Skip to content

feat(capi): implement PyCapsule destructor and name management - #8936

Open
krosci wants to merge 1 commit into
RustPython:mainfrom
krosci:feat/capi-capsule-destructor-name
Open

krosci wants to merge 1 commit into
RustPython:mainfrom
krosci:feat/capi-capsule-destructor-name

Conversation

@krosci

@krosci krosci commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This change implements destructor and name getters and setters for the PyCapsule C-API, updating the internal capsule structure to support runtime modifications, addressing part of #8156.

Summary by CodeRabbit

  • New Features
    • Added support for retrieving and changing a capsule’s destructor.
    • Added support for changing a capsule’s name.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Repository: RustPython/RustPython/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: 121c56f0-441d-4ab1-826f-5773d46fb4b5

📥 Commits

Reviewing files that changed from the base of the PR and between d037ed0 and 9bd74d3.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: RustPython/RustPython/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: 126998b8-ab1a-4df8-8db2-236ebb66e89c

📥 Commits

Reviewing files that changed from the base of the PR and between 112b7ef and d037ed0.

📒 Files selected for processing (2)
  • crates/capi/src/pycapsule.rs
  • crates/vm/src/builtins/capsule.rs

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The change stores capsule names and destructors in atomic pointers. It adds C API functions to retrieve a capsule destructor and to set a capsule’s destructor or name.

Changes

Capsule metadata updates

Layer / File(s) Summary
Atomic capsule metadata
crates/vm/src/builtins/capsule.rs
PyCapsule stores its name and destructor in atomic pointers. Its accessors load those pointers, and new setters update them.
Capsule metadata C API
crates/capi/src/pycapsule.rs
Adds PyCapsule_GetDestructor, PyCapsule_SetDestructor, and PyCapsule_SetName. The tests check name changes and destructor retrieval and replacement.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: bschoenmaeckers

Merge Risk: ⚪ Minimal · up to d037e

This change adds C API getters and setters for capsule names and destructors. No concrete merge-blocking risk was identified from the supplied evidence.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d037e

The new operations retain capsule type checks and extend an interface whose callers already control native pointers. No new privilege boundary violation was established. Concurrent metadata publication, borrowed-name lifetime, and cleanup coordination remain incompletely established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Misuse of these operations can affect capsule-backed native memory and resource cleanup within the embedding process. The caller must already supply a native capsule handle and, for callback replacement, a native function pointer.

Trust Boundaries and Controls

  • inferred — Exact-type and name checks provide compatibility validation, not isolation from native callers already authorized to manipulate raw pointers. Metadata replacement alone does not establish a new trust-boundary crossing.

Resilience and Maintainability Implications

  • observed — The reference-count teardown path marks objects finalized before callback invocation and accounts for resurrection. This supplies a cleanup guard, but the metadata methods themselves provide no compound transaction or synchronization beyond individual relaxed pointer operations.

Hardening Proposals

  • proposed — Make the borrowed-name lifetime and publication requirements explicit, together with coordination requirements for name, payload, and destructor replacement. Clarify how callers keep callback code valid through finalization and synchronize concurrent metadata readers and writers.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 16 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: implementing PyCapsule C API management for destructors and names.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@krosci
krosci force-pushed the feat/capi-capsule-destructor-name branch from d037ed0 to 9bd74d3 Compare October 1, 2026 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant