MoanasDaddyXu opened a new issue, #66390: URL: https://github.com/apache/doris/issues/66390
### Search before asking - [x] I searched the existing issues. #16495 reports a crash in the same comparator, but it is closed and its stack reaches `VMergeIteratorContext::compare()` from `_next_batch()`. The crash reported here occurs while `VMergeIterator::init()` is building its heap on a current master commit. ### Version Reproduced on Apache Doris commit [`1590e7e3228f8f0cafcaa89e841fece09c2475be`](https://github.com/apache/doris/commit/1590e7e3228f8f0cafcaa89e841fece09c2475be) in a non-cloud deployment with 1 FE and 3 BEs. ### What's Wrong? During a ROW binlog regression workload, a valid query caused a BE to receive `SIGSEGV`. The first Doris business frame is `VMergeIteratorContext::compare()` at `src/storage/iterator/vgeneric_iterators.cpp:128`. The comparator is called by `std::push_heap()` while `VMergeIterator::init()` initializes rowset readers. The crash terminates the BE instead of returning a query error. ### What You Expected? A valid OLAP scan should initialize its rowset merge iterators and complete normally. If a rowset or iterator state is invalid, Doris should return a diagnostic error instead of dereferencing invalid memory and terminating the BE process. ### How to Reproduce? The crash was observed during a ROW binlog regression workload on a 1 FE / 3 BE cluster. The original SQL could not be recovered from the retained audit/profile records, so a standalone deterministic reproduction is not available yet. The current reproduction gap is to recover or minimize the query and identify the exact rowset/segment combination passed to `VMergeIterator::init()`. ### Regression Test Result Sanitized continuous stack: ```text doris::signal::FailureSignalHandler(...) libc.so.6 doris::VMergeIteratorContext::compare(...) const at src/storage/iterator/vgeneric_iterators.cpp:128 std::__push_heap(...) at bits/stl_heap.h:140 std::push_heap(...) doris::VMergeIterator::init(...) at src/storage/iterator/vgeneric_iterators.cpp:373 doris::BetaRowsetReader::_init_iterator() at src/storage/rowset/beta_rowset_reader.cpp:407 doris::BetaRowsetReader::_init_iterator_once() at src/storage/rowset/beta_rowset_reader.cpp:368 doris::BetaRowsetReader::_next_batch<doris::BlockWithSameBit>(...) at src/storage/rowset/beta_rowset_reader.h:102 doris::BetaRowsetReader::next_batch(...) at src/storage/rowset/beta_rowset_reader.h:59 doris::VCollectIterator::Level0Iterator::refresh_current_row() at src/storage/iterator/vcollect_iterator.cpp:537 doris::VCollectIterator::Level0Iterator::init(bool) at src/storage/iterator/vcollect_iterator.cpp:489 doris::VCollectIterator::build_heap(...) at src/storage/iterator/vcollect_iterator.cpp:142 doris::BlockReader::_init_collect_iter(...) at src/storage/iterator/block_reader.cpp:481 doris::BlockReader::init(...) at src/storage/iterator/block_reader.cpp:601 doris::OlapScanner::_open_impl(...) at src/exec/scan/olap_scanner.cpp:316 doris::Scanner::open(...) doris::ScannerScheduler::_scanner_scan(...) doris::ScannerSplitRunner::process_for(...) at src/exec/scan/scanner_scheduler.cpp:384 doris::PrioritizedSplitRunner::process() doris::TimeSharingTaskExecutor::_dispatch_thread() at src/exec/scan/task_executor/time_sharing/time_sharing_task_executor.cpp:574 doris::Thread::supervise_thread(void*) at src/util/thread.cpp:461 start_thread clone3 ``` ### Initial Analysis Confirmed: - The direct crash point is `VMergeIteratorContext::compare()`. - The crash happens during heap construction in `VMergeIterator::init()`, before the scanner starts returning normal batches. - The running BE commit matches the public Apache Doris commit listed above. - This differs from #16495, where the comparator was reached from `_next_batch()`. Suspected: - One merge context may contain an invalid current-row reference, comparison column, or underlying column object when the heap comparator runs. - The lifetime and initialization state of the contexts inserted into the heap should be checked, especially after each rowset reader performs its first batch load. ### Anything Else? Tracking issue: #65265 Related historical issue: #16495 Additional evidence still needed: - A minimized SQL/DDL/data reproduction. - The exact rowset and segment metadata involved in the failing comparison. - Core-variable inspection for both comparator operands at the crash frame. ### Are you willing to submit PR? - [ ] Yes I am willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
