behavior
coderdan Sep 25, 2026
6d7234d
test(stack): cover remaining mutation paths
coderdan Sep 25, 2026
9fdd770
test(stack): address PR review findings
coderdan Sep 25, 2026
a9a5e48
test(auth): keep browser launcher mutable
coderdan Sep 25, 2026
00e1d6f
test(stack): address review notes on assertion messages
claude Sep 28, 2026
85dc6ff
feat(stackauth): add Go credential strategies
coderdan Sep 26, 2026
b5a39b3
fix(stackauth): satisfy credential guest CI
coderdan Sep 26, 2026
dcea252
fix(stackauth): lock only device refresh
coderdan Sep 26, 2026
2584100
fix(stackauth): never replay a spent refresh token after a failed save
coderdan Sep 28, 2026
73c94f1
fix(stackauth): report malformed credentials as configuration errors
claude Sep 28, 2026
b13be20
fix(stackauth): identify every auth request with a user-agent
coderdan Sep 29, 2026
23a3993
feat(go): resolve stackencrypt credentials from the environment, then…
coderdan Sep 28, 2026
bb149b3
fix(go): address credential resolution review findings
claude Sep 28, 2026
db88f12
fix(go): report the credentials' memory lock live and name a spent key
claude Sep 29, 2026
7193e61
fix(go): a refused config marks explicit credentials consumed
coderdan Sep 29, 2026
5cecdcb
feat(go): functional options for stackencrypt.NewClient; Config removed
coderdan Sep 28, 2026
de6ad64
test(go): live test of AutoCredentials through a real access-key exch…
coderdan Sep 29, 2026
b836591
feat(go)!: tokens come only from stackauth strategies
coderdan Sep 29, 2026
66654af
fix(go): address the cipherstash/cipherstash-suite#2267 review
coderdan Sep 29, 2026
250cb28
fix(go): name the credential guest when it cannot be locked at all
coderdan Sep 29, 2026
e8ed7f4
docs(go): a runnable example of explicit credentials
coderdan Sep 29, 2026
e753829
fix(go): consume replaced credentials; no ZeroKMS URL in the examples
coderdan Sep 29, 2026
16c6121
feat(go)!: no public option to pin the ZeroKMS endpoint
coderdan Sep 29, 2026
ad774a0
ci(go): lint the Go bindings with golangci-lint
auxesis Sep 29, 2026
7e6ee60
Merge pull request cipherstash/cipherstash-suite#2274 from cipherstas…
auxesis Sep 29, 2026
a695c72
fix(go): same credentials twice are not consumed; classify refused co…
coderdan Sep 29, 2026
6dce6e2
fix(go): refuse buffers the guest's i32 allocator cannot address
auxesis Sep 29, 2026
2501d4e
fix(go): refuse HTTP statuses the guest's i32 cannot carry
auxesis Sep 29, 2026
08df071
fix(go): refuse an expires_at beyond int64
auxesis Sep 29, 2026
ff95b40
fix(go): discard the request body Close error explicitly
auxesis Sep 29, 2026
ffba33a
chore(go): mark the Windows allocator's unsafe as audited
auxesis Sep 29, 2026
36964cb
chore(go): mark PackedResult's narrowing as intentional
auxesis Sep 29, 2026
2f7728f
chore(go): mark caller-chosen file paths for gosec
auxesis Sep 29, 2026
4fcd788
ci(go): add gosec to the Go bindings lint
auxesis Sep 29, 2026
99b9e4a
test(go): pin stackauth's status and expires_at range checks
auxesis Sep 29, 2026
4cb1e1b
Merge pull request cipherstash/cipherstash-suite#2275 from cipherstas…
coderdan Sep 29, 2026
e67d13f
feat(go): plan.Policy maps a field's facts to a record plan
coderdan Sep 28, 2026
f4ca03b
fix(go): close the plan package's review findings
claude Sep 28, 2026
1afeb31
feat(go): split plan.Column into Column and Identity
coderdan Sep 29, 2026
f799a1e
refactor(go)!: move the struct-tag fact source out of the plan API
coderdan Sep 29, 2026
c0efd52
fix(go): terminate the embedded-struct scan and refuse a nil type
claude Sep 29, 2026
9aff82f
fix(go): refuse plan.Any/All with no matchers; test pointer-embedded …
auxesis Sep 29, 2026
118e1d1
fix(go): silence unused lint on the recursive-embedding test fixtures
auxesis Sep 29, 2026
96c0079
Merge pull request cipherstash/cipherstash-suite#2268 from cipherstas…
coderdan Sep 29, 2026
82a85b4
test(stack-encrypt): order Go string terms by their collated form
auxesis Oct 2, 2026
d0cea7c
Merge remote-tracking branch 'suite-export-2/main' into build/import-…
auxesis Oct 2, 2026
359a6f1
chore: clean up the suite import deposit
auxesis Oct 1, 2026
6bb5775
build: keep Biome off the frozen and generated binding files
auxesis Oct 1, 2026
fa05f24
style: reformat the imported bindings with the root Biome config
auxesis Oct 1, 2026
d94d6a7
fix: guard two optional chains in the auth binding tests
auxesis Oct 1, 2026
2371f73
build: make the repository root the Rust and Go workspace root
auxesis Oct 1, 2026
8c86f4b
build: freeze the @cipherstash/auth packages and add Dependabot entries
auxesis Oct 1, 2026
542fa51
test: register the stack-* workspaces with the guards that list them
auxesis Oct 1, 2026
1c52c8f
docs: describe the stack-* crates, bindings and Go module
auxesis Oct 1, 2026
f7b0031
build(mise): move the cargo tools into mise.test.toml, pinned
auxesis Oct 2, 2026
8e8dd7a
fix(profile): write the napi typings to native.d.ts
auxesis Oct 1, 2026
0dc76af
ci(tests): build the auth and profile bindings before the test run
auxesis Oct 2, 2026
5147dd0
build: give cts-common and zerokms-protocol caret requirements
auxesis Oct 2, 2026
a981590
build(go): name the Go module by its stack path
auxesis Oct 2, 2026
d3524b8
test: guard the Go module path
auxesis Oct 2, 2026
1ad1055
fix(mise): make the wasi-check dependency gate see through colour
auxesis Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
23 changes: 23 additions & 0 deletions .cargo-crap.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# Configuration for `cargo crap` — the CRAP (Change Risk Anti-Patterns) metric.
#
# CRAP rewards complex code that is well tested and penalises complex code that
# is not:
#
# CRAP = CC^2 * (1 - coverage)^3 + CC (CC = cyclomatic complexity)
#
# A simple or fully covered function scores roughly its complexity; a complex,
# untested one scores into the hundreds. It surfaces exactly the kind of risky,
# under-tested logic where a subtle mistake can hide (see CIP-3233 / #2036).
#
# Run it via `mise run crap:stack-auth` (generates coverage first, then scores).
# Config discovery walks up from the working directory, so this single root file
# applies anywhere in the workspace.

# CRAP score above which a function is flagged for refactoring or more tests.
# 30 is the long-standing Crap4J default: a CC-10 function needs ~42% coverage,
# a CC-15 function ~59%, to fall below it.
threshold = 30

# Functions with complexity but no coverage data are scored as 0% covered
# (worst case) rather than silently skipped — uninstrumented code is risk too.
missing = "pessimistic"
7 changes: 7 additions & 0 deletions .cargo/config.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Wasm target needs the `wasm_js` getrandom backend (used by deps that pull
# `getrandom >= 0.3`, e.g. `rand 0.9+` via `vitaminc-random`). Without this
# rustflag, those crates fail to compile on wasm32-unknown-unknown — the
# stack-auth-wasm build (`languages/typescript/packages/stack-auth-wasm`).
# See: https://docs.rs/getrandom/latest/getrandom/#opt-in-backends
[target.wasm32-unknown-unknown]
rustflags = ['--cfg', 'getrandom_backend="wasm_js"']
81 changes: 81 additions & 0 deletions .cargo/mutants.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
# Configuration for cargo-mutants — mutation testing for the stack crates.
#
# Mutation testing rewrites small pieces of logic (flip a `<` to `<=`, replace
# a body with `Default::default()`, drop an `&&` arm) and reruns the tests: a
# mutant that survives is a line the suite does not actually pin down. CRAP
# (`crap:*`) says which complex code is uncovered; this says which covered
# code is not asserted on — in a crypto crate, the comparisons, length checks
# and context bindings a test can execute without ever checking.
#
# CI runs this `--in-diff` as a per-PR gate (.github/workflows/mutants.yml):
# only the lines a PR changes are mutated, so the gate trips when a PR adds
# logic its tests do not exercise. A full per-crate sweep is
# `mise run mutants:<crate>` (stack-auth ~15 min, stack-encrypt ~60 min on a
# laptop with four jobs); `mise run mutants` runs every crate that has one.
# Both read the settings below, so they stay in sync.

# Build and test with every feature on, so feature-gated code (stack-encrypt's
# `dynamic` module, the `http` transports) is compiled and exercised. Without
# this a mutant there would "survive" only because the feature was off.
additional_cargo_args = ["--all-features"]

# nextest, as everywhere else in the suite. The filterset drops two things
# from the per-mutant test command that are slow and pin no mutant:
# stack-encrypt's trybuild UI suite (`binary(ui)`: it compiles the derive's
# compile-fail cases in a scratch project, ~60s, and exercises no mutable
# line) and stack-auth's wall-clock stress tests (real servers, real sleeps,
# flaky under a slowed build). A filter naming something a package does not
# have matches nothing, so one filter serves every package.
test_tool = "nextest"
additional_cargo_test_args = ["-E", "not binary(ui) & not test(stress_tests)"]

# Skip the derive crate: its logic runs inside `#[proc_macro_derive]` entry
# points at compile time, not in the instrumented test binary, so every
# mutant there survives spuriously. Its behaviour is pinned by stack-encrypt's
# `tests/derive.rs` and the trybuild UI suite instead.
exclude_globs = ["packages/stack-encrypt-derive/**"]

# Mutants no test binary can kill, by name. Every other survivor is a test to
# write, not a line to add here. Two kinds qualify:
#
# - Unreachable: code compiled out of the native `--all-features` test build
# (wasm32-only impls, the no-`http` fallback, the non-test reqwest client).
# A mutant there builds and "survives" because nothing it touches is run.
# - Equivalent: the replacement is the value the code already returns
# (`Some(())` for a `()` credential, `Map::new()` for `Default::default()`,
# a builder's `new()` for its `Default`), so no test can tell them apart.
#
# The regexes match the name `--list` prints, `path:line:col: replace …`.
# Anchor on the replacement text, so an entry cannot swallow a reachable
# sibling with the same function name. The wasm32 `TokenStoreFn`,
# `AutoStrategy::detect_inner` and `Pending::into_future` entries also anchor
# on the line because their names are identical to the native impl's.
# If those lines move, a full sweep reports them again and the line numbers
# here need moving with them.
exclude_re = [
# stack-auth — unreachable under the native test build.
'stack-auth/src/transport\.rs:\d+:\d+: replace <impl std::fmt::Display for NoTransport>::fmt ',
'stack-auth/src/transport\.rs:\d+:\d+: replace <impl DynTransport for T>::send_dyn -> std::pin::Pin<Box<dyn Future<Output = Result<HttpResponse, RequestError>>\+\x27a>> ',
# Production http_client variants are cfg-disabled here; the test variant
# builds an unconfigured Client, equivalent to Client::default().
'stack-auth/src/transport\.rs:\d+:\d+: replace http_client -> reqwest::Client with Default::default\(\)$',
'stack-auth/src/auto_strategy\.rs:150:9: replace AutoStrategy::detect_inner -> Result<Self, AuthError> with Ok\(Default::default\(\)\)$',
'stack-auth/src/token_store\.rs:(258|266):9: replace <impl TokenStore for TokenStoreFn<L, S>>::(load|save)',
# stack-auth — equivalent.
'stack-auth/src/(access_key|oidc)_refresher\.rs:\d+:\d+: replace <impl Refresher for \w+(<P>)?>::try_credential -> Option<Self::Credential> with Some\(Default::default\(\)\)$',
'stack-auth/src/error\.rs:\d+:\d+: replace AuthErrorKind::payload -> serde_json::Map<String, serde_json::Value> with Default::default\(\)$',
# stack-encrypt — unreachable under the native test build (the wasm32
# variant; the native one returns a `FallbackKeyProvider`).
'stack-encrypt/src/cipher\.rs:\d+:\d+: replace client_key_provider -> EnvKeyProvider with Default::default\(\)$',
'stack-encrypt/src/target/pending\.rs:443:9: replace <impl IntoFuture for Pending<.*>>::into_future -> Self::IntoFuture with Default::default\(\)$',
# stack-encrypt — equivalent.
'stack-encrypt/src/cipher\.rs:\d+:\d+: replace StackCipher<FromEnv>::builder -> StackCipherBuilder with Default::default\(\)$',
'stack-encrypt/src/sem/mod\.rs:\d+:\d+: replace <impl MatchConfig for DefaultMatch>::options -> MatchOptions with Default::default\(\)$',
# Both unit-context conversions explicitly return Self::default().
'stack-encrypt/src/target/context\.rs:\d+:\d+: replace <impl From<\(\)> for (DeclaredContext|ExpectedContext<T>)>::from -> Self with Default::default\(\)$',
]

# Headroom over the measured baseline before a slow-but-correct mutant is
# misreported as a timeout.
timeout_multiplier = 5.0
minimum_test_timeout = 90
4 changes: 4 additions & 0 deletions .config/nextest.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Workflows set NEXTEST_PROFILE=ci.
[profile.ci]
# Do not cancel the test run on the first failure.
fail-fast = false
9 changes: 9 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,12 @@
/pnpm-lock.yaml @cipherstash/developers
/.npmrc @cipherstash/developers
/skills/stash-supply-chain-security/ @cipherstash/developers

# The stack-* crates, their node bindings and the Go module, imported from
# cipherstash-suite. stack-auth, stack-profile and @cipherstash/auth publish to
# crates.io and npm.
/packages/stack-*/ @cipherstash/developers
/languages/golang/ @cipherstash/developers
/languages/typescript/packages/auth/ @cipherstash/developers
/languages/typescript/packages/profile/ @cipherstash/developers
/languages/typescript/packages/stack-auth-wasm/ @cipherstash/developers
68 changes: 68 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -212,6 +212,74 @@ updates:
update-types:
- version-update:semver-major

# ── Cargo (the root workspace — the stack-* crates) ─────────────
# The root workspace (the six stack-* crates and the three node binding
# crates) and the five detached workspaces beside it: the three cargo-fuzz
# crates and the two Go WASI guests. Each has its own Cargo.lock, and each
# is its own workspace root, so each is listed.
- package-ecosystem: cargo
directories:
- /
- /packages/stack-auth/fuzz
- /packages/stack-kms/fuzz
- /packages/stack-encrypt/fuzz
- /languages/golang/stackencrypt/guest
- /languages/golang/stackauth/guest
# Monthly, matching the other two cargo entries.
schedule:
interval: monthly
cooldown:
default-days: 7
open-pull-requests-limit: 3
labels:
- dependencies
- supply-chain
commit-message:
prefix: "chore"
include: scope
groups:
cargo-minor-patch:
patterns:
- "*"
update-types:
- minor
- patch
ignore:
# Released from cipherstash-suite and pinned with exact `=` requirements

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: this comment predates 5147dd00. cts-common and zerokms-protocol now take caret requirements in the root Cargo.toml; only recipher and cllw-ore (and the two Go guests) still pin with =. The ignore list itself is still right, since all four move in lockstep with the suite by hand. Same stale wording as the AGENTS.md line already flagged above.


Generated by Claude Code

# in the root Cargo.toml and the guests: stack-auth's API carries their
# types, so they move in lockstep with the suite, by hand.
- dependency-name: "cts-common"
- dependency-name: "zerokms-protocol"
- dependency-name: "recipher"
- dependency-name: "cllw-ore"
# vitaminc is pinned at 0.5.0 across the crates and the guests; the
# guests' `FfiValue: Decrypt` bound fails if two versions resolve.
- dependency-name: "vitaminc*"
# Major bumps are reviewed and applied manually, not by Dependabot.
- dependency-name: "*"
update-types:
- version-update:semver-major

# ── Go (languages/golang) ──────────────────────────────────────
- package-ecosystem: gomod
directory: /languages/golang
schedule:
interval: monthly
cooldown:
default-days: 7
open-pull-requests-limit: 3
labels:
- dependencies
- supply-chain
commit-message:
prefix: "chore"
include: scope
ignore:
# Major bumps are reviewed and applied manually, not by Dependabot.
- dependency-name: "*"
update-types:
- version-update:semver-major

# ── GitHub Actions ─────────────────────────────────────────────
- package-ecosystem: github-actions
directory: /
Expand Down
16 changes: 16 additions & 0 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,15 @@ jobs:
- name: Build the protect-ffi binding
uses: ./.github/actions/build-ffi-binding

# `pnpm run test` below also runs the @cipherstash/auth and
# @cipherstash/profile vitest suites, which load the napi module. Their
# `test` scripts do not build it, so cargo stays off the default `test`
# path; this step builds it, as the protect-ffi step above does for
# `index.node`. Each `build:debug` writes its typings to the committed
# `native.d.ts`, so the build leaves the tree clean.
- name: Build the auth and profile node bindings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking: this step compiles the root workspace with whatever Rust the runner ships, not the 1.94.1 pinned in the root mise.toml. Nothing in this job runs mise install at the repo root (the protect-ffi action runs mise from its own folder, which does not pin Rust). It passes today, and napi build only needs the crates to compile, so this is fine for PR B. Worth keeping in mind for the CI port, where the trybuild snapshots and clippy do depend on the pinned toolchain.


Generated by Claude Code

run: pnpm --filter @cipherstash/auth --filter @cipherstash/profile run build:debug

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker. In each run-tests matrix leg, this step compiles two napi bindings from cold. It has no Rust cache, and it uses the default rustc of the runner, not the 1.94.1 pin in mise.toml. The protect-ffi step above restores index.node from a content-hash cache. If PR C does not add a cache here, please record that as a follow-up.


- name: Type tests (stack)
run: pnpm exec turbo run test:types --filter @cipherstash/stack

Expand Down Expand Up @@ -285,6 +294,13 @@ jobs:
- name: Lint — no references to deleted package directories
run: pnpm run lint:package-paths

# TEMPORARY — delete with the script in the arming PR (PR E) of the
# stack-* crates import. The seven @cipherstash/auth packages live here
# but still publish from cipherstash/cipherstash-suite, so a changeset
# naming one would bump a frozen package and block every release.
- name: Lint — no @cipherstash/auth changeset before the publishing cutover
run: pnpm run lint:auth-changeset

# `eql-bindings` emits EQL payloads; `@cipherstash/eql` carries the SQL
# that stores them. Both live here now and release at one lockstep
# version. A registry pin on either lets them drift apart — it compiles,
Expand Down
19 changes: 19 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -91,3 +91,22 @@ sql/cipherstash-*.sql
.cipherstash/

notes/

# Rust crates imported from cipherstash-suite (packages/stack-*).
# cargo-fuzz: crash artifacts, coverage data, and the corpus that grows during
# a campaign. Ignore the generated corpus entries but keep the hand-written seed
# corpora (committed as `valid-*`) tracked. The fuzz crates' Cargo.lock files
# are tracked here, unlike in the suite, so `--locked` and Dependabot see them.
packages/*/fuzz/artifacts/
packages/*/fuzz/coverage/
packages/*/fuzz/corpus/*/*
!packages/*/fuzz/corpus/*/valid-*
# cargo-mutants output (`mise run mutants:<crate>` writes it to the cwd).
mutants.out/

# The Go module's embedded WASI guests: build outputs of `mise run
# wasm:guest:build` and `mise run wasm:auth-guest:build`.
languages/golang/stackencrypt/wasm/*.wasm
languages/golang/stackauth/wasm/*.wasm
languages/golang/stackencrypt/wasm/*.sha256
languages/golang/stackauth/wasm/*.sha256
Loading
Loading