Yukihiro "Matz" Matsumoto
bfc1f37b91
Merge pull request #6775 from dearblue/array-combination.2
2026-04-23 18:56:46 +09:00
Yukihiro "Matz" Matsumoto
7eab8302b0
Merge pull request #6774 from dearblue/array-combination.1
2026-04-23 18:49:28 +09:00
Yukihiro "Matz" Matsumoto
05f7236586
Merge pull request #6805 from mruby/dependabot/github_actions/github-actions-dependencies-f3e34333ea
2026-04-23 16:01:46 +09:00
Yukihiro "Matz" Matsumoto
d359182b47
Merge pull request #6804 from mruby/dependabot/bundler/bundler-dependencies-39953ac9c0
2026-04-23 15:52:01 +09:00
dependabot[bot]
ccd661b429
build(deps): bump github/codeql-action
...
Bumps the github-actions-dependencies group with 1 update: [github/codeql-action](https://github.com/github/codeql-action ).
Updates `github/codeql-action` from 4.35.1 to 4.35.2
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4.35.1...v4.35.2 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-22 14:54:14 +00:00
dependabot[bot]
aea5d584f0
build(deps): bump rake in the bundler-dependencies group
...
Bumps the bundler-dependencies group with 1 update: [rake](https://github.com/ruby/rake ).
Updates `rake` from 13.3.1 to 13.4.1
- [Release notes](https://github.com/ruby/rake/releases )
- [Changelog](https://github.com/ruby/rake/blob/master/History.rdoc )
- [Commits](https://github.com/ruby/rake/compare/v13.3.1...v13.4.1 )
---
updated-dependencies:
- dependency-name: rake
dependency-version: 13.4.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: bundler-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-21 14:53:28 +00:00
Yukihiro "Matz" Matsumoto
f469e7567a
Merge pull request #6801 from mruby/dependabot/github_actions/github-actions-dependencies-9527efa922
2026-04-21 08:34:06 +09:00
dependabot[bot]
86940418c7
build(deps): bump the github-actions-dependencies group with 2 updates
...
Bumps the github-actions-dependencies group with 2 updates: [actions/cache](https://github.com/actions/cache ) and [j178/prek-action](https://github.com/j178/prek-action ).
Updates `actions/cache` from 5.0.4 to 5.0.5
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae )
Updates `j178/prek-action` from 2.0.1 to 2.0.2
- [Release notes](https://github.com/j178/prek-action/releases )
- [Commits](https://github.com/j178/prek-action/compare/53276d8b0d10f8b6672aa85b4588c6921d0370cc...cbc2f23eb5539cf20d82d1aabd0d0ecbcc56f4e3 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: 5.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions-dependencies
- dependency-name: j178/prek-action
dependency-version: 2.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-20 17:20:54 +00:00
Yukihiro "Matz" Matsumoto
7546d53a3a
Merge pull request #6800 from mruby/stable
2026-04-20 18:54:55 +09:00
mimaki
831da26b90
Update version and release date. (mruby 4.0.0 (2026-04-20))
4.0.0
2026-04-20 17:43:06 +09:00
Yukihiro "Matz" Matsumoto
0112fe6659
Merge pull request #6796 from mruby/dependabot/pre_commit/pre-commit-hooks-be5b5e25f5
2026-04-18 08:29:15 +09:00
Yukihiro "Matz" Matsumoto
605ef4919b
Merge pull request #6797 from mruby/dependabot/github_actions/github-actions-dependencies-fd00acb19b
2026-04-18 08:28:56 +09:00
Yukihiro "Matz" Matsumoto
e1ed206cae
Merge pull request #6798 from mruby/dependabot/bundler/yard-0.9.42
2026-04-18 08:28:31 +09:00
Yukihiro "Matz" Matsumoto
82b91d15c5
Merge pull request #6794 from mattn/fix/readfloat-18-digits
2026-04-18 08:27:58 +09:00
dependabot[bot]
f80f825bcf
build(deps): bump yard from 0.9.38 to 0.9.42
...
Bumps [yard](https://yardoc.org ) from 0.9.38 to 0.9.42.
---
updated-dependencies:
- dependency-name: yard
dependency-version: 0.9.42
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-17 22:33:28 +00:00
dependabot[bot]
eb51c63196
build(deps): bump github/codeql-action
...
Bumps the github-actions-dependencies group with 1 update: [github/codeql-action](https://github.com/github/codeql-action ).
Updates `github/codeql-action` from 4 to 4.35.1
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v4...v4.35.1 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-17 14:53:59 +00:00
dependabot[bot]
c2145c8642
build(deps): bump https://github.com/rubocop/rubocop
...
Bumps the pre-commit-hooks group with 1 update: [https://github.com/rubocop/rubocop ](https://github.com/rubocop/rubocop ).
Updates `https://github.com/rubocop/rubocop ` from v1.86.0 to 1.86.1
- [Release notes](https://github.com/rubocop/rubocop/releases )
- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rubocop/rubocop/compare/v1.86.0...v1.86.1 )
---
updated-dependencies:
- dependency-name: https://github.com/rubocop/rubocop
dependency-version: 1.86.1
dependency-type: direct:production
dependency-group: pre-commit-hooks
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-16 14:57:37 +00:00
Yasuhiro Matsumoto
b82f1c2ec0
readfloat.c: keep one extra fraction digit (17 -> 18)
...
18 decimal digits still fit in uint64_t (max ~1.8e19), so we can hold
one more digit of precision without overflow risk.
2026-04-16 17:13:17 +09:00
Yukihiro "Matz" Matsumoto
a6a92bf95b
Merge pull request #6793 from mattn/fix/readfloat-correctly-rounded
2026-04-16 17:09:10 +09:00
Yasuhiro Matsumoto
10c9e83128
readfloat.c: correctly round fraction via division by exact 10^n
...
The previous code computed `frac_part * pow10_negative[n]`, where
pow10_negative[n] is already a rounded approximation of 10^-n (since
10^-n is not exactly representable in binary). The multiplication then
adds another rounding step, leaving up to ~1 ulp of error.
Dividing `frac_part` by `pow10_positive[n]` is exact for n <= 22 (the
range where 10^n fits exactly in a double), so the division is the
only rounding and the result is correctly rounded. For example,
"0.3".to_f now matches the 0.3 literal's bit pattern (and libc strtod).
2026-04-16 14:47:14 +09:00
Yukihiro "Matz" Matsumoto
2f5a24ed9b
Merge pull request #6792 from mruby/fix/host-cxx-build-dir
2026-04-15 15:34:09 +09:00
Yukihiro "Matz" Matsumoto
984f23a94e
Merge pull request #6788 from mruby/dependabot/github_actions/github-actions-dependencies-d2d9db5a03
2026-04-15 09:49:36 +09:00
Yukihiro "Matz" Matsumoto
2575735152
Merge pull request #6791 from mruby/fix/bigint-cxx-compat
2026-04-15 09:33:59 +09:00
Yukihiro "Matz" Matsumoto
eb87d59941
Merge pull request #6790 from mruby/fix/mrb-mt-entry-cxx-compat
2026-04-15 09:33:23 +09:00
Yukihiro "Matz" Matsumoto
8b44a52176
host-cxx: use distinct build directory from host-debug
...
build_config/host-cxx.rb defaulted to MRuby::Build.new (no name),
which is equivalent to MRuby::Build.new('host'), so it shared
build/host/ with build_config/host-debug.rb.
The two configs produce ABI-incompatible object files (C linkage
vs. C++-mangled). Switching between configs without a clean step
silently mixes stale objects, leading to confusing undefined
reference errors at link time.
Name the C++ build 'host-cxx' so it gets its own build/host-cxx/
directory. No external paths reference build/host/ in a way that
this change would break.
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-15 09:30:33 +09:00
Yukihiro "Matz" Matsumoto
617a55b775
mruby-bigint: avoid C99 compound literal in MPZ_CTX_INIT
...
MPZ_CTX_INIT used a compound literal with designated initializers:
mpz_ctx_t ctx##_struct = ((mpz_ctx_t){.mrb = ..., .pool = ...});
Both features are C99-only, and are not accepted by legacy C++
compilers (notably gcc 4.x) when mruby is pulled into a C++
translation unit via the -cxx.cxx wrapper.
Replace with plain member assignment so the macro expands to code
that is valid under C89/C++98 as well.
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-15 09:01:19 +09:00
Yukihiro "Matz" Matsumoto
a33ccd67b1
class.h: avoid C99 designated initializers in MRB_MT_ENTRY
...
Older C++ compilers (notably gcc 4.x) do not support C99 struct field
designators (.func = ...) even as an extension, which blocks building
mruby when it is included from a C++ translation unit under such
toolchains.
Reorder union mrb_mt_ptr so that mrb_func_t is the first member, and
switch MRB_MT_ENTRY to positional aggregate initialization. Both are
compatible with pre-C99 / pre-C++20 compilers.
Fixes #6789
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-15 07:31:11 +09:00
dependabot[bot]
c43eba8979
build(deps): bump softprops/action-gh-release
...
Bumps the github-actions-dependencies group with 1 update: [softprops/action-gh-release](https://github.com/softprops/action-gh-release ).
Updates `softprops/action-gh-release` from 2 to 2.6.1
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 2.6.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-13 16:11:02 +00:00
mimaki
65eb1df5a3
Update version to 4.0.0RC4.
4.0.0-rc4
2026-04-13 18:54:26 +09:00
mimaki
3b483db61d
Merge branch 'master' into stable
2026-04-13 18:51:16 +09:00
Yukihiro "Matz" Matsumoto
d65f7a9c5a
Merge pull request #6784 from mruby/fix/news-security-updates
2026-04-13 09:01:38 +09:00
Yukihiro "Matz" Matsumoto
e0aadaf6c4
NEWS.md: add security fixes and merged PRs ( #6780 , #6781 , #6783 )
...
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-13 08:39:21 +09:00
Yukihiro "Matz" Matsumoto
dfd4eb52cc
Merge pull request #6783 from jbampton/pin-actions
2026-04-13 08:16:14 +09:00
John Bampton
ebed2d32a2
gha: pin workflows to hash
2026-04-11 17:51:28 +10:00
Yukihiro "Matz" Matsumoto
48fc4220d3
Merge pull request #6781 from mruby/fix/sprintf-uaf
2026-04-11 16:33:05 +09:00
Yukihiro "Matz" Matsumoto
18ba02662b
Merge pull request #6780 from mruby/fix/string-prepend-overflow
2026-04-11 16:32:24 +09:00
Yukihiro "Matz" Matsumoto
59552ecb8e
mruby-sprintf: protect format string from mutation during callbacks
...
mrb_str_format captured raw C pointers (p, end) into the format
string's buffer before the main loop. The %s and %p specifiers call
to_s and inspect, which can invoke Ruby code that mutates the format
string via String#replace, freeing or reallocating its buffer. The
loop then continued iterating with dangling pointers, reading freed
memory and potentially leaking adjacent heap contents into the result.
Duplicate the format string with mrb_str_dup() before the loop. This
is O(1) because mrb_str_dup shares the underlying buffer; if the
original is later mutated via String#replace, str_replace decrements
the shared refcount, leaving our duplicate's buffer intact.
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-10 14:51:59 +09:00
Yukihiro "Matz" Matsumoto
af6f23ddb3
mruby-string-ext: fix String#prepend with self-referencing arguments
...
String#prepend(s, s) read RSTRING_LEN(argv[i]) in the copy loop after
mrb_str_resize had already updated the receiver's length, causing the
memcpy to write past the allocated buffer.
Detect self-references with mrb_obj_eq() and read from the memmoved
original data at p + total_prepend_len using the captured self_len.
This also handles mixed cases like s.prepend("X", s) where earlier
writes would otherwise corrupt the source of later reads.
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-10 14:44:46 +09:00
Yukihiro "Matz" Matsumoto
4eb4884219
Merge pull request #6778 from mruby/dependabot/github_actions/github-actions-dependencies-6289042708
2026-04-09 07:55:37 +09:00
dependabot[bot]
c394525da6
build(deps): bump super-linter/super-linter
...
Bumps the github-actions-dependencies group with 1 update: [super-linter/super-linter](https://github.com/super-linter/super-linter ).
Updates `super-linter/super-linter` from 8.5.0 to 8.6.0
- [Release notes](https://github.com/super-linter/super-linter/releases )
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md )
- [Commits](https://github.com/super-linter/super-linter/compare/v8.5.0...v8.6.0 )
---
updated-dependencies:
- dependency-name: super-linter/super-linter
dependency-version: 8.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-08 14:54:46 +00:00
dearblue
5e3e982442
Improve the calculation of the next index for Array#__combination_next
...
When the index wraps around, the lower index becomes a fixed value.
2026-04-08 22:16:59 +09:00
dearblue
3a9ef9d27e
Avoid using the deprecated function mrb_data_check_and_get()
...
The "d" directive in `mrb_get_args()` can be used as an alternative.
Furthermore, NULL checking is unnecessary for the following reasons:
- Incomplete objects from `ary_combination_init()` are not passed to the caller and are garbage collected when `ObjectSpace.each_object` is called, so they are never retrieved
- Even if `state.clone` is called, the `RData::type` of the cloned object is set to NULL, so it is rejected by `mrb_get_args()`
2026-04-08 21:10:45 +09:00
Yukihiro "Matz" Matsumoto
5d5cf0c3ea
Merge pull request #6772 from mruby/fix/update-news
2026-04-02 20:33:46 +09:00
Yukihiro "Matz" Matsumoto
3a5c45f282
NEWS.md: update for recent changes
...
Add entries for language changes (case/in NoMatchingPatternError,
compound statement in tLPAREN_ARG), C API additions (mrb_bigint_p(),
RVALUE union), compiler optimizations (literal chunking), build
fixes (MSYS2), security fixes, and 26 merged pull requests.
Co-authored-by: Claude <noreply@anthropic.com >
2026-04-02 20:17:19 +09:00
mimaki
6c121b9708
Update version to 4.0.0RC3.
4.0.0-rc3
2026-04-02 11:23:31 +09:00
mimaki
d06cb40725
Merge branch 'master' into stable
2026-04-02 10:31:49 +09:00
Yukihiro "Matz" Matsumoto
0cc4caad2b
Merge pull request #6769 from khasinski/fix-socket-recvfrom-nonblock
2026-04-01 09:23:00 +09:00
Yukihiro "Matz" Matsumoto
0cef3e5414
Merge pull request #6770 from jbampton/patch-2
2026-04-01 09:17:38 +09:00
Yukihiro "Matz" Matsumoto
825d4c388e
Merge pull request #6771 from mruby/dependabot/pre_commit/pre-commit-hooks-820b35f878
2026-04-01 09:16:17 +09:00
dependabot[bot]
141a8bc406
build(deps): bump https://github.com/rhysd/actionlint
...
Bumps the pre-commit-hooks group with 1 update: [https://github.com/rhysd/actionlint ](https://github.com/rhysd/actionlint ).
Updates `https://github.com/rhysd/actionlint ` from v1.7.11 to 1.7.12
- [Release notes](https://github.com/rhysd/actionlint/releases )
- [Changelog](https://github.com/rhysd/actionlint/blob/main/CHANGELOG.md )
- [Commits](https://github.com/rhysd/actionlint/compare/v1.7.11...v1.7.12 )
---
updated-dependencies:
- dependency-name: https://github.com/rhysd/actionlint
dependency-version: 1.7.12
dependency-type: direct:production
dependency-group: pre-commit-hooks
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-31 15:00:01 +00:00