From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on starla X-Spam-Level: X-Spam-Status: No, score=0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_BL_SPAMCOP_NET,SPF_HELO_PASS, SPF_PASS autolearn=no autolearn_force=no version=3.4.6 Received: from nue.mailmanlists.eu (nue.mailmanlists.eu [94.130.110.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by dcvr.yhbt.net (Postfix) with ESMTPS id 135CB1F4CC for ; Fri, 20 Dec 2024 03:16:24 +0000 (UTC) Authentication-Results: dcvr.yhbt.net; dkim=pass (1024-bit key; unprotected) header.d=ml.ruby-lang.org header.i=@ml.ruby-lang.org header.a=rsa-sha256 header.s=mail header.b=2kviCIc/; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=ruby-lang.org header.i=@ruby-lang.org header.a=rsa-sha256 header.s=s1 header.b=W3WArdJi; dkim-atps=neutral DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ml.ruby-lang.org; s=mail; t=1734664582; bh=L1qtfJz8pJOFA19ptmjLKVg9oQYxn/NRlMshfoR4TDM=; h=Date:References:To:Reply-To:Subject:List-Id:List-Archive: List-Help:List-Owner:List-Post:List-Subscribe:List-Unsubscribe: From:Cc:From; b=2kviCIc/MHOriasaAknt2vcIGzk6sk2ke1goXFXwkH4kSgnLuTjcpvPg4ZDIS1xmS HJuRv6k68jvDUu0RKelPS44Rvtn4WRKHK9S5N8ofyBpFJJxE3rwxYfFTxMYtCpdmW2 MRO8Pvc9HRqAyYBxEwuvwWwv6h4l0DqhTu/Zmnds= Received: from nue.mailmanlists.eu (localhost [IPv6:::1]) by nue.mailmanlists.eu (Postfix) with ESMTP id 9A56B452DA for ; Fri, 20 Dec 2024 03:16:22 +0000 (UTC) Authentication-Results: nue.mailmanlists.eu; dkim=pass (2048-bit key; unprotected) header.d=ruby-lang.org header.i=@ruby-lang.org header.a=rsa-sha256 header.s=s1 header.b=W3WArdJi; dkim-atps=neutral Received: from s.wrqvtzvf.outbound-mail.sendgrid.net (s.wrqvtzvf.outbound-mail.sendgrid.net [149.72.126.143]) by nue.mailmanlists.eu (Postfix) with ESMTPS id C8CC344B62 for ; Fri, 20 Dec 2024 03:16:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ruby-lang.org; h=from:references:subject:mime-version:content-type: content-transfer-encoding:list-id:to:cc:content-type:from:subject:to; s=s1; bh=2vnbVoysUrEYa8fTFFbJFAxILfQxLwclKxSD1063lbw=; b=W3WArdJizY3rAXWdmGfTUQYeY3PMCpwqakuONWISmO975WVGnrreaaBcHyGk62hvaIcd SAcRhm5vADtK7gDMHE/KX6dc4GoAi70kirzD1Ul0Nnp6l2iiLYep570ReNwubO6DzKK9b9 NRSB5OAF3ofQNXWzETVa6BWnYoL/bMJcfuu7k4nO/TtKQXshcui69e1FmlvheuRy1De3rx grtOSs0hvLoiW1BGe5hKU63Z/k8TIBcqk7NquHj+A5uz0QICpOvcU+j1zCiLeRMBl2+uti q1kJ2mMTrg4jCh219EbEMth+BHsu7o+t/mnzsbRd4clarUUDrYk1e35yHvXLXj8A== Received: by recvd-5f54b5d587-ggvnt with SMTP id recvd-5f54b5d587-ggvnt-1-6764E181-9 2024-12-20 03:16:17.213477357 +0000 UTC m=+3045124.409024065 Received: from herokuapp.com (unknown) by geopod-ismtpd-0 (SG) with ESMTP id HA_kQ3bYQgeLfma1YoF9ZQ for ; Fri, 20 Dec 2024 03:16:17.152 +0000 (UTC) Date: Fri, 20 Dec 2024 03:16:17 +0000 (UTC) Message-ID: References: Mime-Version: 1.0 X-Redmine-Project: ruby-master X-Redmine-Issue-Tracker: Feature X-Redmine-Issue-Id: 20971 X-Redmine-Issue-Author: Earlopain X-Redmine-Issue-Priority: Normal X-Redmine-Sender: nobu X-Mailer: Redmine X-Redmine-Host: bugs.ruby-lang.org X-Redmine-Site: Ruby Issue Tracking System X-Auto-Response-Suppress: All Auto-Submitted: auto-generated X-Redmine-MailingListIntegration-Message-Ids: 97016 X-SG-EID: =?us-ascii?Q?u001=2E5PtzXJ23KrYzgM1nrOIr+EQ222PyrDaWSg0Er8CZ8tP86xyXmBM81zBKD?= =?us-ascii?Q?HreavdFYMbHjxXOR6UPMkt=2Fu9CyBIp6y52n8D2y?= =?us-ascii?Q?qA9zqurrgUcnYedtsE1+iqWF42syR45RrQnA0j8?= =?us-ascii?Q?pjL2NxmC9EUVVxQp3VUByIhhpPSOKo0WZ9h=2FEZd?= =?us-ascii?Q?9m+OsOOAjEyOknf5N3hyJq3Y6JrL2+dnlD2wZXu?= =?us-ascii?Q?e=2FLeQRQ5xwgkc36o61EmmgzflLJ019+u6wjerb9?= =?us-ascii?Q?yx43blWXNWSGf0R3vhw=2F8ONEsQ=3D=3D?= To: ruby-core@ml.ruby-lang.org X-Entity-ID: u001.I8uzylDtAfgbeCOeLBYDww== Message-ID-Hash: J4WIQIXUHDCIQOH7OT3XO3FMA4TFC3V7 X-Message-ID-Hash: J4WIQIXUHDCIQOH7OT3XO3FMA4TFC3V7 X-MailFrom: bounces+313651-b711-ruby-core=ml.ruby-lang.org@em5188.ruby-lang.org X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.9 Precedence: list Reply-To: Ruby developers Subject: [ruby-core:120339] [Ruby master Feature#20971] Deprecate `rb_path_check` List-Id: Ruby developers Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: "nobu (Nobuyoshi Nakada) via ruby-core" Cc: "nobu (Nobuyoshi Nakada)" Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Issue #20971 has been updated by nobu (Nobuyoshi Nakada). I mean this warning went away since 2.7, which should be unrelated to tainted-ness. ```sh-session $ ruby2.6 -w -rtmpdir -e 'Dir.mktmpdir("", "/tmp") {|w| File.chmod(0777, w); ENV["PATH"] = w}' -e:1: warning: Insecure world writable dir /tmp/20241220-14749-10itz6k in PATH, mode 040777 ``` ---------------------------------------- Feature #20971: Deprecate `rb_path_check` https://bugs.ruby-lang.org/issues/20971#change-111113 * Author: Earlopain (Earlopain _) * Status: Open ---------------------------------------- With #16131, various code around $SAFE, taint, etc. has been deprecated and removed. GH PR https://github.com/ruby/ruby/pull/2476. Now, [`rb_path_check`] still exists as part of the public API, with Ruby itself never using or testing it. I believe it should have been deprecated and was simply missed. Should it be deprecated today or is that not worth the effort? Docs for it are pretty vague: https://github.com/ruby/ruby/blob/33f95d632dce42fac35da29eaed33f0a5a4f0dcb/include/ruby/internal/intern/hash.h#L289-L297 > This function is mysterious. What it does is not immediately obvious. Also what it does seems platform dependent. [`rb_path_check`]: https://github.com/ruby/ruby/blob/33f95d632dce42fac35da29eaed33f0a5a4f0dcb/file.c#L6427 -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/