If there is the following variable definition, it may cause double free:
static MYSQL_SYSVAR_STR(variable_name,
|
variable,
|
PLUGIN_VAR_RQCMDARG | PLUGIN_VAR_MEMALLOC, // PLUGIN_VAR_MEMALLOC is important!
|
"description",
|
NULL,
|
NULL, // using the default update function is important!
|
NULL);
|
The points are PLUGIN_VAR_MEMALLOC and the default update function.
If this pattern is used, the following SQL causes double free:
SET GLOBAL variable = "value";
|
SET GLOBAL variable = NULL;
|
If a variable uses PLUGIN_VAR_MEMALLOC and the default update function, the following code is used in sql/sql_plugin.cc:
static void update_func_str(THD *thd, struct st_mysql_sys_var *var,
|
void *tgt, const void *save)
|
{
|
char *value= *(char**) save;
|
if (var->flags & PLUGIN_VAR_MEMALLOC)
|
{ // This clause is used!
|
char *old= *(char**) tgt;
|
if (value)
|
*(char**) tgt= my_strdup(value, MYF(0));
|
my_free(old);
|
}
|
else
|
*(char**) tgt= value;
|
}
|
if value is NULL, tgt still referes freed memory. It is freed in sql/sql_plugin.cc:plugin_vars_free_values(). It causes double free.
This pattern isn't used all of bundled storage engines. It is used in mroonga storage engine: https://github.com/mroonga/mroonga/blob/3156280442792c1446175044ba666428690b9c55/ha_mroonga.cpp#L699
(I'm a mroonga storage engine developer.)
I will attach a patch to fix the problem.
- is part of
-
MDEV-4907
merge 5.5 → 10.0-base → 10.0
-
-
Closed
{"report":{"fcp":1354.8999999761581,"ttfb":504.19999998807907,"pageVisibility":"visible","entityId":25616,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"3b3608d7-519b-4330-aee7-2b23bf527216","navigationType":0,"readyForUser":1475.699999988079,"redirectCount":0,"resourceLoadedEnd":1532.5999999642372,"resourceLoadedStart":514.0999999642372,"resourceTiming":[{"duration":282.60000002384186,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":514.0999999642372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":514.0999999642372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":796.6999999880791,"responseStart":0,"secureConnectionStart":0},{"duration":282.69999998807907,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":514.3999999761581,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":514.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":797.0999999642372,"responseStart":0,"secureConnectionStart":0},{"duration":353.10000002384186,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":514.5999999642372,"connectEnd":514.5999999642372,"connectStart":514.5999999642372,"domainLookupEnd":514.5999999642372,"domainLookupStart":514.5999999642372,"fetchStart":514.5999999642372,"redirectEnd":0,"redirectStart":0,"requestStart":514.5999999642372,"responseEnd":867.6999999880791,"responseStart":867.6999999880791,"secureConnectionStart":514.5999999642372},{"duration":457.30000001192093,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/2bf333562ca6724060a9d5f1535471f6/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":514.7999999523163,"connectEnd":514.7999999523163,"connectStart":514.7999999523163,"domainLookupEnd":514.7999999523163,"domainLookupStart":514.7999999523163,"fetchStart":514.7999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":514.7999999523163,"responseEnd":972.0999999642372,"responseStart":972.0999999642372,"secureConnectionStart":514.7999999523163},{"duration":354.89999997615814,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":515,"connectEnd":515,"connectStart":515,"domainLookupEnd":515,"domainLookupStart":515,"fetchStart":515,"redirectEnd":0,"redirectStart":0,"requestStart":515,"responseEnd":869.8999999761581,"responseStart":869.8999999761581,"secureConnectionStart":515},{"duration":461.30000001192093,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":515.1999999880791,"connectEnd":515.1999999880791,"connectStart":515.1999999880791,"domainLookupEnd":515.1999999880791,"domainLookupStart":515.1999999880791,"fetchStart":515.1999999880791,"redirectEnd":0,"redirectStart":0,"requestStart":515.1999999880791,"responseEnd":976.5,"responseStart":976.5,"secureConnectionStart":515.1999999880791},{"duration":461.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":515.2999999523163,"connectEnd":515.2999999523163,"connectStart":515.2999999523163,"domainLookupEnd":515.2999999523163,"domainLookupStart":515.2999999523163,"fetchStart":515.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":515.2999999523163,"responseEnd":977,"responseStart":977,"secureConnectionStart":515.2999999523163},{"duration":499.89999997615814,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":515.3999999761581,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":515.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1015.2999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":461.80000001192093,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":515.5999999642372,"connectEnd":515.5999999642372,"connectStart":515.5999999642372,"domainLookupEnd":515.5999999642372,"domainLookupStart":515.5999999642372,"fetchStart":515.5999999642372,"redirectEnd":0,"redirectStart":0,"requestStart":515.5999999642372,"responseEnd":977.3999999761581,"responseStart":977.3999999761581,"secureConnectionStart":515.5999999642372},{"duration":499.60000002384186,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":515.7999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":515.7999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1015.3999999761581,"responseStart":0,"secureConnectionStart":0},{"duration":462.10000002384186,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":515.8999999761581,"connectEnd":515.8999999761581,"connectStart":515.8999999761581,"domainLookupEnd":515.8999999761581,"domainLookupStart":515.8999999761581,"fetchStart":515.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":515.8999999761581,"responseEnd":978,"responseStart":978,"secureConnectionStart":515.8999999761581},{"duration":652.3000000119209,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":536.8999999761581,"connectEnd":536.8999999761581,"connectStart":536.8999999761581,"domainLookupEnd":536.8999999761581,"domainLookupStart":536.8999999761581,"fetchStart":536.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":536.8999999761581,"responseEnd":1189.199999988079,"responseStart":1189.199999988079,"secureConnectionStart":536.8999999761581},{"duration":859,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":536.8999999761581,"connectEnd":536.8999999761581,"connectStart":536.8999999761581,"domainLookupEnd":536.8999999761581,"domainLookupStart":536.8999999761581,"fetchStart":536.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":536.8999999761581,"responseEnd":1395.8999999761581,"responseStart":1395.8999999761581,"secureConnectionStart":536.8999999761581},{"duration":162.19999998807907,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1027.699999988079,"connectEnd":1027.699999988079,"connectStart":1027.699999988079,"domainLookupEnd":1027.699999988079,"domainLookupStart":1027.699999988079,"fetchStart":1027.699999988079,"redirectEnd":0,"redirectStart":0,"requestStart":1027.699999988079,"responseEnd":1189.8999999761581,"responseStart":1189.8999999761581,"secureConnectionStart":1027.699999988079},{"duration":116.39999997615814,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1290.8999999761581,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1290.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1407.2999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":240.69999998807907,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":1291.8999999761581,"connectEnd":1291.8999999761581,"connectStart":1291.8999999761581,"domainLookupEnd":1291.8999999761581,"domainLookupStart":1291.8999999761581,"fetchStart":1291.8999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":1291.8999999761581,"responseEnd":1532.5999999642372,"responseStart":1532.5999999642372,"secureConnectionStart":1291.8999999761581},{"duration":245.60000002384186,"initiatorType":"script","name":"https://jira.mariadb.org/s/097ae97cb8fbec7d6ea4bbb1f26955b9-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":1292.3999999761581,"connectEnd":1292.3999999761581,"connectStart":1292.3999999761581,"domainLookupEnd":1292.3999999761581,"domainLookupStart":1292.3999999761581,"fetchStart":1292.3999999761581,"redirectEnd":0,"redirectStart":0,"requestStart":1292.3999999761581,"responseEnd":1538,"responseStart":1537.8999999761581,"secureConnectionStart":1292.3999999761581}],"fetchStart":0,"domainLookupStart":315,"domainLookupEnd":319,"connectStart":319,"connectEnd":341,"secureConnectionStart":327,"requestStart":341,"responseStart":504,"responseEnd":523,"domLoading":509,"domInteractive":1535,"domContentLoadedEventStart":1535,"domContentLoadedEventEnd":1574,"domComplete":1840,"loadEventStart":1840,"loadEventEnd":1841,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1517.2999999523163},{"name":"bigPipe.sidebar-id.end","time":1518.0999999642372},{"name":"bigPipe.activity-panel-pipe-id.start","time":1518.2999999523163},{"name":"bigPipe.activity-panel-pipe-id.end","time":1519.2999999523163},{"name":"activityTabFullyLoaded","time":1594.0999999642372}],"measures":[],"correlationId":"6feed6d9583ad3","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":96,"dbReadsTimeInMs":11,"dbConnsTimeInMs":20,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}
Yes, thanks!
We've just did the same fix in 5.5, and soon I'll merge it into 10.0. This should be fixed in the 5.5.33 and in 10.0.5.