MariaDB server is a community developed fork of MySQL server. Started by core members of the original MySQL team, MariaDB actively works with outside developers to deliver the most featureful, stable, and sanely licensed open SQL server in the industry.
Go to file
Thirunarayanan Balathandayuthapani 413c59db32 MDEV-27675 Incorrect r-tree split after group assignment causes page overflow
Problem:
========
- When an R-tree root page becomes full and requires splitting,
InnoDB follows a specific root-raising procedure to maintain
tree integrity. The process involves allocating a new page
(Page X) to hold the current root's content, preserving the
original root page number as the tree's entry point, and
migrating all existing records to Page X.

The root page is then cleared and reconstructed as an
internal node containing a single node pointer with an
MBR that encompasses all spatial objects on Page X.
Subsequently, InnoDB should split the records on Page X
into two spatially optimized groups using the
pick_seeds() and pick_next() algorithms,
creating a second page (Page Y) for Group B records
while retaining Group A records on Page X.

After records are redistributed between Page X and Page Y,
the recalculated MBR for Page X must remain within
or be smaller than the original MBR stored in the
root page's node pointer.

Bug scenario:
============
- When root page 4 becomes full, it triggers a split operation
where the content is copied to page 7 and root page 4 is cleared
to become an internal node.
- During the first split attempt on page 7, Group 1 overflows
and remaining entries are reassigned to Group 2.
- A new page 8 is created and the remaining entry record
is inserted, but the combined size of the remaining entry
record and new record exceeds the page size limit.
- This triggers a second split operation on page 7, where
Group 2 overflows again and entries are moved back to Group 1.
- When the new record is finally inserted into page 7,
it causes the MBR (Minimum Bounding Rectangle) for page 7
to expand beyond its original boundaries.
- Subsequently, when InnoDB attempts to update the parent
page 4 with the new MBR information, it fails to locate
the corresponding internal node, leading to spatial
index corruption and the reported failure.

Problem:
========
- Second split operation should happen on page 8, not on page 7.
- split_rtree_node() considers key_size to estimate
record sizes during the splitting algorithm, which fails to
account for variable-length fields in spatial records.
- In rtr_page_split_and_insert(), when reorganization
succeeds, InnoDB doesn't attempt the insert the entry

Solution:
========
rtr_page_split_and_insert(): InnoDB should do insert the
tuple when btr_page_reorganize() is successful.

rtr_page_split_and_insert(): Use the overflow page
for consecutive split operation.

split_rtree_node(): Store the record length for each
record in r-tree node. This should give proper
estimation while determining the group entries and
also helpful in overflow validation
2025-10-23 07:16:26 +03:00
.github Merge 10.5 into 10.6 2023-05-19 14:24:09 +03:00
BUILD Check and remove high stack usage 2024-04-23 14:12:31 +03:00
client MDEV-37483 - fix output differences Linux vs Windows in the test 2025-09-12 11:12:17 +02:00
cmake MDEV-34388: Stack overflow on Alpine Linux (postfix) - sanitizers 2025-06-02 11:40:39 +02:00
dbug Merge branch '10.6.12' into 10.6 2023-02-06 20:18:44 +01:00
debian Merge branch '10.5' into 10.6 2025-01-29 11:17:38 +01:00
Docs Merge 10.4 into 10.5 2022-09-26 13:34:38 +03:00
extra mariadb-backup: read --tables-file in the text mode on Windows 2025-07-25 19:15:09 +02:00
include Fix clang-21 -Wuninitialized-const-pointer 2025-08-21 14:38:48 +03:00
libmariadb@9e2b0370de new CC 3.3 2025-10-20 11:48:59 +02:00
libmysqld Merge branch '10.5' into 10.6 2025-01-29 11:17:38 +01:00
libservices MDEV-33277 In-place upgrade causes invalid AUTO_INCREMENT values 2024-02-08 10:35:45 +02:00
man Merge branch '10.5' into 10.6 2024-07-16 15:54:22 +08:00
mysql-test MDEV-27675 Incorrect r-tree split after group assignment causes page overflow 2025-10-23 07:16:26 +03:00
mysys MDEV-31678: UPDATE_ROWS_EVENT not setting updating columns in read_set 2025-10-07 09:40:36 +02:00
mysys_ssl MDEV-35838 libressl support differences in CRYPTO_set_mem_functions 2025-01-14 12:13:22 +11:00
plugin MDEV-36337 auth_ed25519 correct UDF pointers for is_null/error 2025-05-21 09:47:55 +02:00
randgen/conf
scripts Continuation of previous FreeBSD-related fix for Galera SST scripts 2025-08-14 21:36:22 +02:00
sql MDEV-7451 Server audit: Table events for partitioned tables are duplicated for each partition. 2025-10-23 00:25:52 +04:00
sql-bench
sql-common Merge branch '10.5' into 10.6 2025-01-29 11:17:38 +01:00
storage MDEV-27675 Incorrect r-tree split after group assignment causes page overflow 2025-10-23 07:16:26 +03:00
strings MDEV-37048 revert MSAN my_vsnprintf_ex for double workaround 2025-07-03 10:43:40 +03:00
support-files MDEV-36009: Systemd: Restart on OOM 2025-10-14 18:46:20 +02:00
tests Merge branch '10.5' into 10.6 2025-04-26 10:41:52 +02:00
tpool MDEV-36482: Make liburing work WITH_MSAN=ON (fix) 2025-08-25 17:31:40 +10:00
unittest Fix small stack problem on some ARM. 2025-08-08 09:57:02 +02:00
vio Compiling - fix warnings with MSVC 17.14 2025-05-26 16:58:21 +02:00
win HeidiSQL 12.11 2025-07-25 12:28:30 +02:00
wsrep-lib@14ce8cab76 galera: wsrep-lib submodule update 2025-08-13 17:53:56 +02:00
zlib Merge branch 'merge-zlib' (1.3.1) into 10.4 2024-04-26 13:50:03 +02:00
.clang-format Remove duplicate key "Language" from .clang-format 2024-04-17 16:52:37 +02:00
.gitattributes
.gitignore print_ddl_recovery_log.pl ; Print content of the ddl_recovery.log 2025-04-27 15:12:21 +03:00
.gitlab-ci.yml Merge branch '10.5' into 10.6 2024-07-18 16:25:33 +02:00
.gitmodules Merge remote-tracking branch '10.4' into 10.5 2023-03-31 21:32:41 +02:00
appveyor.yml Merge 10.5 into 10.6 2024-06-07 10:03:51 +03:00
BUILD-CMAKE
CMakeLists.txt Merge branch '10.5' into '10.6' 2025-04-15 01:49:48 +02:00
config.h.cmake Merge branch '10.5' into 10.6 2024-10-29 14:20:03 +01:00
configure.cmake Merge branch '10.5' into 10.6 2024-10-29 14:20:03 +01:00
CONTRIBUTING.md
COPYING
CREDITS Update sponsors 2024-08-12 09:32:30 +01:00
INSTALL-SOURCE
INSTALL-WIN-SOURCE
KNOWN_BUGS.txt
README.md Update README for branch choice 2024-05-29 13:49:32 +01:00
THIRDPARTY Added socketpair.c as a replacement for 'pipe()' call for Windows. 2024-01-23 13:03:11 +02:00
VERSION bump the VERSION 2025-08-06 17:19:15 -04:00

Code status:

  • Appveyor CI status ci.appveyor.com

MariaDB: The innovative open source database

MariaDB was designed as a drop-in replacement of MySQL(R) with more features, new storage engines, fewer bugs, and better performance.

MariaDB is brought to you by the MariaDB Foundation and the MariaDB Corporation. Please read the CREDITS file for details about the MariaDB Foundation, and who is developing MariaDB.

MariaDB is developed by many of the original developers of MySQL who now work for the MariaDB Corporation, the MariaDB Foundation and by many people in the community.

MySQL, which is the base of MariaDB, is a product and trademark of Oracle Corporation, Inc. For a list of developers and other contributors, see the Credits appendix. You can also run 'SHOW authors' to get a list of active contributors.

A description of the MariaDB project and a manual can be found at:

https://mariadb.org

https://mariadb.com/kb/en/

https://mariadb.com/kb/en/mariadb-vs-mysql-features/

https://mariadb.com/kb/en/mariadb-versus-mysql-compatibility/

https://mariadb.com/kb/en/new-and-old-releases/

Getting the code, building it and testing it

Refer to the following guide: https://mariadb.org/get-involved/getting-started-for-developers/get-code-build-test/ which outlines how to build the source code correctly and run the MariaDB testing framework, as well as which branch to target for your contributions.

Help

More help is available from the Maria Discuss mailing list https://lists.mariadb.org/postorius/lists/discuss.lists.mariadb.org/ and MariaDB's Zulip instance, https://mariadb.zulipchat.com/

Licensing


MariaDB is specifically available only under version 2 of the GNU General Public License (GPLv2). (I.e. Without the "any later version" clause.) This is inherited from MySQL. Please see the README file in the MySQL distribution for more information.

License information can be found in the COPYING file. Third party license information can be found in the THIRDPARTY file.


Bug Reports

Bug and/or error reports regarding MariaDB should be submitted at: https://jira.mariadb.org

For reporting security vulnerabilities see: https://mariadb.org/about/security-policy/

The code for MariaDB, including all revision history, can be found at: https://github.com/MariaDB/server