Details
-
Bug
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Duplicate
-
11.3.0
-
None
-
Ubuntu 20.04
Description
Run these queries in release build:
CREATE TABLE t0 REPLACE AS SELECT REPEAT ( 68 , NOT CONVERT ( -124 , UNSIGNED ) BETWEEN 116 AND -85 = TRUE ) AS c34 ;
INSERT INTO t0 VALUES ( DEFAULT ) , ( DEFAULT ) ;
DELETE FROM t0 WHERE c34 = -63 ;
SELECT t0 . c34 AS c37 FROM t0 AS t1 JOIN t0 ON ( SELECT t0 . c34 AS c55 FROM ( SELECT SQRT ( CONVERT ( -31 , UNSIGNED ) % RAND ( ) - RAND ( 2 ) << + EXISTS ( SELECT 115 AS c18 ) IS NULL ) << c34 AS c6 FROM t0 ) AS t2 JOIN t0 ON t2 . c6 = t0 . c34 EXCEPT SELECT c34 + 70 AS c61 FROM t0 WHERE c34 < 4719043402954803319 GROUP BY c34 , c34 LIMIT 1 ) = t1 . c34 ;
Will trigger Segmentation fault.
GDB info:
Thread 16 "mariadbd" received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0x7fffd242e300 (LWP 2467)]
0x0000000000c38925 in AGGR_OP::put_record (this=0x0, end_of_records=false) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:32251
32251 if (!join_tab->table->file->inited)
#0 0x0000000000c38925 in AGGR_OP::put_record (this=0x0, end_of_records=false) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:32251
#1 AGGR_OP::put_record (this=0x0) at /home/wx/mariadb-11.3.0/sql/sql_select.h:1180
#2 sub_select_postjoin_aggr (join=0x6290000ba420, join_tab=0x62d0000d9100, end_of_records=false) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:23134
#3 0x0000000000c9e284 in evaluate_join_record (join=join@entry=0x6290000ba420, join_tab=<optimized out>, join_tab@entry=0x62d0000d8c88, error=error@entry=0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:23677
#4 0x0000000000be3396 in sub_select (join=0x6290000ba420, join_tab=0x62d0000d8c88, end_of_records=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:23444
#5 0x0000000000c45121 in do_select (join=0x6290000ba420, procedure=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:22961
#6 JOIN::exec_inner (this=0x6290000ba420) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:4941
#7 0x0000000000c428e9 in JOIN::exec (this=0x6290000ba420) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:4718
#8 0x0000000000df0df7 in st_select_lex_unit::exec_inner (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_union.cc:2389
#9 0x00000000015d8bb5 in subselect_union_engine::exec (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/item_subselect.cc:4187
#10 0x00000000015b3edc in Item_subselect::exec (this=0x6290000b5300) at /home/wx/mariadb-11.3.0/sql/item_subselect.cc:812
#11 0x00000000015b9a0c in Item_singlerow_subselect::val_str (this=0x6290000b5300, str=0x6290000b5818) at /home/wx/mariadb-11.3.0/sql/item_subselect.cc:1484
#12 0x00000000013aa621 in Arg_comparator::compare_string (this=0x6290000b56e8) at /home/wx/mariadb-11.3.0/sql/item_cmpfunc.cc:771
#13 0x00000000013b5ea2 in Arg_comparator::compare (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/item_cmpfunc.h:104
#14 Item_func_eq::val_int (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/item_cmpfunc.cc:1780
#15 0x0000000000c9dd1c in evaluate_join_record (join=join@entry=0x6290000b69e8, join_tab=0x62d0000d8c88, join_tab@entry=0x6290000bfd10, error=error@entry=0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:23545
#16 0x0000000000be340f in sub_select (join=0x6290000b69e8, join_tab=0x6290000bfd10, end_of_records=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:23481
#17 0x0000000000c45121 in do_select (join=0x6290000b69e8, procedure=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:22961
#18 JOIN::exec_inner (this=0x6290000b69e8) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:4941
#19 0x0000000000c428e9 in JOIN::exec (this=this@entry=0x6290000b69e8) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:4718
#20 0x0000000000be5128 in mysql_select (thd=<optimized out>, thd@entry=0x62b00016c218, tables=<optimized out>, fields=..., conds=<optimized out>, og_num=<optimized out>, order=<optimized out>, group=0x0, having=0x0, proc_param=0x0, select_options=<optimized out>, result=0x6290000b69b8, unit=0x62b0001704a8, select_lex=0x629000091570) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:5249
#21 0x0000000000be4596 in handle_select (thd=thd@entry=0x62b00016c218, lex=<optimized out>, lex@entry=0x62b0001703c8, result=<optimized out>, result@entry=0x6290000b69b8, setup_tables_done_option=<optimized out>, setup_tables_done_option@entry=0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:628
#22 0x0000000000b3df18 in execute_sqlcom_select (thd=0x62b00016c218, all_tables=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:6013
#23 0x0000000000b2cd51 in mysql_execute_command (thd=0x62b00016c218, is_called_from_prepared_stmt=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:3912
#24 0x0000000000b1fe79 in mysql_parse (thd=thd@entry=0x62b00016c218, rawbuf=<optimized out>, length=<optimized out>, parser_state=<optimized out>, parser_state@entry=0x7fffd242ca80) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:7734
#25 0x0000000000b19069 in dispatch_command (command=<optimized out>, thd=0x62b00016c218, packet=<optimized out>, packet_length=<optimized out>, blocking=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1893
#26 0x0000000000b20b71 in do_command (thd=0x62b00016c218, blocking=true) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1406
#27 0x0000000000f03476 in do_handle_one_connection (connect=<optimized out>, put_in_cache=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1445
#28 0x0000000000f02eb9 in handle_one_connection (arg=arg@entry=0x6080013732b8) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1347
#29 0x0000000001a00c1b in pfs_spawn_thread (arg=0x617000006618) at /home/wx/mariadb-11.3.0/storage/perfschema/pfs.cc:2201
#30 0x00007ffff79f7609 in start_thread () from /lib/x86_64-linux-gnu/libpthread.so.0
#31 0x00007ffff770f133 in clone () from /lib/x86_64-linux-gnu/libc.so.6