I used my fuzzing tool to test Mariadb , and found a bug that can result in an abortion.
Mariadb installation:
1) cd mariadb-10.5.9
2) mkdir build; cd build
3) cmake -DWITH_ASAN=ON -DWITH_ASAN_SCOPE=ON -DCMAKE_BUILD_TYPE=Debug ../
4) make -j8 && sudo make install
How to Repeat:
export ASAN_OPTIONS=detect_leaks=0
/usr/local/mysql/bin/mysqld_safe &
/usr/local/mysql/bin/mysql -uroot -p123456(your password)
MariaDB> drop database if exists test_db;
MariaDB> create database test_db;
MariaDB> use test_db;
MariaDB> source fuzz.sql;
I have simplified the content of fuzz.sql, and I hope fuzz.sql can help you reproduce the bug and fix it. In addition, I attach the failure report (which has its stack trace).
Zuming Jiang
made changes -
2021-08-13 04:28
Field
Original Value
New Value
Attachment
fuzz.sql
[ 58528
]
Daniel Black
made changes -
2021-08-13 23:16
Summary
BUG: Abortion in sql/item_func.cc:0
BUG: segfault in sql/item_func.cc:0
Daniel Black
made changes -
2021-08-18 04:07
Fix Version/s
N/A
[ 14700
]
Assignee
Daniel Black
[ danblack
]
Resolution
Cannot Reproduce
[ 5
]
Status
Open
[ 1
]
Closed
[ 6
]
Sergei Golubchik
made changes -
2021-12-06 21:53
Workflow
MariaDB v3
[ 124257
]
MariaDB v4
[ 159572
]
{"report":{"fcp":839.5,"ttfb":234.79999923706055,"pageVisibility":"visible","entityId":101913,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"c794b3e2-944a-4d61-8f55-4c9561505313","navigationType":0,"readyForUser":945.3999996185303,"redirectCount":0,"resourceLoadedEnd":881.7999992370605,"resourceLoadedStart":241.69999980926514,"resourceTiming":[{"duration":47.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":241.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":241.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":289.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":48,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":241.89999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":241.89999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":289.8999996185303,"responseStart":0,"secureConnectionStart":0},{"duration":114.60000038146973,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":242.0999994277954,"connectEnd":242.0999994277954,"connectStart":242.0999994277954,"domainLookupEnd":242.0999994277954,"domainLookupStart":242.0999994277954,"fetchStart":242.0999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":242.0999994277954,"responseEnd":356.69999980926514,"responseStart":356.69999980926514,"secureConnectionStart":242.0999994277954},{"duration":180.70000076293945,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":242.29999923706055,"connectEnd":242.29999923706055,"connectStart":242.29999923706055,"domainLookupEnd":242.29999923706055,"domainLookupStart":242.29999923706055,"fetchStart":242.29999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":242.29999923706055,"responseEnd":423,"responseStart":423,"secureConnectionStart":242.29999923706055},{"duration":184.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":242.5999994277954,"connectEnd":242.5999994277954,"connectStart":242.5999994277954,"domainLookupEnd":242.5999994277954,"domainLookupStart":242.5999994277954,"fetchStart":242.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":242.5999994277954,"responseEnd":426.79999923706055,"responseStart":426.79999923706055,"secureConnectionStart":242.5999994277954},{"duration":184.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":242.69999980926514,"connectEnd":242.69999980926514,"connectStart":242.69999980926514,"domainLookupEnd":242.69999980926514,"domainLookupStart":242.69999980926514,"fetchStart":242.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":242.69999980926514,"responseEnd":427.3999996185303,"responseStart":427.3999996185303,"secureConnectionStart":242.69999980926514},{"duration":184.89999961853027,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":242.89999961853027,"connectEnd":242.89999961853027,"connectStart":242.89999961853027,"domainLookupEnd":242.89999961853027,"domainLookupStart":242.89999961853027,"fetchStart":242.89999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":242.89999961853027,"responseEnd":427.79999923706055,"responseStart":427.79999923706055,"secureConnectionStart":242.89999961853027},{"duration":255.69999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":243.0999994277954,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":243.0999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":498.79999923706055,"responseStart":0,"secureConnectionStart":0},{"duration":185,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":243.29999923706055,"connectEnd":243.29999923706055,"connectStart":243.29999923706055,"domainLookupEnd":243.29999923706055,"domainLookupStart":243.29999923706055,"fetchStart":243.29999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":243.29999923706055,"responseEnd":428.29999923706055,"responseStart":428.29999923706055,"secureConnectionStart":243.29999923706055},{"duration":255.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":243.39999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":243.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":498.8999996185303,"responseStart":0,"secureConnectionStart":0},{"duration":185.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":243.5999994277954,"connectEnd":243.5999994277954,"connectStart":243.5999994277954,"domainLookupEnd":243.5999994277954,"domainLookupStart":243.5999994277954,"fetchStart":243.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":243.5999994277954,"responseEnd":428.79999923706055,"responseStart":428.79999923706055,"secureConnectionStart":243.5999994277954},{"duration":601.1999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":244.5,"connectEnd":244.5,"connectStart":244.5,"domainLookupEnd":244.5,"domainLookupStart":244.5,"fetchStart":244.5,"redirectEnd":0,"redirectStart":0,"requestStart":244.5,"responseEnd":845.6999998092651,"responseStart":845.6999998092651,"secureConnectionStart":244.5},{"duration":602.0999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":244.5,"connectEnd":244.5,"connectStart":244.5,"domainLookupEnd":244.5,"domainLookupStart":244.5,"fetchStart":244.5,"redirectEnd":0,"redirectStart":0,"requestStart":244.5,"responseEnd":846.5999994277954,"responseStart":846.5999994277954,"secureConnectionStart":244.5},{"duration":120.40000057220459,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":510.79999923706055,"connectEnd":510.79999923706055,"connectStart":510.79999923706055,"domainLookupEnd":510.79999923706055,"domainLookupStart":510.79999923706055,"fetchStart":510.79999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":510.79999923706055,"responseEnd":631.1999998092651,"responseStart":631.1999998092651,"secureConnectionStart":510.79999923706055},{"duration":93.39999961853027,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":788.3999996185303,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":788.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":881.7999992370605,"responseStart":0,"secureConnectionStart":0},{"duration":75.89999961853027,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":789.3999996185303,"connectEnd":789.3999996185303,"connectStart":789.3999996185303,"domainLookupEnd":789.3999996185303,"domainLookupStart":789.3999996185303,"fetchStart":789.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":789.3999996185303,"responseEnd":865.2999992370605,"responseStart":865.2999992370605,"secureConnectionStart":789.3999996185303},{"duration":149.10000038146973,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":830.5999994277954,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":830.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":979.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":84.90000057220459,"initiatorType":"script","name":"https://jira.mariadb.org/s/097ae97cb8fbec7d6ea4bbb1f26955b9-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":789.7999992370605,"connectEnd":789.7999992370605,"connectStart":789.7999992370605,"domainLookupEnd":789.7999992370605,"domainLookupStart":789.7999992370605,"fetchStart":789.7999992370605,"redirectEnd":0,"redirectStart":0,"requestStart":789.7999992370605,"responseEnd":874.6999998092651,"responseStart":874.6999998092651,"secureConnectionStart":789.7999992370605}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":68,"responseStart":235,"responseEnd":238,"domLoading":239,"domInteractive":1028,"domContentLoadedEventStart":1028,"domContentLoadedEventEnd":1084,"domComplete":1231,"loadEventStart":1231,"loadEventEnd":1231,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":987.0999994277954},{"name":"bigPipe.sidebar-id.end","time":987.8999996185303},{"name":"bigPipe.activity-panel-pipe-id.start","time":988},{"name":"bigPipe.activity-panel-pipe-id.end","time":991},{"name":"activityTabFullyLoaded","time":1100.8999996185303}],"measures":[],"correlationId":"d82dee84dbc7a6","effectiveType":"4g","downlink":9.6,"rtt":0,"serverDuration":114,"dbReadsTimeInMs":18,"dbConnsTimeInMs":27,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
Failed to reproduce on:
10.5.13-0268b871228
CMakeCache.txt:WITH_ASAN:BOOL=ON
CMakeCache.txt:WITH_ASAN_SCOPE:BOOL=ON
CMAKE_CXX_COMPILER:STRING=/usr/lib64/ccache/clang++
CMAKE_C_COMPILER:STRING=/usr/lib64/ccache/clang
CMAKE_BUILD_TYPE:STRING=RelWithDebInfo
$ /usr/lib64/ccache/clang++ --version
clang version 12.0.0 (Fedora 12.0.0-2.fc34)
Target: x86_64-unknown-linux-gnu
Thread model: posix
InstalledDir: /usr/bin
Also failed to reproduce on same commit with CMAKE_BUILD_TYPE=Debug
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 3
Server version: 10.5.13-MariaDB-debug Source distribution
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MariaDB [(none)]> create or replace database test_db;
Query OK, 1 row affected (0.001 sec)
MariaDB [(none)]> use test_db;
Database changed
MariaDB [test_db]> source ~/Downloads/fuzz-MDEV-26348.sql
Query OK, 0 rows affected (0.007 sec)
Query OK, 0 rows affected (0.008 sec)
Records: 0 Duplicates: 0 Warnings: 0
Empty set (0.005 sec)
MariaDB [test_db]>