Skip to content

Bump sqlite3 from 2.9.5 to 2.9.6 in /ruby/driver/riverqueue-activerecord - #1488

Merged
bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6
Oct 9, 2026
Merged

bgentry merged 1 commit into
masterfrom
dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps sqlite3 from 2.9.5 to 2.9.6.

Release notes

Sourced from sqlite3's releases.

2.9.6 / 2026-08-11

Security / Stability

  • Fix a garbage collection bug where the argument array passed to a custom aggregate function's step was not visible to the GC, so arguments could be collected mid-conversion when the aggregate takes two or more arguments, corrupting the values passed to step or crashing the process. See GHSA-mwm8-39rw-8826 for more information. #733 @​jeremy

Fixed

  • Fix a leak where custom aggregate handler instances were never released, so a connection accumulated one instance per GROUP BY group per query for its lifetime. #722 @​djmb
  • Fix GC compaction issues with custom functions, aggregates, collations, #trace and #authorizer=. These callbacks were registered with sqlite by passing a raw Ruby object pointer as user data; keeping the object reachable prevented collection but not relocation, after which sqlite held a stale address and the next call could raise NoMethodError, return a wrong result, or segfault. Affects applications that call GC.compact or run with GC.auto_compact = true. The equivalent issue in #busy_handler was fixed in #466. #723 @​djmb
  • Fix the private methods Database#open_v2 and #open16 silently replacing a live connection and leaking the previous connection handle when invoked via send on an open database. They now raise SQLite3::Exception. #729 @​flavorjones
  • Fix TEXT values containing an embedded NUL byte being truncated at the first NUL when passed as arguments to functions created with Database#define_function. #730 @​flavorjones
  • Fix an exception raised inside a Database#define_function block leaving the connection's sqlite mutex held, which deadlocked any other thread that later used the connection. The exception now propagates to the caller and the connection remains usable. #731 @​flavorjones
  • Database.new now raises ArgumentError when the filename or VFS name contains an embedded NUL byte (or an embedded 0x0000 code unit in a UTF-16 filename), instead of silently opening a path truncated at the NUL. #732 @​flavorjones

Improved

  • When Database.new fails to open the database file, the underlying sqlite3 connection handle is now closed immediately instead of waiting for the garbage collector to clean it up. #719 @​katafrakt
d8b1f7d23efd7abac285775a9566562fc7debfef79d594e3a20354406fb7907c  gems/sqlite3-2.9.6-aarch64-linux-gnu.gem
3579e1c98cdc7ff5c3722847bb63ed4e1efb7ff675cb5e1e48ef2d4da5fb3bc9  gems/sqlite3-2.9.6-aarch64-linux-musl.gem
33541500e3615da02afe54a9cc38b17a6985d3cf9d8b76d6d0a83002f114e7ec  gems/sqlite3-2.9.6-arm-linux-gnu.gem
c5490af48bb228fefa54314e9541375c3907e70f8109f3881b5ff97e1c93ae33  gems/sqlite3-2.9.6-arm-linux-musl.gem
849b5d7f795e60fe25076d62c72dd722beb45b3850b516ad978d60ee848ec15b  gems/sqlite3-2.9.6-arm64-darwin.gem
1f2b88f417fd0a8c1d5ef19c7e817d8b9c61bee6e33b6b36255fb6e40148e6f8  gems/sqlite3-2.9.6-x64-mingw-ucrt.gem
fbaa9f46f9708f57dd8a459b37fc269f9613e0cacf1547df01aa439cc45c20c0  gems/sqlite3-2.9.6-x86-linux-gnu.gem
6715026fbb5530e810b28ef43b9c4f84cd3c991f67b9d808a31fcc32b847abbd  gems/sqlite3-2.9.6-x86-linux-musl.gem
b5842fea77781c14da03fa7bc0feb82db03a69e135affcb6f5399cbd2797a5f3  gems/sqlite3-2.9.6-x86_64-darwin.gem
613188ce02f614126ddbc38c5e217ccffd6306d0dcd9adca9764547aa890a634  gems/sqlite3-2.9.6-x86_64-linux-gnu.gem
d493b11818a3573387a1d56e1ee8fa00da23a683a7a1cc063e7a0feeed843abf  gems/sqlite3-2.9.6-x86_64-linux-musl.gem
956fe606956420d04ac7157d3ace620c8caba2135b2e05c76e483493da24d08e  gems/sqlite3-2.9.6.gem
Changelog

Sourced from sqlite3's changelog.

2.9.6 / 2026-08-11

Security / Stability

  • Fix a garbage collection bug where the argument array passed to a custom aggregate function's step was not visible to the GC, so arguments could be collected mid-conversion when the aggregate takes two or more arguments, corrupting the values passed to step or crashing the process. See GHSA-mwm8-39rw-8826 for more information. #733 @​jeremy

Fixed

  • Fix a leak where custom aggregate handler instances were never released, so a connection accumulated one instance per GROUP BY group per query for its lifetime. #722 @​djmb
  • Fix GC compaction issues with custom functions, aggregates, collations, #trace and #authorizer=. These callbacks were registered with sqlite by passing a raw Ruby object pointer as user data; keeping the object reachable prevented collection but not relocation, after which sqlite held a stale address and the next call could raise NoMethodError, return a wrong result, or segfault. Affects applications that call GC.compact or run with GC.auto_compact = true. The equivalent issue in #busy_handler was fixed in #466. #723 @​djmb
  • Fix the private methods Database#open_v2 and #open16 silently replacing a live connection and leaking the previous connection handle when invoked via send on an open database. They now raise SQLite3::Exception. #729 @​flavorjones
  • Fix TEXT values containing an embedded NUL byte being truncated at the first NUL when passed as arguments to functions created with Database#define_function. #730 @​flavorjones
  • Fix an exception raised inside a Database#define_function block leaving the connection's sqlite mutex held, which deadlocked any other thread that later used the connection. The exception now propagates to the caller and the connection remains usable. #731 @​flavorjones
  • Database.new now raises ArgumentError when the filename or VFS name contains an embedded NUL byte (or an embedded 0x0000 code unit in a UTF-16 filename), instead of silently opening a path truncated at the NUL. #732 @​flavorjones

Improved

  • When Database.new fails to open the database file, the underlying sqlite3 connection handle is now closed immediately instead of waiting for the garbage collector to clean it up. #719 @​katafrakt
Commits
  • a52dc0d version bump to v2.9.6
  • cc5ac0c Root the aggregate argument array so GC cannot free live values (GHSA-mwm8-39...
  • abcb0f6 Reject database filenames and VFS names containing NUL (#732)
  • 1d86b7a Raise when open_v2 or open16 is called on an open database (#729)
  • 7230171 Stop a raise inside a UDF block from deadlocking other threads (#731)
  • 2677f9a Pass TEXT values containing embedded NULs to UDFs intact (#730)
  • 3de8f6e doc: update CHANGELOG.md
  • ac6bd2f Release aggregate instances when sqlite finishes with them (#722)
  • 32460e9 Stop sqlite calling into moved Ruby objects (#723)
  • f600993 build(deps-dev): update rubocop-minitest requirement (#727)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Oct 9, 2026
@bgentry

bgentry commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [sqlite3](https://github.com/sparklemotion/sqlite3-ruby) from 2.9.5 to 2.9.6.
- [Release notes](https://github.com/sparklemotion/sqlite3-ruby/releases)
- [Changelog](https://github.com/sparklemotion/sqlite3-ruby/blob/main/CHANGELOG.md)
- [Commits](sparklemotion/sqlite3-ruby@v2.9.5...v2.9.6)

---
updated-dependencies:
- dependency-name: sqlite3
  dependency-version: 2.9.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6 branch from ef1e73c to d814cb8 Compare October 9, 2026 23:46

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security and compatibility review.

Upgrade

  • sqlite3: 2.9.5 → 2.9.6, the Active Record adapter's development/test dependency, for both arm64-darwin and x86_64-linux-gnu.
  • Reviewed current head: d814cb8cfb5a0ed968f046af813491cfea1a1533; base: 2e37dd3b756b856e971f32c3811c8cf8476236f8.

Security review

  • Confirmed fix for GHSA-mwm8-39rw-8826: GC can free TEXT/BLOB values used by multi-argument aggregates in versions through 2.9.5. Inspected the actual C fix rooting argument storage with ALLOCV_N/ALLOCV_END, callback/compaction lifetime fixes, and all published source changes.
  • Downloaded all six old/new source and platform gem artifacts. Whole-gem SHA256 matches RubyGems and upstream release checksums; internal archive hashes match. All 198 packaged files with corresponding upstream-tag files match byte-for-byte. Authors, source, license, dependency graph, extension hooks, and runtime loader remain consistent with upstream. Bundled SQLite stays at 3.53.2 with an unchanged source archive.
  • Statically inspected all eight rebuilt native binary pairs (two platforms, four Ruby ABIs). Library dependencies are unchanged; import changes correspond to the reviewed GC/buffer/hash/string fixes, with no suspicious new network/credential/process strings. The build environment allowlist is unchanged. No unexpected trust expansion or blocking supply-chain issue found. Exact-version advisory query for 2.9.6 returns no remaining advisories.
  • Current arm64 artifact SHA256 is 849b5d7f795e60fe25076d62c72dd722beb45b3850b516ad978d60ee848ec15b; Linux GNU is 613188ce02f614126ddbc38c5e217ccffd6306d0dcd9adca9764547aa890a634. The local cache matches the reviewed arm64 identity.
  • Reused exact version/platform/checksum source and pairwise evidence from initially reviewed head ef1e73c7481a5ef53811378c0ae80794035ae423. Re-read the rebased PR and inspected the security delta: the only added base change is the already-reviewed JSON 2.19.3 → 2.19.9 security fix from #1489. The current PR still changes only the same two SQLite version entries; no new artifacts, graph churn, integrity rewrites, or other source changes appear. Parallel per-PR review is consolidated here; the coordinator performs all validation and GitHub writes.

Compatibility verification

  • Reinstalled all four bundles frozen at the current head's exact gem versions in isolation. Ruby 3.3.12/macOS arm64 requires a temporary arm64-darwin-25 → arm64-darwin-27 platform-label adjustment only; no dependency entries change. Temporary labels are restored afterward and the tracked tree is clean.
  • SQLite aggregate regression: 200 two-argument, 2 KB text rows under GC.stress — passed with loaded SQLite3 2.9.6. JSON streaming-buffer/parser/generator regression — passed with loaded JSON 2.19.9 on this combined tree.
  • Refreshed make test/ruby with required Postgres 18.6 and SQLite coverage — passed: 2,357 examples, zero failures, one expected Ruby-4-only Ractor example pending locally.
  • Refreshed make lint/ruby typecheck/ruby verify/ruby-migrations build/ruby — passed, including four gem builds and 32 migrations.
  • Reused successful make test, make lint, make tidy, make verify/migrations verify/rust-migrations verify/sqlc check/modzip, and CHECK=true make update-mod-go evidence: a complete tree comparison against validated JSON head fc101deff53f5501f5e7270d8df19ad527d81c30 shows no changes outside this Active Record lockfile. All Go, generator, SQL, module, CI, and other relevant inputs are identical.
  • Current-head GitHub CI is green, including Ruby 3.2–4.0/Postgres 14–18, SQLite, Rails, Go race tests, and Linux/Windows CLI. Bot CodeQL is neutral; no CodeQL analysis result is claimed.

Residual risk

  • Gems are unsigned. Precompiled binary behavior was screened statically; equivalence to reviewed source was not established through a reproducible rebuild. Local runtime checks cover arm64/Ruby 3.3; GitHub CI supplies the Linux and broader Ruby matrix. No blocking findings identified.

@bgentry
bgentry merged commit d1a7694 into master Oct 9, 2026
26 checks passed
@bgentry
bgentry deleted the dependabot/bundler/ruby/driver/riverqueue-activerecord/sqlite3-2.9.6 branch October 9, 2026 23:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant