Skip to content

SIGABRT when a script result table has an __index metamethod that calls redis.call #8268

Description

@vyavdoshenko

Found while running the Valkey TCL suite (unit/scripting, "Return table with a metatable that calls the server") against Dragonfly. If a script returns a table whose metatable __index calls redis.call, the metamethod fires while the result is being serialized, which is after the script transaction has already been unlocked. The nested command is then scheduled on a transaction that is no longer runnable and the server aborts (transaction.cc: "Check failed: !IsAtomicMulti() || cid_->IsMultiTransactional()"). Any client with EVAL access can crash the server. In a release build the DCHECK is gone and the nested write would run outside the script's atomic scope.

Reproduce:

redis-cli eval "local a={}; setmetatable(a,{__index=function() redis.call('set','x','1') end}) return a" 1 x
# Error: Server closed the connection
redis-cli ping
# Could not connect: connection refused

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions