Issue #22242 has been updated by kamipo (Ryuta Kamizono). A `VM_CHECK_MODE` build turns this from a rare SEGV in random places into an assertion at the moment the corrupted call cache is used, and the assertion says the cc is holding a reclaimed cme. ``` RUBY_CONFIGURE_OPTS="cppflags=-DVM_CHECK_MODE=1" ruby-build 4.0.6 ~/.rbenv/versions/4.0.6-vmcheck cd activerecord && bundle exec rake sqlite3_mem:test TESTOPTS="--seed=$RANDOM" ``` One hit in 53 full-suite runs (arm64-darwin25; lower rate than on CI here): ``` /vm_insnhelper.c:131: Assertion Failed: callable_method_entry_p:IMEMO_TYPE_P((VALUE)cme, imemo_ment): imemo_type:svar ruby 4.0.6 (2026-07-14 revision 03b6d3f889) +PRISM [arm64-darwin25] c:0082 METHOD .../active_support/notifications/fanout.rb:176 # Time.now ``` So `vm_cc_cme(cc)` points at an object whose imemo type is `svar`: the method entry was collected and its slot reused while a live cc still refers to it. The assertion fires from `vm_sendish`, i.e. at the `METHOD_ENTRY_INVALIDATED(vm_cc_cme(cc))` check in `vm_search_method_fastpath`, which is already reading freed memory. That is the invariant `rb_imemo_mark_and_move()` documents for `imemo_callcache`, so something frees a cme that a live, non-invalidated cc still refers to — which also explains why the fault addresses in this ticket vary so much. The crashes I have looked at are all on a plain `Time.now` call. `Time.now` is `def self.now(in: nil)` in `<internal:timev>`, i.e. keyword-only parameters, so it always takes the `kwparm_nokwarg` fast path, and it is also constantly redefined by `ActiveSupport::Testing::TimeHelpers`, which is presumably why this mid is the one that surfaces it. ---------------------------------------- Bug #22242: SEGV in method dispatch (`vm_call_iseq_setup_kwparm_nokwarg` / `def_iseq_ptr`) on Ruby 4.0.6 — Rails CI https://bugs.ruby-lang.org/issues/22242#change-118634 * Author: yahonda (Yasuo Honda) * Status: Open * ruby -v: ruby 4.0.6 (2026-07-14 revision 03b6d3f889) +PRISM [x86_64-linux] * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN ---------------------------------------- Recently Rails CI sometimes got SEGV. ## Steps to reproduce Run the Rails (rails/rails main branch) ActiveRecord test suite on Ruby 4.0.6, as Rails CI does. For example: ``` $ git clone https://github.com/rails/rails.git $ cd rails && bundle install $ cd activerecord $ bundle exec rake sqlite3_mem:test # also reproduced with trilogy:test and mysql2:test ``` The crash is intermittent (a small percentage of Rails CI runs) and the crashing test is different every time, so it may take many runs to reproduce. Rails CI log files for the five occurrences observed so far are attached, with Buildkite permalinks to the segfault in each job: - `rails_build_132123_activerecord-sqlite3-mem-4-dot-0.log` — https://buildkite.com/rails/rails/builds/132123#019fd767-de5d-4a26-8bd0-aa37... - `rails_build_132137_activerecord-trilogy-4-dot-0-mysql-5-7.log` — https://buildkite.com/rails/rails/builds/132137#019fd855-0650-42f5-8771-a683... - `rails_build_132289_activerecord-mysql2-4-dot-0-mariadb.log` — https://buildkite.com/rails/rails/builds/132289#019fe7b7-0c81-43bf-8661-7a3f... - `rails_build_132357_activerecord-sqlite3-mem-4-dot-0.log` — https://buildkite.com/rails/rails/builds/132357#019fefa9-5187-425b-9967-c10c... - `rails_build_132357_activerecord-trilogy-4-dot-0-mysql-5-7.log` — https://buildkite.com/rails/rails/builds/132357#019fefa9-5188-4728-b712-b226... ## Expected behavior It should always pass. ## Actual behavior The test process intermittently dies with `[BUG] Segmentation fault`. Every crash has the same signature: SEGV inside the interpreter's method dispatch while reading the iseq out of the callable method entry taken from an inline call cache — `def_iseq_ptr(vm_cc_cme(cc)->def)` — in either `vm_call_iseq_setup_kwparm_nokwarg` (vm_insnhelper.c:3116-3117) or `vm_call_iseq_setup_normal` (vm_insnhelper.c:3496): | Rails CI build | Job | Crashing test | Fault address | Crash frame | |---|---|---|---|---| | 132123 | activerecord sqlite3_mem (4.0) | NestedRelationScopingTest#test_nested_scoped_create | 0x17 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3116 | | 132137 | activerecord trilogy (4.0) [mysql_5_7] | CompatibilityTest5_1#test_datetime_doesnt_set_precision_on_change_column | 0x08 | vm_call_iseq_setup_normal vm_insnhelper.c:3496 | | 132289 | activerecord mysql2 (4.0) [mariadb] | OptimisticLockingTest#test_polymorphic_destroy_with_dependencies_and_lock_version | 0x17b9 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3117 | | 132357 | activerecord sqlite3_mem (4.0) | IntegrationTest#test_cache_version_format_is_not_too_precise | 0x1109 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3117 | | 132357 | activerecord trilogy (4.0) [mysql_5_7] | ActiveRecord::ConnectionAdapters::ConnectionHandlersShardingDbTest#test_establish_connection_using_3_levels_config_with_shards_and_replica | 0x18 | vm_call_iseq_setup_kwparm_nokwarg vm_insnhelper.c:3116 | The crash-site frames of the C-level backtraces, showing that all five crashes are duplicates of the same bug (full crash dumps are in the attached log files): Build 132123, activerecord sqlite3_mem (4.0): ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0x0) [0x7fa976246636] /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg) /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fa97625ecb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 ``` Build 132137, activerecord trilogy (4.0) [mysql_5_7]: ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0xd) [0x7ff68de8a350] /usr/src/ruby/vm_core.h:626 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_normal) /usr/src/ruby/vm_insnhelper.c:3496 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_normal_0start_0params_0locals) /usr/src/ruby/vm_call_iseq_optimized.inc:14 /usr/local/lib/libruby.so.4.0(vm_sendish+0xce) [0x7ff68de9692e] /usr/src/ruby/vm_insnhelper.c:6134 ``` Build 132289, activerecord mysql2 (4.0) [mariadb]: ``` /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg+0x2e) [0x7fb4fd53763e] /usr/src/ruby/vm_insnhelper.c:3117 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fb4fd54fcb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 /usr/local/lib/libruby.so.4.0(vm_exec_loop+0xa) [0x7fb4fd5565ca] /usr/src/ruby/vm.c:2825 ``` Build 132357, activerecord sqlite3_mem (4.0): ``` /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg+0x2e) [0x7ff26cc2163e] /usr/src/ruby/vm_insnhelper.c:3117 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7ff26cc39cb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 /usr/local/lib/libruby.so.4.0(vm_exec_loop+0xa) [0x7ff26cc405ca] /usr/src/ruby/vm.c:2825 ``` Build 132357, activerecord trilogy (4.0) [mysql_5_7]: ``` /usr/local/lib/libruby.so.4.0(def_iseq_ptr+0x0) [0x7fa242c65636] /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_call_iseq_setup_kwparm_nokwarg) /usr/src/ruby/vm_insnhelper.c:3116 /usr/local/lib/libruby.so.4.0(vm_sendish+0xb0) [0x7fa242c7dcb5] /usr/src/ruby/vm_insnhelper.c:6134 /usr/local/lib/libruby.so.4.0(vm_exec_core) /usr/src/ruby/insns.def:904 ``` ---Files-------------------------------- rails-ci-ruby406-segv-logs.zip (942 KB) rails_build_132611_activerecord-mysql2-4-dot-0.log.zip (314 KB) -- https://bugs.ruby-lang.org/