[#70977] [Ruby trunk - Feature #11473] Immutable String literal in Ruby 3 — arai@...
Issue #11473 has been updated by Shunichi Arai.
3 messages
2015/10/04
[#70982] limiting scope of magic comments like frozen_string_literal — Eric Wong <normalperson@...>
How about being able to limit the scope of magic comments like
4 messages
2015/10/05
[#71062] [Ruby trunk - Bug #10892] Deadlock in autoload — eregontp@...
Issue #10892 has been updated by Benoit Daloze.
4 messages
2015/10/12
[#71090] Re: [Ruby trunk - Bug #10892] Deadlock in autoload
— Eric Wong <normalperson@...>
2015/10/14
eregontp@gmail.com wrote:
[#71127] [Ruby trunk - Feature #11607] [PATCH] fiddle: release GVL for ffi_call — normalperson@...
Issue #11607 has been updated by Eric Wong.
3 messages
2015/10/20
[#71164] [Ruby trunk - Feature #11614] [Open] [RFC] use id_table for constant tables — normalperson@...
Issue #11614 has been reported by Eric Wong.
3 messages
2015/10/22
[#71211] [Ruby trunk - Feature #11607] [PATCH] fiddle: release GVL for ffi_call — naruse@...
Issue #11607 has been updated by Yui NARUSE.
6 messages
2015/10/27
[#71212] Re: [Ruby trunk - Feature #11607] [PATCH] fiddle: release GVL for ffi_call
— Eric Wong <normalperson@...>
2015/10/27
Yes, user must check if the function is MT-safe. Probably fine
[#71246] Re: [Ruby trunk - Feature #11607] [PATCH] fiddle: release GVL for ffi_call
— Aaron Patterson <tenderlove@...>
2015/10/28
On Tue, Oct 27, 2015 at 08:54:07AM +0000, Eric Wong wrote:
[#71254] Re: [Ruby trunk - Feature #11607] [PATCH] fiddle: release GVL for ffi_call
— Eric Wong <normalperson@...>
2015/10/28
Aaron Patterson <tenderlove@ruby-lang.org> wrote:
[#71230] [Ruby trunk - Feature #11625] Unlock GVL for SHA1 calculations — tenderlove@...
Issue #11625 has been updated by Aaron Patterson.
5 messages
2015/10/27
[#71236] Re: [Ruby trunk - Feature #11625] Unlock GVL for SHA1 calculations
— Юрий Соколов <funny.falcon@...>
2015/10/28
What's about other hashsum algos? MD5, SHA2, etc
[#71242] Re: [Ruby trunk - Feature #11625] Unlock GVL for SHA1 calculations
— Eric Wong <normalperson@...>
2015/10/28
Юрий Соколов <funny.falcon@gmail.com> wrote:
[#71239] [Ruby trunk - Bug #11384] multi-threaded autoload sometimes fails — shugo@...
Issue #11384 has been updated by Shugo Maeda.
4 messages
2015/10/28
[ruby-core:71018] [Ruby trunk - Feature #7846] [Closed] [ext/openssl] Disable TLS/SSL compression by default?
From:
zzak@...
Date:
2015-10-08 05:28:25 UTC
List:
ruby-core #71018
Issue #7846 has been updated by Zachary Scott. Status changed from Assigned to Closed Completed in r45274: https://github.com/ruby/ruby/commit/699b209cf8cf11809620e12985ad33ae33b119ee ---------------------------------------- Feature #7846: [ext/openssl] Disable TLS/SSL compression by default? https://bugs.ruby-lang.org/issues/7846#change-54392 * Author: Martin Bosslet * Status: Closed * Priority: Normal * Assignee: openssl ---------------------------------------- I'd like to disable TLS compression for all TLS connections by default using SSL_OP_NO_COMPRESSION to effectively disable CRIME-like attacks [1]. The patch would be relatively easy to write, but I'm aware that I'm well beyond the deadline for implementing new features. I'm sorry I couldn't raise this issue earlier, but I still feel this is something that should make it into 2.0.0 because - We already included a similar fix to prevent the BEAST attack. CRIME is its logical descendant, so it would be only consequent to prevent it by default, too. - If it's not added now, somebody else outside ruby-core might report it in the future anyway :) I have to admit that I'm not sure if this could negatively affect any existing installations, though. It shouldn't, as this is normally a completely transparent feature that nobody should explicitly rely on, but of course, I can't give any guarantees. What do you think, may I still implement this for 2.0.0? If accepted, please reassign to me! [1] http://comments.gmane.org/gmane.comp.encryption.openssl.devel/21638 -- https://bugs.ruby-lang.org/