Describe the problem as clearly as you can
When using ruby/setup-ruby on GitHub Actions, which installs gems using BUNDLE_PATH and installs the Bundler version locked in Gemfile.lock, bundle exec aborts with Bundler::CorruptBundlerInstallError.
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: ruby/setup-ruby@v1
with:
ruby-version: head
bundler-cache: true
- run: bundle exec rake
This happens on Ruby head, where 4.1.0.beta1 is the default RubyGems, and on any Ruby after gem update --system 4.1.0.beta1.
What I think is going on here
Since 268b317b (#9650), bundler.gemspec lists copies of RubyGems files, such as lib/rubygems/vendor/uri/** and lib/rubygems/yaml_serializer.rb (bundler.gemspec:46-52). When Bundler is the default gem, Gem.register_default_spec maps each of those require paths to the default Bundler (rubygems.rb:1323-1336). Kernel#require then activates the default Bundler for any of those paths if no bundler gem is activated yet (kernel_require.rb:45-69).
Under bundle exec, Bundler 4.0.18 is loaded through RUBYLIB, so no bundler gem is activated. By the time it evaluates the Gemfile, Bundler has pointed Gem.path at BUNDLE_PATH, where 4.0.18 is not installed. RubyGems prefers the locked Bundler version only when it is on Gem.path (bundler_version_finder.rb:30-35), so the only candidate left is the default gem. Bundler 4.0.18's require "rubygems/vendor/uri/lib/uri" (vendored_uri.rb:10 in 4.0.18) therefore activates the default Bundler 4.1.0.beta1. Bundler::Source::Metadata#specs then raises on the version mismatch (metadata.rb:13-14 in 4.0.18).
A possible fix is for Gem.register_default_spec to skip rubygems/ paths, since RubyGems owns those files. The Bundler gem would still ship its copies; only the default gem's require-path mapping changes. I opened #9920 with this fix and a test.
Did you try upgrading rubygems & bundler?
Yes. RubyGems 4.1.0.beta1 is the latest release. Updating the lockfile to Bundler 4.1.0.beta1 avoids the error.
Post steps to reproduce the problem
FROM ruby:4.0
RUN gem update --system 4.1.0.beta1 --no-document && gem install bundler -v 4.0.18 --no-document
ENV BUNDLE_PATH=/app/vendor/bundle
WORKDIR /app
RUN printf 'source "https://rubygems.org"\ngem "rake"\n' > Gemfile && bundle _4.0.18_ lock && bundle install
Which command did you run?
docker build -t repro . && docker run --rm repro bundle exec ruby -e 'puts Bundler::VERSION'
What were you expecting to happen?
It prints 4.0.18.
What happened instead?
/usr/local/bundle/gems/bundler-4.0.18/lib/bundler/source/metadata.rb:14:in 'block in Bundler::Source::Metadata#specs': The running version of Bundler (4.0.18) does not match the version of the specification installed for it (4.1.0.beta1). This can be caused by reinstalling Ruby without removing previous installation, leaving around an upgraded default version of Bundler. Reinstalling Ruby from scratch should fix the problem. (Bundler::CorruptBundlerInstallError)
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/index.rb:9:in 'Bundler::Index.build'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/source/metadata.rb:7:in 'Bundler::Source::Metadata#specs'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:756:in 'Bundler::Definition#materialize'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:250:in 'Bundler::Definition#specs'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/definition.rb:323:in 'Bundler::Definition#specs_for'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler/runtime.rb:18:in 'Bundler::Runtime#setup'
from /usr/local/bundle/gems/bundler-4.0.18/lib/bundler.rb:166:in 'Bundler.setup'
...
If not included with the output of your command, run bundle env and paste the output below
bundle env
Environment
Bundler 4.0.18
Platforms ruby, x86_64-linux
Ruby 4.0.7p0 (2026-09-15 revision 229531a6cfbf07e3caef30dbac24a2a3f3fed482) [x86_64-linux]
Full Path /usr/local/bin/ruby
Config Dir /usr/local/etc
RubyGems 4.1.0.beta1
Gem Home /usr/local/bundle
Gem Path /root/.local/share/gem/ruby/4.0.0:/usr/local/lib/ruby/gems/4.0.0:/usr/local/bundle
User Home /root
User Path /root/.local/share/gem/ruby/4.0.0
Bin Dir /usr/local/bundle/bin
Tools
Git 2.47.3
RVM not installed
rbenv not installed
chruby not installed
Bundler Build Metadata
Timestamp 2026-09-29
Git SHA 7e934435ff
Bundler settings
app_config
Set via BUNDLE_APP_CONFIG: "/usr/local/bundle"
path
Set via BUNDLE_PATH: "/app/vendor/bundle"
silence_root_warning
Set via BUNDLE_SILENCE_ROOT_WARNING: true
Gemfile
Gemfile
source "https://rubygems.org"
gem "rake"
Gemfile.lock
GEM
remote: https://rubygems.org/
specs:
rake (13.4.2)
PLATFORMS
ruby
x86_64-linux
DEPENDENCIES
rake
CHECKSUMS
bundler (4.0.18) sha256=02d9a17429de1847b4e0c9f27a9ee4b20c0a74c0a641b4e77195d6019e3618ac
rake (13.4.2) sha256=cb825b2bd5f1f8e91ca37bddb4b9aaf345551b4731da62949be002fa89283701
BUNDLED WITH
4.0.18
Describe the problem as clearly as you can
When using
ruby/setup-rubyon GitHub Actions, which installs gems usingBUNDLE_PATHand installs the Bundler version locked inGemfile.lock,bundle execaborts withBundler::CorruptBundlerInstallError.This happens on Ruby head, where 4.1.0.beta1 is the default RubyGems, and on any Ruby after
gem update --system 4.1.0.beta1.What I think is going on here
Since 268b317b (#9650),
bundler.gemspeclists copies of RubyGems files, such aslib/rubygems/vendor/uri/**andlib/rubygems/yaml_serializer.rb(bundler.gemspec:46-52). When Bundler is the default gem,Gem.register_default_specmaps each of those require paths to the default Bundler (rubygems.rb:1323-1336).Kernel#requirethen activates the default Bundler for any of those paths if nobundlergem is activated yet (kernel_require.rb:45-69).Under
bundle exec, Bundler 4.0.18 is loaded throughRUBYLIB, so nobundlergem is activated. By the time it evaluates the Gemfile, Bundler has pointedGem.pathatBUNDLE_PATH, where 4.0.18 is not installed. RubyGems prefers the locked Bundler version only when it is onGem.path(bundler_version_finder.rb:30-35), so the only candidate left is the default gem. Bundler 4.0.18'srequire "rubygems/vendor/uri/lib/uri"(vendored_uri.rb:10in 4.0.18) therefore activates the default Bundler 4.1.0.beta1.Bundler::Source::Metadata#specsthen raises on the version mismatch (metadata.rb:13-14in 4.0.18).A possible fix is for
Gem.register_default_specto skiprubygems/paths, since RubyGems owns those files. The Bundler gem would still ship its copies; only the default gem's require-path mapping changes. I opened #9920 with this fix and a test.Did you try upgrading rubygems & bundler?
Yes. RubyGems 4.1.0.beta1 is the latest release. Updating the lockfile to Bundler 4.1.0.beta1 avoids the error.
Post steps to reproduce the problem
Which command did you run?
What were you expecting to happen?
It prints
4.0.18.What happened instead?
If not included with the output of your command, run
bundle envand paste the output belowbundle envEnvironment
Bundler Build Metadata
Bundler settings
Gemfile
Gemfile
Gemfile.lock