Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-32310

Prepare phase: Server crashes at Field_iterator_table::set

    XMLWordPrintable

Details

    • Bug
    • Status: Confirmed (View Workflow)
    • Critical
    • Resolution: Unresolved
    • 11.1.2, 11.2.1, 10.4(EOL), 10.5, 10.6, 10.9(EOL), 10.10(EOL), 10.11, 11.0(EOL), 11.1(EOL)
    • 10.5, 10.6, 10.11, 11.2
    • None
    • Ubuntu 20.04 x86-64, docker image mariadb:11.1.2

    Description

      PoC:

      SELECT ( WITH RECURSIVE x AS ( SELECT 1 UNION SELECT x FROM ( WITH x AS ( WITH x AS ( SELECT * FROM x ) SELECT 1 ) SELECT * FROM x ) x ) SELECT x FROM x ) ;
      

      docker log:

      mariadbd(my_print_stacktrace+0x32)[0x559394b457c2]
      mariadbd(handle_fatal_signal+0x488)[0x55939461ecf8]
      /lib/x86_64-linux-gnu/libc.so.6(+0x42520)[0x7fad7de9a520]
      mariadbd(_ZN20Field_iterator_table3setEP10TABLE_LIST+0xb)[0x5593944b1f2b]
      mariadbd(_Z13insert_fieldsP3THDP23Name_resolution_contextPKcS4_P13List_iteratorI4ItemEbPjb+0x264)[0x55939433efe4]
      mariadbd(_Z10setup_wildP3THDP10TABLE_LISTR4ListI4ItemEPS5_P13st_select_lexb+0x1f4)[0x55939433f734]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0x359)[0x559394417b49]
      mariadbd(_ZN18st_select_lex_unit12prepare_joinEP3THDP13st_select_lexP13select_resultyb+0x414)[0x55939447ec14]
      mariadbd(_ZN18st_select_lex_unit7prepareEP10TABLE_LISTP13select_resulty+0x79b)[0x559394481a2b]
      mariadbd(+0x7ed21f)[0x55939436621f]
      mariadbd(_Z27mysql_handle_single_derivedP3LEXP10TABLE_LISTj+0xda)[0x559394364e7a]
      mariadbd(_ZN13st_select_lex14handle_derivedEP3LEXj+0x47)[0x559394383697]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0x20f)[0x5593944179ff]
      mariadbd(_ZN18st_select_lex_unit12prepare_joinEP3THDP13st_select_lexP13select_resultyb+0x414)[0x55939447ec14]
      mariadbd(_ZN18st_select_lex_unit7prepareEP10TABLE_LISTP13select_resulty+0x10c7)[0x559394482357]
      mariadbd(+0x7ed21f)[0x55939436621f]
      mariadbd(_Z27mysql_handle_single_derivedP3LEXP10TABLE_LISTj+0xda)[0x559394364e7a]
      mariadbd(_ZN13st_select_lex14handle_derivedEP3LEXj+0x47)[0x559394383697]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0x20f)[0x5593944179ff]
      mariadbd(_ZN18st_select_lex_unit12prepare_joinEP3THDP13st_select_lexP13select_resultyb+0x414)[0x55939447ec14]
      mariadbd(_ZN18st_select_lex_unit7prepareEP10TABLE_LISTP13select_resulty+0x79b)[0x559394481a2b]
      mariadbd(_ZN12With_element20prepare_unreferencedEP3THD+0x88)[0x559394589598]
      mariadbd(_ZN11With_clause29prepare_unreferenced_elementsEP3THD+0x5c)[0x55939458963c]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0xd56)[0x559394418546]
      mariadbd(_ZN18st_select_lex_unit12prepare_joinEP3THDP13st_select_lexP13select_resultyb+0x414)[0x55939447ec14]
      mariadbd(_ZN18st_select_lex_unit7prepareEP10TABLE_LISTP13select_resulty+0x79b)[0x559394481a2b]
      mariadbd(+0x7ed21f)[0x55939436621f]
      mariadbd(_Z27mysql_handle_single_derivedP3LEXP10TABLE_LISTj+0xda)[0x559394364e7a]
      mariadbd(_ZN13st_select_lex14handle_derivedEP3LEXj+0x47)[0x559394383697]
      mariadbd(_ZN10TABLE_LIST14handle_derivedEP3LEXj+0x56)[0x5593944ae776]
      mariadbd(_ZN13st_select_lex14handle_derivedEP3LEXj+0x47)[0x559394383697]
      mariadbd(_ZN10TABLE_LIST14handle_derivedEP3LEXj+0x56)[0x5593944ae776]
      mariadbd(_ZN13st_select_lex14handle_derivedEP3LEXj+0x47)[0x559394383697]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0x20f)[0x5593944179ff]
      mariadbd(+0xb8b908)[0x559394704908]
      mariadbd(_ZN14Item_subselect10fix_fieldsEP3THDPP4Item+0x1ad)[0x559394703fcd]
      mariadbd(_Z12setup_fieldsP3THD20Bounds_checked_arrayIP4ItemER4ListIS2_E17enum_column_usagePS6_S9_b+0x147)[0x55939433e0a7]
      mariadbd(_ZN4JOIN7prepareEP10TABLE_LISTP4ItemjP8st_orderbS5_S3_S5_P13st_select_lexP18st_select_lex_unit+0x52d)[0x559394417d1d]
      mariadbd(_Z12mysql_selectP3THDP10TABLE_LISTR4ListI4ItemEPS4_jP8st_orderS9_S7_S9_yP13select_resultP18st_select_lex_unitP13st_select_lex+0x624)[0x55939442c474]
      mariadbd(_Z13handle_selectP3THDP3LEXP13select_resulty+0x154)[0x55939442c774]
      mariadbd(+0x826f55)[0x55939439ff55]
      mariadbd(_Z21mysql_execute_commandP3THDb+0x419e)[0x5593943aef0e]
      mariadbd(_Z11mysql_parseP3THDPcjP12Parser_state+0x1e7)[0x5593943b0237]
      mariadbd(_Z16dispatch_command19enum_server_commandP3THDPcjb+0x14bd)[0x5593943b2a1d]
      mariadbd(_Z10do_commandP3THDb+0x138)[0x5593943b4818]
      mariadbd(_Z24do_handle_one_connectionP7CONNECTb+0x3bf)[0x5593944dc3af]
      mariadbd(handle_one_connection+0x5d)[0x5593944dc6fd]
      mariadbd(+0xcd1906)[0x55939484a906]
      /lib/x86_64-linux-gnu/libc.so.6(+0x94b43)[0x7fad7deecb43]
      /lib/x86_64-linux-gnu/libc.so.6(clone+0x44)[0x7fad7df7dbb4]
       
      Trying to get some variables.
      Some pointers may be invalid and cause the dump to abort.
      Query (0x7fad100130d8): SELECT ( WITH RECURSIVE x AS ( SELECT 1 UNION SELECT x FROM ( WITH x AS ( WITH x AS ( SELECT * FROM x ) SELECT 1 ) SELECT * FROM x ) x ) SELECT x FROM x )
       
      Connection ID (thread ID): 4
      Status: NOT_KILLED
       
      Optimizer switch: index_merge=on,index_merge_union=on,index_merge_sort_union=on,index_merge_intersection=on,index_merge_sort_intersection=off,engine_condition_pushdown=off,index_condition_pushdown=on,derived_merge=on,derived_with_keys=on,firstmatch=on,loosescan=on,materialization=on,in_to_exists=on,semijoin=on,partial_match_rowid_merge=on,partial_match_table_scan=on,subquery_cache=on,mrr=off,mrr_cost_based=off,mrr_sort_keys=off,outer_join_with_cache=on,semijoin_with_cache=on,join_cache_incremental=on,join_cache_hashed=on,join_cache_bka=on,optimize_join_buffer_size=on,table_elimination=on,extended_keys=on,exists_to_in=on,orderby_uses_equalities=on,condition_pushdown_for_derived=on,split_materialized=on,condition_pushdown_for_subquery=on,rowid_filter=on,condition_pushdown_from_having=on,not_null_range_scan=off,hash_join_cardinality=on
      

      Attachments

        Issue Links

          Activity

            People

              sanja Oleksandr Byelkin
              fuboat Jingzhou Fu
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.