Changelog¶
Python next¶
Release date: XXXX-XX-XX
Tools/Demos¶
gh-113318: Fix Argument Clinic for
@getterand@setterin a preprocessor conditional block. It failed with an internal error. Argument Clinic now also rejects the accessors of the same attribute with different C basenames, and the same accessor defined twice, which silently generated invalid or duplicated entries ofPyGetSetDef.
Tests¶
gh-155997: Fix
test.support.interpreters.list_all(). It failed if an interpreter was destroyed during the call, in particular by a garbage collection which finalized the object owning the last reference to it.gh-155411: Fix
test.support.subTests()for asynchronous test methods. They were wrapped in a synchronous function, which discarded the coroutine without awaiting it, so the test silently did not run at all.gh-132581: The list of tests which altered the execution environment now includes the reasons why the environment was considered altered, for example an unraisable exception or a modified
sys.path. The final result no longer repeats the same state twice (likeENV CHANGED then ENV CHANGED).
Security¶
gh-155999: Fix the
tarfiletaranddataextraction filters creating directories outside the destination for members whose name leaves the destination and returns to it, such as../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE 2026-72522.
gh-155694: Fix CVE 2026-15806 by scoping
HTTPPasswordMgrcredentials to the URL scheme, preventing credentials stored for an HTTPS URL from being used for a matching HTTP URL, while URIs without a scheme continue to match any scheme.
Library¶
gh-156166:
ssl: A failed assignment or deletion of the_msg_callbackattribute ofssl.SSLContextno longer removes the current callback. Deleting it now raisesAttributeErrorinstead ofTypeError.gh-152817:
sqlite3: Disallow removing therow_factoryattribute of a cursor to prevent a crash on a query.gh-156112:
_ios_supportno longer fails to import whenctypes.util.find_library()cannot resolve the ObjC runtime through the dyld shared cache, as is the case on iOS 13. The runtime is now loaded by name, which dyld resolves against the cache directly.gh-156100: Fix crashes in
sqlite3.Connectionwhen deleting theautocommitattribute or setting it to an integer which does not fit in C long. Both now raise an exception.gh-156099: Fix a crash when deleting the
keylog_filenameattribute ofssl.SSLContext. It now raisesAttributeError.gh-156067: Fix error handling in the
zoneinfoaccelerator module when a transition index is-1or a TZ string’s__bool__raises.gh-155952: Fix the signatures of
sqlite3.Connection.execute(),warnings.warn()andlocale.setlocale()which rendered<unrepresentable>instead of the correct defaults for parameters.gh-113318: Fix crashes when deleting an attribute whose setter is generated by Argument Clinic and is not prepared for deletion, among them the
context,ownerandsessionattributes of_ssl._SSLSocket. Deleting such attribute now raisesAttributeError.gh-155336: Fix error handling in
socket.gethostbyaddr()andsocket.gethostbyname_ex()when hostname resolution fails.gh-155319:
warnings.warn_explicit()now displays the source line taken from the loader of the module whose globals are passed as module_globals. It also no longer raisesIndexErrorif lineno is out of the range of the module source.gh-123011:
warnings.warn_explicit()no longer emits a spuriousDeprecationWarningor raisesImportErrorwhen it is called with the globals of the__main__module.gh-153005:
concurrent.interpreters.Queue.get()andconcurrent.interpreters.Queue.put()now compute theirtimeoutdeadline fromtime.monotonic()instead of the wall clock, so adjusting the system clock during the call no longer makes them over- or under-wait.gh-153603: Fix a crash in the ISO-2022 decoders when decoding a byte after an unknown charset designation is set via the decoder’s
setstatemethod. Patch by tonghuaroot.gh-153539: Fix a crash in the C implementation of
io.TextIOWrapper.tell()when the decoder’sgetstatemethod triggers a reentrant seek, or when another thread seeks the same stream concurrently. Patch by tonghuaroot.gh-146004: All
-Xoptions from the Python command line are now propagated to child processes spawned bymultiprocessing, not just a hard-coded subset. This makes the behavior consistent between default “spawn” and “forkserver” start methods and the old “fork” start method. The options that were previously not propagated are:context_aware_warnings,cpu_count,disable-remote-debug,int_max_str_digits,lazy_imports,no_debug_ranges,pathconfig_warnings,perf,perf_jit,presite,pycache_prefix,thread_inherit_context, andwarn_default_encoding.gh-113329: Fix
OSErrorbeing raised when trying to run doctests on a class objects in the REPL. Patch by Sten Wessel.gh-102967: A bug in
doctest._SpoofOut.truncate()was causing None to be passed toStringIO.seek()when no size was given. A simple fix skips the seek call when no size is given so the buffer can be truncated from the current position.gh-82039:
http.cookiejar.FileCookieJar.load()now checks the first, format signature line in a case-insensitive manner. Patch by Ashley Harvey.gh-70758: Creating a new
turtlescreen after the previous one was closed no longer raisesturtle.Terminatoron the first turtle command.bpo-44012: The
explodedattribute ofipaddress.IPv6Addressandipaddress.IPv6Interfacenow supports addresses with a scope ID (link-local addresses). Previously the former raisedAddressValueErrorand the latter omitted the scope ID.gh-83869: Fix
tarfilereading an archive with a GNU sparse 1.0 member whose size is set in the pax extended header. The offset of the next header was computed from the offset of the data, which is already past the sparse map, and from the size of the member, which can be the apparent size of the sparse file. All following members were unreachable.gh-61366:
http.cookiejar.MozillaCookieJarnow reads session cookies written by curl and Wget, which use0in the expiration time field. Contributed by Jérémie Detrey.
Core and Builtins¶
gh-156196: A failed assignment to an attribute defined with
PyMemberDefof typePy_T_LONG,Py_T_LONGLONG,Py_T_PYSSIZETorPy_T_DOUBLEno longer changes its value.gh-156189: Fix a crash when deleting the
f_trace_opcodesattribute of a frame object. It now raisesAttributeError.gh-155515: Track the internal HAMT iterators, which back iteration over a
contextvars.Context, with the garbage collector. A reference cycle running through such an iterator was never collected, leaking the whole context it iterated over.gh-153578: Fix an out-of-bounds write in
bytearray.extend()when the bytearray is resized while the argument’s__buffer__()is being acquired, for example by another thread. Patch by tonghuaroot.gh-130094: Fix two race conditions involving concurrent imports that could lead to spurious failures with
ModuleNotFoundError.gh-85260:
compile()now raisesValueErrorinstead of crashing on a debug build if an identifier field of an AST node (such as the name of a function, a class, an imported module or a caught exception) is"None","True"or"False".
Build¶
gh-155911: Fix curses detection when a curses library is already in
LIBS. Patch by Shamil Abdulaev.gh-156115: iOS simulator builds are now configured with
-mios-simulator-version-mininstead of the device’s-mios-version-min. The device flag made the linker reject libraries resolved from the simulator SDK, so library detection silently failed.
Python 3.13.15 final¶
Release date: 2026-08-05
macOS¶
Windows¶
Tools/Demos¶
gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms.
gh-155207: Argument Clinic now supports the
--dry-runand--diffoptions. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file.gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code.
gh-154580: Fix
python-gdb.pyraisingUnicodeEncodeErrorwhen pretty-printing a non-ASCIIstrin a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale.
Tests¶
gh-76595: Add C API tests for
PyCapsule_Import().gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job.
gh-154144: Fix building the
_testcapimodule on NetBSD.gh-152548: Add the
test.support.isolation.runInSubprocess()decorator to run a test method orTestCasesubclass in a fresh interpreter subprocess, isolated from the rest of the test run.gh-151626: Fix several tests in
test.test_inspect,test.test_import,test.test_importlib,test.test_py_compileandtest.test_compileallthat failed when the test suite was run withPYTHONPYCACHEPREFIXset. These tests now neutralize the pycache prefix where they assume the default__pycache__bytecode layout.gh-151096: Fix
test_embedfailing when CPython is configured with a split exec prefix (--exec-prefixdiffering from--prefix).
Security¶
gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in
html.parser.HTMLParser, which could be exploited for a denial of service.gh-152674: The
xml.etree.ElementTree.Elementmethodsfindall(),iterfind()andfind()avoid quadratic behavior when using XPath index predicates ([1],[last()],[last()-N]) on XML documents with many same-tag siblings.gh-151987: The
tarfile.TarFile.extract()method now applies the given filter when it extracts a link target from the archive as a fallback.gh-151981: In
tarfile, seeking a stream now stops when end of the stream is reached.gh-151544:
Modules/Setup.localis no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. Thepybuilddir.txtfile is now the sole indicator of running in a source tree.gh-151558: Fixed an vulnerability in the
tarfiledataandtarextraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330.gh-150743:
http.clientnow limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or100 Continueresponses forever, hanging the client even when a socket timeout was in use. Reported by@YLChen-007via GHSA-w4q2-g22w-6fr4.gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted.
Library¶
gh-155063: Bump the version of pip bundled in ensurepip to version 26.2.1
gh-155063: Bump the version of pip bundled in ensurepip to version 26.2
gh-154936: Fix the pure Python
jsondecoder to report the correct position for invalid literal control characters in JSON strings.gh-154892: Fix a bug in the C accelerator for
zoneinfowheredatetime.datetimesubclasses returning-1forhour,minute, orsecondcould incorrectly raise aSystemError.gh-154871: Fixed a crash in
asyncio.Task.get_context()when called on an uninitialized task.gh-154848: The
pickleC accelerator now enforces frame boundaries when unpickling, as the pure Python implementation already did. An argument that straddles a frame boundary, or a frame that begins before the previous one has ended, now raisespickle.UnpicklingErrorinstead of being silently read across the boundary. This prevents the loaded data from diverging from thepickletoolsdisassembly of the same pickle.gh-109638: Fix exponential time in
csv.Sniffer.sniff()for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break.gh-98820: Fix quadratic time in
csv.Sniffer.sniff()for a sample which contains quoted fields, in particular for a single column of quoted fields.gh-154738: Fix
ExternalEntityParserCreate()not propagating the reparse-deferral setting to the subparser, which leftGetReparseDeferralEnabled()returning an uninitialized value. Patch by tonghuaroot.gh-93251: Fix
UnicodeDecodeErrorinsocketfunctions (such asgetaddrinfo()andgethostbyaddr()) when the localized error message of the C library is not UTF-8: decode it from the locale encoding.gh-154551: Fix
ctypes.util.find_library()returningNonein non-UTF-8 locales.gh-79366: Fixed a race condition in
logging: if a handler was removed while a record was being emitted, the following handlers of the same logger could be skipped.gh-73458: Fix
logging.config.listen(): it left the caller waiting for thereadyevent forever if the server could not be started, for example if the port was invalid or already in use. It now also binds to an IPv6 address if the host has no IPv4 address, for example iflocalhostis only aliased to::1.gh-154460: Fix
time.strftime()anddatetime.datetime.strftime()returning a wrong ISO 8601 week number (%V) on OpenBSD.gh-154435: Fix
os.posix_fadvise()andos.posix_fallocate()on DragonFly BSD: they raisedOSErrorwith a meaningless error code, because these functions return -1 and seterrnothere.gh-154399: Fix
venvactivation in a non-interactive csh:activate.cshno longer fails when thepromptvariable is not set.gh-154389: Fix
uuid.uuid1()on OpenBSD: it returned a version 4 UUID, becauseuuid_create()generates random UUIDs on this platform.gh-154324: Fix
os.sendfile()on illumos: it no longer reports a successful transfer when the underlying system call failed without writing any data.gh-154307: Fix
tempfile.TemporaryDirectory.cleanup()on DragonFly BSD, where removing a file with theUF_NOUNLINKflag failed withEISDIRinstead ofEPERM.gh-154291: Fix
socket.has_dualstack_ipv6()to returnFalseon platforms such as DragonFly BSD where settingIPV6_V6ONLYto 0 silently has no effect.gh-154283: On DragonFly BSD,
threading.get_native_id()now returns a value that is unique across processes, matching the other platforms.gh-154258: Fix a crash in
mmap.mmap.resize()on NetBSD when growing a shared anonymous mapping.resize()now raisesValueErrorin this case, as it already did on Linux.gh-154225: Fix
os.openpty()on Solaris and illumos: it no longer leaves the pseudo-terminal as the controlling terminal of the calling process.gh-154227: Fix
os.posix_openpt()on OpenBSD, where it rejected theO_CLOEXECflag.gh-145030: Fix
asynciowrite pipe transports for named FIFOs on macOS and Solaris. Unread data sitting in the FIFO made the transport misinterpret a poll event as the reader disconnecting, wrongly closing the transport.gh-154001: Fix
random.binomialvariate()raisingZeroDivisionErrorwhenrandom.random()returns zero.gh-153896: Deduplicate unhashable args in
typing.Literal.gh-153864: On a wide
cursesbuild,curses.window.insch()now inserts a non-ASCII byte as the character it encodes in the window’s encoding, consistently withaddch(), instead of its code point.gh-153862: On a wide
cursesbuild,curses.window.inch()now returns the locale-encoded byte of a non-ASCII character, matchinginstr(), instead of the low byte of its code point.gh-146011: Fix a heap-use-after-free in the C implementation of
decimalwhen callingrepr()after deleting theContext.gh-153761: Fix cancelling
asyncio.loop.sock_accept()dropping a pending connection.gh-153695: Hashing a
sqlite3.Rowthat contains an unhashable value now raisesTypeErrorinstead ofSystemError. Patch by tonghuaroot.gh-153658: Fix
sqlite3.Connection.iterdump()raisingsqlite3.OperationalErrorwhen a table name contains a single quote. Patch by tonghuaroot.gh-85943: Fix
structfunctions raisingBytesWarningunder the-bbcommand line option when astrformat is used after an equalbytesformat (or vice versa). The internal format cache no longer mixesstrandbyteskeys.gh-153404:
urllib.robotparser.RobotFileParsernow silently ignores aCrawl-delayorRequest-ratevalue written with non-decimal digits (such asU+00B2 SUPERSCRIPT TWO) instead of raisingValueErrorand aborting the parse of the wholerobots.txtfile.gh-153417: Error messages from
imaplib.IMAP4.select()andimaplib.IMAP4.uid()no longer raiseBytesWarningunder-bbwhen the mailbox or command argument isbytes.gh-153406:
email.utils.parsedate_to_datetime()now raisesValueErrorinstead ofOverflowErrorwhen the parsed year or timezone offset is out of range, matching its documented behavior.gh-153083: Defer GC tracking of an
array.arrayto the end of its construction. Patch by Donghee Na.gh-143990: A
tkinter.font.Fontcreated from a named font, including bycopy(), now copies its configured options rather than the options resolved by Tcl’sfont actual, preserving a size specified in pixels (a negative size).gh-153210: Fix crash on
arrayimport under a memory pressure.gh-153200: Fix
math.isqrt()returning an incorrect result for arguments not less than 2**64 that are instances of anintsubclass with an overridden comparison operator.gh-153068: Fix
cProfile.Profile.enable()to no longer overwrite errors fromsys.monitoring.gh-153056: Fix
string.Templateraising a spuriousValueErrorwhen the pattern attribute is a compiled regular expression object, which the documentation allows.gh-135661: Fix
html.parser.HTMLParser: an abruptly closed empty comment (<!-->or<!--->) no longer extends up to a later-->in the samefeed()call.gh-54930: Error responses of
http.server.BaseHTTPRequestHandlerto malformed request lines now include a status line and headers instead of being sent in the bare HTTP/0.9 style. Only a valid HTTP/0.9 request (a two-wordGETrequest line) now receives an HTTP/0.9 style response.gh-152951:
collections.dequeprevent rare crash when callingextendunder high memory pressure conditions.gh-150880: Normalize non-extended Windows paths before appending the wildcard used by
os.listdir()andos.scandir(), making paths with trailing spaces behave consistently with other filesystem APIs.gh-152849: Out-of-range float and integer timestamps now raise
OverflowErrorwith the same message. Patch by tonghuaroot.gh-152847: Reject a POSIX TZ transition rule with non-digit characters in the day-of-year field in the pure-Python
zoneinfoparser. Patch by tonghuaroot.gh-108280: Connecting
imaplibto a server that does not send a valid IMAP4 greeting (for example a POP3 server answering on the IMAP port) now raises an error reporting the server’s response instead ofimaplib.IMAP4.error: None.gh-151126: Fix a crash caused by failing to set
MemoryErroron allocation failure when passingctypes.Structureorctypes.Unioninstances by value to ctypes foreign functions.gh-63121:
imaplibnow refreshes the cached capability list after a successfullogin()orauthenticate(), using theCAPABILITYresponse sent by the server or, if none was sent, by querying it, so that capabilities that become available only after authentication (such asENABLEon Gmail) are recognized. Capabilities advertised in the server greeting are now also used, avoiding a redundantCAPABILITYcommand.gh-88574:
imaplibno longer fails when a server sends a spurious blank line after the counted data of a literal, including after a literal that terminates a response (such as a mailbox name returned byLIST). Such blank lines are now skipped without swallowing the following line.gh-152502: Detect the
cursesmouse interface (getmouse(), theBUTTON*constants, and others) with a configure capability probe or library macros instead of gating it on ncurses-specific macros. It is now also available with other curses implementations that provide it, such as NetBSD curses and PDCurses (the latter underpinswindows-curses).gh-40038:
imaplibnow again quotes command arguments when necessary, for example mailbox names containing a space. Such quoting was inadvertently disabled when the module was ported to Python 3, and the arguments are now quoted according to the RFC 3501 grammar. For backward compatibility, an argument already enclosed in double quotes is left unchanged, so code that quotes arguments itself keeps working.gh-50966: Fix unbounded recursion in
turtlewhen a mouse event handler that moves the turtle is reentered while the screen is being redrawn, for example withscreen.ondrag(turtle.goto). This could previously crash the interpreter.gh-78335: Update the docstrings of
tkinterandtkinter.ttkwidget classes to list all supported widget options, including options added in Tk 9.0 and 9.1.tkinter.Menubuttonandtkinter.Messagepreviously had no option list at all.gh-151126: Fix two crashes in
tkinterandsocketmodules initialization under a memory pressure. Sets missingMemoryError.gh-133031:
curses.textpad.Textboxnow enters and reads back the non-ASCII characters of an 8-bit locale encoding, instead of mangling them with a 7-bit mask.gh-71880:
curses.textpad.Textboxnow lets the lower-right cell of the window be edited. Writing it withaddch()would move the cursor past the end of the window, raising an error and scrolling a scrollable window, so it is now written withinsch(), which keeps the cursor in place.gh-83274: Deallocating a
tkinterapplication from a thread other than the one it was created in no longer crashes the interpreter. The underlying Tcl interpreter is leaked instead, and aRuntimeWarningis reported.gh-88758:
tkinter.Misc.focus_get(),focus_displayof(),focus_lastfor()andwinfo_containing()now returnNoneinstead of raisingKeyErrorwhen the widget was not created bytkinter(for example a torn-off menu).gh-38464:
tkinter.Misc.nametowidget()now resolves the auto-generated names of cloned menus (a menu used as a menubar or a cascade) back to the original widget.gh-152248: Make the C and pure-Python
zoneinfoparsers validate POSIX TZ abbreviations consistently, rejecting unquoted abbreviations with non-letter characters and empty quoted abbreviations. Patch by tonghuaroot.gh-80937: Fix a memory leak in
tkinterwhen a Tcl command created withcreatecommandwas not explicitly removed before the interpreter was deleted. The command no longer keeps the interpreter alive through a reference cycle.gh-152246: Fix the pure-Python
zoneinfoparser accepting an invalid POSIX TZ transition rule with a non-period separator. Patch by tonghuaroot.gh-139816: Fix a hang in
tkinteron interactive Python built withoutreadline. An exception raised in a callback no longer causes the event loop to stop and wait for the user to press Enter; pending callbacks now keep running until input is actually available on stdin.gh-139145: Fix a busy loop in
tkinteron interactive Python. When a Tcl command running its own event loop (such asvwaitorwait_variable()) was active and input arrived on stdin, the event loop kept spinning at 100% CPU. The stdin file handler is now removed as soon as input is available. Based on a patch by Michiel de Hoon.gh-152212: Fix the pure-Python
zoneinfoparser accepting a POSIX TZ string with astdabbreviation but no offset. This is invalid per POSIX and now raisesValueError, matching the C accelerator. Patch by tonghuaroot.gh-152156: Fix a possible crash in
_interpreters.create()under limited memory conditions.gh-152157: The C implementations of
fromisoformat()andfromisoformat()now reject a decimal separator that is not followed by any fractional digit before a timezone designator.gh-151763: Fix crash in
_interpqueues.create()wheMemoryErrorhappens on queue creation.gh-105895: Add
matchandcaseto the list of supported topics byhelp().gh-152079: Fix
datetime.datetime.fromisoformat()in the C implementation dropping the sub-second part of a UTC offset whose whole-second part is zero, matching the pure-Python implementation.gh-152052: The
jsonC accelerator now correctly reports an unterminated string for a\uXXXXescape at the end of the input.gh-152060: Fix
datetime.datetime.fromisoformat()raisingAssertionErrorinstead ofValueErrorfor some malformed strings in the pure-Python implementation, matching the C implementation.gh-126219: Fixed a crash in
tkinter.Tkwhen className contains a non-BMP character and tkinter is built against Tcl/Tk 8.x. Such a name is now rejected with aValueError.gh-151955: Allow more types to be used in the
boundargument totyping.ParamSpec.gh-86165: Fix
imaplib.Time2Internaldate()to use the local timezone offset fortime.struct_timevalues withtm_gmtoffset toNone, as returned bydatetime.datetime.timetuple(). Contributed by Xiao Yuan.gh-151814: Fix unbounded memory growth in
io.TextIOWrapperwhen repeatedly writing an empty string.gh-151695: Fix a use-after-free in the
cursesmodule. The encoding of the initial screen, used bycurses.unctrl()andcurses.ungetch()to encode non-ASCII characters, is now kept as a private copy instead of a borrowed pointer to a window object that may be deallocated.gh-151596: Add missing
sizepositional argument to the pure-Python implementation ofio.TextIOBase.readline().gh-148660: Fix a crash in
collections.OrderedDict.copy()when a key’s__eq__or a subclass method mutates the dict during the copy. Now raisesRuntimeErrorinstead, as iteration does.gh-151497: Opening a
tarfilearchive no longer attempts to pre-allocate a huge buffer when a crafted or truncated member claims an oversized extended header (a GNU long name/link or a pax header). The extended header is now read in bounded chunks, so its size field can no longer trigger memory exhaustion.gh-151403: Fixed a crash in
subprocess.Popen(and_posixsubprocess.fork_exec) when anargvitem’s__fspath__()concurrently mutates theargssequence being converted.gh-151126: Fix crash on unset
MemoryErroron allocation failure inctypes.get_errno().gh-151416: Fix a crash in
os.spawnv()andos.spawnve()when an argv item’s__fspath__()method mutates the argv list during argument conversion.os.spawnv()argument conversion errors other thanTypeError, such as theValueErrorfor an embedded null, are no longer replaced with a genericTypeError.gh-151337: Avoid possible memory leak in
tkinter.con Windows.gh-151126: Fix a crash when
MemoryErrorinos._path_splitroot()was not set properly.gh-119710: Fix
asynciosubprocesswait()hanging when the process has exited but one of its pipes is kept open by an inherited child process (so the pipe never reaches EOF).wait()now returns as soon as the process exits, regardless of the pipes’ state.gh-151295: Fixed a crash (use-after-free) in
bytes.join()andbytearray.join()that could occur if an item’s__buffer__()concurrently mutates the sequence being joined. The mutation is now reported as aRuntimeErrorinstead.gh-109940: Fix Windows
venvactivation incmd.exeto respectVIRTUAL_ENV_DISABLE_PROMPT.gh-117807: Fix
mimetypesinitialization from MIME map files containing invalid UTF-8 bytes.gh-150771: Fix serialization of
emailmessages using theshift_jisoreuc-jpcharsets:set_content()now encodes the payload using the output charset, sostr(m)no longer raisesUnicodeEncodeError.gh-150484: Fix
unittest.mock.mock_open()__exit__raisingTypeErrorwhen used withcontextlib.ExitStack.gh-149319: The
asyncioREPL now ignoresPYTHONSTARTUPandPYTHON_BASIC_REPLwhen-Eor-Iis used. Patch by Jonathan Dung.gh-149221: Catch rare math domain error for
random.binomialvariate().gh-148441:
xml.parsers.expat: prevent a crash inCharacterDataHandler()when the character data size exceeds the parser’sbuffer size.gh-47005: Fix
urllib.request.AbstractHTTPHandler.do_open()to give regular headers set viaadd_header()priority over unredirected headers, consistent withget_header()andheader_items().gh-123720: asyncio: Fix
asyncio.Server.serve_forever()shutdown regression. Since 3.12, cancellingserve_forever()could hang waiting for a handler blocked on a read from a client that never closed (effectively requiring two interrupts to stop); the shutdown sequence now ensures client streams are closed soserve_forever()exits promptly and handlers observe EOF.gh-143988: Fixed crashes in
socket.socket.sendmsg()andsocket.socket.recvmsg_into()that could occur if buffer sequences are concurrently mutated.gh-130796: Undeprecate the
locale.getdefaultlocale()function. Patch by Victor Stinner.gh-115634: Fix a deadlock in
concurrent.futures.ProcessPoolExecutorwhen usingmax_tasks_per_child, present since the feature was introduced in Python 3.11. The executor stopped scheduling queued tasks after a worker process exited upon reaching its task limit. Based on a fix proposed by Tabrez Mohammed.gh-79638: Disallow all access in
urllib.robotparserif therobots.txtfile is unreachable due to server or network errors.gh-120665: Fixed an issue where
unittestloaders would load and instantiateunittest.TestCase-derived subclasses that are also abstract base classes, which can’t be instantiated.gh-105708: Accept an uppercase V prefix in IPvFuture addresses in
urllib.parse.urlsplit().gh-103925: Fix
csv.Sniffer.sniff()for a sample with\r\nline endings in which a quoted field ends a line: a letter could be detected as the delimiter.gh-101267: When a worker process terminates unexpectedly,
concurrent.futures.ProcessPoolExecutornow sets a separateBrokenProcessPoolexception on each pending future instead of sharing a single instance among them all. Sharing one exception produced malformed tracebacks: eachFuture.result()call re-raised the same object, appending another copy of the traceback to it.
IDLE¶
gh-82183: When the shell is busy running code, using “Run… Customized” with “Restart shell” unchecked now reports that the shell is executing instead of restarting it anyway.
gh-83653: Blanking an integer entry in IDLE’s Settings dialog, such as “Auto squeeze min lines”, no longer saves an empty string as an invalid configuration value.
gh-65339: Saving the IDLE Shell or an Output window now defaults to a
.txtextension and lists text files before Python files, since their content is not Python source.gh-80504: The “In files:” field of IDLE’s Find in Files dialog now always contains a full directory path, even for an unsaved editor or the Shell. This shows in the grep output which directory was searched.
gh-134300: Do not add the
idlelibdirectory to the path of the IDLE user process. User code run in IDLE can no longer importidlelibsubmodules as top-level modules, such asimport help.gh-89360: Fix a rare crash in the IDLE editor when the completion window is closed: deleting a key binding for a sequence that is not bound to the virtual event is now ignored instead of raising a
ValueError.gh-71956: Fix Replace All in the IDLE editor’s Replace dialog when the search direction is “Up” and “Wrap around” is off: it now replaces all matches above the current position instead of only the first one.
gh-152728: Move functions run.fix_scaling, editor.fixwordbreaks (as fix_word_breaks) and pyshell.fix_x11_paste to idlelib.util.
gh-66331: Set the
WM_CLASSwindow property of IDLE’s windows toIdleon X11, so that window managers group and label them correctly instead of using the defaultToplevel.gh-85320: IDLE now reads and writes its configuration files and the breakpoints file using UTF-8 instead of the locale encoding. This keeps non-ASCII data (such as non-ASCII paths) from being corrupted and makes the files portable between environments.
gh-94523: Detect file if modified at local disk and prompt to ask refresh. Patch by Shixian Li.
gh-139551: Support rendering
BaseExceptionGroupin IDLE.gh-89520: Make IDLE extension configuration look at user config files, allowing user-installed extensions to have settings and key bindings defined in ~/.idlerc.
Documentation¶
gh-118150: Clarify in the
difflibdocumentation what junk actually does, its drawbacks, and how to control it.gh-86726: Greatly expand the
tkinterdocumentation to cover the full public API of the package and its submodules. The descriptions are oriented towards Python rather than Tcl/Tk, with corrected return types andversionadded/versionchangedinformation.
Core and Builtins¶
gh-154937: Fix a data race on thread handle identifiers when
_thread._shutdown()runs concurrently with the startup of non-daemon threads in the free-threaded build.gh-154709: Fix an out-of-bounds access in reverse dictionary iterators when the underlying dictionary is cleared and modified after the iterator is created.
gh-154275: Fix a crash when getting deeply nested
__parameters__from atypes.GenericAliasobjects.gh-152682: Fix NULL pointer dereference in
compile()when a reserved name (e.g.__classdict__) is used as a type parameter name and memory allocation fails while formatting the error message.gh-152635: Fix a crash caused when running out of memory creating a
_interpchannelschannel. Now aMemoryErroris correctly raised.gh-152375: Fix undefined behaviour when a
sys.monitoringcallback raised an exception while the program was following a branch or loop.gh-152235: Defer GC tracking of
set.intersection(),set.difference(),set.symmetric_difference(),set.union()andset.__sub__. Patch by Donghee Na.gh-152235: Defer GC tracking of a
setorfrozensetto the end of its construction from iterable. Patch by Donghee Na.gh-151905: Fix OOM error handling in
PyFrame_GetBack()to propagate exceptions instead of masking them as None.gh-151763: Fix a potential crash in
compile(),exec(),eval()andast.parse()when an allocation fails: the parser or compiler could return without setting an exception.gh-151912: Fixed a crash in
type()when selecting a metaclass whosetp_newslot isNULL. Such metaclasses are now rejected withTypeErrorinstead of causing a NULL pointer dereference.gh-151773: Fix a crash in
contextvars.ContextVar.set()when memory allocation fails.gh-151126: Fix a crash when sharing
memoryviewobjects between interpreters fails due to running out of memory. It now raises a properMemoryError.gh-151126: Avoid possible crash in
_winapi.cwhere a device has no memory left. Now it properly raises aMemoryError. Patch by Ivy Xu.gh-151253: If
import encodings(first import) fails at Python startup, dump the Python path configuration to help users debugging their configuration. Patch by Victor Stinner.gh-151126: Fix a crash, when there’s no memory left on a device, which happened in
_interpchannelsmodule.Now it raises proper
MemoryErrorerrors.gh-151065: Fix memory leak when using the mimalloc memory allocator.
gh-150988: Fix a reference leak in
OSErrorwhen attributes are set beforesuper().__init__().gh-149689: Fix missing error propagation in parser action helpers when memory allocation fails. Patch by Thomas Kowalski.
C API¶
gh-152132: Fix
Py_RunMain()to return an exit code, rather than callingPy_Exit(), when running a script, a command, or the REPL. Patch by Victor Stinner.
Build¶
gh-154070: Build the
cursesmodule against a wide-character capable ncurses even when it is not namedncursesw– for example the pkgsrc ncurses on NetBSD and illumos, or the system ncurses on macOS. Such a library previously produced a narrow build.gh-126877: Fix the configure check for Tcl/Tk which could wrongly succeed with optimizing compilers when the libraries are missing.
gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for
nuget.exe.gh-152502: The
cursesmodule now detectsset_escdelay(),set_tabsize()and theESCDELAYandTABSIZEvariables with configure capability probes instead of the ncurses-specificNCURSES_EXT_FUNCSmacro, so they are exposed when building against other curses implementations such as NetBSD curses that provide them.gh-138800: Fix library name in python3.pc on Android.
gh-115869: Make
jit_stencils.h(which is produced during JIT builds) reproducible.
Python 3.13.14 final¶
Release date: 2026-06-10
macOS¶
gh-124111: Update macOS installer to use Tcl/Tk 8.6.18.
gh-150644: When system logging is enabled (with
config.use_system_logger, messages are now tagged as public. This allows the macOS 26 system logger to view messages without special configuration.gh-115119: Update macOS installer to use libmpdecimal 4.0.1.
gh-151159: Update macOS installer to use OpenSSL 3.0.21.
Windows¶
gh-151159: Updated bundled version of OpenSSL to 3.0.21.
Tests¶
Security¶
gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.
gh-150599: Fix a possible stack buffer overflow in
bz2when abz2.BZ2Decompressoris reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.gh-149835:
shutil.move()now resolves symlinks viaos.path.realpath()when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard.gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186.
gh-87451: The
ftplibmodule’s undocumentedftpcpfunction no longer trusts the IPv4 address value returned from the source server in response to thePASVcommand by default, completing the fix for CVE-2021-4189. As withftplib.FTP, the former behavior can be re-enabled by setting thetrust_server_pasv_ipv4_addressattribute on the sourceftplib.FTPinstance toTrue. Thanks to Qi Deng at Aurascape AI for the report.gh-149486:
tarfile.data_filter()now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of thedataextraction filter.gh-149079: Fix a potential denial of service in
unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.gh-149018: Improved protection against XML hash-flooding attacks in
xml.parsers.expatandxml.etree.ElementTreewhen Python is compiled with libExpat 2.8.0 or later.gh-90309: Base64-encode values when embedding cookies to JavaScript using the
http.cookies.BaseCookie.js_output()method to avoid injection and escaping.gh-148808: Added buffer boundary check when using
nbytesparameter withasyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and theasyncio.ProactorEventLoop.gh-148395: Fix a dangling input pointer in
lzma.LZMADecompressor,bz2.BZ2Decompressor, and internalzlib._ZlibDecompressorwhen memory allocation fails withMemoryError, which could let a subsequentdecompress()call read or write through a stale pointer to the already-released caller buffer.gh-148169: A bypass in
webbrowserallowed URLs prefixed with%actionto pass the dash-prefix safety check.gh-146581: Fix vulnerability in
shutil.unpack_archive()for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped.gh-146333: Fix quadratic backtracking in
configparser.RawConfigParseroption parsing regexes (OPTCREandOPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage.gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.
Library¶
gh-150913: Fix
sqlite3.Blobslice assignment to raiseTypeErrorandIndexErrorfor type and size mismatches respectively, even when the target slice is empty.gh-143008: Fix race conditions when re-initializing a
io.TextIOWrapperobject.gh-150685: Update bundled pip to 26.1.2
gh-150406: Fix a possible crash occurring during
socketmodule initialization when the system is out of memory on platforms without a reentrantgethostbyname.gh-150372:
readline: Fix a potential crash during tab completion caused by an out-of-memory error during module initialization.gh-150175: Fix race condition in
unittest.mock.ThreadingMockwhere concurrent calls could lose increments tocall_countand other attributes due to a missing lock in_increment_mock_call.gh-84353: Preserve non-UTF-8 encoded filenames when appending to a
zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8.gh-88726: The
emailpackage now uses standard MIME charset names “gb2312” and “big5” instead of non-standard names “eucgb2312_cn” and “big5_tw”.gh-149571: Fix the C implementation of
xml.etree.ElementTree.Element.itertext(): it no longer emits text for comments and processing instructions.gh-149921: Fix reference leaks in error paths of the
_interpchannelsand_interpqueuesextension modules.gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs.
gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled
gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects.
gh-149388: Make
asyncio.windows_utils.PipeHandleclosing idempotent.gh-149489: Fix
ElementTreeserialization to HTML. The content of elements “xmp”, “iframe”, “noembed”, “noframes”, and “plaintext” is no longer escaped. The “plaintext” element no longer have the closing tag.gh-149377: Update bundled pip to 26.1.1
gh-149231: In
tomllib, the number of parts in TOML keys is now limited.gh-149117: Fix
runpy.run_module()andrunpy.run_path()to set thenameattribute on theImportErrorthey raise.gh-149148:
ensurepip: Upgrade bundled pip to 26.1. This version fixes the CVE 2026-3219 vulnerability. Patch by Victor Stinner.gh-148093: Fix an out-of-bounds read of one byte in
binascii.a2b_uu(). Raisebinascii.Error, instead of reading past the buffer end.gh-148914: Fix memoization of in-band
PickleBufferin the Python implementation ofpickle. Previously, identicalPickleBuffers did not preserve identity, and empty writablePickleBuffermemoized an empty bytearray object in place ofb'', so the following references tob''were unpickled as an empty bytearray object.gh-138907: Support RFC 9309 in
urllib.robotparser.gh-148954: Fix XML injection vulnerability in
xmlrpc.client.dumps()where themethodnamewas not being escaped before interpolation into the XML body.gh-148801:
xml.etree.ElementTree: Fix a crash inElement.__deepcopy__on deeply nested trees.gh-148735:
xml.etree.ElementTree: Fix a use-after-free inElement.findtextwhen the element tree is mutated concurrently during the search.gh-146553: Fix infinite loop in
typing.get_type_hints()when__wrapped__forms a cycle. Patch by Shamil Abdulaev.gh-148508: An intermittent timing error when running SSL tests on iOS has been resolved.
gh-148518: If an email containing an address header that ended in an open double quote was parsed with a non-
compat32policy, accessing theusernameattribute of the mailbox accessed through that header object would result in anIndexError. It now correctly returns an empty string as the result.gh-148370:
configparser: prevent quadratic behavior when aParsingErroris raised after a parser fails to parse multiple lines. Patch by Bénédikt Tran.gh-148254: Use singular “sec” instead of “secs” in
timeitverbose output for consistency with other time units.gh-148192:
email.generator.Generator._make_boundarycould fail to detect a duplicate boundary string if linesep was not n. It now correctly detects boundary strings when linesep is rn as well.gh-146313: Fix a deadlock in
multiprocessing’s resource tracker where the parent process could hang indefinitely inos.waitpid()during interpreter shutdown if a child created viaos.fork()still held the resource tracker’s pipe open.gh-145831: Fix
email.quoprimime.decode()leaving a stray\rwheneol='\r\n'by stripping the full eol string instead of one character.gh-145105: Fix crash in
csvreader when iterating with a re-entrant iterator that callsnext()on the same reader from within__next__.gh-130750: Restore quoting of choices in
argparseerror messages for improved clarity and consistency with documentation.gh-105936: Attempting to mutate non-field attributes of
dataclasseswith both frozen and slots beingTruenow raisesFrozenInstanceErrorinstead ofTypeError. Their non-dataclass subclasses can now freely mutate non-field attributes, and the original non-slotted class can be garbage collected. The fix also handles the case of an empty__class__cell on a function found within the class (gh-148947).gh-142516:
ssl: fix reference leaks inssl.SSLContextobjects. Patch by Bénédikt Tran.gh-142831: Fix a crash in the
jsonmodule where a use-after-free could occur if the object being encoded is modified during serialization.gh-140287: The
asyncioREPL now handles exceptions when executingPYTHONSTARTUPscripts. Patch by Bartosz Sławecki.gh-90949: Add
SetBillionLaughsAttackProtectionActivationThreshold()andSetBillionLaughsAttackProtectionMaximumAmplification()to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.gh-132631: Fix “I/O operation on closed file” when parsing JSON Lines file with
JSON CLI.gh-128110: Fix bug in the parsing of
emailaddress headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject).gh-107398: Fix
tarfilestream mode exception when process the file with the gzip extra field.gh-123853: Update the table of Windows language code identifiers (LCIDs) used by
locale.getdefaultlocale()on Windows to protocol version 16.0 (2024-04-23).gh-70039: Fixed bug where
smtplib.SMTP.starttls()could fail ifsmtplib.SMTP.connect()is called explicitly rather than implicitly.gh-83281:
email: improve handling trailing garbage in address lists to avoid throwing AttributeError in certain edge casesgh-91099:
imaplib.IMAP4.login()now raises exceptions withstrinstead ofbytes. Patch by Florian Best.
IDLE¶
bpo-6699: Warn the user if a file will be overwritten when saving.
Documentation¶
gh-150319: Generic builtin and standard library types now document the meaning of their type parameters.
gh-148663: Document that
calendar.IllegalMonthErroris a subclass of bothValueErrorandIndexErrorsince Python 3.12.gh-146646: Document that
glob.glob(),glob.iglob(),pathlib.Path.glob(), andpathlib.Path.rglob()silently suppressOSErrorexceptions raised from scanning the filesystem.gh-109503: Fix documentation for
shutil.move()on usage ofos.rename()since nonatomic move might be used even if the files are on the same filesystem. Patch by Fang Li
Core and Builtins¶
gh-151112: Fix a crash in the compiler that could occur when running out of memory.
gh-151126: Fix a crash, when there’s no memory left on a device, which happened in:
code compilation -
_winapi.CreateProcess()
Now these places raise proper
MemoryErrorerrors.gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the
sys.modulescache and create duplicate module objects.gh-149156: Fix an intermittent crash after
os.fork()when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process.gh-149449: Fix a use-after-free crash when the
unicodedatamodule was removed fromsys.modulesand garbage-collected between calls that decode\N{...}escapes or use thenamereplacecodec error handler.gh-148450: Fix
abc.register()so it invalidates type version tags for registered classes.gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper
MemoryErroris now raised instead.gh-150107:
asyncio:sendfile()andsock_sendfile()event loop methods now callfile.seek(offset)if file has aseek()method, even if offset is0(default value).gh-150146: Fix a crash on a complex type variable substitution.
from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[..., ...]]used to fail due to missingNULLcheck on_unpack_argsC function call.gh-149590: Fix crash when faulthandler is imported more than once.
gh-149738:
sqlite3: Disallow removingrow_factoryandtext_factoryattributes of a connection to prevent a crash on a query.gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by
-X perf_jit(Linux perf profiler integration).gh-148820: Fix a race in
_PyRawMutexon the free-threaded build where aPy_PARK_INTRreturn from_PySemaphore_Waitcould let the waiter destroy its semaphore before the unlocking thread’s_PySemaphore_Wakeupcompleted, causing a fatalReleaseSemaphoreerror.gh-148653: Forbid
marshallingrecursive code objects which cannot be correctly unmarshalled.gh-148390: Fix an undefined behavior in
memoryviewwhen using the native boolean format (?) incast(). Previously, on some common platforms, callingmemoryview(b).cast("?").tolist()incorrectly returned[False]instead of[True]for any even byte b. Patch by Bénédikt Tran.gh-148418: Fix a possible reference leak in a corrupted
TYPE_CODEmarshal stream.gh-148222: Fix vectorcall support in
types.GenericAliaswhen the underlying type does not support the vectorcall protocol. Fix possible leaks intypes.GenericAliasandtypes.UnionTypein case of memory error.gh-145376: Fix reference leaks in various unusual error scenarios.
C API¶
gh-150907: Fix
dynamic_annotations.hheader file when built with C++ and Valgrind: addextern "C++" scopefor the C++ template. Patch by Victor Stinner.
Build¶
gh-149351: Avoid possible broken macOS framework install names when DESTDIR is specified during builds.
gh-146475: Block Apple Clang from being used to build the JIT as it ships without required LLVM tools.
gh-148535: No longer use the
gcc -fprofile-update=atomicflag on i686. The flag has been added to fix a random GCC internal error on PGO build (gh-145801) caused by corruption of profile data (.gcda files). The problem is that it makes the PGO build way slower (up to 47x slower) on i686. Since the GCC internal error was not seen on i686 so far, don’t use-fprofile-update=atomicon i686 anymore. Patch by Victor Stinner.
Python 3.13.13 final¶
Release date: 2026-04-07
macOS¶
gh-144551: Update macOS installer to use OpenSSL 3.0.19.
gh-137586: Invoke osascript with absolute path in
webbrowserandturtledemo.
Windows¶
Tests¶
gh-144418: The Android testbed’s emulator RAM has been increased from 2 GB to 4 GB.
gh-146202: Fix a race condition in regrtest: make sure that the temporary directory is created in the worker process. Previously, temp_cwd() could fail on Windows if the “build” directory was not created. Patch by Victor Stinner.
gh-144739: When Python was compiled with system expat older then 2.7.2 but tests run with newer expat, still skip
test.test_pyexpat.MemoryProtectionTest.
Security¶
gh-145986:
xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models withElementDeclHandler(). This addresses CVE 2026-4224.gh-145599: Reject control characters in
http.cookies.Morselupdate()andjs_output(). This addresses CVE 2026-3644.gh-145506: Fixes CVE 2026-2297 by ensuring that
SourcelessFileLoaderusesio.open_code()when opening.pycfiles.gh-144370: Disallow usage of control characters in status in
wsgiref.handlersto prevent HTTP header injections. Patch by Benedikt Johannes.gh-143930: Reject leading dashes in URLs passed to
webbrowser.open().
Library¶
gh-144503: Fix a regression introduced in 3.14.3 and 3.13.12 where the
multiprocessingforkserverstart method would fail withBrokenPipeErrorwhen the parent process had a very largesys.argv. The argv is now passed to the forkserver as separate command-line arguments rather than being embedded in the-ccommand string, avoiding the operating system’s per-argument length limit.gh-146613:
itertools: Fix a crash initertools.groupby()when the grouper iterator is concurrently mutated.gh-146080:
ssl: fix a crash when an SNI callback tries to use an SSL object that has already been garbage-collected. Patch by Bénédikt Tran.gh-146090:
sqlite3: fix a crash whensqlite3.Connection.create_collation()fails with SQLITE_BUSY. Patch by Bénédikt Tran.gh-146090:
sqlite3: properly raiseMemoryErrorinstead ofSystemErrorwhen a context callback fails to be allocated. Patch by Bénédikt Tran.gh-145633: Fix
struct.pack('f', float): usePyFloat_Pack4()to raiseOverflowError. Patch by Sergey B Kirpichev and Victor Stinner.gh-146310: The
ensurepipmodule no longer looks forpip-*.whlwheel packages in the current directory.gh-146076:
zoneinfo: fix crashes when deleting_weak_cachefrom azoneinfo.ZoneInfosubclass.gh-146054: Limit the size of
encodings.search_function()cache. Found by OSS Fuzz in #493449985.gh-145883:
zoneinfo: Fix heap buffer overflow reads from malformed TZif data. Found by OSS Fuzz, issues #492245058 and #492230068.gh-145750: Avoid undefined behaviour from signed integer overflow when parsing format strings in the
structmodule. Found by OSS Fuzz in #488466741.gh-145492: Fix infinite recursion in
collections.defaultdict__repr__when adefaultdictcontains itself. Based on analysis by KowalskiThomas in gh-145492.gh-145623: Fix crash in
structwhen callingrepr()or__sizeof__()on an uninitializedstruct.Structobject created viaStruct.__new__()without calling__init__().gh-145616: Detect Android sysconfig ABI correctly on 32-bit ARM Android on 64-bit ARM kernel
gh-145376: Fix null pointer dereference in unusual error scenario in
hashlib.gh-145551: Fix InvalidStateError when cancelling process created by
asyncio.create_subprocess_exec()orasyncio.create_subprocess_shell(). Patch by Daan De Meyer.gh-145417:
venv: Prevent incorrect preservation of SELinux context when copying theActivate.ps1script. The script inherited the SELinux security context of the system template directory, rather than the destination project directory.gh-145301:
hashlib: fix a crash when the initialization of the underlying C extension module fails.gh-145264: Base64 decoder (see
binascii.a2b_base64(),base64.b64decode(), etc) no longer ignores excess data after the first padded quad in non-strict (default) mode. Instead, in conformance with RFC 4648, section 3.3, it now ignores the pad character, “=”, if it is present before the end of the encoded data.gh-145158: Avoid undefined behaviour from signed integer overflow when parsing format strings in the
structmodule.gh-144984: Fix crash in
xml.parsers.expat.xmlparser.ExternalEntityParserCreate()when an allocation fails. The error paths could dereference NULLhandlersand double-decrement the parent parser’s reference count.gh-88091: Fix
unicodedata.decomposition()for Hangul characters.gh-144835: Added missing explanations for some parameters in
glob.glob()andglob.iglob().gh-144833: Fixed a use-after-free in
sslwhenSSL_new()returns NULL innewPySSLSocket(). The error was reported via a dangling pointer after the object had already been freed.gh-144259: Fix inconsistent display of long multiline pasted content in the REPL.
gh-144156: Fix the folding of headers by the
emaillibrary when RFC 2047 encoded words are used. Now whitespace is correctly preserved and also correctly added between adjacent encoded words. The latter property was broken by the fix for gh-92081, which mostly fixed previous failures to preserve whitespace.gh-66305: Fixed a hang on Windows in the
tempfilemodule when trying to create a temporary file or subdirectory in a non-writable directory.gh-140814:
multiprocessing.freeze_support()no longer sets the default start method as a side effect, which previously caused a subsequentmultiprocessing.set_start_method()call to raiseRuntimeError.gh-144475: Calling
repr()onfunctools.partial()is now safer when the partial object’s internal attributes are replaced while the string representation is being generated.gh-144538: Bump the version of pip bundled in ensurepip to version 26.0.1
gh-143637: Fixed a crash in socket.sendmsg() that could occur if ancillary data is mutated re-entrantly during argument parsing.
gh-143880: Fix data race in
functools.partial()in the free threading build.gh-143543: Fix a crash in itertools.groupby that could occur when a user-defined
__eq__()method re-enters the iterator during key comparison.gh-140652: Fix a crash in
_interpchannels.list_all()after closing a channel.gh-143698: Allow scheduler and setpgroup arguments to be explicitly
Nonewhen callingos.posix_spawn()oros.posix_spawnp(). Patch by Bénédikt Tran.gh-143698: Raise
TypeErrorinstead ofSystemErrorwhen the scheduler inos.posix_spawn()oros.posix_spawnp()is not a tuple. Patch by Bénédikt Tran.gh-143304: Fix
ctypes.CDLLto honor thehandleparameter on POSIX systems.gh-142781:
zoneinfo: fix a crash when instantiatingZoneInfoobjects for which the internal class-level cache is inconsistent.gh-142763: Fix a race condition between
zoneinfo.ZoneInfocreation andzoneinfo.ZoneInfo.clear_cache()that could raiseKeyError.gh-142787: Fix assertion failure in
sqlite3blob subscript when slicing with indices that result in an empty slice.gh-142352: Fix
asyncio.StreamWriter.start_tls()to transfer buffered data fromStreamReaderto the SSL layer, preventing data loss when upgrading a connection to TLS mid-stream (e.g., when implementing PROXY protocol support).gh-141707: Don’t change
tarfile.TarInfotype fromAREGTYPEtoDIRTYPEwhen parsing GNU long name or link headers.gh-139933: Improve
AttributeErrorsuggestions for classes with a custom__dir__()method returning a list of unsortable values. Patch by Bénédikt Tran.gh-138891: Fix
SyntaxErrorwheninspect.get_annotations(f, eval_str=True)is called on a function annotated with a PEP 646star_expressiongh-137335: Get rid of any possibility of a name conflict for named pipes in
multiprocessingandasyncioon Windows, no matter how small.gh-80667: Support lookup for Tangut Ideographs in
unicodedata.bpo-40243: Fix
unicodedata.ucd_3_2_0.numeric()for non-decimal values.
Documentation¶
gh-126676: Expand
argparsedocumentation fortype=boolwith a demonstration of the surprising behavior and pointers to common alternatives.gh-145450: Document missing public
wave.Wave_writegetter methods.
Core and Builtins¶
gh-148157: Fix an unlikely crash when parsing an invalid type comments for function parameters. Found by OSS Fuzz in #492782951.
gh-146615: Fix a crash in
__get__()for METH_METHOD descriptors when an invalid (non-type) object is passed as the second argument. Patch by Steven Sun.gh-146128: Fix a bug which could cause constant values to be partially corrupted in AArch64 JIT code. This issue is theoretical, and hasn’t actually been observed in unmodified Python interpreters.
gh-146250: Fixed a memory leak in
SyntaxErrorwhen re-initializing it.gh-146245: Fixed reference leaks in
socketwhen audit hooks raise exceptions insocket.getaddrinfo()andsocket.sendto().gh-146227: Fix wrong type in
_Py_atomic_load_uint16in the C11 atomics backend (pyatomic_std.h), which used a 32-bit atomic load instead of 16-bit. Found by Mohammed Zuhaib.gh-145990:
python --help-envsections are now sorted by environment variable name.gh-145376: Fix GC tracking in
structseq.__replace__().gh-142183: Avoid a pathological case where repeated calls at a specific stack depth could be significantly slower.
gh-145783: Fix an unlikely crash in the parser when certain errors were erroneously not propagated. Found by OSS Fuzz in #491369109.
gh-145701: Fix
SystemErrorwhen__classdict__or__conditional_annotations__is in a class-scope inlined comprehension. Found by OSS Fuzz in #491105000.gh-145335: Fix a crash in
os.pathconf()when called with-1as the path argument.gh-145234: Fixed a
SystemErrorin the parser when an encoding cookie (for example, UTF-7) decodes to carriage returns (\r). Newlines are now normalized after decoding in the string tokenizer.Patch by Pablo Galindo.
gh-130555: Fix use-after-free in
dict.clear()when the dictionary values are embedded in an object and a destructor causes re-entrant mutation of the dictionary.gh-145008: Fix a bug when calling certain methods at the recursion limit which manifested as a corruption of Python’s operand stack. Patch by Ken Jin.
gh-144872: Fix heap buffer overflow in the parser found by OSS-Fuzz.
gh-144766: Fix a crash in fork child process when perf support is enabled.
gh-144759: Fix undefined behavior in the lexer when
startandmulti_line_startpointers areNULLin_PyLexer_remember_fstring_buffers()and_PyLexer_restore_fstring_buffers(). TheNULLpointer arithmetic (NULL - valid_pointer) is now guarded with explicitNULLchecks.gh-144601: Fix crash when importing a module whose
PyInitfunction raises an exception from a subinterpreter.gh-143636: Fix a crash when calling
SimpleNamespace.__replace__()on non-namespace instances. Patch by Bénédikt Tran.gh-143650: Fix race condition in
importlibwhere a thread could receive a stale module reference when another thread’s import fails.gh-140594: Fix an out of bounds read when a single NUL character is read from the standard input. Patch by Shamil Abdulaev.
gh-91636: While performing garbage collection, clear weakrefs to unreachable objects that are created during running of finalizers. If those weakrefs were are not cleared, they could reveal unreachable objects.
gh-130327: Fix erroneous clearing of an object’s
__dict__if overwritten at runtime.gh-80667: Literals using the
\N{name}escape syntax can now construct CJK ideographs and Hangul syllables using case-insensitive names.
Build¶
gh-146541: The Android testbed can now be built for 32-bit ARM and x86 targets.
gh-146450: The Android build script was modified to improve parity with other platform build scripts.
gh-145801: When Python build is optimized with GCC using PGO, use
-fprofile-update=atomicoption to use atomic operations when updating profile information. This option reduces the risk of gcov Data Files (.gcda) corruption which can cause random GCC crashes. Patch by Victor Stinner.gh-129259: Fix AIX build failures caused by incorrect struct alignment in
_Py_CODEUNITand_Py_BackoffCounterby adding AIX-specific#pragma packdirectives.
Python 3.13.12 final¶
Release date: 2026-02-03
Windows¶
gh-128067: Fix a bug in PyREPL on Windows where output without a trailing newline was overwritten by the next prompt.
Tools/Demos¶
gh-142095: Make gdb ‘py-bt’ command use frame from thread local state when available. Patch by Sam Gross and Victor Stinner.
Tests¶
gh-144415: The Android testbed now distinguishes between stdout/stderr messages which were triggered by a newline, and those triggered by a manual call to
flush. This fixes logging of progress indicators and similar content.gh-65784: Add support for parametrized resource
wantobjectsin regrtests, which allows to run Tkinter tests with the specified value oftkinter.wantobjects, for example-u wantobjects=0.gh-143553: Add support for parametrized resources, such as
-u xpickle=2.7.gh-142836: Accommodated Solaris in
test_pdb.test_script_target_anonymous_pipe.gh-129401: Fix a flaky test in
test_repr_rlockthat checks the representation ofmultiprocessing.RLock.bpo-31391: Forward-port test_xpickle from Python 2 to Python 3 and add the resource back to test’s command line.
Security¶
gh-144125:
BytesGeneratorwill now refuse to serialize (write) headers that are unsafely folded or delimited; seeverify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
gh-143925: Reject control characters in
data:URL media types.gh-143919: Reject control characters in
http.cookies.Morselfields and values.gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
Library¶
gh-144380: Improve performance of
io.BufferedReaderline iteration by ~49%.gh-144169: Fix three crashes when non-string keyword arguments are supplied to objects in the
astmodule.gh-144100: Fixed a crash in ctypes when using a deprecated
POINTER(str)type inargtypes. Instead of aborting, ctypes now raises a proper Python exception when the pointer target type is unresolved.gh-144050: Fix
stat.filemode()in the pure-Python implementation to avoid misclassifying invalid mode values as block devices.gh-144023: Fixed validation of file descriptor 0 in posix functions when used with follow_symlinks parameter.
gh-143999: Fix an issue where
inspect.getgeneratorstate()andinspect.getcoroutinestate()could fail for generators wrapped bytypes.coroutine()in the suspended state.gh-143706: Fix
multiprocessingforkserver so thatsys.argvis correctly set before__main__is preloaded. Previously,sys.argvwas empty during main module import in forkserver child processes. This fixes a regression introduced in 3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test provided by Thomas Watson, thanks!gh-143638: Forbid reentrant calls of the
pickle.Picklerandpickle.Unpicklermethods for the C implementation. Previously, this could cause crash or data corruption, now concurrent calls of methods of the same object raiseRuntimeError.gh-78724: Raise
RuntimeError’s when user attempts to call methods on half-initializedStructobjects, For example, created byStruct.__new__(Struct). Patch by Sergey B Kirpichev.gh-143602: Fix a inconsistency issue in
write()that leads to unexpected buffer overwrite by deduplicating the buffer exports.gh-143547: Fix
sys.unraisablehook()when the hook raises an exception and changessys.unraisablehook(): hold a strong reference to the old hook. Patch by Victor Stinner.gh-143378: Fix use-after-free crashes when a
BytesIOobject is concurrently mutated duringwrite()orwritelines().gh-143346: Fix incorrect wrapping of the Base64 data in
plistlib._PlistWriterwhen the indent contains a mix of tabs and spaces.gh-143310:
tkinter: fix a crash when a Pythonlistis mutated during the conversion to a Tcl object (e.g., when setting a Tcl variable). Patch by Bénédikt Tran.gh-143309: Fix a crash in
os.execve()on non-Windows platforms when given a custom environment mapping which is then mutated during parsing. Patch by Bénédikt Tran.gh-143308:
pickle: fix use-after-free crashes when aPickleBufferis concurrently mutated by a custom buffer callback during pickling. Patch by Bénédikt Tran and Aaron Wieczorek.gh-143237: Fix support of named pipes in the rotating
logginghandlers.gh-143249: Fix possible buffer leaks in Windows overlapped I/O on error handling.
gh-143241:
zoneinfo: fix infinite loop inZoneInfo.from_filewhen parsing a malformed TZif file. Patch by Fatih Celik.gh-142830:
sqlite3: fix use-after-free crashes when the connection’s callbacks are mutated during a callback execution. Patch by Bénédikt Tran.gh-143200:
xml.etree.ElementTree: fix use-after-free crashes in__getitem__()and__setitem__()methods ofElementwhen the element is concurrently mutated. Patch by Bénédikt Tran.gh-142195: Updated timeout evaluation logic in
subprocessto be compatible with deterministic environments like Shadow where time moves exactly as requested.gh-143145: Fixed a possible reference leak in ctypes when constructing results with multiple output parameters on error.
gh-122431: Corrected the error message in
readline.append_history_file()to state thatnelementsmust be non-negative instead of positive.gh-143004: Fix a potential use-after-free in
collections.Counter.update()when user code mutates the Counter during an update.gh-143046: The
asyncioREPL no longer prints copyright and version messages in the quiet mode (-q). Patch by Bartosz Sławecki.gh-140648: The
asyncioREPL now respects the-Iflag (isolated mode). Previously, it would load and executePYTHONSTARTUPeven if the flag was set. Contributed by Bartosz Sławecki.gh-142991: Fixed socket operations such as recvfrom() and sendto() for FreeBSD divert(4) socket.
gh-143010: Fixed a bug in
mailboxwhere the precise timing of an external event could result in the library opening an existing file instead of a file it expected to create.gh-142881: Fix concurrent and reentrant call of
atexit.unregister().gh-112127: Fix possible use-after-free in
atexit.unregister()when the callback is unregistered during comparison.gh-142783: Fix zoneinfo use-after-free with descriptor _weak_cache. a descriptor as _weak_cache could cause crashes during object creation. The fix ensures proper reference counting for descriptor-provided objects.
gh-142754: Add the ownerDocument attribute to
xml.dom.minidomelements and attributes created by directly instantiating theElementorAttrclass. Note that this way of creating nodes is not supported; creator functions likexml.dom.Document.documentElement()should be used instead.gh-142784: The
asyncioREPL now properly closes the loop upon the end of interactive session. Previously, it could cause surprising warnings. Contributed by Bartosz Sławecki.gh-142555:
array: fix a crash ina[i] = vwhen converting i to an index viai.__index__ori.__float__mutates the array.gh-142594: Fix crash in
TextIOWrapper.close()when the underlying buffer’sclosedproperty callsdetach().gh-142451:
hmac: Ensure that theHMAC.block_sizeattribute is correctly copied byHMAC.copy. Patch by Bénédikt Tran.gh-142495:
collections.defaultdictnow prioritizes__setitem__()when inserting default values fromdefault_factory. This prevents race conditions where a default value would overwrite a value set beforedefault_factoryreturns.gh-142651:
unittest.mock: fix a thread safety issue whereMock.call_countmay return inaccurate values when the mock is called concurrently from multiple threads.gh-142595: Added type check during initialization of the
decimalmodule to prevent a crash in case of broken stdlib. Patch by Sergey B Kirpichev.gh-142517: The non-
compat32emailpolicies now correctly handle refolding encoded words that contain bytes that can not be decoded in their specified character set. Previously this resulted in an encoding exception during folding.gh-112527: The help text for required options in
argparseno longer extended with “ (default: None)”.gh-142315: Pdb can now run scripts from anonymous pipes used in process substitution. Patch by Bartosz Sławecki.
gh-142282: Fix
winreg.QueryValueEx()to not accidentally read garbage buffer under race condition.gh-75949: Fix
argparseto preserve|separators in mutually exclusive groups when the usage line wraps due to length.gh-68552:
MisplacedEnvelopeHeaderDefectandMissing header namedefects are now correctly passed to thehandle_defectmethod ofpolicyinFeedParser.gh-142006: Fix a bug in the
email.policy.defaultfolding algorithm which incorrectly resulted in a doubled newline when a line ending at exactly max_line_length was followed by an unfoldable token.gh-105836: Fix
asyncio.run_coroutine_threadsafe()leaving underlying cancelled asyncio task running.gh-139971:
pydoc: Ensure that the link to the online documentation of a stdlib module is correct.gh-139262: Some keystrokes can be swallowed in the new
PyREPLon Windows, especially when used together with the ALT key. Fix by Chris Eibl.gh-138897: Improved
license/copyright/creditsdisplay in the REPL: now uses a pager.gh-79986: Add parsing for
ReferencesandIn-Reply-Toheaders to theemaillibrary that parses the header content as lists of message id tokens. This prevents them from being folded incorrectly.gh-109263: Starting a process from spawn context in
multiprocessingno longer sets the start method globally.gh-90871: Fixed an off by one error concerning the backlog parameter in
create_unix_server(). Contributed by Christian Harries.gh-132715: Skip writing objects during marshalling once a failure has occurred.
gh-127529: Correct behavior of
asyncio.selector_events.BaseSelectorEventLoop._accept_connection()in handlingConnectionAbortedErrorin a loop. This improves performance on OpenBSD.
IDLE¶
gh-143774: Better explain the operation of Format / Format Paragraph.
Documentation¶
gh-140806: Add documentation for
enum.bin().
Core and Builtins¶
gh-144307: Prevent a reference leak in module teardown at interpreter finalization.
gh-144194: Fix error handling in perf jitdump initialization on memory allocation failure.
gh-141805: Fix crash in
setwhen objects with the same hash are concurrently added to the set after removing an element with the same hash while the set still contains elements with the same hash.gh-143670: Fixes a crash in
ga_repr_items_listfunction.gh-143377: Fix a crash in
_interpreters.capture_exception()when the exception is incorrectly formatted. Patch by Bénédikt Tran.gh-143189: Fix crash when inserting a non-
strkey into a split table dictionary when the key matches an existing key in the split table but has no corresponding value in the dict.gh-143228: Fix use-after-free in perf trampoline when toggling profiling while threads are running or during interpreter finalization with daemon threads active. The fix uses reference counting to ensure trampolines are not freed while any code object could still reference them. Pach by Pablo Galindo
gh-142664: Fix a use-after-free crash in
memoryview.__hash__when the__hash__method of the referenced object mutates that object or the view. Patch by Bénédikt Tran.gh-142557: Fix a use-after-free crash in bytearray.__mod__ when the
bytearrayis mutated while formatting the%-style arguments. Patch by Bénédikt Tran.gh-143195: Fix use-after-free crashes in
bytearray.hex()andmemoryview.hex()when the separator’s__len__()mutates the original object. Patch by Bénédikt Tran.gh-143135: Set
sys.flags.inspectto1whenPYTHONINSPECTis0. Previously, it was set to0in this case.gh-143003: Fix an overflow of the shared empty buffer in
bytearray.extend()when__length_hint__()returns 0 for non-empty iterator.gh-143006: Fix a possible assertion error when comparing negative non-integer
floatandintwith the same number of bits in the integer part.gh-142776: Fix a file descriptor leak in import.c
gh-142829: Fix a use-after-free crash in
contextvars.Contextcomparison when a custom__eq__method modifies the context viaset().gh-142766: Clear the frame of a generator when
generator.close()is called.gh-142737: Tracebacks will be displayed in fallback mode even if
io.open()is lost. Previously, this would crash the interpreter. Patch by Bartosz Sławecki.gh-142554: Fix a crash in
divmod()when_pylong.int_divmod()does not return a tuple of length two exactly. Patch by Bénédikt Tran.gh-142560: Fix use-after-free in
bytearraysearch-like methods (find(),count(),index(),rindex(), andrfind()) by marking the storage as exported which causes reallocation attempts to raiseBufferError. Forcontains(),split(), andrsplit()the buffer protocol is used for this.gh-142343: Fix SIGILL crash on m68k due to incorrect assembly constraint.
gh-141732: Ensure the
__repr__()forExceptionGroupandBaseExceptionGroupdoes not change when the exception sequence that was original passed in to its constructor is subsequently mutated.gh-100964: Fix reference cycle in exhausted generator frames. Patch by Savannah Ostrowski.
gh-140373: Correctly emit
PY_UNWINDevent when generator object is closed. Patch by Mikhail Efimov.gh-138568: Adjusted the built-in
help()function so that empty inputs are ignored in interactive mode.gh-127773: Do not use the type attribute cache for types with incompatible MRO.
C API¶
gh-142571:
PyUnstable_CopyPerfMapFile()now checks that opening the file succeeded before flushing.
Build¶
gh-142454: When calculating the digest of the JIT stencils input, sort the hashed files by filenames before adding their content to the hasher. This ensures deterministic hash input and hence deterministic hash, independent on filesystem order.
gh-141808: When running
make clean-retain-profile, keep the generated JIT stencils. That way, the stencils are not generated twice when Profile-guided optimization (PGO) is used. It also allows distributors to supply their own pre-built JIT stencils.gh-138061: Ensure reproducible builds by making JIT stencil header generation deterministic.
Python 3.13.11 final¶
Release date: 2025-12-05
Security¶
gh-142145: Remove quadratic behavior in
xml.minidomnode ID cache clearing.gh-119451: Fix a potential memory denial of service in the
http.clientmodule. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including aMemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.gh-119452: Fix a potential memory denial of service in the
http.servermodule. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including aMemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library¶
gh-140797: Revert changes to the undocumented
re.Scannerclass. Capturing groups are still allowed for backward compatibility, although using them can lead to incorrect result. They will be forbidden in future Python versions.gh-142206: The resource tracker in the
multiprocessingmodule now uses the original communication protocol, as in Python 3.14.0 and below, by default. This avoids issues with upgrading Python while it is running. (Note that such ‘in-place’ upgrades are not tested.) The tracker remains compatible with subprocesses that use new protocol (that is, subprocesses using Python 3.13.10, 3.14.1 and 3.15).
Core and Builtins¶
Python 3.13.10 final¶
Release date: 2025-12-02
Tools/Demos¶
gh-141442: The iOS testbed now correctly handles test arguments that contain spaces.
Tests¶
gh-140482: Preserve and restore the state of
stty echoas part of the test environment.gh-140082: Update
python -m testto setFORCE_COLOR=1when being run with color enabled so thatunittestwhich is run by it with redirected output will output in color.gh-136442: Use exitcode
1instead of5ifunittest.TestCase.setUpClass()raises an exception
Security¶
gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” if there are no bytes prepended to the ZIP file.
gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in
html.parser.HTMLParser.gh-136063:
email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.gh-136065: Fix quadratic complexity in
os.path.expandvars().gh-119342: Fix a potential memory denial of service in the
plistlibmodule. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including aMemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library¶
gh-74389: When the stdin being used by a
subprocess.Popeninstance is closed, this is now ignored insubprocess.Popen.communicate()instead of leaving the class in an inconsistent state.gh-87512: Fix
subprocess.Popen.communicate()timeout handling on Windows when writing large input. Previously, the timeout was ignored during stdin writing, causing the method to block indefinitely if the child process did not consume input quickly. The stdin write is now performed in a background thread, allowing the timeout to be properly enforced.gh-141473: When
subprocess.Popen.communicate()was called with input and a timeout and is called for a second time after aTimeoutExpiredexception before the process has died, it should no longer hang.gh-59000: Fix
pdbbreakpoint resolution for class methods when the module defining the class is not imported.gh-141570: Support file-like object raising
OSErrorfromfileno()in color detection (_colorize.can_colorize()). This can occur whensys.stdoutis redirected.gh-141659: Fix bad file descriptor errors from
_posixsubprocesson AIX.gh-141497:
ipaddress: ensure that the methodsIPv4Network.hosts()andIPv6Network.hosts()always return an iterator.gh-140938: The
statistics.stdev()andstatistics.pstdev()functions now raise aValueErrorwhen the input contains an infinity or a NaN.gh-124111: Updated Tcl threading configuration in
_tkinterto assume that threads are always available in Tcl 9 and later.gh-137109: The
os.forkand related forking APIs will no longer warn in the common case where Linux or macOS platform APIs return the number of threads in a process and find the answer to be 1 even when aos.register_at_fork()after_in_parent=callback (re)starts a thread.gh-141314: Fix assertion failure in
io.TextIOWrapper.tell()when reading files with standalone carriage return (\r) line endings.gh-141311: Fix assertion failure in
io.BytesIO.readinto()and undefined behavior arising when read position is above capcity inio.BytesIO.gh-141141: Fix a thread safety issue with
base64.b85decode(). Contributed by Benel Tayar.gh-140911:
collections: Ensure that the methodsUserString.rindex()andUserString.index()acceptcollections.UserStringinstances as the sub argument.gh-140797: The undocumented
re.Scannerclass now forbids regular expressions containing capturing groups in its lexicon patterns. Patterns using capturing groups could previously lead to crashes with segmentation fault. Use non-capturing groups (?:…) instead.gh-140815:
faulthandlernow detects if a frame or a code object is invalid or freed. Patch by Victor Stinner.gh-100218: Correctly set
errnowhensocket.if_nametoindex()orsocket.if_indextoname()raise anOSError. Patch by Bénédikt Tran.gh-140875: Fix handling of unclosed character references (named and numerical) followed by the end of file in
html.parser.HTMLParserwithconvert_charrefs=False.gh-140734:
multiprocessing: fix off-by-one error when checking the length of a temporary socket file path. Patch by Bénédikt Tran.gh-140874: Bump the version of pip bundled in
ensurepipto version 25.3gh-140691: In
urllib.request, when opening a FTP URL fails because a data connection cannot be made, the control connection’s socket is now closed to avoid aResourceWarning.gh-103847: Fix hang when cancelling process created by
asyncio.create_subprocess_exec()orasyncio.create_subprocess_shell(). Patch by Kumar Aditya.gh-140590: Fix arguments checking for the
functools.partial.__setstate__()that may lead to internal state corruption and crash. Patch by Sergey Miryanov.gh-140634: Fix a reference counting bug in
os.sched_param.__reduce__().gh-140633: Ignore
AttributeErrorwhen setting a module’s__file__attribute when loading an extension module packaged as Apple Framework.gh-140593:
xml.parsers.expat: Fix a memory leak that could affect users withElementDeclHandler()set to a custom element declaration handler. Patch by Sebastian Pipping.gh-140607: Inside
io.RawIOBase.read(), validate that the count of bytes returned byio.RawIOBase.readinto()is valid (inside the provided buffer).gh-138162: Fix
logging.LoggerAdapterwithmerge_extra=Trueand without the extra argument.gh-140474: Fix memory leak in
array.arraywhen creating arrays from an emptystrand theutype code.gh-140272: Fix memory leak in the
clear()method of thedbm.gnudatabase.gh-140041: Fix import of
ctypeson Android and Cygwin when ABI flags are present.gh-139905: Add suggestion to error message for
typing.Genericsubclasses whencls.__parameters__is missing due to a parent class failing to callsuper().__init_subclass__()in its__init_subclass__.gh-139845: Fix to not print KeyboardInterrupt twice in default asyncio REPL.
gh-139783: Fix
inspect.getsourcelines()for the case when a decorator is followed by a comment or an empty line.gh-70765:
http.server: fix default handling of HTTP/0.9 requests inBaseHTTPRequestHandler. Previously,BaseHTTPRequestHandler.parse_request()incorrectly waited for headers in the request although those are not supported in HTTP/0.9. Patch by Bénédikt Tran.gh-139391: Fix an issue when, on non-Windows platforms, it was not possible to gracefully exit a
python -m asyncioprocess suspended by Ctrl+Z and later resumed by fg other than with kill.gh-101828: Fix
'shift_jisx0213','shift_jis_2004','euc_jisx0213'and'euc_jis_2004'codecs truncating null chars as they were treated as part of multi-character sequences.gh-139246: fix: paste zero-width in default repl width is wrong.
gh-90949: Add
SetAllocTrackerActivationThreshold()andSetAllocTrackerMaximumAmplification()to xmlparser objects to tune protections against disproportional amounts of dynamic memory usage from within an Expat parser. Patch by Bénédikt Tran.gh-139065: Fix trailing space before a wrapped long word if the line length is exactly width in
textwrap.gh-138859: Fix generic type parameterization raising a
TypeErrorwhen omitting aParamSpecthat has a default which is not a list of types.gh-138775: Use of
python -mwithbase64has been fixed to detect input from a terminal so that it properly notices EOF.gh-98896: Fix a failure in multiprocessing resource_tracker when SharedMemory names contain colons. Patch by Rani Pinchuk.
gh-75989:
tarfile.TarFile.extractall()andtarfile.TarFile.extract()now overwrite symlinks when extracting hardlinks. (Contributed by Alexander Enrique Urieles Nieto in gh-75989.)gh-83424: Allows creating a
ctypes.CDLLwithout name when passing a handle as an argument.gh-136234: Fix
asyncio.WriteTransport.writelines()to be robust to connection failure, by using the same behavior aswrite().gh-136057: Fixed the bug in
pdbandbdbwherenextandstepcan’t go over the line if a loop exists in the line.gh-135307:
email: Fix exception inset_content()when encoding text and max_line_length is set to0orNone(unlimited).gh-134453: Fixed
subprocess.Popen.communicate()input=handling ofmemoryviewinstances that were non-byte shaped on POSIX platforms. Those are now properly cast to a byte shaped view instead of truncating the input. Windows platforms did not have this bug.gh-102431: Clarify constraints for “logical” arguments in methods of
decimal.Context.
IDLE¶
gh-96491: Deduplicate version number in IDLE shell title bar after saving to a file.
Documentation¶
gh-141994:
xml.sax.handler: Make Documentation ofxml.sax.handler.feature_external_geswarn of opening up to external entity attacks. Patch by Sebastian Pipping.gh-140578: Remove outdated sencence in the documentation for
multiprocessing, that implied thatconcurrent.futures.ThreadPoolExecutordid not exist.
Core and Builtins¶
gh-142048: Fix quadratically increasing garbage collection delays in free-threaded build.
gh-141930: When importing a module, use Python’s regular file object to ensure that writes to
.pycfiles are complete or an appropriate error is raised.gh-120158: Fix inconsistent state when enabling or disabling monitoring events too many times.
gh-141579: Fix
sys.activate_stack_trampoline()to properly support theperf_jitbackend. Patch by Pablo Galindo.gh-141312: Fix the assertion failure in the
__setstate__method of the range iterator when a non-integer argument is passed. Patch by Sergey Miryanov.gh-140939: Fix memory leak when
bytearrayorbytesis formated with the%*bformat with a large width that results in aMemoryError.gh-140530: Fix a reference leak when
raise exc from causefails. Patch by Bénédikt Tran.gh-140576: Fixed crash in
tokenize.generate_tokens()in case of specific incorrect input. Patch by Mikhail Efimov.gh-140551: Fixed crash in
dictifdict.clear()is called at the lookup stage. Patch by Mikhail Efimov and Inada Naoki.gh-140471: Fix potential buffer overflow in
ast.ASTnode initialization when encountering malformed_fieldscontaining non-str.gh-140406: Fix memory leak when an object’s
__hash__()method returns an object that isn’t anint.gh-140306: Fix memory leaks in cross-interpreter channel operations and shared namespace handling.
gh-140301: Fix memory leak of
PyConfigin subinterpreters.gh-140000: Fix potential memory leak when a reference cycle exists between an instance of
typing.TypeAliasType,typing.TypeVar,typing.ParamSpec, ortyping.TypeVarTupleand its__name__attribute. Patch by Mikhail Efimov.gh-139748: Fix reference leaks in error branches of functions accepting path strings or bytes such as
compile()andos.system(). Patch by Bénédikt Tran.gh-139516: Fix lambda colon erroneously start format spec in f-string in tokenizer.
gh-139640: Fix swallowing some syntax warnings in different modules if they accidentally have the same message and are emitted from the same line. Fix duplicated warnings in the
finallyblock.gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with
PyEval_SetProfileAllThreads()orPyEval_SetTraceAllThreads()or their Python equivalentsthreading.settrace_all_threads()andthreading.setprofile_all_threads().gh-133400: Fixed Ctrl+D (^D) behavior in _pyrepl module to match old pre-3.13 REPL behavior.
C API¶
gh-140042: Removed the sqlite3_shutdown call that could cause closing connections for sqlite when used with multiple sub interpreters.
gh-140487: Fix
Py_RETURN_NOTIMPLEMENTEDin limited C API 3.11 and older: don’t treatPy_NotImplementedas immortal. Patch by Victor Stinner.
Python 3.13.9 final¶
Release date: 2025-10-14
Library¶
gh-139783: Fix
inspect.getsourcelines()for the case when a decorator is followed by a comment or an empty line.
Python 3.13.8 final¶
Release date: 2025-10-07
macOS¶
Windows¶
Tools/Demos¶
gh-139330: SBOM generation tool didn’t cross-check the version and checksum values against the
Modules/expat/refresh.shscript, leading to the values becoming out-of-date during routine updates.gh-137873: The iOS test runner has been simplified, resolving some issues that have been observed using the runner in GitHub Actions and Azure Pipelines test environments.
Tests¶
gh-139208: Fix regrtest
--fast-ci --verbose: don’t ignore the--verboseoption anymore. Patch by Victor Stinner.
Security¶
gh-139400:
xml.parsers.expat: Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created byExternalEntityParserCreate(). Patch by Sebastian Pipping.gh-139283:
sqlite3: correctly handle maximum number of rows to fetch inCursor.fetchmanyand reject negative values forCursor.arraysize. Patch by Bénédikt Tran.gh-135661: Fix CDATA section parsing in
html.parser.HTMLParseraccording to the HTML5 standard:] ]>and]] >no longer end the CDATA section. Add private method_set_support_cdata()which can be used to specify how to parse<[CDATA[— as a CDATA section in foreign content (SVG or MathML) or as a bogus comment in the HTML namespace.
Library¶
gh-139312: Upgrade bundled libexpat to 2.7.3
gh-139289: Do a real lazy-import on
rlcompleterinpdband restore the existing completer after importingrlcompleter.gh-139210: Fix use-after-free when reporting unknown event in
xml.etree.ElementTree.iterparse(). Patch by Ken Jin.gh-138860: Lazy import
rlcompleterinpdbto avoid deadlock in subprocess.gh-112729: Fix crash when calling
_interpreters.createwhen the process is out of memory.gh-139076: Fix a bug in the
pydocmodule that was hiding functions in a Python module if they were implemented in an extension module and the module did not have__all__.gh-138998: Update bundled libexpat to 2.7.2
gh-130567: Fix possible crash in
locale.strxfrm()due to a platform bug on macOS.gh-138779: Support device numbers larger than
2**63-1for thest_rdevfield of theos.stat_resultstructure.gh-128636: Fix crash in PyREPL when os.environ is overwritten with an invalid value for mac
gh-88375: Fix normalization of the
robots.txtrules and URLs in theurllib.robotparsermodule. No longer ignore trailing?. Distinguish raw special characters?,=and&from the percent-encoded ones.gh-111788: Fix parsing errors in the
urllib.robotparsermodule. Don’t fail trying to parse weird paths. Don’t fail trying to decode non-UTF-8robots.txtfiles.gh-138432:
zoneinfo.reset_tzpath()will now convert anyos.PathLikeobjects it receives into strings before adding them toTZPATH. It will raiseTypeErrorif anything other than a string is found after this conversion. If given anos.PathLikeobject that represents a relative path, it will now raiseValueErrorinstead ofTypeError, and present a more informative error message.gh-138008: Fix segmentation faults in the
ctypesmodule due to invalidargtypes. Patch by Dung Nguyen.gh-60462: Fix
locale.strxfrm()on Solaris (and possibly other platforms).gh-138204: Forbid expansion of shared anonymous
memory mapson Linux, which caused a bus error.gh-138010: Fix an issue where defining a class with a
@warnings.deprecated-decorated base class may not invoke the correct__init_subclass__()method in cases involving multiple inheritance. Patch by Brian Schubert.gh-138133: Prevent infinite traceback loop when sending CTRL^C to Python through
strace.gh-134869: Fix an issue where pressing Ctrl+C during tab completion in the REPL would leave the autocompletion menu in a corrupted state.
gh-137317:
inspect.signature()now correctly handles classes that use a descriptor on a wrapped__init__()or__new__()method. Contributed by Yongyu Yan.gh-137754: Fix import of the
zoneinfomodule if the C implementation of thedatetimemodule is not available.gh-137490: Handle
ECANCELEDin the same way asEINTRinsignal.sigwaitinfo()on NetBSD.gh-137477: Fix
inspect.getblock(),inspect.getsourcelines()andinspect.getsource()for generator expressions.gh-137017: Fix
threading.Thread.is_aliveto remainTrueuntil the underlying OS thread is fully cleaned up. This avoids false negatives in edge cases involving thread monitoring or prematurethreading.Thread.is_alivecalls.gh-136134:
SMTP.auth_cram_md5()now raises anSMTPExceptioninstead of aValueErrorif Python has been built without MD5 support. In particular,SMTPclients will not attempt to use this method even if the remote server is assumed to support it. Patch by Bénédikt Tran.gh-136134:
IMAP4.login_cram_md5now raises anIMAP4.errorif CRAM-MD5 authentication is not supported. Patch by Bénédikt Tran.gh-135386: Fix opening a
dbm.sqlite3database for reading from read-only file or directory.gh-126631: Fix
multiprocessingforkserverbug which prevented__main__from being preloaded.gh-123085: In a bare call to
importlib.resources.files(), ensure the caller’s frame is properly detected whenimportlib.resourcesis itself available as a compiled module only (no source).gh-118981: Fix potential hang in
multiprocessing.popen_spawn_posixthat can happen when the child proc dies early by closing the child fds right away.gh-78319: UTF8 support for the IMAP APPEND command has been made RFC compliant.
bpo-38735: Fix failure when importing a module from the root directory on unix-like platforms with sys.pycache_prefix set.
bpo-41839: Allow negative priority values from
os.sched_get_priority_min()andos.sched_get_priority_max()functions.
Core and Builtins¶
gh-134466: Don’t run PyREPL in a degraded environment where setting termios attributes is not allowed.
gh-71810: Raise
OverflowErrorfor(-1).to_bytes()for signed conversions when bytes count is zero. Patch by Sergey B Kirpichev.gh-105487: Remove non-existent
__copy__(),__deepcopy__(), and__bases__from the__dir__()entries oftypes.GenericAlias.gh-134163: Fix a hang when the process is out of memory inside an exception handler.
gh-138479: Fix a crash when a generic object’s
__typing_subst__returns an object that isn’t atuple.gh-137576: Fix for incorrect source code being shown in tracebacks from the Basic REPL when
PYTHONSTARTUPis given. Patch by Adam Hartz.gh-132744: Certain calls now check for runaway recursion and respect the system recursion limit.
C API¶
gh-87135: Attempting to acquire the GIL after runtime finalization has begun in a different thread now causes the thread to hang rather than terminate, which avoids potential crashes or memory corruption caused by attempting to terminate a thread that is running code not specifically designed to support termination. In most cases this hanging is harmless since the process will soon exit anyway.
While not officially marked deprecated until 3.14,
PyThread_exit_threadis no longer called internally and remains solely for interface compatibility. Its behavior is inconsistent across platforms, and it can only be used safely in the unlikely case that every function in the entire call stack has been designed to support the platform-dependent termination mechanism. It is recommended that users of this function change their design to not require thread termination. In the unlikely case that thread termination is needed and can be done safely, users may migrate to calling platform-specific APIs such aspthread_exit(POSIX) or_endthreadex(Windows) directly.
Build¶
gh-135734: Python can correctly be configured and built with
./configure --enable-optimizations --disable-test-modules. Previously, the profile data generation step failed due to PGO tests where immortalization couldn’t be properly suppressed. Patch by Bénédikt Tran.
Python 3.13.7 final¶
Release date: 2025-08-14
Library¶
gh-137583: Fix a deadlock introduced in 3.13.6 when a call to
ssl.SSLSocket.recvwas blocked in one thread, and then another method on the object (such asssl.SSLSocket.send) was subsequently called in another thread.gh-137044: Return large limit values as positive integers instead of negative integers in
resource.getrlimit(). Accept large values and reject negative values (exceptRLIM_INFINITY) for limits inresource.setrlimit().gh-136914: Fix retrieval of
doctest.DocTest.linenofor objects decorated withfunctools.cache()orfunctools.cached_property.gh-131788: Make
ResourceTracker.sendfrommultiprocessingre-entrant safe
Documentation¶
gh-136155: We are now checking for fatal errors in EPUB builds in CI.
Core and Builtins¶
gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with
PyEval_SetProfileAllThreads()orPyEval_SetTraceAllThreads()or their Python equivalentsthreading.settrace_all_threads()andthreading.setprofile_all_threads().
Python 3.13.6 final¶
Release date: 2025-08-06
macOS¶
Windows¶
gh-137134: Update Windows installer to ship with SQLite 3.50.4.
Tools/Demos¶
gh-135968: Stubs for
stripare now provided as part of an iOS install.
Tests¶
Security¶
gh-135661: Fix parsing start and end tags in
html.parser.HTMLParseraccording to the HTML5 standard.Whitespaces no longer accepted between
</and the tag name. E.g.</ script>does not end the script section.Vertical tabulation (
\v) and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are\t\n\r\fand space.Null character (U+0000) no longer ends the tag name.
Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first
>in quoted attribute value. E.g.</script/foo=">"/>.Multiple slashes and whitespaces between the last attribute and closing
>are now ignored in both start and end tags. E.g.<a foo=bar/ //>.Multiple
=between attribute name and value are no longer collapsed. E.g.<a foo==bar>produces attribute “foo” with value “=bar”.
gh-102555: Fix comment parsing in
html.parser.HTMLParseraccording to the HTML5 standard.--!>now ends the comment.-- >no longer ends the comment. Support abnormally ended empty comments<-->and<--->.gh-135462: Fix quadratic complexity in processing specially crafted input in
html.parser.HTMLParser. End-of-file errors are now handled according to the HTML5 specs – comments and declarations are automatically closed, tags are ignored.gh-118350: Fix support of escapable raw text mode (elements “textarea” and “title”) in
html.parser.HTMLParser.
Library¶
gh-132710: If possible, ensure that
uuid.getnode()returns the same result even across different processes. Previously, the result was constant only within the same process. Patch by Bénédikt Tran.gh-137273: Fix debug assertion failure in
locale.setlocale()on Windows.gh-137257: Bump the version of pip bundled in ensurepip to version 25.2
gh-81325:
tarfile.TarFilenow accepts a path-like when working on a tar archive. (Contributed by Alexander Enrique Urieles Nieto in gh-81325.)gh-130522: Fix unraisable
TypeErrorraised during interpreter shutdown in thethreadingmodule.gh-130577:
tarfilenow validates archives to ensure member offsets are non-negative. (Contributed by Alexander Enrique Urieles Nieto in gh-130577.)gh-136549: Fix signature of
threading.excepthook().gh-136523: Fix
wave.Wave_writeemitting an unraisable when open raises.gh-52876: Add missing
keepends(defaultTrue) parameter tocodecs.StreamReaderWriter.readline()andcodecs.StreamReaderWriter.readlines().gh-85702: If
zoneinfo._common.load_tzdatais given a package without a resource azoneinfo.ZoneInfoNotFoundErroris raised rather than aPermissionError. Patch by Victor Stinner.gh-134759: Fix
UnboundLocalErrorinemail.message.Message.get_payload()when the payload to decode is abytesobject. Patch by Kliment Lamonov.gh-136028: Fix parsing month names containing “İ” (U+0130, LATIN CAPITAL LETTER I WITH DOT ABOVE) in
time.strptime(). This affects locales az_AZ, ber_DZ, ber_MA and crh_UA.gh-135995: In the palmos encoding, make byte
0x9bdecode to›(U+203A - SINGLE RIGHT-POINTING ANGLE QUOTATION MARK).gh-53203: Fix
time.strptime()for%cand%xformats on locales byn_ER, wal_ET and lzh_TW, and for%Xformat on locales ar_SA, bg_BG and lzh_TW.gh-91555: An earlier change, which was introduced in 3.13.4, has been reverted. It disabled logging for a logger during handling of log messages for that logger. Since the reversion, the behaviour should be as it was before 3.13.4.
gh-135878: Fixes a crash of
types.SimpleNamespaceon free threading builds, when several threads were calling its__repr__()method at the same time.gh-135836: Fix
IndexErrorinasyncio.loop.create_connection()that could occur when non-OSErrorexception is raised during connection and socket’sclose()raisesOSError.gh-135836: Fix
IndexErrorinasyncio.loop.create_connection()that could occur when the Happy Eyeballs algorithm resulted in an empty exceptions list during connection attempts.gh-135855: Raise
TypeErrorinstead ofSystemErrorwhen_interpreters.set___main___attrs()is passed a non-dict object. Patch by Brian Schubert.gh-135815:
netrc: skip security checks ifos.getuid()is missing. Patch by Bénédikt Tran.gh-135640: Address bug where it was possible to call
xml.etree.ElementTree.ElementTree.write()on an ElementTree object with an invalid root element. This behavior blanked the file passed towriteif it already existed.gh-135444: Fix
asyncio.DatagramTransport.sendto()to account for datagram header size when data cannot be sent.gh-135497: Fix
os.getlogin()failing for longer usernames on BSD-based platforms.gh-135487: Fix
reprlib.Repr.repr_int()when given integers with more thansys.get_int_max_str_digits()digits. Patch by Bénédikt Tran.gh-135335:
multiprocessing: Flushstdoutandstderrafter preloading modules in theforkserver.gh-135244:
uuid: when the MAC address cannot be determined, the 48-bit node ID is now generated with a cryptographically-secure pseudo-random number generator (CSPRNG) as per RFC 9562, §6.10.3. This affectsuuid1().gh-135069: Fix the “Invalid error handling” exception in
encodings.idna.IncrementalDecoderto correctly replace the ‘errors’ parameter.gh-134698: Fix a crash when calling methods of
ssl.SSLContextorssl.SSLSocketacross multiple threads.gh-132124: On POSIX-compliant systems,
multiprocessing.util.get_temp_dir()now ignoresTMPDIR(and similar environment variables) if the path length ofAF_UNIXsocket files exceeds the platform-specific maximum length when using the forkserver start method. Patch by Bénédikt Tran.gh-133439: Fix dot commands with trailing spaces are mistaken for multi-line SQL statements in the sqlite3 command-line interface.
gh-132969: Prevent the
ProcessPoolExecutorexecutor thread, which remains running whenshutdown(wait=False), from attempting to adjust the pool’s worker processes after the object state has already been reset during shutdown. A combination of conditions, including a worker process having terminated abormally, resulted in an exception and a potential hang when the still-running executor thread attempted to replace dead workers within the pool.gh-130664: Support the
'_'digit separator in formatting of the integral part ofDecimal’s. Patch by Sergey B Kirpichev.gh-85702: If
zoneinfo._common.load_tzdatais given a package without a resource aZoneInfoNotFoundErroris raised rather than aIsADirectoryError.gh-130664: Handle corner-case for
Fraction’s formatting: treat zero-padding (preceding the width field by a zero ('0') character) as an equivalent to a fill character of'0'with an alignment type of'=', just as in case offloat’s.
Documentation¶
Core and Builtins¶
gh-58124: Fix name of the Python encoding in Unicode errors of the code page codec: use “cp65000” and “cp65001” instead of “CP_UTF7” and “CP_UTF8” which are not valid Python code names. Patch by Victor Stinner.
gh-137314: Fixed a regression where raw f-strings incorrectly interpreted escape sequences in format specifications. Raw f-strings now properly preserve literal backslashes in format specs, matching the behavior from Python 3.11. For example,
rf"{obj:\xFF}"now correctly produces'\\xFF'instead of'ÿ'. Patch by Pablo Galindo.gh-136541: Fix some issues with the perf trampolines on x86-64 and aarch64. The trampolines were not being generated correctly for some cases, which could lead to the perf integration not working correctly. Patch by Pablo Galindo.
gh-109700: Fix memory error handling in
PyDict_SetDefault().gh-78465: Fix error message for
cls.__new__(cls, ...)whereclsis not instantiable builtin or extension type (withtp_newset toNULL).gh-135871: Non-blocking mutex lock attempts now return immediately when the lock is busy instead of briefly spinning in the free threading build.
gh-135607: Fix potential
weakrefraces in an object’s destructor on the free threaded build.gh-135496: Fix typo in the f-string conversion type error (“exclamanation” -> “exclamation”).
gh-130077: Properly raise custom syntax errors when incorrect syntax containing names that are prefixes of soft keywords is encountered. Patch by Pablo Galindo.
gh-135148: Fixed a bug where f-string debug expressions (using =) would incorrectly strip out parts of strings containing escaped quotes and # characters. Patch by Pablo Galindo.
gh-133136: Limit excess memory usage in the free threading build when a large dictionary or list is resized and accessed by multiple threads.
gh-132617: Fix
dict.update()modification check that could incorrectly raise a “dict mutated during update” error when a different dictionary was modified that happens to share the same underlying keys object.gh-91153: Fix a crash when a
bytearrayis concurrently mutated during item assignment.gh-127971: Fix off-by-one read beyond the end of a string in string search.
gh-125723: Fix crash with
gi_frame.f_localswhen generator frames outlive their generator. Patch by Mikhail Efimov.
Build¶
gh-135497: Fix the detection of
MAXLOGNAMEin theconfigure.acscript.
Python 3.13.5 final¶
Release date: 2025-06-11
Windows¶
gh-135151: Avoid distributing modified
pyconfig.hin the traditional installer. Extension module builds must always specifyPy_GIL_DISABLEDwhen targeting the free-threaded runtime.
Tests¶
gh-135120: Add
test.support.subTests().
Library¶
gh-133967: Do not normalize
localename ‘C.UTF-8’ to ‘en_US.UTF-8’.gh-135326: Restore support of integer-like objects with
__index__()inrandom.getrandbits().gh-135321: Raise a correct exception for values greater than 0x7fffffff for the
BINSTRINGopcode in the C implementation ofpickle.gh-135276: Backported bugfixes in zipfile.Path from zipp 3.23. Fixed
.name,.stemand other basename-based properties on Windows when working with a zipfile on disk.gh-134151:
email: FixTypeErrorinemail.utils.decode_params()when sorting RFC 2231 continuations that contain an unnumbered section.gh-134152:
email: Fix parsing of email message ID with invalid domain.gh-127081: Fix libc thread safety issues with
osby replacinggetloginwithgetlogin_rre-entrant version.gh-131884: Fix formatting issues in
json.dump()when both indent and skipkeys are used.
Core and Builtins¶
C API¶
gh-134989: Fix
Py_RETURN_NONE,Py_RETURN_TRUEandPy_RETURN_FALSEmacros in the limited C API 3.11 and older: don’t treatPy_None,Py_TrueandPy_Falseas immortal. Patch by Victor Stinner.gh-134989: Implement
PyObject_DelAttr()andPyObject_DelAttrString()as macros in the limited C API 3.12 and older. Patch by Victor Stinner.
Python 3.13.4 final¶
Release date: 2025-06-03
Windows¶
gh-130727: Fix a race in internal calls into WMI that can result in an “invalid handle” exception under high load. Patch by Chris Eibl.
gh-76023: Make
os.path.realpath()ignore Windows error 1005 when in non-strict mode.gh-133626: Ensures packages are not accidentally bundled into the traditional installer.
gh-133512: Add warnings to Python Launcher for Windows about use of subcommands belonging to the Python install manager.
Tests¶
gh-133744: Fix multiprocessing interrupt test. Add an event to synchronize the parent process with the child process: wait until the child process starts sleeping. Patch by Victor Stinner.
gh-133639: Fix
TestPyReplAutoindent.test_auto_indent_default()doesn’t runinput_code.gh-133131: The iOS testbed will now select the most recently released “SE-class” device for testing if a device isn’t explicitly specified.
gh-109981: The test helper that counts the list of open file descriptors now uses the optimised
/dev/fdapproach on all Apple platforms, not just macOS. This avoids crashes caused by guarded file descriptors.
Security¶
gh-135034: Fixes multiple issues that allowed
tarfileextraction filters (filter="data"andfilter="tar") to be bypassed using crafted symlinks and hard links.Addresses CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, and CVE 2025-4517.
gh-133767: Fix use-after-free in the “unicode-escape” decoder with a non-“strict” error handler.
gh-128840: Short-circuit the processing of long IPv6 addresses early in
ipaddressto prevent excessive memory consumption and a minor denial-of-service.
Library¶
gh-134718:
ast.dump()now only omitsNoneand[]values if they are default values.gh-128840: Fix parsing long IPv6 addresses with embedded IPv4 address.
gh-134696: Built-in HACL* and OpenSSL implementations of hash function constructors now correctly accept the same documented named arguments. For instance,
md5()could be previously invoked asmd5(data=data)ormd5(string=string)depending on the underlying implementation but these calls were not compatible. Patch by Bénédikt Tran.gh-134210:
curses.window.getch()now correctly handles signals. Patch by Bénédikt Tran.gh-80334:
multiprocessing.freeze_support()now checks for work on any “spawn” start method platform rather than only on Windows.gh-114177: Fix
asyncioto not close subprocess pipes which would otherwise error out when the event loop is already closed.gh-134152: Fixed
UnboundLocalErrorthat could occur duringemailheader parsing if an expected trailing delimiter is missing in some contexts.gh-62184: Remove import of C implementation of
io.FileIOfrom Python implementation which has its own implementationgh-133982: Emit
RuntimeWarningin the Python implementation ofiowhen the file-like object is not closed explicitly in the presence of multiple I/O layers.gh-133890: The
tarfilemodule now handlesUnicodeEncodeErrorin the same way asOSErrorwhen cannot extract a member.gh-134097: Fix interaction of the new REPL and
-X showrefcountcommand line option.gh-133889: The generated directory listing page in
http.server.SimpleHTTPRequestHandlernow only shows the decoded path component of the requested URL, and not the query and fragment.gh-134098: Fix handling paths that end with a percent-encoded slash (
%2for%2F) inhttp.server.SimpleHTTPRequestHandler.gh-134062:
ipaddress: fix collisions in__hash__()forIPv4NetworkandIPv6Networkobjects.gh-133745: In 3.13.3 we accidentally changed the signature of the asyncio
create_task()family of methods and how it calls a custom task factory in a backwards incompatible way. Since some 3rd party libraries have already made changes to work around the issue that might break if we simply reverted the changes, we’re instead changing things to be backwards compatible with 3.13.2 while still supporting those workarounds for 3.13.3. In particular, the special-casing ofnameandcontextis back (until 3.14) and consequently eager tasks may still find that their name hasn’t been set before they execute their first yielding await.gh-71253: Raise
ValueErrorinopen()if opener returns a negative file-descriptor in the Python implementation ofioto match the C implementation.gh-77057: Fix handling of invalid markup declarations in
html.parser.HTMLParser.gh-133489:
random.getrandbits()can now generate more that 231 bits.random.randbytes()can now generate more that 256 MiB.gh-133290: Fix attribute caching issue when setting
ctypes._Pointer._type_in the undocumented and deprecatedctypes.SetPointerType()function and the undocumentedset_type()method.gh-132876:
ldexp()on Windows doesn’t round subnormal results before Windows 11, but should. Python’smath.ldexp()wrapper now does round them, so results may change slightly, in rare cases of very small results, on Windows versions before 11.gh-133089: Use original timeout value for
subprocess.TimeoutExpiredwhen the funcsubprocess.run()is called with a timeout instead of sometimes a confusing partial remaining time out value used internally on the finalwait().gh-133009:
xml.etree.ElementTree: Fix a crash inElement.__deepcopy__when the element is concurrently mutated. Patch by Bénédikt Tran.gh-132995: Bump the version of pip bundled in ensurepip to version 25.1.1
gh-132017: Fix error when
pyreplis suspended, then resumed and terminated.gh-132673: Fix a crash when using
_align_ = 0and_fields_ = []in actypes.Structure.gh-132527: Include the valid typecode ‘w’ in the error message when an invalid typecode is passed to
array.array.gh-132439: Fix
PyREPLon Windows: characters entered via AltGr are swallowed. Patch by Chris Eibl.gh-132429: Fix support of Bluetooth sockets on NetBSD and DragonFly BSD.
gh-132106:
QueueListener.startnow raises aRuntimeErrorif the listener is already started.gh-132417: Fix a
NULLpointer dereference when a C function called usingctypeswithrestypepy_objectreturnsNULL.gh-132385: Fix instance error suggestions trigger potential exceptions in
object.__getattr__()intraceback.gh-132308: A
traceback.TracebackExceptionnow correctly renders the__context__and__cause__attributes from falseyException, and theexceptionsattribute from falseyExceptionGroup.gh-132250: Fixed the
SystemErrorincProfilewhen locating the actual C function of a method raises an exception.gh-132063: Prevent exceptions that evaluate as falsey (namely, when their
__bool__method returnsFalseor their__len__method returns 0) from being ignored byconcurrent.futures.ProcessPoolExecutorandconcurrent.futures.ThreadPoolExecutor.gh-119605: Respect
follow_wrappedfor__init__()and__new__()methods when getting the class signature for a class withinspect.signature(). Preserve class signature after wrapping withwarnings.deprecated(). Patch by Xuehai Pan.gh-91555: Ignore log messages generated during handling of log messages, to avoid deadlock or infinite recursion. [NOTE: This change has since been reverted.]
gh-131434: Improve error reporting for incorrect format in
time.strptime().gh-131127: Systems using LibreSSL now successfully build.
gh-130999: Avoid exiting the new REPL and offer suggestions even if there are non-string candidates when errors occur.
gh-130941: Fix
configparser.ConfigParserparsing empty interpolation withallow_no_valueset toTrue.gh-129098: Fix REPL traceback reporting when using
compile()with an inexisting file. Patch by Bénédikt Tran.gh-130631:
http.cookiejar.join_header_words()is now more similar to the original Perl version. It now quotes the same set of characters and always quote values that end with"\n".gh-129719: Fix missing
socket.CAN_RAW_ERR_FILTERconstant in the socket module on Linux systems. It was missing since Python 3.11.gh-124096: Turn on virtual terminal mode and enable bracketed paste in REPL on Windows console. (If the terminal does not support bracketed paste, enabling it does nothing.)
gh-122559: Remove
__reduce__()and__reduce_ex__()methods that always raiseTypeErrorin the C implementation ofio.FileIO,io.BufferedReader,io.BufferedWriterandio.BufferedRandomand replace them with default__getstate__()methods that raiseTypeError. This restores fine details of behavior of Python 3.11 and older versions.gh-122179:
hashlib.file_digest()now raisesBlockingIOErrorwhen no data is available during non-blocking I/O. Before, it added spurious null bytes to the digest.gh-86155:
html.parser.HTMLParser.close()no longer loses data when the<script>tag is not closed. Patch by Waylan Limberg.gh-69426: Fix
html.parser.HTMLParserto not unescape character entities in attribute values if they are followed by an ASCII alphanumeric or an equals sign.bpo-44172: Keep a reference to original
curseswindows in subwindows so that the original window does not get deleted before subwindows.
IDLE¶
gh-112936: fix IDLE: no Shell menu item in single-process mode.
Documentation¶
gh-107006: Move documentation and example code for
threading.localfrom its docstring to the official docs.
Library¶
gh-134908: Fix crash when iterating over lines in a text file on the free threaded build.
Core and Builtins¶
gh-127682: No longer call
__iter__twice in list comprehensions. This brings the behavior of list comprehensions in line with other forms of iteration
Library¶
gh-134381: Fix
RuntimeErrorwhen using a not-startedthreading.Threadafter callingos.fork()
Core and Builtins¶
gh-128066: Fixes an edge case where PyREPL improperly threw an error when Python is invoked on a read only filesystem while trying to write history file entries.
gh-134100: Fix a use-after-free bug that occurs when an imported module isn’t in
sys.modulesafter its initial import. Patch by Nico-Posada.gh-133703: Fix hashtable in dict can be bigger than intended in some situations.
gh-132869: Fix crash in the free threading build when accessing an object attribute that may be concurrently inserted or deleted.
gh-132762:
fromkeys()no longer loops forever when adding a small set of keys to a large base dict. Patch by Angela Liss.gh-133543: Fix a possible memory leak that could occur when directly accessing instance dictionaries (
__dict__) that later become part of a reference cycle.gh-133516: Raise
ValueErrorwhen constantsTrue,FalseorNoneare used as an identifier after NFKC normalization.gh-133441: Fix crash upon setting an attribute with a
dictsubclass. Patch by Victor Stinner.gh-132942: Fix two races in the type lookup cache. This affected the free-threaded build and could cause crashes (apparently quite difficult to trigger).
gh-132713: Fix
repr(list)race condition: hold a strong reference to the item while callingrepr(item). Patch by Victor Stinner.gh-132747: Fix a crash when calling
__get__()of a method with aNonesecond argument.gh-132542: Update
Thread.native_idafter fork(2) to ensure accuracy. Patch by Noam Cohen.gh-124476: Fix decoding from the locale encoding in the C.UTF-8 locale.
gh-131927: Compiler warnings originating from the same module and line number are now only emitted once, matching the behaviour of warnings emitted from user code. This can also be configured with
warningsfilters.gh-127682: No longer call
__iter__twice when creating and executing a generator expression. Creating a generator expression from a non-interable will raise only when the generator expression is executed. This brings the behavior of generator expressions in line with other generators.gh-131878: Handle uncaught exceptions in the main input loop for the new REPL.
gh-131878: Fix support of unicode characters with two or more codepoints on Windows in the new REPL.
gh-130804: Fix support of unicode characters on Windows in the new REPL.
gh-130070: Fixed an assertion error for
exec()passed a stringsourceand a non-Noneclosure. Patch by Bartosz Sławecki.gh-129958: Fix a bug that was allowing newlines inconsitently in format specifiers for single-quoted f-strings. Patch by Pablo Galindo.
C API¶
gh-132909: Fix an overflow when handling the K format in
Py_BuildValue(). Patch by Bénédikt Tran.
Build¶
gh-134923: Windows builds with profile-guided optimization enabled now use
/GENPROFILEand/USEPROFILEinstead of deprecated/LTCG:options.gh-133183: iOS compiler shims now include
IPHONEOS_DEPLOYMENT_TARGETin target triples, ensuring that SDK version minimums are honored.gh-133167: Fix compilation process with
--enable-optimizationsand--without-docstrings.gh-132649: The
PClayoutscript now allows passing--include-tcltkon Windows ARM64.gh-117088: AIX linker don’t support -h option, so avoid it through platform check
gh-132026: Fix use of undefined identifiers in platform triplet detection on MIPS Linux platforms.
Python 3.13.3 final¶
Release date: 2025-04-08
macOS¶
Windows¶
gh-131423: Update bundled version of OpenSSL to 3.0.16. The new build also disables uplink support, which may be relevant to embedders but has no impact on normal use.
gh-131025: Update Windows installer to ship with SQLite 3.49.1.
gh-131020: pylauncher correctly detects a BOM when searching for the shebang. Fix by Chris Eibl.
Tools/Demos¶
Tests¶
gh-131050:
test_ssl.test_dh_paramsis skipped if the underlying TLS library does not support finite-field ephemeral Diffie-Hellman.gh-129200: Multiple iOS testbed runners can now be started at the same time without introducing an ambiguity over simulator ownership.
gh-130292: The iOS testbed will now run successfully on a machine that has not previously run Xcode tests (such as CI configurations).
gh-130293: The tests of terminal colorization are no longer sensitive to the value of the
TERMvariable in the testing environment.gh-126332: Add unit tests for pyrepl.
Security¶
gh-131809: Update bundled libexpat to 2.7.1
gh-131261: Upgrade to libexpat 2.7.0
gh-127371: Avoid unbounded buffering for
tempfile.SpooledTemporaryFile.writelines(). Previously, disk spillover was only checked after the lines iterator had been exhausted. This is now done after each line is written.gh-121284: Fix bug in the folding of rfc2047 encoded-words when flattening an email message using a modern email policy. Previously when an encoded-word was too long for a line, it would be decoded, split across lines, and re-encoded. But commas and other special characters in the original text could be left unencoded and unquoted. This could theoretically be used to spoof header lines using a carefully constructed encoded-word if the resulting rendered email was transmitted or re-parsed.
Library¶
gh-132174: Fix function name in error message of
_interpreters.run_string.gh-132171: Fix crash of
_interpreters.run_stringon string subclasses.gh-129204: Introduce new
_PYTHON_SUBPROCESS_USE_POSIX_SPAWNenvironment variable knob insubprocessto control the use ofos.posix_spawn().gh-132159: Do not shadow user arguments in generated
__new__()by decoratorwarnings.deprecated. Patch by Xuehai Pan.gh-132075: Fix possible use of
socketaddress structures with uninitialized members. Now all structure members are initialized with zeroes by default.gh-132002: Fix crash when deallocating
contextvars.ContextVarwith weird unahashable string names.gh-131668:
socket: Fix code parsing AF_BLUETOOTH socket addresses.gh-131492: Fix a resource leak when constructing a
gzip.GzipFilewith a filename fails, for example when passing an invalidcompresslevel.gh-131325: Fix sendfile fallback implementation to drain data after writing to transport in
asyncio.gh-129843: Fix incorrect argument passing in
warnings.warn_explicit().gh-131204: Use monospace font from System Font Stack for cross-platform support in
difflib.HtmlDiff.gh-130940: The
PyConfig.use_system_loggerattribute, introduced in Python 3.13.2, has been removed. The introduction of this attribute inadvertently introduced an ABI breakage on macOS and iOS. The use of the system logger is now enabled by default on iOS, and disabled by default on macOS.gh-131045: Fix issue with
__contains__, values, and pseudo-members forenum.Flag.gh-130959: Fix pure-Python implementation of
datetime.time.fromisoformat()to reject times with spaces in fractional part (for example,12:34:56.400 +02:00), matching the C implementation. Patch by Michał Gorny.gh-130637: Add validation for numeric response data in poplib.POP3.stat() method
gh-130461: Remove
.. index::directives from theuuidmodule documentation. These directives previously created entries in the general index forgetnode()as well as theuuid1(),uuid3(),uuid4(), anduuid5()constructor functions.gh-130379: The zipapp module now calculates the list of files to be added to the archive before creating the archive. This avoids accidentally including the target when it is being created in the source directory.
gh-130285: Fix corner case for
random.sample()allowing the counts parameter to specify an empty population. So now,sample([], 0, counts=[])andsample('abc', k=0, counts=[0, 0, 0])both give the same result assample([], 0).gh-130250: Fix regression in
traceback.print_last().gh-130230: Fix crash in
pow()with onlyDecimalthird argument.gh-118761: Reverts a change in the previous release attempting to make some stdlib imports used within the
subprocessmodule lazy as this was causing errors during__del__finalizers calling methods such asterminate, orkill, orsend_signal.gh-130164: Fixed failure to raise
TypeErrorininspect.Signature.bind()for positional-only arguments provided by keyword when a variadic keyword argument (e.g.**kwargs) is present.gh-130151: Fix reference leaks in
_hashlib.hmac_new()and_hashlib.hmac_digest(). Patch by Bénédikt Tran.gh-130145: Fix
asyncio.AbstractEventloop.run_forever()when another loop is already running.gh-129726: Fix
gzip.GzipFileraising an unraisable exception during garbage collection when referring to a temporary object by breaking the reference loop withweakref.gh-127750: Remove broken
functools.singledispatchmethod()caching introduced in gh-85160.gh-129583: Update bundled pip to 25.0.1
gh-97850: Update the deprecation warning of
importlib.abc.Loader.load_module().gh-129646: Update the locale alias mapping in the
localemodule to match the latest X Org locale alias mapping and support new locales in Glibc 2.41.gh-129603: Fix bugs where
sqlite3.Rowobjects could segfault if their inheriteddescriptionwas set toNone. Patch by Erlend Aasland.gh-128231: Execution of multiple statements in the new REPL now stops immediately upon the first exception encountered. Patch by Bartosz Sławecki.
gh-117779: Fix reading duplicated entries in
zipfileby name. Reading duplicated entries (except the last one) byZipInfonow emits a warning instead of raising an exception.gh-128772: Fix
pydocfor methods with the__module__attribute equal toNone.gh-92897: Scheduled the deprecation of the
check_homeargument ofsysconfig.is_python_build()to Python 3.15.gh-128657: Fix possible extra reference when using objects returned by
hashlib.sha256()under free threading.gh-128703: Fix
mimetypes.guess_type()to use default mapping for emptyContent-Typein registry.gh-128308: Support the name keyword argument for eager tasks in
asyncio.loop.create_task(),asyncio.create_task()andasyncio.TaskGroup.create_task(), by passing on all kwargs to the task factory set byasyncio.loop.set_task_factory().gh-128388: Fix
PyREPLon Windows to support more keybindings, like the Control-← and Control-→ word-skipping keybindings and those with meta (i.e. Alt), e.g. Alt-d tokill-wordor Alt-Backspacebackward-kill-word.gh-126037:
xml.etree.ElementTree: Fix a crash inElement.find,Element.findtextandElement.findallwhen the tag to find implements an__eq__()method mutating the element being queried. Patch by Bénédikt Tran.gh-127712: Fix handling of the
secureargument oflogging.handlers.SMTPHandler.gh-126033:
xml.etree.ElementTree: Fix a crash inElement.removewhen the element is concurrently mutated. Patch by Bénédikt Tran.gh-118201: Fixed intermittent failures of
os.confstr,os.pathconfandos.sysconfon iOS and Android.gh-124927: Non-printing characters are now properly handled in the new REPL.
IDLE¶
gh-129873: Simplify displaying the IDLE doc by only copying the text section of idle.html to idlelib/help.html. Patch by Stan Ulbrych.
Documentation¶
gh-131417: Mention
asyncio.Futureandasyncio.Taskin generic classes list.gh-125722: Require Sphinx 8.2.0 or later to build the Python documentation. Patch by Adam Turner.
gh-129712: The wheel tags supported by each macOS universal SDK option are now documented.
gh-46236: C API: Document
PyUnicode_RSplit(),PyUnicode_Partition()andPyUnicode_RPartition().
Core and Builtins¶
gh-132011: Fix crash when calling
list.append()as an unbound method.gh-131998: Fix a crash when using an unbound method descriptor object in a function where a bound method descriptor was used.
gh-131988: Fix a performance regression that caused scaling bottlenecks in the free threaded build in 3.13.1 and 3.13.2.
gh-131719: Fix missing NULL check in
_PyMem_FreeDelayedin free-threaded build.gh-131670: Fix
anext()failing on sync__anext__()raising an exception.gh-131141: Fix data race in
sys.monitoringinstrumentation while registering callback.gh-130932: Fix incorrect exception handling in
_PyModule_IsPossiblyShadowinggh-130851: Fix a crash in the free threading build when constructing a
codeobject withco_conststhat contains instances of types that are not otherwise generated by the bytecode compiler.gh-130794: Fix memory leak in the free threaded build when resizing a shared list or dictionary from multiple short-lived threads.
gh-130775: Do not crash on negative
columnandend_columninastlocations.gh-130382: Fix
PyRefTracer_DESTROYnot being sent fromPython/ceval.cPy_DECREF().gh-130618: Fix a bug that was causing
UnicodeDecodeErrororSystemErrorto be raised when using f-strings withlambdaexpressions with non-ASCII characters. Patch by Pablo Galindogh-130163: Fix possible crashes related to concurrent change and use of the
sysmodule attributes.gh-88887: Fixing multiprocessing Resource Tracker process leaking, usually observed when running Python as PID 1.
gh-130115: Fix an issue with thread identifiers being sign-extended on some platforms.
gh-128396: Fix a crash that occurs when calling
locals()inside an inline comprehension that uses the same local variable as the outer frame scope where the variable is a free or cell var.gh-116042: Fix location for SyntaxErrors of invalid escapes in the tokenizer. Patch by Pablo Galindo
Library¶
gh-129983: Fix data race in compile_template in
sre.c.
Core and Builtins¶
gh-129967: Fix a race condition in the free threading build when
repr(set)is called concurrently withset.clear().gh-129900: Fix return codes inside
SystemExitnot getting returned by the REPL.gh-129732: Fixed a race in
_Py_qsbr_reservein the free threading build.gh-129643: Fix thread safety of
PyList_Insert()in free-threading builds.gh-129668: Fix race condition when raising
MemoryErrorin the free threaded build.gh-129643: Fix thread safety of
PyList_SetItem()in free-threading builds. Patch by Kumar Aditya.gh-128714: Fix the potential races in get/set dunder methods
__annotations__,__annotate__and__type_params__for function object, and add related tests.gh-128632: Disallow
__classdict__as the name of a type parameter. Using this name would previously crash the interpreter in some circumstances.gh-127953: The time to handle a
LINEevent in sys.monitoring (and sys.settrace) is now independent of the number of lines in the code object.gh-125331:
from __future__ import barry_as_FLUFLnow works in more contexts, including when it is used in files, with the-cflag, and in the REPL when there are multiple statements on the same line. Previously, it worked only on subsequent lines in the REPL, and when the appropriate flags were passed directly tocompile(). Patch by Pablo Galindo.
C API¶
gh-131740: Update PyUnstable_GC_VisitObjects to traverse perm gen.
gh-129533: Update
PyGC_Enable(),PyGC_Disable(),PyGC_IsEnabled()to use atomic operation for thread-safety at free-threading build. Patch by Donghee Na.
Build¶
gh-131865: The DTrace build now properly passes the
CCandCFLAGSvariables to thedtracecommand when utilizing SystemTap on Linux.gh-131675: Fix mimalloc library builds for 32-bit ARM targets.
gh-130673: Fix potential
KeyErrorwhen handling object sections during JIT building process.gh-130740: Ensure that
Python.his included beforestdbool.hunlesspyconfig.his included before or in some platform-specific contexts.gh-129838: Don’t redefine
_Py_NO_SANITIZE_UNDEFINEDwhen compiling with a recent GCC version and undefined sanitizer enabled.gh-129660: Drop
test_embedfrom PGO training, whose contribution in recent versions is considered to be ignorable.
Python 3.13.2 final¶
Release date: 2025-02-04
macOS¶
gh-127592: Usage of the unified Apple System Log APIs was disabled when the minimum macOS version is earlier than 10.12.
Windows¶
gh-127353: Allow to force color output on Windows using environment variables. Patch by Andrey Efremov.
Tools/Demos¶
Tests¶
Security¶
gh-105704: When using
urllib.parse.urlsplit()andurllib.parse.urlparse()host parsing would not reject domain names containing square brackets ([and]). Square brackets are only valid for IPv6 and IPvFuture hosts according to RFC 3986 Section 3.2.2.gh-127655: Fixed the
asyncio.selector_events._SelectorSocketTransporttransport not pausing writes for the protocol when the buffer reaches the high water mark when usingasyncio.WriteTransport.writelines().gh-126108: Fix a possible
NULLpointer dereference inPySys_AddWarnOptionUnicode().gh-80222: Fix bug in the folding of quoted strings when flattening an email message using a modern email policy. Previously when a quoted string was folded so that it spanned more than one line, the surrounding quotes and internal escapes would be omitted. This could theoretically be used to spoof header lines using a carefully constructed quoted string if the resulting rendered email was transmitted or re-parsed.
gh-119511: Fix a potential denial of service in the
imaplibmodule. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. On many systems this is harmless as unused virtual memory is only a mapping, but if this hit a virtual address size limit it could lead to aMemoryErroror other process crash. On unusual systems or builds where all allocated memory is touched and backed by actual ram or storage it could’ve consumed resources doing so until similarly crashing.
Library¶
gh-129502: Unlikely errors in preparing arguments for
ctypescallback are now handled in the same way as errors raised in the callback of in converting the result of the callback – usingsys.unraisablehook()instead ofsys.excepthook()and not settingsys.last_excand other variables.gh-129403: Corrected
ValueErrormessage forasyncio.Barrierandthreading.Barrier.gh-129409: Fix an integer overflow in the
csvmodule when writing a data field larger than 2GB.gh-118761: Improve import time of
subprocessby lazy importinglocaleandsignal. Patch by Taneli Hukkinen.gh-129346: In
sqlite3, handle out-of-memory when creating user-defined SQL functions.gh-129061: Fix FORCE_COLOR and NO_COLOR when empty strings. Patch by Hugo van Kemenade.
gh-128550: Removed an incorrect optimization relating to eager tasks in
asyncio.TaskGroupthat resulted in cancellations being missed.gh-128991: Release the enter frame reference within
bdbcallbackgh-128978: Fix a
NameErrorinsysconfig.expand_makefile_vars(). Patch by Bénédikt Tran.gh-128961: Fix a crash when setting state on an exhausted
array.arrayiterator.gh-128894: Fix
traceback.TracebackException._format_syntax_errornot to fail on exceptions with custom metadata.gh-128916: Do not attempt to set
SO_REUSEPORTon sockets of address families other thanAF_INETandAF_INET6, as it is meaningless with these address families, and the call with fail with Linux kernel 6.12.9 and newer.gh-128679: Fix
tracemalloc.stop()race condition. Fixtracemallocto support callingtracemalloc.stop()in one thread, while another thread is tracing memory allocations. Patch by Victor Stinner.gh-128636: Fix PyREPL failure when
os.environis overwritten with an invalid value.gh-128562: Fix possible conflicts in generated
tkinterwidget names if the widget class name ends with a digit.gh-128498: Default to stdout isatty for color detection instead of stderr. Patch by Hugo van Kemenade.
gh-128552: Fix cyclic garbage introduced by
asyncio.loop.create_task()andasyncio.TaskGroup.create_task()holding a reference to the created task if it is eager.gh-128479: Fix
asyncio.staggered.staggered_race()leaking tasks and issuing an unhandled exception.gh-128400: Fix crash when using
faulthandler.dump_traceback()while other threads are active on the free threaded build.gh-88834: Unify the instance check for
typing.Unionandtypes.UnionType:Unionnow uses the instance checks against its parameters instead of the subclass checks.gh-128302: Fix
xml.dom.xmlbuilder.DOMEntityResolver.resolveEntity(), which was broken by the Python 3.0 transition.gh-128302: Allow
xml.dom.xmlbuilder.DOMParser.parse()to correctly handlexml.dom.xmlbuilder.DOMInputSourceinstances that only have asystemIdattribute set.gh-112064: Fix incorrect handling of negative read sizes in
HTTPResponse.read. Patch by Yury Manushkin.gh-128131: Completely support random access of uncompressed unencrypted read-only zip files obtained by
ZipFile.open.gh-112328:
enum.EnumDictcan now be used without resorting to private API.gh-127975: Avoid reusing quote types in
ast.unparse()if not needed.gh-128062: Revert the font of
turtledemo’s menu bar to its default value and display the shortcut keys in the correct position.gh-128014: Fix resetting the default window icon by passing
default=''to thetkintermethodwm_iconbitmap().gh-115514: Fix exceptions and incomplete writes after
asyncio._SelectorTransportis closed before writes are completed.gh-41872: Fix quick extraction of module docstrings from a file in
pydoc. It now supports docstrings with single quotes, escape sequences, raw string literals, and other Python syntax.gh-127060: Set TERM environment variable to “dumb” to disable traceback colors in IDLE, since IDLE doesn’t understand ANSI escape sequences. Patch by Victor Stinner.
gh-126742: Fix support of localized error messages reported by dlerror(3) and gdbm_strerror in
ctypesanddbm.gnufunctions respectively. Patch by Bénédikt Tran.gh-127873: When
-Eis set, only ignorePYTHON_COLORSand notFORCE_COLOR/NO_COLOR/TERMwhen colourising output. Patch by Hugo van Kemenade.gh-127870: Detect recursive calls in ctypes
_as_parameter_handling. Patch by Victor Stinner.gh-127847: Fix the position when doing interleaved seeks and reads in uncompressed, unencrypted zip files returned by
zipfile.ZipFile.open().gh-127732: The
platformmodule now correctly detects Windows Server 2025.gh-126821: macOS and iOS apps can now choose to redirect stdout and stderr to the system log during interpreter configuration.
gh-93312: Include
<sys/pidfd.h>to getos.PIDFD_NONBLOCKconstant. Patch by Victor Stinner.gh-83662: Add missing
__class_getitem__method to the Python implementation offunctools.partial(), to make it compatible with the C version. This is mainly relevant for alternative Python implementations like PyPy and GraalPy, because CPython will usually use the C-implementation of that function.gh-127586:
multiprocessing.pool.Poolnow properly restores blocked signal handlers of the parent thread when creating processes via either spawn or forkserver.gh-98188: Fix an issue in
email.message.Message.get_payload()where data cannot be decoded if the Content Transfer Encoding mechanism contains trailing whitespaces or additional junk text. Patch by Hui Liu.gh-127257: In
ssl, system call failures that OpenSSL reports usingERR_LIB_SYSare now raised asOSError.gh-127096: Do not recreate unnamed section on every read in
configparser.ConfigParser. Patch by Andrey Efremov.gh-127196: Fix crash when dict with keys in invalid encoding were passed to several functions in
_interpretersmodule.gh-126775: Make
linecache.checkcache()thread safe and GC re-entrancy safe.gh-126332: Fix _pyrepl crash when entering a double CTRL-Z on an overflowing line.
gh-126225:
getoptandoptparseare no longer marked as deprecated. There are legitimate reasons to use one of these modules in preference toargparse, and none of these modules are at risk of being removed from the standard library. Of the three,argparseremains the recommended default choice, unless one of the concerns noted at the top of theoptparsemodule documentation applies.gh-125553: Fix round-trip invariance for backslash continuations in
tokenize.untokenize().gh-123987: Fixed issue in NamespaceReader where a non-path item in a namespace path, such as a sentinel added by an editable installer, would break resource loading.
gh-123401: The
http.cookiesmodule now supports parsing obsolete RFC 850 date formats, in accordance with RFC 9110 requirements. Patch by Nano Zheng.gh-122431:
readline.append_history_file()now raises aValueErrorwhen given a negative value.gh-119257: Show tab completions menu below the current line, which results in less janky behaviour, and fixes a cursor movement bug. Patch by Daniel Hollas
Documentation¶
gh-125722: Require Sphinx 8.1.3 or later to build the Python documentation. Patch by Adam Turner.
gh-67206: Document that
string.printableis not printable in the POSIX sense. In particular,string.printable.isprintable()returnsFalse. Patch by Bénédikt Tran.
Library¶
gh-129345: Fix null pointer dereference in
syslog.openlog()when an audit hook raises an exception.
Core and Builtins¶
gh-129093: Fix f-strings such as
f'{expr=}'sometimes not displaying the full expression when the expression contains!=.gh-124363: Treat debug expressions in f-string as raw strings. Patch by Pablo Galindo
gh-128799: Add frame of
except*to traceback when it wraps a naked exception.gh-128078: Fix a
SystemErrorwhen usinganext()with a default tuple value. Patch by Bénédikt Tran.gh-128717: Fix a crash when setting the recursion limit while other threads are active on the free threaded build.
gh-128330: Restore terminal control characters on REPL exit.
gh-128079: Fix a bug where
except*does not properly check the return value of anExceptionGroup’ssplit()function, leading to a crash in some cases. Now whensplit()returns an invalid object,except*raises aTypeErrorwith the original raisedExceptionGroupobject chained to it.gh-128030: Avoid error from calling
PyModule_GetFilenameObjecton a non-module object when importing a non-existent symbol from a non-module object.gh-127903:
Objects/unicodeobject.c: fix a crash on DEBUG builds in_copy_characterswhen there is nothing to copy.gh-127599: Fix statistics for increments of object reference counts (in particular, when a reference count was increased by more than 1 in a single operation).
gh-127651: When raising
ImportErrorfor missing symbols infromimports, use__file__in the error message if__spec__.originis not a locationgh-127582: Fix non-thread-safe object resurrection when calling finalizers and watcher callbacks in the free threading build.
gh-127434: The iOS compiler shims can now accept arguments with spaces.
gh-127536: Add missing locks around some list assignment operations in the free threading build.
gh-126862: Fix a possible overflow when a class inherits from an absurd number of super-classes. Reported by Valery Fedorenko. Patch by Bénédikt Tran.
gh-127349: Fixed the error when resizing terminal in Python REPL. Patch by Semyon Moroz.
gh-126076: Relocated objects such as
tuple,bytesandstrobjects are properly tracked bytracemallocand its associated hooks. Patch by Pablo Galindo.
C API¶
gh-127791: Fix loss of callbacks after more than one call to
PyUnstable_AtExit().
Build¶
gh-129539: Don’t redefine
EX_OKwhen the system has thesysexits.hheader.gh-128472: Skip BOLT optimization of functions using computed gotos, fixing errors on build with LLVM 19.
gh-123925: Fix building the
cursesmodule on platforms with libncurses but without libncursesw.gh-128321: Set
LIBSinstead ofLDFLAGSwhen checking ifsqlite3library functions are available. This fixes the ordering of linked libraries during checks, which was incorrect when using a statically linkedlibsqlite3.gh-127865: Fix build failure on systems without thread-locals support.
Python 3.13.1 final¶
Release date: 2024-12-03
macOS¶
gh-124448: Update bundled Tcl/Tk in macOS installer to 8.6.15.
Windows¶
gh-126911: Update credits command output.
gh-118973: Ensures the experimental free-threaded install includes the
_tkintermodule. The optional Tcl/Tk component must also be installed in order for the module to work.gh-126497: Fixes venv failure due to missing redirector executables in experimental free-threaded installs.
gh-126074: Removed unnecessary DLLs from Windows embeddable package
gh-125315: Avoid crashing in
platformdue to slow WMI calls on some Windows machines.gh-126084: Fix venvwlauncher to launch pythonw instead of python so no extra console window is created.
gh-125842: Fix a
SystemErrorwhensys.exit()is called with0xffffffffon Windows.gh-125550: Enable the Python Launcher for Windows to detect Python 3.14 installs from the Windows Store.
gh-124448: Updated bundled Tcl/Tk to 8.6.15.
Tools/Demos¶
Tests¶
gh-126909: Fix test_os extended attribute tests to work on filesystems with 1 KiB xattr size limit.
gh-125041: Re-enable skipped tests for
zlibon the s390x architecture: only skip checks of the compressed bytes, which can be different between zlib’s software implementation and the hardware-accelerated implementation.
Security¶
gh-126623: Upgrade libexpat to 2.6.4
gh-125140: Remove the current directory from
sys.pathwhen using PyREPL.gh-122792: Changed IPv4-mapped
ipaddress.IPv6Addressto consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed areis_multicast,is_reserved,is_link_local,is_global, andis_unspecified.
Library¶
gh-127321:
pdb.set_trace()will not stop at an opcode that does not have an associated line number anymore.gh-127303: Publicly expose
EXACT_TOKEN_TYPESintoken.__all__.gh-123967: Fix faulthandler for trampoline frames. If the top-most frame is a trampoline frame, skip it. Patch by Victor Stinner.
gh-127182: Fix
io.StringIO.__setstate__()crash, whenNonewas passed as the first value.gh-127217: Fix
urllib.request.pathname2url()for paths starting with multiple slashes on Posix.gh-127035: Fix
shutil.whichon Windows. Now it looks at direct match if and only if the command ends with a PATHEXT extension or X_OK is not in mode. Support extensionless files if “.” is in PATHEXT. Support PATHEXT extensions that end with a dot.gh-122273: Support PyREPL history on Windows. Patch by devdanzin and Victor Stinner.
gh-127078: Fix issue where
urllib.request.url2pathname()failed to discard an extra slash before a UNC drive in the URL path on Windows.gh-126766: Fix issue where
urllib.request.url2pathname()failed to discard any ‘localhost’ authority present in the URL.gh-127065: Fix crash when calling a
operator.methodcaller()instance from multiple threads in the free threading build.gh-126997: Fix support of STRING and GLOBAL opcodes with non-ASCII arguments in
pickletools.pickletools.dis()now outputs non-ASCII bytes in STRING, BINSTRING and SHORT_BINSTRING arguments as escaped (\xXX).gh-126316:
grp: Makegrp.getgrall()thread-safe by adding a mutex. Patch by Victor Stinner.gh-126618: Fix the representation of
itertools.countobjects when the count value issys.maxsize.gh-85168: Fix issue where
urllib.request.url2pathname()andpathname2url()always used UTF-8 when quoting and unquoting file URIs. They now use the filesystem encoding and error handler.gh-67877: Fix memory leaks when
regular expressionmatching terminates abruptly, either because of a signal or because memory allocation fails.gh-126789: Fixed the values of
sysconfig.get_config_vars(),sysconfig.get_paths(), and their siblings when thesiteinitialization happens aftersysconfighas built a cache forsysconfig.get_config_vars().gh-126188: Update bundled pip to 24.3.1
gh-126780: Fix
os.path.normpath()for drive-relative paths on Windows.gh-126766: Fix issue where
urllib.request.url2pathname()failed to discard two leading slashes introducing an empty authority section.gh-126727:
locale.nl_langinfo(locale.ERA)now returns multiple era description segments separated by semicolons. Previously it only returned the first segment on platforms with Glibc.gh-126699: Allow
collections.abc.AsyncIteratorto be a base for Protocols.gh-126654: Fix crash when non-dict was passed to several functions in
_interpretersmodule.gh-104745: Limit starting a patcher (from
unittest.mock.patch()orunittest.mock.patch.object()) more than once without stopping itgh-126595: Fix a crash when instantiating
itertools.countwith an initial count ofsys.maxsizeon debug builds. Patch by Bénédikt Tran.gh-120423: Fix issue where
urllib.request.pathname2url()mishandled Windows paths with embedded forward slashes.gh-126565: Improve performances of
zipfile.Path.open()for non-reading modes.gh-126505: Fix bugs in compiling case-insensitive
regular expressionswith character classes containing non-BMP characters: upper-case non-BMP character did was ignored and the ASCII flag was ignored when matching a character range whose upper bound is beyond the BMP region.gh-117378: Fixed the
multiprocessing"forkserver"start method forkserver process to correctly inherit the parent’ssys.pathduring the importing ofmultiprocessing.set_forkserver_preload()modules in the same manner assys.pathis configured in workers before executing work items.This bug caused some forkserver module preloading to silently fail to preload. This manifested as a performance degration in child processes when the
sys.pathwas required due to additional repeated work in every worker.It could also have a side effect of
""remaining insys.pathduring forkserver preload imports instead of the absolute path fromos.getcwd()at multiprocessing import time used in the workersys.path.The
sys.pathdifferences between phases in the child process could potentially have caused preload to import incorrect things from the wrong location. We are unaware of that actually having happened in practice.gh-125679: The
multiprocessing.Lockandmultiprocessing.RLockreprvalues no longer say “unknown” on macOS.gh-126476: Raise
calendar.IllegalMonthError(now a subclass ofIndexError) forcalendar.month()when the input month is not correct.gh-126489: The Python implementation of
pickleno longer callspickle.Pickler.persistent_id()for the result ofpersistent_id().gh-126313: Fix an issue in
curses.napms()whencurses.initscr()has not yet been called. Patch by Bénédikt Tran.gh-126303: Fix pickling and copying of
os.sched_paramobjects.gh-126138: Fix a use-after-free crash on
asyncio.Taskobjects whose underlying coroutine yields an object that implements an evil__getattribute__(). Patch by Nico Posada.gh-126220: Fix crash in
cProfile.Profileand_lsprof.Profilerwhen their callbacks were directly called with 0 arguments.gh-126212: Fix issue where
urllib.request.pathname2url()andurl2pathname()removed slashes from Windows DOS drive paths and URLs.gh-126223: Raise a
UnicodeEncodeErrorinstead of aSystemErrorupon calling_interpreters.create()with an invalid Unicode character.gh-126205: Fix issue where
urllib.request.pathname2url()generated URLs beginning with four slashes (rather than two) when given a Windows UNC path.gh-126105: Fix a crash in
astwhen theast.AST._fieldsattribute is deleted.gh-126106: Fixes a possible
NULLpointer dereference inssl.gh-126080: Fix a use-after-free crash on
asyncio.Taskobjects for which the underlying event loop implements an evil__getattribute__(). Reported by Nico-Posada. Patch by Bénédikt Tran.gh-126083: Fixed a reference leak in
asyncio.Taskobjects when reinitializing the same object with a non-Nonecontext. Patch by Nico Posada.gh-125984: Fix use-after-free crashes on
asyncio.Futureobjects for which the underlying event loop implements an evil__getattribute__(). Reported by Nico-Posada. Patch by Bénédikt Tran.gh-125969: Fix an out-of-bounds crash when an evil
asyncio.loop.call_soon()mutates the length of the internal callbacks list. Patch by Bénédikt Tran.gh-125966: Fix a use-after-free crash in
asyncio.Future.remove_done_callback(). Patch by Bénédikt Tran.gh-125789: Fix possible crash when mutating list of callbacks returned by
asyncio.Future._callbacks. It now always returns a new copy in C implementation_asyncio. Patch by Kumar Aditya.gh-124452: Fix an issue in
email.policy.EmailPolicy.header_source_parse()andemail.policy.Compat32.header_source_parse()that introduced spurious leading whitespaces into header values when the header includes a newline character after the header name delimiter (:) and before the value.gh-125884: Fixed the bug for
pdbwhere it can’t set breakpoints on functions with certain annotations.gh-125355: Fix several bugs in
argparse.ArgumentParser.parse_intermixed_args().The parser no longer changes temporarily during parsing.
Default values are not processed twice.
Required mutually exclusive groups containing positional arguments are now supported.
The missing arguments report now includes the names of all required optional and positional arguments.
Unknown options can be intermixed with positional arguments in parse_known_intermixed_args().
gh-125666: Avoid the exiting the interpreter if a null byte is given as input in the new REPL.
gh-125710: [Enum] fix hashable<->nonhashable comparisons for member values
gh-125631: Restore ability to set
persistent_idandpersistent_loadattributes of instances of thePicklerandUnpicklerclasses in thepicklemodule.gh-125378: Fixed the bug in
pdbwhere after a multi-line command, an empty line repeats the first line of the multi-line command, instead of the full command.gh-125682: Reject non-ASCII digits in the Python implementation of
json.loads()conforming to the JSON specification.gh-125660: Reject invalid unicode escapes for Python implementation of
json.loads().gh-125259: Fix the notes removal logic for errors thrown in enum initialization.
gh-125590: Allow
FrameLocalsProxyto delete and pop if the key is not a fast variable.gh-125519: Improve traceback if
importlib.reload()is called with an object that is not a module. Patch by Alex Waygood.gh-125451: Fix deadlock when
concurrent.futures.ProcessPoolExecutorshuts down concurrently with an error when feeding a job to a worker process.gh-125422: Fixed the bug where
pdbandbdbcan step into the bottom caller frame.gh-100141: Fixed the bug where
pdbwill be stuck in an infinite loop when debugging an empty file.gh-125115: Fixed a bug in
pdbwhere arguments starting with-can’t be passed to the debugged script.gh-53203: Fix
time.strptime()for%c,%xand%Xformats in many locales that use non-ASCII digits, like Persian, Burmese, Odia and Shan.gh-125398: Fix the conversion of the
VIRTUAL_ENVpath in the activate script invenvwhen running in Git Bash for Windows.gh-125316: Fix using
functools.partial()asenum.Enummember. A FutureWarning with suggestion to useenum.member()is now emitted when thepartialinstance is used as an enum member.gh-125245: Fix race condition when importing
collections.abc, which could incorrectly return an empty module.gh-125243: Fix data race when creating
zoneinfo.ZoneInfoobjects in the free threading build.gh-125254: Fix a bug where ArgumentError includes the incorrect ambiguous option in
argparse.gh-125235: Keep
tkinterTCL paths in venv pointing to base installation on Windows.gh-61011: Fix inheritance of nested mutually exclusive groups from parent parser in
argparse.ArgumentParser. Previously, all nested mutually exclusive groups lost their connection to the group containing them and were displayed as belonging directly to the parser.gh-52551: Fix encoding issues in
time.strftime(), thestrftime()method of thedatetimeclassesdatetime,dateandtimeand formatting of these classes. Characters not encodable in the current locale are now acceptable in the format string. Surrogate pairs and sequence of surrogatescape-encoded bytes are no longer recombinated. Embedded null character no longer terminates the format string.gh-125118: Don’t copy arbitrary values to _Bool in the
structmodule.gh-125069: Fix an issue where providing a
pathlib.PurePathobject as an initializer argument to a secondPurePathobject with a differentparserresulted in arguments to the former object’s initializer being joined by the latter object’s parser.gh-125096: If the
PYTHON_BASIC_REPLenvironment variable is set, thesitemodule no longer imports the_pyreplmodule. Moreover, thesitemodule now respects-Eand-Icommand line options: ignorePYTHON_BASIC_REPLin this case. Patch by Victor Stinner.gh-124969: Fix
locale.nl_langinfo(locale.ALT_DIGITS)on platforms with glibc. Now it returns a string consisting of up to 100 semicolon-separated symbols (an empty string in most locales) on all Posix platforms. Previously it only returned the first symbol or an empty string.gh-124960: Fix support for the
barry_as_FLUFLfuture flag in the new REPL.gh-124984: Fixed thread safety in
sslin the free-threaded build. OpenSSL operations are now protected by a per-object lock.gh-124958: Fix refcycles in exceptions raised from
asyncio.TaskGroupand the python implementation ofasyncio.Futuregh-53203: Fix
time.strptime()for%cand%xformats in many locales: Arabic, Bislama, Breton, Bodo, Kashubian, Chuvash, Estonian, French, Irish, Ge’ez, Gurajati, Manx Gaelic, Hebrew, Hindi, Chhattisgarhi, Haitian Kreyol, Japanese, Kannada, Korean, Marathi, Malay, Norwegian, Nynorsk, Punjabi, Rajasthani, Tok Pisin, Yoruba, Yue Chinese, Yau/Nungon and Chinese.gh-124917: Allow calling
os.path.exists()andos.path.lexists()with keyword arguments on Windows. Fixes a regression in 3.13.0.gh-124653: Fix detection of the minimal Queue API needed by the
loggingmodule. Patch by Bénédikt Tran.gh-124858: Fix reference cycles left in tracebacks in
asyncio.open_connection()when used withhappy_eyeballs_delaygh-124390: Fixed
AssertionErrorwhen usingasyncio.staggered.staggered_race()withasyncio.eager_task_factory.gh-124651: Properly quote template strings in
venvactivation scripts.gh-116850: Fix
argparsefor namespaces with not directly writable dict (e.g. classes).gh-58573: Fix conflicts between abbreviated long options in the parent parser and subparsers in
argparse.gh-124594: All
asyncioREPL prompts run in the samecontext. Contributed by Bartosz Sławecki.gh-61181: Fix support of choices with string value in
argparse. Substrings of the specified string no longer considered valid values.gh-80259: Fix
argparsesupport of positional arguments withnargs='?',default=argparse.SUPPRESSand specifiedtype.gh-120378: Fix a crash related to an integer overflow in
curses.resizeterm()andcurses.resize_term().gh-123884: Fixed bug in itertools.tee() handling of other tee inputs (a tee in a tee). The output now has the promised n independent new iterators. Formerly, the first iterator was identical (not independent) to the input iterator. This would sometimes give surprising results.
gh-58956: Fixed a bug in
pdbwhere sometimes the breakpoint won’t trigger if it was set on a function which is already in the call stack.gh-124345:
argparsevim supports abbreviated single-dash long options separated by=from its value.gh-104860: Fix disallowing abbreviation of single-dash long options in
argparsewithallow_abbrev=False.gh-63143: Fix parsing mutually exclusive arguments in
argparse. Arguments with the value identical to the default value (e.g. booleans, small integers, empty or 1-character strings) are no longer considered “not present”.gh-72795: Positional arguments with nargs equal to
'*'orargparse.REMAINDERare no longer required. This allows to use positional argument withnargs='*'and withoutdefaultin mutually exclusive group and improves error message about required arguments.gh-59317: Fix parsing positional argument with nargs equal to
'?'or'*'if it is preceded by an option and another positional argument.gh-53780:
argparsenow ignores the first"--"(double dash) between an option and command.gh-124217: Add RFC 9637 reserved IPv6 block
3fff::/20inipaddressmodule.gh-81691: Fix handling of multiple
"--"(double dashes) inargparse. Only the first one has now been removed, all subsequent ones are now taken literally.gh-123978: Remove broken
time.thread_time()andtime.thread_time_ns()on NetBSD.gh-124008: Fix possible crash (in debug build), incorrect output or returning incorrect value from raw binary
write()when writing to console on Windows.gh-123935: Fix parent slots detection for dataclasses that inherit from classes with
__dictoffset__.gh-122765: Fix unbalanced quote errors occurring when activate.csh in
venvwas sourced with a custom prompt containing unpaired quotes or newlines.gh-123370: Fix the canvas not clearing after running turtledemo clock.
gh-116810: Resolve a memory leak introduced in CPython 3.10’s
sslwhen thessl.SSLSocket.sessionproperty was accessed. Speeds up read and write access to said property by no longer unnecessarily cloning session objects via serialization.gh-120754: Update unbounded
readcalls inzipfileto specify an explicitsizeputting a limit on how much data they may read. This also updates handling around ZIP max comment size to match the standard instead of reading comments that are one byte too long.gh-70764: Fixed an issue where
inspect.getclosurevars()would incorrectly classify an attribute name as a global variable when the name exists both as an attribute name and a global variable.gh-118289:
posixpath.realpath()now raisesNotADirectoryErrorwhen strict mode is enabled and a non-directory path with a trailing slash is supplied.gh-119826: Always return an absolute path for
os.path.abspath()on Windows.gh-101955: Fix SystemError when match regular expression pattern containing some combination of possessive quantifier, alternative and capture group.
gh-88110: Fixed
multiprocessing.Processreporting a.exitcodeof 1 even on success when using the"fork"start method while using aconcurrent.futures.ThreadPoolExecutor.gh-71936: Fix a race condition in
multiprocessing.pool.Pool.bpo-46128: Strip
unittest.IsolatedAsyncioTestCasestack frames from reported stacktraces.bpo-14074: Fix
argparsemetavar processing to allow positional arguments to have a tuple metavar.
IDLE¶
gh-122392: Increase currently inadequate vertical spacing for the IDLE browsers (path, module, and stack) on high-resolution monitors.
Documentation¶
gh-126622: Added stub pages for removed modules explaining their removal, where to find replacements, and linking to the last Python version that supported them. Contributed by Ned Batchelder.
gh-125277: Require Sphinx 7.2.6 or later to build the Python documentation. Patch by Adam Turner.
gh-124872: Added definitions for context, current context, and context management protocol, updated related definitions to be consistent, and expanded the documentation for
contextvars.Context.gh-125018: The
importlib.metadatadocumentation now includes semantic cross-reference targets for the significant documented APIs. This means intersphinx references likeimportlib.metadata.version()will now work as expected.gh-70870: Clarified the dual usage of the term “free variable” (both the formal meaning of any reference to names defined outside the local scope, and the narrower pragmatic meaning of nonlocal variables named in
co_freevars).gh-121277: Writers of CPython’s documentation can now use
nextas the version for theversionchanged,versionadded,deprecateddirectives.gh-60712: Include the
objecttype in the lists of documented types. Change by Furkan Onder and Martin Panter.bpo-34008: The
Py_Main()documentation moved from the “Very High Level API” section to the “Initialization and Finalization” section.Also make it explicit that we expect
Py_Mainto typically be called instead ofPy_Initializerather than after it (sincePy_Mainmakes its own call toPy_Initialize). Document that calling both is supported but is version dependent on which settings will be applied correctly.
Core and Builtins¶
gh-113841: Fix possible undefined behavior division by zero in
complex’s_Py_c_pow().gh-127020: Fix a crash in the free threading build when
PyCode_GetCode(),PyCode_GetVarnames(),PyCode_GetCellvars(), orPyCode_GetFreevars()were called from multiple threads at the same time.gh-126980: Fix
__buffer__()ofbytearraycrashing whenREADorWRITEare passed as flags.gh-126881: Fix crash in finalization of dtoa state. Patch by Kumar Aditya.
gh-126341: Now
ValueErroris raised instead ofSystemErrorwhen trying to iterate over a releasedmemoryviewobject.gh-126688: Fix a crash when calling
os.fork()on some operating systems, including SerenityOS.
Library¶
Core and Builtins¶
gh-126312: Fix crash during garbage collection on an object frozen by
gc.freeze()on the free-threaded build.gh-126139: Provide better error location when attempting to use a future statement with an unknown future feature.
gh-126018: Fix a crash in
sys.audit()when passing a non-string as first argument and Python was compiled in debug mode.gh-125942: On Android, the
errorssetting ofsys.stdoutwas changed fromsurrogateescapetobackslashreplace.gh-125859: Fix a crash in the free threading build when
gc.get_objects()orgc.get_referrers()is called during an in-progress garbage collection.gh-125703: Correctly honour
tracemallochooks in specializedPy_DECREFpaths. Patch by Pablo Galindogh-125593: Use color to highlight error locations in traceback from exception group
gh-125444: Fix illegal instruction for older Arm architectures. Patch by Diego Russo, testing by Ross Burton.
gh-124375: Fix a crash in the free threading build when the GC runs concurrently with a new thread starting.
gh-125221: Fix possible race condition when calling
__reduce_ex__()for the first time in the free threading build.gh-125038: Fix crash when iterating over a generator expression after direct changes on
gi_frame.f_locals. Patch by Mikhail Efimov.gh-123378: Fix a crash in the
__str__()method ofUnicodeErrorobjects when theUnicodeError.startandUnicodeError.endvalues are invalid or out-of-range. Patch by Bénédikt Tran.gh-116510: Fix a crash caused by immortal interned strings being shared between sub-interpreters that use basic single-phase init. In that case, the string can be used by an interpreter that outlives the interpreter that created and interned it. For interpreters that share obmalloc state, also share the interned dict with the main interpreter.
gh-122878: Use the
pagerbinary, if available (e.g. on Debian and derivatives), to display REPLhelp().gh-124188: Fix reading and decoding a line from the source file witn non-UTF-8 encoding for syntax errors raised in the compiler.
gh-123930: Improve the error message when a script shadowing a module from the standard library causes
ImportErrorto be raised during a “from” import. Similarly, improve the error message when a script shadowing a third party module attempts to “from” import an attribute from that third party module while still initialising.gh-122907: Building with
HAVE_DYNAMIC_LOADINGnow works as well as it did in 3.12. Existing deficiences will be addressed separately. (See https://github.com/python/cpython/issues/122950.)
Library¶
Core and Builtins¶
gh-109746: If
_thread.start_new_thread()fails to start a new thread, it deletes its state from interpreter and thus avoids its repeated cleanup on finalization.
C API¶
gh-126554: Fix error handling in
ctypes.CDLLobjects which could result in a crash in rare situations.gh-125608: Fix a bug where dictionary watchers (e.g.,
PyDict_Watch()) on an object’s attribute dictionary (__dict__) were not triggered when the object’s attributes were modified.bpo-34008: Added
Py_IsInitializedto the list of APIs that are safe to call before the interpreter is initialized, and updated the embedding tests to cover it.
Build¶
gh-123877: Set
wasm32-wasip1as the WASI target. The oldwasm32-wasitarget is deprecated so it can be used for an eventual WASI 1.0.gh-89640: Hard-code float word ordering as little endian on WASM.
gh-125940: The Android build now supports 16 KB page sizes.
gh-89640: Improve detection of float word ordering on Linux when link-time optimizations are enabled.
gh-125269: Fix detection of whether
-latomicis needed when cross-compiling CPython using the configure script.gh-121634: Allow for specifying the target compile triple for WASI.
gh-122578: Use WASI SDK 24 for testing.
gh-115382: Fix cross compile failures when the host and target SOABIs match.
Python 3.13.0 final¶
Release date: 2024-10-07
Library¶
gh-125008: Fix
tokenize.untokenize()producing invalid syntax for double braces preceded by certain escape characters.
Core and Builtins¶
gh-124871: Fix compiler bug (in some versions of 3.13) where an assertion fails during reachability analysis.
Python 3.13.0 release candidate 3¶
Release date: 2024-10-01
macOS¶
gh-123797: Check for runtime availability of
ptsname_rfunction on macos.
Windows¶
Tests¶
gh-124378: Updated
test_ttkto pass with Tcl/Tk 8.6.15.
Library¶
gh-124538: Fixed crash when using
gc.get_referents()on a capsule object.gh-124498: Fix
typing.TypeAliasTypenot to be generic, whentype_paramsis an empty tuple.gh-123017: Due to unreliable results on some devices,
time.strftime()no longer accepts negative years on Android.gh-123014:
os.pidfd_open()andsignal.pidfd_send_signal()are now unavailable when building against Android API levels older than 31, since the underlying system calls may cause a crash.gh-124248: Fixed potential crash when using
structto process zero-width ‘Pascal string’ fields (0p).gh-87041: Fix a bug in
argparsewhere lengthy subparser argument help is incorrectly indented.gh-124212: Fix invalid variable in
venvhandling of failed symlink on Windowsgh-124171: Add workaround for broken
fmod()implementations on Windows, that loose zero sign (e.g.fmod(-10, 1)returns0.0). Patch by Sergey B Kirpichev.gh-123934: Fix
unittest.mock.MagicMockreseting magic methods return values after.reset_mock(return_value=True)was called.gh-123968: Fix the command-line interface for the
randommodule to select floats between 0 and N, not 1 and N.gh-123892: Add
"_wmi"tosys.stdlib_module_names. Patch by Victor Stinner.gh-123339: Fix
inspect.getsource()for classes incollections.abcanddecimal(for pure Python implementation) modules.inspect.getcomments()now raises OSError instead of IndexError if the__firstlineno__value for a class is out of bound.gh-121735: When working with zip archives, importlib.resources now properly honors module-adjacent references (e.g.
files(pkg.mod)and not justfiles(pkg)).gh-122145: Fix an issue when reporting tracebacks corresponding to Python code emitting an empty AST body. Patch by Nikita Sobolev and Bénédikt Tran.
gh-119004: Fix a crash in OrderedDict.__eq__ when operands are mutated during the check. Patch by Bénédikt Tran.
bpo-44864: Do not translate user-provided strings in
argparse.ArgumentParser.
IDLE¶
Documentation¶
Core and Builtins¶
gh-124567: Revert the incremental GC (in 3.13), since it’s not clear the benefits outweigh the costs at this point.
gh-124642: Fixed scalability issue in free-threaded builds for lock-free reads from dictionaries in multi-threaded scenarios
gh-116510: Fix a bug that can cause a crash when sub-interpreters use “basic” single-phase extension modules. Shared objects could refer to PyGC_Head nodes that had been freed as part of interpreter cleanup.
gh-124547: When deallocating an object with inline values whose
__dict__is still live: if memory allocation for the inline values fails, clear the dictionary. Prevents an interpreter crash.gh-124513: Fix a crash in FrameLocalsProxy constructor: check the number of arguments. Patch by Victor Stinner.
gh-124442: Fix nondeterminism in compilation by sorting the value of
__static_attributes__. Patch by kp2pml30.gh-123856: Fix PyREPL failure when a keyboard interrupt is triggered after using a history search
gh-65961: Document the deprecation of setting and using
__package__and__cached__.gh-124027: Support
<page up>,<page down>, and<delete>keys in the Python REPL when$TERMis set tovt100.gh-77894: Fix possible crash in the garbage collector when it tries to break a reference loop containing a
memoryviewobject. Now amemoryviewobject can only be cleared if there are no buffers that refer it.gh-123339: Setting the
__module__attribute for a class now removes the__firstlineno__item from the type’s dict, so they will no longer be inconsistent.
C API¶
Build¶
gh-124487: Windows builds now use Windows 8.1 as their API baseline (installation already required Windows 8.1).
gh-124043: Building using
--with-trace-refsis (temporarily) disallowed when the GIL is disabled.
Python 3.13.0 release candidate 2¶
Release date: 2024-09-06
macOS¶
gh-123418: Updated macOS installer build to use OpenSSL 3.0.15.
Windows¶
gh-123418: Updated Windows build to use OpenSSL 3.0.15.
gh-122573: The Windows build of CPython now requires 3.10 or newer.
gh-100256:
mimetypesno longer fails when it encounters an inaccessible registry key.gh-79846: Makes
ssl.create_default_context()ignore invalid certificates in the Windows certificate store
Tools/Demos¶
gh-123418: Update GitHub CI workflows to use OpenSSL 3.0.15 and multissltests to use 3.0.15, 3.1.7, and 3.2.3.
Tests¶
Security¶
Library¶
gh-123657: Fix crash and memory leak in
decimal.getcontext(). It crashed when using a thread-local context by--with-decimal-contextvar=no.gh-123448: Fixed memory leak of
typing.NoDefaultby moving it to the static types array.gh-123409: Fix
ipaddress.IPv6Address.reverse_pointeroutput according to RFC 3596, §2.5. Patch by Bénédikt Tran.gh-123270: Applied a more surgical fix for malformed payloads in
zipfile.Pathcausing infinite loops (gh-122905) without breaking contents using legitimate characters.gh-123228: Fix return type for
_pyrepl.readline._ReadlineWrapper.get_line_buffer()to bestr(). Patch by Sergey B Kirpichev.gh-123240: Raise audit events for the
input()in the new REPL.gh-123243: Fix memory leak in
_decimal.gh-122546: Consistently use same file name for different exceptions in the new repl. Patch by Sergey B Kirpichev.
gh-123213:
xml.etree.ElementTree.Element.extend()andElementassignment no longer hide the internal exception if an erronous generator is passed. Patch by Bar Harel.gh-85110: Preserve relative path in URL without netloc in
urllib.parse.urlunsplit()andurllib.parse.urlunparse().gh-123067: Fix quadratic complexity in parsing
"-quoted cookie values with backslashes byhttp.cookies.gh-122981: Fix
inspect.getsource()for generated classes with Python base classes (e.g. enums).gh-122903:
zipfile.Path.globnow correctly matches directories instead of silently omitting them.gh-122905:
zipfile.Pathobjects now sanitize names from the zipfile.gh-122695: Fixed double-free when using
gc.get_referents()with a freedasyncio.Futureiterator.gh-116263:
logging.handlers.RotatingFileHandlerno longer rolls over empty log files.gh-105376: Restore the deprecated
loggingwarn()method. It was removed in Python 3.13 alpha 1. Keep the deprecatedwarn()method in Python 3.13. Patch by Victor Stinner.gh-122744: Bump the version of pip bundled in ensurepip to version 24.2.
gh-118814: Fix the
typing.TypeVarconstructor when name is passed by keyword.gh-122478: Remove internal frames from tracebacks shown in
code.InteractiveInterpreterwith non-defaultsys.excepthook(). Save correct tracebacks insys.last_tracebackand update__traceback__attribute ofsys.last_valueandsys.last_exc.gh-116622: On Android, the
FICLONEandFICLONERANGEconstants are no longer exposed byfcntl, as these ioctls are blocked by SELinux.gh-82378: Make sure that the new REPL interprets
sys.tracebacklimitin the same way that the classic REPL did.gh-122334: Fix crash when importing
sslafter the main interpreter restarts.gh-87320: In
code.InteractiveInterpreter, handle exceptions caused by calling a non-defaultsys.excepthook(). Before, the exception bubbled up to the caller, ending the REPL.gh-121650:
emailheaders with embedded newlines are now quoted on output. Thegeneratorwill now refuse to serialize (write) headers that are unsafely folded or delimited; seeverify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650.)gh-121723: Make
logging.config.dictConfig()accept any object implementing the Queue public API. See the queue configuration section for details. Patch by Bénédikt Tran.gh-122081: Fix a crash in the
decimal.IEEEContext()optional function available via theEXTRA_FUNCTIONALITYconfiguration flag.gh-121804: Correctly show error locations, when
SyntaxErrorraised in new repl. Patch by Sergey B Kirpichev.gh-121151: Fix wrapping of long usage text of arguments inside a mutually exclusive group in
argparse.gh-108172:
webbrowserhonors OS preferred browser on Linux when its desktop entry name contains the text of a known browser name.gh-109109: You can now get the raw TLS certificate chains from TLS connections via
ssl.SSLSocket.get_verified_chain()andssl.SSLSocket.get_unverified_chain()methods.Contributed by Mateusz Nowak.
IDLE¶
gh-120083: Add explicit black IDLE Hovertip foreground color needed for recent macOS. Fixes Sonoma showing unreadable white on pale yellow. Patch by John Riggles.
Library¶
gh-120221: asyncio REPL is now again properly recognizing KeyboardInterrupts. Display of exceptions raised in secondary threads is fixed.
Core and Builtins¶
gh-119310: Allow the new interactive shell to read history files written with the editline library that use unicode-escaped entries. Patch by aorcajo and Łukasz Langa.
gh-123572: Fix key mappings for various F-keys in Windows for the new REPL. Patch by devdanzin
gh-119034: Change
<page up>and<page down>keys of the Python REPL to history search forward/backward. Patch by Victor Stinner.gh-123545: Fix a double decref in rare cases on experimental JIT builds.
gh-123484: Fix
_Py_DebugOffsetsfor long objects to be relative to the start of the object rather than the start of a subobject.gh-123344: Add AST optimizations for type parameter defaults.
gh-123321: Prevent Parser/myreadline race condition from segfaulting on multi-threaded use. Patch by Bar Harel and Amit Wienner.
gh-123177: Fix a bug causing stray prompts to appear in the middle of wrapped lines in the new REPL.
gh-122982: Extend the deprecation period for bool inversion (
~) by two years.gh-123275: Support
-X gil=1andPYTHON_GIL=1on non-free-threaded builds.gh-123177: Deactivate line wrap in the Apple Terminal via a ANSI escape code. Patch by Pablo Galindo
gh-123229: Fix valgrind warning by initializing the f-string buffers to 0 in the tokenizer. Patch by Pablo Galindo
gh-122298: Restore printout of GC stats when
gc.set_debug(gc.DEBUG_STATS)is called. This featue was accidentally removed when implementing incremental GC.gh-121804: Correctly show error locations when a
SyntaxErroris raised in the basic REPL. Patch by Sergey B Kirpichev.gh-123142: Fix too-wide source location in exception tracebacks coming from broken iterables in comprehensions.
gh-123048: Fix a bug where pattern matching code could emit a
JUMP_FORWARDwith no source location.gh-123123: Fix displaying
SyntaxErrorexceptions covering multiple lines. Patch by Pablo Galindogh-123083: Fix a potential use-after-free in
STORE_ATTR_WITH_HINT.gh-123022: Fix crash in free-threaded build when calling
Py_Initialize()from a non-main thread.gh-122888: Fix crash on certain calls to
str()with positional arguments of the wrong type. Patch by Jelle Zijlstra.gh-116622: Fix Android stdout and stderr messages being truncated or lost.
gh-122527: Fix a crash that occurred when a
PyStructSequencewas deallocated after its type’s dictionary was cleared by the GC. The type’stp_basicsizenow accounts for non-sequence fields that aren’t included in thePy_SIZEof the sequence.gh-122445: Add only fields which are modified via self.* to
__static_attributes__.gh-98442: Fix too wide source locations of the cleanup instructions of a with statement.
gh-93691: Fix source locations of instructions generated for with statements.
gh-120097:
FrameLocalsProxynow subclassescollections.abc.Mappingand can be matched as a mapping inmatchstatements
C API¶
gh-122728: Fix
PyEval_GetLocals()to avoidSystemError(“bad argument to internal function”). Patch by Victor Stinner.
Build¶
gh-123418: Updated Android build to use OpenSSL 3.0.15.
gh-123297: Propagate the value of
LDFLAGStoLDCXXSHAREDinsysconfig. Patch by Pablo Galindogh-116622: Rename build variable
MODULE_LDFLAGSback toLIBPYTHON, as it’s used by package build systems (e.g. Meson).gh-118943: Fix an issue where the experimental JIT could be built several times by the
make regen-alltarget, leading to possible race conditions on heavily parallelized builds.gh-118943: Fix a possible race condition affecting parallel builds configured with
--enable-experimental-jit, in whichFileNotFoundErrorcould be caused by another process already movingjit_stencils.h.newtojit_stencils.h.
Python 3.13.0 release candidate 1¶
Release date: 2024-07-31
Tests¶
gh-59022: Add tests for
pkgutil.extend_path(). Patch by Andreas Stocker.gh-99242:
os.getloadavg()may throwOSErrorwhen running regression tests under certain conditions (e.g. chroot). This error is now caught and ignored, since reporting load average is optional.
Security¶
gh-122133: Authenticate the socket connection for the
socket.socketpair()fallback on platforms whereAF_UNIXis not available like Windows.Patch by Gregory P. Smith <greg@krypto.org> and Seth Larson <seth@python.org>. Reported by Ellie <el@horse64.org>
gh-121957: Fixed missing audit events around interactive use of Python, now also properly firing for
python -i, as well as forpython -m asyncio. The events in question arecpython.run_stdinandcpython.run_startup.
Library¶
gh-122400: Handle
ValueErrors raised byos.stat()infilecmp.dircmpandfilecmp.cmpfiles(). Patch by Bénédikt Tran.gh-122332: Fixed segfault with
asyncio.Task.get_coro()when using an eager task factory.gh-105733:
ctypes.ARRAY()is now soft deprecated: it no longer emits deprecation warnings and is not scheduled for removal.gh-122087: Restore
inspect.ismethoddescriptor()andinspect.isroutine()returningFalseforfunctools.partialobjects.gh-122170: Handle
ValueErrors raised byos.stat()inlinecache. Patch by Bénédikt Tran.gh-82951: Serializing objects with complex
__qualname__(such as unbound methods and nested classes) by name no longer involves serializing parent objects by value in pickle protocols < 4.gh-113785:
csvnow correctly parses numeric fields (when used withcsv.QUOTE_NONNUMERICorcsv.QUOTE_STRINGS) which start with an escape character.gh-122088:
@warnings.deprecatednow copies the coroutine status of functions and methods so thatinspect.iscoroutinefunction()returns the correct result.gh-120930: Fixed a bug introduced by gh-92081 that added an incorrect extra blank to encoded words occurring in wrapped headers.
gh-121474: Fix missing sanity check for
partiesarg inthreading.Barrierconstructor. Patch by Clinton Christian (pygeek).gh-120289: Fixed the use-after-free issue in
cProfileby disallowingdisable()andclear()in external timers.
IDLE¶
gh-122482: Change About IDLE to direct users to discuss.python.org instead of the now unused idle-dev email and mailing list.
Core and Builtins¶
gh-116090: Fix an issue in JIT builds that prevented some
forloops from correctly firingRAISEmonitoring events.gh-122208: Dictionary watchers now only deliver the PyDict_EVENT_ADDED event when the insertion is in a known good state to succeed.
gh-122300: Preserve AST nodes for f-string with single-element format specifiers. Patch by Pablo Galindo
gh-120906:
frame.f_localsnow supports arbitrary hashable objects as keys.gh-122029: Emit
c_callevents insys.setprofile()when aPyMethodObjectpointing to aPyCFunctionis called.gh-122026: Fix a bug that caused the tokenizer to not correctly identify mismatched parentheses inside f-strings in some situations. Patch by Pablo Galindo
gh-118934: Make
PyEval_GetLocalsreturn borrowed reference
C API¶
gh-116622: Make
PyObject_Printwork around a bug in Android and OpenBSD which prevented it from throwing an exception when trying to write to a read-only stream.gh-121489: Export private
_PyBytes_Join()again.
Build¶
gh-120522: Added a
--with-app-store-complianceoption to patch out known issues with macOS/iOS App Store review processes.
Python 3.13.0 beta 4¶
Release date: 2024-07-18
Tests¶
gh-121084: Fix test_typing random leaks. Clear typing ABC caches when running tests for refleaks (
-Roption): call_abc_caches_clear()on typing abstract classes and their subclasses. Patch by Victor Stinner.gh-121160: Add a test for
readline.set_history_length(). Note that this test may fail on readline libraries.gh-121200: Fix
test_expanduser_pwd2()oftest_posixpath. Callgetpwnam()to getpw_dir, since it can be different thangetpwall()pw_dir. Patch by Victor Stinner.gh-121188: When creating the JUnit XML file, regrtest now escapes characters which are invalid in XML, such as the chr(27) control character used in ANSI escape sequences. Patch by Victor Stinner.
Library¶
gh-57141: The shallow argument to
filecmp.dircmp(new in Python 3.13) is now keyword-only.gh-121245: Simplify handling of the history file in
site.register_readline()helper. TheCAN_USE_PYREPLvariable now will be initialized, when imported. Patch by Sergey B Kirpichev.gh-121332: Fix constructor of
astnodes with custom_attributes. Previously, passing custom attributes would raise aDeprecationWarning. Passing arguments to the constructor that are not in_fieldsor_attributesremains deprecated. Patch by Jelle Zijlstra.gh-121279: Avoid
NameErrorfor thewarningsmodule when accessing the depracated atributes of theimportlib.abcmodule.gh-121245: Fix a bug in the handling of the command history of the new REPL that caused the history file to be wiped at REPL exit.
gh-87744: Fix waitpid race while calling
send_signal()in asyncio. Patch by Kumar Aditya.gh-121018: Fixed other issues where
argparse.ArgumentParserdid not honorexit_on_error=False.gh-120678: Fix regression in the new REPL that meant that globals from files passed using the
-iargument would not be included in the REPL’s global namespace. Patch by Alex Waygood.gh-120782: Fix wrong references of the
datetimetypes after reloading the module.gh-120713:
datetime.datetime.strftime()now 0-pads years with less than four digits for the format specifiers%Yand%Gon Linux. Patch by Ben Hsinggh-117983: Defer the
threadingimport inimportlib.utiluntil lazy loading is used.gh-119189: When using the
**operator orpow()withFractionas the base and an exponent that is not rational, a float, or a complex, the fraction is no longer converted to a float.gh-118714: Allow
restartin post-mortem debugging ofpdb. Removed restart message when the user quits pdb from post-mortem mode.gh-105623: Fix performance degradation in
logging.handlers.RotatingFileHandler. Patch by Craig Robson.
IDLE¶
gh-78889: Stop Shell freezes by blocking user access to non-method sys.stdout.shell attributes, which are all private.
Documentation¶
gh-121749: Fix documentation for
PyModule_AddObjectRef().gh-120012: Clarify the behaviours of
multiprocessing.Queue.empty()andmultiprocessing.SimpleQueue.empty()on closed queues. Patch by Bénédikt Tran.
Core and Builtins¶
gh-121860: Fix crash when rematerializing a managed dictionary after it was deleted.
gh-121814: Fixed the SegFault when
PyEval_SetTrace()is used with no Python frame on stack.gh-121295: Fix PyREPL console getting into a blocked state after interrupting a long paste
gh-121794: Fix bug in free-threaded Python where a resurrected object could lead to a negative ref count assertion failure.
gh-121657: Improve the
SyntaxErrormessage if the user tries to useyield fromoutside a function.gh-121609: Fix pasting of characters containing unicode character joiners in the new REPL. Patch by Marta Gomez Macias
gh-117482: Unexpected slot wrappers are no longer created for builtin static types in subinterpreters.
gh-121499: Fix a bug affecting how multi-line history was being rendered in the new REPL after interacting with the new screen cache. Patch by Pablo Galindo
gh-121497: Fix a bug that was preventing the REPL to correctly respect the history when an input hook was set. Patch by Pablo Galindo
gh-121012: Tier 2 execution now ensures that list iterators remain exhausted, once they become exhausted.
gh-121439: Allow tuples of length 20 in the freelist to be reused.
gh-121368: Fix race condition in
_PyType_Lookupin the free-threaded build due to a missing memory fence. This could lead to_PyType_Lookupreturning incorrect results on arm64.gh-121130: Fix f-strings with debug expressions in format specifiers. Patch by Pablo Galindo
gh-121115:
PyLong_AsNativeBytes()no longer uses__index__()methods by default. ThePy_ASNATIVEBYTES_ALLOW_INDEXflag has been added to allow it.
C API¶
gh-89364: Export the
PySignal_SetWakeupFd()function. Previously, the function was documented but it couldn’t be used in 3rd party code. Patch by Victor Stinner.gh-113993:
PyUnicode_InternInPlace()no longer prevents its argument from being garbage collected.Several functions that take
char *are now documented as possibly preventing string objects from being garbage collected; refer to their documentation for details:PyUnicode_InternFromString(),PyDict_SetItemString(),PyObject_SetAttrString(),PyObject_DelAttrString(),PyUnicode_InternFromString(), andPyModule_Add*convenience functions.gh-113601: Removed debug build assertions related to interning strings, which were falsely triggered by stable ABI extensions.
gh-112136: Restore the private
_PyArg_Parserstructure and the private_PyArg_ParseTupleAndKeywordsFast()function, previously removed in Python 3.13 alpha 1. Patch by Victor Stinner.
Build¶
gh-120371: Support WASI SDK 22 by explicitly skipping functions that are just stubs in wasi-libc.
gh-121731: Fix mimalloc compile error on GNU/Hurd
gh-121487: Fix deprecation warning for ATOMIC_VAR_INIT in mimalloc.
gh-121467: Fix a Makefile bug that prevented mimalloc header files from being installed.
gh-121103: On POSIX systems, excluding macOS framework installs, the lib directory for the free-threaded build now includes a “t” suffix to avoid conflicts with a co-located default build installation.
gh-120831: The default minimum iOS version was increased to 13.0.
gh-113565: Improve
cursesandcurses.paneldependency checks in configure.
Python 3.13.0 beta 3¶
Release date: 2024-06-27
Core and Builtins¶
gh-120838:
Py_Finalize()andPy_FinalizeEx()now always run with the main interpreter active.gh-113433: Subinterpreters now get cleaned up automatically during runtime finalization.
gh-119462: Make sure that invariants of type versioning are maintained: * Superclasses always have their version number assigned before subclasses * The version tag is always zero if the tag is not valid. * The version tag is always non-zero if the tag is valid.
gh-120437: Fix
_CHECK_STACK_SPACEoptimization problems introduced in gh-118322.gh-120722: Correctly set the bytecode position on return instructions within lambdas. Patch by Jelle Zijlstra.
gh-120367: Fix bug where compiler creates a redundant jump during pseudo-op replacement. Can only happen with a synthetic AST that has a try on the same line as the instruction following the exception handler.
gh-113993: Strings interned with
sys.intern()are again garbage-collected when no longer used, as per the documentation. Strings interned with the C functionPyUnicode_InternInPlace()are still immortal. Internals of the string interning mechanism have been changed. This may affect performance and identities ofstrobjects.gh-120384: Fix an array out of bounds crash in
list_ass_subscript, which could be invoked via some specificly tailored input: including concurrent modification of a list object, where one thread assigns a slice and another clears it.gh-120367: Fix crash in compiler on code with redundant NOPs and JUMPs which show up after exception handlers are moved to the end of the code.
Library¶
gh-120380: Fix Python implementation of
pickle.Picklerforbytesandbytearrayobjects when using protocol version 5. Patch by Bénédikt Tran.
Core and Builtins¶
gh-120400: Support Linux perf profiler to see Python calls on RISC-V architecture.
gh-120221: Deliver real signals on Ctrl-C and Ctrl-Z in the new REPL. Patch by Pablo Galindo
gh-120346: Respect
PYTHON_BASIC_REPLwhen running in interative inspect mode (python -i). Patch by Pablo Galindogh-93691: Fix source locations of instructions generated for the iterator of a for statement.
gh-120198: Fix a crash when multiple threads read and write to the same
__class__of an object concurrently.gh-120298: Fix use-after free in
list_richcompare_implwhich can be invoked via some specificly tailored evil input.gh-119666: Fix a compiler crash in the case where two comprehensions in class scope both reference
__class__.gh-120225: Fix crash in compiler on empty block at end of exception handler.
gh-119933: Improve
SyntaxErrormessages for invalid expressions in a type parameters bound, a type parameter constraint tuple or a default type parameter. Patch by Bénédikt Tran.bpo-24766: Fix handling of
docargument to subclasses ofproperty.
Library¶
gh-121027: Add a future warning in
functools.partial.__get__(). In future Python versionsfunctools.partialwill be a method descriptor.gh-121025: Improve the
__repr__()offunctools.partialmethod. Patch by Bénédikt Tran.gh-121018: Fixed an issue where
argparse.ArgumentParser.parses_args()did not honorexit_on_error=Falsewhen given unrecognized arguments. Patch by Ben Hsing.gh-119614: Fix truncation of strings with embedded null characters in some internal operations in
tkinter.gh-120910: When reading installed files from an egg, use
relative_to(walk_up=True)to honor files installed outside of the installation root.gh-120888: Upgrade pip wheel bundled with ensurepip (pip 24.1.1)
gh-101830: Accessing the
tkinterobject’s string representation no longer converts the underlying Tcl object to a string on Windows.gh-120811: Fix possible memory leak in
contextvars.Context.run().gh-120769: Make empty line in
pdbrepeats the last command even when the command is fromcmdqueue.gh-120732: Fix
namepassing tounittest.mock.Mockobject when usingunittest.mock.create_autospec().gh-120683: Fix an error in
logging.LogRecord, when the integer part of the timestamp is rounded up, while the millisecond calculation truncates, causing the log timestamp to be wrong by up to 999 ms (affected roughly 1 in 8 million timestamps).gh-120633: Move scrollbar and remove tear-off menus in turtledemo.
gh-120541: Improve the prompt in the “less” pager when
help()is called with non-string argument.gh-120495: Fix incorrect exception handling in Tab Nanny. Patch by Wulian233.
gh-120381: Correct
inspect.ismethoddescriptor()to check also for the lack of__delete__(). Patch by Jan Kaliszewski.gh-90425: The OS byte in gzip headers is now always set to 255 when using
gzip.compress().gh-120343: Fix column offset reporting for tokens that come after multiline f-strings in the
tokenizemodule.gh-119600: Fix
unittest.mock.patch()to not read attributes of the target whennew_callableis set. Patch by Robert Collins.gh-114053: Fix edge-case bug where
typing.get_type_hints()would produce incorrect results if type parameters in a class scope were overridden by assignments in a class scope andfrom __future__ import annotationssemantics were enabled. Patch by Alex Waygood.gh-114053: Fix erroneous
NameErrorwhen callinginspect.get_annotations()witheval_str=True`on a class that made use of PEP 695 type parameters in a module that hadfrom __future__ import annotationsat the top of the file. Patch by Alex Waygood.gh-120268: Prohibit passing
Noneto pure-Pythondatetime.date.fromtimestamp()to achieve consistency with C-extension implementation.gh-120244: Fix memory leak in
re.sub()when the replacement string contains backreferences.gh-120211: Fix
tkinter.ttkwith Tcl/Tk 9.0.gh-71587: Fix crash in C version of
datetime.datetime.strptime()when called again on the restarted interpreter.gh-120161:
datetimeno longer crashes in certain complex reference cycle situations.gh-119698: Fix
symtable.Class.get_methods()and document its behaviour. Patch by Bénédikt Tran.gh-120121: Add
concurrent.futures.InvalidStateErrorto module’s__all__.gh-119933: Add the
symtable.SymbolTableTypeenumeration to represent the possible outputs of thesymtable.SymbolTable.get_typemethod. Patch by Bénédikt Tran.gh-120108: Fix calling
copy.deepcopy()onasttrees that have been modified to have references to parent nodes. Patch by Jelle Zijlstra.gh-65454:
unittest.mock.Mock.attach_mock()no longer triggers a call to aPropertyMockbeing attached.gh-81936:
help()andshowtopic()methods now respect a configured output argument topydoc.Helperand not use the pager in such cases. Patch by Enrico Tröger.gh-119577: The
DeprecationWarningemitted when testing the truth value of anxml.etree.ElementTree.Elementnow describes unconditionally returningTruein a future version rather than raising an exception in Python 3.14.gh-118908: Limit exposed globals from internal imports and definitions on new REPL startup. Patch by Eugene Triguba and Pablo Galindo.
gh-119506: Fix
io.TextIOWrapper.write()method breaks internal buffer when the method is called again during flushing internal buffer.
Build¶
gh-120671: Fix failing configure tests due to a missing space when appending to CFLAGS.
gh-120602: Correctly handle LLVM installs with
LLVM_VERSION_SUFFIXwhen building with--enable-experimental-jit.gh-120326: On Windows, fix build error when
--disable-giland--experimental-jitoptions are combined.gh-120291: Make the
python-configshell script compatible with non-bash shells.
C API¶
gh-120642: Remove the private
_Py_CODEUNITtype from the public C API. The internalpycore_code.hheader should now be used to get this internal type. Patch by Victor Stinner.gh-120858:
PyDict_Next()no longer locks the dictionary in the free-threaded build. The locking needs to be done by the caller around the entire iteration loop.gh-120642: Remove the following unstable functions:
PyUnstable_Replace_Executor()PyUnstable_SetOptimizer()PyUnstable_GetOptimizer()PyUnstable_GetExecutor()PyUnstable_Optimizer_NewCounter()PyUnstable_Optimizer_NewUOpOptimizer()
Patch by Victor Stinner.
gh-119344: The critical section API is now public as part of the non-limited C API.
gh-118789: Add
PyUnstable_Object_ClearWeakRefsNoCallbacks(), which clears weakrefs without calling their callbacks.gh-117511: Make the
PyMutexpublic in the non-limited C API.
Python 3.13.0 beta 2¶
Release date: 2024-06-05
Security¶
gh-118773: Fixes creation of ACLs in
os.mkdir()on Windows to work correctly on non-English machines.gh-118486:
os.mkdir()on Windows now accepts mode of0o700to restrict the new directory to the current user. This fixes CVE 2024-4030 affectingtempfile.mkdtemp()in scenarios where the base temporary directory is more permissive than the default.
Core and Builtins¶
gh-119724: Reverted improvements to error messages for
elif/elsestatements not matching any valid statements, which made in hard to locate the syntax errors inside thoseelif/elseblocks.gh-119842: Honor
PyOS_InputHook()in the new REPL. Patch by Pablo Galindogh-119821: Fix execution of annotation scopes within classes when
globalsis set to a non-dict. Patch by Jelle Zijlstra.gh-119548: Add a
clearcommand to the REPL. Patch by Pablo Galindogh-111999: Fix the signature of
str.format_map().gh-119560: An invalid assert in beta 1 has been removed. The assert would fail if
PyState_FindModule()was used in an extension module’s init function before the module def had been initialized.gh-119369: Fix deadlock during thread deletion in free-threaded build, which could occur when the GIL was enabled at runtime.
gh-119525: Fix deadlock involving
_PyType_Lookup()cache in the free-threaded build when the GIL is dynamically enabled at runtime.gh-119311: Fix bug where names are unexpectedly mangled in the bases of generic classes.
gh-119395: Fix bug where names appearing after a generic class are mangled as if they are in the generic class.
gh-119213: Non-builtin modules built with argument clinic were crashing if used in a subinterpreter before the main interpreter. The objects that were causing the problem by leaking between interpreters carelessly have been fixed.
gh-119011: Fixes
type.__type_params__to return an empty tuple instead of a descriptor.gh-118692: Avoid creating unnecessary
StopIterationinstances for monitoring.gh-119049: Fix displaying the source line for warnings created by the C API if the
warningsmodule had not yet been imported.gh-118844: Fix build failures when configuring with both
--disable-giland--enable-experimental-jit.gh-118921: Add
copy()method forFrameLocalsProxywhich returns a snapshotdictfor local variables.gh-117657: Fix data races on the field that stores a pointer to the interpreter’s main thread that occur in free-threaded builds.
gh-118561: Fix race condition in free-threaded build where
list.extend()could expose uninitialised memory to concurrent readers.gh-117195: Avoid assertion failure for debug builds when calling
object.__sizeof__(1)
Library¶
gh-119819: Fix regression to allow logging configuration with multiprocessing queue types.
gh-117142: The
ctypesmodule may now be imported in all subinterpreters, including those that have their own GIL.gh-118835: Fix _pyrepl crash when using custom prompt with ANSI escape codes.
gh-117398: The
_datetimemodule (C implementation fordatetime) now supports being imported in multiple interpreters.gh-89727: Fix issue with
shutil.rmtree()where aRecursionErroris raised on deep directory trees.gh-89727: Partially fix issue with
shutil.rmtree()where aRecursionErroris raised on deep directory trees. A recursion error is no longer raised whenrmtree.avoids_symlink_attacksis false.gh-119118: Fix performance regression in the
tokenizemodule by caching thelinetoken attribute and calculating the column offset more efficiently.gh-89727: Fix issue with
os.fwalk()where aRecursionErrorwas raised on deep directory trees by adjusting the implementation to be iterative instead of recursive.gh-119588:
zipfile.Path.is_symlinknow assesses if the given path is a symlink.gh-119555: Catch
SyntaxErrorfromcompile()in the runsource() method of the InteractiveColoredConsole. Patch by Sergey B Kirpichev.gh-113892: Now, the method
sock_connectofasyncio.ProactorEventLoopraises aValueErrorif given socket is not in non-blocking mode, as well as in other loop implementations.gh-119443: The interactive REPL no longer runs with
from __future__ import annotationsenabled. Patch by Jelle Zijlstra.gh-117398: Objects in the datetime C-API are now all statically allocated, which means better memory safety, especially when the module is reloaded. This should be transparent to users.
gh-118894:
asyncioREPL now has the same capabilities as PyREPL.gh-118911: In PyREPL, updated
maybe-accept’s logic so that if the user hits Enter twice, they are able to terminate the block even if there’s trailing whitespace. Also, now when the user hits arrow up, the cursor is on the last functional line. This matches IPython’s behavior. Patch by Aya Elsayed.gh-111201: Remove dependency to
readlinefrom the new Python REPL.gh-119174: Fix high DPI causes turtledemo(turtle-graphics examples) windows blurry Patch by Wulian233 and Terry Jan Reedy
gh-119121: Fix a NameError happening in
asyncio.staggered.staggered_race. This function is now tested.gh-119113: Fix issue where
pathlib.PurePath.with_suffix()didn’t raiseTypeErrorwhen givenNoneas a suffix.gh-118643: Fix an AttributeError in the
emailmodule when re-fold a long address list. Also fix more cases of incorrect encoding of the address separator in the address list.gh-58933: Make
pdbreturn to caller frame correctly whenf_traceof the caller frame is not setgh-118895: Setting attributes on
typing.NoDefaultnow raisesAttributeErrorinstead ofTypeError.gh-118868: Fixed issue where kwargs were no longer passed to the logging handler QueueHandler
gh-118851:
ctxarguments to the constructors ofastnode classes now default toast.Load(). Patch by Jelle Zijlstra.gh-118760: Restore the default value of
tkiter.wantobjectsto1.gh-118760: Fix errors in calling Tkinter bindings on Windows.
gh-118507: Fix
os.path.isfile()on Windows for pipes. Speedupos.path.isjunction()andos.path.lexists()on Windows with a native implementation.gh-118772: Allow
typing.TypeVarinstances without a default to follow instances without a default in some cases. Patch by Jelle Zijlstra.gh-110863:
os.path.realpath()now suppresses anyOSErrorfromos.readlink()when strict mode is disabled (the default).gh-118263: Speed up
os.path.splitroot()&os.path.normpath()with a direct C call.gh-118033: Fix
dataclasses.dataclass()not creating a__weakref__slot when subclassingtyping.Generic.gh-106531: In
importlib.resources, sync with importlib_resources 6.3.2, including:MultiplexedPathnow expectsTraversablepaths, deprecating string arguments toMultiplexedPath; Enabled support for resources in namespace packages in zip files; FixedNotADirectoryErrorwhen calling files on a subdirectory of a namespace package.gh-113978: Ignore warnings on text completion inside REPL.
gh-103956: Fix lack of newline characters in
tracemodule output when line tracing is enabled but source code line for current frame is not available.gh-92081: Fix missing spaces in email headers when the spaces are mixed with encoded 8-bit characters.
gh-103194: Prepare Tkinter for C API changes in Tcl 8.7/9.0 to avoid
_tkinter.Tcl_Objbeing unexpectedly returned instead ofbool,str,bytearray, orint.gh-87106: Fixed handling in
inspect.Signature.bind()of keyword arguments having the same name as positional-only arguments when a variadic keyword argument (e.g.**kwargs) is present.bpo-45767: Fix integer conversion in
os.major(),os.minor(), andos.makedev(). Support device numbers larger than2**63-1. Support non-existent device number (NODEV).gh-67693: Fix
urllib.parse.urlunparse()andurllib.parse.urlunsplit()for URIs with path starting with multiple slashes and no authority. Based on patch by Ashwin Ramaswami.
Tests¶
gh-119050: regrtest test runner: Add XML support to the refleak checker (-R option). Patch by Victor Stinner.
Build¶
gh-119729: On POSIX systems, the pkg-config (
.pc) filenames now include the ABI flags, which may include debug (“d”) and free-threaded (“t”). For example: *python-3.14.pc(default, non-debug build) *python-3.14d.pc(default, debug build) *python-3.14t.pc(free-threaded build)gh-115119: Fall back to the bundled libmpdec if a system version cannot be found.
gh-119132: Update
sys.versionto identify whether the build is default build or free-threading build. Patch By Donghee Na.gh-118836: Fix an
AssertionErrorwhen building with--enable-experimental-jitand the compiler emits aSHT_NOTEsection.gh-118943: Fix a possible race condition affecting parallel builds configured with
--enable-experimental-jit, in which compilation errors could be caused by an incompletely-generated header file.
Windows¶
gh-119679: Ensures correct import libraries are included in Windows installs.
gh-119690: Adds Unicode support and fixes audit events for
_winapi.CreateNamedPipe.gh-111201: Add support for new pyrepl on Windows
gh-119070: Fixes
py.exehandling of shebangs like/usr/bin/env python3.12, which were previously interpreted aspython3.exeinstead ofpython3.12.exe.gh-117505: Fixes an issue with the Windows installer not running ensurepip in a fully isolated environment. This could cause unexpected interactions with the user site-packages.
gh-118209: Avoid crashing in
mmapon Windows when the mapped memory is inaccessible due to file system errors or access violations.gh-116145: Updated bundled Tcl/Tk to 8.6.14.
C API¶
gh-119585: Fix crash when a thread state that was created by
PyGILState_Ensure()calls a destructor that duringPyThreadState_Clear()that calls back intoPyGILState_Ensure()andPyGILState_Release(). This might occur when in the free-threaded build or when using thread-local variables whose destructors callPyGILState_Ensure().gh-119336: Restore the removed
_PyLong_NumBits()function. It is used by the pywin32 project. Patch by Ethan Smithgh-119247: Added
Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FASTandPy_END_CRITICAL_SECTION_SEQUENCE_FASTmacros to make it possible to use PySequence_Fast APIs safely when free-threaded, and update str.join to work without the GIL using them.gh-111389: Add
PyHASH_MULTIPLIERconstant: prime multiplier used in string and various other hashes. Patch by Victor Stinner.gh-116984: Make mimalloc includes relative to the current file to avoid embedders or extensions needing to include
Internal/mimallocif they are already including internal CPython headers.gh-118789: Restore
_PyWeakref_ClearRefthat was previously removed in Python 3.13 alpha 1.
Python 3.13.0 beta 1¶
Release date: 2024-05-08
Security¶
Core and Builtins¶
gh-118414: Add instrumented opcodes to YIELD_VALUE assertion for tracing cases.
gh-117953: When a builtin or extension module is imported for the first time, while a subinterpreter is active, the module’s init function is now run by the main interpreter first before import continues in the subinterpreter. Consequently, single-phase init modules now fail in an isolated subinterpreter without the init function running under that interpreter, whereas before it would run under the subinterpreter before failing, potentially leaving behind global state and callbacks and otherwise leaving the module in an inconsistent state.
gh-117549: Don’t use designated initializer syntax in inline functions in internal headers. They cause problems for C++ or MSVC users who aren’t yet using the latest C++ standard (C++20). While internal, pycore_backoff.h, is included (indirectly, via pycore_code.h) by some key 3rd party software that does so for speed.
Library¶
gh-95382: Improve performance of
json.dumps()andjson.dump()when using the argument indent. Depending on the data the encoding usingjson.dumps()with indent can be up to 2 to 3 times faster.
Core and Builtins¶
gh-116322: In
--disable-gilbuilds, the GIL will be enabled while loading C extension modules. If the module indicates that it supports running without the GIL, the GIL will be disabled once loading is complete. Otherwise, the GIL will remain enabled for the remainder of the interpreter’s lifetime. This behavior does not apply if the GIL has been explicitly enabled or disabled withPYTHON_GILor-Xgil.gh-118513: Fix incorrect
UnboundLocalErrorwhen two comprehensions in the same function both reference the same name, and in one comprehension the name is bound while in the other it’s an implicit global.gh-118518: Allow the Linux perf support to work without frame pointers using perf’s advanced JIT support. The feature is activated when using the
PYTHON_PERF_JIT_SUPPORTenvironment variable or when running Python with-Xperf_jit. Patch by Pablo Galindo.gh-117514: Add
sys._is_gil_enabled()function that returns whether the GIL is currently enabled. In the default build it always returnsTruebecause the GIL is always enabled. In the free-threaded build, it may returnTrueorFalse.gh-118164: Break a loop between the Python implementation of the
decimalmodule and the Python code for integer to string conversion. Also optimize integer to string conversion for values in the range from 9_000 to 135_000 decimal digits.gh-118473: Fix
sys.set_asyncgen_hooks()not to be partially set when raisingTypeError.gh-118465: Compiler populates the new
__firstlineno__field on a class with the line number of the first line of the class definition.gh-118492: Fix an issue where the type cache can expose a previously accessed attribute when a finalizer is run.
gh-117714: update
async_generator.athrow().close()andasync_generator.asend().close()to close their section of the underlying async generatorgh-111201: The interactive interpreter is now implemented in Python, which allows for a number of new features like colors, multiline input, history viewing, and paste mode. Contributed by Pablo Galindo, Łukasz Langa and Lysandros Nikolaou based on code from the PyPy project.
gh-74929: Implement PEP 667: converted
FrameType.f_localsandPyFrame_GetLocals()to return a write-through proxy object when the frame refers to a function or comprehension.gh-116767: Fix crash in compiler on ‘async with’ that has many context managers.
gh-118335: Change how to use the tier 2 interpreter. Instead of running Python with
-X uopsor setting the environment variablePYTHON_UOPS=1, this choice is now made at build time by configuring with--enable-experimental-jit=interpreter.Beware! This changes the environment variable to enable or disable micro-ops to
PYTHON_JIT. The oldPYTHON_UOPSis no longer used.gh-118306: Update JIT compilation to use LLVM 18
gh-118160: Annotation scopes within classes can now contain comprehensions. However, such comprehensions are not inlined into their parent scope at runtime. Patch by Jelle Zijlstra.
gh-118272: Fix bug where
generator.closedoes not free the generator frame’s locals.gh-118216: Don’t consider
__future__imports with dots before the module name.gh-118074: Make sure that the Executor objects in the COLD_EXITS array aren’t assumed to be GC-able (which would access bytes outside the object).
gh-107674: Lazy load frame line number to improve performance of tracing
gh-118082: Improve
SyntaxErrormessage for imports without names, like infrom x importandimportcases. It now points out to users thatimportexpects at least one name after it.gh-118090: Improve
SyntaxErrormessage for empty type param brackets.gh-117958: Added a
get_jit_code()method to access JIT compiled machine code from the UOp Executor when the experimental JIT is enabled. Patch by Anthony Shaw.gh-117901: Add option for compiler’s codegen to save nested instruction sequences for introspection.
gh-116622: Redirect stdout and stderr to system log when embedded in an Android app.
gh-109118: annotation scope within class scopes can now contain lambdas.
gh-117894: Prevent
agen.aclose()objects being re-used after.throw().gh-117881: prevent concurrent access to an async generator via athrow().throw() or asend().throw()
gh-117536: Fix a
RuntimeWarningwhen callingagen.aclose().throw(Exception).gh-117755: Fix mimalloc allocator for huge memory allocation (around 8,589,934,592 GiB) on s390x. Patch by Victor Stinner.
gh-117750: Fix issue where an object’s dict would get out of sync with the object’s internal values when being cleared.
obj.__dict__.clear()now clears the internal values, but leaves the dict attached to the object.gh-117431: Improve the performance of the following
bytesandbytearraymethods by adapting them to theMETH_FASTCALLcalling convention:count()find()index()rfind()rindex()
gh-117709: Speed up calls to
str()with positional-only argument, by using the PEP 590vectorcallcalling convention. Patch by Erlend Aasland.gh-117680: Give
_PyInstructionSequencea Python interface and use it in tests.gh-115776: Statically allocated objects are, by definition, immortal so must be marked as such regardless of whether they are in extension modules or not.
gh-117385: Remove unhandled
PY_MONITORING_EVENT_BRANCHandPY_MONITORING_EVENT_EXCEPTION_HANDLEDevents fromsys.settrace().gh-116322: Extension modules may indicate to the runtime that they can run without the GIL. Multi-phase init modules do so by calling providing
Py_MOD_GIL_NOT_USEDfor thePy_mod_gilslot, while single-phase init modules callPyUnstable_Module_SetGIL(mod, Py_MOD_GIL_NOT_USED)from their init function.gh-116129: Implement PEP 696, adding support for defaults on type parameters. Patch by Jelle Zijlstra.
gh-93502: Add two new functions to the C-API,
PyRefTracer_SetTracer()andPyRefTracer_GetTracer(), that allows to track object creation and destruction the same way thetracemallocmodule does. Patch by Pablo Galindogh-107674: Improved the performance of
sys.settrace()significantlygh-95754: Improve the error message when a script shadowing a module from the standard library causes
AttributeErrorto be raised. Similarly, improve the error message when a script shadowing a third party module attempts to access an attribute from that third party module while still initialising.gh-99180: Elide uninformative traceback indicators in
returnand simpleassignmentstatements. Patch by Pablo Galindo.gh-105879: Allow the globals and locals arguments to
exec()andeval()to be passed as keywords.
Library¶
gh-118418: A
DeprecationWarningis now emitted if you fail to pass a value to the new type_params parameter oftyping._eval_type()ortyping.ForwardRef._evaluate(). (Using either of these private and undocumented functions is discouraged to begin with, but failing to pass a value to thetype_paramsparameter may lead to incorrect behaviour on Python 3.12 or newer.)gh-118660: Add an optional second type parameter to
typing.ContextManagerandtyping.AsyncContextManager, representing the return types of__exit__()and__aexit__()respectively. This parameter defaults tobool | None.gh-118650: The
enummodule allows method named_repr_*to be defined onEnumtypes.gh-118648: Add type parameter defaults to
typing.Generatorandtyping.AsyncGenerator.gh-101137: Mime type
text/x-rstis now supported bymimetypes.gh-118164: The Python implementation of the
decimalmodule could appear to hang in relatively small power cases (like2**117) if context precision was set to a very high value. A different method to check for exactly representable results is used now that doesn’t rely on computing10**precision(which could be effectively too large to compute).gh-111744:
breakpoint()andpdb.set_trace()now enter the debugger immediately after the call rather than before the next line is executed.gh-118406: Add signature for
sqlite3.Connectionobjects.gh-101732: Use a Y2038 compatible openssl time function when available.
gh-118404: Fix
inspect.signature()for non-comparable callables.gh-118402: Fix
inspect.signature()for the result of thefunctools.cmp_to_key()call.gh-116622: On Android,
sysconfig.get_platformnow returns the format specified by PEP 738.gh-118285: Allow to specify the signature of custom callable instances of extension type by the
__text_signature__attribute. Specify signatures ofoperator.attrgetter,operator.itemgetter, andoperator.methodcallerinstances.gh-118314: Fix an edge case in
binascii.a2b_base64()strict mode, where excessive padding is not detected when no padding is necessary.gh-118271: Add the
PhotoImagemethodsread()to read an image from a file anddata()to get the image data. Add background and grayscale parameters toPhotoImagemethodwrite().gh-118225: Add the
PhotoImagemethodcopy_replace()to copy a region from one image to other image, possibly with pixel zooming and/or subsampling. Add from_coords parameter toPhotoImagemethodscopy(),zoom()andsubsample(). Add zoom and subsample parameters toPhotoImagemethodcopy().gh-118221: Fix a bug where
sqlite3.Connection.iterdump()could fail if a customrow factorywas used. Patch by Erlend Aasland.gh-118013: Fix regression introduced in gh-103193 that meant that calling
inspect.getattr_static()on an instance would cause a strong reference to that instance’s class to persist in an internal cache in theinspectmodule. This caused unexpected memory consumption if the class was dynamically created, the class held strong references to other objects which took up a significant amount of memory, and the cache contained the sole strong reference to the class. The fix for the regression leads to a slowdown ingetattr_static(), but the function should still be significantly faster than it was in Python 3.11. Patch by Alex Waygood.gh-118218: Speed up
itertools.pairwise()in the common case by up to 1.8x.gh-117486: Improve the behavior of user-defined subclasses of
ast.AST. Such classes will now require no changes in the usual case to conform with the behavior changes of theastmodule in Python 3.13. Patch by Jelle Zijlstra.gh-90848: Fixed
unittest.mock.create_autospec()to configure parent mock with keyword arguments.gh-118168: Fix incorrect argument substitution when
typing.Unpackis used with the builtintuple.typing.Unpacknow raisesTypeErrorwhen used with certain invalid types. Patch by Jelle Zijlstra.gh-118131: Add command-line interface for the
randommodule. Patch by Hugo van Kemenade.gh-118107: Fix
zipimportreading of ZIP64 files with file entries that are too big or offset too far.gh-102511: Fix
os.path.normpath()for UNC paths on Windows. Speed upos.path.splitroot()with a native implementation.gh-117535: Change the unknown filename of
warningsfromsysto<sys>to clarify that it’s not a real filename.gh-114053: Fix erroneous
NameErrorwhen callingtyping.get_type_hints()on a class that made use of PEP 695 type parameters in a module that hadfrom __future__ import annotationsat the top of the file. Patch by Alex Waygood.gh-116931: Add parameter fileobj check for
tarfile.TarFile.addfile()gh-117995: Don’t raise
DeprecationWarningwhen a sequence of parameters is used to bind indexed, nameless placeholders. See also gh-100668.gh-80361: Fix TypeError in
email.message.Message.get_payload()when the charset is RFC 2231 encoded.gh-86650: Fix IndexError when parse some emails with invalid Message-ID (including one-off addresses generated by Microsoft Outlook).
gh-117691: Improve the error messages emitted by
tarfiledeprecation warnings relating to PEP 706. If afilterargument is not provided toextract()orextractall, the deprecation warning now points to the line in the user’s code where the relevant function was called. Patch by Alex Waygood.gh-115874: Fixed a possible segfault during garbage collection of
_asyncio.FutureIterobjects. Patch by Savannah Ostrowski.gh-115060: Speed up
pathlib.Path.glob()by omitting an initialis_dir()call. As a result of this change,glob()can no longer raiseOSError.gh-77102:
sitemodule now parses.pthfile with UTF-8 first, and locale encoding ifUnicodeDecodeErrorhappened. It supported only locale encoding before.gh-76785: We’ve exposed the low-level
_interpretersmodule for the sake of the PyPI implementation of PEP 734. It was sometimes available as the_xxsubinterpretersmodule and was formerly used only for testing. For the most part, it should be considered an internal module, like_threadand_imp. See https://discuss.python.org/t/pep-734-multiple-interpreters-in-the-stdlib/41147/26.gh-115060: Speed up
pathlib.Path.glob()by not scanning directories for non-wildcard pattern segments.gh-117727: Speed up
pathlib.Path.iterdir()by usingos.scandir()internally.gh-117586: Speed up
pathlib.Path.walk()by working with strings internally.gh-117722: Change the new multi-separator support in
asyncio.StreamReader.readuntil()to only accept tuples of separators rather than arbitrary iterables.gh-117692: Fixes a bug when
doctest.DocTestFinderwas failing on wrappedbuiltin_function_or_method.gh-117348: Largely restored import time performance of configparser by avoiding dataclasses.
gh-117641: Speedup
os.path.commonpath()on Unix.gh-117663: Fix
_simple_enumto detect aliases when multiple arguments are present but only one is the member value.gh-117636: Speedup
os.path.join().gh-117618: Support
package.moduleasfilenameforbreakcommand ofpdbgh-102247: the status codes enum with constants in http.HTTPStatus are updated to include the names from RFC9110. This RFC includes some HTTP statuses previously only used for WEBDAV and assigns more generic names to them.
The old constants are preserved for backwards compatibility.
gh-117607: Speedup
os.path.relpath().gh-117586: Speed up
pathlib.Path.glob()by working with strings internally.gh-117225: Add colour to doctest output. Patch by Hugo van Kemenade.
gh-117566:
ipaddress.IPv6Address.is_loopback()will now returnTruefor IPv4-mapped loopback addresses, i.e. addresses in the::ffff:127.0.0.0/104address space.gh-117546: Fix issue where
os.path.realpath()stopped resolving symlinks after encountering a symlink loop on POSIX.gh-116720: Improved behavior of
asyncio.TaskGroupwhen an external cancellation collides with an internal cancellation. For example, when two task groups are nested and both experience an exception in a child task simultaneously, it was possible that the outer task group would misbehave, because its internal cancellation was swallowed by the inner task group.In the case where a task group is cancelled externally and also must raise an
ExceptionGroup, it will now call the parent task’scancel()method. This ensures that aasyncio.CancelledErrorwill be raised at the nextawait, so the cancellation is not lost.An added benefit of these changes is that task groups now preserve the cancellation count (
asyncio.Task.cancelling()).In order to handle some corner cases,
asyncio.Task.uncancel()may now reset the undocumented_must_cancelflag when the cancellation count reaches zero.gh-117516: Add
typing.TypeIs, implementing PEP 742. Patch by Jelle Zijlstra.gh-117503: Fix support of non-ASCII user names in bytes paths in
os.path.expanduser()on Posix.gh-117394:
os.path.ismount()is now 2-3 times faster if the user has permissions.gh-117313: Only treat
'\n','\r'and'\r\n'as line separators in re-folding theemailmessages. Preserve control characters'\v','\f','\x1c','\x1d'and'\x1e'and Unicode line separators'\x85','\u2028'and'\u2029'as is.gh-117142: Convert
_ctypesto multi-phase initialisation (PEP 489).gh-66543: Add the
mimetypes.guess_file_type()function which works with file path. Passing file path instead of URL inguess_type()is soft deprecated.gh-68583: webbrowser CLI: replace getopt with argparse, add long options. Patch by Hugo van Kemenade.
gh-116871: Name suggestions for
AttributeErrorandImportErrornow only include underscored names if the original name was underscored.gh-116023: Don’t show empty fields (value
Noneor[]) inast.dump()by default. Addshow_empty=Falseparameter to optionally show them.gh-115961: Added
nameandmodeattributes for compressed and archived file-like objects in modulesbz2,lzma,tarfileandzipfile. The value of themodeattribute ofgzip.GzipFilewas changed from integer (1or2) to string ('rb'or'wb'). The value of themodeattribute of the readable file-like object returned byzipfile.ZipFile.open()was changed from'r'to'rb'.gh-82062: Fix
inspect.signature()to correctly handle parameter defaults on methods in extension modules that use names defined in the module namespace.gh-83856: Honor
atexitfor allmultiprocessingstart methodsgh-113081: Print colorized exception just like built-in traceback in
pdbgh-112855: Speed up pickling of
pathlib.PurePathobjects. Patch by Barney Gale.gh-109617:
ncurses: fixed a crash that could occur on macOS 13 or earlier when Python was built with Apple Xcode 15’s SDK.gh-83151: Enabled arbitrary statements and evaluations in
pdbshell to access the local variables of the current frame, which made it possible for multi-scope code like generators or nested function to work.gh-110209: Add
__class_getitem__()totypes.GeneratorTypeandtypes.CoroutineTypefor type hinting purposes. Patch by James Hilton-Balfe.gh-108191: The
types.SimpleNamespacenow accepts an optional positional argument which specifies initial values of attributes as a dict or an iterable of key-value pairs.gh-62090: Fix assertion errors caused by whitespace in metavars or
SUPPRESS-ed groups inargparseby simplifying usage formatting. Patch by Ali Hamdan.gh-102402: Adjust
logging.LogRecordto usetime.time_ns()and fix minor bug related to floating-point math.gh-100242: Bring pure Python implementation
functools.partial.__new__more in line with the C-implementation by not just always checking for the presence of the attribute'func'on the first argument ofpartial. Instead, both the Python version and the C version perform anisinstance(func, partial)check on the first argument ofpartial.gh-99730: HEAD requests are no longer upgraded to GET request during redirects in urllib.
gh-66410: Setting the
tkintermodule globalwantobjectsto2before creating theTkobject or call thewantobjects()method of theTkobject with argument2makes now arguments to callbacks registered in thetkintermodule to be passed as various Python objects (int,float,bytes,tuple), depending on their internal representation in Tcl, instead of alwaysstr.tkinter.wantobjectsis now set to2by default.bpo-40943: Fix several IndexError when parse emails with truncated Message-ID, address, routes, etc, e.g.
example@.bpo-39324: Add mime type mapping for .md <-> text/markdown
bpo-18108:
shutil.chown()now supports dir_fd and follow_symlinks keyword arguments.bpo-30988: Fix parsing of emails with invalid address headers having a leading or trailing dot. Patch by tsufeki.
bpo-32839: Add the
after_info()method for Tkinter widgets.
Documentation¶
gh-117928: The minimum Sphinx version required for the documentation is now 6.2.1.
Build¶
gh-118734: Fixes Windows build when invoked directly (not through the
build.batscript) without specifying a value forUseTIER2.gh-115119: The
configureoption--with-system-libmpdecnow defaults toyes. The bundled copy oflibmpdecimalwill be removed in Python 3.15.gh-117845: Fix building against recent libedit versions by detecting readline hook signatures in configure.
gh-116622: A testbed project was added to run the test suite on Android.
gh-117645: Increase WASI stack size from 512 KiB to 8 MiB and the initial memory from 10 MiB to 20 MiB. Patch by Victor Stinner.
gh-115119: configure now uses pkg-config to detect
decimaldependencies if the--with-system-libmpdecoption is given.
Windows¶
gh-115119: Update Windows installer to use libmpdecimal 4.0.0.
gh-118486:
os.mkdir()now accepts mode of0o700to restrict the new directory to the current user.gh-118347: Fixes launcher updates not being installed.
gh-118293: The
multiprocessingmodule now passes theSTARTF_FORCEOFFFEEDBACKflag when spawning processes to tell Windows not to change the mouse cursor.gh-115009: Update Windows installer to use SQLite 3.45.3.
gh-90329: Suppress the warning displayed on virtual environment creation when the requested and created paths differ only by a short (8.3 style) name. Warnings will continue to be shown if a junction or symlink in the path caused the venv to be created in a different location than originally requested.
gh-117786: Fixes virtual environments not correctly launching when created from a Store install.
macOS¶
gh-115119: Update macOS installer to use libmpdecimal 4.0.0.
gh-114099: iOS preprocessor symbol usage was made compatible with older macOS SDKs.
gh-115009: Update macOS installer to use SQLite 3.45.3.
gh-91629: Use
~/.config/fish/conf.dconfigs and fish_add_path to setPATHwhen installing for the Fish shell.
IDLE¶
bpo-34774: Use user-selected color theme for Help => IDLE Doc.
C API¶
gh-118124: Fix
Py_BUILD_ASSERTandPy_BUILD_ASSERT_EXPRfor non-constant expressions: usestatic_assert()on C11 and newer. Patch by Victor Stinner.gh-110850: Add “Raw” variant of PyTime functions
Patch by Victor Stinner.
gh-117987: Restore functions removed in Python 3.13 alpha 1:
Patch by Victor Stinner.
gh-117929: Restore removed
PyEval_InitThreads()function. Patch by Victor Stinner.gh-117534: Improve validation logic in the C implementation of
datetime.datetime.fromisoformat()to better handle invalid years. Patch by Vlad Efanov.gh-68114: Fixed skipitem()’s handling of the old ‘w’ and ‘w#’ formatters. These are no longer supported and now raise an exception if used.
gh-111997: Add a C-API for firing monitoring events.
Python 3.13.0 alpha 6¶
Release date: 2024-04-09
Core and Builtins¶
gh-117494: Refactored the instruction sequence data structure out of compile.c into instruction_sequence.c.
gh-116968: Introduce a unified 16-bit backoff counter type (
_Py_BackoffCounter), shared between the Tier 1 adaptive specializer and the Tier 2 optimizer. The API used for adaptive specialization counters is changed but the behavior is (supposed to be) identical.The behavior of the Tier 2 counters is changed:
There are no longer dynamic thresholds (we never varied these).
All counters now use the same exponential backoff.
The counter for
JUMP_BACKWARDstarts counting down from 16.The
temperaturein side exits starts counting down from 64.
gh-117431: Improve the performance of the following
bytesandbytearraymethods by adapting them to theMETH_FASTCALLcalling convention:endswith()startswith()
gh-117431: Improve the performance of the following
strmethods by adapting them to theMETH_FASTCALLcalling convention:gh-117411: Move
PyFutureFeaturesto an internal header and make it private.gh-109120: Added handle of incorrect star expressions, e.g
f(3, *). Patch by Grigoryev Semyongh-117266: Fix crashes for certain user-created subclasses of
ast.AST. Such classes are now expected to set the_field_typesattribute.gh-99108: Updated the
hashlibbuilt-in HACL* project C code from upstream that we use for many implementations when they are not present via OpenSSL in a given build. This also avoids the rare potential for a C symbol name one definition rule linking issue.gh-117108: Change the old space bit of objects in the young generation from 0 to gcstate->visited, so that any objects created during GC will have the old bit set correctly if they get moved into the old generation.
gh-117108: The cycle GC now chooses the size of increments based on the total heap size, instead of the rate of object creation. This ensures that it can keep up with growing heaps.
gh-116735: For
INSTRUMENTED_CALL_FUNCTION_EX, setarg0tosys.monitoring.MISSINGinstead ofNoneforCALLevent.gh-113964: Starting new threads and process creation through
os.fork()are now only prevented once all non-daemon threads exit.gh-116626: Ensure
INSTRUMENTED_CALL_FUNCTION_EXalways emitsCALLgh-116554:
list.sort()now exploits more cases of partial ordering, particularly those with long descending runs with sub-runs of equal values. Those are recognized as single runs now (previously, each block of repeated values caused a new run to be created).gh-114099: Added a Loader that can discover extension modules in an iOS-style Frameworks folder.
gh-115775: Compiler populates the new
__static_attributes__field on a class with the names of attributes of this class which are accessed through self.X from any function in its body.gh-115776: The array of values, the
PyDictValuesstruct is now embedded in the object during allocation. This provides better performance in the common case, and does not degrade as much when the object’s__dict__is materialized.gh-108362: Implement an incremental cyclic garbage collector. By collecting the old generation in increments, there is no need for a full heap scan. This can hugely reduce maximum pause time for programs with large heaps.
Reduce the number of generations from three to two. The old generation is split into two spaces, “visited” and “pending”.
Collection happens in two steps:: * An increment is formed from the young generation and a small part of the pending space. * This increment is scanned and the survivors moved to the end of the visited space.
When the collecting space becomes empty, the two spaces are swapped.
Library¶
Core and Builtins¶
bpo-24612: Improve the
SyntaxErrorthat happens when ‘not’ appears after an operator. Patch by Pablo Galindo
Library¶
gh-117648: Improve performance of
os.path.join()andos.path.expanduser().gh-117584: Raise
TypeErrorfor non-paths inposixpath.relpath.gh-117467: Preserve mailbox ownership when rewriting in
mailbox.mbox.flush. Patch by Tony Mountifield.gh-114848: Raise
FileNotFoundErrorwhengetcwd()returns ‘(unreachable)’, which can happen on Linux >= 2.6.36 with glibc < 2.27.gh-117459:
asyncio.asyncio.run_coroutine_threadsafe()now keeps the traceback ofCancelledError,TimeoutErrorandInvalidStateErrorwhich are raised in the coroutine.gh-117381: Fix error message for
ntpath.commonpath().gh-117337: Deprecate undocumented
glob.glob0()andglob.glob1()functions. Useglob.glob()and pass a directory to its root_dir argument instead.gh-117348: Refactored
configparser.RawConfigParser._read()to reduce cyclometric complexity and improve comprehensibility.gh-117335: Raise TypeError for non-sequences for
ntpath.commonpath().gh-66449:
configparser.ConfigParsernow accepts unnamed sections before named ones, if configured to do so.gh-88014: In documentation of
gzip.GzipFilein module gzip, explain data type of optional constructor argument mtime, and recommendmtime = 0for generating deterministic streams.gh-117310: Fixed an unlikely early & extra
Py_DECREFtriggered crash insslwhen creating a new_ssl._SSLContextif CPython was built implausibly such that the default cipher list is empty or the SSL library it was linked against reports a failure from its CSSL_CTX_set_cipher_list()API.gh-117294: A
DocTestCasenow reports as skipped if all examples in the doctest are skipped.gh-98966: In
subprocess, raise a more informative message whenstdout=STDOUT.gh-117225: doctest: only print “and X failed” when non-zero, don’t pluralise “1 items”. Patch by Hugo van Kemenade.
gh-117205: Speed up
compileall.compile_dir()by 20% when using multiprocessing by increasingchunksize.gh-117178: Fix regression in lazy loading of self-referential modules, introduced in gh-114781.
gh-112383: Fix
dismodule’s handling ofENTER_EXECUTORinstructions.gh-117182: Lazy-loading of modules that modify their own
__class__no longer reverts the__class__totypes.ModuleType.gh-117084: Fix
zipfileextraction for directory entries with the name containing backslashes on Windows.gh-117114: Make
os.path.isdevdrive()available on all platforms. For those that do not offer Dev Drives, it will always returnFalse.gh-117110: Fix a bug that prevents subclasses of
typing.Anyto be instantiated with arguments. Patch by Chris Fu.gh-109653: Deferred select imports in importlib.metadata and importlib.resources for a 14% speedup.
gh-70647: Start the deprecation period for the current behavior of
datetime.datetime.strptime()andtime.strptime()which always fails to parse a date string with aValueErrorinvolving a day of month such asstrptime("02-29", "%m-%d")when a year is not specified and the date happen to be February 29th. This should help avoid users finding new bugs every four years due to a natural mistaken assumption about the API when parsing partial date values.gh-116987: Fixed
inspect.findsource()for class code objects.gh-114099: Modify standard library to allow for iOS platform differences.
gh-90872: On Windows,
subprocess.Popen.wait()no longer callsWaitForSingleObject()with a negative timeout: pass0ms if the timeout is negative. Patch by Victor Stinner.gh-116957: configparser: Don’t leave ConfigParser values in an invalid state (stored as a list instead of a str) after an earlier read raised DuplicateSectionError or DuplicateOptionError.
gh-115538:
_io.WindowsConsoleIOnow emit a warning if a boolean value is passed as a filedescriptor argument.gh-90095: Ignore empty lines and comments in
.pdbrcgh-106531: Refreshed zipfile._path from zipp 3.18, providing better compatibility for PyPy, better glob performance for deeply nested zipfiles, and providing internal access to
CompleteDirs.injectfor use in other tests (like importlib.resources).gh-63207: On Windows,
time.time()now uses theGetSystemTimePreciseAsFileTime()clock to have a resolution better than 1 us, instead of theGetSystemTimeAsFileTime()clock which has a resolution of 15.6 ms. Patch by Victor Stinner.gh-116764: Restore support of
Noneand other false values inurllib.parsefunctionsparse_qs()andparse_qsl(). Also, they now raise a TypeError for non-zero integers and non-empty sequences.gh-116811: In
PathFinder.invalidate_caches, delegate toMetadataPathFinder.invalidate_caches.gh-116647: Fix recursive child in dataclasses
gh-113171: Fixed various false positives and false negatives in
ipaddress.IPv4Address.is_private(see these docs for details)
Also in the corresponding
ipaddress.IPv4Networkandipaddress.IPv6Networkattributes.gh-63283: In
encodings.idna, any capitalization of the ACE prefix (xn--) is now acceptable. Patch by Pepijn de Vos and Zackery Spytz.gh-71042: Add
platform.android_ver(), which provides device and OS information on Android.gh-73468: Added new
math.fma()function, wrapping C99’sfma()operation: fused multiply-add function. Patch by Mark Dickinson and Victor Stinner.gh-116608: The
importlib.resourcesfunctionsis_resource(),open_binary(),open_text(),path(),read_binary(), andread_text()are un-deprecated, and support subdirectories via multiple positional arguments. Thecontents()function also allows subdirectories, but remains deprecated.gh-116484: Change automatically generated
tkinter.Checkbuttonwidget names to avoid collisions with automatically generatedtkinter.ttk.Checkbuttonwidget names within the same parent widget.gh-114314: In
ctypes, ctype data is now stored in type objects directly rather than in a dict subclass. This is an internal change that should not affect usage.gh-116401: Fix blocking
os.fwalk()andshutil.rmtree()on opening named pipe.gh-71052: Implement
ctypes.util.find_library()on Android.gh-90535: Fix support of interval values > 1 in
logging.TimedRotatingFileHandlerforwhen='MIDNIGHT'andwhen='Wx'.gh-113308: Remove some internal protected parts from
uuid:_has_uuid_generate_time_safe,_netbios_getnode,_ipconfig_getnode, and_load_system_functions. They were unused.gh-115627: Fix the
sslmodule error handling of connection terminate by peer. It now throws an OSError with the appropriate error code instead of an EOFError.gh-114847: Speed up
os.path.realpath()on non-Windows platforms.gh-114271: Fix a race in
threading.Thread.join().threading._MainThreadnow always represents the main thread of the main interpreter.PyThreadState.on_deleteandPyThreadState.on_delete_datahave been removed.gh-113538: Add
asyncio.Server.close_clients()andasyncio.Server.abort_clients()methods which allow to more forcefully close an asyncio server.gh-85287: Changes Unicode codecs to return UnicodeEncodeError or UnicodeDecodeError, rather than just UnicodeError.
gh-105866: Fixed
_get_slotsbug which caused error when defining dataclasses with slots and a weakref_slot.gh-96471: Add
asyncio.Queuetermination withshutdown()method.bpo-33533:
asyncio.as_completed()now returns an object that is both an asynchronous iterator and plain iterator. The new asynchronous iteration pattern allows for easier correlation between prior tasks and their completed results. This is a closer match toconcurrent.futures.as_completed()’s iteration pattern. Patch by Justin Arthur.bpo-27578:
inspect.getsource()(and related functions) work with empty module files, returning'\n'(or reasonable equivalent) instead of raisingOSError. Patch by Kernc.bpo-37141: Accept an iterable of separators in
asyncio.StreamReader.readuntil(), stopping when one of them is encountered.gh-66543: Make
mimetypes.guess_type()properly parsing of URLs with only a host name, URLs containing fragment or query, and filenames with only a UNC sharepoint on Windows. Based on patch by Dong-hee Na.bpo-15010:
unittest.TestLoader.discover()now saves the original value ofunittest.TestLoader._top_level_dirand restores it at the end of the call.
Documentation¶
Tests¶
gh-83434: Disable JUnit XML output (
--junit-xml=FILEcommand line option) in regrtest when hunting for reference leaks (-Roption). Patch by Victor Stinner.gh-117187: Fix XML tests for vanilla Expat <2.6.0.
gh-116333: Tests of TLS related things (error codes, etc) were updated to be more lenient about specific error message strings and behaviors as seen in the BoringSSL and AWS-LC forks of OpenSSL.
gh-117089: Consolidated tests for importlib.metadata in their own
metadatapackage.gh-115979: Update test_importlib so that it passes under WASI SDK 21.
gh-112536: Add –tsan to test.regrtest for running TSAN tests in reasonable execution times. Patch by Donghee Na.
gh-116307: Added import helper
isolated_modulesasCleanImportdoes not remove modules imported during the context. Use it in importlib.resources tests to avoid leavingmodaround to impede importlib.metadata tests.
Build¶
Windows¶
gh-117267: Ensure
DirEntry.stat().st_ctimebehaves consistently withos.stat()during the deprecation period ofst_ctimeby containing the same value asst_birthtime. After the deprecation period,st_ctimewill be the metadata change time (or unavailable throughDirEntry), and onlyst_birthtimewill contain the creation time.gh-116195: Improves performance of
os.getppid()by using an alternate system API when available. Contributed by vxiiduu.gh-88494: On Windows,
time.monotonic()now uses theQueryPerformanceCounter()clock to have a resolution better than 1 us, instead of theGetTickCount64()clock which has a resolution of 15.6 ms. Patch by Victor Stinner.gh-116773: Fix instances of
<_overlapped.Overlapped object at 0xXXX> still has pending operation at deallocation, the process may crash.gh-91227: Fix the asyncio ProactorEventLoop implementation so that sending a datagram to an address that is not listening does not prevent receiving any more datagrams.
gh-115119: Switched from vendored
libmpdecimalcode to a separately-hosted external package in thecpython-source-depsrepository when building the_decimalmodule.
C API¶
gh-87193:
_PyBytes_Resize()can now be called for bytes objects with reference count > 1, including 1-byte bytes objects. It creates a new bytes object and destroys the old one if it has reference count > 1.gh-117021: Fix integer overflow in
PyLong_AsPid()on non-Windows 64-bit platforms.gh-115756:
PyCode_GetFirstFree()is an ustable API now and has been renamed toPyUnstable_Code_GetFirstFree(). (Contributed by Bogdan Romanyuk in gh-115781)gh-116869: Add
test_cexttest: build a C extension to check if the Python C API emits C compiler warnings. Patch by Victor Stinner.gh-116869: Make the C API compatible with
-Werror=declaration-after-statementcompiler flag again. Patch by Victor Stinner.gh-116936: Add
PyType_GetModuleByDef()to the limited C API. Patch by Victor Stinner.gh-116809: Restore removed private
_PyErr_ChainExceptions1()function. Patch by Victor Stinner.gh-115754: In the limited C API version 3.13, getting
Py_None,Py_False,Py_True,Py_EllipsisandPy_NotImplementedsingletons is now implemented as function calls at the stable ABI level to hide implementation details. Getting these constants still return borrowed references. Patch by Victor Stinner.gh-115754: Add
Py_GetConstant()andPy_GetConstantBorrowed()functions to get constants. For example,Py_GetConstant(Py_CONSTANT_ZERO)returns a strong reference to the constant zero. Patch by Victor Stinner.gh-111696: Add support for
%T,%T#,%Nand%N#formats toPyUnicode_FromFormat(): format the fully qualified name of an object type and of a type: callPyType_GetModuleName(). See PEP 737 for more information. Patch by Victor Stinner.gh-111696: Add
PyType_GetModuleName()function to get the type’s module name. Equivalent to getting thetype.__module__attribute. Patch by Eric Snow and Victor Stinner.gh-111696: Add
PyType_GetFullyQualifiedName()function to get the type’s fully qualified name. Equivalent tof"{type.__module__}.{type.__qualname__}", ortype.__qualname__iftype.__module__is not a string or is equal to"builtins". Patch by Victor Stinner.gh-85283: The
fcntl,grp,pwd,termios,_statisticsand_testconsoleC extensions are now built with the limited C API. Patch by Victor Stinner.gh-111140: Add additional flags to
PyLong_AsNativeBytes()andPyLong_FromNativeBytes()to allow the caller to determine how to handle edge cases around values that fill the entire buffer.gh-113024: Add
PyObject_GenericHash()function.
Python 3.13.0 alpha 5¶
Release date: 2024-03-12
Security¶
gh-115398: Allow controlling Expat >=2.6.0 reparse deferral (CVE 2023-52425) by adding five new methods:
gh-114572:
ssl.SSLContext.cert_store_stats()andssl.SSLContext.get_ca_certs()now correctly lock access to the certificate store, when thessl.SSLContextis shared across multiple threads.
Core and Builtins¶
gh-116604: Respect the status of the garbage collector when indirect calls are made via
PyErr_CheckSignals()and the evaluation breaker. Patch by Pablo Galindogh-112087:
listis now compatible with the implementation of PEP 703.gh-116381: Add specialization for
CONTAINS_OP.gh-116296: Fix possible refleak in
object.__reduce__()internal error handling.gh-115823: Properly calculate error ranges in the parser when raising
SyntaxErrorexceptions caused by invalid byte sequences. Patch by Pablo Galindogh-115778: Add
tierNannotation for instruction definition in interpreter DSL.gh-115733: Fix crash when calling
next()on exhausted list iterators.gh-115700: The regen-cases build stage now works on Windows.
gh-115347: Fix bug where docstring was replaced by a redundant NOP when Python is run with
-OO.gh-115323: Make error message more meaningful for when
bytearray.extend()is called with astrobject.gh-112175: Every
PyThreadStatenow has its owneval_breaker, allowing specific threads to be interrupted.
Library¶
gh-115154: Fix a bug that was causing the
tokenize.untokenize()function to handle unicode named literals incorrectly. Patch by Pablo Galindo
Core and Builtins¶
gh-112433: Add ability to force alignment of
ctypes.Structureby way of the new_align_attribute on the class.
Library¶
gh-104090: The multiprocessing resource tracker now exits with non-zero status code if a resource leak was detected. It still exits with status code 0 otherwise.
Core and Builtins¶
gh-105858: Improve the constructors for
astnodes. Arguments of list types now default to an empty list if omitted, and optional fields default toNone. AST nodes now have an__annotations__attribute with the expected types of their attributes. Passing unrecognized extra arguments to AST nodes is deprecated and will become an error in Python 3.15. Omitting a required argument to an AST node is deprecated and will become an error in Python 3.15. Patch by Jelle Zijlstra.gh-101860: Expose
__name__attribute on property.gh-96497: Fix incorrect resolution of mangled class variables used in assignment expressions in comprehensions.
Library¶
gh-116349:
platform.java_ver()is deprecated and will be removed in 3.15. It was largely untested, had a confusing API, and was only useful for Jython support.gh-116143: Fix a race in pydoc
_start_server, eliminating a window in which_start_servercan return a thread that is “serving” but without adocserverset.gh-116127:
typing: implement PEP 705 which addstyping.ReadOnlysupport totyping.TypedDict.gh-116325:
typing: raiseSyntaxErrorinstead ofAttributeErroron forward references as empty strings.gh-115957: When
asyncio.TaskGroup.create_taskis called on an inactiveasyncio.TaskGroup, the given coroutine will be closed (which prevents aRuntimeWarning).gh-115978: Disable preadv(), readv(), pwritev(), and writev() on WASI.
Under wasmtime for WASI 0.2, these functions don’t pass test_posix (https://github.com/bytecodealliance/wasmtime/issues/7830).
gh-88352: Fix the computation of the next rollover time in the
logging.TimedRotatingFileHandlerhandler.computeRollover()now always returns a timestamp larger than the specified time and works correctly during the DST change.doRollover()no longer overwrite the already rolled over file, saving from data loss when run at midnight or during repeated time at the DST change.gh-87115: Set
__main__.__spec__toNonewhen running a script withpdbgh-76511: Fix UnicodeEncodeError in
email.Message.as_string()that results when a message that claims to be in the ascii character set actually has non-ascii characters. Non-ascii characters are now replaced with the U+FFFD replacement character, like in thereplaceerror handler.gh-89547: Add support for nested typing special forms like Final[ClassVar[int]].
gh-116040: [Enum] fix by-value calls when second value is falsey; e.g. Cardinal(1, 0)
gh-115821: [Enum] Improve error message when calling super().__new__() in custom __new__.
gh-85644: Use the
XDG_CURRENT_DESKTOPenvironment variable inwebbrowserto check desktop. Prefer it to the deprecatedGNOME_DESKTOP_SESSION_IDfor GNOME detection.gh-75988: Fixed
unittest.mock.create_autospec()to pass the call through to the wrapped object to return the real result.gh-115881: Fix issue where
ast.parse()would incorrectly flag conditional context managers (such aswith (x() if y else z()): ...) as invalid syntax iffeature_version=(3, 8)was passed. This reverts changes to the grammar made as part of gh-94949.gh-115886: Fix silent truncation of the name with an embedded null character in
multiprocessing.shared_memory.SharedMemory.gh-115532: Add kernel density estimation to the statistics module.
gh-115714: On WASI, the
timemodule no longer get process time usingtimes()orCLOCK_PROCESS_CPUTIME_ID, system API is that is unreliable and is likely to be removed from WASI. The affected clock functions fall back to callingclock().gh-115809: Improve algorithm for computing which rolled-over log files to delete in
logging.TimedRotatingFileHandler. It is now reliable for handlers withoutnamerand with arbitrary deterministicnamerthat leaves the datetime part in the file name unmodified.gh-74668:
urllib.parsefunctionsparse_qs()andparse_qsl()now support bytes arguments containing raw and percent-encoded non-ASCII data.gh-67044:
csv.writer()now always quotes or escapes'\r'and'\n', regardless of lineterminator value.gh-115712: Restore support of space delimiter with
skipinitialspace=Trueincsv.csv.writer()now quotes empty fields if delimiter is a space and skipinitialspace is true and raises exception if quoting is not possible.gh-112364: Fixed
ast.unparse()to handle format_spec with",'or\\. Patched by Frank Hoffmann.gh-112997: Stop logging potentially sensitive callback arguments in
asynciounless debug mode is active.gh-114914: Fix an issue where an abandoned
StreamWriterwould not be garbage collected.gh-111358: Fix a bug in
asyncio.BaseEventLoop.shutdown_default_executor()to ensure the timeout passed to the coroutine behaves as expected.gh-115618: Fix improper decreasing the reference count for
Noneargument inpropertymethodsgetter(),setter()anddeleter().gh-112720: Refactor
dis.ArgResolverto make it possible to subclass and change the way jump args are interpreted.gh-112006: Fix
inspect.unwrap()for types with the__wrapper__data descriptor. Fixinspect.Signature.from_callable()for builtinsclassmethod()andstaticmethod().gh-101293: Support callables with the
__call__()method and types with__new__()and__init__()methods set to class methods, static methods, bound methods, partial functions, and other types of methods and descriptors ininspect.Signature.from_callable().gh-113942:
pydocno longer skips global functions implemented as builtin methods, such asMethodDescriptorTypeandWrapperDescriptorType.gh-115256: Added DeprecationWarning when accessing the tarfile attribute of TarInfo objects. The attribute is never used internally and is only attached to TarInfos when the tarfile is opened in write-mode, not read-mode. The attribute creates an unnecessary reference cycle which may cause corruption when not closing the handle after writing a tarfile.
gh-115197:
urllib.requestno longer resolves the hostname before checking it against the system’s proxy bypass list on macOS and Windows.gh-113812:
DatagramTransport.sendto()will now send zero-length datagrams if called with an empty bytes object. The transport flow control also now accounts for the datagram header when calculating the buffer size.gh-114763: Protect modules loaded with
importlib.util.LazyLoaderfrom race conditions when multiple threads try to access attributes before the loading is complete.gh-114709:
posixpath.commonpath()now raises aValueErrorexception when passed an empty iterable. Previously,IndexErrorwas raised.posixpath.commonpath()now raises aTypeErrorexception when passedNone. Previously,ValueErrorwas raised.gh-114610: Fix bug where
pathlib.PurePath.with_stem()converted a non-empty path suffix to a stem when given an empty stem argument. It now raisesValueError, just likepathlib.PurePath.with_suffix()does when called on a path with an empty stem, given a non-empty suffix argument.gh-107361: Add
ssl.VERIFY_X509_PARTIAL_CHAINandVERIFY_X509_STRICTto the default SSL context created withssl.create_default_context().gh-112281: Allow creating union of types for
typing.Annotatedwith unhashable metadata.gh-111775: Fix
importlib.resources.simple.ResourceHandle.open()for text mode, added missedstreamargument.gh-90095: Make .pdbrc and -c work with any valid pdb commands.
gh-107625: Raise
configparser.ParsingErrorfromread()andread_file()methods ofconfigparser.ConfigParserif a key without a corresponding value is continued (that is, followed by an indented line).gh-107155: Fix incorrect output of
help(x)wherexis alambdafunction, which has an__annotations__dictionary attribute with a"return"key.gh-57141: Add option for non-shallow comparisons to
filecmp.dircmplikefilecmp.cmp(). Original patch by Steven Ward. Enhanced by Tobias Rautenkranzgh-69990:
Profile.print_stats()has been improved to accept multiple sort arguments. Patched by Chiu-Hsiang Hsu and Furkan Onder.gh-104061: Add
socket.SO_BINDTOIFINDEXconstant.gh-60346: Fix ArgumentParser inconsistent with parse_known_args.
gh-102389: Add
windows_31jto aliases forcp932codecgh-72249: Always include the module name in the
repr()offunctools.partial()objects. Patch by Furkan Onder and Anilyka Barry.gh-100985: Update HTTPSConnection to consistently wrap IPv6 Addresses when using a proxy.
gh-100884: email: fix misfolding of comma in address-lists over multiple lines in combination with unicode encoding.
gh-95782: Fix
io.BufferedReader.tell(),io.BufferedReader.seek(),_pyio.BufferedReader.tell(),io.BufferedRandom.tell(),io.BufferedRandom.seek()and_pyio.BufferedRandom.tell()being able to return negative offsets.gh-96310: Fix a traceback in
argparsewhen all options in a mutually exclusive group are suppressed.gh-93205: Fixed a bug in
logging.handlers.TimedRotatingFileHandlerwhere multiple rotating handler instances pointing to files with the same name but different extensions would conflict and not delete the correct files.bpo-31116: Add Z85 encoding to
base64.bpo-44865: Add missing call to localization function in
argparse.bpo-43952: Fix
multiprocessing.connection.Listener.accept()to accept empty bytes as authkey. Not accepting empty bytes as key causes it to hang indefinitely.bpo-42125: linecache: get module name from
__spec__if available. This allows getting source code for the__main__module when a custom loader is used.bpo-41122: Failing to pass arguments properly to
functools.singledispatchmethod()now throws a TypeError instead of hitting an index out of bounds internally.bpo-40818: The asyncio REPL now runs
sys.__interactivehook__on startup. The default implementation ofsys.__interactivehook__provides auto-completion to the asyncio REPL. Patch contributed by Rémi Lapeyre.bpo-33775: Add ‘default’ and ‘version’ help text for localization in argparse.
Documentation¶
gh-115399: Document CVE 2023-52425 of Expat <2.6.0 under “XML vulnerabilities”.
Tests¶
gh-71052: Add test exclusions to support running the test suite on Android.
gh-71052: Enable
test_concurrent_futureson platforms that support threading but not multiprocessing.gh-115796: Make ‘_testinternalcapi.assemble_code_object’ construct the exception table for the code object.
gh-115720: Leak tests (
-R,--huntrleaks) now show a summary of the number of leaks found in each iteration.gh-115122: Add
--bisectoption to regrtest test runner: run failed tests withtest.bisect_cmdto identify failing tests. Patch by Victor Stinner.gh-115596: Fix
ProgramPriorityTestsintest_ospermanently changing the process priority.gh-115556: On Windows, commas passed in arguments to
Tools\buildbot\test.batandPCbuild\\rt.batare now properly handled.gh-115420: Fix translation of exception handler targets by
_testinternalcapi.optimize_cfg.gh-115376: Fix segfault in
_testinternalcapi.compiler_codegenon bad input.
Build¶
gh-116313: Get WASI builds to work under wasmtime 18 w/ WASI 0.2/preview2 primitives.
gh-71052: Change Android’s
sys.platformfrom"linux"to"android".gh-116117: Backport
libb2’s PR #42 to fix compiling CPython on 32-bit Windows withclang-cl.gh-71052: Fix several Android build issues
gh-114099: A testbed project was added to run the test suite on iOS.
gh-115350: Fix building ctypes module with -DWIN32_LEAN_AND_MEAN defined
gh-111225: Link extension modules against libpython on Android.
gh-115737: The install name for libPython is now correctly set for non-framework macOS builds.
gh-114099: Makefile targets were added to support compiling an iOS-compatible framework build.
Windows¶
gh-116012: Ensure the value of
GetLastError()is preserved across GIL operations.gh-115582: Building extensions intended for free-threaded builds of CPython now require compiling with
/DPy_GIL_DISABLEDmanually when using a regular install. This is expected to change in future releases.gh-115554: The installer now has more strict rules about updating the Python Launcher for Windows. In general, most users only have a single launcher installed and will see no difference. When multiple launchers have been installed, the option to install the launcher is disabled until all but one have been removed. Downgrading the launcher (which was never allowed) is now more obviously blocked.
gh-115543: Python Launcher for Windows can now detect Python 3.13 when installed from the Microsoft Store, and will install Python 3.12 by default when
PYLAUNCHER_ALLOW_INSTALLis set.
macOS¶
gh-116145: Update macOS installer to Tcl/Tk 8.6.14.
IDLE¶
gh-88516: On macOS show a proxy icon in the title bar of editor windows to match platform behaviour.
Tools/Demos¶
C API¶
gh-114626: Add again
_PyCFunctionFastWithKeywordsname, removed in Python 3.13 alpha 4 by mistake. Keep the old private_PyCFunctionFastWithKeywordsname (Python 3.7) as an alias to the new public namePyCFunctionFastWithKeywords(Python 3.13a4). Patch by Victor Stinner.gh-111418: Add
PyHASH_MODULUS,PyHASH_BITS,PyHASH_INFandPyHASH_IMAGC macros. Patch by Sergey B Kirpichev.
Python 3.13.0 alpha 4¶
Release date: 2024-02-15
Security¶
gh-115399: Update bundled libexpat to 2.6.0
gh-115243: Fix possible crashes in
collections.deque.index()when the deque is concurrently modified.
Core and Builtins¶
gh-112087: For an empty reverse iterator for list will be reduced to
reversed(). Patch by Donghee Nagh-114570: Add
PythonFinalizationErrorexception. This exception derived fromRuntimeErroris raised when an operation is blocked during the Python finalization. Patch by Victor Stinner.gh-114695: Add
sys._clear_internal_caches(), which clears all internal performance-related caches (and deprecate the less-generalsys._clear_type_cache()function).gh-114828: Fix compilation crashes in uncommon code examples using
super()inside a comprehension in a class body.gh-112069: Adapt
setandfrozensetmethods to Argument Clinic.gh-115011: Setters for members with an unsigned integer type now support the same range of valid values for objects that has a
__index__()method as forint.gh-114887: Changed socket type validation in
create_datagram_endpoint()to accept all non-stream sockets. This fixes a regression in compatibility with raw sockets.gh-114944: Fixes a race between
PyParkingLot_Parkand_PyParkingLot_UnparkAll.gh-113462: Limit the number of versions that a single class can use. Prevents a few wayward classes using up all the version numbers.
gh-76763: The
chr()builtin function now always raisesValueErrorfor values outside the valid range. Previously it raisedOverflowErrorfor very large or small values.gh-114806: No longer specialize calls to classes, if those classes have metaclasses. Fixes bug where the
__call__method of the metaclass was not being called.gh-107944: Improve error message for function calls with bad keyword arguments via getargs
gh-112529: The free-threaded build no longer allocates space for the
PyGC_Headstructure in objects that support cyclic garbage collection. A number of other fields and data structures are used as replacements, includingob_gc_bits,ob_tid, and mimalloc internal data structures.gh-114456: Lower the recursion limit under a debug build of WASI.
gh-114083: Compiler applies folding of LOAD_CONST with following instruction in a separate pass before other optimisations. This enables jump threading in certain circumstances.
gh-114388: Fix a
RuntimeWarningemitted when assign an integer-like value that is not an instance ofintto an attribute that corresponds to a C struct member of type T_UINT and T_ULONG. Fix a doubleRuntimeWarningemitted when assign a negative integer value to an attribute that corresponds to a C struct member of type T_UINT.gh-114265: Compiler propagates line numbers before optimization, leading to more optimization opportunities and removing the need for the
guarantee_lineno_for_exitshack.gh-112529: The free-threaded build now has its own thread-safe GC implementation that uses mimalloc to find GC tracked objects. It is non-generational, unlike the existing GC implementation.
gh-114050: Fix segmentation fault caused by an incorrect format string in
TypeErrorexception when more than two arguments are passed toint.gh-112354: The
END_FORinstruction now pops only one value. This is to better support side exits in loops.gh-113884: Make
queue.SimpleQueuethread safe when the GIL is disabled.gh-114058: Implement the foundations of the Tier 2 redundancy eliminator.
gh-113939: frame.clear(): Clear frame.f_locals as well, and not only the fast locals. This is relevant once frame.f_locals was accessed, which would contain also references to all the locals.
gh-112050: Convert
collections.dequeto use Argument Clinic.gh-112050: Make methods on
collections.dequethread-safe when the GIL is disabled.gh-113464: Add an option (
--enable-experimental-jitforconfigure-based builds or--experimental-jitforPCbuild-based ones) to build an experimental just-in-time compiler, based on copy-and-patchgh-113055: Make interp->obmalloc a pointer. For interpreters that share state with the main interpreter, this points to the same static memory structure. For interpreters with their own obmalloc state, it is heap allocated. Add free_obmalloc_arenas() which will free the obmalloc arenas and radix tree structures for interpreters with their own obmalloc state.
gh-55664: Add warning when creating
typeusing a namespace dictionary with non-string keys. Patched by Daniel Urban and Furkan Onder.gh-104530: Use native Win32 condition variables.
Library¶
gh-115392: Fix a bug in
doctestwhere incorrect line numbers would be reported for decorated functions.gh-114563: Fix several
format()bugs when using the C implementation ofDecimal: * memory leak in some rare cases when using thezformat option (coerce negative 0) * incorrect output when applying thezformat option to typeF(fixed-point with capitalNAN/INF) * incorrect output when applying the#format option (alternate form)gh-102840: Fix confused traceback when floordiv, mod, or divmod operations happens between instances of
fractions.Fractionandcomplex.gh-115165: Most exceptions are now ignored when attempting to set the
__orig_class__attribute on objects returned when callingtypinggeneric aliases (including generic aliases created usingtyping.Annotated). Previously onlyAttributeErrorwas ignored. Patch by Dave Shawley.gh-112903: Fix “issubclass() arg 1 must be a class” errors in certain cases of multiple inheritance with generic aliases (regression in early 3.13 alpha releases).
gh-115133: Fix tests for
XMLPullParserwith Expat 2.6.0.gh-115059:
io.BufferedRandom.read1()now flushes the underlying write buffer.gh-79382: Trailing
**no longer allows to match files and non-existing paths in recursiveglob().gh-67837: Avoid race conditions in the creation of directories during concurrent extraction in
tarfileandzipfile.gh-115060: Speed up
pathlib.Path.glob()by removing redundant regex matching.gh-97928: Partially revert the behavior of
tkinter.Text.count(). By default it preserves the behavior of older Python versions, except that settingwantobjectsto 0 no longer has effect. Add a new parameter return_ints: specifyingreturn_ints=TruemakesText.count()always returning the single count as an integer instead of a 1-tuple orNone.gh-114628: When csv.Error is raised when handling TypeError, do not print the TypeError traceback.
gh-85984: Added
_POSIX_VDISABLEfrom C’s<unistd.h>totermios.gh-114965: Update bundled pip to 24.0
gh-114959:
tarfileno longer ignores errors when trying to extract a directory on top of a file.gh-114894: Add
array.array.clear().gh-114071: Support tuple subclasses using auto() for enum member value.
gh-109475: Fix support of explicit option value “–” in
argparse(e.g.--option=--).gh-49766: Fix
date-datetimecomparison. Now the special comparison methods like__eq__and__lt__returnNotImplementedif one of comparands isdateand other isdatetimeinstead of ignoring the time part and the time zone or forcefully return “not equal” or raiseTypeError. It makes comparison ofdateanddatetimesubclasses more symmetric and allows to change the default behavior by overriding the special comparison methods in subclasses.gh-110190: Fix ctypes structs with array on Windows ARM64 platform by setting
MAX_STRUCT_SIZEto 32 in stgdict. Patch by Diego Russogh-114678: Ensure that deprecation warning for ‘N’ specifier in
Decimalformat is not raised for cases where ‘N’ appears in other places in the format specifier. Based on patch by Stefan Krah.gh-70303: Return both files and directories from
pathlib.Path.glob()if a pattern ends with “**”. Previously only directories were returned.gh-109653: Improve import time of
importlib.metadataandemail.utils.gh-113280: Fix a leak of open socket in rare cases when error occurred in
ssl.SSLSocketcreation.gh-77749:
email.policy.EmailPolicy.fold()now always encodes non-ASCII characters in headers ifutf8is false.gh-83383: Synchronization of the
dbm.dumbdatabase is now no-op if there was no modification since opening or last synchronization. The directory file for a newly created emptydbm.dumbdatabase is now created immediately after opening instead of deferring this until synchronizing or closing.gh-91602: Add filter keyword-only parameter to
sqlite3.Connection.iterdump()for filtering database objects to dump. Patch by Mariusz Felisiak.gh-112451: Prohibit subclassing pure-Python
datetime.timezone. This is consistent with C-extension implementation. Patch by Mariusz Felisiak.gh-69893: Add the
close()method for the iterator returned byxml.etree.ElementTree.iterparse().gh-109653: Reduce the import time of
threadingmodule by ~50%. Patch by Daniel Hollas.gh-114492: Make the result of
termios.tcgetattr()reproducible on Alpine Linux. Previously it could leave a random garbage in some fields.gh-114315: Make
threading.Locka real class, not a factory function. Add__new__to_thread.locktype.gh-100414: Add
dbm.sqlite3as a backend todbm, and make it the new defaultdbmbackend. Patch by Raymond Hettinger and Erlend E. Aasland.gh-113267: Revert changes in gh-106584 which made calls of
TestResultmethodsstartTest()andstopTest()unbalanced.gh-75128: Ignore an
OSErrorinasyncio.BaseEventLoop.create_server()when IPv6 is available but the interface cannot actually support it.gh-114423:
_DummyThreadentries inthreading._activeare now automatically removed when the related thread dies.gh-114257: Dismiss the
FileNotFounderror inctypes.util.find_library()and just returnNoneon Linux.gh-114321: Expose more platform specific constants in the
fcntlmodule on Linux, macOS, FreeBSD and NetBSD.gh-114328: The
tty.setcbreak()and newtty.cfmakecbreak()no longer clears the terminal input ICRLF flag. This fixes a regression introduced in 3.12 that no longer matched how OSes define cbreak mode in theirstty(1)manual pages.gh-114281: Remove type hints from
Lib/asyncio/staggered.py. The annotations in the typeshed project should be used instead.gh-101438: Avoid reference cycle in ElementTree.iterparse. The iterator returned by
ElementTree.iterparsemay hold on to a file descriptor. The reference cycle prevented prompt clean-up of the file descriptor if the returned iterator was not exhausted.gh-114198: The signature for the
__replace__method ondataclassesnow has the first argument namedself, rather thanobj.gh-104522:
OSErrorraised when run a subprocess now only has filename attribute set to cwd if the error was caused by a failed attempt to change the current directory.gh-114149: Enum: correctly handle tuple subclasses in custom
__new__.gh-83648: Support deprecation of options, positional arguments and subcommands in
argparse.gh-114087: Speed up
dataclasses.asdictup to 1.35x.gh-109534: Fix a reference leak in
asyncio.selector_events.BaseSelectorEventLoopwhen SSL handshakes fail. Patch contributed by Jamie Phan.gh-79634: Accept path-like objects as patterns in
pathlib.Path.glob()andrglob().gh-112202: Ensure that a
asyncio.Condition.notify()call does not get lost if the awakenedTaskis simultaneously cancelled or encounters any other error.gh-113951: Fix the behavior of
tag_unbind()methods oftkinter.Textandtkinter.Canvasclasses with three arguments. Previously,widget.tag_unbind(tag, sequence, funcid)destroyed the current binding for sequence, leaving sequence unbound, and deleted the funcid command. Now it removes only funcid from the binding for sequence, keeping other commands, and deletes the funcid command. It leaves sequence unbound only if funcid was the last bound command.gh-97959: Fix rendering class methods, bound methods, method and function aliases in
pydoc. Class methods no longer have “method of builtins.type instance” note. Corresponding notes are now added for class and unbound methods. Method and function aliases now have references to the module or the class where the origin was defined if it differs from the current. Bound methods are now listed in the static methods section. Methods of builtin classes are now supported as well as methods of Python classes.gh-113796: Add more validation checks in the
csv.Dialectconstructor.ValueErroris now raised if the same character is used in different roles.gh-113732: Fix support of
QUOTE_NOTNULLandQUOTE_STRINGSincsv.reader().gh-113225: Speed up
pathlib.Path.walk()by usingos.DirEntry.pathwhere possible.gh-89039: When replace() method is called on a subclass of datetime, date or time, properly call derived constructor. Previously, only the base class’s constructor was called.
Also, make sure to pass non-zero fold values when creating subclasses in various methods. Previously, fold was silently ignored.
gh-112919: Speed-up
datetime.datetime.replace(),datetime.date.replace()anddatetime.time.replace().gh-59013: Set breakpoint on the first executable line of the function, instead of the line of function definition when the user do
break funcusingpdbgh-112343: Improve handling of pdb convenience variables to avoid replacing string contents.
gh-112240: Add option to calendar module CLI to specify the weekday to start each week. Patch by Steven Ward.
gh-111741: Recognise
image/webpas a standard format in themimetypesmodule.gh-43457: Fix the
tkinterwidget methodwm_attributes(). It now accepts the attribute name without the minus prefix to get window attributes and allows to specify attributes and values to set as keyword arguments. Add new optional keyword argument return_python_dict: callingw.wm_attributes(return_python_dict=True)returns the attributes as a dict instead of a tuple. Callingw.wm_attributes()now returns a tuple instead of string if wantobjects was set to 0.gh-82626: Many functions now emit a warning if a boolean value is passed as a file descriptor argument.
gh-111051: Added check for file modification during debugging with
pdbgh-110345: Show the Tcl/Tk patchlevel (rather than version) in
tkinter._test().gh-38807: Fix race condition in
trace. Instead of checking if a directory exists and creating it, directly callos.makedirs()with the kwargexist_ok=True.gh-75705: Set unixfrom envelope in
mailbox.mboxandmailbox.MMDF.gh-106233: Fix stacklevel in
InvalidTZPathWarningduringzoneinfomodule import.gh-105102: Allow
ctypes.Unionto be nested inctypes.Structurewhen the system endianness is the opposite of the classes.gh-104282: Fix null pointer dereference in
lzma._decode_filter_properties()due to improper handling of BCJ filters with properties of zero length. Patch by Radislav Chugunov.gh-96471: Add
queue.Queuetermination withshutdown().gh-101599: Changed argparse flag options formatting to remove redundancy.
gh-85984: Add POSIX pseudo-terminal functions
os.posix_openpt(),os.grantpt(),os.unlockpt(), andos.ptsname().gh-102512: When
os.fork()is called from a foreign thread (aka_DummyThread), the type of the thread in a child process is changed to_MainThread. Also changed its name and daemonic status, it can be now joined.gh-88569: Add
os.path.isreserved(), which identifies reserved pathnames such as “NUL”, “AUX” and “CON”. This function is only available on Windows.Deprecate
pathlib.PurePath.is_reserved().bpo-38364: The
inspectfunctionsisgeneratorfunction,iscoroutinefunction,isasyncgenfunctionnow supportfunctools.partialmethodwrapped functions the same way they supportfunctools.partial.
Documentation¶
gh-115233: Fix an example for
LoggerAdapterin the Logging Cookbook.gh-114123: Move the
csvmodule docstring to thecsvmodule instead of reexporting it from the internal_csvmodule, and remove__doc__fromcsv.__all__.Move
csv.__version__to thecsvmodule instead of reexporting it from the internal_csvmodule, and remove__version__fromcsv.__all__.
Tests¶
Build¶
gh-115167: Avoid vendoring
vcruntime140_threads.dllwhen building with Visual Studio 2022 version 17.8.gh-113632: Promote WASI to a tier 2 platform and drop Emscripten from tier 3 in configure.ac.
gh-114099: configure and Makefile were refactored to accommodate framework builds on Apple platforms other than macOS.
gh-114875: Add
getgrent()as a prerequisite for building thegrpmodule.
Windows¶
gh-115049: Fixes
py.exelauncher failing when run as users without user profiles.gh-115009: Update Windows installer to use SQLite 3.45.1.
gh-109991: Update Windows build to use OpenSSL 3.0.13.
gh-111239: Update Windows builds to use zlib v1.3.1.
gh-100107: The
py.exelauncher will no longer attempt to run the Microsoft Store redirector when launching a script containing a/usr/bin/envshebanggh-112984: Adds free-threaded binaries to Windows installer as an optional component.
gh-89240: Allows
multiprocessingto create pools of greater than 62 processes.
macOS¶
gh-115009: Update macOS installer to use SQLite 3.45.1.
gh-109991: Update macOS installer to use OpenSSL 3.0.13.
gh-114490: Add Mach-O linkage support for
platform.architecture().gh-87804: On macOS the result of
os.statvfsandos.fstatvfsnow correctly report the size of very large disks, in previous versions the reported number of blocks was wrong for disks with at least 2**32 blocks.
IDLE¶
Tools/Demos¶
gh-113516: Don’t set
LDSHAREDwhen building for WASI.gh-109991: Update GitHub CI workflows to use OpenSSL 3.0.13 and multissltests to use 1.1.1w, 3.0.13, 3.1.5, and 3.2.1.
gh-115015: Fix a bug in Argument Clinic that generated incorrect code for methods with no parameters that use the METH_METHOD | METH_FASTCALL | METH_KEYWORDS calling convention. Only the positional parameter count was checked; any keyword argument passed would be silently accepted.
C API¶
gh-111140: Adds
PyLong_AsNativeBytes(),PyLong_FromNativeBytes()andPyLong_FromUnsignedNativeBytes()functions.gh-114685:
PyBuffer_FillInfo()now raises aSystemErrorif called withPyBUF_READorPyBUF_WRITEas flags. These flags should only be used with thePyMemoryView_*C API.gh-114685:
PyObject_GetBuffer()now raises aSystemErrorif called withPyBUF_READorPyBUF_WRITEas flags. These flags should only be used with thePyMemoryView_*C API.gh-114626: Add
PyCFunctionFastandPyCFunctionFastWithKeywordstypedefs (identical to the existing_PyCFunctionFastand_PyCFunctionFastWithKeywordstypedefs, just without a leading_prefix).gh-114329: Add
PyList_GetItemRef(), which is similar toPyList_GetItem()but returns a strong reference instead of a borrowed reference.gh-110850: Add PyTime C API:
PyTime_ttype.PyTime_MINandPyTime_MAXconstants.PyTime_AsSecondsDouble(),PyTime_Monotonic(),PyTime_PerfCounter(), andPyTime_Time()functions.
Patch by Victor Stinner.
gh-112066: Add
PyDict_SetDefaultRef(): insert a key and value into a dictionary if the key is not already present. This is similar todict.setdefault(), but returns an integer value indicating if the key was already present. It is also similar toPyDict_SetDefault(), but returns a strong reference instead of a borrowed reference.
Python 3.13.0 alpha 3¶
Release date: 2024-01-17
Security¶
Core and Builtins¶
gh-107901: Compiler duplicates basic blocks that have an eval breaker check, no line number, and multiple predecessors.
gh-107901: A jump leaving an exception handler back to normal code no longer checks the eval breaker.
gh-113655: Set the C recursion limit to 4000 on Windows, and 10000 on Linux/OSX. This seems to be near the sweet spot to maintain safety, but not compromise backwards compatibility.
gh-113710: Add typed stack effects to the interpreter DSL, along with various instruction annotations.
gh-77046: On Windows, file descriptors wrapping Windows handles are now created non inheritable by default (PEP 446). Patch by Zackery Spytz and Victor Stinner.
gh-113853: Guarantee that all executors make progress. This then guarantees that tier 2 execution always makes progress.
gh-113753: Fix an issue where the finalizer of
PyAsyncGenASendobjects might not be called if they were allocated from a free list.gh-107901: Compiler changed so that synthetic jumps which are not at loop end no longer check the eval breaker.
gh-113703: Fix a regression in the
codeopmodule that was causing it to incorrectly identify incomplete f-strings. Patch by Pablo Galindogh-89811: Check for a valid
tp_version_tagbefore performing bytecode specializations that rely on this value being usable.gh-111488: Changed error message in case of no ‘in’ keyword after ‘for’ in list comprehensions
gh-113657: Fix an issue that caused important instruction pointer updates to be optimized out of tier two traces.
gh-113603: Fixed bug where a redundant NOP is not removed, causing an assertion to fail in the compiler in debug mode.
gh-113602: Fix an error that was causing the parser to try to overwrite existing errors and crashing in the process. Patch by Pablo Galindo
gh-113486: No longer issue spurious
PY_UNWINDevents for optimized calls to classes.gh-113297: Fix segfault in the compiler on with statement with 19 context managers.
gh-111375: Only use
NULLin the exception stack to indicate an exception was handled. Patch by Carey Metcalfe.gh-112215: Increase the C recursion limit by a factor of 3 for non-debug builds, except for webassembly and s390 platforms which are unchanged. This mitigates some regressions in 3.12 with deep recursion mixing builtin (C) and Python code.
gh-113054: Fixed bug where a redundant NOP is not removed, causing an assertion to fail in the compiler in debug mode.
gh-106905: Use per AST-parser state rather than global state to track recursion depth within the AST parser to prevent potential race condition due to simultaneous parsing.
The issue primarily showed up in 3.11 by multithreaded users of
ast.parse(). In 3.12 a change to when garbage collection can be triggered prevented the race condition from occurring.gh-108866: Change the API and contract of
_PyExecutorObjectto return the next_instr pointer, instead of the frame, and to always execute at least one instruction.gh-112943: Correctly compute end column offsets for multiline tokens in the
tokenizemodule. Patch by Pablo Galindogh-112125: Fix
None.__ne__(None)returningNotImplementedinstead ofFalse.gh-74616:
input()now raises a ValueError when output on the terminal if the prompt contains embedded null characters instead of silently truncating it.gh-112716: Fix SystemError in the
importstatement and in__reduce__()methods of builtin types when__builtins__is not a dict.gh-112730: Use color to highlight error locations in tracebacks. Patch by Pablo Galindo
gh-112625: Fixes a bug where a bytearray object could be cleared while iterating over an argument in the
bytearray.join()method that could result in reading memory after it was freed.gh-112660: Do not clear unexpected errors during formatting error messages for ImportError and AttributeError for modules.
gh-105967: Workaround a bug in Apple’s macOS platform zlib library where
zlib.crc32()andbinascii.crc32()could produce incorrect results on multi-gigabyte inputs. Including when usingzipfileon zips containing large data.gh-95754: Provide a better error message when accessing invalid attributes on partially initialized modules. The origin of the module being accessed is now included in the message to help with the common issue of shadowing other modules.
gh-112217: Add check for the type of
__cause__returned from calling the typeTinraise from T.gh-111058: Change coro.cr_frame/gen.gi_frame to return
Noneafter the coroutine/generator has been closed. This fixes a bug wheregetcoroutinestate()andgetgeneratorstate()return the wrong state for a closed coroutine/generator.gh-112388: Fix an error that was causing the parser to try to overwrite tokenizer errors. Patch by pablo Galindo
gh-112387: Fix error positions for decoded strings with backwards tokenize errors. Patch by Pablo Galindo
gh-99606: Make code generated for an empty f-string identical to the code of an empty normal string.
gh-112367: Avoid undefined behaviour when using the perf trampolines by not freeing the code arenas until shutdown. Patch by Pablo Galindo
gh-112320: The Tier 2 translator now tracks the confidence level for staying “on trace” (i.e. not exiting back to the Tier 1 interpreter) for branch instructions based on the number of bits set in the branch “counter”. Trace translation ends when the confidence drops below 1/3rd.
gh-109598:
PyComplex_RealAsDouble()/PyComplex_ImagAsDouble()now tries to convert an object to acomplexinstance using its__complex__()method before falling back to the__float__()method. Patch by Sergey B Kirpichev.gh-94606: Fix UnicodeEncodeError when
email.message.get_payload()reads a message with a Unicode surrogate character and the message content is not well-formed for surrogateescape encoding. Patch by Sidney Markowitz.bpo-21861: Use the object’s actual class name in
_io.FileIO.__repr__(),_io._WindowsConsoleIO()and_io.TextIOWrapper.__repr__(), to make these methods subclass friendly.bpo-34392: Added
sys._is_interned().
Library¶
gh-114077: Fix possible
OverflowErrorinsocket.socket.sendfile()when pass count larger than 2 GiB on 32-bit platform.gh-111803:
plistlibnow supports loading more deeply nested lists in binary format.gh-114014: Fixed a bug in
fractions.Fractionwhere an invalid string usingdin the decimals part creates a different error compared to other invalid letters/characters. Patch by Jeremiah Gabriel Pascual.gh-108364:
sqlite3.Connection.iterdump()now ensures that foreign key support is disabled before dumping the database schema, if there is any foreign key violation. Patch by Erlend E. Aasland and Mariusz Felisiak.gh-113971: The
zipfile.ZipInfopreviously protected._compresslevelattribute has been made public as.compress_levelwith the old_compresslevelname remaining available as a property to retain compatibility.gh-113877: Fix
tkintermethodwinfo_pathname()on 64-bit Windows.gh-113868: Added
mmap.MAP_NORESERVE,mmap.MAP_NOEXTEND,mmap.MAP_HASSEMAPHORE,mmap.MAP_NOCACHE,mmap.MAP_JIT,mmap.MAP_RESILIENT_CODESIGN,mmap.MAP_RESILIENT_MEDIA,mmap.MAP_32BIT,mmap.MAP_TRANSLATED_ALLOW_EXECUTE,mmap.MAP_UNIX03andmmap.MAP_TPRO. All of them aremmap(2)flags on macOS.gh-113848:
asyncio.TaskGroup()andasyncio.timeout()context managers now handleCancelledErrorsubclasses as well as exactCancelledError.gh-113661: unittest runner: Don’t exit 5 if tests were skipped. The intention of exiting 5 was to detect issues where the test suite wasn’t discovered at all. If we skipped tests, it was correctly discovered.
gh-96037: Insert
TimeoutErrorin the context of the exception that was raised during exiting an expiredasyncio.timeout()block.gh-113781: Silence unraisable AttributeError when warnings are emitted during Python finalization.
gh-113238: Add
Anchortoimportlib.resources(in order for the code to comply with the documentation)gh-111693:
asyncio.Condition.wait()now re-raises the sameCancelledErrorinstance that may have caused it to be interrupted. Fixed race condition inasyncio.Semaphore.acquire()when interrupted with aCancelledError.gh-113791: Add
CLOCK_MONOTONIC_RAW_APPROXandCLOCK_UPTIME_RAW_APPROXtotimeon macOS. These are clocks available on macOS 10.12 or later.gh-112932: Restore the ability for
zipfiletoextractallfrom zip files with a “/” directory entry in them as is commonly added to zips by some wiki or bug tracker data exporters.gh-113568: Raise deprecation warnings from
pathlib.PurePathand not its private base classPurePathBase.gh-113594: Fix
UnicodeEncodeErrorinemailwhen re-fold lines that contain unknown-8bit encoded part followed by non-unknown-8bit encoded part.gh-113538: In
asyncio.StreamReaderProtocol.connection_made(), there is callback that logs an error if the task wrapping the “connected callback” fails. This callback would itself fail if the task was cancelled. Prevent this by checking whether the task was cancelled first. If so, close the transport but don’t log an error.gh-113626: Add support for the allow_code argument in the
marshalmodule. Passingallow_code=Falseprevents serialization and de-serialization of code objects which is incompatible between Python versions.gh-85567: Fix resource warnings for unclosed files in
pickleandpickletoolscommand line interfaces.gh-113537: Support loads
strinplistlib.loads().gh-89850: Add default implementations of
pickle.Pickler.persistent_id()andpickle.Unpickler.persistent_load()methods in the C implementation. Callingsuper().persistent_id()andsuper().persistent_load()in subclasses of the C implementation ofpickle.Picklerandpickle.Unpicklerclasses no longer causes infinite recursion.gh-113569: Indicate if there were no actual calls in unittest
assert_has_calls()failure.gh-101225: Increase the backlog for
multiprocessing.connection.Listenerobjects created bymultiprocessing.managerandmultiprocessing.resource_sharerto significantly reduce the risk of getting a connection refused error when creating amultiprocessing.connection.Connectionto them.gh-113568: Raise audit events from
pathlib.Pathand not its private base classPathBase.gh-113543: Make sure that
webbrowser.MacOSXOSAScriptsendswebbrowser.openaudit event.gh-113028: When a second reference to a string appears in the input to
pickle, and the Python implementation is in use, we are guaranteed that a single copy gets pickled and a single object is shared when reloaded. Previously, in protocol 0, when a string contained certain characters (e.g. newline) it resulted in duplicate objects.gh-113421: Fix multiprocessing logger for
%(filename)s.gh-111784: Fix segfaults in the
_elementtreemodule. Fix first segfault during deallocation of_elementtree.XMLParserinstances by keeping strong reference topyexpatmodule in module state for capsule lifetime. Fix second segfault which happens in the same deallocation process by keeping strong reference to_elementtreemodule inXMLParserstructure for_elementtreemodule lifetime.gh-113407: Fix import of
unittest.mockwhen CPython is built without docstrings.gh-113320: Fix regression in Python 3.12 where
Protocolclasses that were not marked asruntime-checkablewould be unnecessarily introspected, potentially causing exceptions to be raised if the protocol had problematic members. Patch by Alex Waygood.gh-53502: Add a new option
aware_datetimeinplistlibto loads or dumps aware datetime.gh-113358: Fix rendering tracebacks with exceptions with a broken __getattr__
gh-113214: Fix an
AttributeErrorduring asyncio SSL protocol aborts in SSL-over-SSL scenarios.gh-113246: Update bundled pip to 23.3.2.
gh-87264: Fixed tarfile list() method to show file type.
gh-112182:
asyncio.futures.Future.set_exception()now transformsStopIterationintoRuntimeErrorinstead of hanging or other misbehavior. Patch contributed by Jamie Phan.gh-113225: Speed up
pathlib.Path.glob()by usingos.DirEntry.pathwhere possible.gh-113149: Improve error message when a JSON array or object contains a trailing comma. Patch by Carson Radtke.
gh-113117: The
subprocessmodule can now use theos.posix_spawn()function withclose_fds=Trueon platforms whereposix_spawn_file_actions_addclosefrom_npis available. Patch by Jakub Kulik.gh-113199: Make
http.client.HTTPResponse.read1andhttp.client.HTTPResponse.readlineclose IO after reading all data when content length is known. Patch by Illia Volochii.gh-113191: Add support of
os.fchmod()and a file descriptor inos.chmod()on Windows.gh-113188: Fix
shutil.copymode()andshutil.copystat()on Windows. Previously they worked differently if dst is a symbolic link: they modified the permission bits of dst itself rather than the file it points to if follow_symlinks is true or src is not a symbolic link, and did not modify the permission bits if follow_symlinks is false and src is a symbolic link.gh-113119:
os.posix_spawn()now acceptsenv=None, which makes the newly spawned process use the current process environment. Patch by Jakub Kulik.gh-113202: Add a
strictoption tobatched()in theitertoolsmodule.gh-61648: Detect line numbers of properties in doctests.
gh-113175: Sync with importlib_metadata 7.0, including improved type annotations, fixed issue with symlinked packages in
package_distributions, addedEntryPoints.__repr__, introduced thediagnosescript, addedDistribution.originproperty, and removed deprecatedEntryPointaccess by numeric index (tuple behavior).gh-59616: Add support of
os.lchmod()and the follow_symlinks argument inos.chmod()on Windows. Note that the default value of follow_symlinks inos.lchmod()isFalseon Windows.gh-112559:
signal.signal()andsignal.getsignal()no longer callrepron callable handlers.asyncio.run()andasyncio.Runner.run()no longer callrepron the task results. Patch by Yilei Yang.gh-112962:
dismodule functions add cache information to theInstructioninstance rather than creating fakeInstructioninstances to represent the cache entries.gh-112989: Reduce overhead to connect sockets with
asyncioSelectorEventLoop.gh-112970: Use
closefrom()on Linux where available (e.g. glibc-2.34), rather than only FreeBSD.gh-110190: Fix ctypes structs with array on PPC64LE platform by setting
MAX_STRUCT_SIZEto 64 in stgdict. Patch by Diego Russo.gh-112540: The statistics.geometric_mean() function now returns zero for datasets containing a zero. Formerly, it would raise an exception.
gh-87286: Added
LOG_FTP,LOG_NETINFO,LOG_REMOTEAUTH,LOG_INSTALL,LOG_RAS, andLOG_LAUNCHDtot thesyslogmodule, all of them constants on used on macOS.gh-112800: Fix
asyncioSubprocessTransport.close()not to throwPermissionErrorwhen used with setuid executables.gh-51944: Add the following constants to the
termiosmodule. These values are present in macOS system headers:ALTWERASE,B14400,B28800,B7200,B76800,CCAR_OFLOW,CCTS_OFLOW,CDSR_OFLOW,CDTR_IFLOW,CIGNORE,CRTS_IFLOW,EXTPROC,IUTF8,MDMBUF,NL2,NL3,NOKERNINFO,ONOEOT,OXTABS,VDSUSP,VSTATUS.gh-79325: Fix an infinite recursion error in
tempfile.TemporaryDirectory()cleanup on Windows.gh-94692:
shutil.rmtree()now only catches OSError exceptions. Previously a symlink attack resistant version ofshutil.rmtree()could ignore or pass to the error handler arbitrary exception when invalid arguments were provided.gh-112736: The use of del-safe symbols in
subprocesswas refactored to allow for use in cross-platform build environments.gh-112727: Speed up
pathlib.Path.absolute(). Patch by Barney Gale.gh-74690: Speedup
issubclass()checks against simpleruntime-checkable protocolsby around 6%. Patch by Alex Waygood.gh-74690: Speedup
isinstance()checks by roughly 20% forruntime-checkable protocolsthat only have one callable member. Speedupissubclass()checks for these protocols by roughly 10%. Patch by Alex Waygood.gh-112645: Remove deprecation error on passing
onerrortoshutil.rmtree().gh-112640: Add
kwdefaultsparameter totypes.FunctionTypeto set default keyword argument values.gh-112622: Ensure
nameparameter is passed to event loop inasyncio.create_task().gh-112618: Fix a caching bug relating to
typing.Annotated.Annotated[str, True]is no longer identical toAnnotated[str, 1].gh-112334: Fixed a performance regression in 3.12’s
subprocesson Linux where it would no longer use the fast-pathvfork()system call when it could have due to a logic bug, instead falling back to the safe but slowerfork().Also fixed a second 3.12.0 potential security bug. If a value of
extra_groups=[]was passed tosubprocess.Popenor related APIs, the underlyingsetgroups(0, NULL)system call to clear the groups list would not be made in the child process prior toexec().This was identified via code inspection in the process of fixing the first bug.
gh-110190: Fix ctypes structs with array on Arm platform by setting
MAX_STRUCT_SIZEto 32 in stgdict. Patch by Diego Russo.gh-81194: Fix a crash in
socket.if_indextoname()with specific value (UINT_MAX). Fix an integer overflow insocket.if_indextoname()on 64-bit non-Windows platforms.gh-112578: Fix a spurious
RuntimeWarningwhen executing thezipfilemodule.gh-112516: Update the bundled copy of pip to version 23.3.1.
gh-112510: Add
readline.backendfor the backend readline uses (editlineorreadline)gh-112328: [Enum] Make
EnumDict,EnumDict.member_names,EnumType._add_alias_andEnumType._add_value_alias_public.gh-112509: Fix edge cases that could cause a key to be present in both the
__required_keys__and__optional_keys__attributes of atyping.TypedDict. Patch by Jelle Zijlstra.gh-101336: Add
keep_alivekeyword parameter forAbstractEventLoop.create_server()andBaseEventLoop.create_server().gh-63284: Added support for TLS-PSK (pre-shared key) mode to the
sslmodule.gh-112414: Fix regression in Python 3.12 where calling
repr()on a module that had been imported using a custom loader could fail withAttributeError. Patch by Alex Waygood.gh-112358: Revert change to
struct.Structinitialization that broke some cases of subclassing.gh-112405: Optimize
pathlib.PurePath.relative_to(). Patch by Alex Waygood.gh-94722: Fix bug where comparison between instances of
DocTestfails if one of them hasNoneas its lineno.gh-112361: Speed up a small handful of
pathlibmethods by removing some temporary objects.gh-112345: Improve error message when trying to call
issubclass()against atyping.Protocolthat has non-method members. Patch by Randolf Scholz.gh-112137: Change
disoutput to display no-lineno as “–” instead of “None”.gh-112332: Deprecate the
exc_typefield oftraceback.TracebackException. Addexc_type_strto replace it.gh-81620: Add extra tests for
random.binomialvariate()gh-112292: Fix a crash in
readlinewhen imported from a sub interpreter. Patch by Anthony Shawgh-77621: Slightly improve the import time of the
pathlibmodule by deferring some imports. Patch by Barney Gale.gh-112137: Change
disoutput to display logical labels for jump targets instead of offsets.gh-112139: Add
Signature.format()to format signatures to string with extra options. And use it inpydocto render more readable signatures that have new lines between parameters.gh-112105: Make
readline.set_completer_delims()work with libeditgh-106922: Display multiple lines with
tracebackwhen errors span multiple lines.gh-111874: When creating a
typing.NamedTupleclass, ensure__set_name__()is called on all objects that define__set_name__and exist in the values of theNamedTupleclass’s class dictionary. Patch by Alex Waygood.gh-68166: Add support of the “vsapi” element type in
tkinter.ttk.Style.element_create().gh-110275: Named tuple’s methods
_replace()and__replace__()now raise TypeError instead of ValueError for invalid keyword arguments.gh-99367: Do not mangle
sys.path[0]inpdbif safe_path is setgh-111615: Fix a regression caused by a fix to gh-93162 whereby you couldn’t configure a
QueueHandlerwithout specifying handlers.gh-75666: Fix the behavior of
tkinterwidget’sunbind()method with two arguments. Previously,widget.unbind(sequence, funcid)destroyed the current binding for sequence, leaving sequence unbound, and deleted the funcid command. Now it removes only funcid from the binding for sequence, keeping other commands, and deletes the funcid command. It leaves sequence unbound only if funcid was the last bound command.gh-67790: Implement basic formatting support (minimum width, alignment, fill) for
fractions.Fraction.gh-111049: Fix crash during garbage collection of the
io.BytesIObuffer object.gh-102980: Redirect the output of
interactcommand ofpdbto the same channel as the debugger. Add tests and improve docs.gh-102988:
email.utils.getaddresses()andemail.utils.parseaddr()now return('', '')2-tuples in more situations where invalid email addresses are encountered instead of potentially inaccurate values. Add optional strict parameter to these two functions: usestrict=Falseto get the old behavior, accept malformed inputs.getattr(email.utils, 'supports_strict_parsing', False)can be use to check if the strict parameter is available. Patch by Thomas Dwyer and Victor Stinner to improve the CVE 2023-27043 fix.gh-52161:
cmd.Cmd.do_help()now cleans docstrings withinspect.cleandoc()before writing them. Patch by Filip Łapkiewicz.gh-82300: Add
trackparameter tomultiprocessing.shared_memory.SharedMemorythat allows using shared memory blocks without having to register with the POSIX resource tracker that automatically releases them upon process exit.gh-110109: Add private
pathlib._PurePathBaseclass: a base class forpathlib.PurePaththat omits certain magic methods. It may be made public (along with_PathBase) in future.gh-109858: Protect
zipfilefrom “quoted-overlap” zipbomb. It now raises BadZipFile when try to read an entry that overlaps with other entry or central directory.gh-109786: Fix possible reference leaks and crash when re-enter the
__next__()method ofitertools.pairwise.gh-91539: Small (10 - 20%) and trivial performance improvement of
urllib.request.getproxies_environment(), typically useful when there are many environment variables to go over.gh-103363: Add follow_symlinks keyword-only argument to
pathlib.Path.owner()andgroup(), defaulting toTrue.gh-99437:
runpy.run_path()now decodes path-like objects, making sure __file__ and sys.argv[0] of the module being run are always strings.gh-104003: Add
warnings.deprecated(), a decorator to mark deprecated functions to static type checkers and to warn on usage of deprecated classes and functions. See PEP 702. Patch by Jelle Zijlstra.gh-103708: Make hardcoded python name, a configurable parameter so that different implementations of python can override it instead of making huge diffs in sysconfig.py
gh-66515:
mailbox.MHnow supports folders that do not contain a.mh_sequencesfile (e.g. Claws Mail IMAP-cache folders). Patch by Serhiy Storchaka.gh-83162: Renamed
re.errortoPatternErrorfor clarity, and keptre.errorfor backward compatibility. Patch by Matthias Bussonnier and Adam Chhina.gh-91133: Fix a bug in
tempfile.TemporaryDirectorycleanup, which now no longer dereferences symlinks when working around file system permission errors.bpo-43153: On Windows,
tempfile.TemporaryDirectorypreviously masked aPermissionErrorwithNotADirectoryErrorduring directory cleanup. It now correctly raisesPermissionErrorif errors are not ignored. Patch by Andrei Kulakov and Ken Jin.bpo-32731:
getpass.getuser()now raisesOSErrorfor all failures rather thanImportErroron systems lacking thepwdmodule orKeyErrorif the password database is empty.bpo-34321:
mmap.mmapnow has a trackfd parameter on Unix; if it isFalse, the file descriptor specified by fileno will not be duplicated.bpo-35332: The
shutil.rmtree()function now ignores errors when callingos.close()when ignore_errors isTrue, andos.close()no longer retried after error.bpo-35928:
io.TextIOWrappernow correctly handles the decoding buffer afterread()andwrite().bpo-26791:
shutil.move()now moves a symlink into a directory when that directory is the target of the symlink. This provides the same behavior as the mv shell command. The previous behavior raised an exception. Patch by Jeffrey Kintscher.bpo-41422: Fixed memory leaks of
pickle.Picklerandpickle.Unpicklerinvolving cyclic references via the internal memo mapping.bpo-19821: The
pydoc.ispackage()function has been deprecated.bpo-40262: The
ssl.SSLSocket.recv_into()method no longer requires the buffer argument to implement__len__and supports buffers with arbitrary item size.bpo-39912:
warnings.filterwarnings()andwarnings.simplefilter()now raise appropriate exceptions instead ofAssertionError. Patch contributed by Rémi Lapeyre.bpo-37260: Fixed a race condition in
shutil.rmtree()in which directory entries removed by another process or thread whileshutil.rmtree()is running can cause it to raise FileNotFoundError. Patch by Jeffrey Kintscher.bpo-36959: Fix some error messages for invalid ISO format string combinations in
strptime()that referred to directives not contained in the format string. Patch by Gordon P. Hemsley.bpo-18060: Fixed a class inheritance issue that can cause segfaults when deriving two or more levels of subclasses from a base class of Structure or Union.
bpo-29779: Add a new
PYTHON_HISTORYenvironment variable to set the location of a.python_historyfile.bpo-21360:
mailbox.Maildirnow ignores files with a leading dot.
Documentation¶
gh-111699: Relocate
smtpddeprecation notice to its own section rather than underlocalein What’s New in Python 3.12 documentgh-110746: Improved markup for valid options/values for methods ttk.treeview.column and ttk.treeview.heading, and for Layouts.
gh-95649: Document that the
asynciomodule contains code taken from v0.16.0 of the uvloop project, as well as the required MIT licensing information.
Tests¶
gh-111798: Disable
test_super_deep()fromtest_callunder pydebug builds on WASI; the stack depth is too small to make the test useful.gh-111801: Lower the recursion limit in
test_isinstancefortest_infinitely_many_bases(). This prevents a stack overflow on a pydebug build of WASI.gh-111802: Specify a low recursion depth for
test_bad_getattr()intest.pickletesterto avoid exhausting the stack under a pydebug build for WASI.gh-44626: Fix
os.path.isabs()incorrectly returningTruewhen given a path that starts with exactly one (back)slash on Windows.Fix
pathlib.PureWindowsPath.is_absolute()incorrectly returningFalsefor some paths beginning with two (back)slashes.gh-113633: Use module state for the _testcapi extension module.
gh-109980: Fix
test_tarfile_vs_tarintest_shutilfor macOS, where system tar can include more information in the archive thanshutil.make_archive.gh-112769: The tests now correctly compare zlib version when
zlib.ZLIB_RUNTIME_VERSIONcontains non-integer suffixes. For example zlib-ng defines the version as1.3.0.zlib-ng.gh-112334: Adds a regression test to verify that
vfork()is used when expected bysubprocesson vfork enabled POSIX systems (Linux).gh-108927: Fixed order dependence in running tests in the same process when a test that has submodules (e.g. test_importlib) follows a test that imports its submodule (e.g. test_importlib.util) and precedes a test (e.g. test_unittest or test_compileall) that uses that submodule.
bpo-40648: Test modes that file can get with chmod() on Windows.
Build¶
gh-114013: Fix
Tools/wasm/wasi.pyto not include the path topython.wasmas part ofHOSTRUNNER. The environment variable is meant to specify how to run the WASI host only, havingpython.wasmand relevant flags appended to theHOSTRUNNER. This fixesmake testwork.gh-113258: Changed the Windows build to write out generated frozen modules into the build tree instead of the source tree.
gh-112305: Fixed the
check-clean-srcstep performed on out of tree builds to detect errant$(srcdir)/Python/frozen_modules/*.hfiles and recommend appropriate source tree cleanup steps to get a working build again.gh-112536: Add support for thread sanitizer (TSAN)
gh-112867: Fix the build for the case that WITH_PYMALLOC_RADIX_TREE=0 set.
gh-103065: Introduce
Tools/wasm/wasi.pyto simplify doing a WASI build.bpo-11102: The
os.major(),os.makedev(), andos.minor()functions are now available on HP-UX v3.bpo-36351: Do not set ipv6type when cross-compiling.
Windows¶
gh-114096: Process privileges that are activated for creating directory junctions are now restored afterwards, avoiding behaviour changes in other parts of the program.
gh-111877:
os.stat()calls were returning incorrect time values for files that could not be accessed directly.gh-111973: Update Windows installer to use SQLite 3.44.2.
gh-113009:
multiprocessing: On Windows, fix a race condition inProcess.terminate(): no longer set thereturncodeattribute to always callWaitForSingleObject()inProcess.wait(). Previously, sometimes the process was still running afterTerminateProcess()even ifGetExitCodeProcess()is notSTILL_ACTIVE. Patch by Victor Stinner.gh-86179: Fixes path calculations when launching Python on Windows through a symlink.
gh-71383: Update Tcl/Tk in Windows installer to 8.6.13 with a patch to suppress incorrect ThemeChanged warnings.
gh-111650: Ensures the
Py_GIL_DISABLEDpreprocessor variable is defined inpyconfig.hso that extension modules written in C are able to use it.gh-112278: Reduce the time cost for some functions in
platformon Windows if current user has no permission to the WMI.gh-73427: Deprecate
sys._enablelegacywindowsfsencoding(). UsePYTHONLEGACYWINDOWSFSENCODINGinstead. Patch by Inada Naoki.gh-87868: Correctly sort and remove duplicate environment variables in
_winapi.CreateProcess().bpo-37308: Fix mojibake in
mmap.mmapwhen using a non-ASCII tagname argument on Windows.
macOS¶
gh-113666: Add the following constants to module
stat:UF_SETTABLE,UF_TRACKED,UF_DATAVAULT,SF_SUPPORTED,SF_SETTABLE,SF_SYNTHETIC,SF_RESTRICTED,SF_FIRMLINKandSF_DATALESS. The valuesUF_SETTABLE,SF_SUPPORTED,SF_SETTABLEandSF_SYNTHETICare only available on macOS.gh-113536:
os.waitid()is now available on macOSgh-110459: Running
configure ... --with-openssl-rpath=X/Y/Zno longer fails to detect OpenSSL on macOS.gh-74573: Document that
dbm.ndbmcan silently corrupt DBM files on updates when exceeding undocumented platform limits, and can crash (segmentation fault) when reading such a corrupted file. (FB8919203)gh-65701: The freeze tool doesn’t work with framework builds of Python. Document this and bail out early when running the tool with such a build.
gh-87277: webbrowser: Don’t look for X11 browsers on macOS. Those are generally not used and probing for them can result in starting XQuartz even if it isn’t used otherwise.
gh-111973: Update macOS installer to use SQLite 3.44.2.
gh-108269: Set
CFBundleAllowMixedLocalizationsto true in the Info.plist for the framework, embedded Python.app and IDLE.app with framework installs on macOS. This allows applications to pick up the user’s preferred locale when that’s different from english.gh-102362: Make sure the result of
sysconfig.get_plaform()includes at least a major and minor versions, even ifMACOSX_DEPLOYMENT_TARGETis set to only a major version during build to match the format expected by pip.gh-110017: Disable a signal handling stress test on macOS due to a bug in macOS (FB13453490).
gh-110820: Make sure the preprocessor definitions for
ALIGNOF_MAX_ALIGN_T,SIZEOF_LONG_DOUBLEandHAVE_GCC_ASM_FOR_X64are correct for Universal 2 builds on macOS.gh-109981: Use
/dev/fdon macOS to determine the number of open files intest.support.os_helper.fd_countto avoid a crash with “guarded” file descriptors when probing for open files.
IDLE¶
gh-72284: Improve the lists of features, editor key bindings, and shell key bingings in the IDLE doc.
gh-113903: Fix rare failure of test.test_idle, in test_configdialog.
gh-113729: Fix the “Help -> IDLE Doc” menu bug in 3.11.7 and 3.12.1.
gh-113269: Fix test_editor hang on macOS Catalina.
gh-112898: Fix processing unsaved files when quitting IDLE on macOS.
bpo-13586: Enter the selected text when opening the “Replace” dialog.
C API¶
gh-106560: Fix redundant declarations in the public C API. Declare PyBool_Type, PyLong_Type and PySys_Audit() only once. Patch by Victor Stinner.
gh-112438: Fix support of format units “es”, “et”, “es#”, and “et#” in nested tuples in
PyArg_ParseTuple()-like functions.gh-111545: Add
Py_HashPointer()function to hash a pointer. Patch by Victor Stinner.gh-65210: Change the declaration of the keywords parameter of
PyArg_ParseTupleAndKeywords()andPyArg_VaParseTupleAndKeywords()for better compatibility with C++.
Python 3.13.0 alpha 2¶
Release date: 2023-11-22
Core and Builtins¶
gh-112243: Don’t include comments in f-string debug expressions. Patch by Pablo Galindo
gh-112287: Slightly optimize the Tier 2 (uop) interpreter by only loading
opargandoperandwhen needed. Also double the trace size limit again, to 512 this time.gh-111807: Lower the max parser stack depth to 1000 under WASI debug builds.
gh-111798: When Python is built in debug mode, set the C recursion limit to 500 instead of 1500. A debug build is likely built with low optimization level which implies higher stack memory usage than a release build. Patch by Victor Stinner.
gh-106529: Enable translating unspecialized
FOR_ITERto Tier 2.gh-111916: Make hashlib related modules thread-safe without the GIL
gh-81137: Deprecate assignment to a function’s
__code__field when the new code object is of a mismatched type (e.g., from a generator to a plain function).gh-79932: Raise exception if
frame.clear()is called on a suspended frame.gh-81925: Implement native thread ids for GNU KFreeBSD.
gh-111843: Use exponential backoff to reduce the number of failed tier 2 optimization attempts by over 99%.
gh-110829: Joining a thread now ensures the underlying OS thread has exited. This is required for safer fork() in multi-threaded processes.
gh-109369: Make sure that tier 2 traces are de-optimized if the code is instrumented
gh-111772: Specialize slot loads and stores for _Py_T_OBJECT as well as Py_T_OBJECT_EX
gh-111666: Speed up
BaseExceptionGroup.derive(),BaseExceptionGroup.subgroup(), andBaseExceptionGroup.split()by changing how they parse passed arguments.gh-111654: Fix runtime crash when some error happens in opcode
LOAD_FROM_DICT_OR_DEREF.gh-111623: Add support for sharing tuples between interpreters using the cross-interpreter API. Patch by Anthony Shaw.
gh-111354: The oparg of
YIELD_VALUEis now1if the instruction is part of a yield-from or await, and0otherwise.The SUSPENDED frame state is now split into
SUSPENDEDandSUSPENDED_YIELD_FROM. This simplifies the code in_PyGen_yf.gh-111520: Merge the Tier 1 (bytecode) and Tier 2 (micro-ops) interpreters together, moving the Tier 2 interpreter loop and switch into
_PyEval_EvalFrameDefault()inPython/ceval.c. ThePython/executor.cfile is gone. Also theTIER_ONEandTIER_TWOmacros are now handled by the code generator.Beware! This changes the environment variables to enable micro-ops and their debugging to
PYTHON_UOPSandPYTHON_LLTRACE.gh-109181: Speed up
Tracebackobject creation by lazily compute the line number. Patch by Pablo Galindogh-111420: Allow type comments in parenthesized
withstatementsgh-111438: Add support for sharing floats between interpreters using the cross-interpreter API. Patch by Anthony Shaw.
gh-111435: Add support for sharing of
TrueandFalsebetween interpreters using the cross-interpreter API. Patch by Anthony Shaw.gh-102388: Fix a bug where
iso2022_jp_3andiso2022_jp_2004codecs read out of boundsgh-111366: Fix an issue in the
codeopthat was causingSyntaxErrorexceptions raised in the presence of invalid syntax to not contain precise error messages. Patch by Pablo Galindogh-111380: Fix a bug that was causing
SyntaxWarningto appear twice when parsing if invalid syntax is encountered later. Patch by Pablo galindogh-111374: Added a new environment variable
PYTHON_FROZEN_MODULES. It determines whether or not frozen modules are ignored by the import machinery, equivalent of the-X frozen_modulescommand-line option.gh-111354: Remove
opargfromYIELD_VALUE. ChangeopargofRESUMEto include information about the except-depth. These changes make it possible to simplify the code in generator close.gh-94438: Fix a regression that prevented jumping across
is Noneandis not Nonewhen debugging. Patch by Savannah Ostrowski.gh-67224: Show source lines in tracebacks when using the
-coption when running Python. Patch by Pablo Galindogh-111123: Fix a bug where a
globaldeclaration in anexceptblock is rejected when the global is used in theelseblock.gh-110938: Fix error messages for indented blocks with functions and classes with generic type parameters. Patch by Pablo Galindo
gh-109214: Remove unnecessary instruction pointer updates before returning from frames.
gh-110912: Correctly display the traceback for
MemoryErrorexceptions using thetracebackmodule. Patch by Pablo Galindogh-109894: Fixed crash due to improperly initialized static
MemoryErrorin subinterpreter.gh-110892: Return
NULLforPyTrace_RETURNevents caused by an exceptiongh-110864: Fix argument parsing by
_PyArg_UnpackKeywordsWithVarargfor functions defining pos-or-keyword, vararg, and kw-only parameters.gh-109094: Replace
prev_instron the interpreter frame byinstr_ptrwhich points to the beginning of the instruction that is currently executing (or will execute once the frame resumes).gh-110805: Allow the repl to show source code and complete tracebacks. Patch by Pablo Galindo
gh-110722: Add
PYTHON_PRESITE=package.moduleto import a module early in the interpreter lifecycle beforesite.pyis executed. Python needs to be built in debug mode for this option to exist.gh-110481: Implement biased reference counting in
--disable-gilbuilds.gh-110543: Fix regression in Python 3.12 where
types.CodeType.replace()would produce a broken code object if called on a module or class code object that contains a comprehension. Patch by Jelle Zijlstra.gh-89519: Removed chained
classmethoddescriptors (introduced in bpo-19072). This can no longer be used to wrap other descriptors such asproperty. The core design of this feature was flawed and caused a number of downstream problems. To “pass-through” aclassmethod, consider using the__wrapped__attribute that was added in Python 3.10.gh-103615: Use local events for opcode tracing
bpo-46657: Add mimalloc memory allocator support.
gh-106718: When PyConfig.stdlib_dir is explicitly set, it’s now respected and won’t be overridden by PyConfig.home.
gh-106905: Fix incorrect SystemError about AST constructor recursion depth mismatch.
gh-100445: Improve error message for unterminated strings with escapes.
bpo-45759: Improved error messages for
elif/elsestatements not matching any valid statements. Patch by Jeremiah Vivian.
Library¶
gh-111942: Fix SystemError in the TextIOWrapper constructor with non-encodable “errors” argument in non-debug mode.
gh-111995: Added the
NI_IDNconstant to thesocketmodule when present in C at build time for use withsocket.getnameinfo().gh-109538: Issue warning message instead of having
RuntimeErrorbe displayed when event loop has already been closed atStreamWriter.__del__().gh-111942: Fix crashes in
io.TextIOWrapper.reconfigure()when pass invalid arguments, e.g. non-string encoding.gh-111460:
curses: restore wide character support (includingcurses.unget_wch()andget_wch()) on macOS, which was unavailable due to a regression in Python 3.12.gh-103791:
contextlib.suppressnow supports suppressing exceptions raised as part of aBaseExceptionGroup, in addition to the recent support forExceptionGroup.gh-111835: The
mmap.mmapclass now has anseekable()method that can be used when a seekable file-like object is required. Theseek()method now returns the new absolute position. Patch by Donghee Na.gh-111804: Remove posix.fallocate() under WASI as the underlying posix_fallocate() is not available in WASI preview2.
gh-111841: Fix truncating arguments on an embedded null character in
os.putenv()andos.unsetenv()on Windows.gh-111768:
wsgiref.util.is_hop_by_hop()is now exposed correctly in__all__.gh-80731: Avoid executing the default function in
cmd.Cmdin an except blockgh-111541: Fix
doctestforSyntaxErrornot-builtin subclasses.gh-111719: Add extra argument validation for
aliascommand inpdbgh-111482:
time: Maketime.clock_gettime()andtime.clock_gettime_ns()functions up to 2x faster by faster calling convention. Patch by Victor Stinner.gh-110894: Call loop exception handler for exceptions in
client_connected_cbofasyncio.start_server()so that applications can handle it. Patch by Kumar Aditya.gh-111531: Fix reference leaks in
bind_class()andbind_all()methods oftkinterwidgets.gh-111246:
asyncio.loop.create_unix_server()will now automatically remove the Unix socket when the server is closed.gh-111356: Added
io.text_encoding(),io.DEFAULT_BUFFER_SIZE, andio.IncrementalNewlineDecodertoio.__all__.gh-66425: Remove the code to set the REMOTE_HOST header from wsgiref module, as it is unreachable. This header is used for performance reasons, which is not necessary in the wsgiref module.
gh-111429: Speed up
pathlib.PurePath.relative_to()andis_relative_to().gh-111342: Fixed typo in
math.sumprod().gh-68166: Remove mention of not supported “vsapi” element type in
tkinter.ttk.Style.element_create(). Add tests forelement_create()and otherttk.Stylemethods. Add examples forelement_create()in the documentation.gh-111388: Add
show_groupparameter totraceback.format_exception_only(), which allows to formatExceptionGroupinstances.gh-79033: Another attempt at fixing
asyncio.Server.wait_closed(). It now blocks until both conditions are true: the server is closed, and there are no more active connections. (This means that in some cases where in 3.12.0 this function would incorrectly have returned immediately, it will now block; in particular, when there are no active connections but the server hasn’t been closed yet.)gh-111295: Fix
timenot checking for errors when initializing.gh-111253: Add error checking during
_socketmodule init.gh-111251: Fix
_blake2not checking for errors when initializing.gh-111233: Fix
selectnot checking for errors when initializing.gh-111230: Fix
sslnot checking for errors when initializing.gh-111174: Fix crash in
io.BytesIO.getbuffer()called repeatedly for empty BytesIO.gh-111187: Postpone removal version for locale.getdefaultlocale() to Python 3.15.
gh-111159: Fix
doctestoutput comparison for exceptions with notes.gh-110910: Fix invalid state handling in
asyncio.TaskGroupandasyncio.Timeout. They now raise proper RuntimeError if they are improperly used and are left in consistent state after this.gh-111092: Make turtledemo run without default root enabled.
gh-110944: Support alias and convenience vars for
pdbcompletiongh-110745: Added newline parameter to
pathlib.Path.read_text(). Patch by Junya Okabe.gh-84583: Make
pdbenter post-mortem mode even forSyntaxErrorgh-80675: Set
f_trace_lines = Trueon all frames uponpdb.set_trace()gh-110771: Expose the setup and cleanup portions of
asyncio.run_forever()as the standalone methodsasyncio.run_forever_setup()andasyncio.run_forever_cleanup(). This allows for tighter integration with GUI event loops.gh-110774: Support setting the
asyncio.Runnerloop_factory kwarg inunittest.IsolatedAsyncioTestCasegh-110392: Fix
tty.setraw()andtty.setcbreak(): previously they returned partially modified list of the original tty attributes.tty.cfmakeraw()andtty.cfmakecbreak()now make a copy of the list of special characters before modifying it.gh-59013: Make line number of function breakpoint more precise in
pdbgh-88434: Emit deprecation warning for non-integer numbers in
gettextfunctions and methods that consider plural forms even if the translation was not found.gh-110395: Ensure that
select.kqueue()objects correctly appear as closed in forked children, to prevent operations on an invalid file descriptor.gh-110196: Add
__reduce__method toIPv6Addressin order to keepscope_idgh-109747: Improve errors for unsupported look-behind patterns. Now re.error is raised instead of OverflowError or RuntimeError for too large width of look-behind pattern.
gh-109466: Add the
ipaddress.IPv4Address.ipv6_mappedproperty, which returns the IPv4-mapped IPv6 address.gh-85098: Implement the CLI of the
symtablemodule and improve the repr ofSymbol.gh-108791: Improved error handling in
pdbcommand line interface, making it produce more concise error messages.gh-105931: Change
compileallto only strip the stripdir prefix from the full path recorded in the compiled.pycfile, when the prefix matches the start of the full path in its entirety. When the prefix does not match, no stripping is performed and a warning to this effect is displayed.Previously all path components of the stripdir prefix that matched the full path were removed, while those that did not match were left alone (including ones interspersed between matching components).
gh-107431: Make the
DictProxyandListProxytypes inmultiprocessing.managersGeneric Alias Types for[]use in typing contexts.gh-72904: Add
glob.translate(). This function converts a pathname with shell-style wildcards to a regular expression.gh-90026: Define
USE_XATTRSon Cygwin so that XATTR-related functions in theosmodule become available.gh-90890: New methods
mailbox.Maildir.get_info(),mailbox.Maildir.set_info(),mailbox.Maildir.get_flags(),mailbox.Maildir.set_flags(),mailbox.Maildir.add_flag(),mailbox.Maildir.remove_flag(). These methods speed up accessing a message’s info and/or flags and are useful when it is not necessary to access the message’s contents, as when iterating over a Maildir to find messages with specific flags.gh-102956: Fix returning of empty byte strings after seek in zipfile module
gh-102895: Added a parameter
local_exitforcode.interact()to preventexit()andquitfrom closingsys.stdinand raiseSystemExit.gh-97928: Change the behavior of
tkinter.Text.count(). It now always returns an integer if one or less counting options are specified. Previously it could return a single count as a 1-tuple, an integer (only if option"update"was specified) orNoneif no items found. The result is now the same ifwantobjectsis set to0.gh-96954: Switch the storage of the unicode codepoint names to use a different data-structure, a directed acyclic word graph. This makes the unicodedata shared library about 440 KiB smaller. Contributed by Carl Friedrich Bolz-Tereick using code from the PyPy project.
gh-73561: Omit the interface scope from an IPv6 address when used as Host header by
http.client.gh-86826:
zipinfonow supports the full range of values in the TZ string determined by RFC 8536 and detects all invalid formats. Both Python and C implementations now raise exceptions of the same type on invalid data.
Tests¶
gh-111808: Make the default value of
test.support.infinite_recursion()to be conditional based on whether optimizations were used when compiling the interpreter. This helps with platforms like WASI whose stack size is greatly restricted in debug builds.gh-110722: Gathering line coverage of standard libraries within the regression test suite is now precise, as well as much faster. Patch by Łukasz Langa.
gh-110367: Make regrtest
--verbose3option compatible with--huntrleaks -jNoptions. The./python -m test -j1 -R 3:3 --verbose3command now works as expected. Patch by Victor Stinner.gh-111165: Remove no longer used functions
run_unittest()andrun_doctest()from thetest.supportmodule.gh-110932: Fix regrtest if the
SOURCE_DATE_EPOCHenvironment variable is defined: use the variable value as the random seed. Patch by Victor Stinner.gh-110995: test_gdb: Fix detection of gdb built without Python scripting support. Patch by Victor Stinner.
gh-110918: Test case matching patterns specified by options
--match,--ignore,--matchfileand--ignorefileare now tested in the order of specification, and the last match determines whether the test case be run or ignored.gh-108747: Add unit test for
usercustomizeandsitecustomizehooks fromsite.
Build¶
gh-96954: Make
make regen-unicodedatawork for out-of-tree builds of CPython.gh-112088: Add
Tools/build/regen-configure.shscript to regenerate theconfigurewith an Ubuntu container image. Thequay.io/tiran/cpython_autoconf:271container image (tiran/cpython_autoconf) is no longer used. Patch by Victor Stinner.gh-111046: For wasi-threads, memory is now exported to fix compatibility issues with some wasm runtimes.
gh-110828: AIX 32bit needs
-latomicto build the_testcapiextension module.gh-85283: The
errno,md5,resource,winsound,_ctypes_test,_multiprocessing.posixshmem,_scproxy,_stat,_testimportmultipleand_uuidC extensions are now built with the limited C API. Patch by Victor Stinner.
Windows¶
gh-111856: Fixes
fstat()on file systems that do not support file ID requests. This includes FAT32 and exFAT.gh-111293: Fix
os.DirEntry.inodedropping higher 64 bits of a file id on some filesystems on Windows.gh-110913: WindowsConsoleIO now correctly chunks large buffers without splitting up UTF-8 sequences.
macOS¶
gh-59703: For macOS framework builds, in
getpath.cuse the systemdladdrfunction to find the path to the shared library rather than depending on deprecated macOS APIs.gh-110950: Update macOS installer to include an upstream Tcl/Tk fix for the
Secure coding is not enabled for restorable state!warning encountered in Tkinter on macOS 14 Sonoma.gh-111015: Ensure that IDLE.app and Python Launcher.app are installed with appropriate permissions on macOS builds.
gh-71383: Update macOS installer to include an upstream Tcl/Tk fix for the
ttk::ThemeChangederror encountered in Tkinter.gh-92603: Update macOS installer to include a fix accepted by upstream Tcl/Tk for a crash encountered after the first
tkinter.Tk()instance is destroyed.
IDLE¶
bpo-35668: Add docstrings to the IDLE debugger module. Fix two bugs: initialize
Idb.botframe(should be in Bdb); inIdb.in_rpc_code, check whetherprev_frameisNonebefore trying to use it. Greatly expand test_debugger.
Tools/Demos¶
gh-111903: Argument Clinic now supports the
@critical_sectiondirective that instructs Argument Clinic to generate a critical section around the function call, which locks theselfobject in--disable-gilbuilds. Patch by Sam Gross.
C API¶
gh-112026: Add again the private
_PyThreadState_UncheckedGet()function as an alias to the new publicPyThreadState_GetUnchecked()function. Patch by Victor Stinner.gh-112026: Restore the removed
_PyDict_GetItemStringWithError()function. It is used by numpy. Patch by Victor Stinner.gh-112026: Restore removed private C API functions, macros and structures which have no simple replacement for now:
_PyDict_GetItem_KnownHash()
_PyDict_NewPresized()
_PyHASH_BITS
_PyHASH_IMAG
_PyHASH_INF
_PyHASH_MODULUS
_PyHASH_MULTIPLIER
_PyLong_Copy()
_PyLong_FromDigits()
_PyLong_New()
_PyLong_Sign()
_PyObject_CallMethodId()
_PyObject_CallMethodNoArgs()
_PyObject_CallMethodOneArg()
_PyObject_CallOneArg()
_PyObject_EXTRA_INIT
_PyObject_FastCallDict()
_PyObject_GetAttrId()
_PyObject_Vectorcall()
_PyObject_VectorcallMethod()
_PyStack_AsDict()
_PyThread_CurrentFrames()
_PyUnicodeWriter structure
_PyUnicodeWriter_Dealloc()
_PyUnicodeWriter_Finish()
_PyUnicodeWriter_Init()
_PyUnicodeWriter_Prepare()
_PyUnicodeWriter_PrepareKind()
_PyUnicodeWriter_WriteASCIIString()
_PyUnicodeWriter_WriteChar()
_PyUnicodeWriter_WriteLatin1String()
_PyUnicodeWriter_WriteStr()
_PyUnicodeWriter_WriteSubstring()
_PyUnicode_AsString()
_PyUnicode_FromId()
_PyVectorcall_Function()
_Py_IDENTIFIER()
_Py_c_abs()
_Py_c_diff()
_Py_c_neg()
_Py_c_pow()
_Py_c_prod()
_Py_c_quot()
_Py_c_sum()
_Py_static_string()
_Py_static_string_init()
Patch by Victor Stinner.
gh-112026: Add again
<ctype.h>and<unistd.h>includes inPython.h, but don’t include them in the limited C API version 3.13 and newer. Patch by Victor Stinner.gh-111956: Add internal-only one-time initialization API:
_PyOnceFlagand_PyOnceFlag_CallOnce.gh-111262: Add
PyDict_Pop()andPyDict_PopString()functions: remove a key from a dictionary and optionally return the removed value. This is similar todict.pop(), but without the default value and not raisingKeyErrorif the key missing. Patch by Stefan Behnel and Victor Stinner.gh-111863: Rename
Py_NOGILtoPy_GIL_DISABLED. Patch by Hugo van Kemenade.gh-111138: Add
PyList_Extend()andPyList_Clear()functions: similar to Pythonlist.extend()andlist.clear()methods. Patch by Victor Stinner.gh-108765: On Windows,
Python.hno longer includes the<stddef.h>standard header file. If needed, it should now be included explicitly. Patch by Victor Stinner.gh-111569: Implement “Python Critical Sections” from PEP 703. These are macros to help replace the GIL with per-object locks in the
--disable-gilbuild of CPython. The macros are no-ops in the default build.gh-111506: In the limited C API version 3.13,
Py_SET_REFCNT()function is now implemented as an opaque function call. Patch by Victor Stinner.gh-108082: Add
PyErr_FormatUnraisable()function.gh-110964: Move the undocumented private _PyArg functions and _PyArg_Parser structure to internal C API (
pycore_modsupport.h). Patch by Victor Stinner.gh-110815: Support non-ASCII keyword names in
PyArg_ParseTupleAndKeywords().gh-109587: Introduced
PyUnstable_PerfTrampoline_CompileCode(),PyUnstable_PerfTrampoline_SetPersistAfterFork()andPyUnstable_CopyPerfMapFile(). These functions allow extension modules to initialize trampolines eagerly, after the application is “warmed up”. This makes it possible to have perf-trampolines running in an always-enabled fashion.gh-85283: Add the
PySys_Audit()function to the limited C API. Patch by Victor Stinner.gh-85283: Add
PyMem_RawMalloc(),PyMem_RawCalloc(),PyMem_RawRealloc()andPyMem_RawFree()to the limited C API. Patch by Victor Stinner.gh-106672: Functions
PyDict_GetItem(),PyDict_GetItemString(),PyMapping_HasKey(),PyMapping_HasKeyString(),PyObject_HasAttr(),PyObject_HasAttrString(), andPySys_GetObject(), which clear all errors occurred during calling the function, report now them usingsys.unraisablehook().gh-67565: Remove redundant C-contiguity check in
getargs.c,binascii,ssland Argument Clinic. Patched by Stefan Krah and Furkan Onder
Python 3.13.0 alpha 1¶
Release date: 2023-10-13
Security¶
gh-108310: Fixed an issue where instances of
ssl.SSLSocketwere vulnerable to a bypass of the TLS handshake and included protections (like certificate verification) and treating sent unencrypted data as if it were post-handshake TLS encrypted data. Security issue reported as CVE 2023-40217 by Aapo Oksman. Patch by Gregory P. Smith.gh-107774: PEP 669 specifies that
sys.monitoring.register_callbackwill generate an audit event. Pre-releases of Python 3.12 did not generate the audit event. This is now fixed.gh-102988: Reverted the
email.utilssecurity improvement change released in 3.12beta4 that unintentionally causedemail.utils.getaddressesto fail to parse email addresses with a comma in the quoted name field. See gh-106669.gh-99108: Refresh our new HACL* built-in
hashlibcode from upstream. Built-in SHA2 should be faster and an issue with SHA3 on 32-bit platforms is fixed.gh-102509: Start initializing
ob_digitduring creation ofPyLongObjectobjects. Patch by Illia Volochii.
Core and Builtins¶
gh-110782: Fix crash when
typing.TypeVaris constructed with a keyword argument. Patch by Jelle Zijlstra.gh-110752: Reset
ceval.eval_breakerininterpreter_clear()gh-110721: Use the
tracebackimplementation for the defaultPyErr_Display()functionality. Patch by Pablo Galindogh-110696: Fix incorrect error message for invalid argument unpacking. Patch by Pablo Galindo
gh-104169: Split the tokenizer into two separate directories: - One part includes the actual lexeme producing logic and lives in
Parser/lexer. - The second part wraps the lexer according to the different tokenization modes we have (string, utf-8, file, interactive, readline) and lives inParser/tokenizer.gh-110688: Remove undocumented
test_c_apimethod fromset, which was only defined for testing purposes underPy_DEBUG. Now we have proper CAPI tests.gh-104584: Fix a reference leak when running with
PYTHONUOPSor-X uopsenabled.gh-110514: Add
PY_THROWtosys.setprofile()eventsgh-110489: Optimise
math.ceil()when the input is exactly a float, resulting in about a 10% improvement.gh-110455: Guard
assert(tstate->thread_id > 0)with#ifndef HAVE_PTHREAD_STUBS. This allows for for pydebug builds to work under WASI which (currently) lacks thread support.gh-110309: Remove unnecessary empty constant nodes in the ast of f-string specs.
gh-110259: Correctly identify the format spec in f-strings (with single or triple quotes) that have multiple lines in the expression part and include a formatting spec. Patch by Pablo Galindo
gh-110237: Fix missing error checks for calls to
PyList_Appendin_PyEval_MatchClass.gh-110164: regrtest: If the
SOURCE_DATE_EPOCHenvironment variable is defined, regrtest now disables tests randomization. Patch by Victor Stinner.gh-109889: Fix the compiler’s redundant NOP detection algorithm to skip over NOPs with no line number when looking for the next instruction’s lineno.
gh-109853:
sys.path[0]is now set correctly for subinterpreters.gh-109923: Set line number on the
POP_TOPthat follows aRETURN_GENERATOR.gh-105716: Subinterpreters now correctly handle the case where they have threads running in the background. Before, such threads would interfere with cleaning up and destroying them, as well as prevent running another script.
gh-109369: The internal eval_breaker and supporting flags, plus the monitoring version have been merged into a single atomic integer to speed up checks.
gh-109823: Fix bug where compiler does not adjust labels when removing an empty basic block which is a jump target.
gh-109793: The main thread no longer exits prematurely when a subinterpreter is cleaned up during runtime finalization. The bug was a problem particularly because, when triggered, the Python process would always return with a 0 exitcode, even if it failed.
gh-109719: Fix missing jump target labels when compiler reorders cold/warm blocks.
gh-109595: Add
-X cpu_countcommand line option to override return results ofos.cpu_count()andos.process_cpu_count(). This option is useful for users who need to limit CPU resources of a container system without having to modify the container (application code). Patch by Donghee Na.gh-109627: Fix bug where the compiler does not assign a new jump target label to a duplicated small exit block.
gh-109596: Fix some tokens in the grammar that were incorrectly marked as soft keywords. Also fix some repeated rule names and ensure that repeated rules are not allowed. Patch by Pablo Galindo
gh-109496: On a Python built in debug mode,
Py_DECREF()now calls_Py_NegativeRefcount()if the object is a dangling pointer to deallocated memory: memory filled with0xDD“dead byte” by the debug hook on memory allocators. The fix is to check the reference count before checking for_Py_IsImmortal(). Patch by Victor Stinner.gh-107265: Deopt opcodes hidden by the executor when base opcode is needed
gh-109371: Deopted instructions correctly for tool initialization and modified the incorrect assertion in instrumentation, when a previous tool already sets INSTRUCTION events
gh-105658: Fix bug where the line trace of an except block ending with a conditional includes an excess event with the line of the conditional expression.
gh-109219: Fix compiling type param scopes that use a name which is also free in an inner scope.
gh-109351: Fix crash when compiling an invalid AST involving a named (walrus) expression.
gh-109341: Fix crash when compiling an invalid AST involving a
ast.TypeAlias.gh-109195: Fix source location for the
LOAD_*instruction preceding aLOAD_SUPER_ATTRto load thesuperglobal (or shadowing variable) so that it encompasses only the namesuperand not the following parentheses.gh-109256: Opcode IDs for specialized opcodes are allocated in their own range to improve stability of the IDs for the ‘real’ opcodes.
gh-109207: Fix a SystemError in
__repr__of symtable entry object.gh-109179: Fix bug where the C traceback display drops notes from
SyntaxError.gh-109118: Disallow nested scopes (lambdas, generator expressions, and comprehensions) within PEP 695 annotation scopes that are nested within classes.
gh-109156: Add tests for de-instrumenting instructions while keeping the instrumentation for lines
gh-109114: Relax the detection of the error message for invalid lambdas inside f-strings to not search for arbitrary replacement fields to avoid false positives. Patch by Pablo Galindo
gh-105848: Add a new
CALL_KWopcode, used for calls containing keyword arguments. Also, fix a possible crash when jumping over method calls in a debugger.gh-109052: Use the base opcode when comparing code objects to avoid interference from instrumentation
gh-109118: Fix interpreter crash when a NameError is raised inside the type parameters of a generic class.
gh-88943: Improve syntax error for non-ASCII character that follows a numerical literal. It now points on the invalid non-ASCII character, not on the valid numerical literal.
gh-108976: Fix crash that occurs after de-instrumenting a code object in a monitoring callback.
gh-108732: Make iteration variables of module- and class-scoped comprehensions visible to pdb and other tools that use
frame.f_localsagain.gh-108959: Fix caret placement for error locations for subscript and binary operations that involve non-semantic parentheses and spaces. Patch by Pablo Galindo
gh-104584: Fix a crash when running with
PYTHONUOPSor-X uopsenabled and an error occurs during optimization.gh-108727: Define
tp_deallocforCounterOptimizer_Type. This fixes a segfault on deallocation.gh-108520: Fix
multiprocessing.synchronize.SemLock.__setstate__()to properly initializemultiprocessing.synchronize.SemLock._is_fork_ctx. This fixes a regression when passing a SemLock across nested processes.Rename
multiprocessing.synchronize.SemLock.is_fork_ctxtomultiprocessing.synchronize.SemLock._is_fork_ctxto avoid exposing it as public API.gh-108654: Restore locals shadowed by an inlined comprehension if the comprehension raises an exception.
gh-108488: Change the initialization of inline cache entries so that the cache entry for
JUMP_BACKWARDis initialized to zero, instead of theadaptive_counter_warmup()value used for all other instructions. This counter, unique among instructions, counts up from zero.gh-108716: Turn off deep-freezing of code objects. Modules are still frozen, so that a file system search is not needed for common modules.
gh-108614: Add RESUME_CHECK instruction, to avoid having to handle instrumentation, signals, and contexts switches in the tier 2 execution engine.
gh-108487: Move an assert that would cause a spurious crash in a devious case that should only trigger deoptimization.
gh-106176: Use a
WeakValueDictionaryto track the lists containing the modules each thread is currently importing. This helps avoid a reference leak from keeping the list around longer than necessary. Weakrefs are used as GC can’t interrupt the cleanup.gh-105481: The regen-opcode build stage was removed and its work is now done in regen-cases.
gh-107901: Fix missing line number on
JUMP_BACKWARDat the end of a for loop.gh-108113: The
compile()built-in can now accept a new flag,ast.PyCF_OPTIMIZED_AST, which is similar toast.PyCF_ONLY_ASTexcept that the returnedASTis optimized according to the value of theoptimizeargument.ast.parse()now accepts an optional argumentoptimizewhich is passed on to thecompile()built-in. This makes it possible to obtain an optimizedAST.gh-107971: Opcode IDs are generated from bytecodes.c instead of being hard coded in opcode.py.
gh-107944: Improve error message for function calls with bad keyword arguments. Patch by Pablo Galindo
gh-108390: Raise an exception when setting a non-local event (
RAISE,EXCEPTION_HANDLED, etc.) insys.monitoring.set_local_events.Fixes crash when tracing in recursive calls to Python classes.
gh-108035: Remove the
_PyCFramestruct, moving the pointer to the current interpreter frame back to the threadstate, as it was for 3.10 and earlier. The_PyCFrameexisted as a performance optimization for tracing. Since PEP 669 has been implemented, this optimization no longer applies.gh-91051: Fix abort / segfault when using all eight type watcher slots, on platforms where
charis signed by default.gh-106581: Fix possible assertion failures and missing instrumentation events when
PYTHONUOPSor-X uopsis enabled.gh-107526: Revert converting
vars,dir,next,getattr, anditerto argument clinic.gh-84805: Autogenerate signature for
METH_NOARGSandMETH_Oextension functions.gh-107758: Make the
dump_stack()routine used by thelltracefeature (low-level interpreter debugging) robust against recursion by ensuring that it never calls a__repr__method implemented in Python. Also make the similar output for Tier-2 uops appear onstdout(instead ofstderr), to match thelltracecode in ceval.c.gh-107659: Add docstrings for
ctypes.pointer()andctypes.POINTER().gh-105848: Modify the bytecode so that the actual callable for a
CALLis at a consistent position on the stack (regardless of whether or not bound-method-calling optimizations are active).gh-107674: Fixed performance regression in
sys.settrace.gh-107724: In pre-release versions of 3.12, up to rc1, the sys.monitoring callback function for the
PY_THROWevent was missing the third, exception argument. That is now fixed.gh-84436: Skip reference count modifications for many known immortal objects.
gh-107596: Specialize subscripting
strobjects byintindexes.gh-107080: Trace refs builds (
--with-trace-refs) were crashing when used with isolated subinterpreters. The problematic global state has been isolated to each interpreter. Other fixing the crashes, this change does not affect users.gh-107557: Generate the cases needed for the barebones tier 2 abstract interpreter for optimization passes in CPython.
gh-106608: Make
_PyUOpExecutorObjectvariable length.gh-100964: Clear generators’ exception state after
returnto break reference cycles.gh-107455: Improve error messages when converting an incompatible type to
ctypes.c_char_p,ctypes.c_wchar_pandctypes.c_void_p.gh-107263: Increase C recursion limit for functions other than the main interpreter from 800 to 1500. This should allow functions like
list.__repr__andjson.dumpsto handle all the inputs that they could prior to 3.12gh-104584: Fix an issue which caused incorrect inline caches to be read when running with
PYTHONUOPSor-X uopsenabled.gh-104432: Fix potential unaligned memory access on C APIs involving returned sequences of
char *pointers within thegrpandsocketmodules. These were revealed using a-fsaniziter=alignmentbuild on ARM macOS. Patch by Christopher Chavez.gh-106078: Isolate
_decimal(apply PEP 687). Patch by Charlie Zhao.gh-106898: Add the exception as the third argument to
PY_UNINDcallbacks insys.monitoring. This makes thePY_UNWINDcallback consistent with the other exception handling callbacks.gh-106895: Raise a
ValueErrorwhen a monitoring callback function returnsDISABLEfor events that cannot be disabled locally.gh-106897: Add a
RERAISEevent tosys.monitoring, which occurs when an exception is reraise, either explicitly by a plainraisestatement, or implicitly in anexceptorfinallyblock.gh-77377: Ensure that multiprocessing synchronization objects created in a fork context are not sent to a different process created in a spawn context. This changes a segfault into an actionable RuntimeError in the parent process.
gh-106931: Statically allocated string objects are now interned globally instead of per-interpreter. This fixes a situation where such a string would only be interned in a single interpreter. Normal string objects are unaffected.
gh-104621: Unsupported modules now always fail to be imported.
gh-107122: Add
dbm.ndbm.ndbm.clear()todbm.ndbm. Patch By Donghee Na.gh-107122: Add
dbm.gnu.gdbm.clear()todbm.gnu. Patch By Donghee Na.gh-107015: The ASYNC and AWAIT tokens are removed from the Grammar, which removes the possibility of making
asyncandawaitsoft keywords when usingfeature_version<7inast.parse().gh-106917: Fix classmethod-style
super()method calls (i.e., where the second argument tosuper(), or the implied second argument drawn fromself/clsin the case of zero-arg super, is a type) when the target of the call is not a classmethod.gh-105699: Python no longer crashes due an infrequent race when initializing per-interpreter interned strings. The crash would manifest when the interpreter was finalized.
gh-105699: Python no longer crashes due to an infrequent race in setting
Py_FileSystemDefaultEncodingandPy_FileSystemDefaultEncodeErrors(both deprecated), when simultaneously initializing two isolated subinterpreters. Now they are only set during runtime initialization.gh-106908: Fix various hangs, reference leaks, test failures, and tracing/introspection bugs when running with
PYTHONUOPSor-X uopsenabled.gh-106092: Fix a segmentation fault caused by a use-after-free bug in
frame_deallocwhen the trashcan delays the deallocation of aPyFrameObject.gh-106485: Reduce the number of materialized instances dictionaries by dematerializing them when possible.
gh-106719: No longer suppress arbitrary errors in the
__annotations__getter and setter in the type and module types.gh-106723: Propagate
frozen_modulesto multiprocessing spawned process interpreters.gh-104909: Split
LOAD_ATTR_INSTANCE_VALUEinto micro-ops.gh-104909: Split
LOAD_GLOBALspecializations into micro-ops.gh-106597: A new debug structure of offsets has been added to the
_PyRuntimeStatethat will help out-of-process debuggers and profilers to obtain the offsets to relevant interpreter structures in a way that is agnostic of how Python was compiled and that doesn’t require copying the headers. Patch by Pablo Galindogh-106487: Allow the count argument of
str.replace()to be a keyword. Patch by Hugo van Kemenade.gh-96844: Improve error message of
list.remove(). Patch by Donghee Na.gh-81283: Compiler now strips indents from docstrings. It reduces
pycfile size 5% when the module is heavily documented. This change affects to__doc__so tools like doctest will be affected.gh-106396: When the format specification of an f-string expression is empty, the parser now generates an empty
ast.JoinedStrnode for it instead of an one-elementast.JoinedStrwith an empty stringast.Constant.gh-100288: Specialize
LOAD_ATTRfor non-descriptors on the class. AddsLOAD_ATTR_NONDESCRIPTOR_WITH_VALUESandLOAD_ATTR_NONDESCRIPTOR_NO_DICT.gh-106008: Fix possible reference leaks when failing to optimize comparisons with
Nonein the bytecode compiler.gh-106145: Make
end_linenoandend_col_offsetrequired ontype_paramast nodes.gh-106213: Changed the way that Emscripten call trampolines work for compatibility with Wasm/JS Promise integration.
gh-106182:
sys.getfilesystemencoding()andsys.getfilesystemencodeerrorsnow return interned Unicode object.gh-106210: Removed Emscripten import trampoline as it was no longer necessary for Pyodide.
gh-104584: Added a new, experimental, tracing optimizer and interpreter (a.k.a. “tier 2”). This currently pessimizes, so don’t use yet – this is infrastructure so we can experiment with optimizing passes. To enable it, pass
-Xuopsor setPYTHONUOPS=1. To get debug output, setPYTHONUOPSDEBUG=NwhereNis a debug level (0-4, where 0 is no debug output and 4 is excessively verbose).gh-105775:
LOAD_CLOSUREis now a pseudo-op.gh-105730: Allow any callable other than type objects as the condition predicate in
BaseExceptionGroup.split()andBaseExceptionGroup.subgroup().gh-105979: Fix crash in
_imp.get_frozen_object()due to improper exception handling.gh-106003: Add a new
TO_BOOLinstruction, which performs boolean conversions forPOP_JUMP_IF_TRUE,POP_JUMP_IF_FALSE, andUNARY_NOT(which all expect exactboolvalues now). Also, modify the oparg ofCOMPARE_OPto include an optional “boolean conversion” flag.gh-98931: Ensure custom
SyntaxErrorerror messages are raised for invalid imports with multiple targets. Patch by Pablo Galindogh-105724: Improve
asserterror messages by providing exact error range.gh-105908: Fixed bug where gh-99111 breaks future import
barry_as_FLUFLin the Python REPL.gh-105840: Fix possible crashes when specializing function calls with too many
__defaults__.gh-105831: Fix an f-string bug, where using a debug expression (the
=sign) that appears in the last line of a file results to the debug buffer that holds the expression text being one character too small.gh-105800: Correctly issue
SyntaxWarningin f-strings if invalid sequences are used. Patch by Pablo Galindogh-105340: Include the comprehension iteration variable in
locals()inside a module- or class-scope comprehension.gh-105331: Raise
ValueErrorif thedelayargument toasyncio.sleep()is a NaN (matchingtime.sleep()).gh-105587: The runtime can’t guarantee that immortal objects will not be mutated by Extensions. Thus, this modifies _PyStaticObject_CheckRefcnt to warn instead of asserting.
gh-105564: Don’t include artificil newlines in the
lineattribute of tokens in the APIs of thetokenizemodule. Patch by Pablo Galindogh-105549: Tokenize separately
NUMBERandNAMEtokens that are not ambiguous. Patch by Pablo Galindo.gh-105588: Fix an issue that could result in crashes when compiling malformed
astnodes.gh-100987: Allow objects other than code objects as the “executable” in internal frames. In the long term, this can help tools like Cython and PySpy interact more efficiently. In the shorter term, it allows us to perform some optimizations more simply.
gh-105375: Fix bugs in the
builtinsmodule where exceptions could end up being overwritten.gh-105375: Fix bug in the compiler where an exception could end up being overwritten.
gh-105375: Improve error handling in
PyUnicode_BuildEncodingMap()where an exception could end up being overwritten.gh-105486: Change the repr of
ParamSpeclist of args intypes.GenericAlias.gh-105678: Break the
MAKE_FUNCTIONinstruction into two parts,MAKE_FUNCTIONwhich makes the function andSET_FUNCTION_ATTRIBUTEwhich sets the attributes on the function. This makes the stack effect ofMAKE_FUNCTIONregular to ease optimization and code generation.gh-105435: Fix spurious newline character if file ends on a comment without a newline. Patch by Pablo Galindo
gh-105390: Correctly raise
tokenize.TokenErrorexceptions instead ofSyntaxErrorfor tokenize errors such as incomplete input. Patch by Pablo Galindogh-105259: Don’t include newline character for trailing
NEWLINEtokens emitted in thetokenizemodule. Patch by Pablo Galindogh-104635: Eliminate redundant
STORE_FASTinstructions in the compiler. Patch by Donghee Na and Carl Meyer.gh-105324: Fix the main function of the
tokenizemodule when reading fromsys.stdin. Patch by Pablo Galindogh-33092: Simplify and speed up interpreter for f-strings. Removes
FORMAT_VALUEopcode. AddCONVERT_VALUE,FORMAT_SIMPLEandFORMAT_WITH_SPECopcode. Compiler emits more efficient sequence for each format expression.gh-105229: Remove remaining two-codeunit superinstructions. All remaining superinstructions only take a single codeunit, simplifying instrumentation and quickening.
gh-105235: Prevent out-of-bounds memory access during
mmap.find()calls.gh-98963: Restore the ability for a subclass of
propertyto define__slots__or otherwise be dict-less by ignoring failures to set a docstring on such a class. This behavior had regressed in 3.12beta1. AnAttributeErrorwhere there had not previously been one was disruptive to existing code.gh-104812: The “pending call” machinery now works for all interpreters, not just the main interpreter, and runs in all threads, not just the main thread. Some calls are still only done in the main thread, ergo in the main interpreter. This change does not affect signal handling nor the existing public C-API (
Py_AddPendingCall()), which both still only target the main thread. The new functionality is meant strictly for internal use for now, since consequences of its use are not well understood yet outside some very restricted cases. This change brings the capability in line with the intention when the state was made per-interpreter several years ago.gh-105194: Do not escape with backslashes f-string format specifiers. Patch by Pablo Galindo
gh-105229: Replace some dynamic superinstructions with single instruction equivalents.
gh-105162: Fixed bug in generator.close()/throw() where an inner iterator would be ignored when the outer iterator was instrumented.
gh-105164: Ensure annotations are set up correctly if the only annotation in a block is within a
matchblock. Patch by Jelle Zijlstra.gh-105148: Make
_PyASTOptimizeStateinternal to ast_opt.c. Make_PyAST_Optimizetake two integers instead of a pointer to this struct. This avoids the need to include pycore_compile.h in ast_opt.c.gh-104799: Attributes of
astnodes that are lists now default to the empty list if omitted. This means that some code that previously raisedTypeErrorwhen the AST node was used will now proceed with the empty list instead. Patch by Jelle Zijlstra.gh-105111: Remove the old trashcan macros
Py_TRASHCAN_SAFE_BEGINandPy_TRASHCAN_SAFE_END. They should be replaced by the new macrosPy_TRASHCAN_BEGINandPy_TRASHCAN_END.gh-105035: Fix
super()calls on types with customtp_getattroimplementation (e.g. meta-types.)gh-105017: Show CRLF lines in the tokenize string attribute in both NL and NEWLINE tokens. Patch by Marta Gómez.
gh-105013: Fix handling of multiline parenthesized lambdas in
inspect.getsource(). Patch by Pablo Galindogh-105017: Do not include an additional final
NLtoken when parsing files having CRLF lines. Patch by Marta Gómez.gh-104976: Ensure that trailing
DEDENTtokenize.TokenInfoobjects emitted by thetokenizemodule are reported as in Python 3.11. Patch by Pablo Galindogh-104972: Ensure that the
lineattribute intokenize.TokenInfoobjects in thetokenizemodule are always correct. Patch by Pablo Galindogh-104955: Fix signature for the new
__release_buffer__()slot. Patch by Jelle Zijlstra.gh-104690: Starting new threads and process creation through
os.fork()during interpreter shutdown (such as fromatexithandlers) is no longer supported. It can lead to race condition between the main Python runtime thread freeing thread states while internalthreadingroutines are trying to allocate and use the state of just created threads. Or forked children trying to use the mid-shutdown runtime and thread state in the child process.gh-104879: Fix crash when accessing the
__module__attribute of type aliases defined outside a module. Patch by Jelle Zijlstra.gh-104825: Tokens emitted by the
tokenizemodule do not include an implicit\ncharacter in thelineattribute anymore. Patch by Pablo Galindogh-104770: If a generator returns a value upon being closed, the value is now returned by
generator.close().gh-89091: Raise
RuntimeWarningfor unawaited async generator methods likeasend(),athrow()andaclose(). Patch by Kumar Aditya.gh-96663: Add a better, more introspect-able error message when setting attributes on classes without a
__dict__and no slot member for the attribute.gh-93627: Update the Python pickle module implementation to match the C implementation of the pickle module. For objects setting reduction methods like
__reduce_ex__()or__reduce__()toNone, pickling will result in aTypeError.gh-91095: Specializes calls to most Python classes. Specifically, any class that inherits from
object, or another Python class, and does not override__new__.The specialized instruction does the following:
Creates the object (by calling
object.__new__)Pushes a shim frame to the frame stack (to cleanup after
__init__)Pushes the frame for
__init__to the frame stack
Speeds up the instantiation of most Python classes.
Library¶
gh-110786:
sysconfig’s CLI now ignoresBrokenPipeError, making it exit normally if its output is being piped and the pipe closes.gh-103480: The
sysconfigmodule is now a package, instead of a single-file module.gh-110733: Micro-optimization: Avoid calling
min(),max()inBaseEventLoop._run_once().gh-94597: Added
asyncio.EventLoopfor use with theasyncio.run()loop_factory kwarg to avoid calling the asyncio policy system.gh-110682:
runtime-checkable protocolsused to consider__match_args__a protocol member in__instancecheck__if it was present on the protocol. Now, this attribute is ignored if it is present.gh-110488: Fix a couple of issues in
pathlib.PurePath.with_name(): a single dot was incorrectly considered a valid name, and inPureWindowsPath, a name with an NTFS alternate data stream, likea:b, was incorrectly considered invalid.gh-110590: Fix a bug in
_sre.compile()whereTypeErrorwould be overwritten byOverflowErrorwhen the code argument was a list of non-ints.gh-65052: Prevent
pdbfrom crashing when trying to display undisplayable objectsgh-110519: Deprecation warning about non-integer number in
gettextnow always refers to the line in the user code where gettext function or method is used. Previously it could refer to a line ingettextcode.gh-89902: Deprecate non-standard format specifier “N” for
decimal.Decimal. It was not documented and only supported in the C implementation.gh-110378:
contextmanager()andasynccontextmanager()context managers now close an invalid underlying generator object that yields more then one value.gh-106670: In
pdb, set convenience variable$_exceptionfor post mortem debugging.gh-110365: Fix
termios.tcsetattr()bug that was overwriting existing errors during parsing integers fromtermlist.gh-109653: Slightly improve the import time of several standard-library modules by deferring imports of
warningswithin those modules. Patch by Alex Waygood.gh-110273:
dataclasses.replace()now raises TypeError instead of ValueError if specify keyword argument for a field declared with init=False or miss keyword argument for required InitVar field.gh-110249: Add
--inline-cachesflag todiscommand line.gh-109653: Fix a Python 3.12 regression in the import time of
random. Patch by Alex Waygood.gh-110222: Add support of struct sequence objects in
copy.replace(). Patched by Xuehai Pan.gh-109649:
multiprocessing,concurrent.futures,compileall: Replaceos.cpu_count()withos.process_cpu_count()to select the default number of worker threads and processes. Get the CPU affinity if supported. Patch by Victor Stinner.gh-110150: Fix base case handling in statistics.quantiles. Now allows a single data point.
gh-110036: On Windows, multiprocessing
Popen.terminate()now catchesPermissionErrorand get the process exit code. If the process is still running, raise again thePermissionError. Otherwise, the process terminated as expected: store its exit code. Patch by Victor Stinner.gh-110038: Fixed an issue that caused
KqueueSelector.select()to not return all the ready events in some cases when a file descriptor is registered for both read and write.gh-110045: Update the
symtablemodule to support the new scopes introduced by PEP 695.gh-88402: Add new variables to
sysconfig.get_config_vars()on Windows:LIBRARY,LDLIBRARY,LIBDIR,SOABI, andPy_NOGIL.gh-109631:
refunctions such asre.findall(),re.split(),re.search()andre.sub()which perform short repeated matches can now be interrupted by user.gh-109653: Reduce the import time of
email.utilsby around 43%. This results in the import time ofemail.messagefalling by around 18%, which in turn reduces the import time ofimportlib.metadataby around 6%. Patch by Alex Waygood.gh-109818: Fix
reprlib.recursive_repr()not copying__type_params__from decorated function.gh-109047:
concurrent.futures: The executor manager thread now catches exceptions when adding an item to the call queue. During Python finalization, creating a new thread can now raiseRuntimeError. Catch the exception and callterminate_broken()in this case. Patch by Victor Stinner.gh-109782: Ensure the signature of
os.path.isdir()is identical on all platforms. Patch by Amin Alaee.gh-109653: Improve import time of
functoolsby around 13%. Patch by Alex Waygood.gh-109590:
shutil.which()will prefer files with an extension inPATHEXTif the given mode includesos.X_OKon win32. If noPATHEXTmatch is found, a file without an extension inPATHEXTcan be returned. This change will haveshutil.which()act more similarly to previous behavior in Python 3.11.gh-109653: Reduce the import time of
enumby over 50%. Patch by Alex Waygood.gh-109593: Avoid deadlocking on a reentrant call to the multiprocessing resource tracker. Such a reentrant call, though unlikely, can happen if a GC pass invokes the finalizer for a multiprocessing object such as SemLock.
gh-109653: Reduce the import time of
typingby around a third. Patch by Alex Waygood.gh-109649: Add
os.process_cpu_count()function to get the number of logical CPUs usable by the calling thread of the current process. Patch by Victor Stinner.gh-74481: Add
set_error_moderelated constants inmsvcrtmodule in Python debug build.gh-109613: Fix
os.stat()andos.DirEntry.stat(): check for exceptions. Previously, on Python built in debug mode, these functions could trigger a fatal Python error (and abort the process) when a function succeeded with an exception set. Patch by Victor Stinner.gh-109599: Expose the type of PyCapsule objects as
types.CapsuleType.gh-109109: You can now get the raw TLS certificate chains from TLS connections via
ssl.SSLSocket.get_verified_chain()andssl.SSLSocket.get_unverified_chain()methods.Contributed by Mateusz Nowak.
gh-109559: Update
unicodedatadatabase to Unicode 15.1.0.gh-109543: Remove unnecessary
hasattr()check duringtyping.TypedDictcreation.gh-109495: Remove unnecessary extra
__slots__indatetime's pure python implementation to reduce memory size, as they are defined in the superclass. Patch by James Hilton-Balfegh-109461:
logging: Use a context manager for lock acquisition.gh-109096:
http.server.CGIHTTPRequestHandlerhas been deprecated for removal in 3.15. Its design is old and the web world has long since moved beyond CGI.gh-109409: Fix error when it was possible to inherit a frozen dataclass from multiple parents some of which were possibly not frozen.
gh-109375: The
pdbaliascommand now prevents registering aliases without arguments.gh-109319: Deprecate the
dis.HAVE_ARGUMENTfield in favour ofdis.hasarg.gh-107219: Fix a race condition in
concurrent.futures. When a process in the process pool was terminated abruptly (while the future was running or pending), close the connection write end. If the call queue is blocked on sending bytes to a worker process, closing the connection write end interrupts the send, so the queue can be closed. Patch by Victor Stinner.gh-66143: The
codecs.CodecInfoobject has been made copyable and pickleable. Patched by Robert Lehmann and Furkan Onder.gh-109187:
pathlib.Path.resolve()now treats symlink loops like other errors: in strict mode,OSErroris raised, and in non-strict mode, no exception is raised.gh-50644: Attempts to pickle or create a shallow or deep copy of
codecsstreams now raise a TypeError. Previously, copying failed with a RecursionError, while pickling produced wrong results that eventually caused unpickling to fail with a RecursionError.gh-109174: Add support of
types.SimpleNamespaceincopy.replace().gh-109164:
pdb: Replacegetoptwithargparsefor parsing command line arguments.gh-109151: Enable
readlineediting features in the sqlite3 command-line interface (python -m sqlite3).gh-108987: Fix
_thread.start_new_thread()race condition. If a thread is created during Python finalization, the newly spawned thread now exits immediately instead of trying to access freed memory and lead to a crash. Patch by Victor Stinner.gh-108682: Enum: require
names=()ortype=...to create an empty enum using the functional syntax.gh-109033: Exceptions raised by os.utime builtin function now include the related filename
gh-108843: Fix an issue in
ast.unparse()when unparsing f-strings containing many quote types.gh-108469:
ast.unparse()now supports new f-string syntax introduced in Python 3.12. Note that the f-string quotes are reselected for simplicity under the new syntax. (Patch by Steven Sun)gh-108751: Add
copy.replace()function which allows to create a modified copy of an object. It supports named tuples, dataclasses, and many other objects.gh-108682: Enum: raise
TypeErrorifsuper().__new__()is called from a custom__new__.gh-108278: Deprecate passing the callback callable by keyword for the following
sqlite3.ConnectionAPIs:The affected parameters will become positional-only in Python 3.15.
Patch by Erlend E. Aasland.
gh-105829: Fix concurrent.futures.ProcessPoolExecutor deadlock
gh-108295: Fix crashes related to use of weakrefs on
typing.TypeVar.gh-108463: Make expressions/statements work as expected in pdb
gh-108277: Add
os.timerfd_create(),os.timerfd_settime(),os.timerfd_gettime(),os.timerfd_settime_ns(), andos.timerfd_gettime_ns()to provide a low level interface for Linux’s timer notification file descriptor.gh-107811:
tarfile: extraction of members with overly large UID or GID (e.g. on an OS with 32-bitid_t) now fails in the same way as failing to set the ID.gh-64662: Fix support for virtual tables in
sqlite3.Connection.iterdump(). Patch by Aviv Palivoda.gh-108111: Fix a regression introduced in gh-101251 for 3.12, resulting in an incorrect offset calculation in
gzip.GzipFile.seek().gh-108294:
time.sleep()now raises an auditing event.gh-108278: Deprecate passing name, number of arguments, and the callable as keyword arguments, for the following
sqlite3.ConnectionAPIs:The affected parameters will become positional-only in Python 3.15.
Patch by Erlend E. Aasland.
gh-108322: Speed-up NormalDist.samples() by using the inverse CDF method instead of calling random.gauss().
gh-83417: Add the ability for venv to create a
.gitignorefile which causes the created environment to be ignored by Git. It is on by default when venv is called via its CLI.gh-105736: Harmonized the pure Python version of
OrderedDictwith the C version. Now, both versions set up their internal state in__new__. Formerly, the pure Python version did the set up in__init__.gh-108083: Fix bugs in the constructor of
sqlite3.Connectionandsqlite3.Connection.close()where exceptions could be leaked. Patch by Erlend E. Aasland.gh-107932: Fix
dismodule to properly report and display bytecode that do not have source lines.gh-105539:
sqlite3now emits anResourceWarningif asqlite3.Connectionobject is notclosedexplicitly. Patch by Erlend E. Aasland.gh-107995: The
__module__attribute on instances offunctools.cached_propertyis now set to the name of the module in which the cached_property is defined, rather than “functools”. This means that doctests incached_propertydocstrings are now properly collected by thedoctestmodule. Patch by Tyler Smart.gh-107963: Fix
multiprocessing.set_forkserver_preload()to check the given list of modules names. Patch by Donghee Na.gh-106242: Fixes
os.path.normpath()to handle embedded null characters without truncating the path.gh-81555:
xml.dom.minidomnow only quotes"in attributes.gh-50002:
xml.dom.minidomnow preserves whitespaces in attributes.gh-93057: Passing more than one positional argument to
sqlite3.connect()and thesqlite3.Connectionconstructor is deprecated. The remaining parameters will become keyword-only in Python 3.15. Patch by Erlend E. Aasland.gh-76913: Add merge_extra parameter/feature to
logging.LoggerAdaptergh-107913: Fix possible losses of
errnoandwinerrorvalues inOSErrorexceptions if they were cleared or modified by the cleanup code before creating the exception object.gh-107845:
tarfile.data_filter()now takes the location of symlinks into account when determining their target, so it will no longer reject some valid tarballs withLinkOutsideDestinationError.gh-107812: Extend socket’s netlink support to the FreeBSD platform.
gh-107805: Fix signatures of module-level generated functions in
turtle.gh-107782:
pydocis now able to show signatures which are not representable in Python, e.g. forgetattranddict.pop.gh-56166: Deprecate passing optional arguments maxsplit, count and flags in module-level functions
re.split(),re.sub()andre.subn()as positional. They should only be passed by keyword.gh-107710: Speed up
logging.getHandlerNames().gh-107715: Fix
doctest.DocTestFinder.find()in presence of class names with special characters. Patch by Gertjan van Zwieten.gh-100814: Passing a callable object as an option value to a Tkinter image now raises the expected TclError instead of an AttributeError.
gh-72684: Add
tkinterwidget methods:tk_busy_hold(),tk_busy_configure(),tk_busy_cget(),tk_busy_forget(),tk_busy_current(), andtk_busy_status().gh-106684: Raise
ResourceWarningwhenasyncio.StreamWriteris not closed leading to memory leaks. Patch by Kumar Aditya.gh-107465: Add
pathlib.Path.from_uri()classmethod.gh-107077: Seems that in some conditions, OpenSSL will return
SSL_ERROR_SYSCALLinstead ofSSL_ERROR_SSLwhen a certification verification has failed, but the error parameters will still containERR_LIB_SSLandSSL_R_CERTIFICATE_VERIFY_FAILED. We are now detecting this situation and raising the appropriatessl.SSLCertVerificationError. Patch by Pablo Galindogh-107576: Fix
types.get_original_bases()to only return__orig_bases__if it is present onclsdirectly. Patch by James Hilton-Balfe.gh-105481: Remove
opcode.is_pseudo,opcode.MIN_PSEUDO_OPCODEandopcode.MAX_PSEUDO_OPCODE, which were added in 3.12, were never documented and were not intended to be used externally.gh-105481:
opcode.ENABLE_SPECIALIZATION(which was added in 3.12 but never documented or intended for external usage) is moved to_opcode.ENABLE_SPECIALIZATIONwhere tests can access it.gh-107396: tarfiles; Fixed use before assignment of self.exception for gzip decompression
gh-107409: Set
__wrapped__attribute inreprlib.recursive_repr().gh-107406: Implement new
__repr__()method forstruct.Struct. Now it returnsStruct(<format repr>).gh-107369: Optimize
textwrap.indent(). It is ~30% faster for large input. Patch by Inada Naoki.gh-78722: Fix issue where
pathlib.Path.iterdir()did not raiseOSErroruntil iterated.gh-105578: Deprecate
typing.AnyStrin favor of the new Type Parameter syntax. See PEP 695.gh-62519: Make
gettext.pgettext()search plural definitions when translation is not found.gh-107089: Shelves opened with
shelve.open()have a much fasterclear()method. Patch by James Cave.gh-82500: Fix overflow on 32-bit systems with
asyncioos.sendfile()implementation.gh-83006: Document behavior of
shutil.disk_usage()for non-mounted filesystems on Unix.gh-65495: Use lowercase
mail fromandrcpt toinsmptlib.SMTP.gh-106186: Do not report
MultipartInvariantViolationDefectdefect when theemail.parser.Parserclass is used to parse emails withheadersonly=True.gh-105002: Fix invalid result from
PurePath.relative_to()method when attempting to walk a “..” segment in other with walk_up enabled. AValueErrorexception is now raised in this case.gh-106739: Add the
rtype_cacheto the warning message (as an addition to the type of leaked objects and the number of leaked objects already included in the message) to make debugging leaked objects easier when the multiprocessing resource tracker process finds leaked objects at shutdown. This helps more quickly identify what was leaked and/or why the leaked object was not properly cleaned up.gh-106751: Optimize
SelectSelector.select()for many iteration case. Patch By Donghee Na.gh-106751: Optimize
_PollLikeSelector.select()for many iteration case.gh-106751: Optimize
KqueueSelector.select()for many iteration case. Patch By Donghee Na.gh-106831: Fix potential missing
NULLcheck ofd2i_SSL_SESSIONresult in_ssl.c.gh-105481: The various opcode lists in the
dismodule are now generated from bytecodes.c instead of explicitly constructed in opcode.py.gh-106727: Make
inspect.getsource()smarter for class for same name definitionsgh-105726: Added
__slots__tocontextlib.AbstractContextManagerandcontextlib.AbstractAsyncContextManagerso that child classes can use__slots__.gh-106774: Update the bundled copy of pip to version 23.2.1.
gh-106751:
selectors: OptimizeEpollSelector.select()code by moving some code outside of the loop.gh-106752: Fixed several bugs in zipfile.Path, including: in
zipfile.Path.match(), Windows separators are no longer honored (and never were meant to be); Fixedname/suffix/suffixes/stemoperations when no filename is present and the Path is not at the root of the zipfile; Reworked glob for performance and more correct matching behavior.gh-105293: Remove call to
SSL_CTX_set_session_id_contextduring client side context creation in thesslmodule.gh-105481: Expose opcode metadata through
_opcode.gh-106670: Add the new
exceptionscommand to the Pdb debugger. It makes it possible to move between chained exceptions when using post mortem debugging.gh-106664:
selectors: Add_SelectorMapping.get()method and optimize_SelectorMapping.__getitem__().gh-106628: Speed up parsing of emails by about 20% by not compiling a new regular expression for every single email.
gh-89427: Set the environment variable
VIRTUAL_ENV_PROMPTatvenvactivation, even whenVIRTUAL_ENV_DISABLE_PROMPTis set.gh-106530: Revert a change to
colorsys.rgb_to_hls()that caused division by zero for certain almost-white inputs. Patch by Terry Jan Reedy.gh-106584: Fix exit code for
unittestif all tests are skipped. Patch by Egor Eliseev.gh-106566: Optimize
(?!)(pattern which always fails) in regular expressions.gh-106554:
selectors: Reduce Selector overhead by using adict.get()to lookup file descriptors.gh-106558: Remove ref cycle in callers of
convert_to_error()by deletingresultfrom scope in afinallyblock.gh-100502: Add
pathlib.PurePath.pathmodclass attribute that stores the implementation ofos.pathused for low-level path operations: eitherposixpathorntpath.gh-106527: Reduce overhead to add and remove
asyncioreaders and writers.gh-106524: Fix crash in
_sre.template()with templates containing invalid group indices.gh-106531: Removed
_legacyand the names it provided fromimportlib.resources:Resource,contents,is_resource,open_binary,open_text,path,read_binary, andread_text.gh-106052:
remodule: fix the matching of possessive quantifiers in the case of a subpattern containing backtracking.gh-106510: Improve debug output for atomic groups in regular expressions.
gh-106503: Fix ref cycle in
asyncio._SelectorSocketTransportby removing_write_readyinclose.gh-105497: Fix flag mask inversion when unnamed flags exist.
gh-90876: Prevent
multiprocessing.spawnfrom failing to import in environments wheresys.executableisNone. This regressed in 3.11 with the addition of support for path-like objects in multiprocessing.gh-106403: Instances of
typing.TypeVar,typing.ParamSpec,typing.ParamSpecArgs,typing.ParamSpecKwargs, andtyping.TypeVarTupleonce again support weak references, fixing a regression introduced in Python 3.12.0 beta 1. Patch by Jelle Zijlstra.gh-89812: Add private
pathlib._PathBaseclass, which provides experimental support for virtual filesystems, and may be made public in a future version of Python.gh-106292: Check for an instance-dict cached value in the
__get__()method offunctools.cached_property(). This better matches the pre-3.12 behavior and improves compatibility for users subclassingfunctools.cached_property()and adding a__set__()method.gh-106350: Detect possible memory allocation failure in the libtommath function
mp_init()used by the_tkintermodule.gh-106330: Fix incorrect matching of empty paths in
pathlib.PurePath.match(). This bug was introduced in Python 3.12.0 beta 1.gh-106309: Deprecate
typing.no_type_check_decorator(). No major type checker ever added support for this decorator. Patch by Alex Waygood.gh-102541: Make
pydoc.doc()catch bad moduleImportErrorwhen output stream is notNone.gh-106263: Fix crash when calling
reprwith a manually constructed SignalDict object. Patch by Charlie Zhao.gh-106236: Replace
assertstatements withraise RuntimeErrorinthreading, so that_DummyThreadcannot be joined even with-OO.gh-106238: Fix rare concurrency bug in lock acquisition by the logging package.
gh-106152: Added PY_THROW event hook for
cProfilefor generatorsgh-106075: Added
asyncio.taskgroups.__all__toasyncio.__all__for export in star imports.gh-104527: Zipapp will now skip over appending an archive to itself.
gh-106046: Improve the error message from
os.fspath()if called on an object where__fspath__is set toNone. Patch by Alex Waygood.gh-105987: Fix crash due to improper reference counting in
asyncioeager task factory internal routines.gh-105974: Fix bug where a
typing.Protocolclass that had one or more non-callable members would raiseTypeErrorwhenissubclass()was called against it, even if it defined a custom__subclasshook__method. The behaviour in Python 3.11 and lower – which has now been restored – was not to raiseTypeErrorin these situations if a custom__subclasshook__method was defined. Patch by Alex Waygood.gh-96145: Reverted addition of
json.AttrDict.gh-89812: Add
pathlib.UnsupportedOperation, which is raised instead ofNotImplementedErrorwhen a path operation isn’t supported.gh-105808: Fix a regression introduced in gh-101251 for 3.12, causing
gzip.GzipFile.flush()to not flush the compressor (nor pass along thezip_modeargument).gh-105481:
stack_effect()no longer raises an exception if anopargis provided for anopcodethat doesn’t use its arg, or when it is not provided for anopcodethat does use it. In the latter case, the stack effect is returned foroparg=0.gh-104799: Enable
ast.unparse()to unparse function and class definitions created without the newtype_paramsfield from PEP 695. Patch by Jelle Zijlstra.gh-105793: Add follow_symlinks keyword-only argument to
pathlib.Path.is_dir()andis_file(), defaulting toTrue.gh-105570: Deprecate two methods of creating
typing.TypedDictclasses with 0 fields using the functional syntax:TD = TypedDict("TD")andTD = TypedDict("TD", None). Both will be disallowed in Python 3.15. To create aTypedDictclass with 0 fields, either useclass TD(TypedDict): passorTD = TypedDict("TD", {}).gh-105745: Fix
webbrowser.Konqueror.openmethod.gh-105733:
ctypes: Deprecate undocumentedctypes.SetPointerType()andctypes.ARRAY()functions. Patch by Victor Stinner.gh-105687: Remove deprecated
re.template,re.T,re.TEMPLATE,sre_constans.SRE_FLAG_TEMPLATE.gh-105684: Supporting
asyncio.Task.set_name()is now mandatory for third party task implementations. The undocumented_set_task_name()function (deprecated since 3.8) has been removed. Patch by Kumar Aditya.gh-105375: Fix a bug in
_Unpickler_SetInputStream()where an exception could end up being overwritten in case of failure.gh-105626: Change the default return value of
http.client.HTTPConnection.get_proxy_response_headers()to beNoneand not{}.gh-105375: Fix bugs in
syswhere exceptions could end up being overwritten because of deferred error handling.gh-105605: Harden
pyexpaterror handling during module initialisation to prevent exceptions from possibly being overwritten, and objects from being dereferenced twice.gh-105375: Fix bug in
decimalwhere an exception could end up being overwritten.gh-105375: Fix bugs in
_datetimewhere exceptions could be overwritten in case of module initialisation failure.gh-105375: Fix bugs in
_sslinitialisation which could lead to leaked references and overwritten exceptions.gh-105375: Fix a bug in
array.arraywhere an exception could end up being overwritten.gh-105375: Fix bugs in
_ctypeswhere exceptions could end up being overwritten.gh-105375: Fix a bug in the
posixmodule where an exception could be overwritten.gh-105375: Fix bugs in
_elementtreewhere exceptions could be overwritten.gh-105375: Fix bugs in
zoneinfowhere exceptions could be overwritten.gh-105375: Fix bugs in
errnowhere exceptions could be overwritten.gh-105566: Deprecate creating a
typing.NamedTupleclass using keyword arguments to denote the fields (NT = NamedTuple("NT", x=int, y=str)). This will be disallowed in Python 3.15. Use the class-based syntax or the functional syntax instead.Two methods of creating
NamedTupleclasses with 0 fields using the functional syntax are also deprecated, and will be disallowed in Python 3.15:NT = NamedTuple("NT")andNT = NamedTuple("NT", None). To create aNamedTupleclass with 0 fields, either useclass NT(NamedTuple): passorNT = NamedTuple("NT", []).gh-105545: Remove deprecated in 3.11
webbrowser.MacOSXOSAScript._nameattribute.gh-105497: Fix flag inversion when alias/mask members exist.
gh-105509:
typing.Annotatedis now implemented as an instance oftyping._SpecialFormrather than a class. This should have no user-facing impact for users of thetypingmodule public API.gh-105375: Fix bugs in
picklewhere exceptions could be overwritten.gh-70303: Emit
FutureWarningfrompathlib.Path.glob()andrglob()if the given pattern ends with “**”. In a future Python release, patterns with this ending will match both files and directories. Add a trailing slash to only match directories.gh-105375: Fix a bug in
sqlite3where an exception could be overwritten in thecollationcallback.gh-105382: Remove cafile, capath and cadefault parameters of the
urllib.request.urlopen()function, deprecated in Python 3.6. Patch by Victor Stinner.gh-105376:
logging: Remove undocumented and untestedLogger.warn()andLoggerAdapter.warn()methods andlogging.warn()function. Deprecated since Python 3.3, they were aliases to thelogging.Logger.warning()method,logging.LoggerAdapter.warning()method andlogging.warning()function. Patch by Victor Stinner.gh-105332: Revert pickling method from by-name back to by-value.
gh-104554: Add RTSPS scheme support in urllib.parse
gh-105292: Add option to
traceback.format_exception_only()to recurse into the nested exception of aBaseExceptionGroup.gh-105280: Fix bug where
isinstance([], collections.abc.Mapping)could evaluate toTrueif garbage collection happened at the wrong time. The bug was caused by changes to the implementation oftyping.Protocolin Python 3.12.gh-105239: Fix longstanding bug where
issubclass(object, typing.Protocol)would evaluate toTruein some edge cases. Patch by Alex Waygood.gh-104310: In the beta 1 release we added a utility function for extension module authors, to use when testing their module for support in multiple interpreters or under a per-interpreter GIL. The name of that function has changed from
allowing_all_extensionsto_incompatible_extension_module_restrictions. The default for the “disable_check” argument has change fromTruetoFalse, to better match the new function name.gh-105080: Fixed inconsistent signature on derived classes for
inspect.signature()gh-105144: Fix a recent regression in the
typingmodule. The regression meant that doingclass Foo(X, typing.Protocol), whereXwas a class that hadabc.ABCMetaas its metaclass, would then cause subsequentisinstance(1, X)calls to erroneously raiseTypeError. Patch by Alex Waygood.gh-62948: The
io.IOBasefinalizer now logs theclose()method errors withsys.unraisablehook. Previously, errors were ignored silently by default, and only logged in Python Development Mode or on Python built on debug mode. Patch by Victor Stinner.gh-105096:
wave: Deprecate thegetmark(),setmark()andgetmarkers()methods of thewave.Wave_readandwave.Wave_writeclasses. They will be removed in Python 3.15. Patch by Victor Stinner.gh-104992: Remove the untested and undocumented
unittest.TestProgram.usageExit()method, deprecated in Python 3.11. Patch by Hugo van Kemenade.gh-104996: Improve performance of
pathlib.PurePathinitialisation by deferring joining of paths when multiple arguments are given.gh-101588: Deprecate undocumented copy/deepcopy/pickle support for itertools.
gh-103631: Fix
pathlib.PurePosixPath(pathlib.PureWindowsPath(...))not converting path separators to restore 3.11 compatible behavior.gh-104947: Make comparisons between
pathlib.PureWindowsPathobjects consistent across Windows and Posix to match 3.11 behavior.gh-104773: PEP 594: Remove the
audioopmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
aifcmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
uumodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104935: Fix bugs with the interaction between
typing.runtime_checkable()andtyping.Genericthat were introduced by the PEP 695 implementation. Patch by Jelle Zijlstra.gh-104773: PEP 594: Remove the
cryptmodule and its private_cryptextension, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
nismodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104898: Add missing
__slots__toos.PathLike.gh-104773: PEP 594: Remove the
xdrlibmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
nntplibmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104886: Remove the undocumented
configparser.LegacyInterpolationclass, deprecated in the docstring since Python 3.2, and with a deprecation warning since Python 3.11. Patch by Hugo van Kemenade.gh-104786: Remove kwargs-based
typing.TypedDictcreationgh-104876: Remove the
turtle.RawTurtle.settiltangle()method, deprecated in docs since Python 3.1 and with a deprecation warning since Python 3.11. Patch by Hugo van Kemenade.gh-104773: PEP 594: Removed the
msilibpackage, deprecated in Python 3.11.gh-104773: PEP 594: Remove the
spwdmodule, deprecated in Python 3.11: the python-pam project can be used instead. Patch by Victor Stinner.gh-75552: Removed the
tkinter.tixmodule, deprecated since Python 3.6.gh-104773: PEP 594: Remove the
chunkmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
mailcapmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
sunaumodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104780: PEP 594: Remove the
ossaudiodevmodule, deprecated in Python 3.11. Patch Victor Stinner.gh-104773: PEP 594: Remove the
pipesmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104873: Add
typing.get_protocol_members()to return the set of members defining atyping.Protocol. Addtyping.is_protocol()to check whether a class is atyping.Protocol. Patch by Jelle Zijlstra.gh-104874: Document the
__name__and__supertype__attributes oftyping.NewType. Patch by Jelle Zijlstra.gh-104835: Removed the following
unittestfunctions, deprecated in Python 3.11:unittest.findTestCases()unittest.makeSuite()unittest.getTestCaseNames()
Use
TestLoadermethods instead:Patch by Hugo van Kemenade.
gh-104804: Remove the untested and undocumented
webbrowserMacOSXclass, deprecated in Python 3.11. Patch by Hugo van Kemenade.gh-83863: Support for using
pathlib.Pathobjects as context managers has been removed. Before Python 3.9, exiting the context manager marked a path as “closed”, which caused some (but not all!) methods to raise when called. Since Python 3.9, using a path as a context manager does nothing.gh-104799: Adjust the location of the (see PEP 695)
type_paramsfield onast.ClassDef,ast.AsyncFunctionDef, andast.FunctionDefto better preserve backward compatibility. Patch by Jelle Zijlstragh-104797: Allow
typing.Protocolclasses to inherit fromcollections.abc.Buffer. Patch by Jelle Zijlstra.gh-104783: Remove
locale.resetlocale()function deprecated in Python 3.11. Patch by Victor Stinner.gh-104780: Remove the
2to3program and thelib2to3module, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
telnetlibmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
imghdrmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
cgiandcgitbmodules, deprecated in Python 3.11. Patch by Victor Stinner.gh-104773: PEP 594: Remove the
sndhdrmodule, deprecated in Python 3.11. Patch by Victor Stinner.gh-104372: On Linux where
subprocesscan use thevfork()syscall for faster spawning, prevent the parent process from blocking other threads by dropping the GIL while it waits for the vfork’ed child processexec()outcome. This prevents spawning a binary from a slow filesystem from blocking the rest of the application.gh-99108: We now release the GIL around built-in
hashlibcomputations of reasonable size for the SHA families and MD5 hash functions, matching what our OpenSSL backed hash computations already does.gh-102613: Improve performance of
pathlib.Path.glob()when expanding a pattern with a non-terminal “**” component by filtering walked paths through a regular expression, rather than callingos.scandir()more than once on each directory.gh-104399: Prepare the
_tkintermodule for building with Tcl 9.0 and future libtommath by replacing usage of deprecated functionsmp_to_unsigned_bin_n()andmp_unsigned_bin_size()when necessary.gh-102676: Add fields
start_offset,cache_offset,end_offset,baseopname,baseopcode,jump_targetandopargtodis.Instruction.gh-103558: Fixed
parentargument validation mechanism ofargparse. Improved test coverage.gh-103464: Provide helpful usage messages when parsing incorrect
pdbcommands.gh-103384: Generalize the regex pattern
BaseConfigurator.INDEX_PATTERNto allow spaces and non-alphanumeric characters in keys.gh-101162: Forbid using
builtins.issubclass()withtypes.GenericAliasas the first argument.gh-103200: Fix cache repopulation semantics of zipimport.invalidate_caches(). The cache is now repopulated upon retrieving files with an invalid cache, not when the cache is invalidated.
gh-100061: Fix a bug that causes wrong matches for regular expressions with possessive qualifier.
gh-77609: Add follow_symlinks argument to
pathlib.Path.glob()andrglob(), defaulting to false.gh-102541: Hide traceback in
help()prompt, when import failed.gh-102120: Added a stream mode to
tarfilethat allows for reading archives without caching info about the inner files.gh-102029: Deprecate passing any arguments to
threading.RLock().gh-88233: Refactored
zipfile._strip_extrato use higher level abstractions for extras instead of a heavy-state loop.gh-102024: Reduce calls of
_idle_semaphore.release()inconcurrent.futures.thread._worker().gh-73435: Add support for recursive wildcards in
pathlib.PurePath.match().gh-84867:
unittest.TestLoaderno longer loads test cases from exactunittest.TestCaseandunittest.FunctionTestCaseclasses.gh-99203: Restore following CPython <= 3.10.5 behavior of
shutil.make_archive(): do not create an empty archive ifroot_diris not a directory, and, in that case, raiseFileNotFoundErrororNotADirectoryErrorregardless offormatchoice. Beyond the brought-back behavior, the function may now also raise these exceptions indry_runmode.gh-80480: Emit
DeprecationWarningforarray’s'u'type code, deprecated in docs since Python 3.3.gh-94924:
unittest.mock.create_autospec()now properly returns coroutine functions compatible withinspect.iscoroutinefunction()gh-94777: Fix hanging
multiprocessingProcessPoolExecutorwhen a child process crashes while data is being written in the call queue.gh-92871: Remove the
typing.ioandtyping.renamespaces, deprecated since Python 3.8. All items are still available from the maintypingmodule.bpo-43633: Improve the textual representation of IPv4-mapped IPv6 addresses (RFC 4291 Sections 2.2, 2.5.5.2) in
ipaddress. Patch by Oleksandr Pavliuk.bpo-44850: Improve performance of
operator.methodcaller()using the PEP 590vectorcallconvention. Patch by Anthony Lee and Pieter Eendebak.bpo-44185:
unittest.mock.mock_open()will call theclose()method of the file handle mock when it is exiting from the context manager. Patch by Samet Yaslan.bpo-40988: Improve performance of
functools.singledispatchmethodby caching the generated dispatch wrapper. Optimization suggested by frederico. Patch by @mental32, Alex Waygood and Pieter Eendebak.bpo-41768:
unittest.mockspeccing no longer calls class properties. Patch by Melanie Witt.bpo-18319: Ensure
gettext(msg)retrieve translations even if a plural form exists. In other words:gettext(msg) == ngettext(msg, '', 1).bpo-17013: Add
ThreadingMocktounittest.mockthat can be used to create Mock objects that can wait until they are called. Patch by Karthikeyan Singaravelan and Mario Corchero.
Documentation¶
gh-109209: The minimum Sphinx version required for the documentation is now 4.2.
gh-108826:
dismodule command-line interface is now mentioned in documentation.gh-107305: Add documentation for
PyInterpreterConfigandPy_NewInterpreterFromConfig(). Also clarify some of the nearby docs relative to per-interpreter GIL.gh-107008: Document the
cursesmodule variablesLINESandCOLS.gh-106948: Add a number of standard external names to
nitpick_ignore.gh-106232: Make timeit doc command lines compatible with Windows by using double quotes for arguments. This works on linux and macOS also.
gh-105172: Fixed
functools.lru_cache()docstring accounting fortypedargument’s different handling of str and int. Patch by Bar Harel.gh-105052: Update
timeitdoc to specify that time in seconds is just the default.gh-89455: Add missing documentation for the
max_group_depthandmax_group_widthparameters and theexceptionsattribute of thetraceback.TracebackExceptionclass.gh-89412: Add missing documentation for the
end_linenoandend_offsetattributes of thetraceback.TracebackExceptionclass.gh-104943: Remove mentions of old Python versions in
typing.NamedTuple.gh-54738: Add documentation on how to localize the
argparsemodule.gh-102823: Document the return type of
x // ywhenxandyhave typefloat.gh-102759: Align function signature for
functools.reducein documentation and docstring with the C implementation.
Tests¶
gh-110647: Fix test_stress_modifying_handlers() of test_signal. Patch by Victor Stinner.
gh-103053: Fix test_tools.test_freeze on FreeBSD: run “make distclean” instead of “make clean” in the copied source directory to remove also the “python” program. Patch by Victor Stinner.
gh-110167: Fix a deadlock in test_socket when server fails with a timeout but the client is still running in its thread. Don’t hold a lock to call cleanup functions in doCleanups(). One of the cleanup function waits until the client completes, whereas the client could deadlock if it called addCleanup() in such situation. Patch by Victor Stinner.
gh-110367: regrtest: When using worker processes (-jN) with –verbose3 option, regrtest can now display the worker output even if a worker process does crash. Previously, sys.stdout and sys.stderr were replaced and so the worker output was lost on a crash. Patch by Victor Stinner.
gh-110267: Add tests for pickling and copying PyStructSequence objects. Patched by Xuehai Pan.
gh-110171:
libregrtestnow always sets and showsrandom.seed, so tests are more reproducible. Use--randseedflag to pass the explicit random seed for tests.gh-110152: Remove
Tools/scripts/run_tests.pyandmake hostrunnertest. Just run./python -m test --slow-ci,make buildbottestormake testinstead. Python test runner (regrtest) now handles cross-compilation and HOSTRUNNER. It also adds options to Python such fast-u -E -W default -bbwhen--fast-cior--slow-cioption is used. Patch by Victor Stinner.gh-110031: Skip test_threading tests using thread+fork if Python is built with Address Sanitizer (ASAN). Patch by Victor Stinner.
gh-110088: Fix test_asyncio timeouts: don’t measure the maximum duration, a test should not measure a CI performance. Only measure the minimum duration when a task has a timeout or delay. Add
CLOCK_REStotest_asyncio.utils. Patch by Victor Stinner.gh-109974: Fix race conditions in test_threading lock tests. Wait until a condition is met rather than using
time.sleep()with a hardcoded number of seconds. Patch by Victor Stinner.gh-110033: Fix
test_interprocess_signal()oftest_signal. Make sure that thesubprocess.Popenobject is deleted before the test raising an exception in a signal handler. Otherwise,Popen.__del__()can get the exception which is logged asException ignored in: ...and the test fails. Patch by Victor Stinner.gh-109594: Fix test_timeout() of test_concurrent_futures.test_wait. Remove the future which may or may not complete depending if it takes longer than the timeout or not. Keep the second future which does not complete before wait() timeout. Patch by Victor Stinner.
gh-109972: Split test_gdb.py file into a test_gdb package made of multiple tests, so tests can now be run in parallel. Patch by Victor Stinner.
gh-109566: regrtest: When
--fast-cior--slow-cioption is used, regrtest now replaces the current process with a new process to add-u -W default -bb -Eoptions to Python. Patch by Victor Stinner.gh-109748: Fix
test_zippath_from_non_installed_posix()of test_venv: don’t copy__pycache__/sub-directories, because they can be modified by other Python tests running in parallel. Patch by Victor Stinner.gh-109739: regrtest: Fix reference leak check on Windows. Disable the load tracker on Windows in the reference leak check mode (-R option). Patch by Victor Stinner.
gh-109276: regrtest: When a test fails with “env changed” and the –rerun option is used, the test is now re-run in verbose mode in a fresh process. Patch by Victor Stinner.
gh-103053: Skip test_freeze_simple_script() of test_tools.test_freeze if Python is built with
./configure --enable-optimizations, which means with Profile Guided Optimization (PGO): it just makes the test too slow. The freeze tool is tested by many other CIs with other (faster) compiler flags. Patch by Victor Stinner.gh-109580: Skip
test_perf_profilerif Python is built with ASAN, MSAN or UBSAN sanitizer. Python does crash randomly in this test on such build. Patch by Victor Stinner.gh-109566: regrtest: Add
--fast-ciand--slow-cioptions.--fast-ciuses a default timeout of 10 minutes and-u all,-cpu(skip slowest tests).--slow-ciuses a default timeout of 20 minutes and-u all(run all tests). Patch by Victor Stinner.gh-109425: libregrtest now decodes stdout of test worker processes with the “backslashreplace” error handler to log corrupted stdout, instead of failing with an error and not logging the stdout. Patch by Victor Stinner.
gh-109396: Fix
test_socket.test_hmac_sha1()in FIPS mode. Use a longer key: FIPS mode requires at least of at least 112 bits. The previous key was only 32 bits. Patch by Victor Stinner.gh-104736: Fix test_gdb on Python built with LLVM clang 16 on Linux ppc64le (ex: Fedora 38). Search patterns in gdb “bt” command output to detect when gdb fails to retrieve the traceback. For example, skip a test if
Backtrace stopped: frame did not save the PCis found. Patch by Victor Stinner.gh-109276: libregrtest now calls
random.seed()before running each test file when-r/--randomizecommand line option is used. Moreover, it’s also called in worker processes. It should help to make tests more deterministic. Previously, it was only called once in the main process before running all test files and it was not called in worker processes. Patch by Victor Stinner.gh-109276: libregrtest now uses a separated file descriptor to write test result as JSON. Previously, if a test wrote debug messages late around the JSON, the main test process failed to parse JSON. Patch by Victor Stinner.
gh-108996: Fix and enable
test_msvcrt.gh-109237: Fix
test_site.test_underpth_basic()when the working directory contains at least one non-ASCII character: encode the._pthfile to UTF-8 and enable the UTF-8 Mode to use UTF-8 for the child process stdout. Patch by Victor Stinner.gh-109230: Fix
test_pyexpat.test_exception(): it can now be run from a directory different than Python source code directory. Before, the test failed in this case. Skip the test if Modules/pyexpat.c source is not available. Skip also the test on Python implementations other than CPython. Patch by Victor Stinner.gh-108996: Add tests for
msvcrt.gh-109015: Fix test_asyncio, test_imaplib and test_socket tests on FreeBSD if the TCP blackhole is enabled (
sysctl net.inet.tcp.blackhole). Skip the few tests which failed withETIMEDOUTwhich such non standard configuration. Currently, the FreeBSD GCP image enables TCP and UDP blackhole (sysctl net.inet.tcp.blackhole=2andsysctl net.inet.udp.blackhole=1). Patch by Victor Stinner.gh-91960: Skip
test_gdbif gdb is unable to retrieve Python frame objects: if a frame is<optimized out>. When Python is built with “clang -Og”, gdb can fail to retrieve the frame parameter of_PyEval_EvalFrameDefault(). In this case, tests likepy_bt()are likely to fail. Without getting access to Python frames,python-gdb.pyis mostly clueless on retrieving the Python traceback. Moreover,test_gdbis no longer skipped on macOS if Python is built with Clang. Patch by Victor Stinner.gh-108962: Skip
test_tempfile.test_flags()ifchflags()fails with “OSError: [Errno 45] Operation not supported” (ex: on FreeBSD 13). Patch by Victor Stinner.gh-91960: FreeBSD 13.2 CI coverage for pull requests is now provided by Cirrus-CI (a hosted CI service that supports Linux, macOS, Windows, and FreeBSD).
gh-89392: Removed support of
test_main()function in tests. They now always use normal unittest test runner.gh-108851: Fix
test_tomllibrecursion tests for WASI buildbots: reduce the recursion limit and compute the maximum nested array/dict depending on the current available recursion limit. Patch by Victor Stinner.gh-108851: Add
get_recursion_available()andget_recursion_depth()functions to thetest.supportmodule. Patch by Victor Stinner.gh-108834: Add
--fail-rerun optionoption to regrtest: if a test failed when then passed when rerun in verbose mode, exit the process with exit code 2 (error), instead of exit code 0 (success). Patch by Victor Stinner.gh-108834: Rename regrtest
--verbose2option (-w) to--rerun. Keep--verbose2as a deprecated alias. Patch by Victor Stinner.gh-108834: When regrtest reruns failed tests in verbose mode (
./python -m test --rerun), tests are now rerun in fresh worker processes rather than being executed in the main process. If a test does crash or is killed by a timeout, the main process can detect and handle the killed worker process. Tests are rerun in parallel if the-jNoption is used to run tests in parallel. Patch by Victor Stinner.gh-108822:
regrtestnow computes statistics on all tests: successes, failures and skipped.test_netrc,test_pep646_syntaxandtest_xml_etreenow return results in theirtest_main()function. Patch by Victor Stinner and Alex Waygood.gh-108794: The
doctest.DocTestRunner.run()method now counts the number of skipped tests. Adddoctest.DocTestRunner.skipsanddoctest.TestResults.skippedattributes. Patch by Victor Stinner.gh-108388: Convert test_concurrent_futures to a package of 7 sub-tests. Patch by Victor Stinner.
gh-108388: Split test_multiprocessing_fork, test_multiprocessing_forkserver and test_multiprocessing_spawn into test packages. Each package is made of 4 sub-tests: processes, threads, manager and misc. It allows running more tests in parallel and so reduce the total test duration. Patch by Victor Stinner.
gh-105776: Fix test_cppext when the C compiler command
-std=c11option: remove-std=options from the compiler command. Patch by Victor Stinner.gh-107652: Set up CIFuzz to run fuzz targets in GitHub Actions. Patch by Illia Volochii.
gh-107237:
test_logging: Fixtest_udp_reconnection()by increasing the timeout from 100 ms to 5 minutes (LONG_TIMEOUT). Patch by Victor Stinner.gh-107178: Add the C API test for functions in the Mapping Protocol, the Sequence Protocol and some functions in the Object Protocol.
gh-106714: test_capi: Fix test_no_FatalError_infinite_loop() to no longer write a coredump, by using test.support.SuppressCrashReport. Patch by Victor Stinner.
gh-104090: Avoid creating a reference to the test object in
collectedDurations().gh-106752: Moved tests for
zipfile.PathintoLib/test/test_zipfile/_path. Madezipfile._patha package.gh-106690: Add .coveragerc to cpython repository for use with coverage package.
gh-101634: When running the Python test suite with
-jNoption, if a worker stdout cannot be decoded from the locale encoding report a failed testn so the exitcode is non-zero. Patch by Victor Stinner.gh-105084: When the Python build is configured
--with-wheel-pkg-dir, tests requiring thesetuptoolsandwheelwheels will search for the wheels inWHEEL_PKG_DIR.gh-81005: String tests are modified to reflect that
strandunicodeare merged in Python 3. Patch by Daniel Fortunov.gh-103186: Suppress and assert expected RuntimeWarnings in test_sys_settrace.py
gh-69714: Add additional tests to
calendarto achieve full test coverage.
Build¶
gh-103053: “make check-clean-src” now also checks if the “python” program is found in the source directory: fail with an error if it does exist. Patch by Victor Stinner.
gh-109191: Fix compile error when building with recent versions of libedit.
gh-110276: No longer ignore
PROFILE_TASKfailure silently: command used by Profile Guided Optimization (PGO). Patch by Victor Stinner.gh-109566: Remove
make testalltarget: usemake buildbottestinstead. Patch by Victor Stinner.gh-109740: The experimental
--disable-gilconfigure flag now includes “t” (for “threaded”) in extension ABI tags.gh-109054: Fix building the
_testcapiextension on Linux AArch64 which requires linking to libatomic when<cpython/pyatomic.h>is used: the_Py_atomic_or_uint64()function requires libatomic__atomic_fetch_or_8()on this platform. The configure script now checks if linking to libatomic is needed and generates a new LIBATOMIC variable used to build the _testcapi extension. Patch by Victor Stinner.gh-63760: Fix Solaris build: no longer redefine the
gethostname()function. Solaris defines the function since 2005. Patch by Victor Stinner, original patch by Jakub Kulík.gh-108740: Fix a race condition in
make regen-all. Thedeepfreeze.csource and files generated by Argument Clinic are now generated or updated before generating “global objects”. Previously, some identifiers may miss depending on the order in which these files were generated. Patch by Victor Stinner.gh-108634: Python built with
configure--with-trace-refs(tracing references) is now ABI compatible with Python release build and debug build. Patch by Victor Stinner.gh-85283: The
_statC extension is now built with the limited C API. Patch by Victor Stinner.gh-108447: Fix x86_64 GNU/Hurd build
gh-107814: When calling
find_python.batwith-qit did not properly silence the output of nuget. That is now fixed.gh-105481: Remove the make target
regen-opcode-targets, merge its work intoregen-opcodewhich repeats most of the calculation. This simplifies the code for the build and reduces code duplication.gh-106881: Check for
linux/limits.hbefore including it inModules/posixmodule.c.gh-95855: Refactor platform triplet detection code and add detection for MIPS soft float and musl libc.
gh-106962: Detect MPI compilers in
configure.gh-106118: Fix compilation for platforms without
O_CLOEXEC. The issue was introduced with Python 3.12b1 in gh-103295. Patch by Erlend Aasland.gh-105875: SQLite 3.15.2 or newer is required to build the
sqlite3extension module. Patch by Erlend Aasland.gh-90005: Fix a regression in
configurewhere we could end up unintentionally linking withlibbsd.gh-102404: Document how to perform a WASI build on Linux. Also add Tools/wasm/build_wasi.sh as a reference implementation of the docs.
gh-89886: Autoconf 2.71 and aclocal 1.16.4 is now required to regenerate
!configure.gh-104692: Include
commoninstallas a prerequisite forbininstallThis ensures that
commoninstallis completed beforebininstallis started when parallel builds are used (make -j install), and so thepython3symlink is only installed after all standard library modules are installed.gh-101538: Add experimental wasi-threads support. Patch by Takashi Yamamoto.
Windows¶
gh-110437: Allows overriding the source of VC redistributables so that releases can be guaranteed to never downgrade between updates.
gh-109286: Update Windows installer to use SQLite 3.43.1.
gh-82367:
os.path.realpath()now resolves MS-DOS style file names even if the file is not accessible. Patch by Moonsik Park.gh-109991: Update Windows build to use OpenSSL 3.0.11.
gh-106242: Fixes
realpath()to behave consistently when passed a path containing an embedded null character on Windows. In strict mode, it now raisesOSErrorinstead of the unexpectedValueError, and in non-strict mode will make the path absolute.gh-83180: Changes the Python Launcher for Windows to prefer an active virtual environment when the launched script has a shebang line using a Unix-like virtual command, even if the command requests a specific version of Python.
gh-106844: Fix integer overflow and truncating by the null character in
_winapi.LCMapStringEx()which affectsntpath.normcase().gh-105436: Ensure that an empty environment block is terminated by two null characters, as is required by Windows.
gh-105146: Updated the links at the end of the installer to point to Discourse rather than the mailing lists.
gh-103646: When installed from the Microsoft Store,
pipno longer defaults to per-user installs. However, as the install directory is unwritable, it should automatically decide to do a per-user install anyway. This should resolve issues whenpipis passed an option that conflicts with--user.gh-88745: Improve performance of
shutil.copy2()by using the operating system’sCopyFile2function. This may result in subtle changes to metadata copied along with some files, bringing them in line with normal OS behavior.gh-104820: Fixes
stat()and related functions on file systems that do not support file ID requests. This includes FAT32 and exFAT.gh-104803: Add
os.path.isdevdrive()to detect whether a path is on a Windows Dev Drive. ReturnsFalseon platforms that do not support Dev Drive, and is absent on non-Windows platforms.
macOS¶
IDLE¶
gh-104719: Remove IDLE’s modification of tokenize.tabsize and test other uses of tokenize data and methods.
Tools/Demos¶
gh-109991: Update GitHub CI workflows to use OpenSSL 3.0.11 and multissltests to use 1.1.1w, 3.0.11, and 3.1.3.
gh-108494: Argument Clinic now has a partial support of the Limited API: see documentation in the Python Developer’s Guide Patch by Victor Stinner.
gh-107704: It is now possible to deprecate passing keyword arguments for keyword-or-positional parameters with Argument Clinic, using the new
/ [from X.Y]syntax. (To be read as “positional-only from Python version X.Y”.) See documentation in the Python Developer’s Guide for more information.gh-107880: Argument Clinic can now clone
__init__()and__new__()methods.gh-104683: Add
--excludeoption to Argument Clinic CLI.gh-95065: Argument Clinic now supports overriding automatically generated signature by using directive
@text_signature. See documentation in the Python Developer’s Guidegh-107609: Fix duplicate module check in Argument Clinic. Previously, a duplicate definition would incorrectly be silently accepted. Patch by Erlend E. Aasland.
gh-107467: The Argument Clinic command-line tool now prints to stderr instead of stdout on failure.
gh-106970: Fix bugs in the Argument Clinic
destination <name> clearcommand; the destination buffers would never be cleared, and thedestinationdirective parser would simply continue to the fault handler after processing the command. Patch by Erlend E. Aasland.gh-106706: Change bytecode syntax for families to remove redundant name matching pseudo syntax.
gh-106359: Argument Clinic now explicitly forbids “kwarg splats” in function calls used as annotations.
gh-103186:
freezenow fetchesCONFIG_ARGSfrom the original CPython instance the Makefile uses to call utility scripts. Patch by Ijtaba Hussain.gh-95065: It is now possible to deprecate passing parameters positionally with Argument Clinic, using the new
* [from X.Y]syntax. (To be read as “keyword-only from Python version X.Y”.) See documentation in the Python Developer’s Guide for more information. Patch by Erlend E. Aasland with help from Alex Waygood, Nikita Sobolev, and Serhiy Storchaka.
C API¶
gh-85283: If the
Py_LIMITED_APImacro is defined,Py_BUILD_CORE,Py_BUILD_CORE_BUILTINandPy_BUILD_CORE_MODULEmacros are now undefined by<Python.h>. Patch by Victor Stinner.gh-110289: Add
PyUnicode_EqualToUTF8AndSize()andPyUnicode_EqualToUTF8()functions.gh-110235: Raise
TypeErrorfor duplicate/unknown fields inPyStructSequenceconstructor. Patched by Xuehai Pan.gh-110014: Remove undocumented
PY_TIMEOUT_MAXconstant from the limited C API. Patch by Victor Stinner.gh-109521:
PyImport_GetImporter()now sets RuntimeError if it fails to getsys.path_hooksorsys.path_importer_cacheor they are not list and dict correspondingly. Previously it could return NULL without setting error in obscure cases, crash or raise SystemError if these attributes have wrong type.gh-108724: Add
PyMutexinternal-only lightweight locking API.gh-85283: Add
PySys_AuditTuple()function: similar toPySys_Audit(), but pass event arguments as a Pythontupleobject. Patch by Victor Stinner.gh-108867: Add
PyThreadState_GetUnchecked()function: similar toPyThreadState_Get(), but don’t kill the process with a fatal error if it is NULL. The caller is responsible to check if the result is NULL. Previously, the function was private and known as_PyThreadState_UncheckedGet(). Patch by Victor Stinner.gh-108765:
Python.hno longer includes the<ctype.h>standard header file. If needed, it should now be included explicitly. For example, it providesisalpha()andtolower()functions which are locale dependent. Python provides locale independent functions, likePy_ISALPHA()andPy_TOLOWER(). Patch by Victor Stinner.gh-108765:
Python.hno longer includes the<unistd.h>standard header file. If needed, it should now be included explicitly. For example, it provides the functions:close(),getpagesize(),getpid()andsysconf(). Patch by Victor Stinner.gh-108765:
Python.hno longer includes the<ieeefp.h>standard header. It was included for thefinite()function which is now provided by the<math.h>header. It should now be included explicitly if needed. Remove also theHAVE_IEEEFP_Hmacro. Patch by Victor Stinner.gh-108765:
Python.hno longer includes these standard header files:<time.h>,<sys/select.h>and<sys/time.h>. If needed, they should now be included explicitly. For example,<time.h>provides theclock()andgmtime()functions,<sys/select.h>provides theselect()function, and<sys/time.h>provides thefutimes(),gettimeofday()andsetitimer()functions. Patch by Victor Stinner.gh-108511: Add functions
PyObject_HasAttrWithError(),PyObject_HasAttrStringWithError(),PyMapping_HasKeyWithError()andPyMapping_HasKeyStringWithError().gh-107073: Add
PyObject_VisitManagedDict()andPyObject_ClearManagedDict()functions which must be called by the traverse and clear functions of a type usingPy_TPFLAGS_MANAGED_DICTflag. Patch by Victor Stinner.gh-108634: Python built with
configure--with-trace-refs(tracing references) now supports the Limited API. Patch by Victor Stinner.gh-108014: Add
PyLong_AsInt()function: similar toPyLong_AsLong(), but store the result in a C int instead of a C long. Previously, it was known as the private function_PyLong_AsInt()(with an underscore prefix). Patch by Victor Stinner.gh-108314: Add
PyDict_ContainsString()function: same asPyDict_Contains(), but key is specified as a const char* UTF-8 encoded bytes string, rather than a PyObject*. Patch by Victor Stinner.gh-108337: Add atomic operations on additional data types in pyatomic.h.
gh-108014: Add
Py_IsFinalizing()function: check if the main Python interpreter is shutting down. Patch by Victor Stinner.gh-107916: C API functions
PyErr_SetFromErrnoWithFilename(),PyErr_SetExcFromWindowsErrWithFilename()andPyErr_SetFromWindowsErrWithFilename()save now the error code before callingPyUnicode_DecodeFSDefault().gh-107915: Such C API functions as
PyErr_SetString(),PyErr_Format(),PyErr_SetFromErrnoWithFilename()and many others no longer crash or ignore errors if it failed to format the error message or decode the filename. Instead, they keep a corresponding error.gh-107810: Improve
DeprecationWarningfor uses ofPyType_Specwith metaclasses that have customtp_new.gh-107249: Implement the
Py_UNUSEDmacro for Windows MSVC compiler. Patch by Victor Stinner.gh-107226:
PyModule_AddObjectRef()is now only available in the limited API version 3.10 or later.gh-106320: Remove private
_PyUnicode_AsString()alias toPyUnicode_AsUTF8(). It was kept for backward compatibility with Python 3.0 - 3.2. ThePyUnicode_AsUTF8()is available since Python 3.3. ThePyUnicode_AsUTF8String()function can be used to keep compatibility with Python 3.2 and older. Patch by Victor Stinner.gh-106572: Convert
PyObject_DelAttr()andPyObject_DelAttrString()macros to functions. Patch by Victor Stinner.gh-106307: Add
PyMapping_GetOptionalItem()function.gh-106521: Add
PyObject_GetOptionalAttr()andPyObject_GetOptionalAttrString()functions.gh-106320: Remove
_PyInterpreterState_Get()alias toPyInterpreterState_Get()which was kept for backward compatibility with Python 3.8. Patch by Victor Stinner.gh-106316: Remove
cpython/pytime.hheader file: it only contained private functions. Patch by Victor Stinner.gh-106023: Remove private
_PyObject_FastCall()function: usePyObject_Vectorcall()which is available since Python 3.8 (PEP 590). Patch by Victor Stinner.gh-106168: If Python is built in debug mode or
with assertions,PyTuple_SET_ITEM()andPyList_SET_ITEM()now check the index argument with an assertion. If the assertion fails, make sure that the size is set before. Patch by Victor Stinner.gh-106084: Remove the old aliases to functions calling functions which were kept for backward compatibility with Python 3.8 provisional API:
_PyObject_CallMethodNoArgs(): usePyObject_CallMethodNoArgs()_PyObject_CallMethodOneArg(): usePyObject_CallMethodOneArg()_PyObject_CallOneArg(): usePyObject_CallOneArg()_PyObject_FastCallDict(): usePyObject_VectorcallDict()_PyObject_Vectorcall(): usePyObject_Vectorcall()_PyObject_VectorcallMethod(): usePyObject_VectorcallMethod()_PyVectorcall_Function(): usePyVectorcall_Function()
Just remove the underscore prefix to update your code. Patch by Victor Stinner.
gh-106004: Adds
PyDict_GetItemRef()andPyDict_GetItemStringRef()functions: similar toPyDict_GetItemWithError()but returning a strong reference instead of a borrowed reference. Patch by Victor Stinner.gh-105927: Deprecate the
PyWeakref_GetObject()andPyWeakref_GET_OBJECT()functions: use the newPyWeakref_GetRef()function instead. Patch by Victor Stinner.gh-105927: Add
PyWeakref_GetRef()function: similar toPyWeakref_GetObject()but returns a strong reference, orNULLif the referent is no longer live. Patch by Victor Stinner.gh-105922: Add
PyImport_AddModuleRef(): similar toPyImport_AddModule(), but return a strong reference instead of a borrowed reference. Patch by Victor Stinner.gh-105227: The new
PyType_GetDict()provides the dictionary for the given type object that is normally exposed bycls.__dict__. Normally it’s sufficient to usetp_dict, but for the static builtin typestp_dictis now alwaysNULL.PyType_GetDict()provides the correct dict object instead.gh-105375: Fix a bug in
PyErr_WarnExplicit()where an exception could end up being overwritten if the API failed internally.gh-105603: We’ve renamed the new (in 3.12)
PyInterpreterConfig.own_giltoPyInterpreterConfig.giland changed the meaning of the value from “bool” to an integer with supported values ofPyInterpreterConfig_DEFAULT_GIL,PyInterpreterConfig_SHARED_GIL, andPyInterpreterConfig_OWN_GIL. The default is “shared”.gh-105387: In the limited C API version 3.12,
Py_INCREF()andPy_DECREF()functions are now implemented as opaque function calls to hide implementation details. Patch by Victor Stinner.gh-105396: Deprecate the
PyImport_ImportModuleNoBlock()function which is just an alias toPyImport_ImportModule()since Python 3.3. Patch by Victor Stinner.gh-103968:
PyType_FromMetaclass()now allows metaclasses withtp_newset toNULL.gh-105268: Remove the old private, undocumented and untested
_PyGC_FINALIZED()macro which was kept for backward compatibility with Python 3.8 and older. Patch by Victor Stinner.gh-105182: Remove
PyEval_AcquireLock()andPyEval_ReleaseLock()functions, deprecated in Python 3.2. Patch by Victor Stinner.gh-105182: Remove
PyEval_InitThreads()andPyEval_ThreadsInitialized()functions, deprecated in Python 3.9. Patch by Victor Stinner.gh-105145: Deprecate old Python initialization functions:
Patch by Victor Stinner.
gh-85275:
PyObject_AsCharBuffer(),PyObject_AsReadBuffer(),PyObject_CheckReadBuffer(), andPyObject_AsWriteBuffer()are removed. Please migrate to new buffer protocol;PyObject_GetBuffer()andPyBuffer_Release().gh-105156: Deprecate the old
Py_UNICODEandPY_UNICODE_TYPEtypes: use directly thewchar_ttype instead. Since Python 3.3,Py_UNICODEandPY_UNICODE_TYPEare just aliases towchar_t. Patch by Victor Stinner.gh-105145: Remove the following old functions to configure the Python initialization, deprecated in Python 3.11:
PySys_AddWarnOptionUnicode()PySys_AddWarnOption()PySys_AddXOption()PySys_HasWarnOptions()PySys_SetArgvEx()PySys_SetArgv()PySys_SetPath()Py_SetPath()Py_SetProgramName()Py_SetPythonHome()Py_SetStandardStreamEncoding()_Py_SetProgramFullPath()
Patch by Victor Stinner.
gh-105107: Remove functions deprecated in Python 3.9.
PyEval_CallObject(),PyEval_CallObjectWithKeywords(): usePyObject_CallNoArgs()andPyObject_Call()(positional arguments must not be NULL) instead.PyEval_CallFunction(): usePyObject_CallFunction()instead.PyEval_CallMethod(): usePyObject_CallMethod()instead.PyCFunction_Call(): usePyObject_Call()instead.
Patch by Victor Stinner.
gh-105115:
PyTypeObject.tp_bases(andtp_mro) for builtin static types are now shared by all interpreters, whereas in 3.12-beta1 they were stored onPyInterpreterState. Also note that now the tuples are immortal objects.gh-105071: Add
PyUnstable_Exc_PrepReraiseStarto the unstable C api to expose the implementation ofexcept*.gh-104922:
PY_SSIZE_T_CLEANis no longer required to use'#'formats in APIs likePyArg_ParseTuple()andPy_BuildValue(). They usesPy_ssize_tfor'#'regardlessPY_SSIZE_T_CLEAN.gh-104584: Add an unstable C API for hooking in an optimizer. This is mainly internal, but marked “unstable” to allow third-party experimentation.
gh-104668: Don’t call
PyOS_InputHookorPyOS_ReadlineFunctionPointerin subinterpreters, since it’s generally difficult to avoid using global state in their registered callbacks. This also avoids situations where extensions may find themselves running in a subinterpreter they don’t support (or haven’t yet been loaded in).bpo-42327: Add
PyModule_Add()function: similar toPyModule_AddObjectRef()andPyModule_AddObject(), but always steals a reference to the value.bpo-40309: Properly handle trailing spaces before closing parenthesis in
Py_BuildValue()format strings.
Python 3.12.0 beta 1¶
Release date: 2023-05-22
Security¶
gh-99889: Fixed a security in flaw in
uu.decode()that could allow for directory traversal based on the input if noout_filewas specified.gh-104049: Do not expose the local on-disk location in directory indexes produced by
http.client.SimpleHTTPRequestHandler.gh-99108: Upgrade built-in
hashlibSHA3 implementation to a verified implementation from theHACL*project. Used when OpenSSL is not present or lacks SHA3.gh-102153:
urllib.parse.urlsplit()now strips leading C0 control and space characters following the specification for URLs defined by WHATWG in response to CVE 2023-24329. Patch by Illia Volochii.
Library¶
Core and Builtins¶
gh-104615: Fix wrong ordering of assignments in code like
a, a = x, y. Contributed by Carl Meyer.gh-104572: Improve syntax error message for invalid constructs in PEP 695 contexts and in annotations when
from __future__ import annotationsis active.gh-104482: Fix three error handling bugs in ast.c’s validation of pattern matching statements.
gh-102818: Do not add a frame to the traceback in the
sys.setprofileandsys.settracetrampoline functions. This ensures that frames are not duplicated if an exception is raised in the callback function, and ensures that frames are not omitted if a C callback is used and that does not add the frame.gh-104405: Fix an issue where some bytecode instructions could ignore PEP 523 when “inlining” calls.
gh-103082: Change behavior of
sys.monitoring.events.LINEevents insys.monitoring: Line events now occur when a new line is reached dynamically, instead of using a static approximation, as before. This makes the behavior very similar to that of “line” events insys.settrace. This should ease porting of tools from 3.11 to 3.12.gh-104263: Fix
float("nan")to produce a quiet NaN on platforms (like MIPS) where the meaning of the signalling / quiet bit is inverted from its usual meaning. Also introduce a new macroPy_INFINITYmatching C99’sINFINITY, and refactor internals to rely on C99’sNANandINFINITYmacros instead of hard-coding bit patterns for infinities and NaNs. Thanks Sebastian Berg.gh-99113: Multi-phase init extension modules may now indicate that they support running in subinterpreters that have their own GIL. This is done by using
Py_MOD_PER_INTERPRETER_GIL_SUPPORTEDas the value for thePy_mod_multiple_interpretersmodule def slot. Otherwise the module, by default, cannot be imported in such subinterpreters. (This does not affect the main interpreter or subinterpreters that do not have their own GIL.) In addition to the isolation that multi-phase init already normally requires, support for per-interpreter GIL involves one additional constraint: thread-safety. If the module has external (linked) dependencies and those libraries have any state that isn’t thread-safe then the module must do the additional work to add thread-safety. This should be an uncommon case.gh-99113: The GIL is now (optionally) per-interpreter. This is the fundamental change for PEP 684. This is all made possible by virtue of the isolated state of each interpreter in the process. The behavior of the main interpreter remains unchanged. Likewise, interpreters created using
Py_NewInterpreter()are not affected. To get an interpreter with its own GIL, callPy_NewInterpreterFromConfig().gh-104108: Multi-phase init extension modules may now indicate whether or not they actually support multiple interpreters. By default such modules are expected to support use in multiple interpreters. In the uncommon case that one does not, it may use the new
Py_mod_multiple_interpretersmodule def slot. A value of0means the module does not support them.1means it does. The default is1.gh-104142: Fix an issue where
listortuplerepetition could fail to respect PEP 683.gh-104078: Improve the performance of
PyObject_HasAttrString()gh-104066: Improve the performance of
hasattr()for module objects with a missing attribute.gh-104028: Reduce object creation while calling callback function from gc. Patch by Donghee Na.
gh-104018: Disallow the “z” format specifier in %-format of bytes objects.
gh-102213: Fix performance loss when accessing an object’s attributes with
__getattr__defined.gh-103895: Improve handling of edge cases in showing
Exception.__notes__. Ensures that the messages always end with a newline and that string/bytes are not exploded over multiple lines. Patch by Carey Metcalfe.gh-103907: Don’t modify the refcounts of known immortal objects (
True,False, andNone) in the main interpreter loop.gh-103899: Provide a helpful hint in the
TypeErrormessage when accidentally calling a module object that has a callable attribute of the same name (such asdis.dis()ordatetime.datetime).gh-103845: Remove both line and instruction instrumentation before adding new ones for monitoring, to avoid newly added instrumentation being removed immediately.
gh-103763: Implement PEP 695, adding syntactic support for generic classes, generic functions, and type aliases.
A new
type X = ...syntax is added for type aliases, which resolves at runtime to an instance of the new classtyping.TypeAliasType. The value is lazily evaluated and is accessible through the.__value__attribute. This is implemented as a new AST nodeast.TypeAlias.New syntax (
class X[T]: ...,def func[T](): ...) is added for defining generic functions and classes. This is implemented as a newtype_paramsattribute on the AST nodes for classes and functions. This node holds instances of the new AST classesast.TypeVar,ast.ParamSpec, andast.TypeVarTuple.typing.TypeVar,typing.ParamSpec,typing.ParamSpecArgs,typing.ParamSpecKwargs,typing.TypeVarTuple, andtyping.Genericare now implemented in C rather than Python.There are new bytecode instructions
LOAD_LOCALS,LOAD_CLASSDICT_OR_GLOBAL, andLOAD_CLASSDICT_OR_DEREFto support correct resolution of names in class namespaces.Patch by Eric Traut, Larry Hastings, and Jelle Zijlstra.
Library¶
gh-103801: Adds three minor linting fixes to the wasm module caught that were caught by ruff.
gh-103793: Optimized asyncio Task creation by deferring expensive string formatting (task name generation) from Task creation to the first time
get_nameis called. This makes asyncio benchmarks up to 5% faster.
Core and Builtins¶
gh-102310: Change the error range for invalid bytes literals.
gh-103590: Do not wrap a single exception raised from a
try-except*construct in anExceptionGroup.gh-103650: Change the perf map format to remove the ‘0x’ prefix from the addresses
gh-102856: Implement the required C tokenizer changes for PEP 701. Patch by Pablo Galindo Salgado, Lysandros Nikolaou, Batuhan Taskaya, Marta Gómez Macías and sunmy2019.
gh-100530: Clarify the error message raised when the called part of a class pattern isn’t actually a class.
gh-101517: Fix bug in line numbers of instructions emitted for
except*.gh-103492: Clarify
SyntaxWarningwith literaliscomparison by specifying which literal is problematic, since comparisons usingiswith e.g.Noneand bool literals are idiomatic.gh-87729: Add
LOAD_SUPER_ATTR(and a specialization forsuper().method()) to speed upsuper().method()andsuper().attr. This makessuper().method()roughly 2.3x faster and brings it within 20% of the performance of a simple method call. Patch by Vladimir Matveev and Carl Meyer.gh-103488: Change the internal offset distinguishing yield and return target addresses, so that the instruction pointer is correct for exception handling and other stack unwinding.
gh-82012: The bitwise inversion operator (
~) on bool is deprecated. It returns the bitwise inversion of the underlyingintrepresentation such thatbool(~True) == True, which can be confusing. Usenotfor logical negation of bools. In the rare case that you really need the bitwise inversion of the underlyingint, convert to int explicitly~int(x).gh-77757: Exceptions raised in a typeobject’s
__set_name__method are no longer wrapped by aRuntimeError. Context information is added to the exception as a PEP 678 note.gh-103333:
AttributeErrornow retains thenameattribute when pickled and unpickled.
Library¶
gh-103242: Migrate
set_ecdh_curve()method not to use deprecated OpenSSL APIs. Patch by Donghee Na.
Core and Builtins¶
gh-103323: We’ve replaced our use of
_PyRuntime.tstate_currentwith a thread-local variable. This is a fairly low-level implementation detail, and there should be no change in behavior.gh-84436: The implementation of PEP-683 which adds Immortal Objects by using a fixed reference count that skips reference counting to make objects truly immutable.
gh-102700: Allow built-in modules to be submodules. This allows submodules to be statically linked into a CPython binary.
gh-103082: Implement PEP 669 Low Impact Monitoring for CPython.
gh-88691: Reduce the number of inline
CACHEentries forCALL.gh-102500: Make the buffer protocol accessible in Python code using the new
__buffer__and__release_buffer__magic methods. See PEP 688 for details. Patch by Jelle Zijlstra.gh-97933: PEP 709: inline list, dict and set comprehensions to improve performance and reduce bytecode size.
gh-99184: Bypass instance attribute access of
__name__inreprofweakref.ref.gh-98003: Complex function calls are now faster and consume no C stack space.
bpo-39610:
len()for 0-dimensionalmemoryviewobjects (such asmemoryview(ctypes.c_uint8(42))) now raises aTypeError. Previously this returned1, which was not consistent withmem_0d[0]raising anIndexError.
Library¶
bpo-31821: Fix
pause_reading()to work when called fromconnection_made()inasyncio.gh-104600:
functools.update_wrapper()now sets the__type_params__attribute (added by PEP 695).gh-104340: When an
asynciopipe protocol loses its connection due to an error, and the caller doesn’t awaitwait_closed()on the correspondingStreamWriter, don’t log a warning about an exception that was never retrieved. After all, according to theStreamWriter.close()docs, thewait_closed()call is optional (“not mandatory”).gh-104555: Fix issue where an
issubclass()check comparing a classXagainst aruntime-checkable protocolYwith non-callable members would not causeTypeErrorto be raised if anisinstance()call had previously been made comparing an instance ofXtoY. This issue was present in edge cases on Python 3.11, but became more prominent in 3.12 due to some unrelated changes that were made to runtime-checkable protocols. Patch by Alex Waygood.gh-104372: Refactored the
_posixsubprocessinternals to avoid Python C API usage between fork and exec when markingpass_fds=file descriptors inheritable.gh-104484: Added case_sensitive argument to
pathlib.PurePath.match()gh-75367: Fix data descriptor detection in
inspect.getattr_static().gh-104536: Fix a race condition in the internal
multiprocessing.processcleanup logic that could manifest as an unintendedAttributeErrorwhen callingprocess.close().gh-103857: Update datetime deprecations’ stracktrace to point to the calling line
gh-101520: Move the core functionality of the
tracemallocmodule in thePython/folder, leaving just the module wrapper inModules/.gh-104392: Remove undocumented and unused
_paramspec_tvarsattribute from some classes intyping.gh-102613: Fix issue where
pathlib.Path.glob()raisedRecursionErrorwhen walking deep directory trees.gh-103000: Improve performance of
dataclasses.asdict()for the common case where dict_factory isdict. Patch by David C Ellis.gh-104301: Allow leading whitespace in disambiguated statements in
pdb.gh-104139: Teach
urllib.parse.unsplit()to retain the"//"when assemblingitms-services://?action=generate-bugsstyle Apple Platform Deployment URLs.gh-104307:
socket.getnameinfo()now releases the GIL while contacting the DNS servergh-104310: Users may now use
importlib.util.allowing_all_extensions()(a context manager) to temporarily disable the strict compatibility checks for importing extension modules in subinterpreters.gh-87695: Fix issue where
pathlib.Path.glob()raisedOSErrorwhen it encountered a symlink to an overly long path.gh-104265: Prevent possible crash by disallowing instantiation of the
_csv.Readerand_csv.Writertypes. The regression was introduced in 3.10.0a4 with PR 23224 (bpo-14935). Patch by Radislav Chugunov.gh-102613: Improve performance of
pathlib.Path.glob()when expanding recursive wildcards (”**”) by merging adjacent wildcards and de-duplicating results only when necessary.gh-65772: Remove unneeded comments and code in turtle.py.
gh-90208: Fixed issue where
pathlib.Path.glob()returned incomplete results when it encountered aPermissionError. This method now suppresses allOSErrorexceptions, except those raised from callingis_dir()on the top-level path.gh-104144: Optimize
asyncio.TaskGroupwhen usingasyncio.eager_task_factory(). Skip scheduling a done callback if a TaskGroup task completes eagerly.gh-104144: Optimize
asyncio.gather()when usingasyncio.eager_task_factory()to complete eagerly if all fututres completed eagerly. Avoid scheduling done callbacks for futures that complete eagerly.gh-104114: Fix issue where
pathlib.Path.glob()returns paths using the case of non-wildcard segments for corresponding path segments, rather than the real filesystem case.gh-104104: Improve performance of
pathlib.Path.glob()by usingre.IGNORECASEto implement case-insensitive matching.gh-104102: Improve performance of
pathlib.Path.glob()when evaluating patterns that contain'../'segments.gh-103822: Update the return type of
weekdayto the newly added Day attributegh-103629: Update the
reproftyping.Unpackaccording to PEP 692.gh-103963: Make
disdisplay the names of the args forCALL_INTRINSIC_*.gh-104035: Do not ignore user-defined
__getstate__and__setstate__methods for slotted frozen dataclasses.gh-103987: In
mmap, fix several bugs that could lead to access to memory-mapped files after they have been invalidated.gh-88773: Added
turtle.teleport()to theturtlemodule to move a turtle to a new point without tracing a line, visible or invisible. Patch by Liam Gersten.gh-103935: Use
io.open_code()for files to be executed instead of rawopen()gh-68968: Fixed garbled output of
assertEqual()when an input lacks final newline.gh-100370: Fix potential
OverflowErrorinsqlite3.Connection.blobopen()for 32-bit builds. Patch by Erlend E. Aasland.gh-102628: Substitute CTRL-D with CTRL-Z in
sqlite3CLI banner when running on Windows.gh-103636: Module-level attributes
JanuaryandFebruaryare deprecated fromcalendar.gh-103583: Isolate
_multibytecodecand codecs extension modules. Patches by Erlend E. Aasland.gh-103848: Add checks to ensure that
[bracketed]hosts found byurllib.parse.urlsplit()are of IPv6 or IPvFuture format.gh-103872: Update the bundled copy of pip to version 23.1.2.
gh-74940: The C.UTF-8 locale is no longer converted to en_US.UTF-8, enabling the use of UTF-8 encoding on systems which have no locales installed.
gh-103861: Fix
zipfile.Zipfilecreating invalid zip files whenforce_zip64was used to add files to them. Patch by Carey Metcalfe.gh-103857: Deprecated
datetime.datetime.utcnow()anddatetime.datetime.utcfromtimestamp(). (Patch by Paul Ganssle)gh-103839: Avoid compilation error due to tommath.h not being found when building Tkinter against Tcl 8.7 built with bundled libtommath.
gh-103791:
contextlib.suppressnow supports suppressing exceptions raised as part of anExceptionGroup. If other exceptions exist on the group, they are re-raised in a group that does not contain the suppressed exceptions.gh-90750: Use
datetime.datetime.fromisocalendar()in the implementation ofdatetime.datetime.strptime(), which should now accept only valid ISO dates. (Patch by Paul Ganssle)gh-103685: Prepare
tkinter.Menu.index()for Tk 8.7 so that it does not raiseTclError: expected integer but got ""when it should returnNone.gh-81403:
urllib.request.CacheFTPHandlerno longer raisesURLErrorif a cached FTP instance is reused. ftplib’s endtransfer method calls voidresp to drain the connection to handle FTP instance reuse properly.gh-103699: Add
__orig_bases__to non-generic TypedDicts, call-based TypedDicts, and call-based NamedTuples. Other TypedDicts and NamedTuples already had the attribute.gh-92248: Deprecate
type,choices, andmetavarparameters ofargparse.BooleanOptionalAction.gh-89415: Add
socketconstants for source-specific multicast. Patch by Reese Hyde.gh-103673:
socketservergainsForkingUnixStreamServerandForkingUnixDatagramServerclasses. Patch by Jay Berry.gh-103636: Added Enum for months and days in the calendar module.
gh-84976: Create a new
Lib/_pydatetime.pyfile that defines the Python version of thedatetimemodule, and makedatetimeimport the contents of the new library only if the C implementation is missing. Currently, the full Python implementation is defined and then deleted if the C implementation is not available, slowing downimport datetimeunnecessarily.gh-103596: Attributes/methods are no longer shadowed by same-named enum members, although they may be shadowed by enum.property’s.
gh-103584: Updated
importlib.metadatawith changes fromimportlib_metadata5.2 through 6.5.0, including: Supportinstalled-files.txtforDistribution.fileswhen present.PackageMetadatanow stipulates an additionalgetmethod allowing for easy querying of metadata keys that may not be present.packages_distributionsnow honors packages and modules with Python modules that not.pysources (e.g..pyc,.so). Expand protocol forPackageMetadata.get_allto match the upstream implementation ofemail.message.Message.get_allin python/typeshed#9620. Deprecated use ofDistributionwithout defining abstract methods. Deprecated expectation thatPackageMetadata.__getitem__will returnNonefor missing keys. In the future, it will raise aKeyError.gh-103578: Fixed a bug where
pdbcrashes when reading source file with different encoding by replacingio.open()withio.open_code(). The new method would also call into the hook set byPyFile_SetOpenCodeHook().gh-103556: Now creating
inspect.Signatureobjects with positional-only parameter with a default followed by a positional-or-keyword parameter without one is impossible.gh-103559: Update the bundled copy of pip to version 23.1.1.
gh-103548: Improve performance of
pathlib.Path.absolute()andcwd()by joining paths only when necessary. Also improve performance ofpathlib.PurePath.is_absolute()on Posix by skipping path parsing and normalization.gh-103538: Remove
_tkintermodule code guarded by definition of theTK_AQUAmacro which was only needed for Tk 8.4.7 or earlier and was never actually defined by any build system or documented for manual use.gh-103525: Fix misleading exception message when mixed
strandbytesarguments are supplied topathlib.PurePathandPath.gh-103489: Add
getconfig()andsetconfig()toConnectionto make configuration changes to a database connection. Patch by Erlend E. Aasland.gh-103365: Set default Flag boundary to
STRICTand fix bitwise operations.gh-103472: Avoid a potential
ResourceWarninginhttp.client.HTTPConnectionby closing the proxy / tunnel’s CONNECT response explicitly.gh-103462: Fixed an issue with using
writelines()inasyncioto send very large payloads that exceed the amount of data that can be written in one call tosocket.socket.send()orsocket.socket.sendmsg(), resulting in the remaining buffer being left unwritten.gh-103449: Fix a bug in doc string generation in
dataclasses.dataclass().gh-103092: Isolate
_collections(apply PEP 687). Patch by Erlend E. Aasland.gh-103357: Added support for
logging.Formatterdefaultsparameter tologging.config.dictConfig()andlogging.config.fileConfig(). Patch by Bar Harel.gh-74690: The performance of
isinstance()checks againstruntime-checkable protocolshas been considerably improved for protocols that only have a few members. To achieve this improvement, several internal implementation details of thetypingmodule have been refactored, includingtyping._ProtocolMeta.__instancecheck__,typing._is_callable_members_only, andtyping._get_protocol_attrs. Patches by Alex Waygood.gh-74690: The members of a runtime-checkable protocol are now considered “frozen” at runtime as soon as the class has been created. See “What’s new in Python 3.12” for more details.
gh-103256: Fixed a bug that caused
hmacto raise an exception when the requested hash algorithm was not available in OpenSSL despite being available separately as part ofhashlibitself. It now falls back properly to the built-in. This could happen when, for example, your OpenSSL does not include SHA3 support and you want to computehmac.digest(b'K', b'M', 'sha3_256').gh-103285: Improve performance of
ast.get_source_segment().gh-103225: Fix a bug in
pdbwhen displaying line numbers of module-level source code.gh-93910: Remove deprecation of enum
member.memberaccess.gh-102978: Fixes
unittest.mock.patch()not enforcing function signatures for methods decorated with@classmethodor@staticmethodwhen patch is called withautospec=True.gh-103092: Isolate
_socket(apply PEP 687). Patch by Erlend E. Aasland.gh-100479: Add
pathlib.PurePath.with_segments(), which creates a path object from arguments. This method is called whenever a derivative path is created, such as frompathlib.PurePath.parent. Subclasses may override this method to share information between path objects.gh-103220: Fix issue where
os.path.join()added a slash when joining onto an incomplete UNC drive with a trailing slash on Windows.gh-103204: Fixes
http.serveraccepting HTTP requests with HTTP version numbers preceded by ‘+’, or ‘-’, or with digit-separating ‘_’ characters. The length of the version numbers is also constrained.gh-75586: Fix various Windows-specific issues with
shutil.which.gh-103193: Improve performance of
inspect.getattr_static(). Patch by Alex Waygood.gh-103176:
sys._current_exceptions()now returns a mapping from thread-id to an exception instance, rather than to a(typ, exc, tb)tuple.gh-103015: Add entrypoint keyword-only parameter to
sqlite3.Connection.load_extension(), for overriding the SQLite extension entry point. Patch by Erlend E. Aasland.gh-103000: Improve performance of
dataclasses.astuple()anddataclasses.asdict()in cases where the contents are common Python types.gh-102953: The extraction methods in
tarfile, andshutil.unpack_archive(), have a new a filter argument that allows limiting tar features than may be surprising or dangerous, such as creating files outside the destination directory. See Extraction filters for details.gh-97696: Implemented an eager task factory in asyncio. When used as a task factory on an event loop, it performs eager execution of coroutines. Coroutines that are able to complete synchronously (e.g. return or raise without blocking) are returned immediately as a finished task, and the task is never scheduled to the event loop. If the coroutine blocks, the (pending) task is scheduled and returned.
gh-81079: Add case_sensitive keyword-only argument to
pathlib.Path.glob()andrglob().gh-101819: Isolate the
ioextension module by applying PEP 687. Patch by Kumar Aditya, Victor Stinner, and Erlend E. Aasland.gh-91896: Deprecate
collections.abc.ByteStringgh-101362: Speed up
pathlib.Pathconstruction by omitting the path anchor from the internal list of path parts.gh-102114: Functions in the
dismodule that accept a source code string as argument now print a more concise traceback when the string contains a syntax or indentation error.gh-62432: The
unittestrunner will now exit with status code 5 if no tests were run. It is common for test runner misconfiguration to fail to find any tests, this should be an error.gh-78079: Fix incorrect normalization of UNC device path roots, and partial UNC share path roots, in
pathlib.PurePath. Pathlib no longer appends a trailing slash to such paths.gh-85984: Add
tty.cfmakeraw()andtty.cfmakecbreak()tottyand modernize, the behavior oftty.setraw()andtty.setcbreak()to use POSIX.1-2017 Chapter 11 “General Terminal Interface” flag masks by default.gh-101688: Implement
types.get_original_bases()to provide further introspection for types.gh-101640:
argparse.ArgumentParsernow catches errors when writing messages, such as whensys.stderrisNone. Patch by Oleg Iarygin.gh-83861: Fix datetime.astimezone method return value when invoked on a naive datetime instance that represents local time falling in a timezone transition gap. PEP 495 requires that instances with fold=1 produce earlier times than those with fold=0 in this case.
gh-89550: Decrease execution time of some
gzipfile writes by 15% by adding more appropriate buffering.gh-95299: Remove the bundled setuptools wheel from
ensurepip, and stop installing setuptools in environments created byvenv.gh-99353: Respect the
http.client.HTTPConnection.debuglevelflag inurllib.request.AbstractHTTPHandlerwhen its constructor parameterdebuglevelis not set. And do the same for*HTTPS*.gh-98040: Remove the long-deprecated
impmodule.gh-97850: Deprecate
pkgutil.find_loader()andpkgutil.get_loader()in favor ofimportlib.util.find_spec().gh-94473: Flatten arguments in
tkinter.Canvas.coords(). It now accepts not onlyx1, y1, x2, y2, ...and[x1, y1, x2, y2, ...], but also(x1, y1), (x2, y2), ...and[(x1, y1), (x2, y2), ...].gh-98040: Remove more deprecated importlib APIs:
find_loader(),find_module(),importlib.abc.Finder,pkgutil.ImpImporter,pkgutil.ImpLoader.gh-96522: Fix potential deadlock in pty.spawn()
gh-96534: Support divert(4) added in FreeBSD 14.
gh-87474: Fix potential file descriptor leaks in
subprocess.Popen.gh-94906: Support multiple steps in
math.nextafter(). Patch by Shantanu Jain and Matthias Gorgens.gh-51574: Make
tempfile.mkdtemp()return absolute paths when its dir parameter is relative.gh-94518: Convert private
_posixsubprocess.fork_exec()to use Argument Clinic.gh-92184: When creating zip files using
zipfile,os.altsep, if notNone, will always be treated as a path separator even when it is not/. Patch by Carey Metcalfe.bpo-46797: Deprecation warnings are now emitted for
ast.Num,ast.Bytes,ast.Str,ast.NameConstantandast.Ellipsis. These have been documented as deprecated since Python 3.8, and will be removed in Python 3.14.bpo-44844: Enables
webbrowserto detect and launch Microsoft Edge browser.bpo-45606: Fixed the bug in
pathlib.Path.glob()– previously a dangling symlink would not be found by this method when the pattern is an exact match, but would be found when the pattern contains a wildcard or the recursive wildcard (**). With this change, a dangling symlink will be found in both cases.bpo-23041: Add
QUOTE_STRINGSandQUOTE_NOTNULLto the suite ofcsvmodule quoting styles.bpo-24964: Added
http.client.HTTPConnection.get_proxy_response_headers()that provides access to the HTTP headers on a proxy server response to theCONNECTrequest.bpo-17258:
multiprocessingnow supports stronger HMAC algorithms for inter-process connection authentication rather than only HMAC-MD5.bpo-39744: Make
asyncio.subprocess.Process.communicate()close the subprocess’s stdin even when called withinput=None.bpo-22708: http.client CONNECT method tunnel improvements: Use HTTP 1.1 protocol; send a matching Host: header with CONNECT, if one is not provided; convert IDN domain names to Punycode. Patch by Michael Handler.
Documentation¶
gh-67056: Document that the effect of registering or unregistering an
atexitcleanup function from within a registered cleanup function is undefined.gh-103629: Mention the new way of typing
**kwargswithUnpackandTypedDictintroduced in PEP 692.gh-48241: Clarifying documentation about the url parameter to urllib.request.urlopen and urllib.request.Request needing to be encoded properly.
gh-86094: Add support for Unicode Path Extra Field in ZipFile. Patch by Yeojin Kim and Andrea Giudiceandrea
gh-99202: Fix extension type from documentation for compiling in C++20 mode
Tests¶
gh-104494: Update
test_pack_configure_inandtest_place_configure_infor changes to error message formatting in Tk 8.7.gh-104461: Run test_configure_screen on X11 only, since the
DISPLAYenvironment variable and-screenoption for toplevels are not useful on Tk for Win32 or Aqua.gh-86275: Added property-based tests to the
zoneinfotests, along with stubs for thehypothesisinterface. (Patch by Paul Ganssle)gh-103329: Regression tests for the behaviour of
unittest.mock.PropertyMockwere added.gh-102795: fix use of poll in test_epoll’s test_control_and_wait
gh-75729: Fix the
os.spawn*tests failing on Windows when the working directory or interpreter path contains spaces.
Build¶
gh-101282: BOLT optimization is now applied to the libpython shared library if building a shared library. BOLT instrumentation and application settings can now be influenced via the
BOLT_INSTRUMENT_FLAGSandBOLT_APPLY_FLAGSconfigure variables.gh-99017:
PYTHON_FOR_REGENnow require Python 3.10 or newer.gh-104490: Define
.PHONY/ virtual make targets consistently and properly.gh-104106: Add gcc fallback of mkfifoat/mknodat for macOS. Patch by Donghee Na.
gh-103532: The
TKINTER_PROTECT_LOADTKmacro is no longer defined or used in the_tkintermodule. It was previously only defined when building against Tk 8.4.13 and older, but Tk older than 8.5.12 has been unsupported since gh-91152.gh-99069: Extended workaround defining
static_assertwhen missing from the libc headers to all clang and gcc builds. In particular, this fixes building on macOS <= 10.10.gh-100220: Changed the default value of the
SHELLMakefile variable from/bin/shto/bin/sh -eto ensure that complex recipes correctly fail after an error. Previously,make installcould fail to install some files and yet return a successful result.gh-90656: Add platform triplets for 64-bit LoongArch:
loongarch64-linux-gnusf
loongarch64-linux-gnuf32
loongarch64-linux-gnu
Patch by Zhang Na.
Windows¶
gh-104623: Update Windows installer to use SQLite 3.42.0.
gh-82814: Fix a potential
[Errno 13] Permission deniedwhen usingshutil.copystat()within Windows Subsystem for Linux (WSL) on a mounted filesystem by addingerrno.EACCESto the list of ignored errors within the internal implementation.gh-103088: Fix virtual environment
activatescript having incorrect line endings for Cygwin.gh-103088: Fixes venvs not working in bash on Windows across different disks
gh-102997: Update Windows installer to use SQLite 3.41.2.
gh-88013: Fixed a bug where
TypeErrorwas raised when callingntpath.realpath()with a bytes parameter in some cases.
macOS¶
gh-99834: Update macOS installer to Tcl/Tk 8.6.13.
gh-104623: Update macOS installer to SQLite 3.42.0.
gh-103545: Add
os.PRIO_DARWIN_THREAD,os.PRIO_DARWIN_PROCESS,os.PRIO_DARWIN_BGandos.PRIO_DARWIN_NONUI. These can be used withos.setpriorityto run the process at a lower priority and make use of the efficiency cores on Apple Silicon systems.gh-104180: Support reading SOCKS proxy configuration from macOS System Configuration. Patch by Sam Schott.
gh-60436: update curses textbox to additionally handle backspace using the
curses.ascii.DELkey press.gh-102997: Update macOS installer to SQLite 3.41.2.
IDLE¶
Tools/Demos¶
C API¶
gh-101291: Added unstable C API for extracting the value of “compact” integers:
PyUnstable_Long_IsCompact()andPyUnstable_Long_CompactValue().gh-104109: We’ve added
Py_NewInterpreterFromConfig()andPyInterpreterConfigto the public C-API (but not the stable ABI; not yet at least). The new function may be used to create a new interpreter with various features configured. The function was added to support PEP 684 (per-interpreter GIL).gh-103968:
PyType_FromSpec()and its variants now allow creating classes whose metaclass overridestp_new. Thetp_newis ignored. This behavior is deprecated and will be disallowed in 3.14+. The newPyType_FromMetaclass()already disallows it.gh-103743: Add
PyUnstable_Object_GC_NewWithExtraData()function that can be used to allocate additional memory after an object for data not managed by Python.gh-103295: Introduced
PyUnstable_WritePerfMapEntry(),PyUnstable_PerfMapState_Init()andPyUnstable_PerfMapState_Fini(). These allow extension modules (JIT compilers in particular) to write to perf-map files in a thread safe manner. The Python support for the Linux perf profiler also uses these APIs to write entries in the perf-map file.gh-103509: Added C API for extending types whose instance memory layout is opaque:
PyType_Spec.basicsizecan now be zero or negative,PyObject_GetTypeData()can be used to get subclass-specific data, andPy_TPFLAGS_ITEMS_AT_ENDcan be used to safely extend variable-size objects. See PEP 697 for details.gh-103091: Add a new C-API function to eagerly assign a version tag to a PyTypeObject:
PyUnstable_Type_AssignVersionTag().gh-101408:
PyObject_GC_Resizeshould calculate preheader size if needed. Patch by Donghee Na.gh-98836: Add support of more formatting options (left aligning, octals, uppercase hexadecimals,
intmax_t,ptrdiff_t,wchar_tC strings, variable width and precision) inPyUnicode_FromFormat()andPyUnicode_FromFormatV().gh-96803: Add unstable C-API functions to get the code object, lasti and line number from the internal
_PyInterpreterFramein the limited API. The functions are:PyCodeObject * PyUnstable_InterpreterFrame_GetCode(struct _PyInterpreterFrame *frame)int PyUnstable_InterpreterFrame_GetLasti(struct _PyInterpreterFrame *frame)int PyUnstable_InterpreterFrame_GetLine(struct _PyInterpreterFrame *frame)
Python 3.12.0 alpha 7¶
Release date: 2023-04-04
Core and Builtins¶
gh-102192: Deprecated
_PyErr_ChainExceptionsin favour of_PyErr_ChainExceptions1.gh-89987: Reduce the number of inline
CACHEentries forBINARY_SUBSCR.gh-102859: Removed
JUMP_IF_FALSE_OR_POPandJUMP_IF_TRUE_OR_POPinstructions.gh-101975: Fixed
stacktopvalue on tracing entries to avoid corruption on garbage collection.gh-102778: Add
sys.last_excand deprecatesys.last_type,sys.last_valueandsys.last_traceback, which hold the same information in its legacy form.gh-100982: Replace all occurrences of
COMPARE_AND_BRANCHwithCOMPARE_OP.gh-102701: Fix overflow when creating very large dict.
gh-102755: Add
PyErr_DisplayException()which takes just an exception instance, to replace the legacyPyErr_Display()which takes the(typ, exc, tb)triplet.gh-102594: Add note to exception raised in
PyErr_SetObjectwhen normalization fails.gh-90997: Shrink the number of inline
CACHEentries used byLOAD_GLOBAL.
Library¶
gh-102491: Improve import time of
platformby removing IronPython version parsing. The IronPython version parsing was not functional (see https://github.com/IronLanguages/ironpython3/issues/1667).
Core and Builtins¶
gh-101291: Rearrage bits in first field (after header) of PyLongObject. * Bits 0 and 1: 1 - sign. I.e. 0 for positive numbers, 1 for zero and 2 for negative numbers. * Bit 2 reserved (probably for the immortal bit) * Bits 3+ the unsigned size.
This makes a few operations slightly more efficient, and will enable a more compact and faster 2s-complement representation of most ints in future.
gh-102397: Fix segfault from race condition in signal handling during garbage collection. Patch by Kumar Aditya.
gh-102406:
codecsencoding/decoding errors now get the context information (which operation and which codecs) attached as PEP 678 notes instead of through chaining a new instance of the exception.gh-102281: Fix potential nullptr dereference and use of uninitialized memory in fileutils. Patch by Max Bachmann.
gh-102300: Reuse operands with refcount of 1 in float specializations of BINARY_OP.
gh-102213: Fix performance loss when accessing an object’s attributes with
__getattr__defined.gh-102255: Improve build support for the Xbox. Patch by Max Bachmann.
Build¶
gh-102027: Fix SSE2 and SSE3 detection in
_blake2internal module. Patch by Max Bachmann.
Core and Builtins¶
gh-101865: Deprecate
co_lnotabin code objects, schedule it for removal in Python 3.14
Library¶
bpo-1635741: Adapt
_pickleto PEP 687. Patch by Mohamed Koubaa and Erlend Aasland.gh-103085: Pure python
locale.getencoding()will not warn deprecation.gh-103068: It’s no longer possible to register conditional breakpoints in
Pdbthat raiseSyntaxError. Patch by Tian Gao.gh-102549: Don’t ignore exceptions in member type creation.
gh-103056: Ensure final
_generate_next_value_is astaticmethod.gh-103046: Display current line label correctly in
diswhenshow_cachesis False andlastipoints to a CACHE entry.gh-102433:
isinstance()checks againstruntime-checkable protocolsnow useinspect.getattr_static()rather thanhasattr()to lookup whether attributes exist. This means that descriptors and__getattr__()methods are no longer unexpectedly evaluated duringisinstance()checks against runtime-checkable protocols. However, it may also mean that some objects which used to be considered instances of a runtime-checkable protocol may no longer be considered instances of that protocol on Python 3.12+, and vice versa. Most users are unlikely to be affected by this change. Patch by Alex Waygood.gh-103023: It’s no longer possible to register expressions to display in
Pdbthat raiseSyntaxError. Patch by Tian Gao.gh-102947: Improve traceback when
dataclasses.fields()is called on a non-dataclass. Patch by Alex Waygoodgh-102780: The
asyncio.Timeoutcontext manager now works reliably even when performing cleanup due to task cancellation. Previously it could raise aCancelledErrorinstead of anTimeoutErrorin such cases.gh-102871: Remove support for obsolete browsers from
webbrowser. Removed browsers include Grail, Mosaic, Netscape, Galeon, Skipstone, Iceape, Firebird, and Firefox versions 35 and below.gh-102839: Improve performance of
math.log()arguments handling by removing the argument clinic.gh-102828: Add the
onexcarg toshutil.rmtree(), which is likeonerrorbut expects an exception instance rather than an exc_info tuple. Deprecateonerror.gh-88965: typing: Fix a bug relating to substitution in custom classes generic over a
ParamSpec. Previously, if theParamSpecwas substituted with a parameters list that itself contained aTypeVar, theTypeVarin the parameters list could not be subsequently substituted. This is now fixed.Patch by Nikita Sobolev.
gh-76846: Fix issue where
__new__()and__init__()methods ofpathlib.PurePathandPathsubclasses were not called in some circumstances.gh-78530:
asyncio.wait()now accepts generators yielding tasks. Patch by Kumar Aditya.gh-102748:
asyncio.iscoroutine()now returnsFalsefor generators asasynciodoes not support legacy generator-based coroutines. Patch by Kumar Aditya.gh-102670: Optimized fmean(), correlation(), covariance(), and linear_regression() using the new math.sumprod() function.
gh-102615: Typing: Improve the
reprof generic aliases for classes generic over aParamSpec. (Use square brackets to represent a parameter list.)gh-100112:
asyncio.Task.get_coro()now always returns a coroutine when wrapping an awaitable object. Patch by Kumar Aditya.gh-102578: Speed up setting or deleting mutable attributes on non-dataclass subclasses of frozen dataclasses. Due to the implementation of
__setattr__and__delattr__for frozen dataclasses, this previously had a time complexity of O(n). It now has a time complexity of O(1).gh-102519: Add
os.listdrives(),os.listvolumes()andos.listmounts()functions on Windows for enumerating drives, volumes and mount pointsgh-74468: Attribute name of the extracted
tarfilefile object now holds filename of itself rather than of the archive it is contained in. Patch by Oleg Iarygin.gh-102378: Private helper method
inspect._signature_strip_non_python_syntaxwill no longer strip/from the input string.gh-79940: Add
inspect.getasyncgenstate()andinspect.getasyncgenlocals(). Patch by Thomas Krennwallner.gh-102103: Add
moduleargument todataclasses.make_dataclass()and make classes produced by it pickleable.gh-102069: Fix
__weakref__descriptor generation for custom dataclasses.gh-102038: Skip a
statinsiteif we have already found apyvenv.cfggh-98886: Fix issues when defining dataclasses that have fields with specific underscore names that aren’t clearly reserved by
dataclasses.gh-101673: Fix a
pdbbug wherellclears the changes to local variables.gh-101313: Added -h and –help arguments to the webbrowser CLI
gh-100372:
ssl.SSLContext.load_verify_locations()no longer incorrectly accepts some cases of trailing data when parsing DER.gh-89727: Fix pathlib.Path.walk RecursionError on deep directory trees by rewriting it using iteration instead of recursion.
gh-100131: Added an optional
deletekeyword argument totempfile.TemporaryDirectory.gh-48330: Added
--durationscommand line option, showing the N slowest test cases.unittest.TextTestRunnerandunittest.TextTestResultconstructors accept a new durations keyword argument. Subclasses should take this into account or accept**kwargs. Addedunittest.TestResult.addDuration()method andunittest.TestResult.collectedDurationsattribute.(Contributed by Giampaolo Rodola)
gh-98169: Fix
dataclasses.astuple()crash whencollections.defaultdictis present in the attributes.gh-96931: Fix incorrect results from
ssl.SSLSocket.shared_ciphers()gh-95495: When built against OpenSSL 3.0, the
sslmodule had a bug where it reported unauthenticated EOFs (i.e. without close_notify) as a clean TLS-level EOF. It now raisesSSLEOFError, matching the behavior in previous versions of OpenSSL. Theoptionsattribute onSSLContextalso no longer includesOP_IGNORE_UNEXPECTED_EOFby default. This option may be set to specify the previous OpenSSL 3.0 behavior.gh-94684: Now
uuid.uuid3()anduuid.uuid5()functions supportbytesobjects as their name argument.gh-94440: Fix a
concurrent.futures.processbug whereProcessPoolExecutorshutdown could hang after a future has been quickly submitted and canceled.gh-72346: Added deprecation warning to isdst parameter of
email.utils.localtime().bpo-36305: Fix handling of Windows filenames that resemble drives, such as
./a:b, inpathlib.
Documentation¶
gh-103112: Add docstring to
http.client.HTTPResponse.read()to fixpydocoutput.
Tests¶
Build¶
Windows¶
gh-102690: Update
webbrowserto fall back to Microsoft Edge instead of Internet Explorer.gh-99726: Improves correctness of stat results for Windows, and uses faster API when available
Tools/Demos¶
gh-102809:
Misc/gdbinitwas removed.
C API¶
gh-102013: Add a new (unstable) C-API function for iterating over GC’able objects using a callback:
PyUnstable_VisitObjects.
Python 3.12.0 alpha 6¶
Release date: 2023-03-07
Security¶
gh-99108: Replace builtin hashlib implementations of MD5 and SHA1 with verified ones from the HACL* project.
gh-101727: Updated the OpenSSL version used in Windows and macOS binary release builds to 1.1.1t to address CVE 2023-0286, CVE 2022-4303, and CVE 2022-4303 per the OpenSSL 2023-02-07 security advisory.
gh-99108: Replace the builtin
hashlibimplementations of SHA2-384 and SHA2-512 originally from LibTomCrypt with formally verified, side-channel resistant code from the HACL* project. The builtins remain a fallback only used when OpenSSL does not provide them.gh-101283:
subprocess.Popennow uses a safer approach to findcmd.exewhen launching withshell=True. Patch by Eryk Sun, based on a patch by Oleg Iarygin.
Core and Builtins¶
gh-102493: Fix regression in semantics of normalisation in
PyErr_SetObject.gh-102416: Do not memoize incorrectly automatically generated loop rules in the parser. Patch by Pablo Galindo.
gh-102356: Fix a bug that caused a crash when deallocating deeply nested filter objects. Patch by Marta Gómez Macías.
gh-102336: Cleanup Windows 7 specific special handling. Patch by Max Bachmann.
gh-102250: Fixed a segfault occurring when the interpreter calls a
__bool__method that raises.gh-102126: Fix deadlock at shutdown when clearing thread states if any finalizer tries to acquire the runtime head lock. Patch by Kumar Aditya.
gh-102027: Use
GetCurrentProcessIdon Windows whengetpidis unavailable. Patch by Max Bachmann.gh-102056: Fix error handling bugs in interpreter’s exception printing code, which could cause a crash on infinite recursion.
gh-100982: Restrict the scope of the
FOR_ITER_RANGEinstruction to the scope of the originalFOR_ITERinstruction, to allow instrumentation.gh-101967: Fix possible segfault in
positional_only_passed_as_keywordfunction, when new list created.gh-101952: Fix possible segfault in
BUILD_SETopcode, when new set created.gh-74895:
socket.getaddrinfono longer raisesOverflowErrorforintport values outside of the C long range. Out of range values are left up to the underlying string based C library API to report. Asocket.gaierrorSAI_SERVICEmay occur instead, or no error at all as not all platform C libraries generate an error.gh-101799: Add
CALL_INTRINSIC_2and use it instead ofPREP_RERAISE_STAR.gh-101857: Fix xattr support detection on Linux systems by widening the check to linux, not just glibc. This fixes support for musl.
gh-84783: Make the slice object hashable. Patch by Will Bradshaw and Furkan Onder.
gh-87849: Change the
SENDinstruction to leave the receiver on the stack. This allows the specialized form ofSENDto skip the chain of C calls and jump directly to theRESUMEin the generator or coroutine.gh-101765: Fix SystemError / segmentation fault in iter
__reduce__when internal access ofbuiltins.__dict__keys mutates the iter object.gh-101430: Update
tracemallocto handle presize of object properly. Patch by Donghee Na.gh-101696: Invalidate type version tag in
_PyStaticType_Deallocfor static types, avoiding bug where a false cache hit could crash the interpreter. Patch by Kumar Aditya.gh-101632: Adds a new
RETURN_CONSTinstruction.gh-100719: Remove gi_code field from generator (and coroutine and async generator) objects as it is redundant. The frame already includes a reference to the code object.
gh-98627: When an interpreter is configured to check (and only then), importing an extension module will now fail when the extension does not support multiple interpreters (i.e. doesn’t implement PEP 489 multi-phase init). This does not apply to the main interpreter, nor to subinterpreters created with
Py_NewInterpreter().
Library¶
gh-102302: Micro-optimise hashing of
inspect.Parameter, reducing the time it takes to hash an instance by around 40%.gh-101979: Fix a bug where parentheses in the
metavarargument toargparse.ArgumentParser.add_argument()were dropped. Patch by Yeojin Kim.gh-91038:
platform.platform()now has boolean default arguments.gh-81652: Add
mmap.MAP_ALIGNED_SUPERFreeBSD andmmap.MAP_CONCEALOpenBSD constants tommap. Patch by Yeojin Kim.gh-101961: For the binary mode,
fileinput.hookcompressed()doesn’t set theencodingvalue even if the value isNone. Patch by Gihwan Kim.gh-101936: The default value of
fpbecomesio.BytesIOifHTTPErroris initialized without a designatedfpparameter. Patch by Long Vo.gh-101566: In zipfile, sync Path with zipp 3.14, including fix for extractall on the underlying zipfile after being wrapped in
Path.gh-97930: Apply changes from importlib_resources 5.12, including fix for
MultiplexedPathto support directories in multiple namespaces (python/importlib_resources#265).gh-101997: Upgrade pip wheel bundled with ensurepip (pip 23.0.1)
gh-99108: The built-in extension modules for
hashlibSHA2 algorithms, used when OpenSSL does not provide them, now live in a single internal_sha2module instead of separate_sha256and_sha512modules.gh-101892: Callable iterators no longer raise
SystemErrorwhen the callable object exhausts the iterator but forgets to either return a sentinel value or raiseStopIteration.gh-87634: Remove locking behavior from
functools.cached_property().gh-97786: Fix potential undefined behaviour in corner cases of floating-point-to-time conversions.
gh-101517: Fixed bug where
bdblooks up the source line withlinecachewith alineno=None, which causes it to fail with an unhandled exception.gh-101773: Optimize
fractions.Fractionfor small components. The private argument_normalizeof thefractions.Fractionconstructor has been removed.gh-101693: In
sqlite3.Cursor.execute(),DeprecationWarningis now emitted when named placeholders are used together with parameters supplied as a sequence instead of as adict. Starting from Python 3.14, using named placeholders with parameters supplied as a sequence will raise aProgrammingError. Patch by Erlend E. Aasland.gh-101446: Change repr of
collections.OrderedDictto use regular dictionary formatting instead of pairs of keys and values.gh-101362: Speed up
pathlib.PurePathconstruction by handling arguments more uniformly. When apathlib.Pathargument is supplied, we use its string representation rather than joining its parts withos.path.join().gh-101362: Speed up
pathlib.PurePathconstruction by callingos.path.join()only when two or more arguments are given.gh-101362: Speed up
pathlib.Pathconstruction by running the path flavour compatibility check only when pathlib is imported.gh-85984: Refactored the implementation of
pty.fork()to useos.login_tty().A
DeprecationWarningis now raised bypty.master_open()andpty.slave_open(). They were undocumented and deprecated long long ago in the docstring in favor ofpty.openpty().gh-101561: Add a new decorator
typing.override(). See PEP 698 for details. Patch by Steven Troxler.gh-101360: Fix anchor matching in
pathlib.PureWindowsPath.match(). Path and pattern anchors are now matched withfnmatch, just like other path parts. This allows patterns such as"*:/Users/*"to be matched.gh-101277: Remove global state from
itertoolsmodule (PEP 687). Patches by Erlend E. Aasland.gh-100809: Fix handling of drive-relative paths (like ‘C:’ and ‘C:foo’) in
pathlib.Path.absolute(). This method now uses the OS API to retrieve the correct current working directory for the drive.gh-99138: Apply PEP 687 to
zoneinfo. Patch by Erlend E. Aasland.gh-96764:
asyncio.wait_for()now usesasyncio.timeout()as its underlying implementation. Patch by Kumar Aditya.gh-88233: Correctly preserve “extra” fields in
zipfileregardless of their ordering relative to a zip64 “extra.”bpo-23224: Fix segfaults when creating
lzma.LZMADecompressorandbz2.BZ2Decompressorobjects without calling__init__(), and fix leakage of locks and internal buffers when calling the__init__()methods oflzma.LZMADecompressor,lzma.LZMACompressor,bz2.BZ2Compressor, andbz2.BZ2Decompressorobjects multiple times.
Documentation¶
gh-85417: Update
cmathdocumentation to clarify behaviour on branch cuts.gh-97725: Fix
asyncio.Task.print_stack()description forfile=None. Patch by Oleg Iarygin.
Tests¶
gh-102019: Fix deadlock on shutdown if
test_current_{exception,frames}fails. Patch by Jacob Bower.gh-85984: Utilize new “winsize” functions from termios in pty tests.
gh-89792:
test_toolsnow copies up to 10x less source data to a temporary directory during thefreezetest by ignoring git metadata and other artifacts. It also limits its python build parallelism based on os.cpu_count instead of hard coding it as 8 cores.
Build¶
gh-99942: On Android, in a static build, python-config in embed mode no longer incorrectly reports a library to link to.
gh-99942: On Android, python.pc now correctly reports the library to link to, the same as python-config.sh.
gh-100221: Fix creating install directories in
make sharedinstallif they exist outsideDESTDIRalready.gh-96821: Explicitly mark C extension modules that need defined signed integer overflow, and add a configure option
--with-strict-overflow. Patch by Matthias Görgens and Shantanu Jain.
Windows¶
gh-102344: Implement
winreg.QueryValueusingQueryValueExandwinreg.SetValueusingSetValueEx. Patch by Max Bachmann.gh-101881: Handle read and write operations on non-blocking pipes properly on Windows.
gh-101881: Add support for the os.get_blocking() and os.set_blocking() functions on Windows.
gh-101849: Ensures installer will correctly upgrade existing
py.exelauncher installs.gh-101763: Updates copy of libffi bundled with Windows installs to 3.4.4.
gh-101759: Update Windows installer to SQLite 3.40.1.
gh-101614: Correctly handle extensions built against debug binaries that reference
python3_d.dll.gh-101196: The functions
os.path.isdir,os.path.isfile,os.path.islinkandos.path.existsare now 13% to 28% faster on Windows, by making fewer Win32 API calls.
macOS¶
gh-101759: Update macOS installer to SQLite 3.40.1.
C API¶
gh-101907: Removes use of non-standard C++ extension in public header files.
gh-99293: Document that the Py_TPFLAGS_VALID_VERSION_TAG is an internal feature, should not be used, and will be removed.
gh-101578: Add
PyErr_GetRaisedException()andPyErr_SetRaisedException()for saving and restoring the current exception. These functions return and accept a single exception object, rather than the triple arguments of the now-deprecatedPyErr_Fetch()andPyErr_Restore(). This is less error prone and a bit more efficient.Add
PyException_GetArgs()andPyException_SetArgs()as convenience functions for retrieving and modifying theargspassed to the exception’s constructor.gh-91744: Introduced the Unstable C API tier, marking APi that is allowed to change in minor releases without a deprecation period. See PEP 689 for details.
Python 3.12.0 alpha 5¶
Release date: 2023-02-07
Security¶
Core and Builtins¶
gh-92173: Fix the
defsandkwdefsarguments toPyEval_EvalCodeEx()and a reference leak in that function.gh-59956: The GILState API is now partially compatible with subinterpreters. Previously,
PyThreadState_GET()andPyGILState_GetThisThreadState()would get out of sync, causing inconsistent behavior and crashes.gh-101400: Fix wrong lineno in exception message on
continueorbreakwhich are not in a loop. Patch by Donghee Na.gh-101372: Fix
is_normalized()to properly handle the UCD 3.2.0 cases. Patch by Donghee Na.gh-101266: Fix
sys.getsizeof()reporting forintsubclasses.gh-101291: Refactor the
PyLongObjectstruct into a normal Python object header and aPyLongValuestruct.gh-101046: Fix a possible memory leak in the parser when raising
MemoryError. Patch by Pablo Galindogh-101037: Fix potential memory underallocation issue for instances of
intsubclasses with value zero.gh-100762: Record the (virtual) exception block depth in the oparg of
YIELD_VALUE. Use this to avoid the expensivethrow()when closing generators (and coroutines) that can be closed trivially.gh-100982: Adds a new
COMPARE_AND_BRANCHinstruction. This is a bit more efficient when performing a comparison immediately followed by a branch, and restores the design intent of PEP 659 that specializations are local to a single instruction.gh-100942: Fixed segfault in property.getter/setter/deleter that occurred when a property subclass overrode the
__new__method to return a non-property instance.gh-100923: Remove the
maskcache entry for theCOMPARE_OPinstruction and embed the mask into the oparg.gh-100892: Fix race while iterating over thread states in clearing
threading.local. Patch by Kumar Aditya.gh-91351: Fix a case where re-entrant imports could corrupt the import deadlock detection code and cause a
KeyErrorto be raised out ofimportlib/_bootstrap. In addition to the straightforward cases, this could also happen when garbage collection leads to a warning being emitted – as happens when it collects an open socket or file)gh-100726: Optimize construction of
rangeobject for medium size integers.gh-100712: Added option to build cpython with specialization disabled, by setting
ENABLE_SPECIALIZATION=Falseinopcode, followed bymake regen-all.
Library¶
bpo-32780: Inter-field padding is now inserted into the PEP3118 format strings obtained from
ctypes.Structureobjects, reflecting their true representation in memory.gh-101541: [Enum] - fix psuedo-flag creation
gh-101570: Upgrade pip wheel bundled with ensurepip (pip 23.0)
gh-101323: Fix a bug where errors where not thrown by zlib._ZlibDecompressor if encountered during decompressing.
gh-101317: Add ssl_shutdown_timeout parameter for
asyncio.StreamWriter.start_tls().gh-101326: Fix regression when passing
Noneas second or third argument toFutureIter.throw.gh-92123: Adapt the
_elementtreeextension module to multi-phase init (PEP 489). Patches by Erlend E. Aasland.gh-100795: Avoid potential unexpected
freeaddrinfocall (double free) insocketwhen when a libcgetaddrinfo()implementation leaves garbage in an output pointer when returning an error. Original patch by Sergey G. Brester.gh-101143: Remove unused references to
TimerHandleinasyncio.base_events.BaseEventLoop._add_callback.gh-101144: Make
zipfile.Path.open()andzipfile.Path.read_text()also acceptencodingas a positional argument. This was the behavior in Python 3.9 and earlier. 3.10 introduced a regression where supplying it as a positional argument would lead to aTypeError.gh-94518: Group-related variables of
_posixsubprocessmodule are renamed to stress that supplementary group affinity is added to a fork, not replace the inherited ones. Patch by Oleg Iarygin.gh-101015: Fix
typing.get_type_hints()on'*tuple[...]'and*tuple[...]. It must not drop theUnpackpart.gh-101000: Add
os.path.splitroot(), which splits a path into a 3-item tuple(drive, root, tail). This new function is used bypathlibto improve the performance of path construction by up to a third.gh-100573: Fix a Windows
asynciobug with named pipes where a client doingos.stat()on the pipe would cause an error in the server that disabled serving future requests.gh-39615:
warnings.warn()now has the ability to skip stack frames based on code filename prefix rather than only a numericstacklevelvia the newskip_file_prefixeskeyword argument.gh-100750: pass encoding kwarg to subprocess in platform
gh-100160: Emit a deprecation warning in
asyncio.DefaultEventLoopPolicy.get_event_loop()if there is no current event loop set and it decides to create one.gh-96290: Fix handling of partial and invalid UNC drives in
ntpath.splitdrive(), and inntpath.normpath()on non-Windows systems. Paths such as ‘\server’ and ‘\’ are now considered bysplitdrive()to contain only a drive, and consequently are not modified bynormpath()on non-Windows systems. The behaviour ofnormpath()on Windows systems is unaffected, as native OS APIs are used. Patch by Eryk Sun, with contributions by Barney Gale.gh-99952: Fix a reference undercounting issue in
ctypes.Structurewithfrom_param()results larger than a C pointer.gh-67790: Add float-style formatting support for
fractions.Fractioninstances.gh-86682: Ensure runtime-created collections have the correct module name using the newly added (internal)
sys._getframemodulename().gh-88597:
uuidnow has a command line interface. Trypython -m uuid -h.gh-60580:
ctypes.wintypes.BYTEdefinition changed fromc_bytetoc_ubyteto match Windows SDK. Patch by Anatoly Techtonik and Oleg Iarygin.gh-94518:
_posixsubprocessnow initializes all UID and GID variables using a reserved-1value instead of a separate flag. Patch by Oleg Iarygin.bpo-38941: The
xml.etree.ElementTreemodule now emitsDeprecationWarningwhen testing the truth value of anxml.etree.ElementTree.Element. Before, the Python implementation emittedFutureWarning, and the C implementation emitted nothing.bpo-40077: Convert
elementtreetypes to heap types. Patch by Erlend E. Aasland.bpo-29847: Fix a bug where
pathlib.Pathaccepted and ignored keyword arguments. Patch provided by Yurii Karabas.gh-77772:
ctypes.CDLL,ctypes.OleDLL,ctypes.WinDLL, andctypes.PyDLLnow accept path-like objects as theirnameargument. Patch by Robert Hoelzl.
Documentation¶
gh-88324: Reword
subprocessto emphasize default behavior of stdin, stdout, and stderr arguments. Remove inaccurate statement about child file handle inheritance.
Tests¶
gh-101334:
test_tarfilehas been updated to pass when run as a high UID.
Build¶
gh-101282: Update BOLT configuration not to use deprecated usage of
--split functions. Patch by Donghee Na.gh-101522: Allow overriding Windows dependencies versions and paths using MSBuild properties.
gh-77532: Minor fixes to allow building with
PlatformToolset=ClangCLon Windows.gh-101152: In accordance with PEP 699, the
ma_version_tagfield inPyDictObjectis deprecated for extension modules. Accessing this field will generate a compiler warning at compile time. This field will be removed in Python 3.14.gh-100340: Allows -Wno-int-conversion for wasm-sdk 17 and onwards, thus enables building WASI builds once against the latest sdk.
gh-101060: Conditionally add
-fno-reorder-blocks-and-partitionin configure. Effectively fixes--enable-boltwhen using Clang, as this appears to be a GCC-only flag.gh-98705:
__bool__is defined in AIX system header files which breaks the build in AIX, so undefine it.gh-98636: Fix a regression in detecting
gdbm_compatlibrary for the_gdbmmodule build.gh-96305:
_aix_supportnow uses a simple code to get platform details rather than the now non-existent_bootsubprocessduring bootstrap.
Windows¶
gh-101543: Ensure the install path in the registry is only used when the standard library hasn’t been located in any other way.
gh-101467: The
py.exelauncher now correctly filters when only a single runtime is installed. It also correctly handles prefix matches on tags so that-3.1does not match3.11, but would still match3.1-32.gh-99834: Updates bundled copy of Tcl/Tk to 8.6.13.0
gh-101135: Restore ability to launch older 32-bit versions from the
py.exelauncher when both 32-bit and 64-bit installs of the same version are available.gh-82052: Fixed an issue where writing more than 32K of Unicode output to the console screen in one go can result in mojibake.
gh-100320: Ensures the
PythonPathregistry key from an install is used when launching from a different copy of Python that relies on an existing install to provide a copy of its modules and standard library.gh-100247: Restores support for the
py.exelauncher finding shebang commands in its configuration file using the full command name.
Python 3.12.0 alpha 4¶
Release date: 2023-01-10
Core and Builtins¶
gh-100776: Fix misleading default value in
input()’s__text_signature__.gh-99005: Remove
UNARY_POSITIVE,ASYNC_GEN_WRAPandLIST_TO_TUPLE, replacing them with intrinsics.gh-99005: Add new
CALL_INTRINSIC_1instruction. RemoveIMPORT_STAR,PRINT_EXPRandSTOPITERATION_ERROR, replacing them with theCALL_INTRINSIC_1instruction.gh-100288: Remove the LOAD_ATTR_METHOD_WITH_DICT specialized instruction. Stats show it is not useful.
gh-100720: Added
_PyFrame_NumSlotsForCodeObject, which returns the number of slots needed in a frame for a given code object.gh-100719: Removed the co_nplaincellvars field from the code object, as it is redundant.
gh-100637: Fix
int.__sizeof__()calculation to include the 1-elementob_digitarray for0andFalse.gh-100649: Update the native_thread_id field of PyThreadState after fork.
gh-100126: Fix an issue where “incomplete” frames could be briefly visible to C code while other frames are being torn down, possibly resulting in corruption or hard crashes of the interpreter while running finalizers.
gh-87447: Fix
SyntaxErroron comprehension rebind checking with names that are not actually redefined.Now reassigning
bin[(b := 1) for a, b.prop in some_iter]is allowed. Reassigningais still disallowed as per PEP 572.gh-100268: Add
int.is_integer()to improve duck type compatibility betweenintandfloat.gh-100425: Improve the accuracy of
sum()with compensated summation.
Library¶
gh-100374: Fix incorrect result and delay in
socket.getfqdn(). Patch by Dominic Socular.
Core and Builtins¶
gh-100357: Convert
vars,dir,next,getattr, anditerto argument clinic.gh-100117: Improve the output of
codeobject.co_lines()by emitting only one entry for each line range.gh-90043: Handle NaNs when specializing
COMPARE_OPforfloatvalues.gh-100222: Redefine the
_Py_CODEUNITtypedef as a union to describe its layout to the C compiler, avoiding type punning and improving clarity.gh-99955: Internal compiler functions (in compile.c) now consistently return -1 on error and 0 on success.
gh-100188: The
BINARY_SUBSCR_LIST_INTandBINARY_SUBSCR_TUPLE_INTinstructions are no longer used for negative integers because those instructions always miss when encountering negative integers.gh-99110: Initialize frame->previous in frameobject.c to fix a segmentation fault when accessing frames created by
PyFrame_New().gh-94155: Improved the hashing algorithm for code objects, mitigating some hash collisions.
gh-99540:
Nonenow hashes to a constant value. This is not a requirements change.gh-100143: When built with
--enable-pystats, stats collection is now off by default. To enable it early at startup, pass the-Xpystatsflag. Stats are now always dumped, even if switched off.gh-100146: Improve
BUILD_LISTopcode so that it works similarly to theBUILD_TUPLEopcode, by stealing references from the stack rather than repeatedly using stack operations to set list elements. Implementation details are in a new private API_PyList_FromArraySteal().gh-100110: Specialize
FOR_ITERfor tuples.gh-100050: Honor existing errors obtained when searching for mismatching parentheses in the tokenizer. Patch by Pablo Galindo
gh-92216: Improve the performance of
hasattr()for type objects with a missing attribute.gh-99554: Pack debugging location tables more efficiently during bytecode compilation.
gh-98522: Add an internal version number to code objects, to give better versioning of inner functions and comprehensions, and thus better specialization of those functions. This change is invisible to both Python and C extensions.
gh-94603: Improve performance of
list.popfor small lists.
Library¶
Core and Builtins¶
bpo-32782:
ctypesarrays of length 0 now report a correct itemsize when amemoryviewis constructed from them, rather than always giving a value of 0.
Library¶
gh-100833: Speed up
math.fsum()by removing defensivevolatilequalifiers.gh-100805: Modify
random.choice()implementation to once again work with NumPy arrays.gh-100813: Add
socket.IP_PKTINFOconstant.gh-100792: Make
email.message.Message.__contains__()twice as fast.gh-91851: Microoptimizations for
fractions.Fraction.__round__(),fractions.Fraction.__ceil__()andfractions.Fraction.__floor__().gh-90104: Avoid RecursionError on
reprif a dataclass field definition has a cyclic reference.gh-100689: Fix crash in
pyexpatby statically allocatingPyExpat_CAPIcapsule.gh-100740: Fix
unittest.mock.Mocknot respecting the spec for attribute names prefixed withassert.gh-91219: Change
SimpleHTTPRequestHandlerto support subclassing to provide a different set of index file names instead of using__init__parameters.gh-100690:
Mockobjects which are not unsafe will now raise anAttributeErrorwhen accessing an attribute that matches the name of an assertion but without the prefixassert_, e.g. accessingcalled_onceinstead ofassert_called_once. This is in addition to this already happening for accessing attributes with prefixesassert,assret,asert,aseert, andassrt.gh-89727: Simplify and optimize
os.walk()by usingisinstance()checks to check the top of the stack.gh-100485: Add math.sumprod() to compute the sum of products.
gh-86508: Fix
asyncio.open_connection()to skip binding to local addresses of different family. Patch by Kumar Aditya.gh-97930:
importlib.resources.filesnow accepts a module as an anchor instead of only accepting packages. If a module is passed, resources are resolved adjacent to that module (in the same package or at the package root). The parameter was renamed frompackagetoanchorwith a compatibility shim for those passing by keyword. Additionally, the newanchorparameter is now optional and will default to the caller’s module.gh-100585: Fixed a bug where importlib.resources.as_file was leaving file pointers open
gh-100562: Improve performance of
pathlib.Path.absolute()by nearly 2x. This comes at the cost of a performance regression inpathlib.Path.cwd(), which is generally used less frequently in user code.gh-100519: Small simplification of
http.cookiejar.eff_request_host()that improves readability and better matches the RFC wording.gh-100287: Fix the interaction of
unittest.mock.seal()withunittest.mock.AsyncMock.gh-100488: Add
Fraction.is_integer()to check whether afractions.Fractionis an integer. This improves duck type compatibility withfloatandint.gh-100474:
http.servernow checks that an index page is actually a regular file before trying to serve it. This avoids issues with directories namedindex.html.gh-100363: Speed up
asyncio.get_running_loop()by removing redundantgetpidchecks. Patch by Kumar Aditya.gh-78878: Fix crash when creating an instance of
_ctypes.CField.gh-100348: Fix ref cycle in
asyncio._SelectorSocketTransportby removing_read_ready_cbinclose.gh-100344: Provide C implementation for
asyncio.current_task()for a 4x-6x speedup.gh-100272: Fix JSON serialization of OrderedDict. It now preserves the order of keys.
gh-83076: Instantiation of
Mock()andAsyncMock()is now 3.8x faster.gh-100234: Set a default value of 1.0 for the
lambdparameter in random.expovariate().gh-100228: A
DeprecationWarningmay be raised whenos.fork()oros.forkpty()is called from multi-threaded processes. Forking with threads is unsafe and can cause deadlocks, crashes and subtle problems. Lack of a warning does not indicate that the fork call was actually safe, as Python may not be aware of all threads.gh-100039: Improve signatures for enums and flags.
gh-100133: Fix regression in
asynciowhere a subprocess would sometimes lose data received from pipe.bpo-44592: Fixes inconsistent handling of case sensitivity of extrasaction arg in
csv.DictWriter.gh-100098: Fix
tuplesubclasses being cast totuplewhen used as enum values.gh-85432: Rename the fmt parameter of the pure-Python implementation of
datetime.time.strftime()to format. Rename the t parameter ofdatetime.datetime.fromtimestamp()to timestamp. These changes mean the parameter names in the pure-Python implementation now match the parameter names in the C implementation. Patch by Alex Waygood.gh-98778: Update
HTTPErrorto be initialized properly, even if thefpisNone. Patch by Donghee Na.gh-99925: Unify error messages in JSON serialization between
json.dumps(float('nan'), allow_nan=False)andjson.dumps(float('nan'), allow_nan=False, indent=<SOMETHING>). Now both include the representation of the value that could not be serialized.gh-89727: Fix issue with
os.walk()where aRecursionErrorwould occur on deep directory structures by adjusting the implementation ofos.walk()to be iterative instead of recursive.gh-94943: Add Dataclass support to the
Enum__repr__(). When inheriting from adataclass, only show the field names in the value section of the memberrepr(), and not the dataclass’ class name.gh-83035: Fix
inspect.getsource()handling of decorator calls with nested parentheses.gh-99576: Fix
.save()method forLWPCookieJarandMozillaCookieJar: saved file was not truncated on repeated save.gh-94912: Add
inspect.markcoroutinefunction()decorator which manually marks a function as a coroutine for the benefit ofiscoroutinefunction().gh-99509: Add PEP 585 support for
multiprocessing.queues.Queue.gh-99482: Remove
Jythonpartial compatibility code from several stdlib modules.gh-99433: Fix
doctestfailure ontypes.MethodWrapperTypein modules.gh-85267: Several improvements to
inspect.signature()’s handling of__text_signature. - Fixes a case whereinspect.signature()dropped parameters - Fixes a case whereinspect.signature()raisedtokenize.TokenError- Allowsinspect.signature()to understand defaults involving binary operations of constants -inspect.signature()is documented as only raisingTypeErrororValueError, but sometimes raisedRuntimeError. These cases now raiseValueError- Removed a dead code pathgh-91166:
asynciois optimized to avoid excessive copying when writing to socket and usesendmsg()if the platform supports it. Patch by Kumar Aditya.gh-98030: Add missing TCP socket options from Linux:
TCP_MD5SIG,TCP_THIN_LINEAR_TIMEOUTS,TCP_THIN_DUPACK,TCP_REPAIR,TCP_REPAIR_QUEUE,TCP_QUEUE_SEQ,TCP_REPAIR_OPTIONS,TCP_TIMESTAMP,TCP_CC_INFO,TCP_SAVE_SYN,TCP_SAVED_SYN,TCP_REPAIR_WINDOW,TCP_FASTOPEN_CONNECT,TCP_ULP,TCP_MD5SIG_EXT,TCP_FASTOPEN_KEY,TCP_FASTOPEN_NO_COOKIE,TCP_ZEROCOPY_RECEIVE,TCP_INQ,TCP_TX_DELAY.gh-88500: Reduced the memory usage of
urllib.parse.unquote()andurllib.parse.unquote_to_bytes()on large values.gh-96127:
inspect.signaturewas raisingTypeErroron call with mock objects. Now it correctly returns(*args, **kwargs)as inferred signature.gh-95882: Fix a 3.11 regression in
asynccontextmanager(), which caused it to propagate exceptions with incorrect tracebacks and fix a 3.11 regression incontextmanager(), which caused it to propagate exceptions with incorrect tracebacks forStopIteration.gh-78707: Deprecate passing more than one positional argument to
pathlib.PurePath.relative_to()andis_relative_to().gh-92122: Fix reStructuredText syntax errors in docstrings in the
enummodule.gh-91851: Optimize the
Fractionarithmetics for small components.bpo-24132: Make
pathlib.PurePathandPathsubclassable (private to start). Previously, attempting to instantiate a subclass resulted in anAttributeErrorbeing raised. Patch by Barney Gale.bpo-40447: Accept
os.PathLike(such aspathlib.Path) in thestripdirarguments ofcompileall.compile_file()andcompileall.compile_dir().bpo-36880: Fix a reference counting issue when a
ctypescallback with return typepy_objectreturnsNone, which could cause crashes.
Documentation¶
gh-100616: Document existing
attrparameter tocurses.window.vline()function incurses.gh-100472: Remove claim in documentation that the
stripdir,prependdirandlimit_sl_destparameters ofcompileall.compile_dir()andcompileall.compile_file()could bebytes.bpo-25377: Clarify use of octal format of mode argument in help(os.chmod) as well as help(os.fchmod)
Tests¶
gh-100454: Start running SSL tests with OpenSSL 3.1.0-beta1.
gh-100086: The Python test runner (libregrtest) now logs Python build information like “debug” vs “release” build, or LTO and PGO optimizations. Patch by Victor Stinner.
gh-93018: Make two tests forgiving towards host system libexpat with backported security fixes applied.
Build¶
gh-100540: Removed the
--with-system-fficonfigureoption;libffimust now always be supplied by the system on all non-Windows platforms. The option has had no effect on non-Darwin platforms for several releases, and in 3.11 only had the non-obvious effect of invokingpkg-configto findlibffiand never setting-DUSING_APPLE_OS_LIBFFI. Now on Darwin platformsconfigurewill first check for the OSlibffiand then fall back to the same processing as other platforms if it is not found.gh-88267: Avoid exporting Python symbols in linked Windows applications when the core is built as static.
bpo-41916: Allow override of ac_cv_cxx_thread so that cross compiled python can set -pthread for CXX.
Windows¶
gh-100180: Update Windows installer to OpenSSL 1.1.1s
gh-99191: Use
_MSVC_LANG >= 202002Linstead of less-precise_MSC_VER >=1929to more accurately test for C++20 support inPC/_wmimodule.cpp.gh-79218: Define
MS_WIN64for Mingw-w64 64bit, fix cython compilation failure.gh-99941: Ensure that
asyncio.Protocol.data_received()receives an immutablebytesobject (as documented), instead ofbytearray.bpo-43984:
winreg.SetValueEx()now leaves the target value untouched in the case of conversion errors. Previously,-1would be written in case of such errors.bpo-34816:
hasattr(ctypes.windll, 'nonexistant')now returnsFalseinstead of raisingOSError.
macOS¶
Tools/Demos¶
bpo-45256: Fix a bug that caused an
AttributeErrorto be raised inpython-gdb.pywhenpy-localsis used without a frame.gh-100342: Add missing
NULLcheck for possible allocation failure in*argsparsing in Argument Clinic.
C API¶
gh-99947: Raising SystemError on import will now have its cause be set to the original unexpected exception.
gh-99240: In argument parsing, after deallocating newly allocated memory, reset its pointer to NULL.
gh-98724: The
Py_CLEAR,Py_SETREFandPy_XSETREFmacros now only evaluate their arguments once. If an argument has side effects, these side effects are no longer duplicated. Patch by Victor Stinner.
Python 3.12.0 alpha 3¶
Release date: 2022-12-06
Security¶
gh-100001:
python -m http.serverno longer allows terminal control characters sent within a garbage request to be printed to the stderr server log.This is done by changing the
http.serverBaseHTTPRequestHandler.log_messagemethod to replace control characters with a\xHHhex escape before printing.gh-87604: Avoid publishing list of active per-interpreter audit hooks via the
gcmodule
Core and Builtins¶
gh-99891: Fix a bug in the tokenizer that could cause infinite recursion when showing syntax warnings that happen in the first line of the source. Patch by Pablo Galindo
gh-91054: Add
PyCode_AddWatcher()andPyCode_ClearWatcher()APIs to register callbacks to receive notification on creation and destruction of code objects.gh-99729: Fix an issue that could cause frames to be visible to Python code as they are being torn down, possibly leading to memory corruption or hard crashes of the interpreter.
gh-99708: Fix bug where compiler crashes on an if expression with an empty body block.
gh-99578: Fix a reference bug in
_imp.create_builtin()after the creation of the first sub-interpreter for modulesbuiltinsandsys. Patch by Victor Stinner.gh-99581: Fixed a bug that was causing a buffer overflow if the tokenizer copies a line missing the newline character from a file that is as long as the available tokenizer buffer. Patch by Pablo galindo
gh-99553: Fix bug where an
ExceptionGroupsubclass can wrap aBaseException.
Library¶
Core and Builtins¶
gh-99377: Add audit events for thread creation and clear operations.
gh-98686: Remove the
BINARY_OP_GENERICandCOMPARE_OP_GENERIC“specializations”.gh-99298: Remove the remaining error paths for attribute specializations, and refuse to specialize attribute accesses on types that haven’t had
PyType_Ready()called on them yet.gh-99127: Allow some features of
syslogto the main interpreter only. Patch by Donghee Na.gh-91053: Optimizing interpreters and JIT compilers may need to invalidate internal metadata when functions are modified. This change adds the ability to provide a callback that will be invoked each time a function is created, modified, or destroyed.
gh-90994: Improve error messages when there’s a syntax error with call arguments. The following three cases are covered: - No value is assigned to a named argument, eg
foo(a=). - A value is assigned to a star argument, egfoo(*args=[0]). - A value is assigned to a double-star keyword argument, egfoo(**kwarg={'a': 0}).bpo-45026: Optimize the
rangeobject iterator. It is now smaller, faster iteration of ranges containing large numbers. Smaller pickles, faster unpickling.bpo-31718: Raise
ValueErrorinstead ofSystemErrorwhen methods of uninitializedio.IncrementalNewlineDecoderobjects are called. Patch by Oren Milman.bpo-38031: Fix a possible assertion failure in
io.FileIOwhen the opener returns an invalid file descriptor.
Library¶
gh-100001: Also escape s in the http.server BaseHTTPRequestHandler.log_message so that it is technically possible to parse the line and reconstruct what the original data was. Without this a xHH is ambiguous as to if it is a hex replacement we put in or the characters r”x” came through in the original request line.
gh-99957: Add
frozen_defaultparameter totyping.dataclass_transform().gh-79033: Fix
asyncio.Server.wait_closed()to actually do what the docs promise – wait for all existing connections to complete, after closing the server.gh-51524: Fix bug when calling trace.CoverageResults with valid infile.
gh-99645: Fix a bug in handling class cleanups in
unittest.TestCase. NowaddClassCleanup()uses separate lists for differentTestCasesubclasses, anddoClassCleanups()only cleans up the particular class.gh-99508: Fix
TypeErrorinLib/importlib/_bootstrap_external.pywhile calling_imp.source_hash().gh-66285: Fix
asyncioto not share event loop and signal wakeupfd in forked processes. Patch by Kumar Aditya.gh-97001: Release the GIL when calling termios APIs to avoid blocking threads.
gh-92647: Use final status of an enum to determine lookup or creation branch of functional API.
gh-99388: Add loop_factory parameter to
asyncio.run()to allow specifying a custom event loop factory. Patch by Kumar Aditya.gh-99341: Fix
ast.increment_lineno()to also coverast.TypeIgnorewhen changing line numbers.gh-99382: Check the number of arguments in substitution in user generics containing a
TypeVarTupleand one or moreTypeVar.gh-99379: Fix substitution of
ParamSpecfollowed byTypeVarTuplein generic aliases.gh-99344: Fix substitution of
TypeVarTupleandParamSpectogether in user generics.gh-99284: Remove
_use_broken_old_ctypes_structure_semantics_old untested and undocumented hack fromctypes.gh-99201: Fix
IndexErrorwhen initializing the config variables on Windows ifHAVE_DYNAMIC_LOADINGis not set.gh-99240: Fix double-free bug in Argument Clinic
str_converterby extracting memory clean up to a newpost_parsingsection.gh-64490: Fix refcount error when arguments are packed to tuple in Argument Clinic.
gh-99029:
pathlib.PurePath.relative_to()now treats naked Windows drive paths as relative. This brings its behaviour in line with other parts of pathlib.gh-98253: The implementation of the typing module is now more resilient to reference leaks in binary extension modules.
Previously, a reference leak in a typed C API-based extension module could leak internals of the typing module, which could in turn introduce leaks in essentially any other package with typed function signatures. Although the typing package is not the original source of the problem, such non-local dependences exacerbate debugging of large-scale projects, and the implementation was therefore changed to reduce harm by providing better isolation.
gh-98458: Fix infinite loop in unittest when a self-referencing chained exception is raised
gh-93453:
asyncio.get_event_loop()and many otherasynciofunctions likeasyncio.ensure_future(),asyncio.shield()orasyncio.gather(), and also theget_event_loop()method ofasyncio.BaseDefaultEventLoopPolicynow raise aRuntimeErrorif called when there is no running event loop and the current event loop was not set. Previously they implicitly created and set a new current event loop.DeprecationWarningis no longer emitted if there is no running event loop but the current event loop was set.gh-97966: On
os.uname_result, restored expectation that_fieldsand_asdictwould include all six properties includingprocessor.gh-98248: Provide informative error messages in
struct.pack()when its integral arguments are not in range.gh-98108:
zipfile.Pathis now pickleable if its initialization parameters were pickleable (e.g. for file system paths).gh-98098: Created packages from zipfile and test_zipfile modules, separating
zipfile.Pathfunctionality.gh-82836: Fix
is_privateproperties in theipaddressmodule. Previously non-private networks (0.0.0.0/0) would returnTruefrom this method; now they correctly returnFalse.gh-96828: Add an
OP_ENABLE_KTLSoption for enabling the use of the kernel TLS (kTLS). Patch by Illia Volochii.gh-88863: To avoid apparent memory leaks when
asyncio.open_connection()raises, break reference cycles generated by local exception and future instances (which has exception instance as its member var). Patch by Dong Uk, Kang.gh-91078:
TarFile.next()now returnsNonewhen called on an empty tarfile.bpo-47220: Document the optional callback parameter of
WeakMethod. Patch by Géry Ogam.bpo-44817: Ignore WinError 53 (ERROR_BAD_NETPATH), 65 (ERROR_NETWORK_ACCESS_DENIED) and 161 (ERROR_BAD_PATHNAME) when using ntpath.realpath().
bpo-41260: Rename the fmt parameter of the pure Python implementation of
datetime.date.strftime()to format.bpo-15999: All built-in functions now accept arguments of any type instead of just
boolandintfor boolean parameters.
Documentation¶
gh-99931: Use sphinxext-opengraph to generate OpenGraph metadata.
gh-89682: Reworded docstring of the default
__contains__to clarify that it returns abool.gh-88330: Improved the description of what a resource is in importlib.resources docs.
gh-92892: Document that calling variadic functions with ctypes requires special care on macOS/arm64 (and possibly other platforms).
bpo-41825: Restructured the documentation for the
os.wait*family of functions, and improved the docs foros.waitid()with more explanation of the possible argument constants.
Tests¶
gh-99892: Skip test_normalization() of test_unicodedata if it fails to download NormalizationTest.txt file from pythontest.net. Patch by Victor Stinner.
gh-99934: Correct test_marsh on (32 bit) x86: test_deterministic sets was failing.
gh-99741: We’ve implemented multi-phase init (PEP 489/630/687) for the internal (for testing) _xxsubinterpreters module.
gh-99659: Optional big memory tests in
test_sqlite3now catch the correctsqlite.DataErrorexception type in case of too large strings and/or blobs passed.gh-99593: Cover the Unicode C API with tests.
gh-96002: Add functional test for Argument Clinic.
Build¶
gh-99086: Fix
-Wimplicit-int,-Wstrict-prototypes, and-Wimplicit-function-declarationcompiler warnings in configure checks.gh-99337: Fix a compilation issue with GCC 12 on macOS.
gh-99289: Add a
COMPILEALL_OPTSvariable in Makefile to overridecompilealloptions (default:-j0) inmake install. Also merged thecompileallcommands into a single command building .pyc files for the all optimization levels (0, 1, 2) at once. Patch by Victor Stinner.gh-98872: Fix a possible fd leak in
Programs/_freeze_module.cintroduced in Python 3.11.gh-88226: Always define
TARGET_*labels inPython/ceval.c, even ifUSE_COMPUTED_GOTOSis disabled. This allows breakpoints to be set at those labels in (for instance)gdb.
Windows¶
gh-99345: Use faster initialization functions to detect install location for Windows Store package
gh-98629: Fix initialization of
sys.versionandsys._giton Windowsgh-99442: Fix handling in Python Launcher for Windows when
argv[0]does not include a file extension.bpo-40882: Fix a memory leak in
multiprocessing.shared_memory.SharedMemoryon Windows.
macOS¶
Tools/Demos¶
gh-64490: Argument Clinic varargs bugfixes
Fix out-of-bounds error in
_PyArg_UnpackKeywordsWithVararg().Fix incorrect check which allowed more than one varargs in clinic.py.
Fix miscalculation of
noptargsin generated code.Do not generate
noptargswhen there is a vararg argument and no optional argument.
C API¶
gh-98680:
PyBUF_*constants were marked as part of Limited API of Python 3.11+. These were available in 3.11.0 withPy_LIMITED_APIdefined for 3.11, and are necessary to use the buffer API.gh-99612: Fix
PyUnicode_DecodeUTF8Stateful()for ASCII-only data:*consumedwas not set.gh-47146: The
structmember.hheader is deprecated. Its non-deprecated contents are now available just by includingPython.h, with aPy_prefix added if it was missing. (Deprecated contents areT_OBJECT,T_NONE, and no-op flags.) Patch by Petr Viktorin, based on earlier work by Alexander Belopolsky and Matthias Braun.
Python 3.12.0 alpha 2¶
Release date: 2022-11-14
Security¶
gh-98433: The IDNA codec decoder used on DNS hostnames by
socketorasynciorelated name resolution functions no longer involves a quadratic algorithm. This prevents a potential CPU denial of service if an out-of-spec excessive length hostname involving bidirectional characters were decoded. Some protocols such asurllibhttp3xxredirects potentially allow for an attacker to supply such a name.Individual labels within an IDNA encoded DNS name will now raise an error early during IDNA decoding if they are longer than 1024 unicode characters given that each decoded DNS label must be 63 or fewer characters and the entire decoded DNS name is limited to 255. Only an application presenting a hostname or label consisting primarily of RFC 3454 section 3.1 “Nothing” characters to be removed would run into of this new limit. See also RFC 5894 section 6 and RFC 3491.
gh-98739: Update bundled libexpat to 2.5.0
Core and Builtins¶
gh-81057: The docs clearly say that
PyImport_Inittab,PyImport_AppendInittab(), andPyImport_ExtendInittab()should not be used afterPy_Initialize()has been called. We now enforce this for the two functions. Additionally, the runtime now uses an internal copy ofPyImport_Inittab, to guard against modification.gh-99298: Fix an issue that could potentially cause incorrect error handling for some bytecode instructions.
gh-99254: The compiler now removes all unused constants from code objects (except the first one, which may be a docstring).
gh-99205: Fix an issue that prevented
PyThreadStateandPyInterpreterStatememory from being freed properly.gh-81057: The 18 global C variables holding the state of the allocators have been moved to
_PyRuntimeState. This is a strictly internal change with no change in behavior.gh-99181: Fix failure in
except*with unhashable exceptions.gh-99204: Fix calculation of
sys._base_executablewhen inside a POSIX virtual environment using copies of the python binary when the base installation does not provide the executable name used by the venv. Calculation will fall back to alternative names (“python<MAJOR>”, “python<MAJOR>.<MINOR>”).gh-96055: Update
faulthandlerto emit an error message with the proper unexpected signal number. Patch by Donghee Na.gh-99153: Fix location of
SyntaxErrorfor atryblock with bothexceptandexcept*.gh-98686: Merge the adaptive opcode logic into each instruction’s unquickened variant, and merge the logic in
EXTENDED_ARG_QUICKintoEXTENDED_ARG. With these changes, the quickening that happens at code object creation is now only responsible for initializing warmup counters and inserting superinstructions.gh-99103: Fix the error reporting positions of specialized traceback anchors when the source line contains Unicode characters.
gh-99139: Improve the error suggestion for
NameErrorexceptions for instances. Now if aNameErroris raised in a method and the instance has an attribute that’s exactly equal to the name in the exception, the suggestion will includeself.<NAME>instead of the closest match in the method scope. Patch by Pablo Galindogh-98401: Octal escapes with value larger than
0o377(ex:"\477"), deprecated in Python 3.11, now produce aSyntaxWarning, instead ofDeprecationWarning. In a future Python version they will be eventually aSyntaxError. Patch by Victor Stinner.gh-98401: A backslash-character pair that is not a valid escape sequence now generates a
SyntaxWarning, instead ofDeprecationWarning. For example,re.compile("\d+\.\d+")now emits aSyntaxWarning("\d"is an invalid escape sequence), use raw strings for regular expression:re.compile(r"\d+\.\d+"). In a future Python version,SyntaxErrorwill eventually be raised, instead ofSyntaxWarning. Patch by Victor Stinner.gh-96793: Handle StopIteration and StopAsyncIteration raised in generator or coroutines in the bytecode, rather than in wrapping C code.
gh-98931: Improve the
SyntaxErrorerror message when the user typesimport x from yinstead offrom y import x. Patch by Pablo Galindogh-98852: Fix subscription of type aliases containing bare generic types or types like
TypeVar: for exampletuple[A, T][int]andtuple[TypeVar, T][int], whereAis a generic type, andTis a type variable.gh-98925: Lower the recursion depth for marshal on WASI to support (in-development) wasmtime 2.0.
gh-98783: Fix multiple crashes in debug mode when
strsubclasses are used instead ofstritself.gh-98811: Use complete source locations to simplify detection of
__future__imports which are not at the beginning of the file. Also corrects the offset in the exception raised in one case, which was off by one and impeded highlighting.gh-96793: Add specialization of
FOR_ITERfor generators. Saves multiple layers of dispatch and checking to get from theFOR_ITERinstruction in the caller to theRESUMEin the generator.gh-98586: Added the methods
PyObject_Vectorcall()andPyObject_VectorcallMethod()to the Limited API along with the auxiliary macro constantPY_VECTORCALL_ARGUMENTS_OFFSET.The availability of these functions enables more efficient PEP 590 vector calls from binary extension modules that avoid argument boxing/unboxing overheads.
gh-99257: Fix an issue where member descriptors (such as those for
__slots__) could behave incorrectly or crash instead of raising aTypeErrorwhen accessed via an instance of an invalid type.gh-93143: Rather than changing
co_code, the interpreter will now display aRuntimeWarningand assignNoneto any fast locals that are left unbound after jumps ordelstatements executed while tracing.gh-96421: When calling into Python code from C code, through
PyEval_EvalFrameEx()or a related C-API function, a shim frame in inserted into the call stack. This occurs in the_PyEval_EvalFrameDefault()function. The extra frame should be invisible to all Python and most C extensions, but out-of-process profilers and debuggers need to be aware of it. These shim frames can be detected by checkingframe->owner == FRAME_OWNED_BY_CSTACK.Extensions implementing their own interpreters using PEP 523 need to be aware of this shim frame and the changes to the semantics of
RETURN_VALUE,YIELD_VALUE, andRETURN_GENERATOR, which now clear the frame.
Build¶
Core and Builtins¶
gh-98686: Quicken all code objects, and specialize adaptive bytecode instructions more aggressively.
gh-92119: Print exception class name instead of its string representation when raising errors from
ctypescalls.gh-91058:
ImportErrorraised from failedfrom <module> import <name>now include suggestions for the value of<name>based on the available names in<module>. Patch by Pablo Galindogh-96793: The
FOR_ITERnow leaves the iterator on the stack on termination of the loop. This is to assist specialization of loops for generators.gh-90716: Add _pylong.py module. It includes asymptotically faster algorithms that can be used for operations on integers with many digits. It is used by longobject.c to speed up some operations.
gh-95389: Expose
ETH_P_ALLand some of the ETHERTYPE_* constants insocket. Patch by Noam Cohen.
Library¶
gh-93696: Allow
pdbto locate source for frozen modules in the standard library.gh-99418: Fix bug in
urllib.parse.urlparse()that causes URL schemes that begin with a digit, a plus sign, or a minus sign to be parsed incorrectly.gh-94597: Deprecate
asyncio.AbstractChildWatcherto be removed in Python 3.14. Patch by Kumar Aditya.gh-99305: Improve performance of
secrets.token_hex().gh-74044: Fixed bug where
inspect.signature()reported incorrect arguments for decorated methods.gh-99275: Fix
SystemErrorinctypeswhen exception was not set during__initsubclass__.gh-99277: Remove older version of
_SSLProtocolTransport.get_write_buffer_limitsinasyncio.sslprotogh-99248: fix negative numbers failing in verify()
gh-99155: Fix
statistics.NormalDistpickle with0and1protocols.gh-93464:
enum.auto()is now correctly activated when combined with other assignment values. E.g.ONE = auto(), 'some text'will now evaluate as(1, 'some text').gh-99134: Update the bundled copy of pip to version 22.3.1.
gh-92584: Remove the
distutilspackage. It was deprecated in Python 3.10 by PEP 632 “Deprecate distutils module”. For projects still usingdistutilsand cannot be updated to something else, thesetuptoolsproject can be installed: it still providesdistutils. Patch by Victor Stinner.gh-98999: Now
_pyiois consistent with_ioin raisingValueErrorwhen executing methods over closed buffers.gh-83004: Clean up refleak on failed module initialisation in
_zoneinfogh-83004: Clean up refleaks on failed module initialisation in
_picklegh-83004: Clean up refleak on failed module initialisation in
_io.gh-98897: Fix memory leak in
math.dist()when both points don’t have the same dimension. Patch by Kumar Aditya.gh-98878: Use the frame bound builtins when offering a name suggestion in
tracebackto prevent crashing when__builtins__is not a dict.gh-98139: In
importlib._bootstrap, enhance namespace package repr to<module 'x' (namespace) from ['path']>.gh-90352: Fix
_SelectorDatagramTransportto inherit fromDatagramTransportinasyncio. Patch by Kumar Aditya.gh-98793: Fix argument typechecks in
_overlapped.WSAConnect()and_overlapped.Overlapped.WSASendTo()functions.gh-98744: Prevent crashing in
tracebackwhen retrieving the byte-offset for some source files that contain certain unicode characters.gh-98740: Fix internal error in the
remodule which in very rare circumstances prevented compilation of a regular expression containing a conditional expression without the “else” branch.gh-98703: Fix
asyncio.StreamWriter.drain()to callprotocol.connection_lostcallback only once on Windows.gh-98624: Add a mutex to unittest.mock.NonCallableMock to protect concurrent access to mock attributes.
gh-98658: The
array.arrayclass now supports subscripting, making it a generic type.gh-98284: Improved
TypeErrormessage for undefined abstract methods of aabc.ABCinstance. The names of the missing methods are surrounded by single-quotes to highlight them.gh-96151: Allow
BUILTINSto be a valid field name for frozen dataclasses.gh-98086: Make sure
patch.dict()can be applied on async functions.gh-72719: Remove modules
asyncoreandasynchat, which were deprecated by PEP 594.gh-96192: Fix handling of
bytespath-like objects inos.ismount().gh-94172:
ftplib: Remove theFTP_TLS.ssl_versionclass attribute: use the context parameter instead. Patch by Victor Stinnergh-94172: Remove the keyfile and certfile parameters from the
ftplib,imaplib,poplibandsmtplibmodules, and the key_file, cert_file and check_hostname parameters from thehttp.clientmodule, all deprecated since Python 3.6. Use the context parameter (ssl_context inimaplib) instead. Patch by Victor Stinner.gh-83638: Add the
autocommitattribute tosqlite3.Connectionand the autocommit parameter tosqlite3.connect()to control PEP 249-compliant transaction handling. Patch by Erlend E. Aasland.gh-92452: Fixed a race condition that could cause
sysconfig.get_config_var()to incorrectly returnNonein multi-threaded programs.gh-91803: Fix an error when using a method of objects mocked with
unittest.mock.create_autospec()after it was sealed withunittest.mock.seal()function.bpo-38523:
shutil.copytree()now applies the ignore_dangling_symlinks argument recursively.bpo-40358: Add walk_up argument in
pathlib.PurePath.relative_to().bpo-36267: Fix IndexError in
argparse.ArgumentParserwhen astore_trueaction is given an explicit argument.
Documentation¶
gh-98832: Changes wording of docstring for
pathlib.Path.iterdir().gh-97966: Update uname docs to clarify the special nature of the platform attribute and to indicate when it became late-bound.
Tests¶
gh-98903: The Python test suite now fails with exit code 4 if no tests ran. It should help detecting typos in test names and test methods.
gh-98713: Fix a bug in the
typingtests where a test relying on CPython-specific implementation details was not decorated with@cpython_onlyand was not skipped on other implementations.gh-87390: Add tests for star-unpacking with PEP 646, and some other miscellaneous PEP 646 tests.
gh-96853: Added explicit coverage of
Py_Initialize(and hencePy_InitializeEx) back to the embedding tests (all other embedding tests migrated toPy_InitializeFromConfigin Python 3.11)bpo-34272: Some C API tests were moved into the new Lib/test/test_capi/ directory.
Build¶
gh-99086: Fix
-Wimplicit-intcompiler warning in configure check forPTHREAD_SCOPE_SYSTEM.gh-99016: Fix build with
PYTHON_FOR_REGEN=python3.8.gh-97731: Specify the full path to the source location for
make docclean(needed for cross-builds).gh-98949: Drop unused build dependency on
readelf.gh-98989: Use
python3.11, if available, for regeneration and freezing.gh-98831: Add new tooling, in
Tools/cases_generator, to generate the interpreter switch statement from a list of opcode definitions. This only affects adding, modifying or removing instruction definitions. The instruction definitions now live inPython/bytecodes.c, in the form of a custom DSL (under development). The tooling reads this file and writesPython/generated_cases.c.h, which is then included byPython/ceval.cto provide most of the cases of the main interpreter switch.gh-98817: Remove PCbuild/lib.pyproj: it’s not used for anything, is only a minor convenience for Visual Studio users (who probably mostly don’t even know about it), and it takes a lot of maintenance effort to keep updated.
gh-98776: Fix
make regen-test-levenshteinfor out-of-tree builds.gh-98707: Don’t use vendored
libmpdecheaders if--with-system-libmpdecis passed to configure. Don’t use vendoredlibexpatheaders if--with-system-expatis passed to configure.
Windows¶
gh-98689: Update Windows builds to zlib v1.2.13. v1.2.12 has CVE 2022-37434, but the vulnerable
inflateGetHeaderAPI is not used by Python.gh-98790: Assumes that a missing
DLLsdirectory means that standard extension modules are in the executable’s directory.gh-98745: Update
py.exelauncher to install 3.11 by default and 3.12 on request.gh-98692: Fix the Python Launcher for Windows ignoring unrecognized shebang lines instead of treating them as local paths
gh-94328: Update Windows installer to use SQLite 3.39.4.
macOS¶
gh-94328: Update macOS installer to SQLite 3.39.4.
C API¶
gh-98724: The
Py_CLEAR,Py_SETREFandPy_XSETREFmacros now only evaluate their argument once. If the argument has side effects, these side effects are no longer duplicated. Patch by Victor Stinner.gh-98978: Fix use-after-free in
Py_SetPythonHome(NULL),Py_SetProgramName(NULL)and_Py_SetProgramFullPath(NULL)function calls. Issue reported by Benedikt Reinartz. Patch by Victor Stinner.gh-98410: Add
getbufferprocandreleasebufferprocto the stable API.gh-98610: Some configurable capabilities of sub-interpreters have changed. They always allow subprocesses (
subprocess) now, whereas before subprocesses could be optionally disallowed for a sub-interpreter. Insteados.exec()can now be disallowed. Disallowing daemon threads is now supported. Disallowing all threads is still allowed, but is never done by default. Note that the optional restrictions are only available through_Py_NewInterpreterFromConfig(), which isn’t a public API. They do not affect the main interpreter, norPy_NewInterpreter().gh-98608: A
_PyInterpreterConfighas been added and_Py_NewInterpreter()has been renamed to_Py_NewInterpreterFromConfig(). The “isolated_subinterpreters” argument is now a granular config that captures the previous behavior. Note that this is all “private” API.gh-96853:
Py_InitializeExnow correctly callsPyConfig_Clearafter initializing the interpreter (the omission didn’t cause a memory leak only because none of the dynamically allocated config fields are populated by the wrapper function)gh-91248: Add
PyFrame_GetVar()andPyFrame_GetVarString()functions to get a frame variable by its name. Patch by Victor Stinner.
Python 3.12.0 alpha 1¶
Release date: 2022-10-25
Security¶
gh-97616: Fix multiplying a list by an integer (
list *= int): detect the integer overflow when the new allocated length is close to the maximum size. Issue reported by Jordan Limor. Patch by Victor Stinner.gh-97514: On Linux the
multiprocessingmodule returns to using filesystem backed unix domain sockets for communication with the forkserver process instead of the Linux abstract socket namespace. Only code that chooses to use the “forkserver” start method is affected.Abstract sockets have no permissions and could allow any user on the system in the same network namespace (often the whole system) to inject code into the multiprocessing forkserver process. This was a potential privilege escalation. Filesystem based socket permissions restrict this to the forkserver process user as was the default in Python 3.8 and earlier.
This prevents Linux CVE 2022-42919.
gh-87389:
http.server: Fix an open redirection vulnerability in the HTTP server when an URI path starts with//. Vulnerability discovered, and initial fix proposed, by Hamza Avvan.gh-79096: LWPCookieJar and MozillaCookieJar create files with file mode 600 instead of 644 (Microsoft Windows is not affected)
gh-92888: Fix
memoryviewuse after free when accessing the backing buffer in certain cases.gh-68966: The deprecated mailcap module now refuses to inject unsafe text (filenames, MIME types, parameters) into shell commands. Instead of using such text, it will warn and act as if a match was not found (or for test commands, as if the test failed).
Core and Builtins¶
gh-98374: Suppress ImportError for invalid query for help() command. Patch by Donghee Na.
gh-98461: Fix source location in bytecode for list, set and dict comprehensions as well as generator expressions.
gh-98354: Added unicode check for
nameattribute ofspecargument passed in_imp.create_builtin()function.gh-98398: Fix source location of ‘assert’ bytecodes.
gh-98390: Fix location of sub-expressions of boolean expressions, by reducing their scope to that of the sub-expression.
gh-98254: Modules from the standard library are now potentially suggested as part of the error messages displayed by the interpreter when an
NameErroris raised to the top level. Patch by Pablo Galindogh-97997: Add running column offset to the tokenizer state to avoid calculating AST column information with pointer arithmetic.
gh-97973: Modify the tokenizer to return all necessary information the parser needs to set location information in the AST nodes, so that the parser does not have to calculate those doing pointer arithmetic.
Library¶
gh-96078:
os.sched_yield()now release the GIL while calling sched_yield(2). Patch by Donghee Na.
Core and Builtins¶
gh-97912: The compiler now avoids quadratic behavior when finding which instructions should use the
LOAD_FAST_CHECKopcode.gh-97002: Fix an issue where several frame objects could be backed by the same interpreter frame, possibly leading to corrupted memory and hard crashes of the interpreter.
gh-97943: Bugfix:
PyFunction_GetAnnotations()should return a borrowed reference. It was returning a new reference.gh-97922: The Garbage Collector now runs only on the eval breaker mechanism of the Python bytecode evaluation loop instead on object allocations. The GC can also run when
PyErr_CheckSignals()is called so C extensions that need to run for a long time without executing any Python code also have a chance to execute the GC periodically.gh-65961: When
__package__is different than__spec__.parent, raise aDeprecationWarninginstead ofImportWarning.Also remove
importlib.util.set_package()which was scheduled for removal.gh-97850: Long deprecated,
module_repr()should now be completely eradicated.gh-86298: In cases where
warnings.warn_explicit()consults the module’s loader, anDeprecationWarningis issued whenm.__loader__differs fromm.__spec__.loader.gh-97779: Ensure that all Python frame objects are backed by “complete” frames.
gh-91052: Add API for subscribing to modification events on selected dictionaries.
gh-97752: Fix possible data corruption or crashes when accessing the
f_backmember of newly-created generator or coroutine frames.gh-97591: Fixed a missing incref/decref pair in
Exception.__setstate__(). Patch by Ofey Chan.gh-97670: Remove the
sys.getdxp()function and theTools/scripts/analyze_dxp.pyscript. DXP stands for “dynamic execution pairs”. They were related toDYNAMIC_EXECUTION_PROFILEandDXPAIRSmacros which have been removed in Python 3.11. Python can now be built with./configure --enable-pystatsto gather statistics on Python opcodes. Patch by Victor Stinner.gh-94526: Fix the Python path configuration used to initialized
sys.pathat Python startup. Paths are no longer encoded to UTF-8/strict to avoid encoding errors if it contains surrogate characters (bytes paths are decoded with the surrogateescape error handler). Patch by Victor Stinner.gh-96670: The parser now raises
SyntaxErrorwhen parsing source code containing null bytes. Patch by Pablo Galindogh-96975: Fix a crash occurring when