[ https://issues.apache.org/jira/browse/CASSANDRA-15153?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17416609#comment-17416609 ]
Aleksei Zotov edited comment on CASSANDRA-15153 at 9/17/21, 10:32 AM: ---------------------------------------------------------------------- [~brandon.williams] [~mck] Sorry for bugging you, I'm just wondering whether there are any concerns on getting this merged. If yes, please, let me know, so I can do the necessary changes on the weekend. As far is I understand, there is no need to update CHANGES.txt for bug fixes. However, in this case we updated version of a dependency, does it need to be mentioned somewhere in documentation? was (Author: azotcsit): [~brandon.williams] [~mck] Sorry for bugging you, I'm just wondering whether there are any concerns on getting this merged. If yes, please, let me know, so I can do the necessary changes on the weekend. > Ensure Caffeine cache does not return stale entries > --------------------------------------------------- > > Key: CASSANDRA-15153 > URL: https://issues.apache.org/jira/browse/CASSANDRA-15153 > Project: Cassandra > Issue Type: Bug > Components: Feature/Authorization > Reporter: Per Otterström > Assignee: Aleksei Zotov > Priority: Normal > Labels: security > Fix For: 4.0.x, 4.x > > > Version 2.3.5 of the Caffeine cache that we're using in various places can > hand out stale entries in some cases. This seem to happen when an update > fails repeatedly, in which case Caffeine may return a previously loaded > value. For instance, the AuthCache may hand out permissions even though the > reload operation is failing, see CASSANDRA-15041. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscr...@cassandra.apache.org For additional commands, e-mail: commits-h...@cassandra.apache.org