Skip to content

Copy attribute input before defaults and cached values mutate it - #166

Open
OskarEichler wants to merge 1 commit into
net-ssh:masterfrom
OskarEichler:codex/attribute-input-ownership
Open

Copy attribute input before defaults and cached values mutate it#166
OskarEichler wants to merge 1 commit into
net-ssh:masterfrom
OskarEichler:codex/attribute-input-ownership

Conversation

@OskarEichler

Copy link
Copy Markdown

Summary

Own a shallow copy of the constructor hash and set the v4 default type through the attribute writer.

Reproduction

Net::SFTP::Protocol::V04::Attributes.new({size: 5}.freeze) currently raises FrozenError while inserting :type. Two instances made from the same mutable hash also share scalar updates. Fixed accepts frozen input and isolates instance updates.

Verification

  • Baseline and this isolated patch: 433 existing tests, 1,201 assertions, zero failures/errors/skips, Ruby 4.0.6 through rbenv, net-ssh 7.3.3, Minitest 5.27.0 and Mocha 2.1.0.
  • 10 external assertions exercise v1/v4/v6 constructors, shared/frozen input, public attributes mutation, serialization and existing unknown-type behavior.
  • The combined consumer candidate also passes 10,384 external model assertions, 21 local OpenSSH pipe assertions, and the existing suite with frozen string literals enabled and disabled. These combined checks include separately attributed portions of Handle frozen strings #157/ensure ruby 4 compatibility and address some security concerns #162; they are not claimed as this isolated branch's changes.
  • Packaging preserves all 37 release paths and dependency metadata. All 26 runtime files compile on Ruby 4.0.6 and parse with Parser::Ruby25. Comparative Lint checks retain the same 33 baseline findings; no all-green lint claim.

Breaking changes and limitations

Intentional compatibility change: later mutations of the original constructor hash no longer update an Attributes instance, and instance writes no longer modify that hash. The public attributes hash remains mutable. The copy is shallow; nested collections retain their existing ownership.

No repository tests were added or modified under the contribution's no-new-tests constraint; focused repro/model drivers ran outside the repository. An external verification Gemfile supplies compatible test tools and RDoc without changing upstream tooling. Actual older Ruby/JRuby/Windows compatibility and upstream CI have not been verified. No production or SSH connections, version bumps, release-tool changes or unrelated modernization are included. Git builds are not signed by the upstream gem release key.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant