-
Bug
-
-
Major
-
Resolution:
Fixed
-
None
-
-
None
-
-
Debian GNU/Linux unstable
When compiling the code with clang 6.0 and cmake -DWITH_ASAN:BOOL=ON I got this error when running tests with
ASAN_OPTIONS=abort_on_error=1,disable_coredump=0,detect_leaks=0 ./mtr --parallel=auto --force --retry=0 --max-test-fail=0
|
10.3 71144afa966a85d08053eb616a1021fd339102d1, libmariadb a12a0b8362fe8c92ec7252c8da19c14d22e289fc
|
CURRENT_TEST: main.connect_debug
|
=================================================================
|
==7822==ERROR: AddressSanitizer: heap-use-after-free on address 0x629000005200 at pc 0x0000005a18b5 bp 0x7fff77936f60 sp 0x7fff77936f58
|
READ of size 1 at 0x629000005200 thread T0
|
#0 0x5a18b4 in client_mpvio_read_packet /mariadb/10.3m/libmariadb/plugins/auth/my_auth.c:360:7
|
#1 0x5a3120 in auth_old_password /mariadb/10.3m/libmariadb/plugins/auth/old_password.c:91:19
|
#2 0x5a0e94 in run_plugin_auth /mariadb/10.3m/libmariadb/plugins/auth/my_auth.c:547:8
|
#3 0x55a14f in mthd_my_real_connect /mariadb/10.3m/libmariadb/libmariadb/mariadb_lib.c:1499:7
|
#4 0x558ba2 in mysql_real_connect /mariadb/10.3m/libmariadb/libmariadb/mariadb_lib.c:1183:10
|
#5 0x53cc09 in do_connect(st_mysql*, char const*, char const*, char const*, char const*, unsigned long) /mariadb/10.3m/client/mysql.cc:1389:10
|
#6 0x5490e5 in sql_real_connect(char*, char*, char*, char*, unsigned int) /mariadb/10.3m/client/mysql.cc:4702:8
|
#7 0x53b6b5 in sql_connect(char*, char*, char*, char*, unsigned int) /mariadb/10.3m/client/mysql.cc:4750:16
|
#8 0x53a8f2 in main /mariadb/10.3m/client/mysql.cc:1207:7
|
#9 0x7f87d58e0a86 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21a86)
|
#10 0x43ce59 in _start (/dev/shm/10.3d/client/mysql+0x43ce59)
|
|
0x629000005200 is located 0 bytes inside of 16384-byte region [0x629000005200,0x629000009200)
|
freed by thread T0 here:
|
#0 0x4fcb40 in __interceptor_free.localalias.0 (/dev/shm/10.3d/client/mysql+0x4fcb40)
|
#1 0x5ab7c2 in ma_net_end /mariadb/10.3m/libmariadb/libmariadb/ma_net.c:114:3
|
|
previously allocated by thread T0 here:
|
#0 0x4fcd10 in __interceptor_malloc (/dev/shm/10.3d/client/mysql+0x4fcd10)
|
#1 0x5ab3a3 in ma_net_init /mariadb/10.3m/libmariadb/libmariadb/ma_net.c:83:28
|
#2 0x558ba2 in mysql_real_connect /mariadb/10.3m/libmariadb/libmariadb/mariadb_lib.c:1183:10
|
#3 0x53cc09 in do_connect(st_mysql*, char const*, char const*, char const*, char const*, unsigned long) /mariadb/10.3m/client/mysql.cc:1389:10
|
|
SUMMARY: AddressSanitizer: heap-use-after-free /mariadb/10.3m/libmariadb/plugins/auth/my_auth.c:360:7 in client_mpvio_read_packet
|
Shadow bytes around the buggy address:
|
0x0c527fff89f0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x0c527fff8a00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x0c527fff8a10: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x0c527fff8a20: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x0c527fff8a30: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
=>0x0c527fff8a40:[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x0c527fff8a50: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x0c527fff8a60: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x0c527fff8a70: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x0c527fff8a80: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x0c527fff8a90: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
Shadow byte legend (one shadow byte represents 8 application bytes):
|
Addressable: 00
|
Partially addressable: 01 02 03 04 05 06 07
|
Heap left redzone: fa
|
Freed heap region: fd
|
Stack left redzone: f1
|
Stack mid redzone: f2
|
Stack right redzone: f3
|
Stack after return: f5
|
Stack use after scope: f8
|
Global redzone: f9
|
Global init order: f6
|
Poisoned by user: f7
|
Container overflow: fc
|
Array cookie: ac
|
Intra object redzone: bb
|
ASan internal: fe
|
Left alloca redzone: ca
|
Right alloca redzone: cb
|
==7822==ABORTING
|
Aborted
|
mysqltest: At line 10: command "$MYSQL --default-auth=mysql_old_password --user=bad --password=worse" failed with wrong error: 134
|
It looks like some error handling is wrong in Connector/C. The test is trying to misauthenticate:
source include/have_debug.inc;
|
set @old_dbug=@@global.debug_dbug;
|
|
#
|
# use after free if need plugin change and auth aborted
|
#
|
set global debug_dbug='+d,auth_disconnect';
|
create user 'bad' identified by 'worse';
|
--error 1
|
--exec $MYSQL --default-auth=mysql_old_password --user=bad --password=worse
|
set global debug_dbug=@old_dbug;
|
drop user bad;
|
It is the exec statement that fails. I wonder if this could explain MDEV-12361.
- relates to
-
MDEV-12361
The MariaDB Server never returns to client after a read error
-
-
Closed
{"report":{"fcp":901.1999998092651,"ttfb":169.9000005722046,"pageVisibility":"visible","entityId":68470,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"c2aa5bd9-85b0-4dc6-ac34-67819c9cd746","navigationType":0,"readyForUser":993.9000005722046,"redirectCount":0,"resourceLoadedEnd":1311.1000003814697,"resourceLoadedStart":175.69999980926514,"resourceTiming":[{"duration":143.80000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":175.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":175.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":319.5,"responseStart":0,"secureConnectionStart":0},{"duration":143.80000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":176,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":176,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":319.80000019073486,"responseStart":0,"secureConnectionStart":0},{"duration":187.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":176.30000019073486,"connectEnd":176.30000019073486,"connectStart":176.30000019073486,"domainLookupEnd":176.30000019073486,"domainLookupStart":176.30000019073486,"fetchStart":176.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":176.30000019073486,"responseEnd":364,"responseStart":364,"secureConnectionStart":176.30000019073486},{"duration":306.0999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":176.4000005722046,"connectEnd":176.4000005722046,"connectStart":176.4000005722046,"domainLookupEnd":176.4000005722046,"domainLookupStart":176.4000005722046,"fetchStart":176.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":176.4000005722046,"responseEnd":482.5,"responseStart":482.5,"secureConnectionStart":176.4000005722046},{"duration":324.3999996185303,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":176.60000038146973,"connectEnd":176.60000038146973,"connectStart":176.60000038146973,"domainLookupEnd":176.60000038146973,"domainLookupStart":176.60000038146973,"fetchStart":176.60000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":176.60000038146973,"responseEnd":501,"responseStart":501,"secureConnectionStart":176.60000038146973},{"duration":336.5999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":176.9000005722046,"connectEnd":176.9000005722046,"connectStart":176.9000005722046,"domainLookupEnd":176.9000005722046,"domainLookupStart":176.9000005722046,"fetchStart":176.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":176.9000005722046,"responseEnd":513.5,"responseStart":513.5,"secureConnectionStart":176.9000005722046},{"duration":337.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":177,"connectEnd":177,"connectStart":177,"domainLookupEnd":177,"domainLookupStart":177,"fetchStart":177,"redirectEnd":0,"redirectStart":0,"requestStart":177,"responseEnd":514.5,"responseStart":514.4000005722046,"secureConnectionStart":177},{"duration":341.6000003814697,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":177.19999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":177.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":518.8000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":337.8999996185303,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":177.4000005722046,"connectEnd":177.4000005722046,"connectStart":177.4000005722046,"domainLookupEnd":177.4000005722046,"domainLookupStart":177.4000005722046,"fetchStart":177.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":177.4000005722046,"responseEnd":515.3000001907349,"responseStart":515.3000001907349,"secureConnectionStart":177.4000005722046},{"duration":341.4000005722046,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":177.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":177.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":518.9000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":338.20000076293945,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":177.69999980926514,"connectEnd":177.69999980926514,"connectStart":177.69999980926514,"domainLookupEnd":177.69999980926514,"domainLookupStart":177.69999980926514,"fetchStart":177.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":177.69999980926514,"responseEnd":515.9000005722046,"responseStart":515.9000005722046,"secureConnectionStart":177.69999980926514},{"duration":459.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":183.9000005722046,"connectEnd":183.9000005722046,"connectStart":183.9000005722046,"domainLookupEnd":183.9000005722046,"domainLookupStart":183.9000005722046,"fetchStart":183.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":183.9000005722046,"responseEnd":643.6000003814697,"responseStart":643.6000003814697,"secureConnectionStart":183.9000005722046},{"duration":1106.1000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":184.30000019073486,"connectEnd":184.30000019073486,"connectStart":184.30000019073486,"domainLookupEnd":184.30000019073486,"domainLookupStart":184.30000019073486,"fetchStart":184.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":184.30000019073486,"responseEnd":1290.4000005722046,"responseStart":1290.4000005722046,"secureConnectionStart":184.30000019073486},{"duration":119.60000038146973,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":526.1999998092651,"connectEnd":526.1999998092651,"connectStart":526.1999998092651,"domainLookupEnd":526.1999998092651,"domainLookupStart":526.1999998092651,"fetchStart":526.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":526.1999998092651,"responseEnd":645.8000001907349,"responseStart":645.8000001907349,"secureConnectionStart":526.1999998092651},{"duration":460.30000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":850.6000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":850.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1310.9000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":459.9000005722046,"initiatorType":"link","name":"https://jira.mariadb.org/s/50bc9be5bfead1a25e72c1a9338c94f6-CDN/lu2cib/820016/12ta74/e108c7645258ccb43280ed3404e3e949/_/download/contextbatch/css/com.atlassian.jira.plugins.jira-development-integration-plugin:0,-_super,-jira.view.issue,-jira.global,-jira.general,-jira.browse.project,-project.issue.navigator,-atl.general/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":851.1999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":851.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1311.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":468.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":852.1000003814697,"connectEnd":852.1000003814697,"connectStart":852.1000003814697,"domainLookupEnd":852.1000003814697,"domainLookupStart":852.1000003814697,"fetchStart":852.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":852.1000003814697,"responseEnd":1320.6000003814697,"responseStart":1320.6000003814697,"secureConnectionStart":852.1000003814697},{"duration":476.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/097ae97cb8fbec7d6ea4bbb1f26955b9-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":852.5,"connectEnd":852.5,"connectStart":852.5,"domainLookupEnd":852.5,"domainLookupStart":852.5,"fetchStart":852.5,"redirectEnd":0,"redirectStart":0,"requestStart":852.5,"responseEnd":1328.8000001907349,"responseStart":1328.8000001907349,"secureConnectionStart":852.5},{"duration":477.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/e0bf5781d46ea69fb123572974cf39de-CDN/lu2cib/820016/12ta74/e108c7645258ccb43280ed3404e3e949/_/download/contextbatch/js/com.atlassian.jira.plugins.jira-development-integration-plugin:0,-_super,-jira.view.issue,-jira.global,-jira.general,-jira.browse.project,-project.issue.navigator,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":852.9000005722046,"connectEnd":852.9000005722046,"connectStart":852.9000005722046,"domainLookupEnd":852.9000005722046,"domainLookupStart":852.9000005722046,"fetchStart":852.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":852.9000005722046,"responseEnd":1330.4000005722046,"responseStart":1330.4000005722046,"secureConnectionStart":852.9000005722046},{"duration":483.80000019073486,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":894.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":894.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1378.3000001907349,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":13,"responseStart":170,"responseEnd":183,"domLoading":174,"domInteractive":1320,"domContentLoadedEventStart":1320,"domContentLoadedEventEnd":1374,"domComplete":2660,"loadEventStart":2660,"loadEventEnd":2663,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1292.6999998092651},{"name":"bigPipe.sidebar-id.end","time":1293.6000003814697},{"name":"bigPipe.activity-panel-pipe-id.start","time":1293.9000005722046},{"name":"bigPipe.activity-panel-pipe-id.end","time":1297},{"name":"activityTabFullyLoaded","time":1385.8000001907349}],"measures":[],"correlationId":"5eaf923b6756ac","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":87,"dbReadsTimeInMs":9,"dbConnsTimeInMs":16,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}