diff --git a/CHANGELOG.md b/CHANGELOG.md index bb7c505..ec8fcc7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,10 +6,46 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). Entries for unreleased work are not written here directly. Each issue drops a -fragment in [`changelog.d/`](https://github.com/riddler/encryptor/blob/v0.5.0/changelog.d/README.md); the fragments are assembled +fragment in [`changelog.d/`](https://github.com/riddler/encryptor/blob/v0.6.0/changelog.d/README.md); the fragments are assembled into a version section at release. See that README for the format and for when a change warrants an entry at all. +## [0.6.0] - 2026-09-30 + +### **Breaking** + +- **Breaking:** a vault refuses to start on an option it does not read, where + it used to ignore it. The refusal is `{:invalid_config, layer, + {:unknown_options, keys}}`, naming the layer (`:use`, `:app_env`, + `:start_link` or `:init`) and the sorted unknown keys. Rename or remove each + listed option - the pre-rename `:telemetry_tenant_ref` is + `:telemetry_scope_ref` - and set `:otp_app` only in `use Encryptor.Vault`. +- **Breaking:** `Encryptor.Provider.GcpKms` answers a `Decrypt` that Cloud + KMS refuses with HTTP 400 or 404 (an AAD mismatch, a key or version that is + not there) as `{:invalid_key_descriptor, {:kms_refused, status}}` from + `encryption_key/2` and `decryption_keys/2`, where it answered + `{:key_unavailable, selector}`; an IAM denial, a throttle, a server error + and a transport or token failure still answer `{:key_unavailable, + selector}`. Match the new term wherever a caller handled a refused row as + `:key_unavailable`, and stop retrying it. + +### Fixed + +- A write after a new key version is minted wraps its data key under that + version at once, even when the vault's materials cache is warm. The write + side's cache partition id now carries the resolved key as well as the + vault and the selector, so the entry from before the mint is no longer + found; `rekey/2`'s write half gets the same fix. Upgrading changes every + write-side partition id once: the first write per context after the deploy + is a cache miss (on the KMS path, one KMS call). Messages, stored rows and + the read side are unchanged. +- Under a shared suspension store, a `suspend/2` or `reinstate/2` that + answered `{:suspension_store_unavailable, store}` on its five-second timeout + is no longer performed seconds later with a second + `[:encryptor, :suspension, :changed]` event, and a store whose `list/1` + hangs no longer blocks every write behind it: a refresh gives the store five + seconds. + ## [0.5.0] - 2026-09-24 ### **Breaking** diff --git a/README.md b/README.md index f5b50c7..6733d5a 100644 --- a/README.md +++ b/README.md @@ -100,7 +100,7 @@ documents: ```elixir def deps do [ - {:encryptor, "~> 0.5.0"} + {:encryptor, "~> 0.6.0"} ] end ``` diff --git a/changelog.d/enc-asn.md b/changelog.d/enc-asn.md deleted file mode 100644 index 7d86e72..0000000 --- a/changelog.d/enc-asn.md +++ /dev/null @@ -1,8 +0,0 @@ -### **Breaking** - -- **Breaking:** a vault refuses to start on an option it does not read, where - it used to ignore it. The refusal is `{:invalid_config, layer, - {:unknown_options, keys}}`, naming the layer (`:use`, `:app_env`, - `:start_link` or `:init`) and the sorted unknown keys. Rename or remove each - listed option - the pre-rename `:telemetry_tenant_ref` is - `:telemetry_scope_ref` - and set `:otp_app` only in `use Encryptor.Vault`. diff --git a/changelog.d/enc-hpx.md b/changelog.d/enc-hpx.md deleted file mode 100644 index f9cbaac..0000000 --- a/changelog.d/enc-hpx.md +++ /dev/null @@ -1,10 +0,0 @@ -### **Breaking** - -- **Breaking:** `Encryptor.Provider.GcpKms` answers a `Decrypt` that Cloud - KMS refuses with HTTP 400 or 404 (an AAD mismatch, a key or version that is - not there) as `{:invalid_key_descriptor, {:kms_refused, status}}` from - `encryption_key/2` and `decryption_keys/2`, where it answered - `{:key_unavailable, selector}`; an IAM denial, a throttle, a server error - and a transport or token failure still answer `{:key_unavailable, - selector}`. Match the new term wherever a caller handled a refused row as - `:key_unavailable`, and stop retrying it. diff --git a/changelog.d/enc-jwkn.md b/changelog.d/enc-jwkn.md deleted file mode 100644 index af82bed..0000000 --- a/changelog.d/enc-jwkn.md +++ /dev/null @@ -1,10 +0,0 @@ -### Fixed - -- A write after a new key version is minted wraps its data key under that - version at once, even when the vault's materials cache is warm. The write - side's cache partition id now carries the resolved key as well as the - vault and the selector, so the entry from before the mint is no longer - found; `rekey/2`'s write half gets the same fix. Upgrading changes every - write-side partition id once: the first write per context after the deploy - is a cache miss (on the KMS path, one KMS call). Messages, stored rows and - the read side are unchanged. diff --git a/changelog.d/enc-ris3.md b/changelog.d/enc-ris3.md deleted file mode 100644 index 1cd1bb4..0000000 --- a/changelog.d/enc-ris3.md +++ /dev/null @@ -1,8 +0,0 @@ -### Fixed - -- Under a shared suspension store, a `suspend/2` or `reinstate/2` that - answered `{:suspension_store_unavailable, store}` on its five-second timeout - is no longer performed seconds later with a second - `[:encryptor, :suspension, :changed]` event, and a store whose `list/1` - hangs no longer blocks every write behind it: a refresh gives the store five - seconds. diff --git a/guides/getting-started.md b/guides/getting-started.md index 40a828b..879b295 100644 --- a/guides/getting-started.md +++ b/guides/getting-started.md @@ -20,13 +20,13 @@ claim nobody can review. ```elixir def deps do [ - {:encryptor, "~> 0.5.0"} + {:encryptor, "~> 0.6.0"} ] end ``` -Pin the minor and read the changelog before upgrading: `~> 0.5.0` admits the -0.5.x patch releases and nothing above them. Until 1.0.0, public APIs, storage +Pin the minor and read the changelog before upgrading: `~> 0.6.0` admits the +0.6.x patch releases and nothing above them. Until 1.0.0, public APIs, storage formats, and derivation constants may change between releases. The reserved `encryptor 0.1.0` on Hex predates the implementation and holds no code; depending on it gets you an empty package. diff --git a/mix.exs b/mix.exs index 9cf54b9..567df99 100644 --- a/mix.exs +++ b/mix.exs @@ -1,7 +1,7 @@ defmodule Encryptor.MixProject do use Mix.Project - @version "0.5.0" + @version "0.6.0" @source_url "https://github.com/riddler/encryptor" def project do