In `symtable_visit_type_param_bound_or_default()`, when a reserved name
(e.g. `__classdict__`) is used as a type parameter, `PyUnicode_FromFormat()`
is called to build the SyntaxError message. If the allocation fails and
returns NULL, the subsequent `PyErr_SetObject()` and `Py_DECREF()` calls
would dereference NULL, causing a segfault.
Fix by returning 0 immediately when `PyUnicode_FromFormat()` returns NULL.
This propagates the MemoryError set by `PyUnicode_FromFormat()`.
The bug was introduced in gh-128632 (commit
891c61c).
(cherry picked from commit
10ed03edf128ed1101ab8d04bcd715f2033fec55)
Co-authored-by: Petr Vaganov <petrvaganoff@gmail.com>
* Remove test
---------
Co-authored-by: Petr Vaganov <petrvaganoff@gmail.com>
Co-authored-by: Stan Ulbrych <stan@python.org>
--- /dev/null
+Fix NULL pointer dereference in :func:`compile` when a reserved name (e.g.
+``__classdict__``) is used as a type parameter name and memory allocation
+fails while formatting the error message.
PyObject *error_msg = PyUnicode_FromFormat("reserved name '%U' cannot be "
"used for type parameter", name);
+ if (error_msg == NULL) {
+ return 0;
+ }
PyErr_SetObject(PyExc_SyntaxError, error_msg);
Py_DECREF(error_msg);
SET_ERROR_LOCATION(st->st_filename, LOCATION(tp));