GoSeverity: LowStatus: Triaged
Non-deterministic result from role policies due to cache collision
Public issue opened by the maintainer and labelled as a bug (kind/bug), crediting ucsurf for the report. When a role policy has two resource entries that both match the requested kind, their first rules get the same cache key, so the second entry’s condition reuses the first entry’s cached result and is never evaluated. Tracked as a bug, not a security advisory. Open.