Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-26350

Assertion failure: select_lex->ref_pointer_array.size() % 5 == 0

    XMLWordPrintable

    Details

      Description

      I used my fuzzing tool to test Mariadb , and found a bug that can result in an abortion.

      Mariadb installation:
      1) cd mariadb-10.5.9
      2) mkdir build; cd build
      3) cmake -DWITH_ASAN=ON -DWITH_ASAN_SCOPE=ON -DCMAKE_BUILD_TYPE=Debug ../
      4) make -j8 && sudo make install

      How to Repeat:
      export ASAN_OPTIONS=detect_leaks=0
      /usr/local/mysql/bin/mysqld_safe &
      /usr/local/mysql/bin/mysql -uroot -p123456(your password)
      MariaDB> drop database if exists test_db;
      MariaDB> create database test_db;
      MariaDB> use test_db;
      MariaDB> source fuzz.sql;

      I have simplified the content of fuzz.sql (this one is still very complicate), and I hope fuzz.sql can help you reproduce the bug and fix it. In addition, I attach the failure report (which has its stack trace).

        Attachments

        1. fuzz.sql
          3.90 MB
        2. gdb.txt
          180 kB
        3. report.txt
          70 kB

          Activity

            People

            Assignee:
            danblack Daniel Black
            Reporter:
            Zuming Jiang Zuming Jiang
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:

                Git Integration