Sign in

John Hawthorn

@jhawthorn.com
1.2K followers 229 following 59 posts

Writing code for @Shopify, Rails, and Ruby. Previously @GitHub. he/him | Victoria, BC | jhawthorn.com

PostsRepliesMedia
Reposted by John Hawthorn
Peter Zhu @peterzhu.ca · 02/09/2026
Ruby's GC and ZJIT got a new collab! We recently introduced inlining of the garbage collector's fastpath into ZJIT. Read more about it here: railsatscale.com/2026-09-01-z...
railsatscale.com
ZJIT 🤝 GC: Inlining GC Fastpath in ZJIT
Object allocations from the garbage collector are now inlined in ZJIT.
1145
Reposted by John Hawthorn
XO Ruby @xoruby.com · 16/08/2026
Feeling on top of the world after a successful #Vancouver event.
A wide angle photo of the mountains and water visible from Squamish’s Sea To Sky Gondola
092
John Hawthorn @jhawthorn.com · 04/08/2026
I'll be speaking at XO Ruby Vancouver on August 15th www.xoruby.com/event/vancou...
xoruby.com
Vancouver
Coffee. Flannel. Van City, Eh.
0112
John Hawthorn @jhawthorn.com · 01/08/2026
I've added the WPBL to faceoff.now - faceoff.now/wpbl
faceoff.now
Faceoff
001
Reposted by John Hawthorn
Mike Dalessio @flavorjon.es · 29/07/2026
Upgrade Rails immediately, kids, this is a big one. github.com/rails/rails/...
github.com
Possible arbitrary file read and remote code execution in Active Storage variant processing
### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process envi...
14930
Reposted by John Hawthorn
k0kubun @k0kubun.com · 14/07/2026
Ruby 4.0.6 Released www.ruby-lang.org/en/news/2026... This is a routine update that includes bugfixes. We recommend upgrading your Ruby version at your earliest convenience.
ruby-lang.org
Ruby 4.0.6 Released | Ruby
Ruby 4.0.6 has been released.
0157
John Hawthorn @jhawthorn.com · 17/06/2026
> i'm going to become rich and famous after i invent a device that allows you to stab Claude Opus 4.8 in the face over the internet
270
John Hawthorn @jhawthorn.com · 12/05/2026
If you haven't upgraded yet, Ruby 4.0's garbage collection is generally much faster than 3.4. This patch release fixes the one area there had previously been a notable regression (allocating/freeing Classes).
0238
Reposted by John Hawthorn
k0kubun @k0kubun.com · 11/05/2026
Ruby 4.0.4 Released www.ruby-lang.org/en/news/2026... This is a routine update that includes bugfixes. We recommend upgrading your Ruby version at your earliest convenience.
ruby-lang.org
Ruby 4.0.4 Released | Ruby
Ruby 4.0.4 has been released.
02410
Reposted by John Hawthorn
Aaron Patterson @tenderlove.dev · 06/05/2026
Made a new blurg post about AI + OSS security. I was going to just complain on here, but I figured a short blog post would be better for my complaining 😂 tenderlovemaking.com/2026/05/06/r...
tenderlovemaking.com
Rails Security, AI, and IBB
For quite a few years the Rails project has been working with the Internet Bug Bounty (IBB). The IBB is an organization that awarded cash to security researchers that reported issues to OSS projects p...
44312
Reposted by John Hawthorn
Jean Boussier @byroot.bsky.social · 26/04/2026
github.com/rails/rails/...
github.com
Enable frozen string literal by default by byroot · Pull Request #57252 · rails/rails
Ref: rails/bootsnap#535 This only impact the app own code, and not dependencies. It is also possible to enable it for gems, but some old ones may still not be ready.
1131
Reposted by John Hawthorn
Aaron Patterson @tenderlove.dev · 18/04/2026
It's just a proof of concept, but this is how I wish Rust extensions for Ruby were written: github.com/tenderworks/...
github.com
GitHub - tenderworks/roost: Generate FFI bindings from Rust extensions
Generate FFI bindings from Rust extensions. Contribute to tenderworks/roost development by creating an account on GitHub.
2276
John Hawthorn @jhawthorn.com · 05/04/2026
Proud of this patch I landed to Ruby this week which makes constants inside of `class << self` scopes faster both in the interpreter and JITs. It's not the most complicated or even impactful, but something I've wanted to fix for years github.com/ruby/ruby/pu...
github.com
Use compile-time flag to determine when a singleton CREF is dynamic by jhawthorn · Pull Request #16604 · ruby/ruby
This aims to allow constant cache accesses inside a singleton CREF to use the same fastpath as most constant caches, without needing to re-check the CREF on every access. class Foo def self.foo1 ...
0190
John Hawthorn @jhawthorn.com · 01/04/2026
I've proposed adding $SECONDS, $RANDOM, and other bash features to Ruby bugs.ruby-lang.org/issues/21976
bugs.ruby-lang.org
Feature #21976: Add $SECONDS, $RANDOM, and other bashisms - Ruby - Ruby Issue Tracking System
Redmine
151
John Hawthorn @jhawthorn.com · 27/03/2026
If the catcher sees his shadow there's 6 more weeks of spring training
050
Reposted by John Hawthorn
k0kubun @k0kubun.com · 16/03/2026
Ruby 4.0.2 Released www.ruby-lang.org/en/news/2026... This is a routine update that includes a bugfix in YJIT for NoMethodError on Puma. We recommend upgrading your Ruby version at your earliest convenience.
ruby-lang.org
Ruby 4.0.2 Released | Ruby
Ruby 4.0.2 has been released.
01813
John Hawthorn @jhawthorn.com · 27/02/2026
Can't wait for Sunday's game
Hockey cards for Jenn Gardiner and Sarah NurseHockey cards for Emily Clarke, Natalie Spooner, Emma Maltais✨, Marie-Philip Poulin, and Laura StaceyMarie-Philip Poulin 💜 holographic hockey card. Also my boy Ernie Clement in the backgroundThe other side of the holographic duo Tim's hockey card is Laura Stacey. She was incredible at the Olympics. Also ern-dog and Paul Skenes are behind her because I have an eBay addiction. Send help.
150
Reposted by John Hawthorn
Stefanni Brasil @stefannibrasil.me · 27/01/2026
The latest faker's version includes this improvement! Nothing like profiling your code to get some quick wins. Huge thanks to @jhawthorn.com for creating Vernier 🤓 hexdevs.com/posts/optimi...
hexdevs.com
Optimizing load time for faker-ruby
A quick win that made loading faker-ruby 19% faster.
061
Reposted by John Hawthorn
Andrea Fomera @afomera.dev · 16/01/2026
hey folks, i’m a rails / ruby dev with a bit over 10 years of experience professionally and i was just hit with my second layoff. looking for a new role would love to chat! #rails #ruby.
53343
Reposted by John Hawthorn
hsbt @hsbt.org · 26/12/2025
Development of Ruby 4.1.0 started ``` ruby 4.1.0dev (2025-12-26T00:31:28Z master 290fa0d8b4) +YJIT +MN +PRISM [arm64-darwin25] ```
0275
Reposted by John Hawthorn
Max @bernsteinbear.com · 24/12/2025
ZJIT is available starting in Ruby 4.0! Please try it out on your test suite, maybe in a staging environment, and let us know how it goes! railsatscale.com/2025-12-24-l...
railsatscale.com
ZJIT is now available in Ruby 4.0
ZJIT is now available with the release of Ruby 4.0. Here’s an update of our progress.
2197
Reposted by John Hawthorn
Aaron Patterson @tenderlove.dev · 13/12/2025
One thing I'm really excited about in Ruby 4.0 is that object allocation is going to get a nice speed boost
Screenshot of a terminal demonstrating object allocation speedup. Ruby 4.0 is about 2x faster
38810
John Hawthorn @jhawthorn.com · 28/10/2025
To the uninitiated, this is what every baseball game is like.
030
John Hawthorn @jhawthorn.com · 19/10/2025
I made it easier to search Ruby's docs www.johnhawthorn.com/2025/searchi...
johnhawthorn.com
Searching Ruby's documentation - John Hawthorn
The official Ruby docs are at https://docs.ruby-lang.org/en/. This documentation (and any documentation built with rdoc 6.15.0 or greater) now can be searched using a query parameter. Check it out! ht...
2385
John Hawthorn @jhawthorn.com · 21/09/2025
I have a hard time placing exactly what it is, but something about `bat` and other "modern" TUI tools really rubs me the wrong way. They're clearly well made, I think it's more of an aesthetic thing where that is exactly what I was running away from by using command line tools.
471
Reposted by John Hawthorn
Jean Boussier @byroot.bsky.social · 11/08/2025
I took some time to delve into my latest work on reducing Ractor contention. This time: Generic Instance Variables byroot.github.io/ruby/perform...
byroot.github.io
Unlocking Ractors: generic instance variables
In two previous posts, I explained that one of the big blockers for Ractors’ viability is that while they’re supposed to run fully in parallel, in many cases, they’d perform worse than a single thread...
1166
Reposted by John Hawthorn
Aaron Patterson @tenderlove.dev · 05/08/2025
One of the AI generated security reports attached a bunch of MD files, and this screenshot was taken from the end of one of them. This gives me lots of feelings, and none of them are good
## 🚀 SUBMISSION STRATEGY

### Approach: "Professional Context-Dependent Security Issue"
- Not claiming pure remote RCE
- Focusing on real-world deployment risks
- Honest about context requirements
- Emphasizing practical security impact

### Expected Response:
```
"While not directly exploitable in default configuration, 
this represents a significant security risk in common 
deployment scenarios. We'll investigate and implement 
appropriate mitigations."
```

### Success Probability: 75%
- Technical merit: Clear vulnerability in core Rails
- Real-world relevance: Common deployment scenarios
- Professional quality: Comprehensive documentation
- Honest assessment: Context-dependent, not oversold

---

## ✅ READY TO SUBMIT!

**All information prepared for professional Rails bug bounty submission.**

**Expected Outcome:**
- Rails Team Response: 1-2 weeks
- Fix Development: 2-8 weeks
- Security Release: 8-12 weeks
- IBB Bounty: $1,040-1,600 (80% of $1,300-2,000)

**Next Step:** Copy information above into HackerOne form and submit!
2212
John Hawthorn @jhawthorn.com · 01/08/2025
"two buttons" meme where the guy can't decide between calloc(n, 1) and calloc(1, n)
1150
Reposted by John Hawthorn
k0kubun @k0kubun.com · 15/07/2025
Ruby 3.4.5 Released www.ruby-lang.org/en/news/2025... This is a routine update that includes bug fixes and GCC 15 support. We recommend upgrading your Ruby version at your earliest convenience.
ruby-lang.org
Ruby 3.4.5 Released
12910
Reposted by John Hawthorn
Matt Godbolt @matt.godbolt.org · 03/06/2025
It's been a while since I've written about the innards of @compiler-explorer.com. xania.org/202506/how-c... has the details, some statistics and some fun war stories.
xania.org
How Compiler Explorer Works in 2025 — Matt Godbolt’s blog
How we handle 92 million compilations a year without everything catching fire
35717
Reposted by John Hawthorn
Peter Zhu @peterzhu.ca · 03/06/2025
I just published "Implementing Embedded TypedData Objects" about a feature @byroot.bsky.social and I worked on for Ruby 3.3. A bit late, but better than never. railsatscale.com/2025-06-03-i...
railsatscale.com
Implementing Embedded TypedData Objects
We implemented a new feature to TypedData objects in Ruby, called embedded TypedData objects. TypedData objects are used across a wide variety of Ruby types, such as Time, Enumerator, and Method. This...
0153
John Hawthorn @jhawthorn.com · 27/05/2025
I'm a nervous flier, but fortunately I've downloaded the new season of Nathan Fielder's show "The Rehearsal" to distract me. No spoilers please, I want to go in blind
160
Reposted by John Hawthorn
Jean Boussier @byroot.bsky.social · 24/05/2025
I wrote a post to braindump what I'm currently working on: allowing lock-free access to class instance variables from Ractors. byroot.github.io/ruby/perform...
byroot.github.io
Unlocking Ractors: class instance variables
In a previous post about ractors, I explained why I think it’s really unlikely you’d ever be able to run an entire application inside a ractor, but that they could still be situationally very useful t...
1256
Reposted by John Hawthorn
k0kubun @k0kubun.com · 14/05/2025
Ruby 3.4.4 Released www.ruby-lang.org/en/news/2025... This release includes a fix for a YJIT bug related to local variables and addresses a build issue on Windows when using GCC 15. It was released ahead of schedule to make these fixes available as soon as possible.
ruby-lang.org
Ruby 3.4.4 Released
02411
Reposted by John Hawthorn
Jean Boussier @byroot.bsky.social · 26/04/2025
I did some sort of rubber duck blogging about a patch I'm currently working on: byroot.github.io/ruby/perform...
byroot.github.io
Unlocking Ractors: object_id
In a previous post about ractors, I explained why I think it’s really unlikely you’d ever be able to run an entire application inside a ractor, but that they could still be situationally very useful t...
2276
Reposted by John Hawthorn
JP Camara @jpcamara.com · 20/04/2025
If you read @byroot.bsky.social 's "What's the deal with Ractors?", and were bummed at how poorly they handled JSON parsing, then @jhawthorn.com has brightened your day! Frozen interned strings are now stored in a lock-free hash, making the Ractor example 2x faster than the single-threaded example!
# == single-threaded
# RUBY_YJIT_ENABLE=1 ruby parse.rb 1.12s user 0.11s system 77% cpu 1.599 total
# == master, pre-optimization
# RUBY_YJIT_ENABLE=1 ruby ractor_parse.rb  3.70s user 6.52s system 256% cpu 3.990 total
# == master, after https://github.com/ruby/ruby/pull/12921
# RUBY_YJIT_ENABLE=1 ruby ractor_parse.rb  1.31s user 0.28s system 210% cpu 0.754 total
13010
Reposted by John Hawthorn
Joshua Young @joshuay03.bsky.social · 10/04/2025
Announcing Dial, a Rails application profiler: github.com/joshuay03/dial I've longed for a free tool that provides Datadog-like profiles, with accurate GVL and GC activity. Thanks to @jhawthorn.com's amazing work on Vernier, all I needed to do was integrate it with Rails and let it do its thing.
github.com
GitHub - joshuay03/dial: A modern profiler for your Rails application
A modern profiler for your Rails application. Contribute to joshuay03/dial development by creating an account on GitHub.
23310
John Hawthorn @jhawthorn.com · 01/04/2025
I've just released unsafe 1.0.0! A gem bringing the power of Rust's unsafe to Ruby! github.com/jhawthorn/un...
github.com
GitHub - jhawthorn/unsafe: Just like in Rust!
Just like in Rust! Contribute to jhawthorn/unsafe development by creating an account on GitHub.
44812
John Hawthorn @jhawthorn.com · 25/03/2025
One of my favourite things (of many) about rr-project.org is how it actually complements my tendency to be a printf debugger, because it's so easy to start gdb at the point that the output goes wrong.
rr-project.org
rr: lightweight recording & deterministic debugging
030
Reposted by John Hawthorn
hsbt @hsbt.org · 19/03/2025
andpad.connpass.com/event/346737/ registration is opened now. We welcomed oversea guest for #rubykaigi
andpad.connpass.com
RubyKaigi 2025 前夜祭 Asakusa.rb Welcome Drinkup (2025/04/15 18:30〜)
## Overview 概要 On the day before RubyKaigi 2025, which will be the regular meeting day for Asakusa.rb, we will host a Welcome Drinkup as a pre-party for overseas committers and Rubyists attending the...
294
Reposted by John Hawthorn
Mike Perham :sidekiq: @getajobmike.ruby.social.ap.brid.gy · 26/02/2025
What's new? - Quickly and easily profile your jobs in production with Vernier integration. - View multi-day job execution metrics to see performance over time. - Heavily rewritten Web UI much faster than 7.3.0. - Many more small improvements Here's Web UI 7.3 vs 8.0.
7.38.0
293
John Hawthorn @jhawthorn.com · 24/02/2025
After an incredible 6.5+ years, Friday was my last day at GitHub. I'm so thankful to have gotten to know and have worked with such a smart and thoughtful group of people. I'm excited to continue working on Ruby as part of the Ruby and Rails Infrastructure team at Shopify ❤️ 💎
11911
John Hawthorn @jhawthorn.com · 13/02/2025
@byroot.bsky.social @bihi.bsky.social Very happy to deprecate my library thanks to all your work on JSON 🎉 github.com/jhawthorn/ra...
github.com
More explicitly recommend json · jhawthorn/rapidjson-ruby@9292377
2265
John Hawthorn @jhawthorn.com · 07/01/2025
GitHub is now running Ruby 3.4.1
416718
Reposted by John Hawthorn
k0kubun @k0kubun.com · 25/12/2024
www.ruby-lang.org/en/news/2024...
ruby-lang.org
Ruby 3.4.0 Released
04515
Reposted by John Hawthorn
Niki Tonsky @tonsky.me · 21/12/2024
I propose we replace semantic versioning with pride versioning
Diagram with large number: 2.7.123
First “2” is commented: Proud version. Bump when you are proud of the release
Second “7” is commented: Default version. Just normal/okay releases
Third “123” is commented: Shame version. Bump when fixing things too embarrassing to admit
332533737
John Hawthorn @jhawthorn.com · 18/12/2024
Vernier 1.5.0 is out! This has some significant changes including rewriting the timer thread sleeping (should be lighter weight), recording Fiber activity (thanks @tenderlove.dev), and showing file listings on the command line. Please let me know if you hit any issues 🙇‍♂️ github.com/jhawthorn/ve...
github.com
Release v1.5.0 · jhawthorn/vernier
This is the most significant release in a while. The timer thread should be lighter weight (hopefully without sacrificing too much accuracy), we now record fiber activity, and memory is measured ov...
14011
John Hawthorn @jhawthorn.com · 15/12/2024
You're telling me a duck typed this code?
4454
John Hawthorn @jhawthorn.com · 10/12/2024
Rails Versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1 have been released. rubyonrails.org/2024/12/10/R... These releases address a potential security vulnerability in applications with pass untrusted input to the content_security_policy helper.
rubyonrails.org
Rails Versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1 have been released!
Hi everyone!
3254
John Hawthorn @jhawthorn.com · 07/12/2024
I'm trying out AeroSpace (nikitabobko.github.io/AeroSpace/gu...). I'd used tiling window managers on Linux for a long time and just assumed they would be clunky on macos. So far it works great!
Two terminal windows side-by-side
4140