danzin
Brazilian (experienced) hobbyist Pythonista. Pythonista amador (experiente).
#python
He/him/ele
There's another researcher, Zhengyu Liu, who's been finding CPython crashes (mostly use-after-free) at breakneck speed (19 in 5 days!): https://github.com/python/cpython/issues?q=is%3Aissue%20author%3Ajackfromeast
Not sure about what technique they're using, but their site states they they favor "leveraging program analysis approaches to detect/exploit/patch vulnerabilities in real-world complex applications and systems".
Their reports are comprehensive, with great presentation and details.
Comprei passagens e reservei hotel para a Python Brasil 2026 @pythonbrasil@pynews.com.br.
Tudo, desde o ingresso até as passagens, cancelável, pois ninguém sabe o dia de amanhã.
Vontade enorme de dar uma palestra, mas não sei se o meu psicológico aguenta. Acho que conseguiria fazer, mas o estresse e a ressaca depois não sei se vale a pena. Talvez uma lightning talk seja mais tranquilo de fazer.
Espero que o @villares@ciberlandia.pt consiga ir.
Joana Francesa, música que o Chico escreveu com palavras em francês e significados em português, ou o contrário.
Sempre adorei essa música, surpreso que ninguém tenha citado ainda.
Historically, automated bug-finding tools have a bad habit of producing high-noise findings (and now worse: convincing AI slop) that just wastes maintainer time.
I built cext-review-toolkit using multiple specialized agents to find bugs, and I try to reproduce every finding from pure Python before reporting it.
Human review + pure-Python reproducers act as a necessary filter against false positives.
I've created a CPython umbrella issue for C bugs found with a new tool: https://github.com/python/cpython/issues/146102
The umbrella issue reported 47 bugs, 18 have been filed by various people, and 14 have been fixed. Each bug has an explanation about it linked in the issue.
That means you can join the fun: pick a bug, create an issue, and fix it in a PR!
There's also a different umbrella issue with more than a hundred (less detailed) bugs to pick from: https://github.com/python/cpython/issues/146103
Have fun!
@paulox@fosstodon.org This might interest you (seems related to your upcoming talk): @danzin@mastodon.social
I also built ft-review-toolkit (using ThreadSanitizer) to check for free-threading readiness, which has found real data races in 12 extensions so far.
If you maintain a Python C extension and want a high-quality, human-reviewed bug report (or help migrating to free-threading), just let me know!
All the toolkits are open source: https://github.com/devdanzin/cext-review-toolkit https://github.com/devdanzin/ft-review-toolkit
labeille Package Registry stats
Top 3.15 Blockers (364 packages):
- PyO3 / Rust / maturin: 111
- C extension build failures: 108
- pydantic-core (transitive PyO3): 69
- numpy / scipy / meson: 43
Once PyO3 adds 3.15 support, ~180 more packages will unlock (PyO3 direct + pydantic-core transitive)
Skip Reasons (418 packages):
- Monorepo subpackage (Azure, GCloud, etc.): 214
- No test suite found: 70
- No source repository: 52
- Type stub packages: 42
@geraldew@fosstodon.org Hi, is geraldew@mastodon.social you, or is someone impersonating you?