Console View
|
Categories: connectors experimental galera main |
|
| connectors | experimental | galera | main | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: wire the launcher into mysql_server_init() Glue (embedded_glue.c) registers the launcher with libmariadb through mariadb_set_embedded_hooks(), so that the plain client API is enough: mysql_server_init(argc, argv) starts the server, connecting to localhost reaches it, mysql_server_end() stops it. launcher_test now uses only that. Points libmariadb at the MDEV-11111-embedded-hooks branch (57875d2c). That commit exists only locally and must be pushed to the libmariadb repository before this one can be. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher: no error log warning check The server exists only while one mysqltest runs, so the per-test check of the error log (which applies mtr.add_suppression from the tests) cannot run, and the final scan flagged warnings that tests provoke on purpose. Disable the check in this mode. ToDo: run check-warnings.inc from mysqltest before the private server is stopped. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher checks the error log; launcher sweeps leftovers * mtr: the per-test check of the error log (include/check-warnings.inc) runs in --embedded-launcher mode too. There is no running mysqld, so the check starts another private server on the datadir the test has left, as mysqltest does for the test, and applies the suppressions that the test stored there with mtr.add_suppression. This replaces the temporary --nowarnings behaviour of this mode. * launcher: an application that is killed cannot remove the private directory (Unix) or the server log (Windows) of its server. Name them with the pid of the application, and remove those of dead applications at the next start. Only the current user's, and not while the pid exists. Linux (WSL, RelWithDebInfo): 286 tests of main and embedded pass, no warnings, no leftover servers or directories. Windows (Debug): 299 tests pass; the only warning is a plugin that is not built there. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: abstract socket on Linux; only the owning process may connect * Linux: the embedded server listens on an abstract socket (@mariadb-embedded-<pid>-<random>). It has no file system entry, so there is no directory to protect or to clean up after a crash. The log of the server is a temp file that is unlinked at once (the launcher keeps its fd to show the tail on a startup failure). Other Unix systems still use a 0700 directory. * New option --embedded-client-pid=<pid>, passed by the launcher: only that process may connect. Linux: SO_PEERCRED pid and uid are checked after accept(), which is what protects an abstract socket. Windows: GetNamedPipeClientProcessId, in addition to the pipe being limited to the user. A refused connection is counted in Aborted_connects and noted in the error log. Checked by hand on Linux and Windows: the application connects; another process of the same user gets the connection closed without a greeting; after kill -9 of the application there is no server and no file or socket left on Linux. mtr --embedded-launcher: 286 tests pass on Linux, 300 on Windows. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
forkfun
alice.sherepa@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-24684 Quadratic time for MIN/MAX/STD/VARIANCE as window functions Frame_scan_cursor cleared and re-scanned the whole frame for every row. Keep the result if the frame did not change (whole-partition frames, peers), and add only the new rows if just the bottom moved down. Argument conversion warnings are no longer repeated on each re-scan. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: launcher: find server next to library, log to file, no-grants default * Server binary: $MARIADB_EMBEDDED_SERVER, else mariadbd next to the library/executable, else PATH. * Unix: server stdout/stderr go to a file in the private socket directory ($MARIADB_EMBEDDED_LOG=stderr keeps the application's stderr); on startup failure the tail of that log is added to mariadb_embedded_error(). * Unix: --skip-grant-tables by default, safe as the socket is in a 0700 directory. $MARIADB_EMBEDDED_GRANTS=1 enables real authentication. Windows keeps grants until the pipe ACL is verified. * Clean up the temp directory on all failure paths. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Hooks for an embedded server launcher (MDEV-11111) Add mariadb_set_embedded_hooks(server_init, server_end, socket_name). A library that spawns a private server (libmariadbd in the server tree) registers itself with it: * mysql_server_init(argc, argv, groups) calls server_init once, from the same once-only initialization, and returns its result. * mysql_server_end() calls server_end. * While socket_name() returns non-NULL, connections to the local host (no host, "localhost", or "." on Windows) that do not give a socket use that socket, or named pipe on Windows. TCP, remote hosts and explicit sockets are unaffected, so there is no need for a "not embedded" option. Without registered hooks nothing changes. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: build the launcher, use it from mysqltest and mtr * libmysqld/launcher/CMakeLists.txt: static library mariadb_embedded_launcher (client side, no server sources). * mariadb-test links it; given --server-arg it registers the launcher, so the ordinary mysqltest runs the "embedded" server as a private mariadbd. * mtr: new --embedded-launcher, implies --embedded-server for the test selection, but uses the regular mariadb-test and passes the server binary in $MARIADB_EMBEDDED_SERVER. The old mariadb-test-embedded path is untouched. Not verified with a full mtr run yet. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher: no error log warning check The server exists only while one mysqltest runs, so the per-test check of the error log (which applies mtr.add_suppression from the tests) cannot run, and the final scan flagged warnings that tests provoke on purpose. Disable the check in this mode. ToDo: run check-warnings.inc from mysqltest before the private server is stopped. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server launcher (phase 1) Prototype of running the embedded server as a private mariadbd child process instead of compiling the server into the application with EMBEDDED_LIBRARY. Running it out of process means the many exit() / unireg_abort() paths of the server cannot take the application down. * libmysqld/launcher: mariadb_embedded_start()/stop(). Spawns mariadbd (posix_spawnp, or CreateProcess with an explicit handle list on Windows) with --skip-networking and a private Unix socket / named pipe, waits until it accepts connections, reports early exit. * mysqld: new option --embedded-lifeline=<fd|HANDLE>. A thread blocks on the inherited pipe and starts a normal shutdown on EOF, i.e. when the client stops the server or dies. No PDEATHSIG (fires on thread exit) and no kill-on-close job object (would beat the graceful shutdown). Not yet wired into mysql_server_init()/mysql_server_end(), and the old libmysqld build is untouched. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PranavKTiwari
pranav.tiwari@mariadb.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *) Problem: Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set. Cause: find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion. Fix: The fix uses a local bitmap instead of tmp_set for the virtual column dependency walk in TABLE::update_virtual_field(), so the active read_set/write_set is not touched. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server launcher (phase 1) Prototype of running the embedded server as a private mariadbd child process instead of compiling the server into the application with EMBEDDED_LIBRARY. Running it out of process means the many exit() / unireg_abort() paths of the server cannot take the application down. * libmysqld/launcher: mariadb_embedded_start()/stop(). Spawns mariadbd (posix_spawnp, or CreateProcess with an explicit handle list on Windows) with --skip-networking and a private Unix socket / named pipe, waits until it accepts connections, reports early exit. * mysqld: new option --embedded-lifeline=<fd|HANDLE>. A thread blocks on the inherited pipe and starts a normal shutdown on EOF, i.e. when the client stops the server or dies. No PDEATHSIG (fires on thread exit) and no kill-on-close job object (would beat the graceful shutdown). Not yet wired into mysql_server_init()/mysql_server_end(), and the old libmysqld build is untouched. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: restrict the embedded server's named pipe to its own user Normally the pipe gives Everyone read/write access. When started with --embedded-lifeline the DACL only has the current user, so that the launcher can default to --skip-grant-tables on Windows as well as Unix (where the socket directory is 0700). Verified on a running server: the DACL is a single ACE for the user's SID. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher runs a test * launcher, Windows: send the server's stdout/stderr to a log file (as on Unix) and add its tail to the startup error, so that a failing option is visible instead of just "status 1". * mtr: with --embedded-launcher pass the [mysqld.1] options via --defaults-group-suffix (the real server does not read [embedded]), use the regular client-test binary and DLL paths. * mysqltest: after starting the private server, default connections use its socket/pipe, not the socket and port from the option files. main.1st passes on Windows with --embedded-launcher. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Embedded hooks: a socket equal to the embedded server's counts as embedded When the application passes the embedded server's own socket (e.g. as the default socket of a test client), "localhost" must still reach it on Windows, where "localhost" alone would otherwise select TCP. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server: real grant tables, no credential check --skip-grant-tables, the launcher's default so far, refuses GRANT, CREATE USER and similar, and gives sessions no real identity. Keep the grant tables, and skip only the check of credentials, as the old embedded server did: its only client is the process that has started it, over a private socket or pipe. With --embedded-lifeline: * acl_authenticate(): do_auth_once() reads the client handshake, which gives the user name, and succeeds without running the account's plugin. The account, if it exists, decides the privileges as usual. A name without an account is the root account; if there is no such account either, the connection is refused. * an empty data directory (no mysql.global_priv) starts as with --skip-grant-tables, with a note in the log, instead of failing. The launcher no longer passes --skip-grant-tables; an application can still pass it. mtr --embedded-launcher no longer needs real grants forced. New test embedded.launcher_auth, only for mtr --embedded-launcher: a wrong password is accepted, the privileges of the account are enforced, COM_CHANGE_USER works, and an unknown name is root. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher runs a test * launcher, Windows: send the server's stdout/stderr to a log file (as on Unix) and add its tail to the startup error, so that a failing option is visible instead of just "status 1". * mtr: with --embedded-launcher pass the [mysqld.1] options via --defaults-group-suffix (the real server does not read [embedded]), use the regular client-test binary and DLL paths. * mysqltest: after starting the private server, default connections use its socket/pipe, not the socket and port from the option files. main.1st passes on Windows with --embedded-launcher. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: abstract socket on Linux; only the owning process may connect * Linux: the embedded server listens on an abstract socket (@mariadb-embedded-<pid>-<random>). It has no file system entry, so there is no directory to protect or to clean up after a crash. The log of the server is a temp file that is unlinked at once (the launcher keeps its fd to show the tail on a startup failure). Other Unix systems still use a 0700 directory. * New option --embedded-client-pid=<pid>, passed by the launcher: only that process may connect. Linux: SO_PEERCRED pid and uid are checked after accept(), which is what protects an abstract socket. Windows: GetNamedPipeClientProcessId, in addition to the pipe being limited to the user. A refused connection is counted in Aborted_connects and noted in the error log. Checked by hand on Linux and Windows: the application connects; another process of the same user gets the connection closed without a greeting; after kill -9 of the application there is no server and no file or socket left on Linux. mtr --embedded-launcher: 286 tests pass on Linux, 300 on Windows. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-33387 - multifactor authentication Support "AND" between authentication plugins in CREATE/ALTER USER, so that a user must pass every factor to log in (multi-factor auth), in addition to the existing "OR" (alternative plugins). Mixing AND and OR in one user definition is rejected. CREATE USER u IDENTIFIED VIA mysql_native_password AS PASSWORD('...') AND some_other_plugin USING '...'; Grammar and storage - USER_AUTH gets a logical_operator (NONE/OR/AND) telling how each factor combines with the next; the parser tags the factor list and rejects a mix of AND/OR. - The operator is persisted in mysql.global_priv: the factor array is stored under "auth_and" (mirroring the existing "auth_or"). ALTER USER that collapses a multi-factor account back to a single plugin removes the stale "auth_and"/"auth_or" key. - SHOW CREATE USER prints " AND " between factors. - Two password-based (hashing) plugins in one AND chain are rejected; at most one factor may carry a password hash. Authentication protocol - New client capability CLIENT_MULTI_FACTOR_AUTHENTICATION and an AuthNextFactor (0x02) command that tells the client to proceed to the next factor after the current one succeeded. send_plugin_request_packet becomes send_change_plugin_packet, handling both the auth-switch (0xFE) and next-factor (0x02) commands. Clients that do not announce the capability fall back to an auth switch. - acl_authenticate() runs the factors sequentially for AND (every factor must return CR_OK), while OR keeps its "first success wins" behavior. - The in-server client (sql-common/client.c, used by mariadb-backup, replication, etc.) also handles AuthNextFactor: it advertises the new capability, recognises the 0x02 packet in run_plugin_auth(), and uses the same is_auth_switch_command() helper (with AUTH_SWITCH_PLUGIN_PACKET and AUTH_NEXT_FACTOR_PACKET symbolic constants) as libmariadb does. TLS server-identity via password hash - When the connection uses a self-signed certificate and no CA is configured, the server sends a fingerprint challenge in the OK packet, computed from the certificate fingerprint and the password hash. For a multi-factor account the salt of the first password-hashing factor is used. The client recomputes it and, on a match, trusts the certificate even with --ssl-verify-server-cert, so password-based verification of the server does not raise a certificate error. Tests - New plugins suite tests: mfa (portable machinery: AuthNextFactor round trip, non-hashing factor, auth_and persistence and ALTER round-trip, distinct per-factor secrets, negative cases, TLS fingerprint), mfa_unix (unix_socket + password), mfa_win (named_pipe/gssapi + password), mfa_unix_pam (password + PAM PIN). - auth_gssapi multiauth trimmed to the OR cases it still owns. Client side changes are in the bundled libmariadb (submodule bump). Assisted-by: Claude:claude-haiku-4.5-20251001 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: build the launcher, use it from mysqltest and mtr * libmysqld/launcher/CMakeLists.txt: static library mariadb_embedded_launcher (client side, no server sources). * mariadb-test links it; given --server-arg it registers the launcher, so the ordinary mysqltest runs the "embedded" server as a private mariadbd. * mtr: new --embedded-launcher, implies --embedded-server for the test selection, but uses the regular mariadb-test and passes the server binary in $MARIADB_EMBEDDED_SERVER. The old mariadb-test-embedded path is untouched. Not verified with a full mtr run yet. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server sessions are root@localhost With --skip-grant-tables, Security_context::skip_grants() leaves priv_user and priv_host empty, so CURRENT_USER() is empty and views, routines etc get DEFINER=``. When started with --embedded-lifeline, the only client is the process that spawned the server, so give the session the identity root@localhost (all privileges were already granted). GRANT, CREATE USER etc are still refused by --skip-grant-tables, so mtr --embedded-launcher keeps real grants (MARIADB_EMBEDDED_GRANTS=1). Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: launcher: find server next to library, log to file, no-grants default * Server binary: $MARIADB_EMBEDDED_SERVER, else mariadbd next to the library/executable, else PATH. * Unix: server stdout/stderr go to a file in the private socket directory ($MARIADB_EMBEDDED_LOG=stderr keeps the application's stderr); on startup failure the tail of that log is added to mariadb_embedded_error(). * Unix: --skip-grant-tables by default, safe as the socket is in a 0700 directory. $MARIADB_EMBEDDED_GRANTS=1 enables real authentication. Windows keeps grants until the pipe ACL is verified. * Clean up the temp directory on all failure paths. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher: tests connecting by $MASTER_MYSOCK * mtr: with real grants for tests (root@localhost), as with a normal server. * mysqltest: the launched server's socket becomes $MASTER_MYSOCK, and is not made relative to the tmp directory. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Dave Gosselin
dave.gosselin@mariadb.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-31180: MyISAMMRG Crash on UPDATE of an updateable VIEW Attach the children of a MERGE table once per statement, and keep the value of pos_in_table_list for a MERGE table on subsequent executions of a prepared statement. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: libmariadbd, a shared client library with the embedded server Build libmariadbd (.dll / .so) from the same objects and the same export list as libmariadb, plus the launcher. Loading it registers the launcher with the client library (DllMain / constructor), so an application links libmariadbd instead of libmariadb and uses only the client API: mysql_server_init(argc, argv) starts a private mariadbd, a connection without host goes to it, mysql_server_end() stops it. embedded_app_test is such an application (not built by default). Verified on Windows: it imports only libmariadbd.dll, prints CURRENT_USER() = root@localhost, and leaves no server behind. The ELF variant (version script, constructor) is not built or run yet, and no install rules are added. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: update libmariadb (embedded socket match) Points libmariadb at 5a29ab9e. Local commit in the libmariadb repository, must be pushed first. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
forkfun
alice.sherepa@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-24684 Quadratic time for MIN/MAX/STD/VARIANCE as window functions Frame_scan_cursor cleared and re-scanned the whole frame for every row. Keep the result if the frame did not change (whole-partition frames, peers), and add only the new rows if just the bottom moved down. Argument conversion warnings are no longer repeated on each re-scan. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Embedded hooks: a socket equal to the embedded server's counts as embedded When the application passes the embedded server's own socket (e.g. as the default socket of a test client), "localhost" must still reach it on Windows, where "localhost" alone would otherwise select TCP. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Hooks for an embedded server launcher (MDEV-11111) Add mariadb_set_embedded_hooks(server_init, server_end, socket_name). A library that spawns a private server (libmariadbd in the server tree) registers itself with it: * mysql_server_init(argc, argv, groups) calls server_init once, from the same once-only initialization, and returns its result. * mysql_server_end() calls server_end. * While socket_name() returns non-NULL, connections to the local host (no host, "localhost", or "." on Windows) that do not give a socket use that socket, or named pipe on Windows. TCP, remote hosts and explicit sockets are unaffected, so there is no need for a "not embedded" option. Without registered hooks nothing changes. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: update libmariadb (embedded socket match) Points libmariadb at 5a29ab9e. Local commit in the libmariadb repository, must be pushed first. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: restrict the embedded server's named pipe to its own user Normally the pipe gives Everyone read/write access. When started with --embedded-lifeline the DACL only has the current user, so that the launcher can default to --skip-grant-tables on Windows as well as Unix (where the socket directory is 0700). Verified on a running server: the DACL is a single ACE for the user's SID. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: libmariadbd, a shared client library with the embedded server Build libmariadbd (.dll / .so) from the same objects and the same export list as libmariadb, plus the launcher. Loading it registers the launcher with the client library (DllMain / constructor), so an application links libmariadbd instead of libmariadb and uses only the client API: mysql_server_init(argc, argv) starts a private mariadbd, a connection without host goes to it, mysql_server_end() stops it. embedded_app_test is such an application (not built by default). Verified on Windows: it imports only libmariadbd.dll, prints CURRENT_USER() = root@localhost, and leaves no server behind. The ELF variant (version script, constructor) is not built or run yet, and no install rules are added. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PranavKTiwari
pranav.tiwari@mariadb.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *) Problem: Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set. Cause: find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion. Fix: Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: wire the launcher into mysql_server_init() Glue (embedded_glue.c) registers the launcher with libmariadb through mariadb_set_embedded_hooks(), so that the plain client API is enough: mysql_server_init(argc, argv) starts the server, connecting to localhost reaches it, mysql_server_end() stops it. launcher_test now uses only that. Points libmariadb at the MDEV-11111-embedded-hooks branch (57875d2c). That commit exists only locally and must be pushed to the libmariadb repository before this one can be. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher: tests connecting by $MASTER_MYSOCK * mtr: with real grants for tests (root@localhost), as with a normal server. * mysqltest: the launched server's socket becomes $MASTER_MYSOCK, and is not made relative to the tmp directory. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PranavKTiwari
pranav.tiwari@mariadb.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *) Problem: Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set. Cause: find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion. Fix: Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: mtr --embedded-launcher checks the error log; launcher sweeps leftovers * mtr: the per-test check of the error log (include/check-warnings.inc) runs in --embedded-launcher mode too. There is no running mysqld, so the check starts another private server on the datadir the test has left, as mysqltest does for the test, and applies the suppressions that the test stored there with mtr.add_suppression. This replaces the temporary --nowarnings behaviour of this mode. * launcher: an application that is killed cannot remove the private directory (Unix) or the server log (Windows) of its server. Name them with the pid of the application, and remove those of dead applications at the next start. Only the current user's, and not while the pid exists. Linux (WSL, RelWithDebInfo): 286 tests of main and embedded pass, no warnings, no leftover servers or directories. Windows (Debug): 299 tests pass; the only warning is a plugin that is not built there. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server: real grant tables, no credential check --skip-grant-tables, the launcher's default so far, refuses GRANT, CREATE USER and similar, and gives sessions no real identity. Keep the grant tables, and skip only the check of credentials, as the old embedded server did: its only client is the process that has started it, over a private socket or pipe. With --embedded-lifeline: * acl_authenticate(): do_auth_once() reads the client handshake, which gives the user name, and succeeds without running the account's plugin. The account, if it exists, decides the privileges as usual. A name without an account is the root account; if there is no such account either, the connection is refused. * an empty data directory (no mysql.global_priv) starts as with --skip-grant-tables, with a note in the log, instead of failing. The launcher no longer passes --skip-grant-tables; an application can still pass it. mtr --embedded-launcher no longer needs real grants forced. New test embedded.launcher_auth, only for mtr --embedded-launcher: a wrong password is accepted, the privileges of the account are enforced, COM_CHANGE_USER works, and an unknown name is root. Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Vladislav Vaintroub
vvaintroub@gmail.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-11111: embedded server sessions are root@localhost With --skip-grant-tables, Security_context::skip_grants() leaves priv_user and priv_host empty, so CURRENT_USER() is empty and views, routines etc get DEFINER=``. When started with --embedded-lifeline, the only client is the process that spawned the server, so give the session the identity root@localhost (all privileges were already granted). GRANT, CREATE USER etc are still refused by --skip-grant-tables, so mtr --embedded-launcher keeps real grants (MARIADB_EMBEDDED_GRANTS=1). Co-Authored-By: Claude Sonnet 5.5 <[email protected]> |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PranavKTiwari
pranav.tiwari@mariadb.com |
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *) Problem: Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set. Cause: find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion. Fix: Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||