From: Matthieu Longo <matthieu.longo@arm.com>
To: Tom Tromey <tom@tromey.com>, gdb-patches@sourceware.org
Subject: Re: [PATCH v3 1/4] Add gdbpy_borrowed_ref
Date: Mon, 29 Jun 2026 14:51:39 +0100 [thread overview]
Message-ID: <16f2909b-c91c-42b4-9a12-7bba24f6949e@arm.com> (raw)
In-Reply-To: <20260521-python-safety-initial-v3-1-d0679c36e499@tromey.com>
On 22/05/2026 00:27, Tom Tromey wrote:
> This adds new gdbpy_opt_borrowed_ref and gdbpy_borrowed_ref classes.
> These classes are primarily for code "documentation" purposes -- it
> makes it clear to the reader that a given reference is borrowed.
> However, they also add a tiny bit of safety, in that conversion to
> gdbpy_ref<> will either be rejected (by the "opt" class) or acquire a
> new reference.
> ---
> gdb/python/py-ref.h | 86 +++++++++++++++++++++++++++++++++++++++++++++++++++++
> 1 file changed, 86 insertions(+)
>
> diff --git a/gdb/python/py-ref.h b/gdb/python/py-ref.h
> index 3d2906fd7f5..3d0373b7001 100644
> --- a/gdb/python/py-ref.h
> +++ b/gdb/python/py-ref.h
> @@ -21,6 +21,7 @@
> #define GDB_PYTHON_PY_REF_H
>
> #include "gdbsupport/gdb_ref_ptr.h"
> +#include "gdbsupport/traits.h"
> #include "python-traits.h"
>
> /* A policy class for gdb::ref_ptr for Python reference counting. */
> @@ -42,6 +43,91 @@ struct gdbpy_ref_policy
> template<typename T = PyObject> using gdbpy_ref
> = gdb::ref_ptr<T, gdbpy_ref_policy>;
>
> +/* A class representing an optional borrowed reference. It is
> + "optional" because NULL is a valid value.
> +
> + This is a simple wrapper for a pointer to PyObject or some subclass
> + of it. Aside from documenting what the code does, the main
> + advantage of using this is that conversion to a gdbpy_ref<T> is
> + prevented.
> +
> + An optional borrowed reference is only used in situations where
> + Python says NULL is valid. For example, it is used as the type of
> + the "keywords" argument to a varargs method. Most code should
> + prefer an ordinary gdbpy_borrowed_ref, see below. */
> +template<typename T = PyObject>
> +class gdbpy_opt_borrowed_ref
> +{
> +public:
> +
> + gdbpy_opt_borrowed_ref (T *obj)
> + : m_obj (obj)
> + {
> + }
> +
> + template<typename U>
> + gdbpy_opt_borrowed_ref (const gdbpy_ref<U> &ref)
> + : m_obj (ref.get ())
> + {
> + }
> +
> + operator T * () const
noexcept ?
> + {
> + return m_obj;
> + }
> +
> + operator gdbpy_ref<T> () = delete;
Is there any possibility to add a bool operator to avoid "if (my_ref == nullptr)" ?
Also, what about:
- T *operator-> () const noexcept
- T *get () const noexcept
> +
> +protected:
> +
> + T *m_obj;
> +};
> +
> +/* A borrowed reference that is guaranteed not to be NULL.
> +
> + Like gdbpy_opt_borrowed_ref, this mostly serves a documentary
> + purpose. However, it also allows a checked cast to any subclass of
> + T, and conversion to a gdbpy_ref<T> will automatically acquire a
> + new reference -- a safety improvement over plain PyObject * or the
> + like. */
> +template<typename T = PyObject>
> +class gdbpy_borrowed_ref : public gdbpy_opt_borrowed_ref<T>
> +{
> +public:
> +
> + gdbpy_borrowed_ref (T *obj)
> + : gdbpy_opt_borrowed_ref<T> (obj)
> + {
> + gdb_assert (this->m_obj != nullptr);
> + }
> +
> + template<typename U>
> + gdbpy_borrowed_ref (const gdbpy_ref<U> &ref)
> + : gdbpy_opt_borrowed_ref<T> (ref)
> + {
> + gdb_assert (this->m_obj != nullptr);
> + }
> +
> + gdbpy_borrowed_ref (std::nullptr_t) = delete;
> +
> + /* Allow a (checked) conversion to any subclass of T. */
> + template<typename U,
> + typename = gdb::Requires<std::is_convertible<U *, T *>>>
> + operator U * () const
> + {
> + gdb_assert (PyObject_TypeCheck (this->m_obj,
> + U::corresponding_object_type));
> + return static_cast<U *> (this->m_obj);
> + }
> +
> + /* When converting a borrowed reference to a gdbpy_ref<>, a new
> + reference is acquired. */
> + operator gdbpy_ref<T> () const
> + {
> + return gdbpy_ref<T>::new_reference (this->m_obj);
> + }
> +};
> +
> /* A wrapper class for Python extension objects that have a __dict__ attribute.
>
> Any Python C object extension needing __dict__ should inherit from this
>
Hi Tom,
How can I help to make this patch be merged ?
Are you waiting for inputs from others maintainers ?
Matthieu
next prev parent reply other threads:[~2026-06-29 13:53 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-21 23:27 [PATCH v3 0/4] Python safety initial work Tom Tromey
2026-05-21 23:27 ` [PATCH v3 1/4] Add gdbpy_borrowed_ref Tom Tromey
2026-06-01 10:00 ` Matthieu Longo
2026-06-03 18:19 ` Tom Tromey
2026-07-24 12:02 ` Yury Khrustalev
2026-06-29 13:51 ` Matthieu Longo [this message]
2026-05-21 23:27 ` [PATCH v3 2/4] Add wrappers for some Python APIs Tom Tromey
2026-05-21 23:27 ` [PATCH v3 3/4] Add wrappers for Python implementation functions and methods Tom Tromey
2026-05-21 23:27 ` [PATCH v3 4/4] Convert py-tui.c to the "python safety" approach Tom Tromey
2026-06-12 15:34 ` [PATCH v3 0/4] Python safety initial work Tom Tromey
2026-07-19 17:16 ` Tom Tromey
2026-07-21 11:45 ` Tom de Vries
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=16f2909b-c91c-42b4-9a12-7bba24f6949e@arm.com \
--to=matthieu.longo@arm.com \
--cc=gdb-patches@sourceware.org \
--cc=tom@tromey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox