Skip to content

Support Python 3.15 #306

Description

@dataflake

Look through the change log of Python 3.15 (once the first release candidate version is released end of July 2026 (see https://peps.python.org/pep-0790/) for potential issues which need to be handled by RestrictedPython to prevent access to otherwise forbidden data/objects.

There is no need to support new language features of Python 3.15 right now, let's see how they evolve after they can be used,

Open tasks:

  • make package installable and fix tests
  • Change log: Allow to use the package with Python 3.15 -- Caution: No security audit has been done so far.
  • cut an alpha dev release
  • security audit after rc1 Python release (detailed instructions)
  • Prepare for a new Python version after its rc1 release (detailed instructions)
  • Create a copy of this ticket for Python 3.16 (first alpha is expected to land late 2026)

Activity

  1. assigned and unassigned on May 27, 2026
  2. icemac commented on Aug 18, 2026

    @icemac
    Member

    The security audit of the Python 3.15 changes (based on 3.15.0rc1) is done; the result is in PR #328. Full rationale: docs/contributing/changes_from314to315.rst.

    Findings requiring action:

    • Lazy imports (PEP 810) compiled silently: they add no new AST node, only a new is_lazy field on Import/ImportFrom, so the default-deny generic_visit did not catch them. At run time they resolve through the new __lazy_import__ builtin instead of __import__, bypassing a guarded __import__. → now explicitly disallowed.
    • Unpacking in comprehensions (PEP 798) compiled silently (reuses the existing Starred node resp. a DictComp without value) and fully executed when guards are provided. The unpacked value is iterated without calling _getiter_, unlike the equivalent nested comprehension. → now explicitly disallowed.
    • Reviewing INSPECT_ATTRIBUTES for the new 3.15 attributes revealed that the async-generator attributes ag_await/ag_frame/ag_code were missing entirely → now blocked. The new gi_state/cr_state/ag_state attributes only return state strings and stay accessible (like gi_running).

    Checked, no action needed: unary + in match patterns (match is denied anyway); new builtins frozendict/sentinel (allow-list); removed ast.Num/Str/Bytes/NameConstant/Ellipsis (unused); compile()/ast.parse() module parameter.

    Remaining after the 3.15.0 final release (October 2026): drop pip_pre = py315: true from tox.ini and move the sdist/wheel build job in tests.yml from py314 to py315.

    — Comment created by Claude

  3. icemac commented on Aug 19, 2026

    @icemac
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions