rusty-opus 1.0.0

Pure-Rust Opus audio codec (RFC 6716): encoder and decoder, SILK/CELT/Hybrid, SIMD-accelerated, zero dependencies
Documentation
# Unsafe code inventory


<!-- Generated by tools/gen_unsafe_inventory.py - do not edit by hand. -->


Every `unsafe` item in `src/`: **69 `unsafe fn`** and **104 `unsafe` blocks**, all audited 2026-10-04.

All of it is in SIMD kernels (`#[target_feature]` AVX/AVX2/FMA/SSE on x86, NEON on aarch64) and their dispatch sites. The entropy coder, packet parsing, and every other untrusted-input stage are entirely safe Rust. Policy:

- every `unsafe fn` documents its contract in a `# Safety` section (required CPU features, slice-length requirements);
- every `unsafe` block carries a `// SAFETY:` comment proving that contract at that site (enforced: `clippy::undocumented_unsafe_blocks = "deny"`);
- every safe function that reaches a kernel enforces the kernel's length contract with an `assert!` or a checked slice, so misuse panics instead of reading out of bounds;
- each kernel has a scalar twin and a `*_matches_scalar` oracle test that runs on x86_64 and, under qemu, aarch64 (`RUSTY_OPUS_ISA=scalar` reaches the twins on both).

Columns: location, kind, enclosing function, and the first line of the justification.

## `src/bands.rs` (20)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 261 | unsafe fn | `stereo_itheta_neon` | - NEON must be available (baseline on aarch64; |
| 416 | unsafe block | `stereo_itheta` | the `isa::neon()` check above guarantees NEON. |
| 1312 | unsafe block | `quant_partition` | `neon` is `isa::neon()`, so NEON is available. |
| 1385 | unsafe fn | `deinterleave_hadamard_neon` | No safety precondition remains: the body is entirely safe code. |
| 1428 | unsafe block | `deinterleave_hadamard` | the kernel has no remaining precondition: `tmp` and `x` accesses are bounds-checked. |
| 1452 | unsafe fn | `interleave_hadamard_neon` | No safety precondition remains: the body is entirely safe code. |
| 1495 | unsafe block | `interleave_hadamard` | the kernel has no remaining precondition: `tmp` and `x` accesses are bounds-checked. |
| 2340 | unsafe block | `compute_band_energy_neon` | NEON is a baseline feature of the aarch64 targets this crate builds for (the caller additionally gates on `isa::neon()`). |
| 2396 | unsafe fn | `compute_band_energy_avx2` | - The CPU must support AVX2 and FMA (`#[target_feature(enable = "avx2,fma")]`); |
| 2471 | unsafe block | `compute_band_energies` | `use_avx2` is `isa::avx2_fma()`, matching the kernel's `avx2,fma` target features; |
| 2534 | unsafe block | `normalise_bands` | `use_avx2` is `isa::avx2()`, matching the kernel's `avx2` target feature; |
| 2542 | unsafe block | `normalise_bands` | `isa::neon()` was checked in the condition; |
| 2564 | unsafe fn | `scale_slice_avx2` | - The CPU must support AVX2 (`#[target_feature(enable = "avx2")]`); |
| 2602 | unsafe fn | `scale_slice_neon` | - NEON must be available (baseline on aarch64; |
| 2674 | unsafe block | `denormalise_bands` | `use_avx2` is `isa::avx2()`, matching the kernel's `avx2` target feature; |
| 2682 | unsafe block | `denormalise_bands` | `isa::neon()` was checked in the condition; |
| 2708 | unsafe fn | `renormalise_vector_neon` | - NEON must be available (baseline on aarch64; |
| 2795 | unsafe fn | `renormalise_vector_avx2` | - The CPU must support AVX2 and FMA (`#[target_feature(enable = "avx2,fma")]`); |
| 2861 | unsafe block | `renormalise_vector` | `isa::neon()` was checked above. |
| 2869 | unsafe block | `renormalise_vector` | `isa::avx2_fma()` in the condition matches the kernel's `avx2,fma` target features. |

## `src/celt.rs` (15)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 168 | unsafe block | `l1_metric` | `l1_metric_avx` is only called after `isa::avx()` confirmed the CPU supports AVX (its sole `#[target_feature]`). |
| 178 | unsafe block | `l1_metric` | `isa::neon()` confirmed NEON (the kernel's `#[target_feature]`). |
| 197 | unsafe fn | `sum_abs_avx` | - The CPU must support AVX (gate on `isa::avx()`). |
| 246 | unsafe fn | `l1_metric_avx` | - The CPU must support AVX (gate on `isa::avx()`). |
| 260 | unsafe fn | `l1_metric_neon` | - The CPU must support NEON (gate on `isa::neon()`). |
| 264 | unsafe block | `l1_metric_neon` | this block only inherits the caller's `# Safety` contract above (NEON present, `tmp.len() >= n`); |
| 608 | unsafe block | `comb_filter_const` | `isa::avx_fma()` confirmed AVX+FMA, exactly the kernel's `#[target_feature(enable = "avx,fma")]`. |
| 620 | unsafe block | `comb_filter_const` | SSE/SSE2 are compile-time enabled (cfg above) and confirmed by `isa::sse2()`. |
| 678 | unsafe block | `comb_filter_const_neon` | NEON is baseline on aarch64 and the only caller, `comb_filter_const`, checked `isa::neon()` first. |
| 692 | unsafe fn | `comb_filter_const_neon_impl` | - The CPU must support NEON (baseline on aarch64; |
| 765 | unsafe fn | `comb_filter_const_sse` | - The CPU must support SSE (compile-time enabled via the `cfg`; |
| 842 | unsafe fn | `comb_filter_const_avx` | - The CPU must support AVX and FMA (gate on `isa::avx_fma()`). |
| 957 | unsafe fn | `comb_filter_const_sse_fma` | - The CPU must support AVX and FMA (only called from `comb_filter_const_avx`, itself gated on `isa::avx_fma()`). |
| 1170 | unsafe block | `comb_filter_inplace` | `isa::avx2()` confirmed AVX2, the kernel's only `#[target_feature]`. |
| 1205 | unsafe fn | `comb_filter_const_avx2` | - The CPU must support AVX2 (gate on `isa::avx2()`). |

## `src/celt_lpc.rs` (4)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 88 | unsafe block | `celt_fir` | NEON is baseline on aarch64 and `isa::neon()` confirmed it. |
| 116 | unsafe block | `celt_iir` | NEON is baseline on aarch64 and `isa::neon()` confirmed it. |
| 147 | unsafe fn | `celt_fir_neon` | - The CPU must support NEON (baseline on aarch64; |
| 203 | unsafe fn | `celt_iir_neon` | - The CPU must support NEON (baseline on aarch64; |

## `src/kiss_fft.rs` (21)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 218 | unsafe fn | `kf_bfly2_m1_neon` | - NEON must be available. |
| 291 | unsafe block | `kf_bfly2` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 304 | unsafe block | `kf_bfly2` | NEON is baseline on aarch64. |
| 355 | unsafe fn | `kf_bfly4_m1_neon` | - NEON must be available (baseline on aarch64). |
| 432 | unsafe fn | `kf_bfly4_neon_inner` | No caller obligations. |
| 520 | unsafe block | `kf_bfly4` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 533 | unsafe block | `kf_bfly4` | NEON is baseline on aarch64. |
| 555 | unsafe block | `kf_bfly4` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 566 | unsafe block | `kf_bfly4` | the kernel uses no intrinsics and no raw pointers. |
| 622 | unsafe block | `kf_bfly3` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 639 | unsafe block | `kf_bfly3` | NEON is baseline on aarch64. |
| 698 | unsafe block | `kf_bfly5` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 715 | unsafe block | `kf_bfly5` | NEON is baseline on aarch64. |
| 800 | unsafe fn | `kf_bfly2_m1_avx` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 817 | unsafe fn | `kf_bfly4_m1_avx` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 842 | unsafe fn | `kf_bfly4_avx_inner` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 895 | unsafe fn | `kf_bfly3_avx_inner` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 945 | unsafe fn | `kf_bfly5_avx_inner` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 1032 | unsafe fn | `neon_cmul_2` | NEON must be available (baseline on aarch64). |
| 1073 | unsafe fn | `kf_bfly3_neon_inner` | - NEON must be available (baseline on aarch64). |
| 1190 | unsafe fn | `kf_bfly5_neon_inner` | - NEON must be available (baseline on aarch64). |

## `src/mdct.rs` (15)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 174 | unsafe block | `forward` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 217 | unsafe block | `forward` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 292 | unsafe block | `backward` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 341 | unsafe block | `backward` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 413 | unsafe block | `backward` | the kernel is only called after `crate::isa::avx()` returns true, which confirms the CPU supports the `avx` feature in its `#[target_feature]`. |
| 457 | unsafe fn | `mdct_pre_rotation_avx` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 486 | unsafe fn | `mdct_post_rotation_avx` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 515 | unsafe fn | `mdct_backward_pre_rotation_avx` | The CPU must support `avx` (check `crate::isa::avx()`). |
| 547 | unsafe fn | `mdct_backward_post_rotation_avx` | The CPU must support `avx`. |
| 598 | unsafe fn | `mdct_tdac_avx` | - The CPU must support `avx` (check `crate::isa::avx()`). |
| 672 | unsafe block | `mdct_pre_rotation_neon` | NEON is a baseline feature of every aarch64 target, so the intrinsics are available; |
| 763 | unsafe block | `mdct_post_rotation_neon` | NEON is baseline on aarch64, so the intrinsics are available. |
| 853 | unsafe block | `mdct_backward_pre_rotation_neon` | NEON is baseline on aarch64, so the intrinsics are available. |
| 928 | unsafe block | `mdct_backward_post_rotation_neon` | the only caller, `MdctLookup::backward`, runs `assert!(output.len() >= overlap2 + n2)` before calling, so `out_base = output + overlap2` is in bounds  |
| 1034 | unsafe block | `mdct_tdac_neon` | NEON is baseline on aarch64, so the intrinsics are available. |

## `src/pitch.rs` (28)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 15 | unsafe block | `inner_prod` | `isa::avx_fma()` confirmed AVX+FMA, exactly the kernel's `#[target_feature(enable = "avx,fma")]`. |
| 25 | unsafe block | `inner_prod` | `isa::neon()` confirmed NEON (aarch64 baseline). |
| 32 | unsafe block | `inner_prod` | SSE is compile-time enabled (cfg) and `isa::sse2()` confirmed it. |
| 53 | unsafe block | `dual_inner_prod` | `isa::avx_fma()` confirmed AVX+FMA, exactly the kernel's `#[target_feature(enable = "avx,fma")]`. |
| 63 | unsafe block | `dual_inner_prod` | `isa::neon()` confirmed NEON (aarch64 baseline). |
| 70 | unsafe block | `dual_inner_prod` | SSE is compile-time enabled (cfg) and `isa::sse2()` confirmed it. |
| 105 | unsafe block | `pitch_xcorr` | `isa::avx_fma()` confirmed AVX+FMA, exactly the kernel's `#[target_feature(enable = "avx,fma")]`. |
| 119 | unsafe block | `pitch_xcorr` | `isa::neon()` confirmed NEON. |
| 128 | unsafe block | `pitch_xcorr` | `isa::neon()` confirmed NEON. |
| 138 | unsafe block | `pitch_xcorr` | SSE is compile-time enabled (cfg) and `isa::sse2()` confirmed it. |
| 158 | unsafe fn | `inner_prod_neon` | - The CPU must support NEON (baseline on aarch64; |
| 203 | unsafe fn | `dual_inner_prod_neon` | - The CPU must support NEON (baseline on aarch64; |
| 261 | unsafe fn | `xcorr_kernel_neon` | - The CPU must support NEON (baseline on aarch64; |
| 354 | unsafe fn | `pitch_xcorr_neon` | - The CPU must support NEON (baseline on aarch64; |
| 373 | unsafe block | `pitch_xcorr_neon` | NEON is part of this fn's own `# Safety` contract. |
| 386 | unsafe block | `pitch_xcorr_neon` | NEON is part of this fn's own `# Safety` contract. |
| 401 | unsafe fn | `inner_prod_sse` | - The CPU must support SSE (compile-time enabled via the `cfg`; |
| 454 | unsafe fn | `dual_inner_prod_sse` | - The CPU must support SSE (compile-time enabled via the `cfg`; |
| 507 | unsafe fn | `xcorr_kernel_sse` | - The CPU must support SSE (compile-time enabled via the `cfg`; |
| 585 | unsafe fn | `pitch_xcorr_sse` | - The CPU must support SSE (compile-time enabled via the `cfg`; |
| 612 | unsafe fn | `inner_prod_avx` | - The CPU must support AVX and FMA (gate on `isa::avx_fma()`). |
| 666 | unsafe fn | `dual_inner_prod_avx` | - The CPU must support AVX and FMA (gate on `isa::avx_fma()`). |
| 739 | unsafe fn | `pitch_xcorr_avx` | - The CPU must support AVX and FMA (gate on `isa::avx_fma()`). |
| 769 | unsafe fn | `xcorr_kernel_avx` | - The CPU must support AVX and FMA (gate on `isa::avx_fma()`). |
| 995 | unsafe block | `pitch_downsample_neon` | NEON is baseline on aarch64 and the only caller (`pitch_downsample`) checked `isa::neon()`. |
| 1089 | unsafe block | `find_best_pitch` | NEON confirmed by `isa::neon()` in the condition above. |
| 1126 | unsafe block | `find_best_pitch` | AVX intrinsics run only inside `if crate::isa::avx()`; |
| 1349 | unsafe block | `sum_squares` | `isa::neon()` confirmed NEON (aarch64 baseline). |

## `src/prof.rs` (1)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 96 | unsafe block | `ticks` | `_rdtsc` is a pure timestamp read with no memory effects; |

## `src/pvq.rs` (33)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 113 | unsafe block | `celt_pvq_u_lookup` | `r < CELT_PVQ_U_ROW.len()` is guaranteed by the early return just above, so `get_unchecked(r)` is in bounds; |
| 587 | unsafe block | `pvq_search` | `isa::avx2_fma()` confirms exactly the kernel's `#[target_feature(enable = "avx2,fma")]`. |
| 612 | unsafe fn | `pvq_fast_select_init_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 723 | unsafe block | `pvq_search_fast_select` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped. |
| 731 | unsafe block | `pvq_search_fast_select` | `abs_x_mu[i]` was initialized two lines above. |
| 739 | unsafe block | `pvq_search_fast_select` | `MaybeUninit<f32>` has the layout of `f32`; |
| 742 | unsafe block | `pvq_search_fast_select` | as for `abs_x`: `signs_mu[0..n]` was fully initialized by the same init path, `MaybeUninit<i32>` has the layout of `i32`, and `n <= MAX_PVQ_N`. |
| 751 | unsafe block | `pvq_search_fast_select` | `i < n`; |
| 767 | unsafe block | `pvq_search_fast_select` | `sum > 1e-15` (enclosing condition) implies at least one element was summed, so `n >= 1`; |
| 808 | unsafe block | `pvq_search_fast_select` | `i < n`; |
| 832 | unsafe fn | `pvq_search_scalar_init_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 931 | unsafe block | `pvq_search_small_k` | `i < n <= 31` (the only caller, `pvq_search_scalar`, is reached from `pvq_search` only when `n < 32`; |
| 953 | unsafe block | `pvq_search_small_k` | every index used (`0`, `i`/`i + 1` < n, and `best_id`, which is only ever 0 or such an index) is < n <= 31 < 32 = `abs_x.len()` = `y2f.len()`. |
| 1001 | unsafe block | `pvq_search_small_k` | `i < n <= 31`, `sign_x` has 32 elements, and `y.len() >= n` (checked by the caller's `y[..n].fill(0)`). |
| 1042 | unsafe block | `pvq_search_scalar` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped. |
| 1051 | unsafe block | `pvq_search_scalar` | `isa::avx2()` confirms exactly the kernel's `#[target_feature(enable = "avx2")]`. |
| 1074 | unsafe block | `pvq_search_scalar` | `i < n <= 31` keeps `abs_x`/`y2f` (32 elements) in bounds, and `y.len() >= n` because `y[..n].fill(0)` at the top would have panicked otherwise. |
| 1104 | unsafe block | `pvq_search_scalar` | reads of `abs_x`/`y2f` at index 0 and `i < n <= 31` stay inside the 32-element arrays. |
| 1137 | unsafe block | `pvq_search_scalar` | `i < n <= 31`, `sign_x` has 32 elements, and `y.len() >= n` (checked by `y[..n].fill(0)` at the top of the function). |
| 1170 | unsafe fn | `pvq_search_avx2` | - The CPU must support AVX2 and FMA (`#[target_feature(enable = "avx2,fma")]`); |
| 1366 | unsafe block | `exp_rotation1` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped. |
| 1406 | unsafe fn | `exp_rotation1_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 1501 | unsafe fn | `extract_collapse_mask_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 1557 | unsafe block | `extract_collapse_mask` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped; |
| 1587 | unsafe fn | `renormalise_vector_avx2` | - The CPU must support AVX2 and FMA (`#[target_feature(enable = "avx2,fma")]`); |
| 1653 | unsafe fn | `alg_quant_resynth_avx2` | - The CPU must support AVX2 and FMA (`#[target_feature(enable = "avx2,fma")]`); |
| 1711 | unsafe fn | `pvq_search_scalar_init_avx2` | - The CPU must support AVX2 (`#[target_feature(enable = "avx2")]`); |
| 1764 | unsafe fn | `renormalise_vector_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 1843 | unsafe block | `renormalise_vector` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped. |
| 1852 | unsafe block | `renormalise_vector` | `isa::avx2_fma()` confirms exactly the kernel's `#[target_feature(enable = "avx2,fma")]`. |
| 1879 | unsafe fn | `alg_quant_resynth_neon` | - NEON is part of the aarch64 baseline, so there is no extra CPU-feature obligation; |
| 1941 | unsafe block | `alg_quant_resynth` | NEON is aarch64 baseline and `isa::neon()` confirms it is not capped. |
| 1954 | unsafe block | `alg_quant_resynth_scalar` | the kernel is only called after `isa::avx2_fma()` confirms exactly its `#[target_feature(enable = "avx2,fma")]`. |

## `src/silk/nsq.rs` (6)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 227 | unsafe block | `silk_nsq_noise_shape_feedback_loop` | every index touched is in `0..order`. |
| 264 | unsafe block | `silk_nsq_noise_shape_feedback_loop_order12` | indices 0..=11 only. |
| 394 | unsafe block | `lpc_pred_order6` | reads `s_lpc[idx - 5..=idx]` and `a_q12[0..6]`. |
| 439 | unsafe block | `lpc_pred_order10` | reads `s_lpc[idx - 9..=idx]` and `a_q12[0..10]`. |
| 504 | unsafe block | `lpc_pred_order16` | reads `s_lpc[idx - 15..=idx]` and `a_q12[0..16]`. |
| 599 | unsafe block | `lpc_pred_generic` | requires `order <= 16`: then `idx - j >= idx - 15 >= 0` (`idx = NSQ_LPC_BUF_LENGTH - 1 + i`), `idx < s_lpc.len()` (see `lpc_pred_order16`), and `j < 1 |

## `src/silk/nsq_del_dec.rs` (8)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 142 | unsafe fn | `silk_lpc_prediction_neon` | - The CPU must support NEON (`crate::isa::neon()`; |
| 211 | unsafe fn | `silk_lpc_prediction_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`); |
| 309 | unsafe block | `silk_noise_shape_quantizer_short_prediction` | NEON confirmed by `isa::neon()`; |
| 320 | unsafe block | `silk_noise_shape_quantizer_short_prediction` | `lpc_avx2_enabled()` is `crate::isa::avx2()`, matching the kernel's `avx2` target feature; |
| 399 | unsafe fn | `nsq_shape_filter_soa_avx2` | The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 473 | unsafe block | `nsq_shape_filter_soa` | `nsq_shape_avx2_enabled()` returns true only if `crate::isa::avx2()` does, which checks exactly the `avx2` feature the kernel is compiled with. |
| 516 | unsafe block | `avx2_matches_scalar` | the test returns early unless `is_x86_feature_detected!("avx2")`. |
| 565 | unsafe block | `nsq_shape_filter_avx2_matches_scalar` | the test returns early unless `is_x86_feature_detected!("avx2")`; |

## `src/silk/resampler.rs` (2)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 190 | unsafe block | `resampler_fir12_8` | `crate::isa::sse2()` just returned true, matching the kernel's `#[target_feature(enable = "sse2")]`. |
| 210 | unsafe fn | `resampler_fir12_8_sse2` | - The CPU must support SSE2 (the kernel is compiled with `#[target_feature(enable = "sse2")]`; |

## `src/silk/sigproc_fix.rs` (20)


| Line | Kind | Function | Justification (first line) |
|---:|---|---|---|
| 118 | unsafe block | `silk_biquad_alt_stride2` | `crate::isa::neon()` just returned true, so NEON is available. |
| 166 | unsafe block | `xcorr_kernel_c` | NEON confirmed by `isa::neon()`; |
| 174 | unsafe block | `xcorr_kernel_c` | `isa::avx2()` matches the kernel's `#[target_feature(enable = "avx2")]`; |
| 266 | unsafe fn | `xcorr_kernel_neon_s16` | - The CPU must support NEON (`crate::isa::neon()`; |
| 461 | unsafe block | `silk_sum_sqr_shift` | `crate::isa::neon()` just returned true, so NEON is available. |
| 470 | unsafe block | `silk_sum_sqr_shift` | `crate::isa::avx2()` just returned true, matching the kernel's `#[target_feature(enable = "avx2")]`. |
| 502 | unsafe fn | `silk_sum_sqr_shift_neon` | - The CPU must support NEON (`crate::isa::neon()`; |
| 550 | unsafe block | `silk_inner_prod_aligned` | `crate::isa::neon()` just returned true, so NEON is available. |
| 559 | unsafe block | `silk_inner_prod_aligned` | `crate::isa::avx2()` just returned true, matching the kernel's `#[target_feature(enable = "avx2")]`. |
| 604 | unsafe fn | `silk_inner_prod_aligned_neon` | - The CPU must support NEON (`crate::isa::neon()`; |
| 887 | unsafe fn | `warped_corr_update_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 923 | unsafe block | `warped_corr_update` | `warped_corr_avx2_enabled()` returns true only if `crate::isa::avx2()` does, which checks exactly the kernel's `avx2` feature. |
| 1018 | unsafe block | `avx2_matches_scalar` | the test returns early unless `is_x86_feature_detected!("avx2")`; |
| 1134 | unsafe block | `silk_lpc_analysis_filter` | `crate::isa::avx2()` just returned true, matching the kernel's `#[target_feature(enable = "avx2")]`; |
| 1170 | unsafe block | `silk_lpc_analysis_filter_scalar` | lower bounds: `ix >= d` and `j + 2 <= d`, so every `input[ix - j - 1]` / `input[ix - j - 2]` index is >= 0 (the public entry `silk_lpc_analysis_filter |
| 1291 | unsafe fn | `silk_inner_prod_aligned_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 1354 | unsafe fn | `xcorr_kernel_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 1416 | unsafe fn | `silk_sum_sqr_shift_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 1473 | unsafe fn | `silk_lpc_analysis_filter_avx2` | - The CPU must support AVX2 (the kernel is compiled with `#[target_feature(enable = "avx2")]`). |
| 1543 | unsafe fn | `silk_biquad_alt_stride2_neon` | - The CPU must support NEON (`crate::isa::neon()`; |