Actions
Bug #22411
closedAssertion Failed: class_call_alloc_func:rb_obj_class(obj) == rb_class_real(klass)
Bug #22411:
Assertion Failed: class_call_alloc_func:rb_obj_class(obj) == rb_class_real(klass)
Description
The following code:
Resulted in this output (RUBY_DEBUG build):
../object.c:2310: Assertion Failed: class_call_alloc_func:rb_obj_class(obj) == rb_class_real(klass)
ruby 4.1.0dev (2026-10-07) +PRISM [x86_64-linux]
-- Ruby level backtrace information ----------------------------------------
stat_min.rb:2:in '<main>'
stat_min.rb:2:in 'allocate'
-- C level backtrace information -------------------------------------------
(rb_assert_failure_detail+0x233) error.c:1268
(rb_assert_failure) (null):0
(RCLASS_INITIALIZED_P+0x0) object.c:2310
(class_get_alloc_func) object.c:2279
(rb_class_alloc) object.c:2270
(vm_call_cfunc_with_frame_+0x27b) ../vm_insnhelper.c:3906
(vm_call_method_each_type+0x24a) ../vm_insnhelper.c:4898
(vm_exec_core+0x113bc) ../vm_insnhelper.c:6285
(rb_vm_exec+0x242) vm.c:2909
On a non-debug build there is no crash, but the behaviour is wrong (regression; v3_4_0 source still passed klass):
class C < File::Stat; end
p C.allocate.class # ruby 3.2.3: C master: File::Stat
class D < File::Stat; def initialize(*) = (@x = 1); end
d = D.new("/")
p d.class, d.instance_variable_get(:@x) # 3.2: D, 1 master: File::Stat, nil (D#initialize is never called)
rb_stat_s_alloc(VALUE klass) calls stat_alloc(rb_cStat, &obj) instead of stat_alloc(klass, &obj).
This appears to have been introduced by 18a036a613 ("[Feature #21205] Define File::Stat#birthtime by statx");
before it the allocator was stat_new_0(klass, 0). Present in v4.0.7 and current master.
To reproduce:
Commit:
3296d5c99ce005e4698fb27a405e01d766ad2647 (2026-09-15); also reproduced on master 9ce0df671980d669cbab8afc48124c7453897533 (2026-10-07)
Build configuration:
../configure --disable-install-doc CC=clang-18 cflags="-fsanitize=address -fno-omit-frame-pointer -DUSE_MN_THREADS=0" cppflags="-DRUBY_DEBUG=1" optflags="-O1" debugflags="-g"
Operating System:
This bug was found by fusion-fuzz
Actions