Problem
encode, encode_json, decode and decode_verified_complete always release the GIL via py.detach (e.g. rust/src/api.rs:180, :448). For HMAC the whole native operation is ~1 µs, so the release/re-acquire can be a noticeable share of single-threaded latency, while giving little concurrency benefit.
Proposal
Measure detach cost for HS256/384/512. If significant, run HMAC operations (and/or tokens below a size threshold) without releasing the GIL; keep detach for RSA/EC/Ed. Must stay correct for free-threaded Python 3.13t/3.14t.
Acceptance criteria
Files
Branch
issue/<N>-hmac-gil-release from dev
Problem
encode,encode_json,decodeanddecode_verified_completealways release the GIL viapy.detach(e.g.rust/src/api.rs:180,:448). For HMAC the whole native operation is ~1 µs, so the release/re-acquire can be a noticeable share of single-threaded latency, while giving little concurrency benefit.Proposal
Measure
detachcost for HS256/384/512. If significant, run HMAC operations (and/or tokens below a size threshold) without releasing the GIL; keepdetachfor RSA/EC/Ed. Must stay correct for free-threaded Python 3.13t/3.14t.Acceptance criteria
detachfor HS256 encode/decode, single-threaded and multi-threaded (e.g. 8 threads)Files
rust/src/api.rsBranch
issue/<N>-hmac-gil-releasefromdev