Changelog

Python next

Release date: XXXX-XX-XX

Tools/Demos

  • gh-113318: Fix Argument Clinic for @getter and @setter in a preprocessor conditional block. It failed with an internal error. Argument Clinic now also rejects the accessors of the same attribute with different C basenames, and the same accessor defined twice, which silently generated invalid or duplicated entries of PyGetSetDef.

Tests

  • gh-155997: Fix test.support.interpreters.list_all(). It failed if an interpreter was destroyed during the call, in particular by a garbage collection which finalized the object owning the last reference to it.

  • gh-155411: Fix test.support.subTests() for asynchronous test methods. They were wrapped in a synchronous function, which discarded the coroutine without awaiting it, so the test silently did not run at all.

  • gh-132581: The list of tests which altered the execution environment now includes the reasons why the environment was considered altered, for example an unraisable exception or a modified sys.path. The final result no longer repeats the same state twice (like ENV CHANGED then ENV CHANGED).

Security

  • gh-155999: Fix the tarfile tar and data extraction filters creating directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.

  • gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE 2026-72522.

  • gh-155694: Fix CVE 2026-15806 by scoping HTTPPasswordMgr credentials to the URL scheme, preventing credentials stored for an HTTPS URL from being used for a matching HTTP URL, while URIs without a scheme continue to match any scheme.

Library

  • gh-156166: ssl: A failed assignment or deletion of the _msg_callback attribute of ssl.SSLContext no longer removes the current callback. Deleting it now raises AttributeError instead of TypeError.

  • gh-152817: sqlite3: Disallow removing the row_factory attribute of a cursor to prevent a crash on a query.

  • gh-156112: _ios_support no longer fails to import when ctypes.util.find_library() cannot resolve the ObjC runtime through the dyld shared cache, as is the case on iOS 13. The runtime is now loaded by name, which dyld resolves against the cache directly.

  • gh-156100: Fix crashes in sqlite3.Connection when deleting the autocommit attribute or setting it to an integer which does not fit in C long. Both now raise an exception.

  • gh-156099: Fix a crash when deleting the keylog_filename attribute of ssl.SSLContext. It now raises AttributeError.

  • gh-156067: Fix error handling in the zoneinfo accelerator module when a transition index is -1 or a TZ string’s __bool__ raises.

  • gh-155952: Fix the signatures of sqlite3.Connection.execute(), warnings.warn() and locale.setlocale() which rendered <unrepresentable> instead of the correct defaults for parameters.

  • gh-113318: Fix crashes when deleting an attribute whose setter is generated by Argument Clinic and is not prepared for deletion, among them the context, owner and session attributes of _ssl._SSLSocket. Deleting such attribute now raises AttributeError.

  • gh-155336: Fix error handling in socket.gethostbyaddr() and socket.gethostbyname_ex() when hostname resolution fails.

  • gh-155319: warnings.warn_explicit() now displays the source line taken from the loader of the module whose globals are passed as module_globals. It also no longer raises IndexError if lineno is out of the range of the module source.

  • gh-123011: warnings.warn_explicit() no longer emits a spurious DeprecationWarning or raises ImportError when it is called with the globals of the __main__ module.

  • gh-153005: concurrent.interpreters.Queue.get() and concurrent.interpreters.Queue.put() now compute their timeout deadline from time.monotonic() instead of the wall clock, so adjusting the system clock during the call no longer makes them over- or under-wait.

  • gh-153603: Fix a crash in the ISO-2022 decoders when decoding a byte after an unknown charset designation is set via the decoder’s setstate method. Patch by tonghuaroot.

  • gh-153539: Fix a crash in the C implementation of io.TextIOWrapper.tell() when the decoder’s getstate method triggers a reentrant seek, or when another thread seeks the same stream concurrently. Patch by tonghuaroot.

  • gh-146004: All -X options from the Python command line are now propagated to child processes spawned by multiprocessing, not just a hard-coded subset. This makes the behavior consistent between default “spawn” and “forkserver” start methods and the old “fork” start method. The options that were previously not propagated are: context_aware_warnings, cpu_count, disable-remote-debug, int_max_str_digits, lazy_imports, no_debug_ranges, pathconfig_warnings, perf, perf_jit, presite, pycache_prefix, thread_inherit_context, and warn_default_encoding.

  • gh-113329: Fix OSError being raised when trying to run doctests on a class objects in the REPL. Patch by Sten Wessel.

  • gh-102967: A bug in doctest._SpoofOut.truncate() was causing None to be passed to StringIO.seek() when no size was given. A simple fix skips the seek call when no size is given so the buffer can be truncated from the current position.

  • gh-82039: http.cookiejar.FileCookieJar.load() now checks the first, format signature line in a case-insensitive manner. Patch by Ashley Harvey.

  • gh-70758: Creating a new turtle screen after the previous one was closed no longer raises turtle.Terminator on the first turtle command.

  • bpo-44012: The exploded attribute of ipaddress.IPv6Address and ipaddress.IPv6Interface now supports addresses with a scope ID (link-local addresses). Previously the former raised AddressValueError and the latter omitted the scope ID.

  • gh-83869: Fix tarfile reading an archive with a GNU sparse 1.0 member whose size is set in the pax extended header. The offset of the next header was computed from the offset of the data, which is already past the sparse map, and from the size of the member, which can be the apparent size of the sparse file. All following members were unreachable.

  • gh-61366: http.cookiejar.MozillaCookieJar now reads session cookies written by curl and Wget, which use 0 in the expiration time field. Contributed by Jérémie Detrey.

Core and Builtins

  • gh-156196: A failed assignment to an attribute defined with PyMemberDef of type Py_T_LONG, Py_T_LONGLONG, Py_T_PYSSIZET or Py_T_DOUBLE no longer changes its value.

  • gh-156189: Fix a crash when deleting the f_trace_opcodes attribute of a frame object. It now raises AttributeError.

  • gh-155515: Track the internal HAMT iterators, which back iteration over a contextvars.Context, with the garbage collector. A reference cycle running through such an iterator was never collected, leaking the whole context it iterated over.

  • gh-153578: Fix an out-of-bounds write in bytearray.extend() when the bytearray is resized while the argument’s __buffer__() is being acquired, for example by another thread. Patch by tonghuaroot.

  • gh-130094: Fix two race conditions involving concurrent imports that could lead to spurious failures with ModuleNotFoundError.

  • gh-85260: compile() now raises ValueError instead of crashing on a debug build if an identifier field of an AST node (such as the name of a function, a class, an imported module or a caught exception) is "None", "True" or "False".

Build

  • gh-155911: Fix curses detection when a curses library is already in LIBS. Patch by Shamil Abdulaev.

  • gh-156115: iOS simulator builds are now configured with -mios-simulator-version-min instead of the device’s -mios-version-min. The device flag made the linker reject libraries resolved from the simulator SDK, so library detection silently failed.

Python 3.13.15 final

Release date: 2026-08-05

macOS

  • gh-153711: On macOS, do not attempt to use the dup3(2) and pipe2(2) system calls introduced in macOS 27 to prevent problems when running on older systems.

Windows

  • gh-140146: Prevent tkinter from hanging on Windows if stdin is redirected to a pipe in an interactive session. This is helpful for testing interactive usage of tkinter from a script, for example as part of the cpython test suite.

Tools/Demos

  • gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms.

  • gh-155207: Argument Clinic now supports the --dry-run and --diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file.

  • gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code.

  • gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale.

Tests

  • gh-76595: Add C API tests for PyCapsule_Import().

  • gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job.

  • gh-154144: Fix building the _testcapi module on NetBSD.

  • gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run.

  • gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout.

  • gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix).

Security

  • gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.

  • gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.

  • gh-152216: Update bundled libexpat to version 2.8.2.

  • gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.

  • gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.

  • gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.

  • gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330.

  • gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4.

  • gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.

  • gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted.

Library

  • gh-155063: Bump the version of pip bundled in ensurepip to version 26.2.1

  • gh-155063: Bump the version of pip bundled in ensurepip to version 26.2

  • gh-154936: Fix the pure Python json decoder to report the correct position for invalid literal control characters in JSON strings.

  • gh-154892: Fix a bug in the C accelerator for zoneinfo where datetime.datetime subclasses returning -1 for hour, minute, or second could incorrectly raise a SystemError.

  • gh-154871: Fixed a crash in asyncio.Task.get_context() when called on an uninitialized task.

  • gh-154848: The pickle C accelerator now enforces frame boundaries when unpickling, as the pure Python implementation already did. An argument that straddles a frame boundary, or a frame that begins before the previous one has ended, now raises pickle.UnpicklingError instead of being silently read across the boundary. This prevents the loaded data from diverging from the pickletools disassembly of the same pickle.

  • gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break.

  • gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields.

  • gh-154738: Fix ExternalEntityParserCreate() not propagating the reparse-deferral setting to the subparser, which left GetReparseDeferralEnabled() returning an uninitialized value. Patch by tonghuaroot.

  • gh-93251: Fix UnicodeDecodeError in socket functions (such as getaddrinfo() and gethostbyaddr()) when the localized error message of the C library is not UTF-8: decode it from the locale encoding.

  • gh-154551: Fix ctypes.util.find_library() returning None in non-UTF-8 locales.

  • gh-79366: Fixed a race condition in logging: if a handler was removed while a record was being emitted, the following handlers of the same logger could be skipped.

  • gh-73458: Fix logging.config.listen(): it left the caller waiting for the ready event forever if the server could not be started, for example if the port was invalid or already in use. It now also binds to an IPv6 address if the host has no IPv4 address, for example if localhost is only aliased to ::1.

  • gh-154460: Fix time.strftime() and datetime.datetime.strftime() returning a wrong ISO 8601 week number (%V) on OpenBSD.

  • gh-154435: Fix os.posix_fadvise() and os.posix_fallocate() on DragonFly BSD: they raised OSError with a meaningless error code, because these functions return -1 and set errno there.

  • gh-154399: Fix venv activation in a non-interactive csh: activate.csh no longer fails when the prompt variable is not set.

  • gh-154389: Fix uuid.uuid1() on OpenBSD: it returned a version 4 UUID, because uuid_create() generates random UUIDs on this platform.

  • gh-154324: Fix os.sendfile() on illumos: it no longer reports a successful transfer when the underlying system call failed without writing any data.

  • gh-154307: Fix tempfile.TemporaryDirectory.cleanup() on DragonFly BSD, where removing a file with the UF_NOUNLINK flag failed with EISDIR instead of EPERM.

  • gh-154291: Fix socket.has_dualstack_ipv6() to return False on platforms such as DragonFly BSD where setting IPV6_V6ONLY to 0 silently has no effect.

  • gh-154283: On DragonFly BSD, threading.get_native_id() now returns a value that is unique across processes, matching the other platforms.

  • gh-154258: Fix a crash in mmap.mmap.resize() on NetBSD when growing a shared anonymous mapping. resize() now raises ValueError in this case, as it already did on Linux.

  • gh-154225: Fix os.openpty() on Solaris and illumos: it no longer leaves the pseudo-terminal as the controlling terminal of the calling process.

  • gh-154227: Fix os.posix_openpt() on OpenBSD, where it rejected the O_CLOEXEC flag.

  • gh-145030: Fix asyncio write pipe transports for named FIFOs on macOS and Solaris. Unread data sitting in the FIFO made the transport misinterpret a poll event as the reader disconnecting, wrongly closing the transport.

  • gh-154001: Fix random.binomialvariate() raising ZeroDivisionError when random.random() returns zero.

  • gh-153896: Deduplicate unhashable args in typing.Literal.

  • gh-153864: On a wide curses build, curses.window.insch() now inserts a non-ASCII byte as the character it encodes in the window’s encoding, consistently with addch(), instead of its code point.

  • gh-153862: On a wide curses build, curses.window.inch() now returns the locale-encoded byte of a non-ASCII character, matching instr(), instead of the low byte of its code point.

  • gh-146011: Fix a heap-use-after-free in the C implementation of decimal when calling repr() after deleting the Context.

  • gh-153761: Fix cancelling asyncio.loop.sock_accept() dropping a pending connection.

  • gh-153695: Hashing a sqlite3.Row that contains an unhashable value now raises TypeError instead of SystemError. Patch by tonghuaroot.

  • gh-153658: Fix sqlite3.Connection.iterdump() raising sqlite3.OperationalError when a table name contains a single quote. Patch by tonghuaroot.

  • gh-85943: Fix struct functions raising BytesWarning under the -bb command line option when a str format is used after an equal bytes format (or vice versa). The internal format cache no longer mixes str and bytes keys.

  • gh-153404: urllib.robotparser.RobotFileParser now silently ignores a Crawl-delay or Request-rate value written with non-decimal digits (such as U+00B2 SUPERSCRIPT TWO) instead of raising ValueError and aborting the parse of the whole robots.txt file.

  • gh-153417: Error messages from imaplib.IMAP4.select() and imaplib.IMAP4.uid() no longer raise BytesWarning under -bb when the mailbox or command argument is bytes.

  • gh-153406: email.utils.parsedate_to_datetime() now raises ValueError instead of OverflowError when the parsed year or timezone offset is out of range, matching its documented behavior.

  • gh-153083: Defer GC tracking of an array.array to the end of its construction. Patch by Donghee Na.

  • gh-143990: A tkinter.font.Font created from a named font, including by copy(), now copies its configured options rather than the options resolved by Tcl’s font actual, preserving a size specified in pixels (a negative size).

  • gh-153210: Fix crash on array import under a memory pressure.

  • gh-153200: Fix math.isqrt() returning an incorrect result for arguments not less than 2**64 that are instances of an int subclass with an overridden comparison operator.

  • gh-153068: Fix cProfile.Profile.enable() to no longer overwrite errors from sys.monitoring.

  • gh-153056: Fix string.Template raising a spurious ValueError when the pattern attribute is a compiled regular expression object, which the documentation allows.

  • gh-135661: Fix html.parser.HTMLParser: an abruptly closed empty comment (<!--> or <!--->) no longer extends up to a later --> in the same feed() call.

  • gh-54930: Error responses of http.server.BaseHTTPRequestHandler to malformed request lines now include a status line and headers instead of being sent in the bare HTTP/0.9 style. Only a valid HTTP/0.9 request (a two-word GET request line) now receives an HTTP/0.9 style response.

  • gh-152951: collections.deque prevent rare crash when calling extend under high memory pressure conditions.

  • gh-150880: Normalize non-extended Windows paths before appending the wildcard used by os.listdir() and os.scandir(), making paths with trailing spaces behave consistently with other filesystem APIs.

  • gh-152849: Out-of-range float and integer timestamps now raise OverflowError with the same message. Patch by tonghuaroot.

  • gh-152847: Reject a POSIX TZ transition rule with non-digit characters in the day-of-year field in the pure-Python zoneinfo parser. Patch by tonghuaroot.

  • gh-108280: Connecting imaplib to a server that does not send a valid IMAP4 greeting (for example a POP3 server answering on the IMAP port) now raises an error reporting the server’s response instead of imaplib.IMAP4.error: None.

  • gh-151126: Fix a crash caused by failing to set MemoryError on allocation failure when passing ctypes.Structure or ctypes.Union instances by value to ctypes foreign functions.

  • gh-63121: imaplib now refreshes the cached capability list after a successful login() or authenticate(), using the CAPABILITY response sent by the server or, if none was sent, by querying it, so that capabilities that become available only after authentication (such as ENABLE on Gmail) are recognized. Capabilities advertised in the server greeting are now also used, avoiding a redundant CAPABILITY command.

  • gh-88574: imaplib no longer fails when a server sends a spurious blank line after the counted data of a literal, including after a literal that terminates a response (such as a mailbox name returned by LIST). Such blank lines are now skipped without swallowing the following line.

  • gh-152502: Detect the curses mouse interface (getmouse(), the BUTTON* constants, and others) with a configure capability probe or library macros instead of gating it on ncurses-specific macros. It is now also available with other curses implementations that provide it, such as NetBSD curses and PDCurses (the latter underpins windows-curses).

  • gh-40038: imaplib now again quotes command arguments when necessary, for example mailbox names containing a space. Such quoting was inadvertently disabled when the module was ported to Python 3, and the arguments are now quoted according to the RFC 3501 grammar. For backward compatibility, an argument already enclosed in double quotes is left unchanged, so code that quotes arguments itself keeps working.

  • gh-50966: Fix unbounded recursion in turtle when a mouse event handler that moves the turtle is reentered while the screen is being redrawn, for example with screen.ondrag(turtle.goto). This could previously crash the interpreter.

  • gh-78335: Update the docstrings of tkinter and tkinter.ttk widget classes to list all supported widget options, including options added in Tk 9.0 and 9.1. tkinter.Menubutton and tkinter.Message previously had no option list at all.

  • gh-151126: Fix two crashes in tkinter and socket modules initialization under a memory pressure. Sets missing MemoryError.

  • gh-133031: curses.textpad.Textbox now enters and reads back the non-ASCII characters of an 8-bit locale encoding, instead of mangling them with a 7-bit mask.

  • gh-71880: curses.textpad.Textbox now lets the lower-right cell of the window be edited. Writing it with addch() would move the cursor past the end of the window, raising an error and scrolling a scrollable window, so it is now written with insch(), which keeps the cursor in place.

  • gh-83274: Deallocating a tkinter application from a thread other than the one it was created in no longer crashes the interpreter. The underlying Tcl interpreter is leaked instead, and a RuntimeWarning is reported.

  • gh-88758: tkinter.Misc.focus_get(), focus_displayof(), focus_lastfor() and winfo_containing() now return None instead of raising KeyError when the widget was not created by tkinter (for example a torn-off menu).

  • gh-38464: tkinter.Misc.nametowidget() now resolves the auto-generated names of cloned menus (a menu used as a menubar or a cascade) back to the original widget.

  • gh-152248: Make the C and pure-Python zoneinfo parsers validate POSIX TZ abbreviations consistently, rejecting unquoted abbreviations with non-letter characters and empty quoted abbreviations. Patch by tonghuaroot.

  • gh-80937: Fix a memory leak in tkinter when a Tcl command created with createcommand was not explicitly removed before the interpreter was deleted. The command no longer keeps the interpreter alive through a reference cycle.

  • gh-152246: Fix the pure-Python zoneinfo parser accepting an invalid POSIX TZ transition rule with a non-period separator. Patch by tonghuaroot.

  • gh-139816: Fix a hang in tkinter on interactive Python built without readline. An exception raised in a callback no longer causes the event loop to stop and wait for the user to press Enter; pending callbacks now keep running until input is actually available on stdin.

  • gh-139145: Fix a busy loop in tkinter on interactive Python. When a Tcl command running its own event loop (such as vwait or wait_variable()) was active and input arrived on stdin, the event loop kept spinning at 100% CPU. The stdin file handler is now removed as soon as input is available. Based on a patch by Michiel de Hoon.

  • gh-152212: Fix the pure-Python zoneinfo parser accepting a POSIX TZ string with a std abbreviation but no offset. This is invalid per POSIX and now raises ValueError, matching the C accelerator. Patch by tonghuaroot.

  • gh-152156: Fix a possible crash in _interpreters.create() under limited memory conditions.

  • gh-152157: The C implementations of fromisoformat() and fromisoformat() now reject a decimal separator that is not followed by any fractional digit before a timezone designator.

  • gh-151763: Fix crash in _interpqueues.create() whe MemoryError happens on queue creation.

  • gh-105895: Add match and case to the list of supported topics by help().

  • gh-152079: Fix datetime.datetime.fromisoformat() in the C implementation dropping the sub-second part of a UTC offset whose whole-second part is zero, matching the pure-Python implementation.

  • gh-152052: The json C accelerator now correctly reports an unterminated string for a \uXXXX escape at the end of the input.

  • gh-152060: Fix datetime.datetime.fromisoformat() raising AssertionError instead of ValueError for some malformed strings in the pure-Python implementation, matching the C implementation.

  • gh-126219: Fixed a crash in tkinter.Tk when className contains a non-BMP character and tkinter is built against Tcl/Tk 8.x. Such a name is now rejected with a ValueError.

  • gh-151955: Allow more types to be used in the bound argument to typing.ParamSpec.

  • gh-86165: Fix imaplib.Time2Internaldate() to use the local timezone offset for time.struct_time values with tm_gmtoff set to None, as returned by datetime.datetime.timetuple(). Contributed by Xiao Yuan.

  • gh-151814: Fix unbounded memory growth in io.TextIOWrapper when repeatedly writing an empty string.

  • gh-151695: Fix a use-after-free in the curses module. The encoding of the initial screen, used by curses.unctrl() and curses.ungetch() to encode non-ASCII characters, is now kept as a private copy instead of a borrowed pointer to a window object that may be deallocated.

  • gh-151596: Add missing size positional argument to the pure-Python implementation of io.TextIOBase.readline().

  • gh-148660: Fix a crash in collections.OrderedDict.copy() when a key’s __eq__ or a subclass method mutates the dict during the copy. Now raises RuntimeError instead, as iteration does.

  • gh-151497: Opening a tarfile archive no longer attempts to pre-allocate a huge buffer when a crafted or truncated member claims an oversized extended header (a GNU long name/link or a pax header). The extended header is now read in bounded chunks, so its size field can no longer trigger memory exhaustion.

  • gh-151403: Fixed a crash in subprocess.Popen (and _posixsubprocess.fork_exec) when an argv item’s __fspath__() concurrently mutates the args sequence being converted.

  • gh-151126: Fix crash on unset MemoryError on allocation failure in ctypes.get_errno().

  • gh-151416: Fix a crash in os.spawnv() and os.spawnve() when an argv item’s __fspath__() method mutates the argv list during argument conversion. os.spawnv() argument conversion errors other than TypeError, such as the ValueError for an embedded null, are no longer replaced with a generic TypeError.

  • gh-151337: Avoid possible memory leak in tkinter.c on Windows.

  • gh-151126: Fix a crash when MemoryError in os._path_splitroot() was not set properly.

  • gh-119710: Fix asyncio subprocess wait() hanging when the process has exited but one of its pipes is kept open by an inherited child process (so the pipe never reaches EOF). wait() now returns as soon as the process exits, regardless of the pipes’ state.

  • gh-151295: Fixed a crash (use-after-free) in bytes.join() and bytearray.join() that could occur if an item’s __buffer__() concurrently mutates the sequence being joined. The mutation is now reported as a RuntimeError instead.

  • gh-109940: Fix Windows venv activation in cmd.exe to respect VIRTUAL_ENV_DISABLE_PROMPT.

  • gh-117807: Fix mimetypes initialization from MIME map files containing invalid UTF-8 bytes.

  • gh-150771: Fix serialization of email messages using the shift_jis or euc-jp charsets: set_content() now encodes the payload using the output charset, so str(m) no longer raises UnicodeEncodeError.

  • gh-150484: Fix unittest.mock.mock_open() __exit__ raising TypeError when used with contextlib.ExitStack.

  • gh-149319: The asyncio REPL now ignores PYTHONSTARTUP and PYTHON_BASIC_REPL when -E or -I is used. Patch by Jonathan Dung.

  • gh-149221: Catch rare math domain error for random.binomialvariate().

  • gh-148441: xml.parsers.expat: prevent a crash in CharacterDataHandler() when the character data size exceeds the parser’s buffer size.

  • gh-47005: Fix urllib.request.AbstractHTTPHandler.do_open() to give regular headers set via add_header() priority over unredirected headers, consistent with get_header() and header_items().

  • gh-123720: asyncio: Fix asyncio.Server.serve_forever() shutdown regression. Since 3.12, cancelling serve_forever() could hang waiting for a handler blocked on a read from a client that never closed (effectively requiring two interrupts to stop); the shutdown sequence now ensures client streams are closed so serve_forever() exits promptly and handlers observe EOF.

  • gh-143988: Fixed crashes in socket.socket.sendmsg() and socket.socket.recvmsg_into() that could occur if buffer sequences are concurrently mutated.

  • gh-130796: Undeprecate the locale.getdefaultlocale() function. Patch by Victor Stinner.

  • gh-115634: Fix a deadlock in concurrent.futures.ProcessPoolExecutor when using max_tasks_per_child, present since the feature was introduced in Python 3.11. The executor stopped scheduling queued tasks after a worker process exited upon reaching its task limit. Based on a fix proposed by Tabrez Mohammed.

  • gh-79638: Disallow all access in urllib.robotparser if the robots.txt file is unreachable due to server or network errors.

  • gh-120665: Fixed an issue where unittest loaders would load and instantiate unittest.TestCase-derived subclasses that are also abstract base classes, which can’t be instantiated.

  • gh-105708: Accept an uppercase V prefix in IPvFuture addresses in urllib.parse.urlsplit().

  • gh-103925: Fix csv.Sniffer.sniff() for a sample with \r\n line endings in which a quoted field ends a line: a letter could be detected as the delimiter.

  • gh-101267: When a worker process terminates unexpectedly, concurrent.futures.ProcessPoolExecutor now sets a separate BrokenProcessPool exception on each pending future instead of sharing a single instance among them all. Sharing one exception produced malformed tracebacks: each Future.result() call re-raised the same object, appending another copy of the traceback to it.

IDLE

  • gh-82183: When the shell is busy running code, using “Run… Customized” with “Restart shell” unchecked now reports that the shell is executing instead of restarting it anyway.

  • gh-83653: Blanking an integer entry in IDLE’s Settings dialog, such as “Auto squeeze min lines”, no longer saves an empty string as an invalid configuration value.

  • gh-65339: Saving the IDLE Shell or an Output window now defaults to a .txt extension and lists text files before Python files, since their content is not Python source.

  • gh-80504: The “In files:” field of IDLE’s Find in Files dialog now always contains a full directory path, even for an unsaved editor or the Shell. This shows in the grep output which directory was searched.

  • gh-134300: Do not add the idlelib directory to the path of the IDLE user process. User code run in IDLE can no longer import idlelib submodules as top-level modules, such as import help.

  • gh-89360: Fix a rare crash in the IDLE editor when the completion window is closed: deleting a key binding for a sequence that is not bound to the virtual event is now ignored instead of raising a ValueError.

  • gh-71956: Fix Replace All in the IDLE editor’s Replace dialog when the search direction is “Up” and “Wrap around” is off: it now replaces all matches above the current position instead of only the first one.

  • gh-152728: Move functions run.fix_scaling, editor.fixwordbreaks (as fix_word_breaks) and pyshell.fix_x11_paste to idlelib.util.

  • gh-66331: Set the WM_CLASS window property of IDLE’s windows to Idle on X11, so that window managers group and label them correctly instead of using the default Toplevel.

  • gh-85320: IDLE now reads and writes its configuration files and the breakpoints file using UTF-8 instead of the locale encoding. This keeps non-ASCII data (such as non-ASCII paths) from being corrupted and makes the files portable between environments.

  • gh-94523: Detect file if modified at local disk and prompt to ask refresh. Patch by Shixian Li.

  • gh-139551: Support rendering BaseExceptionGroup in IDLE.

  • gh-89520: Make IDLE extension configuration look at user config files, allowing user-installed extensions to have settings and key bindings defined in ~/.idlerc.

Documentation

  • gh-118150: Clarify in the difflib documentation what junk actually does, its drawbacks, and how to control it.

  • gh-86726: Greatly expand the tkinter documentation to cover the full public API of the package and its submodules. The descriptions are oriented towards Python rather than Tcl/Tk, with corrected return types and versionadded/versionchanged information.

Core and Builtins

  • gh-154937: Fix a data race on thread handle identifiers when _thread._shutdown() runs concurrently with the startup of non-daemon threads in the free-threaded build.

  • gh-154709: Fix an out-of-bounds access in reverse dictionary iterators when the underlying dictionary is cleared and modified after the iterator is created.

  • gh-154275: Fix a crash when getting deeply nested __parameters__ from a types.GenericAlias objects.

  • gh-152682: Fix NULL pointer dereference in compile() when a reserved name (e.g. __classdict__) is used as a type parameter name and memory allocation fails while formatting the error message.

  • gh-152635: Fix a crash caused when running out of memory creating a _interpchannels channel. Now a MemoryError is correctly raised.

  • gh-152375: Fix undefined behaviour when a sys.monitoring callback raised an exception while the program was following a branch or loop.

  • gh-152235: Defer GC tracking of set.intersection(), set.difference(), set.symmetric_difference(), set.union() and set.__sub__. Patch by Donghee Na.

  • gh-152235: Defer GC tracking of a set or frozenset to the end of its construction from iterable. Patch by Donghee Na.

  • gh-151905: Fix OOM error handling in PyFrame_GetBack() to propagate exceptions instead of masking them as None.

  • gh-151763: Fix a potential crash in compile(), exec(), eval() and ast.parse() when an allocation fails: the parser or compiler could return without setting an exception.

  • gh-151912: Fixed a crash in type() when selecting a metaclass whose tp_new slot is NULL. Such metaclasses are now rejected with TypeError instead of causing a NULL pointer dereference.

  • gh-151773: Fix a crash in contextvars.ContextVar.set() when memory allocation fails.

  • gh-151126: Fix a crash when sharing memoryview objects between interpreters fails due to running out of memory. It now raises a proper MemoryError.

  • gh-151126: Avoid possible crash in _winapi.c where a device has no memory left. Now it properly raises a MemoryError. Patch by Ivy Xu.

  • gh-151253: If import encodings (first import) fails at Python startup, dump the Python path configuration to help users debugging their configuration. Patch by Victor Stinner.

  • gh-151126: Fix a crash, when there’s no memory left on a device, which happened in _interpchannels module.

    Now it raises proper MemoryError errors.

  • gh-151065: Fix memory leak when using the mimalloc memory allocator.

  • gh-150988: Fix a reference leak in OSError when attributes are set before super().__init__().

  • gh-149689: Fix missing error propagation in parser action helpers when memory allocation fails. Patch by Thomas Kowalski.

C API

  • gh-152132: Fix Py_RunMain() to return an exit code, rather than calling Py_Exit(), when running a script, a command, or the REPL. Patch by Victor Stinner.

Build

  • gh-154070: Build the curses module against a wide-character capable ncurses even when it is not named ncursesw – for example the pkgsrc ncurses on NetBSD and illumos, or the system ncurses on macOS. Such a library previously produced a narrow build.

  • gh-126877: Fix the configure check for Tcl/Tk which could wrongly succeed with optimizing compilers when the libraries are missing.

  • gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe.

  • gh-152502: The curses module now detects set_escdelay(), set_tabsize() and the ESCDELAY and TABSIZE variables with configure capability probes instead of the ncurses-specific NCURSES_EXT_FUNCS macro, so they are exposed when building against other curses implementations such as NetBSD curses that provide them.

  • gh-138800: Fix library name in python3.pc on Android.

  • gh-115869: Make jit_stencils.h (which is produced during JIT builds) reproducible.

Python 3.13.14 final

Release date: 2026-06-10

macOS

  • gh-124111: Update macOS installer to use Tcl/Tk 8.6.18.

  • gh-150644: When system logging is enabled (with config.use_system_logger, messages are now tagged as public. This allows the macOS 26 system logger to view messages without special configuration.

  • gh-115119: Update macOS installer to use libmpdecimal 4.0.1.

  • gh-151159: Update macOS installer to use OpenSSL 3.0.21.

Windows

  • gh-151159: Updated bundled version of OpenSSL to 3.0.21.

Tests

  • gh-151130: Add more tests for PyWeakref_* C API.

  • gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.

Security

  • gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.

  • gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.

  • gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard.

  • gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186.

  • gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report.

  • gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter.

  • gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.

  • gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later.

  • gh-149017: Update bundled libexpat to version 2.8.0.

  • gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping.

  • gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop.

  • gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer.

  • gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check.

  • gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped.

  • gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage.

  • gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.

Library

  • gh-150913: Fix sqlite3.Blob slice assignment to raise TypeError and IndexError for type and size mismatches respectively, even when the target slice is empty.

  • gh-143008: Fix race conditions when re-initializing a io.TextIOWrapper object.

  • gh-150685: Update bundled pip to 26.1.2

  • gh-150406: Fix a possible crash occurring during socket module initialization when the system is out of memory on platforms without a reentrant gethostbyname.

  • gh-150372: readline: Fix a potential crash during tab completion caused by an out-of-memory error during module initialization.

  • gh-150175: Fix race condition in unittest.mock.ThreadingMock where concurrent calls could lose increments to call_count and other attributes due to a missing lock in _increment_mock_call.

  • gh-84353: Preserve non-UTF-8 encoded filenames when appending to a zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8.

  • gh-149995: Update various docstrings in typing.

  • gh-88726: The email package now uses standard MIME charset names “gb2312” and “big5” instead of non-standard names “eucgb2312_cn” and “big5_tw”.

  • gh-149571: Fix the C implementation of xml.etree.ElementTree.Element.itertext(): it no longer emits text for comments and processing instructions.

  • gh-149921: Fix reference leaks in error paths of the _interpchannels and _interpqueues extension modules.

  • gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs.

  • gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled

  • gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects.

  • gh-149388: Make asyncio.windows_utils.PipeHandle closing idempotent.

  • gh-149489: Fix ElementTree serialization to HTML. The content of elements “xmp”, “iframe”, “noembed”, “noframes”, and “plaintext” is no longer escaped. The “plaintext” element no longer have the closing tag.

  • gh-149377: Update bundled pip to 26.1.1

  • gh-149231: In tomllib, the number of parts in TOML keys is now limited.

  • gh-149117: Fix runpy.run_module() and runpy.run_path() to set the name attribute on the ImportError they raise.

  • gh-149148: ensurepip: Upgrade bundled pip to 26.1. This version fixes the CVE 2026-3219 vulnerability. Patch by Victor Stinner.

  • gh-148093: Fix an out-of-bounds read of one byte in binascii.a2b_uu(). Raise binascii.Error, instead of reading past the buffer end.

  • gh-148914: Fix memoization of in-band PickleBuffer in the Python implementation of pickle. Previously, identical PickleBuffers did not preserve identity, and empty writable PickleBuffer memoized an empty bytearray object in place of b'', so the following references to b'' were unpickled as an empty bytearray object.

  • gh-138907: Support RFC 9309 in urllib.robotparser.

  • gh-148954: Fix XML injection vulnerability in xmlrpc.client.dumps() where the methodname was not being escaped before interpolation into the XML body.

  • gh-148801: xml.etree.ElementTree: Fix a crash in Element.__deepcopy__ on deeply nested trees.

  • gh-148735: xml.etree.ElementTree: Fix a use-after-free in Element.findtext when the element tree is mutated concurrently during the search.

  • gh-146553: Fix infinite loop in typing.get_type_hints() when __wrapped__ forms a cycle. Patch by Shamil Abdulaev.

  • gh-148508: An intermittent timing error when running SSL tests on iOS has been resolved.

  • gh-148518: If an email containing an address header that ended in an open double quote was parsed with a non-compat32 policy, accessing the username attribute of the mailbox accessed through that header object would result in an IndexError. It now correctly returns an empty string as the result.

  • gh-148370: configparser: prevent quadratic behavior when a ParsingError is raised after a parser fails to parse multiple lines. Patch by Bénédikt Tran.

  • gh-148254: Use singular “sec” instead of “secs” in timeit verbose output for consistency with other time units.

  • gh-148192: email.generator.Generator._make_boundary could fail to detect a duplicate boundary string if linesep was not n. It now correctly detects boundary strings when linesep is rn as well.

  • gh-146313: Fix a deadlock in multiprocessing’s resource tracker where the parent process could hang indefinitely in os.waitpid() during interpreter shutdown if a child created via os.fork() still held the resource tracker’s pipe open.

  • gh-145831: Fix email.quoprimime.decode() leaving a stray \r when eol='\r\n' by stripping the full eol string instead of one character.

  • gh-145105: Fix crash in csv reader when iterating with a re-entrant iterator that calls next() on the same reader from within __next__.

  • gh-130750: Restore quoting of choices in argparse error messages for improved clarity and consistency with documentation.

  • gh-105936: Attempting to mutate non-field attributes of dataclasses with both frozen and slots being True now raises FrozenInstanceError instead of TypeError. Their non-dataclass subclasses can now freely mutate non-field attributes, and the original non-slotted class can be garbage collected. The fix also handles the case of an empty __class__ cell on a function found within the class (gh-148947).

  • gh-142516: ssl: fix reference leaks in ssl.SSLContext objects. Patch by Bénédikt Tran.

  • gh-142831: Fix a crash in the json module where a use-after-free could occur if the object being encoded is modified during serialization.

  • gh-140287: The asyncio REPL now handles exceptions when executing PYTHONSTARTUP scripts. Patch by Bartosz Sławecki.

  • gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.

  • gh-132631: Fix “I/O operation on closed file” when parsing JSON Lines file with JSON CLI.

  • gh-128110: Fix bug in the parsing of email address headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject).

  • gh-107398: Fix tarfile stream mode exception when process the file with the gzip extra field.

  • gh-123853: Update the table of Windows language code identifiers (LCIDs) used by locale.getdefaultlocale() on Windows to protocol version 16.0 (2024-04-23).

  • gh-70039: Fixed bug where smtplib.SMTP.starttls() could fail if smtplib.SMTP.connect() is called explicitly rather than implicitly.

  • gh-83281: email: improve handling trailing garbage in address lists to avoid throwing AttributeError in certain edge cases

  • gh-91099: imaplib.IMAP4.login() now raises exceptions with str instead of bytes. Patch by Florian Best.

IDLE

  • bpo-6699: Warn the user if a file will be overwritten when saving.

Documentation

Core and Builtins

  • gh-151112: Fix a crash in the compiler that could occur when running out of memory.

  • gh-151126: Fix a crash, when there’s no memory left on a device, which happened in:

    • code compilation - _winapi.CreateProcess()

    Now these places raise proper MemoryError errors.

  • gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects.

  • gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process.

  • gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler.

  • gh-148450: Fix abc.register() so it invalidates type version tags for registered classes.

  • gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper MemoryError is now raised instead.

  • gh-150107: asyncio: sendfile() and sock_sendfile() event loop methods now call file.seek(offset) if file has a seek() method, even if offset is 0 (default value).

  • gh-150146: Fix a crash on a complex type variable substitution.

    from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to fail due to missing NULL check on _unpack_args C function call.

  • gh-149590: Fix crash when faulthandler is imported more than once.

  • gh-149738: sqlite3: Disallow removing row_factory and text_factory attributes of a connection to prevent a crash on a query.

  • gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by -X perf_jit (Linux perf profiler integration).

  • gh-148820: Fix a race in _PyRawMutex on the free-threaded build where a Py_PARK_INTR return from _PySemaphore_Wait could let the waiter destroy its semaphore before the unlocking thread’s _PySemaphore_Wakeup completed, causing a fatal ReleaseSemaphore error.

  • gh-148653: Forbid marshalling recursive code objects which cannot be correctly unmarshalled.

  • gh-148390: Fix an undefined behavior in memoryview when using the native boolean format (?) in cast(). Previously, on some common platforms, calling memoryview(b).cast("?").tolist() incorrectly returned [False] instead of [True] for any even byte b. Patch by Bénédikt Tran.

  • gh-148418: Fix a possible reference leak in a corrupted TYPE_CODE marshal stream.

  • gh-148222: Fix vectorcall support in types.GenericAlias when the underlying type does not support the vectorcall protocol. Fix possible leaks in types.GenericAlias and types.UnionType in case of memory error.

  • gh-145376: Fix reference leaks in various unusual error scenarios.

C API

  • gh-150907: Fix dynamic_annotations.h header file when built with C++ and Valgrind: add extern "C++" scope for the C++ template. Patch by Victor Stinner.

Build

  • gh-149351: Avoid possible broken macOS framework install names when DESTDIR is specified during builds.

  • gh-146475: Block Apple Clang from being used to build the JIT as it ships without required LLVM tools.

  • gh-148535: No longer use the gcc -fprofile-update=atomic flag on i686. The flag has been added to fix a random GCC internal error on PGO build (gh-145801) caused by corruption of profile data (.gcda files). The problem is that it makes the PGO build way slower (up to 47x slower) on i686. Since the GCC internal error was not seen on i686 so far, don’t use -fprofile-update=atomic on i686 anymore. Patch by Victor Stinner.

Python 3.13.13 final

Release date: 2026-04-07

macOS

Windows

  • gh-144551: Updated bundled version of OpenSSL to 3.0.19.

  • gh-140131: Fix REPL cursor position on Windows when module completion suggestion line hits console width.

Tests

  • gh-144418: The Android testbed’s emulator RAM has been increased from 2 GB to 4 GB.

  • gh-146202: Fix a race condition in regrtest: make sure that the temporary directory is created in the worker process. Previously, temp_cwd() could fail on Windows if the “build” directory was not created. Patch by Victor Stinner.

  • gh-144739: When Python was compiled with system expat older then 2.7.2 but tests run with newer expat, still skip test.test_pyexpat.MemoryProtectionTest.

Security

Library

Documentation

  • gh-126676: Expand argparse documentation for type=bool with a demonstration of the surprising behavior and pointers to common alternatives.

  • gh-145450: Document missing public wave.Wave_write getter methods.

Core and Builtins

  • gh-148157: Fix an unlikely crash when parsing an invalid type comments for function parameters. Found by OSS Fuzz in #492782951.

  • gh-146615: Fix a crash in __get__() for METH_METHOD descriptors when an invalid (non-type) object is passed as the second argument. Patch by Steven Sun.

  • gh-146128: Fix a bug which could cause constant values to be partially corrupted in AArch64 JIT code. This issue is theoretical, and hasn’t actually been observed in unmodified Python interpreters.

  • gh-146250: Fixed a memory leak in SyntaxError when re-initializing it.

  • gh-146245: Fixed reference leaks in socket when audit hooks raise exceptions in socket.getaddrinfo() and socket.sendto().

  • gh-146227: Fix wrong type in _Py_atomic_load_uint16 in the C11 atomics backend (pyatomic_std.h), which used a 32-bit atomic load instead of 16-bit. Found by Mohammed Zuhaib.

  • gh-146056: Fix repr() for lists containing NULLs.

  • gh-145990: python --help-env sections are now sorted by environment variable name.

  • gh-145376: Fix GC tracking in structseq.__replace__().

  • gh-142183: Avoid a pathological case where repeated calls at a specific stack depth could be significantly slower.

  • gh-145783: Fix an unlikely crash in the parser when certain errors were erroneously not propagated. Found by OSS Fuzz in #491369109.

  • gh-145701: Fix SystemError when __classdict__ or __conditional_annotations__ is in a class-scope inlined comprehension. Found by OSS Fuzz in #491105000.

  • gh-145335: Fix a crash in os.pathconf() when called with -1 as the path argument.

  • gh-145234: Fixed a SystemError in the parser when an encoding cookie (for example, UTF-7) decodes to carriage returns (\r). Newlines are now normalized after decoding in the string tokenizer.

    Patch by Pablo Galindo.

  • gh-130555: Fix use-after-free in dict.clear() when the dictionary values are embedded in an object and a destructor causes re-entrant mutation of the dictionary.

  • gh-145008: Fix a bug when calling certain methods at the recursion limit which manifested as a corruption of Python’s operand stack. Patch by Ken Jin.

  • gh-144872: Fix heap buffer overflow in the parser found by OSS-Fuzz.

  • gh-144766: Fix a crash in fork child process when perf support is enabled.

  • gh-144759: Fix undefined behavior in the lexer when start and multi_line_start pointers are NULL in _PyLexer_remember_fstring_buffers() and _PyLexer_restore_fstring_buffers(). The NULL pointer arithmetic (NULL - valid_pointer) is now guarded with explicit NULL checks.

  • gh-144601: Fix crash when importing a module whose PyInit function raises an exception from a subinterpreter.

  • gh-143636: Fix a crash when calling SimpleNamespace.__replace__() on non-namespace instances. Patch by Bénédikt Tran.

  • gh-143650: Fix race condition in importlib where a thread could receive a stale module reference when another thread’s import fails.

  • gh-140594: Fix an out of bounds read when a single NUL character is read from the standard input. Patch by Shamil Abdulaev.

  • gh-91636: While performing garbage collection, clear weakrefs to unreachable objects that are created during running of finalizers. If those weakrefs were are not cleared, they could reveal unreachable objects.

  • gh-130327: Fix erroneous clearing of an object’s __dict__ if overwritten at runtime.

  • gh-80667: Literals using the \N{name} escape syntax can now construct CJK ideographs and Hangul syllables using case-insensitive names.

Build

  • gh-146541: The Android testbed can now be built for 32-bit ARM and x86 targets.

  • gh-146450: The Android build script was modified to improve parity with other platform build scripts.

  • gh-145801: When Python build is optimized with GCC using PGO, use -fprofile-update=atomic option to use atomic operations when updating profile information. This option reduces the risk of gcov Data Files (.gcda) corruption which can cause random GCC crashes. Patch by Victor Stinner.

  • gh-129259: Fix AIX build failures caused by incorrect struct alignment in _Py_CODEUNIT and _Py_BackoffCounter by adding AIX-specific #pragma pack directives.

Python 3.13.12 final

Release date: 2026-02-03

Windows

  • gh-128067: Fix a bug in PyREPL on Windows where output without a trailing newline was overwritten by the next prompt.

Tools/Demos

  • gh-142095: Make gdb ‘py-bt’ command use frame from thread local state when available. Patch by Sam Gross and Victor Stinner.

Tests

  • gh-144415: The Android testbed now distinguishes between stdout/stderr messages which were triggered by a newline, and those triggered by a manual call to flush. This fixes logging of progress indicators and similar content.

  • gh-65784: Add support for parametrized resource wantobjects in regrtests, which allows to run Tkinter tests with the specified value of tkinter.wantobjects, for example -u wantobjects=0.

  • gh-143553: Add support for parametrized resources, such as -u xpickle=2.7.

  • gh-142836: Accommodated Solaris in test_pdb.test_script_target_anonymous_pipe.

  • gh-129401: Fix a flaky test in test_repr_rlock that checks the representation of multiprocessing.RLock.

  • bpo-31391: Forward-port test_xpickle from Python 2 to Python 3 and add the resource back to test’s command line.

Security

  • gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).

  • gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.

  • gh-143925: Reject control characters in data: URL media types.

  • gh-143919: Reject control characters in http.cookies.Morsel fields and values.

  • gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.

Library

  • gh-144380: Improve performance of io.BufferedReader line iteration by ~49%.

  • gh-144169: Fix three crashes when non-string keyword arguments are supplied to objects in the ast module.

  • gh-144100: Fixed a crash in ctypes when using a deprecated POINTER(str) type in argtypes. Instead of aborting, ctypes now raises a proper Python exception when the pointer target type is unresolved.

  • gh-144050: Fix stat.filemode() in the pure-Python implementation to avoid misclassifying invalid mode values as block devices.

  • gh-144023: Fixed validation of file descriptor 0 in posix functions when used with follow_symlinks parameter.

  • gh-143999: Fix an issue where inspect.getgeneratorstate() and inspect.getcoroutinestate() could fail for generators wrapped by types.coroutine() in the suspended state.

  • gh-143706: Fix multiprocessing forkserver so that sys.argv is correctly set before __main__ is preloaded. Previously, sys.argv was empty during main module import in forkserver child processes. This fixes a regression introduced in 3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test provided by Thomas Watson, thanks!

  • gh-143638: Forbid reentrant calls of the pickle.Pickler and pickle.Unpickler methods for the C implementation. Previously, this could cause crash or data corruption, now concurrent calls of methods of the same object raise RuntimeError.

  • gh-78724: Raise RuntimeError’s when user attempts to call methods on half-initialized Struct objects, For example, created by Struct.__new__(Struct). Patch by Sergey B Kirpichev.

  • gh-143602: Fix a inconsistency issue in write() that leads to unexpected buffer overwrite by deduplicating the buffer exports.

  • gh-143547: Fix sys.unraisablehook() when the hook raises an exception and changes sys.unraisablehook(): hold a strong reference to the old hook. Patch by Victor Stinner.

  • gh-143378: Fix use-after-free crashes when a BytesIO object is concurrently mutated during write() or writelines().

  • gh-143346: Fix incorrect wrapping of the Base64 data in plistlib._PlistWriter when the indent contains a mix of tabs and spaces.

  • gh-143310: tkinter: fix a crash when a Python list is mutated during the conversion to a Tcl object (e.g., when setting a Tcl variable). Patch by Bénédikt Tran.

  • gh-143309: Fix a crash in os.execve() on non-Windows platforms when given a custom environment mapping which is then mutated during parsing. Patch by Bénédikt Tran.

  • gh-143308: pickle: fix use-after-free crashes when a PickleBuffer is concurrently mutated by a custom buffer callback during pickling. Patch by Bénédikt Tran and Aaron Wieczorek.

  • gh-143237: Fix support of named pipes in the rotating logging handlers.

  • gh-143249: Fix possible buffer leaks in Windows overlapped I/O on error handling.

  • gh-143241: zoneinfo: fix infinite loop in ZoneInfo.from_file when parsing a malformed TZif file. Patch by Fatih Celik.

  • gh-142830: sqlite3: fix use-after-free crashes when the connection’s callbacks are mutated during a callback execution. Patch by Bénédikt Tran.

  • gh-143200: xml.etree.ElementTree: fix use-after-free crashes in __getitem__() and __setitem__() methods of Element when the element is concurrently mutated. Patch by Bénédikt Tran.

  • gh-142195: Updated timeout evaluation logic in subprocess to be compatible with deterministic environments like Shadow where time moves exactly as requested.

  • gh-143145: Fixed a possible reference leak in ctypes when constructing results with multiple output parameters on error.

  • gh-122431: Corrected the error message in readline.append_history_file() to state that nelements must be non-negative instead of positive.

  • gh-143004: Fix a potential use-after-free in collections.Counter.update() when user code mutates the Counter during an update.

  • gh-143046: The asyncio REPL no longer prints copyright and version messages in the quiet mode (-q). Patch by Bartosz Sławecki.

  • gh-140648: The asyncio REPL now respects the -I flag (isolated mode). Previously, it would load and execute PYTHONSTARTUP even if the flag was set. Contributed by Bartosz Sławecki.

  • gh-142991: Fixed socket operations such as recvfrom() and sendto() for FreeBSD divert(4) socket.

  • gh-143010: Fixed a bug in mailbox where the precise timing of an external event could result in the library opening an existing file instead of a file it expected to create.

  • gh-142881: Fix concurrent and reentrant call of atexit.unregister().

  • gh-112127: Fix possible use-after-free in atexit.unregister() when the callback is unregistered during comparison.

  • gh-142783: Fix zoneinfo use-after-free with descriptor _weak_cache. a descriptor as _weak_cache could cause crashes during object creation. The fix ensures proper reference counting for descriptor-provided objects.

  • gh-142754: Add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.

  • gh-142784: The asyncio REPL now properly closes the loop upon the end of interactive session. Previously, it could cause surprising warnings. Contributed by Bartosz Sławecki.

  • gh-142555: array: fix a crash in a[i] = v when converting i to an index via i.__index__ or i.__float__ mutates the array.

  • gh-142594: Fix crash in TextIOWrapper.close() when the underlying buffer’s closed property calls detach().

  • gh-142451: hmac: Ensure that the HMAC.block_size attribute is correctly copied by HMAC.copy. Patch by Bénédikt Tran.

  • gh-142495: collections.defaultdict now prioritizes __setitem__() when inserting default values from default_factory. This prevents race conditions where a default value would overwrite a value set before default_factory returns.

  • gh-142651: unittest.mock: fix a thread safety issue where Mock.call_count may return inaccurate values when the mock is called concurrently from multiple threads.

  • gh-142595: Added type check during initialization of the decimal module to prevent a crash in case of broken stdlib. Patch by Sergey B Kirpichev.

  • gh-142517: The non-compat32 email policies now correctly handle refolding encoded words that contain bytes that can not be decoded in their specified character set. Previously this resulted in an encoding exception during folding.

  • gh-112527: The help text for required options in argparse no longer extended with “ (default: None)”.

  • gh-142315: Pdb can now run scripts from anonymous pipes used in process substitution. Patch by Bartosz Sławecki.

  • gh-142282: Fix winreg.QueryValueEx() to not accidentally read garbage buffer under race condition.

  • gh-75949: Fix argparse to preserve | separators in mutually exclusive groups when the usage line wraps due to length.

  • gh-68552: MisplacedEnvelopeHeaderDefect and Missing header name defects are now correctly passed to the handle_defect method of policy in FeedParser.

  • gh-142006: Fix a bug in the email.policy.default folding algorithm which incorrectly resulted in a doubled newline when a line ending at exactly max_line_length was followed by an unfoldable token.

  • gh-105836: Fix asyncio.run_coroutine_threadsafe() leaving underlying cancelled asyncio task running.

  • gh-139971: pydoc: Ensure that the link to the online documentation of a stdlib module is correct.

  • gh-139262: Some keystrokes can be swallowed in the new PyREPL on Windows, especially when used together with the ALT key. Fix by Chris Eibl.

  • gh-138897: Improved license/copyright/credits display in the REPL: now uses a pager.

  • gh-79986: Add parsing for References and In-Reply-To headers to the email library that parses the header content as lists of message id tokens. This prevents them from being folded incorrectly.

  • gh-109263: Starting a process from spawn context in multiprocessing no longer sets the start method globally.

  • gh-90871: Fixed an off by one error concerning the backlog parameter in create_unix_server(). Contributed by Christian Harries.

  • gh-133253: Fix thread-safety issues in linecache.

  • gh-132715: Skip writing objects during marshalling once a failure has occurred.

  • gh-127529: Correct behavior of asyncio.selector_events.BaseSelectorEventLoop._accept_connection() in handling ConnectionAbortedError in a loop. This improves performance on OpenBSD.

IDLE

  • gh-143774: Better explain the operation of Format / Format Paragraph.

Documentation

Core and Builtins

  • gh-144307: Prevent a reference leak in module teardown at interpreter finalization.

  • gh-144194: Fix error handling in perf jitdump initialization on memory allocation failure.

  • gh-141805: Fix crash in set when objects with the same hash are concurrently added to the set after removing an element with the same hash while the set still contains elements with the same hash.

  • gh-143670: Fixes a crash in ga_repr_items_list function.

  • gh-143377: Fix a crash in _interpreters.capture_exception() when the exception is incorrectly formatted. Patch by Bénédikt Tran.

  • gh-143189: Fix crash when inserting a non-str key into a split table dictionary when the key matches an existing key in the split table but has no corresponding value in the dict.

  • gh-143228: Fix use-after-free in perf trampoline when toggling profiling while threads are running or during interpreter finalization with daemon threads active. The fix uses reference counting to ensure trampolines are not freed while any code object could still reference them. Pach by Pablo Galindo

  • gh-142664: Fix a use-after-free crash in memoryview.__hash__ when the __hash__ method of the referenced object mutates that object or the view. Patch by Bénédikt Tran.

  • gh-142557: Fix a use-after-free crash in bytearray.__mod__ when the bytearray is mutated while formatting the %-style arguments. Patch by Bénédikt Tran.

  • gh-143195: Fix use-after-free crashes in bytearray.hex() and memoryview.hex() when the separator’s __len__() mutates the original object. Patch by Bénédikt Tran.

  • gh-143135: Set sys.flags.inspect to 1 when PYTHONINSPECT is 0. Previously, it was set to 0 in this case.

  • gh-143003: Fix an overflow of the shared empty buffer in bytearray.extend() when __length_hint__() returns 0 for non-empty iterator.

  • gh-143006: Fix a possible assertion error when comparing negative non-integer float and int with the same number of bits in the integer part.

  • gh-142776: Fix a file descriptor leak in import.c

  • gh-142829: Fix a use-after-free crash in contextvars.Context comparison when a custom __eq__ method modifies the context via set().

  • gh-142766: Clear the frame of a generator when generator.close() is called.

  • gh-142737: Tracebacks will be displayed in fallback mode even if io.open() is lost. Previously, this would crash the interpreter. Patch by Bartosz Sławecki.

  • gh-142554: Fix a crash in divmod() when _pylong.int_divmod() does not return a tuple of length two exactly. Patch by Bénédikt Tran.

  • gh-142560: Fix use-after-free in bytearray search-like methods (find(), count(), index(), rindex(), and rfind()) by marking the storage as exported which causes reallocation attempts to raise BufferError. For contains(), split(), and rsplit() the buffer protocol is used for this.

  • gh-142343: Fix SIGILL crash on m68k due to incorrect assembly constraint.

  • gh-141732: Ensure the __repr__() for ExceptionGroup and BaseExceptionGroup does not change when the exception sequence that was original passed in to its constructor is subsequently mutated.

  • gh-100964: Fix reference cycle in exhausted generator frames. Patch by Savannah Ostrowski.

  • gh-140373: Correctly emit PY_UNWIND event when generator object is closed. Patch by Mikhail Efimov.

  • gh-138568: Adjusted the built-in help() function so that empty inputs are ignored in interactive mode.

  • gh-127773: Do not use the type attribute cache for types with incompatible MRO.

C API

  • gh-142571: PyUnstable_CopyPerfMapFile() now checks that opening the file succeeded before flushing.

Build

  • gh-142454: When calculating the digest of the JIT stencils input, sort the hashed files by filenames before adding their content to the hasher. This ensures deterministic hash input and hence deterministic hash, independent on filesystem order.

  • gh-141808: When running make clean-retain-profile, keep the generated JIT stencils. That way, the stencils are not generated twice when Profile-guided optimization (PGO) is used. It also allows distributors to supply their own pre-built JIT stencils.

  • gh-138061: Ensure reproducible builds by making JIT stencil header generation deterministic.

Python 3.13.11 final

Release date: 2025-12-05

Security

  • gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing.

  • gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.

  • gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.

Library

  • gh-140797: Revert changes to the undocumented re.Scanner class. Capturing groups are still allowed for backward compatibility, although using them can lead to incorrect result. They will be forbidden in future Python versions.

  • gh-142206: The resource tracker in the multiprocessing module now uses the original communication protocol, as in Python 3.14.0 and below, by default. This avoids issues with upgrading Python while it is running. (Note that such ‘in-place’ upgrades are not tested.) The tracker remains compatible with subprocesses that use new protocol (that is, subprocesses using Python 3.13.10, 3.14.1 and 3.15).

Core and Builtins

  • gh-142218: Fix crash when inserting into a split table dictionary with a non str key that matches an existing key.

Python 3.13.10 final

Release date: 2025-12-02

Tools/Demos

  • gh-141442: The iOS testbed now correctly handles test arguments that contain spaces.

Tests

  • gh-140482: Preserve and restore the state of stty echo as part of the test environment.

  • gh-140082: Update python -m test to set FORCE_COLOR=1 when being run with color enabled so that unittest which is run by it with redirected output will output in color.

  • gh-136442: Use exitcode 1 instead of 5 if unittest.TestCase.setUpClass() raises an exception

Security

  • gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” if there are no bytes prepended to the ZIP file.

  • gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.

  • gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.

  • gh-136065: Fix quadratic complexity in os.path.expandvars().

  • gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.

Library

IDLE

  • gh-96491: Deduplicate version number in IDLE shell title bar after saving to a file.

Documentation

Core and Builtins

C API

  • gh-140042: Removed the sqlite3_shutdown call that could cause closing connections for sqlite when used with multiple sub interpreters.

  • gh-140487: Fix Py_RETURN_NOTIMPLEMENTED in limited C API 3.11 and older: don’t treat Py_NotImplemented as immortal. Patch by Victor Stinner.

Python 3.13.9 final

Release date: 2025-10-14

Library

Python 3.13.8 final

Release date: 2025-10-07

macOS

  • gh-124111: Update macOS installer to use Tcl/Tk 8.6.17.

  • gh-139573: Updated bundled version of OpenSSL to 3.0.18.

Windows

  • gh-139573: Updated bundled version of OpenSSL to 3.0.18.

  • gh-138896: Fix error installing C runtime on non-updated Windows machines

Tools/Demos

  • gh-139330: SBOM generation tool didn’t cross-check the version and checksum values against the Modules/expat/refresh.sh script, leading to the values becoming out-of-date during routine updates.

  • gh-137873: The iOS test runner has been simplified, resolving some issues that have been observed using the runner in GitHub Actions and Azure Pipelines test environments.

Tests

  • gh-139208: Fix regrtest --fast-ci --verbose: don’t ignore the --verbose option anymore. Patch by Victor Stinner.

Security

  • gh-139400: xml.parsers.expat: Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created by ExternalEntityParserCreate(). Patch by Sebastian Pipping.

  • gh-139283: sqlite3: correctly handle maximum number of rows to fetch in Cursor.fetchmany and reject negative values for Cursor.arraysize. Patch by Bénédikt Tran.

  • gh-135661: Fix CDATA section parsing in html.parser.HTMLParser according to the HTML5 standard: ] ]> and ]] > no longer end the CDATA section. Add private method _set_support_cdata() which can be used to specify how to parse <[CDATA[ — as a CDATA section in foreign content (SVG or MathML) or as a bogus comment in the HTML namespace.

Library

  • gh-139312: Upgrade bundled libexpat to 2.7.3

  • gh-139289: Do a real lazy-import on rlcompleter in pdb and restore the existing completer after importing rlcompleter.

  • gh-139210: Fix use-after-free when reporting unknown event in xml.etree.ElementTree.iterparse(). Patch by Ken Jin.

  • gh-138860: Lazy import rlcompleter in pdb to avoid deadlock in subprocess.

  • gh-112729: Fix crash when calling _interpreters.create when the process is out of memory.

  • gh-139076: Fix a bug in the pydoc module that was hiding functions in a Python module if they were implemented in an extension module and the module did not have __all__.

  • gh-138998: Update bundled libexpat to 2.7.2

  • gh-130567: Fix possible crash in locale.strxfrm() due to a platform bug on macOS.

  • gh-138779: Support device numbers larger than 2**63-1 for the st_rdev field of the os.stat_result structure.

  • gh-128636: Fix crash in PyREPL when os.environ is overwritten with an invalid value for mac

  • gh-88375: Fix normalization of the robots.txt rules and URLs in the urllib.robotparser module. No longer ignore trailing ?. Distinguish raw special characters ?, = and & from the percent-encoded ones.

  • gh-138515: email is added to Emscripten build.

  • gh-111788: Fix parsing errors in the urllib.robotparser module. Don’t fail trying to parse weird paths. Don’t fail trying to decode non-UTF-8 robots.txt files.

  • gh-138432: zoneinfo.reset_tzpath() will now convert any os.PathLike objects it receives into strings before adding them to TZPATH. It will raise TypeError if anything other than a string is found after this conversion. If given an os.PathLike object that represents a relative path, it will now raise ValueError instead of TypeError, and present a more informative error message.

  • gh-138008: Fix segmentation faults in the ctypes module due to invalid argtypes. Patch by Dung Nguyen.

  • gh-60462: Fix locale.strxfrm() on Solaris (and possibly other platforms).

  • gh-138204: Forbid expansion of shared anonymous memory maps on Linux, which caused a bus error.

  • gh-138010: Fix an issue where defining a class with a @warnings.deprecated-decorated base class may not invoke the correct __init_subclass__() method in cases involving multiple inheritance. Patch by Brian Schubert.

  • gh-138133: Prevent infinite traceback loop when sending CTRL^C to Python through strace.

  • gh-134869: Fix an issue where pressing Ctrl+C during tab completion in the REPL would leave the autocompletion menu in a corrupted state.

  • gh-137317: inspect.signature() now correctly handles classes that use a descriptor on a wrapped __init__() or __new__() method. Contributed by Yongyu Yan.

  • gh-137754: Fix import of the zoneinfo module if the C implementation of the datetime module is not available.

  • gh-137490: Handle ECANCELED in the same way as EINTR in signal.sigwaitinfo() on NetBSD.

  • gh-137477: Fix inspect.getblock(), inspect.getsourcelines() and inspect.getsource() for generator expressions.

  • gh-137017: Fix threading.Thread.is_alive to remain True until the underlying OS thread is fully cleaned up. This avoids false negatives in edge cases involving thread monitoring or premature threading.Thread.is_alive calls.

  • gh-136134: SMTP.auth_cram_md5() now raises an SMTPException instead of a ValueError if Python has been built without MD5 support. In particular, SMTP clients will not attempt to use this method even if the remote server is assumed to support it. Patch by Bénédikt Tran.

  • gh-136134: IMAP4.login_cram_md5 now raises an IMAP4.error if CRAM-MD5 authentication is not supported. Patch by Bénédikt Tran.

  • gh-135386: Fix opening a dbm.sqlite3 database for reading from read-only file or directory.

  • gh-126631: Fix multiprocessing forkserver bug which prevented __main__ from being preloaded.

  • gh-123085: In a bare call to importlib.resources.files(), ensure the caller’s frame is properly detected when importlib.resources is itself available as a compiled module only (no source).

  • gh-118981: Fix potential hang in multiprocessing.popen_spawn_posix that can happen when the child proc dies early by closing the child fds right away.

  • gh-78319: UTF8 support for the IMAP APPEND command has been made RFC compliant.

  • bpo-38735: Fix failure when importing a module from the root directory on unix-like platforms with sys.pycache_prefix set.

  • bpo-41839: Allow negative priority values from os.sched_get_priority_min() and os.sched_get_priority_max() functions.

Core and Builtins

  • gh-134466: Don’t run PyREPL in a degraded environment where setting termios attributes is not allowed.

  • gh-71810: Raise OverflowError for (-1).to_bytes() for signed conversions when bytes count is zero. Patch by Sergey B Kirpichev.

  • gh-105487: Remove non-existent __copy__(), __deepcopy__(), and __bases__ from the __dir__() entries of types.GenericAlias.

  • gh-134163: Fix a hang when the process is out of memory inside an exception handler.

  • gh-138479: Fix a crash when a generic object’s __typing_subst__ returns an object that isn’t a tuple.

  • gh-137576: Fix for incorrect source code being shown in tracebacks from the Basic REPL when PYTHONSTARTUP is given. Patch by Adam Hartz.

  • gh-132744: Certain calls now check for runaway recursion and respect the system recursion limit.

C API

  • gh-87135: Attempting to acquire the GIL after runtime finalization has begun in a different thread now causes the thread to hang rather than terminate, which avoids potential crashes or memory corruption caused by attempting to terminate a thread that is running code not specifically designed to support termination. In most cases this hanging is harmless since the process will soon exit anyway.

    While not officially marked deprecated until 3.14, PyThread_exit_thread is no longer called internally and remains solely for interface compatibility. Its behavior is inconsistent across platforms, and it can only be used safely in the unlikely case that every function in the entire call stack has been designed to support the platform-dependent termination mechanism. It is recommended that users of this function change their design to not require thread termination. In the unlikely case that thread termination is needed and can be done safely, users may migrate to calling platform-specific APIs such as pthread_exit (POSIX) or _endthreadex (Windows) directly.

Build

  • gh-135734: Python can correctly be configured and built with ./configure --enable-optimizations --disable-test-modules. Previously, the profile data generation step failed due to PGO tests where immortalization couldn’t be properly suppressed. Patch by Bénédikt Tran.

Python 3.13.7 final

Release date: 2025-08-14

Library

Documentation

  • gh-136155: We are now checking for fatal errors in EPUB builds in CI.

Core and Builtins

Python 3.13.6 final

Release date: 2025-08-06

macOS

  • gh-137450: macOS installer shell path management improvements: separate the installer Shell profile updater postinstall script from the Update Shell Profile.command to enable more robust error handling.

  • gh-137134: Update macOS installer to ship with SQLite version 3.50.4.

Windows

  • gh-137134: Update Windows installer to ship with SQLite 3.50.4.

Tools/Demos

  • gh-135968: Stubs for strip are now provided as part of an iOS install.

Tests

  • gh-135966: The iOS testbed now handles the app_packages folder as a site directory.

  • gh-135494: Fix regrtest to support excluding tests from --pgo tests. Patch by Victor Stinner.

  • gh-135489: Show verbose output for failing tests during PGO profiling step with –enable-optimizations.

Security

  • gh-135661: Fix parsing start and end tags in html.parser.HTMLParser according to the HTML5 standard.

    • Whitespaces no longer accepted between </ and the tag name. E.g. </ script> does not end the script section.

    • Vertical tabulation (\v) and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are \t\n\r\f and space.

    • Null character (U+0000) no longer ends the tag name.

    • Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first > in quoted attribute value. E.g. </script/foo=">"/>.

    • Multiple slashes and whitespaces between the last attribute and closing > are now ignored in both start and end tags. E.g. <a foo=bar/ //>.

    • Multiple = between attribute name and value are no longer collapsed. E.g. <a foo==bar> produces attribute “foo” with value “=bar”.

  • gh-102555: Fix comment parsing in html.parser.HTMLParser according to the HTML5 standard. --!> now ends the comment. -- > no longer ends the comment. Support abnormally ended empty comments <--> and <--->.

  • gh-135462: Fix quadratic complexity in processing specially crafted input in html.parser.HTMLParser. End-of-file errors are now handled according to the HTML5 specs – comments and declarations are automatically closed, tags are ignored.

  • gh-118350: Fix support of escapable raw text mode (elements “textarea” and “title”) in html.parser.HTMLParser.

Library

  • gh-132710: If possible, ensure that uuid.getnode() returns the same result even across different processes. Previously, the result was constant only within the same process. Patch by Bénédikt Tran.

  • gh-137273: Fix debug assertion failure in locale.setlocale() on Windows.

  • gh-137257: Bump the version of pip bundled in ensurepip to version 25.2

  • gh-81325: tarfile.TarFile now accepts a path-like when working on a tar archive. (Contributed by Alexander Enrique Urieles Nieto in gh-81325.)

  • gh-130522: Fix unraisable TypeError raised during interpreter shutdown in the threading module.

  • gh-130577: tarfile now validates archives to ensure member offsets are non-negative. (Contributed by Alexander Enrique Urieles Nieto in gh-130577.)

  • gh-136549: Fix signature of threading.excepthook().

  • gh-136523: Fix wave.Wave_write emitting an unraisable when open raises.

  • gh-52876: Add missing keepends (default True) parameter to codecs.StreamReaderWriter.readline() and codecs.StreamReaderWriter.readlines().

  • gh-85702: If zoneinfo._common.load_tzdata is given a package without a resource a zoneinfo.ZoneInfoNotFoundError is raised rather than a PermissionError. Patch by Victor Stinner.

  • gh-134759: Fix UnboundLocalError in email.message.Message.get_payload() when the payload to decode is a bytes object. Patch by Kliment Lamonov.

  • gh-136028: Fix parsing month names containing “İ” (U+0130, LATIN CAPITAL LETTER I WITH DOT ABOVE) in time.strptime(). This affects locales az_AZ, ber_DZ, ber_MA and crh_UA.

  • gh-135995: In the palmos encoding, make byte 0x9b decode to (U+203A - SINGLE RIGHT-POINTING ANGLE QUOTATION MARK).

  • gh-53203: Fix time.strptime() for %c and %x formats on locales byn_ER, wal_ET and lzh_TW, and for %X format on locales ar_SA, bg_BG and lzh_TW.

  • gh-91555: An earlier change, which was introduced in 3.13.4, has been reverted. It disabled logging for a logger during handling of log messages for that logger. Since the reversion, the behaviour should be as it was before 3.13.4.

  • gh-135878: Fixes a crash of types.SimpleNamespace on free threading builds, when several threads were calling its __repr__() method at the same time.

  • gh-135836: Fix IndexError in asyncio.loop.create_connection() that could occur when non-OSError exception is raised during connection and socket’s close() raises OSError.

  • gh-135836: Fix IndexError in asyncio.loop.create_connection() that could occur when the Happy Eyeballs algorithm resulted in an empty exceptions list during connection attempts.

  • gh-135855: Raise TypeError instead of SystemError when _interpreters.set___main___attrs() is passed a non-dict object. Patch by Brian Schubert.

  • gh-135815: netrc: skip security checks if os.getuid() is missing. Patch by Bénédikt Tran.

  • gh-135640: Address bug where it was possible to call xml.etree.ElementTree.ElementTree.write() on an ElementTree object with an invalid root element. This behavior blanked the file passed to write if it already existed.

  • gh-135444: Fix asyncio.DatagramTransport.sendto() to account for datagram header size when data cannot be sent.

  • gh-135497: Fix os.getlogin() failing for longer usernames on BSD-based platforms.

  • gh-135487: Fix reprlib.Repr.repr_int() when given integers with more than sys.get_int_max_str_digits() digits. Patch by Bénédikt Tran.

  • gh-135335: multiprocessing: Flush stdout and stderr after preloading modules in the forkserver.

  • gh-135244: uuid: when the MAC address cannot be determined, the 48-bit node ID is now generated with a cryptographically-secure pseudo-random number generator (CSPRNG) as per RFC 9562, §6.10.3. This affects uuid1().

  • gh-135069: Fix the “Invalid error handling” exception in encodings.idna.IncrementalDecoder to correctly replace the ‘errors’ parameter.

  • gh-134698: Fix a crash when calling methods of ssl.SSLContext or ssl.SSLSocket across multiple threads.

  • gh-132124: On POSIX-compliant systems, multiprocessing.util.get_temp_dir() now ignores TMPDIR (and similar environment variables) if the path length of AF_UNIX socket files exceeds the platform-specific maximum length when using the forkserver start method. Patch by Bénédikt Tran.

  • gh-133439: Fix dot commands with trailing spaces are mistaken for multi-line SQL statements in the sqlite3 command-line interface.

  • gh-132969: Prevent the ProcessPoolExecutor executor thread, which remains running when shutdown(wait=False), from attempting to adjust the pool’s worker processes after the object state has already been reset during shutdown. A combination of conditions, including a worker process having terminated abormally, resulted in an exception and a potential hang when the still-running executor thread attempted to replace dead workers within the pool.

  • gh-130664: Support the '_' digit separator in formatting of the integral part of Decimal’s. Patch by Sergey B Kirpichev.

  • gh-85702: If zoneinfo._common.load_tzdata is given a package without a resource a ZoneInfoNotFoundError is raised rather than a IsADirectoryError.

  • gh-130664: Handle corner-case for Fraction’s formatting: treat zero-padding (preceding the width field by a zero ('0') character) as an equivalent to a fill character of '0' with an alignment type of '=', just as in case of float’s.

Documentation

  • gh-135171: Document that the iterator for the leftmost for clause in the generator expression is created immediately.

Core and Builtins

  • gh-58124: Fix name of the Python encoding in Unicode errors of the code page codec: use “cp65000” and “cp65001” instead of “CP_UTF7” and “CP_UTF8” which are not valid Python code names. Patch by Victor Stinner.

  • gh-137314: Fixed a regression where raw f-strings incorrectly interpreted escape sequences in format specifications. Raw f-strings now properly preserve literal backslashes in format specs, matching the behavior from Python 3.11. For example, rf"{obj:\xFF}" now correctly produces '\\xFF' instead of 'ÿ'. Patch by Pablo Galindo.

  • gh-136541: Fix some issues with the perf trampolines on x86-64 and aarch64. The trampolines were not being generated correctly for some cases, which could lead to the perf integration not working correctly. Patch by Pablo Galindo.

  • gh-109700: Fix memory error handling in PyDict_SetDefault().

  • gh-78465: Fix error message for cls.__new__(cls, ...) where cls is not instantiable builtin or extension type (with tp_new set to NULL).

  • gh-135871: Non-blocking mutex lock attempts now return immediately when the lock is busy instead of briefly spinning in the free threading build.

  • gh-135607: Fix potential weakref races in an object’s destructor on the free threaded build.

  • gh-135496: Fix typo in the f-string conversion type error (“exclamanation” -> “exclamation”).

  • gh-130077: Properly raise custom syntax errors when incorrect syntax containing names that are prefixes of soft keywords is encountered. Patch by Pablo Galindo.

  • gh-135148: Fixed a bug where f-string debug expressions (using =) would incorrectly strip out parts of strings containing escaped quotes and # characters. Patch by Pablo Galindo.

  • gh-133136: Limit excess memory usage in the free threading build when a large dictionary or list is resized and accessed by multiple threads.

  • gh-132617: Fix dict.update() modification check that could incorrectly raise a “dict mutated during update” error when a different dictionary was modified that happens to share the same underlying keys object.

  • gh-91153: Fix a crash when a bytearray is concurrently mutated during item assignment.

  • gh-127971: Fix off-by-one read beyond the end of a string in string search.

  • gh-125723: Fix crash with gi_frame.f_locals when generator frames outlive their generator. Patch by Mikhail Efimov.

Build

  • gh-135497: Fix the detection of MAXLOGNAME in the configure.ac script.

Python 3.13.5 final

Release date: 2025-06-11

Windows

  • gh-135151: Avoid distributing modified pyconfig.h in the traditional installer. Extension module builds must always specify Py_GIL_DISABLED when targeting the free-threaded runtime.

Tests

Library

  • gh-133967: Do not normalize locale name ‘C.UTF-8’ to ‘en_US.UTF-8’.

  • gh-135326: Restore support of integer-like objects with __index__() in random.getrandbits().

  • gh-135321: Raise a correct exception for values greater than 0x7fffffff for the BINSTRING opcode in the C implementation of pickle.

  • gh-135276: Backported bugfixes in zipfile.Path from zipp 3.23. Fixed .name, .stem and other basename-based properties on Windows when working with a zipfile on disk.

  • gh-134151: email: Fix TypeError in email.utils.decode_params() when sorting RFC 2231 continuations that contain an unnumbered section.

  • gh-134152: email: Fix parsing of email message ID with invalid domain.

  • gh-127081: Fix libc thread safety issues with os by replacing getlogin with getlogin_r re-entrant version.

  • gh-131884: Fix formatting issues in json.dump() when both indent and skipkeys are used.

Core and Builtins

  • gh-135171: Roll back changes to generator and list comprehensions that went into 3.13.4 to fix gh-127682, but which involved semantic and bytecode changes not appropriate for a bugfix release.

C API

  • gh-134989: Fix Py_RETURN_NONE, Py_RETURN_TRUE and Py_RETURN_FALSE macros in the limited C API 3.11 and older: don’t treat Py_None, Py_True and Py_False as immortal. Patch by Victor Stinner.

  • gh-134989: Implement PyObject_DelAttr() and PyObject_DelAttrString() as macros in the limited C API 3.12 and older. Patch by Victor Stinner.

Python 3.13.4 final

Release date: 2025-06-03

Windows

  • gh-130727: Fix a race in internal calls into WMI that can result in an “invalid handle” exception under high load. Patch by Chris Eibl.

  • gh-76023: Make os.path.realpath() ignore Windows error 1005 when in non-strict mode.

  • gh-133626: Ensures packages are not accidentally bundled into the traditional installer.

  • gh-133512: Add warnings to Python Launcher for Windows about use of subcommands belonging to the Python install manager.

Tests

  • gh-133744: Fix multiprocessing interrupt test. Add an event to synchronize the parent process with the child process: wait until the child process starts sleeping. Patch by Victor Stinner.

  • gh-133639: Fix TestPyReplAutoindent.test_auto_indent_default() doesn’t run input_code.

  • gh-133131: The iOS testbed will now select the most recently released “SE-class” device for testing if a device isn’t explicitly specified.

  • gh-109981: The test helper that counts the list of open file descriptors now uses the optimised /dev/fd approach on all Apple platforms, not just macOS. This avoids crashes caused by guarded file descriptors.

Security

  • gh-135034: Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links.

    Addresses CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, and CVE 2025-4517.

  • gh-133767: Fix use-after-free in the “unicode-escape” decoder with a non-“strict” error handler.

  • gh-128840: Short-circuit the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service.

Library

  • gh-134718: ast.dump() now only omits None and [] values if they are default values.

  • gh-128840: Fix parsing long IPv6 addresses with embedded IPv4 address.

  • gh-134696: Built-in HACL* and OpenSSL implementations of hash function constructors now correctly accept the same documented named arguments. For instance, md5() could be previously invoked as md5(data=data) or md5(string=string) depending on the underlying implementation but these calls were not compatible. Patch by Bénédikt Tran.

  • gh-134210: curses.window.getch() now correctly handles signals. Patch by Bénédikt Tran.

  • gh-80334: multiprocessing.freeze_support() now checks for work on any “spawn” start method platform rather than only on Windows.

  • gh-114177: Fix asyncio to not close subprocess pipes which would otherwise error out when the event loop is already closed.

  • gh-134152: Fixed UnboundLocalError that could occur during email header parsing if an expected trailing delimiter is missing in some contexts.

  • gh-62184: Remove import of C implementation of io.FileIO from Python implementation which has its own implementation

  • gh-133982: Emit RuntimeWarning in the Python implementation of io when the file-like object is not closed explicitly in the presence of multiple I/O layers.

  • gh-133890: The tarfile module now handles UnicodeEncodeError in the same way as OSError when cannot extract a member.

  • gh-134097: Fix interaction of the new REPL and -X showrefcount command line option.

  • gh-133889: The generated directory listing page in http.server.SimpleHTTPRequestHandler now only shows the decoded path component of the requested URL, and not the query and fragment.

  • gh-134098: Fix handling paths that end with a percent-encoded slash (%2f or %2F) in http.server.SimpleHTTPRequestHandler.

  • gh-134062: ipaddress: fix collisions in __hash__() for IPv4Network and IPv6Network objects.

  • gh-133745: In 3.13.3 we accidentally changed the signature of the asyncio create_task() family of methods and how it calls a custom task factory in a backwards incompatible way. Since some 3rd party libraries have already made changes to work around the issue that might break if we simply reverted the changes, we’re instead changing things to be backwards compatible with 3.13.2 while still supporting those workarounds for 3.13.3. In particular, the special-casing of name and context is back (until 3.14) and consequently eager tasks may still find that their name hasn’t been set before they execute their first yielding await.

  • gh-71253: Raise ValueError in open() if opener returns a negative file-descriptor in the Python implementation of io to match the C implementation.

  • gh-77057: Fix handling of invalid markup declarations in html.parser.HTMLParser.

  • gh-133489: random.getrandbits() can now generate more that 231 bits. random.randbytes() can now generate more that 256 MiB.

  • gh-133290: Fix attribute caching issue when setting ctypes._Pointer._type_ in the undocumented and deprecated ctypes.SetPointerType() function and the undocumented set_type() method.

  • gh-132876: ldexp() on Windows doesn’t round subnormal results before Windows 11, but should. Python’s math.ldexp() wrapper now does round them, so results may change slightly, in rare cases of very small results, on Windows versions before 11.

  • gh-133089: Use original timeout value for subprocess.TimeoutExpired when the func subprocess.run() is called with a timeout instead of sometimes a confusing partial remaining time out value used internally on the final wait().

  • gh-133009: xml.etree.ElementTree: Fix a crash in Element.__deepcopy__ when the element is concurrently mutated. Patch by Bénédikt Tran.

  • gh-132995: Bump the version of pip bundled in ensurepip to version 25.1.1

  • gh-132017: Fix error when pyrepl is suspended, then resumed and terminated.

  • gh-132673: Fix a crash when using _align_ = 0 and _fields_ = [] in a ctypes.Structure.

  • gh-132527: Include the valid typecode ‘w’ in the error message when an invalid typecode is passed to array.array.

  • gh-132439: Fix PyREPL on Windows: characters entered via AltGr are swallowed. Patch by Chris Eibl.

  • gh-132429: Fix support of Bluetooth sockets on NetBSD and DragonFly BSD.

  • gh-132106: QueueListener.start now raises a RuntimeError if the listener is already started.

  • gh-132417: Fix a NULL pointer dereference when a C function called using ctypes with restype py_object returns NULL.

  • gh-132385: Fix instance error suggestions trigger potential exceptions in object.__getattr__() in traceback.

  • gh-132308: A traceback.TracebackException now correctly renders the __context__ and __cause__ attributes from falsey Exception, and the exceptions attribute from falsey ExceptionGroup.

  • gh-132250: Fixed the SystemError in cProfile when locating the actual C function of a method raises an exception.

  • gh-132063: Prevent exceptions that evaluate as falsey (namely, when their __bool__ method returns False or their __len__ method returns 0) from being ignored by concurrent.futures.ProcessPoolExecutor and concurrent.futures.ThreadPoolExecutor.

  • gh-119605: Respect follow_wrapped for __init__() and __new__() methods when getting the class signature for a class with inspect.signature(). Preserve class signature after wrapping with warnings.deprecated(). Patch by Xuehai Pan.

  • gh-91555: Ignore log messages generated during handling of log messages, to avoid deadlock or infinite recursion. [NOTE: This change has since been reverted.]

  • gh-131434: Improve error reporting for incorrect format in time.strptime().

  • gh-131127: Systems using LibreSSL now successfully build.

  • gh-130999: Avoid exiting the new REPL and offer suggestions even if there are non-string candidates when errors occur.

  • gh-130941: Fix configparser.ConfigParser parsing empty interpolation with allow_no_value set to True.

  • gh-129098: Fix REPL traceback reporting when using compile() with an inexisting file. Patch by Bénédikt Tran.

  • gh-130631: http.cookiejar.join_header_words() is now more similar to the original Perl version. It now quotes the same set of characters and always quote values that end with "\n".

  • gh-129719: Fix missing socket.CAN_RAW_ERR_FILTER constant in the socket module on Linux systems. It was missing since Python 3.11.

  • gh-124096: Turn on virtual terminal mode and enable bracketed paste in REPL on Windows console. (If the terminal does not support bracketed paste, enabling it does nothing.)

  • gh-122559: Remove __reduce__() and __reduce_ex__() methods that always raise TypeError in the C implementation of io.FileIO, io.BufferedReader, io.BufferedWriter and io.BufferedRandom and replace them with default __getstate__() methods that raise TypeError. This restores fine details of behavior of Python 3.11 and older versions.

  • gh-122179: hashlib.file_digest() now raises BlockingIOError when no data is available during non-blocking I/O. Before, it added spurious null bytes to the digest.

  • gh-86155: html.parser.HTMLParser.close() no longer loses data when the <script> tag is not closed. Patch by Waylan Limberg.

  • gh-69426: Fix html.parser.HTMLParser to not unescape character entities in attribute values if they are followed by an ASCII alphanumeric or an equals sign.

  • bpo-44172: Keep a reference to original curses windows in subwindows so that the original window does not get deleted before subwindows.

IDLE

  • gh-112936: fix IDLE: no Shell menu item in single-process mode.

Documentation

Library

Core and Builtins

  • gh-127682: No longer call __iter__ twice in list comprehensions. This brings the behavior of list comprehensions in line with other forms of iteration

Library

Core and Builtins

  • gh-128066: Fixes an edge case where PyREPL improperly threw an error when Python is invoked on a read only filesystem while trying to write history file entries.

  • gh-134100: Fix a use-after-free bug that occurs when an imported module isn’t in sys.modules after its initial import. Patch by Nico-Posada.

  • gh-133703: Fix hashtable in dict can be bigger than intended in some situations.

  • gh-132869: Fix crash in the free threading build when accessing an object attribute that may be concurrently inserted or deleted.

  • gh-132762: fromkeys() no longer loops forever when adding a small set of keys to a large base dict. Patch by Angela Liss.

  • gh-133543: Fix a possible memory leak that could occur when directly accessing instance dictionaries (__dict__) that later become part of a reference cycle.

  • gh-133516: Raise ValueError when constants True, False or None are used as an identifier after NFKC normalization.

  • gh-133441: Fix crash upon setting an attribute with a dict subclass. Patch by Victor Stinner.

  • gh-132942: Fix two races in the type lookup cache. This affected the free-threaded build and could cause crashes (apparently quite difficult to trigger).

  • gh-132713: Fix repr(list) race condition: hold a strong reference to the item while calling repr(item). Patch by Victor Stinner.

  • gh-132747: Fix a crash when calling __get__() of a method with a None second argument.

  • gh-132542: Update Thread.native_id after fork(2) to ensure accuracy. Patch by Noam Cohen.

  • gh-124476: Fix decoding from the locale encoding in the C.UTF-8 locale.

  • gh-131927: Compiler warnings originating from the same module and line number are now only emitted once, matching the behaviour of warnings emitted from user code. This can also be configured with warnings filters.

  • gh-127682: No longer call __iter__ twice when creating and executing a generator expression. Creating a generator expression from a non-interable will raise only when the generator expression is executed. This brings the behavior of generator expressions in line with other generators.

  • gh-131878: Handle uncaught exceptions in the main input loop for the new REPL.

  • gh-131878: Fix support of unicode characters with two or more codepoints on Windows in the new REPL.

  • gh-130804: Fix support of unicode characters on Windows in the new REPL.

  • gh-130070: Fixed an assertion error for exec() passed a string source and a non-None closure. Patch by Bartosz Sławecki.

  • gh-129958: Fix a bug that was allowing newlines inconsitently in format specifiers for single-quoted f-strings. Patch by Pablo Galindo.

C API

Build

  • gh-134923: Windows builds with profile-guided optimization enabled now use /GENPROFILE and /USEPROFILE instead of deprecated /LTCG: options.

  • gh-133183: iOS compiler shims now include IPHONEOS_DEPLOYMENT_TARGET in target triples, ensuring that SDK version minimums are honored.

  • gh-133167: Fix compilation process with --enable-optimizations and --without-docstrings.

  • gh-132649: The PClayout script now allows passing --include-tcltk on Windows ARM64.

  • gh-117088: AIX linker don’t support -h option, so avoid it through platform check

  • gh-132026: Fix use of undefined identifiers in platform triplet detection on MIPS Linux platforms.

Python 3.13.3 final

Release date: 2025-04-08

macOS

  • gh-124111: Update macOS installer to use Tcl/Tk 8.6.16.

  • gh-131423: Update macOS installer to use OpenSSL 3.0.16. Patch by Bénédikt Tran.

  • gh-131025: Update macOS installer to ship with SQLite 3.49.1.

  • gh-91132: Update macOS installer to use ncurses 6.5.

Windows

  • gh-131423: Update bundled version of OpenSSL to 3.0.16. The new build also disables uplink support, which may be relevant to embedders but has no impact on normal use.

  • gh-131025: Update Windows installer to ship with SQLite 3.49.1.

  • gh-131020: pylauncher correctly detects a BOM when searching for the shebang. Fix by Chris Eibl.

Tools/Demos

  • gh-131852: msgfmt no longer adds the POT-Creation-Date to generated .mo files for consistency with GNU msgfmt.

  • gh-85012: Correctly reset msgctxt when compiling messages in msgfmt.

  • gh-130025: The iOS testbed now correctly handles symlinks used as Python framework references.

Tests

  • gh-131050: test_ssl.test_dh_params is skipped if the underlying TLS library does not support finite-field ephemeral Diffie-Hellman.

  • gh-129200: Multiple iOS testbed runners can now be started at the same time without introducing an ambiguity over simulator ownership.

  • gh-130292: The iOS testbed will now run successfully on a machine that has not previously run Xcode tests (such as CI configurations).

  • gh-130293: The tests of terminal colorization are no longer sensitive to the value of the TERM variable in the testing environment.

  • gh-126332: Add unit tests for pyrepl.

Security

  • gh-131809: Update bundled libexpat to 2.7.1

  • gh-131261: Upgrade to libexpat 2.7.0

  • gh-127371: Avoid unbounded buffering for tempfile.SpooledTemporaryFile.writelines(). Previously, disk spillover was only checked after the lines iterator had been exhausted. This is now done after each line is written.

  • gh-121284: Fix bug in the folding of rfc2047 encoded-words when flattening an email message using a modern email policy. Previously when an encoded-word was too long for a line, it would be decoded, split across lines, and re-encoded. But commas and other special characters in the original text could be left unencoded and unquoted. This could theoretically be used to spoof header lines using a carefully constructed encoded-word if the resulting rendered email was transmitted or re-parsed.

Library

IDLE

  • gh-129873: Simplify displaying the IDLE doc by only copying the text section of idle.html to idlelib/help.html. Patch by Stan Ulbrych.

Documentation

Core and Builtins

  • gh-132011: Fix crash when calling list.append() as an unbound method.

  • gh-131998: Fix a crash when using an unbound method descriptor object in a function where a bound method descriptor was used.

  • gh-131988: Fix a performance regression that caused scaling bottlenecks in the free threaded build in 3.13.1 and 3.13.2.

  • gh-131719: Fix missing NULL check in _PyMem_FreeDelayed in free-threaded build.

  • gh-131670: Fix anext() failing on sync __anext__() raising an exception.

  • gh-131141: Fix data race in sys.monitoring instrumentation while registering callback.

  • gh-130932: Fix incorrect exception handling in _PyModule_IsPossiblyShadowing

  • gh-130851: Fix a crash in the free threading build when constructing a code object with co_consts that contains instances of types that are not otherwise generated by the bytecode compiler.

  • gh-130794: Fix memory leak in the free threaded build when resizing a shared list or dictionary from multiple short-lived threads.

  • gh-130775: Do not crash on negative column and end_column in ast locations.

  • gh-130382: Fix PyRefTracer_DESTROY not being sent from Python/ceval.c Py_DECREF().

  • gh-130618: Fix a bug that was causing UnicodeDecodeError or SystemError to be raised when using f-strings with lambda expressions with non-ASCII characters. Patch by Pablo Galindo

  • gh-130163: Fix possible crashes related to concurrent change and use of the sys module attributes.

  • gh-88887: Fixing multiprocessing Resource Tracker process leaking, usually observed when running Python as PID 1.

  • gh-130115: Fix an issue with thread identifiers being sign-extended on some platforms.

  • gh-128396: Fix a crash that occurs when calling locals() inside an inline comprehension that uses the same local variable as the outer frame scope where the variable is a free or cell var.

  • gh-116042: Fix location for SyntaxErrors of invalid escapes in the tokenizer. Patch by Pablo Galindo

Library

  • gh-129983: Fix data race in compile_template in sre.c.

Core and Builtins

  • gh-129967: Fix a race condition in the free threading build when repr(set) is called concurrently with set.clear().

  • gh-129900: Fix return codes inside SystemExit not getting returned by the REPL.

  • gh-129732: Fixed a race in _Py_qsbr_reserve in the free threading build.

  • gh-129643: Fix thread safety of PyList_Insert() in free-threading builds.

  • gh-129668: Fix race condition when raising MemoryError in the free threaded build.

  • gh-129643: Fix thread safety of PyList_SetItem() in free-threading builds. Patch by Kumar Aditya.

  • gh-128714: Fix the potential races in get/set dunder methods __annotations__, __annotate__ and __type_params__ for function object, and add related tests.

  • gh-128632: Disallow __classdict__ as the name of a type parameter. Using this name would previously crash the interpreter in some circumstances.

  • gh-127953: The time to handle a LINE event in sys.monitoring (and sys.settrace) is now independent of the number of lines in the code object.

  • gh-125331: from __future__ import barry_as_FLUFL now works in more contexts, including when it is used in files, with the -c flag, and in the REPL when there are multiple statements on the same line. Previously, it worked only on subsequent lines in the REPL, and when the appropriate flags were passed directly to compile(). Patch by Pablo Galindo.

C API

Build

  • gh-131865: The DTrace build now properly passes the CC and CFLAGS variables to the dtrace command when utilizing SystemTap on Linux.

  • gh-131675: Fix mimalloc library builds for 32-bit ARM targets.

  • gh-130673: Fix potential KeyError when handling object sections during JIT building process.

  • gh-130740: Ensure that Python.h is included before stdbool.h unless pyconfig.h is included before or in some platform-specific contexts.

  • gh-129838: Don’t redefine _Py_NO_SANITIZE_UNDEFINED when compiling with a recent GCC version and undefined sanitizer enabled.

  • gh-129660: Drop test_embed from PGO training, whose contribution in recent versions is considered to be ignorable.

Python 3.13.2 final

Release date: 2025-02-04

macOS

  • gh-127592: Usage of the unified Apple System Log APIs was disabled when the minimum macOS version is earlier than 10.12.

Windows

  • gh-127353: Allow to force color output on Windows using environment variables. Patch by Andrey Efremov.

Tools/Demos

  • gh-129248: The iOS test runner now strips the log prefix from each line output by the test suite.

  • gh-128152: Fix a bug where Argument Clinic’s C pre-processor parser tried to parse pre-processor directives inside C comments. Patch by Erlend Aasland.

Tests

  • gh-127906: Test the limited C API in test_cppext. Patch by Victor Stinner.

  • gh-127637: Add tests for the dis command-line interface. Patch by Bénédikt Tran.

  • gh-126925: iOS test results are now streamed during test execution, and the deprecated xcresulttool is no longer used.

Security

  • gh-105704: When using urllib.parse.urlsplit() and urllib.parse.urlparse() host parsing would not reject domain names containing square brackets ([ and ]). Square brackets are only valid for IPv6 and IPvFuture hosts according to RFC 3986 Section 3.2.2.

  • gh-127655: Fixed the asyncio.selector_events._SelectorSocketTransport transport not pausing writes for the protocol when the buffer reaches the high water mark when using asyncio.WriteTransport.writelines().

  • gh-126108: Fix a possible NULL pointer dereference in PySys_AddWarnOptionUnicode().

  • gh-80222: Fix bug in the folding of quoted strings when flattening an email message using a modern email policy. Previously when a quoted string was folded so that it spanned more than one line, the surrounding quotes and internal escapes would be omitted. This could theoretically be used to spoof header lines using a carefully constructed quoted string if the resulting rendered email was transmitted or re-parsed.

  • gh-119511: Fix a potential denial of service in the imaplib module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. On many systems this is harmless as unused virtual memory is only a mapping, but if this hit a virtual address size limit it could lead to a MemoryError or other process crash. On unusual systems or builds where all allocated memory is touched and backed by actual ram or storage it could’ve consumed resources doing so until similarly crashing.

Library

  • gh-129502: Unlikely errors in preparing arguments for ctypes callback are now handled in the same way as errors raised in the callback of in converting the result of the callback – using sys.unraisablehook() instead of sys.excepthook() and not setting sys.last_exc and other variables.

  • gh-129403: Corrected ValueError message for asyncio.Barrier and threading.Barrier.

  • gh-129409: Fix an integer overflow in the csv module when writing a data field larger than 2GB.

  • gh-118761: Improve import time of subprocess by lazy importing locale and signal. Patch by Taneli Hukkinen.

  • gh-129346: In sqlite3, handle out-of-memory when creating user-defined SQL functions.

  • gh-129061: Fix FORCE_COLOR and NO_COLOR when empty strings. Patch by Hugo van Kemenade.

  • gh-128550: Removed an incorrect optimization relating to eager tasks in asyncio.TaskGroup that resulted in cancellations being missed.

  • gh-128991: Release the enter frame reference within bdb callback

  • gh-128978: Fix a NameError in sysconfig.expand_makefile_vars(). Patch by Bénédikt Tran.

  • gh-128961: Fix a crash when setting state on an exhausted array.array iterator.

  • gh-128894: Fix traceback.TracebackException._format_syntax_error not to fail on exceptions with custom metadata.

  • gh-128916: Do not attempt to set SO_REUSEPORT on sockets of address families other than AF_INET and AF_INET6, as it is meaningless with these address families, and the call with fail with Linux kernel 6.12.9 and newer.

  • gh-128679: Fix tracemalloc.stop() race condition. Fix tracemalloc to support calling tracemalloc.stop() in one thread, while another thread is tracing memory allocations. Patch by Victor Stinner.

  • gh-128636: Fix PyREPL failure when os.environ is overwritten with an invalid value.

  • gh-128562: Fix possible conflicts in generated tkinter widget names if the widget class name ends with a digit.

  • gh-128498: Default to stdout isatty for color detection instead of stderr. Patch by Hugo van Kemenade.

  • gh-128552: Fix cyclic garbage introduced by asyncio.loop.create_task() and asyncio.TaskGroup.create_task() holding a reference to the created task if it is eager.

  • gh-128479: Fix asyncio.staggered.staggered_race() leaking tasks and issuing an unhandled exception.

  • gh-128400: Fix crash when using faulthandler.dump_traceback() while other threads are active on the free threaded build.

  • gh-88834: Unify the instance check for typing.Union and types.UnionType: Union now uses the instance checks against its parameters instead of the subclass checks.

  • gh-128302: Fix xml.dom.xmlbuilder.DOMEntityResolver.resolveEntity(), which was broken by the Python 3.0 transition.

  • gh-128302: Allow xml.dom.xmlbuilder.DOMParser.parse() to correctly handle xml.dom.xmlbuilder.DOMInputSource instances that only have a systemId attribute set.

  • gh-112064: Fix incorrect handling of negative read sizes in HTTPResponse.read. Patch by Yury Manushkin.

  • gh-58956: Fixed a frame reference leak in bdb.

  • gh-128131: Completely support random access of uncompressed unencrypted read-only zip files obtained by ZipFile.open.

  • gh-112328: enum.EnumDict can now be used without resorting to private API.

  • gh-127975: Avoid reusing quote types in ast.unparse() if not needed.

  • gh-128062: Revert the font of turtledemo’s menu bar to its default value and display the shortcut keys in the correct position.

  • gh-128014: Fix resetting the default window icon by passing default='' to the tkinter method wm_iconbitmap().

  • gh-115514: Fix exceptions and incomplete writes after asyncio._SelectorTransport is closed before writes are completed.

  • gh-41872: Fix quick extraction of module docstrings from a file in pydoc. It now supports docstrings with single quotes, escape sequences, raw string literals, and other Python syntax.

  • gh-127060: Set TERM environment variable to “dumb” to disable traceback colors in IDLE, since IDLE doesn’t understand ANSI escape sequences. Patch by Victor Stinner.

  • gh-126742: Fix support of localized error messages reported by dlerror(3) and gdbm_strerror in ctypes and dbm.gnu functions respectively. Patch by Bénédikt Tran.

  • gh-127873: When -E is set, only ignore PYTHON_COLORS and not FORCE_COLOR/NO_COLOR/TERM when colourising output. Patch by Hugo van Kemenade.

  • gh-127870: Detect recursive calls in ctypes _as_parameter_ handling. Patch by Victor Stinner.

  • gh-127847: Fix the position when doing interleaved seeks and reads in uncompressed, unencrypted zip files returned by zipfile.ZipFile.open().

  • gh-127732: The platform module now correctly detects Windows Server 2025.

  • gh-126821: macOS and iOS apps can now choose to redirect stdout and stderr to the system log during interpreter configuration.

  • gh-93312: Include <sys/pidfd.h> to get os.PIDFD_NONBLOCK constant. Patch by Victor Stinner.

  • gh-83662: Add missing __class_getitem__ method to the Python implementation of functools.partial(), to make it compatible with the C version. This is mainly relevant for alternative Python implementations like PyPy and GraalPy, because CPython will usually use the C-implementation of that function.

  • gh-127586: multiprocessing.pool.Pool now properly restores blocked signal handlers of the parent thread when creating processes via either spawn or forkserver.

  • gh-98188: Fix an issue in email.message.Message.get_payload() where data cannot be decoded if the Content Transfer Encoding mechanism contains trailing whitespaces or additional junk text. Patch by Hui Liu.

  • gh-127257: In ssl, system call failures that OpenSSL reports using ERR_LIB_SYS are now raised as OSError.

  • gh-127096: Do not recreate unnamed section on every read in configparser.ConfigParser. Patch by Andrey Efremov.

  • gh-127196: Fix crash when dict with keys in invalid encoding were passed to several functions in _interpreters module.

  • gh-126775: Make linecache.checkcache() thread safe and GC re-entrancy safe.

  • gh-126332: Fix _pyrepl crash when entering a double CTRL-Z on an overflowing line.

  • gh-126225: getopt and optparse are no longer marked as deprecated. There are legitimate reasons to use one of these modules in preference to argparse, and none of these modules are at risk of being removed from the standard library. Of the three, argparse remains the recommended default choice, unless one of the concerns noted at the top of the optparse module documentation applies.

  • gh-125553: Fix round-trip invariance for backslash continuations in tokenize.untokenize().

  • gh-123987: Fixed issue in NamespaceReader where a non-path item in a namespace path, such as a sentinel added by an editable installer, would break resource loading.

  • gh-123401: The http.cookies module now supports parsing obsolete RFC 850 date formats, in accordance with RFC 9110 requirements. Patch by Nano Zheng.

  • gh-122431: readline.append_history_file() now raises a ValueError when given a negative value.

  • gh-119257: Show tab completions menu below the current line, which results in less janky behaviour, and fixes a cursor movement bug. Patch by Daniel Hollas

Documentation

Library

Core and Builtins

  • gh-129093: Fix f-strings such as f'{expr=}' sometimes not displaying the full expression when the expression contains !=.

  • gh-124363: Treat debug expressions in f-string as raw strings. Patch by Pablo Galindo

  • gh-128799: Add frame of except* to traceback when it wraps a naked exception.

  • gh-128078: Fix a SystemError when using anext() with a default tuple value. Patch by Bénédikt Tran.

  • gh-128717: Fix a crash when setting the recursion limit while other threads are active on the free threaded build.

  • gh-128330: Restore terminal control characters on REPL exit.

  • gh-128079: Fix a bug where except* does not properly check the return value of an ExceptionGroup’s split() function, leading to a crash in some cases. Now when split() returns an invalid object, except* raises a TypeError with the original raised ExceptionGroup object chained to it.

  • gh-128030: Avoid error from calling PyModule_GetFilenameObject on a non-module object when importing a non-existent symbol from a non-module object.

  • gh-127903: Objects/unicodeobject.c: fix a crash on DEBUG builds in _copy_characters when there is nothing to copy.

  • gh-127599: Fix statistics for increments of object reference counts (in particular, when a reference count was increased by more than 1 in a single operation).

  • gh-127651: When raising ImportError for missing symbols in from imports, use __file__ in the error message if __spec__.origin is not a location

  • gh-127582: Fix non-thread-safe object resurrection when calling finalizers and watcher callbacks in the free threading build.

  • gh-127434: The iOS compiler shims can now accept arguments with spaces.

  • gh-127536: Add missing locks around some list assignment operations in the free threading build.

  • gh-126862: Fix a possible overflow when a class inherits from an absurd number of super-classes. Reported by Valery Fedorenko. Patch by Bénédikt Tran.

  • gh-127349: Fixed the error when resizing terminal in Python REPL. Patch by Semyon Moroz.

  • gh-126076: Relocated objects such as tuple, bytes and str objects are properly tracked by tracemalloc and its associated hooks. Patch by Pablo Galindo.

C API

Build

  • gh-129539: Don’t redefine EX_OK when the system has the sysexits.h header.

  • gh-128472: Skip BOLT optimization of functions using computed gotos, fixing errors on build with LLVM 19.

  • gh-123925: Fix building the curses module on platforms with libncurses but without libncursesw.

  • gh-128321: Set LIBS instead of LDFLAGS when checking if sqlite3 library functions are available. This fixes the ordering of linked libraries during checks, which was incorrect when using a statically linked libsqlite3.

  • gh-127865: Fix build failure on systems without thread-locals support.

Python 3.13.1 final

Release date: 2024-12-03

macOS

  • gh-124448: Update bundled Tcl/Tk in macOS installer to 8.6.15.

Windows

  • gh-126911: Update credits command output.

  • gh-118973: Ensures the experimental free-threaded install includes the _tkinter module. The optional Tcl/Tk component must also be installed in order for the module to work.

  • gh-126497: Fixes venv failure due to missing redirector executables in experimental free-threaded installs.

  • gh-126074: Removed unnecessary DLLs from Windows embeddable package

  • gh-125315: Avoid crashing in platform due to slow WMI calls on some Windows machines.

  • gh-126084: Fix venvwlauncher to launch pythonw instead of python so no extra console window is created.

  • gh-125842: Fix a SystemError when sys.exit() is called with 0xffffffff on Windows.

  • gh-125550: Enable the Python Launcher for Windows to detect Python 3.14 installs from the Windows Store.

  • gh-124448: Updated bundled Tcl/Tk to 8.6.15.

Tools/Demos

  • gh-126807: Fix extraction warnings in pygettext.py caused by mistaking function definitions for function calls.

  • gh-126167: The iOS testbed was modified so that it can be used by third-party projects for testing purposes.

Tests

  • gh-126909: Fix test_os extended attribute tests to work on filesystems with 1 KiB xattr size limit.

  • gh-125041: Re-enable skipped tests for zlib on the s390x architecture: only skip checks of the compressed bytes, which can be different between zlib’s software implementation and the hardware-accelerated implementation.

  • gh-124295: Add translation tests to the argparse module.

Security

  • gh-126623: Upgrade libexpat to 2.6.4

  • gh-125140: Remove the current directory from sys.path when using PyREPL.

  • gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and is_unspecified.

Library

  • gh-127321: pdb.set_trace() will not stop at an opcode that does not have an associated line number anymore.

  • gh-127303: Publicly expose EXACT_TOKEN_TYPES in token.__all__.

  • gh-123967: Fix faulthandler for trampoline frames. If the top-most frame is a trampoline frame, skip it. Patch by Victor Stinner.

  • gh-127182: Fix io.StringIO.__setstate__() crash, when None was passed as the first value.

  • gh-127217: Fix urllib.request.pathname2url() for paths starting with multiple slashes on Posix.

  • gh-127035: Fix shutil.which on Windows. Now it looks at direct match if and only if the command ends with a PATHEXT extension or X_OK is not in mode. Support extensionless files if “.” is in PATHEXT. Support PATHEXT extensions that end with a dot.

  • gh-122273: Support PyREPL history on Windows. Patch by devdanzin and Victor Stinner.

  • gh-127078: Fix issue where urllib.request.url2pathname() failed to discard an extra slash before a UNC drive in the URL path on Windows.

  • gh-126766: Fix issue where urllib.request.url2pathname() failed to discard any ‘localhost’ authority present in the URL.

  • gh-127065: Fix crash when calling a operator.methodcaller() instance from multiple threads in the free threading build.

  • gh-126997: Fix support of STRING and GLOBAL opcodes with non-ASCII arguments in pickletools. pickletools.dis() now outputs non-ASCII bytes in STRING, BINSTRING and SHORT_BINSTRING arguments as escaped (\xXX).

  • gh-126316: grp: Make grp.getgrall() thread-safe by adding a mutex. Patch by Victor Stinner.

  • gh-126618: Fix the representation of itertools.count objects when the count value is sys.maxsize.

  • gh-85168: Fix issue where urllib.request.url2pathname() and pathname2url() always used UTF-8 when quoting and unquoting file URIs. They now use the filesystem encoding and error handler.

  • gh-67877: Fix memory leaks when regular expression matching terminates abruptly, either because of a signal or because memory allocation fails.

  • gh-126789: Fixed the values of sysconfig.get_config_vars(), sysconfig.get_paths(), and their siblings when the site initialization happens after sysconfig has built a cache for sysconfig.get_config_vars().

  • gh-126188: Update bundled pip to 24.3.1

  • gh-126780: Fix os.path.normpath() for drive-relative paths on Windows.

  • gh-126766: Fix issue where urllib.request.url2pathname() failed to discard two leading slashes introducing an empty authority section.

  • gh-126727: locale.nl_langinfo(locale.ERA) now returns multiple era description segments separated by semicolons. Previously it only returned the first segment on platforms with Glibc.

  • gh-126699: Allow collections.abc.AsyncIterator to be a base for Protocols.

  • gh-126654: Fix crash when non-dict was passed to several functions in _interpreters module.

  • gh-104745: Limit starting a patcher (from unittest.mock.patch() or unittest.mock.patch.object()) more than once without stopping it

  • gh-126595: Fix a crash when instantiating itertools.count with an initial count of sys.maxsize on debug builds. Patch by Bénédikt Tran.

  • gh-120423: Fix issue where urllib.request.pathname2url() mishandled Windows paths with embedded forward slashes.

  • gh-126565: Improve performances of zipfile.Path.open() for non-reading modes.

  • gh-126505: Fix bugs in compiling case-insensitive regular expressions with character classes containing non-BMP characters: upper-case non-BMP character did was ignored and the ASCII flag was ignored when matching a character range whose upper bound is beyond the BMP region.

  • gh-117378: Fixed the multiprocessing "forkserver" start method forkserver process to correctly inherit the parent’s sys.path during the importing of multiprocessing.set_forkserver_preload() modules in the same manner as sys.path is configured in workers before executing work items.

    This bug caused some forkserver module preloading to silently fail to preload. This manifested as a performance degration in child processes when the sys.path was required due to additional repeated work in every worker.

    It could also have a side effect of "" remaining in sys.path during forkserver preload imports instead of the absolute path from os.getcwd() at multiprocessing import time used in the worker sys.path.

    The sys.path differences between phases in the child process could potentially have caused preload to import incorrect things from the wrong location. We are unaware of that actually having happened in practice.

  • gh-125679: The multiprocessing.Lock and multiprocessing.RLock repr values no longer say “unknown” on macOS.

  • gh-126476: Raise calendar.IllegalMonthError (now a subclass of IndexError) for calendar.month() when the input month is not correct.

  • gh-126489: The Python implementation of pickle no longer calls pickle.Pickler.persistent_id() for the result of persistent_id().

  • gh-126313: Fix an issue in curses.napms() when curses.initscr() has not yet been called. Patch by Bénédikt Tran.

  • gh-126303: Fix pickling and copying of os.sched_param objects.

  • gh-126138: Fix a use-after-free crash on asyncio.Task objects whose underlying coroutine yields an object that implements an evil __getattribute__(). Patch by Nico Posada.

  • gh-126220: Fix crash in cProfile.Profile and _lsprof.Profiler when their callbacks were directly called with 0 arguments.

  • gh-126212: Fix issue where urllib.request.pathname2url() and url2pathname() removed slashes from Windows DOS drive paths and URLs.

  • gh-126223: Raise a UnicodeEncodeError instead of a SystemError upon calling _interpreters.create() with an invalid Unicode character.

  • gh-126205: Fix issue where urllib.request.pathname2url() generated URLs beginning with four slashes (rather than two) when given a Windows UNC path.

  • gh-126105: Fix a crash in ast when the ast.AST._fields attribute is deleted.

  • gh-126106: Fixes a possible NULL pointer dereference in ssl.

  • gh-126080: Fix a use-after-free crash on asyncio.Task objects for which the underlying event loop implements an evil __getattribute__(). Reported by Nico-Posada. Patch by Bénédikt Tran.

  • gh-126083: Fixed a reference leak in asyncio.Task objects when reinitializing the same object with a non-None context. Patch by Nico Posada.

  • gh-125984: Fix use-after-free crashes on asyncio.Future objects for which the underlying event loop implements an evil __getattribute__(). Reported by Nico-Posada. Patch by Bénédikt Tran.

  • gh-125969: Fix an out-of-bounds crash when an evil asyncio.loop.call_soon() mutates the length of the internal callbacks list. Patch by Bénédikt Tran.

  • gh-125966: Fix a use-after-free crash in asyncio.Future.remove_done_callback(). Patch by Bénédikt Tran.

  • gh-125789: Fix possible crash when mutating list of callbacks returned by asyncio.Future._callbacks. It now always returns a new copy in C implementation _asyncio. Patch by Kumar Aditya.

  • gh-124452: Fix an issue in email.policy.EmailPolicy.header_source_parse() and email.policy.Compat32.header_source_parse() that introduced spurious leading whitespaces into header values when the header includes a newline character after the header name delimiter (:) and before the value.

  • gh-125884: Fixed the bug for pdb where it can’t set breakpoints on functions with certain annotations.

  • gh-125355: Fix several bugs in argparse.ArgumentParser.parse_intermixed_args().

    • The parser no longer changes temporarily during parsing.

    • Default values are not processed twice.

    • Required mutually exclusive groups containing positional arguments are now supported.

    • The missing arguments report now includes the names of all required optional and positional arguments.

    • Unknown options can be intermixed with positional arguments in parse_known_intermixed_args().

  • gh-125666: Avoid the exiting the interpreter if a null byte is given as input in the new REPL.

  • gh-125710: [Enum] fix hashable<->nonhashable comparisons for member values

  • gh-125631: Restore ability to set persistent_id and persistent_load attributes of instances of the Pickler and Unpickler classes in the pickle module.

  • gh-125378: Fixed the bug in pdb where after a multi-line command, an empty line repeats the first line of the multi-line command, instead of the full command.

  • gh-125682: Reject non-ASCII digits in the Python implementation of json.loads() conforming to the JSON specification.

  • gh-125660: Reject invalid unicode escapes for Python implementation of json.loads().

  • gh-125259: Fix the notes removal logic for errors thrown in enum initialization.

  • gh-125590: Allow FrameLocalsProxy to delete and pop if the key is not a fast variable.

  • gh-125519: Improve traceback if importlib.reload() is called with an object that is not a module. Patch by Alex Waygood.

  • gh-125451: Fix deadlock when concurrent.futures.ProcessPoolExecutor shuts down concurrently with an error when feeding a job to a worker process.

  • gh-125422: Fixed the bug where pdb and bdb can step into the bottom caller frame.

  • gh-100141: Fixed the bug where pdb will be stuck in an infinite loop when debugging an empty file.

  • gh-125115: Fixed a bug in pdb where arguments starting with - can’t be passed to the debugged script.

  • gh-53203: Fix time.strptime() for %c, %x and %X formats in many locales that use non-ASCII digits, like Persian, Burmese, Odia and Shan.

  • gh-125398: Fix the conversion of the VIRTUAL_ENV path in the activate script in venv when running in Git Bash for Windows.

  • gh-125316: Fix using functools.partial() as enum.Enum member. A FutureWarning with suggestion to use enum.member() is now emitted when the partial instance is used as an enum member.

  • gh-125245: Fix race condition when importing collections.abc, which could incorrectly return an empty module.

  • gh-125243: Fix data race when creating zoneinfo.ZoneInfo objects in the free threading build.

  • gh-125254: Fix a bug where ArgumentError includes the incorrect ambiguous option in argparse.

  • gh-125235: Keep tkinter TCL paths in venv pointing to base installation on Windows.

  • gh-61011: Fix inheritance of nested mutually exclusive groups from parent parser in argparse.ArgumentParser. Previously, all nested mutually exclusive groups lost their connection to the group containing them and were displayed as belonging directly to the parser.

  • gh-52551: Fix encoding issues in time.strftime(), the strftime() method of the datetime classes datetime, date and time and formatting of these classes. Characters not encodable in the current locale are now acceptable in the format string. Surrogate pairs and sequence of surrogatescape-encoded bytes are no longer recombinated. Embedded null character no longer terminates the format string.

  • gh-125118: Don’t copy arbitrary values to _Bool in the struct module.

  • gh-125069: Fix an issue where providing a pathlib.PurePath object as an initializer argument to a second PurePath object with a different parser resulted in arguments to the former object’s initializer being joined by the latter object’s parser.

  • gh-125096: If the PYTHON_BASIC_REPL environment variable is set, the site module no longer imports the _pyrepl module. Moreover, the site module now respects -E and -I command line options: ignore PYTHON_BASIC_REPL in this case. Patch by Victor Stinner.

  • gh-124969: Fix locale.nl_langinfo(locale.ALT_DIGITS) on platforms with glibc. Now it returns a string consisting of up to 100 semicolon-separated symbols (an empty string in most locales) on all Posix platforms. Previously it only returned the first symbol or an empty string.

  • gh-124960: Fix support for the barry_as_FLUFL future flag in the new REPL.

  • gh-124984: Fixed thread safety in ssl in the free-threaded build. OpenSSL operations are now protected by a per-object lock.

  • gh-124958: Fix refcycles in exceptions raised from asyncio.TaskGroup and the python implementation of asyncio.Future

  • gh-53203: Fix time.strptime() for %c and %x formats in many locales: Arabic, Bislama, Breton, Bodo, Kashubian, Chuvash, Estonian, French, Irish, Ge’ez, Gurajati, Manx Gaelic, Hebrew, Hindi, Chhattisgarhi, Haitian Kreyol, Japanese, Kannada, Korean, Marathi, Malay, Norwegian, Nynorsk, Punjabi, Rajasthani, Tok Pisin, Yoruba, Yue Chinese, Yau/Nungon and Chinese.

  • gh-124917: Allow calling os.path.exists() and os.path.lexists() with keyword arguments on Windows. Fixes a regression in 3.13.0.

  • gh-124653: Fix detection of the minimal Queue API needed by the logging module. Patch by Bénédikt Tran.

  • gh-124858: Fix reference cycles left in tracebacks in asyncio.open_connection() when used with happy_eyeballs_delay

  • gh-124390: Fixed AssertionError when using asyncio.staggered.staggered_race() with asyncio.eager_task_factory.

  • gh-124651: Properly quote template strings in venv activation scripts.

  • gh-116850: Fix argparse for namespaces with not directly writable dict (e.g. classes).

  • gh-58573: Fix conflicts between abbreviated long options in the parent parser and subparsers in argparse.

  • gh-124594: All asyncio REPL prompts run in the same context. Contributed by Bartosz Sławecki.

  • gh-61181: Fix support of choices with string value in argparse. Substrings of the specified string no longer considered valid values.

  • gh-80259: Fix argparse support of positional arguments with nargs='?', default=argparse.SUPPRESS and specified type.

  • gh-120378: Fix a crash related to an integer overflow in curses.resizeterm() and curses.resize_term().

  • gh-123884: Fixed bug in itertools.tee() handling of other tee inputs (a tee in a tee). The output now has the promised n independent new iterators. Formerly, the first iterator was identical (not independent) to the input iterator. This would sometimes give surprising results.

  • gh-58956: Fixed a bug in pdb where sometimes the breakpoint won’t trigger if it was set on a function which is already in the call stack.

  • gh-124345: argparse vim supports abbreviated single-dash long options separated by = from its value.

  • gh-104860: Fix disallowing abbreviation of single-dash long options in argparse with allow_abbrev=False.

  • gh-63143: Fix parsing mutually exclusive arguments in argparse. Arguments with the value identical to the default value (e.g. booleans, small integers, empty or 1-character strings) are no longer considered “not present”.

  • gh-72795: Positional arguments with nargs equal to '*' or argparse.REMAINDER are no longer required. This allows to use positional argument with nargs='*' and without default in mutually exclusive group and improves error message about required arguments.

  • gh-59317: Fix parsing positional argument with nargs equal to '?' or '*' if it is preceded by an option and another positional argument.

  • gh-53780: argparse now ignores the first "--" (double dash) between an option and command.

  • gh-124217: Add RFC 9637 reserved IPv6 block 3fff::/20 in ipaddress module.

  • gh-81691: Fix handling of multiple "--" (double dashes) in argparse. Only the first one has now been removed, all subsequent ones are now taken literally.

  • gh-123978: Remove broken time.thread_time() and time.thread_time_ns() on NetBSD.

  • gh-124008: Fix possible crash (in debug build), incorrect output or returning incorrect value from raw binary write() when writing to console on Windows.

  • gh-123935: Fix parent slots detection for dataclasses that inherit from classes with __dictoffset__.

  • gh-122765: Fix unbalanced quote errors occurring when activate.csh in venv was sourced with a custom prompt containing unpaired quotes or newlines.

  • gh-123370: Fix the canvas not clearing after running turtledemo clock.

  • gh-116810: Resolve a memory leak introduced in CPython 3.10’s ssl when the ssl.SSLSocket.session property was accessed. Speeds up read and write access to said property by no longer unnecessarily cloning session objects via serialization.

  • gh-120754: Update unbounded read calls in zipfile to specify an explicit size putting a limit on how much data they may read. This also updates handling around ZIP max comment size to match the standard instead of reading comments that are one byte too long.

  • gh-70764: Fixed an issue where inspect.getclosurevars() would incorrectly classify an attribute name as a global variable when the name exists both as an attribute name and a global variable.

  • gh-118289: posixpath.realpath() now raises NotADirectoryError when strict mode is enabled and a non-directory path with a trailing slash is supplied.

  • gh-119826: Always return an absolute path for os.path.abspath() on Windows.

  • gh-117766: Always use str() to print choices in argparse.

  • gh-101955: Fix SystemError when match regular expression pattern containing some combination of possessive quantifier, alternative and capture group.

  • gh-88110: Fixed multiprocessing.Process reporting a .exitcode of 1 even on success when using the "fork" start method while using a concurrent.futures.ThreadPoolExecutor.

  • gh-71936: Fix a race condition in multiprocessing.pool.Pool.

  • bpo-46128: Strip unittest.IsolatedAsyncioTestCase stack frames from reported stacktraces.

  • bpo-14074: Fix argparse metavar processing to allow positional arguments to have a tuple metavar.

IDLE

  • gh-122392: Increase currently inadequate vertical spacing for the IDLE browsers (path, module, and stack) on high-resolution monitors.

Documentation

  • gh-126622: Added stub pages for removed modules explaining their removal, where to find replacements, and linking to the last Python version that supported them. Contributed by Ned Batchelder.

  • gh-125277: Require Sphinx 7.2.6 or later to build the Python documentation. Patch by Adam Turner.

  • gh-124872: Added definitions for context, current context, and context management protocol, updated related definitions to be consistent, and expanded the documentation for contextvars.Context.

  • gh-125018: The importlib.metadata documentation now includes semantic cross-reference targets for the significant documented APIs. This means intersphinx references like importlib.metadata.version() will now work as expected.

  • gh-70870: Clarified the dual usage of the term “free variable” (both the formal meaning of any reference to names defined outside the local scope, and the narrower pragmatic meaning of nonlocal variables named in co_freevars).

  • gh-121277: Writers of CPython’s documentation can now use next as the version for the versionchanged, versionadded, deprecated directives.

  • gh-60712: Include the object type in the lists of documented types. Change by Furkan Onder and Martin Panter.

  • bpo-34008: The Py_Main() documentation moved from the “Very High Level API” section to the “Initialization and Finalization” section.

    Also make it explicit that we expect Py_Main to typically be called instead of Py_Initialize rather than after it (since Py_Main makes its own call to Py_Initialize). Document that calling both is supported but is version dependent on which settings will be applied correctly.

Core and Builtins

Library

  • gh-126066: Fix importlib to not write an incomplete .pyc files when a ulimit or some other operating system mechanism is preventing the write to go through fully.

Core and Builtins

  • gh-126312: Fix crash during garbage collection on an object frozen by gc.freeze() on the free-threaded build.

  • gh-126139: Provide better error location when attempting to use a future statement with an unknown future feature.

  • gh-126018: Fix a crash in sys.audit() when passing a non-string as first argument and Python was compiled in debug mode.

  • gh-125942: On Android, the errors setting of sys.stdout was changed from surrogateescape to backslashreplace.

  • gh-125859: Fix a crash in the free threading build when gc.get_objects() or gc.get_referrers() is called during an in-progress garbage collection.

  • gh-125703: Correctly honour tracemalloc hooks in specialized Py_DECREF paths. Patch by Pablo Galindo

  • gh-125593: Use color to highlight error locations in traceback from exception group

  • gh-125444: Fix illegal instruction for older Arm architectures. Patch by Diego Russo, testing by Ross Burton.

  • gh-124375: Fix a crash in the free threading build when the GC runs concurrently with a new thread starting.

  • gh-125221: Fix possible race condition when calling __reduce_ex__() for the first time in the free threading build.

  • gh-125038: Fix crash when iterating over a generator expression after direct changes on gi_frame.f_locals. Patch by Mikhail Efimov.

  • gh-123378: Fix a crash in the __str__() method of UnicodeError objects when the UnicodeError.start and UnicodeError.end values are invalid or out-of-range. Patch by Bénédikt Tran.

  • gh-116510: Fix a crash caused by immortal interned strings being shared between sub-interpreters that use basic single-phase init. In that case, the string can be used by an interpreter that outlives the interpreter that created and interned it. For interpreters that share obmalloc state, also share the interned dict with the main interpreter.

  • gh-122878: Use the pager binary, if available (e.g. on Debian and derivatives), to display REPL help().

  • gh-124188: Fix reading and decoding a line from the source file witn non-UTF-8 encoding for syntax errors raised in the compiler.

  • gh-123930: Improve the error message when a script shadowing a module from the standard library causes ImportError to be raised during a “from” import. Similarly, improve the error message when a script shadowing a third party module attempts to “from” import an attribute from that third party module while still initialising.

  • gh-122907: Building with HAVE_DYNAMIC_LOADING now works as well as it did in 3.12. Existing deficiences will be addressed separately. (See https://github.com/python/cpython/issues/122950.)

Library

  • gh-118950: Fix bug where SSLProtocol.connection_lost wasn’t getting called when OSError was thrown on writing to socket.

  • gh-113570: Fixed a bug in reprlib.repr where it incorrectly called the repr method on shadowed Python built-in types.

Core and Builtins

  • gh-109746: If _thread.start_new_thread() fails to start a new thread, it deletes its state from interpreter and thus avoids its repeated cleanup on finalization.

C API

  • gh-126554: Fix error handling in ctypes.CDLL objects which could result in a crash in rare situations.

  • gh-125608: Fix a bug where dictionary watchers (e.g., PyDict_Watch()) on an object’s attribute dictionary (__dict__) were not triggered when the object’s attributes were modified.

  • bpo-34008: Added Py_IsInitialized to the list of APIs that are safe to call before the interpreter is initialized, and updated the embedding tests to cover it.

Build

  • gh-123877: Set wasm32-wasip1 as the WASI target. The old wasm32-wasi target is deprecated so it can be used for an eventual WASI 1.0.

  • gh-89640: Hard-code float word ordering as little endian on WASM.

  • gh-125940: The Android build now supports 16 KB page sizes.

  • gh-89640: Improve detection of float word ordering on Linux when link-time optimizations are enabled.

  • gh-125269: Fix detection of whether -latomic is needed when cross-compiling CPython using the configure script.

  • gh-121634: Allow for specifying the target compile triple for WASI.

  • gh-122578: Use WASI SDK 24 for testing.

  • gh-115382: Fix cross compile failures when the host and target SOABIs match.

Python 3.13.0 final

Release date: 2024-10-07

Library

Core and Builtins

  • gh-124871: Fix compiler bug (in some versions of 3.13) where an assertion fails during reachability analysis.

Python 3.13.0 release candidate 3

Release date: 2024-10-01

macOS

  • gh-123797: Check for runtime availability of ptsname_r function on macos.

Windows

  • gh-124609: Fix _Py_ThreadId for Windows builds using MinGW. Patch by Tony Roberts.

  • gh-124254: Ensures experimental free-threaded binaries remain installed when updating.

  • gh-123915: Ensure that Tools\msi\buildrelease.bat uses different directories for AMD64 and ARM64 builds.

Tests

  • gh-124378: Updated test_ttk to pass with Tcl/Tk 8.6.15.

Library

IDLE

  • gh-112938: Fix uninteruptable hang when Shell gets rapid continuous output.

  • gh-120104: Fix padding in config and search dialog windows in IDLE.

Documentation

  • gh-124720: Update “Using Python on a Mac” section of the “Python Setup and Usage” document and include information on installing free-threading support.

  • gh-116622: Add an Android platform guide, and flag modules not available on Android.

Core and Builtins

  • gh-124567: Revert the incremental GC (in 3.13), since it’s not clear the benefits outweigh the costs at this point.

  • gh-124642: Fixed scalability issue in free-threaded builds for lock-free reads from dictionaries in multi-threaded scenarios

  • gh-116510: Fix a bug that can cause a crash when sub-interpreters use “basic” single-phase extension modules. Shared objects could refer to PyGC_Head nodes that had been freed as part of interpreter cleanup.

  • gh-124547: When deallocating an object with inline values whose __dict__ is still live: if memory allocation for the inline values fails, clear the dictionary. Prevents an interpreter crash.

  • gh-124513: Fix a crash in FrameLocalsProxy constructor: check the number of arguments. Patch by Victor Stinner.

  • gh-124442: Fix nondeterminism in compilation by sorting the value of __static_attributes__. Patch by kp2pml30.

  • gh-123856: Fix PyREPL failure when a keyboard interrupt is triggered after using a history search

  • gh-65961: Document the deprecation of setting and using __package__ and __cached__.

  • gh-124027: Support <page up>, <page down>, and <delete> keys in the Python REPL when $TERM is set to vt100.

  • gh-77894: Fix possible crash in the garbage collector when it tries to break a reference loop containing a memoryview object. Now a memoryview object can only be cleared if there are no buffers that refer it.

  • gh-123339: Setting the __module__ attribute for a class now removes the __firstlineno__ item from the type’s dict, so they will no longer be inconsistent.

C API

  • gh-124160: Fix crash when importing modules containing state and single-phase initialization in a subinterpreter.

  • gh-123880: Fixed a bug that prevented circular imports of extension modules that use single-phase initialization.

Build

  • gh-124487: Windows builds now use Windows 8.1 as their API baseline (installation already required Windows 8.1).

  • gh-124043: Building using --with-trace-refs is (temporarily) disallowed when the GIL is disabled.

Python 3.13.0 release candidate 2

Release date: 2024-09-06

macOS

  • gh-123418: Updated macOS installer build to use OpenSSL 3.0.15.

Windows

  • gh-123418: Updated Windows build to use OpenSSL 3.0.15.

  • gh-122573: The Windows build of CPython now requires 3.10 or newer.

  • gh-100256: mimetypes no longer fails when it encounters an inaccessible registry key.

  • gh-79846: Makes ssl.create_default_context() ignore invalid certificates in the Windows certificate store

Tools/Demos

  • gh-123418: Update GitHub CI workflows to use OpenSSL 3.0.15 and multissltests to use 3.0.15, 3.1.7, and 3.2.3.

Tests

  • gh-119727: Add --single-process command line option to Python test runner (regrtest). Patch by Victor Stinner.

  • gh-101525: Skip test_gdb if the binary is relocated by BOLT. Patch by Donghee Na.

Security

  • gh-123678: Upgrade libexpat to 2.6.3

  • gh-121285: Remove backtracking from tarfile header parsing for hdrcharset, PAX, and GNU sparse headers.

Library

IDLE

  • gh-120083: Add explicit black IDLE Hovertip foreground color needed for recent macOS. Fixes Sonoma showing unreadable white on pale yellow. Patch by John Riggles.

Library

  • gh-120221: asyncio REPL is now again properly recognizing KeyboardInterrupts. Display of exceptions raised in secondary threads is fixed.

Core and Builtins

  • gh-119310: Allow the new interactive shell to read history files written with the editline library that use unicode-escaped entries. Patch by aorcajo and Łukasz Langa.

  • gh-123572: Fix key mappings for various F-keys in Windows for the new REPL. Patch by devdanzin

  • gh-119034: Change <page up> and <page down> keys of the Python REPL to history search forward/backward. Patch by Victor Stinner.

  • gh-123545: Fix a double decref in rare cases on experimental JIT builds.

  • gh-123484: Fix _Py_DebugOffsets for long objects to be relative to the start of the object rather than the start of a subobject.

  • gh-123344: Add AST optimizations for type parameter defaults.

  • gh-123321: Prevent Parser/myreadline race condition from segfaulting on multi-threaded use. Patch by Bar Harel and Amit Wienner.

  • gh-123177: Fix a bug causing stray prompts to appear in the middle of wrapped lines in the new REPL.

  • gh-122982: Extend the deprecation period for bool inversion (~) by two years.

  • gh-123275: Support -X gil=1 and PYTHON_GIL=1 on non-free-threaded builds.

  • gh-123177: Deactivate line wrap in the Apple Terminal via a ANSI escape code. Patch by Pablo Galindo

  • gh-123229: Fix valgrind warning by initializing the f-string buffers to 0 in the tokenizer. Patch by Pablo Galindo

  • gh-122298: Restore printout of GC stats when gc.set_debug(gc.DEBUG_STATS) is called. This featue was accidentally removed when implementing incremental GC.

  • gh-121804: Correctly show error locations when a SyntaxError is raised in the basic REPL. Patch by Sergey B Kirpichev.

  • gh-123142: Fix too-wide source location in exception tracebacks coming from broken iterables in comprehensions.

  • gh-123048: Fix a bug where pattern matching code could emit a JUMP_FORWARD with no source location.

  • gh-123123: Fix displaying SyntaxError exceptions covering multiple lines. Patch by Pablo Galindo

  • gh-123083: Fix a potential use-after-free in STORE_ATTR_WITH_HINT.

  • gh-123022: Fix crash in free-threaded build when calling Py_Initialize() from a non-main thread.

  • gh-122888: Fix crash on certain calls to str() with positional arguments of the wrong type. Patch by Jelle Zijlstra.

  • gh-116622: Fix Android stdout and stderr messages being truncated or lost.

  • gh-122527: Fix a crash that occurred when a PyStructSequence was deallocated after its type’s dictionary was cleared by the GC. The type’s tp_basicsize now accounts for non-sequence fields that aren’t included in the Py_SIZE of the sequence.

  • gh-122445: Add only fields which are modified via self.* to __static_attributes__.

  • gh-98442: Fix too wide source locations of the cleanup instructions of a with statement.

  • gh-93691: Fix source locations of instructions generated for with statements.

  • gh-120097: FrameLocalsProxy now subclasses collections.abc.Mapping and can be matched as a mapping in match statements

C API

Build

  • gh-123418: Updated Android build to use OpenSSL 3.0.15.

  • gh-123297: Propagate the value of LDFLAGS to LDCXXSHARED in sysconfig. Patch by Pablo Galindo

  • gh-116622: Rename build variable MODULE_LDFLAGS back to LIBPYTHON, as it’s used by package build systems (e.g. Meson).

  • gh-118943: Fix an issue where the experimental JIT could be built several times by the make regen-all target, leading to possible race conditions on heavily parallelized builds.

  • gh-118943: Fix a possible race condition affecting parallel builds configured with --enable-experimental-jit, in which FileNotFoundError could be caused by another process already moving jit_stencils.h.new to jit_stencils.h.

Python 3.13.0 release candidate 1

Release date: 2024-07-31

Tests

Security

  • gh-122133: Authenticate the socket connection for the socket.socketpair() fallback on platforms where AF_UNIX is not available like Windows.

    Patch by Gregory P. Smith <greg@krypto.org> and Seth Larson <seth@python.org>. Reported by Ellie <el@horse64.org>

  • gh-121957: Fixed missing audit events around interactive use of Python, now also properly firing for python -i, as well as for python -m asyncio. The events in question are cpython.run_stdin and cpython.run_startup.

Library

IDLE

  • gh-122482: Change About IDLE to direct users to discuss.python.org instead of the now unused idle-dev email and mailing list.

Core and Builtins

  • gh-116090: Fix an issue in JIT builds that prevented some for loops from correctly firing RAISE monitoring events.

  • gh-122208: Dictionary watchers now only deliver the PyDict_EVENT_ADDED event when the insertion is in a known good state to succeed.

  • gh-122300: Preserve AST nodes for f-string with single-element format specifiers. Patch by Pablo Galindo

  • gh-120906: frame.f_locals now supports arbitrary hashable objects as keys.

  • gh-122029: Emit c_call events in sys.setprofile() when a PyMethodObject pointing to a PyCFunction is called.

  • gh-122026: Fix a bug that caused the tokenizer to not correctly identify mismatched parentheses inside f-strings in some situations. Patch by Pablo Galindo

  • gh-118934: Make PyEval_GetLocals return borrowed reference

C API

  • gh-116622: Make PyObject_Print work around a bug in Android and OpenBSD which prevented it from throwing an exception when trying to write to a read-only stream.

  • gh-121489: Export private _PyBytes_Join() again.

Build

Python 3.13.0 beta 4

Release date: 2024-07-18

Tests

  • gh-121084: Fix test_typing random leaks. Clear typing ABC caches when running tests for refleaks (-R option): call _abc_caches_clear() on typing abstract classes and their subclasses. Patch by Victor Stinner.

  • gh-121160: Add a test for readline.set_history_length(). Note that this test may fail on readline libraries.

  • gh-121200: Fix test_expanduser_pwd2() of test_posixpath. Call getpwnam() to get pw_dir, since it can be different than getpwall() pw_dir. Patch by Victor Stinner.

  • gh-121188: When creating the JUnit XML file, regrtest now escapes characters which are invalid in XML, such as the chr(27) control character used in ANSI escape sequences. Patch by Victor Stinner.

Library

  • gh-57141: The shallow argument to filecmp.dircmp (new in Python 3.13) is now keyword-only.

  • gh-121245: Simplify handling of the history file in site.register_readline() helper. The CAN_USE_PYREPL variable now will be initialized, when imported. Patch by Sergey B Kirpichev.

  • gh-121332: Fix constructor of ast nodes with custom _attributes. Previously, passing custom attributes would raise a DeprecationWarning. Passing arguments to the constructor that are not in _fields or _attributes remains deprecated. Patch by Jelle Zijlstra.

  • gh-121279: Avoid NameError for the warnings module when accessing the depracated atributes of the importlib.abc module.

  • gh-121245: Fix a bug in the handling of the command history of the new REPL that caused the history file to be wiped at REPL exit.

  • gh-87744: Fix waitpid race while calling send_signal() in asyncio. Patch by Kumar Aditya.

  • gh-121018: Fixed other issues where argparse.ArgumentParser did not honor exit_on_error=False.

  • gh-120678: Fix regression in the new REPL that meant that globals from files passed using the -i argument would not be included in the REPL’s global namespace. Patch by Alex Waygood.

  • gh-120782: Fix wrong references of the datetime types after reloading the module.

  • gh-120713: datetime.datetime.strftime() now 0-pads years with less than four digits for the format specifiers %Y and %G on Linux. Patch by Ben Hsing

  • gh-117983: Defer the threading import in importlib.util until lazy loading is used.

  • gh-119189: When using the ** operator or pow() with Fraction as the base and an exponent that is not rational, a float, or a complex, the fraction is no longer converted to a float.

  • gh-118714: Allow restart in post-mortem debugging of pdb. Removed restart message when the user quits pdb from post-mortem mode.

  • gh-105623: Fix performance degradation in logging.handlers.RotatingFileHandler. Patch by Craig Robson.

IDLE

  • gh-78889: Stop Shell freezes by blocking user access to non-method sys.stdout.shell attributes, which are all private.

Documentation

Core and Builtins

  • gh-121860: Fix crash when rematerializing a managed dictionary after it was deleted.

  • gh-121814: Fixed the SegFault when PyEval_SetTrace() is used with no Python frame on stack.

  • gh-121295: Fix PyREPL console getting into a blocked state after interrupting a long paste

  • gh-121794: Fix bug in free-threaded Python where a resurrected object could lead to a negative ref count assertion failure.

  • gh-121657: Improve the SyntaxError message if the user tries to use yield from outside a function.

  • gh-121609: Fix pasting of characters containing unicode character joiners in the new REPL. Patch by Marta Gomez Macias

  • gh-117482: Unexpected slot wrappers are no longer created for builtin static types in subinterpreters.

  • gh-121499: Fix a bug affecting how multi-line history was being rendered in the new REPL after interacting with the new screen cache. Patch by Pablo Galindo

  • gh-121497: Fix a bug that was preventing the REPL to correctly respect the history when an input hook was set. Patch by Pablo Galindo

  • gh-121012: Tier 2 execution now ensures that list iterators remain exhausted, once they become exhausted.

  • gh-121439: Allow tuples of length 20 in the freelist to be reused.

  • gh-121368: Fix race condition in _PyType_Lookup in the free-threaded build due to a missing memory fence. This could lead to _PyType_Lookup returning incorrect results on arm64.

  • gh-121130: Fix f-strings with debug expressions in format specifiers. Patch by Pablo Galindo

  • gh-121115: PyLong_AsNativeBytes() no longer uses __index__() methods by default. The Py_ASNATIVEBYTES_ALLOW_INDEX flag has been added to allow it.

C API

  • gh-89364: Export the PySignal_SetWakeupFd() function. Previously, the function was documented but it couldn’t be used in 3rd party code. Patch by Victor Stinner.

  • gh-113993: PyUnicode_InternInPlace() no longer prevents its argument from being garbage collected.

    Several functions that take char * are now documented as possibly preventing string objects from being garbage collected; refer to their documentation for details: PyUnicode_InternFromString(), PyDict_SetItemString(), PyObject_SetAttrString(), PyObject_DelAttrString(), PyUnicode_InternFromString(), and PyModule_Add* convenience functions.

  • gh-113601: Removed debug build assertions related to interning strings, which were falsely triggered by stable ABI extensions.

  • gh-112136: Restore the private _PyArg_Parser structure and the private _PyArg_ParseTupleAndKeywordsFast() function, previously removed in Python 3.13 alpha 1. Patch by Victor Stinner.

Build

  • gh-120371: Support WASI SDK 22 by explicitly skipping functions that are just stubs in wasi-libc.

  • gh-121731: Fix mimalloc compile error on GNU/Hurd

  • gh-121487: Fix deprecation warning for ATOMIC_VAR_INIT in mimalloc.

  • gh-121467: Fix a Makefile bug that prevented mimalloc header files from being installed.

  • gh-121103: On POSIX systems, excluding macOS framework installs, the lib directory for the free-threaded build now includes a “t” suffix to avoid conflicts with a co-located default build installation.

  • gh-120831: The default minimum iOS version was increased to 13.0.

  • gh-113565: Improve curses and curses.panel dependency checks in configure.

Python 3.13.0 beta 3

Release date: 2024-06-27

Core and Builtins

  • gh-120838: Py_Finalize() and Py_FinalizeEx() now always run with the main interpreter active.

  • gh-113433: Subinterpreters now get cleaned up automatically during runtime finalization.

  • gh-119462: Make sure that invariants of type versioning are maintained: * Superclasses always have their version number assigned before subclasses * The version tag is always zero if the tag is not valid. * The version tag is always non-zero if the tag is valid.

  • gh-120437: Fix _CHECK_STACK_SPACE optimization problems introduced in gh-118322.

  • gh-120722: Correctly set the bytecode position on return instructions within lambdas. Patch by Jelle Zijlstra.

  • gh-120367: Fix bug where compiler creates a redundant jump during pseudo-op replacement. Can only happen with a synthetic AST that has a try on the same line as the instruction following the exception handler.

  • gh-113993: Strings interned with sys.intern() are again garbage-collected when no longer used, as per the documentation. Strings interned with the C function PyUnicode_InternInPlace() are still immortal. Internals of the string interning mechanism have been changed. This may affect performance and identities of str objects.

  • gh-120384: Fix an array out of bounds crash in list_ass_subscript, which could be invoked via some specificly tailored input: including concurrent modification of a list object, where one thread assigns a slice and another clears it.

  • gh-120367: Fix crash in compiler on code with redundant NOPs and JUMPs which show up after exception handlers are moved to the end of the code.

Library

Core and Builtins

  • gh-120400: Support Linux perf profiler to see Python calls on RISC-V architecture.

  • gh-120221: Deliver real signals on Ctrl-C and Ctrl-Z in the new REPL. Patch by Pablo Galindo

  • gh-120346: Respect PYTHON_BASIC_REPL when running in interative inspect mode (python -i). Patch by Pablo Galindo

  • gh-93691: Fix source locations of instructions generated for the iterator of a for statement.

  • gh-120198: Fix a crash when multiple threads read and write to the same __class__ of an object concurrently.

  • gh-120298: Fix use-after free in list_richcompare_impl which can be invoked via some specificly tailored evil input.

  • gh-119666: Fix a compiler crash in the case where two comprehensions in class scope both reference __class__.

  • gh-120225: Fix crash in compiler on empty block at end of exception handler.

  • gh-119933: Improve SyntaxError messages for invalid expressions in a type parameters bound, a type parameter constraint tuple or a default type parameter. Patch by Bénédikt Tran.

  • bpo-24766: Fix handling of doc argument to subclasses of property.

Library

Build

  • gh-120671: Fix failing configure tests due to a missing space when appending to CFLAGS.

  • gh-120602: Correctly handle LLVM installs with LLVM_VERSION_SUFFIX when building with --enable-experimental-jit.

  • gh-120326: On Windows, fix build error when --disable-gil and --experimental-jit options are combined.

  • gh-120291: Make the python-config shell script compatible with non-bash shells.

C API

  • gh-120642: Remove the private _Py_CODEUNIT type from the public C API. The internal pycore_code.h header should now be used to get this internal type. Patch by Victor Stinner.

  • gh-120858: PyDict_Next() no longer locks the dictionary in the free-threaded build. The locking needs to be done by the caller around the entire iteration loop.

  • gh-120642: Remove the following unstable functions:

    • PyUnstable_Replace_Executor()

    • PyUnstable_SetOptimizer()

    • PyUnstable_GetOptimizer()

    • PyUnstable_GetExecutor()

    • PyUnstable_Optimizer_NewCounter()

    • PyUnstable_Optimizer_NewUOpOptimizer()

    Patch by Victor Stinner.

  • gh-119344: The critical section API is now public as part of the non-limited C API.

  • gh-118789: Add PyUnstable_Object_ClearWeakRefsNoCallbacks(), which clears weakrefs without calling their callbacks.

  • gh-117511: Make the PyMutex public in the non-limited C API.

Python 3.13.0 beta 2

Release date: 2024-06-05

Security

  • gh-118773: Fixes creation of ACLs in os.mkdir() on Windows to work correctly on non-English machines.

  • gh-118486: os.mkdir() on Windows now accepts mode of 0o700 to restrict the new directory to the current user. This fixes CVE 2024-4030 affecting tempfile.mkdtemp() in scenarios where the base temporary directory is more permissive than the default.

Core and Builtins

  • gh-119724: Reverted improvements to error messages for elif/else statements not matching any valid statements, which made in hard to locate the syntax errors inside those elif/else blocks.

  • gh-119842: Honor PyOS_InputHook() in the new REPL. Patch by Pablo Galindo

  • gh-119821: Fix execution of annotation scopes within classes when globals is set to a non-dict. Patch by Jelle Zijlstra.

  • gh-119548: Add a clear command to the REPL. Patch by Pablo Galindo

  • gh-111999: Fix the signature of str.format_map().

  • gh-119560: An invalid assert in beta 1 has been removed. The assert would fail if PyState_FindModule() was used in an extension module’s init function before the module def had been initialized.

  • gh-119369: Fix deadlock during thread deletion in free-threaded build, which could occur when the GIL was enabled at runtime.

  • gh-119525: Fix deadlock involving _PyType_Lookup() cache in the free-threaded build when the GIL is dynamically enabled at runtime.

  • gh-119311: Fix bug where names are unexpectedly mangled in the bases of generic classes.

  • gh-119395: Fix bug where names appearing after a generic class are mangled as if they are in the generic class.

  • gh-119213: Non-builtin modules built with argument clinic were crashing if used in a subinterpreter before the main interpreter. The objects that were causing the problem by leaking between interpreters carelessly have been fixed.

  • gh-119011: Fixes type.__type_params__ to return an empty tuple instead of a descriptor.

  • gh-118692: Avoid creating unnecessary StopIteration instances for monitoring.

  • gh-119049: Fix displaying the source line for warnings created by the C API if the warnings module had not yet been imported.

  • gh-118844: Fix build failures when configuring with both --disable-gil and --enable-experimental-jit.

  • gh-118921: Add copy() method for FrameLocalsProxy which returns a snapshot dict for local variables.

  • gh-117657: Fix data races on the field that stores a pointer to the interpreter’s main thread that occur in free-threaded builds.

  • gh-118561: Fix race condition in free-threaded build where list.extend() could expose uninitialised memory to concurrent readers.

  • gh-117195: Avoid assertion failure for debug builds when calling object.__sizeof__(1)

Library

  • gh-119819: Fix regression to allow logging configuration with multiprocessing queue types.

  • gh-117142: The ctypes module may now be imported in all subinterpreters, including those that have their own GIL.

  • gh-118835: Fix _pyrepl crash when using custom prompt with ANSI escape codes.

  • gh-117398: The _datetime module (C implementation for datetime) now supports being imported in multiple interpreters.

  • gh-89727: Fix issue with shutil.rmtree() where a RecursionError is raised on deep directory trees.

  • gh-89727: Partially fix issue with shutil.rmtree() where a RecursionError is raised on deep directory trees. A recursion error is no longer raised when rmtree.avoids_symlink_attacks is false.

  • gh-119118: Fix performance regression in the tokenize module by caching the line token attribute and calculating the column offset more efficiently.

  • gh-89727: Fix issue with os.fwalk() where a RecursionError was raised on deep directory trees by adjusting the implementation to be iterative instead of recursive.

  • gh-119588: zipfile.Path.is_symlink now assesses if the given path is a symlink.

  • gh-119555: Catch SyntaxError from compile() in the runsource() method of the InteractiveColoredConsole. Patch by Sergey B Kirpichev.

  • gh-113892: Now, the method sock_connect of asyncio.ProactorEventLoop raises a ValueError if given socket is not in non-blocking mode, as well as in other loop implementations.

  • gh-119443: The interactive REPL no longer runs with from __future__ import annotations enabled. Patch by Jelle Zijlstra.

  • gh-117398: Objects in the datetime C-API are now all statically allocated, which means better memory safety, especially when the module is reloaded. This should be transparent to users.

  • gh-118894: asyncio REPL now has the same capabilities as PyREPL.

  • gh-118911: In PyREPL, updated maybe-accept’s logic so that if the user hits Enter twice, they are able to terminate the block even if there’s trailing whitespace. Also, now when the user hits arrow up, the cursor is on the last functional line. This matches IPython’s behavior. Patch by Aya Elsayed.

  • gh-111201: Remove dependency to readline from the new Python REPL.

  • gh-119174: Fix high DPI causes turtledemo(turtle-graphics examples) windows blurry Patch by Wulian233 and Terry Jan Reedy

  • gh-119121: Fix a NameError happening in asyncio.staggered.staggered_race. This function is now tested.

  • gh-119113: Fix issue where pathlib.PurePath.with_suffix() didn’t raise TypeError when given None as a suffix.

  • gh-118643: Fix an AttributeError in the email module when re-fold a long address list. Also fix more cases of incorrect encoding of the address separator in the address list.

  • gh-58933: Make pdb return to caller frame correctly when f_trace of the caller frame is not set

  • gh-118895: Setting attributes on typing.NoDefault now raises AttributeError instead of TypeError.

  • gh-118868: Fixed issue where kwargs were no longer passed to the logging handler QueueHandler

  • gh-118851: ctx arguments to the constructors of ast node classes now default to ast.Load(). Patch by Jelle Zijlstra.

  • gh-118760: Restore the default value of tkiter.wantobjects to 1.

  • gh-118760: Fix errors in calling Tkinter bindings on Windows.

  • gh-118507: Fix os.path.isfile() on Windows for pipes. Speedup os.path.isjunction() and os.path.lexists() on Windows with a native implementation.

  • gh-118772: Allow typing.TypeVar instances without a default to follow instances without a default in some cases. Patch by Jelle Zijlstra.

  • gh-110863: os.path.realpath() now suppresses any OSError from os.readlink() when strict mode is disabled (the default).

  • gh-118263: Speed up os.path.splitroot() & os.path.normpath() with a direct C call.

  • gh-118033: Fix dataclasses.dataclass() not creating a __weakref__ slot when subclassing typing.Generic.

  • gh-106531: In importlib.resources, sync with importlib_resources 6.3.2, including: MultiplexedPath now expects Traversable paths, deprecating string arguments to MultiplexedPath; Enabled support for resources in namespace packages in zip files; Fixed NotADirectoryError when calling files on a subdirectory of a namespace package.

  • gh-113978: Ignore warnings on text completion inside REPL.

  • gh-103956: Fix lack of newline characters in trace module output when line tracing is enabled but source code line for current frame is not available.

  • gh-92081: Fix missing spaces in email headers when the spaces are mixed with encoded 8-bit characters.

  • gh-103194: Prepare Tkinter for C API changes in Tcl 8.7/9.0 to avoid _tkinter.Tcl_Obj being unexpectedly returned instead of bool, str, bytearray, or int.

  • gh-87106: Fixed handling in inspect.Signature.bind() of keyword arguments having the same name as positional-only arguments when a variadic keyword argument (e.g. **kwargs) is present.

  • bpo-45767: Fix integer conversion in os.major(), os.minor(), and os.makedev(). Support device numbers larger than 2**63-1. Support non-existent device number (NODEV).

  • gh-67693: Fix urllib.parse.urlunparse() and urllib.parse.urlunsplit() for URIs with path starting with multiple slashes and no authority. Based on patch by Ashwin Ramaswami.

Tests

  • gh-119050: regrtest test runner: Add XML support to the refleak checker (-R option). Patch by Victor Stinner.

Build

  • gh-119729: On POSIX systems, the pkg-config (.pc) filenames now include the ABI flags, which may include debug (“d”) and free-threaded (“t”). For example: * python-3.14.pc (default, non-debug build) * python-3.14d.pc (default, debug build) * python-3.14t.pc (free-threaded build)

  • gh-115119: Fall back to the bundled libmpdec if a system version cannot be found.

  • gh-119132: Update sys.version to identify whether the build is default build or free-threading build. Patch By Donghee Na.

  • gh-118836: Fix an AssertionError when building with --enable-experimental-jit and the compiler emits a SHT_NOTE section.

  • gh-118943: Fix a possible race condition affecting parallel builds configured with --enable-experimental-jit, in which compilation errors could be caused by an incompletely-generated header file.

Windows

  • gh-119679: Ensures correct import libraries are included in Windows installs.

  • gh-119690: Adds Unicode support and fixes audit events for _winapi.CreateNamedPipe.

  • gh-111201: Add support for new pyrepl on Windows

  • gh-119070: Fixes py.exe handling of shebangs like /usr/bin/env python3.12, which were previously interpreted as python3.exe instead of python3.12.exe.

  • gh-117505: Fixes an issue with the Windows installer not running ensurepip in a fully isolated environment. This could cause unexpected interactions with the user site-packages.

  • gh-118209: Avoid crashing in mmap on Windows when the mapped memory is inaccessible due to file system errors or access violations.

  • gh-116145: Updated bundled Tcl/Tk to 8.6.14.

C API

  • gh-119585: Fix crash when a thread state that was created by PyGILState_Ensure() calls a destructor that during PyThreadState_Clear() that calls back into PyGILState_Ensure() and PyGILState_Release(). This might occur when in the free-threaded build or when using thread-local variables whose destructors call PyGILState_Ensure().

  • gh-119336: Restore the removed _PyLong_NumBits() function. It is used by the pywin32 project. Patch by Ethan Smith

  • gh-119247: Added Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST and Py_END_CRITICAL_SECTION_SEQUENCE_FAST macros to make it possible to use PySequence_Fast APIs safely when free-threaded, and update str.join to work without the GIL using them.

  • gh-111389: Add PyHASH_MULTIPLIER constant: prime multiplier used in string and various other hashes. Patch by Victor Stinner.

  • gh-116984: Make mimalloc includes relative to the current file to avoid embedders or extensions needing to include Internal/mimalloc if they are already including internal CPython headers.

  • gh-118789: Restore _PyWeakref_ClearRef that was previously removed in Python 3.13 alpha 1.

Python 3.13.0 beta 1

Release date: 2024-05-08

Security

  • gh-116741: Update bundled libexpat to 2.6.2

  • gh-117233: Detect BLAKE2, SHA3, Shake, & truncated SHA512 support in the OpenSSL-ish libcrypto library at build time. This allows hashlib to be used with libraries that do not to support every algorithm that upstream OpenSSL does.

Core and Builtins

  • gh-118414: Add instrumented opcodes to YIELD_VALUE assertion for tracing cases.

  • gh-117953: When a builtin or extension module is imported for the first time, while a subinterpreter is active, the module’s init function is now run by the main interpreter first before import continues in the subinterpreter. Consequently, single-phase init modules now fail in an isolated subinterpreter without the init function running under that interpreter, whereas before it would run under the subinterpreter before failing, potentially leaving behind global state and callbacks and otherwise leaving the module in an inconsistent state.

  • gh-117549: Don’t use designated initializer syntax in inline functions in internal headers. They cause problems for C++ or MSVC users who aren’t yet using the latest C++ standard (C++20). While internal, pycore_backoff.h, is included (indirectly, via pycore_code.h) by some key 3rd party software that does so for speed.

Library

  • gh-95382: Improve performance of json.dumps() and json.dump() when using the argument indent. Depending on the data the encoding using json.dumps() with indent can be up to 2 to 3 times faster.

Core and Builtins

  • gh-116322: In --disable-gil builds, the GIL will be enabled while loading C extension modules. If the module indicates that it supports running without the GIL, the GIL will be disabled once loading is complete. Otherwise, the GIL will remain enabled for the remainder of the interpreter’s lifetime. This behavior does not apply if the GIL has been explicitly enabled or disabled with PYTHON_GIL or -Xgil.

  • gh-118513: Fix incorrect UnboundLocalError when two comprehensions in the same function both reference the same name, and in one comprehension the name is bound while in the other it’s an implicit global.

  • gh-118518: Allow the Linux perf support to work without frame pointers using perf’s advanced JIT support. The feature is activated when using the PYTHON_PERF_JIT_SUPPORT environment variable or when running Python with -Xperf_jit. Patch by Pablo Galindo.

  • gh-117514: Add sys._is_gil_enabled() function that returns whether the GIL is currently enabled. In the default build it always returns True because the GIL is always enabled. In the free-threaded build, it may return True or False.

  • gh-118164: Break a loop between the Python implementation of the decimal module and the Python code for integer to string conversion. Also optimize integer to string conversion for values in the range from 9_000 to 135_000 decimal digits.

  • gh-118473: Fix sys.set_asyncgen_hooks() not to be partially set when raising TypeError.

  • gh-118465: Compiler populates the new __firstlineno__ field on a class with the line number of the first line of the class definition.

  • gh-118492: Fix an issue where the type cache can expose a previously accessed attribute when a finalizer is run.

  • gh-117714: update async_generator.athrow().close() and async_generator.asend().close() to close their section of the underlying async generator

  • gh-111201: The interactive interpreter is now implemented in Python, which allows for a number of new features like colors, multiline input, history viewing, and paste mode. Contributed by Pablo Galindo, Łukasz Langa and Lysandros Nikolaou based on code from the PyPy project.

  • gh-74929: Implement PEP 667: converted FrameType.f_locals and PyFrame_GetLocals() to return a write-through proxy object when the frame refers to a function or comprehension.

  • gh-116767: Fix crash in compiler on ‘async with’ that has many context managers.

  • gh-118335: Change how to use the tier 2 interpreter. Instead of running Python with -X uops or setting the environment variable PYTHON_UOPS=1, this choice is now made at build time by configuring with --enable-experimental-jit=interpreter.

    Beware! This changes the environment variable to enable or disable micro-ops to PYTHON_JIT. The old PYTHON_UOPS is no longer used.

  • gh-118306: Update JIT compilation to use LLVM 18

  • gh-118160: Annotation scopes within classes can now contain comprehensions. However, such comprehensions are not inlined into their parent scope at runtime. Patch by Jelle Zijlstra.

  • gh-118272: Fix bug where generator.close does not free the generator frame’s locals.

  • gh-118216: Don’t consider __future__ imports with dots before the module name.

  • gh-118074: Make sure that the Executor objects in the COLD_EXITS array aren’t assumed to be GC-able (which would access bytes outside the object).

  • gh-107674: Lazy load frame line number to improve performance of tracing

  • gh-118082: Improve SyntaxError message for imports without names, like in from x import and import cases. It now points out to users that import expects at least one name after it.

  • gh-118090: Improve SyntaxError message for empty type param brackets.

  • gh-117958: Added a get_jit_code() method to access JIT compiled machine code from the UOp Executor when the experimental JIT is enabled. Patch by Anthony Shaw.

  • gh-117901: Add option for compiler’s codegen to save nested instruction sequences for introspection.

  • gh-116622: Redirect stdout and stderr to system log when embedded in an Android app.

  • gh-109118: annotation scope within class scopes can now contain lambdas.

  • gh-117894: Prevent agen.aclose() objects being re-used after .throw().

  • gh-117881: prevent concurrent access to an async generator via athrow().throw() or asend().throw()

  • gh-117536: Fix a RuntimeWarning when calling agen.aclose().throw(Exception).

  • gh-117755: Fix mimalloc allocator for huge memory allocation (around 8,589,934,592 GiB) on s390x. Patch by Victor Stinner.

  • gh-117750: Fix issue where an object’s dict would get out of sync with the object’s internal values when being cleared. obj.__dict__.clear() now clears the internal values, but leaves the dict attached to the object.

  • gh-117431: Improve the performance of the following bytes and bytearray methods by adapting them to the METH_FASTCALL calling convention:

    • count()

    • find()

    • index()

    • rfind()

    • rindex()

  • gh-117709: Speed up calls to str() with positional-only argument, by using the PEP 590 vectorcall calling convention. Patch by Erlend Aasland.

  • gh-117680: Give _PyInstructionSequence a Python interface and use it in tests.

  • gh-115776: Statically allocated objects are, by definition, immortal so must be marked as such regardless of whether they are in extension modules or not.

  • gh-117385: Remove unhandled PY_MONITORING_EVENT_BRANCH and PY_MONITORING_EVENT_EXCEPTION_HANDLED events from sys.settrace().

  • gh-116322: Extension modules may indicate to the runtime that they can run without the GIL. Multi-phase init modules do so by calling providing Py_MOD_GIL_NOT_USED for the Py_mod_gil slot, while single-phase init modules call PyUnstable_Module_SetGIL(mod, Py_MOD_GIL_NOT_USED) from their init function.

  • gh-116129: Implement PEP 696, adding support for defaults on type parameters. Patch by Jelle Zijlstra.

  • gh-93502: Add two new functions to the C-API, PyRefTracer_SetTracer() and PyRefTracer_GetTracer(), that allows to track object creation and destruction the same way the tracemalloc module does. Patch by Pablo Galindo

  • gh-107674: Improved the performance of sys.settrace() significantly

  • gh-95754: Improve the error message when a script shadowing a module from the standard library causes AttributeError to be raised. Similarly, improve the error message when a script shadowing a third party module attempts to access an attribute from that third party module while still initialising.

  • gh-99180: Elide uninformative traceback indicators in return and simple assignment statements. Patch by Pablo Galindo.

  • gh-105879: Allow the globals and locals arguments to exec() and eval() to be passed as keywords.

Library

  • gh-118418: A DeprecationWarning is now emitted if you fail to pass a value to the new type_params parameter of typing._eval_type() or typing.ForwardRef._evaluate(). (Using either of these private and undocumented functions is discouraged to begin with, but failing to pass a value to the type_params parameter may lead to incorrect behaviour on Python 3.12 or newer.)

  • gh-118660: Add an optional second type parameter to typing.ContextManager and typing.AsyncContextManager, representing the return types of __exit__() and __aexit__() respectively. This parameter defaults to bool | None.

  • gh-118650: The enum module allows method named _repr_* to be defined on Enum types.

  • gh-118648: Add type parameter defaults to typing.Generator and typing.AsyncGenerator.

  • gh-101137: Mime type text/x-rst is now supported by mimetypes.

  • gh-118164: The Python implementation of the decimal module could appear to hang in relatively small power cases (like 2**117) if context precision was set to a very high value. A different method to check for exactly representable results is used now that doesn’t rely on computing 10**precision (which could be effectively too large to compute).

  • gh-111744: breakpoint() and pdb.set_trace() now enter the debugger immediately after the call rather than before the next line is executed.

  • gh-118500: Add pdb support for zipapps

  • gh-118406: Add signature for sqlite3.Connection objects.

  • gh-101732: Use a Y2038 compatible openssl time function when available.

  • gh-118404: Fix inspect.signature() for non-comparable callables.

  • gh-118402: Fix inspect.signature() for the result of the functools.cmp_to_key() call.

  • gh-116622: On Android, sysconfig.get_platform now returns the format specified by PEP 738.

  • gh-118285: Allow to specify the signature of custom callable instances of extension type by the __text_signature__ attribute. Specify signatures of operator.attrgetter, operator.itemgetter, and operator.methodcaller instances.

  • gh-118314: Fix an edge case in binascii.a2b_base64() strict mode, where excessive padding is not detected when no padding is necessary.

  • gh-118271: Add the PhotoImage methods read() to read an image from a file and data() to get the image data. Add background and grayscale parameters to PhotoImage method write().

  • gh-118225: Add the PhotoImage method copy_replace() to copy a region from one image to other image, possibly with pixel zooming and/or subsampling. Add from_coords parameter to PhotoImage methods copy(), zoom() and subsample(). Add zoom and subsample parameters to PhotoImage method copy().

  • gh-118221: Fix a bug where sqlite3.Connection.iterdump() could fail if a custom row factory was used. Patch by Erlend Aasland.

  • gh-118013: Fix regression introduced in gh-103193 that meant that calling inspect.getattr_static() on an instance would cause a strong reference to that instance’s class to persist in an internal cache in the inspect module. This caused unexpected memory consumption if the class was dynamically created, the class held strong references to other objects which took up a significant amount of memory, and the cache contained the sole strong reference to the class. The fix for the regression leads to a slowdown in getattr_static(), but the function should still be significantly faster than it was in Python 3.11. Patch by Alex Waygood.

  • gh-118218: Speed up itertools.pairwise() in the common case by up to 1.8x.

  • gh-117486: Improve the behavior of user-defined subclasses of ast.AST. Such classes will now require no changes in the usual case to conform with the behavior changes of the ast module in Python 3.13. Patch by Jelle Zijlstra.

  • gh-90848: Fixed unittest.mock.create_autospec() to configure parent mock with keyword arguments.

  • gh-118168: Fix incorrect argument substitution when typing.Unpack is used with the builtin tuple. typing.Unpack now raises TypeError when used with certain invalid types. Patch by Jelle Zijlstra.

  • gh-118131: Add command-line interface for the random module. Patch by Hugo van Kemenade.

  • gh-118107: Fix zipimport reading of ZIP64 files with file entries that are too big or offset too far.

  • gh-102511: Fix os.path.normpath() for UNC paths on Windows. Speed up os.path.splitroot() with a native implementation.

  • gh-117535: Change the unknown filename of warnings from sys to <sys> to clarify that it’s not a real filename.

  • gh-114053: Fix erroneous NameError when calling typing.get_type_hints() on a class that made use of PEP 695 type parameters in a module that had from __future__ import annotations at the top of the file. Patch by Alex Waygood.

  • gh-116931: Add parameter fileobj check for tarfile.TarFile.addfile()

  • gh-117995: Don’t raise DeprecationWarning when a sequence of parameters is used to bind indexed, nameless placeholders. See also gh-100668.

  • gh-80361: Fix TypeError in email.message.Message.get_payload() when the charset is RFC 2231 encoded.

  • gh-86650: Fix IndexError when parse some emails with invalid Message-ID (including one-off addresses generated by Microsoft Outlook).

  • gh-117691: Improve the error messages emitted by tarfile deprecation warnings relating to PEP 706. If a filter argument is not provided to extract() or extractall, the deprecation warning now points to the line in the user’s code where the relevant function was called. Patch by Alex Waygood.

  • gh-115874: Fixed a possible segfault during garbage collection of _asyncio.FutureIter objects. Patch by Savannah Ostrowski.

  • gh-115060: Speed up pathlib.Path.glob() by omitting an initial is_dir() call. As a result of this change, glob() can no longer raise OSError.

  • gh-77102: site module now parses .pth file with UTF-8 first, and locale encoding if UnicodeDecodeError happened. It supported only locale encoding before.

  • gh-76785: We’ve exposed the low-level _interpreters module for the sake of the PyPI implementation of PEP 734. It was sometimes available as the _xxsubinterpreters module and was formerly used only for testing. For the most part, it should be considered an internal module, like _thread and _imp. See https://discuss.python.org/t/pep-734-multiple-interpreters-in-the-stdlib/41147/26.

  • gh-115060: Speed up pathlib.Path.glob() by not scanning directories for non-wildcard pattern segments.

  • gh-117727: Speed up pathlib.Path.iterdir() by using os.scandir() internally.

  • gh-117586: Speed up pathlib.Path.walk() by working with strings internally.

  • gh-117722: Change the new multi-separator support in asyncio.StreamReader.readuntil() to only accept tuples of separators rather than arbitrary iterables.

  • gh-117692: Fixes a bug when doctest.DocTestFinder was failing on wrapped builtin_function_or_method.

  • gh-117348: Largely restored import time performance of configparser by avoiding dataclasses.

  • gh-117641: Speedup os.path.commonpath() on Unix.

  • gh-117663: Fix _simple_enum to detect aliases when multiple arguments are present but only one is the member value.

  • gh-117636: Speedup os.path.join().

  • gh-117618: Support package.module as filename for break command of pdb

  • gh-102247: the status codes enum with constants in http.HTTPStatus are updated to include the names from RFC9110. This RFC includes some HTTP statuses previously only used for WEBDAV and assigns more generic names to them.

    The old constants are preserved for backwards compatibility.

  • gh-117607: Speedup os.path.relpath().

  • gh-117586: Speed up pathlib.Path.glob() by working with strings internally.

  • gh-117225: Add colour to doctest output. Patch by Hugo van Kemenade.

  • gh-117566: ipaddress.IPv6Address.is_loopback() will now return True for IPv4-mapped loopback addresses, i.e. addresses in the ::ffff:127.0.0.0/104 address space.

  • gh-117546: Fix issue where os.path.realpath() stopped resolving symlinks after encountering a symlink loop on POSIX.

  • gh-116720: Improved behavior of asyncio.TaskGroup when an external cancellation collides with an internal cancellation. For example, when two task groups are nested and both experience an exception in a child task simultaneously, it was possible that the outer task group would misbehave, because its internal cancellation was swallowed by the inner task group.

    In the case where a task group is cancelled externally and also must raise an ExceptionGroup, it will now call the parent task’s cancel() method. This ensures that a asyncio.CancelledError will be raised at the next await, so the cancellation is not lost.

    An added benefit of these changes is that task groups now preserve the cancellation count (asyncio.Task.cancelling()).

    In order to handle some corner cases, asyncio.Task.uncancel() may now reset the undocumented _must_cancel flag when the cancellation count reaches zero.

  • gh-117516: Add typing.TypeIs, implementing PEP 742. Patch by Jelle Zijlstra.

  • gh-117503: Fix support of non-ASCII user names in bytes paths in os.path.expanduser() on Posix.

  • gh-117394: os.path.ismount() is now 2-3 times faster if the user has permissions.

  • gh-117313: Only treat '\n', '\r' and '\r\n' as line separators in re-folding the email messages. Preserve control characters '\v', '\f', '\x1c', '\x1d' and '\x1e' and Unicode line separators '\x85', '\u2028' and '\u2029' as is.

  • gh-117142: Convert _ctypes to multi-phase initialisation (PEP 489).

  • gh-66543: Add the mimetypes.guess_file_type() function which works with file path. Passing file path instead of URL in guess_type() is soft deprecated.

  • gh-68583: webbrowser CLI: replace getopt with argparse, add long options. Patch by Hugo van Kemenade.

  • gh-116871: Name suggestions for AttributeError and ImportError now only include underscored names if the original name was underscored.

  • gh-116023: Don’t show empty fields (value None or []) in ast.dump() by default. Add show_empty=False parameter to optionally show them.

  • gh-115961: Added name and mode attributes for compressed and archived file-like objects in modules bz2, lzma, tarfile and zipfile. The value of the mode attribute of gzip.GzipFile was changed from integer (1 or 2) to string ('rb' or 'wb'). The value of the mode attribute of the readable file-like object returned by zipfile.ZipFile.open() was changed from 'r' to 'rb'.

  • gh-82062: Fix inspect.signature() to correctly handle parameter defaults on methods in extension modules that use names defined in the module namespace.

  • gh-83856: Honor atexit for all multiprocessing start methods

  • gh-113081: Print colorized exception just like built-in traceback in pdb

  • gh-112855: Speed up pickling of pathlib.PurePath objects. Patch by Barney Gale.

  • gh-111744: Support opcode events in bdb

  • gh-109617: ncurses: fixed a crash that could occur on macOS 13 or earlier when Python was built with Apple Xcode 15’s SDK.

  • gh-83151: Enabled arbitrary statements and evaluations in pdb shell to access the local variables of the current frame, which made it possible for multi-scope code like generators or nested function to work.

  • gh-110209: Add __class_getitem__() to types.GeneratorType and types.CoroutineType for type hinting purposes. Patch by James Hilton-Balfe.

  • gh-108191: The types.SimpleNamespace now accepts an optional positional argument which specifies initial values of attributes as a dict or an iterable of key-value pairs.

  • gh-62090: Fix assertion errors caused by whitespace in metavars or SUPPRESS-ed groups in argparse by simplifying usage formatting. Patch by Ali Hamdan.

  • gh-102402: Adjust logging.LogRecord to use time.time_ns() and fix minor bug related to floating-point math.

  • gh-100242: Bring pure Python implementation functools.partial.__new__ more in line with the C-implementation by not just always checking for the presence of the attribute 'func' on the first argument of partial. Instead, both the Python version and the C version perform an isinstance(func, partial) check on the first argument of partial.

  • gh-99730: HEAD requests are no longer upgraded to GET request during redirects in urllib.

  • gh-66410: Setting the tkinter module global wantobjects to 2 before creating the Tk object or call the wantobjects() method of the Tk object with argument 2 makes now arguments to callbacks registered in the tkinter module to be passed as various Python objects (int, float, bytes, tuple), depending on their internal representation in Tcl, instead of always str. tkinter.wantobjects is now set to 2 by default.

  • bpo-40943: Fix several IndexError when parse emails with truncated Message-ID, address, routes, etc, e.g. example@.

  • bpo-39324: Add mime type mapping for .md <-> text/markdown

  • bpo-18108: shutil.chown() now supports dir_fd and follow_symlinks keyword arguments.

  • bpo-30988: Fix parsing of emails with invalid address headers having a leading or trailing dot. Patch by tsufeki.

  • bpo-32839: Add the after_info() method for Tkinter widgets.

Documentation

  • gh-117928: The minimum Sphinx version required for the documentation is now 6.2.1.

Build

  • gh-118734: Fixes Windows build when invoked directly (not through the build.bat script) without specifying a value for UseTIER2.

  • gh-115119: The configure option --with-system-libmpdec now defaults to yes. The bundled copy of libmpdecimal will be removed in Python 3.15.

  • gh-117845: Fix building against recent libedit versions by detecting readline hook signatures in configure.

  • gh-116622: A testbed project was added to run the test suite on Android.

  • gh-117645: Increase WASI stack size from 512 KiB to 8 MiB and the initial memory from 10 MiB to 20 MiB. Patch by Victor Stinner.

  • gh-115119: configure now uses pkg-config to detect decimal dependencies if the --with-system-libmpdec option is given.

Windows

  • gh-115119: Update Windows installer to use libmpdecimal 4.0.0.

  • gh-118486: os.mkdir() now accepts mode of 0o700 to restrict the new directory to the current user.

  • gh-118347: Fixes launcher updates not being installed.

  • gh-118293: The multiprocessing module now passes the STARTF_FORCEOFFFEEDBACK flag when spawning processes to tell Windows not to change the mouse cursor.

  • gh-115009: Update Windows installer to use SQLite 3.45.3.

  • gh-90329: Suppress the warning displayed on virtual environment creation when the requested and created paths differ only by a short (8.3 style) name. Warnings will continue to be shown if a junction or symlink in the path caused the venv to be created in a different location than originally requested.

  • gh-117786: Fixes virtual environments not correctly launching when created from a Store install.

macOS

  • gh-115119: Update macOS installer to use libmpdecimal 4.0.0.

  • gh-114099: iOS preprocessor symbol usage was made compatible with older macOS SDKs.

  • gh-115009: Update macOS installer to use SQLite 3.45.3.

  • gh-91629: Use ~/.config/fish/conf.d configs and fish_add_path to set PATH when installing for the Fish shell.

IDLE

  • bpo-34774: Use user-selected color theme for Help => IDLE Doc.

C API

Python 3.13.0 alpha 6

Release date: 2024-04-09

Core and Builtins

  • gh-117494: Refactored the instruction sequence data structure out of compile.c into instruction_sequence.c.

  • gh-116968: Introduce a unified 16-bit backoff counter type (_Py_BackoffCounter), shared between the Tier 1 adaptive specializer and the Tier 2 optimizer. The API used for adaptive specialization counters is changed but the behavior is (supposed to be) identical.

    The behavior of the Tier 2 counters is changed:

    • There are no longer dynamic thresholds (we never varied these).

    • All counters now use the same exponential backoff.

    • The counter for JUMP_BACKWARD starts counting down from 16.

    • The temperature in side exits starts counting down from 64.

  • gh-117431: Improve the performance of the following bytes and bytearray methods by adapting them to the METH_FASTCALL calling convention:

    • endswith()

    • startswith()

  • gh-117431: Improve the performance of the following str methods by adapting them to the METH_FASTCALL calling convention:

  • gh-117411: Move PyFutureFeatures to an internal header and make it private.

  • gh-109120: Added handle of incorrect star expressions, e.g f(3, *). Patch by Grigoryev Semyon

  • gh-117266: Fix crashes for certain user-created subclasses of ast.AST. Such classes are now expected to set the _field_types attribute.

  • gh-99108: Updated the hashlib built-in HACL* project C code from upstream that we use for many implementations when they are not present via OpenSSL in a given build. This also avoids the rare potential for a C symbol name one definition rule linking issue.

  • gh-117108: Change the old space bit of objects in the young generation from 0 to gcstate->visited, so that any objects created during GC will have the old bit set correctly if they get moved into the old generation.

  • gh-117108: The cycle GC now chooses the size of increments based on the total heap size, instead of the rate of object creation. This ensures that it can keep up with growing heaps.

  • gh-116735: For INSTRUMENTED_CALL_FUNCTION_EX, set arg0 to sys.monitoring.MISSING instead of None for CALL event.

  • gh-113964: Starting new threads and process creation through os.fork() are now only prevented once all non-daemon threads exit.

  • gh-116626: Ensure INSTRUMENTED_CALL_FUNCTION_EX always emits CALL

  • gh-116554: list.sort() now exploits more cases of partial ordering, particularly those with long descending runs with sub-runs of equal values. Those are recognized as single runs now (previously, each block of repeated values caused a new run to be created).

  • gh-114099: Added a Loader that can discover extension modules in an iOS-style Frameworks folder.

  • gh-115775: Compiler populates the new __static_attributes__ field on a class with the names of attributes of this class which are accessed through self.X from any function in its body.

  • gh-115776: The array of values, the PyDictValues struct is now embedded in the object during allocation. This provides better performance in the common case, and does not degrade as much when the object’s __dict__ is materialized.

  • gh-108362: Implement an incremental cyclic garbage collector. By collecting the old generation in increments, there is no need for a full heap scan. This can hugely reduce maximum pause time for programs with large heaps.

    Reduce the number of generations from three to two. The old generation is split into two spaces, “visited” and “pending”.

    Collection happens in two steps:: * An increment is formed from the young generation and a small part of the pending space. * This increment is scanned and the survivors moved to the end of the visited space.

    When the collecting space becomes empty, the two spaces are swapped.

Library

  • gh-109870: Dataclasses now calls exec() once per dataclass, instead of once per method being added. This can speed up dataclass creation by up to 20%.

  • gh-97901: Mime type text/rtf is now supported by mimetypes.

Core and Builtins

  • bpo-24612: Improve the SyntaxError that happens when ‘not’ appears after an operator. Patch by Pablo Galindo

Library

  • gh-117648: Improve performance of os.path.join() and os.path.expanduser().

  • gh-117584: Raise TypeError for non-paths in posixpath.relpath.

  • gh-117467: Preserve mailbox ownership when rewriting in mailbox.mbox.flush. Patch by Tony Mountifield.

  • gh-114848: Raise FileNotFoundError when getcwd() returns ‘(unreachable)’, which can happen on Linux >= 2.6.36 with glibc < 2.27.

  • gh-117459: asyncio.asyncio.run_coroutine_threadsafe() now keeps the traceback of CancelledError, TimeoutError and InvalidStateError which are raised in the coroutine.

  • gh-117381: Fix error message for ntpath.commonpath().

  • gh-117337: Deprecate undocumented glob.glob0() and glob.glob1() functions. Use glob.glob() and pass a directory to its root_dir argument instead.

  • gh-117349: Optimise several functions in os.path.

  • gh-117348: Refactored configparser.RawConfigParser._read() to reduce cyclometric complexity and improve comprehensibility.

  • gh-117335: Raise TypeError for non-sequences for ntpath.commonpath().

  • gh-66449: configparser.ConfigParser now accepts unnamed sections before named ones, if configured to do so.

  • gh-88014: In documentation of gzip.GzipFile in module gzip, explain data type of optional constructor argument mtime, and recommend mtime = 0 for generating deterministic streams.

  • gh-117310: Fixed an unlikely early & extra Py_DECREF triggered crash in ssl when creating a new _ssl._SSLContext if CPython was built implausibly such that the default cipher list is empty or the SSL library it was linked against reports a failure from its C SSL_CTX_set_cipher_list() API.

  • gh-117294: A DocTestCase now reports as skipped if all examples in the doctest are skipped.

  • gh-98966: In subprocess, raise a more informative message when stdout=STDOUT.

  • gh-117225: doctest: only print “and X failed” when non-zero, don’t pluralise “1 items”. Patch by Hugo van Kemenade.

  • gh-117205: Speed up compileall.compile_dir() by 20% when using multiprocessing by increasing chunksize.

  • gh-117178: Fix regression in lazy loading of self-referential modules, introduced in gh-114781.

  • gh-112383: Fix dis module’s handling of ENTER_EXECUTOR instructions.

  • gh-117182: Lazy-loading of modules that modify their own __class__ no longer reverts the __class__ to types.ModuleType.

  • gh-117084: Fix zipfile extraction for directory entries with the name containing backslashes on Windows.

  • gh-117114: Make os.path.isdevdrive() available on all platforms. For those that do not offer Dev Drives, it will always return False.

  • gh-117110: Fix a bug that prevents subclasses of typing.Any to be instantiated with arguments. Patch by Chris Fu.

  • gh-109653: Deferred select imports in importlib.metadata and importlib.resources for a 14% speedup.

  • gh-70647: Start the deprecation period for the current behavior of datetime.datetime.strptime() and time.strptime() which always fails to parse a date string with a ValueError involving a day of month such as strptime("02-29", "%m-%d") when a year is not specified and the date happen to be February 29th. This should help avoid users finding new bugs every four years due to a natural mistaken assumption about the API when parsing partial date values.

  • gh-116987: Fixed inspect.findsource() for class code objects.

  • gh-114099: Modify standard library to allow for iOS platform differences.

  • gh-90872: On Windows, subprocess.Popen.wait() no longer calls WaitForSingleObject() with a negative timeout: pass 0 ms if the timeout is negative. Patch by Victor Stinner.

  • gh-116957: configparser: Don’t leave ConfigParser values in an invalid state (stored as a list instead of a str) after an earlier read raised DuplicateSectionError or DuplicateOptionError.

  • gh-115538: _io.WindowsConsoleIO now emit a warning if a boolean value is passed as a filedescriptor argument.

  • gh-90095: Ignore empty lines and comments in .pdbrc

  • gh-106531: Refreshed zipfile._path from zipp 3.18, providing better compatibility for PyPy, better glob performance for deeply nested zipfiles, and providing internal access to CompleteDirs.inject for use in other tests (like importlib.resources).

  • gh-63207: On Windows, time.time() now uses the GetSystemTimePreciseAsFileTime() clock to have a resolution better than 1 us, instead of the GetSystemTimeAsFileTime() clock which has a resolution of 15.6 ms. Patch by Victor Stinner.

  • gh-116764: Restore support of None and other false values in urllib.parse functions parse_qs() and parse_qsl(). Also, they now raise a TypeError for non-zero integers and non-empty sequences.

  • gh-116811: In PathFinder.invalidate_caches, delegate to MetadataPathFinder.invalidate_caches.

  • gh-116647: Fix recursive child in dataclasses

  • gh-113171: Fixed various false positives and false negatives in

    Also in the corresponding ipaddress.IPv4Network and ipaddress.IPv6Network attributes.

  • gh-63283: In encodings.idna, any capitalization of the ACE prefix (xn--) is now acceptable. Patch by Pepijn de Vos and Zackery Spytz.

  • gh-71042: Add platform.android_ver(), which provides device and OS information on Android.

  • gh-73468: Added new math.fma() function, wrapping C99’s fma() operation: fused multiply-add function. Patch by Mark Dickinson and Victor Stinner.

  • gh-116608: The importlib.resources functions is_resource(), open_binary(), open_text(), path(), read_binary(), and read_text() are un-deprecated, and support subdirectories via multiple positional arguments. The contents() function also allows subdirectories, but remains deprecated.

  • gh-116484: Change automatically generated tkinter.Checkbutton widget names to avoid collisions with automatically generated tkinter.ttk.Checkbutton widget names within the same parent widget.

  • gh-114314: In ctypes, ctype data is now stored in type objects directly rather than in a dict subclass. This is an internal change that should not affect usage.

  • gh-116401: Fix blocking os.fwalk() and shutil.rmtree() on opening named pipe.

  • gh-71052: Implement ctypes.util.find_library() on Android.

  • gh-90535: Fix support of interval values > 1 in logging.TimedRotatingFileHandler for when='MIDNIGHT' and when='Wx'.

  • gh-113308: Remove some internal protected parts from uuid: _has_uuid_generate_time_safe, _netbios_getnode, _ipconfig_getnode, and _load_system_functions. They were unused.

  • gh-115627: Fix the ssl module error handling of connection terminate by peer. It now throws an OSError with the appropriate error code instead of an EOFError.

  • gh-114847: Speed up os.path.realpath() on non-Windows platforms.

  • gh-114271: Fix a race in threading.Thread.join().

    threading._MainThread now always represents the main thread of the main interpreter.

    PyThreadState.on_delete and PyThreadState.on_delete_data have been removed.

  • gh-113538: Add asyncio.Server.close_clients() and asyncio.Server.abort_clients() methods which allow to more forcefully close an asyncio server.

  • gh-85287: Changes Unicode codecs to return UnicodeEncodeError or UnicodeDecodeError, rather than just UnicodeError.

  • gh-113548: pdb now allows CLI arguments to pdb -m.

  • gh-112948: Make completion of pdb similar to Python REPL

  • gh-105866: Fixed _get_slots bug which caused error when defining dataclasses with slots and a weakref_slot.

  • gh-96471: Add asyncio.Queue termination with shutdown() method.

  • gh-89739: The zipimport module can now read ZIP64 files.

  • bpo-33533: asyncio.as_completed() now returns an object that is both an asynchronous iterator and plain iterator. The new asynchronous iteration pattern allows for easier correlation between prior tasks and their completed results. This is a closer match to concurrent.futures.as_completed()’s iteration pattern. Patch by Justin Arthur.

  • bpo-27578: inspect.getsource() (and related functions) work with empty module files, returning '\n' (or reasonable equivalent) instead of raising OSError. Patch by Kernc.

  • bpo-37141: Accept an iterable of separators in asyncio.StreamReader.readuntil(), stopping when one of them is encountered.

  • gh-66543: Make mimetypes.guess_type() properly parsing of URLs with only a host name, URLs containing fragment or query, and filenames with only a UNC sharepoint on Windows. Based on patch by Dong-hee Na.

  • bpo-15010: unittest.TestLoader.discover() now saves the original value of unittest.TestLoader._top_level_dir and restores it at the end of the call.

Documentation

  • gh-115977: Remove compatibility references to Emscripten.

  • gh-114099: Add an iOS platform guide, and flag modules not available on iOS.

  • gh-91565: Changes to documentation files and config outputs to reflect the new location for reporting bugs - i.e. GitHub rather than bugs.python.org.

Tests

  • gh-83434: Disable JUnit XML output (--junit-xml=FILE command line option) in regrtest when hunting for reference leaks (-R option). Patch by Victor Stinner.

  • gh-117187: Fix XML tests for vanilla Expat <2.6.0.

  • gh-116333: Tests of TLS related things (error codes, etc) were updated to be more lenient about specific error message strings and behaviors as seen in the BoringSSL and AWS-LC forks of OpenSSL.

  • gh-117089: Consolidated tests for importlib.metadata in their own metadata package.

  • gh-115979: Update test_importlib so that it passes under WASI SDK 21.

  • gh-112536: Add –tsan to test.regrtest for running TSAN tests in reasonable execution times. Patch by Donghee Na.

  • gh-116307: Added import helper isolated_modules as CleanImport does not remove modules imported during the context. Use it in importlib.resources tests to avoid leaving mod around to impede importlib.metadata tests.

Build

  • gh-114736: Have WASI builds use WASI SDK 21.

  • gh-115983: Skip building test modules that must be built as shared under WASI.

  • gh-71052: Add Android build script and instructions.

Windows

  • gh-117267: Ensure DirEntry.stat().st_ctime behaves consistently with os.stat() during the deprecation period of st_ctime by containing the same value as st_birthtime. After the deprecation period, st_ctime will be the metadata change time (or unavailable through DirEntry), and only st_birthtime will contain the creation time.

  • gh-116195: Improves performance of os.getppid() by using an alternate system API when available. Contributed by vxiiduu.

  • gh-88494: On Windows, time.monotonic() now uses the QueryPerformanceCounter() clock to have a resolution better than 1 us, instead of the GetTickCount64() clock which has a resolution of 15.6 ms. Patch by Victor Stinner.

  • gh-116773: Fix instances of <_overlapped.Overlapped object at 0xXXX> still has pending operation at deallocation, the process may crash.

  • gh-91227: Fix the asyncio ProactorEventLoop implementation so that sending a datagram to an address that is not listening does not prevent receiving any more datagrams.

  • gh-115119: Switched from vendored libmpdecimal code to a separately-hosted external package in the cpython-source-deps repository when building the _decimal module.

C API

  • gh-117642: Fix PEP 737 implementation for %#T and %#N.

  • gh-87193: _PyBytes_Resize() can now be called for bytes objects with reference count > 1, including 1-byte bytes objects. It creates a new bytes object and destroys the old one if it has reference count > 1.

  • gh-117021: Fix integer overflow in PyLong_AsPid() on non-Windows 64-bit platforms.

  • gh-115756: PyCode_GetFirstFree() is an ustable API now and has been renamed to PyUnstable_Code_GetFirstFree(). (Contributed by Bogdan Romanyuk in gh-115781)

  • gh-116869: Add test_cext test: build a C extension to check if the Python C API emits C compiler warnings. Patch by Victor Stinner.

  • gh-116869: Make the C API compatible with -Werror=declaration-after-statement compiler flag again. Patch by Victor Stinner.

  • gh-116936: Add PyType_GetModuleByDef() to the limited C API. Patch by Victor Stinner.

  • gh-116809: Restore removed private _PyErr_ChainExceptions1() function. Patch by Victor Stinner.

  • gh-115754: In the limited C API version 3.13, getting Py_None, Py_False, Py_True, Py_Ellipsis and Py_NotImplemented singletons is now implemented as function calls at the stable ABI level to hide implementation details. Getting these constants still return borrowed references. Patch by Victor Stinner.

  • gh-115754: Add Py_GetConstant() and Py_GetConstantBorrowed() functions to get constants. For example, Py_GetConstant(Py_CONSTANT_ZERO) returns a strong reference to the constant zero. Patch by Victor Stinner.

  • gh-111696: Add support for %T, %T#, %N and %N# formats to PyUnicode_FromFormat(): format the fully qualified name of an object type and of a type: call PyType_GetModuleName(). See PEP 737 for more information. Patch by Victor Stinner.

  • gh-111696: Add PyType_GetModuleName() function to get the type’s module name. Equivalent to getting the type.__module__ attribute. Patch by Eric Snow and Victor Stinner.

  • gh-111696: Add PyType_GetFullyQualifiedName() function to get the type’s fully qualified name. Equivalent to f"{type.__module__}.{type.__qualname__}", or type.__qualname__ if type.__module__ is not a string or is equal to "builtins". Patch by Victor Stinner.

  • gh-85283: The fcntl, grp, pwd, termios, _statistics and _testconsole C extensions are now built with the limited C API. Patch by Victor Stinner.

  • gh-111140: Add additional flags to PyLong_AsNativeBytes() and PyLong_FromNativeBytes() to allow the caller to determine how to handle edge cases around values that fill the entire buffer.

  • gh-113024: Add PyObject_GenericHash() function.

Python 3.13.0 alpha 5

Release date: 2024-03-12

Security

Core and Builtins

  • gh-116604: Respect the status of the garbage collector when indirect calls are made via PyErr_CheckSignals() and the evaluation breaker. Patch by Pablo Galindo

  • gh-112087: list is now compatible with the implementation of PEP 703.

  • gh-116381: Add specialization for CONTAINS_OP.

  • gh-116296: Fix possible refleak in object.__reduce__() internal error handling.

  • gh-115823: Properly calculate error ranges in the parser when raising SyntaxError exceptions caused by invalid byte sequences. Patch by Pablo Galindo

  • gh-115778: Add tierN annotation for instruction definition in interpreter DSL.

  • gh-115733: Fix crash when calling next() on exhausted list iterators.

  • gh-115700: The regen-cases build stage now works on Windows.

  • gh-115347: Fix bug where docstring was replaced by a redundant NOP when Python is run with -OO.

  • gh-115323: Make error message more meaningful for when bytearray.extend() is called with a str object.

  • gh-112175: Every PyThreadState now has its own eval_breaker, allowing specific threads to be interrupted.

Library

Core and Builtins

Library

  • gh-104090: The multiprocessing resource tracker now exits with non-zero status code if a resource leak was detected. It still exits with status code 0 otherwise.

Core and Builtins

  • gh-105858: Improve the constructors for ast nodes. Arguments of list types now default to an empty list if omitted, and optional fields default to None. AST nodes now have an __annotations__ attribute with the expected types of their attributes. Passing unrecognized extra arguments to AST nodes is deprecated and will become an error in Python 3.15. Omitting a required argument to an AST node is deprecated and will become an error in Python 3.15. Patch by Jelle Zijlstra.

  • gh-101860: Expose __name__ attribute on property.

  • gh-96497: Fix incorrect resolution of mangled class variables used in assignment expressions in comprehensions.

Library

  • gh-116600: Fix repr() for global Flag members.

  • gh-116349: platform.java_ver() is deprecated and will be removed in 3.15. It was largely untested, had a confusing API, and was only useful for Jython support.

  • gh-116143: Fix a race in pydoc _start_server, eliminating a window in which _start_server can return a thread that is “serving” but without a docserver set.

  • gh-116127: typing: implement PEP 705 which adds typing.ReadOnly support to typing.TypedDict.

  • gh-116325: typing: raise SyntaxError instead of AttributeError on forward references as empty strings.

  • gh-115957: When asyncio.TaskGroup.create_task is called on an inactive asyncio.TaskGroup, the given coroutine will be closed (which prevents a RuntimeWarning).

  • gh-115978: Disable preadv(), readv(), pwritev(), and writev() on WASI.

    Under wasmtime for WASI 0.2, these functions don’t pass test_posix (https://github.com/bytecodealliance/wasmtime/issues/7830).

  • gh-88352: Fix the computation of the next rollover time in the logging.TimedRotatingFileHandler handler. computeRollover() now always returns a timestamp larger than the specified time and works correctly during the DST change. doRollover() no longer overwrite the already rolled over file, saving from data loss when run at midnight or during repeated time at the DST change.

  • gh-87115: Set __main__.__spec__ to None when running a script with pdb

  • gh-76511: Fix UnicodeEncodeError in email.Message.as_string() that results when a message that claims to be in the ascii character set actually has non-ascii characters. Non-ascii characters are now replaced with the U+FFFD replacement character, like in the replace error handler.

  • gh-89547: Add support for nested typing special forms like Final[ClassVar[int]].

  • gh-65824: Improve the less prompt in pydoc.

  • gh-116040: [Enum] fix by-value calls when second value is falsey; e.g. Cardinal(1, 0)

  • gh-115821: [Enum] Improve error message when calling super().__new__() in custom __new__.

  • gh-85644: Use the XDG_CURRENT_DESKTOP environment variable in webbrowser to check desktop. Prefer it to the deprecated GNOME_DESKTOP_SESSION_ID for GNOME detection.

  • gh-75988: Fixed unittest.mock.create_autospec() to pass the call through to the wrapped object to return the real result.

  • gh-115881: Fix issue where ast.parse() would incorrectly flag conditional context managers (such as with (x() if y else z()): ...) as invalid syntax if feature_version=(3, 8) was passed. This reverts changes to the grammar made as part of gh-94949.

  • gh-115886: Fix silent truncation of the name with an embedded null character in multiprocessing.shared_memory.SharedMemory.

  • gh-115532: Add kernel density estimation to the statistics module.

  • gh-115714: On WASI, the time module no longer get process time using times() or CLOCK_PROCESS_CPUTIME_ID, system API is that is unreliable and is likely to be removed from WASI. The affected clock functions fall back to calling clock().

  • gh-115809: Improve algorithm for computing which rolled-over log files to delete in logging.TimedRotatingFileHandler. It is now reliable for handlers without namer and with arbitrary deterministic namer that leaves the datetime part in the file name unmodified.

  • gh-74668: urllib.parse functions parse_qs() and parse_qsl() now support bytes arguments containing raw and percent-encoded non-ASCII data.

  • gh-67044: csv.writer() now always quotes or escapes '\r' and '\n', regardless of lineterminator value.

  • gh-115712: Restore support of space delimiter with skipinitialspace=True in csv. csv.writer() now quotes empty fields if delimiter is a space and skipinitialspace is true and raises exception if quoting is not possible.

  • gh-112364: Fixed ast.unparse() to handle format_spec with ", ' or \\. Patched by Frank Hoffmann.

  • gh-112997: Stop logging potentially sensitive callback arguments in asyncio unless debug mode is active.

  • gh-114914: Fix an issue where an abandoned StreamWriter would not be garbage collected.

  • gh-111358: Fix a bug in asyncio.BaseEventLoop.shutdown_default_executor() to ensure the timeout passed to the coroutine behaves as expected.

  • gh-115618: Fix improper decreasing the reference count for None argument in property methods getter(), setter() and deleter().

  • gh-112720: Refactor dis.ArgResolver to make it possible to subclass and change the way jump args are interpreted.

  • gh-112006: Fix inspect.unwrap() for types with the __wrapper__ data descriptor. Fix inspect.Signature.from_callable() for builtins classmethod() and staticmethod().

  • gh-101293: Support callables with the __call__() method and types with __new__() and __init__() methods set to class methods, static methods, bound methods, partial functions, and other types of methods and descriptors in inspect.Signature.from_callable().

  • gh-103092: Isolate _lsprof (apply PEP 687).

  • gh-113942: pydoc no longer skips global functions implemented as builtin methods, such as MethodDescriptorType and WrapperDescriptorType.

  • gh-115256: Added DeprecationWarning when accessing the tarfile attribute of TarInfo objects. The attribute is never used internally and is only attached to TarInfos when the tarfile is opened in write-mode, not read-mode. The attribute creates an unnecessary reference cycle which may cause corruption when not closing the handle after writing a tarfile.

  • gh-115197: urllib.request no longer resolves the hostname before checking it against the system’s proxy bypass list on macOS and Windows.

  • gh-113812: DatagramTransport.sendto() will now send zero-length datagrams if called with an empty bytes object. The transport flow control also now accounts for the datagram header when calculating the buffer size.

  • gh-114763: Protect modules loaded with importlib.util.LazyLoader from race conditions when multiple threads try to access attributes before the loading is complete.

  • gh-114709: posixpath.commonpath() now raises a ValueError exception when passed an empty iterable. Previously, IndexError was raised.

    posixpath.commonpath() now raises a TypeError exception when passed None. Previously, ValueError was raised.

  • gh-114610: Fix bug where pathlib.PurePath.with_stem() converted a non-empty path suffix to a stem when given an empty stem argument. It now raises ValueError, just like pathlib.PurePath.with_suffix() does when called on a path with an empty stem, given a non-empty suffix argument.

  • gh-107361: Add ssl.VERIFY_X509_PARTIAL_CHAIN and VERIFY_X509_STRICT to the default SSL context created with ssl.create_default_context().

  • gh-112281: Allow creating union of types for typing.Annotated with unhashable metadata.

  • gh-111775: Fix importlib.resources.simple.ResourceHandle.open() for text mode, added missed stream argument.

  • gh-90095: Make .pdbrc and -c work with any valid pdb commands.

  • gh-107625: Raise configparser.ParsingError from read() and read_file() methods of configparser.ConfigParser if a key without a corresponding value is continued (that is, followed by an indented line).

  • gh-107155: Fix incorrect output of help(x) where x is a lambda function, which has an __annotations__ dictionary attribute with a "return" key.

  • gh-57141: Add option for non-shallow comparisons to filecmp.dircmp like filecmp.cmp(). Original patch by Steven Ward. Enhanced by Tobias Rautenkranz

  • gh-69990: Profile.print_stats() has been improved to accept multiple sort arguments. Patched by Chiu-Hsiang Hsu and Furkan Onder.

  • gh-104061: Add socket.SO_BINDTOIFINDEX constant.

  • gh-60346: Fix ArgumentParser inconsistent with parse_known_args.

  • gh-102389: Add windows_31j to aliases for cp932 codec

  • gh-72249: Always include the module name in the repr() of functools.partial() objects. Patch by Furkan Onder and Anilyka Barry.

  • gh-100985: Update HTTPSConnection to consistently wrap IPv6 Addresses when using a proxy.

  • gh-100884: email: fix misfolding of comma in address-lists over multiple lines in combination with unicode encoding.

  • gh-95782: Fix io.BufferedReader.tell(), io.BufferedReader.seek(), _pyio.BufferedReader.tell(), io.BufferedRandom.tell(), io.BufferedRandom.seek() and _pyio.BufferedRandom.tell() being able to return negative offsets.

  • gh-96310: Fix a traceback in argparse when all options in a mutually exclusive group are suppressed.

  • gh-93205: Fixed a bug in logging.handlers.TimedRotatingFileHandler where multiple rotating handler instances pointing to files with the same name but different extensions would conflict and not delete the correct files.

  • bpo-31116: Add Z85 encoding to base64.

  • bpo-44865: Add missing call to localization function in argparse.

  • bpo-43952: Fix multiprocessing.connection.Listener.accept() to accept empty bytes as authkey. Not accepting empty bytes as key causes it to hang indefinitely.

  • bpo-42125: linecache: get module name from __spec__ if available. This allows getting source code for the __main__ module when a custom loader is used.

  • bpo-41122: Failing to pass arguments properly to functools.singledispatchmethod() now throws a TypeError instead of hitting an index out of bounds internally.

  • bpo-40818: The asyncio REPL now runs sys.__interactivehook__ on startup. The default implementation of sys.__interactivehook__ provides auto-completion to the asyncio REPL. Patch contributed by Rémi Lapeyre.

  • bpo-33775: Add ‘default’ and ‘version’ help text for localization in argparse.

Documentation

Tests

  • gh-71052: Add test exclusions to support running the test suite on Android.

  • gh-71052: Enable test_concurrent_futures on platforms that support threading but not multiprocessing.

  • gh-115796: Make ‘_testinternalcapi.assemble_code_object’ construct the exception table for the code object.

  • gh-115720: Leak tests (-R, --huntrleaks) now show a summary of the number of leaks found in each iteration.

  • gh-115122: Add --bisect option to regrtest test runner: run failed tests with test.bisect_cmd to identify failing tests. Patch by Victor Stinner.

  • gh-115596: Fix ProgramPriorityTests in test_os permanently changing the process priority.

  • gh-115556: On Windows, commas passed in arguments to Tools\buildbot\test.bat and PCbuild\\rt.bat are now properly handled.

  • gh-115420: Fix translation of exception handler targets by _testinternalcapi.optimize_cfg.

  • gh-115376: Fix segfault in _testinternalcapi.compiler_codegen on bad input.

Build

  • gh-116313: Get WASI builds to work under wasmtime 18 w/ WASI 0.2/preview2 primitives.

  • gh-71052: Change Android’s sys.platform from "linux" to "android".

  • gh-116117: Backport libb2’s PR #42 to fix compiling CPython on 32-bit Windows with clang-cl.

  • gh-71052: Fix several Android build issues

  • gh-114099: A testbed project was added to run the test suite on iOS.

  • gh-115350: Fix building ctypes module with -DWIN32_LEAN_AND_MEAN defined

  • gh-111225: Link extension modules against libpython on Android.

  • gh-115737: The install name for libPython is now correctly set for non-framework macOS builds.

  • gh-114099: Makefile targets were added to support compiling an iOS-compatible framework build.

Windows

  • gh-116012: Ensure the value of GetLastError() is preserved across GIL operations.

  • gh-115582: Building extensions intended for free-threaded builds of CPython now require compiling with /DPy_GIL_DISABLED manually when using a regular install. This is expected to change in future releases.

  • gh-115554: The installer now has more strict rules about updating the Python Launcher for Windows. In general, most users only have a single launcher installed and will see no difference. When multiple launchers have been installed, the option to install the launcher is disabled until all but one have been removed. Downgrading the launcher (which was never allowed) is now more obviously blocked.

  • gh-115543: Python Launcher for Windows can now detect Python 3.13 when installed from the Microsoft Store, and will install Python 3.12 by default when PYLAUNCHER_ALLOW_INSTALL is set.

macOS

  • gh-116145: Update macOS installer to Tcl/Tk 8.6.14.

IDLE

  • gh-88516: On macOS show a proxy icon in the title bar of editor windows to match platform behaviour.

Tools/Demos

  • gh-100176: Remove outdated Tools/{io,cc,string}bench

  • bpo-45101: Add consistency in usage message IO between 2 versions of python-config.

C API

  • gh-114626: Add again _PyCFunctionFastWithKeywords name, removed in Python 3.13 alpha 4 by mistake. Keep the old private _PyCFunctionFastWithKeywords name (Python 3.7) as an alias to the new public name PyCFunctionFastWithKeywords (Python 3.13a4). Patch by Victor Stinner.

  • gh-111418: Add PyHASH_MODULUS, PyHASH_BITS, PyHASH_INF and PyHASH_IMAG C macros. Patch by Sergey B Kirpichev.

Python 3.13.0 alpha 4

Release date: 2024-02-15

Security

Core and Builtins

  • gh-112087: For an empty reverse iterator for list will be reduced to reversed(). Patch by Donghee Na

  • gh-114570: Add PythonFinalizationError exception. This exception derived from RuntimeError is raised when an operation is blocked during the Python finalization. Patch by Victor Stinner.

  • gh-114695: Add sys._clear_internal_caches(), which clears all internal performance-related caches (and deprecate the less-general sys._clear_type_cache() function).

  • gh-114828: Fix compilation crashes in uncommon code examples using super() inside a comprehension in a class body.

  • gh-112069: Adapt set and frozenset methods to Argument Clinic.

  • gh-115011: Setters for members with an unsigned integer type now support the same range of valid values for objects that has a __index__() method as for int.

  • gh-114887: Changed socket type validation in create_datagram_endpoint() to accept all non-stream sockets. This fixes a regression in compatibility with raw sockets.

  • gh-114944: Fixes a race between PyParkingLot_Park and _PyParkingLot_UnparkAll.

  • gh-113462: Limit the number of versions that a single class can use. Prevents a few wayward classes using up all the version numbers.

  • gh-76763: The chr() builtin function now always raises ValueError for values outside the valid range. Previously it raised OverflowError for very large or small values.

  • gh-114806: No longer specialize calls to classes, if those classes have metaclasses. Fixes bug where the __call__ method of the metaclass was not being called.

  • gh-107944: Improve error message for function calls with bad keyword arguments via getargs

  • gh-112529: The free-threaded build no longer allocates space for the PyGC_Head structure in objects that support cyclic garbage collection. A number of other fields and data structures are used as replacements, including ob_gc_bits, ob_tid, and mimalloc internal data structures.

  • gh-114456: Lower the recursion limit under a debug build of WASI.

  • gh-114083: Compiler applies folding of LOAD_CONST with following instruction in a separate pass before other optimisations. This enables jump threading in certain circumstances.

  • gh-114388: Fix a RuntimeWarning emitted when assign an integer-like value that is not an instance of int to an attribute that corresponds to a C struct member of type T_UINT and T_ULONG. Fix a double RuntimeWarning emitted when assign a negative integer value to an attribute that corresponds to a C struct member of type T_UINT.

  • gh-114265: Compiler propagates line numbers before optimization, leading to more optimization opportunities and removing the need for the guarantee_lineno_for_exits hack.

  • gh-112529: The free-threaded build now has its own thread-safe GC implementation that uses mimalloc to find GC tracked objects. It is non-generational, unlike the existing GC implementation.

  • gh-114050: Fix segmentation fault caused by an incorrect format string in TypeError exception when more than two arguments are passed to int.

  • gh-112354: The END_FOR instruction now pops only one value. This is to better support side exits in loops.

  • gh-113884: Make queue.SimpleQueue thread safe when the GIL is disabled.

  • gh-114058: Implement the foundations of the Tier 2 redundancy eliminator.

  • gh-113939: frame.clear(): Clear frame.f_locals as well, and not only the fast locals. This is relevant once frame.f_locals was accessed, which would contain also references to all the locals.

  • gh-112050: Convert collections.deque to use Argument Clinic.

  • gh-112050: Make methods on collections.deque thread-safe when the GIL is disabled.

  • gh-113464: Add an option (--enable-experimental-jit for configure-based builds or --experimental-jit for PCbuild-based ones) to build an experimental just-in-time compiler, based on copy-and-patch

  • gh-113055: Make interp->obmalloc a pointer. For interpreters that share state with the main interpreter, this points to the same static memory structure. For interpreters with their own obmalloc state, it is heap allocated. Add free_obmalloc_arenas() which will free the obmalloc arenas and radix tree structures for interpreters with their own obmalloc state.

  • gh-55664: Add warning when creating type using a namespace dictionary with non-string keys. Patched by Daniel Urban and Furkan Onder.

  • gh-104530: Use native Win32 condition variables.

Library

  • gh-115392: Fix a bug in doctest where incorrect line numbers would be reported for decorated functions.

  • gh-114563: Fix several format() bugs when using the C implementation of Decimal: * memory leak in some rare cases when using the z format option (coerce negative 0) * incorrect output when applying the z format option to type F (fixed-point with capital NAN / INF) * incorrect output when applying the # format option (alternate form)

  • gh-102840: Fix confused traceback when floordiv, mod, or divmod operations happens between instances of fractions.Fraction and complex.

  • gh-115165: Most exceptions are now ignored when attempting to set the __orig_class__ attribute on objects returned when calling typing generic aliases (including generic aliases created using typing.Annotated). Previously only AttributeError was ignored. Patch by Dave Shawley.

  • gh-112903: Fix “issubclass() arg 1 must be a class” errors in certain cases of multiple inheritance with generic aliases (regression in early 3.13 alpha releases).

  • gh-115133: Fix tests for XMLPullParser with Expat 2.6.0.

  • gh-115059: io.BufferedRandom.read1() now flushes the underlying write buffer.

  • gh-79382: Trailing ** no longer allows to match files and non-existing paths in recursive glob().

  • gh-67837: Avoid race conditions in the creation of directories during concurrent extraction in tarfile and zipfile.

  • gh-115060: Speed up pathlib.Path.glob() by removing redundant regex matching.

  • gh-97928: Partially revert the behavior of tkinter.Text.count(). By default it preserves the behavior of older Python versions, except that setting wantobjects to 0 no longer has effect. Add a new parameter return_ints: specifying return_ints=True makes Text.count() always returning the single count as an integer instead of a 1-tuple or None.

  • gh-114628: When csv.Error is raised when handling TypeError, do not print the TypeError traceback.

  • gh-85984: Added _POSIX_VDISABLE from C’s <unistd.h> to termios.

  • gh-114965: Update bundled pip to 24.0

  • gh-114959: tarfile no longer ignores errors when trying to extract a directory on top of a file.

  • gh-114894: Add array.array.clear().

  • gh-114071: Support tuple subclasses using auto() for enum member value.

  • gh-109475: Fix support of explicit option value “–” in argparse (e.g. --option=--).

  • gh-49766: Fix date-datetime comparison. Now the special comparison methods like __eq__ and __lt__ return NotImplemented if one of comparands is date and other is datetime instead of ignoring the time part and the time zone or forcefully return “not equal” or raise TypeError. It makes comparison of date and datetime subclasses more symmetric and allows to change the default behavior by overriding the special comparison methods in subclasses.

  • gh-110190: Fix ctypes structs with array on Windows ARM64 platform by setting MAX_STRUCT_SIZE to 32 in stgdict. Patch by Diego Russo

  • gh-114678: Ensure that deprecation warning for ‘N’ specifier in Decimal format is not raised for cases where ‘N’ appears in other places in the format specifier. Based on patch by Stefan Krah.

  • gh-70303: Return both files and directories from pathlib.Path.glob() if a pattern ends with “**”. Previously only directories were returned.

  • gh-109653: Improve import time of importlib.metadata and email.utils.

  • gh-113280: Fix a leak of open socket in rare cases when error occurred in ssl.SSLSocket creation.

  • gh-77749: email.policy.EmailPolicy.fold() now always encodes non-ASCII characters in headers if utf8 is false.

  • gh-83383: Synchronization of the dbm.dumb database is now no-op if there was no modification since opening or last synchronization. The directory file for a newly created empty dbm.dumb database is now created immediately after opening instead of deferring this until synchronizing or closing.

  • gh-91602: Add filter keyword-only parameter to sqlite3.Connection.iterdump() for filtering database objects to dump. Patch by Mariusz Felisiak.

  • gh-112451: Prohibit subclassing pure-Python datetime.timezone. This is consistent with C-extension implementation. Patch by Mariusz Felisiak.

  • gh-69893: Add the close() method for the iterator returned by xml.etree.ElementTree.iterparse().

  • gh-109653: Reduce the import time of threading module by ~50%. Patch by Daniel Hollas.

  • gh-114492: Make the result of termios.tcgetattr() reproducible on Alpine Linux. Previously it could leave a random garbage in some fields.

  • gh-114315: Make threading.Lock a real class, not a factory function. Add __new__ to _thread.lock type.

  • gh-100414: Add dbm.sqlite3 as a backend to dbm, and make it the new default dbm backend. Patch by Raymond Hettinger and Erlend E. Aasland.

  • gh-113267: Revert changes in gh-106584 which made calls of TestResult methods startTest() and stopTest() unbalanced.

  • gh-75128: Ignore an OSError in asyncio.BaseEventLoop.create_server() when IPv6 is available but the interface cannot actually support it.

  • gh-114423: _DummyThread entries in threading._active are now automatically removed when the related thread dies.

  • gh-114257: Dismiss the FileNotFound error in ctypes.util.find_library() and just return None on Linux.

  • gh-114321: Expose more platform specific constants in the fcntl module on Linux, macOS, FreeBSD and NetBSD.

  • gh-114328: The tty.setcbreak() and new tty.cfmakecbreak() no longer clears the terminal input ICRLF flag. This fixes a regression introduced in 3.12 that no longer matched how OSes define cbreak mode in their stty(1) manual pages.

  • gh-114281: Remove type hints from Lib/asyncio/staggered.py. The annotations in the typeshed project should be used instead.

  • gh-101438: Avoid reference cycle in ElementTree.iterparse. The iterator returned by ElementTree.iterparse may hold on to a file descriptor. The reference cycle prevented prompt clean-up of the file descriptor if the returned iterator was not exhausted.

  • gh-114198: The signature for the __replace__ method on dataclasses now has the first argument named self, rather than obj.

  • gh-104522: OSError raised when run a subprocess now only has filename attribute set to cwd if the error was caused by a failed attempt to change the current directory.

  • gh-114149: Enum: correctly handle tuple subclasses in custom __new__.

  • gh-83648: Support deprecation of options, positional arguments and subcommands in argparse.

  • gh-114087: Speed up dataclasses.asdict up to 1.35x.

  • gh-109534: Fix a reference leak in asyncio.selector_events.BaseSelectorEventLoop when SSL handshakes fail. Patch contributed by Jamie Phan.

  • gh-79634: Accept path-like objects as patterns in pathlib.Path.glob() and rglob().

  • gh-112202: Ensure that a asyncio.Condition.notify() call does not get lost if the awakened Task is simultaneously cancelled or encounters any other error.

  • gh-113951: Fix the behavior of tag_unbind() methods of tkinter.Text and tkinter.Canvas classes with three arguments. Previously, widget.tag_unbind(tag, sequence, funcid) destroyed the current binding for sequence, leaving sequence unbound, and deleted the funcid command. Now it removes only funcid from the binding for sequence, keeping other commands, and deletes the funcid command. It leaves sequence unbound only if funcid was the last bound command.

  • gh-97959: Fix rendering class methods, bound methods, method and function aliases in pydoc. Class methods no longer have “method of builtins.type instance” note. Corresponding notes are now added for class and unbound methods. Method and function aliases now have references to the module or the class where the origin was defined if it differs from the current. Bound methods are now listed in the static methods section. Methods of builtin classes are now supported as well as methods of Python classes.

  • gh-113796: Add more validation checks in the csv.Dialect constructor. ValueError is now raised if the same character is used in different roles.

  • gh-113732: Fix support of QUOTE_NOTNULL and QUOTE_STRINGS in csv.reader().

  • gh-113225: Speed up pathlib.Path.walk() by using os.DirEntry.path where possible.

  • gh-89039: When replace() method is called on a subclass of datetime, date or time, properly call derived constructor. Previously, only the base class’s constructor was called.

    Also, make sure to pass non-zero fold values when creating subclasses in various methods. Previously, fold was silently ignored.

  • gh-112919: Speed-up datetime.datetime.replace(), datetime.date.replace() and datetime.time.replace().

  • gh-59013: Set breakpoint on the first executable line of the function, instead of the line of function definition when the user do break func using pdb

  • gh-112343: Improve handling of pdb convenience variables to avoid replacing string contents.

  • gh-112240: Add option to calendar module CLI to specify the weekday to start each week. Patch by Steven Ward.

  • gh-111741: Recognise image/webp as a standard format in the mimetypes module.

  • gh-43457: Fix the tkinter widget method wm_attributes(). It now accepts the attribute name without the minus prefix to get window attributes and allows to specify attributes and values to set as keyword arguments. Add new optional keyword argument return_python_dict: calling w.wm_attributes(return_python_dict=True) returns the attributes as a dict instead of a tuple. Calling w.wm_attributes() now returns a tuple instead of string if wantobjects was set to 0.

  • gh-82626: Many functions now emit a warning if a boolean value is passed as a file descriptor argument.

  • gh-111051: Added check for file modification during debugging with pdb

  • gh-110345: Show the Tcl/Tk patchlevel (rather than version) in tkinter._test().

  • gh-38807: Fix race condition in trace. Instead of checking if a directory exists and creating it, directly call os.makedirs() with the kwarg exist_ok=True.

  • gh-75705: Set unixfrom envelope in mailbox.mbox and mailbox.MMDF.

  • gh-106233: Fix stacklevel in InvalidTZPathWarning during zoneinfo module import.

  • gh-105102: Allow ctypes.Union to be nested in ctypes.Structure when the system endianness is the opposite of the classes.

  • gh-104282: Fix null pointer dereference in lzma._decode_filter_properties() due to improper handling of BCJ filters with properties of zero length. Patch by Radislav Chugunov.

  • gh-96471: Add queue.Queue termination with shutdown().

  • gh-101599: Changed argparse flag options formatting to remove redundancy.

  • gh-85984: Add POSIX pseudo-terminal functions os.posix_openpt(), os.grantpt(), os.unlockpt(), and os.ptsname().

  • gh-102512: When os.fork() is called from a foreign thread (aka _DummyThread), the type of the thread in a child process is changed to _MainThread. Also changed its name and daemonic status, it can be now joined.

  • gh-88569: Add os.path.isreserved(), which identifies reserved pathnames such as “NUL”, “AUX” and “CON”. This function is only available on Windows.

    Deprecate pathlib.PurePath.is_reserved().

  • bpo-38364: The inspect functions isgeneratorfunction, iscoroutinefunction, isasyncgenfunction now support functools.partialmethod wrapped functions the same way they support functools.partial.

Documentation

  • gh-115233: Fix an example for LoggerAdapter in the Logging Cookbook.

  • gh-114123: Move the csv module docstring to the csv module instead of reexporting it from the internal _csv module, and remove __doc__ from csv.__all__.

    Move csv.__version__ to the csv module instead of reexporting it from the internal _csv module, and remove __version__ from csv.__all__.

Tests

  • gh-114099: Added test exclusions required to run the test suite on iOS.

  • gh-105089: Fix test.test_zipfile.test_core.TestWithDirectory.test_create_directory_with_write test in AIX by doing a bitwise AND of 0xFFFF on mode , so that it will be in sync with zinfo.external_attr

Build

  • gh-115167: Avoid vendoring vcruntime140_threads.dll when building with Visual Studio 2022 version 17.8.

  • gh-113632: Promote WASI to a tier 2 platform and drop Emscripten from tier 3 in configure.ac.

  • gh-114099: configure and Makefile were refactored to accommodate framework builds on Apple platforms other than macOS.

  • gh-114875: Add getgrent() as a prerequisite for building the grp module.

Windows

  • gh-115049: Fixes py.exe launcher failing when run as users without user profiles.

  • gh-115009: Update Windows installer to use SQLite 3.45.1.

  • gh-109991: Update Windows build to use OpenSSL 3.0.13.

  • gh-111239: Update Windows builds to use zlib v1.3.1.

  • gh-100107: The py.exe launcher will no longer attempt to run the Microsoft Store redirector when launching a script containing a /usr/bin/env shebang

  • gh-112984: Adds free-threaded binaries to Windows installer as an optional component.

  • gh-89240: Allows multiprocessing to create pools of greater than 62 processes.

macOS

  • gh-115009: Update macOS installer to use SQLite 3.45.1.

  • gh-109991: Update macOS installer to use OpenSSL 3.0.13.

  • gh-114490: Add Mach-O linkage support for platform.architecture().

  • gh-87804: On macOS the result of os.statvfs and os.fstatvfs now correctly report the size of very large disks, in previous versions the reported number of blocks was wrong for disks with at least 2**32 blocks.

IDLE

  • gh-96905: In idlelib code, stop redefining built-ins ‘dict’ and ‘object’.

  • gh-103820: Revise IDLE bindings so that events from mouse button 4/5 on non-X11 windowing systems (i.e. Win32 and Aqua) are not mistaken for scrolling.

Tools/Demos

  • gh-113516: Don’t set LDSHARED when building for WASI.

  • gh-109991: Update GitHub CI workflows to use OpenSSL 3.0.13 and multissltests to use 1.1.1w, 3.0.13, 3.1.5, and 3.2.1.

  • gh-115015: Fix a bug in Argument Clinic that generated incorrect code for methods with no parameters that use the METH_METHOD | METH_FASTCALL | METH_KEYWORDS calling convention. Only the positional parameter count was checked; any keyword argument passed would be silently accepted.

C API

Python 3.13.0 alpha 3

Release date: 2024-01-17

Security

  • gh-113659: Skip .pth files with names starting with a dot or hidden file attribute.

  • gh-112302: Created a Software Bill-of-Materials document and tooling for tracking dependencies.

Core and Builtins

  • gh-107901: Compiler duplicates basic blocks that have an eval breaker check, no line number, and multiple predecessors.

  • gh-107901: A jump leaving an exception handler back to normal code no longer checks the eval breaker.

  • gh-113655: Set the C recursion limit to 4000 on Windows, and 10000 on Linux/OSX. This seems to be near the sweet spot to maintain safety, but not compromise backwards compatibility.

  • gh-113710: Add typed stack effects to the interpreter DSL, along with various instruction annotations.

  • gh-77046: On Windows, file descriptors wrapping Windows handles are now created non inheritable by default (PEP 446). Patch by Zackery Spytz and Victor Stinner.

  • gh-113853: Guarantee that all executors make progress. This then guarantees that tier 2 execution always makes progress.

  • gh-113753: Fix an issue where the finalizer of PyAsyncGenASend objects might not be called if they were allocated from a free list.

  • gh-107901: Compiler changed so that synthetic jumps which are not at loop end no longer check the eval breaker.

  • gh-113703: Fix a regression in the codeop module that was causing it to incorrectly identify incomplete f-strings. Patch by Pablo Galindo

  • gh-89811: Check for a valid tp_version_tag before performing bytecode specializations that rely on this value being usable.

  • gh-111488: Changed error message in case of no ‘in’ keyword after ‘for’ in list comprehensions

  • gh-113657: Fix an issue that caused important instruction pointer updates to be optimized out of tier two traces.

  • gh-113603: Fixed bug where a redundant NOP is not removed, causing an assertion to fail in the compiler in debug mode.

  • gh-113602: Fix an error that was causing the parser to try to overwrite existing errors and crashing in the process. Patch by Pablo Galindo

  • gh-113486: No longer issue spurious PY_UNWIND events for optimized calls to classes.

  • gh-113297: Fix segfault in the compiler on with statement with 19 context managers.

  • gh-113212: Improve super error messages.

  • gh-111375: Only use NULL in the exception stack to indicate an exception was handled. Patch by Carey Metcalfe.

  • gh-112215: Increase the C recursion limit by a factor of 3 for non-debug builds, except for webassembly and s390 platforms which are unchanged. This mitigates some regressions in 3.12 with deep recursion mixing builtin (C) and Python code.

  • gh-113054: Fixed bug where a redundant NOP is not removed, causing an assertion to fail in the compiler in debug mode.

  • gh-106905: Use per AST-parser state rather than global state to track recursion depth within the AST parser to prevent potential race condition due to simultaneous parsing.

    The issue primarily showed up in 3.11 by multithreaded users of ast.parse(). In 3.12 a change to when garbage collection can be triggered prevented the race condition from occurring.

  • gh-108866: Change the API and contract of _PyExecutorObject to return the next_instr pointer, instead of the frame, and to always execute at least one instruction.

  • gh-90350: Optimize builtin functions min() and max().

  • gh-112943: Correctly compute end column offsets for multiline tokens in the tokenize module. Patch by Pablo Galindo

  • gh-112125: Fix None.__ne__(None) returning NotImplemented instead of False.

  • gh-74616: input() now raises a ValueError when output on the terminal if the prompt contains embedded null characters instead of silently truncating it.

  • gh-112716: Fix SystemError in the import statement and in __reduce__() methods of builtin types when __builtins__ is not a dict.

  • gh-112730: Use color to highlight error locations in tracebacks. Patch by Pablo Galindo

  • gh-112625: Fixes a bug where a bytearray object could be cleared while iterating over an argument in the bytearray.join() method that could result in reading memory after it was freed.

  • gh-112660: Do not clear unexpected errors during formatting error messages for ImportError and AttributeError for modules.

  • gh-105967: Workaround a bug in Apple’s macOS platform zlib library where zlib.crc32() and binascii.crc32() could produce incorrect results on multi-gigabyte inputs. Including when using zipfile on zips containing large data.

  • gh-95754: Provide a better error message when accessing invalid attributes on partially initialized modules. The origin of the module being accessed is now included in the message to help with the common issue of shadowing other modules.

  • gh-112217: Add check for the type of __cause__ returned from calling the type T in raise from T.

  • gh-111058: Change coro.cr_frame/gen.gi_frame to return None after the coroutine/generator has been closed. This fixes a bug where getcoroutinestate() and getgeneratorstate() return the wrong state for a closed coroutine/generator.

  • gh-112388: Fix an error that was causing the parser to try to overwrite tokenizer errors. Patch by pablo Galindo

  • gh-112387: Fix error positions for decoded strings with backwards tokenize errors. Patch by Pablo Galindo

  • gh-99606: Make code generated for an empty f-string identical to the code of an empty normal string.

  • gh-112367: Avoid undefined behaviour when using the perf trampolines by not freeing the code arenas until shutdown. Patch by Pablo Galindo

  • gh-112320: The Tier 2 translator now tracks the confidence level for staying “on trace” (i.e. not exiting back to the Tier 1 interpreter) for branch instructions based on the number of bits set in the branch “counter”. Trace translation ends when the confidence drops below 1/3rd.

  • gh-109598: PyComplex_RealAsDouble()/PyComplex_ImagAsDouble() now tries to convert an object to a complex instance using its __complex__() method before falling back to the __float__() method. Patch by Sergey B Kirpichev.

  • gh-94606: Fix UnicodeEncodeError when email.message.get_payload() reads a message with a Unicode surrogate character and the message content is not well-formed for surrogateescape encoding. Patch by Sidney Markowitz.

  • bpo-21861: Use the object’s actual class name in _io.FileIO.__repr__(), _io._WindowsConsoleIO() and _io.TextIOWrapper.__repr__(), to make these methods subclass friendly.

  • bpo-45369: Remove LibreSSL workarounds as per PEP 644.

  • bpo-34392: Added sys._is_interned().

Library

  • gh-114077: Fix possible OverflowError in socket.socket.sendfile() when pass count larger than 2 GiB on 32-bit platform.

  • gh-111803: plistlib now supports loading more deeply nested lists in binary format.

  • gh-114014: Fixed a bug in fractions.Fraction where an invalid string using d in the decimals part creates a different error compared to other invalid letters/characters. Patch by Jeremiah Gabriel Pascual.

  • gh-108364: sqlite3.Connection.iterdump() now ensures that foreign key support is disabled before dumping the database schema, if there is any foreign key violation. Patch by Erlend E. Aasland and Mariusz Felisiak.

  • gh-113971: The zipfile.ZipInfo previously protected ._compresslevel attribute has been made public as .compress_level with the old _compresslevel name remaining available as a property to retain compatibility.

  • gh-113877: Fix tkinter method winfo_pathname() on 64-bit Windows.

  • gh-113868: Added mmap.MAP_NORESERVE, mmap.MAP_NOEXTEND, mmap.MAP_HASSEMAPHORE, mmap.MAP_NOCACHE, mmap.MAP_JIT, mmap.MAP_RESILIENT_CODESIGN, mmap.MAP_RESILIENT_MEDIA, mmap.MAP_32BIT, mmap.MAP_TRANSLATED_ALLOW_EXECUTE, mmap.MAP_UNIX03 and mmap.MAP_TPRO. All of them are mmap(2) flags on macOS.

  • gh-113848: asyncio.TaskGroup() and asyncio.timeout() context managers now handle CancelledError subclasses as well as exact CancelledError.

  • gh-113661: unittest runner: Don’t exit 5 if tests were skipped. The intention of exiting 5 was to detect issues where the test suite wasn’t discovered at all. If we skipped tests, it was correctly discovered.

  • gh-96037: Insert TimeoutError in the context of the exception that was raised during exiting an expired asyncio.timeout() block.

  • gh-113781: Silence unraisable AttributeError when warnings are emitted during Python finalization.

  • gh-113238: Add Anchor to importlib.resources (in order for the code to comply with the documentation)

  • gh-111693: asyncio.Condition.wait() now re-raises the same CancelledError instance that may have caused it to be interrupted. Fixed race condition in asyncio.Semaphore.acquire() when interrupted with a CancelledError.

  • gh-113791: Add CLOCK_MONOTONIC_RAW_APPROX and CLOCK_UPTIME_RAW_APPROX to time on macOS. These are clocks available on macOS 10.12 or later.

  • gh-112932: Restore the ability for zipfile to extractall from zip files with a “/” directory entry in them as is commonly added to zips by some wiki or bug tracker data exporters.

  • gh-113568: Raise deprecation warnings from pathlib.PurePath and not its private base class PurePathBase.

  • gh-113594: Fix UnicodeEncodeError in email when re-fold lines that contain unknown-8bit encoded part followed by non-unknown-8bit encoded part.

  • gh-113538: In asyncio.StreamReaderProtocol.connection_made(), there is callback that logs an error if the task wrapping the “connected callback” fails. This callback would itself fail if the task was cancelled. Prevent this by checking whether the task was cancelled first. If so, close the transport but don’t log an error.

  • gh-113626: Add support for the allow_code argument in the marshal module. Passing allow_code=False prevents serialization and de-serialization of code objects which is incompatible between Python versions.

  • gh-85567: Fix resource warnings for unclosed files in pickle and pickletools command line interfaces.

  • gh-113537: Support loads str in plistlib.loads().

  • gh-89850: Add default implementations of pickle.Pickler.persistent_id() and pickle.Unpickler.persistent_load() methods in the C implementation. Calling super().persistent_id() and super().persistent_load() in subclasses of the C implementation of pickle.Pickler and pickle.Unpickler classes no longer causes infinite recursion.

  • gh-113569: Indicate if there were no actual calls in unittest assert_has_calls() failure.

  • gh-101225: Increase the backlog for multiprocessing.connection.Listener objects created by multiprocessing.manager and multiprocessing.resource_sharer to significantly reduce the risk of getting a connection refused error when creating a multiprocessing.connection.Connection to them.

  • gh-113568: Raise audit events from pathlib.Path and not its private base class PathBase.

  • gh-113543: Make sure that webbrowser.MacOSXOSAScript sends webbrowser.open audit event.

  • gh-113028: When a second reference to a string appears in the input to pickle, and the Python implementation is in use, we are guaranteed that a single copy gets pickled and a single object is shared when reloaded. Previously, in protocol 0, when a string contained certain characters (e.g. newline) it resulted in duplicate objects.

  • gh-113421: Fix multiprocessing logger for %(filename)s.

  • gh-111784: Fix segfaults in the _elementtree module. Fix first segfault during deallocation of _elementtree.XMLParser instances by keeping strong reference to pyexpat module in module state for capsule lifetime. Fix second segfault which happens in the same deallocation process by keeping strong reference to _elementtree module in XMLParser structure for _elementtree module lifetime.

  • gh-113407: Fix import of unittest.mock when CPython is built without docstrings.

  • gh-113320: Fix regression in Python 3.12 where Protocol classes that were not marked as runtime-checkable would be unnecessarily introspected, potentially causing exceptions to be raised if the protocol had problematic members. Patch by Alex Waygood.

  • gh-53502: Add a new option aware_datetime in plistlib to loads or dumps aware datetime.

  • gh-113358: Fix rendering tracebacks with exceptions with a broken __getattr__

  • gh-113214: Fix an AttributeError during asyncio SSL protocol aborts in SSL-over-SSL scenarios.

  • gh-113246: Update bundled pip to 23.3.2.

  • gh-87264: Fixed tarfile list() method to show file type.

  • gh-112182: asyncio.futures.Future.set_exception() now transforms StopIteration into RuntimeError instead of hanging or other misbehavior. Patch contributed by Jamie Phan.

  • gh-113225: Speed up pathlib.Path.glob() by using os.DirEntry.path where possible.

  • gh-113149: Improve error message when a JSON array or object contains a trailing comma. Patch by Carson Radtke.

  • gh-113117: The subprocess module can now use the os.posix_spawn() function with close_fds=True on platforms where posix_spawn_file_actions_addclosefrom_np is available. Patch by Jakub Kulik.

  • gh-113199: Make http.client.HTTPResponse.read1 and http.client.HTTPResponse.readline close IO after reading all data when content length is known. Patch by Illia Volochii.

  • gh-113191: Add support of os.fchmod() and a file descriptor in os.chmod() on Windows.

  • gh-113188: Fix shutil.copymode() and shutil.copystat() on Windows. Previously they worked differently if dst is a symbolic link: they modified the permission bits of dst itself rather than the file it points to if follow_symlinks is true or src is not a symbolic link, and did not modify the permission bits if follow_symlinks is false and src is a symbolic link.

  • gh-113119: os.posix_spawn() now accepts env=None, which makes the newly spawned process use the current process environment. Patch by Jakub Kulik.

  • gh-113202: Add a strict option to batched() in the itertools module.

  • gh-61648: Detect line numbers of properties in doctests.

  • gh-113175: Sync with importlib_metadata 7.0, including improved type annotations, fixed issue with symlinked packages in package_distributions, added EntryPoints.__repr__, introduced the diagnose script, added Distribution.origin property, and removed deprecated EntryPoint access by numeric index (tuple behavior).

  • gh-59616: Add support of os.lchmod() and the follow_symlinks argument in os.chmod() on Windows. Note that the default value of follow_symlinks in os.lchmod() is False on Windows.

  • gh-112559: signal.signal() and signal.getsignal() no longer call repr on callable handlers. asyncio.run() and asyncio.Runner.run() no longer call repr on the task results. Patch by Yilei Yang.

  • gh-112962: dis module functions add cache information to the Instruction instance rather than creating fake Instruction instances to represent the cache entries.

  • gh-112989: Reduce overhead to connect sockets with asyncio SelectorEventLoop.

  • gh-112970: Use closefrom() on Linux where available (e.g. glibc-2.34), rather than only FreeBSD.

  • gh-110190: Fix ctypes structs with array on PPC64LE platform by setting MAX_STRUCT_SIZE to 64 in stgdict. Patch by Diego Russo.

  • gh-112540: The statistics.geometric_mean() function now returns zero for datasets containing a zero. Formerly, it would raise an exception.

  • gh-87286: Added LOG_FTP, LOG_NETINFO, LOG_REMOTEAUTH, LOG_INSTALL, LOG_RAS, and LOG_LAUNCHD tot the syslog module, all of them constants on used on macOS.

  • gh-112800: Fix asyncio SubprocessTransport.close() not to throw PermissionError when used with setuid executables.

  • gh-51944: Add the following constants to the termios module. These values are present in macOS system headers: ALTWERASE, B14400, B28800, B7200, B76800, CCAR_OFLOW, CCTS_OFLOW, CDSR_OFLOW, CDTR_IFLOW, CIGNORE, CRTS_IFLOW, EXTPROC, IUTF8, MDMBUF, NL2, NL3, NOKERNINFO, ONOEOT, OXTABS, VDSUSP, VSTATUS.

  • gh-79325: Fix an infinite recursion error in tempfile.TemporaryDirectory() cleanup on Windows.

  • gh-94692: shutil.rmtree() now only catches OSError exceptions. Previously a symlink attack resistant version of shutil.rmtree() could ignore or pass to the error handler arbitrary exception when invalid arguments were provided.

  • gh-112736: The use of del-safe symbols in subprocess was refactored to allow for use in cross-platform build environments.

  • gh-112727: Speed up pathlib.Path.absolute(). Patch by Barney Gale.

  • gh-74690: Speedup issubclass() checks against simple runtime-checkable protocols by around 6%. Patch by Alex Waygood.

  • gh-74690: Speedup isinstance() checks by roughly 20% for runtime-checkable protocols that only have one callable member. Speedup issubclass() checks for these protocols by roughly 10%. Patch by Alex Waygood.

  • gh-112645: Remove deprecation error on passing onerror to shutil.rmtree().

  • gh-112640: Add kwdefaults parameter to types.FunctionType to set default keyword argument values.

  • gh-112622: Ensure name parameter is passed to event loop in asyncio.create_task().

  • gh-112618: Fix a caching bug relating to typing.Annotated. Annotated[str, True] is no longer identical to Annotated[str, 1].

  • gh-112334: Fixed a performance regression in 3.12’s subprocess on Linux where it would no longer use the fast-path vfork() system call when it could have due to a logic bug, instead falling back to the safe but slower fork().

    Also fixed a second 3.12.0 potential security bug. If a value of extra_groups=[] was passed to subprocess.Popen or related APIs, the underlying setgroups(0, NULL) system call to clear the groups list would not be made in the child process prior to exec().

    This was identified via code inspection in the process of fixing the first bug.

  • gh-110190: Fix ctypes structs with array on Arm platform by setting MAX_STRUCT_SIZE to 32 in stgdict. Patch by Diego Russo.

  • gh-81194: Fix a crash in socket.if_indextoname() with specific value (UINT_MAX). Fix an integer overflow in socket.if_indextoname() on 64-bit non-Windows platforms.

  • gh-112578: Fix a spurious RuntimeWarning when executing the zipfile module.

  • gh-112516: Update the bundled copy of pip to version 23.3.1.

  • gh-112510: Add readline.backend for the backend readline uses (editline or readline)

  • gh-112328: [Enum] Make EnumDict, EnumDict.member_names, EnumType._add_alias_ and EnumType._add_value_alias_ public.

  • gh-112509: Fix edge cases that could cause a key to be present in both the __required_keys__ and __optional_keys__ attributes of a typing.TypedDict. Patch by Jelle Zijlstra.

  • gh-101336: Add keep_alive keyword parameter for AbstractEventLoop.create_server() and BaseEventLoop.create_server().

  • gh-63284: Added support for TLS-PSK (pre-shared key) mode to the ssl module.

  • gh-112414: Fix regression in Python 3.12 where calling repr() on a module that had been imported using a custom loader could fail with AttributeError. Patch by Alex Waygood.

  • gh-112358: Revert change to struct.Struct initialization that broke some cases of subclassing.

  • gh-112405: Optimize pathlib.PurePath.relative_to(). Patch by Alex Waygood.

  • gh-94722: Fix bug where comparison between instances of DocTest fails if one of them has None as its lineno.

  • gh-112361: Speed up a small handful of pathlib methods by removing some temporary objects.

  • gh-112345: Improve error message when trying to call issubclass() against a typing.Protocol that has non-method members. Patch by Randolf Scholz.

  • gh-112137: Change dis output to display no-lineno as “–” instead of “None”.

  • gh-112332: Deprecate the exc_type field of traceback.TracebackException. Add exc_type_str to replace it.

  • gh-81620: Add extra tests for random.binomialvariate()

  • gh-112292: Fix a crash in readline when imported from a sub interpreter. Patch by Anthony Shaw

  • gh-77621: Slightly improve the import time of the pathlib module by deferring some imports. Patch by Barney Gale.

  • gh-112137: Change dis output to display logical labels for jump targets instead of offsets.

  • gh-112139: Add Signature.format() to format signatures to string with extra options. And use it in pydoc to render more readable signatures that have new lines between parameters.

  • gh-112105: Make readline.set_completer_delims() work with libedit

  • gh-106922: Display multiple lines with traceback when errors span multiple lines.

  • gh-111874: When creating a typing.NamedTuple class, ensure __set_name__() is called on all objects that define __set_name__ and exist in the values of the NamedTuple class’s class dictionary. Patch by Alex Waygood.

  • gh-68166: Add support of the “vsapi” element type in tkinter.ttk.Style.element_create().

  • gh-110275: Named tuple’s methods _replace() and __replace__() now raise TypeError instead of ValueError for invalid keyword arguments.

  • gh-99367: Do not mangle sys.path[0] in pdb if safe_path is set

  • gh-111615: Fix a regression caused by a fix to gh-93162 whereby you couldn’t configure a QueueHandler without specifying handlers.

  • gh-75666: Fix the behavior of tkinter widget’s unbind() method with two arguments. Previously, widget.unbind(sequence, funcid) destroyed the current binding for sequence, leaving sequence unbound, and deleted the funcid command. Now it removes only funcid from the binding for sequence, keeping other commands, and deletes the funcid command. It leaves sequence unbound only if funcid was the last bound command.

  • gh-67790: Implement basic formatting support (minimum width, alignment, fill) for fractions.Fraction.

  • gh-111049: Fix crash during garbage collection of the io.BytesIO buffer object.

  • gh-102980: Redirect the output of interact command of pdb to the same channel as the debugger. Add tests and improve docs.

  • gh-102988: email.utils.getaddresses() and email.utils.parseaddr() now return ('', '') 2-tuples in more situations where invalid email addresses are encountered instead of potentially inaccurate values. Add optional strict parameter to these two functions: use strict=False to get the old behavior, accept malformed inputs. getattr(email.utils, 'supports_strict_parsing', False) can be use to check if the strict parameter is available. Patch by Thomas Dwyer and Victor Stinner to improve the CVE 2023-27043 fix.

  • gh-52161: cmd.Cmd.do_help() now cleans docstrings with inspect.cleandoc() before writing them. Patch by Filip Łapkiewicz.

  • gh-82300: Add track parameter to multiprocessing.shared_memory.SharedMemory that allows using shared memory blocks without having to register with the POSIX resource tracker that automatically releases them upon process exit.

  • gh-110109: Add private pathlib._PurePathBase class: a base class for pathlib.PurePath that omits certain magic methods. It may be made public (along with _PathBase) in future.

  • gh-109858: Protect zipfile from “quoted-overlap” zipbomb. It now raises BadZipFile when try to read an entry that overlaps with other entry or central directory.

  • gh-109786: Fix possible reference leaks and crash when re-enter the __next__() method of itertools.pairwise.

  • gh-91539: Small (10 - 20%) and trivial performance improvement of urllib.request.getproxies_environment(), typically useful when there are many environment variables to go over.

  • gh-103363: Add follow_symlinks keyword-only argument to pathlib.Path.owner() and group(), defaulting to True.

  • gh-102130: Support tab completion in cmd for editline.

  • gh-99437: runpy.run_path() now decodes path-like objects, making sure __file__ and sys.argv[0] of the module being run are always strings.

  • gh-104003: Add warnings.deprecated(), a decorator to mark deprecated functions to static type checkers and to warn on usage of deprecated classes and functions. See PEP 702. Patch by Jelle Zijlstra.

  • gh-103708: Make hardcoded python name, a configurable parameter so that different implementations of python can override it instead of making huge diffs in sysconfig.py

  • gh-66515: mailbox.MH now supports folders that do not contain a .mh_sequences file (e.g. Claws Mail IMAP-cache folders). Patch by Serhiy Storchaka.

  • gh-83162: Renamed re.error to PatternError for clarity, and kept re.error for backward compatibility. Patch by Matthias Bussonnier and Adam Chhina.

  • gh-91133: Fix a bug in tempfile.TemporaryDirectory cleanup, which now no longer dereferences symlinks when working around file system permission errors.

  • bpo-43153: On Windows, tempfile.TemporaryDirectory previously masked a PermissionError with NotADirectoryError during directory cleanup. It now correctly raises PermissionError if errors are not ignored. Patch by Andrei Kulakov and Ken Jin.

  • bpo-32731: getpass.getuser() now raises OSError for all failures rather than ImportError on systems lacking the pwd module or KeyError if the password database is empty.

  • bpo-34321: mmap.mmap now has a trackfd parameter on Unix; if it is False, the file descriptor specified by fileno will not be duplicated.

  • bpo-35332: The shutil.rmtree() function now ignores errors when calling os.close() when ignore_errors is True, and os.close() no longer retried after error.

  • bpo-35928: io.TextIOWrapper now correctly handles the decoding buffer after read() and write().

  • bpo-26791: shutil.move() now moves a symlink into a directory when that directory is the target of the symlink. This provides the same behavior as the mv shell command. The previous behavior raised an exception. Patch by Jeffrey Kintscher.

  • bpo-41422: Fixed memory leaks of pickle.Pickler and pickle.Unpickler involving cyclic references via the internal memo mapping.

  • bpo-19821: The pydoc.ispackage() function has been deprecated.

  • bpo-40262: The ssl.SSLSocket.recv_into() method no longer requires the buffer argument to implement __len__ and supports buffers with arbitrary item size.

  • bpo-39912: warnings.filterwarnings() and warnings.simplefilter() now raise appropriate exceptions instead of AssertionError. Patch contributed by Rémi Lapeyre.

  • bpo-37260: Fixed a race condition in shutil.rmtree() in which directory entries removed by another process or thread while shutil.rmtree() is running can cause it to raise FileNotFoundError. Patch by Jeffrey Kintscher.

  • bpo-36959: Fix some error messages for invalid ISO format string combinations in strptime() that referred to directives not contained in the format string. Patch by Gordon P. Hemsley.

  • bpo-18060: Fixed a class inheritance issue that can cause segfaults when deriving two or more levels of subclasses from a base class of Structure or Union.

  • bpo-29779: Add a new PYTHON_HISTORY environment variable to set the location of a .python_history file.

  • bpo-21360: mailbox.Maildir now ignores files with a leading dot.

Documentation

  • gh-111699: Relocate smtpd deprecation notice to its own section rather than under locale in What’s New in Python 3.12 document

  • gh-110746: Improved markup for valid options/values for methods ttk.treeview.column and ttk.treeview.heading, and for Layouts.

  • gh-95649: Document that the asyncio module contains code taken from v0.16.0 of the uvloop project, as well as the required MIT licensing information.

Tests

  • gh-111798: Disable test_super_deep() from test_call under pydebug builds on WASI; the stack depth is too small to make the test useful.

  • gh-111801: Lower the recursion limit in test_isinstance for test_infinitely_many_bases(). This prevents a stack overflow on a pydebug build of WASI.

  • gh-111802: Specify a low recursion depth for test_bad_getattr() in test.pickletester to avoid exhausting the stack under a pydebug build for WASI.

  • gh-44626: Fix os.path.isabs() incorrectly returning True when given a path that starts with exactly one (back)slash on Windows.

    Fix pathlib.PureWindowsPath.is_absolute() incorrectly returning False for some paths beginning with two (back)slashes.

  • gh-113633: Use module state for the _testcapi extension module.

  • gh-109980: Fix test_tarfile_vs_tar in test_shutil for macOS, where system tar can include more information in the archive than shutil.make_archive.

  • gh-112769: The tests now correctly compare zlib version when zlib.ZLIB_RUNTIME_VERSION contains non-integer suffixes. For example zlib-ng defines the version as 1.3.0.zlib-ng.

  • gh-112334: Adds a regression test to verify that vfork() is used when expected by subprocess on vfork enabled POSIX systems (Linux).

  • gh-108927: Fixed order dependence in running tests in the same process when a test that has submodules (e.g. test_importlib) follows a test that imports its submodule (e.g. test_importlib.util) and precedes a test (e.g. test_unittest or test_compileall) that uses that submodule.

  • bpo-40648: Test modes that file can get with chmod() on Windows.

Build

  • gh-114013: Fix Tools/wasm/wasi.py to not include the path to python.wasm as part of HOSTRUNNER. The environment variable is meant to specify how to run the WASI host only, having python.wasm and relevant flags appended to the HOSTRUNNER. This fixes make test work.

  • gh-113258: Changed the Windows build to write out generated frozen modules into the build tree instead of the source tree.

  • gh-112305: Fixed the check-clean-src step performed on out of tree builds to detect errant $(srcdir)/Python/frozen_modules/*.h files and recommend appropriate source tree cleanup steps to get a working build again.

  • gh-112536: Add support for thread sanitizer (TSAN)

  • gh-112867: Fix the build for the case that WITH_PYMALLOC_RADIX_TREE=0 set.

  • gh-103065: Introduce Tools/wasm/wasi.py to simplify doing a WASI build.

  • bpo-11102: The os.major(), os.makedev(), and os.minor() functions are now available on HP-UX v3.

  • bpo-36351: Do not set ipv6type when cross-compiling.

Windows

  • gh-114096: Process privileges that are activated for creating directory junctions are now restored afterwards, avoiding behaviour changes in other parts of the program.

  • gh-111877: os.stat() calls were returning incorrect time values for files that could not be accessed directly.

  • gh-111973: Update Windows installer to use SQLite 3.44.2.

  • gh-113009: multiprocessing: On Windows, fix a race condition in Process.terminate(): no longer set the returncode attribute to always call WaitForSingleObject() in Process.wait(). Previously, sometimes the process was still running after TerminateProcess() even if GetExitCodeProcess() is not STILL_ACTIVE. Patch by Victor Stinner.

  • gh-86179: Fixes path calculations when launching Python on Windows through a symlink.

  • gh-71383: Update Tcl/Tk in Windows installer to 8.6.13 with a patch to suppress incorrect ThemeChanged warnings.

  • gh-111650: Ensures the Py_GIL_DISABLED preprocessor variable is defined in pyconfig.h so that extension modules written in C are able to use it.

  • gh-112278: Reduce the time cost for some functions in platform on Windows if current user has no permission to the WMI.

  • gh-73427: Deprecate sys._enablelegacywindowsfsencoding(). Use PYTHONLEGACYWINDOWSFSENCODING instead. Patch by Inada Naoki.

  • gh-87868: Correctly sort and remove duplicate environment variables in _winapi.CreateProcess().

  • bpo-37308: Fix mojibake in mmap.mmap when using a non-ASCII tagname argument on Windows.

macOS

  • gh-113666: Add the following constants to module stat: UF_SETTABLE, UF_TRACKED, UF_DATAVAULT, SF_SUPPORTED, SF_SETTABLE, SF_SYNTHETIC, SF_RESTRICTED, SF_FIRMLINK and SF_DATALESS. The values UF_SETTABLE, SF_SUPPORTED, SF_SETTABLE and SF_SYNTHETIC are only available on macOS.

  • gh-113536: os.waitid() is now available on macOS

  • gh-110459: Running configure ... --with-openssl-rpath=X/Y/Z no longer fails to detect OpenSSL on macOS.

  • gh-74573: Document that dbm.ndbm can silently corrupt DBM files on updates when exceeding undocumented platform limits, and can crash (segmentation fault) when reading such a corrupted file. (FB8919203)

  • gh-65701: The freeze tool doesn’t work with framework builds of Python. Document this and bail out early when running the tool with such a build.

  • gh-87277: webbrowser: Don’t look for X11 browsers on macOS. Those are generally not used and probing for them can result in starting XQuartz even if it isn’t used otherwise.

  • gh-111973: Update macOS installer to use SQLite 3.44.2.

  • gh-108269: Set CFBundleAllowMixedLocalizations to true in the Info.plist for the framework, embedded Python.app and IDLE.app with framework installs on macOS. This allows applications to pick up the user’s preferred locale when that’s different from english.

  • gh-102362: Make sure the result of sysconfig.get_plaform() includes at least a major and minor versions, even if MACOSX_DEPLOYMENT_TARGET is set to only a major version during build to match the format expected by pip.

  • gh-110017: Disable a signal handling stress test on macOS due to a bug in macOS (FB13453490).

  • gh-110820: Make sure the preprocessor definitions for ALIGNOF_MAX_ALIGN_T, SIZEOF_LONG_DOUBLE and HAVE_GCC_ASM_FOR_X64 are correct for Universal 2 builds on macOS.

  • gh-109981: Use /dev/fd on macOS to determine the number of open files in test.support.os_helper.fd_count to avoid a crash with “guarded” file descriptors when probing for open files.

IDLE

  • gh-72284: Improve the lists of features, editor key bindings, and shell key bingings in the IDLE doc.

  • gh-113903: Fix rare failure of test.test_idle, in test_configdialog.

  • gh-113729: Fix the “Help -> IDLE Doc” menu bug in 3.11.7 and 3.12.1.

  • gh-113269: Fix test_editor hang on macOS Catalina.

  • gh-112898: Fix processing unsaved files when quitting IDLE on macOS.

  • bpo-13586: Enter the selected text when opening the “Replace” dialog.

C API

Python 3.13.0 alpha 2

Release date: 2023-11-22

Core and Builtins

  • gh-112243: Don’t include comments in f-string debug expressions. Patch by Pablo Galindo

  • gh-112287: Slightly optimize the Tier 2 (uop) interpreter by only loading oparg and operand when needed. Also double the trace size limit again, to 512 this time.

  • gh-112266: Change docstrings of __dict__ and __weakref__.

  • gh-111807: Lower the max parser stack depth to 1000 under WASI debug builds.

  • gh-111798: When Python is built in debug mode, set the C recursion limit to 500 instead of 1500. A debug build is likely built with low optimization level which implies higher stack memory usage than a release build. Patch by Victor Stinner.

  • gh-106529: Enable translating unspecialized FOR_ITER to Tier 2.

  • gh-111916: Make hashlib related modules thread-safe without the GIL

  • gh-81137: Deprecate assignment to a function’s __code__ field when the new code object is of a mismatched type (e.g., from a generator to a plain function).

  • gh-79932: Raise exception if frame.clear() is called on a suspended frame.

  • gh-81925: Implement native thread ids for GNU KFreeBSD.

  • gh-111843: Use exponential backoff to reduce the number of failed tier 2 optimization attempts by over 99%.

  • gh-110829: Joining a thread now ensures the underlying OS thread has exited. This is required for safer fork() in multi-threaded processes.

  • gh-109369: Make sure that tier 2 traces are de-optimized if the code is instrumented

  • gh-111772: Specialize slot loads and stores for _Py_T_OBJECT as well as Py_T_OBJECT_EX

  • gh-111666: Speed up BaseExceptionGroup.derive(), BaseExceptionGroup.subgroup(), and BaseExceptionGroup.split() by changing how they parse passed arguments.

  • gh-111654: Fix runtime crash when some error happens in opcode LOAD_FROM_DICT_OR_DEREF.

  • gh-111623: Add support for sharing tuples between interpreters using the cross-interpreter API. Patch by Anthony Shaw.

  • gh-111354: The oparg of YIELD_VALUE is now 1 if the instruction is part of a yield-from or await, and 0 otherwise.

    The SUSPENDED frame state is now split into SUSPENDED and SUSPENDED_YIELD_FROM. This simplifies the code in _PyGen_yf.

  • gh-111520: Merge the Tier 1 (bytecode) and Tier 2 (micro-ops) interpreters together, moving the Tier 2 interpreter loop and switch into _PyEval_EvalFrameDefault() in Python/ceval.c. The Python/executor.c file is gone. Also the TIER_ONE and TIER_TWO macros are now handled by the code generator.

    Beware! This changes the environment variables to enable micro-ops and their debugging to PYTHON_UOPS and PYTHON_LLTRACE.

  • gh-109181: Speed up Traceback object creation by lazily compute the line number. Patch by Pablo Galindo

  • gh-111420: Allow type comments in parenthesized with statements

  • gh-111438: Add support for sharing floats between interpreters using the cross-interpreter API. Patch by Anthony Shaw.

  • gh-111435: Add support for sharing of True and False between interpreters using the cross-interpreter API. Patch by Anthony Shaw.

  • gh-102388: Fix a bug where iso2022_jp_3 and iso2022_jp_2004 codecs read out of bounds

  • gh-111366: Fix an issue in the codeop that was causing SyntaxError exceptions raised in the presence of invalid syntax to not contain precise error messages. Patch by Pablo Galindo

  • gh-111380: Fix a bug that was causing SyntaxWarning to appear twice when parsing if invalid syntax is encountered later. Patch by Pablo galindo

  • gh-111374: Added a new environment variable PYTHON_FROZEN_MODULES. It determines whether or not frozen modules are ignored by the import machinery, equivalent of the -X frozen_modules command-line option.

  • gh-111354: Remove oparg from YIELD_VALUE. Change oparg of RESUME to include information about the except-depth. These changes make it possible to simplify the code in generator close.

  • gh-94438: Fix a regression that prevented jumping across is None and is not None when debugging. Patch by Savannah Ostrowski.

  • gh-67224: Show source lines in tracebacks when using the -c option when running Python. Patch by Pablo Galindo

  • gh-111123: Fix a bug where a global declaration in an except block is rejected when the global is used in the else block.

  • gh-110938: Fix error messages for indented blocks with functions and classes with generic type parameters. Patch by Pablo Galindo

  • gh-109214: Remove unnecessary instruction pointer updates before returning from frames.

  • gh-110912: Correctly display the traceback for MemoryError exceptions using the traceback module. Patch by Pablo Galindo

  • gh-109894: Fixed crash due to improperly initialized static MemoryError in subinterpreter.

  • gh-110892: Return NULL for PyTrace_RETURN events caused by an exception

  • gh-110864: Fix argument parsing by _PyArg_UnpackKeywordsWithVararg for functions defining pos-or-keyword, vararg, and kw-only parameters.

  • gh-109094: Replace prev_instr on the interpreter frame by instr_ptr which points to the beginning of the instruction that is currently executing (or will execute once the frame resumes).

  • gh-110805: Allow the repl to show source code and complete tracebacks. Patch by Pablo Galindo

  • gh-110722: Add PYTHON_PRESITE=package.module to import a module early in the interpreter lifecycle before site.py is executed. Python needs to be built in debug mode for this option to exist.

  • gh-110481: Implement biased reference counting in --disable-gil builds.

  • gh-110543: Fix regression in Python 3.12 where types.CodeType.replace() would produce a broken code object if called on a module or class code object that contains a comprehension. Patch by Jelle Zijlstra.

  • gh-89519: Removed chained classmethod descriptors (introduced in bpo-19072). This can no longer be used to wrap other descriptors such as property. The core design of this feature was flawed and caused a number of downstream problems. To “pass-through” a classmethod, consider using the __wrapped__ attribute that was added in Python 3.10.

  • gh-103615: Use local events for opcode tracing

  • bpo-46657: Add mimalloc memory allocator support.

  • gh-106718: When PyConfig.stdlib_dir is explicitly set, it’s now respected and won’t be overridden by PyConfig.home.

  • gh-106905: Fix incorrect SystemError about AST constructor recursion depth mismatch.

  • gh-100445: Improve error message for unterminated strings with escapes.

  • bpo-45759: Improved error messages for elif/else statements not matching any valid statements. Patch by Jeremiah Vivian.

Library

Tests

  • gh-111808: Make the default value of test.support.infinite_recursion() to be conditional based on whether optimizations were used when compiling the interpreter. This helps with platforms like WASI whose stack size is greatly restricted in debug builds.

  • gh-110722: Gathering line coverage of standard libraries within the regression test suite is now precise, as well as much faster. Patch by Łukasz Langa.

  • gh-110367: Make regrtest --verbose3 option compatible with --huntrleaks -jN options. The ./python -m test -j1 -R 3:3 --verbose3 command now works as expected. Patch by Victor Stinner.

  • gh-111165: Remove no longer used functions run_unittest() and run_doctest() from the test.support module.

  • gh-110932: Fix regrtest if the SOURCE_DATE_EPOCH environment variable is defined: use the variable value as the random seed. Patch by Victor Stinner.

  • gh-110995: test_gdb: Fix detection of gdb built without Python scripting support. Patch by Victor Stinner.

  • gh-110918: Test case matching patterns specified by options --match, --ignore, --matchfile and --ignorefile are now tested in the order of specification, and the last match determines whether the test case be run or ignored.

  • gh-108747: Add unit test for usercustomize and sitecustomize hooks from site.

Build

  • gh-96954: Make make regen-unicodedata work for out-of-tree builds of CPython.

  • gh-112088: Add Tools/build/regen-configure.sh script to regenerate the configure with an Ubuntu container image. The quay.io/tiran/cpython_autoconf:271 container image (tiran/cpython_autoconf) is no longer used. Patch by Victor Stinner.

  • gh-111046: For wasi-threads, memory is now exported to fix compatibility issues with some wasm runtimes.

  • gh-110828: AIX 32bit needs -latomic to build the _testcapi extension module.

  • gh-85283: The errno, md5, resource, winsound, _ctypes_test, _multiprocessing.posixshmem, _scproxy, _stat, _testimportmultiple and _uuid C extensions are now built with the limited C API. Patch by Victor Stinner.

Windows

  • gh-111856: Fixes fstat() on file systems that do not support file ID requests. This includes FAT32 and exFAT.

  • gh-111293: Fix os.DirEntry.inode dropping higher 64 bits of a file id on some filesystems on Windows.

  • gh-110913: WindowsConsoleIO now correctly chunks large buffers without splitting up UTF-8 sequences.

macOS

  • gh-59703: For macOS framework builds, in getpath.c use the system dladdr function to find the path to the shared library rather than depending on deprecated macOS APIs.

  • gh-110950: Update macOS installer to include an upstream Tcl/Tk fix for the Secure coding is not enabled for restorable state! warning encountered in Tkinter on macOS 14 Sonoma.

  • gh-111015: Ensure that IDLE.app and Python Launcher.app are installed with appropriate permissions on macOS builds.

  • gh-71383: Update macOS installer to include an upstream Tcl/Tk fix for the ttk::ThemeChanged error encountered in Tkinter.

  • gh-92603: Update macOS installer to include a fix accepted by upstream Tcl/Tk for a crash encountered after the first tkinter.Tk() instance is destroyed.

IDLE

  • bpo-35668: Add docstrings to the IDLE debugger module. Fix two bugs: initialize Idb.botframe (should be in Bdb); in Idb.in_rpc_code, check whether prev_frame is None before trying to use it. Greatly expand test_debugger.

Tools/Demos

  • gh-111903: Argument Clinic now supports the @critical_section directive that instructs Argument Clinic to generate a critical section around the function call, which locks the self object in --disable-gil builds. Patch by Sam Gross.

C API

  • gh-112026: Add again the private _PyThreadState_UncheckedGet() function as an alias to the new public PyThreadState_GetUnchecked() function. Patch by Victor Stinner.

  • gh-112026: Restore the removed _PyDict_GetItemStringWithError() function. It is used by numpy. Patch by Victor Stinner.

  • gh-112026: Restore removed private C API functions, macros and structures which have no simple replacement for now:

    • _PyDict_GetItem_KnownHash()

    • _PyDict_NewPresized()

    • _PyHASH_BITS

    • _PyHASH_IMAG

    • _PyHASH_INF

    • _PyHASH_MODULUS

    • _PyHASH_MULTIPLIER

    • _PyLong_Copy()

    • _PyLong_FromDigits()

    • _PyLong_New()

    • _PyLong_Sign()

    • _PyObject_CallMethodId()

    • _PyObject_CallMethodNoArgs()

    • _PyObject_CallMethodOneArg()

    • _PyObject_CallOneArg()

    • _PyObject_EXTRA_INIT

    • _PyObject_FastCallDict()

    • _PyObject_GetAttrId()

    • _PyObject_Vectorcall()

    • _PyObject_VectorcallMethod()

    • _PyStack_AsDict()

    • _PyThread_CurrentFrames()

    • _PyUnicodeWriter structure

    • _PyUnicodeWriter_Dealloc()

    • _PyUnicodeWriter_Finish()

    • _PyUnicodeWriter_Init()

    • _PyUnicodeWriter_Prepare()

    • _PyUnicodeWriter_PrepareKind()

    • _PyUnicodeWriter_WriteASCIIString()

    • _PyUnicodeWriter_WriteChar()

    • _PyUnicodeWriter_WriteLatin1String()

    • _PyUnicodeWriter_WriteStr()

    • _PyUnicodeWriter_WriteSubstring()

    • _PyUnicode_AsString()

    • _PyUnicode_FromId()

    • _PyVectorcall_Function()

    • _Py_IDENTIFIER()

    • _Py_c_abs()

    • _Py_c_diff()

    • _Py_c_neg()

    • _Py_c_pow()

    • _Py_c_prod()

    • _Py_c_quot()

    • _Py_c_sum()

    • _Py_static_string()

    • _Py_static_string_init()

    Patch by Victor Stinner.

  • gh-112026: Add again <ctype.h> and <unistd.h> includes in Python.h, but don’t include them in the limited C API version 3.13 and newer. Patch by Victor Stinner.

  • gh-111956: Add internal-only one-time initialization API: _PyOnceFlag and _PyOnceFlag_CallOnce.

  • gh-111262: Add PyDict_Pop() and PyDict_PopString() functions: remove a key from a dictionary and optionally return the removed value. This is similar to dict.pop(), but without the default value and not raising KeyError if the key missing. Patch by Stefan Behnel and Victor Stinner.

  • gh-111863: Rename Py_NOGIL to Py_GIL_DISABLED. Patch by Hugo van Kemenade.

  • gh-111138: Add PyList_Extend() and PyList_Clear() functions: similar to Python list.extend() and list.clear() methods. Patch by Victor Stinner.

  • gh-108765: On Windows, Python.h no longer includes the <stddef.h> standard header file. If needed, it should now be included explicitly. Patch by Victor Stinner.

  • gh-111569: Implement “Python Critical Sections” from PEP 703. These are macros to help replace the GIL with per-object locks in the --disable-gil build of CPython. The macros are no-ops in the default build.

  • gh-111506: In the limited C API version 3.13, Py_SET_REFCNT() function is now implemented as an opaque function call. Patch by Victor Stinner.

  • gh-108082: Add PyErr_FormatUnraisable() function.

  • gh-110964: Move the undocumented private _PyArg functions and _PyArg_Parser structure to internal C API (pycore_modsupport.h). Patch by Victor Stinner.

  • gh-110815: Support non-ASCII keyword names in PyArg_ParseTupleAndKeywords().

  • gh-109587: Introduced PyUnstable_PerfTrampoline_CompileCode(), PyUnstable_PerfTrampoline_SetPersistAfterFork() and PyUnstable_CopyPerfMapFile(). These functions allow extension modules to initialize trampolines eagerly, after the application is “warmed up”. This makes it possible to have perf-trampolines running in an always-enabled fashion.

  • gh-85283: Add the PySys_Audit() function to the limited C API. Patch by Victor Stinner.

  • gh-85283: Add PyMem_RawMalloc(), PyMem_RawCalloc(), PyMem_RawRealloc() and PyMem_RawFree() to the limited C API. Patch by Victor Stinner.

  • gh-106672: Functions PyDict_GetItem(), PyDict_GetItemString(), PyMapping_HasKey(), PyMapping_HasKeyString(), PyObject_HasAttr(), PyObject_HasAttrString(), and PySys_GetObject(), which clear all errors occurred during calling the function, report now them using sys.unraisablehook().

  • gh-67565: Remove redundant C-contiguity check in getargs.c, binascii, ssl and Argument Clinic. Patched by Stefan Krah and Furkan Onder

Python 3.13.0 alpha 1

Release date: 2023-10-13

Security

  • gh-108310: Fixed an issue where instances of ssl.SSLSocket were vulnerable to a bypass of the TLS handshake and included protections (like certificate verification) and treating sent unencrypted data as if it were post-handshake TLS encrypted data. Security issue reported as CVE 2023-40217 by Aapo Oksman. Patch by Gregory P. Smith.

  • gh-107774: PEP 669 specifies that sys.monitoring.register_callback will generate an audit event. Pre-releases of Python 3.12 did not generate the audit event. This is now fixed.

  • gh-102988: Reverted the email.utils security improvement change released in 3.12beta4 that unintentionally caused email.utils.getaddresses to fail to parse email addresses with a comma in the quoted name field. See gh-106669.

  • gh-99108: Refresh our new HACL* built-in hashlib code from upstream. Built-in SHA2 should be faster and an issue with SHA3 on 32-bit platforms is fixed.

  • gh-102509: Start initializing ob_digit during creation of PyLongObject objects. Patch by Illia Volochii.

Core and Builtins

  • gh-110782: Fix crash when typing.TypeVar is constructed with a keyword argument. Patch by Jelle Zijlstra.

  • gh-110752: Reset ceval.eval_breaker in interpreter_clear()

  • gh-110721: Use the traceback implementation for the default PyErr_Display() functionality. Patch by Pablo Galindo

  • gh-110696: Fix incorrect error message for invalid argument unpacking. Patch by Pablo Galindo

  • gh-104169: Split the tokenizer into two separate directories: - One part includes the actual lexeme producing logic and lives in Parser/lexer. - The second part wraps the lexer according to the different tokenization modes we have (string, utf-8, file, interactive, readline) and lives in Parser/tokenizer.

  • gh-110688: Remove undocumented test_c_api method from set, which was only defined for testing purposes under Py_DEBUG. Now we have proper CAPI tests.

  • gh-104584: Fix a reference leak when running with PYTHONUOPS or -X uops enabled.

  • gh-110514: Add PY_THROW to sys.setprofile() events

  • gh-110489: Optimise math.ceil() when the input is exactly a float, resulting in about a 10% improvement.

  • gh-110455: Guard assert(tstate->thread_id > 0) with #ifndef HAVE_PTHREAD_STUBS. This allows for for pydebug builds to work under WASI which (currently) lacks thread support.

  • gh-110309: Remove unnecessary empty constant nodes in the ast of f-string specs.

  • gh-110259: Correctly identify the format spec in f-strings (with single or triple quotes) that have multiple lines in the expression part and include a formatting spec. Patch by Pablo Galindo

  • gh-110237: Fix missing error checks for calls to PyList_Append in _PyEval_MatchClass.

  • gh-110164: regrtest: If the SOURCE_DATE_EPOCH environment variable is defined, regrtest now disables tests randomization. Patch by Victor Stinner.

  • gh-109889: Fix the compiler’s redundant NOP detection algorithm to skip over NOPs with no line number when looking for the next instruction’s lineno.

  • gh-109853: sys.path[0] is now set correctly for subinterpreters.

  • gh-109923: Set line number on the POP_TOP that follows a RETURN_GENERATOR.

  • gh-105716: Subinterpreters now correctly handle the case where they have threads running in the background. Before, such threads would interfere with cleaning up and destroying them, as well as prevent running another script.

  • gh-109369: The internal eval_breaker and supporting flags, plus the monitoring version have been merged into a single atomic integer to speed up checks.

  • gh-109823: Fix bug where compiler does not adjust labels when removing an empty basic block which is a jump target.

  • gh-109793: The main thread no longer exits prematurely when a subinterpreter is cleaned up during runtime finalization. The bug was a problem particularly because, when triggered, the Python process would always return with a 0 exitcode, even if it failed.

  • gh-109719: Fix missing jump target labels when compiler reorders cold/warm blocks.

  • gh-109595: Add -X cpu_count command line option to override return results of os.cpu_count() and os.process_cpu_count(). This option is useful for users who need to limit CPU resources of a container system without having to modify the container (application code). Patch by Donghee Na.

  • gh-109627: Fix bug where the compiler does not assign a new jump target label to a duplicated small exit block.

  • gh-109596: Fix some tokens in the grammar that were incorrectly marked as soft keywords. Also fix some repeated rule names and ensure that repeated rules are not allowed. Patch by Pablo Galindo

  • gh-109496: On a Python built in debug mode, Py_DECREF() now calls _Py_NegativeRefcount() if the object is a dangling pointer to deallocated memory: memory filled with 0xDD “dead byte” by the debug hook on memory allocators. The fix is to check the reference count before checking for _Py_IsImmortal(). Patch by Victor Stinner.

  • gh-107265: Deopt opcodes hidden by the executor when base opcode is needed

  • gh-109371: Deopted instructions correctly for tool initialization and modified the incorrect assertion in instrumentation, when a previous tool already sets INSTRUCTION events

  • gh-105658: Fix bug where the line trace of an except block ending with a conditional includes an excess event with the line of the conditional expression.

  • gh-109219: Fix compiling type param scopes that use a name which is also free in an inner scope.

  • gh-109351: Fix crash when compiling an invalid AST involving a named (walrus) expression.

  • gh-109341: Fix crash when compiling an invalid AST involving a ast.TypeAlias.

  • gh-109195: Fix source location for the LOAD_* instruction preceding a LOAD_SUPER_ATTR to load the super global (or shadowing variable) so that it encompasses only the name super and not the following parentheses.

  • gh-109256: Opcode IDs for specialized opcodes are allocated in their own range to improve stability of the IDs for the ‘real’ opcodes.

  • gh-109216: Fix possible memory leak in BUILD_MAP.

  • gh-109207: Fix a SystemError in __repr__ of symtable entry object.

  • gh-109179: Fix bug where the C traceback display drops notes from SyntaxError.

  • gh-109118: Disallow nested scopes (lambdas, generator expressions, and comprehensions) within PEP 695 annotation scopes that are nested within classes.

  • gh-109156: Add tests for de-instrumenting instructions while keeping the instrumentation for lines

  • gh-109114: Relax the detection of the error message for invalid lambdas inside f-strings to not search for arbitrary replacement fields to avoid false positives. Patch by Pablo Galindo

  • gh-105848: Add a new CALL_KW opcode, used for calls containing keyword arguments. Also, fix a possible crash when jumping over method calls in a debugger.

  • gh-109052: Use the base opcode when comparing code objects to avoid interference from instrumentation

  • gh-109118: Fix interpreter crash when a NameError is raised inside the type parameters of a generic class.

  • gh-88943: Improve syntax error for non-ASCII character that follows a numerical literal. It now points on the invalid non-ASCII character, not on the valid numerical literal.

  • gh-108976: Fix crash that occurs after de-instrumenting a code object in a monitoring callback.

  • gh-108732: Make iteration variables of module- and class-scoped comprehensions visible to pdb and other tools that use frame.f_locals again.

  • gh-108959: Fix caret placement for error locations for subscript and binary operations that involve non-semantic parentheses and spaces. Patch by Pablo Galindo

  • gh-104584: Fix a crash when running with PYTHONUOPS or -X uops enabled and an error occurs during optimization.

  • gh-108727: Define tp_dealloc for CounterOptimizer_Type. This fixes a segfault on deallocation.

  • gh-108520: Fix multiprocessing.synchronize.SemLock.__setstate__() to properly initialize multiprocessing.synchronize.SemLock._is_fork_ctx. This fixes a regression when passing a SemLock across nested processes.

    Rename multiprocessing.synchronize.SemLock.is_fork_ctx to multiprocessing.synchronize.SemLock._is_fork_ctx to avoid exposing it as public API.

  • gh-108654: Restore locals shadowed by an inlined comprehension if the comprehension raises an exception.

  • gh-108488: Change the initialization of inline cache entries so that the cache entry for JUMP_BACKWARD is initialized to zero, instead of the adaptive_counter_warmup() value used for all other instructions. This counter, unique among instructions, counts up from zero.

  • gh-108716: Turn off deep-freezing of code objects. Modules are still frozen, so that a file system search is not needed for common modules.

  • gh-108614: Add RESUME_CHECK instruction, to avoid having to handle instrumentation, signals, and contexts switches in the tier 2 execution engine.

  • gh-108487: Move an assert that would cause a spurious crash in a devious case that should only trigger deoptimization.

  • gh-106176: Use a WeakValueDictionary to track the lists containing the modules each thread is currently importing. This helps avoid a reference leak from keeping the list around longer than necessary. Weakrefs are used as GC can’t interrupt the cleanup.

  • gh-105481: The regen-opcode build stage was removed and its work is now done in regen-cases.

  • gh-107901: Fix missing line number on JUMP_BACKWARD at the end of a for loop.

  • gh-108113: The compile() built-in can now accept a new flag, ast.PyCF_OPTIMIZED_AST, which is similar to ast.PyCF_ONLY_AST except that the returned AST is optimized according to the value of the optimize argument.

    ast.parse() now accepts an optional argument optimize which is passed on to the compile() built-in. This makes it possible to obtain an optimized AST.

  • gh-107971: Opcode IDs are generated from bytecodes.c instead of being hard coded in opcode.py.

  • gh-107944: Improve error message for function calls with bad keyword arguments. Patch by Pablo Galindo

  • gh-108390: Raise an exception when setting a non-local event (RAISE, EXCEPTION_HANDLED, etc.) in sys.monitoring.set_local_events.

    Fixes crash when tracing in recursive calls to Python classes.

  • gh-108035: Remove the _PyCFrame struct, moving the pointer to the current interpreter frame back to the threadstate, as it was for 3.10 and earlier. The _PyCFrame existed as a performance optimization for tracing. Since PEP 669 has been implemented, this optimization no longer applies.

  • gh-91051: Fix abort / segfault when using all eight type watcher slots, on platforms where char is signed by default.

  • gh-106581: Fix possible assertion failures and missing instrumentation events when PYTHONUOPS or -X uops is enabled.

  • gh-107526: Revert converting vars, dir, next, getattr, and iter to argument clinic.

  • gh-84805: Autogenerate signature for METH_NOARGS and METH_O extension functions.

  • gh-107758: Make the dump_stack() routine used by the lltrace feature (low-level interpreter debugging) robust against recursion by ensuring that it never calls a __repr__ method implemented in Python. Also make the similar output for Tier-2 uops appear on stdout (instead of stderr), to match the lltrace code in ceval.c.

  • gh-107659: Add docstrings for ctypes.pointer() and ctypes.POINTER().

  • gh-105848: Modify the bytecode so that the actual callable for a CALL is at a consistent position on the stack (regardless of whether or not bound-method-calling optimizations are active).

  • gh-107674: Fixed performance regression in sys.settrace.

  • gh-107724: In pre-release versions of 3.12, up to rc1, the sys.monitoring callback function for the PY_THROW event was missing the third, exception argument. That is now fixed.

  • gh-84436: Skip reference count modifications for many known immortal objects.

  • gh-107596: Specialize subscripting str objects by int indexes.

  • gh-107080: Trace refs builds (--with-trace-refs) were crashing when used with isolated subinterpreters. The problematic global state has been isolated to each interpreter. Other fixing the crashes, this change does not affect users.

  • gh-107557: Generate the cases needed for the barebones tier 2 abstract interpreter for optimization passes in CPython.

  • gh-106608: Make _PyUOpExecutorObject variable length.

  • gh-100964: Clear generators’ exception state after return to break reference cycles.

  • gh-107455: Improve error messages when converting an incompatible type to ctypes.c_char_p, ctypes.c_wchar_p and ctypes.c_void_p.

  • gh-107263: Increase C recursion limit for functions other than the main interpreter from 800 to 1500. This should allow functions like list.__repr__ and json.dumps to handle all the inputs that they could prior to 3.12

  • gh-104584: Fix an issue which caused incorrect inline caches to be read when running with PYTHONUOPS or -X uops enabled.

  • gh-104432: Fix potential unaligned memory access on C APIs involving returned sequences of char * pointers within the grp and socket modules. These were revealed using a -fsaniziter=alignment build on ARM macOS. Patch by Christopher Chavez.

  • gh-106078: Isolate _decimal (apply PEP 687). Patch by Charlie Zhao.

  • gh-106898: Add the exception as the third argument to PY_UNIND callbacks in sys.monitoring. This makes the PY_UNWIND callback consistent with the other exception handling callbacks.

  • gh-106895: Raise a ValueError when a monitoring callback function returns DISABLE for events that cannot be disabled locally.

  • gh-106897: Add a RERAISE event to sys.monitoring, which occurs when an exception is reraise, either explicitly by a plain raise statement, or implicitly in an except or finally block.

  • gh-77377: Ensure that multiprocessing synchronization objects created in a fork context are not sent to a different process created in a spawn context. This changes a segfault into an actionable RuntimeError in the parent process.

  • gh-106931: Statically allocated string objects are now interned globally instead of per-interpreter. This fixes a situation where such a string would only be interned in a single interpreter. Normal string objects are unaffected.

  • gh-104621: Unsupported modules now always fail to be imported.

  • gh-107122: Add dbm.ndbm.ndbm.clear() to dbm.ndbm. Patch By Donghee Na.

  • gh-107122: Add dbm.gnu.gdbm.clear() to dbm.gnu. Patch By Donghee Na.

  • gh-107015: The ASYNC and AWAIT tokens are removed from the Grammar, which removes the possibility of making async and await soft keywords when using feature_version<7 in ast.parse().

  • gh-106917: Fix classmethod-style super() method calls (i.e., where the second argument to super(), or the implied second argument drawn from self/cls in the case of zero-arg super, is a type) when the target of the call is not a classmethod.

  • gh-105699: Python no longer crashes due an infrequent race when initializing per-interpreter interned strings. The crash would manifest when the interpreter was finalized.

  • gh-105699: Python no longer crashes due to an infrequent race in setting Py_FileSystemDefaultEncoding and Py_FileSystemDefaultEncodeErrors (both deprecated), when simultaneously initializing two isolated subinterpreters. Now they are only set during runtime initialization.

  • gh-106908: Fix various hangs, reference leaks, test failures, and tracing/introspection bugs when running with PYTHONUOPS or -X uops enabled.

  • gh-106092: Fix a segmentation fault caused by a use-after-free bug in frame_dealloc when the trashcan delays the deallocation of a PyFrameObject.

  • gh-106485: Reduce the number of materialized instances dictionaries by dematerializing them when possible.

  • gh-106719: No longer suppress arbitrary errors in the __annotations__ getter and setter in the type and module types.

  • gh-106723: Propagate frozen_modules to multiprocessing spawned process interpreters.

  • gh-104909: Split LOAD_ATTR_INSTANCE_VALUE into micro-ops.

  • gh-104909: Split LOAD_GLOBAL specializations into micro-ops.

  • gh-106597: A new debug structure of offsets has been added to the _PyRuntimeState that will help out-of-process debuggers and profilers to obtain the offsets to relevant interpreter structures in a way that is agnostic of how Python was compiled and that doesn’t require copying the headers. Patch by Pablo Galindo

  • gh-106487: Allow the count argument of str.replace() to be a keyword. Patch by Hugo van Kemenade.

  • gh-96844: Improve error message of list.remove(). Patch by Donghee Na.

  • gh-81283: Compiler now strips indents from docstrings. It reduces pyc file size 5% when the module is heavily documented. This change affects to __doc__ so tools like doctest will be affected.

  • gh-106396: When the format specification of an f-string expression is empty, the parser now generates an empty ast.JoinedStr node for it instead of an one-element ast.JoinedStr with an empty string ast.Constant.

  • gh-100288: Specialize LOAD_ATTR for non-descriptors on the class. Adds LOAD_ATTR_NONDESCRIPTOR_WITH_VALUES and LOAD_ATTR_NONDESCRIPTOR_NO_DICT.

  • gh-106008: Fix possible reference leaks when failing to optimize comparisons with None in the bytecode compiler.

  • gh-106145: Make end_lineno and end_col_offset required on type_param ast nodes.

  • gh-106213: Changed the way that Emscripten call trampolines work for compatibility with Wasm/JS Promise integration.

  • gh-106182: sys.getfilesystemencoding() and sys.getfilesystemencodeerrors now return interned Unicode object.

  • gh-106210: Removed Emscripten import trampoline as it was no longer necessary for Pyodide.

  • gh-104584: Added a new, experimental, tracing optimizer and interpreter (a.k.a. “tier 2”). This currently pessimizes, so don’t use yet – this is infrastructure so we can experiment with optimizing passes. To enable it, pass -Xuops or set PYTHONUOPS=1. To get debug output, set PYTHONUOPSDEBUG=N where N is a debug level (0-4, where 0 is no debug output and 4 is excessively verbose).

  • gh-105775: LOAD_CLOSURE is now a pseudo-op.

  • gh-105730: Allow any callable other than type objects as the condition predicate in BaseExceptionGroup.split() and BaseExceptionGroup.subgroup().

  • gh-105979: Fix crash in _imp.get_frozen_object() due to improper exception handling.

  • gh-106003: Add a new TO_BOOL instruction, which performs boolean conversions for POP_JUMP_IF_TRUE, POP_JUMP_IF_FALSE, and UNARY_NOT (which all expect exact bool values now). Also, modify the oparg of COMPARE_OP to include an optional “boolean conversion” flag.

  • gh-98931: Ensure custom SyntaxError error messages are raised for invalid imports with multiple targets. Patch by Pablo Galindo

  • gh-105724: Improve assert error messages by providing exact error range.

  • gh-105908: Fixed bug where gh-99111 breaks future import barry_as_FLUFL in the Python REPL.

  • gh-105840: Fix possible crashes when specializing function calls with too many __defaults__.

  • gh-105831: Fix an f-string bug, where using a debug expression (the = sign) that appears in the last line of a file results to the debug buffer that holds the expression text being one character too small.

  • gh-105800: Correctly issue SyntaxWarning in f-strings if invalid sequences are used. Patch by Pablo Galindo

  • gh-105340: Include the comprehension iteration variable in locals() inside a module- or class-scope comprehension.

  • gh-105331: Raise ValueError if the delay argument to asyncio.sleep() is a NaN (matching time.sleep()).

  • gh-105587: The runtime can’t guarantee that immortal objects will not be mutated by Extensions. Thus, this modifies _PyStaticObject_CheckRefcnt to warn instead of asserting.

  • gh-105564: Don’t include artificil newlines in the line attribute of tokens in the APIs of the tokenize module. Patch by Pablo Galindo

  • gh-105549: Tokenize separately NUMBER and NAME tokens that are not ambiguous. Patch by Pablo Galindo.

  • gh-105588: Fix an issue that could result in crashes when compiling malformed ast nodes.

  • gh-100987: Allow objects other than code objects as the “executable” in internal frames. In the long term, this can help tools like Cython and PySpy interact more efficiently. In the shorter term, it allows us to perform some optimizations more simply.

  • gh-105375: Fix bugs in the builtins module where exceptions could end up being overwritten.

  • gh-105375: Fix bug in the compiler where an exception could end up being overwritten.

  • gh-105375: Improve error handling in PyUnicode_BuildEncodingMap() where an exception could end up being overwritten.

  • gh-105486: Change the repr of ParamSpec list of args in types.GenericAlias.

  • gh-105678: Break the MAKE_FUNCTION instruction into two parts, MAKE_FUNCTION which makes the function and SET_FUNCTION_ATTRIBUTE which sets the attributes on the function. This makes the stack effect of MAKE_FUNCTION regular to ease optimization and code generation.

  • gh-105435: Fix spurious newline character if file ends on a comment without a newline. Patch by Pablo Galindo

  • gh-105390: Correctly raise tokenize.TokenError exceptions instead of SyntaxError for tokenize errors such as incomplete input. Patch by Pablo Galindo

  • gh-105259: Don’t include newline character for trailing NEWLINE tokens emitted in the tokenize module. Patch by Pablo Galindo

  • gh-104635: Eliminate redundant STORE_FAST instructions in the compiler. Patch by Donghee Na and Carl Meyer.

  • gh-105324: Fix the main function of the tokenize module when reading from sys.stdin. Patch by Pablo Galindo

  • gh-33092: Simplify and speed up interpreter for f-strings. Removes FORMAT_VALUE opcode. Add CONVERT_VALUE, FORMAT_SIMPLE and FORMAT_WITH_SPEC opcode. Compiler emits more efficient sequence for each format expression.

  • gh-105229: Remove remaining two-codeunit superinstructions. All remaining superinstructions only take a single codeunit, simplifying instrumentation and quickening.

  • gh-105235: Prevent out-of-bounds memory access during mmap.find() calls.

  • gh-98963: Restore the ability for a subclass of property to define __slots__ or otherwise be dict-less by ignoring failures to set a docstring on such a class. This behavior had regressed in 3.12beta1. An AttributeError where there had not previously been one was disruptive to existing code.

  • gh-104812: The “pending call” machinery now works for all interpreters, not just the main interpreter, and runs in all threads, not just the main thread. Some calls are still only done in the main thread, ergo in the main interpreter. This change does not affect signal handling nor the existing public C-API (Py_AddPendingCall()), which both still only target the main thread. The new functionality is meant strictly for internal use for now, since consequences of its use are not well understood yet outside some very restricted cases. This change brings the capability in line with the intention when the state was made per-interpreter several years ago.

  • gh-105194: Do not escape with backslashes f-string format specifiers. Patch by Pablo Galindo

  • gh-105229: Replace some dynamic superinstructions with single instruction equivalents.

  • gh-105162: Fixed bug in generator.close()/throw() where an inner iterator would be ignored when the outer iterator was instrumented.

  • gh-105164: Ensure annotations are set up correctly if the only annotation in a block is within a match block. Patch by Jelle Zijlstra.

  • gh-105148: Make _PyASTOptimizeState internal to ast_opt.c. Make _PyAST_Optimize take two integers instead of a pointer to this struct. This avoids the need to include pycore_compile.h in ast_opt.c.

  • gh-104799: Attributes of ast nodes that are lists now default to the empty list if omitted. This means that some code that previously raised TypeError when the AST node was used will now proceed with the empty list instead. Patch by Jelle Zijlstra.

  • gh-105111: Remove the old trashcan macros Py_TRASHCAN_SAFE_BEGIN and Py_TRASHCAN_SAFE_END. They should be replaced by the new macros Py_TRASHCAN_BEGIN and Py_TRASHCAN_END.

  • gh-105035: Fix super() calls on types with custom tp_getattro implementation (e.g. meta-types.)

  • gh-105017: Show CRLF lines in the tokenize string attribute in both NL and NEWLINE tokens. Patch by Marta Gómez.

  • gh-105013: Fix handling of multiline parenthesized lambdas in inspect.getsource(). Patch by Pablo Galindo

  • gh-105017: Do not include an additional final NL token when parsing files having CRLF lines. Patch by Marta Gómez.

  • gh-104976: Ensure that trailing DEDENT tokenize.TokenInfo objects emitted by the tokenize module are reported as in Python 3.11. Patch by Pablo Galindo

  • gh-104972: Ensure that the line attribute in tokenize.TokenInfo objects in the tokenize module are always correct. Patch by Pablo Galindo

  • gh-104955: Fix signature for the new __release_buffer__() slot. Patch by Jelle Zijlstra.

  • gh-104690: Starting new threads and process creation through os.fork() during interpreter shutdown (such as from atexit handlers) is no longer supported. It can lead to race condition between the main Python runtime thread freeing thread states while internal threading routines are trying to allocate and use the state of just created threads. Or forked children trying to use the mid-shutdown runtime and thread state in the child process.

  • gh-104879: Fix crash when accessing the __module__ attribute of type aliases defined outside a module. Patch by Jelle Zijlstra.

  • gh-104825: Tokens emitted by the tokenize module do not include an implicit \n character in the line attribute anymore. Patch by Pablo Galindo

  • gh-104770: If a generator returns a value upon being closed, the value is now returned by generator.close().

  • gh-89091: Raise RuntimeWarning for unawaited async generator methods like asend(), athrow() and aclose(). Patch by Kumar Aditya.

  • gh-96663: Add a better, more introspect-able error message when setting attributes on classes without a __dict__ and no slot member for the attribute.

  • gh-93627: Update the Python pickle module implementation to match the C implementation of the pickle module. For objects setting reduction methods like __reduce_ex__() or __reduce__() to None, pickling will result in a TypeError.

  • gh-101006: Improve error handling when read marshal data.

  • gh-91095: Specializes calls to most Python classes. Specifically, any class that inherits from object, or another Python class, and does not override __new__.

    The specialized instruction does the following:

    1. Creates the object (by calling object.__new__)

    2. Pushes a shim frame to the frame stack (to cleanup after __init__)

    3. Pushes the frame for __init__ to the frame stack

    Speeds up the instantiation of most Python classes.

Library

  • gh-110786: sysconfig’s CLI now ignores BrokenPipeError, making it exit normally if its output is being piped and the pipe closes.

  • gh-103480: The sysconfig module is now a package, instead of a single-file module.

  • gh-110733: Micro-optimization: Avoid calling min(), max() in BaseEventLoop._run_once().

  • gh-94597: Added asyncio.EventLoop for use with the asyncio.run() loop_factory kwarg to avoid calling the asyncio policy system.

  • gh-110682: runtime-checkable protocols used to consider __match_args__ a protocol member in __instancecheck__ if it was present on the protocol. Now, this attribute is ignored if it is present.

  • gh-110488: Fix a couple of issues in pathlib.PurePath.with_name(): a single dot was incorrectly considered a valid name, and in PureWindowsPath, a name with an NTFS alternate data stream, like a:b, was incorrectly considered invalid.

  • gh-110590: Fix a bug in _sre.compile() where TypeError would be overwritten by OverflowError when the code argument was a list of non-ints.

  • gh-65052: Prevent pdb from crashing when trying to display undisplayable objects

  • gh-110519: Deprecation warning about non-integer number in gettext now always refers to the line in the user code where gettext function or method is used. Previously it could refer to a line in gettext code.

  • gh-89902: Deprecate non-standard format specifier “N” for decimal.Decimal. It was not documented and only supported in the C implementation.

  • gh-110378: contextmanager() and asynccontextmanager() context managers now close an invalid underlying generator object that yields more then one value.

  • gh-106670: In pdb, set convenience variable $_exception for post mortem debugging.

  • gh-110365: Fix termios.tcsetattr() bug that was overwriting existing errors during parsing integers from term list.

  • gh-109653: Slightly improve the import time of several standard-library modules by deferring imports of warnings within those modules. Patch by Alex Waygood.

  • gh-110273: dataclasses.replace() now raises TypeError instead of ValueError if specify keyword argument for a field declared with init=False or miss keyword argument for required InitVar field.

  • gh-110249: Add --inline-caches flag to dis command line.

  • gh-109653: Fix a Python 3.12 regression in the import time of random. Patch by Alex Waygood.

  • gh-110222: Add support of struct sequence objects in copy.replace(). Patched by Xuehai Pan.

  • gh-109649: multiprocessing, concurrent.futures, compileall: Replace os.cpu_count() with os.process_cpu_count() to select the default number of worker threads and processes. Get the CPU affinity if supported. Patch by Victor Stinner.

  • gh-110150: Fix base case handling in statistics.quantiles. Now allows a single data point.

  • gh-110036: On Windows, multiprocessing Popen.terminate() now catches PermissionError and get the process exit code. If the process is still running, raise again the PermissionError. Otherwise, the process terminated as expected: store its exit code. Patch by Victor Stinner.

  • gh-110038: Fixed an issue that caused KqueueSelector.select() to not return all the ready events in some cases when a file descriptor is registered for both read and write.

  • gh-110045: Update the symtable module to support the new scopes introduced by PEP 695.

  • gh-88402: Add new variables to sysconfig.get_config_vars() on Windows: LIBRARY, LDLIBRARY, LIBDIR, SOABI, and Py_NOGIL.

  • gh-109631: re functions such as re.findall(), re.split(), re.search() and re.sub() which perform short repeated matches can now be interrupted by user.

  • gh-109653: Reduce the import time of email.utils by around 43%. This results in the import time of email.message falling by around 18%, which in turn reduces the import time of importlib.metadata by around 6%. Patch by Alex Waygood.

  • gh-109818: Fix reprlib.recursive_repr() not copying __type_params__ from decorated function.

  • gh-109047: concurrent.futures: The executor manager thread now catches exceptions when adding an item to the call queue. During Python finalization, creating a new thread can now raise RuntimeError. Catch the exception and call terminate_broken() in this case. Patch by Victor Stinner.

  • gh-109782: Ensure the signature of os.path.isdir() is identical on all platforms. Patch by Amin Alaee.

  • gh-109653: Improve import time of functools by around 13%. Patch by Alex Waygood.

  • gh-109590: shutil.which() will prefer files with an extension in PATHEXT if the given mode includes os.X_OK on win32. If no PATHEXT match is found, a file without an extension in PATHEXT can be returned. This change will have shutil.which() act more similarly to previous behavior in Python 3.11.

  • gh-109653: Reduce the import time of enum by over 50%. Patch by Alex Waygood.

  • gh-109593: Avoid deadlocking on a reentrant call to the multiprocessing resource tracker. Such a reentrant call, though unlikely, can happen if a GC pass invokes the finalizer for a multiprocessing object such as SemLock.

  • gh-109653: Reduce the import time of typing by around a third. Patch by Alex Waygood.

  • gh-109649: Add os.process_cpu_count() function to get the number of logical CPUs usable by the calling thread of the current process. Patch by Victor Stinner.

  • gh-74481: Add set_error_mode related constants in msvcrt module in Python debug build.

  • gh-109613: Fix os.stat() and os.DirEntry.stat(): check for exceptions. Previously, on Python built in debug mode, these functions could trigger a fatal Python error (and abort the process) when a function succeeded with an exception set. Patch by Victor Stinner.

  • gh-109599: Expose the type of PyCapsule objects as types.CapsuleType.

  • gh-109109: You can now get the raw TLS certificate chains from TLS connections via ssl.SSLSocket.get_verified_chain() and ssl.SSLSocket.get_unverified_chain() methods.

    Contributed by Mateusz Nowak.

  • gh-109559: Update unicodedata database to Unicode 15.1.0.

  • gh-109543: Remove unnecessary hasattr() check during typing.TypedDict creation.

  • gh-109495: Remove unnecessary extra __slots__ in datetime's pure python implementation to reduce memory size, as they are defined in the superclass. Patch by James Hilton-Balfe

  • gh-109461: logging: Use a context manager for lock acquisition.

  • gh-109096: http.server.CGIHTTPRequestHandler has been deprecated for removal in 3.15. Its design is old and the web world has long since moved beyond CGI.

  • gh-109409: Fix error when it was possible to inherit a frozen dataclass from multiple parents some of which were possibly not frozen.

  • gh-109375: The pdb alias command now prevents registering aliases without arguments.

  • gh-109319: Deprecate the dis.HAVE_ARGUMENT field in favour of dis.hasarg.

  • gh-107219: Fix a race condition in concurrent.futures. When a process in the process pool was terminated abruptly (while the future was running or pending), close the connection write end. If the call queue is blocked on sending bytes to a worker process, closing the connection write end interrupts the send, so the queue can be closed. Patch by Victor Stinner.

  • gh-66143: The codecs.CodecInfo object has been made copyable and pickleable. Patched by Robert Lehmann and Furkan Onder.

  • gh-109187: pathlib.Path.resolve() now treats symlink loops like other errors: in strict mode, OSError is raised, and in non-strict mode, no exception is raised.

  • gh-50644: Attempts to pickle or create a shallow or deep copy of codecs streams now raise a TypeError. Previously, copying failed with a RecursionError, while pickling produced wrong results that eventually caused unpickling to fail with a RecursionError.

  • gh-109174: Add support of types.SimpleNamespace in copy.replace().

  • gh-109164: pdb: Replace getopt with argparse for parsing command line arguments.

  • gh-109151: Enable readline editing features in the sqlite3 command-line interface (python -m sqlite3).

  • gh-108987: Fix _thread.start_new_thread() race condition. If a thread is created during Python finalization, the newly spawned thread now exits immediately instead of trying to access freed memory and lead to a crash. Patch by Victor Stinner.

  • gh-108682: Enum: require names=() or type=... to create an empty enum using the functional syntax.

  • gh-109033: Exceptions raised by os.utime builtin function now include the related filename

  • gh-108843: Fix an issue in ast.unparse() when unparsing f-strings containing many quote types.

  • gh-108469: ast.unparse() now supports new f-string syntax introduced in Python 3.12. Note that the f-string quotes are reselected for simplicity under the new syntax. (Patch by Steven Sun)

  • gh-108751: Add copy.replace() function which allows to create a modified copy of an object. It supports named tuples, dataclasses, and many other objects.

  • gh-108682: Enum: raise TypeError if super().__new__() is called from a custom __new__.

  • gh-108278: Deprecate passing the callback callable by keyword for the following sqlite3.Connection APIs:

    The affected parameters will become positional-only in Python 3.15.

    Patch by Erlend E. Aasland.

  • gh-105829: Fix concurrent.futures.ProcessPoolExecutor deadlock

  • gh-108295: Fix crashes related to use of weakrefs on typing.TypeVar.

  • gh-108463: Make expressions/statements work as expected in pdb

  • gh-108277: Add os.timerfd_create(), os.timerfd_settime(), os.timerfd_gettime(), os.timerfd_settime_ns(), and os.timerfd_gettime_ns() to provide a low level interface for Linux’s timer notification file descriptor.

  • gh-107811: tarfile: extraction of members with overly large UID or GID (e.g. on an OS with 32-bit id_t) now fails in the same way as failing to set the ID.

  • gh-64662: Fix support for virtual tables in sqlite3.Connection.iterdump(). Patch by Aviv Palivoda.

  • gh-108111: Fix a regression introduced in gh-101251 for 3.12, resulting in an incorrect offset calculation in gzip.GzipFile.seek().

  • gh-108294: time.sleep() now raises an auditing event.

  • gh-108278: Deprecate passing name, number of arguments, and the callable as keyword arguments, for the following sqlite3.Connection APIs:

    The affected parameters will become positional-only in Python 3.15.

    Patch by Erlend E. Aasland.

  • gh-108322: Speed-up NormalDist.samples() by using the inverse CDF method instead of calling random.gauss().

  • gh-83417: Add the ability for venv to create a .gitignore file which causes the created environment to be ignored by Git. It is on by default when venv is called via its CLI.

  • gh-105736: Harmonized the pure Python version of OrderedDict with the C version. Now, both versions set up their internal state in __new__. Formerly, the pure Python version did the set up in __init__.

  • gh-108083: Fix bugs in the constructor of sqlite3.Connection and sqlite3.Connection.close() where exceptions could be leaked. Patch by Erlend E. Aasland.

  • gh-107932: Fix dis module to properly report and display bytecode that do not have source lines.

  • gh-105539: sqlite3 now emits an ResourceWarning if a sqlite3.Connection object is not closed explicitly. Patch by Erlend E. Aasland.

  • gh-107995: The __module__ attribute on instances of functools.cached_property is now set to the name of the module in which the cached_property is defined, rather than “functools”. This means that doctests in cached_property docstrings are now properly collected by the doctest module. Patch by Tyler Smart.

  • gh-107963: Fix multiprocessing.set_forkserver_preload() to check the given list of modules names. Patch by Donghee Na.

  • gh-106242: Fixes os.path.normpath() to handle embedded null characters without truncating the path.

  • gh-81555: xml.dom.minidom now only quotes " in attributes.

  • gh-50002: xml.dom.minidom now preserves whitespaces in attributes.

  • gh-93057: Passing more than one positional argument to sqlite3.connect() and the sqlite3.Connection constructor is deprecated. The remaining parameters will become keyword-only in Python 3.15. Patch by Erlend E. Aasland.

  • gh-76913: Add merge_extra parameter/feature to logging.LoggerAdapter

  • gh-107913: Fix possible losses of errno and winerror values in OSError exceptions if they were cleared or modified by the cleanup code before creating the exception object.

  • gh-107845: tarfile.data_filter() now takes the location of symlinks into account when determining their target, so it will no longer reject some valid tarballs with LinkOutsideDestinationError.

  • gh-107812: Extend socket’s netlink support to the FreeBSD platform.

  • gh-107805: Fix signatures of module-level generated functions in turtle.

  • gh-107782: pydoc is now able to show signatures which are not representable in Python, e.g. for getattr and dict.pop.

  • gh-56166: Deprecate passing optional arguments maxsplit, count and flags in module-level functions re.split(), re.sub() and re.subn() as positional. They should only be passed by keyword.

  • gh-107710: Speed up logging.getHandlerNames().

  • gh-107715: Fix doctest.DocTestFinder.find() in presence of class names with special characters. Patch by Gertjan van Zwieten.

  • gh-100814: Passing a callable object as an option value to a Tkinter image now raises the expected TclError instead of an AttributeError.

  • gh-72684: Add tkinter widget methods: tk_busy_hold(), tk_busy_configure(), tk_busy_cget(), tk_busy_forget(), tk_busy_current(), and tk_busy_status().

  • gh-106684: Raise ResourceWarning when asyncio.StreamWriter is not closed leading to memory leaks. Patch by Kumar Aditya.

  • gh-107465: Add pathlib.Path.from_uri() classmethod.

  • gh-107077: Seems that in some conditions, OpenSSL will return SSL_ERROR_SYSCALL instead of SSL_ERROR_SSL when a certification verification has failed, but the error parameters will still contain ERR_LIB_SSL and SSL_R_CERTIFICATE_VERIFY_FAILED. We are now detecting this situation and raising the appropriate ssl.SSLCertVerificationError. Patch by Pablo Galindo

  • gh-107576: Fix types.get_original_bases() to only return __orig_bases__ if it is present on cls directly. Patch by James Hilton-Balfe.

  • gh-105481: Remove opcode.is_pseudo, opcode.MIN_PSEUDO_OPCODE and opcode.MAX_PSEUDO_OPCODE, which were added in 3.12, were never documented and were not intended to be used externally.

  • gh-105481: opcode.ENABLE_SPECIALIZATION (which was added in 3.12 but never documented or intended for external usage) is moved to _opcode.ENABLE_SPECIALIZATION where tests can access it.

  • gh-107396: tarfiles; Fixed use before assignment of self.exception for gzip decompression

  • gh-107409: Set __wrapped__ attribute in reprlib.recursive_repr().

  • gh-107406: Implement new __repr__() method for struct.Struct. Now it returns Struct(<format repr>).

  • gh-107369: Optimize textwrap.indent(). It is ~30% faster for large input. Patch by Inada Naoki.

  • gh-78722: Fix issue where pathlib.Path.iterdir() did not raise OSError until iterated.

  • gh-105578: Deprecate typing.AnyStr in favor of the new Type Parameter syntax. See PEP 695.

  • gh-62519: Make gettext.pgettext() search plural definitions when translation is not found.

  • gh-107089: Shelves opened with shelve.open() have a much faster clear() method. Patch by James Cave.

  • gh-82500: Fix overflow on 32-bit systems with asyncio os.sendfile() implementation.

  • gh-83006: Document behavior of shutil.disk_usage() for non-mounted filesystems on Unix.

  • gh-65495: Use lowercase mail from and rcpt to in smptlib.SMTP.

  • gh-106186: Do not report MultipartInvariantViolationDefect defect when the email.parser.Parser class is used to parse emails with headersonly=True.

  • gh-105002: Fix invalid result from PurePath.relative_to() method when attempting to walk a “..” segment in other with walk_up enabled. A ValueError exception is now raised in this case.

  • gh-106739: Add the rtype_cache to the warning message (as an addition to the type of leaked objects and the number of leaked objects already included in the message) to make debugging leaked objects easier when the multiprocessing resource tracker process finds leaked objects at shutdown. This helps more quickly identify what was leaked and/or why the leaked object was not properly cleaned up.

  • gh-106751: Optimize SelectSelector.select() for many iteration case. Patch By Donghee Na.

  • gh-106751: Optimize _PollLikeSelector.select() for many iteration case.

  • gh-106751: Optimize KqueueSelector.select() for many iteration case. Patch By Donghee Na.

  • gh-106831: Fix potential missing NULL check of d2i_SSL_SESSION result in _ssl.c.

  • gh-105481: The various opcode lists in the dis module are now generated from bytecodes.c instead of explicitly constructed in opcode.py.

  • gh-106727: Make inspect.getsource() smarter for class for same name definitions

  • gh-106789: Remove import of pprint from sysconfig.

  • gh-105726: Added __slots__ to contextlib.AbstractContextManager and contextlib.AbstractAsyncContextManager so that child classes can use __slots__.

  • gh-106774: Update the bundled copy of pip to version 23.2.1.

  • gh-106751: selectors: Optimize EpollSelector.select() code by moving some code outside of the loop.

  • gh-106752: Fixed several bugs in zipfile.Path, including: in zipfile.Path.match(), Windows separators are no longer honored (and never were meant to be); Fixed name/suffix/suffixes/stem operations when no filename is present and the Path is not at the root of the zipfile; Reworked glob for performance and more correct matching behavior.

  • gh-105293: Remove call to SSL_CTX_set_session_id_context during client side context creation in the ssl module.

  • gh-106734: Disable tab completion in multiline mode of pdb

  • gh-105481: Expose opcode metadata through _opcode.

  • gh-106670: Add the new exceptions command to the Pdb debugger. It makes it possible to move between chained exceptions when using post mortem debugging.

  • gh-106602: Add __copy__ and __deepcopy__ in enum

  • gh-106664: selectors: Add _SelectorMapping.get() method and optimize _SelectorMapping.__getitem__().

  • gh-106628: Speed up parsing of emails by about 20% by not compiling a new regular expression for every single email.

  • gh-89427: Set the environment variable VIRTUAL_ENV_PROMPT at venv activation, even when VIRTUAL_ENV_DISABLE_PROMPT is set.

  • gh-106530: Revert a change to colorsys.rgb_to_hls() that caused division by zero for certain almost-white inputs. Patch by Terry Jan Reedy.

  • gh-106584: Fix exit code for unittest if all tests are skipped. Patch by Egor Eliseev.

  • gh-106566: Optimize (?!) (pattern which always fails) in regular expressions.

  • gh-106554: selectors: Reduce Selector overhead by using a dict.get() to lookup file descriptors.

  • gh-106558: Remove ref cycle in callers of convert_to_error() by deleting result from scope in a finally block.

  • gh-100502: Add pathlib.PurePath.pathmod class attribute that stores the implementation of os.path used for low-level path operations: either posixpath or ntpath.

  • gh-106527: Reduce overhead to add and remove asyncio readers and writers.

  • gh-106524: Fix crash in _sre.template() with templates containing invalid group indices.

  • gh-106531: Removed _legacy and the names it provided from importlib.resources: Resource, contents, is_resource, open_binary, open_text, path, read_binary, and read_text.

  • gh-106052: re module: fix the matching of possessive quantifiers in the case of a subpattern containing backtracking.

  • gh-106510: Improve debug output for atomic groups in regular expressions.

  • gh-106503: Fix ref cycle in asyncio._SelectorSocketTransport by removing _write_ready in close.

  • gh-105497: Fix flag mask inversion when unnamed flags exist.

  • gh-90876: Prevent multiprocessing.spawn from failing to import in environments where sys.executable is None. This regressed in 3.11 with the addition of support for path-like objects in multiprocessing.

  • gh-106403: Instances of typing.TypeVar, typing.ParamSpec, typing.ParamSpecArgs, typing.ParamSpecKwargs, and typing.TypeVarTuple once again support weak references, fixing a regression introduced in Python 3.12.0 beta 1. Patch by Jelle Zijlstra.

  • gh-89812: Add private pathlib._PathBase class, which provides experimental support for virtual filesystems, and may be made public in a future version of Python.

  • gh-106292: Check for an instance-dict cached value in the __get__() method of functools.cached_property(). This better matches the pre-3.12 behavior and improves compatibility for users subclassing functools.cached_property() and adding a __set__() method.

  • gh-106350: Detect possible memory allocation failure in the libtommath function mp_init() used by the _tkinter module.

  • gh-106330: Fix incorrect matching of empty paths in pathlib.PurePath.match(). This bug was introduced in Python 3.12.0 beta 1.

  • gh-106309: Deprecate typing.no_type_check_decorator(). No major type checker ever added support for this decorator. Patch by Alex Waygood.

  • gh-102541: Make pydoc.doc() catch bad module ImportError when output stream is not None.

  • gh-106263: Fix crash when calling repr with a manually constructed SignalDict object. Patch by Charlie Zhao.

  • gh-106236: Replace assert statements with raise RuntimeError in threading, so that _DummyThread cannot be joined even with -OO.

  • gh-106238: Fix rare concurrency bug in lock acquisition by the logging package.

  • gh-106152: Added PY_THROW event hook for cProfile for generators

  • gh-106075: Added asyncio.taskgroups.__all__ to asyncio.__all__ for export in star imports.

  • gh-104527: Zipapp will now skip over appending an archive to itself.

  • gh-106046: Improve the error message from os.fspath() if called on an object where __fspath__ is set to None. Patch by Alex Waygood.

  • gh-105987: Fix crash due to improper reference counting in asyncio eager task factory internal routines.

  • gh-105974: Fix bug where a typing.Protocol class that had one or more non-callable members would raise TypeError when issubclass() was called against it, even if it defined a custom __subclasshook__ method. The behaviour in Python 3.11 and lower – which has now been restored – was not to raise TypeError in these situations if a custom __subclasshook__ method was defined. Patch by Alex Waygood.

  • gh-96145: Reverted addition of json.AttrDict.

  • gh-89812: Add pathlib.UnsupportedOperation, which is raised instead of NotImplementedError when a path operation isn’t supported.

  • gh-105808: Fix a regression introduced in gh-101251 for 3.12, causing gzip.GzipFile.flush() to not flush the compressor (nor pass along the zip_mode argument).

  • gh-105481: stack_effect() no longer raises an exception if an oparg is provided for an opcode that doesn’t use its arg, or when it is not provided for an opcode that does use it. In the latter case, the stack effect is returned for oparg=0.

  • gh-104799: Enable ast.unparse() to unparse function and class definitions created without the new type_params field from PEP 695. Patch by Jelle Zijlstra.

  • gh-105793: Add follow_symlinks keyword-only argument to pathlib.Path.is_dir() and is_file(), defaulting to True.

  • gh-105570: Deprecate two methods of creating typing.TypedDict classes with 0 fields using the functional syntax: TD = TypedDict("TD") and TD = TypedDict("TD", None). Both will be disallowed in Python 3.15. To create a TypedDict class with 0 fields, either use class TD(TypedDict): pass or TD = TypedDict("TD", {}).

  • gh-105745: Fix webbrowser.Konqueror.open method.

  • gh-105733: ctypes: Deprecate undocumented ctypes.SetPointerType() and ctypes.ARRAY() functions. Patch by Victor Stinner.

  • gh-105687: Remove deprecated re.template, re.T, re.TEMPLATE, sre_constans.SRE_FLAG_TEMPLATE.

  • gh-105684: Supporting asyncio.Task.set_name() is now mandatory for third party task implementations. The undocumented _set_task_name() function (deprecated since 3.8) has been removed. Patch by Kumar Aditya.

  • gh-105375: Fix a bug in _Unpickler_SetInputStream() where an exception could end up being overwritten in case of failure.

  • gh-105626: Change the default return value of http.client.HTTPConnection.get_proxy_response_headers() to be None and not {}.

  • gh-105375: Fix bugs in sys where exceptions could end up being overwritten because of deferred error handling.

  • gh-105605: Harden pyexpat error handling during module initialisation to prevent exceptions from possibly being overwritten, and objects from being dereferenced twice.

  • gh-105375: Fix bug in decimal where an exception could end up being overwritten.

  • gh-105375: Fix bugs in _datetime where exceptions could be overwritten in case of module initialisation failure.

  • gh-105375: Fix bugs in _ssl initialisation which could lead to leaked references and overwritten exceptions.

  • gh-105375: Fix a bug in array.array where an exception could end up being overwritten.

  • gh-105375: Fix bugs in _ctypes where exceptions could end up being overwritten.

  • gh-105375: Fix a bug in the posix module where an exception could be overwritten.

  • gh-105375: Fix bugs in _elementtree where exceptions could be overwritten.

  • gh-105375: Fix bugs in zoneinfo where exceptions could be overwritten.

  • gh-105375: Fix bugs in errno where exceptions could be overwritten.

  • gh-105566: Deprecate creating a typing.NamedTuple class using keyword arguments to denote the fields (NT = NamedTuple("NT", x=int, y=str)). This will be disallowed in Python 3.15. Use the class-based syntax or the functional syntax instead.

    Two methods of creating NamedTuple classes with 0 fields using the functional syntax are also deprecated, and will be disallowed in Python 3.15: NT = NamedTuple("NT") and NT = NamedTuple("NT", None). To create a NamedTuple class with 0 fields, either use class NT(NamedTuple): pass or NT = NamedTuple("NT", []).

  • gh-105545: Remove deprecated in 3.11 webbrowser.MacOSXOSAScript._name attribute.

  • gh-105497: Fix flag inversion when alias/mask members exist.

  • gh-105509: typing.Annotated is now implemented as an instance of typing._SpecialForm rather than a class. This should have no user-facing impact for users of the typing module public API.

  • gh-105375: Fix bugs in pickle where exceptions could be overwritten.

  • gh-70303: Emit FutureWarning from pathlib.Path.glob() and rglob() if the given pattern ends with “**”. In a future Python release, patterns with this ending will match both files and directories. Add a trailing slash to only match directories.

  • gh-105375: Fix a bug in sqlite3 where an exception could be overwritten in the collation callback.

  • gh-105382: Remove cafile, capath and cadefault parameters of the urllib.request.urlopen() function, deprecated in Python 3.6. Patch by Victor Stinner.

  • gh-105376: logging: Remove undocumented and untested Logger.warn() and LoggerAdapter.warn() methods and logging.warn() function. Deprecated since Python 3.3, they were aliases to the logging.Logger.warning() method, logging.LoggerAdapter.warning() method and logging.warning() function. Patch by Victor Stinner.

  • gh-105332: Revert pickling method from by-name back to by-value.

  • gh-104554: Add RTSPS scheme support in urllib.parse

  • gh-105292: Add option to traceback.format_exception_only() to recurse into the nested exception of a BaseExceptionGroup.

  • gh-105280: Fix bug where isinstance([], collections.abc.Mapping) could evaluate to True if garbage collection happened at the wrong time. The bug was caused by changes to the implementation of typing.Protocol in Python 3.12.

  • gh-80480: array: Add 'w' typecode that represents Py_UCS4.

  • gh-105239: Fix longstanding bug where issubclass(object, typing.Protocol) would evaluate to True in some edge cases. Patch by Alex Waygood.

  • gh-104310: In the beta 1 release we added a utility function for extension module authors, to use when testing their module for support in multiple interpreters or under a per-interpreter GIL. The name of that function has changed from allowing_all_extensions to _incompatible_extension_module_restrictions. The default for the “disable_check” argument has change from True to False, to better match the new function name.

  • gh-105080: Fixed inconsistent signature on derived classes for inspect.signature()

  • gh-105144: Fix a recent regression in the typing module. The regression meant that doing class Foo(X, typing.Protocol), where X was a class that had abc.ABCMeta as its metaclass, would then cause subsequent isinstance(1, X) calls to erroneously raise TypeError. Patch by Alex Waygood.

  • gh-62948: The io.IOBase finalizer now logs the close() method errors with sys.unraisablehook. Previously, errors were ignored silently by default, and only logged in Python Development Mode or on Python built on debug mode. Patch by Victor Stinner.

  • gh-105096: wave: Deprecate the getmark(), setmark() and getmarkers() methods of the wave.Wave_read and wave.Wave_write classes. They will be removed in Python 3.15. Patch by Victor Stinner.

  • gh-104992: Remove the untested and undocumented unittest.TestProgram.usageExit() method, deprecated in Python 3.11. Patch by Hugo van Kemenade.

  • gh-104996: Improve performance of pathlib.PurePath initialisation by deferring joining of paths when multiple arguments are given.

  • gh-101588: Deprecate undocumented copy/deepcopy/pickle support for itertools.

  • gh-103631: Fix pathlib.PurePosixPath(pathlib.PureWindowsPath(...)) not converting path separators to restore 3.11 compatible behavior.

  • gh-104947: Make comparisons between pathlib.PureWindowsPath objects consistent across Windows and Posix to match 3.11 behavior.

  • gh-104773: PEP 594: Remove the audioop module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the aifc module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the uu module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104935: Fix bugs with the interaction between typing.runtime_checkable() and typing.Generic that were introduced by the PEP 695 implementation. Patch by Jelle Zijlstra.

  • gh-104773: PEP 594: Remove the crypt module and its private _crypt extension, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the nis module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104898: Add missing __slots__ to os.PathLike.

  • gh-104773: PEP 594: Remove the xdrlib module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the nntplib module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104886: Remove the undocumented configparser.LegacyInterpolation class, deprecated in the docstring since Python 3.2, and with a deprecation warning since Python 3.11. Patch by Hugo van Kemenade.

  • gh-104786: Remove kwargs-based typing.TypedDict creation

  • gh-104876: Remove the turtle.RawTurtle.settiltangle() method, deprecated in docs since Python 3.1 and with a deprecation warning since Python 3.11. Patch by Hugo van Kemenade.

  • gh-104773: PEP 594: Removed the msilib package, deprecated in Python 3.11.

  • gh-104773: PEP 594: Remove the spwd module, deprecated in Python 3.11: the python-pam project can be used instead. Patch by Victor Stinner.

  • gh-75552: Removed the tkinter.tix module, deprecated since Python 3.6.

  • gh-104773: PEP 594: Remove the chunk module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the mailcap module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the sunau module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104780: PEP 594: Remove the ossaudiodev module, deprecated in Python 3.11. Patch Victor Stinner.

  • gh-104773: PEP 594: Remove the pipes module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104873: Add typing.get_protocol_members() to return the set of members defining a typing.Protocol. Add typing.is_protocol() to check whether a class is a typing.Protocol. Patch by Jelle Zijlstra.

  • gh-104874: Document the __name__ and __supertype__ attributes of typing.NewType. Patch by Jelle Zijlstra.

  • gh-104835: Removed the following unittest functions, deprecated in Python 3.11:

    • unittest.findTestCases()

    • unittest.makeSuite()

    • unittest.getTestCaseNames()

    Use TestLoader methods instead:

    Patch by Hugo van Kemenade.

  • gh-104804: Remove the untested and undocumented webbrowser MacOSX class, deprecated in Python 3.11. Patch by Hugo van Kemenade.

  • gh-83863: Support for using pathlib.Path objects as context managers has been removed. Before Python 3.9, exiting the context manager marked a path as “closed”, which caused some (but not all!) methods to raise when called. Since Python 3.9, using a path as a context manager does nothing.

  • gh-104799: Adjust the location of the (see PEP 695) type_params field on ast.ClassDef, ast.AsyncFunctionDef, and ast.FunctionDef to better preserve backward compatibility. Patch by Jelle Zijlstra

  • gh-104797: Allow typing.Protocol classes to inherit from collections.abc.Buffer. Patch by Jelle Zijlstra.

  • gh-104783: Remove locale.resetlocale() function deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104780: Remove the 2to3 program and the lib2to3 module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the telnetlib module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the imghdr module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the cgi and cgitb modules, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104773: PEP 594: Remove the sndhdr module, deprecated in Python 3.11. Patch by Victor Stinner.

  • gh-104372: On Linux where subprocess can use the vfork() syscall for faster spawning, prevent the parent process from blocking other threads by dropping the GIL while it waits for the vfork’ed child process exec() outcome. This prevents spawning a binary from a slow filesystem from blocking the rest of the application.

  • gh-99108: We now release the GIL around built-in hashlib computations of reasonable size for the SHA families and MD5 hash functions, matching what our OpenSSL backed hash computations already does.

  • gh-102613: Improve performance of pathlib.Path.glob() when expanding a pattern with a non-terminal “**” component by filtering walked paths through a regular expression, rather than calling os.scandir() more than once on each directory.

  • gh-104399: Prepare the _tkinter module for building with Tcl 9.0 and future libtommath by replacing usage of deprecated functions mp_to_unsigned_bin_n() and mp_unsigned_bin_size() when necessary.

  • gh-102676: Add fields start_offset, cache_offset, end_offset, baseopname, baseopcode, jump_target and oparg to dis.Instruction.

  • gh-103558: Fixed parent argument validation mechanism of argparse. Improved test coverage.

  • gh-103464: Provide helpful usage messages when parsing incorrect pdb commands.

  • gh-103384: Generalize the regex pattern BaseConfigurator.INDEX_PATTERN to allow spaces and non-alphanumeric characters in keys.

  • gh-103124: Added multiline statement support for pdb

  • gh-101162: Forbid using builtins.issubclass() with types.GenericAlias as the first argument.

  • gh-103200: Fix cache repopulation semantics of zipimport.invalidate_caches(). The cache is now repopulated upon retrieving files with an invalid cache, not when the cache is invalidated.

  • gh-100061: Fix a bug that causes wrong matches for regular expressions with possessive qualifier.

  • gh-77609: Add follow_symlinks argument to pathlib.Path.glob() and rglob(), defaulting to false.

  • gh-102541: Hide traceback in help() prompt, when import failed.

  • gh-102120: Added a stream mode to tarfile that allows for reading archives without caching info about the inner files.

  • gh-102029: Deprecate passing any arguments to threading.RLock().

  • gh-88233: Refactored zipfile._strip_extra to use higher level abstractions for extras instead of a heavy-state loop.

  • gh-102024: Reduce calls of _idle_semaphore.release() in concurrent.futures.thread._worker().

  • gh-73435: Add support for recursive wildcards in pathlib.PurePath.match().

  • gh-84867: unittest.TestLoader no longer loads test cases from exact unittest.TestCase and unittest.FunctionTestCase classes.

  • gh-99203: Restore following CPython <= 3.10.5 behavior of shutil.make_archive(): do not create an empty archive if root_dir is not a directory, and, in that case, raise FileNotFoundError or NotADirectoryError regardless of format choice. Beyond the brought-back behavior, the function may now also raise these exceptions in dry_run mode.

  • gh-80480: Emit DeprecationWarning for array’s 'u' type code, deprecated in docs since Python 3.3.

  • gh-94924: unittest.mock.create_autospec() now properly returns coroutine functions compatible with inspect.iscoroutinefunction()

  • gh-94777: Fix hanging multiprocessing ProcessPoolExecutor when a child process crashes while data is being written in the call queue.

  • gh-92871: Remove the typing.io and typing.re namespaces, deprecated since Python 3.8. All items are still available from the main typing module.

  • bpo-43633: Improve the textual representation of IPv4-mapped IPv6 addresses (RFC 4291 Sections 2.2, 2.5.5.2) in ipaddress. Patch by Oleksandr Pavliuk.

  • bpo-44850: Improve performance of operator.methodcaller() using the PEP 590 vectorcall convention. Patch by Anthony Lee and Pieter Eendebak.

  • bpo-44185: unittest.mock.mock_open() will call the close() method of the file handle mock when it is exiting from the context manager. Patch by Samet Yaslan.

  • bpo-40988: Improve performance of functools.singledispatchmethod by caching the generated dispatch wrapper. Optimization suggested by frederico. Patch by @mental32, Alex Waygood and Pieter Eendebak.

  • bpo-41768: unittest.mock speccing no longer calls class properties. Patch by Melanie Witt.

  • bpo-18319: Ensure gettext(msg) retrieve translations even if a plural form exists. In other words: gettext(msg) == ngettext(msg, '', 1).

  • bpo-17013: Add ThreadingMock to unittest.mock that can be used to create Mock objects that can wait until they are called. Patch by Karthikeyan Singaravelan and Mario Corchero.

Documentation

Tests

  • gh-110647: Fix test_stress_modifying_handlers() of test_signal. Patch by Victor Stinner.

  • gh-103053: Fix test_tools.test_freeze on FreeBSD: run “make distclean” instead of “make clean” in the copied source directory to remove also the “python” program. Patch by Victor Stinner.

  • gh-110167: Fix a deadlock in test_socket when server fails with a timeout but the client is still running in its thread. Don’t hold a lock to call cleanup functions in doCleanups(). One of the cleanup function waits until the client completes, whereas the client could deadlock if it called addCleanup() in such situation. Patch by Victor Stinner.

  • gh-110388: Add tests for tty.

  • gh-81002: Add tests for termios.

  • gh-110367: regrtest: When using worker processes (-jN) with –verbose3 option, regrtest can now display the worker output even if a worker process does crash. Previously, sys.stdout and sys.stderr were replaced and so the worker output was lost on a crash. Patch by Victor Stinner.

  • gh-110267: Add tests for pickling and copying PyStructSequence objects. Patched by Xuehai Pan.

  • gh-110171: libregrtest now always sets and shows random.seed, so tests are more reproducible. Use --randseed flag to pass the explicit random seed for tests.

  • gh-110152: Remove Tools/scripts/run_tests.py and make hostrunnertest. Just run ./python -m test --slow-ci, make buildbottest or make test instead. Python test runner (regrtest) now handles cross-compilation and HOSTRUNNER. It also adds options to Python such fast -u -E -W default -bb when --fast-ci or --slow-ci option is used. Patch by Victor Stinner.

  • gh-110031: Skip test_threading tests using thread+fork if Python is built with Address Sanitizer (ASAN). Patch by Victor Stinner.

  • gh-110088: Fix test_asyncio timeouts: don’t measure the maximum duration, a test should not measure a CI performance. Only measure the minimum duration when a task has a timeout or delay. Add CLOCK_RES to test_asyncio.utils. Patch by Victor Stinner.

  • gh-109974: Fix race conditions in test_threading lock tests. Wait until a condition is met rather than using time.sleep() with a hardcoded number of seconds. Patch by Victor Stinner.

  • gh-110033: Fix test_interprocess_signal() of test_signal. Make sure that the subprocess.Popen object is deleted before the test raising an exception in a signal handler. Otherwise, Popen.__del__() can get the exception which is logged as Exception ignored in: ... and the test fails. Patch by Victor Stinner.

  • gh-109594: Fix test_timeout() of test_concurrent_futures.test_wait. Remove the future which may or may not complete depending if it takes longer than the timeout or not. Keep the second future which does not complete before wait() timeout. Patch by Victor Stinner.

  • gh-109972: Split test_gdb.py file into a test_gdb package made of multiple tests, so tests can now be run in parallel. Patch by Victor Stinner.

  • gh-109566: regrtest: When --fast-ci or --slow-ci option is used, regrtest now replaces the current process with a new process to add -u -W default -bb -E options to Python. Patch by Victor Stinner.

  • gh-109748: Fix test_zippath_from_non_installed_posix() of test_venv: don’t copy __pycache__/ sub-directories, because they can be modified by other Python tests running in parallel. Patch by Victor Stinner.

  • gh-109739: regrtest: Fix reference leak check on Windows. Disable the load tracker on Windows in the reference leak check mode (-R option). Patch by Victor Stinner.

  • gh-109276: regrtest: When a test fails with “env changed” and the –rerun option is used, the test is now re-run in verbose mode in a fresh process. Patch by Victor Stinner.

  • gh-103053: Skip test_freeze_simple_script() of test_tools.test_freeze if Python is built with ./configure --enable-optimizations, which means with Profile Guided Optimization (PGO): it just makes the test too slow. The freeze tool is tested by many other CIs with other (faster) compiler flags. Patch by Victor Stinner.

  • gh-109580: Skip test_perf_profiler if Python is built with ASAN, MSAN or UBSAN sanitizer. Python does crash randomly in this test on such build. Patch by Victor Stinner.

  • gh-109566: regrtest: Add --fast-ci and --slow-ci options. --fast-ci uses a default timeout of 10 minutes and -u all,-cpu (skip slowest tests). --slow-ci uses a default timeout of 20 minutes and -u all (run all tests). Patch by Victor Stinner.

  • gh-109425: libregrtest now decodes stdout of test worker processes with the “backslashreplace” error handler to log corrupted stdout, instead of failing with an error and not logging the stdout. Patch by Victor Stinner.

  • gh-109396: Fix test_socket.test_hmac_sha1() in FIPS mode. Use a longer key: FIPS mode requires at least of at least 112 bits. The previous key was only 32 bits. Patch by Victor Stinner.

  • gh-104736: Fix test_gdb on Python built with LLVM clang 16 on Linux ppc64le (ex: Fedora 38). Search patterns in gdb “bt” command output to detect when gdb fails to retrieve the traceback. For example, skip a test if Backtrace stopped: frame did not save the PC is found. Patch by Victor Stinner.

  • gh-109276: libregrtest now calls random.seed() before running each test file when -r/--randomize command line option is used. Moreover, it’s also called in worker processes. It should help to make tests more deterministic. Previously, it was only called once in the main process before running all test files and it was not called in worker processes. Patch by Victor Stinner.

  • gh-109276: libregrtest now uses a separated file descriptor to write test result as JSON. Previously, if a test wrote debug messages late around the JSON, the main test process failed to parse JSON. Patch by Victor Stinner.

  • gh-108996: Fix and enable test_msvcrt.

  • gh-109237: Fix test_site.test_underpth_basic() when the working directory contains at least one non-ASCII character: encode the ._pth file to UTF-8 and enable the UTF-8 Mode to use UTF-8 for the child process stdout. Patch by Victor Stinner.

  • gh-109230: Fix test_pyexpat.test_exception(): it can now be run from a directory different than Python source code directory. Before, the test failed in this case. Skip the test if Modules/pyexpat.c source is not available. Skip also the test on Python implementations other than CPython. Patch by Victor Stinner.

  • gh-108996: Add tests for msvcrt.

  • gh-109015: Fix test_asyncio, test_imaplib and test_socket tests on FreeBSD if the TCP blackhole is enabled (sysctl net.inet.tcp.blackhole). Skip the few tests which failed with ETIMEDOUT which such non standard configuration. Currently, the FreeBSD GCP image enables TCP and UDP blackhole (sysctl net.inet.tcp.blackhole=2 and sysctl net.inet.udp.blackhole=1). Patch by Victor Stinner.

  • gh-91960: Skip test_gdb if gdb is unable to retrieve Python frame objects: if a frame is <optimized out>. When Python is built with “clang -Og”, gdb can fail to retrieve the frame parameter of _PyEval_EvalFrameDefault(). In this case, tests like py_bt() are likely to fail. Without getting access to Python frames, python-gdb.py is mostly clueless on retrieving the Python traceback. Moreover, test_gdb is no longer skipped on macOS if Python is built with Clang. Patch by Victor Stinner.

  • gh-108962: Skip test_tempfile.test_flags() if chflags() fails with “OSError: [Errno 45] Operation not supported” (ex: on FreeBSD 13). Patch by Victor Stinner.

  • gh-91960: FreeBSD 13.2 CI coverage for pull requests is now provided by Cirrus-CI (a hosted CI service that supports Linux, macOS, Windows, and FreeBSD).

  • gh-89392: Removed support of test_main() function in tests. They now always use normal unittest test runner.

  • gh-108851: Fix test_tomllib recursion tests for WASI buildbots: reduce the recursion limit and compute the maximum nested array/dict depending on the current available recursion limit. Patch by Victor Stinner.

  • gh-108851: Add get_recursion_available() and get_recursion_depth() functions to the test.support module. Patch by Victor Stinner.

  • gh-108834: Add --fail-rerun option option to regrtest: if a test failed when then passed when rerun in verbose mode, exit the process with exit code 2 (error), instead of exit code 0 (success). Patch by Victor Stinner.

  • gh-108834: Rename regrtest --verbose2 option (-w) to --rerun. Keep --verbose2 as a deprecated alias. Patch by Victor Stinner.

  • gh-108834: When regrtest reruns failed tests in verbose mode (./python -m test --rerun), tests are now rerun in fresh worker processes rather than being executed in the main process. If a test does crash or is killed by a timeout, the main process can detect and handle the killed worker process. Tests are rerun in parallel if the -jN option is used to run tests in parallel. Patch by Victor Stinner.

  • gh-108822: regrtest now computes statistics on all tests: successes, failures and skipped. test_netrc, test_pep646_syntax and test_xml_etree now return results in their test_main() function. Patch by Victor Stinner and Alex Waygood.

  • gh-108794: The doctest.DocTestRunner.run() method now counts the number of skipped tests. Add doctest.DocTestRunner.skips and doctest.TestResults.skipped attributes. Patch by Victor Stinner.

  • gh-108388: Convert test_concurrent_futures to a package of 7 sub-tests. Patch by Victor Stinner.

  • gh-108388: Split test_multiprocessing_fork, test_multiprocessing_forkserver and test_multiprocessing_spawn into test packages. Each package is made of 4 sub-tests: processes, threads, manager and misc. It allows running more tests in parallel and so reduce the total test duration. Patch by Victor Stinner.

  • gh-105776: Fix test_cppext when the C compiler command -std=c11 option: remove -std= options from the compiler command. Patch by Victor Stinner.

  • gh-107652: Set up CIFuzz to run fuzz targets in GitHub Actions. Patch by Illia Volochii.

  • gh-107237: test_logging: Fix test_udp_reconnection() by increasing the timeout from 100 ms to 5 minutes (LONG_TIMEOUT). Patch by Victor Stinner.

  • gh-107178: Add the C API test for functions in the Mapping Protocol, the Sequence Protocol and some functions in the Object Protocol.

  • gh-106714: test_capi: Fix test_no_FatalError_infinite_loop() to no longer write a coredump, by using test.support.SuppressCrashReport. Patch by Victor Stinner.

  • gh-104090: Avoid creating a reference to the test object in collectedDurations().

  • gh-106752: Moved tests for zipfile.Path into Lib/test/test_zipfile/_path. Made zipfile._path a package.

  • gh-106690: Add .coveragerc to cpython repository for use with coverage package.

  • gh-101634: When running the Python test suite with -jN option, if a worker stdout cannot be decoded from the locale encoding report a failed testn so the exitcode is non-zero. Patch by Victor Stinner.

  • gh-105084: When the Python build is configured --with-wheel-pkg-dir, tests requiring the setuptools and wheel wheels will search for the wheels in WHEEL_PKG_DIR.

  • gh-81005: String tests are modified to reflect that str and unicode are merged in Python 3. Patch by Daniel Fortunov.

  • gh-103186: Suppress and assert expected RuntimeWarnings in test_sys_settrace.py

  • gh-69714: Add additional tests to calendar to achieve full test coverage.

Build

  • gh-103053: “make check-clean-src” now also checks if the “python” program is found in the source directory: fail with an error if it does exist. Patch by Victor Stinner.

  • gh-109191: Fix compile error when building with recent versions of libedit.

  • gh-110276: No longer ignore PROFILE_TASK failure silently: command used by Profile Guided Optimization (PGO). Patch by Victor Stinner.

  • gh-109566: Remove make testall target: use make buildbottest instead. Patch by Victor Stinner.

  • gh-109740: The experimental --disable-gil configure flag now includes “t” (for “threaded”) in extension ABI tags.

  • gh-109054: Fix building the _testcapi extension on Linux AArch64 which requires linking to libatomic when <cpython/pyatomic.h> is used: the _Py_atomic_or_uint64() function requires libatomic __atomic_fetch_or_8() on this platform. The configure script now checks if linking to libatomic is needed and generates a new LIBATOMIC variable used to build the _testcapi extension. Patch by Victor Stinner.

  • gh-63760: Fix Solaris build: no longer redefine the gethostname() function. Solaris defines the function since 2005. Patch by Victor Stinner, original patch by Jakub Kulík.

  • gh-108740: Fix a race condition in make regen-all. The deepfreeze.c source and files generated by Argument Clinic are now generated or updated before generating “global objects”. Previously, some identifiers may miss depending on the order in which these files were generated. Patch by Victor Stinner.

  • gh-108634: Python built with configure --with-trace-refs (tracing references) is now ABI compatible with Python release build and debug build. Patch by Victor Stinner.

  • gh-85283: The _stat C extension is now built with the limited C API. Patch by Victor Stinner.

  • gh-108447: Fix x86_64 GNU/Hurd build

  • gh-107814: When calling find_python.bat with -q it did not properly silence the output of nuget. That is now fixed.

  • gh-105481: Remove the make target regen-opcode-targets, merge its work into regen-opcode which repeats most of the calculation. This simplifies the code for the build and reduces code duplication.

  • gh-106881: Check for linux/limits.h before including it in Modules/posixmodule.c.

  • gh-95855: Refactor platform triplet detection code and add detection for MIPS soft float and musl libc.

  • gh-106962: Detect MPI compilers in configure.

  • gh-106118: Fix compilation for platforms without O_CLOEXEC. The issue was introduced with Python 3.12b1 in gh-103295. Patch by Erlend Aasland.

  • gh-105875: SQLite 3.15.2 or newer is required to build the sqlite3 extension module. Patch by Erlend Aasland.

  • gh-90005: Fix a regression in configure where we could end up unintentionally linking with libbsd.

  • gh-102404: Document how to perform a WASI build on Linux. Also add Tools/wasm/build_wasi.sh as a reference implementation of the docs.

  • gh-89886: Autoconf 2.71 and aclocal 1.16.4 is now required to regenerate !configure.

  • gh-104692: Include commoninstall as a prerequisite for bininstall

    This ensures that commoninstall is completed before bininstall is started when parallel builds are used (make -j install), and so the python3 symlink is only installed after all standard library modules are installed.

  • gh-101538: Add experimental wasi-threads support. Patch by Takashi Yamamoto.

Windows

  • gh-110437: Allows overriding the source of VC redistributables so that releases can be guaranteed to never downgrade between updates.

  • gh-109286: Update Windows installer to use SQLite 3.43.1.

  • gh-82367: os.path.realpath() now resolves MS-DOS style file names even if the file is not accessible. Patch by Moonsik Park.

  • gh-109991: Update Windows build to use OpenSSL 3.0.11.

  • gh-106242: Fixes realpath() to behave consistently when passed a path containing an embedded null character on Windows. In strict mode, it now raises OSError instead of the unexpected ValueError, and in non-strict mode will make the path absolute.

  • gh-83180: Changes the Python Launcher for Windows to prefer an active virtual environment when the launched script has a shebang line using a Unix-like virtual command, even if the command requests a specific version of Python.

  • gh-106844: Fix integer overflow and truncating by the null character in _winapi.LCMapStringEx() which affects ntpath.normcase().

  • gh-105436: Ensure that an empty environment block is terminated by two null characters, as is required by Windows.

  • gh-105146: Updated the links at the end of the installer to point to Discourse rather than the mailing lists.

  • gh-103646: When installed from the Microsoft Store, pip no longer defaults to per-user installs. However, as the install directory is unwritable, it should automatically decide to do a per-user install anyway. This should resolve issues when pip is passed an option that conflicts with --user.

  • gh-88745: Improve performance of shutil.copy2() by using the operating system’s CopyFile2 function. This may result in subtle changes to metadata copied along with some files, bringing them in line with normal OS behavior.

  • gh-104820: Fixes stat() and related functions on file systems that do not support file ID requests. This includes FAT32 and exFAT.

  • gh-104803: Add os.path.isdevdrive() to detect whether a path is on a Windows Dev Drive. Returns False on platforms that do not support Dev Drive, and is absent on non-Windows platforms.

macOS

  • gh-109286: Update macOS installer to use SQLite 3.43.1.

  • gh-109991: Update macOS installer to use OpenSSL 3.0.11.

  • gh-99079: Update macOS installer to use OpenSSL 3.0.9.

IDLE

  • gh-104719: Remove IDLE’s modification of tokenize.tabsize and test other uses of tokenize data and methods.

Tools/Demos

  • gh-109991: Update GitHub CI workflows to use OpenSSL 3.0.11 and multissltests to use 1.1.1w, 3.0.11, and 3.1.3.

  • gh-108494: Argument Clinic now has a partial support of the Limited API: see documentation in the Python Developer’s Guide Patch by Victor Stinner.

  • gh-107704: It is now possible to deprecate passing keyword arguments for keyword-or-positional parameters with Argument Clinic, using the new / [from X.Y] syntax. (To be read as “positional-only from Python version X.Y”.) See documentation in the Python Developer’s Guide for more information.

  • gh-107880: Argument Clinic can now clone __init__() and __new__() methods.

  • gh-104683: Add --exclude option to Argument Clinic CLI.

  • gh-95065: Argument Clinic now supports overriding automatically generated signature by using directive @text_signature. See documentation in the Python Developer’s Guide

  • gh-107609: Fix duplicate module check in Argument Clinic. Previously, a duplicate definition would incorrectly be silently accepted. Patch by Erlend E. Aasland.

  • gh-107467: The Argument Clinic command-line tool now prints to stderr instead of stdout on failure.

  • gh-106970: Fix bugs in the Argument Clinic destination <name> clear command; the destination buffers would never be cleared, and the destination directive parser would simply continue to the fault handler after processing the command. Patch by Erlend E. Aasland.

  • gh-106706: Change bytecode syntax for families to remove redundant name matching pseudo syntax.

  • gh-106359: Argument Clinic now explicitly forbids “kwarg splats” in function calls used as annotations.

  • gh-103186: freeze now fetches CONFIG_ARGS from the original CPython instance the Makefile uses to call utility scripts. Patch by Ijtaba Hussain.

  • gh-95065: It is now possible to deprecate passing parameters positionally with Argument Clinic, using the new * [from X.Y] syntax. (To be read as “keyword-only from Python version X.Y”.) See documentation in the Python Developer’s Guide for more information. Patch by Erlend E. Aasland with help from Alex Waygood, Nikita Sobolev, and Serhiy Storchaka.

C API

Python 3.12.0 beta 1

Release date: 2023-05-22

Security

  • gh-99889: Fixed a security in flaw in uu.decode() that could allow for directory traversal based on the input if no out_file was specified.

  • gh-104049: Do not expose the local on-disk location in directory indexes produced by http.client.SimpleHTTPRequestHandler.

  • gh-99108: Upgrade built-in hashlib SHA3 implementation to a verified implementation from the HACL* project. Used when OpenSSL is not present or lacks SHA3.

  • gh-102153: urllib.parse.urlsplit() now strips leading C0 control and space characters following the specification for URLs defined by WHATWG in response to CVE 2023-24329. Patch by Illia Volochii.

Library

  • gh-102856: Implement PEP 701 changes in the tokenize module. Patch by Marta Gómez Macías and Pablo Galindo Salgado

Core and Builtins

  • gh-104615: Fix wrong ordering of assignments in code like a, a = x, y. Contributed by Carl Meyer.

  • gh-104572: Improve syntax error message for invalid constructs in PEP 695 contexts and in annotations when from __future__ import annotations is active.

  • gh-104482: Fix three error handling bugs in ast.c’s validation of pattern matching statements.

  • gh-102818: Do not add a frame to the traceback in the sys.setprofile and sys.settrace trampoline functions. This ensures that frames are not duplicated if an exception is raised in the callback function, and ensures that frames are not omitted if a C callback is used and that does not add the frame.

  • gh-104405: Fix an issue where some bytecode instructions could ignore PEP 523 when “inlining” calls.

  • gh-103082: Change behavior of sys.monitoring.events.LINE events in sys.monitoring: Line events now occur when a new line is reached dynamically, instead of using a static approximation, as before. This makes the behavior very similar to that of “line” events in sys.settrace. This should ease porting of tools from 3.11 to 3.12.

  • gh-104263: Fix float("nan") to produce a quiet NaN on platforms (like MIPS) where the meaning of the signalling / quiet bit is inverted from its usual meaning. Also introduce a new macro Py_INFINITY matching C99’s INFINITY, and refactor internals to rely on C99’s NAN and INFINITY macros instead of hard-coding bit patterns for infinities and NaNs. Thanks Sebastian Berg.

  • gh-99113: Multi-phase init extension modules may now indicate that they support running in subinterpreters that have their own GIL. This is done by using Py_MOD_PER_INTERPRETER_GIL_SUPPORTED as the value for the Py_mod_multiple_interpreters module def slot. Otherwise the module, by default, cannot be imported in such subinterpreters. (This does not affect the main interpreter or subinterpreters that do not have their own GIL.) In addition to the isolation that multi-phase init already normally requires, support for per-interpreter GIL involves one additional constraint: thread-safety. If the module has external (linked) dependencies and those libraries have any state that isn’t thread-safe then the module must do the additional work to add thread-safety. This should be an uncommon case.

  • gh-99113: The GIL is now (optionally) per-interpreter. This is the fundamental change for PEP 684. This is all made possible by virtue of the isolated state of each interpreter in the process. The behavior of the main interpreter remains unchanged. Likewise, interpreters created using Py_NewInterpreter() are not affected. To get an interpreter with its own GIL, call Py_NewInterpreterFromConfig().

  • gh-104108: Multi-phase init extension modules may now indicate whether or not they actually support multiple interpreters. By default such modules are expected to support use in multiple interpreters. In the uncommon case that one does not, it may use the new Py_mod_multiple_interpreters module def slot. A value of 0 means the module does not support them. 1 means it does. The default is 1.

  • gh-104142: Fix an issue where list or tuple repetition could fail to respect PEP 683.

  • gh-104078: Improve the performance of PyObject_HasAttrString()

  • gh-104066: Improve the performance of hasattr() for module objects with a missing attribute.

  • gh-104028: Reduce object creation while calling callback function from gc. Patch by Donghee Na.

  • gh-104018: Disallow the “z” format specifier in %-format of bytes objects.

  • gh-102213: Fix performance loss when accessing an object’s attributes with __getattr__ defined.

  • gh-103895: Improve handling of edge cases in showing Exception.__notes__. Ensures that the messages always end with a newline and that string/bytes are not exploded over multiple lines. Patch by Carey Metcalfe.

  • gh-103907: Don’t modify the refcounts of known immortal objects (True, False, and None) in the main interpreter loop.

  • gh-103899: Provide a helpful hint in the TypeError message when accidentally calling a module object that has a callable attribute of the same name (such as dis.dis() or datetime.datetime).

  • gh-103845: Remove both line and instruction instrumentation before adding new ones for monitoring, to avoid newly added instrumentation being removed immediately.

  • gh-103763: Implement PEP 695, adding syntactic support for generic classes, generic functions, and type aliases.

    A new type X = ... syntax is added for type aliases, which resolves at runtime to an instance of the new class typing.TypeAliasType. The value is lazily evaluated and is accessible through the .__value__ attribute. This is implemented as a new AST node ast.TypeAlias.

    New syntax (class X[T]: ..., def func[T](): ...) is added for defining generic functions and classes. This is implemented as a new type_params attribute on the AST nodes for classes and functions. This node holds instances of the new AST classes ast.TypeVar, ast.ParamSpec, and ast.TypeVarTuple.

    typing.TypeVar, typing.ParamSpec, typing.ParamSpecArgs, typing.ParamSpecKwargs, typing.TypeVarTuple, and typing.Generic are now implemented in C rather than Python.

    There are new bytecode instructions LOAD_LOCALS, LOAD_CLASSDICT_OR_GLOBAL, and LOAD_CLASSDICT_OR_DEREF to support correct resolution of names in class namespaces.

    Patch by Eric Traut, Larry Hastings, and Jelle Zijlstra.

Library

  • gh-103801: Adds three minor linting fixes to the wasm module caught that were caught by ruff.

  • gh-103793: Optimized asyncio Task creation by deferring expensive string formatting (task name generation) from Task creation to the first time get_name is called. This makes asyncio benchmarks up to 5% faster.

Core and Builtins

  • gh-102310: Change the error range for invalid bytes literals.

  • gh-103590: Do not wrap a single exception raised from a try-except* construct in an ExceptionGroup.

  • gh-103650: Change the perf map format to remove the ‘0x’ prefix from the addresses

  • gh-102856: Implement the required C tokenizer changes for PEP 701. Patch by Pablo Galindo Salgado, Lysandros Nikolaou, Batuhan Taskaya, Marta Gómez Macías and sunmy2019.

  • gh-100530: Clarify the error message raised when the called part of a class pattern isn’t actually a class.

  • gh-101517: Fix bug in line numbers of instructions emitted for except*.

  • gh-103492: Clarify SyntaxWarning with literal is comparison by specifying which literal is problematic, since comparisons using is with e.g. None and bool literals are idiomatic.

  • gh-87729: Add LOAD_SUPER_ATTR (and a specialization for super().method()) to speed up super().method() and super().attr. This makes super().method() roughly 2.3x faster and brings it within 20% of the performance of a simple method call. Patch by Vladimir Matveev and Carl Meyer.

  • gh-103488: Change the internal offset distinguishing yield and return target addresses, so that the instruction pointer is correct for exception handling and other stack unwinding.

  • gh-82012: The bitwise inversion operator (~) on bool is deprecated. It returns the bitwise inversion of the underlying int representation such that bool(~True) == True, which can be confusing. Use not for logical negation of bools. In the rare case that you really need the bitwise inversion of the underlying int, convert to int explicitly ~int(x).

  • gh-77757: Exceptions raised in a typeobject’s __set_name__ method are no longer wrapped by a RuntimeError. Context information is added to the exception as a PEP 678 note.

  • gh-103333: AttributeError now retains the name attribute when pickled and unpickled.

Library

Core and Builtins

  • gh-103323: We’ve replaced our use of _PyRuntime.tstate_current with a thread-local variable. This is a fairly low-level implementation detail, and there should be no change in behavior.

  • gh-84436: The implementation of PEP-683 which adds Immortal Objects by using a fixed reference count that skips reference counting to make objects truly immutable.

  • gh-102700: Allow built-in modules to be submodules. This allows submodules to be statically linked into a CPython binary.

  • gh-103082: Implement PEP 669 Low Impact Monitoring for CPython.

  • gh-88691: Reduce the number of inline CACHE entries for CALL.

  • gh-102500: Make the buffer protocol accessible in Python code using the new __buffer__ and __release_buffer__ magic methods. See PEP 688 for details. Patch by Jelle Zijlstra.

  • gh-97933: PEP 709: inline list, dict and set comprehensions to improve performance and reduce bytecode size.

  • gh-99184: Bypass instance attribute access of __name__ in repr of weakref.ref.

  • gh-98003: Complex function calls are now faster and consume no C stack space.

  • bpo-39610: len() for 0-dimensional memoryview objects (such as memoryview(ctypes.c_uint8(42))) now raises a TypeError. Previously this returned 1, which was not consistent with mem_0d[0] raising an IndexError.

Library

  • bpo-31821: Fix pause_reading() to work when called from connection_made() in asyncio.

  • gh-104600: functools.update_wrapper() now sets the __type_params__ attribute (added by PEP 695).

  • gh-104340: When an asyncio pipe protocol loses its connection due to an error, and the caller doesn’t await wait_closed() on the corresponding StreamWriter, don’t log a warning about an exception that was never retrieved. After all, according to the StreamWriter.close() docs, the wait_closed() call is optional (“not mandatory”).

  • gh-104555: Fix issue where an issubclass() check comparing a class X against a runtime-checkable protocol Y with non-callable members would not cause TypeError to be raised if an isinstance() call had previously been made comparing an instance of X to Y. This issue was present in edge cases on Python 3.11, but became more prominent in 3.12 due to some unrelated changes that were made to runtime-checkable protocols. Patch by Alex Waygood.

  • gh-104372: Refactored the _posixsubprocess internals to avoid Python C API usage between fork and exec when marking pass_fds= file descriptors inheritable.

  • gh-104484: Added case_sensitive argument to pathlib.PurePath.match()

  • gh-75367: Fix data descriptor detection in inspect.getattr_static().

  • gh-104536: Fix a race condition in the internal multiprocessing.process cleanup logic that could manifest as an unintended AttributeError when calling process.close().

  • gh-103857: Update datetime deprecations’ stracktrace to point to the calling line

  • gh-101520: Move the core functionality of the tracemalloc module in the Python/ folder, leaving just the module wrapper in Modules/.

  • gh-104392: Remove undocumented and unused _paramspec_tvars attribute from some classes in typing.

  • gh-102613: Fix issue where pathlib.Path.glob() raised RecursionError when walking deep directory trees.

  • gh-103000: Improve performance of dataclasses.asdict() for the common case where dict_factory is dict. Patch by David C Ellis.

  • gh-104301: Allow leading whitespace in disambiguated statements in pdb.

  • gh-104139: Teach urllib.parse.unsplit() to retain the "//" when assembling itms-services://?action=generate-bugs style Apple Platform Deployment URLs.

  • gh-104307: socket.getnameinfo() now releases the GIL while contacting the DNS server

  • gh-104310: Users may now use importlib.util.allowing_all_extensions() (a context manager) to temporarily disable the strict compatibility checks for importing extension modules in subinterpreters.

  • gh-87695: Fix issue where pathlib.Path.glob() raised OSError when it encountered a symlink to an overly long path.

  • gh-104265: Prevent possible crash by disallowing instantiation of the _csv.Reader and _csv.Writer types. The regression was introduced in 3.10.0a4 with PR 23224 (bpo-14935). Patch by Radislav Chugunov.

  • gh-102613: Improve performance of pathlib.Path.glob() when expanding recursive wildcards (”**”) by merging adjacent wildcards and de-duplicating results only when necessary.

  • gh-65772: Remove unneeded comments and code in turtle.py.

  • gh-90208: Fixed issue where pathlib.Path.glob() returned incomplete results when it encountered a PermissionError. This method now suppresses all OSError exceptions, except those raised from calling is_dir() on the top-level path.

  • gh-104144: Optimize asyncio.TaskGroup when using asyncio.eager_task_factory(). Skip scheduling a done callback if a TaskGroup task completes eagerly.

  • gh-104144: Optimize asyncio.gather() when using asyncio.eager_task_factory() to complete eagerly if all fututres completed eagerly. Avoid scheduling done callbacks for futures that complete eagerly.

  • gh-104114: Fix issue where pathlib.Path.glob() returns paths using the case of non-wildcard segments for corresponding path segments, rather than the real filesystem case.

  • gh-104104: Improve performance of pathlib.Path.glob() by using re.IGNORECASE to implement case-insensitive matching.

  • gh-104102: Improve performance of pathlib.Path.glob() when evaluating patterns that contain '../' segments.

  • gh-103822: Update the return type of weekday to the newly added Day attribute

  • gh-103629: Update the repr of typing.Unpack according to PEP 692.

  • gh-103963: Make dis display the names of the args for CALL_INTRINSIC_*.

  • gh-104035: Do not ignore user-defined __getstate__ and __setstate__ methods for slotted frozen dataclasses.

  • gh-103987: In mmap, fix several bugs that could lead to access to memory-mapped files after they have been invalidated.

  • gh-103977: Improve import time of platform module.

  • gh-88773: Added turtle.teleport() to the turtle module to move a turtle to a new point without tracing a line, visible or invisible. Patch by Liam Gersten.

  • gh-103935: Use io.open_code() for files to be executed instead of raw open()

  • gh-68968: Fixed garbled output of assertEqual() when an input lacks final newline.

  • gh-100370: Fix potential OverflowError in sqlite3.Connection.blobopen() for 32-bit builds. Patch by Erlend E. Aasland.

  • gh-102628: Substitute CTRL-D with CTRL-Z in sqlite3 CLI banner when running on Windows.

  • gh-103636: Module-level attributes January and February are deprecated from calendar.

  • gh-103583: Isolate _multibytecodec and codecs extension modules. Patches by Erlend E. Aasland.

  • gh-103848: Add checks to ensure that [ bracketed ] hosts found by urllib.parse.urlsplit() are of IPv6 or IPvFuture format.

  • gh-103872: Update the bundled copy of pip to version 23.1.2.

  • gh-99944: Make dis display the value of oparg of KW_NAMES.

  • gh-74940: The C.UTF-8 locale is no longer converted to en_US.UTF-8, enabling the use of UTF-8 encoding on systems which have no locales installed.

  • gh-103861: Fix zipfile.Zipfile creating invalid zip files when force_zip64 was used to add files to them. Patch by Carey Metcalfe.

  • gh-103857: Deprecated datetime.datetime.utcnow() and datetime.datetime.utcfromtimestamp(). (Patch by Paul Ganssle)

  • gh-103839: Avoid compilation error due to tommath.h not being found when building Tkinter against Tcl 8.7 built with bundled libtommath.

  • gh-103791: contextlib.suppress now supports suppressing exceptions raised as part of an ExceptionGroup. If other exceptions exist on the group, they are re-raised in a group that does not contain the suppressed exceptions.

  • gh-90750: Use datetime.datetime.fromisocalendar() in the implementation of datetime.datetime.strptime(), which should now accept only valid ISO dates. (Patch by Paul Ganssle)

  • gh-103685: Prepare tkinter.Menu.index() for Tk 8.7 so that it does not raise TclError: expected integer but got "" when it should return None.

  • gh-81403: urllib.request.CacheFTPHandler no longer raises URLError if a cached FTP instance is reused. ftplib’s endtransfer method calls voidresp to drain the connection to handle FTP instance reuse properly.

  • gh-103699: Add __orig_bases__ to non-generic TypedDicts, call-based TypedDicts, and call-based NamedTuples. Other TypedDicts and NamedTuples already had the attribute.

  • gh-103693: Add convenience variable feature to pdb

  • gh-92248: Deprecate type, choices, and metavar parameters of argparse.BooleanOptionalAction.

  • gh-89415: Add socket constants for source-specific multicast. Patch by Reese Hyde.

  • gh-103673: socketserver gains ForkingUnixStreamServer and ForkingUnixDatagramServer classes. Patch by Jay Berry.

  • gh-103636: Added Enum for months and days in the calendar module.

  • gh-84976: Create a new Lib/_pydatetime.py file that defines the Python version of the datetime module, and make datetime import the contents of the new library only if the C implementation is missing. Currently, the full Python implementation is defined and then deleted if the C implementation is not available, slowing down import datetime unnecessarily.

  • gh-103596: Attributes/methods are no longer shadowed by same-named enum members, although they may be shadowed by enum.property’s.

  • gh-103584: Updated importlib.metadata with changes from importlib_metadata 5.2 through 6.5.0, including: Support installed-files.txt for Distribution.files when present. PackageMetadata now stipulates an additional get method allowing for easy querying of metadata keys that may not be present. packages_distributions now honors packages and modules with Python modules that not .py sources (e.g. .pyc, .so). Expand protocol for PackageMetadata.get_all to match the upstream implementation of email.message.Message.get_all in python/typeshed#9620. Deprecated use of Distribution without defining abstract methods. Deprecated expectation that PackageMetadata.__getitem__ will return None for missing keys. In the future, it will raise a KeyError.

  • gh-103578: Fixed a bug where pdb crashes when reading source file with different encoding by replacing io.open() with io.open_code(). The new method would also call into the hook set by PyFile_SetOpenCodeHook().

  • gh-103556: Now creating inspect.Signature objects with positional-only parameter with a default followed by a positional-or-keyword parameter without one is impossible.

  • gh-103559: Update the bundled copy of pip to version 23.1.1.

  • gh-103548: Improve performance of pathlib.Path.absolute() and cwd() by joining paths only when necessary. Also improve performance of pathlib.PurePath.is_absolute() on Posix by skipping path parsing and normalization.

  • gh-103538: Remove _tkinter module code guarded by definition of the TK_AQUA macro which was only needed for Tk 8.4.7 or earlier and was never actually defined by any build system or documented for manual use.

  • gh-103533: Update cProfile to use PEP 669 API

  • gh-103525: Fix misleading exception message when mixed str and bytes arguments are supplied to pathlib.PurePath and Path.

  • gh-103489: Add getconfig() and setconfig() to Connection to make configuration changes to a database connection. Patch by Erlend E. Aasland.

  • gh-103365: Set default Flag boundary to STRICT and fix bitwise operations.

  • gh-103472: Avoid a potential ResourceWarning in http.client.HTTPConnection by closing the proxy / tunnel’s CONNECT response explicitly.

  • gh-103462: Fixed an issue with using writelines() in asyncio to send very large payloads that exceed the amount of data that can be written in one call to socket.socket.send() or socket.socket.sendmsg(), resulting in the remaining buffer being left unwritten.

  • gh-103449: Fix a bug in doc string generation in dataclasses.dataclass().

  • gh-103092: Isolate _collections (apply PEP 687). Patch by Erlend E. Aasland.

  • gh-103357: Added support for logging.Formatter defaults parameter to logging.config.dictConfig() and logging.config.fileConfig(). Patch by Bar Harel.

  • gh-103092: Adapt the winreg extension module to PEP 687.

  • gh-74690: The performance of isinstance() checks against runtime-checkable protocols has been considerably improved for protocols that only have a few members. To achieve this improvement, several internal implementation details of the typing module have been refactored, including typing._ProtocolMeta.__instancecheck__, typing._is_callable_members_only, and typing._get_protocol_attrs. Patches by Alex Waygood.

  • gh-74690: The members of a runtime-checkable protocol are now considered “frozen” at runtime as soon as the class has been created. See “What’s new in Python 3.12” for more details.

  • gh-103256: Fixed a bug that caused hmac to raise an exception when the requested hash algorithm was not available in OpenSSL despite being available separately as part of hashlib itself. It now falls back properly to the built-in. This could happen when, for example, your OpenSSL does not include SHA3 support and you want to compute hmac.digest(b'K', b'M', 'sha3_256').

  • gh-102778: Support sys.last_exc in idlelib.

  • gh-103285: Improve performance of ast.get_source_segment().

  • gh-103225: Fix a bug in pdb when displaying line numbers of module-level source code.

  • gh-103092: Adapt the msvcrt extension module to PEP 687.

  • gh-103092: Adapt the winsound extension module to PEP 687.

  • gh-93910: Remove deprecation of enum member.member access.

  • gh-102978: Fixes unittest.mock.patch() not enforcing function signatures for methods decorated with @classmethod or @staticmethod when patch is called with autospec=True.

  • gh-103092: Isolate _socket (apply PEP 687). Patch by Erlend E. Aasland.

  • gh-100479: Add pathlib.PurePath.with_segments(), which creates a path object from arguments. This method is called whenever a derivative path is created, such as from pathlib.PurePath.parent. Subclasses may override this method to share information between path objects.

  • gh-103220: Fix issue where os.path.join() added a slash when joining onto an incomplete UNC drive with a trailing slash on Windows.

  • gh-103204: Fixes http.server accepting HTTP requests with HTTP version numbers preceded by ‘+’, or ‘-’, or with digit-separating ‘_’ characters. The length of the version numbers is also constrained.

  • gh-75586: Fix various Windows-specific issues with shutil.which.

  • gh-103193: Improve performance of inspect.getattr_static(). Patch by Alex Waygood.

  • gh-103176: sys._current_exceptions() now returns a mapping from thread-id to an exception instance, rather than to a (typ, exc, tb) tuple.

  • gh-103143: Polish the help messages and docstrings of pdb.

  • gh-103015: Add entrypoint keyword-only parameter to sqlite3.Connection.load_extension(), for overriding the SQLite extension entry point. Patch by Erlend E. Aasland.

  • gh-103000: Improve performance of dataclasses.astuple() and dataclasses.asdict() in cases where the contents are common Python types.

  • gh-102953: The extraction methods in tarfile, and shutil.unpack_archive(), have a new a filter argument that allows limiting tar features than may be surprising or dangerous, such as creating files outside the destination directory. See Extraction filters for details.

  • gh-97696: Implemented an eager task factory in asyncio. When used as a task factory on an event loop, it performs eager execution of coroutines. Coroutines that are able to complete synchronously (e.g. return or raise without blocking) are returned immediately as a finished task, and the task is never scheduled to the event loop. If the coroutine blocks, the (pending) task is scheduled and returned.

  • gh-81079: Add case_sensitive keyword-only argument to pathlib.Path.glob() and rglob().

  • gh-101819: Isolate the io extension module by applying PEP 687. Patch by Kumar Aditya, Victor Stinner, and Erlend E. Aasland.

  • gh-91896: Deprecate collections.abc.ByteString

  • gh-101362: Speed up pathlib.Path construction by omitting the path anchor from the internal list of path parts.

  • gh-102114: Functions in the dis module that accept a source code string as argument now print a more concise traceback when the string contains a syntax or indentation error.

  • gh-62432: The unittest runner will now exit with status code 5 if no tests were run. It is common for test runner misconfiguration to fail to find any tests, this should be an error.

  • gh-78079: Fix incorrect normalization of UNC device path roots, and partial UNC share path roots, in pathlib.PurePath. Pathlib no longer appends a trailing slash to such paths.

  • gh-85984: Add tty.cfmakeraw() and tty.cfmakecbreak() to tty and modernize, the behavior of tty.setraw() and tty.setcbreak() to use POSIX.1-2017 Chapter 11 “General Terminal Interface” flag masks by default.

  • gh-101688: Implement types.get_original_bases() to provide further introspection for types.

  • gh-101640: argparse.ArgumentParser now catches errors when writing messages, such as when sys.stderr is None. Patch by Oleg Iarygin.

  • gh-83861: Fix datetime.astimezone method return value when invoked on a naive datetime instance that represents local time falling in a timezone transition gap. PEP 495 requires that instances with fold=1 produce earlier times than those with fold=0 in this case.

  • gh-89550: Decrease execution time of some gzip file writes by 15% by adding more appropriate buffering.

  • gh-95299: Remove the bundled setuptools wheel from ensurepip, and stop installing setuptools in environments created by venv.

  • gh-99353: Respect the http.client.HTTPConnection .debuglevel flag in urllib.request.AbstractHTTPHandler when its constructor parameter debuglevel is not set. And do the same for *HTTPS*.

  • gh-98040: Remove the long-deprecated imp module.

  • gh-97850: Deprecate pkgutil.find_loader() and pkgutil.get_loader() in favor of importlib.util.find_spec().

  • gh-94473: Flatten arguments in tkinter.Canvas.coords(). It now accepts not only x1, y1, x2, y2, ... and [x1, y1, x2, y2, ...], but also (x1, y1), (x2, y2), ... and [(x1, y1), (x2, y2), ...].

  • gh-98040: Remove more deprecated importlib APIs: find_loader(), find_module(), importlib.abc.Finder, pkgutil.ImpImporter, pkgutil.ImpLoader.

  • gh-96522: Fix potential deadlock in pty.spawn()

  • gh-96534: Support divert(4) added in FreeBSD 14.

  • gh-87474: Fix potential file descriptor leaks in subprocess.Popen.

  • gh-94906: Support multiple steps in math.nextafter(). Patch by Shantanu Jain and Matthias Gorgens.

  • gh-51574: Make tempfile.mkdtemp() return absolute paths when its dir parameter is relative.

  • gh-94518: Convert private _posixsubprocess.fork_exec() to use Argument Clinic.

  • gh-92184: When creating zip files using zipfile, os.altsep, if not None, will always be treated as a path separator even when it is not /. Patch by Carey Metcalfe.

  • bpo-46797: Deprecation warnings are now emitted for ast.Num, ast.Bytes, ast.Str, ast.NameConstant and ast.Ellipsis. These have been documented as deprecated since Python 3.8, and will be removed in Python 3.14.

  • bpo-44844: Enables webbrowser to detect and launch Microsoft Edge browser.

  • bpo-45606: Fixed the bug in pathlib.Path.glob() – previously a dangling symlink would not be found by this method when the pattern is an exact match, but would be found when the pattern contains a wildcard or the recursive wildcard (**). With this change, a dangling symlink will be found in both cases.

  • bpo-23041: Add QUOTE_STRINGS and QUOTE_NOTNULL to the suite of csv module quoting styles.

  • bpo-24964: Added http.client.HTTPConnection.get_proxy_response_headers() that provides access to the HTTP headers on a proxy server response to the CONNECT request.

  • bpo-17258: multiprocessing now supports stronger HMAC algorithms for inter-process connection authentication rather than only HMAC-MD5.

  • bpo-39744: Make asyncio.subprocess.Process.communicate() close the subprocess’s stdin even when called with input=None.

  • bpo-22708: http.client CONNECT method tunnel improvements: Use HTTP 1.1 protocol; send a matching Host: header with CONNECT, if one is not provided; convert IDN domain names to Punycode. Patch by Michael Handler.

Documentation

  • gh-67056: Document that the effect of registering or unregistering an atexit cleanup function from within a registered cleanup function is undefined.

  • gh-103629: Mention the new way of typing **kwargs with Unpack and TypedDict introduced in PEP 692.

  • gh-48241: Clarifying documentation about the url parameter to urllib.request.urlopen and urllib.request.Request needing to be encoded properly.

  • gh-86094: Add support for Unicode Path Extra Field in ZipFile. Patch by Yeojin Kim and Andrea Giudiceandrea

  • gh-99202: Fix extension type from documentation for compiling in C++20 mode

Tests

  • gh-104494: Update test_pack_configure_in and test_place_configure_in for changes to error message formatting in Tk 8.7.

  • gh-104461: Run test_configure_screen on X11 only, since the DISPLAY environment variable and -screen option for toplevels are not useful on Tk for Win32 or Aqua.

  • gh-86275: Added property-based tests to the zoneinfo tests, along with stubs for the hypothesis interface. (Patch by Paul Ganssle)

  • gh-103329: Regression tests for the behaviour of unittest.mock.PropertyMock were added.

  • gh-102795: fix use of poll in test_epoll’s test_control_and_wait

  • gh-75729: Fix the os.spawn* tests failing on Windows when the working directory or interpreter path contains spaces.

Build

  • gh-101282: BOLT optimization is now applied to the libpython shared library if building a shared library. BOLT instrumentation and application settings can now be influenced via the BOLT_INSTRUMENT_FLAGS and BOLT_APPLY_FLAGS configure variables.

  • gh-99017: PYTHON_FOR_REGEN now require Python 3.10 or newer.

  • gh-104490: Define .PHONY / virtual make targets consistently and properly.

  • gh-104106: Add gcc fallback of mkfifoat/mknodat for macOS. Patch by Donghee Na.

  • gh-103532: The TKINTER_PROTECT_LOADTK macro is no longer defined or used in the _tkinter module. It was previously only defined when building against Tk 8.4.13 and older, but Tk older than 8.5.12 has been unsupported since gh-91152.

  • gh-99069: Extended workaround defining static_assert when missing from the libc headers to all clang and gcc builds. In particular, this fixes building on macOS <= 10.10.

  • gh-100220: Changed the default value of the SHELL Makefile variable from /bin/sh to /bin/sh -e to ensure that complex recipes correctly fail after an error. Previously, make install could fail to install some files and yet return a successful result.

  • gh-90656: Add platform triplets for 64-bit LoongArch:

    • loongarch64-linux-gnusf

    • loongarch64-linux-gnuf32

    • loongarch64-linux-gnu

    Patch by Zhang Na.

Windows

  • gh-104623: Update Windows installer to use SQLite 3.42.0.

  • gh-82814: Fix a potential [Errno 13] Permission denied when using shutil.copystat() within Windows Subsystem for Linux (WSL) on a mounted filesystem by adding errno.EACCES to the list of ignored errors within the internal implementation.

  • gh-103088: Fix virtual environment activate script having incorrect line endings for Cygwin.

  • gh-103088: Fixes venvs not working in bash on Windows across different disks

  • gh-102997: Update Windows installer to use SQLite 3.41.2.

  • gh-88013: Fixed a bug where TypeError was raised when calling ntpath.realpath() with a bytes parameter in some cases.

macOS

  • gh-99834: Update macOS installer to Tcl/Tk 8.6.13.

  • gh-104623: Update macOS installer to SQLite 3.42.0.

  • gh-103545: Add os.PRIO_DARWIN_THREAD, os.PRIO_DARWIN_PROCESS, os.PRIO_DARWIN_BG and os.PRIO_DARWIN_NONUI. These can be used with os.setpriority to run the process at a lower priority and make use of the efficiency cores on Apple Silicon systems.

  • gh-104180: Support reading SOCKS proxy configuration from macOS System Configuration. Patch by Sam Schott.

  • gh-60436: update curses textbox to additionally handle backspace using the curses.ascii.DEL key press.

  • gh-102997: Update macOS installer to SQLite 3.41.2.

IDLE

  • gh-104499: Fix completions for Tk Aqua 8.7 (currently blank).

  • gh-104496: About prints both tcl and tk versions if different (expected someday).

  • gh-88496: Fix IDLE test hang on macOS.

Tools/Demos

  • gh-104389: Argument Clinic C converters now accept the unused keyword, for wrapping a parameter with Py_UNUSED. Patch by Erlend E. Aasland.

C API

Python 3.12.0 alpha 7

Release date: 2023-04-04

Core and Builtins

Library

Core and Builtins

  • gh-101291: Rearrage bits in first field (after header) of PyLongObject. * Bits 0 and 1: 1 - sign. I.e. 0 for positive numbers, 1 for zero and 2 for negative numbers. * Bit 2 reserved (probably for the immortal bit) * Bits 3+ the unsigned size.

    This makes a few operations slightly more efficient, and will enable a more compact and faster 2s-complement representation of most ints in future.

  • gh-102397: Fix segfault from race condition in signal handling during garbage collection. Patch by Kumar Aditya.

  • gh-102406: codecs encoding/decoding errors now get the context information (which operation and which codecs) attached as PEP 678 notes instead of through chaining a new instance of the exception.

  • gh-102281: Fix potential nullptr dereference and use of uninitialized memory in fileutils. Patch by Max Bachmann.

  • gh-102300: Reuse operands with refcount of 1 in float specializations of BINARY_OP.

  • gh-102213: Fix performance loss when accessing an object’s attributes with __getattr__ defined.

  • gh-102255: Improve build support for the Xbox. Patch by Max Bachmann.

Build

  • gh-102027: Fix SSE2 and SSE3 detection in _blake2 internal module. Patch by Max Bachmann.

Core and Builtins

  • gh-101865: Deprecate co_lnotab in code objects, schedule it for removal in Python 3.14

Library

Documentation

Tests

  • gh-102980: Improve test coverage on pdb.

  • gh-102537: Adjust the error handling strategy in test_zoneinfo.TzPathTest.python_tzpath_context. Patch by Paul Ganssle.

  • gh-101377: Improved test_locale_calendar_formatweekday of calendar.

Build

  • gh-102973: Add a dev container (along with accompanying Dockerfile) for development purposes.

  • gh-102711: Fix -Wstrict-prototypes compiler warnings.

Windows

  • gh-102690: Update webbrowser to fall back to Microsoft Edge instead of Internet Explorer.

  • gh-99726: Improves correctness of stat results for Windows, and uses faster API when available

Tools/Demos

C API

  • gh-102013: Add a new (unstable) C-API function for iterating over GC’able objects using a callback: PyUnstable_VisitObjects.

Python 3.12.0 alpha 6

Release date: 2023-03-07

Security

  • gh-99108: Replace builtin hashlib implementations of MD5 and SHA1 with verified ones from the HACL* project.

  • gh-101727: Updated the OpenSSL version used in Windows and macOS binary release builds to 1.1.1t to address CVE 2023-0286, CVE 2022-4303, and CVE 2022-4303 per the OpenSSL 2023-02-07 security advisory.

  • gh-99108: Replace the builtin hashlib implementations of SHA2-384 and SHA2-512 originally from LibTomCrypt with formally verified, side-channel resistant code from the HACL* project. The builtins remain a fallback only used when OpenSSL does not provide them.

  • gh-101283: subprocess.Popen now uses a safer approach to find cmd.exe when launching with shell=True. Patch by Eryk Sun, based on a patch by Oleg Iarygin.

Core and Builtins

  • gh-102493: Fix regression in semantics of normalisation in PyErr_SetObject.

  • gh-102416: Do not memoize incorrectly automatically generated loop rules in the parser. Patch by Pablo Galindo.

  • gh-102356: Fix a bug that caused a crash when deallocating deeply nested filter objects. Patch by Marta Gómez Macías.

  • gh-102336: Cleanup Windows 7 specific special handling. Patch by Max Bachmann.

  • gh-102250: Fixed a segfault occurring when the interpreter calls a __bool__ method that raises.

  • gh-102126: Fix deadlock at shutdown when clearing thread states if any finalizer tries to acquire the runtime head lock. Patch by Kumar Aditya.

  • gh-102027: Use GetCurrentProcessId on Windows when getpid is unavailable. Patch by Max Bachmann.

  • gh-102056: Fix error handling bugs in interpreter’s exception printing code, which could cause a crash on infinite recursion.

  • gh-100982: Restrict the scope of the FOR_ITER_RANGE instruction to the scope of the original FOR_ITER instruction, to allow instrumentation.

  • gh-101967: Fix possible segfault in positional_only_passed_as_keyword function, when new list created.

  • gh-101952: Fix possible segfault in BUILD_SET opcode, when new set created.

  • gh-74895: socket.getaddrinfo no longer raises OverflowError for int port values outside of the C long range. Out of range values are left up to the underlying string based C library API to report. A socket.gaierror SAI_SERVICE may occur instead, or no error at all as not all platform C libraries generate an error.

  • gh-101799: Add CALL_INTRINSIC_2 and use it instead of PREP_RERAISE_STAR.

  • gh-101857: Fix xattr support detection on Linux systems by widening the check to linux, not just glibc. This fixes support for musl.

  • gh-84783: Make the slice object hashable. Patch by Will Bradshaw and Furkan Onder.

  • gh-87849: Change the SEND instruction to leave the receiver on the stack. This allows the specialized form of SEND to skip the chain of C calls and jump directly to the RESUME in the generator or coroutine.

  • gh-101765: Fix SystemError / segmentation fault in iter __reduce__ when internal access of builtins.__dict__ keys mutates the iter object.

  • gh-101430: Update tracemalloc to handle presize of object properly. Patch by Donghee Na.

  • gh-101696: Invalidate type version tag in _PyStaticType_Dealloc for static types, avoiding bug where a false cache hit could crash the interpreter. Patch by Kumar Aditya.

  • gh-101632: Adds a new RETURN_CONST instruction.

  • gh-100719: Remove gi_code field from generator (and coroutine and async generator) objects as it is redundant. The frame already includes a reference to the code object.

  • gh-98627: When an interpreter is configured to check (and only then), importing an extension module will now fail when the extension does not support multiple interpreters (i.e. doesn’t implement PEP 489 multi-phase init). This does not apply to the main interpreter, nor to subinterpreters created with Py_NewInterpreter().

Library

Documentation

Tests

  • gh-102019: Fix deadlock on shutdown if test_current_{exception,frames} fails. Patch by Jacob Bower.

  • gh-85984: Utilize new “winsize” functions from termios in pty tests.

  • gh-89792: test_tools now copies up to 10x less source data to a temporary directory during the freeze test by ignoring git metadata and other artifacts. It also limits its python build parallelism based on os.cpu_count instead of hard coding it as 8 cores.

Build

  • gh-99942: On Android, in a static build, python-config in embed mode no longer incorrectly reports a library to link to.

  • gh-99942: On Android, python.pc now correctly reports the library to link to, the same as python-config.sh.

  • gh-100221: Fix creating install directories in make sharedinstall if they exist outside DESTDIR already.

  • gh-96821: Explicitly mark C extension modules that need defined signed integer overflow, and add a configure option --with-strict-overflow. Patch by Matthias Görgens and Shantanu Jain.

Windows

  • gh-102344: Implement winreg.QueryValue using QueryValueEx and winreg.SetValue using SetValueEx. Patch by Max Bachmann.

  • gh-101881: Handle read and write operations on non-blocking pipes properly on Windows.

  • gh-101881: Add support for the os.get_blocking() and os.set_blocking() functions on Windows.

  • gh-101849: Ensures installer will correctly upgrade existing py.exe launcher installs.

  • gh-101763: Updates copy of libffi bundled with Windows installs to 3.4.4.

  • gh-101759: Update Windows installer to SQLite 3.40.1.

  • gh-101614: Correctly handle extensions built against debug binaries that reference python3_d.dll.

  • gh-101196: The functions os.path.isdir, os.path.isfile, os.path.islink and os.path.exists are now 13% to 28% faster on Windows, by making fewer Win32 API calls.

macOS

  • gh-101759: Update macOS installer to SQLite 3.40.1.

C API

  • gh-101907: Removes use of non-standard C++ extension in public header files.

  • gh-99293: Document that the Py_TPFLAGS_VALID_VERSION_TAG is an internal feature, should not be used, and will be removed.

  • gh-101578: Add PyErr_GetRaisedException() and PyErr_SetRaisedException() for saving and restoring the current exception. These functions return and accept a single exception object, rather than the triple arguments of the now-deprecated PyErr_Fetch() and PyErr_Restore(). This is less error prone and a bit more efficient.

    Add PyException_GetArgs() and PyException_SetArgs() as convenience functions for retrieving and modifying the args passed to the exception’s constructor.

  • gh-91744: Introduced the Unstable C API tier, marking APi that is allowed to change in minor releases without a deprecation period. See PEP 689 for details.

Python 3.12.0 alpha 5

Release date: 2023-02-07

Security

  • gh-99108: Replace the builtin hashlib implementations of SHA2-224 and SHA2-256 originally from LibTomCrypt with formally verified, side-channel resistant code from the HACL* project. The builtins remain a fallback only used when OpenSSL does not provide them.

Core and Builtins

  • gh-92173: Fix the defs and kwdefs arguments to PyEval_EvalCodeEx() and a reference leak in that function.

  • gh-59956: The GILState API is now partially compatible with subinterpreters. Previously, PyThreadState_GET() and PyGILState_GetThisThreadState() would get out of sync, causing inconsistent behavior and crashes.

  • gh-101400: Fix wrong lineno in exception message on continue or break which are not in a loop. Patch by Donghee Na.

  • gh-101372: Fix is_normalized() to properly handle the UCD 3.2.0 cases. Patch by Donghee Na.

  • gh-101266: Fix sys.getsizeof() reporting for int subclasses.

  • gh-101291: Refactor the PyLongObject struct into a normal Python object header and a PyLongValue struct.

  • gh-101046: Fix a possible memory leak in the parser when raising MemoryError. Patch by Pablo Galindo

  • gh-101037: Fix potential memory underallocation issue for instances of int subclasses with value zero.

  • gh-100762: Record the (virtual) exception block depth in the oparg of YIELD_VALUE. Use this to avoid the expensive throw() when closing generators (and coroutines) that can be closed trivially.

  • gh-100982: Adds a new COMPARE_AND_BRANCH instruction. This is a bit more efficient when performing a comparison immediately followed by a branch, and restores the design intent of PEP 659 that specializations are local to a single instruction.

  • gh-100942: Fixed segfault in property.getter/setter/deleter that occurred when a property subclass overrode the __new__ method to return a non-property instance.

  • gh-100923: Remove the mask cache entry for the COMPARE_OP instruction and embed the mask into the oparg.

  • gh-100892: Fix race while iterating over thread states in clearing threading.local. Patch by Kumar Aditya.

  • gh-91351: Fix a case where re-entrant imports could corrupt the import deadlock detection code and cause a KeyError to be raised out of importlib/_bootstrap. In addition to the straightforward cases, this could also happen when garbage collection leads to a warning being emitted – as happens when it collects an open socket or file)

  • gh-100726: Optimize construction of range object for medium size integers.

  • gh-100712: Added option to build cpython with specialization disabled, by setting ENABLE_SPECIALIZATION=False in opcode, followed by make regen-all.

Library

  • bpo-32780: Inter-field padding is now inserted into the PEP3118 format strings obtained from ctypes.Structure objects, reflecting their true representation in memory.

  • gh-101541: [Enum] - fix psuedo-flag creation

  • gh-101570: Upgrade pip wheel bundled with ensurepip (pip 23.0)

  • gh-101323: Fix a bug where errors where not thrown by zlib._ZlibDecompressor if encountered during decompressing.

  • gh-101317: Add ssl_shutdown_timeout parameter for asyncio.StreamWriter.start_tls().

  • gh-101326: Fix regression when passing None as second or third argument to FutureIter.throw.

  • gh-92123: Adapt the _elementtree extension module to multi-phase init (PEP 489). Patches by Erlend E. Aasland.

  • gh-100795: Avoid potential unexpected freeaddrinfo call (double free) in socket when when a libc getaddrinfo() implementation leaves garbage in an output pointer when returning an error. Original patch by Sergey G. Brester.

  • gh-101143: Remove unused references to TimerHandle in asyncio.base_events.BaseEventLoop._add_callback.

  • gh-101144: Make zipfile.Path.open() and zipfile.Path.read_text() also accept encoding as a positional argument. This was the behavior in Python 3.9 and earlier. 3.10 introduced a regression where supplying it as a positional argument would lead to a TypeError.

  • gh-94518: Group-related variables of _posixsubprocess module are renamed to stress that supplementary group affinity is added to a fork, not replace the inherited ones. Patch by Oleg Iarygin.

  • gh-101015: Fix typing.get_type_hints() on '*tuple[...]' and *tuple[...]. It must not drop the Unpack part.

  • gh-101000: Add os.path.splitroot(), which splits a path into a 3-item tuple (drive, root, tail). This new function is used by pathlib to improve the performance of path construction by up to a third.

  • gh-100573: Fix a Windows asyncio bug with named pipes where a client doing os.stat() on the pipe would cause an error in the server that disabled serving future requests.

  • gh-39615: warnings.warn() now has the ability to skip stack frames based on code filename prefix rather than only a numeric stacklevel via the new skip_file_prefixes keyword argument.

  • gh-100750: pass encoding kwarg to subprocess in platform

  • gh-100160: Emit a deprecation warning in asyncio.DefaultEventLoopPolicy.get_event_loop() if there is no current event loop set and it decides to create one.

  • gh-96290: Fix handling of partial and invalid UNC drives in ntpath.splitdrive(), and in ntpath.normpath() on non-Windows systems. Paths such as ‘\server’ and ‘\’ are now considered by splitdrive() to contain only a drive, and consequently are not modified by normpath() on non-Windows systems. The behaviour of normpath() on Windows systems is unaffected, as native OS APIs are used. Patch by Eryk Sun, with contributions by Barney Gale.

  • gh-99952: Fix a reference undercounting issue in ctypes.Structure with from_param() results larger than a C pointer.

  • gh-67790: Add float-style formatting support for fractions.Fraction instances.

  • gh-99266: Preserve more detailed error messages in ctypes.

  • gh-86682: Ensure runtime-created collections have the correct module name using the newly added (internal) sys._getframemodulename().

  • gh-88597: uuid now has a command line interface. Try python -m uuid -h.

  • gh-60580: ctypes.wintypes.BYTE definition changed from c_byte to c_ubyte to match Windows SDK. Patch by Anatoly Techtonik and Oleg Iarygin.

  • gh-94518: _posixsubprocess now initializes all UID and GID variables using a reserved -1 value instead of a separate flag. Patch by Oleg Iarygin.

  • bpo-38941: The xml.etree.ElementTree module now emits DeprecationWarning when testing the truth value of an xml.etree.ElementTree.Element. Before, the Python implementation emitted FutureWarning, and the C implementation emitted nothing.

  • bpo-40077: Convert elementtree types to heap types. Patch by Erlend E. Aasland.

  • bpo-29847: Fix a bug where pathlib.Path accepted and ignored keyword arguments. Patch provided by Yurii Karabas.

  • gh-77772: ctypes.CDLL, ctypes.OleDLL, ctypes.WinDLL, and ctypes.PyDLL now accept path-like objects as their name argument. Patch by Robert Hoelzl.

Documentation

  • gh-88324: Reword subprocess to emphasize default behavior of stdin, stdout, and stderr arguments. Remove inaccurate statement about child file handle inheritance.

Tests

  • gh-101334: test_tarfile has been updated to pass when run as a high UID.

Build

  • gh-101282: Update BOLT configuration not to use deprecated usage of --split functions. Patch by Donghee Na.

  • gh-101522: Allow overriding Windows dependencies versions and paths using MSBuild properties.

  • gh-77532: Minor fixes to allow building with PlatformToolset=ClangCL on Windows.

  • gh-101152: In accordance with PEP 699, the ma_version_tag field in PyDictObject is deprecated for extension modules. Accessing this field will generate a compiler warning at compile time. This field will be removed in Python 3.14.

  • gh-100340: Allows -Wno-int-conversion for wasm-sdk 17 and onwards, thus enables building WASI builds once against the latest sdk.

  • gh-101060: Conditionally add -fno-reorder-blocks-and-partition in configure. Effectively fixes --enable-bolt when using Clang, as this appears to be a GCC-only flag.

  • gh-98705: __bool__ is defined in AIX system header files which breaks the build in AIX, so undefine it.

  • gh-98636: Fix a regression in detecting gdbm_compat library for the _gdbm module build.

  • gh-96305: _aix_support now uses a simple code to get platform details rather than the now non-existent _bootsubprocess during bootstrap.

Windows

  • gh-101543: Ensure the install path in the registry is only used when the standard library hasn’t been located in any other way.

  • gh-101467: The py.exe launcher now correctly filters when only a single runtime is installed. It also correctly handles prefix matches on tags so that -3.1 does not match 3.11, but would still match 3.1-32.

  • gh-99834: Updates bundled copy of Tcl/Tk to 8.6.13.0

  • gh-101135: Restore ability to launch older 32-bit versions from the py.exe launcher when both 32-bit and 64-bit installs of the same version are available.

  • gh-82052: Fixed an issue where writing more than 32K of Unicode output to the console screen in one go can result in mojibake.

  • gh-100320: Ensures the PythonPath registry key from an install is used when launching from a different copy of Python that relies on an existing install to provide a copy of its modules and standard library.

  • gh-100247: Restores support for the py.exe launcher finding shebang commands in its configuration file using the full command name.

Python 3.12.0 alpha 4

Release date: 2023-01-10

Core and Builtins

  • gh-100776: Fix misleading default value in input()’s __text_signature__.

  • gh-99005: Remove UNARY_POSITIVE, ASYNC_GEN_WRAP and LIST_TO_TUPLE, replacing them with intrinsics.

  • gh-99005: Add new CALL_INTRINSIC_1 instruction. Remove IMPORT_STAR, PRINT_EXPR and STOPITERATION_ERROR, replacing them with the CALL_INTRINSIC_1 instruction.

  • gh-100288: Remove the LOAD_ATTR_METHOD_WITH_DICT specialized instruction. Stats show it is not useful.

  • gh-100720: Added _PyFrame_NumSlotsForCodeObject, which returns the number of slots needed in a frame for a given code object.

  • gh-100719: Removed the co_nplaincellvars field from the code object, as it is redundant.

  • gh-100637: Fix int.__sizeof__() calculation to include the 1-element ob_digit array for 0 and False.

  • gh-100649: Update the native_thread_id field of PyThreadState after fork.

  • gh-100126: Fix an issue where “incomplete” frames could be briefly visible to C code while other frames are being torn down, possibly resulting in corruption or hard crashes of the interpreter while running finalizers.

  • gh-87447: Fix SyntaxError on comprehension rebind checking with names that are not actually redefined.

    Now reassigning b in [(b := 1) for a, b.prop in some_iter] is allowed. Reassigning a is still disallowed as per PEP 572.

  • gh-100268: Add int.is_integer() to improve duck type compatibility between int and float.

  • gh-100425: Improve the accuracy of sum() with compensated summation.

Library

Core and Builtins

  • gh-100357: Convert vars, dir, next, getattr, and iter to argument clinic.

  • gh-100117: Improve the output of codeobject.co_lines() by emitting only one entry for each line range.

  • gh-90043: Handle NaNs when specializing COMPARE_OP for float values.

  • gh-100222: Redefine the _Py_CODEUNIT typedef as a union to describe its layout to the C compiler, avoiding type punning and improving clarity.

  • gh-99955: Internal compiler functions (in compile.c) now consistently return -1 on error and 0 on success.

  • gh-100188: The BINARY_SUBSCR_LIST_INT and BINARY_SUBSCR_TUPLE_INT instructions are no longer used for negative integers because those instructions always miss when encountering negative integers.

  • gh-99110: Initialize frame->previous in frameobject.c to fix a segmentation fault when accessing frames created by PyFrame_New().

  • gh-94155: Improved the hashing algorithm for code objects, mitigating some hash collisions.

  • gh-99540: None now hashes to a constant value. This is not a requirements change.

  • gh-100143: When built with --enable-pystats, stats collection is now off by default. To enable it early at startup, pass the -Xpystats flag. Stats are now always dumped, even if switched off.

  • gh-100146: Improve BUILD_LIST opcode so that it works similarly to the BUILD_TUPLE opcode, by stealing references from the stack rather than repeatedly using stack operations to set list elements. Implementation details are in a new private API _PyList_FromArraySteal().

  • gh-100110: Specialize FOR_ITER for tuples.

  • gh-100050: Honor existing errors obtained when searching for mismatching parentheses in the tokenizer. Patch by Pablo Galindo

  • gh-92216: Improve the performance of hasattr() for type objects with a missing attribute.

  • gh-99582: Freeze zipimport module into _bootstrap_python.

  • gh-99554: Pack debugging location tables more efficiently during bytecode compilation.

  • gh-98522: Add an internal version number to code objects, to give better versioning of inner functions and comprehensions, and thus better specialization of those functions. This change is invisible to both Python and C extensions.

  • gh-94603: Improve performance of list.pop for small lists.

Library

Core and Builtins

  • bpo-32782: ctypes arrays of length 0 now report a correct itemsize when a memoryview is constructed from them, rather than always giving a value of 0.

Library

  • gh-100833: Speed up math.fsum() by removing defensive volatile qualifiers.

  • gh-100805: Modify random.choice() implementation to once again work with NumPy arrays.

  • gh-100813: Add socket.IP_PKTINFO constant.

  • gh-100792: Make email.message.Message.__contains__() twice as fast.

  • gh-91851: Microoptimizations for fractions.Fraction.__round__(), fractions.Fraction.__ceil__() and fractions.Fraction.__floor__().

  • gh-90104: Avoid RecursionError on repr if a dataclass field definition has a cyclic reference.

  • gh-100689: Fix crash in pyexpat by statically allocating PyExpat_CAPI capsule.

  • gh-100740: Fix unittest.mock.Mock not respecting the spec for attribute names prefixed with assert.

  • gh-91219: Change SimpleHTTPRequestHandler to support subclassing to provide a different set of index file names instead of using __init__ parameters.

  • gh-100690: Mock objects which are not unsafe will now raise an AttributeError when accessing an attribute that matches the name of an assertion but without the prefix assert_, e.g. accessing called_once instead of assert_called_once. This is in addition to this already happening for accessing attributes with prefixes assert, assret, asert, aseert, and assrt.

  • gh-89727: Simplify and optimize os.walk() by using isinstance() checks to check the top of the stack.

  • gh-100485: Add math.sumprod() to compute the sum of products.

  • gh-86508: Fix asyncio.open_connection() to skip binding to local addresses of different family. Patch by Kumar Aditya.

  • gh-97930: importlib.resources.files now accepts a module as an anchor instead of only accepting packages. If a module is passed, resources are resolved adjacent to that module (in the same package or at the package root). The parameter was renamed from package to anchor with a compatibility shim for those passing by keyword. Additionally, the new anchor parameter is now optional and will default to the caller’s module.

  • gh-100585: Fixed a bug where importlib.resources.as_file was leaving file pointers open

  • gh-100562: Improve performance of pathlib.Path.absolute() by nearly 2x. This comes at the cost of a performance regression in pathlib.Path.cwd(), which is generally used less frequently in user code.

  • gh-100519: Small simplification of http.cookiejar.eff_request_host() that improves readability and better matches the RFC wording.

  • gh-100287: Fix the interaction of unittest.mock.seal() with unittest.mock.AsyncMock.

  • gh-100488: Add Fraction.is_integer() to check whether a fractions.Fraction is an integer. This improves duck type compatibility with float and int.

  • gh-100474: http.server now checks that an index page is actually a regular file before trying to serve it. This avoids issues with directories named index.html.

  • gh-100363: Speed up asyncio.get_running_loop() by removing redundant getpid checks. Patch by Kumar Aditya.

  • gh-78878: Fix crash when creating an instance of _ctypes.CField.

  • gh-100348: Fix ref cycle in asyncio._SelectorSocketTransport by removing _read_ready_cb in close.

  • gh-100344: Provide C implementation for asyncio.current_task() for a 4x-6x speedup.

  • gh-100272: Fix JSON serialization of OrderedDict. It now preserves the order of keys.

  • gh-83076: Instantiation of Mock() and AsyncMock() is now 3.8x faster.

  • gh-100234: Set a default value of 1.0 for the lambd parameter in random.expovariate().

  • gh-100228: A DeprecationWarning may be raised when os.fork() or os.forkpty() is called from multi-threaded processes. Forking with threads is unsafe and can cause deadlocks, crashes and subtle problems. Lack of a warning does not indicate that the fork call was actually safe, as Python may not be aware of all threads.

  • gh-100039: Improve signatures for enums and flags.

  • gh-100133: Fix regression in asyncio where a subprocess would sometimes lose data received from pipe.

  • bpo-44592: Fixes inconsistent handling of case sensitivity of extrasaction arg in csv.DictWriter.

  • gh-100098: Fix tuple subclasses being cast to tuple when used as enum values.

  • gh-85432: Rename the fmt parameter of the pure-Python implementation of datetime.time.strftime() to format. Rename the t parameter of datetime.datetime.fromtimestamp() to timestamp. These changes mean the parameter names in the pure-Python implementation now match the parameter names in the C implementation. Patch by Alex Waygood.

  • gh-98778: Update HTTPError to be initialized properly, even if the fp is None. Patch by Donghee Na.

  • gh-99925: Unify error messages in JSON serialization between json.dumps(float('nan'), allow_nan=False) and json.dumps(float('nan'), allow_nan=False, indent=<SOMETHING>). Now both include the representation of the value that could not be serialized.

  • gh-89727: Fix issue with os.walk() where a RecursionError would occur on deep directory structures by adjusting the implementation of os.walk() to be iterative instead of recursive.

  • gh-94943: Add Dataclass support to the Enum __repr__(). When inheriting from a dataclass, only show the field names in the value section of the member repr(), and not the dataclass’ class name.

  • gh-83035: Fix inspect.getsource() handling of decorator calls with nested parentheses.

  • gh-99576: Fix .save() method for LWPCookieJar and MozillaCookieJar: saved file was not truncated on repeated save.

  • gh-94912: Add inspect.markcoroutinefunction() decorator which manually marks a function as a coroutine for the benefit of iscoroutinefunction().

  • gh-99509: Add PEP 585 support for multiprocessing.queues.Queue.

  • gh-99482: Remove Jython partial compatibility code from several stdlib modules.

  • gh-99433: Fix doctest failure on types.MethodWrapperType in modules.

  • gh-85267: Several improvements to inspect.signature()’s handling of __text_signature. - Fixes a case where inspect.signature() dropped parameters - Fixes a case where inspect.signature() raised tokenize.TokenError - Allows inspect.signature() to understand defaults involving binary operations of constants - inspect.signature() is documented as only raising TypeError or ValueError, but sometimes raised RuntimeError. These cases now raise ValueError - Removed a dead code path

  • gh-91166: asyncio is optimized to avoid excessive copying when writing to socket and use sendmsg() if the platform supports it. Patch by Kumar Aditya.

  • gh-98030: Add missing TCP socket options from Linux: TCP_MD5SIG, TCP_THIN_LINEAR_TIMEOUTS, TCP_THIN_DUPACK, TCP_REPAIR, TCP_REPAIR_QUEUE, TCP_QUEUE_SEQ, TCP_REPAIR_OPTIONS, TCP_TIMESTAMP, TCP_CC_INFO, TCP_SAVE_SYN, TCP_SAVED_SYN, TCP_REPAIR_WINDOW, TCP_FASTOPEN_CONNECT, TCP_ULP, TCP_MD5SIG_EXT, TCP_FASTOPEN_KEY, TCP_FASTOPEN_NO_COOKIE, TCP_ZEROCOPY_RECEIVE, TCP_INQ, TCP_TX_DELAY.

  • gh-88500: Reduced the memory usage of urllib.parse.unquote() and urllib.parse.unquote_to_bytes() on large values.

  • gh-96127: inspect.signature was raising TypeError on call with mock objects. Now it correctly returns (*args, **kwargs) as inferred signature.

  • gh-95882: Fix a 3.11 regression in asynccontextmanager(), which caused it to propagate exceptions with incorrect tracebacks and fix a 3.11 regression in contextmanager(), which caused it to propagate exceptions with incorrect tracebacks for StopIteration.

  • gh-78707: Deprecate passing more than one positional argument to pathlib.PurePath.relative_to() and is_relative_to().

  • gh-92122: Fix reStructuredText syntax errors in docstrings in the enum module.

  • gh-91851: Optimize the Fraction arithmetics for small components.

  • bpo-24132: Make pathlib.PurePath and Path subclassable (private to start). Previously, attempting to instantiate a subclass resulted in an AttributeError being raised. Patch by Barney Gale.

  • bpo-40447: Accept os.PathLike (such as pathlib.Path) in the stripdir arguments of compileall.compile_file() and compileall.compile_dir().

  • bpo-36880: Fix a reference counting issue when a ctypes callback with return type py_object returns None, which could cause crashes.

Documentation

Tests

  • gh-100454: Start running SSL tests with OpenSSL 3.1.0-beta1.

  • gh-100086: The Python test runner (libregrtest) now logs Python build information like “debug” vs “release” build, or LTO and PGO optimizations. Patch by Victor Stinner.

  • gh-93018: Make two tests forgiving towards host system libexpat with backported security fixes applied.

Build

  • gh-100540: Removed the --with-system-ffi configure option; libffi must now always be supplied by the system on all non-Windows platforms. The option has had no effect on non-Darwin platforms for several releases, and in 3.11 only had the non-obvious effect of invoking pkg-config to find libffi and never setting -DUSING_APPLE_OS_LIBFFI. Now on Darwin platforms configure will first check for the OS libffi and then fall back to the same processing as other platforms if it is not found.

  • gh-88267: Avoid exporting Python symbols in linked Windows applications when the core is built as static.

  • bpo-41916: Allow override of ac_cv_cxx_thread so that cross compiled python can set -pthread for CXX.

Windows

  • gh-100180: Update Windows installer to OpenSSL 1.1.1s

  • gh-99191: Use _MSVC_LANG >= 202002L instead of less-precise _MSC_VER >=1929 to more accurately test for C++20 support in PC/_wmimodule.cpp.

  • gh-79218: Define MS_WIN64 for Mingw-w64 64bit, fix cython compilation failure.

  • gh-99941: Ensure that asyncio.Protocol.data_received() receives an immutable bytes object (as documented), instead of bytearray.

  • bpo-43984: winreg.SetValueEx() now leaves the target value untouched in the case of conversion errors. Previously, -1 would be written in case of such errors.

  • bpo-34816: hasattr(ctypes.windll, 'nonexistant') now returns False instead of raising OSError.

macOS

  • gh-100180: Update macOS installer to OpenSSL 1.1.1s

  • gh-100540: Removed obsolete dlfcn.h shim from the _ctypes extension module, which has not been necessary since Mac OS X 10.2.

Tools/Demos

  • bpo-45256: Fix a bug that caused an AttributeError to be raised in python-gdb.py when py-locals is used without a frame.

  • gh-100342: Add missing NULL check for possible allocation failure in *args parsing in Argument Clinic.

C API

  • gh-99947: Raising SystemError on import will now have its cause be set to the original unexpected exception.

  • gh-99240: In argument parsing, after deallocating newly allocated memory, reset its pointer to NULL.

  • gh-98724: The Py_CLEAR, Py_SETREF and Py_XSETREF macros now only evaluate their arguments once. If an argument has side effects, these side effects are no longer duplicated. Patch by Victor Stinner.

Python 3.12.0 alpha 3

Release date: 2022-12-06

Security

  • gh-100001: python -m http.server no longer allows terminal control characters sent within a garbage request to be printed to the stderr server log.

    This is done by changing the http.server BaseHTTPRequestHandler .log_message method to replace control characters with a \xHH hex escape before printing.

  • gh-87604: Avoid publishing list of active per-interpreter audit hooks via the gc module

Core and Builtins

  • gh-99891: Fix a bug in the tokenizer that could cause infinite recursion when showing syntax warnings that happen in the first line of the source. Patch by Pablo Galindo

  • gh-91054: Add PyCode_AddWatcher() and PyCode_ClearWatcher() APIs to register callbacks to receive notification on creation and destruction of code objects.

  • gh-99729: Fix an issue that could cause frames to be visible to Python code as they are being torn down, possibly leading to memory corruption or hard crashes of the interpreter.

  • gh-99708: Fix bug where compiler crashes on an if expression with an empty body block.

  • gh-99578: Fix a reference bug in _imp.create_builtin() after the creation of the first sub-interpreter for modules builtins and sys. Patch by Victor Stinner.

  • gh-99581: Fixed a bug that was causing a buffer overflow if the tokenizer copies a line missing the newline character from a file that is as long as the available tokenizer buffer. Patch by Pablo galindo

  • gh-99553: Fix bug where an ExceptionGroup subclass can wrap a BaseException.

Library

  • gh-99547: Add a function to os.path to check if a path is a junction: isjunction. Add similar functionality to pathlib.Path as is_junction.

  • gh-99370: Fix zip path for venv created from a non-installed python on POSIX platforms.

Core and Builtins

  • gh-99377: Add audit events for thread creation and clear operations.

  • gh-98686: Remove the BINARY_OP_GENERIC and COMPARE_OP_GENERIC “specializations”.

  • gh-99298: Remove the remaining error paths for attribute specializations, and refuse to specialize attribute accesses on types that haven’t had PyType_Ready() called on them yet.

  • gh-99127: Allow some features of syslog to the main interpreter only. Patch by Donghee Na.

  • gh-91053: Optimizing interpreters and JIT compilers may need to invalidate internal metadata when functions are modified. This change adds the ability to provide a callback that will be invoked each time a function is created, modified, or destroyed.

  • gh-90994: Improve error messages when there’s a syntax error with call arguments. The following three cases are covered: - No value is assigned to a named argument, eg foo(a=). - A value is assigned to a star argument, eg foo(*args=[0]). - A value is assigned to a double-star keyword argument, eg foo(**kwarg={'a': 0}).

  • bpo-45026: Optimize the range object iterator. It is now smaller, faster iteration of ranges containing large numbers. Smaller pickles, faster unpickling.

  • bpo-31718: Raise ValueError instead of SystemError when methods of uninitialized io.IncrementalNewlineDecoder objects are called. Patch by Oren Milman.

  • bpo-38031: Fix a possible assertion failure in io.FileIO when the opener returns an invalid file descriptor.

Library

  • gh-100001: Also escape s in the http.server BaseHTTPRequestHandler.log_message so that it is technically possible to parse the line and reconstruct what the original data was. Without this a xHH is ambiguous as to if it is a hex replacement we put in or the characters r”x” came through in the original request line.

  • gh-99957: Add frozen_default parameter to typing.dataclass_transform().

  • gh-79033: Fix asyncio.Server.wait_closed() to actually do what the docs promise – wait for all existing connections to complete, after closing the server.

  • gh-51524: Fix bug when calling trace.CoverageResults with valid infile.

  • gh-99645: Fix a bug in handling class cleanups in unittest.TestCase. Now addClassCleanup() uses separate lists for different TestCase subclasses, and doClassCleanups() only cleans up the particular class.

  • gh-99508: Fix TypeError in Lib/importlib/_bootstrap_external.py while calling _imp.source_hash().

  • gh-66285: Fix asyncio to not share event loop and signal wakeupfd in forked processes. Patch by Kumar Aditya.

  • gh-97001: Release the GIL when calling termios APIs to avoid blocking threads.

  • gh-92647: Use final status of an enum to determine lookup or creation branch of functional API.

  • gh-99388: Add loop_factory parameter to asyncio.run() to allow specifying a custom event loop factory. Patch by Kumar Aditya.

  • gh-99341: Fix ast.increment_lineno() to also cover ast.TypeIgnore when changing line numbers.

  • gh-99382: Check the number of arguments in substitution in user generics containing a TypeVarTuple and one or more TypeVar.

  • gh-99379: Fix substitution of ParamSpec followed by TypeVarTuple in generic aliases.

  • gh-99344: Fix substitution of TypeVarTuple and ParamSpec together in user generics.

  • gh-99284: Remove _use_broken_old_ctypes_structure_semantics_ old untested and undocumented hack from ctypes.

  • gh-99201: Fix IndexError when initializing the config variables on Windows if HAVE_DYNAMIC_LOADING is not set.

  • gh-99240: Fix double-free bug in Argument Clinic str_converter by extracting memory clean up to a new post_parsing section.

  • gh-64490: Fix refcount error when arguments are packed to tuple in Argument Clinic.

  • gh-99029: pathlib.PurePath.relative_to() now treats naked Windows drive paths as relative. This brings its behaviour in line with other parts of pathlib.

  • gh-98253: The implementation of the typing module is now more resilient to reference leaks in binary extension modules.

    Previously, a reference leak in a typed C API-based extension module could leak internals of the typing module, which could in turn introduce leaks in essentially any other package with typed function signatures. Although the typing package is not the original source of the problem, such non-local dependences exacerbate debugging of large-scale projects, and the implementation was therefore changed to reduce harm by providing better isolation.

  • gh-98458: Fix infinite loop in unittest when a self-referencing chained exception is raised

  • gh-93453: asyncio.get_event_loop() and many other asyncio functions like asyncio.ensure_future(), asyncio.shield() or asyncio.gather(), and also the get_event_loop() method of asyncio.BaseDefaultEventLoopPolicy now raise a RuntimeError if called when there is no running event loop and the current event loop was not set. Previously they implicitly created and set a new current event loop. DeprecationWarning is no longer emitted if there is no running event loop but the current event loop was set.

  • gh-97966: On os.uname_result, restored expectation that _fields and _asdict would include all six properties including processor.

  • gh-98248: Provide informative error messages in struct.pack() when its integral arguments are not in range.

  • gh-98108: zipfile.Path is now pickleable if its initialization parameters were pickleable (e.g. for file system paths).

  • gh-98098: Created packages from zipfile and test_zipfile modules, separating zipfile.Path functionality.

  • gh-82836: Fix is_private properties in the ipaddress module. Previously non-private networks (0.0.0.0/0) would return True from this method; now they correctly return False.

  • gh-96828: Add an OP_ENABLE_KTLS option for enabling the use of the kernel TLS (kTLS). Patch by Illia Volochii.

  • gh-88863: To avoid apparent memory leaks when asyncio.open_connection() raises, break reference cycles generated by local exception and future instances (which has exception instance as its member var). Patch by Dong Uk, Kang.

  • gh-91078: TarFile.next() now returns None when called on an empty tarfile.

  • bpo-47220: Document the optional callback parameter of WeakMethod. Patch by Géry Ogam.

  • bpo-44817: Ignore WinError 53 (ERROR_BAD_NETPATH), 65 (ERROR_NETWORK_ACCESS_DENIED) and 161 (ERROR_BAD_PATHNAME) when using ntpath.realpath().

  • bpo-41260: Rename the fmt parameter of the pure Python implementation of datetime.date.strftime() to format.

  • bpo-15999: All built-in functions now accept arguments of any type instead of just bool and int for boolean parameters.

Documentation

  • gh-99931: Use sphinxext-opengraph to generate OpenGraph metadata.

  • gh-89682: Reworded docstring of the default __contains__ to clarify that it returns a bool.

  • gh-88330: Improved the description of what a resource is in importlib.resources docs.

  • gh-92892: Document that calling variadic functions with ctypes requires special care on macOS/arm64 (and possibly other platforms).

  • bpo-41825: Restructured the documentation for the os.wait* family of functions, and improved the docs for os.waitid() with more explanation of the possible argument constants.

Tests

  • gh-99892: Skip test_normalization() of test_unicodedata if it fails to download NormalizationTest.txt file from pythontest.net. Patch by Victor Stinner.

  • gh-99934: Correct test_marsh on (32 bit) x86: test_deterministic sets was failing.

  • gh-99741: We’ve implemented multi-phase init (PEP 489/630/687) for the internal (for testing) _xxsubinterpreters module.

  • gh-99659: Optional big memory tests in test_sqlite3 now catch the correct sqlite.DataError exception type in case of too large strings and/or blobs passed.

  • gh-99593: Cover the Unicode C API with tests.

  • gh-96002: Add functional test for Argument Clinic.

Build

  • gh-99086: Fix -Wimplicit-int, -Wstrict-prototypes, and -Wimplicit-function-declaration compiler warnings in configure checks.

  • gh-99337: Fix a compilation issue with GCC 12 on macOS.

  • gh-99289: Add a COMPILEALL_OPTS variable in Makefile to override compileall options (default: -j0) in make install. Also merged the compileall commands into a single command building .pyc files for the all optimization levels (0, 1, 2) at once. Patch by Victor Stinner.

  • gh-98872: Fix a possible fd leak in Programs/_freeze_module.c introduced in Python 3.11.

  • gh-88226: Always define TARGET_* labels in Python/ceval.c, even if USE_COMPUTED_GOTOS is disabled. This allows breakpoints to be set at those labels in (for instance) gdb.

Windows

macOS

  • gh-87235: On macOS python3 /dev/fd/9 9</path/to/script.py failed for any script longer than a couple of bytes.

  • gh-98940: Fix Mac/Extras.install.py file filter bug.

Tools/Demos

  • gh-64490: Argument Clinic varargs bugfixes

    • Fix out-of-bounds error in _PyArg_UnpackKeywordsWithVararg().

    • Fix incorrect check which allowed more than one varargs in clinic.py.

    • Fix miscalculation of noptargs in generated code.

    • Do not generate noptargs when there is a vararg argument and no optional argument.

C API

  • gh-98680: PyBUF_* constants were marked as part of Limited API of Python 3.11+. These were available in 3.11.0 with Py_LIMITED_API defined for 3.11, and are necessary to use the buffer API.

  • gh-99612: Fix PyUnicode_DecodeUTF8Stateful() for ASCII-only data: *consumed was not set.

  • gh-47146: The structmember.h header is deprecated. Its non-deprecated contents are now available just by including Python.h, with a Py_ prefix added if it was missing. (Deprecated contents are T_OBJECT, T_NONE, and no-op flags.) Patch by Petr Viktorin, based on earlier work by Alexander Belopolsky and Matthias Braun.

Python 3.12.0 alpha 2

Release date: 2022-11-14

Security

  • gh-98433: The IDNA codec decoder used on DNS hostnames by socket or asyncio related name resolution functions no longer involves a quadratic algorithm. This prevents a potential CPU denial of service if an out-of-spec excessive length hostname involving bidirectional characters were decoded. Some protocols such as urllib http 3xx redirects potentially allow for an attacker to supply such a name.

    Individual labels within an IDNA encoded DNS name will now raise an error early during IDNA decoding if they are longer than 1024 unicode characters given that each decoded DNS label must be 63 or fewer characters and the entire decoded DNS name is limited to 255. Only an application presenting a hostname or label consisting primarily of RFC 3454 section 3.1 “Nothing” characters to be removed would run into of this new limit. See also RFC 5894 section 6 and RFC 3491.

  • gh-98739: Update bundled libexpat to 2.5.0

Core and Builtins

  • gh-81057: The docs clearly say that PyImport_Inittab, PyImport_AppendInittab(), and PyImport_ExtendInittab() should not be used after Py_Initialize() has been called. We now enforce this for the two functions. Additionally, the runtime now uses an internal copy of PyImport_Inittab, to guard against modification.

  • gh-99298: Fix an issue that could potentially cause incorrect error handling for some bytecode instructions.

  • gh-99254: The compiler now removes all unused constants from code objects (except the first one, which may be a docstring).

  • gh-99205: Fix an issue that prevented PyThreadState and PyInterpreterState memory from being freed properly.

  • gh-81057: The 18 global C variables holding the state of the allocators have been moved to _PyRuntimeState. This is a strictly internal change with no change in behavior.

  • gh-99181: Fix failure in except* with unhashable exceptions.

  • gh-99204: Fix calculation of sys._base_executable when inside a POSIX virtual environment using copies of the python binary when the base installation does not provide the executable name used by the venv. Calculation will fall back to alternative names (“python<MAJOR>”, “python<MAJOR>.<MINOR>”).

  • gh-96055: Update faulthandler to emit an error message with the proper unexpected signal number. Patch by Donghee Na.

  • gh-99153: Fix location of SyntaxError for a try block with both except and except*.

  • gh-98686: Merge the adaptive opcode logic into each instruction’s unquickened variant, and merge the logic in EXTENDED_ARG_QUICK into EXTENDED_ARG. With these changes, the quickening that happens at code object creation is now only responsible for initializing warmup counters and inserting superinstructions.

  • gh-99103: Fix the error reporting positions of specialized traceback anchors when the source line contains Unicode characters.

  • gh-99139: Improve the error suggestion for NameError exceptions for instances. Now if a NameError is raised in a method and the instance has an attribute that’s exactly equal to the name in the exception, the suggestion will include self.<NAME> instead of the closest match in the method scope. Patch by Pablo Galindo

  • gh-98401: Octal escapes with value larger than 0o377 (ex: "\477"), deprecated in Python 3.11, now produce a SyntaxWarning, instead of DeprecationWarning. In a future Python version they will be eventually a SyntaxError. Patch by Victor Stinner.

  • gh-98401: A backslash-character pair that is not a valid escape sequence now generates a SyntaxWarning, instead of DeprecationWarning. For example, re.compile("\d+\.\d+") now emits a SyntaxWarning ("\d" is an invalid escape sequence), use raw strings for regular expression: re.compile(r"\d+\.\d+"). In a future Python version, SyntaxError will eventually be raised, instead of SyntaxWarning. Patch by Victor Stinner.

  • gh-96793: Handle StopIteration and StopAsyncIteration raised in generator or coroutines in the bytecode, rather than in wrapping C code.

  • gh-98931: Improve the SyntaxError error message when the user types import x from y instead of from y import x. Patch by Pablo Galindo

  • gh-98852: Fix subscription of type aliases containing bare generic types or types like TypeVar: for example tuple[A, T][int] and tuple[TypeVar, T][int], where A is a generic type, and T is a type variable.

  • gh-98925: Lower the recursion depth for marshal on WASI to support (in-development) wasmtime 2.0.

  • gh-98783: Fix multiple crashes in debug mode when str subclasses are used instead of str itself.

  • gh-98811: Use complete source locations to simplify detection of __future__ imports which are not at the beginning of the file. Also corrects the offset in the exception raised in one case, which was off by one and impeded highlighting.

  • gh-96793: Add specialization of FOR_ITER for generators. Saves multiple layers of dispatch and checking to get from the FOR_ITER instruction in the caller to the RESUME in the generator.

  • gh-98762: Fix source locations of match sub-patterns.

  • gh-98586: Added the methods PyObject_Vectorcall() and PyObject_VectorcallMethod() to the Limited API along with the auxiliary macro constant PY_VECTORCALL_ARGUMENTS_OFFSET.

    The availability of these functions enables more efficient PEP 590 vector calls from binary extension modules that avoid argument boxing/unboxing overheads.

  • gh-99257: Fix an issue where member descriptors (such as those for __slots__) could behave incorrectly or crash instead of raising a TypeError when accessed via an instance of an invalid type.

  • gh-93143: Rather than changing co_code, the interpreter will now display a RuntimeWarning and assign None to any fast locals that are left unbound after jumps or del statements executed while tracing.

  • gh-96421: When calling into Python code from C code, through PyEval_EvalFrameEx() or a related C-API function, a shim frame in inserted into the call stack. This occurs in the _PyEval_EvalFrameDefault() function. The extra frame should be invisible to all Python and most C extensions, but out-of-process profilers and debuggers need to be aware of it. These shim frames can be detected by checking frame->owner == FRAME_OWNED_BY_CSTACK.

    Extensions implementing their own interpreters using PEP 523 need to be aware of this shim frame and the changes to the semantics of RETURN_VALUE, YIELD_VALUE, and RETURN_GENERATOR, which now clear the frame.

Build

  • gh-98415: Fix detection of MAC addresses for uuid on certain OSs. Patch by Chaim Sanders

Core and Builtins

  • gh-98686: Quicken all code objects, and specialize adaptive bytecode instructions more aggressively.

  • gh-92119: Print exception class name instead of its string representation when raising errors from ctypes calls.

  • gh-91058: ImportError raised from failed from <module> import <name> now include suggestions for the value of <name> based on the available names in <module>. Patch by Pablo Galindo

  • gh-96793: The FOR_ITER now leaves the iterator on the stack on termination of the loop. This is to assist specialization of loops for generators.

  • gh-90716: Add _pylong.py module. It includes asymptotically faster algorithms that can be used for operations on integers with many digits. It is used by longobject.c to speed up some operations.

  • gh-95389: Expose ETH_P_ALL and some of the ETHERTYPE_* constants in socket. Patch by Noam Cohen.

Library

  • gh-93696: Allow pdb to locate source for frozen modules in the standard library.

  • gh-99418: Fix bug in urllib.parse.urlparse() that causes URL schemes that begin with a digit, a plus sign, or a minus sign to be parsed incorrectly.

  • gh-94597: Deprecate asyncio.AbstractChildWatcher to be removed in Python 3.14. Patch by Kumar Aditya.

  • gh-99305: Improve performance of secrets.token_hex().

  • gh-74044: Fixed bug where inspect.signature() reported incorrect arguments for decorated methods.

  • gh-99275: Fix SystemError in ctypes when exception was not set during __initsubclass__.

  • gh-99277: Remove older version of _SSLProtocolTransport.get_write_buffer_limits in asyncio.sslproto

  • gh-99248: fix negative numbers failing in verify()

  • gh-99155: Fix statistics.NormalDist pickle with 0 and 1 protocols.

  • gh-93464: enum.auto() is now correctly activated when combined with other assignment values. E.g. ONE = auto(), 'some text' will now evaluate as (1, 'some text').

  • gh-99134: Update the bundled copy of pip to version 22.3.1.

  • gh-92584: Remove the distutils package. It was deprecated in Python 3.10 by PEP 632 “Deprecate distutils module”. For projects still using distutils and cannot be updated to something else, the setuptools project can be installed: it still provides distutils. Patch by Victor Stinner.

  • gh-98999: Now _pyio is consistent with _io in raising ValueError when executing methods over closed buffers.

  • gh-83004: Clean up refleak on failed module initialisation in _zoneinfo

  • gh-83004: Clean up refleaks on failed module initialisation in _pickle

  • gh-83004: Clean up refleak on failed module initialisation in _io.

  • gh-98897: Fix memory leak in math.dist() when both points don’t have the same dimension. Patch by Kumar Aditya.

  • gh-98878: Use the frame bound builtins when offering a name suggestion in traceback to prevent crashing when __builtins__ is not a dict.

  • gh-98139: In importlib._bootstrap, enhance namespace package repr to <module 'x' (namespace) from ['path']>.

  • gh-90352: Fix _SelectorDatagramTransport to inherit from DatagramTransport in asyncio. Patch by Kumar Aditya.

  • gh-98793: Fix argument typechecks in _overlapped.WSAConnect() and _overlapped.Overlapped.WSASendTo() functions.

  • gh-98744: Prevent crashing in traceback when retrieving the byte-offset for some source files that contain certain unicode characters.

  • gh-98740: Fix internal error in the re module which in very rare circumstances prevented compilation of a regular expression containing a conditional expression without the “else” branch.

  • gh-98703: Fix asyncio.StreamWriter.drain() to call protocol.connection_lost callback only once on Windows.

  • gh-98624: Add a mutex to unittest.mock.NonCallableMock to protect concurrent access to mock attributes.

  • gh-98658: The array.array class now supports subscripting, making it a generic type.

  • gh-98284: Improved TypeError message for undefined abstract methods of a abc.ABC instance. The names of the missing methods are surrounded by single-quotes to highlight them.

  • gh-96151: Allow BUILTINS to be a valid field name for frozen dataclasses.

  • gh-98086: Make sure patch.dict() can be applied on async functions.

  • gh-72719: Remove modules asyncore and asynchat, which were deprecated by PEP 594.

  • gh-96192: Fix handling of bytes path-like objects in os.ismount().

  • gh-94172: ftplib: Remove the FTP_TLS.ssl_version class attribute: use the context parameter instead. Patch by Victor Stinner

  • gh-94172: Remove the keyfile and certfile parameters from the ftplib, imaplib, poplib and smtplib modules, and the key_file, cert_file and check_hostname parameters from the http.client module, all deprecated since Python 3.6. Use the context parameter (ssl_context in imaplib) instead. Patch by Victor Stinner.

  • gh-83638: Add the autocommit attribute to sqlite3.Connection and the autocommit parameter to sqlite3.connect() to control PEP 249-compliant transaction handling. Patch by Erlend E. Aasland.

  • gh-92452: Fixed a race condition that could cause sysconfig.get_config_var() to incorrectly return None in multi-threaded programs.

  • gh-91803: Fix an error when using a method of objects mocked with unittest.mock.create_autospec() after it was sealed with unittest.mock.seal() function.

  • bpo-38523: shutil.copytree() now applies the ignore_dangling_symlinks argument recursively.

  • bpo-40358: Add walk_up argument in pathlib.PurePath.relative_to().

  • bpo-36267: Fix IndexError in argparse.ArgumentParser when a store_true action is given an explicit argument.

Documentation

  • gh-98832: Changes wording of docstring for pathlib.Path.iterdir().

  • gh-97966: Update uname docs to clarify the special nature of the platform attribute and to indicate when it became late-bound.

Tests

  • gh-98903: The Python test suite now fails with exit code 4 if no tests ran. It should help detecting typos in test names and test methods.

  • gh-98713: Fix a bug in the typing tests where a test relying on CPython-specific implementation details was not decorated with @cpython_only and was not skipped on other implementations.

  • gh-87390: Add tests for star-unpacking with PEP 646, and some other miscellaneous PEP 646 tests.

  • gh-96853: Added explicit coverage of Py_Initialize (and hence Py_InitializeEx) back to the embedding tests (all other embedding tests migrated to Py_InitializeFromConfig in Python 3.11)

  • bpo-34272: Some C API tests were moved into the new Lib/test/test_capi/ directory.

Build

  • gh-99086: Fix -Wimplicit-int compiler warning in configure check for PTHREAD_SCOPE_SYSTEM.

  • gh-99016: Fix build with PYTHON_FOR_REGEN=python3.8.

  • gh-97731: Specify the full path to the source location for make docclean (needed for cross-builds).

  • gh-98949: Drop unused build dependency on readelf.

  • gh-98989: Use python3.11, if available, for regeneration and freezing.

  • gh-98831: Add new tooling, in Tools/cases_generator, to generate the interpreter switch statement from a list of opcode definitions. This only affects adding, modifying or removing instruction definitions. The instruction definitions now live in Python/bytecodes.c, in the form of a custom DSL (under development). The tooling reads this file and writes Python/generated_cases.c.h, which is then included by Python/ceval.c to provide most of the cases of the main interpreter switch.

  • gh-98817: Remove PCbuild/lib.pyproj: it’s not used for anything, is only a minor convenience for Visual Studio users (who probably mostly don’t even know about it), and it takes a lot of maintenance effort to keep updated.

  • gh-98776: Fix make regen-test-levenshtein for out-of-tree builds.

  • gh-98707: Don’t use vendored libmpdec headers if --with-system-libmpdec is passed to configure. Don’t use vendored libexpat headers if --with-system-expat is passed to configure.

Windows

  • gh-98689: Update Windows builds to zlib v1.2.13. v1.2.12 has CVE 2022-37434, but the vulnerable inflateGetHeader API is not used by Python.

  • gh-98790: Assumes that a missing DLLs directory means that standard extension modules are in the executable’s directory.

  • gh-98745: Update py.exe launcher to install 3.11 by default and 3.12 on request.

  • gh-98692: Fix the Python Launcher for Windows ignoring unrecognized shebang lines instead of treating them as local paths

  • gh-94328: Update Windows installer to use SQLite 3.39.4.

macOS

  • gh-94328: Update macOS installer to SQLite 3.39.4.

C API

  • gh-98724: The Py_CLEAR, Py_SETREF and Py_XSETREF macros now only evaluate their argument once. If the argument has side effects, these side effects are no longer duplicated. Patch by Victor Stinner.

  • gh-98978: Fix use-after-free in Py_SetPythonHome(NULL), Py_SetProgramName(NULL) and _Py_SetProgramFullPath(NULL) function calls. Issue reported by Benedikt Reinartz. Patch by Victor Stinner.

  • gh-98410: Add getbufferproc and releasebufferproc to the stable API.

  • gh-98610: Some configurable capabilities of sub-interpreters have changed. They always allow subprocesses (subprocess) now, whereas before subprocesses could be optionally disallowed for a sub-interpreter. Instead os.exec() can now be disallowed. Disallowing daemon threads is now supported. Disallowing all threads is still allowed, but is never done by default. Note that the optional restrictions are only available through _Py_NewInterpreterFromConfig(), which isn’t a public API. They do not affect the main interpreter, nor Py_NewInterpreter().

  • gh-98608: A _PyInterpreterConfig has been added and _Py_NewInterpreter() has been renamed to _Py_NewInterpreterFromConfig(). The “isolated_subinterpreters” argument is now a granular config that captures the previous behavior. Note that this is all “private” API.

  • gh-96853: Py_InitializeEx now correctly calls PyConfig_Clear after initializing the interpreter (the omission didn’t cause a memory leak only because none of the dynamically allocated config fields are populated by the wrapper function)

  • gh-91248: Add PyFrame_GetVar() and PyFrame_GetVarString() functions to get a frame variable by its name. Patch by Victor Stinner.

Python 3.12.0 alpha 1

Release date: 2022-10-25

Security

  • gh-97616: Fix multiplying a list by an integer (list *= int): detect the integer overflow when the new allocated length is close to the maximum size. Issue reported by Jordan Limor. Patch by Victor Stinner.

  • gh-97514: On Linux the multiprocessing module returns to using filesystem backed unix domain sockets for communication with the forkserver process instead of the Linux abstract socket namespace. Only code that chooses to use the “forkserver” start method is affected.

    Abstract sockets have no permissions and could allow any user on the system in the same network namespace (often the whole system) to inject code into the multiprocessing forkserver process. This was a potential privilege escalation. Filesystem based socket permissions restrict this to the forkserver process user as was the default in Python 3.8 and earlier.

    This prevents Linux CVE 2022-42919.

  • gh-87389: http.server: Fix an open redirection vulnerability in the HTTP server when an URI path starts with //. Vulnerability discovered, and initial fix proposed, by Hamza Avvan.

  • gh-79096: LWPCookieJar and MozillaCookieJar create files with file mode 600 instead of 644 (Microsoft Windows is not affected)

  • gh-92888: Fix memoryview use after free when accessing the backing buffer in certain cases.

  • gh-68966: The deprecated mailcap module now refuses to inject unsafe text (filenames, MIME types, parameters) into shell commands. Instead of using such text, it will warn and act as if a match was not found (or for test commands, as if the test failed).

Core and Builtins

  • gh-98374: Suppress ImportError for invalid query for help() command. Patch by Donghee Na.

  • gh-98461: Fix source location in bytecode for list, set and dict comprehensions as well as generator expressions.

  • gh-98354: Added unicode check for name attribute of spec argument passed in _imp.create_builtin() function.

  • gh-98398: Fix source location of ‘assert’ bytecodes.

  • gh-98390: Fix location of sub-expressions of boolean expressions, by reducing their scope to that of the sub-expression.

  • gh-98254: Modules from the standard library are now potentially suggested as part of the error messages displayed by the interpreter when an NameError is raised to the top level. Patch by Pablo Galindo

  • gh-97997: Add running column offset to the tokenizer state to avoid calculating AST column information with pointer arithmetic.

  • gh-97973: Modify the tokenizer to return all necessary information the parser needs to set location information in the AST nodes, so that the parser does not have to calculate those doing pointer arithmetic.

Library

Core and Builtins

  • gh-97912: The compiler now avoids quadratic behavior when finding which instructions should use the LOAD_FAST_CHECK opcode.

  • gh-97002: Fix an issue where several frame objects could be backed by the same interpreter frame, possibly leading to corrupted memory and hard crashes of the interpreter.

  • gh-97943: Bugfix: PyFunction_GetAnnotations() should return a borrowed reference. It was returning a new reference.

  • gh-97922: The Garbage Collector now runs only on the eval breaker mechanism of the Python bytecode evaluation loop instead on object allocations. The GC can also run when PyErr_CheckSignals() is called so C extensions that need to run for a long time without executing any Python code also have a chance to execute the GC periodically.

  • gh-65961: When __package__ is different than __spec__.parent, raise a DeprecationWarning instead of ImportWarning.

    Also remove importlib.util.set_package() which was scheduled for removal.

  • gh-97850: Long deprecated, module_repr() should now be completely eradicated.

  • gh-86298: In cases where warnings.warn_explicit() consults the module’s loader, an DeprecationWarning is issued when m.__loader__ differs from m.__spec__.loader.

  • gh-97779: Ensure that all Python frame objects are backed by “complete” frames.

  • gh-91052: Add API for subscribing to modification events on selected dictionaries.

  • gh-97752: Fix possible data corruption or crashes when accessing the f_back member of newly-created generator or coroutine frames.

  • gh-97591: Fixed a missing incref/decref pair in Exception.__setstate__(). Patch by Ofey Chan.

  • gh-97670: Remove the sys.getdxp() function and the Tools/scripts/analyze_dxp.py script. DXP stands for “dynamic execution pairs”. They were related to DYNAMIC_EXECUTION_PROFILE and DXPAIRS macros which have been removed in Python 3.11. Python can now be built with ./configure --enable-pystats to gather statistics on Python opcodes. Patch by Victor Stinner.

  • gh-94526: Fix the Python path configuration used to initialized sys.path at Python startup. Paths are no longer encoded to UTF-8/strict to avoid encoding errors if it contains surrogate characters (bytes paths are decoded with the surrogateescape error handler). Patch by Victor Stinner.

  • gh-96670: The parser now raises SyntaxError when parsing source code containing null bytes. Patch by Pablo Galindo

  • gh-96975: Fix a crash occurring when