Type:
Bug
Priority:
Critical
Resolution:
Fixed
Affects Version/s:
10.5.2 , 10.3(EOL) , 10.4(EOL) , 10.5 , 10.6
Server crashes in Item_ref::fix_fields/Item::fix_fields_if_needed, assertion `*ref && (*ref)->fixed()' failed in Item_ref::fix_fields
We found a memory corruption bug that crash the debug build of mariadb.
POC:
—
CREATE TABLE v0 ( v1 INT ) ;
INSERT INTO v0 ( v1 ) VALUES ( 60 ) ;
UPDATE v0 SET v1 = NULL BETWEEN ( SELECT 95 FROM v0 WHERE v1 = 95 AND v1 < -1 GROUP BY - 'x' >= v1 HAVING ( -128 = 2147483647 AND v1 = 94 ) ) AND 36 WHERE v1 = 2 ;
—
Stack dump:
—
200505 5:53:28 [ERROR] mysqld got signal 11 ;
This could be because you hit a bug. It is also possible that this binary
or one of the libraries it was linked against is corrupt, improperly built,
or misconfigured. This error can also be caused by malfunctioning hardware.
To report this bug, see https://mariadb.com/kb/en/reporting-bugs
We will try our best to scrape up some info that will hopefully help
diagnose the problem, but since we have already crashed,
something is definitely wrong and this may fail.
Server version: 10.5.3-MariaDB-debug
key_buffer_size=134217728
read_buffer_size=131072
max_used_connections=3
max_threads=153
thread_count=4
It is possible that mysqld could use up to
key_buffer_size + (read_buffer_size + sort_buffer_size)*max_threads = 467925 K bytes of memory
Hope that's ok; if not, decrease some variables in the equation.
Thread pointer: 0x7f32b8000d78
Attempting backtrace. You can use the following information to find out
where mysqld died. If you see no messages after this, something went
terribly wrong...
stack_bottom = 0x7f32f8ea9dc0 thread_stack 0x49000
fil/fil0fil.cc:3410(fil_ibd_discover(unsigned long, Datafile&))[0x32d4681]
sql/multi_range_read.cc:764(Mrr_ordered_index_reader::refill_buffer(bool))[0x13c0898]
??:0(__restore_rt)[0x7f331352b890]
sql/sql_list.h:696(Ack_receiver::~Ack_receiver())[0x147a8e0]
sql/sql_bitmap.h:78(TABLE::prune_range_rowid_filters())[0x1570027]
sql/field.h:3573(Field_time_with_dec::Field_time_with_dec(unsigned char*, unsigned char*, unsigned char, Field::utype, st_mysql_const_lex_string const*, unsigned int))[0x14fa4b4]
psi/mysql_thread.h:738(inline_mysql_mutex_lock(st_mysql_mutex*, char const*, unsigned int))[0xaf14d0]
sql-common/client.c:1103(cli_fetch_lengths)[0x16bb78b]
sql/sql_yacc_ora.yy:2919(ORAparse(THD*))[0x168f4ba]
sql/sql_bitmap.h:78(TABLE::prune_range_rowid_filters())[0x1570027]
/usr/local/mysql/bin/mysqld(_Z12setup_fieldsP3THD20Bounds_checked_arrayIP4ItemER4ListIS2_E17enum_column_usagePS6_S9_b+0x864)[0x84aa74]
sql/sql_lex.cc:6312(LEX::sp_variable_declarations_copy_type_finalize(THD*, int, Column_definition const&, Row_definition_list*, Item*))[0xd908a2]
sql/slave.cc:4171(apply_event_and_update_pos_for_parallel(Log_event*, THD*, rpl_group_info*))[0xaf4a5d]
sql/sql_alloc.h:39(show_master_info_get_fields(THD*, List<Item>*, bool, unsigned long))[0xae3e76]
sql/item.h:3609(Item_null::Item_null(THD*, char const*, charset_info_st const*))[0xd8f934]
handler/i_s.cc:312(__cxx_global_var_init.15)[0xa25a6b]
sql/sys_vars.ic:627(Sys_var_charptr_fscs::Sys_var_charptr(char const*, char const, int, long, unsigned long, CMD_LINE, char const, PolyLock*, sys_var::binlog_status_enum, bool (*)(PolyLock**, THD*, set_var*), bool (*)(sys_var::binlog_status_enum, THD, enum_var_type), char const))[0xa07b70]
sql/set_var.h:258(_GLOBAL__sub_I_sys_vars.cc)[0x9fd70e]
sql/sys_vars.cc:5730(__cxx_global_var_init.1236)[0xa099cb]
sql/item.h:4563(Item_empty_string::Item_empty_string(THD*, char const*, unsigned int, charset_info_st const*))[0xedb6d1]
sql/item.h:746(show_binlog_info_get_fields(THD*, List<Item>*))[0xedaec1]
gcalc_slicescan.cc:0(__afl_fork_wait_loop)[0x1e8dfc6]
nptl/pthread_create.c:463(start_thread)[0x7f33135206db]
x86_64/clone.S:97(clone)[0x7f33112c088f]
Trying to get some variables.
Some pointers may be invalid and cause the dump to abort.
Query (0x7f32b8015055): UPDATE v0 SET v1 = NULL BETWEEN ( SELECT 95 FROM v0 WHERE v1 = 95 AND v1 < -1 GROUP BY - 'x' >= v1 HAVING ( -128 = 2147483647 AND v1 = 94 ) ) AND 36 WHERE v1 = 2
Connection ID (thread ID): 7521
Status: NOT_KILLED
Optimizer switch: index_merge=on,index_merge_union=on,index_merge_sort_union=on,index_merge_intersection=on,index_merge_sort_intersection=off,engine_condition_pushdown=off,index_condition_pushdown=on,derived_merge=on,derived_with_keys=on,firstmatch=on,loosescan=on,materialization=on,in_to_exists=on,semijoin=on,partial_match_rowid_merge=on,partial_match_table_scan=on,subquery_cache=on,mrr=off,mrr_cost_based=off,mrr_sort_keys=off,outer_join_with_cache=on,semijoin_with_cache=on,join_cache_incremental=on,join_cache_hashed=on,join_cache_bka=on,optimize_join_buffer_size=on,table_elimination=on,extended_keys=on,exists_to_in=on,orderby_uses_equalities=on,condition_pushdown_for_derived=on,split_materialized=on,condition_pushdown_for_subquery=on,rowid_filter=on,condition_pushdown_from_having=on,not_null_range_scan=off
The manual page at http://dev.mysql.com/doc/mysql/en/crashing.html contains
information that should help you find out what is causing the crash.
Writing a core file...
Working directory at /usr/local/mysql/data
Resource Limits:
Limit Soft Limit Hard Limit Units
Max cpu time unlimited unlimited seconds
Max file size unlimited unlimited bytes
Max data size unlimited unlimited bytes
Max stack size 8388608 unlimited bytes
Max core file size unlimited unlimited bytes
Max resident set unlimited unlimited bytes
Max processes unlimited unlimited processes
Max open files 1048576 1048576 files
Max locked memory 16777216 16777216 bytes
Max address space unlimited unlimited bytes
Max file locks unlimited unlimited locks
Max pending signals 1030951 1030951 signals
Max msgqueue size 819200 819200 bytes
Max nice priority 0 0
Max realtime priority 0 0
Max realtime timeout unlimited unlimited us
Core pattern: co...
---
{"report":{"fcp":1017.4000000953674,"ttfb":143.90000009536743,"pageVisibility":"visible","entityId":86493,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"fcd04166-6d7a-44f7-8b0d-e1c738fac2bc","navigationType":0,"readyForUser":1095.4000000953674,"redirectCount":0,"resourceLoadedEnd":1264.8000001907349,"resourceLoadedStart":148.5,"resourceTiming":[{"duration":455.40000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":148.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":148.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":603.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":455.2999999523163,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":148.70000004768372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":148.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":604,"responseStart":0,"secureConnectionStart":0},{"duration":464.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":148.80000019073486,"connectEnd":148.80000019073486,"connectStart":148.80000019073486,"domainLookupEnd":148.80000019073486,"domainLookupStart":148.80000019073486,"fetchStart":148.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":148.80000019073486,"responseEnd":612.9000000953674,"responseStart":612.9000000953674,"secureConnectionStart":148.80000019073486},{"duration":492.10000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":149,"connectEnd":149,"connectStart":149,"domainLookupEnd":149,"domainLookupStart":149,"fetchStart":149,"redirectEnd":0,"redirectStart":0,"requestStart":149,"responseEnd":641.1000001430511,"responseStart":641,"secureConnectionStart":149},{"duration":488.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":149,"connectEnd":149,"connectStart":149,"domainLookupEnd":149,"domainLookupStart":149,"fetchStart":149,"redirectEnd":0,"redirectStart":0,"requestStart":149,"responseEnd":637.5,"responseStart":637.5,"secureConnectionStart":149},{"duration":492.39999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":149.10000014305115,"connectEnd":149.10000014305115,"connectStart":149.10000014305115,"domainLookupEnd":149.10000014305115,"domainLookupStart":149.10000014305115,"fetchStart":149.10000014305115,"redirectEnd":0,"redirectStart":0,"requestStart":149.10000014305115,"responseEnd":641.5,"responseStart":641.5,"secureConnectionStart":149.10000014305115},{"duration":492.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":149.30000019073486,"connectEnd":149.30000019073486,"connectStart":149.30000019073486,"domainLookupEnd":149.30000019073486,"domainLookupStart":149.30000019073486,"fetchStart":149.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":149.30000019073486,"responseEnd":642,"responseStart":642,"secureConnectionStart":149.30000019073486},{"duration":493.2000000476837,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":149.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":149.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":642.6000001430511,"responseStart":0,"secureConnectionStart":0},{"duration":492.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":149.40000009536743,"connectEnd":149.40000009536743,"connectStart":149.40000009536743,"domainLookupEnd":149.40000009536743,"domainLookupStart":149.40000009536743,"fetchStart":149.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":149.40000009536743,"responseEnd":642.3000001907349,"responseStart":642.3000001907349,"secureConnectionStart":149.40000009536743},{"duration":493.2000000476837,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":149.60000014305115,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":149.60000014305115,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":642.8000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":493.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":149.70000004768372,"connectEnd":149.70000004768372,"connectStart":149.70000004768372,"domainLookupEnd":149.70000004768372,"domainLookupStart":149.70000004768372,"fetchStart":149.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":149.70000004768372,"responseEnd":642.9000000953674,"responseStart":642.9000000953674,"secureConnectionStart":149.70000004768372},{"duration":873.0999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":161.10000014305115,"connectEnd":161.10000014305115,"connectStart":161.10000014305115,"domainLookupEnd":161.10000014305115,"domainLookupStart":161.10000014305115,"fetchStart":161.10000014305115,"redirectEnd":0,"redirectStart":0,"requestStart":161.10000014305115,"responseEnd":1034.2000000476837,"responseStart":1034.2000000476837,"secureConnectionStart":161.10000014305115},{"duration":1052.8999998569489,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":163.30000019073486,"connectEnd":163.30000019073486,"connectStart":163.30000019073486,"domainLookupEnd":163.30000019073486,"domainLookupStart":163.30000019073486,"fetchStart":163.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":163.30000019073486,"responseEnd":1216.2000000476837,"responseStart":1216.2000000476837,"secureConnectionStart":163.30000019073486},{"duration":388.5,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":826.9000000953674,"connectEnd":826.9000000953674,"connectStart":826.9000000953674,"domainLookupEnd":826.9000000953674,"domainLookupStart":826.9000000953674,"fetchStart":826.9000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":826.9000000953674,"responseEnd":1215.4000000953674,"responseStart":1215.4000000953674,"secureConnectionStart":826.9000000953674},{"duration":235.79999995231628,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":996.4000000953674,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":996.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1232.2000000476837,"responseStart":0,"secureConnectionStart":0},{"duration":46.10000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1218.7000000476837,"connectEnd":1218.7000000476837,"connectStart":1218.7000000476837,"domainLookupEnd":1218.7000000476837,"domainLookupStart":1218.7000000476837,"fetchStart":1218.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":1218.7000000476837,"responseEnd":1264.8000001907349,"responseStart":1264.8000001907349,"secureConnectionStart":1218.7000000476837},{"duration":77.60000014305115,"initiatorType":"iframe","name":"https://jira.mariadb.org/plugins/servlet/gadgets/ifr?container=atlassian&mid=0&country=&lang=en&view=issuetab&view-params=%7B%22writable%22%3A%22false%22%7D&st=atlassian%3AH6J1zWJJxrpY35FKcJ4MF4fG37hcYVsUlIXNy6dzw3L8gJM7ZICxXIF2pIN9O%2FsvXKsnnkD6bN%2FWPCwd3Z%2F3zvSbE1XmXokAPqsqvM20lKquQesBl5GKh03qrIUwfeg1RNyJ7hKcGlGY%2BlBYYbJTkoxuUEURGR9S1eqO3yQ%2BduA6Y8KRM3PhVQqiQFSfClWcaEoHtHxaQidCPV14dB9kG44y28EeXjjEtF3hmJCNp%2FOO5knsc1S16r2Z6pVxI%2BUnCoeypw%3D%3D&up_isConfigured=true&up_isReallyConfigured=true&up_title=Activity+Stream&up_titleRequired=false&up_numofentries=20&up_refresh=false&up_maxProviderLabelCharacters=50&up_rules=%7B%22providers%22%3A%5B%7B%22provider%22%3A%22streams%22%2C%22rules%22%3A%5B%7B%22provider%22%3A%22streams%22%2C%22rule%22%3A%22issue-key%22%2C%22type%22%3A%22string%22%2C%22value%22%3A%22MDEV-22464%22%2C%22operator%22%3A%22is%22%7D%2C%7B%22provider%22%3A%22streams%22%2C%22rule%22%3A%22key%22%2C%22type%22%3A%22select%22%2C%22value%22%3A%5B%22MDEV%22%5D%2C%22operator%22%3A%22is%22%7D%5D%7D%5D%7D&up_renderingContext=view-issue&up_keys=&up_itemKeys=&up_username=&url=https%3A%2F%2Fjira.mariadb.org%2Frest%2Fgadgets%2F1.0%2Fg%2Fcom.atlassian.streams.streams-jira-plugin%2Fgadgets%2Factivitystream-gadget.xml&libs=auth-refresh#rpctoken=44032152","startTime":1223.5,"connectEnd":1223.5,"connectStart":1223.5,"domainLookupEnd":1223.5,"domainLookupStart":1223.5,"fetchStart":1223.5,"redirectEnd":0,"redirectStart":0,"requestStart":1266.1000001430511,"responseEnd":1301.1000001430511,"responseStart":1299.5,"secureConnectionStart":1223.5}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":3,"responseStart":144,"responseEnd":163,"domLoading":147,"domInteractive":1287,"domContentLoadedEventStart":1287,"domContentLoadedEventEnd":1325,"domComplete":1645,"loadEventStart":1645,"loadEventEnd":1646,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1220.7000000476837},{"name":"bigPipe.sidebar-id.end","time":1221.3000001907349},{"name":"bigPipe.activity-panel-pipe-id.start","time":1221.4000000953674},{"name":"bigPipe.activity-panel-pipe-id.end","time":1223.7000000476837},{"name":"activityTabFullyLoaded","time":1337.1000001430511}],"measures":[],"correlationId":"e33692c01f6e8d","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":73,"dbReadsTimeInMs":14,"dbConnsTimeInMs":21,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}