From: Tomoyuki Chikanaga Date: 2013-05-14T23:42:51+09:00 Subject: [ANN] Ruby 2.0.0-p195 is released (includes a security fix) --047d7b34336063f71404dcae8a6d Content-Type: text/plain; charset=ISO-8859-1 Hello, Rubyists Ruby 2.0.0-p195 is released. This is the first patchlevel release of 2.0.0. http://www.ruby-lang.org/en/news/2013/05/14/ruby-2-0-0-p195-is-released/ This release include a security fix of Ruby DL/Fiddle extension. * Object taint bypassing in DL and Fiddle in Ruby (CVE-2013-2065) http://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/ And there're many bug-fixes and some optimization, and documentation fixes. # Downloads ftp://ftp.ruby-lang.org/pub/ruby/2.0/ruby-2.0.0-p195.tar.bz2 SIZE: 10807456 bytes MD5: 2f54faea6ee1ca500632ec3c0cb59cb6 SHA256: 0be32aef7a7ab6e3708cc1d65cd3e0a99fa801597194bbedd5799c11d652eb5b ftp://ftp.ruby-lang.org/pub/ruby/2.0/ruby-2.0.0-p195.tar.gz SIZE: 13641558 bytes MD5: 0672e5af309ae99d1703d0e96eff8ea5 SHA256: a2fe8d44eac3c27d191ca2d0ee2d871f9aed873c74491b2a8df229bfdc4e5a93 ftp://ftp.ruby-lang.org/pub/ruby/2.0/ruby-2.0.0-p195.zip SIZE: 15092199 bytes MD5: 924fe4bea72b1b258655211998631791 SHA256: 81a4dc6cc09e491d417a51e5983c4584eff849e2a186ec3affdbe5bc15cd7db5 # Changes Major fixes are below. See ChangeLog or Tickets for details. https://bugs.ruby-lang.org/projects/ruby-200/issues?set_filter=1&status_id=5 Thank you all committers/contributors. ## Core - prepend #7841 Module#prepend now detect cyclic prepend. #7843 removing prepended methods causes exceptions. #8357 Module#prepend breaks Module's comparison operators. #7983 Module#prepend can't override Fixnum's operator methods. #8005 methods made private/protected after definition become uncallable on prepended class. #8025 Module#included_modules include classes when prepended. ## Core - keyword arguments #7922 unnamed keyword rest argument cause SyntaxError. #7942 support define method only receive keyword arguments without paren. #8008 fix a bug in super with keyword arguments. #8236 fix a treatment of rest arguments and keyword arguments through `super'. #8260 non-symbol key should not treated as keyword arguments. ## Core - refinements #7925 fix a bug of refinements with a method call super in a block. ## Core - GC #8092 improve accuracy of GC.stat[:heap_live_num] #8146 avoid unnecessary heap growth. #8145 fix unlimited memory growth with large values of RUBY_FREE_MIN. ## Core - Regexp #7972 Regexp POSIX space class is location sensitive. #7974 Regexp case-insensitive group doesn't work. #8023 Regexp lookbehind assertion fails with /m mode enabled #8001 Regexp \Z matches where it shouldn't ## Core - other #8063 fix a potential memory violation and avoid abort on the environment _FORTIFY_SOURCE=2 (ex. Ubuntu). #8175 ARGF#skip doesn't work as documented. #8069 File.expand_path('something', '~') now support home path on Windows. #8220 fix a Segmentation fault when defined? (). #8367 fix a regression in defined?(super). #8283 Dir.glob doesn't recurse hidden directories. #8165 fix a bug of multiple require with non-ascii file path. #8290 fix an incompatible String#inspect behavior with NUL character. #8360 fix a Segmentation fault of Thread#join(Float::INFINITY) on some platforms. ## RubyGems Bundled RubyGems version is updated to 2.0.2+ #7698 fix an rubygems' incompatibility about installation of extension libraries. #8019 fix a bug of gem list --remote doesn't work. ## Libraries #7911 File.fnmatch with US-ASCII pattern and UTF-8 path raise an exception. #8240 fix a bug about OpenSSL::SSL::SSLSocket breaks other connections or files on GC. #8183 CGI.unescapeHTML can't decode Numeric Character References with uppercase (&#Xnnnn). ## Build/Platform specific. #7830 fix build failure with compiler warning. #7950 fix a build failure on mswin/VC with --with-static-linked-ext. Regards, -- Tomoyuki Chikanaga --047d7b34336063f71404dcae8a6d Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
Hello, Rubyists

Ruby 2= .0.0-p195 is released. This is the first patchlevel release of 2.0.0.
=
http://www.ruby-lang.org/en/news/2013/05/14/ruby-2-0-0-p195-= is-released/

This release include a security fix of Ruby DL/Fi= ddle extension.
* Object taint bypassing in DL and Fiddle in Ruby= (CVE-2013-2065)
=A0=A0http://www.ruby-lang.or= g/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/

And there're many bug-fixes and some optimization, = and documentation fixes.

# Downloads
ftp://ftp.ruby-lang.org/pub/ruby/2.0/ruby-2.0.0-p195.tar.bz2<= /div>
=A0 SIZE: =A0 10807456 bytes
=A0 MD5: =A0 =A02f54faea6ee1ca5= 00632ec3c0cb59cb6
=A0 SHA256: 0be32aef7a7ab6e3708cc1d65cd3e0a99fa= 801597194bbedd5799c11d652eb5b

ftp://ftp.ruby-lang.org= /pub/ruby/2.0/ruby-2.0.0-p195.tar.gz
=A0 SIZE: =A0 13641558 bytes
=A0 MD5: =A0 =A00672e5af309ae99= d1703d0e96eff8ea5
=A0 SHA256: a2fe8d44eac3c27d191ca2d0ee2d871f9ae= d873c74491b2a8df229bfdc4e5a93

ftp://ftp.ruby-lang.org/pu= b/ruby/2.0/ruby-2.0.0-p195.zip
=A0 SIZE: =A0 15092199 bytes
=A0 MD5: =A0 =A0924fe4bea72b1b2= 58655211998631791
=A0 SHA256: 81a4dc6cc09e491d417a51e5983c4584eff= 849e2a186ec3affdbe5bc15cd7db5

# Changes
=
Major fixes are below. See ChangeLog or Tickets for details.
https://bugs.ruby-lang.org/projects/ruby-200/issues= ?set_filter=3D1&status_id=3D5

Thank you all committers/contributors.

## Core - prepend
=A0 #7841 Module#prepend now detect cy= clic prepend.
=A0 #7843 removing prepended methods causes excepti= ons.
=A0 #8357 Module#prepend breaks Module's comparison operators.
=A0 #7983 Module#prepend can't override Fixnum's operator me= thods.
=A0 #8005 methods made private/protected after definition = become uncallable on
=A0 =A0 =A0 =A0 prepended class.
=A0 #8025 Module#included_m= odules include classes when prepended.

## Core - k= eyword arguments
=A0 #7922 unnamed keyword rest argument cause Sy= ntaxError.
=A0 #7942 support define method only receive keyword arguments without= paren.
=A0 #8008 fix a bug in super with keyword arguments.
=A0 #8236 fix a treatment of rest arguments and keyword arguments thr= ough `super'.
=A0 #8260 non-symbol key should not treated as keyword arguments.

## Core - refinements
=A0 #7925 fix a bug of= refinements with a method call super in a block.

## Core - GC
=A0 #8092 improve accuracy of GC.stat[:heap_live_num= ]
=A0 #8146 avoid unnecessary heap growth.
=A0 #8145 = =A0fix unlimited memory growth with large values of RUBY_FREE_MIN.

## Core - Regexp
=A0 #7972 Regexp POSIX space class is= location sensitive.
=A0 #7974 Regexp case-insensitive group does= n't work.
=A0 #8023 Regexp lookbehind assertion fails with /m= mode enabled
=A0 #8001 Regexp \Z matches where it shouldn't

## Core - other
=A0 #8063 fix a potential memory violation = and avoid abort on the environment
=A0 =A0 =A0 =A0 _FORTIFY_SOURC= E=3D2 (ex. Ubuntu).
=A0 #8175 ARGF#skip doesn't work as documented.
=A0 #806= 9 File.expand_path('something', '~') now support home path = on Windows.
=A0 #8220 fix a Segmentation fault when defined? ().<= /div>
=A0 #8367 fix a regression in defined?(super).
=A0 #8283 Dir= .glob doesn't recurse hidden directories.
=A0 #8165 fix a bug= of multiple require with non-ascii file path.
=A0 #8290 fix an i= ncompatible String#inspect behavior with NUL character.
=A0 #8360 fix a Segmentation fault of Thread#join(Float::INFINITY) on = some
=A0 =A0 =A0 =A0 platforms.

## RubyG= ems
=A0 Bundled RubyGems version is updated to 2.0.2+
= =A0 #7698 fix an rubygems' incompatibility about installation of extens= ion
=A0 =A0 =A0 =A0 libraries.
=A0 #8019 fix a bug of gem list -= -remote doesn't work.

## Libraries
= =A0 #7911 File.fnmatch with US-ASCII pattern and UTF-8 path raise an except= ion.
=A0 #8240 fix a bug about OpenSSL::SSL::SSLSocket breaks other connect= ions or files on GC.
=A0 #8183 CGI.unescapeHTML can't decode = Numeric Character References with uppercase (&#Xnnnn).

## Build/Platform specific.
=A0 #7830 fix build failure with= compiler warning.
=A0 #7950 fix a build failure on mswin/VC with= --with-static-linked-ext.

Regards,

--
Tomoyuki Chikanaga <nagachika@ruby-lang.org>
--047d7b34336063f71404dcae8a6d--