Skip to content

ruby: update to 4.0.7 - #30660

Open
luizluca wants to merge 1 commit into
openwrt:masterfrom
luizluca:ruby-4.0.7
Open

luizluca wants to merge 1 commit into
openwrt:masterfrom
luizluca:ruby-4.0.7

Conversation

@luizluca

@luizluca luizluca commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

ruby: update to 4.0.7

ruby 4.0.3 only contains ERB 6.0.1.1, which fixes CVE-2026-41316.

ruby 4.0.4 is a routine update that includes bugfixes.

ruby 4.0.5 only contains a security fix for CVE-2026-46727:
Use-after-free in pthread-based getaddrinfo timeout handler and a build
system regression in Ruby 4.0.4 under C locale.

ruby 4.0.6 is a routine update that includes bugfixes.

ruby 4.0.7 is a routine update that includes bugfixes.

Packaging changes:

  • Patch 010-fix-riscv64-build.patch was dropped as MUSL 1.2.5 fixes the
    issue.
  • Exclude source files (*.c, *.h, Makefile...) from packages.
  • Updated ruby_missingfiles to match package files exclusions.
  • Changed the dependency order (rake -> rubygem, racc -> rubygem)
  • Moved rdoc_plugin.rb to ruby-rdoc package (and dropping ruby-gems
    dependency on ruby-rdoc).
  • Refreshed the dependencies.
  • ruby_find_pkgsdeps:
    • fixed a bug in dependency expansion
    • updated weak dependencies
  • Added custom test-version.sh to ignore version check on subpackages
    commands as they use their own gem version.

📦 Package Details

Maintainer: me

Description:
Routine updates


🧪 Run Testing Details

  • OpenWrt Version: c759267c92b0697a6fd6f369164a5ed4c1a6a03c
  • OpenWrt Target/Subtarget: x86/64 (runtime) mediatek/filogic (build)
  • OpenWrt Device: Qemu

Tested with gem update


✅ Formalities

  • I have reviewed the CONTRIBUTING.md file for detailed contributing guidelines.

If your PR contains a patch:

  • It can be applied using git am
  • It has been refreshed to avoid offsets, fuzzes, etc., using
  • It is structured in a way that it is potentially upstreamable

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; no new issues found.


Generated by Claude Code

@luizluca

luizluca commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

It looks like ruby is installing source and object files to PKG_INSTALL_DIR. I'll remove them using a filter.

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; 1 inline note.


Generated by Claude Code

Comment thread lang/ruby/Makefile Outdated

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commits; no new issues found.


Generated by Claude Code

ruby 4.0.3 only contains ERB 6.0.1.1, which fixes CVE-2026-41316.

ruby 4.0.4 is a routine update that includes bugfixes.

ruby 4.0.5 only contains a security fix for CVE-2026-46727:
Use-after-free in pthread-based getaddrinfo timeout handler and a build
system regression in Ruby 4.0.4 under C locale.

ruby 4.0.6 is a routine update that includes bugfixes.

ruby 4.0.7 is a routine update that includes bugfixes.

Packaging changes:
- Patch 010-fix-riscv64-build.patch was dropped as MUSL 1.2.5 fixes the
  issue.
- Exclude source files (*.c, *.h, Makefile...) from packages.
- Updated ruby_missingfiles to match package files exclusions.
- Changed the dependency order (rake -> rubygem, racc -> rubygem)
- Moved rdoc_plugin.rb to ruby-rdoc package (and dropping ruby-gems
  dependency on ruby-rdoc).
- Refreshed the dependencies.
- ruby_find_pkgsdeps:
  * fixed a bug in dependency expansion
  * updated weak dependencies
- Added custom test-version.sh to ignore version check on subpackages
  commands as they use their own gem version.

Link: https://www.ruby-lang.org/en/news/2026/04/21/ruby-4-0-3-released/
Changelog: https://github.com/ruby/ruby/releases/tag/v4.0.3
Link: https://www.ruby-lang.org/en/news/2026/05/11/ruby-4-0-4-released/
Changelog: https://github.com/ruby/ruby/releases/tag/v4.0.4
Link: https://www.ruby-lang.org/en/news/2026/05/20/ruby-4-0-5-released/
Changelog: https://github.com/ruby/ruby/releases/tag/v4.0.5
Link: https://www.ruby-lang.org/en/news/2026/07/14/ruby-4-0-6-released/
Changelog: https://github.com/ruby/ruby/releases/tag/v4.0.6
Link: https://www.ruby-lang.org/en/news/2026/09/15/ruby-4-0-7-released/
Changelog: https://github.com/ruby/ruby/releases/tag/v4.0.7
Signed-off-by: Luiz Angelo Daros de Luca <luizluca@gmail.com>

@openwrt-ai openwrt-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 1 new commit; 2 inline notes.


Generated by Claude Code

Comment thread lang/ruby/test-version.sh
if [ "$PKG_NAME" = "ruby" ]; then
# Execute the ruby binary and check if the expected version string
# is present in its standard output or standard error.
if ruby --version 2>&1 | grep -q "$PKG_VERSION"; then

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't use grep -q in test-version.sh. The matched version line should show up in the CI log. Use -F too, so the dots in the version are matched literally (the other in-tree test-version.sh scripts do the same).

Suggested change
if ruby --version 2>&1 | grep -q "$PKG_VERSION"; then
if ruby --version 2>&1 | grep -F "$PKG_VERSION"; then

Generated by Claude Code

Comment thread lang/ruby/test-version.sh
PKG_VERSION="$2"

# Only perform the version check for the main 'ruby' package.
# This prevents errors where subpackages (like gems) have their own

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: trailing whitespace.

Suggested change
# This prevents errors where subpackages (like gems) have their own
# This prevents errors where subpackages (like gems) have their own

Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants