Apparently all tests that access the information_schema.processlist table would crash when the server is built with cmake -DWITH_ASAN, due to an out-of-bounds string access, reported like this:
CURRENT_TEST: innodb.innodb_bug12400341
|
mysqltest: At line 64: query 'select count(*) from information_schema.processlist' failed: 2013: Lost connection to MySQL server during query
|
this one is something definitely outside InnoDB:
|
==32392==ERROR: AddressSanitizer: global-buffer-overflow on address 0x0000018b90ac at pc 0x00000176c633 bp 0x7f8ceda19960 sp 0x7f8ceda19958
|
READ of size 1 at 0x0000018b90ac thread T55
|
#0 0x176c632 in my_string_repertoire_8bit /home/marko/mariadb/server/strings/ctype.c:829:18
|
#1 0x176c6bf in my_string_metadata_get /home/marko/mariadb/server/strings/ctype.c:895:27
|
#2 0x6f6312 in Item_string::Item_string(THD*, char const*, unsigned int, charset_info_st const*, Derivation) /home/marko/mariadb/server/sql/item.h:2978:37
|
#3 0x6f61ee in Item_partition_func_safe_string::Item_partition_func_safe_string(THD*, char const*, unsigned int, charset_info_st const*) /home/marko/mariadb/server/sql/item.h:3183:5
|
#4 0x94d293 in Item_blob::Item_blob(THD*, char const*, unsigned int) /home/marko/mariadb/server/sql/item.h:3209:5
|
#5 0x93761f in create_schema_table(THD*, TABLE_LIST*) /home/marko/mariadb/server/sql/sql_show.cc:7557:13
|
#6 0x93955c in mysql_schema_table(THD*, LEX*, TABLE_LIST*) /home/marko/mariadb/server/sql/sql_show.cc:7806:16
|
…
|
0x0000018b90ac is located 52 bytes to the left of global variable '<string literal>' defined in '/home/marko/mariadb/server/sql/sql_show.cc:8837:4' (0x18b90e0) of size 12
|
'<string literal>' is ascii string 'Info_binary'
|
0x0000018b90ac is located 0 bytes to the right of global variable '<string literal>' defined in '/home/marko/mariadb/server/sql/sql_show.cc:8836:4' (0x18b90a0) of size 12
|
'<string literal>' is ascii string 'INFO_BINARY'
|
The patch below works around the issue and allows the tests to pass (albeit with memory leaks ignored, because there is no ./mtr --sanitize option available):
diff --git a/sql/sql_show.cc b/sql/sql_show.cc
|
index ae3874506dd..c3610da05af 100644
|
--- a/sql/sql_show.cc
|
+++ b/sql/sql_show.cc
|
@@ -7555,7 +7555,8 @@ TABLE *create_schema_table(THD *thd, TABLE_LIST *table_list)
|
case MYSQL_TYPE_BLOB:
|
if (!(item= new (mem_root)
|
Item_blob(thd, fields_info->field_name,
|
- fields_info->field_length)))
|
+ std::min(unsigned (strlen(fields_info->field_name)),
|
+ fields_info->field_length))))
|
{
|
DBUG_RETURN(0);
|
}
|
Note that in MariaDB 10.2, cmake -DWITH_ASAN does not work at all at the moment (the feature availability check fails).
- relates to
-
MDEV-9105
Test failures under valgrind
-
-
Closed
{"report":{"fcp":811.7999999523163,"ttfb":148.09999990463257,"pageVisibility":"visible","entityId":59414,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"e63a2218-2355-4893-b44b-adcc73378705","navigationType":0,"readyForUser":890.2999999523163,"redirectCount":0,"resourceLoadedEnd":867,"resourceLoadedStart":154,"resourceTiming":[{"duration":164.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":154,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":154,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":318.5,"responseStart":0,"secureConnectionStart":0},{"duration":164.10000014305115,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":154.39999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":154.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":318.5,"responseStart":0,"secureConnectionStart":0},{"duration":177.20000004768372,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":154.5,"connectEnd":154.5,"connectStart":154.5,"domainLookupEnd":154.5,"domainLookupStart":154.5,"fetchStart":154.5,"redirectEnd":0,"redirectStart":0,"requestStart":154.5,"responseEnd":331.7000000476837,"responseStart":331.7000000476837,"secureConnectionStart":154.5},{"duration":290.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":154.70000004768372,"connectEnd":154.70000004768372,"connectStart":154.70000004768372,"domainLookupEnd":154.70000004768372,"domainLookupStart":154.70000004768372,"fetchStart":154.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":154.70000004768372,"responseEnd":444.7999999523163,"responseStart":444.7999999523163,"secureConnectionStart":154.70000004768372},{"duration":285.89999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":154.70000004768372,"connectEnd":154.70000004768372,"connectStart":154.70000004768372,"domainLookupEnd":154.70000004768372,"domainLookupStart":154.70000004768372,"fetchStart":154.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":154.70000004768372,"responseEnd":440.59999990463257,"responseStart":440.59999990463257,"secureConnectionStart":154.70000004768372},{"duration":291.2999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":154.79999995231628,"connectEnd":154.79999995231628,"connectStart":154.79999995231628,"domainLookupEnd":154.79999995231628,"domainLookupStart":154.79999995231628,"fetchStart":154.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":154.79999995231628,"responseEnd":446.09999990463257,"responseStart":446.09999990463257,"secureConnectionStart":154.79999995231628},{"duration":292.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":154.89999985694885,"connectEnd":154.89999985694885,"connectStart":154.89999985694885,"domainLookupEnd":154.89999985694885,"domainLookupStart":154.89999985694885,"fetchStart":154.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":154.89999985694885,"responseEnd":447.2999999523163,"responseStart":447.2999999523163,"secureConnectionStart":154.89999985694885},{"duration":293.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":155,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":155,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":448.5,"responseStart":0,"secureConnectionStart":0},{"duration":293.2999999523163,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":155.09999990463257,"connectEnd":155.09999990463257,"connectStart":155.09999990463257,"domainLookupEnd":155.09999990463257,"domainLookupStart":155.09999990463257,"fetchStart":155.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":155.09999990463257,"responseEnd":448.39999985694885,"responseStart":448.39999985694885,"secureConnectionStart":155.09999990463257},{"duration":293.89999985694885,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":155.20000004768372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":155.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":449.09999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":293.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":155.39999985694885,"connectEnd":155.39999985694885,"connectStart":155.39999985694885,"domainLookupEnd":155.39999985694885,"domainLookupStart":155.39999985694885,"fetchStart":155.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":155.39999985694885,"responseEnd":449.09999990463257,"responseStart":449.09999990463257,"secureConnectionStart":155.39999985694885},{"duration":394.89999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":156,"connectEnd":156,"connectStart":156,"domainLookupEnd":156,"domainLookupStart":156,"fetchStart":156,"redirectEnd":0,"redirectStart":0,"requestStart":156,"responseEnd":550.8999998569489,"responseStart":550.8999998569489,"secureConnectionStart":156},{"duration":710.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":156.09999990463257,"connectEnd":156.09999990463257,"connectStart":156.09999990463257,"domainLookupEnd":156.09999990463257,"domainLookupStart":156.09999990463257,"fetchStart":156.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":156.09999990463257,"responseEnd":867,"responseStart":867,"secureConnectionStart":156.09999990463257},{"duration":67.89999985694885,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":483.7000000476837,"connectEnd":483.7000000476837,"connectStart":483.7000000476837,"domainLookupEnd":483.7000000476837,"domainLookupStart":483.7000000476837,"fetchStart":483.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":483.7000000476837,"responseEnd":551.5999999046326,"responseStart":551.5999999046326,"secureConnectionStart":483.7000000476837}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":11,"responseStart":148,"responseEnd":151,"domLoading":152,"domInteractive":944,"domContentLoadedEventStart":944,"domContentLoadedEventEnd":986,"domComplete":1594,"loadEventStart":1594,"loadEventEnd":1595,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":926},{"name":"bigPipe.sidebar-id.end","time":927},{"name":"bigPipe.activity-panel-pipe-id.start","time":927.0999999046326},{"name":"bigPipe.activity-panel-pipe-id.end","time":927.8999998569489},{"name":"activityTabFullyLoaded","time":999.7999999523163}],"measures":[],"correlationId":"449cc78bbf6b8d","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":79,"dbReadsTimeInMs":16,"dbConnsTimeInMs":24,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
For what it is worth, MariaDB Server 10.0.29 does not seem to be affected by this issue. (Tests that access information_schema.processlist do not trigger any sanitizer messages.)