Compare commits

...
53 Commits
Author SHA1 Message Date
Motoyuki KimuraandGitHub 03fdde9dcf chore: prepare v1.7.0 (#724) 2024-07-31 13:33:47 +02:00
Alice Ryhl f8c7b574c0 Merge 'v1.6.1' into 'master' (#721) 2024-07-13 09:51:48 +02:00
Alice RyhlandGitHub fd13c7dcdb chore: prepare bytes v1.6.1 (#720) 2024-07-13 09:45:33 +02:00
Emily Crandall FleischmanandGitHub 6b4b0eda29 Fix Bytes::is_unique when created from shared BytesMut (#718)
The `is_unique` entry in the vtable for `Bytes` created from a shared
`BytesMut` just called the `shared_is_unique` function from the `bytes`
module. However, that function dereferences the `data` argument` as
`bytes::Shared`, but the actual underlying type is `bytes_mut::Shared`.
2024-07-13 01:09:46 +02:00
EXPLOSIONandGitHub 9965a04b56 Remove unnecessary file (#719) 2024-07-10 19:08:47 +09:00
vvvviivandGitHub 3443ca5a0b docs: clarify the behavior of Buf::chunk (#717) 2024-07-09 14:13:09 +02:00
Sebastian HahnandGitHub 8cc940779f Allow reclaiming the current allocation (#686) 2024-06-28 14:26:32 +02:00
Paolo BarboliniandGitHub 7a5154ba8b Clarify how BytesMut::zeroed works and advantages to manual impl (#714) 2024-06-21 14:07:25 +02:00
Anthony RamineandGitHub fa1daac3ae Change Bytes::make_mut to impl From<Bytes> for BytesMut (closes #709) (#710)
<Arc<T>>::make_mut returns a &mut T, such an API is doable for Bytes too
and thus we should reserve Bytes::make_mut for that.

Furthermore, it would be helpful to use From<Bytes> as a trait bound
in some cases with other traits such as Hyper's body trait, where Hyper
gives you Bytes values.

Finally, making it impl From<Bytes> for BytesMut means the API is more
easily discoverable as it appears on both Bytes and BytesMut.
2024-05-28 10:14:02 +02:00
Paolo BarboliniandGitHub caf520ac7f Fix iter tests to use the actual bytes IntoIter instead of std (#707) 2024-05-19 15:28:03 -04:00
Brad DunbarandGitHub 4950c50376 Offset from (#705) 2024-05-11 19:41:50 +02:00
Émile FugulinandGitHub 86694b0564 Add zero-copy make_mut (#695) 2024-05-05 17:58:00 +02:00
Alice RyhlandGitHub 0c17e99283 ci: silence unexpected-cfgs warnings due to #[cfg(loom)] (#703) 2024-05-05 14:19:18 +02:00
Alice RyhlandGitHub cb7f8449b5 Tweak clear and truncate length modifications (#700) 2024-04-26 09:24:05 +02:00
Paolo BarboliniandGitHub a8806c2457 Improve BytesMut::split suggestion (#699) 2024-04-25 10:43:15 +02:00
Paolo BarboliniandGitHub baa5053572 Reuse capacity when possible in <BytesMut as Buf>::advance impl (#698) 2024-04-25 09:08:16 +02:00
Brad DunbarandGitHub ce09d7d358 Bytes::split_off - check fast path first (#693)
Follow up to https://github.com/tokio-rs/bytes/pull/689

* If `at == self.len()`, we already know `at <= self.len()`.
* If `at == 0`, we already know `at <= self.len()`.
2024-04-24 08:23:39 -04:00
9d3ec1cffb Resize refactor (#696)
* use checked_sub

* return when additional == 0

* move safe operation out of unsafe block

* use spare_capacity_mut instead of chunk_mut

We don't need to check capacity because it's already been reserved
above.

* Add safety comments

* refactor to use guard clauses

This would be better written with let-else, but we won't get that until
`MSRV >= 1.65.x`.

* use if-let instead of unwrap

* reduce scope of unsafe blocks

Co-authored-by: Alice Ryhl <[email protected]>

---------

Co-authored-by: Alice Ryhl <[email protected]>
2024-04-24 05:49:53 -04:00
Brad DunbarandGitHub 4e2c9c065a Truncate tweaks (#694) 2024-04-17 11:27:00 +02:00
Joseph PerezandGitHub 327615e5d4 test(benches): encloses bytes into test::black_box for clone benches (#691)
Closes #690
Without it, it seems to me that compiler is able to inline the vtable,
resulting in similar results for `clone_shared` and `clone_arg_vec`.
2024-04-11 11:45:18 +02:00
tisonandGitHub b5fbfc3edb perf: improve Bytes::copy_to_bytes (#688)
Signed-off-by: tison <[email protected]>
2024-04-10 16:45:31 +02:00
Brad DunbarandGitHub 4eb62b912a Bytes::split_to - check fast path first (#689)
If `at == self.len()` then we already know `at <= self.len()`. If
`at == 0`, it can't be greater than `self.len()`.
2024-04-10 10:09:09 +02:00
Brad DunbarandGitHub e4af48633c Don't set len in BytesMut::reserve (#682)
A fundamental invariant of `reserve` is that it can extend capacity
while the stored data remains the same, even if it's moved to a new
allocation. As a result, `len` can never change during a call to
`reserve`.
2024-04-09 14:35:54 +02:00
Brad DunbarandGitHub 0d4cc7ffed Bytes: Use ManuallyDrop instead of mem::forget (#678) 2024-04-08 17:05:04 +02:00
Brad DunbarandGitHub ce8d8a0a02 chore: prepare bytes v1.6.0 (#681) 2024-03-22 20:55:20 +01:00
Brad DunbarandGitHub 536db06f16 Use ManuallyDrop instead of mem::forget (#675) 2024-03-14 14:40:03 +01:00
Brad DunbarandGitHub ca004117f8 Remove commented tests for Bytes::unsplit (#677)
Bytes doesn't have an unsplit method anymore. We can always retrieve
these from git history if necessary.
2024-03-04 09:05:00 +01:00
Brad DunbarandGitHub 7968f6f83d Remove redundant reserve call (#674) 2024-03-04 09:04:40 +01:00
Brad DunbarandGitHub c5fae00c76 copy_to_bytes: Add panic section to docs (#676)
Fixes #454.
2024-03-03 22:59:30 +09:00
Brad DunbarandGitHub 99584cc10d Use Iterator from the prelude (#673)
CI is [failing][failure] due to unused_imports because Iterator is
already in the prelude. Removing it fixes things up.

[failure]: https://github.com/tokio-rs/bytes/actions/runs/8034858583/job/21946873895
2024-03-03 00:40:17 +09:00
Brad DunbarandGitHub 46289278f5 Refactor split_at/split_to (#663)
* set len a little more concisely
* inline set_end
* remove kind assertions
* remove a duplicate assertion
* remove redundant assertion and min
* rename set_start to advance_unchecked
2024-02-23 14:22:58 -08:00
Brad DunbarandGitHub 1bcd2129d1 get_vec_pos: use &self instead of &mut self (#670)
I can't see any reason that get_vec_pos needs a &mut self.
2024-02-06 17:34:30 -05:00
Brad DunbarandGitHub f586ffc525 set_vec_pos does not need a second parameter (#672)
The second argument to `set_vec_pos` always contains the value of
`self.data`. Let's just use `self.data` and remove the second parameter
altogether.
2024-02-06 11:03:37 -08:00
Brad DunbarandGitHub c6972d6132 Calculate original capacity only if necessary (#666)
We don't need the original capacity if the shared data is unique, so
let's not calculate it until after that check.
2024-02-06 10:46:49 -08:00
Brad DunbarandGitHub 47e83056f2 Use sub instead of offset (#668)
We're always subtracting here, and we already have a usize, so `sub`
seems like a more appropriate usage to me.
2024-02-06 10:41:44 -08:00
Brad DunbarandGitHub 8bcac21cb4 Restore commented tests (#665)
These seem to have been commented by accident in #298, and are still
passing.
2024-02-06 10:17:01 -08:00
Brad DunbarandGitHub d2e7abdb29 refactor: make parameter mut in From<Vec> (#667)
Instead of re-declaring `vec`, we can just use a mut parameter.
2024-01-31 09:41:23 -05:00
Brad DunbarandGitHub e24587dd61 Remove unreachable else branch (#661) 2024-01-28 15:30:30 +03:30
Brad DunbarandGitHub 9257a6ea08 Remove an unnecessary else branch (#662) 2024-01-28 14:20:56 +03:30
Brad DunbarandGitHub 0ba3b4c4cd Remove unnecessary namespace qualifier (#660) 2024-01-28 14:07:11 +03:30
Cyborus04andGitHub 0864aea970 add Bytes::is_unique (#643) 2024-01-19 23:59:30 +01:00
Brad DunbarandGitHub abb4a2e66c BytesMut: Assert alignment of Shared (#652)
Back in #362, an assertion was added to ensure that the alignment of
bytes::Shared is even so we can use the least significant bit as a flag.
bytes_mut::Shared uses the same technique but has no such assertion so
I've added one here.
2024-01-19 11:08:27 +01:00
Taiki EndoandGitHub 09214ba51b Update CI config (#650) 2024-01-08 01:11:02 +09:00
Taiki EndoandGitHub fbc64bcc67 Update loom to 0.7 (#651) 2024-01-08 01:10:48 +09:00
Alice RyhlandGitHub 3bf6583b5c readme: add security policy (#649) 2024-01-03 17:22:39 +01:00
Brad DunbarandGitHub dbbdb63d76 Use self. instead of Self:: (#642)
I was a little confused about these calls using `Self::` instead of
`self.` here. Is there a reason to use the former instead of the latter?
2023-12-28 14:20:13 +09:00
Luca BrunoandGitHub f73c6c8e85 Simplify UninitSlice::as_uninit_slice_mut() logic (#644)
This reworks `UninitSlice::as_uninit_slice_mut()` using equivalent
simpler logic.
2023-12-28 14:17:53 +09:00
Gabriel GollerandGitHub 72cbb92e0e docs: fix broken links (#639)
Fixed a few broken links and converted a lot of them from the
html-link to intra-doc links.
2023-11-16 06:24:21 -05:00
bde8c50703 docs: typo fix (#637)
Co-authored-by: Daniel Bauman <[email protected]>
2023-10-19 21:50:24 +02:00
Alice RyhlandGitHub fd9243f9e2 Various cleanup (#635) 2023-10-02 15:40:02 +02:00
mxsmandGitHub a4e16a552b docs: fix some spelling mistakes (#633) 2023-09-25 10:47:02 +02:00
Lucas KentandGitHub a14ef4617c Move comment to correct constant (#629) 2023-09-11 11:12:11 +02:00
Alice RyhlandGitHub bd9c164cb6 doc: fix changelog typo (#628) 2023-09-07 14:10:55 +02:00
23 changed files with 1297 additions and 498 deletions
+31 -23
View File
@@ -7,6 +7,8 @@ on:
push:
branches:
- master
schedule:
- cron: '0 2 * * 0'
env:
RUSTFLAGS: -Dwarnings
@@ -23,11 +25,11 @@ jobs:
name: rustfmt
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update stable && rustup default stable
run: rustup update stable
- name: Check formatting
run: cargo fmt --all -- --check
run: cargo fmt --all --check
# TODO
# # Apply clippy lints
@@ -35,7 +37,7 @@ jobs:
# name: clippy
# runs-on: ubuntu-latest
# steps:
# - uses: actions/checkout@v3
# - uses: actions/checkout@v4
# - name: Apply clippy lints
# run: cargo clippy --all-features
@@ -48,11 +50,11 @@ jobs:
name: minrust
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install Rust
run: rustup update 1.39.0 && rustup default 1.39.0
- uses: actions/checkout@v4
- name: Install cargo-hack
uses: taiki-e/install-action@cargo-hack
- name: Check
run: . ci/test-stable.sh check
run: cargo hack check --feature-powerset --optional-deps --rust-version
# Stable
stable:
@@ -65,23 +67,27 @@ jobs:
- windows-latest
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
# --no-self-update is necessary because the windows environment cannot self-update rustup.exe.
run: rustup update stable --no-self-update && rustup default stable
run: rustup update stable --no-self-update
- name: Install cargo-hack
uses: taiki-e/install-action@cargo-hack
- name: Test
run: . ci/test-stable.sh test
run: ci/test-stable.sh test
# Nightly
nightly:
name: nightly
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update $nightly && rustup default $nightly
- name: Install cargo-hack
uses: taiki-e/install-action@cargo-hack
- name: Test
run: . ci/test-stable.sh test
run: ci/test-stable.sh test
# Run tests on some extra platforms
cross:
@@ -96,13 +102,14 @@ jobs:
- wasm32-unknown-unknown
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update stable && rustup default stable
run: rustup update stable
- name: Install cross
uses: taiki-e/install-action@cross
if: matrix.target != 'wasm32-unknown-unknown'
- name: cross build --target ${{ matrix.target }}
run: |
cargo install cross
cross build --target ${{ matrix.target }}
run: cross build --target ${{ matrix.target }}
if: matrix.target != 'wasm32-unknown-unknown'
# WASM support
- name: cargo build --target ${{ matrix.target }}
@@ -116,18 +123,19 @@ jobs:
name: tsan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update $nightly && rustup default $nightly
- name: Install rust-src
run: rustup component add rust-src
- name: ASAN / TSAN
run: . ci/tsan.sh
run: ci/tsan.sh
miri:
name: miri
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Miri
run: ci/miri.sh
@@ -136,7 +144,7 @@ jobs:
name: loom
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update $nightly && rustup default $nightly
- name: Loom tests
@@ -155,7 +163,7 @@ jobs:
- loom
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
- name: Install Rust
run: rustup update $nightly && rustup default $nightly
- name: Build documentation
+72 -1
View File
@@ -1,8 +1,79 @@
# 1.7.0 (July 31, 2024)
### Added
- Add conversion from `Bytes` to `BytesMut` (#695, #710)
- Add reclaim method without additional allocation (#686)
### Documented
- Clarify how `BytesMut::zeroed` works (#714)
- Clarify the behavior of `Buf::chunk` (#717)
### Changed
- Change length condition of `BytesMut::truncate`
- Reuse capacity when possible in `<BytesMut as Buf>::advance` impl (#698)
- Improve `must_use` suggestion of `BytesMut::split` (#699)
### Internal changes
- Use `ManuallyDrop` instead of `mem::forget` (#678)
- Don't set `len` in `BytesMut::reserve` (#682)
- Optimize `Bytes::copy_to_bytes` (#688)
- Refactor `BytesMut::truncate` (#694)
- Refactor `BytesMut::resize` (#696)
- Reorder assertion in `Bytes::split_to`, `Bytes::split_off` (#689, #693)
- Use `offset_from` in more places (#705)
- Correct the wrong usage of `IntoIter` (#707)
# 1.6.1 (July 13, 2024)
This release fixes a bug where `Bytes::is_unique` returns incorrect values when
the `Bytes` originates from a shared `BytesMut`. (#718)
# 1.6.0 (March 22, 2024)
### Added
- Add `Bytes::is_unique` (#643)
### Documented
- Fix changelog typo (#628)
- Fix some spelling mistakes (#633)
- Typo fix (#637)
- Fix broken links (#639)
- Add security policy (#649)
### Internal changes
- Move comment to correct constant (#629)
- Various cleanup (#635)
- Simplify `UninitSlice::as_uninit_slice_mut()` logic (#644)
- Use `self.` instead of `Self::` (#642)
- `BytesMut`: Assert alignment of `Shared` (#652)
- Remove unnecessary namespace qualifier (#660)
- Remove an unnecessary else branch (#662)
- Remove unreachable else branch (#661)
- make parameter mut in `From<Vec>` (#667)
- Restore commented tests (#665)
- Use `sub` instead of `offset` (#668)
- Calculate original capacity only if necessary (#666)
- `set_vec_pos` does not need a second parameter (#672)
- `get_vec_pos`: use `&self` instead of `&mut self` (#670)
- Refactor `split_at`/`split_to` (#663)
- Use `Iterator` from the prelude (#673)
- `copy_to_bytes`: Add panic section to docs (#676)
- Remove redundant reserve call (#674)
- Use `ManuallyDrop` instead of `mem::forget` (#675)
# 1.5.0 (September 7, 2023)
### Added
- Add `UninitSlice::{new,init}` (#598, #599)
- Add `UninitSlice::{new,uninit}` (#598, #599)
- Implement `BufMut` for `&mut [MaybeUninit<u8>]` (#597)
### Changed
+4 -3
View File
@@ -4,7 +4,9 @@ name = "bytes"
# When releasing to crates.io:
# - Update CHANGELOG.md.
# - Create "v1.x.y" git tag.
version = "1.5.0"
version = "1.7.0"
edition = "2018"
rust-version = "1.39"
license = "MIT"
authors = [
"Carl Lerche <[email protected]>",
@@ -15,7 +17,6 @@ repository = "https://github.com/tokio-rs/bytes"
readme = "README.md"
keywords = ["buffers", "zero-copy", "io"]
categories = ["network-programming", "data-structures"]
edition = "2018"
[features]
default = ["std"]
@@ -28,7 +29,7 @@ serde = { version = "1.0.60", optional = true, default-features = false, feature
serde_test = "1.0"
[target.'cfg(loom)'.dev-dependencies]
loom = "0.5"
loom = "0.7"
[package.metadata.docs.rs]
rustdoc-args = ["--cfg", "docsrs"]
+9
View File
@@ -0,0 +1,9 @@
# Security Policy
Bytes is part of the Tokio project and uses the same security policy as [Tokio][tokio-security].
## Report a security issue
The process for reporting an issue is the same as for [Tokio][tokio-security]. This includes private reporting via security@tokio.rs.
[tokio-security]: https://github.com/tokio-rs/tokio/security/policy
+3 -3
View File
@@ -47,7 +47,7 @@ fn clone_static(b: &mut Bencher) {
b.iter(|| {
for _ in 0..1024 {
test::black_box(&bytes.clone());
test::black_box(test::black_box(&bytes).clone());
}
})
}
@@ -58,7 +58,7 @@ fn clone_shared(b: &mut Bencher) {
b.iter(|| {
for _ in 0..1024 {
test::black_box(&bytes.clone());
test::black_box(test::black_box(&bytes).clone());
}
})
}
@@ -70,7 +70,7 @@ fn clone_arc_vec(b: &mut Bencher) {
b.iter(|| {
for _ in 0..1024 {
test::black_box(&bytes.clone());
test::black_box(test::black_box(&bytes).clone());
}
})
}
Regular → Executable
-6
View File
@@ -4,10 +4,6 @@ set -ex
cmd="${1:-test}"
# Install cargo-hack for feature flag test
host=$(rustc -Vv | grep host | sed 's/host: //')
curl -LsSf https://github.com/taiki-e/cargo-hack/releases/latest/download/cargo-hack-$host.tar.gz | tar xzf - -C ~/.cargo/bin
# Run with each feature
# * --each-feature includes both default/no-default features
# * --optional-deps is needed for serde feature
@@ -15,8 +11,6 @@ cargo hack "${cmd}" --each-feature --optional-deps
# Run with all features
cargo "${cmd}" --all-features
cargo doc --no-deps --all-features
if [[ "${RUST_VERSION}" == "nightly"* ]]; then
# Check benchmarks
cargo check --benches
Regular → Executable
View File
+132 -60
View File
@@ -1,8 +1,9 @@
#[cfg(feature = "std")]
use crate::buf::{reader, Reader};
use crate::buf::{take, Chain, Take};
use core::{cmp, mem, ptr};
#[cfg(feature = "std")]
use crate::{min_u64_usize, saturating_sub_usize_u64};
use crate::{panic_advance, panic_does_not_fit};
#[cfg(feature = "std")]
use std::io::IoSlice;
@@ -11,7 +12,12 @@ use alloc::boxed::Box;
macro_rules! buf_get_impl {
($this:ident, $typ:tt::$conv:tt) => {{
const SIZE: usize = mem::size_of::<$typ>();
const SIZE: usize = core::mem::size_of::<$typ>();
if $this.remaining() < SIZE {
panic_advance(SIZE, $this.remaining());
}
// try to convert directly from the bytes
// this Option<ret> trick is to avoid keeping a borrow on self
// when advance() is called (mut borrow) and to call bytes() only once
@@ -32,19 +38,30 @@ macro_rules! buf_get_impl {
}
}};
(le => $this:ident, $typ:tt, $len_to_read:expr) => {{
debug_assert!(mem::size_of::<$typ>() >= $len_to_read);
const SIZE: usize = core::mem::size_of::<$typ>();
// The same trick as above does not improve the best case speed.
// It seems to be linked to the way the method is optimised by the compiler
let mut buf = [0; (mem::size_of::<$typ>())];
$this.copy_to_slice(&mut buf[..($len_to_read)]);
let mut buf = [0; SIZE];
let subslice = match buf.get_mut(..$len_to_read) {
Some(subslice) => subslice,
None => panic_does_not_fit(SIZE, $len_to_read),
};
$this.copy_to_slice(subslice);
return $typ::from_le_bytes(buf);
}};
(be => $this:ident, $typ:tt, $len_to_read:expr) => {{
debug_assert!(mem::size_of::<$typ>() >= $len_to_read);
const SIZE: usize = core::mem::size_of::<$typ>();
let mut buf = [0; (mem::size_of::<$typ>())];
$this.copy_to_slice(&mut buf[mem::size_of::<$typ>() - ($len_to_read)..]);
let slice_at = match SIZE.checked_sub($len_to_read) {
Some(slice_at) => slice_at,
None => panic_does_not_fit(SIZE, $len_to_read),
};
let mut buf = [0; SIZE];
$this.copy_to_slice(&mut buf[slice_at..]);
return $typ::from_be_bytes(buf);
}};
}
@@ -124,9 +141,11 @@ pub trait Buf {
///
/// # Implementer notes
///
/// This function should never panic. Once the end of the buffer is reached,
/// i.e., `Buf::remaining` returns 0, calls to `chunk()` should return an
/// empty slice.
/// This function should never panic. `chunk()` should return an empty
/// slice **if and only if** `remaining()` returns 0. In other words,
/// `chunk()` returning an empty slice implies that `remaining()` will
/// return 0 and `remaining()` returning 0 implies that `chunk()` will
/// return an empty slice.
// The `chunk` method was previously called `bytes`. This alias makes the rename
// more easily discoverable.
#[cfg_attr(docsrs, doc(alias = "bytes"))]
@@ -247,23 +266,18 @@ pub trait Buf {
///
/// # Panics
///
/// This function panics if `self.remaining() < dst.len()`
fn copy_to_slice(&mut self, dst: &mut [u8]) {
let mut off = 0;
/// This function panics if `self.remaining() < dst.len()`.
fn copy_to_slice(&mut self, mut dst: &mut [u8]) {
if self.remaining() < dst.len() {
panic_advance(dst.len(), self.remaining());
}
assert!(self.remaining() >= dst.len());
while !dst.is_empty() {
let src = self.chunk();
let cnt = usize::min(src.len(), dst.len());
while off < dst.len() {
let cnt;
unsafe {
let src = self.chunk();
cnt = cmp::min(src.len(), dst.len() - off);
ptr::copy_nonoverlapping(src.as_ptr(), dst[off..].as_mut_ptr(), cnt);
off += cnt;
}
dst[..cnt].copy_from_slice(&src[..cnt]);
dst = &mut dst[cnt..];
self.advance(cnt);
}
@@ -286,7 +300,9 @@ pub trait Buf {
///
/// This function panics if there is no more remaining data in `self`.
fn get_u8(&mut self) -> u8 {
assert!(self.remaining() >= 1);
if self.remaining() < 1 {
panic_advance(1, 0);
}
let ret = self.chunk()[0];
self.advance(1);
ret
@@ -309,7 +325,9 @@ pub trait Buf {
///
/// This function panics if there is no more remaining data in `self`.
fn get_i8(&mut self) -> i8 {
assert!(self.remaining() >= 1);
if self.remaining() < 1 {
panic_advance(1, 0);
}
let ret = self.chunk()[0] as i8;
self.advance(1);
ret
@@ -877,7 +895,8 @@ pub trait Buf {
///
/// # Panics
///
/// This function panics if there is not enough remaining data in `self`.
/// This function panics if there is not enough remaining data in `self`, or
/// if `nbytes` is greater than 8.
fn get_uint_ne(&mut self, nbytes: usize) -> u64 {
if cfg!(target_endian = "big") {
self.get_uint(nbytes)
@@ -901,7 +920,8 @@ pub trait Buf {
///
/// # Panics
///
/// This function panics if there is not enough remaining data in `self`.
/// This function panics if there is not enough remaining data in `self`, or
/// if `nbytes` is greater than 8.
fn get_int(&mut self, nbytes: usize) -> i64 {
buf_get_impl!(be => self, i64, nbytes);
}
@@ -921,7 +941,8 @@ pub trait Buf {
///
/// # Panics
///
/// This function panics if there is not enough remaining data in `self`.
/// This function panics if there is not enough remaining data in `self`, or
/// if `nbytes` is greater than 8.
fn get_int_le(&mut self, nbytes: usize) -> i64 {
buf_get_impl!(le => self, i64, nbytes);
}
@@ -944,7 +965,8 @@ pub trait Buf {
///
/// # Panics
///
/// This function panics if there is not enough remaining data in `self`.
/// This function panics if there is not enough remaining data in `self`, or
/// if `nbytes` is greater than 8.
fn get_int_ne(&mut self, nbytes: usize) -> i64 {
if cfg!(target_endian = "big") {
self.get_int(nbytes)
@@ -971,7 +993,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f32(&mut self) -> f32 {
f32::from_bits(Self::get_u32(self))
f32::from_bits(self.get_u32())
}
/// Gets an IEEE754 single-precision (4 bytes) floating point number from
@@ -992,7 +1014,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f32_le(&mut self) -> f32 {
f32::from_bits(Self::get_u32_le(self))
f32::from_bits(self.get_u32_le())
}
/// Gets an IEEE754 single-precision (4 bytes) floating point number from
@@ -1016,7 +1038,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f32_ne(&mut self) -> f32 {
f32::from_bits(Self::get_u32_ne(self))
f32::from_bits(self.get_u32_ne())
}
/// Gets an IEEE754 double-precision (8 bytes) floating point number from
@@ -1037,7 +1059,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f64(&mut self) -> f64 {
f64::from_bits(Self::get_u64(self))
f64::from_bits(self.get_u64())
}
/// Gets an IEEE754 double-precision (8 bytes) floating point number from
@@ -1058,7 +1080,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f64_le(&mut self) -> f64 {
f64::from_bits(Self::get_u64_le(self))
f64::from_bits(self.get_u64_le())
}
/// Gets an IEEE754 double-precision (8 bytes) floating point number from
@@ -1082,7 +1104,7 @@ pub trait Buf {
///
/// This function panics if there is not enough remaining data in `self`.
fn get_f64_ne(&mut self) -> f64 {
f64::from_bits(Self::get_u64_ne(self))
f64::from_bits(self.get_u64_ne())
}
/// Consumes `len` bytes inside self and returns new instance of `Bytes`
@@ -1100,10 +1122,16 @@ pub trait Buf {
/// let bytes = (&b"hello world"[..]).copy_to_bytes(5);
/// assert_eq!(&bytes[..], &b"hello"[..]);
/// ```
///
/// # Panics
///
/// This function panics if `len > self.remaining()`.
fn copy_to_bytes(&mut self, len: usize) -> crate::Bytes {
use super::BufMut;
assert!(len <= self.remaining(), "`len` greater than remaining");
if self.remaining() < len {
panic_advance(len, self.remaining());
}
let mut ret = crate::BytesMut::with_capacity(len);
ret.put(self.take(len));
@@ -1195,135 +1223,168 @@ pub trait Buf {
macro_rules! deref_forward_buf {
() => {
#[inline]
fn remaining(&self) -> usize {
(**self).remaining()
}
#[inline]
fn chunk(&self) -> &[u8] {
(**self).chunk()
}
#[cfg(feature = "std")]
#[inline]
fn chunks_vectored<'b>(&'b self, dst: &mut [IoSlice<'b>]) -> usize {
(**self).chunks_vectored(dst)
}
#[inline]
fn advance(&mut self, cnt: usize) {
(**self).advance(cnt)
}
#[inline]
fn has_remaining(&self) -> bool {
(**self).has_remaining()
}
#[inline]
fn copy_to_slice(&mut self, dst: &mut [u8]) {
(**self).copy_to_slice(dst)
}
#[inline]
fn get_u8(&mut self) -> u8 {
(**self).get_u8()
}
#[inline]
fn get_i8(&mut self) -> i8 {
(**self).get_i8()
}
#[inline]
fn get_u16(&mut self) -> u16 {
(**self).get_u16()
}
#[inline]
fn get_u16_le(&mut self) -> u16 {
(**self).get_u16_le()
}
#[inline]
fn get_u16_ne(&mut self) -> u16 {
(**self).get_u16_ne()
}
#[inline]
fn get_i16(&mut self) -> i16 {
(**self).get_i16()
}
#[inline]
fn get_i16_le(&mut self) -> i16 {
(**self).get_i16_le()
}
#[inline]
fn get_i16_ne(&mut self) -> i16 {
(**self).get_i16_ne()
}
#[inline]
fn get_u32(&mut self) -> u32 {
(**self).get_u32()
}
#[inline]
fn get_u32_le(&mut self) -> u32 {
(**self).get_u32_le()
}
#[inline]
fn get_u32_ne(&mut self) -> u32 {
(**self).get_u32_ne()
}
#[inline]
fn get_i32(&mut self) -> i32 {
(**self).get_i32()
}
#[inline]
fn get_i32_le(&mut self) -> i32 {
(**self).get_i32_le()
}
#[inline]
fn get_i32_ne(&mut self) -> i32 {
(**self).get_i32_ne()
}
#[inline]
fn get_u64(&mut self) -> u64 {
(**self).get_u64()
}
#[inline]
fn get_u64_le(&mut self) -> u64 {
(**self).get_u64_le()
}
#[inline]
fn get_u64_ne(&mut self) -> u64 {
(**self).get_u64_ne()
}
#[inline]
fn get_i64(&mut self) -> i64 {
(**self).get_i64()
}
#[inline]
fn get_i64_le(&mut self) -> i64 {
(**self).get_i64_le()
}
#[inline]
fn get_i64_ne(&mut self) -> i64 {
(**self).get_i64_ne()
}
#[inline]
fn get_uint(&mut self, nbytes: usize) -> u64 {
(**self).get_uint(nbytes)
}
#[inline]
fn get_uint_le(&mut self, nbytes: usize) -> u64 {
(**self).get_uint_le(nbytes)
}
#[inline]
fn get_uint_ne(&mut self, nbytes: usize) -> u64 {
(**self).get_uint_ne(nbytes)
}
#[inline]
fn get_int(&mut self, nbytes: usize) -> i64 {
(**self).get_int(nbytes)
}
#[inline]
fn get_int_le(&mut self, nbytes: usize) -> i64 {
(**self).get_int_le(nbytes)
}
#[inline]
fn get_int_ne(&mut self, nbytes: usize) -> i64 {
(**self).get_int_ne(nbytes)
}
#[inline]
fn copy_to_bytes(&mut self, len: usize) -> crate::Bytes {
(**self).copy_to_bytes(len)
}
@@ -1351,41 +1412,52 @@ impl Buf for &[u8] {
#[inline]
fn advance(&mut self, cnt: usize) {
if self.len() < cnt {
panic_advance(cnt, self.len());
}
*self = &self[cnt..];
}
#[inline]
fn copy_to_slice(&mut self, dst: &mut [u8]) {
if self.len() < dst.len() {
panic_advance(dst.len(), self.len());
}
dst.copy_from_slice(&self[..dst.len()]);
self.advance(dst.len());
}
}
#[cfg(feature = "std")]
impl<T: AsRef<[u8]>> Buf for std::io::Cursor<T> {
#[inline]
fn remaining(&self) -> usize {
let len = self.get_ref().as_ref().len();
let pos = self.position();
if pos >= len as u64 {
return 0;
}
len - pos as usize
saturating_sub_usize_u64(self.get_ref().as_ref().len(), self.position())
}
#[inline]
fn chunk(&self) -> &[u8] {
let slice = self.get_ref().as_ref();
let pos = min_u64_usize(self.position(), slice.len());
&slice[pos..]
}
#[inline]
fn advance(&mut self, cnt: usize) {
let len = self.get_ref().as_ref().len();
let pos = self.position();
if pos >= len as u64 {
return &[];
// We intentionally allow `cnt == 0` here even if `pos > len`.
let max_cnt = saturating_sub_usize_u64(len, pos);
if cnt > max_cnt {
panic_advance(cnt, max_cnt);
}
&self.get_ref().as_ref()[pos as usize..]
}
fn advance(&mut self, cnt: usize) {
let pos = (self.position() as usize)
.checked_add(cnt)
.expect("overflow");
assert!(pos <= self.get_ref().as_ref().len());
self.set_position(pos as u64);
// This will not overflow because either `cnt == 0` or the sum is not
// greater than `len`.
self.set_position(pos + cnt as u64);
}
}
+188 -75
View File
@@ -1,8 +1,9 @@
use crate::buf::{limit, Chain, Limit, UninitSlice};
#[cfg(feature = "std")]
use crate::buf::{writer, Writer};
use crate::{panic_advance, panic_does_not_fit};
use core::{cmp, mem, ptr, usize};
use core::{mem, ptr, usize};
use alloc::{boxed::Box, vec::Vec};
@@ -67,8 +68,10 @@ pub unsafe trait BufMut {
/// The next call to `chunk_mut` will return a slice starting `cnt` bytes
/// further into the underlying buffer.
///
/// This function is unsafe because there is no guarantee that the bytes
/// being advanced past have been initialized.
/// # Safety
///
/// The caller must ensure that the next `cnt` bytes of `chunk` are
/// initialized.
///
/// # Examples
///
@@ -121,6 +124,7 @@ pub unsafe trait BufMut {
///
/// assert!(!buf.has_remaining_mut());
/// ```
#[inline]
fn has_remaining_mut(&self) -> bool {
self.remaining_mut() > 0
}
@@ -161,7 +165,7 @@ pub unsafe trait BufMut {
///
/// # Implementer notes
///
/// This function should never panic. `chunk_mut` should return an empty
/// This function should never panic. `chunk_mut()` should return an empty
/// slice **if and only if** `remaining_mut()` returns 0. In other words,
/// `chunk_mut()` returning an empty slice implies that `remaining_mut()` will
/// return 0 and `remaining_mut()` returning 0 implies that `chunk_mut()` will
@@ -194,27 +198,25 @@ pub unsafe trait BufMut {
/// # Panics
///
/// Panics if `self` does not have enough capacity to contain `src`.
#[inline]
fn put<T: super::Buf>(&mut self, mut src: T)
where
Self: Sized,
{
assert!(self.remaining_mut() >= src.remaining());
if self.remaining_mut() < src.remaining() {
panic_advance(src.remaining(), self.remaining_mut());
}
while src.has_remaining() {
let l;
let s = src.chunk();
let d = self.chunk_mut();
let cnt = usize::min(s.len(), d.len());
unsafe {
let s = src.chunk();
let d = self.chunk_mut();
l = cmp::min(s.len(), d.len());
d[..cnt].copy_from_slice(&s[..cnt]);
ptr::copy_nonoverlapping(s.as_ptr(), d.as_mut_ptr() as *mut u8, l);
}
src.advance(l);
unsafe {
self.advance_mut(l);
}
// SAFETY: We just initialized `cnt` bytes in `self`.
unsafe { self.advance_mut(cnt) };
src.advance(cnt);
}
}
@@ -237,31 +239,21 @@ pub unsafe trait BufMut {
///
/// assert_eq!(b"hello\0", &dst);
/// ```
fn put_slice(&mut self, src: &[u8]) {
let mut off = 0;
#[inline]
fn put_slice(&mut self, mut src: &[u8]) {
if self.remaining_mut() < src.len() {
panic_advance(src.len(), self.remaining_mut());
}
assert!(
self.remaining_mut() >= src.len(),
"buffer overflow; remaining = {}; src = {}",
self.remaining_mut(),
src.len()
);
while !src.is_empty() {
let dst = self.chunk_mut();
let cnt = usize::min(src.len(), dst.len());
while off < src.len() {
let cnt;
dst[..cnt].copy_from_slice(&src[..cnt]);
src = &src[cnt..];
unsafe {
let dst = self.chunk_mut();
cnt = cmp::min(dst.len(), src.len() - off);
ptr::copy_nonoverlapping(src[off..].as_ptr(), dst.as_mut_ptr() as *mut u8, cnt);
off += cnt;
}
unsafe {
self.advance_mut(cnt);
}
// SAFETY: We just initialized `cnt` bytes in `self`.
unsafe { self.advance_mut(cnt) };
}
}
@@ -290,9 +282,20 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
fn put_bytes(&mut self, val: u8, cnt: usize) {
for _ in 0..cnt {
self.put_u8(val);
#[inline]
fn put_bytes(&mut self, val: u8, mut cnt: usize) {
if self.remaining_mut() < cnt {
panic_advance(cnt, self.remaining_mut());
}
while cnt > 0 {
let dst = self.chunk_mut();
let dst_len = usize::min(dst.len(), cnt);
// SAFETY: The pointer is valid for `dst_len <= dst.len()` bytes.
unsafe { core::ptr::write_bytes(dst.as_mut_ptr(), val, dst_len) };
// SAFETY: We just initialized `dst_len` bytes in `self`.
unsafe { self.advance_mut(dst_len) };
cnt -= dst_len;
}
}
@@ -314,6 +317,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u8(&mut self, n: u8) {
let src = [n];
self.put_slice(&src);
@@ -337,6 +341,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i8(&mut self, n: i8) {
let src = [n as u8];
self.put_slice(&src)
@@ -360,6 +365,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u16(&mut self, n: u16) {
self.put_slice(&n.to_be_bytes())
}
@@ -382,6 +388,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u16_le(&mut self, n: u16) {
self.put_slice(&n.to_le_bytes())
}
@@ -408,6 +415,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u16_ne(&mut self, n: u16) {
self.put_slice(&n.to_ne_bytes())
}
@@ -430,6 +438,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i16(&mut self, n: i16) {
self.put_slice(&n.to_be_bytes())
}
@@ -452,6 +461,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i16_le(&mut self, n: i16) {
self.put_slice(&n.to_le_bytes())
}
@@ -478,6 +488,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i16_ne(&mut self, n: i16) {
self.put_slice(&n.to_ne_bytes())
}
@@ -500,6 +511,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u32(&mut self, n: u32) {
self.put_slice(&n.to_be_bytes())
}
@@ -522,6 +534,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u32_le(&mut self, n: u32) {
self.put_slice(&n.to_le_bytes())
}
@@ -548,6 +561,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u32_ne(&mut self, n: u32) {
self.put_slice(&n.to_ne_bytes())
}
@@ -570,6 +584,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i32(&mut self, n: i32) {
self.put_slice(&n.to_be_bytes())
}
@@ -592,6 +607,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i32_le(&mut self, n: i32) {
self.put_slice(&n.to_le_bytes())
}
@@ -618,6 +634,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i32_ne(&mut self, n: i32) {
self.put_slice(&n.to_ne_bytes())
}
@@ -640,6 +657,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u64(&mut self, n: u64) {
self.put_slice(&n.to_be_bytes())
}
@@ -662,6 +680,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u64_le(&mut self, n: u64) {
self.put_slice(&n.to_le_bytes())
}
@@ -688,6 +707,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u64_ne(&mut self, n: u64) {
self.put_slice(&n.to_ne_bytes())
}
@@ -710,6 +730,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i64(&mut self, n: i64) {
self.put_slice(&n.to_be_bytes())
}
@@ -732,6 +753,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i64_le(&mut self, n: i64) {
self.put_slice(&n.to_le_bytes())
}
@@ -758,6 +780,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i64_ne(&mut self, n: i64) {
self.put_slice(&n.to_ne_bytes())
}
@@ -780,6 +803,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u128(&mut self, n: u128) {
self.put_slice(&n.to_be_bytes())
}
@@ -802,6 +826,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u128_le(&mut self, n: u128) {
self.put_slice(&n.to_le_bytes())
}
@@ -828,6 +853,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_u128_ne(&mut self, n: u128) {
self.put_slice(&n.to_ne_bytes())
}
@@ -850,6 +876,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i128(&mut self, n: i128) {
self.put_slice(&n.to_be_bytes())
}
@@ -872,6 +899,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i128_le(&mut self, n: i128) {
self.put_slice(&n.to_le_bytes())
}
@@ -898,6 +926,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_i128_ne(&mut self, n: i128) {
self.put_slice(&n.to_ne_bytes())
}
@@ -919,9 +948,15 @@ pub unsafe trait BufMut {
/// # Panics
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_uint(&mut self, n: u64, nbytes: usize) {
self.put_slice(&n.to_be_bytes()[mem::size_of_val(&n) - nbytes..]);
let start = match mem::size_of_val(&n).checked_sub(nbytes) {
Some(start) => start,
None => panic_does_not_fit(nbytes, mem::size_of_val(&n)),
};
self.put_slice(&n.to_be_bytes()[start..]);
}
/// Writes an unsigned n-byte integer to `self` in the little-endian byte order.
@@ -941,9 +976,16 @@ pub unsafe trait BufMut {
/// # Panics
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_uint_le(&mut self, n: u64, nbytes: usize) {
self.put_slice(&n.to_le_bytes()[0..nbytes]);
let slice = n.to_le_bytes();
let slice = match slice.get(..nbytes) {
Some(slice) => slice,
None => panic_does_not_fit(nbytes, slice.len()),
};
self.put_slice(slice);
}
/// Writes an unsigned n-byte integer to `self` in the native-endian byte order.
@@ -967,7 +1009,8 @@ pub unsafe trait BufMut {
/// # Panics
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_uint_ne(&mut self, n: u64, nbytes: usize) {
if cfg!(target_endian = "big") {
self.put_uint(n, nbytes)
@@ -994,8 +1037,14 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_int(&mut self, n: i64, nbytes: usize) {
self.put_slice(&n.to_be_bytes()[mem::size_of_val(&n) - nbytes..]);
let start = match mem::size_of_val(&n).checked_sub(nbytes) {
Some(start) => start,
None => panic_does_not_fit(nbytes, mem::size_of_val(&n)),
};
self.put_slice(&n.to_be_bytes()[start..]);
}
/// Writes low `nbytes` of a signed integer to `self` in little-endian byte order.
@@ -1016,8 +1065,15 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_int_le(&mut self, n: i64, nbytes: usize) {
self.put_slice(&n.to_le_bytes()[0..nbytes]);
let slice = n.to_le_bytes();
let slice = match slice.get(..nbytes) {
Some(slice) => slice,
None => panic_does_not_fit(nbytes, slice.len()),
};
self.put_slice(slice);
}
/// Writes low `nbytes` of a signed integer to `self` in native-endian byte order.
@@ -1042,6 +1098,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self` or if `nbytes` is greater than 8.
#[inline]
fn put_int_ne(&mut self, n: i64, nbytes: usize) {
if cfg!(target_endian = "big") {
self.put_int(n, nbytes)
@@ -1069,6 +1126,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f32(&mut self, n: f32) {
self.put_u32(n.to_bits());
}
@@ -1092,6 +1150,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f32_le(&mut self, n: f32) {
self.put_u32_le(n.to_bits());
}
@@ -1119,6 +1178,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f32_ne(&mut self, n: f32) {
self.put_u32_ne(n.to_bits());
}
@@ -1142,6 +1202,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f64(&mut self, n: f64) {
self.put_u64(n.to_bits());
}
@@ -1165,6 +1226,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f64_le(&mut self, n: f64) {
self.put_u64_le(n.to_bits());
}
@@ -1192,6 +1254,7 @@ pub unsafe trait BufMut {
///
/// This function panics if there is not enough remaining capacity in
/// `self`.
#[inline]
fn put_f64_ne(&mut self, n: f64) {
self.put_u64_ne(n.to_bits());
}
@@ -1209,6 +1272,7 @@ pub unsafe trait BufMut {
/// let dst = arr.limit(10);
/// assert_eq!(dst.remaining_mut(), 10);
/// ```
#[inline]
fn limit(self, limit: usize) -> Limit<Self>
where
Self: Sized,
@@ -1240,6 +1304,7 @@ pub unsafe trait BufMut {
/// ```
#[cfg(feature = "std")]
#[cfg_attr(docsrs, doc(cfg(feature = "std")))]
#[inline]
fn writer(self) -> Writer<Self>
where
Self: Sized,
@@ -1267,6 +1332,7 @@ pub unsafe trait BufMut {
/// assert_eq!(&a[..], b"hello");
/// assert_eq!(&b[..], b" world");
/// ```
#[inline]
fn chain_mut<U: BufMut>(self, next: U) -> Chain<Self, U>
where
Self: Sized,
@@ -1277,98 +1343,122 @@ pub unsafe trait BufMut {
macro_rules! deref_forward_bufmut {
() => {
#[inline]
fn remaining_mut(&self) -> usize {
(**self).remaining_mut()
}
#[inline]
fn chunk_mut(&mut self) -> &mut UninitSlice {
(**self).chunk_mut()
}
#[inline]
unsafe fn advance_mut(&mut self, cnt: usize) {
(**self).advance_mut(cnt)
}
#[inline]
fn put_slice(&mut self, src: &[u8]) {
(**self).put_slice(src)
}
#[inline]
fn put_u8(&mut self, n: u8) {
(**self).put_u8(n)
}
#[inline]
fn put_i8(&mut self, n: i8) {
(**self).put_i8(n)
}
#[inline]
fn put_u16(&mut self, n: u16) {
(**self).put_u16(n)
}
#[inline]
fn put_u16_le(&mut self, n: u16) {
(**self).put_u16_le(n)
}
#[inline]
fn put_u16_ne(&mut self, n: u16) {
(**self).put_u16_ne(n)
}
#[inline]
fn put_i16(&mut self, n: i16) {
(**self).put_i16(n)
}
#[inline]
fn put_i16_le(&mut self, n: i16) {
(**self).put_i16_le(n)
}
#[inline]
fn put_i16_ne(&mut self, n: i16) {
(**self).put_i16_ne(n)
}
#[inline]
fn put_u32(&mut self, n: u32) {
(**self).put_u32(n)
}
#[inline]
fn put_u32_le(&mut self, n: u32) {
(**self).put_u32_le(n)
}
#[inline]
fn put_u32_ne(&mut self, n: u32) {
(**self).put_u32_ne(n)
}
#[inline]
fn put_i32(&mut self, n: i32) {
(**self).put_i32(n)
}
#[inline]
fn put_i32_le(&mut self, n: i32) {
(**self).put_i32_le(n)
}
#[inline]
fn put_i32_ne(&mut self, n: i32) {
(**self).put_i32_ne(n)
}
#[inline]
fn put_u64(&mut self, n: u64) {
(**self).put_u64(n)
}
#[inline]
fn put_u64_le(&mut self, n: u64) {
(**self).put_u64_le(n)
}
#[inline]
fn put_u64_ne(&mut self, n: u64) {
(**self).put_u64_ne(n)
}
#[inline]
fn put_i64(&mut self, n: i64) {
(**self).put_i64(n)
}
#[inline]
fn put_i64_le(&mut self, n: i64) {
(**self).put_i64_le(n)
}
#[inline]
fn put_i64_ne(&mut self, n: i64) {
(**self).put_i64_ne(n)
}
@@ -1391,12 +1481,15 @@ unsafe impl BufMut for &mut [u8] {
#[inline]
fn chunk_mut(&mut self) -> &mut UninitSlice {
// UninitSlice is repr(transparent), so safe to transmute
unsafe { &mut *(*self as *mut [u8] as *mut _) }
UninitSlice::new(self)
}
#[inline]
unsafe fn advance_mut(&mut self, cnt: usize) {
if self.len() < cnt {
panic_advance(cnt, self.len());
}
// Lifetime dance taken from `impl Write for &mut [u8]`.
let (_, b) = core::mem::replace(self, &mut []).split_at_mut(cnt);
*self = b;
@@ -1404,14 +1497,22 @@ unsafe impl BufMut for &mut [u8] {
#[inline]
fn put_slice(&mut self, src: &[u8]) {
self[..src.len()].copy_from_slice(src);
unsafe {
self.advance_mut(src.len());
if self.len() < src.len() {
panic_advance(src.len(), self.len());
}
self[..src.len()].copy_from_slice(src);
// SAFETY: We just initialized `src.len()` bytes.
unsafe { self.advance_mut(src.len()) };
}
#[inline]
fn put_bytes(&mut self, val: u8, cnt: usize) {
assert!(self.remaining_mut() >= cnt);
if self.len() < cnt {
panic_advance(cnt, self.len());
}
// SAFETY: We just checked that the pointer is valid for `cnt` bytes.
unsafe {
ptr::write_bytes(self.as_mut_ptr(), val, cnt);
self.advance_mut(cnt);
@@ -1432,6 +1533,10 @@ unsafe impl BufMut for &mut [core::mem::MaybeUninit<u8>] {
#[inline]
unsafe fn advance_mut(&mut self, cnt: usize) {
if self.len() < cnt {
panic_advance(cnt, self.len());
}
// Lifetime dance taken from `impl Write for &mut [u8]`.
let (_, b) = core::mem::replace(self, &mut []).split_at_mut(cnt);
*self = b;
@@ -1439,14 +1544,24 @@ unsafe impl BufMut for &mut [core::mem::MaybeUninit<u8>] {
#[inline]
fn put_slice(&mut self, src: &[u8]) {
self.chunk_mut()[..src.len()].copy_from_slice(src);
if self.len() < src.len() {
panic_advance(src.len(), self.len());
}
// SAFETY: We just checked that the pointer is valid for `src.len()` bytes.
unsafe {
ptr::copy_nonoverlapping(src.as_ptr(), self.as_mut_ptr().cast(), src.len());
self.advance_mut(src.len());
}
}
#[inline]
fn put_bytes(&mut self, val: u8, cnt: usize) {
assert!(self.remaining_mut() >= cnt);
if self.len() < cnt {
panic_advance(cnt, self.len());
}
// SAFETY: We just checked that the pointer is valid for `cnt` bytes.
unsafe {
ptr::write_bytes(self.as_mut_ptr() as *mut u8, val, cnt);
self.advance_mut(cnt);
@@ -1466,13 +1581,11 @@ unsafe impl BufMut for Vec<u8> {
let len = self.len();
let remaining = self.capacity() - len;
assert!(
cnt <= remaining,
"cannot advance past `remaining_mut`: {:?} <= {:?}",
cnt,
remaining
);
if remaining < cnt {
panic_advance(cnt, remaining);
}
// Addition will not overflow since the sum is at most the capacity.
self.set_len(len + cnt);
}
@@ -1486,28 +1599,26 @@ unsafe impl BufMut for Vec<u8> {
let len = self.len();
let ptr = self.as_mut_ptr();
unsafe { &mut UninitSlice::from_raw_parts_mut(ptr, cap)[len..] }
// SAFETY: Since `ptr` is valid for `cap` bytes, `ptr.add(len)` must be
// valid for `cap - len` bytes. The subtraction will not underflow since
// `len <= cap`.
unsafe { UninitSlice::from_raw_parts_mut(ptr.add(len), cap - len) }
}
// Specialize these methods so they can skip checking `remaining_mut`
// and `advance_mut`.
#[inline]
fn put<T: super::Buf>(&mut self, mut src: T)
where
Self: Sized,
{
// In case the src isn't contiguous, reserve upfront
// In case the src isn't contiguous, reserve upfront.
self.reserve(src.remaining());
while src.has_remaining() {
let l;
// a block to contain the src.bytes() borrow
{
let s = src.chunk();
l = s.len();
self.extend_from_slice(s);
}
let s = src.chunk();
let l = s.len();
self.extend_from_slice(s);
src.advance(l);
}
}
@@ -1517,8 +1628,10 @@ unsafe impl BufMut for Vec<u8> {
self.extend_from_slice(src);
}
#[inline]
fn put_bytes(&mut self, val: u8, cnt: usize) {
let new_len = self.len().checked_add(cnt).unwrap();
// If the addition overflows, then the `resize` will fail.
let new_len = self.len().saturating_add(cnt);
self.resize(new_len, val);
}
}
+2 -4
View File
@@ -25,9 +25,7 @@ use std::io::IoSlice;
/// assert_eq!(full[..], b"hello world"[..]);
/// ```
///
/// [`Buf::chain`]: trait.Buf.html#method.chain
/// [`Buf`]: trait.Buf.html
/// [`BufMut`]: trait.BufMut.html
/// [`Buf::chain`]: Buf::chain
#[derive(Debug)]
pub struct Chain<T, U> {
a: T,
@@ -135,7 +133,7 @@ where
U: Buf,
{
fn remaining(&self) -> usize {
self.a.remaining().checked_add(self.b.remaining()).unwrap()
self.a.remaining().saturating_add(self.b.remaining())
}
fn chunk(&self) -> &[u8] {
-3
View File
@@ -17,9 +17,6 @@ use crate::Buf;
/// assert_eq!(iter.next(), Some(b'c'));
/// assert_eq!(iter.next(), None);
/// ```
///
/// [`iter`]: trait.Buf.html#method.iter
/// [`Buf`]: trait.Buf.html
#[derive(Debug)]
pub struct IntoIter<T> {
inner: T,
-2
View File
@@ -13,8 +13,6 @@
//! See [`Buf`] and [`BufMut`] for more details.
//!
//! [rope]: https://en.wikipedia.org/wiki/Rope_(data_structure)
//! [`Buf`]: trait.Buf.html
//! [`BufMut`]: trait.BufMut.html
mod buf_impl;
mod buf_mut;
+1 -1
View File
@@ -5,7 +5,7 @@ use std::{cmp, io};
/// A `Buf` adapter which implements `io::Read` for the inner value.
///
/// This struct is generally created by calling `reader()` on `Buf`. See
/// documentation of [`reader()`](trait.Buf.html#method.reader) for more
/// documentation of [`reader()`](Buf::reader) for more
/// details.
#[derive(Debug)]
pub struct Reader<B> {
+1 -1
View File
@@ -5,7 +5,7 @@ use core::cmp;
/// A `Buf` adapter which limits the bytes read from an underlying buffer.
///
/// This struct is generally created by calling `take()` on `Buf`. See
/// documentation of [`take()`](trait.Buf.html#method.take) for more details.
/// documentation of [`take()`](Buf::take) for more details.
#[derive(Debug)]
pub struct Take<T> {
inner: T,
+3 -3
View File
@@ -168,7 +168,7 @@ impl UninitSlice {
///
/// The caller **must not** read from the referenced memory and **must not** write
/// **uninitialized** bytes to the slice either. This is because `BufMut` implementation
/// that created the `UninitSlice` knows which parts are initialized. Writing uninitalized
/// that created the `UninitSlice` knows which parts are initialized. Writing uninitialized
/// bytes to the slice may cause the `BufMut` to read those bytes and trigger undefined
/// behavior.
///
@@ -184,8 +184,8 @@ impl UninitSlice {
/// };
/// ```
#[inline]
pub unsafe fn as_uninit_slice_mut<'a>(&'a mut self) -> &'a mut [MaybeUninit<u8>] {
&mut *(self as *mut _ as *mut [MaybeUninit<u8>])
pub unsafe fn as_uninit_slice_mut(&mut self) -> &mut [MaybeUninit<u8>] {
&mut self.0
}
/// Returns the number of bytes in the slice.
+1 -1
View File
@@ -5,7 +5,7 @@ use std::{cmp, io};
/// A `BufMut` adapter which implements `io::Write` for the inner value.
///
/// This struct is generally created by calling `writer()` on `BufMut`. See
/// documentation of [`writer()`](trait.BufMut.html#method.writer) for more
/// documentation of [`writer()`](BufMut::writer) for more
/// details.
#[derive(Debug)]
pub struct Writer<B> {
+217 -41
View File
@@ -1,6 +1,7 @@
use core::iter::FromIterator;
use core::mem::{self, ManuallyDrop};
use core::ops::{Deref, RangeBounds};
use core::{cmp, fmt, hash, mem, ptr, slice, usize};
use core::{cmp, fmt, hash, ptr, slice, usize};
use alloc::{
alloc::{dealloc, Layout},
@@ -14,7 +15,7 @@ use crate::buf::IntoIter;
#[allow(unused)]
use crate::loom::sync::atomic::AtomicMut;
use crate::loom::sync::atomic::{AtomicPtr, AtomicUsize, Ordering};
use crate::Buf;
use crate::{offset_from, Buf, BytesMut};
/// A cheaply cloneable and sliceable chunk of contiguous memory.
///
@@ -63,8 +64,8 @@ use crate::Buf;
/// `Bytes` contains a vtable, which allows implementations of `Bytes` to define
/// how sharing/cloning is implemented in detail.
/// When `Bytes::clone()` is called, `Bytes` will call the vtable function for
/// cloning the backing storage in order to share it behind between multiple
/// `Bytes` instances.
/// cloning the backing storage in order to share it behind multiple `Bytes`
/// instances.
///
/// For `Bytes` implementations which refer to constant memory (e.g. created
/// via `Bytes::from_static()`) the cloning implementation will be a no-op.
@@ -112,6 +113,9 @@ pub(crate) struct Vtable {
///
/// takes `Bytes` to value
pub to_vec: unsafe fn(&AtomicPtr<()>, *const u8, usize) -> Vec<u8>,
pub to_mut: unsafe fn(&AtomicPtr<()>, *const u8, usize) -> BytesMut,
/// fn(data)
pub is_unique: unsafe fn(&AtomicPtr<()>) -> bool,
/// fn(data, ptr, len)
pub drop: unsafe fn(&mut AtomicPtr<()>, *const u8, usize),
}
@@ -208,6 +212,28 @@ impl Bytes {
self.len == 0
}
/// Returns true if this is the only reference to the data.
///
/// Always returns false if the data is backed by a static slice.
///
/// The result of this method may be invalidated immediately if another
/// thread clones this value while this is being called. Ensure you have
/// unique access to this value (`&mut Bytes`) first if you need to be
/// certain the result is valid (i.e. for safety reasons)
/// # Examples
///
/// ```
/// use bytes::Bytes;
///
/// let a = Bytes::from(vec![1, 2, 3]);
/// assert!(a.is_unique());
/// let b = a.clone();
/// assert!(!a.is_unique());
/// ```
pub fn is_unique(&self) -> bool {
unsafe { (self.vtable.is_unique)(&self.data) }
}
/// Creates `Bytes` instance from slice, by copying it.
pub fn copy_from_slice(data: &[u8]) -> Self {
data.to_vec().into()
@@ -242,7 +268,7 @@ impl Bytes {
let begin = match range.start_bound() {
Bound::Included(&n) => n,
Bound::Excluded(&n) => n + 1,
Bound::Excluded(&n) => n.checked_add(1).expect("out of range"),
Bound::Unbounded => 0,
};
@@ -360,13 +386,6 @@ impl Bytes {
/// Panics if `at > len`.
#[must_use = "consider Bytes::truncate if you don't need the other half"]
pub fn split_off(&mut self, at: usize) -> Self {
assert!(
at <= self.len(),
"split_off out of bounds: {:?} <= {:?}",
at,
self.len(),
);
if at == self.len() {
return Bytes::new();
}
@@ -375,6 +394,13 @@ impl Bytes {
return mem::replace(self, Bytes::new());
}
assert!(
at <= self.len(),
"split_off out of bounds: {:?} <= {:?}",
at,
self.len(),
);
let mut ret = self.clone();
self.len = at;
@@ -409,13 +435,6 @@ impl Bytes {
/// Panics if `at > len`.
#[must_use = "consider Bytes::advance if you don't need the other half"]
pub fn split_to(&mut self, at: usize) -> Self {
assert!(
at <= self.len(),
"split_to out of bounds: {:?} <= {:?}",
at,
self.len(),
);
if at == self.len() {
return mem::replace(self, Bytes::new());
}
@@ -424,6 +443,13 @@ impl Bytes {
return Bytes::new();
}
assert!(
at <= self.len(),
"split_to out of bounds: {:?} <= {:?}",
at,
self.len(),
);
let mut ret = self.clone();
unsafe { self.inc_start(at) };
@@ -438,7 +464,7 @@ impl Bytes {
/// If `len` is greater than the buffer's current length, this has no
/// effect.
///
/// The [`split_off`] method can emulate `truncate`, but this causes the
/// The [split_off](`Self::split_off()`) method can emulate `truncate`, but this causes the
/// excess bytes to be returned instead of dropped.
///
/// # Examples
@@ -450,8 +476,6 @@ impl Bytes {
/// buf.truncate(5);
/// assert_eq!(buf, b"hello"[..]);
/// ```
///
/// [`split_off`]: #method.split_off
#[inline]
pub fn truncate(&mut self, len: usize) {
if len < self.len {
@@ -484,6 +508,29 @@ impl Bytes {
self.truncate(0);
}
/// Try to convert self into `BytesMut`.
///
/// If `self` is unique for the entire original buffer, this will succeed
/// and return a `BytesMut` with the contents of `self` without copying.
/// If `self` is not unique for the entire original buffer, this will fail
/// and return self.
///
/// # Examples
///
/// ```
/// use bytes::{Bytes, BytesMut};
///
/// let bytes = Bytes::from(b"hello".to_vec());
/// assert_eq!(bytes.try_into_mut(), Ok(BytesMut::from(&b"hello"[..])));
/// ```
pub fn try_into_mut(self) -> Result<BytesMut, Bytes> {
if self.is_unique() {
Ok(self.into())
} else {
Err(self)
}
}
#[inline]
pub(crate) unsafe fn with_vtable(
ptr: *const u8,
@@ -558,14 +605,8 @@ impl Buf for Bytes {
}
}
fn copy_to_bytes(&mut self, len: usize) -> crate::Bytes {
if len == self.remaining() {
core::mem::replace(self, Bytes::new())
} else {
let ret = self.slice(..len);
self.advance(len);
ret
}
fn copy_to_bytes(&mut self, len: usize) -> Self {
self.split_to(len)
}
}
@@ -807,13 +848,14 @@ impl From<&'static str> for Bytes {
impl From<Vec<u8>> for Bytes {
fn from(vec: Vec<u8>) -> Bytes {
let mut vec = vec;
let mut vec = ManuallyDrop::new(vec);
let ptr = vec.as_mut_ptr();
let len = vec.len();
let cap = vec.capacity();
// Avoid an extra allocation if possible.
if len == cap {
let vec = ManuallyDrop::into_inner(vec);
return Bytes::from(vec.into_boxed_slice());
}
@@ -822,7 +864,6 @@ impl From<Vec<u8>> for Bytes {
cap,
ref_cnt: AtomicUsize::new(1),
});
mem::forget(vec);
let shared = Box::into_raw(shared);
// The pointer should be aligned, so this assert should
@@ -871,6 +912,28 @@ impl From<Box<[u8]>> for Bytes {
}
}
impl From<Bytes> for BytesMut {
/// Convert self into `BytesMut`.
///
/// If `bytes` is unique for the entire original buffer, this will return a
/// `BytesMut` with the contents of `bytes` without copying.
/// If `bytes` is not unique for the entire original buffer, this will make
/// a copy of `bytes` subset of the original buffer in a new `BytesMut`.
///
/// # Examples
///
/// ```
/// use bytes::{Bytes, BytesMut};
///
/// let bytes = Bytes::from(b"hello".to_vec());
/// assert_eq!(BytesMut::from(bytes), BytesMut::from(&b"hello"[..]));
/// ```
fn from(bytes: Bytes) -> Self {
let bytes = ManuallyDrop::new(bytes);
unsafe { (bytes.vtable.to_mut)(&bytes.data, bytes.ptr, bytes.len) }
}
}
impl From<String> for Bytes {
fn from(s: String) -> Bytes {
Bytes::from(s.into_bytes())
@@ -879,7 +942,7 @@ impl From<String> for Bytes {
impl From<Bytes> for Vec<u8> {
fn from(bytes: Bytes) -> Vec<u8> {
let bytes = mem::ManuallyDrop::new(bytes);
let bytes = ManuallyDrop::new(bytes);
unsafe { (bytes.vtable.to_vec)(&bytes.data, bytes.ptr, bytes.len) }
}
}
@@ -900,6 +963,8 @@ impl fmt::Debug for Vtable {
const STATIC_VTABLE: Vtable = Vtable {
clone: static_clone,
to_vec: static_to_vec,
to_mut: static_to_mut,
is_unique: static_is_unique,
drop: static_drop,
};
@@ -913,6 +978,15 @@ unsafe fn static_to_vec(_: &AtomicPtr<()>, ptr: *const u8, len: usize) -> Vec<u8
slice.to_vec()
}
unsafe fn static_to_mut(_: &AtomicPtr<()>, ptr: *const u8, len: usize) -> BytesMut {
let slice = slice::from_raw_parts(ptr, len);
BytesMut::from(slice)
}
fn static_is_unique(_: &AtomicPtr<()>) -> bool {
false
}
unsafe fn static_drop(_: &mut AtomicPtr<()>, _: *const u8, _: usize) {
// nothing to drop for &'static [u8]
}
@@ -922,12 +996,16 @@ unsafe fn static_drop(_: &mut AtomicPtr<()>, _: *const u8, _: usize) {
static PROMOTABLE_EVEN_VTABLE: Vtable = Vtable {
clone: promotable_even_clone,
to_vec: promotable_even_to_vec,
to_mut: promotable_even_to_mut,
is_unique: promotable_is_unique,
drop: promotable_even_drop,
};
static PROMOTABLE_ODD_VTABLE: Vtable = Vtable {
clone: promotable_odd_clone,
to_vec: promotable_odd_to_vec,
to_mut: promotable_odd_to_mut,
is_unique: promotable_is_unique,
drop: promotable_odd_drop,
};
@@ -961,7 +1039,7 @@ unsafe fn promotable_to_vec(
let buf = f(shared);
let cap = (ptr as usize - buf as usize) + len;
let cap = offset_from(ptr, buf) + len;
// Copy back buffer
ptr::copy(ptr, buf, len);
@@ -970,12 +1048,47 @@ unsafe fn promotable_to_vec(
}
}
unsafe fn promotable_to_mut(
data: &AtomicPtr<()>,
ptr: *const u8,
len: usize,
f: fn(*mut ()) -> *mut u8,
) -> BytesMut {
let shared = data.load(Ordering::Acquire);
let kind = shared as usize & KIND_MASK;
if kind == KIND_ARC {
shared_to_mut_impl(shared.cast(), ptr, len)
} else {
// KIND_VEC is a view of an underlying buffer at a certain offset.
// The ptr + len always represents the end of that buffer.
// Before truncating it, it is first promoted to KIND_ARC.
// Thus, we can safely reconstruct a Vec from it without leaking memory.
debug_assert_eq!(kind, KIND_VEC);
let buf = f(shared);
let off = offset_from(ptr, buf);
let cap = off + len;
let v = Vec::from_raw_parts(buf, cap, cap);
let mut b = BytesMut::from_vec(v);
b.advance_unchecked(off);
b
}
}
unsafe fn promotable_even_to_vec(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> Vec<u8> {
promotable_to_vec(data, ptr, len, |shared| {
ptr_map(shared.cast(), |addr| addr & !KIND_MASK)
})
}
unsafe fn promotable_even_to_mut(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> BytesMut {
promotable_to_mut(data, ptr, len, |shared| {
ptr_map(shared.cast(), |addr| addr & !KIND_MASK)
})
}
unsafe fn promotable_even_drop(data: &mut AtomicPtr<()>, ptr: *const u8, len: usize) {
data.with_mut(|shared| {
let shared = *shared;
@@ -1007,6 +1120,10 @@ unsafe fn promotable_odd_to_vec(data: &AtomicPtr<()>, ptr: *const u8, len: usize
promotable_to_vec(data, ptr, len, |shared| shared.cast())
}
unsafe fn promotable_odd_to_mut(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> BytesMut {
promotable_to_mut(data, ptr, len, |shared| shared.cast())
}
unsafe fn promotable_odd_drop(data: &mut AtomicPtr<()>, ptr: *const u8, len: usize) {
data.with_mut(|shared| {
let shared = *shared;
@@ -1022,8 +1139,20 @@ unsafe fn promotable_odd_drop(data: &mut AtomicPtr<()>, ptr: *const u8, len: usi
});
}
unsafe fn promotable_is_unique(data: &AtomicPtr<()>) -> bool {
let shared = data.load(Ordering::Acquire);
let kind = shared as usize & KIND_MASK;
if kind == KIND_ARC {
let ref_cnt = (*shared.cast::<Shared>()).ref_cnt.load(Ordering::Relaxed);
ref_cnt == 1
} else {
true
}
}
unsafe fn free_boxed_slice(buf: *mut u8, offset: *const u8, len: usize) {
let cap = (offset as usize - buf as usize) + len;
let cap = offset_from(offset, buf) + len;
dealloc(buf, Layout::from_size_align(cap, 1).unwrap())
}
@@ -1051,6 +1180,8 @@ const _: [(); 0 - mem::align_of::<Shared>() % 2] = []; // Assert that the alignm
static SHARED_VTABLE: Vtable = Vtable {
clone: shared_clone,
to_vec: shared_to_vec,
to_mut: shared_to_mut,
is_unique: shared_is_unique,
drop: shared_drop,
};
@@ -1075,11 +1206,11 @@ unsafe fn shared_to_vec_impl(shared: *mut Shared, ptr: *const u8, len: usize) ->
.compare_exchange(1, 0, Ordering::AcqRel, Ordering::Relaxed)
.is_ok()
{
let buf = (*shared).buf;
let cap = (*shared).cap;
// Deallocate Shared
drop(Box::from_raw(shared as *mut mem::ManuallyDrop<Shared>));
// Deallocate the `Shared` instance without running its destructor.
let shared = *Box::from_raw(shared);
let shared = ManuallyDrop::new(shared);
let buf = shared.buf;
let cap = shared.cap;
// Copy back buffer
ptr::copy(ptr, buf, len);
@@ -1096,6 +1227,51 @@ unsafe fn shared_to_vec(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> Vec
shared_to_vec_impl(data.load(Ordering::Relaxed).cast(), ptr, len)
}
unsafe fn shared_to_mut_impl(shared: *mut Shared, ptr: *const u8, len: usize) -> BytesMut {
// The goal is to check if the current handle is the only handle
// that currently has access to the buffer. This is done by
// checking if the `ref_cnt` is currently 1.
//
// The `Acquire` ordering synchronizes with the `Release` as
// part of the `fetch_sub` in `release_shared`. The `fetch_sub`
// operation guarantees that any mutations done in other threads
// are ordered before the `ref_cnt` is decremented. As such,
// this `Acquire` will guarantee that those mutations are
// visible to the current thread.
//
// Otherwise, we take the other branch, copy the data and call `release_shared`.
if (*shared).ref_cnt.load(Ordering::Acquire) == 1 {
// Deallocate the `Shared` instance without running its destructor.
let shared = *Box::from_raw(shared);
let shared = ManuallyDrop::new(shared);
let buf = shared.buf;
let cap = shared.cap;
// Rebuild Vec
let off = offset_from(ptr, buf);
let v = Vec::from_raw_parts(buf, len + off, cap);
let mut b = BytesMut::from_vec(v);
b.advance_unchecked(off);
b
} else {
// Copy the data from Shared in a new Vec, then release it
let v = slice::from_raw_parts(ptr, len).to_vec();
release_shared(shared);
BytesMut::from_vec(v)
}
}
unsafe fn shared_to_mut(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> BytesMut {
shared_to_mut_impl(data.load(Ordering::Relaxed).cast(), ptr, len)
}
pub(crate) unsafe fn shared_is_unique(data: &AtomicPtr<()>) -> bool {
let shared = data.load(Ordering::Acquire);
let ref_cnt = (*shared.cast::<Shared>()).ref_cnt.load(Ordering::Relaxed);
ref_cnt == 1
}
unsafe fn shared_drop(data: &mut AtomicPtr<()>, _ptr: *const u8, _len: usize) {
data.with_mut(|shared| {
release_shared(shared.cast());
@@ -1138,7 +1314,7 @@ unsafe fn shallow_clone_vec(
// vector.
let shared = Box::new(Shared {
buf,
cap: (offset as usize - buf as usize) + len,
cap: offset_from(offset, buf) + len,
// Initialize refcount to 2. One for this reference, and one
// for the new clone that will be returned from
// `shallow_clone`.
+276 -166
View File
@@ -1,4 +1,4 @@
use core::iter::{FromIterator, Iterator};
use core::iter::FromIterator;
use core::mem::{self, ManuallyDrop, MaybeUninit};
use core::ops::{Deref, DerefMut};
use core::ptr::{self, NonNull};
@@ -17,7 +17,7 @@ use crate::bytes::Vtable;
#[allow(unused)]
use crate::loom::sync::atomic::AtomicMut;
use crate::loom::sync::atomic::{AtomicPtr, AtomicUsize, Ordering};
use crate::{Buf, BufMut, Bytes};
use crate::{offset_from, Buf, BufMut, Bytes};
/// A unique reference to a contiguous slice of memory.
///
@@ -80,6 +80,12 @@ struct Shared {
ref_count: AtomicUsize,
}
// Assert that the alignment of `Shared` is divisible by 2.
// This is a necessary invariant since we depend on allocating `Shared` a
// shared object to implicitly carry the `KIND_ARC` flag in its pointer.
// This flag is set when the LSB is 0.
const _: [(); 0 - mem::align_of::<Shared>() % 2] = []; // Assert that the alignment of `Shared` is divisible by 2.
// Buffer storage strategy flags.
const KIND_ARC: usize = 0b0;
const KIND_VEC: usize = 0b1;
@@ -96,11 +102,11 @@ const MIN_ORIGINAL_CAPACITY_WIDTH: usize = 10;
const ORIGINAL_CAPACITY_MASK: usize = 0b11100;
const ORIGINAL_CAPACITY_OFFSET: usize = 2;
const VEC_POS_OFFSET: usize = 5;
// When the storage is in the `Vec` representation, the pointer can be advanced
// at most this value. This is due to the amount of storage available to track
// the offset is usize - number of KIND bits and number of ORIGINAL_CAPACITY
// bits.
const VEC_POS_OFFSET: usize = 5;
const MAX_VEC_POS: usize = usize::MAX >> VEC_POS_OFFSET;
const NOT_VEC_POS_MASK: usize = 0b11111;
@@ -237,29 +243,35 @@ impl BytesMut {
/// th.join().unwrap();
/// ```
#[inline]
pub fn freeze(mut self) -> Bytes {
if self.kind() == KIND_VEC {
pub fn freeze(self) -> Bytes {
let bytes = ManuallyDrop::new(self);
if bytes.kind() == KIND_VEC {
// Just re-use `Bytes` internal Vec vtable
unsafe {
let (off, _) = self.get_vec_pos();
let vec = rebuild_vec(self.ptr.as_ptr(), self.len, self.cap, off);
mem::forget(self);
let off = bytes.get_vec_pos();
let vec = rebuild_vec(bytes.ptr.as_ptr(), bytes.len, bytes.cap, off);
let mut b: Bytes = vec.into();
b.advance(off);
b
}
} else {
debug_assert_eq!(self.kind(), KIND_ARC);
debug_assert_eq!(bytes.kind(), KIND_ARC);
let ptr = self.ptr.as_ptr();
let len = self.len;
let data = AtomicPtr::new(self.data.cast());
mem::forget(self);
let ptr = bytes.ptr.as_ptr();
let len = bytes.len;
let data = AtomicPtr::new(bytes.data.cast());
unsafe { Bytes::with_vtable(ptr, len, data, &SHARED_VTABLE) }
}
}
/// Creates a new `BytesMut`, which is initialized with zero.
/// Creates a new `BytesMut` containing `len` zeros.
///
/// The resulting object has a length of `len` and a capacity greater
/// than or equal to `len`. The entire length of the object will be filled
/// with zeros.
///
/// On some platforms or allocators this function may be faster than
/// a manual implementation.
///
/// # Examples
///
@@ -268,6 +280,7 @@ impl BytesMut {
///
/// let zeros = BytesMut::zeroed(42);
///
/// assert!(zeros.capacity() >= 42);
/// assert_eq!(zeros.len(), 42);
/// zeros.into_iter().for_each(|x| assert_eq!(x, 0));
/// ```
@@ -311,8 +324,10 @@ impl BytesMut {
);
unsafe {
let mut other = self.shallow_clone();
other.set_start(at);
self.set_end(at);
// SAFETY: We've checked that `at` <= `self.capacity()` above.
other.advance_unchecked(at);
self.cap = at;
self.len = cmp::min(self.len, at);
other
}
}
@@ -342,7 +357,7 @@ impl BytesMut {
///
/// assert_eq!(other, b"hello world"[..]);
/// ```
#[must_use = "consider BytesMut::advance(len()) if you don't need the other half"]
#[must_use = "consider BytesMut::clear if you don't need the other half"]
pub fn split(&mut self) -> BytesMut {
let len = self.len();
self.split_to(len)
@@ -385,8 +400,11 @@ impl BytesMut {
unsafe {
let mut other = self.shallow_clone();
other.set_end(at);
self.set_start(at);
// SAFETY: We've checked that `at` <= `self.len()` and we know that `self.len()` <=
// `self.capacity()`.
self.advance_unchecked(at);
other.cap = at;
other.len = at;
other
}
}
@@ -399,7 +417,7 @@ impl BytesMut {
///
/// Existing underlying capacity is preserved.
///
/// The [`split_off`] method can emulate `truncate`, but this causes the
/// The [split_off](`Self::split_off()`) method can emulate `truncate`, but this causes the
/// excess bytes to be returned instead of dropped.
///
/// # Examples
@@ -411,13 +429,10 @@ impl BytesMut {
/// buf.truncate(5);
/// assert_eq!(buf, b"hello"[..]);
/// ```
///
/// [`split_off`]: #method.split_off
pub fn truncate(&mut self, len: usize) {
if len <= self.len() {
unsafe {
self.set_len(len);
}
// SAFETY: Shrinking the buffer cannot expose uninitialized bytes.
unsafe { self.set_len(len) };
}
}
@@ -433,7 +448,8 @@ impl BytesMut {
/// assert!(buf.is_empty());
/// ```
pub fn clear(&mut self) {
self.truncate(0);
// SAFETY: Setting the length to zero cannot expose uninitialized bytes.
unsafe { self.set_len(0) };
}
/// Resizes the buffer so that `len` is equal to `new_len`.
@@ -459,18 +475,26 @@ impl BytesMut {
/// assert_eq!(&buf[..], &[0x1, 0x1, 0x3, 0x3]);
/// ```
pub fn resize(&mut self, new_len: usize, value: u8) {
let len = self.len();
if new_len > len {
let additional = new_len - len;
self.reserve(additional);
unsafe {
let dst = self.chunk_mut().as_mut_ptr();
ptr::write_bytes(dst, value, additional);
self.set_len(new_len);
}
let additional = if let Some(additional) = new_len.checked_sub(self.len()) {
additional
} else {
self.truncate(new_len);
return;
};
if additional == 0 {
return;
}
self.reserve(additional);
let dst = self.spare_capacity_mut().as_mut_ptr();
// SAFETY: `spare_capacity_mut` returns a valid, properly aligned pointer and we've
// reserved enough space to write `additional` bytes.
unsafe { ptr::write_bytes(dst, value, additional) };
// SAFETY: There are at least `new_len` initialized bytes in the buffer so no
// uninitialized bytes are being exposed.
unsafe { self.set_len(new_len) };
}
/// Sets the length of the buffer.
@@ -573,12 +597,13 @@ impl BytesMut {
return;
}
self.reserve_inner(additional);
// will always succeed
let _ = self.reserve_inner(additional, true);
}
// In separate function to allow the short-circuits in `reserve` to
// be inline-able. Significant helps performance.
fn reserve_inner(&mut self, additional: usize) {
// In separate function to allow the short-circuits in `reserve` and `try_reclaim` to
// be inline-able. Significantly helps performance. Returns false if it did not succeed.
fn reserve_inner(&mut self, additional: usize, allocate: bool) -> bool {
let len = self.len();
let kind = self.kind();
@@ -592,7 +617,7 @@ impl BytesMut {
// We need to make sure that this optimization does not kill the
// amortized runtimes of BytesMut's operations.
unsafe {
let (off, prev) = self.get_vec_pos();
let off = self.get_vec_pos();
// Only reuse space if we can satisfy the requested additional space.
//
@@ -613,16 +638,19 @@ impl BytesMut {
//
// Just move the pointer back to the start after copying
// data back.
let base_ptr = self.ptr.as_ptr().offset(-(off as isize));
let base_ptr = self.ptr.as_ptr().sub(off);
// Since `off >= self.len()`, the two regions don't overlap.
ptr::copy_nonoverlapping(self.ptr.as_ptr(), base_ptr, self.len);
self.ptr = vptr(base_ptr);
self.set_vec_pos(0, prev);
self.set_vec_pos(0);
// Length stays constant, but since we moved backwards we
// can gain capacity back.
self.cap += off;
} else {
if !allocate {
return false;
}
// Not enough space, or reusing might be too much overhead:
// allocate more space!
let mut v =
@@ -631,11 +659,11 @@ impl BytesMut {
// Update the info
self.ptr = vptr(v.as_mut_ptr().add(off));
self.len = v.len() - off;
self.cap = v.capacity() - off;
debug_assert_eq!(self.len, v.len() - off);
}
return;
return true;
}
}
@@ -646,15 +674,13 @@ impl BytesMut {
// allocating a new vector with the requested capacity.
//
// Compute the new capacity
let mut new_cap = len.checked_add(additional).expect("overflow");
let original_capacity;
let original_capacity_repr;
let mut new_cap = match len.checked_add(additional) {
Some(new_cap) => new_cap,
None if !allocate => return false,
None => panic!("overflow"),
};
unsafe {
original_capacity_repr = (*shared).original_capacity_repr;
original_capacity = original_capacity_from_repr(original_capacity_repr);
// First, try to reclaim the buffer. This is possible if the current
// handle is the only outstanding handle pointing to the buffer.
if (*shared).is_unique() {
@@ -683,6 +709,9 @@ impl BytesMut {
self.ptr = vptr(ptr);
self.cap = v.capacity();
} else {
if !allocate {
return false;
}
// calculate offset
let off = (self.ptr.as_ptr() as usize) - (v.as_ptr() as usize);
@@ -721,11 +750,17 @@ impl BytesMut {
self.cap = v.capacity() - off;
}
return;
} else {
new_cap = cmp::max(new_cap, original_capacity);
return true;
}
}
if !allocate {
return false;
}
let original_capacity_repr = unsafe { (*shared).original_capacity_repr };
let original_capacity = original_capacity_from_repr(original_capacity_repr);
new_cap = cmp::max(new_cap, original_capacity);
// Create a new vector to store the data
let mut v = ManuallyDrop::new(Vec::with_capacity(new_cap));
@@ -741,8 +776,69 @@ impl BytesMut {
let data = (original_capacity_repr << ORIGINAL_CAPACITY_OFFSET) | KIND_VEC;
self.data = invalid_ptr(data);
self.ptr = vptr(v.as_mut_ptr());
self.len = v.len();
self.cap = v.capacity();
debug_assert_eq!(self.len, v.len());
return true;
}
/// Attempts to cheaply reclaim already allocated capacity for at least `additional` more
/// bytes to be inserted into the given `BytesMut` and returns `true` if it succeeded.
///
/// `try_reclaim` behaves exactly like `reserve`, except that it never allocates new storage
/// and returns a `bool` indicating whether it was successful in doing so:
///
/// `try_reclaim` returns false under these conditions:
/// - The spare capacity left is less than `additional` bytes AND
/// - The existing allocation cannot be reclaimed cheaply or it was less than
/// `additional` bytes in size
///
/// Reclaiming the allocation cheaply is possible if the `BytesMut` has no outstanding
/// references through other `BytesMut`s or `Bytes` which point to the same underlying
/// storage.
///
/// # Examples
///
/// ```
/// use bytes::BytesMut;
///
/// let mut buf = BytesMut::with_capacity(64);
/// assert_eq!(true, buf.try_reclaim(64));
/// assert_eq!(64, buf.capacity());
///
/// buf.extend_from_slice(b"abcd");
/// let mut split = buf.split();
/// assert_eq!(60, buf.capacity());
/// assert_eq!(4, split.capacity());
/// assert_eq!(false, split.try_reclaim(64));
/// assert_eq!(false, buf.try_reclaim(64));
/// // The split buffer is filled with "abcd"
/// assert_eq!(false, split.try_reclaim(4));
/// // buf is empty and has capacity for 60 bytes
/// assert_eq!(true, buf.try_reclaim(60));
///
/// drop(buf);
/// assert_eq!(false, split.try_reclaim(64));
///
/// split.clear();
/// assert_eq!(4, split.capacity());
/// assert_eq!(true, split.try_reclaim(64));
/// assert_eq!(64, split.capacity());
/// ```
// I tried splitting out try_reclaim_inner after the short circuits, but it was inlined
// regardless with Rust 1.78.0 so probably not worth it
#[inline]
#[must_use = "consider BytesMut::reserve if you need an infallible reservation"]
pub fn try_reclaim(&mut self, additional: usize) -> bool {
let len = self.len();
let rem = self.capacity() - len;
if additional <= rem {
// The handle can already store at least `additional` more bytes, so
// there is no further work needed to be done.
return true;
}
self.reserve_inner(additional, false)
}
/// Appends given bytes to this `BytesMut`.
@@ -823,11 +919,11 @@ impl BytesMut {
// internal change could make a simple pattern (`BytesMut::from(vec)`)
// suddenly a lot more expensive.
#[inline]
pub(crate) fn from_vec(mut vec: Vec<u8>) -> BytesMut {
pub(crate) fn from_vec(vec: Vec<u8>) -> BytesMut {
let mut vec = ManuallyDrop::new(vec);
let ptr = vptr(vec.as_mut_ptr());
let len = vec.len();
let cap = vec.capacity();
mem::forget(vec);
let original_capacity_repr = original_capacity_to_repr(cap);
let data = (original_capacity_repr << ORIGINAL_CAPACITY_OFFSET) | KIND_VEC;
@@ -850,14 +946,19 @@ impl BytesMut {
unsafe { slice::from_raw_parts_mut(self.ptr.as_ptr(), self.len) }
}
unsafe fn set_start(&mut self, start: usize) {
/// Advance the buffer without bounds checking.
///
/// # SAFETY
///
/// The caller must ensure that `count` <= `self.cap`.
pub(crate) unsafe fn advance_unchecked(&mut self, count: usize) {
// Setting the start to 0 is a no-op, so return early if this is the
// case.
if start == 0 {
if count == 0 {
return;
}
debug_assert!(start <= self.cap, "internal: set_start out of bounds");
debug_assert!(count <= self.cap, "internal: set_start out of bounds");
let kind = self.kind();
@@ -866,11 +967,10 @@ impl BytesMut {
// complicated. First, we have to track how far ahead the
// "start" of the byte buffer from the beginning of the vec. We
// also have to ensure that we don't exceed the maximum shift.
let (mut pos, prev) = self.get_vec_pos();
pos += start;
let pos = self.get_vec_pos() + count;
if pos <= MAX_VEC_POS {
self.set_vec_pos(pos, prev);
self.set_vec_pos(pos);
} else {
// The repr must be upgraded to ARC. This will never happen
// on 64 bit systems and will only happen on 32 bit systems
@@ -883,23 +983,9 @@ impl BytesMut {
// Updating the start of the view is setting `ptr` to point to the
// new start and updating the `len` field to reflect the new length
// of the view.
self.ptr = vptr(self.ptr.as_ptr().add(start));
if self.len >= start {
self.len -= start;
} else {
self.len = 0;
}
self.cap -= start;
}
unsafe fn set_end(&mut self, end: usize) {
debug_assert_eq!(self.kind(), KIND_ARC);
assert!(end <= self.cap, "set_end out of bounds");
self.cap = end;
self.len = cmp::min(self.len, end);
self.ptr = vptr(self.ptr.as_ptr().add(count));
self.len = self.len.checked_sub(count).unwrap_or(0);
self.cap -= count;
}
fn try_unsplit(&mut self, other: BytesMut) -> Result<(), BytesMut> {
@@ -978,19 +1064,18 @@ impl BytesMut {
}
#[inline]
unsafe fn get_vec_pos(&mut self) -> (usize, usize) {
unsafe fn get_vec_pos(&self) -> usize {
debug_assert_eq!(self.kind(), KIND_VEC);
let prev = self.data as usize;
(prev >> VEC_POS_OFFSET, prev)
self.data as usize >> VEC_POS_OFFSET
}
#[inline]
unsafe fn set_vec_pos(&mut self, pos: usize, prev: usize) {
unsafe fn set_vec_pos(&mut self, pos: usize) {
debug_assert_eq!(self.kind(), KIND_VEC);
debug_assert!(pos <= MAX_VEC_POS);
self.data = invalid_ptr((pos << VEC_POS_OFFSET) | (prev & NOT_VEC_POS_MASK));
self.data = invalid_ptr((pos << VEC_POS_OFFSET) | (self.data as usize & NOT_VEC_POS_MASK));
}
/// Returns the remaining spare capacity of the buffer as a slice of `MaybeUninit<u8>`.
@@ -1039,7 +1124,7 @@ impl Drop for BytesMut {
if kind == KIND_VEC {
unsafe {
let (off, _) = self.get_vec_pos();
let off = self.get_vec_pos();
// Vector storage, free the vector
let _ = rebuild_vec(self.ptr.as_ptr(), self.len, self.cap, off);
@@ -1063,6 +1148,13 @@ impl Buf for BytesMut {
#[inline]
fn advance(&mut self, cnt: usize) {
// Advancing by the length is the same as resetting the length to 0,
// except this way we get to reuse the full capacity.
if cnt == self.remaining() {
self.clear();
return;
}
assert!(
cnt <= self.remaining(),
"cannot advance past `remaining`: {:?} <= {:?}",
@@ -1070,11 +1162,13 @@ impl Buf for BytesMut {
self.remaining(),
);
unsafe {
self.set_start(cnt);
// SAFETY: We've checked that `cnt` <= `self.remaining()` and we know that
// `self.remaining()` <= `self.cap`.
self.advance_unchecked(cnt);
}
}
fn copy_to_bytes(&mut self, len: usize) -> crate::Bytes {
fn copy_to_bytes(&mut self, len: usize) -> Bytes {
self.split_to(len).freeze()
}
}
@@ -1087,14 +1181,12 @@ unsafe impl BufMut for BytesMut {
#[inline]
unsafe fn advance_mut(&mut self, cnt: usize) {
let new_len = self.len() + cnt;
assert!(
new_len <= self.cap,
"new_len = {}; capacity = {}",
new_len,
self.cap
);
self.len = new_len;
let remaining = self.cap - self.len();
if cnt > remaining {
super::panic_advance(cnt, remaining);
}
// Addition won't overflow since it is at most `self.cap`.
self.len = self.len() + cnt;
}
#[inline]
@@ -1108,7 +1200,7 @@ unsafe impl BufMut for BytesMut {
// Specialize these methods so they can skip checking `remaining_mut`
// and `advance_mut`.
fn put<T: crate::Buf>(&mut self, mut src: T)
fn put<T: Buf>(&mut self, mut src: T)
where
Self: Sized,
{
@@ -1288,9 +1380,7 @@ impl Extend<u8> for BytesMut {
// TODO: optimize
// 1. If self.kind() == KIND_VEC, use Vec::extend
// 2. Make `reserve` inline-able
for b in iter {
self.reserve(1);
self.put_u8(b);
}
}
@@ -1407,57 +1497,60 @@ fn original_capacity_from_repr(repr: usize) -> usize {
1 << (repr + (MIN_ORIGINAL_CAPACITY_WIDTH - 1))
}
/*
#[test]
fn test_original_capacity_to_repr() {
assert_eq!(original_capacity_to_repr(0), 0);
#[cfg(test)]
mod tests {
use super::*;
let max_width = 32;
#[test]
fn test_original_capacity_to_repr() {
assert_eq!(original_capacity_to_repr(0), 0);
for width in 1..(max_width + 1) {
let cap = 1 << width - 1;
let max_width = 32;
let expected = if width < MIN_ORIGINAL_CAPACITY_WIDTH {
0
} else if width < MAX_ORIGINAL_CAPACITY_WIDTH {
width - MIN_ORIGINAL_CAPACITY_WIDTH
} else {
MAX_ORIGINAL_CAPACITY_WIDTH - MIN_ORIGINAL_CAPACITY_WIDTH
};
for width in 1..(max_width + 1) {
let cap = 1 << width - 1;
assert_eq!(original_capacity_to_repr(cap), expected);
let expected = if width < MIN_ORIGINAL_CAPACITY_WIDTH {
0
} else if width < MAX_ORIGINAL_CAPACITY_WIDTH {
width - MIN_ORIGINAL_CAPACITY_WIDTH
} else {
MAX_ORIGINAL_CAPACITY_WIDTH - MIN_ORIGINAL_CAPACITY_WIDTH
};
if width > 1 {
assert_eq!(original_capacity_to_repr(cap + 1), expected);
}
assert_eq!(original_capacity_to_repr(cap), expected);
// MIN_ORIGINAL_CAPACITY_WIDTH must be bigger than 7 to pass tests below
if width == MIN_ORIGINAL_CAPACITY_WIDTH + 1 {
assert_eq!(original_capacity_to_repr(cap - 24), expected - 1);
assert_eq!(original_capacity_to_repr(cap + 76), expected);
} else if width == MIN_ORIGINAL_CAPACITY_WIDTH + 2 {
assert_eq!(original_capacity_to_repr(cap - 1), expected - 1);
assert_eq!(original_capacity_to_repr(cap - 48), expected - 1);
if width > 1 {
assert_eq!(original_capacity_to_repr(cap + 1), expected);
}
// MIN_ORIGINAL_CAPACITY_WIDTH must be bigger than 7 to pass tests below
if width == MIN_ORIGINAL_CAPACITY_WIDTH + 1 {
assert_eq!(original_capacity_to_repr(cap - 24), expected - 1);
assert_eq!(original_capacity_to_repr(cap + 76), expected);
} else if width == MIN_ORIGINAL_CAPACITY_WIDTH + 2 {
assert_eq!(original_capacity_to_repr(cap - 1), expected - 1);
assert_eq!(original_capacity_to_repr(cap - 48), expected - 1);
}
}
}
#[test]
fn test_original_capacity_from_repr() {
assert_eq!(0, original_capacity_from_repr(0));
let min_cap = 1 << MIN_ORIGINAL_CAPACITY_WIDTH;
assert_eq!(min_cap, original_capacity_from_repr(1));
assert_eq!(min_cap * 2, original_capacity_from_repr(2));
assert_eq!(min_cap * 4, original_capacity_from_repr(3));
assert_eq!(min_cap * 8, original_capacity_from_repr(4));
assert_eq!(min_cap * 16, original_capacity_from_repr(5));
assert_eq!(min_cap * 32, original_capacity_from_repr(6));
assert_eq!(min_cap * 64, original_capacity_from_repr(7));
}
}
#[test]
fn test_original_capacity_from_repr() {
assert_eq!(0, original_capacity_from_repr(0));
let min_cap = 1 << MIN_ORIGINAL_CAPACITY_WIDTH;
assert_eq!(min_cap, original_capacity_from_repr(1));
assert_eq!(min_cap * 2, original_capacity_from_repr(2));
assert_eq!(min_cap * 4, original_capacity_from_repr(3));
assert_eq!(min_cap * 8, original_capacity_from_repr(4));
assert_eq!(min_cap * 16, original_capacity_from_repr(5));
assert_eq!(min_cap * 32, original_capacity_from_repr(6));
assert_eq!(min_cap * 64, original_capacity_from_repr(7));
}
*/
unsafe impl Send for BytesMut {}
unsafe impl Sync for BytesMut {}
@@ -1618,15 +1711,16 @@ impl PartialEq<Bytes> for BytesMut {
}
impl From<BytesMut> for Vec<u8> {
fn from(mut bytes: BytesMut) -> Self {
fn from(bytes: BytesMut) -> Self {
let kind = bytes.kind();
let bytes = ManuallyDrop::new(bytes);
let mut vec = if kind == KIND_VEC {
unsafe {
let (off, _) = bytes.get_vec_pos();
let off = bytes.get_vec_pos();
rebuild_vec(bytes.ptr.as_ptr(), bytes.len, bytes.cap, off)
}
} else if kind == KIND_ARC {
} else {
let shared = bytes.data as *mut Shared;
if unsafe { (*shared).is_unique() } {
@@ -1636,10 +1730,8 @@ impl From<BytesMut> for Vec<u8> {
vec
} else {
return bytes.deref().to_vec();
return ManuallyDrop::into_inner(bytes).deref().to_vec();
}
} else {
return bytes.deref().to_vec();
};
let len = bytes.len;
@@ -1649,8 +1741,6 @@ impl From<BytesMut> for Vec<u8> {
vec.set_len(len);
}
mem::forget(bytes);
vec
}
}
@@ -1676,25 +1766,8 @@ fn invalid_ptr<T>(addr: usize) -> *mut T {
ptr.cast::<T>()
}
/// Precondition: dst >= original
///
/// The following line is equivalent to:
///
/// ```rust,ignore
/// self.ptr.as_ptr().offset_from(ptr) as usize;
/// ```
///
/// But due to min rust is 1.39 and it is only stablised
/// in 1.47, we cannot use it.
#[inline]
fn offset_from(dst: *mut u8, original: *mut u8) -> usize {
debug_assert!(dst >= original);
dst as usize - original as usize
}
unsafe fn rebuild_vec(ptr: *mut u8, mut len: usize, mut cap: usize, off: usize) -> Vec<u8> {
let ptr = ptr.offset(-(off as isize));
let ptr = ptr.sub(off);
len += off;
cap += off;
@@ -1706,6 +1779,8 @@ unsafe fn rebuild_vec(ptr: *mut u8, mut len: usize, mut cap: usize, off: usize)
static SHARED_VTABLE: Vtable = Vtable {
clone: shared_v_clone,
to_vec: shared_v_to_vec,
to_mut: shared_v_to_mut,
is_unique: shared_v_is_unique,
drop: shared_v_drop,
};
@@ -1739,6 +1814,41 @@ unsafe fn shared_v_to_vec(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> V
}
}
unsafe fn shared_v_to_mut(data: &AtomicPtr<()>, ptr: *const u8, len: usize) -> BytesMut {
let shared: *mut Shared = data.load(Ordering::Relaxed).cast();
if (*shared).is_unique() {
let shared = &mut *shared;
// The capacity is always the original capacity of the buffer
// minus the offset from the start of the buffer
let v = &mut shared.vec;
let v_capacity = v.capacity();
let v_ptr = v.as_mut_ptr();
let offset = offset_from(ptr as *mut u8, v_ptr);
let cap = v_capacity - offset;
let ptr = vptr(ptr as *mut u8);
BytesMut {
ptr,
len,
cap,
data: shared,
}
} else {
let v = slice::from_raw_parts(ptr, len).to_vec();
release_shared(shared);
BytesMut::from_vec(v)
}
}
unsafe fn shared_v_is_unique(data: &AtomicPtr<()>) -> bool {
let shared = data.load(Ordering::Acquire);
let ref_count = (*shared.cast::<Shared>()).ref_count.load(Ordering::Relaxed);
ref_count == 1
}
unsafe fn shared_v_drop(data: &mut AtomicPtr<()>, _ptr: *const u8, _len: usize) {
data.with_mut(|shared| {
release_shared(*shared as *mut Shared);
+56 -8
View File
@@ -1,3 +1,4 @@
#![allow(unknown_lints, unexpected_cfgs)]
#![warn(missing_docs, missing_debug_implementations, rust_2018_idioms)]
#![doc(test(
no_crate_inject,
@@ -9,12 +10,9 @@
//! Provides abstractions for working with bytes.
//!
//! The `bytes` crate provides an efficient byte buffer structure
//! ([`Bytes`](struct.Bytes.html)) and traits for working with buffer
//! ([`Bytes`]) and traits for working with buffer
//! implementations ([`Buf`], [`BufMut`]).
//!
//! [`Buf`]: trait.Buf.html
//! [`BufMut`]: trait.BufMut.html
//!
//! # `Bytes`
//!
//! `Bytes` is an efficient container for storing and operating on contiguous
@@ -52,9 +50,7 @@
//! `a` and `b` will share the underlying buffer and maintain indices tracking
//! the view into the buffer represented by the handle.
//!
//! See the [struct docs] for more details.
//!
//! [struct docs]: struct.Bytes.html
//! See the [struct docs](`Bytes`) for more details.
//!
//! # `Buf`, `BufMut`
//!
@@ -70,7 +66,7 @@
//! ## Relation with `Read` and `Write`
//!
//! At first glance, it may seem that `Buf` and `BufMut` overlap in
//! functionality with `std::io::Read` and `std::io::Write`. However, they
//! functionality with [`std::io::Read`] and [`std::io::Write`]. However, they
//! serve different purposes. A buffer is the value that is provided as an
//! argument to `Read::read` and `Write::write`. `Read` and `Write` may then
//! perform a syscall, which has the potential of failing. Operations on `Buf`
@@ -115,3 +111,55 @@ fn abort() -> ! {
panic!("abort");
}
}
#[inline(always)]
#[cfg(feature = "std")]
fn saturating_sub_usize_u64(a: usize, b: u64) -> usize {
use core::convert::TryFrom;
match usize::try_from(b) {
Ok(b) => a.saturating_sub(b),
Err(_) => 0,
}
}
#[inline(always)]
#[cfg(feature = "std")]
fn min_u64_usize(a: u64, b: usize) -> usize {
use core::convert::TryFrom;
match usize::try_from(a) {
Ok(a) => usize::min(a, b),
Err(_) => b,
}
}
/// Panic with a nice error message.
#[cold]
fn panic_advance(idx: usize, len: usize) -> ! {
panic!(
"advance out of bounds: the len is {} but advancing by {}",
len, idx
);
}
#[cold]
fn panic_does_not_fit(size: usize, nbytes: usize) -> ! {
panic!(
"size too large: the integer type can fit {} bytes, but nbytes is {}",
size, nbytes
);
}
/// Precondition: dst >= original
///
/// The following line is equivalent to:
///
/// ```rust,ignore
/// self.ptr.as_ptr().offset_from(ptr) as usize;
/// ```
///
/// But due to min rust is 1.39 and it is only stabilized
/// in 1.47, we cannot use it.
#[inline]
fn offset_from(dst: *const u8, original: *const u8) -> usize {
dst as usize - original as usize
}
+1 -1
View File
@@ -83,7 +83,7 @@ fn test_put_int_le_nbytes_overflow() {
}
#[test]
#[should_panic(expected = "cannot advance")]
#[should_panic(expected = "advance out of bounds: the len is 8 but advancing by 12")]
fn test_vec_advance_mut() {
// Verify fix for #354
let mut buf = Vec::with_capacity(8);
+245 -91
View File
@@ -598,6 +598,28 @@ fn extend_mut_from_bytes() {
assert_eq!(*bytes, LONG[..]);
}
#[test]
fn extend_past_lower_limit_of_size_hint() {
// See https://github.com/tokio-rs/bytes/pull/674#pullrequestreview-1913035700
struct Iter<I>(I);
impl<I: Iterator<Item = u8>> Iterator for Iter<I> {
type Item = u8;
fn next(&mut self) -> Option<Self::Item> {
self.0.next()
}
fn size_hint(&self) -> (usize, Option<usize>) {
(5, None)
}
}
let mut bytes = BytesMut::with_capacity(5);
bytes.extend(Iter(std::iter::repeat(0).take(10)));
assert_eq!(bytes.len(), 10);
}
#[test]
fn extend_mut_without_size_hint() {
let mut bytes = BytesMut::with_capacity(0);
@@ -710,97 +732,6 @@ fn partial_eq_bytesmut() {
assert!(bytesmut != bytes2);
}
/*
#[test]
fn bytes_unsplit_basic() {
let buf = Bytes::from(&b"aaabbbcccddd"[..]);
let splitted = buf.split_off(6);
assert_eq!(b"aaabbb", &buf[..]);
assert_eq!(b"cccddd", &splitted[..]);
buf.unsplit(splitted);
assert_eq!(b"aaabbbcccddd", &buf[..]);
}
#[test]
fn bytes_unsplit_empty_other() {
let buf = Bytes::from(&b"aaabbbcccddd"[..]);
// empty other
let other = Bytes::new();
buf.unsplit(other);
assert_eq!(b"aaabbbcccddd", &buf[..]);
}
#[test]
fn bytes_unsplit_empty_self() {
// empty self
let mut buf = Bytes::new();
let mut other = Bytes::with_capacity(64);
other.extend_from_slice(b"aaabbbcccddd");
buf.unsplit(other);
assert_eq!(b"aaabbbcccddd", &buf[..]);
}
#[test]
fn bytes_unsplit_arc_different() {
let mut buf = Bytes::with_capacity(64);
buf.extend_from_slice(b"aaaabbbbeeee");
buf.split_off(8); //arc
let mut buf2 = Bytes::with_capacity(64);
buf2.extend_from_slice(b"ccccddddeeee");
buf2.split_off(8); //arc
buf.unsplit(buf2);
assert_eq!(b"aaaabbbbccccdddd", &buf[..]);
}
#[test]
fn bytes_unsplit_arc_non_contiguous() {
let mut buf = Bytes::with_capacity(64);
buf.extend_from_slice(b"aaaabbbbeeeeccccdddd");
let mut buf2 = buf.split_off(8); //arc
let buf3 = buf2.split_off(4); //arc
buf.unsplit(buf3);
assert_eq!(b"aaaabbbbccccdddd", &buf[..]);
}
#[test]
fn bytes_unsplit_two_split_offs() {
let mut buf = Bytes::with_capacity(64);
buf.extend_from_slice(b"aaaabbbbccccdddd");
let mut buf2 = buf.split_off(8); //arc
let buf3 = buf2.split_off(4); //arc
buf2.unsplit(buf3);
buf.unsplit(buf2);
assert_eq!(b"aaaabbbbccccdddd", &buf[..]);
}
#[test]
fn bytes_unsplit_overlapping_references() {
let mut buf = Bytes::with_capacity(64);
buf.extend_from_slice(b"abcdefghijklmnopqrstuvwxyz");
let mut buf0010 = buf.slice(0..10);
let buf1020 = buf.slice(10..20);
let buf0515 = buf.slice(5..15);
buf0010.unsplit(buf1020);
assert_eq!(b"abcdefghijklmnopqrst", &buf0010[..]);
assert_eq!(b"fghijklmno", &buf0515[..]);
}
*/
#[test]
fn bytes_mut_unsplit_basic() {
let mut buf = BytesMut::with_capacity(64);
@@ -1208,3 +1139,226 @@ fn test_bytes_capacity_len() {
}
}
}
#[test]
fn static_is_unique() {
let b = Bytes::from_static(LONG);
assert!(!b.is_unique());
}
#[test]
fn vec_is_unique() {
let v: Vec<u8> = LONG.to_vec();
let b = Bytes::from(v);
assert!(b.is_unique());
}
#[test]
fn arc_is_unique() {
let v: Vec<u8> = LONG.to_vec();
let b = Bytes::from(v);
let c = b.clone();
assert!(!b.is_unique());
drop(c);
assert!(b.is_unique());
}
#[test]
fn shared_is_unique() {
let v: Vec<u8> = LONG.to_vec();
let b = Bytes::from(v);
let c = b.clone();
assert!(!c.is_unique());
drop(b);
assert!(c.is_unique());
}
#[test]
fn mut_shared_is_unique() {
let mut b = BytesMut::from(LONG);
let c = b.split().freeze();
assert!(!c.is_unique());
drop(b);
assert!(c.is_unique());
}
#[test]
fn test_bytesmut_from_bytes_static() {
let bs = b"1b23exfcz3r";
// Test STATIC_VTABLE.to_mut
let bytes_mut = BytesMut::from(Bytes::from_static(bs));
assert_eq!(bytes_mut, bs[..]);
}
#[test]
fn test_bytesmut_from_bytes_bytes_mut_vec() {
let bs = b"1b23exfcz3r";
let bs_long = b"1b23exfcz3r1b23exfcz3r";
// Test case where kind == KIND_VEC
let mut bytes_mut: BytesMut = bs[..].into();
bytes_mut = BytesMut::from(bytes_mut.freeze());
assert_eq!(bytes_mut, bs[..]);
bytes_mut.extend_from_slice(&bs[..]);
assert_eq!(bytes_mut, bs_long[..]);
}
#[test]
fn test_bytesmut_from_bytes_bytes_mut_shared() {
let bs = b"1b23exfcz3r";
// Set kind to KIND_ARC so that after freeze, Bytes will use bytes_mut.SHARED_VTABLE
let mut bytes_mut: BytesMut = bs[..].into();
drop(bytes_mut.split_off(bs.len()));
let b1 = bytes_mut.freeze();
let b2 = b1.clone();
// shared.is_unique() = False
let mut b1m = BytesMut::from(b1);
assert_eq!(b1m, bs[..]);
b1m[0] = b'9';
// shared.is_unique() = True
let b2m = BytesMut::from(b2);
assert_eq!(b2m, bs[..]);
}
#[test]
fn test_bytesmut_from_bytes_bytes_mut_offset() {
let bs = b"1b23exfcz3r";
// Test bytes_mut.SHARED_VTABLE.to_mut impl where offset != 0
let mut bytes_mut1: BytesMut = bs[..].into();
let bytes_mut2 = bytes_mut1.split_off(9);
let b1 = bytes_mut1.freeze();
let b2 = bytes_mut2.freeze();
let b1m = BytesMut::from(b1);
let b2m = BytesMut::from(b2);
assert_eq!(b2m, bs[9..]);
assert_eq!(b1m, bs[..9]);
}
#[test]
fn test_bytesmut_from_bytes_promotable_even_vec() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_VEC
let b1 = Bytes::from(vec.clone());
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
}
#[test]
fn test_bytesmut_from_bytes_promotable_even_arc_1() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_ARC, ref_cnt == 1
let b1 = Bytes::from(vec.clone());
drop(b1.clone());
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
}
#[test]
fn test_bytesmut_from_bytes_promotable_even_arc_2() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_ARC, ref_cnt == 2
let b1 = Bytes::from(vec.clone());
let b2 = b1.clone();
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
// Test case where vtable = SHARED_VTABLE, kind == KIND_ARC, ref_cnt == 1
let b2m = BytesMut::from(b2);
assert_eq!(b2m, vec);
}
#[test]
fn test_bytesmut_from_bytes_promotable_even_arc_offset() {
let vec = vec![33u8; 1024];
// Test case where offset != 0
let mut b1 = Bytes::from(vec.clone());
let b2 = b1.split_off(20);
let b1m = BytesMut::from(b1);
let b2m = BytesMut::from(b2);
assert_eq!(b2m, vec[20..]);
assert_eq!(b1m, vec[..20]);
}
#[test]
fn try_reclaim_empty() {
let mut buf = BytesMut::new();
assert_eq!(false, buf.try_reclaim(6));
buf.reserve(6);
assert_eq!(true, buf.try_reclaim(6));
let cap = buf.capacity();
assert!(cap >= 6);
assert_eq!(false, buf.try_reclaim(cap + 1));
let mut buf = BytesMut::new();
buf.reserve(6);
let cap = buf.capacity();
assert!(cap >= 6);
let mut split = buf.split();
drop(buf);
assert_eq!(0, split.capacity());
assert_eq!(true, split.try_reclaim(6));
assert_eq!(false, split.try_reclaim(cap + 1));
}
#[test]
fn try_reclaim_vec() {
let mut buf = BytesMut::with_capacity(6);
buf.put_slice(b"abc");
// Reclaiming a ludicrous amount of space should calmly return false
assert_eq!(false, buf.try_reclaim(usize::MAX));
assert_eq!(false, buf.try_reclaim(6));
buf.advance(2);
assert_eq!(4, buf.capacity());
// We can reclaim 5 bytes, because the byte in the buffer can be moved to the front. 6 bytes
// cannot be reclaimed because there is already one byte stored
assert_eq!(false, buf.try_reclaim(6));
assert_eq!(true, buf.try_reclaim(5));
buf.advance(1);
assert_eq!(true, buf.try_reclaim(6));
assert_eq!(6, buf.capacity());
}
#[test]
fn try_reclaim_arc() {
let mut buf = BytesMut::with_capacity(6);
buf.put_slice(b"abc");
let x = buf.split().freeze();
buf.put_slice(b"def");
// Reclaiming a ludicrous amount of space should calmly return false
assert_eq!(false, buf.try_reclaim(usize::MAX));
let y = buf.split().freeze();
let z = y.clone();
assert_eq!(false, buf.try_reclaim(6));
drop(x);
drop(z);
assert_eq!(false, buf.try_reclaim(6));
drop(y);
assert_eq!(true, buf.try_reclaim(6));
assert_eq!(6, buf.capacity());
assert_eq!(0, buf.len());
buf.put_slice(b"abc");
buf.put_slice(b"def");
assert_eq!(6, buf.capacity());
assert_eq!(6, buf.len());
assert_eq!(false, buf.try_reclaim(6));
buf.advance(4);
assert_eq!(true, buf.try_reclaim(4));
buf.advance(2);
assert_eq!(true, buf.try_reclaim(6));
}
+51 -1
View File
@@ -6,7 +6,7 @@
use std::alloc::{GlobalAlloc, Layout, System};
use std::ptr;
use bytes::Bytes;
use bytes::{Bytes, BytesMut};
#[global_allocator]
static ODD: Odd = Odd;
@@ -95,3 +95,53 @@ fn test_bytes_into_vec() {
assert_eq!(Vec::from(b2), vec[20..]);
assert_eq!(Vec::from(b1), vec[..20]);
}
#[test]
fn test_bytesmut_from_bytes_vec() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_VEC
let b1 = Bytes::from(vec.clone());
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
}
#[test]
fn test_bytesmut_from_bytes_arc_1() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_ARC, ref_cnt == 1
let b1 = Bytes::from(vec.clone());
drop(b1.clone());
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
}
#[test]
fn test_bytesmut_from_bytes_arc_2() {
let vec = vec![33u8; 1024];
// Test case where kind == KIND_ARC, ref_cnt == 2
let b1 = Bytes::from(vec.clone());
let b2 = b1.clone();
let b1m = BytesMut::from(b1);
assert_eq!(b1m, vec);
// Test case where vtable = SHARED_VTABLE, kind == KIND_ARC, ref_cnt == 1
let b2m = BytesMut::from(b2);
assert_eq!(b2m, vec);
}
#[test]
fn test_bytesmut_from_bytes_arc_offset() {
let vec = vec![33u8; 1024];
// Test case where offset != 0
let mut b1 = Bytes::from(vec.clone());
let b2 = b1.split_off(20);
let b1m = BytesMut::from(b1);
let b2m = BytesMut::from(b2);
assert_eq!(b2m, vec[20..]);
assert_eq!(b1m, vec[..20]);
}
+4 -4
View File
@@ -1,11 +1,11 @@
#![warn(rust_2018_idioms)]
use bytes::Bytes;
use bytes::{buf::IntoIter, Bytes};
#[test]
fn iter_len() {
let buf = Bytes::from_static(b"hello world");
let iter = buf.iter();
let iter = IntoIter::new(buf);
assert_eq!(iter.size_hint(), (11, Some(11)));
assert_eq!(iter.len(), 11);
@@ -13,8 +13,8 @@ fn iter_len() {
#[test]
fn empty_iter_len() {
let buf = Bytes::from_static(b"");
let iter = buf.iter();
let buf = Bytes::new();
let iter = IntoIter::new(buf);
assert_eq!(iter.size_hint(), (0, Some(0)));
assert_eq!(iter.len(), 0);