Security bump for CVE-2026-47736 (PROXY Protocol v1 parser memory
exhaustion) and CVE-2026-47737 (PROXY v1 repeated headers). Not exposed:
PROXY protocol is opt-in via set_remote_address proxy_protocol:, which
campfire never calls — default remote_address :socket leaves the parser
unreachable. Thruster/kamal-proxy front campfire over HTTP X-Forwarded-*,
not PROXY protocol.
No 6.x fix exists, so this is a major v6→v7 bump:
- Gemfile pin "~> 6.6" → "~> 7.2", ">= 7.2.1"
- config/puma.rb needs NO changes — every DSL method used (threads,
worker_timeout, bind, environment, pidfile, workers, plugin
:tmp_restart) is unchanged in v7; tmp_restart.rb is byte-identical.
Behavior notes (no action): preload_app effectively defaults on for
clustered mode (safe — Rails eager-loaded in master, Membership.
disconnect_all handles pre-fork conns); persistent_timeout default
20→65s (internal keep-alive). Min Ruby 3.0; campfire runs 3.4.5.
Direct gem. 137 commits triaged, 0 mitigations. Verified green via full
unit + system suites (system tests boot Puma 7.2.1).
https://github.com/basecamp/37signals-hq/blob/main/upgrade-analysis/campfire-20260609-puma_v6.6.1..v7.2.1.md🤖 Assisted by Claude
* Bump Ruby to 3.4.5
* Update dependencies
* Adjust for Rails 8 and Ruby 3.5 API changes
* Mark params strings as mutable in prepapration for frozen strings in Ruby 3.5
* Update test for HTML5 sanitizer
With Rails 7.1 the HTML5 sanitizer became the default, this breakts this test because the old sanitizer used to delete unpermitted nodes, while the new one returns their content
The final string is safe, but different then it used to be in Rails 7.0
* Remove direct Turbo tesh helpers require & parallelize tests
* Fix Zeitwerk issues with rails extensions
* Update Resque setup for Redis 5+
* Remove unused views
* Remove GID v1 handler