1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
// Copyright (c) Microsoft Corporation.
// Licensed under the MIT License.
//! Shared CSR string storage helpers — the crate's single home for unchecked
//! UTF-8 reconstruction.
//!
//! Both interners ([`LocalLexicon`](crate::LocalLexicon) and each
//! [`ThreadedLexicon`](crate::ThreadedLexicon) shard) and their frozen
//! readers store strings the same way: every interned string's bytes are appended
//! to one contiguous `bytes` buffer, and a `u32` `offsets` table records the
//! boundaries CSR-style — `offsets[i]` is the start and `offsets[i + 1]` the end of
//! the `i`-th string, with a leading `0` sentinel so it holds `len() + 1` entries.
//!
//! Because every byte range in `offsets` was produced by appending a `&str`, the
//! bytes it spans are always valid UTF-8. These helpers exploit that to skip
//! re-validation (and, unlike slicing a `&str`, the UTF-8 char-boundary checks that
//! `str` range-indexing performs), which is the crate's fastest resolve path.
//!
//! This is the *only* module that uses `unsafe`. Given valid interner-produced
//! storage, [`resolve`] is memory-safe for any `index` and returns `None` when it
//! is out of range. The hot-path [`str_at`] helper additionally requires an
//! in-range index produced by the storage's own dedup table. Callers must uphold
//! that offsets are monotonic, remain within `bytes`, and delimit valid UTF-8 —
//! guaranteed by construction because ranges are recorded only when appending a
//! `&str`.
/// Reconstructs the string at an **in-range** dense/local `index`
/// (`bytes[offsets[index]..offsets[index + 1]]`).
///
/// Used on the hot interning-compare path, where `index` comes from a handle the
/// table just produced and is therefore always valid.
pub
/// Resolves a possibly-out-of-range dense/local `index`, returning `None` if it
/// does not name a stored string.
///
/// Used on the public `resolve` / `try_resolve` paths, which must tolerate foreign
/// or crafted handles.
pub