)]}'
{".zuul.yaml":[{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"2d4eee78384b2c9daeff26276b1fe133c8d3c35d","unresolved":true,"context_lines":[{"line_number":117,"context_line":"        - barbican-grenade:"},{"line_number":118,"context_line":"            voting: false"},{"line_number":119,"context_line":"        - barbican-tempest-plugin-simple-crypto"},{"line_number":120,"context_line":"        - barbican-tempest-plugin-simple-crypto-jammy"},{"line_number":121,"context_line":"        - barbican-tempest-plugin-simple-crypto-secure-rbac"},{"line_number":122,"context_line":"        - barbican-tempest-plugin-simple-crypto-ipv6-only"},{"line_number":123,"context_line":"        - barbican-tox-functional-fips:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"5a5b7a43_ec0d03ea","side":"PARENT","line":120,"updated":"2026-03-05 10:33:57.000000000","message":"Already in https://review.opendev.org/c/openstack/barbican/+/975349","commit_id":"bbc7d50b3640d13d0ae34d04135066703d4fb62f"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"945a063bf33b541dd2fdb3b5ceb667891b04e32d","unresolved":false,"context_lines":[{"line_number":117,"context_line":"        - barbican-grenade:"},{"line_number":118,"context_line":"            voting: false"},{"line_number":119,"context_line":"        - barbican-tempest-plugin-simple-crypto"},{"line_number":120,"context_line":"        - barbican-tempest-plugin-simple-crypto-jammy"},{"line_number":121,"context_line":"        - barbican-tempest-plugin-simple-crypto-secure-rbac"},{"line_number":122,"context_line":"        - barbican-tempest-plugin-simple-crypto-ipv6-only"},{"line_number":123,"context_line":"        - barbican-tox-functional-fips:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"c09c40e2_19862fff","side":"PARENT","line":120,"in_reply_to":"5a5b7a43_ec0d03ea","updated":"2026-03-05 13:17:26.000000000","message":"Thanks, Ivan, but that patchset was not approved yet.  If it gets approved before this one, I\u0027ll send a new patchset removing the change on .zuul.yaml.","commit_id":"bbc7d50b3640d13d0ae34d04135066703d4fb62f"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"40d5506d7deb62e701fbc601ecc94a4a40a953e9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"20610ec5_c17a9e06","updated":"2026-09-18 14:32:09.000000000","message":"recheck","commit_id":"9475b26a56e2a160cc36727a7e4e56efa5a6ce4e"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"3545aa40323959df843dbafe17b17b9da58aa6a7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"da7057a1_ac848172","updated":"2026-09-25 20:55:03.000000000","message":"Thanks Mauricio — in general, this looks like a good fix/approach.\n\nProblem and approach\n\nThe plugin already kept a long-lived caching_session for KEK unwrap/cache, but still opened a new PKCS#11 session for every encrypt/decrypt/generate_symmetric. Under multi-worker load that exhausts HSM session capacity (CKR_DEVICE_MEMORY). Reusing caching_session and serializing with caching_session_lock caps sessions at ~one per worker for the process lifetime, which matches how we should talk to the HSM.\n\nIssues/Concerns:\n\n1. Consider holding caching_session_lock across _load_kek_from_meta_dto + encrypt/decrypt/generate to close the small window where another thread could TTL-expire/destroy the handle between load and use.\n\n2.  session_context() is a nice helper but unused by the changed call paths; either adopt it in the CLI try/finally sites or remove it and the relevant tests for it.\n\n3. Performance.  \n\nThis patch changes the way that the PKCS11 plugin behaves under load.  Now all of the crypto operations within a single thread are serialized - and the locks across the threads are more utilized.  The way that we scale out to increase load capacity is different too.\n\nWe should probably do a performance test to see how the plugin behaves.  We should also revisit any documentation on scale out/tuning to see what needs to change.\n\nAlso, because the locks are more used - its worthwhile doing an analysis to see what deadlocks are possible.  These potential deadlocks may have existed before, but they may become more likely to occur with this patch.","commit_id":"fbe5295d9c85a0369d4c6143b5717ba560570225"}]}
