Skip to content

Accepts ADR-0005 and ADR-0007 Amendment B (shipped in 0.6.0) - #127

Merged
johnnyt merged 1 commit into
mainfrom
enc-6pji-flip-shipped-amendments
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
enc-6pji-flip-shipped-amendments

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Flips two amendments to accepted now that their code has shipped in encryptor 0.6.0 (tag v0.6.0, commit 91e9643, published on Hex). Docs only: docs/adr/ changes, no Elixir code, so no gate stage runs (this repository's CLAUDE.md: "a change touching no Elixir code has no gate to run and may commit on review of the diff alone"). No changelog fragment (changelog.d/README.md excludes ADRs).

Each Status line flips in place (proposed (2026-09-30) to accepted (2026-09-30), proposed 2026-09-30, the shape of ADR-0007 Amendment A's line), and a dated Note at the foot of each file records the version, the SHA and the claims checked. git diff origin/main -- docs/adr/ removes exactly the two old Status lines. The index rows for ADR-0005 and ADR-0007 already read accepted (..., amended), so docs/adr/README.md does not change.

ADR-0005 Amendment B: P3 does not wait on the cache drain; P2 step 1 and P4 do

Version 0.6.0, verified at 91e9643. Claims checked by anchor: B1's resolution-before-cache order (decrypt/7), GcpKms's per-call store read and its {:unknown_key, selector} for an empty result (rows/2), the bounded-cache obligation in Encryptor.Provider, the four superseded passages at their cited lines, and the shred_drain_test P3 test; B2's P4 step 2 line and its test; B3's engine cites (compute_encryption_cache_id/3, CacheEntry.new/2, aws_encryption_sdk 1.0.0 still locked) and that no code drops an entry at the mint; B4's precondition line; the runbook carrying the drain steps; and that the landing change edited no function body (its one lib/ edit is suspend/2's doc prose).

Superseded sentences: B3's statements that a write after the mint finds a warm encryption entry from before it no longer hold for a vault running 0.6.0, because the write side's cache partition now carries the resolved key (Partition.encryption_id/3, reached from Encryptor.Vault.Encrypt's partition_id/2). The later dated Note on ADR-0005, "what Amendment B's P2 step 1 drain still covers" (2026-09-30), names that change, so the record flips under the superseded-sentence rule and the foot Note cites that Note.

ADR-0007 Amendment B: a Decrypt 400 or 404 answers a permanent refusal

Version 0.6.0, verified at 91e9643. Claims checked by anchor: the Api failure shapes (handle/2, the failure type); decrypt_failure/2 and @refused_statuses ([400, 404]), called from unwrap/3, which both encryption_key/2 and decryption_keys/2 reach; provision/2 and mint/4 unchanged; the reason types in Encryptor.Provider and Encryptor.Error; Resolve carrying provider reasons through unchanged; the provider behaviour's reason doc; Encryptor.Error.describe/1; Encryptor.Telemetry.reason_tag/1; the moduledoc section; the superseded row, paragraph and open question at their cited lines; and the ADR-0002, ADR-0005 and ADR-0010 passages the amendment quotes. One claim is about the cloud service, not this package (a disabled version's 400 is reversible); nothing on main contradicts it, and the foot Note says it was not re-checked against the service.

Review

Own review of the diff against the bead's acceptance: both Status lines flip in place; each foot Note is the last section of its file and names 0.6.0 and 91e9643; every lib/ and engine line cited in the two Notes was re-read at 91e9643; zero removed lines other than the two Status lines; no index row change, following the ADR-0007 Amendment A precedent; docs only. Neither amendment decides anything cryptographic (ADR-0005's "What this amendment does not do"; ADR-0007's decides an error term). ADR-0001 Amendment B is not in this change.

ADR-0005 Amendment B (the cache drain per procedure) and ADR-0007
Amendment B (a Decrypt 400 or 404 answers kms_refused) shipped in
encryptor 0.6.0. Each Status line flips in place to accepted, and a
dated foot Note on each record lists the claims re-verified at the
v0.6.0 commit. B3's write-side sentences are read as the later Note
on ADR-0005 says, since the partition now carries the resolved key.

Refs: enc-6pji
@johnnyt
johnnyt merged commit 682353e into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the enc-6pji-flip-shipped-amendments branch September 30, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant