Type:
Bug
Priority:
Major
Resolution:
Unresolved
Affects Version/s:
10.5 , 10.6 , 10.11 , 11.4 , 11.8
When the server audit plugin logs the COM_CHANGE_USER and subsequent queries, it sometimes logs the queries under the old user, and/or sometimes instead of the database value it writes a corrupt value.
The effect seems to be deterministic for a given build and a set of steps, for example the test case below behaves the same way on all builds that I have on my machine; but it is just empirical, the exact logic when the problem occurs and when it stops happening are so far unclear to me. Maybe there is underlying non-deterministic behavior, or something remains not initialized (although none of ASAN/UBSAN/MSAN complain about anything).
INSTALL SONAME 'server_audit' ;
SET GLOBAL server_audit_logging= ON ;
--let $datadir= `select @@datadir`
create user foo;
--change_user foo
SELECT CURRENT_USER () AS should_be_foo;
--exec tail -n 2 $datadir/server_audit.log
--change_user root
--let $restart_parameters= --general_log=OFF --server-audit-logging=ON
--source include/restart_mysqld.inc
--change_user foo
SELECT CURRENT_USER () AS should_be_foo_again;
--exec tail -n 2 $datadir/server_audit.log
--change_user root
drop user foo;
UNINSTALL SONAME 'server_audit' ;
11.8 cc831f16c82f00d3531e09c2f5c59eadc0abb0d7
SELECT CURRENT_USER () AS should_be_foo;
should_be_foo
foo@%
20250326 12:49:16,mesh,,,4,0,CHANGEUSER,,,0
20250326 12:49:16,mesh,root,,4,27,QUERY,, 'SELECT CURRENT_USER() AS should_be_foo' ,0
# restart: --general_log=OFF --server-audit-logging=ON
SELECT CURRENT_USER () AS should_be_foo_again;
should_be_foo_again
foo@%
20250326 12:49:18,mesh,,,3,0,CHANGEUSER,OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO,,0
20250326 12:49:18,mesh,foo,localhost,3,8,QUERY,, 'SELECT CURRENT_USER() AS should_be_foo_again' ,0
So, in the first case after CHANGE_USER the query (SELECT CURRENT_USER() ) is still logged under the user "root", even though the user has been changed and the query correctly returns "foo".
Then we restart the server with the general log disabled (I have no idea why it is relevant, but apparently it is), and try the same CHANGE_USER again. Now the query after the change is correctly logged under "foo", but the CHANGEUSER record itself looks corrupt.
As said above, I'm getting the same result on all my builds of 10.5..main – release, debug, asan etc. alike.
blocks
MDEV-36395
SET SESSION AUTHORIZATION is written in server audit log under the new user
Open
There are no comments yet on this issue.
{"report":{"fcp":1949.6999998092651,"ttfb":360,"pageVisibility":"visible","entityId":133505,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"5c4bb6cf-0898-468c-8436-7a49df581f32","navigationType":0,"readyForUser":2046.5,"redirectCount":0,"resourceLoadedEnd":1597.6999998092651,"resourceLoadedStart":369.09999990463257,"resourceTiming":[{"duration":139.7999997138977,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":369.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":369.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":508.8999996185303,"responseStart":0,"secureConnectionStart":0},{"duration":139.80000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":369.3999996185303,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":369.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":509.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":939.7999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":369.59999990463257,"connectEnd":369.59999990463257,"connectStart":369.59999990463257,"domainLookupEnd":369.59999990463257,"domainLookupStart":369.59999990463257,"fetchStart":369.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":511.7999997138977,"responseEnd":1309.3999996185303,"responseStart":555.5999999046326,"secureConnectionStart":369.59999990463257},{"duration":1220.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":370.3999996185303,"connectEnd":370.3999996185303,"connectStart":370.3999996185303,"domainLookupEnd":370.3999996185303,"domainLookupStart":370.3999996185303,"fetchStart":370.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":511.8999996185303,"responseEnd":1590.8999996185303,"responseStart":554.0999999046326,"secureConnectionStart":370.3999996185303},{"duration":191.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":370.59999990463257,"connectEnd":370.59999990463257,"connectStart":370.59999990463257,"domainLookupEnd":370.59999990463257,"domainLookupStart":370.59999990463257,"fetchStart":370.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":512.5999999046326,"responseEnd":561.6999998092651,"responseStart":555.1999998092651,"secureConnectionStart":370.59999990463257},{"duration":190.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":370.7999997138977,"connectEnd":370.7999997138977,"connectStart":370.7999997138977,"domainLookupEnd":370.7999997138977,"domainLookupStart":370.7999997138977,"fetchStart":370.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":512.6999998092651,"responseEnd":561.5,"responseStart":554.6999998092651,"secureConnectionStart":370.7999997138977},{"duration":188.89999961853027,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":371,"connectEnd":371,"connectStart":371,"domainLookupEnd":371,"domainLookupStart":371,"fetchStart":371,"redirectEnd":0,"redirectStart":0,"requestStart":512.7999997138977,"responseEnd":559.8999996185303,"responseStart":553.5,"secureConnectionStart":371},{"duration":139.69999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":371.09999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":371.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":510.7999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":190.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":371.2999997138977,"connectEnd":371.2999997138977,"connectStart":371.2999997138977,"domainLookupEnd":371.2999997138977,"domainLookupStart":371.2999997138977,"fetchStart":371.2999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":525.7999997138977,"responseEnd":562.1999998092651,"responseStart":556.6999998092651,"secureConnectionStart":371.2999997138977},{"duration":140.30000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":371.3999996185303,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":371.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":511.69999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":214.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":371.59999990463257,"connectEnd":371.59999990463257,"connectStart":371.59999990463257,"domainLookupEnd":371.59999990463257,"domainLookupStart":371.59999990463257,"fetchStart":371.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":526.5,"responseEnd":585.6999998092651,"responseStart":557.1999998092651,"secureConnectionStart":371.59999990463257},{"duration":1223.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":373.3999996185303,"connectEnd":373.3999996185303,"connectStart":373.3999996185303,"domainLookupEnd":373.3999996185303,"domainLookupStart":373.3999996185303,"fetchStart":373.3999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":972.7999997138977,"responseEnd":1597.2999997138977,"responseStart":1592.5,"secureConnectionStart":373.3999996185303},{"duration":1224.1999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":373.5,"connectEnd":373.5,"connectStart":373.5,"domainLookupEnd":373.5,"domainLookupStart":373.5,"fetchStart":373.5,"redirectEnd":0,"redirectStart":0,"requestStart":1263.0999999046326,"responseEnd":1597.6999998092651,"responseStart":1594.0999999046326,"secureConnectionStart":373.5},{"duration":307.30000019073486,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1451.6999998092651,"connectEnd":1451.6999998092651,"connectStart":1451.6999998092651,"domainLookupEnd":1451.6999998092651,"domainLookupStart":1451.6999998092651,"fetchStart":1451.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":1721.8999996185303,"responseEnd":1759,"responseStart":1757.6999998092651,"secureConnectionStart":1451.6999998092651}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":169,"responseStart":360,"responseEnd":371,"domLoading":364,"domInteractive":2112,"domContentLoadedEventStart":2112,"domContentLoadedEventEnd":2157,"domComplete":2799,"loadEventStart":2799,"loadEventEnd":2800,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":2095.8999996185303},{"name":"bigPipe.sidebar-id.end","time":2096.699999809265},{"name":"bigPipe.activity-panel-pipe-id.start","time":2096.8999996185303},{"name":"bigPipe.activity-panel-pipe-id.end","time":2097.3999996185303},{"name":"activityTabFullyLoaded","time":2161.7999997138977}],"measures":[],"correlationId":"e2e626add283c1","effectiveType":"4g","downlink":9.2,"rtt":0,"serverDuration":118,"dbReadsTimeInMs":18,"dbConnsTimeInMs":30,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}