|
An additional testcase with a partially new stack, and this one will crash 10.3 also.
SET collation_connection=utf32_unicode_520_ci;
|
CREATE TABLE t (a SET('') CHARACTER SET utf32);
|
INSERT INTO t VALUES (DATE_FORMAT(0,0));
|
Leads to:
|
11.0.1 f2dc4d4c10ac36a73b5c1eb765352d3aee808d66 (Debug)
|
mariadbd: /test/11.0_dbg/strings/ctype-ucs2.c:2242: my_lengthsp_utf32: Assertion `(length % 4) == 0' failed.
|
|
11.0.1 f2dc4d4c10ac36a73b5c1eb765352d3aee808d66 (Debug)
|
Core was generated by `/test/MD180223-mariadb-11.0.1-linux-x86_64-dbg/bin/mariadbd --no-defaults --cor'.
|
Program terminated with signal SIGABRT, Aborted.
|
#0 __pthread_kill_implementation (no_tid=0, signo=6, threadid=22628909745728)
|
at ./nptl/pthread_kill.c:44
|
[Current thread is 1 (Thread 0x1494b4208640 (LWP 737379))]
|
(gdb) bt
|
#0 __pthread_kill_implementation (no_tid=0, signo=6, threadid=22628909745728) at ./nptl/pthread_kill.c:44
|
#1 __pthread_kill_internal (signo=6, threadid=22628909745728) at ./nptl/pthread_kill.c:78
|
#2 __GI___pthread_kill (threadid=22628909745728, signo=signo@entry=6) at ./nptl/pthread_kill.c:89
|
#3 0x00001494cd894476 in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
|
#4 0x00001494cd87a7f3 in __GI_abort () at ./stdlib/abort.c:79
|
#5 0x00001494cd87a71b in __assert_fail_base (fmt=0x1494cda2f150 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n", assertion=0x55de30ca9b72 "(length % 4) == 0", file=0x55de30ca9b00 "/test/11.0_dbg/strings/ctype-ucs2.c", line=2242, function=<optimized out>) at ./assert/assert.c:92
|
#6 0x00001494cd88be96 in __GI___assert_fail (assertion=assertion@entry=0x55de30ca9b72 "(length % 4) == 0", file=file@entry=0x55de30ca9b00 "/test/11.0_dbg/strings/ctype-ucs2.c", line=line@entry=2242, function=function@entry=0x55de30caa270 <__PRETTY_FUNCTION__.32> "my_lengthsp_utf32") at ./assert/assert.c:101
|
#7 0x000055de3061495a in my_lengthsp_utf32 (cs=<optimized out>, ptr=<optimized out>, length=<optimized out>) at /test/11.0_dbg/strings/ctype-ucs2.c:2242
|
#8 0x000055de2fd8d92e in charset_info_st::lengthsp (length=1, str=0x1494b4206570 "0e \264\224\024", this=<optimized out>) at /test/11.0_dbg/include/m_ctype.h:810
|
#9 find_set (lib=0x149460028340, str=str@entry=0x1494b4206570 "0e \264\224\024", length=length@entry=1, cs=0x55de311239a0 <my_charset_utf32_general_ci>, err_pos=err_pos@entry=0x1494b42064a0, err_len=err_len@entry=0x1494b420649c, set_warning=0x1494b4206497) at /test/11.0_dbg/sql/strfunc.cc:54
|
#10 0x000055de2ff32304 in Field_set::store (this=0x14946002f408, from=0x1494b4206570 "0e \264\224\024", length=1, cs=0x55de310f2160 <my_charset_utf32_unicode_520_ci>) at /test/11.0_dbg/sql/field.h:2118
|
#11 0x000055de2ff7b0ad in Item::save_str_in_field (this=0x149460013f28, field=0x14946002f408, no_conversions=<optimized out>) at /test/11.0_dbg/sql/item.cc:6834
|
#12 0x000055de2fe6fc9a in Type_handler_string_result::Item_save_in_field (this=<optimized out>, item=<optimized out>, field=<optimized out>, no_conversions=<optimized out>) at /test/11.0_dbg/sql/sql_type.cc:4329
|
#13 0x000055de2ff637db in Item::save_in_field (this=0x149460013f28, field=0x14946002f408, no_conversions=<optimized out>) at /test/11.0_dbg/sql/item.cc:6872
|
#14 0x000055de2fc0b5c2 in fill_record (thd=thd@entry=0x149460000d58, table=table@entry=0x14946002efe8, ptr=0x14946002f400, ptr@entry=0x14946002f3f8, values=@0x149460013e00: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x149460014010, last = 0x149460014010, elements = 1}, <No data fields>}, ignore_errors=ignore_errors@entry=false, use_value=use_value@entry=false) at /test/11.0_dbg/sql/sql_base.cc:9238
|
#15 0x000055de2fc0b722 in fill_record_n_invoke_before_triggers (thd=thd@entry=0x149460000d58, table=table@entry=0x14946002efe8, ptr=0x14946002f3f8, values=@0x149460013e00: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x149460014010, last = 0x149460014010, elements = 1}, <No data fields>}, ignore_errors=ignore_errors@entry=false, event=event@entry=TRG_EVENT_INSERT) at /test/11.0_dbg/sql/sql_base.cc:9293
|
#16 0x000055de2fc4748f in mysql_insert (thd=thd@entry=0x149460000d58, table_list=<optimized out>, fields=@0x149460005ec0: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x55de3115e440 <end_of_list>, last = 0x149460005ec0, elements = 0}, <No data fields>}, values_list=@0x149460005f08: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x149460014058, last = 0x149460014058, elements = 1}, <No data fields>}, update_fields=@0x149460005ef0: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x55de3115e440 <end_of_list>, last = 0x149460005ef0, elements = 0}, <No data fields>}, update_values=@0x149460005ed8: {<base_list> = {<Sql_alloc> = {<No data fields>}, first = 0x55de3115e440 <end_of_list>, last = 0x149460005ed8, elements = 0}, <No data fields>}, duplic=DUP_ERROR, ignore=false, result=0x0) at /test/11.0_dbg/sql/sql_insert.cc:1096
|
#17 0x000055de2fc80e0b in mysql_execute_command (thd=thd@entry=0x149460000d58, is_called_from_prepared_stmt=is_called_from_prepared_stmt@entry=false) at /test/11.0_dbg/sql/sql_parse.cc:4569
|
#18 0x000055de2fc867cf in mysql_parse (thd=thd@entry=0x149460000d58, rawbuf=<optimized out>, length=<optimized out>, parser_state=parser_state@entry=0x1494b42072c0) at /test/11.0_dbg/sql/sql_parse.cc:8002
|
#19 0x000055de2fc88963 in dispatch_command (command=command@entry=COM_QUERY, thd=thd@entry=0x149460000d58, packet=packet@entry=0x14946000ae19 "INSERT INTO t VALUES (DATE_FORMAT(0,0))", packet_length=packet_length@entry=39, blocking=blocking@entry=true) at /test/11.0_dbg/sql/sql_class.h:242
|
#20 0x000055de2fc8a7bc in do_command (thd=0x149460000d58, blocking=blocking@entry=true) at /test/11.0_dbg/sql/sql_parse.cc:1407
|
#21 0x000055de2fddb6e2 in do_handle_one_connection (connect=<optimized out>, connect@entry=0x55de325f9168, put_in_cache=put_in_cache@entry=true) at /test/11.0_dbg/sql/sql_connect.cc:1416
|
#22 0x000055de2fddb941 in handle_one_connection (arg=0x55de325f9168) at /test/11.0_dbg/sql/sql_connect.cc:1318
|
#23 0x00001494cd8e6b43 in start_thread (arg=<optimized out>) at ./nptl/pthread_create.c:442
|
#24 0x00001494cd978a00 in clone3 () at ../sysdeps/unix/sysv/linux/x86_64/clone3.S:81
|
Bug confirmed present in:
MariaDB: 10.3.38 (dbg), 10.4.29 (dbg), 10.5.20 (dbg), 10.6.13 (dbg), 10.7.8 (dbg), 10.8.8 (dbg), 10.9.6 (dbg), 10.10.4 (dbg), 10.11.2 (dbg), 11.0.1 (dbg)
MySQL: 5.6.51 (dbg), 5.7.40 (dbg), 8.0.31 (dbg)
Bug (or feature/syntax) confirmed not present in:
MariaDB: 10.3.38 (opt), 10.4.29 (opt), 10.5.20 (opt), 10.6.13 (opt), 10.7.8 (opt), 10.8.8 (opt), 10.9.6 (opt), 10.10.4 (opt), 10.11.2 (opt), 11.0.1 (opt)
MySQL: 5.5.62 (dbg), 5.5.62 (opt), 5.6.51 (opt), 5.7.40 (opt), 8.0.31 (opt)
All new UniqueID's observed with this testcase accross versions:
(length % 4) == 0|SIGABRT|my_lengthsp_utf32|charset_info_st::lengthsp|find_set|Field_set::store
|
(length % 4) == 0|SIGABRT|my_lengthsp_utf32|find_set|Field_set::store|Item::save_in_field
|
(length % 4) == 0|SIGABRT|my_lengthsp_utf32|find_set|Field_set::store|Item::save_in_field_inner
|
(length % 4) == 0|SIGABRT|my_lengthsp_utf32|find_set|Field_set::store|Item::save_str_in_field
|
|