`ast.AST.__repr__` can crash on missing `_fields`
Đang mở
@johnslavik đang làm issue này rồi.
Từ ngày 3/9/2026.
3.14
3.15
3.16
interpreter-core
type-crash
- Ngôn ngữ chính
- Python
- Star
- 77.2k
- Fork
- 35.9k
- Chỉ số merge pull request
- Chỉ số pull request đang chờ
Mô tả
Bug report
What happened?
Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.
Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.
Crasher:
import ast
class FieldsMissingMeta(type):
def __getattribute__(self, name):
if armed and name == '_fields':
# PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
# The returned sentinel 0 is not handled.
raise AttributeError
return type.__getattribute__(self, name)
class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
pass
armed = False # don't raise during construction
f = FieldsMissing()
armed = True # raise in repr()
repr(f) # problem is in ast_repr_max_depth()
I'll send a patch.
CPython versions tested on:
3.14, 3.15, 3.16, CPython main branch
Operating systems tested on:
macOS
Output from running 'python -VV' on the command line:
No response
Linked PRs
- gh-157297
- gh-157490
- gh-157596
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Đánh giá
Issue này chưa được đánh giá.