mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
BlossomReadAuthTokenProvider.header() reads the token cache, then signOnce() reads the in-flight map — two separate reads. A leader caches its token before retiring its in-flight entry, so a caller sitting between those two reads sees an empty cache (its read came first) and an empty in-flight map (the leader already finished), and signs a second token for the same host. A 300ms test signer never opens that window, which is why the provider's own concurrency test missed it. A local in-process key signs in microseconds, so BlossomReadAuthFetcherTest.aBurstOf401sSharesOneSignature — 16 fetchers that all 401 and all retry — hit it and intermittently saw two distinct tokens. signOnce() now takes a second look at the cache once it finds no in-flight entry: an absent entry proves the leader's cache write is already visible, so the straggler reuses that token instead of starting another signature. Covered by a new aFastSignerStillSharesOneSignature, which runs the 16-caller burst against an instant signer over many rounds — the existing test's slow signer cannot reach the window. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011APd48WJ5pZVK4Ltpj3YpL