Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-28482

SIGSEGV in get_access_value_from_val_int (10.5+) and GRANT_TABLE::GRANT_TABLE (10.4), UBSAN: member call on null pointer in member call on null pointer

    XMLWordPrintable

Details

    Description

      Regression since 10.4. Not present in MySQL.

      ALTER TABLE mysql.tables_priv DROP COLUMN TIMESTAMP;
      FLUSH PRIVILEGES;
      

      Leads to:

      10.9.0 0b14dbd45b5a1c02616d611876158d44b92b77bf (Optimized)

      Core was generated by `/test/MD030522-mariadb-10.9.0-linux-x86_64-opt/bin/mysqld --no-defaults --core-'.
      Program terminated with signal SIGSEGV, Segmentation fault.
      #0  get_access_value_from_val_int (field=0x0)
          at /test/10.9_opt/sql/sql_acl.cc:5268
      5268	  return privilege_t(ALL_KNOWN_ACL & (ulonglong) field->val_int());
      [Current thread is 1 (Thread 0x1485e0061700 (LWP 3927817))]
      (gdb) bt
      #0  get_access_value_from_val_int (field=0x0) at /test/10.9_opt/sql/sql_acl.cc:5268
      #1  GRANT_TABLE::GRANT_TABLE (this=0x1485900396b0, form=0x148590028ca8, col_privs=0x55e804a23b68) at /test/10.9_opt/sql/sql_acl.cc:5384
      #2  0x000055e801926a20 in grant_load (procs_priv=@0x1485e005fe58: {<Grant_table_base> = {min_columns = 8, start_priv_columns = 0, end_priv_columns = 8, m_table = 0x55e804a3cb88}, <No data fields>}, columns_priv=@0x1485e005fe28: {<Grant_table_base> = {min_columns = 7, start_priv_columns = 0, end_priv_columns = 7, m_table = 0x55e804a23b68}, <No data fields>}, tables_priv=@0x1485e005fe10: {<Grant_table_base> = {min_columns = 8, start_priv_columns = 0, end_priv_columns = 7, m_table = 0x148590028ca8}, <No data fields>}, thd=0x148590000c58) at /test/10.9_opt/sql/sql_alloc.h:37
      #3  grant_reload (thd=thd@entry=0x148590000c58) at /test/10.9_opt/sql/sql_acl.cc:8044
      #4  0x000055e801ae6d1f in reload_acl_and_cache (thd=<optimized out>, thd@entry=0x148590000c58, options=1, tables=tables@entry=0x0, write_to_binlog=write_to_binlog@entry=0x1485e00600b0) at /test/10.9_opt/sql/sql_reload.cc:88
      #5  0x000055e8019b7e92 in mysql_execute_command (thd=0x148590000c58, is_called_from_prepared_stmt=<optimized out>) at /test/10.9_opt/sql/sql_parse.cc:5473
      #6  0x000055e8019a7a55 in mysql_parse (rawbuf=<optimized out>, length=<optimized out>, parser_state=<optimized out>, thd=0x148590000c58) at /test/10.9_opt/sql/sql_parse.cc:8046
      #7  mysql_parse (thd=0x148590000c58, rawbuf=<optimized out>, length=<optimized out>, parser_state=<optimized out>) at /test/10.9_opt/sql/sql_parse.cc:7968
      #8  0x000055e8019b371a in dispatch_command (command=COM_QUERY, thd=0x148590000c58, packet=<optimized out>, packet_length=<optimized out>, blocking=<optimized out>) at /test/10.9_opt/sql/sql_class.h:1364
      #9  0x000055e8019b5642 in do_command (thd=0x148590000c58, blocking=blocking@entry=true) at /test/10.9_opt/sql/sql_parse.cc:1408
      #10 0x000055e801aca5bf in do_handle_one_connection (connect=<optimized out>, connect@entry=0x55e804a5b568, put_in_cache=put_in_cache@entry=true) at /test/10.9_opt/sql/sql_connect.cc:1418
      #11 0x000055e801aca89d in handle_one_connection (arg=0x55e804a5b568) at /test/10.9_opt/sql/sql_connect.cc:1312
      #12 0x00001485f90cf609 in start_thread (arg=<optimized out>) at pthread_create.c:477
      #13 0x00001485f8cbb163 in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95
      

      10.9.0 0b14dbd45b5a1c02616d611876158d44b92b77bf (Debug)

      Core was generated by `/test/MD030522-mariadb-10.9.0-linux-x86_64-dbg/bin/mysqld --no-defaults --core-'.
      Program terminated with signal SIGSEGV, Segmentation fault.
      #0  get_access_value_from_val_int (field=0x0)
          at /test/10.9_dbg/sql/sql_acl.cc:5268
      5268	  return privilege_t(ALL_KNOWN_ACL & (ulonglong) field->val_int());
      [Current thread is 1 (Thread 0x14dd74bc9700 (LWP 3931631))]
      (gdb) bt
      #0  get_access_value_from_val_int (field=0x0) at /test/10.9_dbg/sql/sql_acl.cc:5268
      #1  0x00005578d1beb48a in GRANT_TABLE::GRANT_TABLE (this=0x14dd3805dc90, form=0x14dd38051068, col_privs=0x5578d453a2a8) at /test/10.9_dbg/sql/sql_acl.cc:5384
      #2  0x00005578d1bec2d4 in grant_load (procs_priv=@0x14dd74bc7e38: {<Grant_table_base> = {min_columns = 8, start_priv_columns = 0, end_priv_columns = 8, m_table = 0x5578d4505188}, <No data fields>}, columns_priv=@0x14dd74bc7e08: {<Grant_table_base> = {min_columns = 7, start_priv_columns = 0, end_priv_columns = 7, m_table = 0x5578d453a2a8}, <No data fields>}, tables_priv=@0x14dd74bc7df0: {<Grant_table_base> = {min_columns = 8, start_priv_columns = 0, end_priv_columns = 7, m_table = 0x14dd38051068}, <No data fields>}, thd=0x14dd38000db8) at /test/10.9_dbg/sql/handler.h:3389
      #3  grant_reload (thd=thd@entry=0x14dd38000db8) at /test/10.9_dbg/sql/sql_acl.cc:8044
      #4  0x00005578d1e283cd in reload_acl_and_cache (thd=<optimized out>, thd@entry=0x14dd38000db8, options=1, tables=tables@entry=0x0, write_to_binlog=write_to_binlog@entry=0x14dd74bc8080) at /test/10.9_dbg/sql/sql_reload.cc:88
      #5  0x00005578d1ca0925 in mysql_execute_command (thd=thd@entry=0x14dd38000db8, is_called_from_prepared_stmt=is_called_from_prepared_stmt@entry=false) at /test/10.9_dbg/sql/sql_parse.cc:5473
      #6  0x00005578d1c8a67b in mysql_parse (thd=thd@entry=0x14dd38000db8, rawbuf=<optimized out>, length=<optimized out>, parser_state=parser_state@entry=0x14dd74bc8470) at /test/10.9_dbg/sql/sql_parse.cc:8046
      #7  0x00005578d1c97f79 in dispatch_command (command=command@entry=COM_QUERY, thd=thd@entry=0x14dd38000db8, packet=packet@entry=0x14dd3800b699 "FLUSH PRIVILEGES", packet_length=packet_length@entry=16, blocking=blocking@entry=true) at /test/10.9_dbg/sql/sql_class.h:1364
      #8  0x00005578d1c9a686 in do_command (thd=0x14dd38000db8, blocking=blocking@entry=true) at /test/10.9_dbg/sql/sql_parse.cc:1408
      #9  0x00005578d1df7d02 in do_handle_one_connection (connect=<optimized out>, connect@entry=0x5578d454c838, put_in_cache=put_in_cache@entry=true) at /test/10.9_dbg/sql/sql_connect.cc:1418
      #10 0x00005578d1df820b in handle_one_connection (arg=0x5578d454c838) at /test/10.9_dbg/sql/sql_connect.cc:1312
      #11 0x000014dd8de53609 in start_thread (arg=<optimized out>) at pthread_create.c:477
      #12 0x000014dd8da3f163 in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95
      

      Bug confirmed present in:
      MariaDB: 10.4.25 (dbg), 10.4.25 (opt), 10.5.16 (dbg), 10.5.16 (opt), 10.6.8 (dbg), 10.6.8 (opt), 10.7.4 (dbg), 10.7.4 (opt), 10.8.3 (dbg), 10.8.3 (opt), 10.9.0 (dbg), 10.9.0 (opt)

      Bug (or feature/syntax) confirmed not present in:
      MariaDB: 10.2.44 (dbg), 10.2.44 (opt), 10.3.35 (dbg), 10.3.35 (opt)
      MySQL: 5.5.62 (dbg), 5.5.62 (opt), 5.6.51 (dbg), 5.6.51 (opt), 5.7.37 (dbg), 5.7.37 (opt), 8.0.28 (dbg), 8.0.28 (opt)

      Attachments

        Activity

          People

            serg Sergei Golubchik
            Roel Roel Van de Paar
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.