[MDEV-27676] Assertion `str.alloced_length() >= str.length() + data_len' failed in spider_string::q_append Created: 2022-01-29  Updated: 2022-10-25  Resolved: 2022-02-28

Status: Closed
Project: MariaDB Server
Component/s: Storage Engine - Spider
Affects Version/s: 10.8
Fix Version/s: N/A

Type: Bug Priority: Major
Reporter: Roel Van de Paar Assignee: Nayuta Yanagisawa (Inactive)
Resolution: Cannot Reproduce Votes: 0
Labels: regression

Issue Links:
Problem/Incident
is caused by MDEV-27106 Spider: specify connection to data no... Closed
Relates
relates to MDEV-29502 ASAN: heap-buffer-overflow & stack-bu... Closed
relates to MDEV-27184 Assertion `(old_top == initial_top (a... Closed

 Description   

Note MDEV-27184. This bug resurfaced during MDEV-27106 testing. It does not seem reproducible at first outside of the MDEV-27106 feature tree. It seems reproducible on debug only.

INSTALL PLUGIN spider SONAME 'ha_spider.so';
CREATE TABLE t (t_i INT,t_f FLOAT) ENGINE=Spider;
INSERT INTO t SELECT SEQ,SEQ FROM seq_1_to_100000;

Leads to:

10.8.0 1bfeac1aef7025d8e13d92ec85c2bacf1503b794 (Debug)

mysqld: /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_malloc.cc:1116: void spider_string::q_append(const char*, uint32): Assertion `str.alloced_length() >= str.length() + data_len' failed.

10.8.0 1bfeac1aef7025d8e13d92ec85c2bacf1503b794 (Debug)

Core was generated by `/test/MDEV-27106-MD220122-mariadb-10.8.0-linux-x86_64-dbg/bin/mysqld --no-defau'.
Program terminated with signal SIGABRT, Aborted.
#0  __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:50
[Current thread is 1 (Thread 0x148da40ef700 (LWP 550347))]
(gdb) bt
#0  __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:50
#1  0x0000148dacf52859 in __GI_abort () at abort.c:79
#2  0x0000148dacf52729 in __assert_fail_base (fmt=0x148dad0e8588 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n", assertion=0x148d901bc720 "str.alloced_length() >= str.length() + data_len", file=0x148d901bb548 "/test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_malloc.cc", line=1116, function=<optimized out>) at assert.c:92
#3  0x0000148dacf63f36 in __GI___assert_fail (assertion=assertion@entry=0x148d901bc720 "str.alloced_length() >= str.length() + data_len", file=file@entry=0x148d901bb548 "/test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_malloc.cc", line=line@entry=1116, function=function@entry=0x148d901bc750 "void spider_string::q_append(const char*, uint32)") at assert.c:101
#4  0x0000148d901307ad in spider_string::q_append (this=this@entry=0x148cd8088978, data=data@entry=0x148d901a88e0 ")", data_len=data_len@entry=1) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_string.h:431
#5  0x0000148d901679e0 in spider_db_mariadb_util::append_column_value (this=0x148d901faae0 <spider_db_mariadb_utility>, spider=<optimized out>, str=0x148cd8088978, field=<optimized out>, new_ptr=<optimized out>, access_charset=<optimized out>) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_db_mysql.cc:4307
#6  0x0000148d9018cbed in spider_mbase_handler::append_insert_values (this=this@entry=0x148cd8088790, str=str@entry=0x148cd8088978) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_db_mysql.cc:12863
#7  0x0000148d9018ce2e in spider_mbase_handler::append_insert_values_part (this=0x148cd8088790, sql_type=2) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_db_mysql.cc:12806
#8  0x0000148d90141999 in ha_spider::append_insert_values_sql_part (this=this@entry=0x148cd802df00, sql_type=sql_type@entry=2) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/ha_spider.cc:14328
#9  0x0000148d900cb153 in spider_db_bulk_insert (spider=spider@entry=0x148cd802df00, table=0x148cd802d628, copy_info=copy_info@entry=0x148cd802e2f0, bulk_end=bulk_end@entry=false) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/spd_db_conn.cc:6209
#10 0x0000148d90159228 in ha_spider::write_row (this=0x148cd802df00, buf=0x148cd802da78 "\371,") at /test/preview-10.8-MDEV-27106-spider_dbg/storage/spider/ha_spider.cc:9608
#11 0x000055d50b1fc679 in handler::ha_write_row (this=0x148cd802df00, buf=0x148cd802da78 "\371,") at /test/preview-10.8-MDEV-27106-spider_dbg/sql/handler.cc:7516
#12 0x000055d50ae9b06a in write_record (thd=0x148cd8000db8, table=0x148cd802d628, info=info@entry=0x148cd8016e88, sink=0x0) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_insert.cc:2156
#13 0x000055d50ae9b4c1 in select_insert::send_data (this=0x148cd8016e38, values=<optimized out>) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_insert.cc:4112
#14 0x000055d50af6320b in select_result_sink::send_data_with_check (sent=<optimized out>, u=<optimized out>, items=@0x148cd8014860: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x148cd8014b58, last = 0x148cd8014c88, elements = 2}, <No data fields>}, this=<optimized out>) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_class.h:5605
#15 end_send (join=0x148cd8016ef8, join_tab=0x148cd80d1628, end_of_records=<optimized out>) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:22307
#16 0x000055d50af32e45 in evaluate_join_record (join=join@entry=0x148cd8016ef8, join_tab=join_tab@entry=0x148cd80d1278, error=error@entry=0) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:21300
#17 0x000055d50af49024 in sub_select (join=0x148cd8016ef8, join_tab=0x148cd80d1278, end_of_records=<optimized out>) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:21109
#18 0x000055d50af80f9e in do_select (procedure=0x0, join=0x148cd8016ef8) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:20617
#19 JOIN::exec_inner (this=this@entry=0x148cd8016ef8) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:4735
#20 0x000055d50af8154a in JOIN::exec (this=this@entry=0x148cd8016ef8) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:4513
#21 0x000055d50af7f55b in mysql_select (thd=thd@entry=0x148cd8000db8, tables=0x148cd8014ce0, fields=@0x148cd8014860: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x148cd8014b58, last = 0x148cd8014c88, elements = 2}, <No data fields>}, conds=0x0, og_num=0, order=0x0, group=0x0, having=0x0, proc_param=0x0, select_options=2202244745984, result=0x148cd8016e38, unit=0x148cd80051c0, select_lex=0x148cd80145c0) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:4993
#22 0x000055d50af7f810 in handle_select (thd=thd@entry=0x148cd8000db8, lex=lex@entry=0x148cd80050e8, result=result@entry=0x148cd8016e38, setup_tables_done_option=setup_tables_done_option@entry=1073741824) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_select.cc:545
#23 0x000055d50aeedbd1 in mysql_execute_command (thd=thd@entry=0x148cd8000db8, is_called_from_prepared_stmt=is_called_from_prepared_stmt@entry=false) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_parse.cc:4709
#24 0x000055d50aed7e0f in mysql_parse (thd=thd@entry=0x148cd8000db8, rawbuf=<optimized out>, length=<optimized out>, parser_state=parser_state@entry=0x148da40ee400) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_parse.cc:8028
#25 0x000055d50aee6aab in dispatch_command (command=command@entry=COM_QUERY, thd=thd@entry=0x148cd8000db8, packet=packet@entry=0x148cd800b879 "INSERT INTO t SELECT SEQ,SEQ FROM seq_1_to_100000", packet_length=packet_length@entry=49, blocking=blocking@entry=true) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_class.h:1360
#26 0x000055d50aee9eea in do_command (thd=0x148cd8000db8, blocking=blocking@entry=true) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_parse.cc:1402
#27 0x000055d50b063974 in do_handle_one_connection (connect=<optimized out>, connect@entry=0x55d50d914f88, put_in_cache=put_in_cache@entry=true) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_connect.cc:1418
#28 0x000055d50b063f79 in handle_one_connection (arg=arg@entry=0x55d50d914f88) at /test/preview-10.8-MDEV-27106-spider_dbg/sql/sql_connect.cc:1312
#29 0x000055d50b4e5312 in pfs_spawn_thread (arg=0x55d50d828618) at /test/preview-10.8-MDEV-27106-spider_dbg/storage/perfschema/pfs.cc:2201
#30 0x0000148dad461609 in start_thread (arg=<optimized out>) at pthread_create.c:477
#31 0x0000148dad04f293 in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95



 Comments   
Comment by Nayuta Yanagisawa (Inactive) [ 2022-01-31 ]

At first glance, the bug seems not to be due to MDEV-27106 but due to wrong memory allocation. There seem to be some potential bugs of this kind. I expect that MDEV-27684 will fix all such bugs.

Comment by Nayuta Yanagisawa (Inactive) [ 2022-02-22 ]

Affect versions should be double checked.

Comment by Nayuta Yanagisawa (Inactive) [ 2022-02-28 ]

Roel I confirmed the bug on 1bfeac1aef7025d8e13d92ec85c2bacf1503b794. However, it was no longer reproducible on 10.8 HEAD (32d741b5b0087d6322cee0e8a7d34aa694e30d69). So, I closed the issue. Please reopen if you find the bug is reproducible on some development branch.

Comment by Nayuta Yanagisawa (Inactive) [ 2022-02-28 ]

MTR test case:

--echo #
--echo # MDEV-27676 Assertion `str.alloced_length() >= str.length() + data_len' failed in spider_string::q_append
--echo #
 
--source include/have_sequence.inc
 
--disable_query_log
--disable_result_log
--source ../../t/test_init.inc
--enable_result_log
--enable_query_log
 
--connection master_1
CREATE DATABASE auto_test_local;
USE auto_test_local;
 
CREATE TABLE tbl_a (a INT, b FLOAT) ENGINE=Spider;
--error ER_CONNECT_TO_FOREIGN_DATA_SOURCE
INSERT INTO tbl_a SELECT SEQ, SEQ FROM seq_1_to_100000;
 
DROP DATABASE auto_test_local;
 
--disable_query_log
--disable_result_log
--source ../../t/test_deinit.inc
--enable_result_log
--enable_query_log

Comment by Roel Van de Paar [ 2022-03-02 ]

Agreed no longer reproducible, on any version, on builds from 26 Feb 2022.

Comment by Roel Van de Paar [ 2022-03-02 ]

nayuta-yanagisawa Could we please still push the MTR testcase into the test suite? Thank you.

Comment by Roel Van de Paar [ 2022-09-09 ]

nayuta-yanagisawa Hi! Did this testcase make it into the suite? Thanks

Generated at Thu Feb 08 09:54:43 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.