Accepts ADR-0005 and ADR-0007 Amendment B (shipped in 0.6.0) - #127
Merged
Merged
Conversation
ADR-0005 Amendment B (the cache drain per procedure) and ADR-0007 Amendment B (a Decrypt 400 or 404 answers kms_refused) shipped in encryptor 0.6.0. Each Status line flips in place to accepted, and a dated foot Note on each record lists the claims re-verified at the v0.6.0 commit. B3's write-side sentences are read as the later Note on ADR-0005 says, since the partition now carries the resolved key. Refs: enc-6pji
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Flips two amendments to accepted now that their code has shipped in encryptor 0.6.0 (tag
v0.6.0, commit91e9643, published on Hex). Docs only:docs/adr/changes, no Elixir code, so no gate stage runs (this repository's CLAUDE.md: "a change touching no Elixir code has no gate to run and may commit on review of the diff alone"). No changelog fragment (changelog.d/README.mdexcludes ADRs).Each Status line flips in place (
proposed (2026-09-30)toaccepted (2026-09-30), proposed 2026-09-30, the shape of ADR-0007 Amendment A's line), and a dated Note at the foot of each file records the version, the SHA and the claims checked.git diff origin/main -- docs/adr/removes exactly the two old Status lines. The index rows for ADR-0005 and ADR-0007 already readaccepted (..., amended), sodocs/adr/README.mddoes not change.ADR-0005 Amendment B: P3 does not wait on the cache drain; P2 step 1 and P4 do
Version 0.6.0, verified at
91e9643. Claims checked by anchor: B1's resolution-before-cache order (decrypt/7),GcpKms's per-call store read and its{:unknown_key, selector}for an empty result (rows/2), the bounded-cache obligation inEncryptor.Provider, the four superseded passages at their cited lines, and theshred_drain_testP3 test; B2's P4 step 2 line and its test; B3's engine cites (compute_encryption_cache_id/3,CacheEntry.new/2,aws_encryption_sdk1.0.0 still locked) and that no code drops an entry at the mint; B4's precondition line; the runbook carrying the drain steps; and that the landing change edited no function body (its onelib/edit issuspend/2's doc prose).Superseded sentences: B3's statements that a write after the mint finds a warm encryption entry from before it no longer hold for a vault running 0.6.0, because the write side's cache partition now carries the resolved key (
Partition.encryption_id/3, reached fromEncryptor.Vault.Encrypt'spartition_id/2). The later dated Note on ADR-0005, "what Amendment B's P2 step 1 drain still covers" (2026-09-30), names that change, so the record flips under the superseded-sentence rule and the foot Note cites that Note.ADR-0007 Amendment B: a
Decrypt400 or 404 answers a permanent refusalVersion 0.6.0, verified at
91e9643. Claims checked by anchor: theApifailure shapes (handle/2, thefailuretype);decrypt_failure/2and@refused_statuses([400, 404]), called fromunwrap/3, which bothencryption_key/2anddecryption_keys/2reach;provision/2andmint/4unchanged; thereasontypes inEncryptor.ProviderandEncryptor.Error;Resolvecarrying provider reasons through unchanged; the provider behaviour's reason doc;Encryptor.Error.describe/1;Encryptor.Telemetry.reason_tag/1; the moduledoc section; the superseded row, paragraph and open question at their cited lines; and the ADR-0002, ADR-0005 and ADR-0010 passages the amendment quotes. One claim is about the cloud service, not this package (a disabled version's 400 is reversible); nothing on main contradicts it, and the foot Note says it was not re-checked against the service.Review
Own review of the diff against the bead's acceptance: both Status lines flip in place; each foot Note is the last section of its file and names 0.6.0 and
91e9643; every lib/ and engine line cited in the two Notes was re-read at91e9643; zero removed lines other than the two Status lines; no index row change, following the ADR-0007 Amendment A precedent; docs only. Neither amendment decides anything cryptographic (ADR-0005's "What this amendment does not do"; ADR-0007's decides an error term). ADR-0001 Amendment B is not in this change.