From: ts Date: 2006-05-06T20:59:06+09:00 Subject: Re: [BUG] segfault on Proc#call after setting a trace_func >>>>> "M" == Mauricio Fernandez writes: M> l.call Not sure, but it seems to be in proc_invoke() /* modify current frame */ ruby_frame->block = &_block; PUSH_TAG((pcall&YIELD_LAMBDA_CALL) ? PROT_LAMBDA : PROT_NONE); state = EXEC_TAG(); if (state == 0) { proc_set_safe_level(proc); result = rb_yield_0(args, self, (self!=Qundef)?CLASS_OF(self):0, pcall | YIELD_PROC_CALL, avalue); } else if (TAG_DST()) { result = prot_tag->retval; } POP_TAG(); ruby_wrapper = old_wrapper; POP_VARS(); Unfortunately the old block (ruby_frame->block) is never restored when ruby leave proc_invoke() Now when it call call_trace_func() PUSH_TAG(PROT_NONE); will create a 'struct tag' which "overlap" with the variable _block (which is out of scope because ruby has leaved proc_invoke()) and this is at this step that it erase some fields in the struct BLOCK and it crash when it try a call to rb_f_binding() Guy Decoux