`ast.AST.__repr__` can crash on missing `_fields`

Offen
#156,909 0 Kommentare 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

@johnslavik arbeitet bereits daran.

Seit 03.9.2026.

Bewertung

Dieses Issue wurde noch nicht bewertet.

Beschreibung

3.14 3.15 3.16 interpreter-core type-crash

Bug report

What happened?

Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.

Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.

Crasher:

import ast

class FieldsMissingMeta(type):
    def __getattribute__(self, name):
        if armed and name == '_fields':
            # PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
            # The returned sentinel 0 is not handled.
            raise AttributeError
        return type.__getattribute__(self, name)

class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
    pass

armed = False  # don't raise during construction
f = FieldsMissing()
armed = True  # raise in repr()
repr(f)  # problem is in ast_repr_max_depth()

I'll send a patch.

CPython versions tested on:

3.14, 3.15, 3.16, CPython main branch

Operating systems tested on:

macOS

Output from running 'python -VV' on the command line:

No response

Linked PRs
  • gh-157297
  • gh-157490
  • gh-157596
Vorherrschende Sprache
Python
Sterne
77.2k
Forks
36k
Ø Merge
1 T. 9 Std.
Gemergte PRs (30 T.)
558

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus python/cpython

Alle Issues in python/cpython

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.