From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from localhost (localhost [127.0.0.1]) by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 456EE30C2C for ; Thu, 6 Dec 2018 01:59:27 -0500 (EST) Received: from turing.freelists.org ([127.0.0.1]) by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B8gThsYKUqHG for ; Thu, 6 Dec 2018 01:59:27 -0500 (EST) Received: from smtpng3.m.smailru.net (smtpng3.m.smailru.net [94.100.177.149]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTPS id 9D05C30C2B for ; Thu, 6 Dec 2018 01:59:26 -0500 (EST) Subject: [tarantool-patches] Re: [PATCH v1 1/1] sql: fix tarantoolSqlite3TupleColumnFast References: From: Kirill Shcherbatov Message-ID: Date: Thu, 6 Dec 2018 09:59:21 +0300 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: tarantool-patches-bounce@freelists.org Errors-to: tarantool-patches-bounce@freelists.org Reply-To: tarantool-patches@freelists.org List-help: List-unsubscribe: List-software: Ecartis version 1.0.0 List-Id: tarantool-patches List-subscribe: List-owner: List-post: List-archive: To: tarantool-patches@freelists.org, Vladislav Shpilevoy Hi! Thank you for research, I've included your conclusions to the commit message. The tarantoolSqlite3TupleColumnFast routine used to lookup offset_slot in unallocated memory in some cases. The assert with exact_field_count same as motivation to change old correct assert with field_count in 7a8de28 is not correct. assert(format->exact_field_count == 0 || fieldno < format->exact_field_count); The tarantoolSqlite3TupleColumnFast routine requires offset_slot that has been allocated during tuple_format_create call. This value is stored in indexed field with index that limited with index_field_count that is <= field_count. Look at tuple_format_alloc for more details. The format in cursor triggering valid assertion has such structure because first 4 tuples in _space: 257, 272, 276 and 280 have an old format of _space with only one field (format->field_count == 1). It happens because these 4 tuples are recovered not after tuple with id 280 which stores actual format of _space. After tuple 280 is recovered, an actual format is set in struct space of _space and all next tuples have full featured formats. So for these 4 tuples tarantoolSqlite3TupleColumnFast can fail even if a field exists, is indexed and has a name. Those features are just described in a newer format. (thank Gerold103 for problem explanation) Closes #3772