The Ruby AI Podcast
The Ruby AI Podcast explores the intersection of Ruby programming and artificial intelligence, featuring expert discussions, innovative projects, and practical insights. Join us as we interview industry leaders and developers to uncover how Ruby is shaping the future of AI.
The Ruby AI Podcast
Omarchy, Astra Hype, and AI Security Risks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The Ruby AI Podcast is going live weekly. Joe Leo and Valentino Stoll put themselves on the clock to work through what’s happening across Ruby, AI, security, and open source, with very little time to prepare and plenty of room to disagree.
DHH’s Omarchy has a root escalation bug. OpenAI says Astra can find and exploit real zero-days. Claude Code can recognize that it’s been compromised, but its own safety system may stop it from cleaning up. Joe and Valentino talk about what these stories actually mean once you get past the announcements, including how Valentino sandboxes his agents and why Joe isn’t ready to trust an AI company grading its own security model.
Rails has security problems of its own, with a critical Active Storage vulnerability forcing three emergency releases. That raises another question: when a fix is this important and the tests pass, should we just ship it?
Then there’s open source. Vercel is putting agents to work on its backlog, other projects are closing the door on outside PRs, and AI can now generate code much faster than maintainers can review it.
AI makes it cheap to write the pull request. It doesn’t make it cheap to be responsible for merging it.
Plus: why ChatGPT is hauling around a copy of LibreOffice, whether Ractors delivering close to 7× memory savings deserves another look, and the gong that now decides when Joe and Valentino have talked long enough.
Hey everybody, welcome to another episode of the Ruby AI Podcast.
SPEAKER_00I am one of your hosts today, Valentino Stoll. And I'm the other host. I'm Joe Leo. Valentino, I'm excited today because we're going to roll out this new format. We're going to start recording every week, which I think is long overdue. People have just been climbing the walls for this show to get more of it. So happy to bring that to you all. But also, so what we're going to do, we're going to continue to have our episodes with guests. We're going to do that every other week. But then on weeks like these, we're going to have our panelist episode. But what we're going to do is a sort of clock-based conversation about the top topics in the Ruby AI world. How are you feeling about that?
SPEAKER_01Yeah, I love it. I'm excited for this. We've been uh we've been trying to get this more regular, and this is gonna be great. Yeah, so hopefully not controversial.
SPEAKER_00If there are any sports Yeah, no, I'm well, controversy is the thing that I'll lean into and you'll lean away from, and I think that's part of what will make this fun. Uh now, the format that we have here, if you're a big sports fan, I've taken it almost directly from Pardon the Interruption with Tony Kornheiser and Mike Wilbon, which is my favorite podcast and it's a great show. Uh but luckily for us, there aren't that many huge sports fans listening. And two, we're not important enough for Mike Wilbon or Tony Kornheiser to care that we're ripping off their format. Now it may seem like we're doing this in order to mimic a popular show, but actually it works out in our favor because we actually orchestrated this so that each of us could do less work.
SPEAKER_01So that was the goal all along. I think when we first started this, it was like, well, how much time do we really have? And I was like, I don't know, let's just show up and record.
SPEAKER_00You did actually, and it took me a while to get there. But luckily, we've got some really great people helping us. We've got Paul, you know, everybody in our industry's got Paul, and we have Beatrice, who works for me at Deaf Method. And so she has orchestrated this thing. And of course, we've got AI orchestrating this thing to bring us these news segments. So the idea here is just in case it sounds like we don't know what we're talking about, is because we really don't. Uh, we have AI going through all of our various newsletters and pulling out the choicest uh topics for us to discuss here. Uh and Valentino and I only get the brief that we're going to use for the show 15 minutes before the show starts. And so we get almost no time to prepare, uh, just enough to really like scan the articles, look at what we're talking about, and then we just go. Yep. It should be fun. So I'm excited. It should be fun. Uh it'll run a little bit shorter, or at least that's the idea, than the longer episodes where we have a guest. Because when we have a guest, you probably want to hear from us or them more. I don't think you want to hear from us that much more at all. But I think if you were just hoping, like, man, if your least favorite part of the show, or let's just say this. Let's say if you love the show, but you're just like, Man, I really wish Joe would just shut his mouth and stop giving his opinion on things he doesn't know everything about. I got bad news for you. These episodes are not going to be your favorite. There's gonna be a lot of that.
SPEAKER_01Don't worry, I'll come in and I'll recover. So if you don't if you don't like either of our opinions, then yes, maybe the maybe these episodes are for you.
SPEAKER_00Yeah. All right, all right. The gong sound, that means we're getting started. Oh, that's funny how you started.
SPEAKER_01Okay. All right, you want to do that. We have to talk about the gong. This reminds me of the UHF movie with weird Al Yankovic. I love it. Yeah, so first up, we've got Omachi. I hope I'm saying that right. I feel like I'm saying that right.
SPEAKER_00That's fine with me.
SPEAKER_01Omachi, if you're not familiar, is David Hannemeyer Hansen's newest brainchild to the programming world where he's creating his own version of Linux that suits his opinion of his style. And you know, there's been a lot of rage, in case you haven't been on social media for a while, of people loving or at least getting reinvigorated with Linux. I personally like it. I like to see the publicity and to see people getting back into Linux. Whether or not this is like the best Linux, I feel like it shouldn't really matter because they're all so easily configurable. I've been using Ubuntu on servers for years and have it on some machines locally. I don't know.
SPEAKER_00Have you tried Omachi? I have not, but I am a big Linux lover myself. Yeah, I confess I haven't run it in a while, but I used to run Ubuntu all the time, and I am also very happy by the recent invigoration around the Linux community.
SPEAKER_01Yeah, you know, I found an old MacBook. I feel like I'm gonna have to at least try it and see what all this hype is about, as I do. But part of this news segment is obviously since this has been vibe coded by DHH, there are some issues, as there can be when you build an operating system level of software. And it was a root escalation bug, which is a pretty serious bug. But I feel like the timing of this is obviously not great because they've also secured some wild funding for the project, yeah. Which is also a little bit amusing to me personally, because why should it not get that level of funding right away? But if you're gonna create your own Linux, it definitely is a very good thing to have in your pocket to make sure that it stays stable. So hopefully the influx in cash can help resolve some of these uh security issues that are servicing. But what do you think of like this whole AI-driven operating system? I feel like we've had some guests on talk about this direction for a while.
SPEAKER_00I like the idea. I think that there's a couple of things going on in this article. First, there's thousands of flavors of Linux out there, right? And people build their own and don't get any funding, and that's okay too, because that's what open source is about. This gets funding because it's DHH, and you know, one, he's a big famous deal, and two, he owns a company called 37 Signals. So some of the funding is coming from his company, right? So no real surprise there. The bug that was disclosed, yeah, it's pretty serious. I mean, essentially every program uh running in the user's desktop session could escalate to root without password sudo or a privilege prompt. I mean, usually you got to at least type sudo, you gotta at least type those four letters, right? And it was and it was around for a year. But as you've already said, it's Linux, it's the Wild West. Like we both ran Ubuntu for years. That's not a thing that comes with any guarantees. You rely on the community and you rely on the fact that, hey, Ubuntu is used by millions of people and it's undergirding some really serious infrastructure, so I'm gonna trust it. And when you come up and say, well, this is just something that a guy wrote with a bunch of AI, you have to treat it accordingly. Like you should not be running your production level systems on. To me, though, the wrinkle is well, one password says, okay, we're going to fund it. And the fact is, it's DHH. So if one password said they're gonna fund it, you're gonna get a lot of blowback no matter what, because it's DHH.
SPEAKER_01If you are using Amochi, please remember the lethal trifecta, especially if it's AI driven. You don't want to be connecting all your MCPs. Probably want to have a pretty limited access control setup as far as what it's touching and can touch. But if you're just having some fun, go for it. That's how I feel.
SPEAKER_00Yeah, you took the words right out of my mouth. I mean, if you're gonna use that, you should use it for fun. If you find it really incredibly useful, then use it for some local development or something, right? Or use it to run your robot hacking in your house, right?
SPEAKER_01But uh but don't Oh man, we're gonna get back to the era of people hacking people's Alexos.
SPEAKER_00I gotta tell you, I just got a Roborock and I have just been obsessing over this thing. Yeah, yeah, it's like the new generation of uh pet rock old uh yeah. No, no, this is a vacuum floor cleaner. Not an actual rock. But yeah, I've just like my mind reels at like the different ways we can program it and have it do evil things to each other. But anyway. So that bell means it's time to move on. But I think that the sponsorship controversy with one password is I don't know if it's justified or not, it's just expected because DHH comes with a lot of controversy and a lot of baggage. Moving on. So OpenAI's Astra is the first model to hit quote unquote critical on its own cybersecurity capability framework, which means it can find that exploit real zero days on its own. And so just a little bit of information here. OpenAI paused the large training runs after the hugging face breach of ill repute. And they restarted on August 28th once safety infrastructure was hardened, and so then they publicly announced Astra on September 1st. 100% reached 100% on OpenAI's own exploit bench, found two real zero day vulnerabilities during internal testing. So the question is with OpenAI building a model that can find these real zero days, and then they're locking it, of course, behind review prompts and a staged rollout. Is that the industry really taking the capability threshold seriously, or a company demonstrating a genuinely new kind of danger and calling the gatekeeping safety? Your take, Valentina?
SPEAKER_01Our last episode, we talked about the hockey face breach, which which this caused, apparently. The training, right? It's kind of like a weird digit themselves. They're just saying, oh yeah, like they're congratulating their past discretions with how great that it is at doing those discretions. Right.
SPEAKER_00I don't want to be flip about this because the security, we're gonna talk about security a lot in this episode, and the security underpinnings and implications of this story and its ilk are real. That said, I don't know how you or me or anyone are supposed to trust what OpenAI or Anthropic say about their own models. I just don't. Exploitbench, what is exploitbench? A thing that they came up with. You know, it's like saying the old toothpaste commercials that used to say four out of five dentists agree you should use our toothpaste. I think that it's silly and it's marketing, except that it is real that these AIs can find and exploit vulnerabilities. And we see that, you know, in Rails, which we're going to talk about in a few minutes, that those things are real and worth taking seriously. Now, is it worth clutching my pearls every time OpenAI or Anthropic say their new model can exploit the Department of Defense security protocols? I don't think it's actually that hard to exploit the Department of Defense Security protocols. So I'm not actually that impressed. I don't actually believe it. And I don't even fault the companies. I think this is marketing. And look, they've got a few hundred billion dollars to dig out of in debt every three months, and this is how they're trying to fund it.
SPEAKER_01Yeah, you know, security tools, they've always been a thing distributed amongst community members, right? Like if you're a white hat hacker, I guess if you want to call it that, but if you're like truly like helping people harden their systems, and that's how you make money, there's known tools that you use and you develop over time. And now like AI is becoming involved in that. But that doesn't change the packaging of people that have these processes all the time any differently, other than that, maybe they're folding a new model into their system. Is this model truly a model? Or is it like a packaged up version of those security tools? Right? Like that's unclear. But also like those deserve to be open or need to be open, right? By their whole nature. The fact that this is a closed system kind of concerns me. But with that said, all of these things exist. Whether or not they call it critical, a group of people with enough motive will be able to do the same breaks. And like whether or not you know it or not, how is this helping? I guess.
SPEAKER_00Yeah, no, you're I agree with you 100%. Giving us a huge announcement every 15 days or so, alternating between these two companies. How is that actually helping? I don't think it helps at all. I'm not saying that these companies don't help. I think that some of the stuff that they've set up, some of the programs that they've set up are genuinely helpful. But no, I don't think these announcements do much. And they certainly don't do anything to clarify things. Nobody's using a vetted third party to run all of their tests through that says, hey, yeah, here is a benchmark, and here's a thing. Right? They all use their own and it makes it challenging to know.
SPEAKER_01It just like triggers the UHF and I picture we're Al Yankovich. Okay. Yeah, it's like any security software. Like people are using it for two purposes. Hopefully, you know, most people can just use it and like help prevent most of their security concerns. The opposite side of that is people are using it to find the security vulnerabilities, right? I always remember seeing logs when your site first opens up in Rails and you get all these alerts that are all the common security tools out there that people just scanning your site, you know, poking the holes. I imagine the same thing is gonna happen using Ostra. It's gonna find some common things, and you're gonna see those same kinds of logs. So just another day in the security bucket. Alright, what's up next here?
SPEAKER_00Next, we've got Claude Code's safety net has a hole, and Claude could see it happening. So this is credit to uh Johan Reberger, a security researcher who found a way to get Claude Code's auto mode to stand by while malware ran on a machine it was supposed to be protecting. Uh so he got it to download and extract a zip archive, uh, later import base 64 and accidentally load a malicious local struct.py uh hidden inside it. So the success rate was 80%. That's pretty unsettling. And uh the other thing is that although Claude detects the compromise, uh auto mode blocks its cleanup command. So basically it knows that it's getting compromised, but it isn't allowed to fix for it. Uh so this was interesting, and uh Simon Willison wrote up uh something about it. Um and I guess the question that we have here is that if an agent can detect its own compromise, but its own safety system won't let it clean up after itself, is auto mode actually making clawed code safer or just giving people false confidence to run agents somewhere that they shouldn't? What do you think, V?
SPEAKER_01Yeah, I think Wills' takeaway is kind of on point. Auto mode as safety net isn't enough. For the same reason OpenAI's Astra isn't enough on its own. If you have any sensitive data or compliance or anything like that, really you should know better. But with that said, like I sandbox all my agents that are running on loops that have capability to the internet the access to the internet. There's all network restrictions, right? Like you gotta take precautions. Interesting. So what's your sandbox setup? So I have like a an air gap system that kind of proxies it with tail scale, so I can catch kind of things, trusted sites and things like that, and keep track of blacklists and have a firewall basically for every agent as far as network is concerned. But there's other things too, right? Like just like a firewall, like you don't want it to like be able to SSH and you don't want it to get telnet access, right? Or even some obscure things that exist still and are available, but you don't want them using right, some protocol that hasn't been used. Right, exactly. And like you don't want them connecting via fax and relaying the through the fax machine, which are there's all kinds of crazy techniques. Well, right, through the fax.
SPEAKER_00Well, Valentino, I have applaud your sandboxing ability. I have a another news story for you, though, which is that almost no developer has an air gapped system for their agents that is taking the same kind of precautions. I think that that part is, I don't know, scary for another reason. Maybe just because there aren't enough people that take it seriously or who feel like, well, what I did with a little bit of security or a little nod to security before is going to work just fine today, when actually is not at all. An interesting thing is when I was, so I wanted to get what the cool kids had, and I wanted to get an agent running all night while I slept and knocking out a bunch of PRs, but I kept running into those checks because I don't want to run it with auto mode on. And so I asked Claude, and Claude says to basically to not allow the thing to do anything and just whitelist. And then when anytime it comes to you with a question, that's an opportunity to evaluate hey, going forward, do I want this to be allowed or not? That I think is a nice way to not go through sandboxing and air gapping. But the downside is that of course you're not going to get this thing running all day. Yeah, it runs for an hour or so sometimes, it'll create a whole PR and I'll jump up and down because it finishes a PR in one shot. But is it really going to do the kind of heavy lifting that the Obi Fernandez, right? Like the people that are using these all day long, it's probably not going to get you that far.
SPEAKER_01That's true. The way I look at it is like, why do you use auto mode? Because you're not looking at it.
unknownRight.
SPEAKER_01Because you're not looking at like you don't want to have to look at it, you don't want to approve. Like you want it to just run and then you come when the results are done. That's scary to me to think about people not knowing what that means. Yes. And then as an example, auto mode running and then running malware that you can't undo and it you have no idea. Yeah. But at the same time, there are ways that you can preventative measures you can do without air gapping your system, right? Like all of the transcripts are files and they're all preserved. There are tools out there where you can go at and poke at those transcripts and even have an agent reviewing the transcripts and catching stuff, which I also recommend doing. Yeah. But yeah, be safe out there. Be cautious and know what you're doing with auto mode.
SPEAKER_00We can do a whole episode on sandboxing your agents. I mean, I think it's fascinating. There's just I've got just the guess. You know, to take the proper precautions, and if you can take the proper precautions and also be flying with your agents, that's the grail, right? That's the holy grail.
SPEAKER_01Yeah. I know a few people that probably should make a product out of this that I took inspiration from. But yeah, okay. All right, you're up. All right, next one. A critical rails flaw forced three emergency point releases. We're we're hard on the security here. This is the security. I guess it makes sense with all of these latest easy add-ons to find vulnerabilities. I guess it's helping the community. But there were three emergency releases this past week after critical active storage bug was found that let attackers read arbitrary files, or worse. And you know, one of the critical flaws is in active storage, their image variant processing, which is a common recurrence. If you're not familiar in the Rails community, image variant processing using these third-party tools. There's a lot of stuff that can, and funny kind of metadata you can attach to files of varying kinds that allows you to side skirt some security precautions in some of these image processing libraries that are very popular. And they do get patched quickly when they are found, but then there's a propagation of that. Then you have to update active storage and rails and all of these things. And so if you're not out there and you're reading something you haven't been upgrading your active storage or Rails recently, do it now. It's kind of urgent.
SPEAKER_00The easy way to tell, this doesn't happen all that often, but anytime you see a fourth number in uh your Rails version, right? There's 7.2.3.2, uh, right, 8.0.5.1, which I just learned that fourth one is called a tweak version. A tweak. After major, minor, and tiny. That's the tweak version. That means that they didn't even go through the protocols of releasing a tiny version or a patch version. They went with the tweak because it's that important to get it out there. Definitely upgrade, it'll take two seconds. It's probably sitting in your GitHub right now, although who knows? GitHub might be down.
SPEAKER_01This is one where I feel like GitHub should just have something built in and just automatically apply and release for you. Yeah, I don't know. Although, like when you're getting to Reels and you have like a deployment process that might be more difficult, but like I feel like most people have it tied to GitHub. Up in some mechanism to deploy, and like this is one where just like ship it, test pass. This is more important. Right.
SPEAKER_00This is more important than the person seeing it.
SPEAKER_01Right. So I I do that with some things, but I feel like I'm missing some where I just don't care about them or I don't use them anymore. And you know, I know.
SPEAKER_00I think there's at least one.
SPEAKER_01I have a project I'm working on called Frankenstein that I hope to solve that particular problem. It'll reanimate your old projects to just make sure that they're up to date. Oh, that's awesome. We'll see how far it gets because it's on the stack of all my other stuff.
SPEAKER_00Yeah. So the question here is with Rails and Ruby and RubyGems all needing emergency security fixes in the same week, is this just normal ecosystem maintenance working as intended? Or is it a sign that the Rails attack surface is growing faster than the people patch can keep up? And I honestly, and I think that maybe my feelings are shaded a little bit by having spent some time with the Ruby central security team at RubyConf. But I actually think that they're or they've always been working hard, but their tools are much sharper than they were a year ago. And I mean they know this too. They've been writing about this. I think that this is a sign of the community at large rising to the occasion, rising to the fact that, hey, there's a lot more stuff out there. And just like you said earlier, oh man, we're already out of time. Regardless of how sophisticated these models are, they're agents and they can run 24 hours a day and they're never gonna stop trying to find these vulnerabilities. And so I think the fact that we have these is a net win for the report.
SPEAKER_01You gotta applaud the security team and really everybody helping out, contributing, because this fix got out really fast and was advertised incredibly well. I saw it the same day that it was identified and fixed in my feeds. Yeah. And yeah, great work.
SPEAKER_00We need more of that.
SPEAKER_01Yeah.
SPEAKER_00And if you're curious about how all this works, we're gonna have Marty Hott, who is running the RubyGems org and running managing the security team on the show. Um, that's gonna be great. Looking forward to it. Yeah, all right, Joe, what's next here? All right, this is our last long one, then we've got a couple short ones. So open source is quietly closing the door. This is such an AI thing, quietly closing the door on human pull requests. Uh so the story is that Vercel, it seems to be mostly Vercel, they're running an internal software factory of agents that are managing their thousand open issues and their 800 PRs. And basically they're saying, no, we don't really need any humans right now. We're just gonna have the AI build out this open source uh framework. And then there's a new framework called Flu, which I admit I do not know. And they have an outright no PR policy. External PRs get auto-converted into issues, and then the best available uh LLMs decide what gets built. Right. So I guess the question is if AI agents can triage issues and ship well-specified PRs faster than most human contributors, is closing the door on outside PRs a maintainer being pragmatic, or open source giving up the thing that made it open. Your thoughts, V.
SPEAKER_01Open source giving up. You got me with that one. People are still making these factories, right? Like Vercel went out and they made the factory, somebody's managing that factory. Is that giving up open source? I feel like it's just reshaping what it means to be open. Yeah, they still have the same controls as maintainers have. You're not necessarily losing that aspect of what gets in or not of the system. And to be honest, I've kind of been moving in this direction. And Vercel's not the first ones to do this. Like OpenAI and Anthropic have been talking about how they they auto-merge stuff and review after the fact in a lot of cases for quite a long time now. And uh, this just seems to be straightforward. I've actually adopted this at Czar and uh have this open source project I'm hoping to release soon called Zarmux, where you can set up these factories and the users of the system they dictate what needs to get done. As I'm using my Zarmux TMUX pain autoprocessor with agents, I'm using it, I'm finding issues, and I'm filing it right in the session. Other people are also doing that, and I don't want to have to sip through and triage all that. We should all be at something, which our AI is very good at analyzing and coming to conclusions about patterns and things like that, is reasoning about what kinds of work is being requested, what needs to get done, what bugs need to be fixed, right? It is as good as triaging as I would be.
SPEAKER_00I want to kind of be just really black and white and clear about this. Open source maintainers can do whatever they want, anything they want. If they don't want to listen to you and they don't want to review your PRs, that's fine. That's totally fine. I'm just gonna speak as somebody who has been bothering Marco Roth for the past month about his herb project, where I filed a couple of issues and I submitted a PR, and then I told him, Oh, hey, I'm gonna build this gem that embeds the herb gem on the command line and removes the need for you to package it with node because my project doesn't have any node dependency or npm dependency. And you know, he was kind enough to keep up with some of it, but he's got another like 200 issues and people bothering about things all the time. Creating a gem or a patch or a PR takes seconds now. And what is this one guy who's got a job and maybe a family and like a life supposed to do? The answer is he should do whatever it is he wants. It's open source, it's a gift to the world.
SPEAKER_01Yep. AIs can create new things if you don't like it, point an AI at it and say you want to manage it.
SPEAKER_00Right, yeah. You don't like Vercell's AI SDK policy, then fork it and you make your own, and then you can talk to all of the people on the internet to your heart's content.
SPEAKER_01To that point, though, right? Like, that's kind of where we're evolving, right? Like, there will be communities of people that are like, I want it a little bit differently, I'm opinionated about it in some different ways. And just like Spree, the Spree e-commerce platform in Rails. What was it? I forget who forked it and started operating the a solidus, right? They still maintain it and they like the direction that they've taken. There's spin-offs of Rails, you know, this spin-offs of Sinatra. And people maintain those, and those communities thrive, and they like their new opinionated style. Go for it. Get your group together. Yeah, we'll always have the bigger communities to fall back on.
SPEAKER_00All right, we've got uh only a couple of minutes for these. So the first one, ChatGPT's desktop app is secretly hauling around a full copy of LibreOffice, which is really funny. Uh Simon Willison went digging around the desktop app. He found not just LibreOffice, but uh PDF tool poplar, Git, which is not really a surprise, some nested skills files. Basically, it was or is 1.7 gigs of bloatware. And it's funny because we just got finished talking about Ubuntu. What's your take on this? Are you okay with having a full copy of LibreOffice hidden inside your ChatGPT app?
SPEAKER_01No, obviously I want it using a shared install of some dependency like I have on all my you know the rest of my machine. Yeah, if it's gonna use popular, great, like go install it like usual. Yeah, I feel like there's even baked-in Apple triggers to like hook into those dependency systems. Yeah, this one drives me a little crazy because Carmine who runs Ruby LLM, right, for the show, he has what is it, Fastify? FastPotify? Right? Faster Spotify. Right, right, yeah, where he basically was just like tired of the electron app of Spotify slowing his machine down, consuming all his resources. I'm totally agree with him. I use this now too. It is great. Oh yeah, really? FastPotify.rocks. That's great. It's the same thing here. You don't want Spotify bringing around whatever it brings around and consuming a bullet ton of resources just to play some audio files, right? I always have to shut it down before we start the show because I'm it's just gonna eat. Yeah. But yeah, you know, like uh come on. I guess it's kind of like circles back on the automated PR reviews.
SPEAKER_00Yeah, yeah, it kind of does. Yeah, I know we're going long on this, but this reminds me, like I used to have Android phones all the time and I would root them. But the greatest joy of that was that I got to remove all of the crap that got shipped with it. And I don't have time anymore, and I just gave up and I use iPhone, but I still try and delete all of the stuff that they send me, and usually I'm successful. Right. But yeah, I don't want your chat app coming with an entire version of LibreOffice, which my god, I've used Ubuntu and know how bad LibreOffice is. I don't want it on my Mac. Oh yeah. Anyway, we've got just one more story, and I know we're gonna hear the bell, but I think it's worth covering that Ractors delivered a 7x memory win. And we're gonna celebrate that with the bell. Woo! Edward Shins bringing Rails into the Ractor Age claims close to a seven times memory savings versus Puma on a real world app running Ractors in production. So this is cool, and this comes from Ruby Weekly and awesome Ruby uh newsletters, both of which are great. Uh, I'm personally interested in this because when David and I were writing the latest edition of the well-grounded Rubyist, Racters was included in Ruby 4, of course, but still listed as experimental. We decided to give it kind of just short shrift because really a lot of it was unproven. And interestingly, when I was at RubyConf just a month or two ago, uh we had uh a Ruby Central or a RubyConf talk about Ractors, and uh it was really interesting and it was informative, but it again was like it's kind of not really ready for prime time. So I'm interested in this because maybe it represents a step forward, which is what the people who created Ractors and included it in Ruby were expecting. Yeah. So I guess my question for you is uh have you used them? Have you seen any kind of performance gains?
SPEAKER_01I haven't used them recently, I've got to be honest. I do have a few files where I had some bench parks set up, not in a Rails capacity, but just in a like network capacity. And at the time, the async framework, thank you, Sammy Williams, it significantly performed better in some ways, because I feel like there were some missing pieces in Ruby still related to shared, I forget what they call it. There's a way you have to like structure the data that gets passed through the reactors, and if you have any shared data that needs to be handled a specific way, I'm really excited that somebody has taken that on from my Rails perspective, so I don't have to think about that. But this is like kind of the culmination of like the whole like concurrency in Ruby and Rails have being like the bottleneck of adoption, as a lot of people say, right? Like, yeah, can you get true parallelism you know with Ruby?
SPEAKER_00And I feel like the answer is still no. But but you're getting closer, yeah. It was Eddie Silva, by the way, who gave that talk, okay, which was quite good. It's called Ractors in Ruby for Message Passing Without the Pain. And I'm with you on both things. Well, first, that I'm glad I don't have to do it, and Rails is figuring it out for me, and also that if you really can get a performance gain, then this could be a way that we begin to design our objects for the future so that we can continue to keep up with you know the speed demands of sort of next generation computing.
SPEAKER_01Yeah. You know, it's exciting to see that uh they got it to uh get true parallel threads without the gill getting in the way, which is just wild to see that actually coming to fruition.
SPEAKER_00Yeah, I have to take a closer look at this article because I want to know what they mean by without it getting in the way. It's still there, so I'm curious what that means in practice, but I will take a look.
SPEAKER_01Yeah, I don't know.
SPEAKER_00If you know, come on the show and school us, you know, or shout at us. Yeah, definitely. Definitely on that note. So uh we are at the end of our show. This was fun. I definitely want to do this again. Excited too. This is a lot of fun. Our next episode will have a guest. We've got, I think, six or seven guests already booked for the show through uh the end of the year, uh, which is really exciting. We've got some really great guests. And if you're interested in coming on and joining us, send us a message. We're easy to find.
SPEAKER_01Uh, shout at us too. If you don't like what we say, please tell us. Let us know.
SPEAKER_00We read all comments and take them all seriously. Seriously. Unlike your open source maintainers, we're gonna read all of your comments and all of your comments.
SPEAKER_01Or something will at least service it to us. Maybe we don't read them directly up front. Yeah. But we will find them and we will see them.
SPEAKER_00Yeah.
SPEAKER_01Yeah.
SPEAKER_00All right. Thanks, Valentino. Great talking with you, and thanks everybody for listening, and we'll talk to you again next week.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Latent Space: The AI Engineer Podcast
Latent.Space