Skip to content

Commit b6fb3d9

Browse files
committed
Merge origin/main into claude/issue-21310-cli-readme-flags
2 parents a5f7446 + 6c5bef5 commit b6fb3d9

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎docs/adr/0128-producer-discriminated-aad-for-cryptocontext.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,7 @@ Any **one** of these turns the deferral over; none requires re-opening the direc
101101
- **The hazard stops being hypothetical**: any intersection appears between the settings-namespace set and the set of object names carrying a `Field.secret()` field — in shipped platform metadata, in an example app, or in a reported customer deployment. §1.4's "no intersection" is the whole of the deferral's evidence, and it is a fact with a shelf life.
102102
- **A fourth producer of `CryptoContext` is added**, or an existing one's vocabulary is widened to accept names it does not control. A fourth vocabulary in a flat space is the same defect with more surface, and the discriminant is far cheaper to introduce *with* the new producer than after it.
103103
- **`ICryptoProvider` is opened for another breaking change.** The migration is the expensive half; the breaking-export half should be paid once. A queued breaking change to this interface should pull D1 in with it.
104+
> **Note (2026-10-02).** This trigger was met by the keyed-digest break ([#21263](https://github.com/objectstack-ai/objectstack/issues/21263), PR [#21292](https://github.com/objectstack-ai/objectstack/pull/21292): a required `keyedDigest` member on `ICryptoProvider`), which landed without D1 by the maintainer's ruling A (comment [5945612493](https://github.com/objectstack-ai/objectstack/issues/21263#issuecomment-5945612493)) because the director's census (comment [5945420994](https://github.com/objectstack-ai/objectstack/issues/21263#issuecomment-5945420994)) measured zero out-of-repo `ICryptoProvider` implementations in the organisation's repositories, so pulling D1 in would have saved a second breaking-export change for no measured implementer population; D1 is scheduled on its own as [#21326](https://github.com/objectstack-ai/objectstack/issues/21326).
104105
- **A compliance or customer requirement asks the platform to state its at-rest ciphertext binding.** The honest present-tense answer is §1's, and an organisation that needs a stronger one funds the work.
105106

106107
## 5. Alternatives considered

0 commit comments

Comments
 (0)