↓ Ir para o conteúdo principal

← todas as notas

📎 Webclip

Why Ruby’s Timeout is dangerous (and Thread.raise is terrifying)

Julia Evans says Ruby’s Timeout looks convenient, but it works by starting another thread and using Thread.raise to interrupt the target thread after a delay. That means an exception can arrive during normal work, cleanup, rescue code, or object creation, so arbitrary code cannot defend against it safely.

She compares this with other languages: Java deprecated and disabled Thread.stop, Python’s interrupt_main is limited, C#’s Thread.Abort is considered dangerous, and C++ threads are not interruptible. Her conclusion is that a general timeout API that can stop any block of code is flawed, and that Ruby’s documentation should warn more strongly.

Reading notes
#

  • Timeout auto-terminates a potentially long-running operation after a fixed time.
  • Its implementation starts a thread and raises an exception in the original thread when the time is up.
  • Thread.raise can trigger an exception while network requests, cleanup, rescue blocks, or later database work are running.
  • The problem is not just Ruby’s implementation; interrupting an arbitrary block of code is unsafe in general.
  • Java’s interrupt model is presented as safer because interruption is only observed at specific points.
  • The post suggests Ruby documentation should use stronger warning language about Timeout and Thread.raise.