Skip to content

Prevent crashes with non-Proc on_load callbacks - #1084

Merged
byroot merged 1 commit into
ruby:masterfrom
ydah:fix-on-load-proc-conversion
Sep 30, 2026
Merged

byroot merged 1 commit into
ruby:masterfrom
ydah:fix-on-load-proc-conversion

Conversation

@ydah

@ydah ydah commented Sep 30, 2026

Copy link
Copy Markdown
Member

Passing a Method or an unsupported value as on_load can segfault the C parser:

JSON.parse("[1]", on_load: method(:p))
# => [BUG] Segmentation fault

JSON.parse("[1]", on_load: "x")
# => [BUG] Segmentation fault

JSON::Coder.new(on_load: "x").load("[1]")
# => [BUG] Segmentation fault

parser_config_init_i stores the callback without validating it, and json_push_value passes it directly to rb_proc_call_with_block. Unlike JSON.load, JSON.parse does not convert the callback through to_proc.

Convert non-Proc callbacks through to_proc and validate the result in the shared parser configuration. This covers JSON.parse, JSON::Coder, and ResumableParser. Method callbacks now work, while unsupported values and non-Proc conversion results raise TypeError.

@ydah ydah changed the title Passing a Method or an unsupported value as on_load can segfault the C parser: ruby JSON.parse("[1]", on_load: method(:p)) # => [BUG] Segmentation fault JSON.parse("[1]", on_load: "x") # => [BUG] Segmentation fault JSON::Coder.new(on_load: "x").load("[1]") # => [BUG] Segmentation fault parser_config_init_i stores the callback without validating it, and json_push_value passes it directly to rb_proc_call_with_block. Unlike JSON.load, JSON.parse does not convert the callback through to_proc. Convert non-Proc callbacks through to_proc and validate the result in the shared parser configuration. This covers JSON.parse, JSON::Coder, and ResumableParser. Method callbacks now work, while unsupported values and non-Proc conversion results raise TypeError.Prevent crashes with non-Proc on_load callbacks Prevent crashes with non-Proc on_load callbacks Sep 30, 2026
Convert non-Proc on_load callbacks through to_proc and validate the result in the shared parser configuration. Previously, arbitrary values were stored and passed directly to rb_proc_call_with_block.

Cover Method callbacks in JSON.parse, JSON::Coder, and ResumableParser, along with invalid types, invalid conversion results, and nil or false callbacks.
@byroot
byroot force-pushed the fix-on-load-proc-conversion branch from 965456b to 2494520 Compare September 30, 2026 13:45
@byroot
byroot merged commit 672da19 into ruby:master Sep 30, 2026
42 checks passed
@ydah
ydah deleted the fix-on-load-proc-conversion branch September 30, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants