Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-37952

Mroonga: UBSAN invalid-null-argument and SIGSEGV in __strcmp_evex from mrn_default_tokenizer_update on SET

    XMLWordPrintable

Details

    • Can result in hang or crash

    Description

      INSTALL SONAME 'ha_mroonga';
      SET GLOBAL mroonga_default_tokenizer=NULL;
      

      Leads to:

      CS 12.2.0 8d08350dd3cac91df23a7dfbde23c276d7c7cd2b (Debug, Clang 21.1.3-20250923) Build 16/10/2025

      Core was generated by `/test/MD161025-mariadb-12.2.0-linux-x86_64-dbg/bin/mariadbd --no-defaults --max'.
      Program terminated with signal SIGSEGV, Segmentation fault.
      Download failed: Invalid argument.  Continuing without source file ./string/../sysdeps/x86_64/multiarch/strcmp-evex.S.
      #0  __strcmp_evex () at ../sysdeps/x86_64/multiarch/strcmp-evex.S:318
       
      [Current thread is 1 (LWP 246614)]
      (gdb) bt
      #0  __strcmp_evex () at ../sysdeps/x86_64/multiarch/strcmp-evex.S:318
      #1  0x00007d7a289764d9 in mrn_default_tokenizer_update (thd=0x7d7944000d58, var=0x7d7a28e1a530 <mysql_sysvar_default_tokenizer>, var_ptr=0x7d7a28fe41f8 <mrn_default_tokenizer>, save=0x7d794401a050)at /test/12.2_dbg/storage/mroonga/ha_mroonga.cpp:938
      #2  0x00005eedc2e21941 in sys_var_pluginvar::global_update (this=0x7d7944038810, thd=0x7d7944000d58, var=0x7d794401a030)at /test/12.2_dbg/sql/sql_plugin.cc:3702
      #3  0x00005eedc2bfcc43 in sys_var::update (this=0x7d7944038810, thd=0x7d7944000d58, var=0x7d794401a030)at /test/12.2_dbg/sql/set_var.cc:211
      #4  0x00005eedc2bfec50 in set_var::update (this=0x7d794401a030, thd=0x7d7944000d58) at /test/12.2_dbg/sql/set_var.cc:869
      #5  0x00005eedc2bfe83e in sql_set_variables (thd=0x7d7944000d58, var_list=0x7d7944006160, free=true) at /test/12.2_dbg/sql/set_var.cc:750
      #6  0x00005eedc2def4e4 in mysql_execute_command (thd=0x7d7944000d58, is_called_from_prepared_stmt=false) at /test/12.2_dbg/sql/sql_parse.cc:4857
      #7  0x00005eedc2de4818 in mysql_parse (thd=0x7d7944000d58, rawbuf=0x7d7944019ea0 "SET GLOBAL mroonga_default_tokenizer=NULL", length=41, parser_state=0x7d7a64fb2a00)at /test/12.2_dbg/sql/sql_parse.cc:7886
      #8  0x00005eedc2de1ff9 in dispatch_command (command=COM_QUERY, thd=0x7d7944000d58, packet=0x7d794400b219 "SET GLOBAL mroonga_default_tokenizer=NULL", packet_length=41, blocking=true) at /test/12.2_dbg/sql/sql_parse.cc:1878
      #9  0x00005eedc2de529a in do_command (thd=0x7d7944000d58, blocking=true)at /test/12.2_dbg/sql/sql_parse.cc:1417
      #10 0x00005eedc2fd7f2e in do_handle_one_connection (connect=0x5eedc54fb9a8, put_in_cache=true) at /test/12.2_dbg/sql/sql_connect.cc:1503
      #11 0x00005eedc2fd7d11 in handle_one_connection (arg=0x5eedc54575b8)at /test/12.2_dbg/sql/sql_connect.cc:1415
      #12 0x00007d7a7269ca94 in start_thread (arg=<optimized out>)at ./nptl/pthread_create.c:447
      #13 0x00007d7a72729c3c in clone3 ()at ../sysdeps/unix/sysv/linux/x86_64/clone3.S:78
      

      Bug Detection Matrix

          Rel    o/d  Build   Commit                                    UniqueID observed             
      CS  10.6   dbg  161025  8258b2fd56e6c7fad64d3877ca01049778f1a541  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  10.6   opt  161025  8258b2fd56e6c7fad64d3877ca01049778f1a541  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  10.11  dbg  161025  1ac22707205c433a42e60e7340299e9bbf988157  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  10.11  opt  161025  1ac22707205c433a42e60e7340299e9bbf988157  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  11.4   dbg  161025  b2c1ba820b6cda723c58f2ba01ccf2e379b7f313  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  11.4   opt  161025  b2c1ba820b6cda723c58f2ba01ccf2e379b7f313  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  11.8   dbg  161025  29d8f65470394f740fa548e4a4a822273d7362e8  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  11.8   opt  161025  29d8f65470394f740fa548e4a4a822273d7362e8  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  12.1   dbg  161025  d29fb34b8390accaa7700c3a87911180f3fa3dff  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  12.1   opt  161025  d29fb34b8390accaa7700c3a87911180f3fa3dff  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  12.2   dbg  161025  8d08350dd3cac91df23a7dfbde23c276d7c7cd2b  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      CS  12.2   opt  161025  8d08350dd3cac91df23a7dfbde23c276d7c7cd2b  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update    
      ES  10.6   dbg  161025  7fb6f2133cd2a150fb551bb517a3bb6588d79ad6  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      ES  10.6   opt  161025  7fb6f2133cd2a150fb551bb517a3bb6588d79ad6  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      ES  11.4   dbg  161025  bfe2cfd839dacf10f700bb320c09527945d1d6e2  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      ES  11.4   opt  161025  bfe2cfd839dacf10f700bb320c09527945d1d6e2  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      ES  11.8   dbg  161025  08dc6f5144533a3c8747c5d67d363258b4e2ed20  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update
      ES  11.8   opt  161025  08dc6f5144533a3c8747c5d67d363258b4e2ed20  SIGSEGV|__strcmp_evex|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update             
      

      CS 12.2.0 8d08350dd3cac91df23a7dfbde23c276d7c7cd2b (Debug, UBASAN, Clang 21.1.3-20250923) Build 16/10/2025

      /test/12.2_dbg_san/storage/mroonga/ha_mroonga.cpp:938:30: runtime error: null pointer passed as argument 2, which is declared to never be null
      /usr/include/string.h:157:33: note: nonnull attribute specified here
          #0 0x78ea5448c9e9 in mrn_default_tokenizer_update(THD*, st_mysql_sys_var*, void*, void const*) /test/12.2_dbg_san/storage/mroonga/ha_mroonga.cpp:938:7
          #1 0x6369868d7ddd in sys_var_pluginvar::global_update(THD*, set_var*) /test/12.2_dbg_san/sql/sql_plugin.cc:3702:3
          #2 0x636986116d27 in sys_var::update(THD*, set_var*) /test/12.2_dbg_san/sql/set_var.cc:211:12
          #3 0x63698611cc01 in set_var::update(THD*) /test/12.2_dbg_san/sql/set_var.cc:869:23
          #4 0x63698611b7d3 in sql_set_variables(THD*, List<set_var_base>*, bool) /test/12.2_dbg_san/sql/set_var.cc:750:20
          #5 0x6369867ffd43 in mysql_execute_command(THD*, bool) /test/12.2_dbg_san/sql/sql_parse.cc:4857:9
          #6 0x6369867df1a8 in mysql_parse(THD*, char*, unsigned int, Parser_state*) /test/12.2_dbg_san/sql/sql_parse.cc:7886:18
          #7 0x6369867d8963 in dispatch_command(enum_server_command, THD*, char*, unsigned int, bool) /test/12.2_dbg_san/sql/sql_parse.cc:1878:7
          #8 0x6369867e15da in do_command(THD*, bool) /test/12.2_dbg_san/sql/sql_parse.cc:1417:17
          #9 0x636986feb9ec in do_handle_one_connection(CONNECT*, bool) /test/12.2_dbg_san/sql/sql_connect.cc:1503:11
          #10 0x636986feb4f5 in handle_one_connection /test/12.2_dbg_san/sql/sql_connect.cc:1415:5
          #11 0x636985748e2a in asan_thread_start(void*) crtstuff.c
          #12 0x7ceb4709ca93 in start_thread nptl/pthread_create.c:447:8
          #13 0x7ceb47129c3b in clone3 misc/../sysdeps/unix/sysv/linux/x86_64/clone3.S:78
       
      SUMMARY: UndefinedBehaviorSanitizer: invalid-null-argument /test/12.2_dbg_san/storage/mroonga/ha_mroonga.cpp:938:30 
      

      An on UB+ASAN builds to an UBSAN invalid-null-argument:

      SAN Bug Detection Matrix

          Rel    o/d  Build   Commit                                    UniqueID observed             
      CS  10.6   dbg  161025  8258b2fd56e6c7fad64d3877ca01049778f1a541  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  10.6   opt  161025  8258b2fd56e6c7fad64d3877ca01049778f1a541  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  10.11  dbg  161025  1ac22707205c433a42e60e7340299e9bbf988157  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  10.11  opt  161025  1ac22707205c433a42e60e7340299e9bbf988157  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  11.4   dbg  161025  b2c1ba820b6cda723c58f2ba01ccf2e379b7f313  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  11.4   opt  161025  b2c1ba820b6cda723c58f2ba01ccf2e379b7f313  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  11.8   dbg  161025  29d8f65470394f740fa548e4a4a822273d7362e8  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  11.8   opt  161025  29d8f65470394f740fa548e4a4a822273d7362e8  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  12.1   dbg  161025  d29fb34b8390accaa7700c3a87911180f3fa3dff  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  12.1   opt  161025  d29fb34b8390accaa7700c3a87911180f3fa3dff  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  12.2   dbg  161025  8d08350dd3cac91df23a7dfbde23c276d7c7cd2b  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      CS  12.2   opt  161025  8d08350dd3cac91df23a7dfbde23c276d7c7cd2b  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  10.6   dbg  161025  7fb6f2133cd2a150fb551bb517a3bb6588d79ad6  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  10.6   opt  161025  7fb6f2133cd2a150fb551bb517a3bb6588d79ad6  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  11.4   dbg  161025  bfe2cfd839dacf10f700bb320c09527945d1d6e2  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  11.4   opt  161025  bfe2cfd839dacf10f700bb320c09527945d1d6e2  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  11.8   dbg  161025  08dc6f5144533a3c8747c5d67d363258b4e2ed20  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      ES  11.8   opt  161025  08dc6f5144533a3c8747c5d67d363258b4e2ed20  UBSAN|null pointer passed as argument 2, which is declared to never be null|storage/mroonga/ha_mroonga.cpp|mrn_default_tokenizer_update|sys_var_pluginvar::global_update|sys_var::update|set_var::update
      

      Setup:

      Compiled with a recent version of Clang and LLVM. Ubuntu instructions for Clang/LLVM 18:
        # Note: It is strongly recommended to uninstall all old Clang & LLVM packages (ref  dpkg --list | grep -iE 'clang|llvm'  and use  apt purge  and  dpkg --purge  to remove the packages), before installing Clang/LLVM 18
           sudo apt install clang llvm-18 llvm-18-linker-tools llvm-18-runtime llvm-18-tools llvm-18-dev libstdc++-14-dev llvm-dev lld-18
      Compiled with: "-DCMAKE_C_COMPILER=/usr/bin/clang -DCMAKE_CXX_COMPILER=/usr/bin/clang++ -DCMAKE_C{,XX}_FLAGS='-march=native -mtune=native'" and:
          -DWITH_ASAN=ON -DWITH_ASAN_SCOPE=ON -DWITH_UBSAN=ON -DWSREP_LIB_WITH_ASAN=ON
      Set before execution:
          export UBSAN_OPTIONS=print_stacktrace=1:report_error_type=1   # And you may also want to supress UBSAN startup issues using 'suppressions=UBSAN.filter' in UBSAN_OPTIONS. For an example of UBSAN.filter, which includes current startup issues see: https://github.com/mariadb-corporation/mariadb-qa/blob/master/UBSAN.filter
      

      Testcase is MTR and CLI compatible.

      Attachments

        Activity

          People

            sanja Oleksandr Byelkin
            Roel Roel Van de Paar
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: