Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-28095

crash in multi-update and implicit grouping

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 10.9.0, 10.3, 10.4, 10.5, 10.6, 10.7, 10.8
    • Fix Version/s: 10.3.35, 10.4.25, 10.5.16, 10.6.8, 10.7.4
    • Labels:
      None
    • Environment:
      Linux jie-2 5.4.143-1-pve #1 SMP PVE 5.4.143-1 (Tue, 28 Sep 2021 09:10:37 +0200) x86_64 x86_64 x86_64 GNU/Linux

      Description

      PoC:

      CREATE TABLE v0 ( v3 DOUBLE , v2 TEXT UNIQUE NOT NULL , v1 INT NOT NULL ) ;
      INSERT INTO v0 VALUES ( ( 'x' = 62 OR v1 = 33 ) , -1 , 5 ) ;
      CREATE TABLE v5 ( v4 CHAR ( 98 ) UNIQUE NULL , ONE INT ) AS SELECT 'x' FROM v0 ;
      UPDATE v5 SET v1 = ( NOT ( v4 IS NULL ) ) ;
      UPDATE v5 SET v2 = abs ( 0 + 4 ) , v2 = 11 ;
      SELECT DISTINCT -1 , v3 + -1 , -1 FROM v0 UNION SELECT DISTINCT * FROM v5 ;
      UPDATE v5 NATURAL JOIN v0 SET v4 = v2 , v1 = 0 ORDER BY 97811695.000000 * AVG ( v3 ) ASC ;
      

      report (compiled with ASAN):

      Thread pointer: 0x62b00015e218                                                                                                                                                               
      Attempting backtrace. You can use the following information to find out                                                                                                                      
      where mysqld died. If you see no messages after this, something went                                                                                                                         
      terribly wrong...                                                                                                                                                                            
      stack_bottom = 0x7fc262592880 thread_stack 0x5fc00                                                                                                                                           
      ??:0(__interceptor_backtrace)[0x7cbadb]                                                                                                                                                      
      mysys/stacktrace.c:212(my_print_stacktrace)[0x2a86d37]                                                                                                                                       
      sql/signal_handler.cc:0(handle_fatal_signal)[0x15af5d9]                                                                                                                                      
      sigaction.c:0(__restore_rt)[0x7fc286d323c0]                                                                                                                                                  
      ??:0(gsignal)[0x7fc28696003b]                                                                                                                                                                
      ??:0(abort)[0x7fc28693f859]                                                                                                                                                                  
      ut/ut0dbg.cc:40(ut_dbg_assertion_failed(char const*, char const*, unsigned int))[0x25a393e]                                                                                                  
      row/row0mysql.cc:1633(row_update_for_mysql(row_prebuilt_t*))[0x244a426]                                                                                                                      
      handler/ha_innodb.cc:8562(ha_innobase::update_row(unsigned char const*, unsigned char const*))[0x21700b4]                                                                                    
      sql/handler.cc:7575(handler::ha_update_row(unsigned char const*, unsigned char const*))[0x15ee54f]                                                                                           
      sql/sql_update.cc:2593(multi_update::send_data(List<Item>&))[0x100d8b5]                                                                                                                      
      sql/sql_select.cc:22489(end_send_group(JOIN*, st_join_table*, bool))[0xe2f2e7]                                                                                                               
      sql/sql_select.cc:20642(do_select(JOIN*, Procedure*))[0xdc6a47]                                                                                                                              
      sql/sql_select.cc:4528(JOIN::exec())[0xdc344d]                                                                                                                                               
      sql/sql_select.cc:5009(mysql_select(THD*, TABLE_LIST*, List<Item>&, Item*, unsigned int, st_order*, st_order*, Item*, st_order*, unsigned long long, select_result*, st_select_lex_unit*, st_
      select_lex*))[0xd4e4e9]                                                                                                                                                                      
      sql/sql_update.cc:1968(mysql_multi_update(THD*, TABLE_LIST*, List<Item>*, List<Item>*, Item*, unsigned long long, enum_duplicates, bool, st_select_lex_unit*, st_select_lex*, multi_update**)
      )[0x1006043]                                                                                                                                                                                 
      sql/sql_parse.cc:4486(mysql_execute_command(THD*, bool))[0xc682ea]                                                                                                                           
      sql/sql_class.h:2734(THD::enter_stage(PSI_stage_info_v1 const*, char const*, char const*, unsigned int))[0xc4a67f]                                                                           
      sql/sql_parse.cc:1894(dispatch_command(enum_server_command, THD*, char*, unsigned int, bool))[0xc41baa]                                                                                      
      sql/sql_parse.cc:1404(do_command(THD*, bool))[0xc4b74c]                                                                                                                                      
      sql/sql_connect.cc:1418(do_handle_one_connection(CONNECT*, bool))[0x111f9f3]
      ??:0(handle_one_connection)[0x111f249]
      perfschema/pfs.cc:2203(pfs_spawn_thread)[0x1f3f9de]
      nptl/pthread_create.c:478(start_thread)[0x7fc286d26609]
      ??:0(clone)[0x7fc286a3c163]
       
      Trying to get some variables.
      Some pointers may be invalid and cause the dump to abort.
      Query (0x62900008c238): UPDATE v5 NATURAL JOIN v0 SET v4 = v2 , v1 = 0 ORDER BY 97811695.000000 * AVG ( v3 ) ASC
      

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              serg Sergei Golubchik
              Reporter:
              fuboat Jingzhou Fu
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.