[#113407] [Ruby master Feature#19630] [RFC] Deprecate `Kernel.open("|command-here")` due to frequent security issues — "postmodern (Hal Brodigan) via ruby-core" <ruby-core@...>

Issue #19630 has been reported by postmodern (Hal Brodigan).

19 messages 2023/05/05

[#113430] [Ruby master Feature#19633] Allow passing block to `Kernel#autoload` as alternative to second `filename` argument — "shioyama (Chris Salzberg) via ruby-core" <ruby-core@...>

Issue #19633 has been reported by shioyama (Chris Salzberg).

16 messages 2023/05/09

[#113489] [Ruby master Bug#19642] Remove vectored read/write from `io.c`. — "ioquatix (Samuel Williams) via ruby-core" <ruby-core@...>

Issue #19642 has been reported by ioquatix (Samuel Williams).

10 messages 2023/05/15

[#113498] [Ruby master Feature#19644] Module::current to complement Module::nesting — "bughit (bug hit) via ruby-core" <ruby-core@...>

Issue #19644 has been reported by bughit (bug hit).

12 messages 2023/05/16

[#113517] [Ruby master Misc#19679] Migrate Wiki from bugs.ruby-lang.org to ruby/ruby GitHub repository — "jemmai (Jemma Issroff) via ruby-core" <ruby-core@...>

Issue #19679 has been reported by jemmai (Jemma Issroff).

11 messages 2023/05/18

[#113529] [Ruby master Bug#19681] The final classpath of partially named modules is sometimes inconsistent once permanently named — "byroot (Jean Boussier) via ruby-core" <ruby-core@...>

Issue #19681 has been reported by byroot (Jean Boussier).

34 messages 2023/05/19

[#113538] [Ruby master Feature#19682] ability to get a reference to the "default definee" — "bughit (bug hit) via ruby-core" <ruby-core@...>

Issue #19682 has been reported by bughit (bug hit).

28 messages 2023/05/19

[#113601] [Ruby master Bug#19687] Should a development version of the standard library be included in ruby/ruby? — "jaruga (Jun Aruga) via ruby-core" <ruby-core@...>

Issue #19687 has been reported by jaruga (Jun Aruga).

9 messages 2023/05/23

[#113632] [Ruby master Bug#19691] Case insensitive file systems, require filename casing — "MSP-Greg (Greg L) via ruby-core" <ruby-core@...>

Issue #19691 has been reported by MSP-Greg (Greg L).

7 messages 2023/05/24

[#113656] [Ruby master Misc#19693] Data initialization is significantly slower than Struct — janosch-x via ruby-core <ruby-core@...>

Issue #19693 has been reported by janosch-x (Janosch M=FCller).

13 messages 2023/05/25

[#113660] [Ruby master Feature#19694] Add Regexp#timeout= setter — "aharpole (Aaron Harpole) via ruby-core" <ruby-core@...>

Issue #19694 has been reported by aharpole (Aaron Harpole).

15 messages 2023/05/25

[#113676] [Ruby master Bug#19697] Resolv::DNS resolution for international domains fails with "Encoding::CompatibilityError: incompatible character encodings: UTF-8 and ASCII-8BIT" — "clairity (claire c) via ruby-core" <ruby-core@...>

SXNzdWUgIzE5Njk3IGhhcyBiZWVuIHJlcG9ydGVkIGJ5IGNsYWlyaXR5IChjbGFpcmUgYykuDQ0K

6 messages 2023/05/27

[ruby-core:113697] [Ruby master Feature#19694] Add Regexp#timeout= setter

From: janosch-x via ruby-core <ruby-core@...>
Date: 2023-05-29 22:23:13 UTC
List: ruby-core #113697
Issue #19694 has been updated by janosch-x (Janosch M=FCller).





I think it is better if no code can mutate the timeout of the Regexps that =
are passed into it, even if that affected only dupped or non-literal Regexp=
s.



If it is really necessary to set custom timeouts on literals, maybe somethi=
ng like this could work:



```ruby

regexp =3D Regexp.with_timeout(2.0) { /foo/ }

regexp.timeout # =3D> 2.0

```



----------------------------------------

Feature #19694: Add Regexp#timeout=3D setter

https://bugs.ruby-lang.org/issues/19694#change-103343



* Author: aharpole (Aaron Harpole)

* Status: Open

* Priority: Normal

----------------------------------------

# Abstract



In addition to allowing for a Regexp timeout to be set on individual instan=
ces by setting a `timeout` argument in `Regexp.new`, I'm proposing that we =
also allow setting the timeout on Regexp objects with a `#timeout=3D` sette=
r.



# Background



To be able to roll out a global Regexp timeout for a large application, the=
re are inevitably some individual regexes for which a different timeout is =
appropriate. While the `timeout` keyword argument was added to `Regexp.new`=
, this isn't always a viable option.



In the case of regex literal syntax (`/ab*/` or `%r{ab*}`, for instance), i=
t's not possible to set a timeout at all right now without converting to `R=
egexp.new`, which may be awkward depending on the contents of the regex.



It also is desirable from time to time to be able to set a timeout for a re=
gex object after it's been initialized.



Finally, because we offer a `Regexp#timeout` getter, for consistency it wou=
ld be nice to also offer a setter.



The introduction of a `Regexp#timeout=3D` setter was mentioned as a possibl=
e way to set individual timeouts in https://bugs.ruby-lang.org/issues/19104=
#Specification.



# Proposal



I propose that we add the method `Regexp#timeout=3D`. It works the same way=
 the `timeout` argument works in `Regexp.new`, taking either a float or nil.



This makes it relatively easy to add timeouts to specific regex literals (r=
egex literals are frozen by default so you do have to `dup` them first):



```

emoji_filter_pattern =3D %r{

  (?<!#{Regexp.quote(ZERO_WIDTH_JOINER)})

  #{EmojiFilter.unicodes_pattern}

  (?!#{Regexp.union(EmojiFilter::MODIFIER_CHAR_MAP.keys.map { |k| Regexp.qu=
ote k })})

}x.dup

emoji_filter_pattern.timeout =3D 1.0

emoji_filter_pattern.freeze

```



# Implementation



This setter has been implemented in https://github.com/ruby/ruby/pull/7847.



# Evaluation



It's just a setter, so pretty straightforward in terms of implementation an=
d use.



# Discussion



It's worth considering other options for overriding `Regexp.timeout`. I'd l=
ove to see something like the following for overriding regexp timeouts as w=
ell:



```

Regexp.timeout =3D 1.0



Regexp.with_timeout(5.0) do

  evaluate_slower_regexes

end

```



It's possible to implement something like `Regexp.with_timeout` but it's no=
t thread-safe by default since it would involve overwriting `Regexp.timeout=
`.



# Summary



Regexp instances have a getter for timeout, and adding a corresponding sett=
er adds consistency and will make it easier for developers to adopt adding =
a global `Regexp.timeout` by making it simpler to adjust timeouts on a rege=
x by regex basis.



It's a minor change but the added consistency and flexibility help us optim=
ize for developer happiness.







--=20

https://bugs.ruby-lang.org/

 ______________________________________________
 ruby-core mailing list -- ruby-core@ml.ruby-lang.org
 To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org
 ruby-core info -- https://ml.ruby-lang.org/mailman3/postorius/lists/ruby-c=
ore.ml.ruby-lang.org/

In This Thread