1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
//! [`SharedReadToken`] — a `Copy`, read-only capability derived from a brand.
use fmt;
use PhantomData;
use InvariantLifetime;
use Sealed;
use ReadPermit;
/// A freely-copyable, read-only permit for a brand.
///
/// Unlike [`ExclusiveToken`](crate::ExclusiveToken), a `SharedReadToken` is
/// [`Copy`], so it can be stored in many places and handed to many readers
/// (including many threads). Soundness is preserved by construction: the only
/// ways to obtain one are [`ExclusiveToken::share`](crate::ExclusiveToken::share)
/// and [`SyncRegionToken::share`](crate::sync::SyncRegionToken::share), each of
/// which borrows its owning token immutably for `'a`. As long as any copy
/// survives, that immutable borrow keeps the owning token from being borrowed
/// mutably, so no [`WritePermit`](crate::WritePermit) of the same brand can be
/// formed concurrently.
///
/// The `'a` lifetime is the *sharing window*; the `'brand` lifetime is the brand
/// identity. The window phantom is a covariant `&'a ()`—the marker need only
/// carry the immutable-borrow window, not the concrete owning token's type—so
/// the same token type serves every owner family. It is `Send + Sync`, enabling
/// concurrent reads of branded cells across threads.
///
/// Device-buffer observers use the same window: after the write owner returns a
/// [`SyncRegionToken`](crate::sync::SyncRegionToken), a copied
/// `SharedReadToken` may be sent to multiple readback or validation threads.
/// While those copies live, no mutable borrow of the region token can exist, so
/// no host/device write capability for the same brand can be formed.
// SAFETY: the token's `'a` window is a live immutable borrow of the unique
// owning `ExclusiveToken`; no `&mut` of that token, and hence no write permit,
// can exist while any copy of this token lives.
unsafe