Sign in

Jean Boussier

@byroot.bsky.social
1.8K followers 177 following 490 posts

Rails core, Ruby committer, Senior Principal Engineer at Intercom.

PostsRepliesMedia
Jean Boussier @byroot.bsky.social · 25/09/2026
Bio update: blackpilled loser.
2454
Reposted by Jean Boussier
Balkan Ruby @balkanruby.bsky.social · 09/09/2026
This year on Balkan Ruby @byroot.bsky.social offered us more than one hot take and we were blown away. 🔥 Go watch his full talk on multiprocessing on our YouTube channel and comment if you dare. 🎥 youtu.be/QYIGmRXPZcw?... #RubyConference #RubyCommunity #RubySpeaker
022
Jean Boussier @byroot.bsky.social · 09/09/2026
OH: byrootはほんとSIMDが好きだな
061
Jean Boussier @byroot.bsky.social · 08/09/2026
A 3.0.1 may be incoming… but ❤️
041
Jean Boussier @byroot.bsky.social · 13/08/2026
I mean I do to, it's writing them that I hate 😅
030
Jean Boussier @byroot.bsky.social · 13/08/2026
A quick followup on Ruby Hashes byroot.github.io/ruby/perform...
byroot.github.io
Speeding Up (small) Ruby Hashes
Something I must confess is that I absolutely hate writing these blog posts. It’s not quite as bad as having to give a conference talk, but it’s up there on the list of activities that feel like pulli...
1155
Jean Boussier @byroot.bsky.social · 11/08/2026
I honestly don't know. The original SVN history has been lost in the Git transition, so it's unclear. The only difference I ever saw was that it wasn't keeping track of depth, so saving a an increment/decrement when following references at the cost of being unsafe. Not a good tradeoff IMO.
010
Jean Boussier @byroot.bsky.social · 11/08/2026
I'll probably release the final 3.0.0 version early September, so if you got time please try the RC1 and submit any feedback you may have: github.com/ruby/json/re...
github.com
Release v3.0.0.rc1 · ruby/json
With the removal of the insecure create_additions option, JSON.load and JSON.dump are now safe to use. Them being unsafe by default caused multiple security vulnerabilites in the past. If you did d...
1232
Jean Boussier @byroot.bsky.social · 06/08/2026
Good point. I meant to say "40 times powers of 2". A bit of a brain fart there.
020
Jean Boussier @byroot.bsky.social · 06/08/2026
A history of Ruby's Hash tables, and how we can make them use less memory: byroot.github.io/ruby/perform...
byroot.github.io
Shrinking Ruby Hashes
As you may know, one area of Ruby performance optimization that particularly interests me is memory usage. Given that most Ruby deployments rely on fork, improving Copy-on-Write performance is general...
1329
Reposted by Jean Boussier
Mike Dalessio @flavorjon.es · 29/07/2026
Upgrade Rails immediately, kids, this is a big one. github.com/rails/rails/...
github.com
Possible arbitrary file read and remote code execution in Active Storage variant processing
### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process envi...
14930
Jean Boussier @byroot.bsky.social · 26/07/2026
While it has been 18 months since I blogged about it, the json gem performance has improved quite significantly since, so now is a good time to add a few more parts to my JSON serie: byroot.github.io/ruby/json/20...
byroot.github.io
Optimizing Ruby’s JSON, Part 8
It has now been about 18 months since I concluded my post series on optimising Ruby’s json.
0233
Jean Boussier @byroot.bsky.social · 23/06/2026
BTW: will I see you in Brighton?
100
Jean Boussier @byroot.bsky.social · 23/06/2026
Just went two streets away, my eyes are literally burning.🥵
180
Jean Boussier @byroot.bsky.social · 20/06/2026
When reading one extra byte saves a lot of extra work: github.com/ruby/ruby/pu...
github.com
io.c: read files in a single pass by byroot · Pull Request #17418 · ruby/ruby
read_all receives the file size when known, and does all the work to allocate a string of the right size and issue a single read call. However since the condition to check for EOF is read_bytes &lt...
0171
Jean Boussier @byroot.bsky.social · 18/06/2026
❤️
090
Jean Boussier @byroot.bsky.social · 14/06/2026
Where's the data coming from? If it's from an IO object, `io.read(size, old_buffer)` do reuse the capacity.
100
Jean Boussier @byroot.bsky.social · 14/06/2026
Depends. If the capacity did fit in a Slot (up to 623 bytes on 4.0, 1007 bytes on 4.1.0dev) then it's kept. But if the capacity was over that, then yes it is lost. bugs.ruby-lang.org/issues/17790
bugs.ruby-lang.org
Feature #17790: Have a way to clear a String without resetting its capacity - Ruby - Ruby Issue Tracking System
Redmine
110
Jean Boussier @byroot.bsky.social · 06/06/2026
At the end of the day, the hotspot for libraries like panko, alba etc, isn't the JSON serialization but the building of the intermediate object graph (e.g. turning model objects into hashes and arrays).
030
Jean Boussier @byroot.bsky.social · 06/06/2026
That being said, IIRC panko does way more than just being Oj based. It ships with its own C extension that does a lot.
130
Jean Boussier @byroot.bsky.social · 06/06/2026
If it isn't. Unless it's a case of Oj disregarding the spec or doing something I believe is dangerous to be faster, then I consider it a bug. Feel free to file an issue for it.
120
Jean Boussier @byroot.bsky.social · 06/06/2026
Not really. It has a few advanced APIs like SAX style parsing that some people may need, but for classic `Oj.load / Oj.dump`, the stdlib JSON should be substantially faster in all cases.
120
Jean Boussier @byroot.bsky.social · 05/06/2026
And yes, if I find a few dozen free hours and some spare energy between the couch cushions, I'll definitely write a part 8.
060
Jean Boussier @byroot.bsky.social · 05/06/2026
I realized it has been ~1.5 years since I concluded my series of post on JSON optimization. So I got curious how much faster it became since then. 2.7.2 was the last version before I took over maintainership. 2.9.0 was the version I released at the end of the blog series.
3498
Jean Boussier @byroot.bsky.social · 01/06/2026
e.g. it's like getting a security vulnerability report for a buffer overflow in `eval`. Yes it's a bug and it will be fixed, but if an attacker is able to call `eval` with arbitrary input, that overflow doesn't really matter... 3/3
070
Jean Boussier @byroot.bsky.social · 01/06/2026
However it's clear the authors or tools still don't understand the context of the code, they're just searching for patterns. Typically I got reports of overflows and other not properly sanitized inputs in APIs that should never receive untrusted input. 2/3
130
Jean Boussier @byroot.bsky.social · 01/06/2026
Not sure if something changed recently, but I've received a stream of much higher quality security reports in the last few days, but there' still something off with them. I suspect they're AI assisted, but can't be certain. Unlike before, they're easy to read, concise, well explained etc. 1/3
150
Reposted by Jean Boussier
Jean Boussier @byroot.bsky.social · 21/05/2026
It's the Rails 8.2 default yes. No need for backporting, the feature is entirely in Bootsnap, so you can just upgrade to latest Bootsnap, and copy the couple configs: github.com/rails/rails/...
github.com
Enable frozen string literal by default by byroot · Pull Request #57252 · rails/rails
Ref: rails/bootsnap#535 This only impact the app own code, and not dependencies. It is also possible to enable it for gems, but some old ones may still not be ready.
161
Jean Boussier @byroot.bsky.social · 21/05/2026
It's the Rails 8.2 default yes. No need for backporting, the feature is entirely in Bootsnap, so you can just upgrade to latest Bootsnap, and copy the couple configs: github.com/rails/rails/...
github.com
Enable frozen string literal by default by byroot · Pull Request #57252 · rails/rails
Ref: rails/bootsnap#535 This only impact the app own code, and not dependencies. It is also possible to enable it for gems, but some old ones may still not be ready.
161
Jean Boussier @byroot.bsky.social · 21/05/2026
This one feels good. No more stupid comments at the top of files. At least in one repo.
Enable rubocop `StringLiteralsFrozenByDefault` and `FrozenStringLiteralComment: never`
1170
Jean Boussier @byroot.bsky.social · 15/05/2026
Maybe their next step is to connect you with people who enjoy the same videos. But I guess you still won’t be able to sent it to them since they would have already seen it on TikTok 🤔
060
Jean Boussier @byroot.bsky.social · 14/05/2026
Most of the times when trying to convey facts or ideas, concise and strait to the point is the way to go. I’m really surprised that tools that are good at summarizing very large document have this tendency of padding their expression with void.
030
Jean Boussier @byroot.bsky.social · 14/05/2026
That’s my number one gripe with LLMs too. Not particularly internal comms, but just prose in general, typically pull request descriptions or security reports. It feels like reading a student composition with a minimum number of pages requirement and too little substance.
171
Reposted by Jean Boussier
k0kubun @k0kubun.com · 11/05/2026
Ruby 4.0.4 Released www.ruby-lang.org/en/news/2026... This is a routine update that includes bugfixes. We recommend upgrading your Ruby version at your earliest convenience.
ruby-lang.org
Ruby 4.0.4 Released | Ruby
Ruby 4.0.4 has been released.
02410
Reposted by Jean Boussier
Aaron Patterson @tenderlove.dev · 06/05/2026
Made a new blurg post about AI + OSS security. I was going to just complain on here, but I figured a short blog post would be better for my complaining 😂 tenderlovemaking.com/2026/05/06/r...
tenderlovemaking.com
Rails Security, AI, and IBB
For quite a few years the Rails project has been working with the Internet Bug Bounty (IBB). The IBB is an organization that awarded cash to security researchers that reported issues to OSS projects p...
44312
Jean Boussier @byroot.bsky.social · 30/04/2026
Il y a eu un second XXe siècle ?
040
Jean Boussier @byroot.bsky.social · 30/04/2026
Actually, SCGI might be a better fit: en.wikipedia.org/wiki/Simple_... The request is about as easy to parse, but the response is returned as a raw HTTP response, so would be a perfect fit for Pitchfork.
en.wikipedia.org
Simple Common Gateway Interface - Wikipedia
030
Jean Boussier @byroot.bsky.social · 29/04/2026
I thought this was interesting and makes sense www.agwa.name/blog/post/fa... I might add implementing FCGI support in Pitchfork on my infinite pile of things to do eventually.
agwa.name
FastCGI: 30 Years Old and Still the Better Protocol for Reverse Proxies
For FastCGI's 30th birthday, let's look at how it avoids the security problems inherent in HTTP reverse proxying
2111
Jean Boussier @byroot.bsky.social · 29/04/2026
I chuckled www.france24.com/en/americas/...
france24.com
'You'd be speaking French': King Charles pokes fun at Trump during state dinner
Britain's King Charles III used his speech at a state dinner at the White House on Tuesday to poke fun at US President Donald Trump who, in January, told European leaders that without US aid in World…
040
Jean Boussier @byroot.bsky.social · 29/04/2026
I see. I’ll have a look at r10k too.
010
Jean Boussier @byroot.bsky.social · 28/04/2026
On another note, I don't understand why your benchmark uses threads. There no IO at all in the actions, so it makes no difference to any of the benchmarked frameworks.
100
Jean Boussier @byroot.bsky.social · 28/04/2026
But I wonder if this much custom routes is actually common. Might be fun to optimize regardless.
100
Jean Boussier @byroot.bsky.social · 28/04/2026
Which is just the basic linear regexp matching that Journey, and Rails hierarchical router syntax is designed to avoid. It wouldn't be too hard to split custom routes on `/` and use a trie, that would probably 5 or 10x that particular benchmark.
100
Jean Boussier @byroot.bsky.social · 28/04/2026
So we fall in github.com/rails/rails/... And 90% of the time is spent in there: share.firefox.dev/42z3hvP
github.com
rails/actionpack/lib/action_dispatch/journey/router.rb at 238111c4ded06c75db9bc497e65850337ddf8a19 · rails/rails
Ruby on Rails. Contribute to rails/rails development by creating an account on GitHub.
120
Jean Boussier @byroot.bsky.social · 28/04/2026
The Rails results are interesting, because while Journey performance normally scale better than alternatives with the number of routes, the benchmark hit a pretty big blind spot. All routes are defined as "custom routes" at the top level: `get "/segment-a/:a_id/subsegment-a/:id` etc.
github.com
rails/actionpack/lib/action_dispatch/journey/router.rb at 238111c4ded06c75db9bc497e65850337ddf8a19 · rails/rails
Ruby on Rails. Contribute to rails/rails development by creating an account on GitHub.
120
Jean Boussier @byroot.bsky.social · 28/04/2026
I had to debug a coworker's machine the other day because some gem wouldn't compile. Turned out they had a precompiled Ruby from mise. I'm no compiler/linker expert, but I'm not sure precompiled rubies are viable today, because of RbConfig / mkmf.
110
Reposted by Jean Boussier
Robby Russell @robbyonrails.com · 27/04/2026
Can you drop a link to this survey in your Discord/Slack? railsdeveloper.com/survey/
railsdeveloper.com
2026 Ruby on Rails Community Survey
The 2026 Ruby on Rails Community Survey is now open. Add your voice to the community data. Brought to you by Planet Argon.
088
Jean Boussier @byroot.bsky.social · 27/04/2026
bugs.ruby-lang.org/issues/16848
bugs.ruby-lang.org
Feature #16848: Allow callables in $LOAD_PATH - Ruby - Ruby Issue Tracking System
Redmine
000
Jean Boussier @byroot.bsky.social · 27/04/2026
Yes CRuby only. I did request a proper API to reduce hacks in bootsnap but the discussion died years ago.
100
Jean Boussier @byroot.bsky.social · 27/04/2026
It's indeed a bit beyond the original scope of Bootsnap. However since bootsnap caches Ruby compilation (ISeq) it is in a unique place to allow customizing the compilation. Gems like freezolite and require-hooks had to monkey patch it, so I figured I'd give proper hooks: github.com/ruby-next/re...
github.com
Bootsnap mode: improve cache invalidation by palkan · Pull Request #2 · ruby-next/require-hooks
What is the purpose of this pull request? Improve cache invalidation when using Bootsnap: make sure the code affected by the hooks is recognized as stale when we activate hooks, change configuratio...
120