mariadb/storage/myisam
Guilhem Bichot 1756d087cd Fix for BUG#59894
"set optimizer_switch to e or d causes invalid memory writes/valgrind warnings":
due to prefix support, the argument "e" was overwritten with its full value
"engine_condition_pushdown", which caused a buffer overrun.
This was wrong usage of find_type(); other wrong usages are fixed here too.
Please start reading with the comment of typelib.c.

client/mysqldump.c:
  A bug: find_type() expects a bitmap as 3rd argument
  (each bit is a flag controlling a behaviour of the function);
  here it was instead passed the length of the string to search!
  That could give random behaviour of find_type()
  depending on the string.
  We rather need to pass a correct flag to find_type().
  The correct flag is FIND_TYPE_BASIC (0).
  Flag 8 is not needed as buff cannot have a comma (see how buff is filled).
  Flag 1 looks like a superfluous restriction.
  Flag 4 is not user-friendly (why use
  --compatible=2 rather than --compatible=mysql40 ?, and
  we probably not commit to "2" always meaning "mysql40"
  until the end of times).
include/mysql.h.pp:
  This isn't a problematic API change as we go from char* to const char*:
  existing code will run unchanged.
include/typelib.h:
  named constants. Not an enum to not significantly change
  the declaration of find_type() which would be an API change
  (typelib.h is included in mysql.h).
mysql-test/r/mysqldump.result:
  correct result (see the two requested modes in SQL_MODE)
mysql-test/suite/sys_vars/t/optimizer_switch_basic.test:
  test for BUG#59894. The second SET used to crash.
mysql-test/t/mysqldump.test:
  we had no test for multiple modes in --compatible, which is
  supported according to --help
mysys/typelib.c:
  Fix for BUG#59894. parse_name() is asked to match "e" with a row
  of the TYPELIB (the TYPELIB lists permitted flags of optimizer_switch;
  and comes from optimizer_switch_names[] of sys_vars.cc).
  find_type() is capable of supporting prefixes, but if it is not
  passed flag 2 in third argument, it will overwrite its first
  argument (the string to search for) with the complete name,
  here overwriting "e" with "engine_condition_pushdown". But
  as this "e" was a buffer allocated in an Item, it was not big
  enough to host the longer name, thus the crash.
  We don't need to know the complete flag's name; the output used
  from find_type() is just the flag's number (== function's return
  code). So we can pass flag 2 to find_type() in parse_name().
  After doing this fix and the other fixes in this patch, all usages
  of find_type() were using flag 2; in most usages the string to search for,
  is not guaranteed to be long enough to host the complete name
  (it is either directly from argv, or from alloc_root/my_malloc
  done in an earlier call).
  Thus, flag 2 is here made implicit: callers need not pass it anymore,
  it is always automatically turned on.
  This allows to eliminate an oddity: parse_name() took a const char**,
  and then removed "const" before calling find_type(), which could
  theoretically modify the pointed data, thus lying on constness.
  Last, constants for find_type() are now named.
sql-common/client.c:
  Two bugs:
  1) The enum was not in sync with the array (due to a bad porting of WL 1054;
  the extra OPT_ values are about options present in 5.1 and deleted in 5.5);
  added a compile_time_assert() to make sure this doesn't happen again
  2) find_type() was writing past the end of opt_arg; as opt_arg was allocated
  with alloc_root() with no extra space, this was an overrun; it could be seen
  when
  ** building with -DWITH_VALGRIND -DHAVE_purify -DEXTRA_DEBUG
  ** making execution go through the faulty code; this faulty
  code is executed only if the client asks to read a configuration
  file like this:
    mysql_options(mysql, MYSQL_READ_DEFAULT_FILE, "/tmp/cnf.cnf");
  so by adding such line to the start of mysql_client_test.c::client_connect(),
  we could see the valgrind warning:
  ==30548== Invalid write of size 1
  ==30548==    at 0x4C2624C: strcpy (mc_replace_strmem.c:303)
  ==30548==    by 0x48DC29: find_type (typelib.c:120)
  ==30548==    by 0x465686: mysql_read_default_options (client.c:1344)
  ==30548==    by 0x46830F: mysql_real_connect (client.c:2971)
  ==30548==    by 0x409339: client_connect (mysql_client_test.c:331)
  ==30548==    by 0x463A7F: main (mysql_client_test.c:19902)
  ==30548==  Address 0x61875ad is 0 bytes after a block of size 29 alloc'd
  ==30548==    at 0x4C25153: malloc (vg_replace_malloc.c:195)
  ==30548==    by 0x49BFF1: my_malloc (my_malloc.c:38)
  ==30548==    by 0x49C65C: alloc_root (my_alloc.c:166)
  ==30548==    by 0x48EF97: handle_default_option (default.c:381)
  ==30548==    by 0x49068C: search_default_file_with_ext (default.c:992)
  ==30548==    by 0x48F929: search_default_file (default.c:670)
  ==30548==    by 0x48EDC4: my_search_option_files (default.c:312)
  ==30548==    by 0x48F4B1: my_load_defaults (default.c:576)
  ==30548==    by 0x46517A: mysql_read_default_options (client.c:1207)
  ==30548==    by 0x46830F: mysql_real_connect (client.c:2971)
  ==30548==    by 0x409339: client_connect (mysql_client_test.c:331)
  ==30548==    by 0x463A7F: main (mysql_client_test.c:19902)
  This is fixed by having find_type() not overwrite anymore.
sql/sql_help.cc:
  cast not needed anymore.
sql/table.cc:
  cast not needed anymore.
2011-02-11 15:00:09 +01:00
..
ftbench Merge 2010-12-29 00:47:05 +01:00
ChangeLog
CMakeLists.txt Patch for Bug#55854 (MySQL AB should not be AUTHOR, copyright incorrect). 2010-08-12 19:19:57 +04:00
ft_boolean_search.c WL#5498: Remove dead and unused source code 2010-07-23 17:16:29 -03:00
ft_nlq_search.c Merge of mysql-5.1-bugteam into mysql-5.5-bugteam. 2010-11-16 07:45:07 -02:00
ft_parser.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
ft_static.c WL#4738 streamline/simplify @@variable creation process 2009-12-22 10:35:56 +01:00
ft_stopwords.c Backporting Bug#32391 Character sets: crash with --character-set-server 2010-08-19 10:00:43 +04:00
ft_update.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
ftdefs.h Fix for bug #37756: enabling fulltext indexes with 2009-01-26 10:35:15 +04:00
fulltext.h Bug#42733: Type-punning warnings when compiling MySQL -- 2010-06-10 17:16:43 -03:00
ha_myisam.cc Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
ha_myisam.h Bug#49938: Failing assertion: inode or deadlock in fsp/fsp0fsp.c 2010-10-06 11:34:28 -03:00
mi_cache.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_changed.c Backport of: 2009-11-24 16:54:59 +03:00
mi_check.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_checksum.c Moved a lot of old bug fixes and safe cleanups from Maria 5.1 tree to 5.1 2007-10-11 18:07:40 +03:00
mi_close.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_create.c Bug#58057: 5.1 libmysql/libmysql.c unused variable/compile failure 2010-11-10 19:14:47 -02:00
mi_dbug.c A fix for Bug#52432 "Crash in check_table_is_closed on an 2010-06-07 16:05:34 +04:00
mi_delete.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_delete_all.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_delete_table.c WL#5498: Remove dead and unused source code 2010-07-23 17:15:07 -03:00
mi_dynrec.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_extra.c Manual merge of mysql-5.1-bugteam into mysql-trunk-merge. 2010-04-03 12:37:53 +04:00
mi_extrafunc.h Backport from 6.0-codebase. 2009-11-25 16:25:01 +04:00
mi_info.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_key.c Bug#42511 mysqld: ctype-ucs2.c:2044: my_strnncollsp_utf32: Assertion (tlen % 4) == 0' fai 2010-08-26 16:36:33 +04:00
mi_keycache.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_locking.c Merge of mysql-5.1-bugteam into mysql-trunk-merge. 2010-07-20 16:30:10 -03:00
mi_log.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_open.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_packrec.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
mi_page.c Bug#53445: Build with -Wall and fix warnings that it generates 2010-07-02 15:30:47 -03:00
mi_panic.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_preload.c Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled 2010-07-08 18:20:08 -03:00
mi_range.c Merge of mysql-5.1-bugteam into mysql-5.5-merge. 2010-09-24 19:19:30 -03:00
mi_rename.c WL#5498: Remove dead and unused source code 2010-07-23 17:15:07 -03:00
mi_rfirst.c WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
mi_rkey.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_rlast.c WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
mi_rnext.c Manual merge of mysql-5.1-bugteam into mysql-trunk-merge. 2010-04-02 19:17:43 +04:00
mi_rnext_same.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_rprev.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_rrnd.c WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
mi_rsame.c WL#2360 Performance schema 2009-12-04 18:26:15 -07:00
mi_rsamepos.c WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
mi_scan.c WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
mi_search.c Merge of mysql-5.1-bugteam into mysql-5.5-merge. 2010-09-24 19:19:30 -03:00
mi_static.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_statrec.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_test1.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
mi_test2.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
mi_test3.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
mi_test_all.res
mi_test_all.sh Merge 2010-12-29 00:47:05 +01:00
mi_unique.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
mi_update.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
mi_write.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
myisam_ftdump.c Bug#42733: Type-punning warnings when compiling MySQL 2010-07-24 09:24:44 -03:00
myisamchk.c Fix for BUG#59894 2011-02-11 15:00:09 +01:00
myisamdef.h Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
myisamlog.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
myisampack.c Merge 2010-12-29 01:26:31 +01:00
NEWS
rt_index.c Merge 2010-12-29 01:26:31 +01:00
rt_index.h Merge mysql.com:/home/kent/bk/main/mysql-5.0 2006-12-31 01:32:21 +01:00
rt_key.c Merge chilla.local:/home/mydev/mysql-5.0-bug25673 2007-03-08 12:13:54 +01:00
rt_key.h Merge mysql.com:/home/kent/bk/main/mysql-5.0 2006-12-31 01:32:21 +01:00
rt_mbr.c Merge mysql.com:/home/hf/work/30286/my50-30286 2007-10-05 15:43:15 +05:00
rt_mbr.h Merge mysql.com:/home/kent/bk/main/mysql-5.0 2006-12-31 01:32:21 +01:00
rt_split.c Bug#45288: pb2 returns a lot of compilation warnings on linux 2010-09-24 19:13:51 -03:00
rt_test.c WL#5498: Remove dead and unused source code 2010-07-23 17:09:27 -03:00
sort.c Remove configuration preprocessor symbols 'THREAD' 2011-01-11 10:07:37 +01:00
sp_defs.h WL#3817: Simplify string / memory area types and make things more consistent (first part) 2007-05-10 12:59:39 +03:00
sp_key.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
sp_test.c WL#5498: Remove dead and unused source code 2010-07-23 17:17:55 -03:00
test_pack
TODO