Issue #22242 has been updated by yahonda (Yasuo Honda). The crash does not reproduce on master, so bisecting from the 4.0 branch point (d375bcc965d4) gives the first fixed commit:
1da540aeaa1507af4c050bf8a6ee2802e65f9aac "Invalidate CC on cme free as well" (gc.c, +3/-1)
The boundary is sharp between 1da540aeaa and its parent commit 3c251f79a3d9, each built and run through the reproducer up to 1,200 times (the per-commit budget for the bisect): the parent crashes with the same signature (at run 101), while 1da540aeaa completes all 1,200 runs cleanly. **Your `Time.now` observation also explains the reproducer's two files.** A per-file bisect of the Active Record suite narrows CI to the smallest reliable reproducer (one process per run, official ruby:4.0.6 image, recent rails main, in-memory SQLite; the crash is not commit-specific): | test files | crashes / runs | |---|---| | primary_keys_test.rb + timestamp_test.rb, `--seed 57420` | 162 / 400 (≈40%) | | 8-file control set without primary_keys_test.rb | 0 / 37,239 | primary_keys_test.rb is the file that enters multi-Ractor mode (its `test_primary_key_can_be_read_from_a_ractor_*` tests). timestamp_test.rb is the file that drives `ActiveSupport::Testing::TimeHelpers`, i.e. the constant `Time.now` redefinition you point to. Dropping either file gives zero crashes. The rate is very seed-sensitive: the favorable order from `--seed 57420` crashes about 40% of runs, whereas a random seed is around 0.78% (~1 in 130). Consistently, in all six Rails CI failures inspected so far (builds 132123, 132137, 132655, 132673, 132698, 132752), the failure occurred between 1.4 s and about 130 s after the Ractor tests had run in the same process. Since the initial report, this signature keeps recurring — ten and counting. Reproducer. The bug is not specific to this commit; the commit is pinned only so that `--seed 57420` reliably reproduces the same test order — a seed fixes the order only relative to a given set of tests — and that order crashes fast (about 40% of runs here, usually within a few iterations). On any other recent checkout, drop the `git checkout` and `--seed` and loop with a random seed instead (~0.78%, ~10 minutes). ```sh git clone https://github.com/rails/rails && cd rails git checkout 1f0c247be3da # not commit-specific; pins so --seed 57420 gives the same test order bundle install cd activerecord export ARCONN=sqlite3_mem while :; do bin/test test/cases/primary_keys_test.rb test/cases/timestamp_test.rb --seed 57420 >/tmp/run.log 2>&1 grep -qE "\[BUG\]|Segmentation fault" /tmp/run.log && break done tail -60 /tmp/run.log ``` ---------------------------------------- Bug #22242: SEGV in method dispatch (`vm_call_iseq_setup_kwparm_nokwarg` / `def_iseq_ptr`) on Ruby 4.0.6 — Rails CI https://bugs.ruby-lang.org/issues/22242#change-118649 * Author: yahonda (Yasuo Honda) * Status: Open * ruby -v: ruby 4.0.6 (2026-07-14 revision 03b6d3f889) +PRISM [x86_64-linux] * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN ---------------------------------------- Recently Rails CI sometimes got SEGV. ## Steps to reproduce Run the Rails (rails/rails main branch) ActiveRecord test suite on Ruby 4.0.6, as Rails CI does. For example: ``` $ git clone https://github.com/rails/rails.git $ cd rails && bundle install $ cd activerecord $ bundle exec rake sqlite3_mem:test # also reproduced with trilogy:test and mysql2:test ``` The crash is intermittent (a small percentage of Rails CI runs) and the crashing test is different every time, so it may take many runs to reproduce. Rails CI log files for the five occurrences observed so far are attached, with Buildkite permalinks to the segfault in each job: - `rails_build_132123_activerecord-sqlite3-mem-4-dot-0.log` — https://buildkite.com/rails/rails/builds/132123#019fd767-de5d-4a26-8bd0-aa37... - `rails_build_132137_activerecord-trilogy-4-dot-0-mysql-5-7.log` — https://buildkite.com/rails/rails/builds/132137#019fd855-0650-42f5-8771-a683... - `rails_build_132289_activerecord-mysql2-4-dot-0-mariadb.log` — https://buildkite.com/rails/rails/builds/132289#019fe7b7-0c81-43bf-8661-7a3f... - `rails_build_132357_activerecord-sqlite3-mem-4-dot-0.log` — https://buildkite.com/rails/rails/builds/132357#019fefa9-5187-425b-9967-c10c... - `rails_build_132357_activerecord-trilogy-4-dot-0-mysql-5-7.log` — https://buildkite.com/rails/rails/builds/132357#019fefa9-5188-4728-b712-b226... ## Expected behavior It should always pass. ## Actual behavior The test process intermittently dies with `[BUG] Segmentation fault`. Every crash has the same signature: SEGV inside the interpreter's method dispatch while reading the iseq out of the callable method entry taken from an inline call cache — `def_iseq_ptr(vm_cc_cme(cc)->def)` — in either `vm_call_iseq_setup_kwparm_nokwarg` (vm_insnhelper.c:3116-3117) or `vm_call_iseq_setup_normal` (vm_insnhelper.c:3496): | Rails CI build | Job | Crashing test | Fault address | Crash frame | |---|---|---|---|---| | 132123 | activerecord sqlite3_mem (4.0) | NestedRelationScopingTest#test_nested_scoped_create | 0x17 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3116 | | 132137 | activerecord trilogy (4.0) [mysql_5_7] | CompatibilityTest5_1#test_datetime_doesnt_set_precision_on_change_column | 0x08 | vm_call_iseq_setup_normal vm_insnhelper.c:3496 | | 132289 | activerecord mysql2 (4.0) [mariadb] | OptimisticLockingTest#test_polymorphic_destroy_with_dependencies_and_lock_version | 0x17b9 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3117 | | 132357 | activerecord sqlite3_mem (4.0) | IntegrationTest#test_cache_version_format_is_not_too_precise | 0x1109 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3117 | | 132357 | activerecord trilogy (4.0) [mysql_5_7] | ActiveRecord::ConnectionAdapters::ConnectionHandlersShardingDbTest#test_establish_connection_using_3_levels_config_with_shards_and_replica | 0x18 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3116 | The crash-site frames of the C-level backtraces, showing that all five crashes are duplicates of the same bug (full crash dumps are in the attached log files): Build 132123, activerecord sqlite3_mem (4.0): ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0x0) [0x7fa976246636] /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg) /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fa97625ecb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 ``` Build 132137, activerecord trilogy (4.0) [mysql_5_7]: ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0xd) [0x7ff68de8a350] /usr/src/ruby/vm_core.h:626 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_normal) /usr/src/ruby/vm_insnhelper.c:3496 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_normal_0start_0params_0locals) /usr/src/ruby/vm_call_iseq_optimized.inc:14 /usr/local/lib/libruby.so.4.0(vm_sendish+0xce) [0x7ff68de9692e] /usr/src/ruby/vm_insnhelper.c:6134 ``` Build 132289, activerecord mysql2 (4.0) [mariadb]: ``` /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg+0x2e) [0x7fb4fd53763e] /usr/src/ruby/vm_insnhelper.c:3117 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fb4fd54fcb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 /usr/local/lib/libruby.so.4.0(vm_exec_loop+0xa) [0x7fb4fd5565ca] /usr/src/ruby/vm.c:2825 ``` Build 132357, activerecord sqlite3_mem (4.0): ``` /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg+0x2e) [0x7ff26cc2163e] /usr/src/ruby/vm_insnhelper.c:3117 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7ff26cc39cb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 /usr/local/lib/libruby.so.4.0(vm_exec_loop+0xa) [0x7ff26cc405ca] /usr/src/ruby/vm.c:2825 ``` Build 132357, activerecord trilogy (4.0) [mysql_5_7]: ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0x0) [0x7fa242c65636] /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg) /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fa242c7dcb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 ``` ---Files-------------------------------- rails-ci-ruby406-segv-logs.zip (942 KB) rails_build_132611_activerecord-mysql2-4-dot-0.log.zip (314 KB) -- https://bugs.ruby-lang.org/