Motivation
kasKeyCache in sdk/kas_client.go uses a bare map[kasKeyRequest]timeStampedKASInfo with no synchronization. When multiple goroutines call LoadTDF or rewrap concurrently on the same SDK instance, get(), store(), and clear() race on the shared map. Go maps are not safe for concurrent read/write — this can panic or silently corrupt state.
The sibling kasAllowlistCache was fixed in #3898 by adding a sync.Mutex. The same fix should be applied to kasKeyCache.
Details
- File:
sdk/kas_client.go, kasKeyCache struct (line ~422)
- Methods affected:
get(), store(), clear()
- Fix: Add a
sync.Mutex (or sync.RWMutex) and lock in each method, matching the pattern from kasAllowlistCache
Motivation
kasKeyCacheinsdk/kas_client.gouses a baremap[kasKeyRequest]timeStampedKASInfowith no synchronization. When multiple goroutines callLoadTDFor rewrap concurrently on the same SDK instance,get(),store(), andclear()race on the shared map. Go maps are not safe for concurrent read/write — this can panic or silently corrupt state.The sibling
kasAllowlistCachewas fixed in #3898 by adding async.Mutex. The same fix should be applied tokasKeyCache.Details
sdk/kas_client.go,kasKeyCachestruct (line ~422)get(),store(),clear()sync.Mutex(orsync.RWMutex) and lock in each method, matching the pattern fromkasAllowlistCache