Skip to content

Commit 3ba44b6

Browse files
runzwcopybara-github
authored andcommitted
internal change
PiperOrigin-RevId: 992502230
1 parent 799556e commit 3ba44b6

1 file changed

Lines changed: 24 additions & 16 deletions

File tree

‎rust/cpp_kernel/interop.rs‎

Lines changed: 24 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,20 @@
99
//!
1010
//! These traits are deliberately not available on the prelude, as they should
1111
//! be used rarely and with great care.
12+
//!
13+
//! The raw pointers vended and accepted by these traits are only guaranteed to
14+
//! point to a `proto2::MessageLite`. The pointer is only guaranteed to be a full `proto2::Message*`
15+
//! if the Rust type also implements the `WithReflection` trait. Casting a pointer to
16+
//! `proto2::Message*` for a type that does not implement `WithReflection` is
17+
//! undefined behavior.
1218
1319
use super::*;
1420

1521
/// Methods for converting to and from a raw, owned C++ message pointer.
1622
pub trait OwnedMessageInterop: SealedInternal {
1723
/// Drops `self` and returns an underlying pointer that it was wrapping
18-
/// without deleting it.
24+
/// without deleting it. The pointer is a `MessageLite*` in C++ (and only a
25+
/// `Message*` if `Self` implements `WithReflection`, see the module docs).
1926
///
2027
/// The caller is responsible for ensuring the returned pointer is
2128
/// subsequently deleted (eg by moving it into a std::unique_ptr in
@@ -26,8 +33,8 @@ pub trait OwnedMessageInterop: SealedInternal {
2633
///
2734
/// # Safety
2835
/// - The underlying message must be for the same type as `Self`
29-
/// - The pointer passed in must not be used by the caller after being
30-
/// passed here (must not be read, written, or deleted)
36+
/// - The pointer passed in must not be used by the caller after being passed here (must not
37+
/// be read, written, or deleted)
3138
unsafe fn __unstable_take_ownership_of_raw_message(raw_message: *mut std::ffi::c_void) -> Self;
3239
}
3340

@@ -37,9 +44,10 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
3744
///
3845
/// Note that the returned Value must be used under the same constraints
3946
/// as though it were a borrow of `self`: it should be treated as a
40-
/// `const Message*` in C++, and not be mutated in any way, and any
41-
/// mutation to the parent message may invalidate it, and it
42-
/// must not be deleted.
47+
/// `const MessageLite*` in C++ (and only as a `const Message*` if `Self`
48+
/// implements `WithReflection`, see the module docs), and not be mutated
49+
/// in any way, and any mutation to the parent message may invalidate it,
50+
/// and it must not be deleted.
4351
fn __unstable_as_raw_message(&self) -> *const std::ffi::c_void;
4452

4553
/// Wraps the provided pointer as a MessageView.
@@ -58,8 +66,7 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
5866
///
5967
/// # Safety
6068
/// - The underlying message must be for the same type as `Self`
61-
/// - The underlying message must be alive for 'msg and not mutated
62-
/// while the wrapper is live.
69+
/// - The underlying message must be alive for 'msg and not mutated while the wrapper is live.
6370
unsafe fn __unstable_wrap_raw_message(raw: &'msg *const std::ffi::c_void) -> Self;
6471

6572
/// Wraps the provided pointer as a MessageView.
@@ -74,8 +81,8 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
7481
///
7582
/// # Safety
7683
/// - The underlying message must be for the same type as `Self`
77-
/// - The underlying message must be alive for the caller-chosen 'msg
78-
/// and not mutated while the wrapper is live.
84+
/// - The underlying message must be alive for the caller-chosen 'msg and not mutated while
85+
/// the wrapper is live.
7986
unsafe fn __unstable_wrap_raw_message_unchecked_lifetime(raw: *const std::ffi::c_void) -> Self;
8087
}
8188

@@ -85,8 +92,9 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
8592
///
8693
/// Note that the returned Value must be used under the same constraints
8794
/// as though it were a mut borrow of `self`: it should be treated as a
88-
/// non-owned `Message*` in C++. And any mutation to the parent message
89-
/// may invalidate it, and it must not be deleted.
95+
/// non-owned `MessageLite*` in C++ (and only as a `Message*` if `Self`
96+
/// implements `WithReflection`, see the module docs). And any mutation to
97+
/// the parent message may invalidate it, and it must not be deleted.
9098
fn __unstable_as_raw_message_mut(&mut self) -> *mut std::ffi::c_void;
9199

92100
/// Wraps the provided C++ pointer as a MessageMut.
@@ -105,8 +113,8 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
105113
///
106114
/// # Safety
107115
/// - The underlying message must be for the same type as `Self`
108-
/// - The underlying message must be alive for 'msg and not read or
109-
/// mutated while the wrapper is live.
116+
/// - The underlying message must be alive for 'msg and not read or mutated while the wrapper
117+
/// is live.
110118
unsafe fn __unstable_wrap_raw_message_mut(raw: &'msg mut *mut std::ffi::c_void) -> Self;
111119

112120
/// Wraps the provided pointer as a MessageMut.
@@ -121,8 +129,8 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
121129
///
122130
/// # Safety
123131
/// - The underlying message must be for the same type as `Self`
124-
/// - The underlying message must be alive for the caller-chosen 'msg
125-
/// and not mutated while the wrapper is live.
132+
/// - The underlying message must be alive for the caller-chosen 'msg and not mutated while
133+
/// the wrapper is live.
126134
unsafe fn __unstable_wrap_raw_message_mut_unchecked_lifetime(
127135
raw: *mut std::ffi::c_void,
128136
) -> Self;

0 commit comments

Comments
 (0)