[#113756] [Ruby master Bug#19711] NoMethodError "private method `new' called for class" since bebd05fb51ea65bc57344b67100748200f8311eb — "yahonda (Yasuo Honda) via ruby-core" <ruby-core@...>

Issue #19711 has been reported by yahonda (Yasuo Honda).

7 messages 2023/06/05

[#113771] [Ruby master Feature#19712] IO#reopen removes singleton class — "itarato (Peter Arato) via ruby-core" <ruby-core@...>

Issue #19712 has been reported by itarato (Peter Arato).

11 messages 2023/06/05

[#113782] [Ruby master Bug#19716] SystemStackError occurs too easily on Alpine Linux (due to small stack size reported by pthread_attr_getstacksize on musl libc) — "alexdowad (Alex Dowad) via ruby-core" <ruby-core@...>

Issue #19716 has been reported by alexdowad (Alex Dowad).

6 messages 2023/06/07

[#113788] [Ruby master Bug#19717] `ConditionVariable#signal` is not fair when the wakeup is consistently spurious. — "ioquatix (Samuel Williams) via ruby-core" <ruby-core@...>

Issue #19717 has been reported by ioquatix (Samuel Williams).

13 messages 2023/06/07

[#113819] [Ruby master Feature#19720] Warning for non-linear Regexps — "Eregon (Benoit Daloze) via ruby-core" <ruby-core@...>

Issue #19720 has been reported by Eregon (Benoit Daloze).

11 messages 2023/06/08

[#113835] [Ruby master Misc#19722] DevMeeting-2023-07-13 — "mame (Yusuke Endoh) via ruby-core" <ruby-core@...>

Issue #19722 has been reported by mame (Yusuke Endoh).

9 messages 2023/06/09

[#113944] [Ruby master Feature#19737] Add `IO::Buffer#cat` for concat `IO::Buffer` instances — "unasuke (Yusuke Nakamura) via ruby-core" <ruby-core@...>

Issue #19737 has been reported by unasuke (Yusuke Nakamura).

7 messages 2023/06/19

[#113953] [Ruby master Bug#19739] Key cannot be found in a Hash when slice! method is applied to the key — "ilya.andreyuk (Ilya Andreyuk) via ruby-core" <ruby-core@...>

Issue #19739 has been reported by ilya.andreyuk (Ilya Andreyuk).

9 messages 2023/06/20

[#113966] [Ruby master Bug#19742] Introduce `Module#anonymous?` — "ioquatix (Samuel Williams) via ruby-core" <ruby-core@...>

Issue #19742 has been reported by ioquatix (Samuel Williams).

47 messages 2023/06/21

[#114025] [Ruby master Feature#19744] Namespace on read — "tagomoris (Satoshi TAGOMORI) via ruby-core" <ruby-core@...>

Issue #19744 has been reported by tagomoris (Satoshi TAGOMORI).

71 messages 2023/06/27

[#114032] [Ruby master Misc#19747] Propose Kevin Newton and Jemma Issroff as core committers — "k0kubun (Takashi Kokubun) via ruby-core" <ruby-core@...>

Issue #19747 has been reported by k0kubun (Takashi Kokubun).

8 messages 2023/06/28

[#114038] [Ruby master Bug#19749] Confirm correct behaviour when attaching private method with `#define_method` — "itarato (Peter Arato) via ruby-core" <ruby-core@...>

Issue #19749 has been reported by itarato (Peter Arato).

15 messages 2023/06/28

[ruby-core:113848] [Ruby master Feature#19694] Add Regexp#timeout= setter

From: "Eregon (Benoit Daloze) via ruby-core" <ruby-core@...>
Date: 2023-06-09 10:00:16 UTC
List: ruby-core #113848
Issue #19694 has been updated by Eregon (Benoit Daloze).





janosch-x (Janosch M=FCller) wrote in #note-9:

> A custom `timeout` only being available on `Regexp::new` might lead peopl=
e to write less performant code.



I think it is very well known and easy to know though profiling that one sh=
ould always cache the result of `Regexp.new` (e.g., in a constant).

The docs should point this out though.



> I'm not sure this is a strong argument. The big Regexps that take a notew=
orthy time to compile are often those with interpolation, as seen in the OP=
, and I assume these aren't so easy to pre-compile or deduplicate anyway.



Actually TruffleRuby inline-caches interpolated Regexp creation, so if it's=
 the same pattern then the same Regexp is used.

In the OP's case it seems easy to store the Regexp in a constant.



> Maybe there could be an instance method, `Regexp#with_timeout`, that crea=
tes *and memoizes* a copy with a specific timeout? This also sounds a bit h=
acky, though...



I think timeouts are inefficient and insufficient to address ReDoS. IMO the=
 real solution is #19720.



----------------------------------------

Feature #19694: Add Regexp#timeout=3D setter

https://bugs.ruby-lang.org/issues/19694#change-103497



* Author: aharpole (Aaron Harpole)

* Status: Open

* Priority: Normal

----------------------------------------

# Abstract



In addition to allowing for a Regexp timeout to be set on individual instan=
ces by setting a `timeout` argument in `Regexp.new`, I'm proposing that we =
also allow setting the timeout on Regexp objects with a `#timeout=3D` sette=
r.



# Background



To be able to roll out a global Regexp timeout for a large application, the=
re are inevitably some individual regexes for which a different timeout is =
appropriate. While the `timeout` keyword argument was added to `Regexp.new`=
, this isn't always a viable option.



In the case of regex literal syntax (`/ab*/` or `%r{ab*}`, for instance), i=
t's not possible to set a timeout at all right now without converting to `R=
egexp.new`, which may be awkward depending on the contents of the regex.



It also is desirable from time to time to be able to set a timeout for a re=
gex object after it's been initialized.



Finally, because we offer a `Regexp#timeout` getter, for consistency it wou=
ld be nice to also offer a setter.



The introduction of a `Regexp#timeout=3D` setter was mentioned as a possibl=
e way to set individual timeouts in https://bugs.ruby-lang.org/issues/19104=
#Specification.



# Proposal



I propose that we add the method `Regexp#timeout=3D`. It works the same way=
 the `timeout` argument works in `Regexp.new`, taking either a float or nil.



This makes it relatively easy to add timeouts to specific regex literals (r=
egex literals are frozen by default so you do have to `dup` them first):



```

emoji_filter_pattern =3D %r{

  (?<!#{Regexp.quote(ZERO_WIDTH_JOINER)})

  #{EmojiFilter.unicodes_pattern}

  (?!#{Regexp.union(EmojiFilter::MODIFIER_CHAR_MAP.keys.map { |k| Regexp.qu=
ote k })})

}x.dup

emoji_filter_pattern.timeout =3D 1.0

emoji_filter_pattern.freeze

```



# Implementation



This setter has been implemented in https://github.com/ruby/ruby/pull/7847.



# Evaluation



It's just a setter, so pretty straightforward in terms of implementation an=
d use.



# Discussion



It's worth considering other options for overriding `Regexp.timeout`. I'd l=
ove to see something like the following for overriding regexp timeouts as w=
ell:



```

Regexp.timeout =3D 1.0



Regexp.with_timeout(5.0) do

  evaluate_slower_regexes

end

```



It's possible to implement something like `Regexp.with_timeout` but it's no=
t thread-safe by default since it would involve overwriting `Regexp.timeout=
`.



# Summary



Regexp instances have a getter for timeout, and adding a corresponding sett=
er adds consistency and will make it easier for developers to adopt adding =
a global `Regexp.timeout` by making it simpler to adjust timeouts on a rege=
x by regex basis.



It's a minor change but the added consistency and flexibility help us optim=
ize for developer happiness.







--=20

https://bugs.ruby-lang.org/

 ______________________________________________
 ruby-core mailing list -- ruby-core@ml.ruby-lang.org
 To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org
 ruby-core info -- https://ml.ruby-lang.org/mailman3/postorius/lists/ruby-c=
ore.ml.ruby-lang.org/

In This Thread