stable

ruby-3.0.4-153.fc35

FEDORA-2022-8cf0124add created by vondruch 3 years ago for Fedora 35

Upgrade to Ruby 3.0.4.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2022-8cf0124add

This update has been submitted for testing by vondruch.

3 years ago

This update's test gating status has been changed to 'ignored'.

3 years ago

This update has been pushed to testing.

3 years ago

vondruch edited this update.

3 years ago
User Icon toshio commented & provided feedback 3 years ago
karma

The rubygems subpackage built from this appears to break something important. Both vagrant and irb begin to fail once this version's rubygems package is installed:

$ dnf upgrade rubygems-3.2.33-152.fc35

$ irb

Ignoring json-2.3.0 because its extensions are not built. Try: gem pristine json --version 2.3.0 /usr/share/rubygems/rubygems/specification.rb:1406:in rescue in block in activate_dependencies': Could not find 'reline' (>= 0.1.5) among 70 total gem(s) (Gem::MissingSpecError) Checked in 'GEM_PATH=/home/badger/.gem/ruby:/usr/share/gems:/usr/local/share/gems' at: /usr/share/gems/specifications/irb-1.3.5.gemspec, executegem envfor more information from /usr/share/rubygems/rubygems/specification.rb:1403:inblock in activate_dependencies' from /usr/share/rubygems/rubygems/specification.rb:1392:in each' from /usr/share/rubygems/rubygems/specification.rb:1392:inactivate_dependencies' from /usr/share/rubygems/rubygems/specification.rb:1374:in activate' from /usr/share/rubygems/rubygems.rb:299:inblock in activate_bin_path' from /usr/share/rubygems/rubygems.rb:298:in synchronize' from /usr/share/rubygems/rubygems.rb:298:inactivate_bin_path' from /usr/bin/irb:23:in <main>' /usr/share/rubygems/rubygems/dependency.rb:311:into_specs': Could not find 'reline' (>= 0.1.5) among 70 total gem(s) (Gem::MissingSpecError) Checked in 'GEM_PATH=/home/badger/.gem/ruby:/usr/share/gems:/usr/local/share/gems' , execute gem env for more information from /usr/share/rubygems/rubygems/specification.rb:1404:in block in activate_dependencies' from /usr/share/rubygems/rubygems/specification.rb:1392:ineach' from /usr/share/rubygems/rubygems/specification.rb:1392:in activate_dependencies' from /usr/share/rubygems/rubygems/specification.rb:1374:inactivate' from /usr/share/rubygems/rubygems.rb:299:in block in activate_bin_path' from /usr/share/rubygems/rubygems.rb:298:insynchronize' from /usr/share/rubygems/rubygems.rb:298:in activate_bin_path' from /usr/bin/irb:23:in<main>'

Downgrading just the rubygems subpackage to rubygems-3.2.22-151.fc35 appears to fix the issue.

At first glance, the symptoms look like this: https://github.com/rubygems/rubygems/issues/5156 but since you reported that and a fix was merged upstream last year, this might be a red herring.

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

3 years ago
User Icon vondruch commented & provided feedback 3 years ago

Och, good catch. Thx for testing. I'll take a look.

vondruch edited this update.

New build(s):

  • ruby-3.0.4-153.fc35

Removed build(s):

  • ruby-3.0.4-152.fc35

Karma has been reset.

3 years ago

This update has been submitted for testing by vondruch.

3 years ago
User Icon vondruch commented & provided feedback 3 years ago

It was indeed the BZ#2027099. The -153 includes patch to fix this. @toshio thx once again for discovering this.

This update has been pushed to testing.

3 years ago

This update has been submitted for stable by bodhi.

3 years ago

This update has been pushed to stable.

3 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 years ago
in testing
3 years ago
in stable
3 years ago
modified
3 years ago
BZ#2025104 CVE-2021-41817 ruby: Regular expression denial of service vulnerability of Date parsing methods
0
0
BZ#2026671 CVE-2021-41817 ruby: Regular Expression Denial of Service Vulnerability of Date Parsing Methods [fedora-all]
0
0
BZ#2026752 CVE-2021-41816 ruby: buffer overflow in CGI.escape_html
0
0
BZ#2026754 CVE-2021-41816 ruby: buffer overflow in CGI.escape_html [fedora-all]
0
0
BZ#2026757 CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse
0
0
BZ#2026759 CVE-2021-41819 ruby: cookie prefix spoofing in CGI::Cookie.parse [fedora-all]
0
0
BZ#2027099 Fedora/Rawhide Ruby: Running rubygem-irb in CLI fails with "Could not find 'reline'"
0
0
BZ#2075685 CVE-2022-28738 Ruby: Double free in Regexp compilation
0
0
BZ#2075687 CVE-2022-28739 Ruby: Buffer overrun in String-to-Float conversion
0
0
BZ#2078342 CVE-2022-28738 ruby: Double free in Regexp compilation [fedora-all]
0
0
BZ#2078346 CVE-2022-28739 ruby: Buffer overrun in String-to-Float conversion [fedora-all]
0
0

Automated Test Results