python / python/cpython

`ast.AST.__repr__` can crash on missing `_fields`

未关闭
#156,909 0 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

@johnslavik 已经在做这个了。

开始于 2026年9月3日。

3.14 3.15 3.16 interpreter-core type-crash
主要语言
Python
星标
77.2k
派生
36k
PR 合并指标
PR 指标待抓取

描述

Bug report

What happened?

Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.

Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.

Crasher:

import ast

class FieldsMissingMeta(type):
    def __getattribute__(self, name):
        if armed and name == '_fields':
            # PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
            # The returned sentinel 0 is not handled.
            raise AttributeError
        return type.__getattribute__(self, name)

class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
    pass

armed = False  # don't raise during construction
f = FieldsMissing()
armed = True  # raise in repr()
repr(f)  # problem is in ast_repr_max_depth()

I'll send a patch.

CPython versions tested on:

3.14, 3.15, 3.16, CPython main branch

Operating systems tested on:

macOS

Output from running 'python -VV' on the command line:

No response

Linked PRs
  • gh-157297
  • gh-157490
  • gh-157596

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。