ついに捕まえたのですが、次のようにすると core を吐きます。

% ./ruby -e '
def m() /a#{Thread.pass}/o =~ "a" end
Thread.new { m }
m
'
-e:2: [BUG] Segmentation fault
ruby 1.9.0 (2004-02-16) [i686-linux]

% gdb ruby core 
GNU gdb 2002-04-01-cvs
Copyright 2002 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "i386-linux"...
Core was generated by `./ruby -e 
def m() /a#{Thread.pass}/o =~ "a" end
Thread.new { m }
m
'.
Program terminated with signal 6, Aborted.
Reading symbols from /lib/libdl.so.2...done.
Loaded symbols for /lib/libdl.so.2
Reading symbols from /lib/libcrypt.so.1...done.
Loaded symbols for /lib/libcrypt.so.1
Reading symbols from /lib/libm.so.6...done.
Loaded symbols for /lib/libm.so.6
Reading symbols from /lib/libc.so.6...done.
Loaded symbols for /lib/libc.so.6
Reading symbols from /lib/ld-linux.so.2...done.
Loaded symbols for /lib/ld-linux.so.2
#0  0x40093781 in kill () from /lib/libc.so.6
(gdb) where
#0  0x40093781 in kill () from /lib/libc.so.6
#1  0x40093464 in raise () from /lib/libc.so.6
#2  0x40094be1 in abort () from /lib/libc.so.6
#3  0x080c3a5a in rb_bug () at error.c:207
#4  0x080a7b3f in sigsegv () at signal.c:443
#5  0x400936b8 in sigaction () from /lib/libc.so.6
#6  0x080981a3 in rb_reg_search (re=1075473948, str=1075474008, pos=0, reverse=0) at re.c:913
#7  0x08098bd3 in rb_reg_match (re=1075473948, str=1075474008) at re.c:1511
#8  0x08055bc6 in rb_eval (self=1075538448, n=0x401a7010) at eval.c:2721
#9  0x0805be2b in rb_call0 (klass=1075543328, recv=1075538448, id=10185, oid=10185, argc=0, argv=0x0, body=0x401a7010, 
    nosuper=0) at eval.c:5545
#10 0x0805c276 in rb_call (klass=1075543328, recv=1075538448, mid=10185, argc=0, argv=0x0, scope=2) at eval.c:5638
#11 0x08057571 in rb_eval (self=1075538448, n=0x401a6f5c) at eval.c:3261
#12 0x08053490 in eval_node (self=1075538448, node=0x401a6f5c) at eval.c:1275
#13 0x0805395e in ruby_exec () at eval.c:1444
#14 0x080539ba in ruby_run () at eval.c:1465
#15 0x08051e42 in Letext () at main.c:50
#16 0x4008314f in __libc_start_main () from /lib/libc.so.6
(gdb) 

また、

% ./ruby -e '$n = 0
def m() p /a#{Thread.pass; $n += 1}/o end
Thread.new { m }
m
p $n
'
/a1/
"a2"
2

というように、Regexp リテラルに o がついているのに 2回評価されたり、は
たまた Regexp リテラルの返値が String だったりするのもおかしいと思いま
す。
-- 
[田中 哲][たなか あきら][Tanaka Akira]