Skip to content

Fix use-after-free in loadPathPrefixMap on thread pool exception#72870

Merged
jkartseva merged 1 commit intomasterfrom
catch
Dec 14, 2024
Merged

Fix use-after-free in loadPathPrefixMap on thread pool exception#72870
jkartseva merged 1 commit intomasterfrom
catch

Conversation

@al13n321
Copy link
Member

@al13n321 al13n321 commented Dec 6, 2024

Changelog category (leave one):

  • Not for changelog (changelog entry is not required)

If scheduleOrThrowOnError in ThreadPoolCallbackRunnerLocal::operator() throws, loadPathPrefixMap won't call waitForAllToFinishAndRethrowFirstError, and the previously scheduled tasks may use-after-free the local variables.

UBSAN error: https://s3.amazonaws.com/clickhouse-test-reports/71440/e14cbfd9d5cc7aeb33ec56b5a08788cbfd35458b/stress_test__ubsan_.html . stderr.log says it's a corrupted std::map in loadPathPrefixMap, clickhouse-server.final.log says there were some "Cannot schedule a task" exceptions (though not with loadPathPrefixMap in stack trace - suspicious, but maybe the use-after-free killed the process before it printed the exception).

@robot-ch-test-poll3 robot-ch-test-poll3 added the pr-not-for-changelog This PR should not be mentioned in the changelog label Dec 6, 2024
@robot-ch-test-poll1
Copy link
Contributor

robot-ch-test-poll1 commented Dec 6, 2024

This is an automated comment for commit b71d832 with description of existing statuses. It's updated for the latest CI running

❌ Click here to open a full report in a separate page

Check nameDescriptionStatus
Stateless testsRuns stateless functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc❌ failure
Successful checks
Check nameDescriptionStatus
AST fuzzerRuns randomly generated queries to catch program errors. The build type is optionally given in parenthesis. If it fails, ask a maintainer for help✅ success
BuildsThere's no description for the check yet, please add it to tests/ci/ci_config.py:CHECK_DESCRIPTIONS✅ success
ClickBenchRuns [ClickBench](https://github.com/ClickHouse/ClickBench/) with instant-attach table✅ success
Compatibility checkChecks that clickhouse binary runs on distributions with old libc versions. If it fails, ask a maintainer for help✅ success
Docker keeper imageThe check to build and optionally push the mentioned image to docker hub✅ success
Docker server imageThe check to build and optionally push the mentioned image to docker hub✅ success
Docs checkBuilds and tests the documentation✅ success
Fast testNormally this is the first check that is ran for a PR. It builds ClickHouse and runs most of stateless functional tests, omitting some. If it fails, further checks are not started until it is fixed. Look at the report to see which tests fail, then reproduce the failure locally as described here✅ success
Flaky testsChecks if new added or modified tests are flaky by running them repeatedly, in parallel, with more randomization. Functional tests are run 100 times with address sanitizer, and additional randomization of thread scheduling. Integration tests are run up to 10 times. If at least once a new test has failed, or was too long, this check will be red. We don't allow flaky tests, read the doc✅ success
Install packagesChecks that the built packages are installable in a clear environment✅ success
Integration testsThe integration tests report. In parenthesis the package type is given, and in square brackets are the optional part/total tests✅ success
Performance ComparisonMeasure changes in query performance. The performance test report is described in detail here. In square brackets are the optional part/total tests✅ success
Stateful testsRuns stateful functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc✅ success
Stress testRuns stateless functional tests concurrently from several clients to detect concurrency-related errors✅ success
Style checkRuns a set of checks to keep the code style clean. If some of tests failed, see the related log from the report✅ success
Unit testsRuns the unit tests for different release types✅ success
Upgrade checkRuns stress tests on server version from last release and then tries to upgrade it to the version from the PR. It checks if the new server can successfully startup without any errors, crashes or sanitizer asserts✅ success

@jkartseva jkartseva self-assigned this Dec 6, 2024
Copy link
Member

@jkartseva jkartseva left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for fixing this.

@jkartseva
Copy link
Member

Let's merge this PR. I updated the private branch, and it's green now.

@jkartseva jkartseva added this pull request to the merge queue Dec 14, 2024
Merged via the queue into master with commit 21bf133 Dec 14, 2024
@jkartseva jkartseva deleted the catch branch December 14, 2024 03:06
@robot-clickhouse-ci-1 robot-clickhouse-ci-1 added the pr-synced-to-cloud The PR is synced to the cloud repo label Dec 14, 2024
@al13n321 al13n321 added the pr-must-backport Pull request should be backported intentionally. Use this label with great care! label Dec 26, 2024
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
Cherry pick #72870 to 24.8: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
Cherry pick #72870 to 24.10: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
Cherry pick #72870 to 24.11: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
Cherry pick #72870 to 24.12: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-clickhouse added a commit that referenced this pull request Dec 26, 2024
@robot-ch-test-poll2 robot-ch-test-poll2 added the pr-backports-created Backport PRs are successfully created, it won't be processed by CI script anymore label Dec 26, 2024
robot-ch-test-poll3 added a commit that referenced this pull request Dec 26, 2024
Backport #72870 to 24.10: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-clickhouse-ci-1 added a commit that referenced this pull request Dec 26, 2024
Backport #72870 to 24.8: Fix use-after-free in loadPathPrefixMap on thread pool exception
robot-ch-test-poll1 added a commit that referenced this pull request Dec 26, 2024
Backport #72870 to 24.11: Fix use-after-free in loadPathPrefixMap on thread pool exception
al13n321 pushed a commit that referenced this pull request Dec 26, 2024
…thread pool exception (#73862)

Co-authored-by: robot-clickhouse <[email protected]>
@robot-ch-test-poll3 robot-ch-test-poll3 added the pr-backports-created-cloud deprecated label, NOOP label Dec 26, 2024
@robot-clickhouse robot-clickhouse added the pr-must-backport-synced The `*-must-backport` labels are synced into the cloud Sync PR label Jul 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-backports-created Backport PRs are successfully created, it won't be processed by CI script anymore pr-backports-created-cloud deprecated label, NOOP pr-must-backport Pull request should be backported intentionally. Use this label with great care! pr-must-backport-synced The `*-must-backport` labels are synced into the cloud Sync PR pr-not-for-changelog This PR should not be mentioned in the changelog pr-synced-to-cloud The PR is synced to the cloud repo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants