Crash in add_ref_to_table_cond() when grouping by a PK
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
MariaDB |
Fix Released
|
Critical
|
Oleksandr "Sanja" Byelkin |
Bug Description
Query:
SELECT a
FROM t1
WHERE a = (
SELECT t2.a
FROM t2
) OR t1.a = 73
GROUP BY 1;
backtrace:
#3 0x082987db in handle_segfault (sig=11) at mysqld.cc:2810
#4 <signal handler called>
#5 0x08348964 in add_ref_
#6 0x0831dcb6 in JOIN::optimize (this=0xae6269f0) at sql_select.cc:1543
#7 0x08322209 in mysql_select (thd=0xa2c56e0, rref_pointer_
order=0x0, group=0xae614078, having=0x0, proc_param=0x0, select_
at sql_select.cc:2886
#8 0x0831a05f in handle_select (thd=0xa2c56e0, lex=0xa2c6de4, result=0xae614118, setup_tables_
#9 0x082b482c in execute_
#10 0x082ab5e9 in mysql_execute_
#11 0x082b6e5b in mysql_parse (thd=0xa2c56e0, rawbuf=0xae612ec0 "SELECT a\nFROM t1\nWHERE a = (\nSELECT t2.a\nFROM t2\n) OR t1.a = 73\nGROUP BY 1",
length=74, found_semicolon
#12 0x082a9238 in dispatch_command (command=COM_QUERY, thd=0xa2c56e0,
packet=
#13 0x082a8693 in do_command (thd=0xa2c56e0) at sql_parse.cc:916
#14 0x082a5677 in handle_
#15 0x00821919 in start_thread () from /lib/libpthread
#16 0x0076acce in clone () from /lib/libc.so.6
explain also crashes:
reproducible with default switches. reproducible on maria 5.3. not reproducible on maria-5.2, mysql-5.5
bzr version-info
revision-id: <email address hidden>
date: 2011-10-12 02:04:03 +0400
build-date: 2011-10-12 10:25:51 +0300
revno: 3224
branch-nick: maria-5.3
test case:
CREATE TABLE t1 (a int, PRIMARY KEY (a)) ;
INSERT INTO t1 VALUES (14),(15)
CREATE TABLE t2 (a int) ;
SELECT a
FROM t1
WHERE a = (
SELECT t2.a
FROM t2
) OR t1.a = 73
GROUP BY 1;
Changed in maria: | |
milestone: | none → 5.1 |
milestone: | 5.1 → 5.3 |
assignee: | nobody → Oleksandr "Sanja" Byelkin (sanja-byelkin) |
Changed in maria: | |
importance: | Undecided → Critical |
status: | New → In Progress |
Changed in maria: | |
status: | In Progress → Fix Committed |
Changed in maria: | |
status: | Fix Committed → Fix Released |
This bug has been fixed by this cset:
revno: 3226
revision-id: <email address hidden>
parent: <email address hidden>
committer: Sergey Petrunya <email address hidden>
branch nick: 5.3-push19
timestamp: Wed 2011-10-12 14:23:42 +0400
message:
Fix compile error: ‘cond_copy’ may be used uninitialized in this function.