Skip to content

ast.AST.__repr__ can crash on missing _fields #156909

Description

@johnslavik

Bug report

What happened?

Just a null pointer access with no realistic occurence risk. However, it's trivial, so it's worth a fix for correctness so it can't escalate to sth realistic.

Found by @encukou while we were reviewing #156022.

Crasher:

import ast

class FieldsMissingMeta(type):
    def __getattribute__(self, name):
        if armed and name == '_fields':
            # PyObject_GetOptionalAttr() returns 0 now, *fields is NULL.
            # The returned sentinel 0 is not handled.
            raise AttributeError
        return type.__getattribute__(self, name)

class FieldsMissing(ast.Del, metaclass=FieldsMissingMeta):
    pass

armed = False  # don't raise during construction
f = FieldsMissing()
armed = True  # raise in repr()
repr(f)  # problem is in ast_repr_max_depth()

I'll send a patch.

CPython versions tested on:

3.14, 3.15, 3.16, CPython main branch

Operating systems tested on:

macOS

Output from running 'python -VV' on the command line:

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

3.14bugs and security fixes3.15pre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesinterpreter-core(Objects, Python, Grammar, and Parser dirs)type-crashA hard crash of the interpreter, possibly with a core dump

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions