From f8937f9034e4df499734ec7bb330616a49ad6d1f Mon Sep 17 00:00:00 2001 From: drh Date: Sun, 23 Sep 2018 02:01:42 +0000 Subject: [PATCH] Fix a faulty assert() in the validation logic for the LEFT JOIN strength reduction optimization. Problem found by OSSFuzz. FossilOrigin-Name: 2fd62fccd13e326dbd7dd730112542c6faa56e466bf4f7b8e22ced543031280c --- manifest | 14 +++++++------- manifest.uuid | 2 +- src/expr.c | 15 ++++++--------- test/fuzzdata5.db | Bin 7197696 -> 7197696 bytes 4 files changed, 14 insertions(+), 17 deletions(-) diff --git a/manifest b/manifest index 71ed8fba04..d693735ef8 100644 --- a/manifest +++ b/manifest @@ -1,5 +1,5 @@ -C Enhance\sWhereLoopBuilder.iPlanLimit\sto\shandle\sa\scase\sinvolving\sthe\sOR\noptimization\sdiscovered\sovernight\sby\sOSSFuzz. -D 2018-09-22T15:05:32.605 +C Fix\sa\sfaulty\sassert()\sin\sthe\svalidation\slogic\sfor\sthe\sLEFT\sJOIN\sstrength\nreduction\soptimization.\s\sProblem\sfound\sby\sOSSFuzz. +D 2018-09-23T02:01:42.716 F .fossil-settings/empty-dirs dbb81e8fc0401ac46a1491ab34a7f2c7c0452f2f06b54ebb845d024ca8283ef1 F .fossil-settings/ignore-glob 35175cdfcf539b2318cb04a9901442804be81cd677d8b889fcc9149c21f239ea F Makefile.in 01e95208a78b57d056131382c493c963518f36da4c42b12a97eb324401b3a334 @@ -454,7 +454,7 @@ F src/date.c ebe1dc7c8a347117bb02570f1a931c62dd78f4a2b1b516f4837d45b7d6426957 F src/dbpage.c 4aa7f26198934dbd002e69418220eae3dbc71b010bbac32bd78faf86b52ce6c3 F src/dbstat.c edabb82611143727511a45ca0859b8cd037851ebe756ae3db289859dd18b6f91 F src/delete.c 107e28d3ef8bd72fd11953374ca9107cd74e8b09c3ded076a6048742d26ce7d2 -F src/expr.c 610eea078f240e8d55e81666a65b05a42e52008d24059c59093dd18b3d15b565 +F src/expr.c cd7a294bff49641032e2a5511a8e77bfa7e71fd0a2f714de8f3c560d31d273d9 F src/fault.c 460f3e55994363812d9d60844b2a6de88826e007 F src/fkey.c 972a4ba14296bef2303a0abbad1e3d82bc3c61f9e6ce4e8e9528bdee68748812 F src/func.c 7c288b4ce309b5a8b8473514b88e1f8e69a80134509a8c0db8e39c858e367e7f @@ -967,7 +967,7 @@ F test/fuzzdata1.db 7ee3227bad0e7ccdeb08a9e6822916777073c664 F test/fuzzdata2.db 128b3feeb78918d075c9b14b48610145a0dd4c8d6f1ca7c2870c7e425f5bf31f F test/fuzzdata3.db c6586d3e3cef0fbc18108f9bb649aa77bfc38aba F test/fuzzdata4.db b502c7d5498261715812dd8b3c2005bad08b3a26e6489414bd13926cd3e42ed2 -F test/fuzzdata5.db 181aa05f8ca1e4f43a3618ddd4193dfca4499e81bbb9b3e03bce46961a670891 +F test/fuzzdata5.db e35f64af17ec48926481cfaf3b3855e436bd40d1cfe2d59a9474cb4b748a52a5 F test/fuzzdata6.db 92a80e4afc172c24f662a10a612d188fb272de4a9bd19e017927c95f737de6d7 F test/fuzzer1.test 3d4c4b7e547aba5e5511a2991e3e3d07166cfbb8 F test/fuzzer2.test a85ef814ce071293bce1ad8dffa217cbbaad4c14 @@ -1769,7 +1769,7 @@ F vsixtest/vsixtest.tcl 6a9a6ab600c25a91a7acc6293828957a386a8a93 F vsixtest/vsixtest.vcxproj.data 2ed517e100c66dc455b492e1a33350c1b20fbcdc F vsixtest/vsixtest.vcxproj.filters 37e51ffedcdb064aad6ff33b6148725226cd608e F vsixtest/vsixtest_TemporaryKey.pfx e5b1b036facdb453873e7084e1cae9102ccc67a0 -P 50f2fa19532e0f849d61d9e2a97427cfbf64cfb787ca481ef8c860d0f24f6cfe -R a522b9d1d3efe4bffcf66fba31076dce +P 7b59930a1d7b664b54d5a2bc9fa385925b5f4c8f34bf401c798307e3e2dae2c6 +R f03877dafbf8630475fd3e62d89e76e5 U drh -Z cead1160ed2d9cc4ef006a761294eca9 +Z b1773f19e1d7fe0cd47b4aa3fa8da701 diff --git a/manifest.uuid b/manifest.uuid index 490bf19931..f4bb602f2d 100644 --- a/manifest.uuid +++ b/manifest.uuid @@ -1 +1 @@ -7b59930a1d7b664b54d5a2bc9fa385925b5f4c8f34bf401c798307e3e2dae2c6 \ No newline at end of file +2fd62fccd13e326dbd7dd730112542c6faa56e466bf4f7b8e22ced543031280c \ No newline at end of file diff --git a/src/expr.c b/src/expr.c index 1692822840..fa0bcd86af 100644 --- a/src/expr.c +++ b/src/expr.c @@ -4849,18 +4849,15 @@ int sqlite3ExprImpliesExpr(Parse *pParse, Expr *pE1, Expr *pE2, int iTab){ /* ** This is the Expr node callback for sqlite3ExprImpliesNotNullRow(). ** If the expression node requires that the table at pWalker->iCur -** have a non-NULL column, then set pWalker->eCode to 1 and abort. +** have one or more non-NULL column, then set pWalker->eCode to 1 and abort. +** +** This routine controls an optimization. False positives (setting +** pWalker->eCode to 1 when it should not be) are deadly, but false-negatives +** (never setting pWalker->eCode) is a harmless missed optimization. */ static int impliesNotNullRow(Walker *pWalker, Expr *pExpr){ - /* This routine is only called for WHERE clause expressions and so it - ** cannot have any TK_AGG_COLUMN entries because those are only found - ** in HAVING clauses. We can get a TK_AGG_FUNCTION in a WHERE clause, - ** but that is an illegal construct and the query will be rejected at - ** a later stage of processing, so the TK_AGG_FUNCTION case does not - ** need to be considered here. */ - assert( pExpr->op!=TK_AGG_COLUMN ); + testcase( pExpr->op==TK_AGG_COLUMN ); testcase( pExpr->op==TK_AGG_FUNCTION ); - if( ExprHasProperty(pExpr, EP_FromJoin) ) return WRC_Prune; switch( pExpr->op ){ case TK_ISNOT: diff --git a/test/fuzzdata5.db b/test/fuzzdata5.db index 2cf125414c6da8a566a947a6caa4a73b4fcd66fb..cfb0ebe7d8cf01899814f38e21c30b62acd9184c 100644 GIT binary patch delta 6146 zc-pO4dstN0wLg3290m{=k;m{58D4>5c+7x`Jd`(r%2Ny~J~kpEo3j-KRD6J-Tk~qv z*tpWf_=wkN(%u-8)N^YZgL6(^jegfWn)LQ-Z%x~q-mgusNpIWRv?knjAcFSm{qN2< z^P7EsYpuQaTKl#3*?V5I?#18X*ob^ditU%CK9Ts7;k12$`$&UK@`tIQL{N*MRzYP! z6+!(3wF&AkXn>%Bf=&}ONYG$GLj<)8I$h9EL1zdWCTO^z5rRev>JT(a&}czp1dSDR zrl4_x&Jr|UP^X{?f+h-@BxtgrDT3Z7XsV!Tg1Q7v7t}3ihM<{(W(k@ts7Fw*pgDr( z3OZZRIfBj=G*8fZg60caAZVeWMS{*3bb+A7f|dwcDrlLY<$_iSS}ACipbG`97PLmt zMS?CCbcvv~g4PLIFKC0Hje<4_x>V3+L6-@7zo0FGE*Er#peqG!6?B!Ls|8&n=vqNB zK5c@o6SQ5>^@4T?xSURa+{qjy!z@=2Hw<^O7?KXh z@o)7?pG%g8^OsgGsVr}Hwr}p=)R*S!+LYE((_HOrca|e9+xE!CAxm5GTiQ6dt~-@l)19> zz%)}O4pwxs=`hyElC;zT_7YL%$kP5sQ{>S8w396+sl`?)<(r;3+Y;~dg!&d(rEh$2 z4i+>NmeSIBzWLC(n-!8GIJ2AWCxwuRzT)3ON4I^ zvn1GR8eSh}*<>+%HOx|!MQ9UnYy{c)BP?C6u}aJEDFXJ6uu!?$DplfB_%xTRFvFXc z;Z5}|gjYtGi&VkCkFZp^(kkV_C#WHN<9rp6u#d%)awy%$Qj*K8QqqJssfDS9g?3-* zRAk&{WVZQA;Guo&nxow+Wljjva6s$wGrTTugl`@2{mfC{W|h3(2vLwRjxMj=M<;6= z=aE@^FOy;St+|JBVeePN2m7)2tKh5sER(c?Td*{;5}E~@O;*5zf+dsX@Pa^D3;ay5 z401mN96)jzWF26CCC%VE$QCI}F=o@uI48sLgDg&I!spP*X9s+FkbUUcG}*Y@?JaW8 zw)^;941WIdWR6djrB}KpIPe}~PM~jhhH0J$nT?QcnD-DXAq)l{!u8VyR~}+(W^9~{ zYWlA)fBexLUngWe%<{+v*zhn*CmnF)VU{niw@OSvHnI)zVO?D(n{t+&#&)#K$P%_Gbh`;Gt4E*9K z4}#uN7E5f}p;30mqWHbQJnvPUC+9Q$v`hNrdTPHm}18FdAshu zmvP$l^eLvauA<-xyY9M&$wVe?=pM?A;Yyui^3$kApPo|Gw-+3DkbPM%_N zbH{a(?qYJrnZzl^bPK&muu4OBC|otg&S2eXl@cZybRvGzs35<{TjaItv+iPW|82JG zaZ}9fjASqB%$#Dp1vv$%6FbRd&^dE%&b^z#nV7H7fwr4?!p(-KZ?b%n3m@NPMd3M< zYOQUn@%wa*?$uI1VGmkKfp+oNEX_jlwV!^mzFPER$DOkb>VYSdI=si z6NIy;t+QioZ`aO_aZ!MdXKwU_C`8B8HfdQyMQL-Tvn^xYm|dSg-llqIB4GE6?qQNV z!$04t7b?=eSGP~FX6~V#9qm35uawEs*YmaaKJ88-u=#g6esJRToTU)IA-7EP`(<~V zMX8Xb2N#+OK}6f}AKlG_lxx>N?fzvbS*X4Em+ovrstA=fNs#Zk zD?fbx`In55T)o<)1ToM3M=^y7QNIl*?5geie^9$+(x|Ob)HXsIv{64b(gN2))E@(l zRYQUMsf%sPnws`))tj`CKsCjJ#~do}f(t?Fr+C&~4^hv@ zJZ)>3dXgwB@%UM6DzyNQP~TNn++(y-!`iYeWHro>R(bfUspu3YCT2SKm+7tAm1y;) z5VBs|lBQyS+aWt$bwE)|QvkfyTVaEqHZ{gprLP-5or{ONB92{X41v9Gx@0KIR>R=u zFBSP)OZ7I>t{k$`Rm_nPVlk0$-)XCGqJY6(gWc_hiz(5O+Hca;s|kJ`iZuL4mqy#v z;}*EFPVIud9<@fhU9YYUB^$I=ZK_os+J$NNR$~Bhi_wb6jAq0xqXu!KQH;33Sb*4J znAfEBMh;@Tk&U>{$U12MyxZU5EmN`#A*X?VzE_51Y(5|j#y@dAr=`k5OWMWqQ?kC%r*iL zGYx;l48w-#HvACN3>h)iup-`PSP)YTyxhem>t?%2`k*u<#U|=|@F77rBjMC{BF5`m z5ohTfai-ph7_DzW4A(mlr|JKXmztq}e5*mcsH0CY7jy;j1>ZKr=Y741&-u0>p7-@2 zp7U)+JmcGh_>8X|@w5*cjydJSfr~lmn~QkDHyiP39}Zm1ai3ZLQ$8HNm?wQWd@)*U zr@GQl>6E4K1OU#I58?31iiP0WtTw}o-D>Tzmn%xZbE%?AyS-UGFU#EA93DB!li^yQ z8ctOBq)#oxOfarrt;0<4V!xUVPxY%2m=0pOQrRd=PuR?g8{x(Gil@W$m&-%o)Dsom z+K;!XCx~O~)Uqk7Tv$_At#28>Bb?r$W`c7EcUa5x9(ZquS^+n9s70`MYo*O!B7iOk7-)(H+FO~UeRn{;W|4QIEnMBL&JA8r=yZ-RjbV#E09SUa0$$s#Ho@b2)LePH zsTO)bje>w@qobhYkR!scK*ywU7c>f<3Jo7SY(bMX6zcuZIH=AieQ;<{T||1dpAM>3 z7P3oA7*;=%$sPzffV;!)@r#!CfEurTbwKr6$RLcK$2FHVs5&&-7xfs?N*`98L~A>& z+AP|}N7cU&KLeA-M@u2$Bge~H^bz&DvSKk;v4(^{fm`RA{bA@a9`8RQ8<=nI4?c$i za_I>*ix8`Z)rS(TnQKU3>Ni=xQVX`9(jJKX-R zT8>Fy$@kPeS@uUeGZgXK-oB_Di+1fLb*{e>AWKI#o7#VZ+pns-u9D~(}&vax74%AWX6P1F`W2JJrgkh zkq~1#PLTxdiyx{X7VY*e^=5<|hK$zM7c~0rex<3wg&KF_|^{lZ`a9=YLl_lzi;irLkV_4kQ`c^+6s-py4CO^uXfrH9nGSxJ@?1 zs$`D){oWvt9@mJ|BKPqq3&}E9O(MK_$l)-T&UEc_!F>cgUo6-GFCFB2NVevAfIDOv zQ?(j6@i=!tNnW!}9$sL0fj`2p63_oxLyETc5Qas&c8o_6_}MWv&ZZdiFsyd)e&jd` zp2v6($%E66@kMazF`fjTYj|GcZeX`o8*?Db~6NOH9+NBMQ4EWoX#1+IR+ zU?zO;alTl_WNy#oV*ogh@d#36)))pg$9NtogyCa+F(#AOkMWg?QY=d+Q=s$=kA~-u z^JJ~-IDglw)L@qq;OZ&f4>wNn4JIVQ=xHA8KkR2zAYLY~{rRKwWk#8) zQvpS1xEsEAhR4Vy-_((y{q77uOGq;uIm_F~Quyz)yw%=hmEz17VnNG;md`XAVfC|o zR!W0aab!4fvxISki}r??#pp{7SN&~rTG(s`Z~MOq>e zeh=dsSYoumkx^cUDdf#j9N%SH<5iwuB?HiF@HDamjvG8LZM#*99lTvgZhcc=Bt(|A}G;js8%UrRbXpiu+fdtS`}DY zSGr`y%F4iSgW=V`^-dpZ>XtTFmR7ii{f#c12@$PLmF1A|Ca2JIDPbB6zsVhb8?91p zYvIu??NLJo^*dXdZ`h1Zti9D)kl=4@!0}nW?NolCztLe9Q=6+RZN_?(FHfyZbr|hd zY0mQ0>~y&M;~aAZ8tX7drUV}Xj5fT|EKg0XOi8jCblljvV6K6gY43ROFLtE;KBMRN zFy}4qB5PpnTYM#E%9r25Epe6hi?{eW*>9J5VEW+dHC_r0XT$O8a*b!3-~#t`F33*p z;&q-QM_VwY=(ztI1iSm^pN#!vEcXq`D)C#e>3tpvGv4R1WC*g}=kxH$?R=jv^4o)f aA>%ctL;D9jA7Vb>(SCS9?~9vapZ;GUQV<3J delta 6106 zc-pO4d013Ow!hVVFAa#a2-qwl%@%07fo@O{P+1#sVHHKirEmc$ZYc^HaREU~%{Fd{ zCyQ~3pE1eI8)K63PRzt$-t1kD!IEvQG(96@sh%@foss87&* zK??+(F6azFX9`*<=qy2t1T7Y{M9|rS&JlF3prwMA30f{_g`ky!Rtf4Cv|7-4g4PH+ zU(f}DE);Z;ptXY530f~`gP@IqHVL{|&}KoG2)b0z7D1N@x?Io|g0>2}QqWa`t`>BS zpqQUFLDvepPSEv&ZVAlI$nt0MsumSNo+Y6}1%Vt{+TR6VY-2OQ+s-mhbh2Zxq@7j4ui9B|oX_RP z%eiIS=H3liKGz&yq1QLPBH)HkP-SYiRVrNUU*xZBc6M*=+|=8i}<+OZOU^aB@W+kKq&h2LVNik&YVe?~(#!Q{P zUi=Jh3(Nwshy6DxggyPNp3Ky4^s_^RG(hekn*#41WRszPFPlp0;fcL$o>C`EgRyXW zFDoUfpboMus2^l$pqa{t23a0i2tOWVRb&BtJ;*YY`KTUtVhDwEhFG>-W0jWRQ!MNq zVo~xutK`S0mE%`_Z8VU~lFX74d!TGQDQ+_<+XJO=|2}p-daYH;85Lx;)cEU)JU$l;?q?3zyPwJR z)GGPDm7>HGM3>JVSTojKkVj_q-HgW`SalcULibm~2m8_eR`_~9%ONYkEm#&=4$Xp1 zC(GbI!O}?!{7|55Df~h(4_N|X2as%r+ym_IWHGo7vIR;LCT)V5<8(NAkR>UN_#8F% z?0~NhvJbs{taG>9H`_hk9#HRK@cP^1`GGE3dZ}}i1K(lh1o~D-wC25!*$81U>wZ>7 zI-&1=9IuUV^?tT`a>rO&vww5t3c13>O5Nq-A}Wvn)fmGx}t2xc^f~*9s}=b7Ioqb`@ohE@UVAm$2D@IyFbNFfk0N14lT29xq+MZok%0jul+iwO zvfyaQlo;r}!cw#Q$6U$D@_H`0Vgh@tQrtB53_R?MUka_$#(>MQD-)I4K?tQWk7?DOV7Jk znM?abXEpNt*zqn)J-(b$yB>2lGt;g|-^qA$ymo!^I8$KiH0V*#{T6Ei>)R{`ZoS1~ zh<((-HNyzA-bRlj&4eTIHghWzWof7b8i#QnI)@xSxcN3)O(M(~iy`G5mI-Hm$_ABi z)T$lTs(yzJ!Q^3<3x9owwJLeC1TEnH6vG&}&fXvcxnmBMKIADaI%L;#?qWO`m}i`s zx2V1X8TU9--Be$jW!JOsW}J52HO`dRRTV#K*R$?oa*)X!xQlXQhVB_>in7t6NIhfh zg+j(`Cw*LHdUnv~v~i}OAgGgi2a_LUQpOoGER4cwl?J|}@HHuQPSlgFQpy;EK};Jn zDlVGso9(mfNp~=~;x^m$spHIaPr46v62}=|aeguCB#be+MR~qF)QJx=d81UeH`_Z= zj~nYe*PDx}aEu#y-Lu@Y?D`b#%YS7>lL`yRB>m=vx--Wa49=X6Gwx(?@)haRq3tGa zX9e)&O;$wm;p3ZZc8qUKt+j0xex97Kd$r6@*?m@0q+R+A%d(JJ+Rr~{i~fB8_lLBl z<&{g8)E19?Q}S$_UW%K`DB)5cSr*r3qpeRho4K{vM6shCZnzp2&s=V3nZ1b!g zvFo#geX8G01a!aTE+)-8_{*Jou_Enz<=#;?Yiao+?fh`psbr;GmcE&zz4v)n8iCEf z&kuo9ujMa>63&v1^K2N*xO_w0%7XLl0RwC7h;gnsq{pe3>mrNS8 z)r#6iNWC^3qE4}pCb$u)eh4&CjRGE`F0?IaYTCC|Z`2~g)eH;nYpA{pE=H)I!}Un@ zSvX=>V_|Wm+D8^^X!$r%T5ttVHoLjkR9gX&4pl!fS)HXUMM3nKU=z5b)X5MTt=izf zBGf`{YqWZrD9dqkS!gP?0FPDQQI_3hv_iwyaxG*f%!yZdOzU_mN>WpEock;E724H! z^@T{XPTP{DVm8-8UbgCh*)2_B@M=$$4Z7RZ1Y5P<7TkMF2Rma=Tx^Vly>GZ=n4PCa z!!KW$9SYsqYC1GztEps-X`ccQ<9#Al3hwW^D;d4P^sWllqn9$`r)a;;R*y~m2Yq#swHBn@Pwz5sN$^$#GO5SShK-^-iKxD>Z#7?6IaicL8 zvE7)1xWSl(xZdy~t}}8G*BUv9ZH5Pt8g9f@23E0&D~)>)Ta66F02 z#7IJHHl`vr83_aU(`dvaHW+b;b%q0Rp)m!q#)w6%Ht_hASY<>bRv42JXB$z7`9>t7 z*9b$*GeQw_3>%`y2tjlk3SyRFMa(oTi1!!-F+(?dOxODn)AT*kfRvc3@5YA|-OPkj z??X)1w;)c_Rm7=!J7T=P0Wn5jk2pd9e>{T>{PRNy;w2qpO1P-Yh(8SAaWdh#z*fX( z1Ko(v1U4gH2y8+;7vP9b1=b>-4PeI!X975I38w=y5Kjg0IGXTe00%DNWWa3yi2x2? z!s7uPz67ncLtPP~w9C?CVSqE`LpXA}Y94qutIhCyms)$`#i}y!UaqRvZf{nfk!96f z3?4kr)8Trr8bi9^(_Xa%OTDCRY8^bkP4&VP+tgUB_AYHx{Yr-{J!&(XZG`9FE1d+B zUaX9SGmlnvY5%reJw+T_#^0L?|GfEiHF|fj{6D)x%>m~Q?yy$qo8i43Y8BaJ{*=Jp zt$tgmNY}Y6-CqkSeNFK|d;Iy@_xsfA7P$|t;o5F>X4u>kr!)9!K-nI33E20j)5*PX zbvJtQ$R4#o-fn6}9Z=&S?CJP8C_C(k4Jp>KFx&-=f@ea*#|~S>SR*BRFEsY6b4U*y z?pGI(t=iA~)oKgbsih36e~`&;h&+I6#IE2$%6C9b*1kTV`YdD*3_pXfU2ebX&}eVm zF`|_}pgM`tk1Jp~qm8`n!T%W3u1Frt`R zA6gVymd@JDj@QBM@2izq-j)48EtF*&+L`G{*7o+sU~KuyLEBM9b0>TpOIk z|BQ^C|0#sTXt$>DeTot*OQ-CnWS13=eB=n%ZYT2#p~@6l`j-roZnkQ--NjKaaF3o?z7P_4D|kMv^vVACI$;9P`~th35}D9Oer&N&7^c}p{aSO+#!EUWFrbFRzz5wgRq2s)S zBQT>E0~RQSOoe4&iR+@7(=FmRsWv82RoHX7!i;Dw|Z22b#XTH6sG zN3`DnuauR!vUEBF%Fpq5c0LMjZOoDV|0uVUF3&FQ4LWxxy-S zj*9lx#Z0#08S?sHKY9iR&hZ@RIL8x6nW>x&Kfrsr^xJk)wBMiO=LuO1N6+)N;2#Tx zu*LlU>f(8x2%e{Ts=d)FCAG|Nu8CL{v23c*0IQzn(=zIMpPm%?&7dz%X#7gCh_?*+>SR z3q11jGdwMhtbp`k3~)Kr4D7H%CU4PKbF-6|#a-!37yz9t>F_5hS^#fUS3zeX!#0%c#P3$mGWA@^I?A7 z;%0w&m1{86*obo@wzbJ$2`O)I3f-4eCcxku+!4}Ym1pbcLX8bLKFhYBDGCoY)|<7o<& -- 2.47.2