首批通过分布式安全可靠测评,为关键业务系统打造
timezone info 反序化 core 问题
更新时间:2026-06-04 09:56
问题现象
OBServer core dump,堆栈信息如下:
#0 0x00007ff64806bfcb in raise () from /usr/lib64/libpthread.so.0
#1 0x000000000ec0629c in oceanbase::common::coredump_cb (sig=11, si=<optimized out>, context=<optimized out>) at ./deps/oblib/src/lib/signal/ob_signal_handlers.cpp:217
#2 <signal handler called>
#3 oceanbase::common::serialization::decode (buf=0x7fef87eb891b "\200\267\236\300\002", data_len=14, pos=@0x7fe1f9f4a7e8: 0, val=<error reading variable>) at ./deps/oblib/src/lib/utility/serialization.h:1836
#4 oceanbase::common::ObTZTransitionTypeInfo::deserialize_ (this=0xcb0, buf=0x7fef87eb891b "\200\267\236\300\002", data_len=14, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39196
#5 oceanbase::common::ObTZTransitionTypeInfo::deserialize (this=0xcb0, buf=0x7fef87eb8915 "\001\216\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39192
#6 0x000000000e4f57cb in oceanbase::common::ObTZRevertTypeInfo::deserialize_ (this=0xcb0, buf=0x7fef87eb8915 "\001\216\200\200\200", data_len=30, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39284
#7 oceanbase::common::ObTZRevertTypeInfo::deserialize (this=0xcb0, buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39282
#8 oceanbase::common::DefaultItemEncode<oceanbase::common::ObTZRevertTypeInfo>::decode_item_enum (buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0, item=...) at ./deps/oblib/src/lib/utility/ob_serialization_helper.h:77
#9 oceanbase::common::DefaultItemEncode<oceanbase::common::ObTZRevertTypeInfo>::decode_item (buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0, item=...) at ./deps/oblib/src/lib/utility/ob_serialization_helper.h:46
#10 oceanbase::common::ObArrayImpl<oceanbase::common::ObTZRevertTypeInfo, oceanbase::common::ObMalloc, false, oceanbase::common::ObArrayDefaultCallBack<oceanbase::common::ObTZRevertTypeInfo>, oceanbase::common::DefaultItemEncode<oceanbase::common::ObTZRevertTypeInfo> >::deserialize (this=<optimized out>,
buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/container/ob_array_serialization.h:59
#11 oceanbase::common::serialization::EnumEncoder<false, oceanbase::common::ObArray<oceanbase::common::ObTZRevertTypeInfo, oceanbase::common::ObMalloc, false, oceanbase::common::ObArrayDefaultCallBack<oceanbase::common::ObTZRevertTypeInfo>, oceanbase::common::DefaultItemEncode<oceanbase::common::ObTZRevertTypeInfo> > >::decode (
buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1680
#12 oceanbase::common::serialization::decode<oceanbase::common::ObArray<oceanbase::common::ObTZRevertTypeInfo, oceanbase::common::ObMalloc, false, oceanbase::common::ObArrayDefaultCallBack<oceanbase::common::ObTZRevertTypeInfo>, oceanbase::common::DefaultItemEncode<oceanbase::common::ObTZRevertTypeInfo> > > (
buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1792
#13 oceanbase::common::ObTimeZoneInfoPos::deserialize_ (this=0x7fefe893d520, buf=0x7fef87eb832f "\261\002\001\224\200\200\200", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39686
#14 oceanbase::common::ObTimeZoneInfoPos::deserialize (this=0x7fefe893d520, buf=0x7fef87eb8326 "\001\001", data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39679
#15 0x000000000441daee in oceanbase::common::serialization::EnumEncoder<false, oceanbase::common::ObTimeZoneInfoPos>::decode (buf=0x7fef87eb8326 "\001\001", data_len=14, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1680
#16 oceanbase::common::serialization::decode<oceanbase::common::ObTimeZoneInfoPos> (buf=0x7fef87eb8326 "\001\001", data_len=14, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1792
#17 oceanbase::common::ObTimeZoneInfoWrap::deserialize_ (this=0x7fefe893d518, buf=<optimized out>, data_len=14, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39979
#18 oceanbase::common::ObTimeZoneInfoWrap::deserialize (this=0x7fefe893d518, buf=<optimized out>, data_len=<optimized out>, pos=@0x7fe1f9f4a7e8: 0) at ./deps/oblib/src/lib/timezone/ob_timezone_info.cpp:39974
#19 0x0000000004414e93 in oceanbase::common::serialization::EnumEncoder<false, oceanbase::common::ObTimeZoneInfoWrap>::decode (buf=0x7fef87eb8127 "\001\001\363\200\200\200", data_len=14, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1680
#20 oceanbase::common::serialization::decode<oceanbase::common::ObTimeZoneInfoWrap> (buf=0x7fef87eb8127 "\001\001\363\200\200\200", data_len=14, pos=@0x7fe1f9f4a7e8: 0, val=...) at ./deps/oblib/src/lib/utility/serialization.h:1792
#21 oceanbase::sql::ObBasicSessionInfo::deserialize_(char const*, long, long&)::$_400::operator()() const (this=<optimized out>) at ./src/sql/session/ob_basic_session_info.cpp:4312
关键诊断信息
触发条件
触发问题的并发场景如下:
系统变量
time_zone设置为地区。远程
task进行Session反序列化,或者新建联时。后台 5s 更新
timezone线程并发执行(需要当前session的timezone version为 0)时。系统租户出现频率更高, 因为系统租户没有使用
session pool缓存, 新创建的session timezone version才会为 0, 从缓存中获取的session timezone version为 1, 普通租户使用了session pool缓存, 所以出问题频率会降低。
问题原因
因为 session timezone info 并发访问导致 core,场景如下: A 线程是 Session 反序列化 timezone info 线程,遍历 ObTimeZoneInfoPos 中 ObTZRevertTypeInfo array 进行反序列化。B 线程是后台更新相同 session 中 timezone info 的线程, 线程 B 更新时会调用 ObTZRevertTypeInfo array 的 assign 动作。
该 array 的 assign 动作:
先将
array中data_内存先 free。将
data_设置为NULL。重新分配内存设置给
data_, 然后将数据 copy 到data_中。
当 B 线程执行到第一步时, A 线程会并发访问已经被释放的内存, 导致 core。
问题的风险及影响
问题出现时,Server 进程会 core,core 出现概率效低。
影响租户
影响 OceanBase 数据库中的 Oracle 租户和 MySQL 租户,对于 SYS 租户无影响。
影响版本
OceanBase 数据库 V3.2.3 GA(oceanbase-3.2.3.0-20220418212020)及之后版本、V3.2.4 GA(oceanbase-3.2.4.0-100000072022102819)及之后版本、V4.1.0 GA(oceanbase-4.1.0.0-100001122023040322)及之后版本。
解决方法
升级到问题已修复版本,目前已修复的版本包括 OceanBase 数据库 V3.2.3 BP9(oceanbase-3.2.3.3-109000182023071410)、V3.2.4 BP4(oceanbase-3.2.4.4-104000052023062021)、V4.1.0 BP2(oceanbase-4.1.0.1-102000042023061309)及之后的版本。
重新拉起 server 进程应急。
规避方式
可以考虑将系统租户的地理位置时区, 设置为对应时间 offset 的时区; 降低触发概率。