99//!
1010//! These traits are deliberately not available on the prelude, as they should
1111//! be used rarely and with great care.
12+ //!
13+ //! The raw pointers vended and accepted by these traits are only guaranteed to
14+ //! point to a `proto2::MessageLite`. The pointer is only guaranteed to be a full `proto2::Message*`
15+ //! if the Rust type also implements the `WithReflection` trait. Casting a pointer to
16+ //! `proto2::Message*` for a type that does not implement `WithReflection` is
17+ //! undefined behavior.
1218
1319use super :: * ;
1420
1521/// Methods for converting to and from a raw, owned C++ message pointer.
1622pub trait OwnedMessageInterop : SealedInternal {
1723 /// Drops `self` and returns an underlying pointer that it was wrapping
18- /// without deleting it.
24+ /// without deleting it. The pointer is a `MessageLite*` in C++ (and only a
25+ /// `Message*` if `Self` implements `WithReflection`, see the module docs).
1926 ///
2027 /// The caller is responsible for ensuring the returned pointer is
2128 /// subsequently deleted (eg by moving it into a std::unique_ptr in
@@ -26,8 +33,8 @@ pub trait OwnedMessageInterop: SealedInternal {
2633 ///
2734 /// # Safety
2835 /// - The underlying message must be for the same type as `Self`
29- /// - The pointer passed in must not be used by the caller after being
30- /// passed here (must not be read, written, or deleted)
36+ /// - The pointer passed in must not be used by the caller after being passed here (must not
37+ /// be read, written, or deleted)
3138 unsafe fn __unstable_take_ownership_of_raw_message ( raw_message : * mut std:: ffi:: c_void ) -> Self ;
3239}
3340
@@ -37,9 +44,10 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
3744 ///
3845 /// Note that the returned Value must be used under the same constraints
3946 /// as though it were a borrow of `self`: it should be treated as a
40- /// `const Message*` in C++, and not be mutated in any way, and any
41- /// mutation to the parent message may invalidate it, and it
42- /// must not be deleted.
47+ /// `const MessageLite*` in C++ (and only as a `const Message*` if `Self`
48+ /// implements `WithReflection`, see the module docs), and not be mutated
49+ /// in any way, and any mutation to the parent message may invalidate it,
50+ /// and it must not be deleted.
4351 fn __unstable_as_raw_message ( & self ) -> * const std:: ffi:: c_void ;
4452
4553 /// Wraps the provided pointer as a MessageView.
@@ -58,8 +66,7 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
5866 ///
5967 /// # Safety
6068 /// - The underlying message must be for the same type as `Self`
61- /// - The underlying message must be alive for 'msg and not mutated
62- /// while the wrapper is live.
69+ /// - The underlying message must be alive for 'msg and not mutated while the wrapper is live.
6370 unsafe fn __unstable_wrap_raw_message ( raw : & ' msg * const std:: ffi:: c_void ) -> Self ;
6471
6572 /// Wraps the provided pointer as a MessageView.
@@ -74,8 +81,8 @@ pub trait MessageViewInterop<'msg>: SealedInternal {
7481 ///
7582 /// # Safety
7683 /// - The underlying message must be for the same type as `Self`
77- /// - The underlying message must be alive for the caller-chosen 'msg
78- /// and not mutated while the wrapper is live.
84+ /// - The underlying message must be alive for the caller-chosen 'msg and not mutated while
85+ /// the wrapper is live.
7986 unsafe fn __unstable_wrap_raw_message_unchecked_lifetime ( raw : * const std:: ffi:: c_void ) -> Self ;
8087}
8188
@@ -85,8 +92,9 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
8592 ///
8693 /// Note that the returned Value must be used under the same constraints
8794 /// as though it were a mut borrow of `self`: it should be treated as a
88- /// non-owned `Message*` in C++. And any mutation to the parent message
89- /// may invalidate it, and it must not be deleted.
95+ /// non-owned `MessageLite*` in C++ (and only as a `Message*` if `Self`
96+ /// implements `WithReflection`, see the module docs). And any mutation to
97+ /// the parent message may invalidate it, and it must not be deleted.
9098 fn __unstable_as_raw_message_mut ( & mut self ) -> * mut std:: ffi:: c_void ;
9199
92100 /// Wraps the provided C++ pointer as a MessageMut.
@@ -105,8 +113,8 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
105113 ///
106114 /// # Safety
107115 /// - The underlying message must be for the same type as `Self`
108- /// - The underlying message must be alive for 'msg and not read or
109- /// mutated while the wrapper is live.
116+ /// - The underlying message must be alive for 'msg and not read or mutated while the wrapper
117+ /// is live.
110118 unsafe fn __unstable_wrap_raw_message_mut ( raw : & ' msg mut * mut std:: ffi:: c_void ) -> Self ;
111119
112120 /// Wraps the provided pointer as a MessageMut.
@@ -121,8 +129,8 @@ pub trait MessageMutInterop<'msg>: SealedInternal {
121129 ///
122130 /// # Safety
123131 /// - The underlying message must be for the same type as `Self`
124- /// - The underlying message must be alive for the caller-chosen 'msg
125- /// and not mutated while the wrapper is live.
132+ /// - The underlying message must be alive for the caller-chosen 'msg and not mutated while
133+ /// the wrapper is live.
126134 unsafe fn __unstable_wrap_raw_message_mut_unchecked_lifetime (
127135 raw : * mut std:: ffi:: c_void ,
128136 ) -> Self ;
0 commit comments