Skip to content

Bug#120535: Reject lossy integer keys in ref and aggregate lookups - #784

Open
DerZc wants to merge 1 commit into
mysql:trunkfrom
DerZc:fix-bug-120535
Open

DerZc wants to merge 1 commit into
mysql:trunkfrom
DerZc:fix-bug-120535

Conversation

@DerZc

@DerZc DerZc commented Sep 28, 2026 •

Copy link
Copy Markdown

What does this change do?

Integer key conversion can silently round a REAL value or numeric string while reporting success. Compare the stored key with the original predicate value before using a MIN/MAX shortcut or removing a residual equality from a ref lookup. Both checks are needed when aggregate optimization falls back to ordinary indexed execution. Covers Bug#120535, Bug#121226 and Bug#120734.

Bug report: https://bugs.mysql.com/bug.php?id=120535
Bug report: https://bugs.mysql.com/bug.php?id=121226
Bug report: https://bugs.mysql.com/bug.php?id=120734

Why is it needed?

The affected execution path returns a different query result from the equivalent reference. The change preserves the expression or access-path semantics described above.

How was it tested?

On trunk at a1ef44f1d327b940a763b25eee2c6e146a0ebdb0:

  • The unmodified server fails the new regression with a result mismatch.

  • The patched server builds successfully.

  • 121 query-result checks pass against separately established expected results, including repeated prepared statements.

  • Native MTR passes: main.bug_120535, main.select_count, main.subselect, main.type_decimal, main.type_float, main.func_group, main.group_by, main.group_min_max_innodb.

  • The regression passes with the prepared-statement protocol.

  • The full database regression suite was not run.

  • Added MTR coverage under mysql-test/.

  • Ran scripts/ci/mtr.sh with its default selection; the explicit native and related tests above were run instead.

  • Ran the full database regression suite.

Contributor checklist

  • Changed C++ files are formatted with the repository .clang-format.
  • One focused commit with a descriptive message.

AI assistance

  • I did not use AI assistance for this contribution.
  • I used AI assistance for this contribution.

OpenAI Codex assisted with implementation, regression test generation and review. The submitted change was checked with compilation, execution against independently established expected results, a failing unpatched regression, and the MTR tests listed above. No human review is claimed by these automated checks.

Areas touched

mysql-test, sql

@DerZc
DerZc requested a review from a team September 28, 2026 06:09
@oracle-contributor-agreement

Copy link
Copy Markdown

Thank you for your pull request and welcome to our community! To contribute, please sign the Oracle Contributor Agreement (OCA).
The following contributors of this PR have not signed the OCA:

To sign the OCA, please create an Oracle account and sign the OCA in Oracle's Contributor Agreement Application.

When signing the OCA, please provide your GitHub username. After signing the OCA and getting an OCA approval from Oracle, this PR will be automatically updated.

If you are an Oracle employee, please make sure that you are a member of the main Oracle GitHub organization, and your membership in this organization is public.

@oracle-contributor-agreement oracle-contributor-agreement Bot added the OCA Required At least one contributor does not have an approved Oracle Contributor Agreement. label Sep 28, 2026
@github-actions github-actions Bot added Optimizer Changes touching optimizer code Tests Changes touching test code or test data labels Sep 28, 2026
Integer key conversion can silently round a REAL value or numeric string
while reporting success. Compare the stored key with the original
predicate value before using a MIN/MAX shortcut or removing a residual
equality from a ref lookup. Both checks are needed when aggregate
optimization falls back to ordinary indexed execution. Covers
Bug#120535, Bug#121226 and Bug#120734.

Add native regressions for the reported query, equivalent controls, and
repeated prepared-statement execution. Preserve observable results
across the affected execution paths.

Bug report: https://bugs.mysql.com/bug.php?id=120535
Bug report: https://bugs.mysql.com/bug.php?id=121226
Bug report: https://bugs.mysql.com/bug.php?id=120734
@DerZc DerZc changed the title Bug#120535: Preserve equality filters after lossy integer key conversion Bug#120535: Reject lossy integer keys in ref and aggregate lookups Sep 28, 2026
@github-actions github-actions Bot added the Build Passed PR build passed label Sep 28, 2026
@oracle-contributor-agreement

Copy link
Copy Markdown

Thank you for signing the OCA.

@oracle-contributor-agreement oracle-contributor-agreement Bot added OCA Verified All contributors have signed the Oracle Contributor Agreement. and removed OCA Required At least one contributor does not have an approved Oracle Contributor Agreement. labels Sep 28, 2026
@github-actions github-actions Bot added the Review Requested Review requested from code owners label Sep 28, 2026
@RidhaOracle

Copy link
Copy Markdown
Member

/codex

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Codex PR Review completed successfully!

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Codex PR Review for #784

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Found one correctness gap: the new MIN/MAX guard only covers BIGINT, leaving silently rounded equality keys usable for the other integer types. The inline comment includes a concrete query and the missing regression coverage.

Reviewed the two optimizer changes and the added tests statically. No PR code or scripts were executed. CI status could not be read because the tool's access policy rejected that request.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Codex PR Review for #784 · codex · gpt60 · 139.9 AIC · ⌖ 24.2 AIC · ⊞ 14K
Comment /codex to run again

Comment thread sql/opt_sum.cc

// Storing a nonintegral value in BIGINT can round it without reporting
// truncation. An equality lookup must use the value of the predicate.
if (eq_type && part->field->type() == MYSQL_TYPE_LONGLONG &&

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Apply the MIN/MAX round-trip check to all integer types

The MYSQL_TYPE_LONGLONG restriction leaves the same wrong-result path open for TINYINT, SMALLINT, MEDIUMINT and INT. Their store(double) implementations also round with rint() and return TYPE_OK. For example:

CREATE TABLE t (x INT, KEY k(x));
INSERT INTO t VALUES (1), (2);
SELECT MIN(x), MAX(x) FROM t FORCE INDEX(k)
WHERE x = CAST(1.5 AS DOUBLE);

Tracing this query shows that constant folding leaves the CAST expression intact, matching_cond() accepts the rounded key 2, and the MIN/MAX lookup returns 2, 2 instead of NULL, NULL. The ref-lookup fix is bypassed because aggregate optimization completes the query. Please use is_integer_type(part->field->type()) here and extend the aggregate regression coverage beyond BIGINT. This finding is based on static analysis; the query was not executed.

@github-actions github-actions Bot added the MTR Failed MTR suite failed label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Build Passed PR build passed MTR Failed MTR suite failed OCA Verified All contributors have signed the Oracle Contributor Agreement. Optimizer Changes touching optimizer code Review Requested Review requested from code owners Tests Changes touching test code or test data

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants