Clarify and improve ownership semantics Model Editor C/C++ API (#28800)
This pull request improves memory management and exception safety in the
ONNX Runtime Model Editor C and C++ APIs, particularly around ownership
transfer of graph/model components (inputs, outputs, initializers,
nodes, and graphs). The changes ensure that ownership is only
transferred on success, preventing double-free and dangling pointer
issues, and update documentation and types to reflect the new ownership
semantics.
**Key changes:**
### Memory Management and Ownership Semantics
- Added custom deleters (`OrtValueDeleter`, `OrtValueInfoDeleter`,
`OrtNodeDeleter`, `OrtGraphDeleter`) for all major ONNX Runtime types,
ensuring destruction always routes through the correct API release
functions and preventing accidental double-free or memory leaks.
(`onnxruntime/core/graph/model_editor_api_types.h`)
- Updated internal storage in `ModelEditorGraph` to use `unique_ptr`
with the appropriate custom deleters for inputs, outputs, initializers,
and nodes, enforcing correct ownership and destruction.
(`onnxruntime/core/graph/model_editor_api_types.h`)
### API and Documentation Improvements
- Clarified and expanded documentation for ownership transfer and
atomicity in the C API (`onnxruntime_c_api.h`), specifying
all-or-nothing behavior: ownership is only transferred on success, and
pointers are nulled out to make the transfer explicit.
(`onnxruntime/core/session/onnxruntime_c_api.h`)
[[1]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7775-R7780)
[[2]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7791-R7801)
[[3]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7806-R7842)
[[4]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7838-R7867)
[[5]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7887-R7910)
- Updated C++ API comments and signatures to reflect strong exception
safety: ownership is only transferred if the operation succeeds, and on
failure, input objects remain unchanged and owned by the caller.
(`onnxruntime/core/session/onnxruntime_cxx_api.h`)
[[1]](diffhunk://#diff-17f64e8b38fcdcd25e90abcabeec4b420956b15fe63868a5d0b270c376bde209L3624-R3638)
[[2]](diffhunk://#diff-17f64e8b38fcdcd25e90abcabeec4b420956b15fe63868a5d0b270c376bde209L3664-R3674)
### Implementation Updates
- Modified C++ API implementations to transfer ownership only after a
successful call, using `release()` only after the API call succeeds.
This pattern is now used for adding initializers, nodes, and graphs.
(`onnxruntime/core/session/onnxruntime_cxx_inline.h`)
- Updated model editor code to handle new pointer types and ownership
semantics, including moving out of `unique_ptr` when consuming
initializers. (`onnxruntime/core/graph/graph.cc`)
[[1]](diffhunk://#diff-e231a92b40d89409cc8e82436be0a15bc87ef95c93b303b9feaeab6e50c8835cL6846-R6848)
[[2]](diffhunk://#diff-e231a92b40d89409cc8e82436be0a15bc87ef95c93b303b9feaeab6e50c8835cL6869-R6882)
[[3]](diffhunk://#diff-e231a92b40d89409cc8e82436be0a15bc87ef95c93b303b9feaeab6e50c8835cL6895-R6903)
### Minor Cleanups
- Removed unused or redundant `owned_` flags from model editor types, as
ownership is now tracked via smart pointers.
(`onnxruntime/core/graph/model_editor_api_types.h`)
[[1]](diffhunk://#diff-495de13c86ea3c2f1eb9522cd8f9e3b8128eb58e673e47fb75868a378983f0c4L84)
[[2]](diffhunk://#diff-495de13c86ea3c2f1eb9522cd8f9e3b8128eb58e673e47fb75868a378983f0c4L158)
- Improved documentation consistency and removed unnecessary `OrtApi::`
prefixes in comments. (`onnxruntime/core/session/onnxruntime_c_api.h`)
[[1]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7907-R7928)
[[2]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7927-R7954)
[[3]](diffhunk://#diff-5845a5c76fb64abdc8f0cffe21b37f8da1712674eb3abc4cd87190891be1bd48L7953-R7980)
These changes collectively make the ONNX Runtime Model Editor API safer
and more robust, especially in the face of errors or exceptions.