• unknown's avatar
    Fixed BUG#16887: Cursor causes server segfault · 7f02b0a0
    unknown authored
      The problem was a code generation bug: cpop instructions were not generated
      when using ITERATE back to an outer block from a context with a declared
      cursor; this would make it push a new cursor without popping in-between,
      eventually overrunning the cursor stack with a crash as the result.
      Fixed the calculation of how many cursors to pop (in sp_pcontext.cc:
      diff_cursors()), and also corrected diff_cursors() and diff_handlers()
      to when doing a "leave"; don't include the last context we're leaving
      (we are then jumping to the appropriate pop instructions).
    
    
    mysql-test/r/sp.result:
      Updated result for new test case (BUG#16887)
    mysql-test/t/sp.test:
      New test case for BUG#16887
    sql/sp_pcontext.cc:
      Added new parameter to sp_pcontext::diff_handlers() and diff_cursors():
      They can either include (for iterate jumps) or exclude (for leave jumps)
      the outer context.
      Fixed bug in diff_cursors(); it was just plain wrong and would return
      zero in some situations when it shouldn't.
    sql/sp_pcontext.h:
      Added new parameter to sp_pcontext::diff_handlers() and diff_cursors():
      They can either include (for iterate jumps) or exclude (for leave jumps)
      the outer context.
    sql/sql_yacc.yy:
      Added parameter to diff_handlers/diff_cursors depending on if it's an
      iterate or leave jump.
      For "leave", we don't have to include the last context we're leaving since
      we will jump to the appropriate pop instructions.
    7f02b0a0
sp_pcontext.h 8 KB