`ast.AST.__repr__` can crash on missing `_fields`
未關閉
@johnslavik 已經在處理了。
開始於 2026年9月3日。
3.14
3.15
3.16
interpreter-core
type-crash
- 主要語言
- Python
- 星號
- 77.2k
- 分支
- 36k
- PR 合併指標
- PR 指標待擷取
描述
Bug report
What happened?
Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.
Found by @encukou while we were reviewing https://github.com/python/cpython/pull/156022.
Crasher:
import ast
class FieldsMissingMeta(type):
def __getattribute__(self, name):
if armed and name == '_fields':
# PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
# The returned sentinel 0 is not handled.
raise AttributeError
return type.__getattribute__(self, name)
class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
pass
armed = False # don't raise during construction
f = FieldsMissing()
armed = True # raise in repr()
repr(f) # problem is in ast_repr_max_depth()
I'll send a patch.
CPython versions tested on:
3.14, 3.15, 3.16, CPython main branch
Operating systems tested on:
macOS
Output from running 'python -VV' on the command line:
No response
Linked PRs
- gh-157297
- gh-157490
- gh-157596
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
評估
這個 Issue 還沒有評估資料。