From bb338a8c74e9a516481ff7bbbd4c1593be8e055a Mon Sep 17 00:00:00 2001 From: Thomas Klemm Date: Thu, 8 Oct 2026 09:35:53 +0000 Subject: [PATCH 1/3] Test blocked libvips loaders directly Amp-Thread-ID: https://ampcode.com/threads/T-01a11acc-6153-7316-a06c-fcf2d713cd64 Co-authored-by: Amp --- test/lib/vips_loader_policy_test.rb | 21 ++++++++------------- 1 file changed, 8 insertions(+), 13 deletions(-) diff --git a/test/lib/vips_loader_policy_test.rb b/test/lib/vips_loader_policy_test.rb index e522f6a..f434d3d 100644 --- a/test/lib/vips_loader_policy_test.rb +++ b/test/lib/vips_loader_policy_test.rb @@ -10,11 +10,6 @@ class VipsLoaderPolicyTest < ActiveSupport::TestCase # ones are represented by their magic bytes. FTYP_AVIF = "\x00\x00\x00\x1cftypavif\x00\x00\x00\x00avifmif1miaf".b FTYP_HEIC = "\x00\x00\x00\x1cftypheic\x00\x00\x00\x00heicmif1miaf".b - BMP = "BM" + [ 0, 0, 54 ].pack("V3") + "\x00" * 40 - PSD = "8BPS" + [ 1 ].pack("n") + "\x00" * 26 - ICO = "\x00\x00\x01\x00\x01\x00" + "\x00" * 16 - SVG = %q() - test "loads PNG" do assert_equal "VipsForeignLoadPngFile", loader_for(encode("png")) end @@ -43,20 +38,20 @@ class VipsLoaderPolicyTest < ActiveSupport::TestCase assert_equal "VipsForeignLoadHeifFile", loader_for(FTYP_HEIC) end - test "denies BMP through magickload" do - assert_nil loader_for(BMP) + test "blocks BMP through magickload" do + assert_loader_blocked :magickload, ".bmp" end - test "denies PSD through magickload" do - assert_nil loader_for(PSD) + test "blocks PSD through magickload" do + assert_loader_blocked :magickload, ".psd" end - test "denies ICO through magickload" do - assert_nil loader_for(ICO) + test "blocks ICO through magickload" do + assert_loader_blocked :magickload, ".ico" end - test "denies SVG through svgload" do - assert_nil loader_for(SVG) + test "blocks SVG through svgload" do + assert_loader_blocked :svgload, ".svg" end test "denies OpenSlide files through openslideload" do From 66883b6fb1eda402245247592e0af5f54105c5eb Mon Sep 17 00:00:00 2001 From: Thomas Klemm Date: Thu, 8 Oct 2026 09:48:51 +0000 Subject: [PATCH 2/3] Update RuboCop toolchain Amp-Thread-ID: https://ampcode.com/threads/T-01a11acc-6153-7316-a06c-fcf2d713cd64 Co-authored-by: Amp --- Gemfile.lock | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/Gemfile.lock b/Gemfile.lock index 842fcb4..fb4c4a6 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -336,29 +336,29 @@ GEM chunky_png (~> 1.0) rqrcode_core (~> 2.0) rqrcode_core (2.1.0) - rubocop (1.80.2) - json (~> 2.3) + rubocop (1.91.0) + json (>= 2.3) language_server-protocol (~> 3.17.0.2) lint_roller (~> 1.1.0) - parallel (~> 1.10) + parallel (>= 1.10) parser (>= 3.3.0.2) rainbow (>= 2.2.2, < 4.0) regexp_parser (>= 2.9.3, < 3.0) - rubocop-ast (>= 1.46.0, < 2.0) + rubocop-ast (>= 1.49.0, < 2.0) ruby-progressbar (~> 1.7) unicode-display_width (>= 2.4.0, < 4.0) - rubocop-ast (1.46.0) + rubocop-ast (1.50.0) parser (>= 3.3.7.2) - prism (~> 1.4) - rubocop-performance (1.25.0) + prism (~> 1.7) + rubocop-performance (1.27.0) lint_roller (~> 1.1) - rubocop (>= 1.75.0, < 2.0) - rubocop-ast (>= 1.38.0, < 2.0) - rubocop-rails (2.33.3) + rubocop (>= 1.89.0, < 2.0) + rubocop-ast (>= 1.47.1, < 2.0) + rubocop-rails (2.38.0) activesupport (>= 4.2.0) lint_roller (~> 1.1) rack (>= 1.1) - rubocop (>= 1.75.0, < 2.0) + rubocop (>= 1.89.0, < 2.0) rubocop-ast (>= 1.44.0, < 2.0) rubocop-rails-omakase (1.1.0) rubocop (>= 1.72) From 24042e6b4cb64d763e8e1f2b3b99b177236bc63d Mon Sep 17 00:00:00 2001 From: Thomas Klemm Date: Thu, 8 Oct 2026 09:50:32 +0000 Subject: [PATCH 3/3] Upgrade runtime to Ruby 4.0.7 Amp-Thread-ID: https://ampcode.com/threads/T-01a11acc-6153-7316-a06c-fcf2d713cd64 Co-authored-by: Amp --- .ruby-version | 2 +- Dockerfile | 2 +- Dockerfile-export | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.ruby-version b/.ruby-version index 84d6c67..43beb40 100644 --- a/.ruby-version +++ b/.ruby-version @@ -1 +1 @@ -3.4.10 +4.0.7 diff --git a/Dockerfile b/Dockerfile index 1002a6c..195fd22 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ # syntax = docker/dockerfile:1 # Make sure it matches the Ruby version in .ruby-version and Gemfile -ARG RUBY_VERSION=3.4.10 +ARG RUBY_VERSION=4.0.7 FROM docker.io/library/ruby:$RUBY_VERSION-slim AS base # Rails app lives here diff --git a/Dockerfile-export b/Dockerfile-export index d130d17..c1a87a0 100644 --- a/Dockerfile-export +++ b/Dockerfile-export @@ -1,7 +1,7 @@ # syntax = docker/dockerfile:1 # Make sure it matches the Ruby version in .ruby-version and Gemfile -ARG RUBY_VERSION=3.4.10 +ARG RUBY_VERSION=4.0.7 FROM ruby:$RUBY_VERSION-slim as base # Install the tools we need