Details
-
Bug
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Duplicate
-
11.3.0
-
None
-
Ubuntu 20.04
Description
Run these queries in release build:
CREATE TABLE t0 ( c29 INT ) ;
INSERT INTO t0 VALUES ( DEFAULT ) , ( DEFAULT ) ;
CREATE INDEX i0 ON t0 ( c29 ) ;
INSERT INTO t0 VALUES ( DEFAULT ) , ( DEFAULT ) ;
SELECT t0 . c29 AS c54 FROM ( SELECT c41 AS c45 FROM ( SELECT c1 AS c41 FROM ( SELECT t3 . c18 AS c1 FROM ( SELECT c7 AS c18 FROM ( SELECT ROW_NUMBER ( ) OVER ( ) AS c7 FROM t0 ) AS t1 , ( SELECT ROW_NUMBER ( ) OVER ( ) AS c61 FROM t0 ) AS t2 JOIN t0 ON t2 . c61 = ALL ( SELECT c61 AS c8 GROUP BY c61 , c29 HAVING ROUND ( REVERSE ( 10 ) ) - c61 ) ) AS t3 JOIN t0 ON RTRIM ( c29 ) / EXP ( c29 ) = t0 . c29 ) AS t4 JOIN t0 ON REPLACE ( -52 , '#euB]{.!~8s' , '"&1?zqs4{b7QpyzNi_Jc@G' ) IS FALSE XOR ROUND ( 58 , 33 ) ) AS t5 ) AS t6 JOIN ( SELECT c29 AS c34 FROM t0 ) AS t7 JOIN t0 ON t0 . c29 <= t7 . c34 ON NULLIF ( 19 , 119 ) IS NOT NULL ;
Will trigger Segmentation fault.
GDB info:
Thread 16 "mariadbd" received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0x7fffd242e300 (LWP 3209)]
0x0000000000c3c172 in setup_copy_fields (thd=<optimized out>, param=<optimized out>, ref_pointer_array=..., res_selected_fields=..., res_all_fields=...,
elements=<optimized out>, all_fields=...) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:28302
28302 if (item->field->flags & BLOB_FLAG)
(gdb) p item->field
$35 = (Field *) 0x0
#0 0x0000000000c3c172 in setup_copy_fields (thd=<optimized out>, param=<optimized out>, ref_pointer_array=..., res_selected_fields=..., res_all_fields=..., elements=<optimized out>, all_fields=...) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:28302
#1 0x0000000000c2e2f2 in JOIN::make_aggr_tables_info (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:4023
#2 0x0000000000bfc660 in JOIN::optimize_stage2 (this=0x62d0000d52e8) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:3438
#3 0x0000000000c13911 in JOIN::optimize_inner (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:2650
#4 0x0000000000bfc156 in JOIN::optimize (this=0x62d0000d52e8) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:1944
#5 0x0000000000ab5421 in st_select_lex::optimize_unflattened_subqueries (this=<optimized out>, const_only=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_lex.cc:4916
#6 0x0000000000c0856c in JOIN::optimize_stage2 (this=0x62d0000d2d90) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:3229
#7 0x0000000000c13911 in JOIN::optimize_inner (this=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:2650
#8 0x0000000000bfc156 in JOIN::optimize (this=this@entry=0x62d0000d2d90) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:1944
#9 0x0000000000be4fdf in mysql_select (thd=<optimized out>, thd@entry=0x62b00016c218, tables=<optimized out>, fields=..., conds=<optimized out>, og_num=<optimized out>, order=<optimized out>, group=0x0, having=0x0, proc_param=0x0, select_options=<optimized out>, result=0x62d0000d2d60, unit=0x62b0001704a8, select_lex=0x6290000917a0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:5235
#10 0x0000000000be4596 in handle_select (thd=thd@entry=0x62b00016c218, lex=<optimized out>, lex@entry=0x62b0001703c8, result=<optimized out>, result@entry=0x62d0000d2d60, setup_tables_done_option=<optimized out>, setup_tables_done_option@entry=0) at /home/wx/mariadb-11.3.0/sql/sql_select.cc:628
#11 0x0000000000b3df18 in execute_sqlcom_select (thd=0x62b00016c218, all_tables=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:6013
#12 0x0000000000b2cd51 in mysql_execute_command (thd=0x62b00016c218, is_called_from_prepared_stmt=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:3912
#13 0x0000000000b1fe79 in mysql_parse (thd=thd@entry=0x62b00016c218, rawbuf=<optimized out>, length=<optimized out>, parser_state=<optimized out>, parser_state@entry=0x7fffd242ca80) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:7734
#14 0x0000000000b19069 in dispatch_command (command=<optimized out>, thd=0x62b00016c218, packet=<optimized out>, packet_length=<optimized out>, blocking=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1893
#15 0x0000000000b20b71 in do_command (thd=0x62b00016c218, blocking=true) at /home/wx/mariadb-11.3.0/sql/sql_parse.cc:1406
#16 0x0000000000f03476 in do_handle_one_connection (connect=<optimized out>, put_in_cache=<optimized out>) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1445
#17 0x0000000000f02eb9 in handle_one_connection (arg=arg@entry=0x608001adec38) at /home/wx/mariadb-11.3.0/sql/sql_connect.cc:1347
#18 0x0000000001a00c1b in pfs_spawn_thread (arg=0x617000005118) at /home/wx/mariadb-11.3.0/storage/perfschema/pfs.cc:2201
#19 0x00007ffff79f7609 in start_thread () from /lib/x86_64-linux-gnu/libpthread.so.0
#20 0x00007ffff770f133 in clone () from /lib/x86_64-linux-gnu/libc.so.6