`ast.AST.__repr__` can crash on missing `_fields`
オープン
@johnslavik がすでに取り組んでいます。
2026年9月3日 から。
3.14
3.15
3.16
interpreter-core
type-crash
- 主要言語
- Python
- スター
- 77.2k
- フォーク
- 35.9k
- PR マージ指標
- PR 指標を取得中
説明
Bug report
What happened?
Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.
Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.
Crasher:
import ast
class FieldsMissingMeta(type):
def __getattribute__(self, name):
if armed and name == '_fields':
# PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
# The returned sentinel 0 is not handled.
raise AttributeError
return type.__getattribute__(self, name)
class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
pass
armed = False # don't raise during construction
f = FieldsMissing()
armed = True # raise in repr()
repr(f) # problem is in ast_repr_max_depth()
I'll send a patch.
CPython versions tested on:
3.14, 3.15, 3.16, CPython main branch
Operating systems tested on:
macOS
Output from running 'python -VV' on the command line:
No response
Linked PRs
- gh-157297
- gh-157490
- gh-157596
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
評価
この issue はまだ評価されていません。