Crash in subselect_union_engine::no_rows with double UNION and join_cache_level=3,8
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
MariaDB |
Fix Released
|
Critical
|
Oleksandr "Sanja" Byelkin |
Bug Description
This query:
SELECT *
FROM t1, t2
WHERE t2.b IN (
SELECT 'm' UNION
SELECT 'm'
) OR t1.b <> SOME (
SELECT 'v' UNION
SELECT 't'
);
crashes as follows:
#4 <signal handler called>
#5 0x0824c373 in subselect_
#6 0x0820ec2e in Item_in_
#7 0x081e2706 in Item::val_
#8 0x081dd848 in Item_cache_
#9 0x081e67d2 in Item_cache_
#10 0x081dac96 in Item_cache_
#11 0x0820bab4 in Item_func_
#12 0x081ca95c in Item::val_bool (this=0xae514c40) at item.cc:197
#13 0x082170b6 in Item_cond_
#14 0x082f6b52 in SQL_SELECT:
#15 0x082f7749 in JOIN_CACHE:
#16 0x082f3c10 in JOIN_CACHE:
#17 0x082f3a19 in JOIN_CACHE:
#18 0x082f34d9 in JOIN_CACHE:
#19 0x0833dca5 in sub_select_cache (join=0xae526020, join_tab=
#20 0x0833debd in sub_select (join=0xae526020, join_tab=
#21 0x0833d9ac in do_select (join=0xae526020, fields=0x9edd1b4, table=0x0, procedure=0x0) at sql_select.cc:14797
#22 0x08322206 in JOIN::exec (this=0xae526020) at sql_select.cc:2679
#23 0x08322a32 in mysql_select (thd=0x9edb6e0, rref_pointer_
order=0x0, group=0x0, having=0x0, proc_param=0x0, select_
at sql_select.cc:2900
#24 0x0831a92f in handle_select (thd=0x9edb6e0, lex=0x9edcde4, result=0xae514df0, setup_tables_
#25 0x082b5050 in execute_
#26 0x082abe0d in mysql_execute_
#27 0x082b7691 in mysql_parse (thd=0x9edb6e0,
rawbuf=
length=114, found_semicolon
#28 0x082a9a5c in dispatch_command (command=COM_QUERY, thd=0x9edb6e0, packet=0x9f34571 "", packet_length=114) at sql_parse.cc:1221
#29 0x082a8eb7 in do_command (thd=0x9edb6e0) at sql_parse.cc:916
#30 0x082a5e9b in handle_
#31 0x00821919 in start_thread () from /lib/libpthread
#32 0x0076acce in clone () from /lib/libc.so.6
minimal switch: join_cache_level=3
full switch: index_merge=
explain:
id select_type table type possible_keys key key_len ref rows Extra
1 PRIMARY t1 ALL NULL NULL NULL NULL 2
1 PRIMARY t2 ALL NULL NULL NULL NULL 2 Using where; Using join buffer (flat, BNL join)
4 DEPENDENT SUBQUERY NULL NULL NULL NULL NULL NULL NULL No tables used
5 DEPENDENT UNION NULL NULL NULL NULL NULL NULL NULL No tables used
NULL UNION RESULT <union4,5> ALL NULL NULL NULL NULL NULL
2 DEPENDENT SUBQUERY NULL NULL NULL NULL NULL NULL NULL No tables used
3 DEPENDENT UNION NULL NULL NULL NULL NULL NULL NULL No tables used
NULL UNION RESULT <union2,3> ALL NULL NULL NULL NULL NULL
bzr version-info
revision-id: <email address hidden>
date: 2011-11-07 16:39:02 +0400
build-date: 2011-11-08 10:15:29 +0200
revno: 3273
branch-nick: maria-5.3
test case:
CREATE TABLE t2 ( a int, b varchar(1)) ;
INSERT IGNORE INTO t2 VALUES (8,'y'),(8,'y');
CREATE TABLE t1 ( b varchar(1)) ;
INSERT IGNORE INTO t1 VALUES (NULL),(NULL);
SET SESSION join_cache_level=3;
SELECT *
FROM t1, t2
WHERE t2.b IN (
SELECT 'm' UNION
SELECT 'm'
) OR t1.b <> SOME (
SELECT 'v' UNION
SELECT 't'
);
see also bug https:/
Changed in maria: | |
milestone: | none → 5.3 |
assignee: | nobody → Timour Katchaounov (timour) |
Changed in maria: | |
importance: | Undecided → Critical |
status: | New → Confirmed |
description: | updated |
Changed in maria: | |
assignee: | Timour Katchaounov (timour) → Oleksandr "Sanja" Byelkin (sanja-byelkin) |
The same fix as for LP BUG#859375