Prevent crashes with non-Proc on_load callbacks - #1084
Merged
Merged
Conversation
on_load can segfault the C parser: ruby JSON.parse("[1]", on_load: method(:p)) # => [BUG] Segmentation fault JSON.parse("[1]", on_load: "x") # => [BUG] Segmentation fault JSON::Coder.new(on_load: "x").load("[1]") # => [BUG] Segmentation fault parser_config_init_i stores the callback without validating it, and json_push_value passes it directly to rb_proc_call_with_block. Unlike JSON.load, JSON.parse does not convert the callback through to_proc. Convert non-Proc callbacks through to_proc and validate the result in the shared parser configuration. This covers JSON.parse, JSON::Coder, and ResumableParser. Method callbacks now work, while unsupported values and non-Proc conversion results raise TypeError.Prevent crashes with non-Proc on_load callbacksConvert non-Proc on_load callbacks through to_proc and validate the result in the shared parser configuration. Previously, arbitrary values were stored and passed directly to rb_proc_call_with_block. Cover Method callbacks in JSON.parse, JSON::Coder, and ResumableParser, along with invalid types, invalid conversion results, and nil or false callbacks.
byroot
force-pushed
the
fix-on-load-proc-conversion
branch
from
September 30, 2026 13:45
965456b to
2494520
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Passing a Method or an unsupported value as
on_loadcan segfault the C parser:parser_config_init_istores the callback without validating it, andjson_push_valuepasses it directly torb_proc_call_with_block. UnlikeJSON.load,JSON.parsedoes not convert the callback throughto_proc.Convert non-Proc callbacks through
to_procand validate the result in the shared parser configuration. This coversJSON.parse,JSON::Coder, andResumableParser. Method callbacks now work, while unsupported values and non-Proc conversion results raise TypeError.