# Attr :\<symbol\>?

**URL:** <https://rubytalk.org/t/attr-symbol/17254>\
**Category:** ruby-talk\
**Created:** [29 March 2005 17:57 UTC](https://rubytalk.org/t/attr-symbol/17254 "2005-03-29T17:57:58Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luke\_Renn](https://avatars.discourse-cdn.com/v4/letter/l/94ad74/32.png) [@Luke\_Renn](https://rubytalk.org/u/Luke_Renn)\
**Post date:** [29 March 2005 17:57 UTC](https://rubytalk.org/t/attr-symbol/17254/1 "2005-03-29T17:57:58Z")

</div>

What is the proper term for things like attr :\<id\> and belongs\_to  
:\<model\>, etc. How do you code them? I tried googling around, but  
since I don't know what to call it, its a little tough. I looked at  
the ActiveRecord code for a few minutes and it looks like they're just  
class methods, but I don't understand how ruby interprets it i guess.

Thanks.

> **···**
>
> --  
> Luke | PGP: 0xFBE7D8AF  
> [goseigen@comcast.net](mailto:goseigen@comcast.net) | 2A44 9EB2 F541 C1F2 D969 56E3 8617 5B7F FBE7 D8AF

---

<div class="post-metadata">

**Author:** ![Glenn\_Smith](https://avatars.discourse-cdn.com/v4/letter/g/41988e/32.png) [@Glenn\_Smith](https://rubytalk.org/u/Glenn_Smith)\
**Post date:** [29 March 2005 18:08 UTC](https://rubytalk.org/t/attr-symbol/17254/2 "2005-03-29T18:08:40Z")

</div>

A similar thing has just been discussed on the RubyOnRails list, and  
James Britt gave a good example which I'll paste here. It's  
implemented (in this case at least) using "meta programming" which is  
something I'm just reading up on at the moment, because it foxed me  
to!!

Here is James' example:

A simple example

# Meta-programming  
# Add a public array property to an object instance

class Meta  
&nbsp;&nbsp;def self.has\_many( sym )  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp = "def #{sym.to\_s} \n"  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s} = unless @#{sym.to\_s}\n"  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s}; end"  
&nbsp;&nbsp;&nbsp;&nbsp;eval ( attr\_tmp )  
&nbsp;&nbsp;end  
end

class Foo \< Meta  
&nbsp;&nbsp;has\_many :foo  
&nbsp;&nbsp;has\_many :baz  
end

f = Foo.new

# See what methds the new object has ...  
puts (f.methods - Object.methods ).inspect # ["foo", "baz"]

f.foo.push "X"  
f.baz \<\< "hello"

p f.foo.first # "X"  
p f.baz # ["hello"]

James Britt

> **···**
>
> On Wed, 30 Mar 2005 02:57:58 +0900, Luke Renn \<goseigen@comcast.net\> wrote:
> 
> > What is the proper term for things like attr :\<id\> and belongs\_to  
> > :\<model\>, etc. How do you code them? I tried googling around, but  
> > since I don't know what to call it, its a little tough. I looked at  
> > the ActiveRecord code for a few minutes and it looks like they're just  
> > class methods, but I don't understand how ruby interprets it i guess.
> > 
> > Thanks.
> > 
> > --  
> > Luke | PGP: 0xFBE7D8AF  
> > goseigen@comcast.net | 2A44 9EB2 F541 C1F2 D969 56E3 8617 5B7F FBE7 D8AF
> 
> --
> 
> All the best  
> Glenn  
> Aylesbury, UK

---

<div class="post-metadata">

**Author:** ![Glenn\_Smith](https://avatars.discourse-cdn.com/v4/letter/g/41988e/32.png) [@Glenn\_Smith](https://rubytalk.org/u/Glenn_Smith)\
**Post date:** [29 March 2005 18:08 UTC](https://rubytalk.org/t/attr-symbol/17254/3 "2005-03-29T18:08:57Z")

</div>

A similar thing has just been discussed on the RubyOnRails list, and  
James Britt gave a good example which I'll paste here. It's  
implemented (in this case at least) using "meta programming" which is  
something I'm just reading up on at the moment, because it foxed me  
to!!

Here is James' example:

A simple example

# Meta-programming  
# Add a public array property to an object instance

class Meta  
&nbsp;&nbsp;def self.has\_many( sym )  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp = "def #{sym.to\_s} \n"  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s} = unless @#{sym.to\_s}\n"  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s}; end"  
&nbsp;&nbsp;&nbsp;&nbsp;eval ( attr\_tmp )  
&nbsp;&nbsp;end  
end

class Foo \< Meta  
&nbsp;&nbsp;has\_many :foo  
&nbsp;&nbsp;has\_many :baz  
end

f = Foo.new

# See what methds the new object has ...  
puts (f.methods - Object.methods ).inspect # ["foo", "baz"]

f.foo.push "X"  
f.baz \<\< "hello"

p f.foo.first # "X"  
p f.baz # ["hello"]

James Britt

> **···**
>
> On Wed, 30 Mar 2005 02:57:58 +0900, Luke Renn \<goseigen@comcast.net\> wrote:
> 
> > What is the proper term for things like attr :\<id\> and belongs\_to  
> > :\<model\>, etc. How do you code them? I tried googling around, but  
> > since I don't know what to call it, its a little tough. I looked at  
> > the ActiveRecord code for a few minutes and it looks like they're just  
> > class methods, but I don't understand how ruby interprets it i guess.
> > 
> > Thanks.
> > 
> > --  
> > Luke | PGP: 0xFBE7D8AF  
> > goseigen@comcast.net | 2A44 9EB2 F541 C1F2 D969 56E3 8617 5B7F FBE7 D8AF
> 
> --
> 
> All the best  
> Glenn  
> Aylesbury, UK

---

<div class="post-metadata">

**Author:** ![John\_Wilger1](https://avatars.discourse-cdn.com/v4/letter/j/8e8cbc/32.png) [@John\_Wilger1](https://rubytalk.org/u/John_Wilger1)\
**Post date:** [29 March 2005 18:09 UTC](https://rubytalk.org/t/attr-symbol/17254/4 "2005-03-29T18:09:57Z")

</div>

You're absolutely correct that they're just class methods. In Ruby  
(unlike many other languages) the code that defines a class is much  
more than just a "definition". The code between "class Foo ... end" is  
executed just like any other part of your program. Perhaps this simple  
example using a global variable will help clear it up:

irb(main):001:0\> $foo = 'bar'  
=\> "bar"  
irb(main):002:0\> $foo  
=\> "bar"  
irb(main):003:0\> class FooChanger  
irb(main):004:1\> $foo = 'baz'  
irb(main):005:1\> end  
=\> "baz"  
irb(main):006:0\> $foo  
=\> "baz"

> **···**
>
> On Wed, 30 Mar 2005 02:57:58 +0900, Luke Renn \<goseigen@comcast.net\> wrote:
> 
> > the ActiveRecord code for a few minutes and it looks like they're just  
> > class methods, but I don't understand how ruby interprets it i guess.
> 
> --  
> Regards,  
> John Wilger
> 
> -----------  
> Alice came to a fork in the road. "Which road do I take?" she asked.  
> "Where do you want to go?" responded the Cheshire cat.  
> "I don't know," Alice answered.  
> "Then," said the cat, "it doesn't matter."  
> - Lewis Carrol, Alice in Wonderland

---

<div class="post-metadata">

**Author:** ![Patrick\_Hurley1](https://avatars.discourse-cdn.com/v4/letter/p/b77776/32.png) [@Patrick\_Hurley1](https://rubytalk.org/u/Patrick_Hurley1)\
**Post date:** [29 March 2005 18:17 UTC](https://rubytalk.org/t/attr-symbol/17254/5 "2005-03-29T18:17:34Z")

</div>

I am not a Ruby expert (yet :-), but the first thing to realize is  
that attr, etc are just normal methods. And remembering I am far from  
a Ruby expert, I wrote the following code for personal exploration on  
the same topic. It adds attr\_class\_(reader|writer|accessor) methods to  
Module so that any other class or module can then provide easy access  
to class data variables. Note all it does use class eval to "write"  
the access methods -- I do not know if this is what module does or if  
there is a substantially better technique. I would prefer to have used  
a closure over class\_eval, but could not figure out how (if it is  
possible).

Patrick

class Module  
&nbsp;&nbsp;def attr\_class\_reader(sym)  
&nbsp;&nbsp;&nbsp;&nbsp;self.class\_eval \<\<ATTR  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;def self.#{sym}  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;@@#{sym}  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;end  
ATTR  
&nbsp;&nbsp;end

&nbsp;&nbsp;def attr\_class\_writer(sym)  
&nbsp;&nbsp;&nbsp;&nbsp;self.class\_eval \<\<ATTR  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;def self.#{sym}=(new\_value)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;@@#{sym} = new\_value  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;end  
ATTR  
&nbsp;&nbsp;end

&nbsp;&nbsp;def attr\_class\_accessor(sym)  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_class\_reader(sym)  
&nbsp;&nbsp;&nbsp;&nbsp;attr\_class\_writer(sym)  
&nbsp;&nbsp;end  
end

> **···**
>
> On Wed, 30 Mar 2005 02:57:58 +0900, Luke Renn \<goseigen@comcast.net\> wrote:
> 
> > What is the proper term for things like attr :\<id\> and belongs\_to  
> > :\<model\>, etc. How do you code them? I tried googling around, but  
> > since I don't know what to call it, its a little tough. I looked at  
> > the ActiveRecord code for a few minutes and it looks like they're just  
> > class methods, but I don't understand how ruby interprets it i guess.
> > 
> > Thanks.

---

<div class="post-metadata">

**Author:** ![Tim\_Sutherland1](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@Tim\_Sutherland1](https://rubytalk.org/u/Tim_Sutherland1)\
**Post date:** [30 March 2005 11:19 UTC](https://rubytalk.org/t/attr-symbol/17254/6 "2005-03-30T11:19:45Z")

</div>

They are simply methods.

Parentheses for method calls are optional for Ruby.

So  
&nbsp;&nbsp;attr :foo  
is the same as  
&nbsp;&nbsp;attr(:foo)

:foo is a Symbol - similar to a String. You can also write  
&nbsp;&nbsp;attr('foo')

....since the 'attr' method takes either a Symbol or a String.

If you don't know why Symbol exists (why we don't just use String all the  
time), search the archives of this list, and ask again if you're still not  
sure.

(The rest of the reason is explained but other people in this thread: Ruby  
evaluates statements/expressions "as it sees them".)

> **···**
>
> In article \<20050329180034.GA4745@trico.localnet\>, Luke Renn wrote:
> 
> > What is the proper term for things like attr :\<id\> and belongs\_to  
> > :\<model\>, etc. How do you code them? I tried googling around, but  
> > since I don't know what to call it, its a little tough. I looked at  
> > the ActiveRecord code for a few minutes and it looks like they're just  
> > class methods, but I don't understand how ruby interprets it i guess.

---

<div class="post-metadata">

**Author:** ![Luke\_Renn](https://avatars.discourse-cdn.com/v4/letter/l/94ad74/32.png) [@Luke\_Renn](https://rubytalk.org/u/Luke_Renn)\
**Post date:** [29 March 2005 18:16 UTC](https://rubytalk.org/t/attr-symbol/17254/7 "2005-03-29T18:16:50Z")

</div>

\* John Wilger \<johnwilger@gmail.com\> [2005-03-30 03:09:57 +0900]:

> more than just a "definition". The code between "class Foo ... end" is  
> executed just like any other part of your program. Perhaps this simple

That's what i was thinking. So anything in between class Foo ... end  
is like a static { } block in a java class. Thanks to both of you for  
clearing that up.

> **···**
>
> --  
> Luke | PGP: 0xFBE7D8AF  
> goseigen@comcast.net | 2A44 9EB2 F541 C1F2 D969 56E3 8617 5B7F FBE7 D8AF

---

<div class="post-metadata">

**Author:** ![Florian\_Gross](https://avatars.discourse-cdn.com/v4/letter/f/e9a140/32.png) [@Florian\_Gross](https://rubytalk.org/u/Florian_Gross)\
**Post date:** [29 March 2005 19:59 UTC](https://rubytalk.org/t/attr-symbol/17254/8 "2005-03-29T19:59:46Z")

</div>

Glenn Smith wrote:

> Here is James' example:
> 
> A simple example
> 
> # Meta-programming  
> # Add a public array property to an object instance
> 
> class Meta  
> &nbsp;&nbsp;def self.has\_many( sym )  
> &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp = "def #{sym.to\_s} \n"  
> &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s} = unless @#{sym.to\_s}\n"  
> &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s}; end"  
> &nbsp;&nbsp;&nbsp;&nbsp;eval ( attr\_tmp )  
> &nbsp;&nbsp;end  
> end

And here it is without an eval:

class Meta  
&nbsp;&nbsp;&nbsp;def self.has\_many(sym)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ivar = :"@#{sym}"  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;define\_method(sym.to\_sym) do  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value = instance\_variable\_get(ivar) ||   
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;instance\_variable\_set(ivar, new\_value)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;end  
&nbsp;&nbsp;&nbsp;end  
end

---

<div class="post-metadata">

**Author:** ![B\_K\_Oxley\_binkley](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@B\_K\_Oxley\_binkley](https://rubytalk.org/u/B_K_Oxley_binkley)\
**Post date:** [29 March 2005 20:03 UTC](https://rubytalk.org/t/attr-symbol/17254/9 "2005-03-29T20:03:48Z")

</div>

Florian Gross wrote:

> Glenn Smith wrote:
> 
> > class Meta  
> > &nbsp;&nbsp;def self.has\_many( sym )  
> > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp = "def #{sym.to\_s} \n"  
> > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s} = unless @#{sym.to\_s}\n"  
> > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s}; end"  
> > &nbsp;&nbsp;&nbsp;&nbsp;eval ( attr\_tmp )  
> > &nbsp;&nbsp;end  
> > end
> 
> class Meta  
> &nbsp;&nbsp;def self.has\_many(sym)  
> &nbsp;&nbsp;&nbsp;&nbsp;ivar = :"@#{sym}"  
> &nbsp;&nbsp;&nbsp;&nbsp;define\_method(sym.to\_sym) do  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value = instance\_variable\_get(ivar) ||   
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;instance\_variable\_set(ivar, new\_value)  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value  
> &nbsp;&nbsp;&nbsp;&nbsp;end  
> &nbsp;&nbsp;end  
> end

What is the difference between these two approaches?

\* Is one more 'culturally correct'?  
\* Does one perform better?  
\* Is one more future-proof?

Thanks,  
--binkley

---

<div class="post-metadata">

**Author:** ![Austin\_Ziegler5](https://yyz1.discourse-cdn.com/flex029/user_avatar/rubytalk.org/austin_ziegler5/32/1985_2.png) [@Austin\_Ziegler5](https://rubytalk.org/u/Austin_Ziegler5)\
**Post date:** [29 March 2005 20:30 UTC](https://rubytalk.org/t/attr-symbol/17254/10 "2005-03-29T20:30:04Z")

</div>

Florian's will only work on Ruby 1.8 or later and avoids some of the  
concerns that people have around "eval".

-austin

> **···**
>
> On Wed, 30 Mar 2005 05:03:48 +0900, B. K. Oxley (binkley) \<binkley@alumni.rice.edu\> wrote:
> 
> > Florian Gross wrote:  
> > \> class Meta  
> > \> def self.has\_many(sym)  
> > \> ivar = :"@#{sym}"  
> > \> define\_method(sym.to\_sym) do  
> > \> new\_value = instance\_variable\_get(ivar) ||   
> > \> instance\_variable\_set(ivar, new\_value)  
> > \> new\_value  
> > \> end  
> > \> end  
> > \> end  
> > What is the difference between these two approaches?
> 
> --  
> Austin Ziegler \* halostatue@gmail.com  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\* Alternate: austin@halostatue.ca

---

<div class="post-metadata">

**Author:** ![Ptkwt](https://avatars.discourse-cdn.com/v4/letter/p/f14d63/32.png) [@Ptkwt](https://rubytalk.org/u/Ptkwt)\
**Post date:** [29 March 2005 20:54 UTC](https://rubytalk.org/t/attr-symbol/17254/11 "2005-03-29T20:54:50Z")

</div>

In article \<4249B4AA.2090602@alumni.rice.edu\>,

> Florian Gross wrote:
> 
> > Glenn Smith wrote:
> > 
> > > class Meta  
> > > &nbsp;&nbsp;def self.has\_many( sym )  
> > > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp = "def #{sym.to\_s} \n"  
> > > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s} = unless @#{sym.to\_s}\n"  
> > > &nbsp;&nbsp;&nbsp;&nbsp;attr\_tmp \<\< " @#{sym.to\_s}; end"  
> > > &nbsp;&nbsp;&nbsp;&nbsp;eval ( attr\_tmp )  
> > > &nbsp;&nbsp;end  
> > > end
> > 
> > class Meta  
> > &nbsp;&nbsp;def self.has\_many(sym)  
> > &nbsp;&nbsp;&nbsp;&nbsp;ivar = :"@#{sym}"  
> > &nbsp;&nbsp;&nbsp;&nbsp;define\_method(sym.to\_sym) do  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value = instance\_variable\_get(ivar) ||   
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;instance\_variable\_set(ivar, new\_value)  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;new\_value  
> > &nbsp;&nbsp;&nbsp;&nbsp;end  
> > &nbsp;&nbsp;end  
> > end
> 
> What is the difference between these two approaches?
> 
> \* Is one more 'culturally correct'?  
> \* Does one perform better?  
> \* Is one more future-proof?

The second approach would generally be considered 'better'. eval must be  
used with care (security issues, debugging is harder, etc.). The second  
approach doesn't use eval so that's why it would generally be preferred.  
Performance differences between the two are probably negligable. I  
suspect that either approach would work in the future.

Sometimes you need to use eval (or it's cousins instance\_eval and  
class\_eval - the latter should probably be preferred where possible) and  
it's great to have it's power available so I'm not saying you should  
\_never\_ use eval.

Phil

> **···**
>
> B. K. Oxley (binkley) \<binkley@alumni.rice.edu\> wrote:

---

<div class="post-metadata">

**Author:** ![James\_Britt4](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@James\_Britt4](https://rubytalk.org/u/James_Britt4)\
**Post date:** [29 March 2005 21:26 UTC](https://rubytalk.org/t/attr-symbol/17254/12 "2005-03-29T21:26:47Z")

</div>

B. K. Oxley (binkley) wrote:

> What is the difference between these two approaches?
> 
> \* Is one more 'culturally correct'?  
> \* Does one perform better?  
> \* Is one more future-proof?

James prefers Florian's way for real-life usage.

James wrote his as a sort of "Here's a simple example that may help show what sort stuff is going on" thing.

In general, 'eval' is risky because, if you're not careful, you'll execute the wrong raw code. It can also be harder to debug because you're looking at code + code-in-strings, so the actual intent may be obscured.

The eval example is perhaps more useful for someone looking to hack around to see what else can be done using assorted meta-coding and such, but overall you are probably better off if, once you've decide what to accomplish, you find a non-eval way to do it.

James

---

<div class="post-metadata">

**Author:** ![B\_K\_Oxley\_binkley](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@B\_K\_Oxley\_binkley](https://rubytalk.org/u/B_K_Oxley_binkley)\
**Post date:** [29 March 2005 20:32 UTC](https://rubytalk.org/t/attr-symbol/17254/13 "2005-03-29T20:32:31Z")

</div>

Austin Ziegler wrote:

> Florian's will only work on Ruby 1.8 or later and avoids some of the  
> concerns that people have around "eval".

Being new to Ruby, what sorts of concerns?

Thanks,  
--binkley

---

<div class="post-metadata">

**Author:** ![Patrick\_Hurley1](https://avatars.discourse-cdn.com/v4/letter/p/b77776/32.png) [@Patrick\_Hurley1](https://rubytalk.org/u/Patrick_Hurley1)\
**Post date:** [29 March 2005 20:35 UTC](https://rubytalk.org/t/attr-symbol/17254/14 "2005-03-29T20:35:46Z")

</div>

So does there exist (as I cannot find it) a way to access @@vars via  
symbols in a similar manner? @vars tied to the class are easy enough  
(and can often fill the same niche), but I cannot find a method  
similar to instance\_variable\_XXX for @@ vars.

Thanks  
Patrick

> **···**
>
> On Wed, 30 Mar 2005 05:30:04 +0900, Austin Ziegler \<halostatue@gmail.com\> wrote:
> 
> > On Wed, 30 Mar 2005 05:03:48 +0900, B. K. Oxley (binkley) \> \<binkley@alumni.rice.edu\> wrote:  
> > \> Florian Gross wrote:  
> > \> \> class Meta  
> > \> \> def self.has\_many(sym)  
> > \> \> ivar = :"@#{sym}"  
> > \> \> define\_method(sym.to\_sym) do  
> > \> \> new\_value = instance\_variable\_get(ivar) ||   
> > \> \> instance\_variable\_set(ivar, new\_value)  
> > \> \> new\_value  
> > \> \> end  
> > \> \> end  
> > \> \> end  
> > \> What is the difference between these two approaches?
> > 
> > Florian's will only work on Ruby 1.8 or later and avoids some of the  
> > concerns that people have around "eval".
> > 
> > -austin

---

<div class="post-metadata">

**Author:** ![Patrick\_Hurley1](https://avatars.discourse-cdn.com/v4/letter/p/b77776/32.png) [@Patrick\_Hurley1](https://rubytalk.org/u/Patrick_Hurley1)\
**Post date:** [29 March 2005 20:37 UTC](https://rubytalk.org/t/attr-symbol/17254/15 "2005-03-29T20:37:58Z")

</div>

I would take a stab, that minimally "public data" (e.g. web  
processing) situation there is a significant code injection risk that  
is minimized in the block based code.

Patrick

> **···**
>
> On Wed, 30 Mar 2005 05:32:31 +0900, B. K. Oxley (binkley) \<binkley@alumni.rice.edu\> wrote:
> 
> > Being new to Ruby, what sorts of concerns?

---

<div class="post-metadata">

**Author:** ![Ptkwt](https://avatars.discourse-cdn.com/v4/letter/p/f14d63/32.png) [@Ptkwt](https://rubytalk.org/u/Ptkwt)\
**Post date:** [29 March 2005 21:24 UTC](https://rubytalk.org/t/attr-symbol/17254/16 "2005-03-29T21:24:46Z")

</div>

In article \<4249BB65.7040102@alumni.rice.edu\>,

> Austin Ziegler wrote:
> 
> > Florian's will only work on Ruby 1.8 or later and avoids some of the  
> > concerns that people have around "eval".
> 
> Being new to Ruby, what sorts of concerns?

Two main issues come to mind:

1) security. What is someone malicious code that gets eval'ed?  
"system(\"rm -f \*\")"

2) debugging. It can be difficult to debug code that depends on eval.  
Errors get reported, but you've got to match line numbers of the string  
passed in to the eval function and this can be difficult.

Phil

> **···**
>
> B. K. Oxley (binkley) \<binkley@alumni.rice.edu\> wrote:

---

<div class="post-metadata">

**Author:** ![Florian\_Gross](https://avatars.discourse-cdn.com/v4/letter/f/e9a140/32.png) [@Florian\_Gross](https://rubytalk.org/u/Florian_Gross)\
**Post date:** [29 March 2005 21:34 UTC](https://rubytalk.org/t/attr-symbol/17254/17 "2005-03-29T21:34:46Z")

</div>

Patrick Hurley wrote:

> So does there exist (as I cannot find it) a way to access @@vars via  
> symbols in a similar manner? @vars tied to the class are easy enough  
> (and can often fill the same niche), but I cannot find a method  
> similar to instance\_variable\_XXX for @@ vars.

No, probably because they are not supposed to be used too frequently.

But using just instance\_eval("@@" + name) is still better than evaling the whole method definition.

---

<div class="post-metadata">

**Author:** ![Glenn\_Parker1](https://avatars.discourse-cdn.com/v4/letter/g/ba8739/32.png) [@Glenn\_Parker1](https://rubytalk.org/u/Glenn_Parker1)\
**Post date:** [29 March 2005 23:10 UTC](https://rubytalk.org/t/attr-symbol/17254/18 "2005-03-29T23:10:00Z")

</div>

Phil Tomson wrote:

> Two main issues come to mind:
> 
> 1) security. What is someone malicious code that gets eval'ed? "system(\"rm -f \*\")"
> 
> 2) debugging. It can be difficult to debug code that depends on eval. Errors get reported, but you've got to match line numbers of the string passed in to the eval function and this can be difficult.

3) editing. If your editor understands Ruby syntax, it will highlight and indent the code in a block passed to define\_method. But editing code encased in quoted strings makes your editor dumb.

> **···**
>
> --  
> Glenn Parker | glenn.parker-AT-comcast.net | \<[http://www.tetrafoil.com/&gt](http://www.tetrafoil.com/&gt);
