Skip to content

fix(sdk): kasKeyCache has no mutex protection — data race under concurrent use #4083

Description

@eugenioenko

Motivation

kasKeyCache in sdk/kas_client.go uses a bare map[kasKeyRequest]timeStampedKASInfo with no synchronization. When multiple goroutines call LoadTDF or rewrap concurrently on the same SDK instance, get(), store(), and clear() race on the shared map. Go maps are not safe for concurrent read/write — this can panic or silently corrupt state.

The sibling kasAllowlistCache was fixed in #3898 by adding a sync.Mutex. The same fix should be applied to kasKeyCache.

Details

  • File: sdk/kas_client.go, kasKeyCache struct (line ~422)
  • Methods affected: get(), store(), clear()
  • Fix: Add a sync.Mutex (or sync.RWMutex) and lock in each method, matching the pattern from kasAllowlistCache

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions