From aa67ae78792faedeee9cb42bc5da9729a0697dda Mon Sep 17 00:00:00 2001 From: Denis Ledoux Date: Wed, 10 Apr 2024 14:27:36 +0200 Subject: [PATCH] [FIX] tools: safe_eval._UNSAFE_ATTRIBUTES as a list `_UNSAFE_ATTRIBUTES` was changed from a `list` to a `set` in odoo/odoo#151989. odoo/odoo@cde278159184edc35ee195a8093c9fc55b47f11a Reset it to a `list` as before, by retro-compatibility concerns, in case developers used features not working on `set`. For instance: - `_UNSAFE_ATTRIBUTES.append` - `_UNSAFE_ATTRIBUTES.extend` - `_UNSAFE_ATTRIBUTES + ['foo']` The opportunity is taken to add `_co_code_adaptive`, which is a new attribute added from Python 3.11, hence available from Ubuntu Noble. Firstly added as `_co_quickened` in https://github.com/python/cpython/commit/001eb520b5757294dc455c900d94b7b153de6cdd Then renamed to `_co_code_adaptive` in https://github.com/python/cpython/commit/2bde6827ea4f136297b2d882480b981ff26262b6 The opportunity is also taken to move `mro` out of the `Python 2 functions` section, as `mro` is available in Python 3, hence making the comment confusing. Part-of: odoo/odoo#151989 --- odoo/tools/safe_eval.py | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/odoo/tools/safe_eval.py b/odoo/tools/safe_eval.py index 72590f73d1a..9973627276d 100644 --- a/odoo/tools/safe_eval.py +++ b/odoo/tools/safe_eval.py @@ -50,13 +50,15 @@ for module in _ALLOWED_MODULES: __import__(module) -_UNSAFE_ATTRIBUTES = { +_UNSAFE_ATTRIBUTES = [ # Frames 'f_builtins', 'f_code', 'f_globals', 'f_locals', # Python 2 functions - 'func_code', 'func_globals', 'mro', + 'func_code', 'func_globals', # Code object - 'co_code', + 'co_code', '_co_code_adaptive', + # Method resolution order, + 'mro', # Tracebacks 'tb_frame', # Generators @@ -65,8 +67,7 @@ _UNSAFE_ATTRIBUTES = { 'cr_await', 'cr_code', 'cr_frame', # Coroutine generators 'ag_await', 'ag_code', 'ag_frame', - -} +] def to_opcodes(opnames, _opmap=opmap):