Skip to content

[pull] master from ruby:master - #1324

Merged
pull[bot] merged 7 commits into
turkdevops:masterfrom
ruby:master
Aug 18, 2026
Merged

[pull] master from ruby:master#1324
pull[bot] merged 7 commits into
turkdevops:masterfrom
ruby:master

Conversation

@pull

@pull pull Bot commented Aug 18, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

peterzhu2118 and others added 7 commits August 18, 2026 16:25
Share a generated source archive across compiler jobs to avoid
repeating checkout and `make up` on every runner.
Keep the longest compiler jobs below 30 minutes after preparing
sources once.
Split compiler configurations into smaller matrix shards so faster
runners can pick up pending work.
… remaining input

A crafted 4-byte length makes read_array and its siblings allocate the
Array.new backing store before reading a single element, so an 8-byte
payload can request gigabytes of memory (HackerOne 3877678, triaged as
hardening). Since every element consumes at least one byte, a count
larger than the remaining input bytes can never be valid. Raise the new
LengthTooLongError instead of allocating, and add the negative length
check that read_hash was missing.

ruby/rubygems@4c16744929

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A custom IO whose `read` returns more bytes than requested makes the
leftover copy in `r_bytes1_buffered` write past the end of `arg->buf`.
7455eb4 fixed the same overread only for `r_byte1_buffered`.
@pull pull Bot locked and limited conversation to collaborators Aug 18, 2026
@pull pull Bot added the ⤵️ pull label Aug 18, 2026
@pull
pull Bot merged commit 53e139e into turkdevops:master Aug 18, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants