`ast.AST.__repr__` can crash on missing `_fields`
Open
@johnslavik is already working on this.
Since Sep 3, 2026.
3.14
3.15
3.16
interpreter-core
type-crash
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 35.9k
- PR merge metrics
- PR metrics pending
Description
Bug report
What happened?
Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.
Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.
Crasher:
import ast
class FieldsMissingMeta(type):
def __getattribute__(self, name):
if armed and name == '_fields':
# PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
# The returned sentinel 0 is not handled.
raise AttributeError
return type.__getattribute__(self, name)
class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
pass
armed = False # don't raise during construction
f = FieldsMissing()
armed = True # raise in repr()
repr(f) # problem is in ast_repr_max_depth()
I'll send a patch.
CPython versions tested on:
3.14, 3.15, 3.16, CPython main branch
Operating systems tested on:
macOS
Output from running 'python -VV' on the command line:
No response
Linked PRs
- gh-157297
- gh-157490
- gh-157596
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.