Skip to content

MDEV-35472 Server crash in ha_storage_put_memlim upon reading from INNODB_LOCKS - #3649

Merged
dr-m merged 1 commit into
10.6from
10.6-MDEV-35472
Nov 25, 2024
Merged

MDEV-35472 Server crash in ha_storage_put_memlim upon reading from INNODB_LOCKS#3649
dr-m merged 1 commit into
10.6from
10.6-MDEV-35472

Conversation

@dr-m

@dr-m dr-m commented Nov 21, 2024

Copy link
Copy Markdown
Contributor
  • The Jira issue number for this PR is: MDEV-35472

Description

ha_storage_put_memlim(): Initialize node->next in order to avoid a crash on a subsequent invocation, due to dereferencing an uninitialized pointer.

This fixes a regression that had been introduced in #3584 (MDEV-35189).

Release Notes

Because the bug is being fixed in the same releases that introduce it, no mention is needed.

How can this PR be tested?

Apparently, this subsystem is badly covered by existing regression tests. It would be challenging to test this, because there is some rate-limiting of updates of the cache. This was tested with a small stress test using cmake -DWITH_ASAN=ON.

Basing the PR against the correct MariaDB version

  • This is a new feature or a refactoring, and the PR is based against the main branch.
  • This is a bug fix, and the PR is based against the earliest maintained branch in which the bug can be reproduced.

PR quality check

  • I checked the CODING_STANDARDS.md file and my PR conforms to this where appropriate.
  • For any trivial modifications to the PR, I am ok with the reviewer making the changes themselves.

@dr-m dr-m self-assigned this Nov 21, 2024
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

…NODB_LOCKS

ha_storage_put_memlim(): Initialize node->next in order to avoid a
crash on a subsequent invocation, due to dereferencing an uninitialized
pointer.

This fixes a regression that had been introduced in
commit ccb6cd8 (MDEV-35189).

Reviewed by: Debarun Banerjee
@dr-m
dr-m merged commit 2255be0 into 10.6 Nov 25, 2024
@dr-m
dr-m deleted the 10.6-MDEV-35472 branch November 25, 2024 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants