Skip to content

Prevent crashes with non-Proc as_json callbacks - #1083

Merged
byroot merged 1 commit into
ruby:masterfrom
ydah:fix-as-json-proc-conversion
Sep 30, 2026
Merged

byroot merged 1 commit into
ruby:masterfrom
ydah:fix-as-json-proc-conversion

Conversation

@ydah

@ydah ydah commented Sep 30, 2026

Copy link
Copy Markdown
Member

Passing a Method as as_json, such as as_json: method(:serialize), can segfault in the C extension:

JSON.generate(Object.new, strict: true, as_json: 1.method(:+))
# => [BUG] Segmentation fault

rb_convert_type(..., T_DATA, "Proc", "to_proc") accepts any T_DATA object without calling to_proc. Method and other unrelated objects can therefore reach rb_proc_arity or rb_proc_call_with_block as though they were Procs.

Convert non-Proc callbacks through to_proc and validate the result in both option configuration and State#as_json=. Method callbacks are now converted correctly, while unsupported values and non-Proc conversion results raise TypeError.

The reproduction above now raises a normal ArgumentError because + accepts one argument and the callback receives two.

Convert non-Proc callbacks through to_proc and validate the result in both configuration and the as_json setter. rb_convert_type accepts unrelated T_DATA objects without conversion, allowing them to reach Proc APIs and crash.

Cover Method callbacks, invalid callback types, and to_proc returning a non-Proc object.
@byroot
byroot merged commit f5c889d into ruby:master Sep 30, 2026
42 checks passed
@ydah
ydah deleted the fix-as-json-proc-conversion branch September 30, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants