cachekit-rs: v0.9.0
Immutable
release. Only release title and notes can be modified.
0.9.0 (2026-10-02)
⚠ BREAKING CHANGES
- encryption: the raw-bytes master-key APIs (
EncryptionLayer::new,EncryptionLayer::with_previous_keys,CacheKitBuilder::encryption_from_bytesandCacheKitBuilder::encryption_from_bytes_with_previous) now require keys of exactly 32 bytes, current and previous, and returnCachekitError::Configfor any other length. Callers that pass longer keys to a raw-bytes API, including hex keys decoded manually, now get an error at construction. Use exactly 32-byte keys, the only length every SDK accepts (openssl rand -hex 32), or pass the hex string to.encryption()or useCacheKit::from_env(). - interop: an interop namespace or operation containing
..now fails:interop_keyreturnsInvalidKey, and#[cachekit]does not compile. Rename the segment; its keys become a full cache miss.
Bug Fixes
- cachekitio: reject the empty cache key; test path encoding from the protocol fixture (LAB-6551) (#100) (4d11fc1)
- encryption: raw-bytes master keys must be exactly 32 bytes (LAB-4663) (#103) (f85d121)
- file: return a miss for entries with nonzero flags or reserved bytes (LAB-7153) (#107) (6d48ece)
- intents: secure_from_env reads CACHEKIT_PREVIOUS_MASTER_KEYS (LAB-6591) (#102) (dda7f42)
- interop: reject double-dot interop segments (LAB-5906) (#98) (8480457)
- l1: honour X-CacheKit-Freshness and Fresh-For before backfilling L1 (LAB-7155) (#109) (658b198)
- redis: set a 5 s command timeout on the fred client (LAB-7154) (#108) (72db7c7)
Performance Improvements
- bench: instruction-gated hot-path bench and a client wall-time probe (LAB-7057) (#110) (d561d70)
- file: stripe the in-process lock per key so reads skip unrelated fsyncs (LAB-7086) (#106) (e9980df)
- file: sweep orphaned temp files on first set, not on build (LAB-7381) (#113) (222a916)
Dependencies
- The following workspace dependencies were updated
- dependencies
- cachekit-macros bumped from 0.8.0 to 0.9.0
- dependencies