From: Sean Middleditch Date: 2002-04-05T00:25:28+09:00 Subject: Re: Is eval a code/design smell? On Thu, 2002-04-04 at 03:11, Harry Ohlsen wrote: > > I never use eval. However, I use module_eval all the time. That is, > > although I never use eval at "runtime", it's extremely useful at, err, > > "compile" time, to generate code. > > Chris and I have been having a discussion about the use of eval because > we've been corresponding about some changes to his XMLSerialization > module that would make it more usable for me. > > In this particular case, we're not doing a general eval, either, > but a couple of instance_eval calls, to allow the > serialise/deserialise to work with classes that may wish to restrict > access to some of their attributes (for example, if the programmer > wants some attribute to be read-only because it's a derived value, > or for some other reason). > > So, the use of instance_eval is very specific. Ie, all it's ever > doing is setting or getting the value of an attribute, to avoid > dictating to the class designer how they should write their class > in order to be able to use the module. > > I think it was you who pointed to this being something that perhaps > the language should be providing support for. That would be even > nicer, but isn't there right now, so far as I know. > > I've also sent Chris a patch that uses class_eval to avoid calling > initialize, based on some code someone provided in answer to my > query about that issue. Again, this is doing something very > specific, based on a design requirement, rather than doing a general > eval on arbitrary data provided as input to the module. > > I'd be keen to know whether these kinds of uses of eval match with what > you would consider "clean", or whether you'd still have reservations. I know I would. To me, that is indeed a language flaw. There should be methods that don't open up the security holes of eval() for finding/setting attributes of an object. Your specific need for no initialize() still seems weird to me, but if it is necessary, and the language restricts you from doing it, then either the language is flawed or you are using the wrong langauge for the task. People have built applications that do everything Ruby can do in C, and done it faster than the Ruby interpreter could do it (although with a lot more work than Ruby would require) without ever having an eval() for C code. ~,^ Sean Etc.