The semi-join optimizer has two phases:
- When building the join order, advance_sj_state() is invoked after a table has been added to the join prefix.
- When the join order is picked, fix_semijoin_strategies_for_picked_join_order() is called to make the final fixes in semi-join optimization
Both function share some code (e.g. calls optimize_wo_join_buffering()). The issue is:
- the first phase operates on current join prefix: join->positions.
- the second phase operates on the picked join order, join->best_positions.
but some code just refers to the join->positions. That array contains the last-considered query plan. (Sometimes, it's the same as the picked query plan. In general case, it is not).
This can lead to hard-to-catch bugs.
Let's apply this patch to make the issue visible:
diff --git a/sql/opt_subselect.cc b/sql/opt_subselect.cc
|
index 599642b3a26..f0e74157f9a 100644
|
--- a/sql/opt_subselect.cc
|
+++ b/sql/opt_subselect.cc
|
@@ -2786,6 +2786,18 @@ void advance_sj_state(JOIN *join, table_map remaining_tables, uint idx,
|
&pos->dups_weedout_picker,
|
NULL,
|
};
|
+
|
+ MEM_UNDEFINED(&pos->firstmatch_picker, sizeof(pos->firstmatch_picker));
|
+ MEM_UNDEFINED(&pos->loosescan_picker, sizeof(pos->loosescan_picker));
|
+ MEM_UNDEFINED(&pos->sjmat_picker, sizeof(pos->sjmat_picker));
|
+ MEM_UNDEFINED(&pos->dups_weedout_picker, sizeof(pos->dups_weedout_picker));
|
+
|
+ // The following classes use virtual functions so their memory needs to
|
+ // be properly initialized
|
+ new (&pos->firstmatch_picker) Firstmatch_picker;
|
+ new (&pos->loosescan_picker) LooseScan_picker;
|
+ new (&pos->sjmat_picker) Sj_materialization_picker;
|
+ new (&pos->dups_weedout_picker) Duplicate_weedout_picker;
|
|
if (join->emb_sjm_nest)
|
{
|
diff --git a/sql/sql_select.cc b/sql/sql_select.cc
|
index ff07a7aea89..b01769209fe 100644
|
--- a/sql/sql_select.cc
|
+++ b/sql/sql_select.cc
|
@@ -8146,6 +8146,9 @@ choose_plan(JOIN *join, table_map join_tables)
|
if (greedy_search(join, join_tables, search_depth, prune_level,
|
use_cond_selectivity))
|
DBUG_RETURN(TRUE);
|
+ for (uint k=0; k < join->table_count; k++) {
|
+ MEM_UNDEFINED(&join->positions[k], sizeof(join->positions[k]));
|
+ }
|
}
|
|
/*
|
Running
./mysql-test-run --valgrind --mem --parallel=6 --force main/subselect*test
|
Produces a lot of valgrind failures.
Example error
main.subselect_exists2in w2 [ fail ] Found warnings/errors in server log file!
|
Test ended at 2019-08-17 21:45:39
|
line
|
==20460== Thread 6:
|
==20460== Use of uninitialised value of size 8
|
==20460== at 0x95378C: prev_record_reads(st_position*, unsigned int, unsigned long long) (sql_select.cc:9775)
|
==20460== by 0x94C2DC: best_access_path(JOIN*, st_join_table*, unsigned long long, unsigned int, bool, double, st_position*, st_position*) (sql_select.cc:7303)
|
==20460== by 0xAD1970: fix_semijoin_strategies_for_picked_join_order(JOIN*) (opt_subselect.cc:3773)
|
==20460== by 0x95419A: JOIN::get_best_combination() (sql_select.cc:10163)
|
==20460== by 0x93B8CF: JOIN::optimize_stage2() (sql_select.cc:2241)
|
==20460== by 0x93B732: JOIN::optimize_inner() (sql_select.cc:2220)
|
==20460== by 0x9391D9: JOIN::optimize() (sql_select.cc:1563)
|
==20460== by 0x94417B: mysql_select(THD*, TABLE_LIST*, unsigned int, List<Item>&, Item*, unsigned int, st_order*, st_order*, Item*, st_order*, unsigned long long, select_result*, st_select_lex_unit*, st_select_lex*) (sql_select.cc:4592)
|
==20460== by 0x93463C: handle_select(THD*, LEX*, select_result*, unsigned long) (sql_select.cc:413)
|
==20460== by 0x8FD029: execute_sqlcom_select(THD*, TABLE_LIST*) (sql_parse.cc:6356)
|
==20460== by 0x8F2D64: mysql_execute_command(THD*) (sql_parse.cc:3898)
|
==20460== by 0x900DBE: mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool) (sql_parse.cc:7908)
|
==20460== by 0x8ECF02: dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool) (sql_parse.cc:1842)
|
==20460== by 0x8EB647: do_command(THD*) (sql_parse.cc:1359)
|
==20460== by 0xA6B307: do_handle_one_connection(CONNECT*) (sql_connect.cc:1404)
|
==20460== by 0xA6B056: handle_one_connection (sql_connect.cc:1306)
|
{"report":{"fcp":1593.3000001907349,"ttfb":417.40000009536743,"pageVisibility":"visible","entityId":78293,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"55762d31-7a41-4e53-9692-5061b19a5d9e","navigationType":0,"readyForUser":1697.6000003814697,"redirectCount":0,"resourceLoadedEnd":1257.2000002861023,"resourceLoadedStart":446,"resourceTiming":[{"duration":159.10000038146973,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":446,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":446,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":605.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":159.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":446.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":446.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":606,"responseStart":0,"secureConnectionStart":0},{"duration":491.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":446.80000019073486,"connectEnd":446.80000019073486,"connectStart":446.80000019073486,"domainLookupEnd":446.80000019073486,"domainLookupStart":446.80000019073486,"fetchStart":446.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":618.7000002861023,"responseEnd":938.5,"responseStart":644.5,"secureConnectionStart":446.80000019073486},{"duration":810.2000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":447,"connectEnd":447,"connectStart":447,"domainLookupEnd":447,"domainLookupStart":447,"fetchStart":447,"redirectEnd":0,"redirectStart":0,"requestStart":618.4000000953674,"responseEnd":1257.2000002861023,"responseStart":643.1000003814697,"secureConnectionStart":447},{"duration":199.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":447.30000019073486,"connectEnd":447.30000019073486,"connectStart":447.30000019073486,"domainLookupEnd":447.30000019073486,"domainLookupStart":447.30000019073486,"fetchStart":447.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":618.7000002861023,"responseEnd":647,"responseStart":645.4000000953674,"secureConnectionStart":447.30000019073486},{"duration":211.60000038146973,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":447.5,"connectEnd":447.5,"connectStart":447.5,"domainLookupEnd":447.5,"domainLookupStart":447.5,"fetchStart":447.5,"redirectEnd":0,"redirectStart":0,"requestStart":622.6000003814697,"responseEnd":659.1000003814697,"responseStart":650,"secureConnectionStart":447.5},{"duration":237.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":447.7000002861023,"connectEnd":447.7000002861023,"connectStart":447.7000002861023,"domainLookupEnd":447.7000002861023,"domainLookupStart":447.7000002861023,"fetchStart":447.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":633.2000002861023,"responseEnd":684.9000000953674,"responseStart":681.4000000953674,"secureConnectionStart":447.7000002861023},{"duration":180.7000002861023,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":447.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":447.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":628.6000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":234.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":448.2000002861023,"connectEnd":448.2000002861023,"connectStart":448.2000002861023,"domainLookupEnd":448.2000002861023,"domainLookupStart":448.2000002861023,"fetchStart":448.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":633.3000001907349,"responseEnd":683.1000003814697,"responseStart":669.9000000953674,"secureConnectionStart":448.2000002861023},{"duration":181,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":448.30000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":448.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":629.3000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":236.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":448.6000003814697,"connectEnd":448.6000003814697,"connectStart":448.6000003814697,"domainLookupEnd":448.6000003814697,"domainLookupStart":448.6000003814697,"fetchStart":448.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":633.5,"responseEnd":685.1000003814697,"responseStart":682,"secureConnectionStart":448.6000003814697},{"duration":697.4000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":499.80000019073486,"connectEnd":499.80000019073486,"connectStart":499.80000019073486,"domainLookupEnd":499.80000019073486,"domainLookupStart":499.80000019073486,"fetchStart":499.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":916.4000000953674,"responseEnd":1197.2000002861023,"responseStart":1159.6000003814697,"secureConnectionStart":499.80000019073486},{"duration":747.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":499.90000009536743,"connectEnd":499.90000009536743,"connectStart":499.90000009536743,"domainLookupEnd":499.90000009536743,"domainLookupStart":499.90000009536743,"fetchStart":499.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":1193.8000001907349,"responseEnd":1247.4000000953674,"responseStart":1215.9000000953674,"secureConnectionStart":499.90000009536743},{"duration":231.80000019073486,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1109.9000000953674,"connectEnd":1109.9000000953674,"connectStart":1109.9000000953674,"domainLookupEnd":1109.9000000953674,"domainLookupStart":1109.9000000953674,"fetchStart":1109.9000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":1293.7000002861023,"responseEnd":1341.7000002861023,"responseStart":1331,"secureConnectionStart":1109.9000000953674}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":95,"responseStart":417,"responseEnd":507,"domLoading":438,"domInteractive":1815,"domContentLoadedEventStart":1815,"domContentLoadedEventEnd":1894,"domComplete":2596,"loadEventStart":2596,"loadEventEnd":2596,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1763.6000003814697},{"name":"bigPipe.sidebar-id.end","time":1764.5},{"name":"bigPipe.activity-panel-pipe-id.start","time":1764.6000003814697},{"name":"bigPipe.activity-panel-pipe-id.end","time":1769.2000002861023},{"name":"activityTabFullyLoaded","time":1914}],"measures":[],"correlationId":"f337d20a650ee2","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":118,"dbReadsTimeInMs":13,"dbConnsTimeInMs":22,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
Another example:
==20241== Thread 27:
==20241== Use of uninitialised value of size 8
==20241== at 0xB348F4: JOIN::fix_all_splittings_in_plan() (opt_split.cc:1148)
==20241== by 0x93B6B6: JOIN::optimize_inner() (sql_select.cc:2211)
==20241== by 0x9391D9: JOIN::optimize() (sql_select.cc:1563)
==20241== by 0x94417B: mysql_select(THD*, TABLE_LIST*, unsigned int, List<Item>&, Item*, unsigned int, st_order*, st_order*, Item*, st_order*, unsigned long long, select_result*, st_select_lex_unit*, st_select_lex*) (sql_select.cc:4592)
==20241== by 0x93463C: handle_select(THD*, LEX*, select_result*, unsigned long) (sql_select.cc:413)
==20241== by 0x8FD029: execute_sqlcom_select(THD*, TABLE_LIST*) (sql_parse.cc:6356)
==20241== by 0x8F2D64: mysql_execute_command(THD*) (sql_parse.cc:3898)
==20241== by 0x900DBE: mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool) (sql_parse.cc:7908)
==20241== by 0x8ECF02: dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool) (sql_parse.cc:1842)
==20241== by 0x8EB647: do_command(THD*) (sql_parse.cc:1359)
==20241== by 0xA6B307: do_handle_one_connection(CONNECT*) (sql_connect.cc:1404)
==20241== by 0xA6B056: handle_one_connection (sql_connect.cc:1306)
==20241== by 0x13EE80F: pfs_spawn_thread (pfs.cc:1862)
==20241== by 0x662D6DA: start_thread (pthread_create.c:463)
==20241== by 0x74A988E: clone (clone.S:95)