From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id a5rXGHBlB2qUzT0AWB0awg (envelope-from ) for ; Fri, 15 May 2026 14:26:56 -0400 Authentication-Results: simark.ca; dkim=fail reason="signature verification failed" (768-bit key; unprotected) header.d=tromey.com header.i=@tromey.com header.a=rsa-sha256 header.s=default header.b=ZgFwCtpX; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id 576E71E0B1; Fri, 15 May 2026 14:26:56 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-2.1 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_INVALID,DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id D13871E067 for ; Fri, 15 May 2026 14:26:55 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id F34E64BB3BF1 for ; Fri, 15 May 2026 18:26:54 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org F34E64BB3BF1 Authentication-Results: sourceware.org; dkim=fail reason="signature verification failed" (768-bit key, unprotected) header.d=tromey.com header.i=@tromey.com header.a=rsa-sha256 header.s=default header.b=ZgFwCtpX Received: from omta038.useast.a.cloudfilter.net (omta038.useast.a.cloudfilter.net [44.202.169.37]) by sourceware.org (Postfix) with ESMTPS id B82BF4BB3BF1 for ; Fri, 15 May 2026 18:23:23 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org B82BF4BB3BF1 Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=tromey.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=tromey.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org B82BF4BB3BF1 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=44.202.169.37 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1778869408; cv=none; b=r0mkCYok4qshTJdb3Dkpe8Fs8B5tjel0WOMneDawLFm8g9TmSN1//OnY6hXILhmDVY4i4vOFbwsLSdcBWBA8y2B+TdGCw1egqJKmQ2Qud9JJgh6g4ilaXTWjc/A3dPl6dpR/cLZYsUk2q7i5Cf9QBgzfh60YdJeoUUCDPnD0b5M= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1778869408; c=relaxed/simple; bh=kLqC7xcz5ZEyEZJO5u/ABkEkMi98qZTkW6p15KkzcEU=; h=DKIM-Signature:From:Date:Subject:MIME-Version:Message-Id:To; b=TgydsQ3G339+e8GdSNyrDtGk0TVPjS5WOUMeu/Pcqe/miktLSawYKLq0OclYOIES/0yAGRI2njBEjsm0JWRqXIjuworL+prHsiFJN6iJwFgMcXKY3wlzw+qXq1Ea3ALwTFlRoByruJuTyJD8So3qBkpojA1WJI8n2L37Oxrf1a8= ARC-Authentication-Results: i=1; sourceware.org; dkim=policy (768-bit key, unprotected) header.d=tromey.com header.i=@tromey.com header.a=rsa-sha256 header.s=default header.b=ZgFwCtpX reason="signing key too small" DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B82BF4BB3BF1 Received: from eig-obgw-5002b.ext.cloudfilter.net ([10.0.29.226]) by cmsmtp with ESMTPS id NsulwXZhwuVXCNxBzwDwS7; Fri, 15 May 2026 18:23:23 +0000 Received: from box5379.bluehost.com ([162.241.216.53]) by cmsmtp with ESMTPS id NxBxwLHPUZYlBNxBywVz7l; Fri, 15 May 2026 18:23:22 +0000 X-Authority-Analysis: v=2.4 cv=MJRgmNZl c=1 sm=1 tr=0 ts=6a07649a a=ApxJNpeYhEAb1aAlGBBbmA==:117 a=ApxJNpeYhEAb1aAlGBBbmA==:17 a=IkcTkHD0fZMA:10 a=NGcC8JguVDcA:10 a=ItBw4LHWJt0A:10 a=9TWcnZURJYLH-kCpFvEA:9 a=QEXdDO2ut3YA:10 a=DCx65vhANUyCzuf5D8fC:22 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tromey.com; s=default; h=Cc:To:In-Reply-To:References:Message-Id: Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=5Bp5vejn7GFWaIM/0WOs2gqWk3I9Jd53PS7LWo+lQKg=; b=ZgFwCtpXuyzvnZqijJa4rvlaMk NCKpmyTZPN7YXk2O0yxoJxYN2/m7H2SUGgm7+KuENwDj9QVxCwb77XcxAK17PXPo/8P8QEV3VRpm5 /Z5YSOu1++kGINzN3o5xoq89u; Received: from 75-166-225-82.hlrn.qwest.net ([75.166.225.82]:46584 helo=[192.168.0.17]) by box5379.bluehost.com with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.99.2) (envelope-from ) id 1wNxBx-00000002ZaG-26ZW; Fri, 15 May 2026 12:23:21 -0600 From: Tom Tromey Date: Fri, 15 May 2026 12:23:19 -0600 Subject: [PATCH 1/4] Add gdbpy_borrowed_ref MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260515-python-safety-initial-v1-1-8f155338df57@tromey.com> References: <20260515-python-safety-initial-v1-0-8f155338df57@tromey.com> In-Reply-To: <20260515-python-safety-initial-v1-0-8f155338df57@tromey.com> To: gdb-patches@sourceware.org Cc: Tom Tromey X-Mailer: b4 0.14.3 X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - box5379.bluehost.com X-AntiAbuse: Original Domain - sourceware.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - tromey.com X-BWhitelist: no X-Source-IP: 75.166.225.82 X-Source-L: No X-Exim-ID: 1wNxBx-00000002ZaG-26ZW X-Source: X-Source-Args: X-Source-Dir: X-Source-Sender: 75-166-225-82.hlrn.qwest.net ([192.168.0.17]) [75.166.225.82]:46584 X-Source-Auth: tom+tromey.com X-Email-Count: 2 X-Org: HG=bhshared;ORG=bluehost; X-Source-Cap: ZWx5bnJvYmk7ZWx5bnJvYmk7Ym94NTM3OS5ibHVlaG9zdC5jb20= X-Local-Domain: yes X-CMAE-Envelope: MS4xfC6O8sGkrOTsp12z/nOXh+xkWVCFsrPKLjnAVN8HxEW9LDMOntyvxPiWExBjIuflHq0epcZXqBGHaLt517rTYORXpFQH7767cdBbFL/LihJr8UGjaApR gVCZ0ZZZM8ZYvLdjfCRvUIm1IKksQ/fxY5LDFhfHlG8XhOiK+N1iiaU0PVcrsBKbhiN93gIP4eLophNNBjYDKTSCNtJNinf3DT8= X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org This adds new gdbpy_opt_borrowed_ref and gdbpy_borrowed_ref classes. These class is primarily for code "documentation" purposes -- it makes it clear to the reader that a given reference is borrowed. However, they also add a tiny bit of safety, in that conversion to gdbpy_ref<> will either be rejected (by the "opt" class) or acquire a new reference. --- gdb/python/py-ref.h | 80 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 80 insertions(+) diff --git a/gdb/python/py-ref.h b/gdb/python/py-ref.h index dc0b14814af..ef6b9fb427c 100644 --- a/gdb/python/py-ref.h +++ b/gdb/python/py-ref.h @@ -41,6 +41,86 @@ struct gdbpy_ref_policy template using gdbpy_ref = gdb::ref_ptr; +/* A class representing an optional borrowed reference. It is + "optional" because NULL is a valid value. + + This is a simple wrapper for a PyObject*. Aside from documenting + what the code does, the main advantage of using this is that + conversion to a gdbpy_ref<> is prevented. + + An optional borrowed reference is only used in situations where + Python says NULL is valid. For example, it is used as the type of + the "keywords" argument to a varargs method. Most code should + prefer an ordinary gdbpy_borrowed_ref, see below. */ +class gdbpy_opt_borrowed_ref +{ +public: + + gdbpy_opt_borrowed_ref (PyObject *obj) + : m_obj (obj) + { + } + + template + gdbpy_opt_borrowed_ref (const gdbpy_ref &ref) + : m_obj (ref.get ()) + { + } + + operator PyObject * () + { + return m_obj; + } + + operator gdbpy_ref<> () = delete; + +protected: + PyObject *m_obj; +}; + +/* A borrowed reference that is guaranteed not to be NULL. + + Like gdbpy_opt_borrowed_ref, this mostly serves a documentary + purpose. However, it also allows a checked cast to any subclass of + PyObject, and conversion to a gdbpy_ref<> will automatically + acquire a new reference -- a safety improvement over plain + PyObject*. */ +class gdbpy_borrowed_ref : public gdbpy_opt_borrowed_ref +{ +public: + + gdbpy_borrowed_ref (PyObject *obj) + : gdbpy_opt_borrowed_ref (obj) + { + gdb_assert (m_obj != nullptr); + } + + template + gdbpy_borrowed_ref (const gdbpy_ref &ref) + : gdbpy_opt_borrowed_ref (ref) + { + gdb_assert (m_obj != nullptr); + } + + gdbpy_borrowed_ref (std::nullptr_t) = delete; + + /* Allow a (checked) conversion to any subclass of PyObject. */ + template> + operator T * () + { + gdb_assert (PyObject_TypeCheck (m_obj, T::corresponding_object_type)); + return static_cast (m_obj); + } + + /* When converting a borrowed reference to a gdbpy_ref<>, a new + reference is acquired. */ + operator gdbpy_ref<> () + { + return gdbpy_ref<>::new_reference (m_obj); + } +}; + /* A wrapper class for Python extension objects that have a __dict__ attribute. Any Python C object extension needing __dict__ should inherit from this -- 2.49.0