Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-8089

Server crashed or ASAN heap-use-after-free in Apc_target::make_apc_call on SHOW EXPLAIN

    XMLWordPrintable

Details

    • Bug
    • Status: Confirmed (View Workflow)
    • Major
    • Resolution: Unresolved
    • 10.0(EOL), 10.1(EOL), 10.2(EOL)
    • 10.11, 12.2
    • Server
    • None

    Description

      /home/elenst/git/10.1/sql/mysqld(my_print_stacktrace+0x38)[0x7f0eacda7b22]
      sql/signal_handler.cc:155(handle_fatal_signal)[0x7f0eac764040]
      /lib/x86_64-linux-gnu/libpthread.so.0(+0xfcb0)[0x7f0eaa9a4cb0]
      /lib/x86_64-linux-gnu/libc.so.6(_IO_vfprintf+0x29f1)[0x7f0eaa0213b1]
      /lib/x86_64-linux-gnu/libc.so.6(+0x4e1a4)[0x7f0eaa0241a4]
      /lib/x86_64-linux-gnu/libc.so.6(_IO_vfprintf+0x21e)[0x7f0eaa01ebde]
      /lib/x86_64-linux-gnu/libc.so.6(_IO_fprintf+0x87)[0x7f0eaa029837]
      /home/elenst/git/10.1/sql/mysqld(safe_cond_timedwait+0x242)[0x7f0eacdad51b]
      psi/mysql_thread.h:1202(inline_mysql_cond_timedwait)[0x7f0eac6c8f57]
      sql/my_apc.cc:194(Apc_target::make_apc_call(THD*, Apc_target::Apc_call*, int, bool*))[0x7f0eac6c94b5]
      sql/sql_show.cc:2656(fill_show_explain(THD*, TABLE_LIST*, Item*))[0x7f0eac5c3c68]
      sql/sql_show.cc:7939(get_schema_tables_result(JOIN*, enum_schema_table_state))[0x7f0eac5d78d5]
      sql/sql_select.cc:2546(JOIN::exec_inner())[0x7f0eac57a5e3]
      sql/sql_select.cc:2398(JOIN::exec())[0x7f0eac579c71]
      sql/sql_select.cc:3328(mysql_select(THD*, Item***, TABLE_LIST*, unsigned int, List<Item>&, Item*, unsigned int, st_order*, st_order*, Item*, st_order*, unsigned long long, select_result*, st_select_lex_unit*, st_select_lex*))[0x7f0eac57d262]
      sql/sql_select.cc:373(handle_select(THD*, LEX*, select_result*, unsigned long))[0x7f0eac573203]
      sql/sql_parse.cc:5782(execute_sqlcom_select(THD*, TABLE_LIST*))[0x7f0eac544475]
      sql/sql_parse.cc:2926(mysql_execute_command(THD*))[0x7f0eac53a9d2]
      sql/sql_prepare.cc:4012(Prepared_statement::execute(String*, bool))[0x7f0eac561619]
      sql/sql_prepare.cc:3644(Prepared_statement::execute_loop(String*, bool, unsigned char*, unsigned char*))[0x7f0eac5604ba]
      sql/sql_prepare.cc:2778(mysql_sql_stmt_execute(THD*))[0x7f0eac55e519]
      sql/sql_parse.cc:2938(mysql_execute_command(THD*))[0x7f0eac53aa03]
      sql/sql_parse.cc:7165(mysql_parse(THD*, char*, unsigned int, Parser_state*))[0x7f0eac547a0b]
      sql/sql_parse.cc:1464(dispatch_command(enum_server_command, THD*, char*, unsigned int))[0x7f0eac536cbc]
      sql/sql_parse.cc:1090(do_command(THD*))[0x7f0eac535a97]
      sql/sql_connect.cc:1347(do_handle_one_connection(THD*))[0x7f0eac66600d]
      sql/sql_connect.cc:1259(handle_one_connection)[0x7f0eac665d65]
      /lib/x86_64-linux-gnu/libpthread.so.0(+0x7e9a)[0x7f0eaa99ce9a]
      /lib/x86_64-linux-gnu/libc.so.6(clone+0x6d)[0x7f0eaa0c9cbd]

      Trying to get some variables.
      Some pointers may be invalid and cause the dump to abort.
      Query (0x7f0e8242a188): SHOW EXPLAIN FOR 69
      Connection ID (thread ID): 14
      Status: NOT_KILLED

      Happened once so far, on 10.1 tree around commit 46816996 (possibly a few commits earlier).
      RQG revno 1016

      perl /home/elenst/bzr/randgen-mariadb-patches/runall-new.pl --no-mask --seed=1430256717 --threads=16 --duration=400 --queries=100M --reporters=QueryTimeout,Backtrace,ErrorLog,Deadlock --redefine=conf/mariadb/general-workarounds.yy --redefine=conf/mariadb/10.0-features-redefine.yy --mysqld=--log_output=FILE --mysqld=--slow_query_log --mysqld=--log_bin_trust_function_creators=1 --mysqld=--query_cache_size=64M --views --grammar=conf/runtime/connect_kill_sql.yy --gendata=conf/runtime/connect_kill_data.zz --engine=InnoDB --rpl_mode=mixed --mysqld=--slave-skip-errors=1049,1305,1539,1505,1317 --mysqld=--slave-parallel-mode=conservative --mysqld=--binlog_commit_wait_count=10 --mysqld=--binlog_commit_wait_usec=1000000 --mysqld=--slave-parallel-threads=1 --use-gtid=slave_pos --mtr-build-thread=73 --basedir1=/home/elenst/git/10.1 --vardir1=/home/elenst/test_results/10.1-parallel-replication-8/current1_1

      Attachments

        1. mysql.err
          30 kB
          Elena Stepanova
        2. mysql.log
          641 kB
          Elena Stepanova

        Issue Links

          Activity

            People

              psergei Sergei Petrunia
              elenst Elena Stepanova
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.