Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: Andrew Burgess <aburgess@redhat.com>
To: Tom Tromey <tom@tromey.com>, gdb-patches@sourceware.org
Cc: Tom Tromey <tom@tromey.com>
Subject: Re: [PATCH v2 1/4] Add gdbpy_borrowed_ref
Date: Sun, 17 May 2026 12:40:46 +0100	[thread overview]
Message-ID: <87cxyuclhd.fsf@redhat.com> (raw)
In-Reply-To: <20260515-python-safety-initial-v2-1-6129cadf258a@tromey.com>

Tom Tromey <tom@tromey.com> writes:

> This adds new gdbpy_opt_borrowed_ref and gdbpy_borrowed_ref classes.
> These class is primarily for code "documentation" purposes -- it makes

type: These CLASSES ARE primarily ....

> it clear to the reader that a given reference is borrowed.  However,
> they also add a tiny bit of safety, in that conversion to gdbpy_ref<>
> will either be rejected (by the "opt" class) or acquire a new
> reference.
> ---
>  gdb/python/py-ref.h | 80 +++++++++++++++++++++++++++++++++++++++++++++++++++++
>  1 file changed, 80 insertions(+)
>
> diff --git a/gdb/python/py-ref.h b/gdb/python/py-ref.h
> index dc0b14814af..ef6b9fb427c 100644
> --- a/gdb/python/py-ref.h
> +++ b/gdb/python/py-ref.h
> @@ -41,6 +41,86 @@ struct gdbpy_ref_policy
>  template<typename T = PyObject> using gdbpy_ref
>    = gdb::ref_ptr<T, gdbpy_ref_policy>;
>  
> +/* A class representing an optional borrowed reference.  It is
> +   "optional" because NULL is a valid value.
> +
> +   This is a simple wrapper for a PyObject*.  Aside from documenting
> +   what the code does, the main advantage of using this is that
> +   conversion to a gdbpy_ref<> is prevented.
> +
> +   An optional borrowed reference is only used in situations where
> +   Python says NULL is valid.  For example, it is used as the type of
> +   the "keywords" argument to a varargs method.  Most code should
> +   prefer an ordinary gdbpy_borrowed_ref, see below.  */
> +class gdbpy_opt_borrowed_ref
> +{
> +public:
> +
> +  gdbpy_opt_borrowed_ref (PyObject *obj)
> +    : m_obj (obj)
> +  {
> +  }
> +
> +  template<typename T>
> +  gdbpy_opt_borrowed_ref (const gdbpy_ref<T> &ref)
> +    : m_obj (ref.get ())
> +  {
> +  }
> +
> +  operator PyObject * ()
> +  {
> +    return m_obj;
> +  }

Could/should this be marked as 'const'?

> +
> +  operator gdbpy_ref<> () = delete;
> +
> +protected:
> +  PyObject *m_obj;
> +};
> +
> +/* A borrowed reference that is guaranteed not to be NULL.
> +
> +   Like gdbpy_opt_borrowed_ref, this mostly serves a documentary
> +   purpose.  However, it also allows a checked cast to any subclass of
> +   PyObject, and conversion to a gdbpy_ref<> will automatically
> +   acquire a new reference -- a safety improvement over plain
> +   PyObject*.  */
> +class gdbpy_borrowed_ref : public gdbpy_opt_borrowed_ref
> +{
> +public:
> +
> +  gdbpy_borrowed_ref (PyObject *obj)
> +    : gdbpy_opt_borrowed_ref (obj)
> +  {
> +    gdb_assert (m_obj != nullptr);
> +  }
> +
> +  template<typename T>
> +  gdbpy_borrowed_ref (const gdbpy_ref<T> &ref)
> +    : gdbpy_opt_borrowed_ref (ref)
> +  {
> +    gdb_assert (m_obj != nullptr);
> +  }
> +
> +  gdbpy_borrowed_ref (std::nullptr_t) = delete;
> +
> +  /* Allow a (checked) conversion to any subclass of PyObject.  */
> +  template<typename T,
> +	   typename = std::is_convertible<T *, PyObject *>>
> +  operator T * ()
> +  {
> +    gdb_assert (PyObject_TypeCheck (m_obj, T::corresponding_object_type));
> +    return static_cast<T *> (m_obj);
> +  }

OK, please excuse my ignorance here, I might be completely wrong, but I
believe the line 'typename = std::is_convertible<T *, PyObject *>' is
here for the purpose of SFINAE.  I believe this was copied from
gdb_ref_ptr.h, but I think this line might be wrong, both there and
here.

I think std::is_convertible is either true or false, or the type will be
true_type or false_type, but in all cases, I think the type is well
defined, so there will never be substitution failure.

I think what you need here is:

  typename = gdb::Requires<std::is_convertible<T *, PyObject *>>

But it might be that I'm just not understanding what's going on here, in
which case, feel free to correct me.

> +
> +  /* When converting a borrowed reference to a gdbpy_ref<>, a new
> +     reference is acquired.  */
> +  operator gdbpy_ref<> ()
> +  {
> +    return gdbpy_ref<>::new_reference (m_obj);
> +  }

Again with the 'const' maybe?

Thanks,
Andrew

> +};
> +
>  /* A wrapper class for Python extension objects that have a __dict__ attribute.
>  
>     Any Python C object extension needing __dict__ should inherit from this
>
> -- 
> 2.49.0


  reply	other threads:[~2026-05-17 11:41 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-15 19:59 [PATCH v2 0/4] Python safety initial work Tom Tromey
2026-05-15 19:59 ` [PATCH v2 1/4] Add gdbpy_borrowed_ref Tom Tromey
2026-05-17 11:40   ` Andrew Burgess [this message]
2026-05-21 17:48     ` Tom Tromey
2026-05-21 21:01     ` Tom Tromey
2026-05-15 19:59 ` [PATCH v2 2/4] Add wrappers for some Python APIs Tom Tromey
2026-05-17 12:06   ` Andrew Burgess
2026-05-21 21:05     ` Tom Tromey
2026-05-15 19:59 ` [PATCH v2 3/4] Add wrappers for Python implementation functions and methods Tom Tromey
2026-05-18  9:33   ` Andrew Burgess
2026-05-21 21:23     ` Tom Tromey
2026-05-18 10:00   ` Andrew Burgess
2026-05-21 22:41     ` Tom Tromey
2026-05-29 15:58       ` Andrew Burgess
2026-05-15 19:59 ` [PATCH v2 4/4] Convert py-tui.c to the "python safety" approach Tom Tromey
2026-05-18 12:39   ` Andrew Burgess
2026-05-21 21:21     ` Tom Tromey

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87cxyuclhd.fsf@redhat.com \
    --to=aburgess@redhat.com \
    --cc=gdb-patches@sourceware.org \
    --cc=tom@tromey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox