I used my fuzzing tool to test Mariadb , and found a bug that can result in an abortion.
Mariadb installation:
1) cd mariadb-10.5.9
2) mkdir build; cd build
3) cmake -DWITH_ASAN=ON -DWITH_ASAN_SCOPE=ON -DWITH_DEBUG=ON ../
4) make -j8 && sudo make install
How to Repeat:
export ASAN_OPTIONS=detect_leaks=0
/usr/local/mysql/bin/mysqld_safe &
/usr/local/mysql/bin/mysql -uroot -p123456(your password)
MariaDB> drop database if exists test_db;
MariaDB> create database test_db;
MariaDB> source fuzz.sql;
I have simplified the content of fuzz.sql, and I hope fuzz.sql can help you reproduce the bug and fix it. In addition, I attach the abortion report (which has its stack trace).
- duplicates
-
MDEV-22464
Server crash on UPDATE with nested subquery
-
-
Closed
- links to
-
{"report":{"fcp":1750.3000001907349,"ttfb":569.1999998092651,"pageVisibility":"visible","entityId":99512,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"61330754-b7a3-4aa4-858d-9705d3b9a897","navigationType":0,"readyForUser":1848.4000000953674,"redirectCount":0,"resourceLoadedEnd":2515.9000000953674,"resourceLoadedStart":577.0999999046326,"resourceTiming":[{"duration":505.2000002861023,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":577.0999999046326,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":577.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1082.3000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":505.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":577.4000000953674,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":577.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1082.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":564.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":577.5,"connectEnd":577.5,"connectStart":577.5,"domainLookupEnd":577.5,"domainLookupStart":577.5,"fetchStart":577.5,"redirectEnd":0,"redirectStart":0,"requestStart":577.5,"responseEnd":1142.1999998092651,"responseStart":1142.1999998092651,"secureConnectionStart":577.5},{"duration":680,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":577.8000001907349,"connectEnd":577.8000001907349,"connectStart":577.8000001907349,"domainLookupEnd":577.8000001907349,"domainLookupStart":577.8000001907349,"fetchStart":577.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":577.8000001907349,"responseEnd":1257.8000001907349,"responseStart":1257.8000001907349,"secureConnectionStart":577.8000001907349},{"duration":683.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":578,"connectEnd":578,"connectStart":578,"domainLookupEnd":578,"domainLookupStart":578,"fetchStart":578,"redirectEnd":0,"redirectStart":0,"requestStart":578,"responseEnd":1261.6999998092651,"responseStart":1261.6999998092651,"secureConnectionStart":578},{"duration":684,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":578.1999998092651,"connectEnd":578.1999998092651,"connectStart":578.1999998092651,"domainLookupEnd":578.1999998092651,"domainLookupStart":578.1999998092651,"fetchStart":578.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":578.1999998092651,"responseEnd":1262.1999998092651,"responseStart":1262.1999998092651,"secureConnectionStart":578.1999998092651},{"duration":684.5999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":578.3000001907349,"connectEnd":578.3000001907349,"connectStart":578.3000001907349,"domainLookupEnd":578.3000001907349,"domainLookupStart":578.3000001907349,"fetchStart":578.3000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":578.3000001907349,"responseEnd":1262.9000000953674,"responseStart":1262.9000000953674,"secureConnectionStart":578.3000001907349},{"duration":716.9000000953674,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":578.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":578.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1295.4000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":684.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":578.6999998092651,"connectEnd":578.6999998092651,"connectStart":578.6999998092651,"domainLookupEnd":578.6999998092651,"domainLookupStart":578.6999998092651,"fetchStart":578.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":578.6999998092651,"responseEnd":1263.4000000953674,"responseStart":1263.4000000953674,"secureConnectionStart":578.6999998092651},{"duration":716.6999998092651,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":578.9000000953674,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":578.9000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1295.5999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":684.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":579,"connectEnd":579,"connectStart":579,"domainLookupEnd":579,"domainLookupStart":579,"fetchStart":579,"redirectEnd":0,"redirectStart":0,"requestStart":579,"responseEnd":1263.9000000953674,"responseStart":1263.9000000953674,"secureConnectionStart":579},{"duration":1924.4000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":580,"connectEnd":580,"connectStart":580,"domainLookupEnd":580,"domainLookupStart":580,"fetchStart":580,"redirectEnd":0,"redirectStart":0,"requestStart":580,"responseEnd":2504.4000000953674,"responseStart":2504.4000000953674,"secureConnectionStart":580},{"duration":1935.8000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":580.0999999046326,"connectEnd":580.0999999046326,"connectStart":580.0999999046326,"domainLookupEnd":580.0999999046326,"domainLookupStart":580.0999999046326,"fetchStart":580.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":580.0999999046326,"responseEnd":2515.9000000953674,"responseStart":2515.9000000953674,"secureConnectionStart":580.0999999046326},{"duration":1019.9000000953674,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1333.0999999046326,"connectEnd":1333.0999999046326,"connectStart":1333.0999999046326,"domainLookupEnd":1333.0999999046326,"domainLookupStart":1333.0999999046326,"fetchStart":1333.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":1333.0999999046326,"responseEnd":2353,"responseStart":2353,"secureConnectionStart":1333.0999999046326},{"duration":815.4000000953674,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1739.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1739.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":2554.9000000953674,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":65,"responseStart":569,"responseEnd":573,"domLoading":574,"domInteractive":2556,"domContentLoadedEventStart":2556,"domContentLoadedEventEnd":2617,"domComplete":2995,"loadEventStart":2995,"loadEventEnd":2996,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":2524.199999809265},{"name":"bigPipe.sidebar-id.end","time":2530.4000000953674},{"name":"bigPipe.activity-panel-pipe-id.start","time":2530.5999999046326},{"name":"bigPipe.activity-panel-pipe-id.end","time":2532.699999809265},{"name":"activityTabFullyLoaded","time":2635.699999809265}],"measures":[],"correlationId":"1adbd4e1e6ec3f","effectiveType":"4g","downlink":9.4,"rtt":0,"serverDuration":113,"dbReadsTimeInMs":11,"dbConnsTimeInMs":20,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
Thanks! Repeatable on 10.3-10.5. This is a duplicate of
MDEV-22464:10.3 98e6159892ae36d4ab82c
Version: '10.3.29-MariaDB-debug-log'
210510 12:19:43 [ERROR] mysqld got signal 11 ;
sigaction.c:0(__restore_rt)[0x7fef67b3f3c0]
sql/item.cc:7956(Item_ref::fix_fields(THD*, Item**))[0x55e2b7725dfd]
sql/item.h:829(Item::fix_fields_if_needed(THD*, Item**))[0x55e2b6cbc75b]
sql/item_func.cc:352(Item_func::fix_fields(THD*, Item**))[0x55e2b77e33e6]
sql/item.h:829(Item::fix_fields_if_needed(THD*, Item**))[0x55e2b6cbc75b]
sql/item.h:833(Item::fix_fields_if_needed_for_scalar(THD*, Item**))[0x55e2b6cbc795]
sql/item.h:838(Item::fix_fields_if_needed_for_bool(THD*, Item**))[0x55e2b6de1589]
sql/sql_select.cc:1211(JOIN::prepare(TABLE_LIST*, unsigned int, Item*, unsigned int, st_order*, bool, st_order*, Item*, st_order*, st_select_lex*, st_select_lex_unit*))[0x55e2b6fd5c77]
sql/item_subselect.cc:3790(subselect_single_select_engine::prepare(THD*))[0x55e2b78d64fa]
sql/item_subselect.cc:280(Item_subselect::fix_fields(THD*, Item**))[0x55e2b78b04c3]
sql/item.h:829(Item::fix_fields_if_needed(THD*, Item**))[0x55e2b6cbc75b]
sql/item_func.cc:352(Item_func::fix_fields(THD*, Item**))[0x55e2b77e33e6]
sql/item.h:829(Item::fix_fields_if_needed(THD*, Item**))[0x55e2b6cbc75b]
sql/item_func.cc:352(Item_func::fix_fields(THD*, Item**))[0x55e2b77e33e6]
sql/item.h:829(Item::fix_fields_if_needed(THD*, Item**))[0x55e2b6cbc75b]
sql/item.h:833(Item::fix_fields_if_needed_for_scalar(THD*, Item**))[0x55e2b6cbc795]
sql/item.h:838(Item::fix_fields_if_needed_for_bool(THD*, Item**))[0x55e2b6de1589]
sql/sql_base.cc:8299(setup_conds(THD*, TABLE_LIST*, List<TABLE_LIST>&, Item**))[0x55e2b6dd8ed1]
sql/sql_select.cc:660(setup_without_group(THD*, Bounds_checked_array<Item*>, TABLE_LIST*, List<TABLE_LIST>&, List<Item>&, List<Item>&, Item**, st_order*, st_order*, List<Window_spec>&, List<Item_window_func>&, bool*, unsigned int*))[0x55e2b6fcf2bc]
sql/sql_select.cc:1153(JOIN::prepare(TABLE_LIST*, unsigned int, Item*, unsigned int, st_order*, bool, st_order*, Item*, st_order*, st_select_lex*, st_select_lex_unit*))[0x55e2b6fd504e]
sql/sql_select.cc:4318(mysql_select(THD*, TABLE_LIST*, unsigned int, List<Item>&, Item*, unsigned int, st_order*, st_order*, Item*, st_order*, unsigned long long, select_result*, st_select_lex_unit*, st_select_lex*))[0x55e2b6ff6846]
sql/sql_update.cc:1816(mysql_multi_update(THD*, TABLE_LIST*, List<Item>*, List<Item>*, Item*, unsigned long long, enum_duplicates, bool, st_select_lex_unit*, st_select_lex*, multi_update**))[0x55e2b71e1b4e]
sql/sql_parse.cc:4422(mysql_execute_command(THD*))[0x55e2b6f2ff56]
sql/sql_parse.cc:7873(mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool))[0x55e2b6f48888]
sql/sql_parse.cc:1855(dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool))[0x55e2b6f1f66d]
sql/sql_parse.cc:1398(do_command(THD*))[0x55e2b6f1c1a4]
sql/sql_connect.cc:1403(do_handle_one_connection(CONNECT*))[0x55e2b72ea2c9]
sql/sql_connect.cc:1309(handle_one_connection)[0x55e2b72e9b83]
perfschema/pfs.cc:1871(pfs_spawn_thread)[0x55e2b891d7a7]
nptl/pthread_create.c:478(start_thread)[0x7fef67b33609]
x86_64/clone.S:97(__GI___clone)[0x7fef67a5a293]
Query (0x62b000000290): UPDATE v0 SET
v1 = 26 WHERE (
SELECT 33 FROM v0 AS v2
JOIN v0
ON 0<>0 ) = ( SELECT ( v1 + v1 ) / 127 AS v3 FROM v0 AS v4 GROUP BY NOT v1 <= 'x' HAVING v1 ) - v1