Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-41029

AddressSanitizer: use-after-poison - "install soname ha_rocksdb"

    XMLWordPrintable

Details

    • Related to install and upgrade

    Description

      opt_ignore_db_dirs is "PREALLOCATED READ_ONLY"

      MariaDB [(none)]> install soname 'ha_rocksdb';
      ERROR 2013 (HY000): Lost connection to server during query
      

      Version: '10.11.19-MariaDB-asan-debug'  socket: '/tmp/build-mariadb-server-10.11-debug.sock'  port: 0  Source distribution
      =================================================================
      ==739749==ERROR: AddressSanitizer: use-after-poison on address 0x7f9a0f3ed2b8 at pc 0x0000041e0ef0 bp 0x7399e9610a10 sp 0x7399e9610a08
      READ of size 8 at 0x7f9a0f3ed2b8 thread T13
          #0 0x0000041e0eef in my_free /home/dan/repos/mariadb-server-10.11/mysys/my_malloc.c:203:17
          #1 0x00000107e232 in ignore_db_dirs_append(char const*) /home/dan/repos/mariadb-server-10.11/sql/sql_show.cc:782:5
          #2 0x7399e2abe4ce in myrocks::rocksdb_init_func(void*) /home/dan/repos/mariadb-server-10.11/storage/rocksdb/ha_rocksdb.cc:5304:3
          #3 0x000001d69405 in ha_initialize_handlerton(void*) /home/dan/repos/mariadb-server-10.11/sql/handler.cc:654:37
          #4 0x000000d880d5 in plugin_do_initialize(st_plugin_int*, unsigned int&) /home/dan/repos/mariadb-server-10.11/sql/sql_plugin.cc:1457:18
          #5 0x000000d86b6e in plugin_initialize(st_mem_root*, st_plugin_int*, int*, char**, bool) /home/dan/repos/mariadb-server-10.11/sql/sql_plugin.cc:1511:10
          #6 0x000000d930c4 in finalize_install(THD*, TABLE*, st_mysql_const_lex_string const*, int*, char**) /home/dan/repos/mariadb-server-10.11/sql/sql_plugin.cc:2260:9
          #7 0x000000d8fb97 in mysql_install_plugin(THD*, st_mysql_const_lex_string const*, st_mysql_const_lex_string const*) /home/dan/repos/mariadb-server-10.11/sql/sql_plugin.cc:2367:11
          #8 0x000000cc329e in mysql_execute_command(THD*, bool) /home/dan/repos/mariadb-server-10.11/sql/sql_parse.cc:6088:17
          #9 0x000000c7f233 in mysql_parse(THD*, char*, unsigned int, Parser_state*) /home/dan/repos/mariadb-server-10.11/sql/sql_parse.cc:8210:18
          #10 0x000000c72e9c in dispatch_command(enum_server_command, THD*, char*, unsigned int, bool) /home/dan/repos/mariadb-server-10.11/sql/sql_parse.cc:1924:7
          #11 0x000000c83876 in do_command(THD*, bool) /home/dan/repos/mariadb-server-10.11/sql/sql_parse.cc:1434:17
          #12 0x00000152d7f0 in do_handle_one_connection(CONNECT*, bool) /home/dan/repos/mariadb-server-10.11/sql/sql_connect.cc:1486:11
          #13 0x00000152d0de in handle_one_connection /home/dan/repos/mariadb-server-10.11/sql/sql_connect.cc:1398:5
          #14 0x000002b69901 in pfs_spawn_thread /home/dan/repos/mariadb-server-10.11/storage/perfschema/pfs.cc:2201:3
          #15 0x000000567aea in asan_thread_start(void*) asan_interceptors.cpp.o
          #16 0x7f9a0e879c18 in start_thread (/lib64/libc.so.6+0x72c18) (BuildId: 5bd941be836f538fe5e10eff508f7f5dd94905a6)
          #17 0x7f9a0e8fd5cb in __GI___clone3 (/lib64/libc.so.6+0xf65cb) (BuildId: 5bd941be836f538fe5e10eff508f7f5dd94905a6)
       
      Address 0x7f9a0f3ed2b8 is a wild pointer inside of access range of size 0x000000000008.
      SUMMARY: AddressSanitizer: use-after-poison /home/dan/repos/mariadb-server-10.11/mysys/my_malloc.c:203:17 in my_free
      Shadow bytes around the buggy address:
        0x7f9a0f3ed000: 00 00 00 f7 00 00 00 00 00 00 00 00 00 00 00 00
        0x7f9a0f3ed080: 00 00 00 f7 00 00 00 00 00 00 00 00 00 00 00 00
        0x7f9a0f3ed100: 00 00 00 f7 00 00 00 00 00 01 f7 00 03 f7 00 01
        0x7f9a0f3ed180: f7 00 00 00 00 01 f7 01 f7 00 00 04 f7 07 f7 07
        0x7f9a0f3ed200: f7 00 01 f7 01 f7 00 00 00 00 00 03 f7 00 00 00
      =>0x7f9a0f3ed280: 02 f7 01 f7 05 f7 00[04]f7 01 f7 04 f7 00 00 02
        0x7f9a0f3ed300: f7 00 00 00 00 00 00 03 f7 05 f7 00 03 f7 06 f7
        0x7f9a0f3ed380: 04 f7 00 00 00 05 f7 05 f7 00 07 f7 01 f7 f7 f7
        0x7f9a0f3ed400: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7
        0x7f9a0f3ed480: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7
        0x7f9a0f3ed500: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7
      Shadow byte legend (one shadow byte represents 8 application bytes):
        Addressable:           00
        Partially addressable: 01 02 03 04 05 06 07 
        Heap left redzone:       fa
        Freed heap region:       fd
        Stack left redzone:      f1
        Stack mid redzone:       f2
        Stack right redzone:     f3
        Stack after return:      f5
        Stack use after scope:   f8
        Global redzone:          f9
        Global init order:       f6
        Poisoned by user:        f7
        Container overflow:      fc
        Array cookie:            ac
        Intra object redzone:    bb
        ASan internal:           fe
        Left alloca redzone:     ca
        Right alloca redzone:    cb
       
      NOTE: the stack trace above identifies the code that *accessed* the poisoned memory.
      To identify the code that *poisoned* the memory, try the experimental setting ASAN_OPTIONS=poison_history_size=<size>.
      Thread T13 created by T0 here:
          #0 0x00000054d8b5 in pthread_create (/home/dan/repos/build-mariadb-server-10.11-debug/sql/mariadbd+0x54d8b5) (BuildId: 86695fc6426c0ab3f3d32365d4562f00686593d9)
          #1 0x000002b6a3a0 in my_thread_create(unsigned long*, pthread_attr_t const*, void* (*)(void*), void*) /home/dan/repos/mariadb-server-10.11/storage/perfschema/my_thread.h:52:10
          #2 0x000002b6a2ed in pfs_spawn_thread_v1 /home/dan/repos/mariadb-server-10.11/storage/perfschema/pfs.cc:2252:15
          #3 0x0000005c7aca in inline_mysql_thread_create(unsigned int, unsigned long*, pthread_attr_t const*, void* (*)(void*), void*) /home/dan/repos/mariadb-server-10.11/include/mysql/psi/mysql_thread.h:1139:11
          #4 0x0000005c7610 in create_thread_to_handle_connection(CONNECT*) /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:6306:19
          #5 0x0000005c80cd in create_new_thread(CONNECT*) /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:6365:3
          #6 0x0000005c83fa in handle_accepted_socket(st_mysql_socket, st_mysql_socket) /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:6427:5
          #7 0x0000005c9758 in handle_connections_sockets() /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:6550:9
          #8 0x0000005c68f7 in run_main_loop() /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:5792:3
          #9 0x0000005bbb76 in mysqld_main(int, char**) /home/dan/repos/mariadb-server-10.11/sql/mysqld.cc:6202:3
          #10 0x0000005afb19 in main /home/dan/repos/mariadb-server-10.11/sql/main.cc:34:10
          #11 0x7f9a0e80a680 in __libc_start_call_main (/lib64/libc.so.6+0x3680) (BuildId: 5bd941be836f538fe5e10eff508f7f5dd94905a6)
          #12 0x7f9a0e80a797 in __libc_start_main@GLIBC_2.2.5 (/lib64/libc.so.6+0x3797) (BuildId: 5bd941be836f538fe5e10eff508f7f5dd94905a6)
          #13 0x0000004c4224 in _start (/home/dan/repos/build-mariadb-server-10.11-debug/sql/mariadbd+0x4c4224) (BuildId: 86695fc6426c0ab3f3d32365d4562f00686593d9)
      

      Attachments

        Issue Links

          Activity

            People

              serg Sergei Golubchik
              danblack Daniel Black
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.