Home - Waterfall Grid T-Grid Console Builders Recent Builds Buildslaves Changesources - JSON API - About

Console View


Categories: connectors experimental galera main
Legend:   Passed Failed Warnings Failed Again Running Exception Offline No data

connectors experimental galera main
Vladislav Vaintroub
MDEV-11111: wire the launcher into mysql_server_init()

Glue (embedded_glue.c) registers the launcher with libmariadb through
mariadb_set_embedded_hooks(), so that the plain client API is enough:
mysql_server_init(argc, argv) starts the server, connecting to localhost
reaches it, mysql_server_end() stops it. launcher_test now uses only that.

Points libmariadb at the MDEV-11111-embedded-hooks branch (57875d2c).
That commit exists only locally and must be pushed to the libmariadb
repository before this one can be.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher: no error log warning check

The server exists only while one mysqltest runs, so the per-test check of
the error log (which applies mtr.add_suppression from the tests) cannot
run, and the final scan flagged warnings that tests provoke on purpose.
Disable the check in this mode. ToDo: run check-warnings.inc from
mysqltest before the private server is stopped.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher checks the error log; launcher sweeps leftovers

* mtr: the per-test check of the error log (include/check-warnings.inc)
  runs in --embedded-launcher mode too. There is no running mysqld, so the
  check starts another private server on the datadir the test has left, as
  mysqltest does for the test, and applies the suppressions that the test
  stored there with mtr.add_suppression. This replaces the temporary
  --nowarnings behaviour of this mode.
* launcher: an application that is killed cannot remove the private
  directory (Unix) or the server log (Windows) of its server. Name them
  with the pid of the application, and remove those of dead applications
  at the next start. Only the current user's, and not while the pid exists.

Linux (WSL, RelWithDebInfo): 286 tests of main and embedded pass, no
warnings, no leftover servers or directories. Windows (Debug): 299 tests
pass; the only warning is a plugin that is not built there.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: abstract socket on Linux; only the owning process may connect

* Linux: the embedded server listens on an abstract socket
  (@mariadb-embedded-<pid>-<random>). It has no file system entry, so there
  is no directory to protect or to clean up after a crash. The log of the
  server is a temp file that is unlinked at once (the launcher keeps its fd
  to show the tail on a startup failure). Other Unix systems still use a
  0700 directory.
* New option --embedded-client-pid=<pid>, passed by the launcher: only that
  process may connect. Linux: SO_PEERCRED pid and uid are checked after
  accept(), which is what protects an abstract socket. Windows:
  GetNamedPipeClientProcessId, in addition to the pipe being limited to the
  user. A refused connection is counted in Aborted_connects and noted in
  the error log.

Checked by hand on Linux and Windows: the application connects; another
process of the same user gets the connection closed without a greeting;
after kill -9 of the application there is no server and no file or socket
left on Linux. mtr --embedded-launcher: 286 tests pass on Linux, 300 on
Windows.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
forkfun
MDEV-24684 Quadratic time for MIN/MAX/STD/VARIANCE as window functions

Frame_scan_cursor cleared and re-scanned the whole frame for every row.
Keep the result if the frame did not change (whole-partition frames,
peers), and add only the new rows if just the bottom moved down.
Argument conversion warnings are no longer repeated on each re-scan.
Vladislav Vaintroub
MDEV-11111: launcher: find server next to library, log to file, no-grants default

* Server binary: $MARIADB_EMBEDDED_SERVER, else mariadbd next to the
  library/executable, else PATH.
* Unix: server stdout/stderr go to a file in the private socket directory
  ($MARIADB_EMBEDDED_LOG=stderr keeps the application's stderr); on startup
  failure the tail of that log is added to mariadb_embedded_error().
* Unix: --skip-grant-tables by default, safe as the socket is in a 0700
  directory. $MARIADB_EMBEDDED_GRANTS=1 enables real authentication.
  Windows keeps grants until the pipe ACL is verified.
* Clean up the temp directory on all failure paths.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
Hooks for an embedded server launcher (MDEV-11111)

Add mariadb_set_embedded_hooks(server_init, server_end, socket_name).
A library that spawns a private server (libmariadbd in the server tree)
registers itself with it:

* mysql_server_init(argc, argv, groups) calls server_init once, from the
  same once-only initialization, and returns its result.
* mysql_server_end() calls server_end.
* While socket_name() returns non-NULL, connections to the local host (no
  host, "localhost", or "." on Windows) that do not give a socket use that
  socket, or named pipe on Windows. TCP, remote hosts and explicit
  sockets are unaffected, so there is no need for a "not embedded" option.

Without registered hooks nothing changes.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: build the launcher, use it from mysqltest and mtr

* libmysqld/launcher/CMakeLists.txt: static library
  mariadb_embedded_launcher (client side, no server sources).
* mariadb-test links it; given --server-arg it registers the launcher, so
  the ordinary mysqltest runs the "embedded" server as a private mariadbd.
* mtr: new --embedded-launcher, implies --embedded-server for the test
  selection, but uses the regular mariadb-test and passes the server
  binary in $MARIADB_EMBEDDED_SERVER. The old mariadb-test-embedded path
  is untouched.

Not verified with a full mtr run yet.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher: no error log warning check

The server exists only while one mysqltest runs, so the per-test check of
the error log (which applies mtr.add_suppression from the tests) cannot
run, and the final scan flagged warnings that tests provoke on purpose.
Disable the check in this mode. ToDo: run check-warnings.inc from
mysqltest before the private server is stopped.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: embedded server launcher (phase 1)

Prototype of running the embedded server as a private mariadbd child
process instead of compiling the server into the application with
EMBEDDED_LIBRARY. Running it out of process means the many exit() /
unireg_abort() paths of the server cannot take the application down.

* libmysqld/launcher: mariadb_embedded_start()/stop(). Spawns mariadbd
  (posix_spawnp, or CreateProcess with an explicit handle list on
  Windows) with --skip-networking and a private Unix socket / named
  pipe, waits until it accepts connections, reports early exit.
* mysqld: new option --embedded-lifeline=<fd|HANDLE>. A thread blocks on
  the inherited pipe and starts a normal shutdown on EOF, i.e. when the
  client stops the server or dies. No PDEATHSIG (fires on thread exit)
  and no kill-on-close job object (would beat the graceful shutdown).

Not yet wired into mysql_server_init()/mysql_server_end(), and the old
libmysqld build is untouched.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
PranavKTiwari
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *)

Problem:
Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set.
Cause:
find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion.
Fix:
The fix uses a local bitmap instead of tmp_set for the virtual column dependency walk in TABLE::update_virtual_field(), so the active read_set/write_set is not touched.
Vladislav Vaintroub
MDEV-11111: embedded server launcher (phase 1)

Prototype of running the embedded server as a private mariadbd child
process instead of compiling the server into the application with
EMBEDDED_LIBRARY. Running it out of process means the many exit() /
unireg_abort() paths of the server cannot take the application down.

* libmysqld/launcher: mariadb_embedded_start()/stop(). Spawns mariadbd
  (posix_spawnp, or CreateProcess with an explicit handle list on
  Windows) with --skip-networking and a private Unix socket / named
  pipe, waits until it accepts connections, reports early exit.
* mysqld: new option --embedded-lifeline=<fd|HANDLE>. A thread blocks on
  the inherited pipe and starts a normal shutdown on EOF, i.e. when the
  client stops the server or dies. No PDEATHSIG (fires on thread exit)
  and no kill-on-close job object (would beat the graceful shutdown).

Not yet wired into mysql_server_init()/mysql_server_end(), and the old
libmysqld build is untouched.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: restrict the embedded server's named pipe to its own user

Normally the pipe gives Everyone read/write access. When started with
--embedded-lifeline the DACL only has the current user, so that the
launcher can default to --skip-grant-tables on Windows as well as Unix
(where the socket directory is 0700). Verified on a running server: the
DACL is a single ACE for the user's SID.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher runs a test

* launcher, Windows: send the server's stdout/stderr to a log file (as on
  Unix) and add its tail to the startup error, so that a failing option
  is visible instead of just "status 1".
* mtr: with --embedded-launcher pass the [mysqld.1] options via
  --defaults-group-suffix (the real server does not read [embedded]), use
  the regular client-test binary and DLL paths.
* mysqltest: after starting the private server, default connections use
  its socket/pipe, not the socket and port from the option files.

main.1st passes on Windows with --embedded-launcher.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
Embedded hooks: a socket equal to the embedded server's counts as embedded

When the application passes the embedded server's own socket (e.g. as the
default socket of a test client), "localhost" must still reach it on
Windows, where "localhost" alone would otherwise select TCP.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: embedded server: real grant tables, no credential check

--skip-grant-tables, the launcher's default so far, refuses GRANT, CREATE
USER and similar, and gives sessions no real identity. Keep the grant
tables, and skip only the check of credentials, as the old embedded server
did: its only client is the process that has started it, over a private
socket or pipe.

With --embedded-lifeline:
* acl_authenticate(): do_auth_once() reads the client handshake, which
  gives the user name, and succeeds without running the account's plugin.
  The account, if it exists, decides the privileges as usual. A name
  without an account is the root account; if there is no such account
  either, the connection is refused.
* an empty data directory (no mysql.global_priv) starts as with
  --skip-grant-tables, with a note in the log, instead of failing.

The launcher no longer passes --skip-grant-tables; an application can
still pass it. mtr --embedded-launcher no longer needs real grants forced.

New test embedded.launcher_auth, only for mtr --embedded-launcher: a wrong
password is accepted, the privileges of the account are enforced,
COM_CHANGE_USER works, and an unknown name is root.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher runs a test

* launcher, Windows: send the server's stdout/stderr to a log file (as on
  Unix) and add its tail to the startup error, so that a failing option
  is visible instead of just "status 1".
* mtr: with --embedded-launcher pass the [mysqld.1] options via
  --defaults-group-suffix (the real server does not read [embedded]), use
  the regular client-test binary and DLL paths.
* mysqltest: after starting the private server, default connections use
  its socket/pipe, not the socket and port from the option files.

main.1st passes on Windows with --embedded-launcher.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: abstract socket on Linux; only the owning process may connect

* Linux: the embedded server listens on an abstract socket
  (@mariadb-embedded-<pid>-<random>). It has no file system entry, so there
  is no directory to protect or to clean up after a crash. The log of the
  server is a temp file that is unlinked at once (the launcher keeps its fd
  to show the tail on a startup failure). Other Unix systems still use a
  0700 directory.
* New option --embedded-client-pid=<pid>, passed by the launcher: only that
  process may connect. Linux: SO_PEERCRED pid and uid are checked after
  accept(), which is what protects an abstract socket. Windows:
  GetNamedPipeClientProcessId, in addition to the pipe being limited to the
  user. A refused connection is counted in Aborted_connects and noted in
  the error log.

Checked by hand on Linux and Windows: the application connects; another
process of the same user gets the connection closed without a greeting;
after kill -9 of the application there is no server and no file or socket
left on Linux. mtr --embedded-launcher: 286 tests pass on Linux, 300 on
Windows.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-33387 - multifactor authentication

Support "AND" between authentication plugins in CREATE/ALTER USER, so
that a user must pass every factor to log in (multi-factor auth), in
addition to the existing "OR" (alternative plugins). Mixing AND and OR
in one user definition is rejected.

  CREATE USER u IDENTIFIED VIA mysql_native_password AS PASSWORD('...')
                      AND some_other_plugin USING '...';

Grammar and storage
  - USER_AUTH gets a logical_operator (NONE/OR/AND) telling how each factor
    combines with the next; the parser tags the factor list and rejects a
    mix of AND/OR.
  - The operator is persisted in mysql.global_priv: the factor array is
    stored under "auth_and" (mirroring the existing "auth_or"). ALTER USER
    that collapses a multi-factor account back to a single plugin removes
    the stale "auth_and"/"auth_or" key.
  - SHOW CREATE USER prints " AND " between factors.
  - Two password-based (hashing) plugins in one AND chain are rejected;
    at most one factor may carry a password hash.

Authentication protocol
  - New client capability CLIENT_MULTI_FACTOR_AUTHENTICATION and an
    AuthNextFactor (0x02) command that tells the client to proceed to the
    next factor after the current one succeeded. send_plugin_request_packet
    becomes send_change_plugin_packet, handling both the auth-switch (0xFE)
    and next-factor (0x02) commands. Clients that do not announce the
    capability fall back to an auth switch.
  - acl_authenticate() runs the factors sequentially for AND (every factor
    must return CR_OK), while OR keeps its "first success wins" behavior.
  - The in-server client (sql-common/client.c, used by mariadb-backup,
    replication, etc.) also handles AuthNextFactor: it advertises the new
    capability, recognises the 0x02 packet in run_plugin_auth(), and uses
    the same is_auth_switch_command() helper (with AUTH_SWITCH_PLUGIN_PACKET
    and AUTH_NEXT_FACTOR_PACKET symbolic constants) as libmariadb does.

TLS server-identity via password hash
  - When the connection uses a self-signed certificate and no CA is
    configured, the server sends a fingerprint challenge in the OK packet,
    computed from the certificate fingerprint and the password hash. For a
    multi-factor account the salt of the first password-hashing factor is
    used. The client recomputes it and, on a match, trusts the certificate
    even with --ssl-verify-server-cert, so password-based verification of
    the server does not raise a certificate error.

Tests
  - New plugins suite tests: mfa (portable machinery: AuthNextFactor round
    trip, non-hashing factor, auth_and persistence and ALTER round-trip,
    distinct per-factor secrets, negative cases, TLS fingerprint),
    mfa_unix (unix_socket + password), mfa_win (named_pipe/gssapi +
    password), mfa_unix_pam (password + PAM PIN).
  - auth_gssapi multiauth trimmed to the OR cases it still owns.

Client side changes are in the bundled libmariadb (submodule bump).

Assisted-by: Claude:claude-haiku-4.5-20251001
Vladislav Vaintroub
MDEV-11111: build the launcher, use it from mysqltest and mtr

* libmysqld/launcher/CMakeLists.txt: static library
  mariadb_embedded_launcher (client side, no server sources).
* mariadb-test links it; given --server-arg it registers the launcher, so
  the ordinary mysqltest runs the "embedded" server as a private mariadbd.
* mtr: new --embedded-launcher, implies --embedded-server for the test
  selection, but uses the regular mariadb-test and passes the server
  binary in $MARIADB_EMBEDDED_SERVER. The old mariadb-test-embedded path
  is untouched.

Not verified with a full mtr run yet.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: embedded server sessions are root@localhost

With --skip-grant-tables, Security_context::skip_grants() leaves priv_user
and priv_host empty, so CURRENT_USER() is empty and views, routines etc get
DEFINER=``. When started with --embedded-lifeline, the only client is the
process that spawned the server, so give the session the identity
root@localhost (all privileges were already granted).

GRANT, CREATE USER etc are still refused by --skip-grant-tables, so mtr
--embedded-launcher keeps real grants (MARIADB_EMBEDDED_GRANTS=1).

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: launcher: find server next to library, log to file, no-grants default

* Server binary: $MARIADB_EMBEDDED_SERVER, else mariadbd next to the
  library/executable, else PATH.
* Unix: server stdout/stderr go to a file in the private socket directory
  ($MARIADB_EMBEDDED_LOG=stderr keeps the application's stderr); on startup
  failure the tail of that log is added to mariadb_embedded_error().
* Unix: --skip-grant-tables by default, safe as the socket is in a 0700
  directory. $MARIADB_EMBEDDED_GRANTS=1 enables real authentication.
  Windows keeps grants until the pipe ACL is verified.
* Clean up the temp directory on all failure paths.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher: tests connecting by $MASTER_MYSOCK

* mtr: with real grants for tests (root@localhost), as with a normal server.
* mysqltest: the launched server's socket becomes $MASTER_MYSOCK, and is
  not made relative to the tmp directory.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Dave Gosselin
MDEV-31180:  MyISAMMRG Crash on UPDATE of an updateable VIEW

Attach the children of a MERGE table once per statement, and keep the
value of pos_in_table_list for a MERGE table on subsequent executions
of a prepared statement.
Vladislav Vaintroub
MDEV-11111: libmariadbd, a shared client library with the embedded server

Build libmariadbd (.dll / .so) from the same objects and the same export
list as libmariadb, plus the launcher. Loading it registers the launcher
with the client library (DllMain / constructor), so an application links
libmariadbd instead of libmariadb and uses only the client API:
mysql_server_init(argc, argv) starts a private mariadbd, a connection
without host goes to it, mysql_server_end() stops it.

embedded_app_test is such an application (not built by default).
Verified on Windows: it imports only libmariadbd.dll, prints
CURRENT_USER() = root@localhost, and leaves no server behind.
The ELF variant (version script, constructor) is not built or run yet,
and no install rules are added.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: update libmariadb (embedded socket match)

Points libmariadb at 5a29ab9e. Local commit in the libmariadb repository,
must be pushed first.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
forkfun
MDEV-24684 Quadratic time for MIN/MAX/STD/VARIANCE as window functions

Frame_scan_cursor cleared and re-scanned the whole frame for every row.
Keep the result if the frame did not change (whole-partition frames,
peers), and add only the new rows if just the bottom moved down.
Argument conversion warnings are no longer repeated on each re-scan.
Vladislav Vaintroub
Embedded hooks: a socket equal to the embedded server's counts as embedded

When the application passes the embedded server's own socket (e.g. as the
default socket of a test client), "localhost" must still reach it on
Windows, where "localhost" alone would otherwise select TCP.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
Hooks for an embedded server launcher (MDEV-11111)

Add mariadb_set_embedded_hooks(server_init, server_end, socket_name).
A library that spawns a private server (libmariadbd in the server tree)
registers itself with it:

* mysql_server_init(argc, argv, groups) calls server_init once, from the
  same once-only initialization, and returns its result.
* mysql_server_end() calls server_end.
* While socket_name() returns non-NULL, connections to the local host (no
  host, "localhost", or "." on Windows) that do not give a socket use that
  socket, or named pipe on Windows. TCP, remote hosts and explicit
  sockets are unaffected, so there is no need for a "not embedded" option.

Without registered hooks nothing changes.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: update libmariadb (embedded socket match)

Points libmariadb at 5a29ab9e. Local commit in the libmariadb repository,
must be pushed first.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: restrict the embedded server's named pipe to its own user

Normally the pipe gives Everyone read/write access. When started with
--embedded-lifeline the DACL only has the current user, so that the
launcher can default to --skip-grant-tables on Windows as well as Unix
(where the socket directory is 0700). Verified on a running server: the
DACL is a single ACE for the user's SID.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: libmariadbd, a shared client library with the embedded server

Build libmariadbd (.dll / .so) from the same objects and the same export
list as libmariadb, plus the launcher. Loading it registers the launcher
with the client library (DllMain / constructor), so an application links
libmariadbd instead of libmariadb and uses only the client API:
mysql_server_init(argc, argv) starts a private mariadbd, a connection
without host goes to it, mysql_server_end() stops it.

embedded_app_test is such an application (not built by default).
Verified on Windows: it imports only libmariadbd.dll, prints
CURRENT_USER() = root@localhost, and leaves no server behind.
The ELF variant (version script, constructor) is not built or run yet,
and no install rules are added.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
PranavKTiwari
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *)

Problem:
Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set.
Cause:
find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion.
Fix:
Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path.
Vladislav Vaintroub
MDEV-11111: wire the launcher into mysql_server_init()

Glue (embedded_glue.c) registers the launcher with libmariadb through
mariadb_set_embedded_hooks(), so that the plain client API is enough:
mysql_server_init(argc, argv) starts the server, connecting to localhost
reaches it, mysql_server_end() stops it. launcher_test now uses only that.

Points libmariadb at the MDEV-11111-embedded-hooks branch (57875d2c).
That commit exists only locally and must be pushed to the libmariadb
repository before this one can be.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher: tests connecting by $MASTER_MYSOCK

* mtr: with real grants for tests (root@localhost), as with a normal server.
* mysqltest: the launched server's socket becomes $MASTER_MYSOCK, and is
  not made relative to the tmp directory.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
PranavKTiwari
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *)

Problem:
Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set.
Cause:
find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion.
Fix:
Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path.
Vladislav Vaintroub
MDEV-11111: mtr --embedded-launcher checks the error log; launcher sweeps leftovers

* mtr: the per-test check of the error log (include/check-warnings.inc)
  runs in --embedded-launcher mode too. There is no running mysqld, so the
  check starts another private server on the datadir the test has left, as
  mysqltest does for the test, and applies the suppressions that the test
  stored there with mtr.add_suppression. This replaces the temporary
  --nowarnings behaviour of this mode.
* launcher: an application that is killed cannot remove the private
  directory (Unix) or the server log (Windows) of its server. Name them
  with the pid of the application, and remove those of dead applications
  at the next start. Only the current user's, and not while the pid exists.

Linux (WSL, RelWithDebInfo): 286 tests of main and embedded pass, no
warnings, no leftover servers or directories. Windows (Debug): 299 tests
pass; the only warning is a plugin that is not built there.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: embedded server: real grant tables, no credential check

--skip-grant-tables, the launcher's default so far, refuses GRANT, CREATE
USER and similar, and gives sessions no real identity. Keep the grant
tables, and skip only the check of credentials, as the old embedded server
did: its only client is the process that has started it, over a private
socket or pipe.

With --embedded-lifeline:
* acl_authenticate(): do_auth_once() reads the client handshake, which
  gives the user name, and succeeds without running the account's plugin.
  The account, if it exists, decides the privileges as usual. A name
  without an account is the root account; if there is no such account
  either, the connection is refused.
* an empty data directory (no mysql.global_priv) starts as with
  --skip-grant-tables, with a note in the log, instead of failing.

The launcher no longer passes --skip-grant-tables; an application can
still pass it. mtr --embedded-launcher no longer needs real grants forced.

New test embedded.launcher_auth, only for mtr --embedded-launcher: a wrong
password is accepted, the privileges of the account are enforced,
COM_CHANGE_USER works, and an unknown name is root.

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Vladislav Vaintroub
MDEV-11111: embedded server sessions are root@localhost

With --skip-grant-tables, Security_context::skip_grants() leaves priv_user
and priv_host empty, so CURRENT_USER() is empty and views, routines etc get
DEFINER=``. When started with --embedded-lifeline, the only client is the
process that spawned the server, so give the session the identity
root@localhost (all privileges were already granted).

GRANT, CREATE USER etc are still refused by --skip-grant-tables, so mtr
--embedded-launcher keeps real grants (MARIADB_EMBEDDED_GRANTS=1).

Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
PranavKTiwari
MDEV-36896 : Assertion 'marked_for_read()' failed in virtual String *Field_varstring::val_str(String *, String *)

Problem:
Executing queries that require virtual/generated column evaluation during filesort trigger debug assertions due to missing columns in read_set.
Cause:
find_all_keys() temporarily assigns TABLE::tmp_set as both read_set and write_set. Later, TABLE::update_virtual_field() calls bitmap_clear_all(&tmp_set) before evaluating virtual column dependencies. Since all three pointers share the same underlying bitmap buffer, clearing tmp_set also clears the active read_set/write_set, causing required columns to appear missing during execution and triggering the assertion.
Fix:
Before clearing tmp_set in TABLE::update_virtual_field(), save its current state into a stack-allocated bitmap clone using my_safe_alloca + bitmap_copy. After virtual column evaluation is complete, restore tmp_set to its original state before returning. This preserves whatever bits were live in the shared buffer (i.e. the active read_set/write_set) across the call, while still allowing the dependency walk to use tmp_set as scratch space as before. my_safe_alloca is used instead of heap allocation to keep this save/restore overhead minimal on what is a per-row hot path.