Hierarchical Keyring: cold-cache stampede — N concurrent decrypts → N DynamoDB/KMS calls

オープン
#1,663 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
52/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
aws, node.js, typescript
領域
backend, security

調査の方向性

Node Hierarchical Keyring の getBranchKeyMaterials パスから開始し、materials cache がコールドキャッシュの検索をどのように処理するかを追跡します。1 つのブランチキー・バージョンに対する復号または暗号化を同時実行して問題を再現し、in-flight の keystore リクエストが 1 つだけ共有されること、settled エントリが削除されること、失敗したリクエストを再試行できることを確認します。

索引モデルが issue の本文から書いたものです。

説明

Security issue notifications

If you discover a potential security issue in the AWS Encryption SDK we ask that you notify AWS Security via our vulnerability reporting page. Please do not create a public GitHub issue.

Problem:

The Node Hierarchical Keyring doesn't de-dupe concurrent branch-key lookups. If I fire a lot of decrypts for the same branch key at once against a cold cache, they all miss the cache together (it's only filled after the keystore call returns), so each one hits the keystore on its own.

So instead of one lookup I get N DynamoDB GetItem + N KMS Decrypt calls. Easy to repro: await Promise.all of ~3000 decrypts for the same key version, and you see ~3000 keystore calls instead of 1. Encrypt has the same problem since it shares the same code path.

Solution:

Add single-flight to getBranchKeyMaterials: on a miss, the first caller starts the keystore fetch and stores the in-flight promise (keyed by cache entry id); everyone else for the same key awaits that promise instead of starting their own. The entry is dropped once it settles, so the materials cache still owns caching and TTL, and a failed request isn't shared — the next call just retries.

Out of scope:

The legacy caching CMM has the same gap but it's a separate path, so I'm not touching it here.

主要言語
TypeScript
スター
260
フォーク
68
PR マージ指標
30日以内にマージされた PR はありません

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

aws/aws-encryption-sdk-javascript のほかの issue

aws/aws-encryption-sdk-javascript の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。