Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-32396

Segmentation fault at /mariadb-11.3.0/sql/sql_select.cc:27583

    XMLWordPrintable

Details

    Description

      Run these queries in release build:

      CREATE TABLE t0 ( CONSTRAINT cc0 UNIQUE i0 ( c24 ) , c24 INT ) ;
      INSERT INTO t0 VALUES ( -87 ) , ( -61 ) ;
      CREATE UNIQUE INDEX i1 ON t0 ( c24 ) ;
      INSERT INTO t0 VALUES ( -128 ) , ( 86 ) ;
      SELECT COUNT( DISTINCT c25 , c25 < -102 AND c25 < -84 AND c24 < 49 AND c24 < -29 OR c24 = ( IF ( c24 , t0 . c24 = SUBSTRING( t1 . c25 , 'lDO<]uhHvA-bB%S^x?A"w\'5YWeZP#t6%#;!Iy9^?[x#)j' , '?j2[uT(.SDz' ) IS NOT TRUE , -42 ) ) IS UNKNOWN ) OVER ( ORDER BY t0 . c24 , ( t1 . c25 + ( SELECT c24 AS c62 FROM t0 WHERE t1 . c25 >= -39.140759 = RAND ( ) / TRIM( t0 . c24 FROM 'LNc@@u*lKO' ) = 73 GROUP BY c24 , c25 HAVING c24 = 62 LIMIT 1 ) ) ) << RAND ( ) & TRIM( TRAILING FROM t1 . c25 ) = ANY ( SELECT c25 AS c22 FROM t0 HAVING c24 = + EXISTS ( SELECT -18 AS c44 ) ) AS c22 FROM ( SELECT c24 AS c25 FROM t0 ) AS t1 JOIN t0 ON t0 . c24 = t1 . c25 GROUP BY c25 , c24 ;

      Will trigger Segmentation fault.
      GDB info:
      Thread 16 "mariadbd" received signal SIGSEGV, Segmentation fault.
      [Switching to Thread 0x7fffd242e300 (LWP 2721)]
      0x0000000000ca7a01 in setup_order (thd=thd@entry=0x62b00016c218, ref_pointer_array=..., tables=tables@entry=0x6290000c5cd0, fields=..., all_fields=...,
      order=0x6290000942c0, from_window_spec=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:27583
      27583 Item * const item= *order->item;

      #0 0x0000000000ca7a01 in setup_order (thd=thd@entry=0x62b00016c218, ref_pointer_array=..., tables=tables@entry=0x6290000cada0, fields=..., all_fields=..., order=0x629000094310, from_window_spec=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:27583
      #1 0x000000000111e6f1 in setup_windows (thd=<optimized out>, ref_pointer_array=..., tables=<optimized out>, fields=..., all_fields=..., win_specs=..., win_funcs=...) at /home/wx/mariadb-11.3.0/sql/sql_window.cc:241
      #2 0x0000000000bf3a8a in setup_without_group (thd=<optimized out>, ref_pointer_array=..., tables=0x6290000cada0, leaves=..., fields=..., all_fields=..., conds=0x6290000ceb30, order=0x0, group=0x6290000cdb08, win_specs=..., win_funcs=..., hidden_group_fields=<optimized out>, reserved=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:955
      #3 JOIN::prepare (this=0x6290000ce6a0, tables_init=<optimized out>, conds_init=<optimized out>, og_num=<optimized out>, order_init=<optimized out>, skip_order_by=<optimized out>, group_init=<optimized out>, having_init=<optimized out>, proc_param_init=<optimized out>, select_lex_arg=<optimized out>, unit_arg=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:1531
      #4 0x0000000000be4c97 in mysql_select (thd=<optimized out>, thd@entry=0x62b00016c218, tables=0x7fffd1c13400, fields=..., conds=0xd1c13403, og_num=0, order=0x166c380 <sql_print_error(char const*, ...)>, group=0x6290000cdb08, having=0x0, proc_param=0x0, select_options=<optimized out>, result=0x6290000ce670, unit=0x62b0001704a8, select_lex=0x6290000917d0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:5224
      #5 0x0000000000be4596 in handle_select (thd=thd@entry=0x62b00016c218, lex=<optimized out>, lex@entry=0x62b0001703c8, result=<optimized out>, result@entry=0x6290000ce670, setup_tables_done_option=<optimized out>, setup_tables_done_option@entry=0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:628
      #6 0x0000000000b3df18 in execute_sqlcom_select (thd=0x62b00016c218, all_tables=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:6013
      #7 0x0000000000b2cd51 in mysql_execute_command (thd=0x62b00016c218, is_called_from_prepared_stmt=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:3912
      #8 0x0000000000b1fe79 in mysql_parse (thd=thd@entry=0x62b00016c218, rawbuf=<optimized out>, length=<optimized out>, parser_state=<optimized out>, parser_state@entry=0x7fffd1c15a80) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:7734
      #9 0x0000000000b19069 in dispatch_command (command=<optimized out>, thd=0x62b00016c218, packet=<optimized out>, packet_length=<optimized out>, blocking=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1893
      #10 0x0000000000b20b71 in do_command (thd=0x62b00016c218, blocking=true) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1406
      #11 0x0000000000f03476 in do_handle_one_connection (connect=<optimized out>, put_in_cache=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1445
      #12 0x0000000000f02eb9 in handle_one_connection (arg=arg@entry=0x60800151d7b8) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1347
      #13 0x0000000001a00c1b in pfs_spawn_thread (arg=0x617000006618) at /home/wx/mariadb-11.3.0/storage/perfschema/pfs.cc:2201
      #14 0x00007ffff79f7609 in start_thread () from /lib/x86_64-linux-gnu/libpthread.so.0
      #15 0x00007ffff770f133 in clone () from /lib/x86_64-linux-gnu/libc.so.6

      Attachments

        Issue Links

          Activity

            People

              sanja Oleksandr Byelkin
              Xin Wen Xin Wen
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.