Skip to content

del sqlite3.Connection.autocommit crashes #156100

Description

@serhiy-storchaka

Crash report

import sqlite3
cx = sqlite3.connect(":memory:")
del cx.autocommit

set_autocommit() in Modules/_sqlite/connection.c passes the value to autocommit_converter(), which dereferences it in Py_IsTrue().
Deleting row_factory and text_factory of a connection is already rejected with an AttributeError (gh-149738); autocommit should be rejected too.

The same code is in 3.13, 3.14 and 3.15.

Linked PRs

Activity

  1. added
    type-crashA hard crash of the interpreter, possibly with a core dump
    3.13only security fixes
    3.14bugs and security fixes
    on Aug 20, 2026
  2. added
    3.15bugs and security fixes
    3.16new features, bugs and security fixes
    on Aug 20, 2026
  3. serhiy-storchaka commented on Aug 20, 2026

    @serhiy-storchaka
    MemberAuthor

    The same converter has a second bug: autocommit_converter() compares the result of PyLong_AsLong() with LEGACY_TRANSACTION_CONTROL, which is -1, the value returned on error.

    cx.autocommit = 2**1000

    is therefore accepted as LEGACY_TRANSACTION_CONTROL with OverflowError set, and the interpreter continues with a pending exception.
    GH-156104 fixes both.

  4. added a commit that references this issue on Aug 21, 2026
  5. added 2 commits that reference this issue on Aug 21, 2026
  6. added a commit that references this issue on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.13only security fixes3.14bugs and security fixes3.15bugs and security fixes3.16new features, bugs and security fixesextension-modulesC modules in the Modules dirtopic-sqlite3type-crashA hard crash of the interpreter, possibly with a core dump

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions