Skip to content

bundle exec under an older locked Bundler raises CorruptBundlerInstallError when the default Bundler is 4.1.0.beta1 #9919

Description

@flavorjones

Describe the problem as clearly as you can

When using ruby/setup-ruby on GitHub Actions, which installs gems using BUNDLE_PATH and installs the Bundler version locked in Gemfile.lock, bundle exec aborts with Bundler::CorruptBundlerInstallError.

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
      - uses: ruby/setup-ruby@v1
        with:
          ruby-version: head
          bundler-cache: true
      - run: bundle exec rake

This happens on Ruby head, where 4.1.0.beta1 is the default RubyGems, and on any Ruby after gem update --system 4.1.0.beta1.

What I think is going on here

Since 268b317b (#9650), bundler.gemspec lists copies of RubyGems files, such as lib/rubygems/vendor/uri/** and lib/rubygems/yaml_serializer.rb (bundler.gemspec:46-52). When Bundler is the default gem, Gem.register_default_spec maps each of those require paths to the default Bundler (rubygems.rb:1323-1336). Kernel#require then activates the default Bundler for any of those paths if no bundler gem is activated yet (kernel_require.rb:45-69).

Under bundle exec, Bundler 4.0.18 is loaded through RUBYLIB, so no bundler gem is activated. By the time it evaluates the Gemfile, Bundler has pointed Gem.path at BUNDLE_PATH, where 4.0.18 is not installed. RubyGems prefers the locked Bundler version only when it is on Gem.path (bundler_version_finder.rb:30-35), so the only candidate left is the default gem. Bundler 4.0.18's require "rubygems/vendor/uri/lib/uri" (vendored_uri.rb:10 in 4.0.18) therefore activates the default Bundler 4.1.0.beta1. Bundler::Source::Metadata#specs then raises on the version mismatch (metadata.rb:13-14 in 4.0.18).

A possible fix is for Gem.register_default_spec to skip rubygems/ paths, since RubyGems owns those files. The Bundler gem would still ship its copies; only the default gem's require-path mapping changes. I opened #9920 with this fix and a test.

Did you try upgrading rubygems & bundler?

Yes. RubyGems 4.1.0.beta1 is the latest release. Updating the lockfile to Bundler 4.1.0.beta1 avoids the error.

Post steps to reproduce the problem

FROM ruby:4.0
RUN gem update --system 4.1.0.beta1 --no-document && gem install bundler -v 4.0.18 --no-document
ENV BUNDLE_PATH=/app/vendor/bundle
WORKDIR /app
RUN printf 'source "https://rubygems.org"\ngem "rake"\n' > Gemfile && bundle _4.0.18_ lock && bundle install

Which command did you run?

docker build -t repro . && docker run --rm repro bundle exec ruby -e 'puts Bundler::VERSION'

What were you expecting to happen?

It prints 4.0.18.

What happened instead?

/usr/local/bundle/gems/bundler-4.0.18/lib/bundler/source/metadata.rb:14:in 'block in Bundler::Source::Metadata#specs': The running version of Bundler (4.0.18) does not match the version of the specification installed for it (4.1.0.beta1). This can be caused by reinstalling Ruby without removing previous installation, leaving around an upgraded default version of Bundler. Reinstalling Ruby from scratch should fix the problem. (Bundler::CorruptBundlerInstallError)
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/index.rb:9:in 'Bundler::Index.build'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/source/metadata.rb:7:in 'Bundler::Source::Metadata#specs'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:756:in 'Bundler::Definition#materialize'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:250:in 'Bundler::Definition#specs'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:323:in 'Bundler::Definition#specs_for'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/runtime.rb:18:in 'Bundler::Runtime#setup'
	from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler.rb:166:in 'Bundler.setup'
	...

If not included with the output of your command, run bundle env and paste the output below

bundle env

Environment

Bundler       4.0.18
  Platforms   ruby, x86_64-linux
Ruby          4.0.7p0 (2026-09-15 revision 229531a6cfbf07e3caef30dbac24a2a3f3fed482) [x86_64-linux]
  Full Path   /usr/local/bin/ruby
  Config Dir  /usr/local/etc
RubyGems      4.1.0.beta1
  Gem Home    /usr/local/bundle
  Gem Path    /root/.local/share/gem/ruby/4.0.0:/usr/local/lib/ruby/gems/4.0.0:/usr/local/bundle
  User Home   /root
  User Path   /root/.local/share/gem/ruby/4.0.0
  Bin Dir     /usr/local/bundle/bin
Tools         
  Git         2.47.3
  RVM         not installed
  rbenv       not installed
  chruby      not installed

Bundler Build Metadata

Timestamp  2026-09-29
Git SHA    7e934435ff

Bundler settings

app_config
  Set via BUNDLE_APP_CONFIG: "/usr/local/bundle"
path
  Set via BUNDLE_PATH: "/app/vendor/bundle"
silence_root_warning
  Set via BUNDLE_SILENCE_ROOT_WARNING: true

Gemfile

Gemfile

source "https://rubygems.org"
gem "rake"

Gemfile.lock

GEM
  remote: https://rubygems.org/
  specs:
    rake (13.4.2)

PLATFORMS
  ruby
  x86_64-linux

DEPENDENCIES
  rake

CHECKSUMS
  bundler (4.0.18) sha256=02d9a17429de1847b4e0c9f27a9ee4b20c0a74c0a641b4e77195d6019e3618ac
  rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701

BUNDLED WITH
  4.0.18

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions