Skip to content

fix: coalesce concurrent cache misses - #1711

Draft
lucasmcdonald3 wants to merge 5 commits into
masterfrom
lucmcdon/coalesce-cache-misses
Draft

lucasmcdonald3 wants to merge 5 commits into
masterfrom
lucmcdon/coalesce-cache-misses

Conversation

@lucasmcdonald3

@lucasmcdonald3 lucasmcdonald3 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Issue #, if available: Fixes #1663, fixes #1665. Supersedes #1664 (its commit is included with authorship preserved).

Description of changes:

Coalesce concurrent cache misses in the hierarchical keyring and caching CMM

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Check any applicable:

  • Were any files moved? Moving files changes their URL, which breaks all hyperlinks to the files.

Yosef Bensimchon and others added 5 commits October 6, 2026 19:53
When many encrypt/decrypt operations run concurrently against a cold
cache for the same branch key, each cache miss independently queried the
keystore, firing N DynamoDB GetItem and N KMS Decrypt calls instead of
one. getBranchKeyMaterials now shares a single in-flight request per
cache entry id, evicting it on settle so the cryptographic materials
cache keeps ownership of caching and TTL. A rejected request is evicted
too, so the next call retries rather than sharing the failure.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Track in-flight branch key requests per cache, so keyrings sharing a
cache share requests. Coalesce concurrent caching CMM misses the same
way; waiting encrypts read through the cache so each use counts
against the entry's limits.

Co-authored-by: Yosef Bensimchon <yosef.bensimchon@xero.com>
Copy branch key materials before sharing them with waiting callers, so
a concurrent eviction cannot zero them first. In the caching CMM, let
waiters request in parallel when the response cannot serve them.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant