Repository navigation
Egress gateway no longer fetches an actor's egress policy twice when requests race - #2095
Merged
Lior Lieberman (LiorLieberman) merged 1 commit intoOct 1, 2026
Conversation
policyCache.get checks for a live entry and then joins any in-flight fetch through singleflight, but the two steps are not atomic. When the in-flight fetch stores its entry and finishes between them, the caller starts a second fetch from ateapi. TestPolicyCacheFetchOutlivesCanceledCaller asserts a single fetch and failed about once in 300 runs under -race. Look the entry up again at the start of the shared fetch, so a late caller reuses the one that just landed, and move the lookup into a cached helper that both paths use.
Max Thompson (thompsonmax)
marked this pull request as ready for review
October 1, 2026 23:03
Max Thompson (thompsonmax)
requested a review
from Lior Lieberman (LiorLieberman)
October 1, 2026 23:04
Lior Lieberman (LiorLieberman)
approved these changes
Oct 1, 2026
Lior Lieberman (LiorLieberman)
left a comment
Collaborator
There was a problem hiding this comment.
thanks Max Thompson (@thompsonmax) !
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The egress gateway's policy cache checks for a cached entry and then joins any in-flight fetch, and the two steps aren't atomic. If the in-flight fetch stores its result in between, the caller starts a second, redundant fetch from ateapi.
TestPolicyCacheFetchOutlivesCanceledCallerasserts a single fetch, so it fails intermittently (about 1 in 300 runs under-race; seen on #1961).cachedhelper that both the fast path and the shared fetch use.The only behavior change is skipping the duplicate fetch.
Testing: with the fix, the existing test passed 2000 of 2000 runs under
-race. E2E hasn't run locally.