From: "himura467 (Akito Shitara) via ruby-core" Date: 2026-07-14T13:52:25+00:00 Subject: [ruby-core:126085] [Ruby Bug#22195] IO::Buffer read after free silently returns empty data instead of raising Issue #22195 has been updated by himura467 (Akito Shitara). PR: https://github.com/ruby/ruby/pull/17862 ---------------------------------------- Bug #22195: IO::Buffer read after free silently returns empty data instead of raising https://bugs.ruby-lang.org/issues/22195#change-118088 * Author: himura467 (Akito Shitara) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN ---------------------------------------- Reading from an `IO::Buffer` after calling `#free` does not raise. It behaves like an empty buffer: ```ruby buffer = IO::Buffer.for("Hello World") buffer.free buffer.get_string # => "" (no error) ``` ## Why this looks like an unintended regression Originally (https://github.com/ruby/ruby/commit/e30920354f, Ruby 3.1���3.3), accessing a freed buffer raised `IO::Buffer::AllocationError` ("The buffer is not allocated!"). https://github.com/ruby/ruby/commit/c5cf4d4e12 made zero-length buffer operations succeed instead of raising, for [Bug #19542] and [Bug #18805]. Since a freed buffer also has `base == NULL, size == 0`, it was caught in the same code path and stopped raising too. Neither ticket mentions freed buffers, so this appears to be an accidental side effect rather than a decision. Note that the rdoc of `#free` still promises that access after free raises. ## Proposal How about marking a buffer internally as freed when its memory is released, so that: * Any byte access raises `IO::Buffer::AllocationError` again, restoring the pre-3.4 documented behavior. * `#resize` re-allocates and clears the mark, as `#free`'s rdoc promises ("You can resize a freed buffer to re-allocate it"). * The zero-length buffer semantics from https://github.com/ruby/ruby/pull/9532 are preserved. -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/