=================================================================
|
==25904==ERROR: AddressSanitizer: heap-use-after-free on address 0x6060000c5b48 at pc 0x000001e8518d bp 0x7f6a28e941c0 sp 0x7f6a28e941b0
|
READ of size 1 at 0x6060000c5b48 thread T34
|
#0 0x1e8518c in InList /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1545
|
#1 0x1e85e80 in _db_keyword_ /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1764
|
#2 0x1e83a80 in _db_pargs_ /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1264
|
#3 0x1e28b60 in my_write /home/buildbot/buildbot/build/mariadb-10.2.30/mysys/my_write.c:29
|
#4 0x1dcd97c in inline_mysql_file_write /home/buildbot/buildbot/build/mariadb-10.2.30/include/mysql/psi/mysql_file.h:1131
|
#5 0x1dd5bb7 in _my_b_cache_write /home/buildbot/buildbot/build/mariadb-10.2.30/mysys/mf_iocache.c:1749
|
#6 0x1dd6daa in my_b_flush_io_cache /home/buildbot/buildbot/build/mariadb-10.2.30/mysys/mf_iocache.c:1949
|
#7 0xb1df00 in flush_master_info(Master_info*, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/rpl_mi.cc:813
|
#8 0x67cd25 in handle_slave_io /home/buildbot/buildbot/build/mariadb-10.2.30/sql/slave.cc:4580
|
#9 0x130b4c1 in pfs_spawn_thread /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1862
|
#10 0x7f6a40a396b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9)
|
#11 0x7f6a3fece82c in clone (/lib/x86_64-linux-gnu/libc.so.6+0x10682c)
|
|
0x6060000c5b48 is located 8 bytes inside of 55-byte region [0x6060000c5b40,0x6060000c5b77)
|
freed by thread T33 here:
|
#0 0x7f6a422172ca in __interceptor_free (/usr/lib/x86_64-linux-gnu/libasan.so.2+0x982ca)
|
#1 0x1e86101 in FreeList /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1830
|
#2 0x1e85480 in FreeState /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1620
|
#3 0x1e7d204 in DbugParse /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:489
|
#4 0x1e7f9a0 in _db_set_init_ /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:898
|
#5 0xb8cdae in Sys_var_dbug::global_update(THD*, set_var*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sys_vars.ic:923
|
#6 0x65a2f5 in sys_var::update(THD*, set_var*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:208
|
#7 0x65e725 in set_var::update(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:837
|
#8 0x65dca2 in sql_set_variables(THD*, List<set_var_base>*, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:738
|
#9 0x810f38 in mysql_execute_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:4591
|
#10 0x824cfa in mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:7740
|
#11 0x801361 in dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1831
|
#12 0x7fe457 in do_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1385
|
#13 0xb37622 in do_handle_one_connection(CONNECT*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1336
|
#14 0xb37006 in handle_one_connection /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1241
|
#15 0x130b4c1 in pfs_spawn_thread /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1862
|
#16 0x7f6a40a396b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9)
|
|
previously allocated by thread T33 here:
|
#0 0x7f6a42217602 in malloc (/usr/lib/x86_64-linux-gnu/libasan.so.2+0x98602)
|
#1 0x1e872cf in DbugMalloc /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:2065
|
#2 0x1e84dea in ListAddDel /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1461
|
#3 0x1e7de96 in DbugParse /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:563
|
#4 0x1e7f9a0 in _db_set_init_ /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:898
|
#5 0xb8cdae in Sys_var_dbug::global_update(THD*, set_var*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sys_vars.ic:923
|
#6 0x65a2f5 in sys_var::update(THD*, set_var*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:208
|
#7 0x65e725 in set_var::update(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:837
|
#8 0x65dca2 in sql_set_variables(THD*, List<set_var_base>*, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/set_var.cc:738
|
#9 0x810f38 in mysql_execute_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:4591
|
#10 0x824cfa in mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:7740
|
#11 0x801361 in dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1831
|
#12 0x7fe457 in do_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1385
|
#13 0xb37622 in do_handle_one_connection(CONNECT*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1336
|
#14 0xb37006 in handle_one_connection /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1241
|
#15 0x130b4c1 in pfs_spawn_thread /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1862
|
#16 0x7f6a40a396b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9)
|
|
Thread T34 created by T33 here:
|
#0 0x7f6a421b5253 in pthread_create (/usr/lib/x86_64-linux-gnu/libasan.so.2+0x36253)
|
#1 0x130b8ae in spawn_thread_v1 /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1912
|
#2 0x66467a in inline_mysql_thread_create /home/buildbot/buildbot/build/mariadb-10.2.30/include/mysql/psi/mysql_thread.h:1239
|
#3 0x669467 in start_slave_thread(unsigned int, void* (*)(void*), st_mysql_mutex*, st_mysql_mutex*, st_mysql_cond*, unsigned int volatile*, unsigned long volatile*, Master_info*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/slave.cc:934
|
#4 0x669da6 in start_slave_threads(THD*, bool, bool, Master_info*, char const*, char const*, int) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/slave.cc:1056
|
#5 0x88d374 in start_slave(THD*, Master_info*, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_repl.cc:3146
|
#6 0x80bf5b in mysql_execute_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:3846
|
#7 0x824cfa in mysql_parse(THD*, char*, unsigned int, Parser_state*, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:7740
|
#8 0x801361 in dispatch_command(enum_server_command, THD*, char*, unsigned int, bool, bool) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1831
|
#9 0x7fe457 in do_command(THD*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_parse.cc:1385
|
#10 0xb37622 in do_handle_one_connection(CONNECT*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1336
|
#11 0xb37006 in handle_one_connection /home/buildbot/buildbot/build/mariadb-10.2.30/sql/sql_connect.cc:1241
|
#12 0x130b4c1 in pfs_spawn_thread /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1862
|
#13 0x7f6a40a396b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9)
|
|
Thread T33 created by T0 here:
|
#0 0x7f6a421b5253 in pthread_create (/usr/lib/x86_64-linux-gnu/libasan.so.2+0x36253)
|
#1 0x130b8ae in spawn_thread_v1 /home/buildbot/buildbot/build/mariadb-10.2.30/storage/perfschema/pfs.cc:1912
|
#2 0x6016d6 in inline_mysql_thread_create /home/buildbot/buildbot/build/mariadb-10.2.30/include/mysql/psi/mysql_thread.h:1239
|
#3 0x616455 in create_thread_to_handle_connection(CONNECT*) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/mysqld.cc:6506
|
#4 0x616b79 in create_new_thread /home/buildbot/buildbot/build/mariadb-10.2.30/sql/mysqld.cc:6576
|
#5 0x617bd9 in handle_connections_sockets() /home/buildbot/buildbot/build/mariadb-10.2.30/sql/mysqld.cc:6851
|
#6 0x615933 in mysqld_main(int, char**) /home/buildbot/buildbot/build/mariadb-10.2.30/sql/mysqld.cc:6125
|
#7 0x5ffa15 in main /home/buildbot/buildbot/build/mariadb-10.2.30/sql/main.cc:25
|
#8 0x7f6a3fde882f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
|
|
SUMMARY: AddressSanitizer: heap-use-after-free /home/buildbot/buildbot/build/mariadb-10.2.30/dbug/dbug.c:1545 InList
|
Shadow bytes around the buggy address:
|
0x0c0c80010b10: fa fa fa fa fd fd fd fd fd fd fd fa fa fa fa fa
|
0x0c0c80010b20: fd fd fd fd fd fd fd fa fa fa fa fa fd fd fd fd
|
0x0c0c80010b30: fd fd fd fa fa fa fa fa fd fd fd fd fd fd fd fd
|
0x0c0c80010b40: fa fa fa fa fd fd fd fd fd fd fd fd fa fa fa fa
|
0x0c0c80010b50: fd fd fd fd fd fd fd fd fa fa fa fa 00 00 00 00
|
=>0x0c0c80010b60: 00 00 00 00 fa fa fa fa fd[fd]fd fd fd fd fd fa
|
0x0c0c80010b70: fa fa fa fa fd fd fd fd fd fd fd fd fa fa fa fa
|
0x0c0c80010b80: fd fd fd fd fd fd fd fd fa fa fa fa fd fd fd fd
|
0x0c0c80010b90: fd fd fd fd fa fa fa fa fd fd fd fd fd fd fd fd
|
0x0c0c80010ba0: fa fa fa fa 00 00 00 00 00 00 00 00 fa fa fa fa
|
0x0c0c80010bb0: fd fd fd fd fd fd fd fd fa fa fa fa fd fd fd fd
|
Shadow byte legend (one shadow byte represents 8 application bytes):
|
Addressable: 00
|
Partially addressable: 01 02 03 04 05 06 07
|
Heap left redzone: fa
|
Heap right redzone: fb
|
Freed heap region: fd
|
Stack left redzone: f1
|
Stack mid redzone: f2
|
Stack right redzone: f3
|
Stack partial redzone: f4
|
Stack after return: f5
|
Stack use after scope: f8
|
Global redzone: f9
|
Global init order: f6
|
Poisoned by user: f7
|
Container overflow: fc
|
Array cookie: ac
|
Intra object redzone: bb
|
ASan internal: fe
|
|