pub fn buffer_for<T>(n: u64, what: &str) -> Vec<T>Expand description
An empty buffer with room for n elements, for a node whose buffer
size comes from a value — a wire, a constant, or arithmetic on
either.
Vec::with_capacity(n as usize) is the obvious spelling and it is
wrong twice over for a value the node did not choose. A size the
machine cannot hold makes the allocator abort the process, which
no catch_unwind sees: not an error on the program that asked, but
the host gone. And as usize truncates on a 32-bit target, so a
large size silently becomes a small one. Here a size that does not
fit usize, or cannot be reserved, is a failure of the node like
any other — caught, attributed to the node and its inputs, and the
same on every engine.
There is no cap. A size that can be allocated is allocated, however
slow filling it is; how large a string a host asks for is the host’s
business. What this refuses is only what could never have
succeeded. Arithmetic on a size belongs in u64 with
saturating_add, so an overflow reaches here as a size that cannot
be reserved rather than wrapping to a small one first.