Type:
Bug
Priority:
Minor
Resolution:
Duplicate
Affects Version/s:
None
The library used by the ed25519 authentication plugin exhibits undefined behavior as reported by UBSAN.
This is edited example output from UBSAN that shows that negative values are used in left shift operations.
ref10/fe_sq.c:121:76: runtime error: left shift of negative value -46510040
#0 0x7f17794c866d in ref10_fe_sq ref10/fe_sq.c:121
#1 0x7f17794a4700 in ref10_ge_frombytes_negate_vartime ref10/ge_frombytes.c:21
#2 0x7f17794a18c2 in crypto_sign_open ref10/open.c:24
Analyzing the code in the MariaDB server, it is seen that it also uses signed integers with both left and right shift operations. The latter is not as big of a problem (I assume) than the former as right shift of negative integers is only implementation defined whereas a left shift is undefined behavior.
I believe marko can confirm that he has also seen this when running with UBSAN.
{"report":{"fcp":604.7999999523163,"ttfb":134.89999985694885,"pageVisibility":"visible","entityId":123771,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"53480e9a-0808-455e-aada-7e4e15149f7f","navigationType":0,"readyForUser":716.7999999523163,"redirectCount":0,"resourceLoadedEnd":588.0999999046326,"resourceLoadedStart":140.29999995231628,"resourceTiming":[{"duration":6.200000047683716,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":140.29999995231628,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":140.29999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":146.5,"responseStart":0,"secureConnectionStart":0},{"duration":6.099999904632568,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":140.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":140.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":146.69999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":59.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":140.69999980926514,"connectEnd":140.69999980926514,"connectStart":140.69999980926514,"domainLookupEnd":140.69999980926514,"domainLookupStart":140.69999980926514,"fetchStart":140.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":140.69999980926514,"responseEnd":200.19999980926514,"responseStart":200.19999980926514,"secureConnectionStart":140.69999980926514},{"duration":134.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":140.79999995231628,"connectEnd":140.79999995231628,"connectStart":140.79999995231628,"domainLookupEnd":140.79999995231628,"domainLookupStart":140.79999995231628,"fetchStart":140.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":140.79999995231628,"responseEnd":274.89999985694885,"responseStart":274.89999985694885,"secureConnectionStart":140.79999995231628},{"duration":137.70000004768372,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":140.89999985694885,"connectEnd":140.89999985694885,"connectStart":140.89999985694885,"domainLookupEnd":140.89999985694885,"domainLookupStart":140.89999985694885,"fetchStart":140.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":140.89999985694885,"responseEnd":278.59999990463257,"responseStart":278.59999990463257,"secureConnectionStart":140.89999985694885},{"duration":138.29999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":141,"connectEnd":141,"connectStart":141,"domainLookupEnd":141,"domainLookupStart":141,"fetchStart":141,"redirectEnd":0,"redirectStart":0,"requestStart":141,"responseEnd":279.2999999523163,"responseStart":279.2999999523163,"secureConnectionStart":141},{"duration":139.40000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":141.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":141.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":280.5,"responseStart":0,"secureConnectionStart":0},{"duration":138.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":141.09999990463257,"connectEnd":141.09999990463257,"connectStart":141.09999990463257,"domainLookupEnd":141.09999990463257,"domainLookupStart":141.09999990463257,"fetchStart":141.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":141.09999990463257,"responseEnd":279.89999985694885,"responseStart":279.89999985694885,"secureConnectionStart":141.09999990463257},{"duration":139.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":141.19999980926514,"connectEnd":141.19999980926514,"connectStart":141.19999980926514,"domainLookupEnd":141.19999980926514,"domainLookupStart":141.19999980926514,"fetchStart":141.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":141.19999980926514,"responseEnd":280.59999990463257,"responseStart":280.59999990463257,"secureConnectionStart":141.19999980926514},{"duration":139.79999995231628,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":141.39999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":141.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":281.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":139.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":141.5,"connectEnd":141.5,"connectStart":141.5,"domainLookupEnd":141.5,"domainLookupStart":141.5,"fetchStart":141.5,"redirectEnd":0,"redirectStart":0,"requestStart":141.5,"responseEnd":281.2999999523163,"responseStart":281.2999999523163,"secureConnectionStart":141.5},{"duration":443.2000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":142.39999985694885,"connectEnd":142.39999985694885,"connectStart":142.39999985694885,"domainLookupEnd":142.39999985694885,"domainLookupStart":142.39999985694885,"fetchStart":142.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":142.39999985694885,"responseEnd":585.5999999046326,"responseStart":585.5999999046326,"secureConnectionStart":142.39999985694885},{"duration":445.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":142.39999985694885,"connectEnd":142.39999985694885,"connectStart":142.39999985694885,"domainLookupEnd":142.39999985694885,"domainLookupStart":142.39999985694885,"fetchStart":142.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":142.39999985694885,"responseEnd":588.0999999046326,"responseStart":588.0999999046326,"secureConnectionStart":142.39999985694885},{"duration":167.09999990463257,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":414.2999999523163,"connectEnd":414.2999999523163,"connectStart":414.2999999523163,"domainLookupEnd":414.2999999523163,"domainLookupStart":414.2999999523163,"fetchStart":414.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":414.2999999523163,"responseEnd":581.3999998569489,"responseStart":581.3999998569489,"secureConnectionStart":414.2999999523163},{"duration":8.799999952316284,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":583.2999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":583.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":592.0999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":114.09999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":658.5999999046326,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":658.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":772.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":113.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":659.3999998569489,"connectEnd":659.3999998569489,"connectStart":659.3999998569489,"domainLookupEnd":659.3999998569489,"domainLookupStart":659.3999998569489,"fetchStart":659.3999998569489,"redirectEnd":0,"redirectStart":0,"requestStart":659.3999998569489,"responseEnd":773.1999998092651,"responseStart":773.0999999046326,"secureConnectionStart":659.3999998569489},{"duration":125.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/f51ef5507eea4c158f257c66c93b2a3f-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":659.8999998569489,"connectEnd":659.8999998569489,"connectStart":659.8999998569489,"domainLookupEnd":659.8999998569489,"domainLookupStart":659.8999998569489,"fetchStart":659.8999998569489,"redirectEnd":0,"redirectStart":0,"requestStart":659.8999998569489,"responseEnd":785.3999998569489,"responseStart":785.2999999523163,"secureConnectionStart":659.8999998569489}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":17,"responseStart":135,"responseEnd":137,"domLoading":138,"domInteractive":765,"domContentLoadedEventStart":765,"domContentLoadedEventEnd":797,"domComplete":1421,"loadEventStart":1421,"loadEventEnd":1422,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":748.5},{"name":"bigPipe.sidebar-id.end","time":749.2999999523163},{"name":"bigPipe.activity-panel-pipe-id.start","time":749.3999998569489},{"name":"bigPipe.activity-panel-pipe-id.end","time":751.6999998092651},{"name":"activityTabFullyLoaded","time":807.1999998092651}],"measures":[],"correlationId":"a32d00e13fece1","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":68,"dbReadsTimeInMs":13,"dbConnsTimeInMs":19,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}