• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

taosdata / TDengine / #4941

27 Jan 2026 10:23AM UTC coverage: 66.868% (+0.04%) from 66.832%
#4941

push

travis-ci

web-flow
fix: asan invalid write issue (#34400)

7 of 8 new or added lines in 2 files covered. (87.5%)

560 existing lines in 126 files now uncovered.

204401 of 305680 relevant lines covered (66.87%)

126915843.15 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

81.28
/source/libs/executor/src/querytask.c
1
/*
2
 * Copyright (c) 2019 TAOS Data, Inc. <jhtao@taosdata.com>
3
 *
4
 * This program is free software: you can use, redistribute, and/or modify
5
 * it under the terms of the GNU Affero General Public License, version 3
6
 * or later ("AGPL"), as published by the Free Software Foundation.
7
 *
8
 * This program is distributed in the hope that it will be useful, but WITHOUT
9
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
10
 * FITNESS FOR A PARTICULAR PURPOSE.
11
 *
12
 * You should have received a copy of the GNU Affero General Public License
13
 * along with this program. If not, see <http://www.gnu.org/licenses/>.
14
 */
15

16
#include "filter.h"
17
#include "function.h"
18
#include "functionMgt.h"
19
#include "os.h"
20
#include "querynodes.h"
21
#include "tfill.h"
22
#include "tname.h"
23

24
#include "tdatablock.h"
25
#include "tmsg.h"
26

27
#include "executorInt.h"
28
#include "index.h"
29
#include "operator.h"
30
#include "query.h"
31
#include "querytask.h"
32
#include "storageapi.h"
33
#include "thash.h"
34
#include "ttypes.h"
35

36
#define CLEAR_QUERY_STATUS(q, st) ((q)->status &= (~(st)))
37

38
int32_t doCreateTask(uint64_t queryId, uint64_t taskId, int32_t vgId, EOPTR_EXEC_MODEL model, SStorageAPI* pAPI,
299,804,193✔
39
                     SExecTaskInfo** pTaskInfo) {
40
  if (pTaskInfo == NULL) {
299,804,193✔
41
    return TSDB_CODE_SUCCESS;
×
42
  }
43

44
  SExecTaskInfo* p = taosMemoryCalloc(1, sizeof(SExecTaskInfo));
299,804,193✔
45
  if (p == NULL) {
299,717,713✔
46
    return terrno;
×
47
  }
48

49
  setTaskStatus(p, TASK_NOT_COMPLETED);
299,717,713✔
50
  p->cost.created = taosGetTimestampUs();
299,834,051✔
51

52
  p->execModel = model;
299,829,773✔
53
  p->stopInfo.pStopInfo = taosArrayInit(4, sizeof(SExchangeOpStopInfo));
299,835,988✔
54
  p->pResultBlockList = taosArrayInit(128, POINTER_BYTES);
299,789,498✔
55
  if (p->stopInfo.pStopInfo == NULL || p->pResultBlockList == NULL) {
299,730,464✔
UNCOV
56
    doDestroyTask(p);
×
57
    return terrno;
×
58
  }
59

60
  p->storageAPI = *pAPI;
299,774,555✔
61
  taosInitRWLatch(&p->lock);
299,807,858✔
62

63
  p->id.vgId = vgId;
299,804,858✔
64
  p->id.queryId = queryId;
299,803,848✔
65
  p->id.taskId = taskId;
299,815,772✔
66
  p->id.str = taosMemoryMalloc(64);
299,801,823✔
67
  if (p->id.str == NULL) {
299,751,017✔
68
    doDestroyTask(p);
×
69
    return terrno;
×
70
  }
71

72
  buildTaskId(taskId, queryId, p->id.str, 64);
299,782,018✔
73
  p->schemaInfos = taosArrayInit(1, sizeof(SSchemaInfo));
299,742,854✔
74
  if (p->id.str == NULL || p->schemaInfos == NULL) {
299,649,486✔
75
    doDestroyTask(p);
427✔
76
    return terrno;
×
77
  }
78

79
  *pTaskInfo = p;
299,703,260✔
80
  return TSDB_CODE_SUCCESS;
299,730,042✔
81
}
82

83
int32_t getTaskCode(void* pTaskInfo) { return ((SExecTaskInfo*)pTaskInfo)->code; }
75,518✔
84

85
bool isTaskKilled(void* pTaskInfo) { return (0 != ((SExecTaskInfo*)pTaskInfo)->code); }
1,751,389,205✔
86

87
void setTaskKilled(SExecTaskInfo* pTaskInfo, int32_t rspCode) {
164,285✔
88
  pTaskInfo->code = rspCode;
164,285✔
89
  (void)stopTableScanOperator(pTaskInfo->pRoot, pTaskInfo->id.str, &pTaskInfo->storageAPI);
164,285✔
90
}
164,285✔
91

92
void setTaskStatus(SExecTaskInfo* pTaskInfo, int8_t status) {
942,892,582✔
93
  if (status == TASK_NOT_COMPLETED) {
942,892,582✔
94
    pTaskInfo->status = status;
299,915,495✔
95
  } else {
96
    // QUERY_NOT_COMPLETED is not compatible with any other status, so clear its position first
97
    CLEAR_QUERY_STATUS(pTaskInfo, TASK_NOT_COMPLETED);
642,977,087✔
98
    pTaskInfo->status |= status;
642,993,561✔
99
  }
100
}
942,937,567✔
101

102

103
int32_t initTaskSubJobCtx(SExecTaskInfo* pTaskInfo, SArray* subEndPoints, SReadHandle* readHandle) {
299,567,421✔
104
  STaskSubJobCtx* ctx = &pTaskInfo->subJobCtx;
299,567,421✔
105

106
  ctx->queryId = pTaskInfo->id.queryId;
299,634,785✔
107
  ctx->taskId = pTaskInfo->id.taskId;
299,567,554✔
108
  ctx->idStr = pTaskInfo->id.str;
299,583,684✔
109
  ctx->pTaskInfo = pTaskInfo;
299,556,317✔
110
  ctx->subEndPoints = subEndPoints;
299,644,718✔
111
  ctx->rpcHandle = (readHandle && readHandle->pMsgCb) ? readHandle->pMsgCb->clientRpc : NULL;
299,486,515✔
112
  
113
  int32_t subJobNum = taosArrayGetSize(subEndPoints);
299,647,477✔
114
  if (subJobNum > 0) {
299,641,934✔
115
    pTaskInfo->subJobCtx.subResNodes = taosArrayInit_s(POINTER_BYTES, subJobNum);
32,843,724✔
116
    if (NULL == pTaskInfo->subJobCtx.subResNodes) {
32,839,060✔
117
      qError("%s taosArrayInit_s %d subResNodes failed, error:%s", GET_TASKID(pTaskInfo), subJobNum, tstrerror(terrno));
×
118
      return terrno;
×
119
    }
120
    
121
    int32_t code = tsem_init(&ctx->ready, 0, 0);
32,838,546✔
122
    if (code) {
32,819,423✔
123
      qError("%s tsem_init failed, error:%s", GET_TASKID(pTaskInfo), tstrerror(code));
×
124
      return code;
×
125
    }
126
    
127
    pTaskInfo->subJobCtx.hasSubJobs = true;
32,819,423✔
128

129
    qDebug("%s subJobCtx with %d endPoints inited", pTaskInfo->id.str, subJobNum);
32,823,021✔
130
  }
131

132
  return TSDB_CODE_SUCCESS;
299,567,284✔
133
}
134

135

136

137
int32_t createExecTaskInfo(SSubplan* pPlan, SExecTaskInfo** pTaskInfo, SReadHandle* pHandle, uint64_t taskId,
299,686,582✔
138
                           int32_t vgId, char* sql, EOPTR_EXEC_MODEL model, SArray* subEndPoints) {
139
  int32_t code = doCreateTask(pPlan->id.queryId, taskId, vgId, model, &pHandle->api, pTaskInfo);
299,686,582✔
140
  if (*pTaskInfo == NULL || code != 0) {
299,581,092✔
141
    nodesDestroyNode((SNode*)pPlan);
47✔
142
    return code;
×
143
  }
144

145
  (*pTaskInfo)->pSubplan = pPlan;
299,610,739✔
146

147
  if (pHandle) {
299,612,867✔
148
    if (pHandle->pStateBackend) {
299,597,514✔
149
      (*pTaskInfo)->streamInfo.pState = pHandle->pStateBackend;
×
150
      (*pTaskInfo)->streamInfo.pOtherState = pHandle->pOtherBackend;
×
151
    }
152
  }
153

154
  if (NULL != sql) {
299,639,377✔
155
    (*pTaskInfo)->sql = taosStrdup(sql);
297,104,536✔
156
    if (NULL == (*pTaskInfo)->sql) {
297,100,016✔
157
      code = terrno;
×
158
      doDestroyTask(*pTaskInfo);
×
159
      (*pTaskInfo) = NULL;
×
160
      return code;
×
161
    }
162
  }
163

164
  (*pTaskInfo)->pWorkerCb = pHandle->pWorkerCb;
299,603,995✔
165
  (*pTaskInfo)->pStreamRuntimeInfo = pHandle->streamRtInfo;
299,612,995✔
166

167
  code = initTaskSubJobCtx(*pTaskInfo, subEndPoints, pHandle);
299,503,613✔
168
  if (code != TSDB_CODE_SUCCESS) {
299,539,414✔
169
    doDestroyTask(*pTaskInfo);
×
170
    (*pTaskInfo) = NULL;
×
171
    return code;
×
172
  }
173

174
  setTaskScalarExtraInfo(*pTaskInfo);
299,539,414✔
175
  
176
  code = createOperator(pPlan->pNode, *pTaskInfo, pHandle, pPlan->pTagCond, pPlan->pTagIndexCond, pPlan->user,
299,509,283✔
177
                        pPlan->dbFName, &((*pTaskInfo)->pRoot), model);
299,513,658✔
178

179
  if (NULL == (*pTaskInfo)->pRoot || code != 0) {
299,180,628✔
180
    doDestroyTask(*pTaskInfo);
3,544,700✔
181
    (*pTaskInfo) = NULL;
3,504,598✔
182
  }
183
  return code;
299,247,288✔
184
}
185

186
void cleanupQueriedTableScanInfo(void* p) {
211,224,589✔
187
  SSchemaInfo* pSchemaInfo = p;
211,224,589✔
188

189
  taosMemoryFreeClear(pSchemaInfo->dbname);
211,224,589✔
190
  taosMemoryFreeClear(pSchemaInfo->tablename);
211,170,529✔
191
  tDeleteSchemaWrapper(pSchemaInfo->sw);
211,110,030✔
192
  tDeleteSchemaWrapper(pSchemaInfo->qsw);
211,114,712✔
193
}
211,092,070✔
194

195
int32_t initQueriedTableSchemaInfo(SReadHandle* pHandle, SScanPhysiNode* pScanNode, const char* dbName,
211,332,510✔
196
                                   SExecTaskInfo* pTaskInfo) {
197
  SMetaReader mr = {0};
211,332,510✔
198
  if (pHandle == NULL) {
211,342,254✔
199
    return TSDB_CODE_INVALID_PARA;
×
200
  }
201

202
  SStorageAPI* pAPI = &pTaskInfo->storageAPI;
211,342,254✔
203

204
  pAPI->metaReaderFn.initReader(&mr, pHandle->vnode, META_READER_LOCK, &pAPI->metaFn);
211,323,723✔
205
  int32_t code = pAPI->metaReaderFn.getEntryGetUidCache(&mr, pScanNode->uid);
211,344,460✔
206
  if (code != TSDB_CODE_SUCCESS) {
210,909,978✔
207
    qError("failed to get the table meta, uid:0x%" PRIx64 ", suid:0x%" PRIx64 ", %s", pScanNode->uid, pScanNode->suid,
×
208
           GET_TASKID(pTaskInfo));
209

210
    pAPI->metaReaderFn.clearReader(&mr);
×
211
    return code;
×
212
  }
213

214
  SSchemaInfo schemaInfo = {0};
210,909,978✔
215

216
  schemaInfo.tablename = taosStrdup(mr.me.name);
210,902,439✔
217
  schemaInfo.dbname = taosStrdup(dbName);
210,895,820✔
218
  if (schemaInfo.tablename == NULL || schemaInfo.dbname == NULL) {
210,958,482✔
219
    pAPI->metaReaderFn.clearReader(&mr);
242,866✔
220
    cleanupQueriedTableScanInfo(&schemaInfo);
×
221
    return terrno;
×
222
  }
223

224
  if (mr.me.type == TSDB_VIRTUAL_NORMAL_TABLE || mr.me.type == TSDB_VIRTUAL_CHILD_TABLE) {
210,715,618✔
225
    schemaInfo.rversion = mr.me.colRef.version;
274,675✔
226
  }
227

228
  if (mr.me.type == TSDB_SUPER_TABLE) {
210,715,618✔
229
    schemaInfo.sw = tCloneSSchemaWrapper(&mr.me.stbEntry.schemaRow);
116,780,753✔
230
    schemaInfo.tversion = mr.me.stbEntry.schemaTag.version;
116,780,753✔
231
  } else if (mr.me.type == TSDB_CHILD_TABLE || mr.me.type == TSDB_VIRTUAL_CHILD_TABLE) {
94,265,130✔
232
    tDecoderClear(&mr.coder);
52,546,436✔
233

234
    tb_uid_t suid = mr.me.ctbEntry.suid;
52,391,125✔
235
    code = pAPI->metaReaderFn.getEntryGetUidCache(&mr, suid);
52,391,125✔
236
    if (code != TSDB_CODE_SUCCESS) {
52,387,957✔
237
      pAPI->metaReaderFn.clearReader(&mr);
×
238
      cleanupQueriedTableScanInfo(&schemaInfo);
×
239
      return code;
×
240
    }
241

242
    schemaInfo.sw = tCloneSSchemaWrapper(&mr.me.stbEntry.schemaRow);
52,385,268✔
243
    schemaInfo.tversion = mr.me.stbEntry.schemaTag.version;
52,385,268✔
244
  } else {
245
    schemaInfo.sw = tCloneSSchemaWrapper(&mr.me.ntbEntry.schemaRow);
41,766,840✔
246
  }
247

248
  pAPI->metaReaderFn.clearReader(&mr);
210,932,861✔
249

250
  if (schemaInfo.sw == NULL) {
210,738,476✔
251
    cleanupQueriedTableScanInfo(&schemaInfo);
×
252
    return terrno;
×
253
  }
254

255
  schemaInfo.qsw = extractQueriedColumnSchema(pScanNode);
210,738,476✔
256
  if (schemaInfo.qsw == NULL) {
210,991,809✔
257
    cleanupQueriedTableScanInfo(&schemaInfo);
×
258
    return terrno;
×
259
  }
260

261
  void* p = taosArrayPush(pTaskInfo->schemaInfos, &schemaInfo);
210,991,809✔
262
  if (p == NULL) {
211,129,926✔
263
    cleanupQueriedTableScanInfo(&schemaInfo);
×
264
    return terrno;
×
265
  }
266

267
  return code;
211,129,926✔
268
}
269

270
SSchemaWrapper* extractQueriedColumnSchema(SScanPhysiNode* pScanNode) {
210,753,238✔
271
  int32_t numOfCols = LIST_LENGTH(pScanNode->pScanCols);
210,753,238✔
272
  int32_t numOfTags = LIST_LENGTH(pScanNode->pScanPseudoCols);
211,010,893✔
273

274
  SSchemaWrapper* pqSw = taosMemoryCalloc(1, sizeof(SSchemaWrapper));
210,970,089✔
275
  if (pqSw == NULL) {
210,763,508✔
276
    return NULL;
×
277
  }
278

279
  pqSw->pSchema = taosMemoryCalloc(numOfCols + numOfTags, sizeof(SSchema));
210,763,508✔
280
  if (pqSw->pSchema == NULL) {
210,430,226✔
281
    taosMemoryFree(pqSw);
×
282
    return NULL;
×
283
  }
284

285
  for (int32_t i = 0; i < numOfCols; ++i) {
981,843,381✔
286
    STargetNode* pNode = (STargetNode*)nodesListGetNode(pScanNode->pScanCols, i);
770,737,144✔
287
    SColumnNode* pColNode = (SColumnNode*)pNode->pExpr;
770,717,975✔
288

289
    SSchema* pSchema = &pqSw->pSchema[pqSw->nCols++];
770,725,975✔
290
    pSchema->colId = pColNode->colId;
770,743,513✔
291
    pSchema->type = pColNode->node.resType.type;
771,157,394✔
292
    pSchema->bytes = pColNode->node.resType.bytes;
771,061,797✔
293
    tstrncpy(pSchema->name, pColNode->colName, tListLen(pSchema->name));
770,885,304✔
294
  }
295

296
  // this the tags and pseudo function columns, we only keep the tag columns
297
  for (int32_t i = 0; i < numOfTags; ++i) {
353,925,416✔
298
    STargetNode* pNode = (STargetNode*)nodesListGetNode(pScanNode->pScanPseudoCols, i);
142,810,160✔
299

300
    int32_t type = nodeType(pNode->pExpr);
142,867,403✔
301
    if (type == QUERY_NODE_COLUMN) {
142,933,670✔
302
      SColumnNode* pColNode = (SColumnNode*)pNode->pExpr;
105,733,517✔
303

304
      SSchema* pSchema = &pqSw->pSchema[pqSw->nCols++];
105,694,255✔
305
      pSchema->colId = pColNode->colId;
105,619,317✔
306
      pSchema->type = pColNode->node.resType.type;
105,718,879✔
307
      pSchema->bytes = pColNode->node.resType.bytes;
105,572,831✔
308
      tstrncpy(pSchema->name, pColNode->colName, tListLen(pSchema->name));
105,689,668✔
309
    }
310
  }
311

312
  return pqSw;
211,115,256✔
313
}
314

315
static void cleanupStreamInfo(SStreamTaskInfo* pStreamInfo) {
299,633,850✔
316
  tDeleteSchemaWrapper(pStreamInfo->schema);
299,633,850✔
317
  tOffsetDestroy(&pStreamInfo->currentOffset);
299,699,601✔
318
  tDeleteSchemaWrapper(pStreamInfo->notifyResultSchema);
299,475,502✔
319
  taosMemoryFree(pStreamInfo->stbFullName);
299,653,462✔
320
}
299,554,642✔
321

322
static void freeBlock(void* pParam) {
441,145,650✔
323
  SSDataBlock* pBlock = *(SSDataBlock**)pParam;
441,145,650✔
324
  blockDataDestroy(pBlock);
441,163,452✔
325
}
441,197,540✔
326

327

328
void destroySubJobCtx(STaskSubJobCtx* pCtx) {
299,727,487✔
329
  if (pCtx->transporterId > 0) {
299,727,487✔
330
    int32_t ret = asyncFreeConnById(pCtx->rpcHandle, pCtx->transporterId);
56,814✔
331
    if (ret != 0) {
56,814✔
332
      qDebug("%s failed to free subQ rpc handle, code:%s", pCtx->idStr, tstrerror(ret));
×
333
    }
334
    pCtx->transporterId = -1;
56,814✔
335
  }
336
  taosArrayDestroy(pCtx->subResNodes);
299,793,593✔
337
}
299,742,883✔
338

339
void doDestroyTask(SExecTaskInfo* pTaskInfo) {
299,794,368✔
340
  qDebug("%s execTask is freed", GET_TASKID(pTaskInfo));
299,794,368✔
341
  destroyOperator(pTaskInfo->pRoot);
299,794,368✔
342
  pTaskInfo->pRoot = NULL;
299,683,685✔
343

344
  destroySubJobCtx(&pTaskInfo->subJobCtx);
299,723,916✔
345

346
  taosArrayDestroyEx(pTaskInfo->schemaInfos, cleanupQueriedTableScanInfo);
299,747,914✔
347
  cleanupStreamInfo(&pTaskInfo->streamInfo);
299,676,589✔
348

349
  if (!pTaskInfo->localFetch.localExec) {
299,602,085✔
350
    nodesDestroyNode((SNode*)pTaskInfo->pSubplan);
299,623,277✔
351
    pTaskInfo->pSubplan = NULL;
299,635,382✔
352
  }
353

354
  taosArrayDestroyEx(pTaskInfo->pResultBlockList, freeBlock);
299,669,497✔
355
  taosArrayDestroy(pTaskInfo->stopInfo.pStopInfo);
299,709,023✔
356
  if (!pTaskInfo->paramSet) {
299,677,080✔
357
    freeOperatorParam(pTaskInfo->pOpParam, OP_GET_PARAM);
292,860,182✔
358
    pTaskInfo->pOpParam = NULL;
292,791,188✔
359
  }
360
  taosMemoryFreeClear(pTaskInfo->sql);
299,655,589✔
361
  taosMemoryFreeClear(pTaskInfo->id.str);
299,631,171✔
362
  taosMemoryFreeClear(pTaskInfo);
299,638,618✔
363
}
299,524,835✔
364

365
void buildTaskId(uint64_t taskId, uint64_t queryId, char* dst, int32_t len) {
325,407,427✔
366
  int32_t ret = snprintf(dst, len, "TID:0x%" PRIx64 " QID:0x%" PRIx64, taskId, queryId);
325,407,427✔
367
  if (ret < 0) {
325,407,427✔
368
    qError("TID:0x%"PRIx64" QID:0x%"PRIx64" create task id failed,  ignore and continue", taskId, queryId);
×
369
  }
370
}
325,407,427✔
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc