Type:
Bug
Priority:
Major
Resolution:
Fixed
Affects Version/s:
3.1.6
Component/s:
None
We discovered that mysql_list_processes crashes in unpack_fields .
I have attached a simple test program.
First, create a user account:
CREATE USER 'list_processes_test' @ 'localhost' IDENTIFIED BY 'test' ;
GRANT ALL PRIVILEGES ON *.* TO 'list_processes_test' @ 'localhost' ;
And then compile it:
$ gcc -ggdb $(mariadb_config --include --libs) ./test_list_processes.c
And then run it via gdb :
$ gdb ./a.out
...
(gdb) run
It crashes with a segmentation fault with the following backtrace:
Program received signal SIGSEGV, Segmentation fault.
unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
808 field->charsetnr= uint2korr(p);
Missing separate debuginfos, use: debuginfo-install glibc-2.17-292.el7.x86_64 keyutils-libs-1.5.8-3.el7.x86_64 krb5-libs-1.15.1-34.el7.x86_64 libcom_err-1.42.9-13.el7.x86_64 libselinux-2.5-14.1.el7.x86_64 openssl-libs-1.0.2k-16.el7_6.1.x86_64 pcre-8.32-17.el7.x86_64 zlib-1.2.7-18.el7.x86_64
(gdb) bt
#0 unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
#1 0x00007ffff7ba8d22 in mysql_list_processes (mysql=0x623a70) at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:2555
#2 0x00000000004008ac in list_processes (conn=0x623a70) at ./test_list_processes.c:12
#3 0x00000000004009ab in main (argc=1, argv=0x7fffffffe558) at ./test_list_processes.c:36
The crash happens here:
https://github.com/mariadb-corporation/mariadb-connector-c/blob/v3.1.6/libmariadb/mariadb_lib.c#L808
Geoff Montee (Inactive)
made changes -
2020-02-28 01:03
Field
Original Value
New Value
Description
We discovered that {{mysql_list_processes}} crashes in {{unpack_fields}}.
I have attached a simple test program.
First, create a user account:
{code:sql}
CREATE USER 'list_processes_test'@'localhost' IDENTIFIED BY 'test';
GRANT ALL PRIVILEGES ON *.* TO 'list_processes_test'@'localhost';
{code}
And then compile it:
{code:sh}
$ gcc -ggdb $(mariadb_config --include --libs) ./test_list_processes.c
{code}
And then run it via {{gdb}}:
{code:sh}
$ gdb ./a.out
...
(gdb) run
{code}
It crashes with a segmentation fault the following backtrace:
{noformat}
Program received signal SIGSEGV, Segmentation fault.
unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
808 field->charsetnr= uint2korr(p);
Missing separate debuginfos, use: debuginfo-install glibc-2.17-292.el7.x86_64 keyutils-libs-1.5.8-3.el7.x86_64 krb5-libs-1.15.1-34.el7.x86_64 libcom_err-1.42.9-13.el7.x86_64 libselinux-2.5-14.1.el7.x86_64 openssl-libs-1.0.2k-16.el7_6.1.x86_64 pcre-8.32-17.el7.x86_64 zlib-1.2.7-18.el7.x86_64
(gdb) bt
#0 unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
#1 0x00007ffff7ba8d22 in mysql_list_processes (mysql=0x623a70) at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:2555
#2 0x00000000004008ac in list_processes (conn=0x623a70) at ./test_list_processes.c:12
#3 0x00000000004009ab in main (argc=1, argv=0x7fffffffe558) at ./test_list_processes.c:36
{noformat}
The crash happens here:
https://github.com/mariadb-corporation/mariadb-connector-c/blob/v3.1.6/libmariadb/mariadb_lib.c#L808
We discovered that {{mysql_list_processes}} crashes in {{unpack_fields}}.
I have attached a simple test program.
First, create a user account:
{code:sql}
CREATE USER 'list_processes_test'@'localhost' IDENTIFIED BY 'test';
GRANT ALL PRIVILEGES ON *.* TO 'list_processes_test'@'localhost';
{code}
And then compile it:
{code:sh}
$ gcc -ggdb $(mariadb_config --include --libs) ./test_list_processes.c
{code}
And then run it via {{gdb}}:
{code:sh}
$ gdb ./a.out
...
(gdb) run
{code}
It crashes with a segmentation fault with the following backtrace:
{noformat}
Program received signal SIGSEGV, Segmentation fault.
unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
808 field->charsetnr= uint2korr(p);
Missing separate debuginfos, use: debuginfo-install glibc-2.17-292.el7.x86_64 keyutils-libs-1.5.8-3.el7.x86_64 krb5-libs-1.15.1-34.el7.x86_64 libcom_err-1.42.9-13.el7.x86_64 libselinux-2.5-14.1.el7.x86_64 openssl-libs-1.0.2k-16.el7_6.1.x86_64 pcre-8.32-17.el7.x86_64 zlib-1.2.7-18.el7.x86_64
(gdb) bt
#0 unpack_fields (data=0x62c390, alloc=alloc@entry=0x623d70, fields=fields@entry=9, default_value=default_value@entry=0 '\000', long_flag_protocol=<optimized out>)
at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:808
#1 0x00007ffff7ba8d22 in mysql_list_processes (mysql=0x623a70) at /usr/src/debug/MariaDB-10.4.11-5/src_0/libmariadb/libmariadb/mariadb_lib.c:2555
#2 0x00000000004008ac in list_processes (conn=0x623a70) at ./test_list_processes.c:12
#3 0x00000000004009ab in main (argc=1, argv=0x7fffffffe558) at ./test_list_processes.c:36
{noformat}
The crash happens here:
https://github.com/mariadb-corporation/mariadb-connector-c/blob/v3.1.6/libmariadb/mariadb_lib.c#L808
Georg Richter
made changes -
2020-02-28 12:08
Fix Version/s
3.1.8
[ 24230
]
Fix Version/s
3.1
[ 23223
]
Resolution
Fixed
[ 1
]
Status
Open
[ 1
]
Closed
[ 6
]
Julien Fritsch
made changes -
2022-01-11 15:33
Workflow
MariaDB connectors
[ 104401
]
MariaDB v4
[ 161199
]
{"report":{"fcp":1349.5,"ttfb":306.7999999523163,"pageVisibility":"visible","entityId":83647,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"ad972604-5597-4f6f-b583-186d194841d3","navigationType":0,"readyForUser":1432.7999999523163,"redirectCount":0,"resourceLoadedEnd":1812.2000000476837,"resourceLoadedStart":312.09999990463257,"resourceTiming":[{"duration":462.2000000476837,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":312.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":312.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":774.2999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":463.2000000476837,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":312.2999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":312.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":775.5,"responseStart":0,"secureConnectionStart":0},{"duration":521.7999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":312.5,"connectEnd":312.5,"connectStart":312.5,"domainLookupEnd":312.5,"domainLookupStart":312.5,"fetchStart":312.5,"redirectEnd":0,"redirectStart":0,"requestStart":312.5,"responseEnd":834.2999999523163,"responseStart":834.2999999523163,"secureConnectionStart":312.5},{"duration":613.7999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":312.7000000476837,"connectEnd":312.7000000476837,"connectStart":312.7000000476837,"domainLookupEnd":312.7000000476837,"domainLookupStart":312.7000000476837,"fetchStart":312.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":312.7000000476837,"responseEnd":926.5,"responseStart":926.5,"secureConnectionStart":312.7000000476837},{"duration":618.3999998569489,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":312.90000009536743,"connectEnd":312.90000009536743,"connectStart":312.90000009536743,"domainLookupEnd":312.90000009536743,"domainLookupStart":312.90000009536743,"fetchStart":312.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":312.90000009536743,"responseEnd":931.2999999523163,"responseStart":931.2999999523163,"secureConnectionStart":312.90000009536743},{"duration":619,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":313,"connectEnd":313,"connectStart":313,"domainLookupEnd":313,"domainLookupStart":313,"fetchStart":313,"redirectEnd":0,"redirectStart":0,"requestStart":313,"responseEnd":932,"responseStart":932,"secureConnectionStart":313},{"duration":620.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":313.2000000476837,"connectEnd":313.2000000476837,"connectStart":313.2000000476837,"domainLookupEnd":313.2000000476837,"domainLookupStart":313.2000000476837,"fetchStart":313.2000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":313.2000000476837,"responseEnd":933.4000000953674,"responseStart":933.4000000953674,"secureConnectionStart":313.2000000476837},{"duration":676.5999999046326,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":313.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":313.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":990,"responseStart":0,"secureConnectionStart":0},{"duration":622.5,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":313.5,"connectEnd":313.5,"connectStart":313.5,"domainLookupEnd":313.5,"domainLookupStart":313.5,"fetchStart":313.5,"redirectEnd":0,"redirectStart":0,"requestStart":313.5,"responseEnd":936,"responseStart":936,"secureConnectionStart":313.5},{"duration":676.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":313.7999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":313.7999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":990.2999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":622.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":313.90000009536743,"connectEnd":313.90000009536743,"connectStart":313.90000009536743,"domainLookupEnd":313.90000009536743,"domainLookupStart":313.90000009536743,"fetchStart":313.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":313.90000009536743,"responseEnd":936.5999999046326,"responseStart":936.5999999046326,"secureConnectionStart":313.90000009536743},{"duration":1193.5999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":319.7000000476837,"connectEnd":319.7000000476837,"connectStart":319.7000000476837,"domainLookupEnd":319.7000000476837,"domainLookupStart":319.7000000476837,"fetchStart":319.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":319.7000000476837,"responseEnd":1513.2999999523163,"responseStart":1513.2999999523163,"secureConnectionStart":319.7000000476837},{"duration":1491.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":320.5,"connectEnd":320.5,"connectStart":320.5,"domainLookupEnd":320.5,"domainLookupStart":320.5,"fetchStart":320.5,"redirectEnd":0,"redirectStart":0,"requestStart":320.5,"responseEnd":1812.2000000476837,"responseStart":1812.2000000476837,"secureConnectionStart":320.5},{"duration":501.09999990463257,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1014.4000000953674,"connectEnd":1014.4000000953674,"connectStart":1014.4000000953674,"domainLookupEnd":1014.4000000953674,"domainLookupStart":1014.4000000953674,"fetchStart":1014.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":1014.4000000953674,"responseEnd":1515.5,"responseStart":1515.4000000953674,"secureConnectionStart":1014.4000000953674}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":136,"responseStart":306,"responseEnd":320,"domLoading":310,"domInteractive":1838,"domContentLoadedEventStart":1838,"domContentLoadedEventEnd":1884,"domComplete":2428,"loadEventStart":2428,"loadEventEnd":2428,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1816.5},{"name":"bigPipe.sidebar-id.end","time":1817.5},{"name":"bigPipe.activity-panel-pipe-id.start","time":1817.7000000476837},{"name":"bigPipe.activity-panel-pipe-id.end","time":1819.5},{"name":"activityTabFullyLoaded","time":1899.5999999046326}],"measures":[],"correlationId":"7df7d70c8d5e18","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":105,"dbReadsTimeInMs":16,"dbConnsTimeInMs":25,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}