1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
//! Centralized allocation-request precondition checks.
//!
//! The allocator exposes three caller surfaces with subtly different
//! preconditions:
//!
//! - `thread_alloc(size, align)` accepts arbitrary unsafe inputs and must
//! reject every invalid `(size, align)` combination before dispatch.
//! - `thread_alloc_layout(size, align)` is invoked from `GlobalAlloc::alloc`
//! after `Layout::from_size_align` has already enforced the
//! nonzero-power-of-two alignment contract, so it only needs to enforce
//! Mnemosyne's allocator-specific upper bounds.
//! - `allocate_large_or_huge(size, align)` is reachable both from the
//! high-alignment fast path inside `thread_alloc` and as the large-block
//! fallback; it must apply the full validation surface because callers can
//! bypass `thread_alloc`.
//!
//! Centralizing these checks here keeps every entry point in sync with a
//! single set of `const fn` predicates so a future change to
//! `MAX_ALLOC_SIZE`, the segment-alignment cap, or the power-of-two
//! requirement only edits one definition.
use crate;
/// Returns `true` when `(size, align)` is a valid Mnemosyne allocation
/// request for the unsafe direct entry points.
///
/// The predicate is the conjunction of five clauses:
///
/// 1. `size != 0` — zero-size allocations are routed through the dedicated
/// null-return path because Mnemosyne does not return a unique sentinel
/// for `size == 0`.
/// 2. `size <= MAX_ALLOC_SIZE` — the payload bound preserves pointer-offset
/// arithmetic safety throughout the arena.
/// 3. `align != 0` — a zero alignment is not a valid `Layout` alignment.
/// 4. `align.is_power_of_two()` — Mnemosyne aligns through bitwise masks,
/// which assume a power-of-two alignment.
/// 5. `align <= SEGMENT_SIZE` — alignments above the segment alignment
/// would break the small-free classifier's segment-rounding header
/// recovery.
pub const
/// Returns `true` when `(size, align)` is a valid Mnemosyne allocation
/// request for `Layout`-validated callers.
///
/// The caller is responsible for guaranteeing that `align` is a nonzero
/// power of two, which `Layout::from_size_align` already enforces. This
/// predicate therefore checks only the size bounds and the segment-alignment
/// upper limit, leaving the power-of-two contract to be `debug_assert!`ed
/// at the entry point.
pub const