[]Struct safer_ffi::prelude::Out

#[repr(transparent)]pub struct Out<'out, T>(_, _)
    T: 'out + ?Sized
This is supported on feature="out-refs" only.

Wrapper expressing the semantics of &out T references

In other words, this has the semantics of &'out mut MaybeUninit<T> but for the ability to write garbage (MaybeUninit::uninit()) into it (else coercing &mut T to &out T = Out<T> would be unsound).

This means that the reference may point to uninitialized memory (or not), and thus that writes to the pointee will not call the .drop() destructor.

This type can be [trivially constructed][crate::AsOut] from:

  • a &'out mut MaybeUninit<T> (main point of the type),

  • a &'out mut T (to keep the ergonomics of being able to overwrite an already initialized value).

    • To avoid "accidentally" leaking memory in this second case, either T must be Copy (sufficient condition to prove there is no drop glue), or you must first call [.manually_drop_mut()][crate::ManuallyDropMut] before the [.as_out()][crate::AsOut] "coercion".


impl<'out, T> Out<'out, T> where
    T: 'out + ?Sized

pub fn reborrow<'reborrow>(&'reborrow mut self) -> Out<'reborrow, T> where
    'out: 'reborrow, 

This is supported on feature="out-refs" only.

Reborrows the &out _ reference for a shorter lifetime.

pub fn r<'reborrow>(&'reborrow mut self) -> Out<'reborrow, T> where
    'out: 'reborrow, 

This is supported on feature="out-refs" only.

Shorthand for .reborrow().

impl<'out, T> Out<'out, T> where
    T: 'out, 

pub fn write(self, value: T) -> &'out mut T

This is supported on feature="out-refs" only.

Write a value into the pointee, returning an .assume_init()-ed reference to it.

Guarantees (that unsafe code may rely on)

After the function returns, the pointee is guaranteed to have been initialized; it is thus sound to use that property to manually assume_init() it or any chunk of such items.

pub fn replace(self, value: T) -> (MaybeUninit<T>, &'out mut T)

This is supported on feature="out-refs" only.

Similar to .write(), but getting the previous value back. Such previous value may or may not be initialized.

Guarantees (that unsafe code may rely on)

  • After the function returns, the pointee is guaranteed to have been initialized; it is thus sound to use that property to manually assume_init() it or any chunk of such items.

  • there is no such guarantee regarding the previous value, which is thus only sound to assume_init() if the pointee already was (before the call to .replace()).

pub fn as_mut_ptr(&mut self) -> *mut T

This is supported on feature="out-refs" only.

Returns a raw mutable pointer to the pointee.

Guarantees (that unsafe code may rely on)

  • The returned pointer does point to the pointee, meaning that if such returned pointer is used to .write() to the pointee, then it is safe to assume_init() it.

  • The returned pointer is non null, well-aligned, and writeable.

    It is also technically readable:

    • you can read a MaybeUninit<T> out of it after .cast()ing it,

    • otherwise, except when sound to assume_init(), the obtained pointer cannot be used to read the value : T of the pointee!

pub unsafe fn assume_init(self) -> &'out mut T

This is supported on feature="out-refs" only.

Upgrades the &out _ (write-only) reference to a read-writeable &mut _.


Don't be lured by the &mut reference: Rust validity invariants imply that an &mut reference is only sound to produce if it points to an initialized value; it is otherwise instant UB. See [MaybeUninit::assume_init] for more info about it. Thus:

  • The pointee must have been initialized.

This is a validity invariant, meaning that UB does happen from just calling that function to produce an ill-formed reference, even if the obtained reference is "never actually used".


The following program exhibits Undefined Behavior:

use ::uninit::prelude::*;

let mut x = MaybeUninit::uninit();
let _unused: &mut u8 = unsafe {
    x   .as_out()
        .assume_init() // UB!

pub unsafe fn as_mut_uninit(self) -> &'out mut MaybeUninit<T>

This is supported on feature="out-refs" only.

Upgrades the &out _ (write-valid-values-only) reference to a &mut MaybeUninit<_> (write-anything) reference.


  • The obtained reference cannot be used to write garbage (MaybeUninit::uninit()) into the pointee.

    This means that it can thus not be fed to opaque APIs!!

  • Exception: if the given &out reference has originated from a &mut MaybeUninit<_>, then calling .as_mut_uninit() is a sound way to make the trip back.

This is a safety invariant (i.e., even if it is never "instant" UB to produce such a value, it does break the safety invariant of &mut MaybeUninit<_> (that of being allowed to write MaybeUninit::uninit() garbage into the pointee), so UB can happen afterwards). This is different than .assume_init() soundness relying on a validity invariant, meaning that UB does happen from just calling that function to produce an ill-formed reference, even if the obtained reference is never actually used.


The following code is Undefined Behavior:

use ::uninit::prelude::*;

let mut my_box = Box::new(42);
let at_my_box: Out<'_, Box<i32>> =
// Overwrite `my_box` with uninitialized bytes / garbage content.
unsafe {
    *at_my_box.as_mut_uninit() = MaybeUninit::uninit();
// Runs the destructor for a `Box<i32>` using a garbage pointer that
// may thus point anywhere in memory!

A function from an external library must always be seen as opaque (unless its documentation makes implementation-detail guarantees, such as this very crate does), so one cannot rely on its implementation (unless the lib is open source AND you pin-point to that version of the crate, either through version = "=x.y.z" or through git = ..., rev = ... in Cargo.toml).

This example is not tested
// `fn zeroize (out: &'_ mut MaybeUninit<u8>) -> &'_ mut u8;`
// The author of the crate says it uses that `out` reference to write
// `0` to the pointee.
use ::some_lib::zeroize;

let mut x = 42;
let at_x = x.as_out();
// Unsound! The lib implementation is free to write
// `MaybeUninit::uninit()` garbage to the pointee!
zeroize(unsafe { at_x.as_mut_uninit() });

impl<'out, T> Out<'out, [T]> where
    T: 'out, 

pub fn from_out(out: Out<'out, T>) -> Out<'out, [T]>

This is supported on feature="out-refs" only.

Converts a single item out reference into a 1-long out slice.

This is the &out version of [slice::from_ref] and [slice::from_mut].

pub fn as_ptr(&self) -> *const T

This is supported on feature="out-refs" only.

Obtains a read-only non-NULL and well-aligned raw pointer to a potentially uninitialized T.

Unless maybe with interior mutability through raw pointers, there is no case where using this function is more useful than going through [<[MaybeUninit<_>]>::assume_init_by_ref()][ MaybeUninitExt::assume_init_by_ref].

Worse, the lack of unsafe-ty of the method (ignoring the one needed to use the pointer) and its "boring" name may lead to code read-dereferencing the pointer (which implicitly assume_init()s it) without having ensured the soundness of such (implicit) assume_init().

pub fn as_mut_ptr(&mut self) -> *mut T

This is supported on feature="out-refs" only.

Returns a raw mutable pointer to the pointee.

See Out::as_mut_ptr for more info regarding safety and guarantees.

pub unsafe fn as_mut_uninit(self) -> &'out mut [MaybeUninit<T>]

This is supported on feature="out-refs" only.

Upgrades the &out _ (write-valid-values-only) reference to a &mut MaybeUninit<_> (write-anything) reference.

See Out::as_mut_uninit for more info regarding safety.

pub fn get_out<Index>(
    idx: Index
) -> Option<<Index as SliceIndex<'out, T>>::Output> where
    Index: SliceIndex<'out, T>, 

This is supported on feature="out-refs" only.

Main indexing operation on an &out [_].

The type Index of idx may be:

  • a usize, and then Index::Output is a Out<T> reference to a single element.

  • a Range<usize> (e.g., a .. b), and then Index::Output is a Out<[T]> reference to a subslice.


use ::uninit::prelude::*;

let src: &[u8] = b"Hello, World!";
// Stack-allocate an uninitialized buffer.
let mut buf = uninit_array![u8; 256];
// copy `src` into this stack allocated buffer, effectively initializing it.
let buf: &mut [u8] =
    // buf[.. src.len()].as_out()
    buf.as_out().get_out(.. src.len()).unwrap()
assert_eq!(buf, b"Hello, World!");
buf[7 ..].copy_from_slice(b"Earth!");
assert_eq!(buf, b"Hello, Earth!");

pub unsafe fn get_unchecked_out<Index>(
    idx: Index
) -> <Index as SliceIndex<'out, T>>::Output where
    Index: SliceIndex<'out, T>, 

This is supported on feature="out-refs" only.

Same as .get_out(), but with the bound check being elided.


The given idx mut be in bounds:

  • if idx: usize, then idx must be < self.len().

  • if idx is an upper-bounded range (e.g., .. b, a ..= b), then the upper bound (b in the example) must be < self.len().

  • etc.

See .get_unchecked_mut() for more info about the safety of such call.

pub fn as_uninit(self) -> &'out [MaybeUninit<T>]

This is supported on feature="out-refs" only.

Downgrades the Out<'_, [T]> slice into a &'_ [MaybeUninit<T>].

This leads to a read-only1 "unreadable" slice which is thus only useful for accessing &'_ [] metadata, mainly the length of the slice.

In practice, calling this function explicitely is not even needed given that Out<'_, [T]> : Deref<Target = [MaybeUninit<T>], so one can do:

use ::uninit::prelude::*;

let mut backing_array = uninit_array![_; 42];
let buf: Out<'_, [u8]> = backing_array.as_out();
assert_eq!(buf.len(), 42); // no need to `.r().as_uninit()`

1 Unless Interior Mutability is involved; speaking of which:

Interior Mutability

The whole design of Out references is to forbid any non-unsafe API that would allow writing MaybeUninit::uninit() garbage into the pointee. So, for instance, this crate does not offer any API like:

use ::core::{cell::Cell, mem::MaybeUninit};

// /!\ This is UNSOUND when combined with the `::uninit` crate!
fn swap_mb_uninit_and_cell<T> (
    p: &'_ MaybeUninit<Cell<T>>,
) -> &'_ Cell<MaybeUninit<T>>
    unsafe {
        // Safety: both `Cell` and `MaybeUninit` are `#[repr(transparent)]`

Indeed, if both such non-unsafe API and the uninit crate were present, then one could trigger UB with:

This example is not tested
let mut x = [Cell::new(42)];
let at_mb_uninit_cell: &'_ MaybeUninit<Cell<u8>> =
    .set(MaybeUninit::uninit()) // UB!

The author of the crate believes that such UB is the responsibility of the one who defined swap_mb_uninit_and_cell, and that in general that function is unsound: MaybeUninit-ness and interior mutability do not commute!

  • the Safety annotation in the given example only justifies that it is not breaking any layout-based validity invariants, but it is actually impossible to semantically prove that it is safe for these properties to commute.

If you are strongly convinced of the opposite, please file an issue (if there isn't already one: since this question is not that clear the author is very likely to create an issue themself).

pub unsafe fn assume_all_init(self) -> &'out mut [T]

This is supported on feature="out-refs" only.

Upgrades the &out [_] (write-only) reference to a read-writeable &mut [_].


Don't be lured by the &mut reference: Rust validity invariants imply that an &mut reference is only sound to produce if it points to initialized values; it is otherwise instant UB. See [MaybeUninit::assume_init] for more info about it. Thus:

  • The pointee(s) must have been initialized.

This is a validity invariant, meaning that UB does happen from just calling that function to produce an ill-formed reference, even if the obtained reference is "never actually used".

pub fn copy_from_slice(self, source_slice: &[T]) -> &'out mut [T] where
    T: Copy

This is supported on feature="out-refs" only.

Initialize the buffer with a copy from another (already initialized) buffer.

It returns a read-writable slice to the initialized bytes for convenience (automatically assume_init-ed).


The function panics if the slices' lengths are not equal.

Guarantees (that unsafe code may rely on)

A non-panic!king return from this function guarantees that the input slice has been (successfully) initialized, and that it is thus then sound to .assume_init().

It also guarantees that the returned slice does correspond to the input slice (e.g., for [crate::ReadIntoUninit]'s safety guarantees).


use ::uninit::prelude::*;

let mut array = uninit_array![_; 13];
    array.as_out().copy_from_slice(b"Hello, World!"),
    b"Hello, World!",
// we can thus soundly `assume_init` our array:
let array = unsafe {
        [MaybeUninit<u8>; 13],
        [            u8 ; 13],
    *b"Hello, World!",

pub fn init_with(self, iterable: impl IntoIterator<Item = T>) -> &'out mut [T]

This is supported on feature="out-refs" only.

Fills the buffer with values from up to the first self.len() elements of an iterable.

Guarantees (that unsafe code may rely on)

A non-panicking return from this function guarantees that the first k values of the buffer have been initialized and are thus sound to .assume_init(), where k, the numbers of elements that iterable has yielded (capped at self.len()), is the length of the returned buffer.

pub fn iter_out(&'reborrow mut self) -> IterOut<'reborrow, T>

This is supported on feature="out-refs" only.


pub fn split_at_out(self, idx: usize) -> (Out<'out, [T]>, Out<'out, [T]>)

This is supported on feature="out-refs" only.

Same as .split_at_mut(), but with &out [_] references.


Panics if idx > len.

Methods from Deref<Target = [MaybeUninit<T>]>

pub const fn len(&self) -> usize1.0.0[src]

Returns the number of elements in the slice.


let a = [1, 2, 3];
assert_eq!(a.len(), 3);

pub const fn is_empty(&self) -> bool1.0.0[src]

Returns true if the slice has a length of 0.


let a = [1, 2, 3];

pub fn first(&self) -> Option<&T>1.0.0[src]

Returns the first element of the slice, or None if it is empty.


let v = [10, 40, 30];
assert_eq!(Some(&10), v.first());

let w: &[i32] = &[];
assert_eq!(None, w.first());

pub fn split_first(&self) -> Option<(&T, &[T])>1.5.0[src]

Returns the first and all the rest of the elements of the slice, or None if it is empty.


let x = &[0, 1, 2];

if let Some((first, elements)) = x.split_first() {
    assert_eq!(first, &0);
    assert_eq!(elements, &[1, 2]);

pub fn split_last(&self) -> Option<(&T, &[T])>1.5.0[src]

Returns the last and all the rest of the elements of the slice, or None if it is empty.


let x = &[0, 1, 2];

if let Some((last, elements)) = x.split_last() {
    assert_eq!(last, &2);
    assert_eq!(elements, &[0, 1]);

pub fn last(&self) -> Option<&T>1.0.0[src]

Returns the last element of the slice, or None if it is empty.


let v = [10, 40, 30];
assert_eq!(Some(&30), v.last());

let w: &[i32] = &[];
assert_eq!(None, w.last());

pub fn get<I>(&self, index: I) -> Option<&<I as SliceIndex<[T]>>::Output> where
    I: SliceIndex<[T]>, 

Returns a reference to an element or subslice depending on the type of index.

  • If given a position, returns a reference to the element at that position or None if out of bounds.
  • If given a range, returns the subslice corresponding to that range, or None if out of bounds.


let v = [10, 40, 30];
assert_eq!(Some(&40), v.get(1));
assert_eq!(Some(&[10, 40][..]), v.get(0..2));
assert_eq!(None, v.get(3));
assert_eq!(None, v.get(0..4));

pub unsafe fn get_unchecked<I>(
    index: I
) -> &<I as SliceIndex<[T]>>::Output where
    I: SliceIndex<[T]>, 

Returns a reference to an element or subslice, without doing bounds checking.

This is generally not recommended, use with caution! Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used. For a safe alternative see get.


let x = &[1, 2, 4];

unsafe {
    assert_eq!(x.get_unchecked(1), &2);

pub const fn as_ptr(&self) -> *const T1.0.0[src]

Returns a raw pointer to the slice's buffer.

The caller must ensure that the slice outlives the pointer this function returns, or else it will end up pointing to garbage.

The caller must also ensure that the memory the pointer (non-transitively) points to is never written to (except inside an UnsafeCell) using this pointer or any pointer derived from it. If you need to mutate the contents of the slice, use as_mut_ptr.

Modifying the container referenced by this slice may cause its buffer to be reallocated, which would also make any pointers to it invalid.


let x = &[1, 2, 4];
let x_ptr = x.as_ptr();

unsafe {
    for i in 0..x.len() {
        assert_eq!(x.get_unchecked(i), &*x_ptr.add(i));

pub fn as_ptr_range(&self) -> Range<*const T>[src]

🔬 This is a nightly-only experimental API. (slice_ptr_range)

Returns the two raw pointers spanning the slice.

The returned range is half-open, which means that the end pointer points one past the last element of the slice. This way, an empty slice is represented by two equal pointers, and the difference between the two pointers represents the size of the size.

See as_ptr for warnings on using these pointers. The end pointer requires extra caution, as it does not point to a valid element in the slice.

This function is useful for interacting with foreign interfaces which use two pointers to refer to a range of elements in memory, as is common in C++.

It can also be useful to check if a pointer to an element refers to an element of this slice:


let a = [1, 2, 3];
let x = &a[1] as *const _;
let y = &5 as *const _;


pub fn iter(&self) -> Iter<T>1.0.0[src]

Returns an iterator over the slice.


let x = &[1, 2, 4];
let mut iterator = x.iter();

assert_eq!(iterator.next(), Some(&1));
assert_eq!(iterator.next(), Some(&2));
assert_eq!(iterator.next(), Some(&4));
assert_eq!(iterator.next(), None);

pub fn windows(&self, size: usize) -> Windows<T>1.0.0[src]

Returns an iterator over all contiguous windows of length size. The windows overlap. If the slice is shorter than size, the iterator returns no values.


Panics if size is 0.


let slice = ['r', 'u', 's', 't'];
let mut iter = slice.windows(2);
assert_eq!(iter.next().unwrap(), &['r', 'u']);
assert_eq!(iter.next().unwrap(), &['u', 's']);
assert_eq!(iter.next().unwrap(), &['s', 't']);

If the slice is shorter than size:

let slice = ['f', 'o', 'o'];
let mut iter = slice.windows(4);

pub fn chunks(&self, chunk_size: usize) -> Chunks<T>1.0.0[src]

Returns an iterator over chunk_size elements of the slice at a time, starting at the beginning of the slice.

The chunks are slices and do not overlap. If chunk_size does not divide the length of the slice, then the last chunk will not have length chunk_size.

See chunks_exact for a variant of this iterator that returns chunks of always exactly chunk_size elements, and rchunks for the same iterator but starting at the end of the slice.


Panics if chunk_size is 0.


let slice = ['l', 'o', 'r', 'e', 'm'];
let mut iter = slice.chunks(2);
assert_eq!(iter.next().unwrap(), &['l', 'o']);
assert_eq!(iter.next().unwrap(), &['r', 'e']);
assert_eq!(iter.next().unwrap(), &['m']);

pub fn chunks_exact(&self, chunk_size: usize) -> ChunksExact<T>1.31.0[src]

Returns an iterator over chunk_size elements of the slice at a time, starting at the beginning of the slice.

The chunks are slices and do not overlap. If chunk_size does not divide the length of the slice, then the last up to chunk_size-1 elements will be omitted and can be retrieved from the remainder function of the iterator.

Due to each chunk having exactly chunk_size elements, the compiler can often optimize the resulting code better than in the case of chunks.

See chunks for a variant of this iterator that also returns the remainder as a smaller chunk, and rchunks_exact for the same iterator but starting at the end of the slice.


Panics if chunk_size is 0.


let slice = ['l', 'o', 'r', 'e', 'm'];
let mut iter = slice.chunks_exact(2);
assert_eq!(iter.next().unwrap(), &['l', 'o']);
assert_eq!(iter.next().unwrap(), &['r', 'e']);
assert_eq!(iter.remainder(), &['m']);

pub fn rchunks(&self, chunk_size: usize) -> RChunks<T>1.31.0[src]

Returns an iterator over chunk_size elements of the slice at a time, starting at the end of the slice.

The chunks are slices and do not overlap. If chunk_size does not divide the length of the slice, then the last chunk will not have length chunk_size.

See rchunks_exact for a variant of this iterator that returns chunks of always exactly chunk_size elements, and chunks for the same iterator but starting at the beginning of the slice.


Panics if chunk_size is 0.


let slice = ['l', 'o', 'r', 'e', 'm'];
let mut iter = slice.rchunks(2);
assert_eq!(iter.next().unwrap(), &['e', 'm']);
assert_eq!(iter.next().unwrap(), &['o', 'r']);
assert_eq!(iter.next().unwrap(), &['l']);

pub fn rchunks_exact(&self, chunk_size: usize) -> RChunksExact<T>1.31.0[src]

Returns an iterator over chunk_size elements of the slice at a time, starting at the end of the slice.

The chunks are slices and do not overlap. If chunk_size does not divide the length of the slice, then the last up to chunk_size-1 elements will be omitted and can be retrieved from the remainder function of the iterator.

Due to each chunk having exactly chunk_size elements, the compiler can often optimize the resulting code better than in the case of chunks.

See rchunks for a variant of this iterator that also returns the remainder as a smaller chunk, and chunks_exact for the same iterator but starting at the beginning of the slice.


Panics if chunk_size is 0.


let slice = ['l', 'o', 'r', 'e', 'm'];
let mut iter = slice.rchunks_exact(2);
assert_eq!(iter.next().unwrap(), &['e', 'm']);
assert_eq!(iter.next().unwrap(), &['o', 'r']);
assert_eq!(iter.remainder(), &['l']);

pub fn split_at(&self, mid: usize) -> (&[T], &[T])1.0.0[src]

Divides one slice into two at an index.

The first will contain all indices from [0, mid) (excluding the index mid itself) and the second will contain all indices from [mid, len) (excluding the index len itself).


Panics if mid > len.


let v = [1, 2, 3, 4, 5, 6];

   let (left, right) = v.split_at(0);
   assert!(left == []);
   assert!(right == [1, 2, 3, 4, 5, 6]);

    let (left, right) = v.split_at(2);
    assert!(left == [1, 2]);
    assert!(right == [3, 4, 5, 6]);

    let (left, right) = v.split_at(6);
    assert!(left == [1, 2, 3, 4, 5, 6]);
    assert!(right == []);

pub fn split<F>(&self, pred: F) -> Split<T, F> where
    F: FnMut(&T) -> bool

Returns an iterator over subslices separated by elements that match pred. The matched element is not contained in the subslices.


let slice = [10, 40, 33, 20];
let mut iter = slice.split(|num| num % 3 == 0);

assert_eq!(iter.next().unwrap(), &[10, 40]);
assert_eq!(iter.next().unwrap(), &[20]);

If the first element is matched, an empty slice will be the first item returned by the iterator. Similarly, if the last element in the slice is matched, an empty slice will be the last item returned by the iterator:

let slice = [10, 40, 33];
let mut iter = slice.split(|num| num % 3 == 0);

assert_eq!(iter.next().unwrap(), &[10, 40]);
assert_eq!(iter.next().unwrap(), &[]);

If two matched elements are directly adjacent, an empty slice will be present between them:

let slice = [10, 6, 33, 20];
let mut iter = slice.split(|num| num % 3 == 0);

assert_eq!(iter.next().unwrap(), &[10]);
assert_eq!(iter.next().unwrap(), &[]);
assert_eq!(iter.next().unwrap(), &[20]);

pub fn split_inclusive<F>(&self, pred: F) -> SplitInclusive<T, F> where
    F: FnMut(&T) -> bool

🔬 This is a nightly-only experimental API. (split_inclusive)

Returns an iterator over subslices separated by elements that match pred. The matched element is contained in the end of the previous subslice as a terminator.


let slice = [10, 40, 33, 20];
let mut iter = slice.split_inclusive(|num| num % 3 == 0);

assert_eq!(iter.next().unwrap(), &[10, 40, 33]);
assert_eq!(iter.next().unwrap(), &[20]);

If the last element of the slice is matched, that element will be considered the terminator of the preceding slice. That slice will be the last item returned by the iterator.

let slice = [3, 10, 40, 33];
let mut iter = slice.split_inclusive(|num| num % 3 == 0);

assert_eq!(iter.next().unwrap(), &[3]);
assert_eq!(iter.next().unwrap(), &[10, 40, 33]);

pub fn rsplit<F>(&self, pred: F) -> RSplit<T, F> where
    F: FnMut(&T) -> bool

Returns an iterator over subslices separated by elements that match pred, starting at the end of the slice and working backwards. The matched element is not contained in the subslices.


let slice = [11, 22, 33, 0, 44, 55];
let mut iter = slice.rsplit(|num| *num == 0);

assert_eq!(iter.next().unwrap(), &[44, 55]);
assert_eq!(iter.next().unwrap(), &[11, 22, 33]);
assert_eq!(iter.next(), None);

As with split(), if the first or last element is matched, an empty slice will be the first (or last) item returned by the iterator.

let v = &[0, 1, 1, 2, 3, 5, 8];
let mut it = v.rsplit(|n| *n % 2 == 0);
assert_eq!(it.next().unwrap(), &[]);
assert_eq!(it.next().unwrap(), &[3, 5]);
assert_eq!(it.next().unwrap(), &[1, 1]);
assert_eq!(it.next().unwrap(), &[]);
assert_eq!(it.next(), None);

pub fn splitn<F>(&self, n: usize, pred: F) -> SplitN<T, F> where
    F: FnMut(&T) -> bool

Returns an iterator over subslices separated by elements that match pred, limited to returning at most n items. The matched element is not contained in the subslices.

The last element returned, if any, will contain the remainder of the slice.


Print the slice split once by numbers divisible by 3 (i.e., [10, 40], [20, 60, 50]):

let v = [10, 40, 30, 20, 60, 50];

for group in v.splitn(2, |num| *num % 3 == 0) {
    println!("{:?}", group);

pub fn rsplitn<F>(&self, n: usize, pred: F) -> RSplitN<T, F> where
    F: FnMut(&T) -> bool

Returns an iterator over subslices separated by elements that match pred limited to returning at most n items. This starts at the end of the slice and works backwards. The matched element is not contained in the subslices.

The last element returned, if any, will contain the remainder of the slice.


Print the slice split once, starting from the end, by numbers divisible by 3 (i.e., [50], [10, 40, 30, 20]):

let v = [10, 40, 30, 20, 60, 50];

for group in v.rsplitn(2, |num| *num % 3 == 0) {
    println!("{:?}", group);

pub fn contains(&self, x: &T) -> bool where
    T: PartialEq<T>, 

Returns true if the slice contains an element with the given value.


let v = [10, 40, 30];

If you do not have an &T, but just an &U such that T: Borrow<U> (e.g. String: Borrow<str>), you can use iter().any:

let v = [String::from("hello"), String::from("world")]; // slice of `String`
assert!(v.iter().any(|e| e == "hello")); // search with `&str`
assert!(!v.iter().any(|e| e == "hi"));

pub fn starts_with(&self, needle: &[T]) -> bool where
    T: PartialEq<T>, 

Returns true if needle is a prefix of the slice.


let v = [10, 40, 30];
assert!(v.starts_with(&[10, 40]));
assert!(!v.starts_with(&[10, 50]));

Always returns true if needle is an empty slice:

let v = &[10, 40, 30];
let v: &[u8] = &[];

pub fn ends_with(&self, needle: &[T]) -> bool where
    T: PartialEq<T>, 

Returns true if needle is a suffix of the slice.


let v = [10, 40, 30];
assert!(v.ends_with(&[40, 30]));
assert!(!v.ends_with(&[50, 30]));

Always returns true if needle is an empty slice:

let v = &[10, 40, 30];
let v: &[u8] = &[];

Binary searches this sorted slice for a given element.

If the value is found then Result::Ok is returned, containing the index of the matching element. If there are multiple matches, then any one of the matches could be returned. If the value is not found then Result::Err is returned, containing the index where a matching element could be inserted while maintaining sorted order.


Looks up a series of four elements. The first is found, with a uniquely determined position; the second and third are not found; the fourth could match any position in [1, 4].

let s = [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];

assert_eq!(s.binary_search(&13),  Ok(9));
assert_eq!(s.binary_search(&4),   Err(7));
assert_eq!(s.binary_search(&100), Err(13));
let r = s.binary_search(&1);
assert!(match r { Ok(1..=4) => true, _ => false, });

If you want to insert an item to a sorted vector, while maintaining sort order:

let mut s = vec![0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
let num = 42;
let idx = s.binary_search(&num).unwrap_or_else(|x| x);
s.insert(idx, num);
assert_eq!(s, [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 42, 55]);

pub fn binary_search_by<'a, F>(&'a self, f: F) -> Result<usize, usize> where
    F: FnMut(&'a T) -> Ordering

Binary searches this sorted slice with a comparator function.

The comparator function should implement an order consistent with the sort order of the underlying slice, returning an order code that indicates whether its argument is Less, Equal or Greater the desired target.

If the value is found then Result::Ok is returned, containing the index of the matching element. If there are multiple matches, then any one of the matches could be returned. If the value is not found then Result::Err is returned, containing the index where a matching element could be inserted while maintaining sorted order.


Looks up a series of four elements. The first is found, with a uniquely determined position; the second and third are not found; the fourth could match any position in [1, 4].

let s = [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];

let seek = 13;
assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Ok(9));
let seek = 4;
assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Err(7));
let seek = 100;
assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Err(13));
let seek = 1;
let r = s.binary_search_by(|probe| probe.cmp(&seek));
assert!(match r { Ok(1..=4) => true, _ => false, });

pub fn binary_search_by_key<'a, B, F>(
    &'a self,
    b: &B,
    f: F
) -> Result<usize, usize> where
    B: Ord,
    F: FnMut(&'a T) -> B, 

Binary searches this sorted slice with a key extraction function.

Assumes that the slice is sorted by the key, for instance with sort_by_key using the same key extraction function.

If the value is found then Result::Ok is returned, containing the index of the matching element. If there are multiple matches, then any one of the matches could be returned. If the value is not found then Result::Err is returned, containing the index where a matching element could be inserted while maintaining sorted order.


Looks up a series of four elements in a slice of pairs sorted by their second elements. The first is found, with a uniquely determined position; the second and third are not found; the fourth could match any position in [1, 4].

let s = [(0, 0), (2, 1), (4, 1), (5, 1), (3, 1),
         (1, 2), (2, 3), (4, 5), (5, 8), (3, 13),
         (1, 21), (2, 34), (4, 55)];

assert_eq!(s.binary_search_by_key(&13, |&(a,b)| b),  Ok(9));
assert_eq!(s.binary_search_by_key(&4, |&(a,b)| b),   Err(7));
assert_eq!(s.binary_search_by_key(&100, |&(a,b)| b), Err(13));
let r = s.binary_search_by_key(&1, |&(a,b)| b);
assert!(match r { Ok(1..=4) => true, _ => false, });

pub unsafe fn align_to<U>(&self) -> (&[T], &[U], &[T])1.30.0[src]

Transmute the slice to a slice of another type, ensuring alignment of the types is maintained.

This method splits the slice into three distinct slices: prefix, correctly aligned middle slice of a new type, and the suffix slice. The method may make the middle slice the greatest length possible for a given type and input slice, but only your algorithm's performance should depend on that, not its correctness. It is permissible for all of the input data to be returned as the prefix or suffix slice.

This method has no purpose when either input element T or output element U are zero-sized and will return the original slice without splitting anything.


This method is essentially a transmute with respect to the elements in the returned middle slice, so all the usual caveats pertaining to transmute::<T, U> also apply here.


Basic usage:

unsafe {
    let bytes: [u8; 7] = [1, 2, 3, 4, 5, 6, 7];
    let (prefix, shorts, suffix) = bytes.align_to::<u16>();
    // less_efficient_algorithm_for_bytes(prefix);
    // more_efficient_algorithm_for_aligned_shorts(shorts);
    // less_efficient_algorithm_for_bytes(suffix);

pub fn is_sorted(&self) -> bool where
    T: PartialOrd<T>, 

🔬 This is a nightly-only experimental API. (is_sorted)

new API

Checks if the elements of this slice are sorted.

That is, for each element a and its following element b, a <= b must hold. If the slice yields exactly zero or one element, true is returned.

Note that if Self::Item is only PartialOrd, but not Ord, the above definition implies that this function returns false if any two consecutive items are not comparable.


let empty: [i32; 0] = [];

assert!([1, 2, 2, 9].is_sorted());
assert!(![1, 3, 2, 4].is_sorted());
assert!(![0.0, 1.0, f32::NAN].is_sorted());

pub fn is_sorted_by<F>(&self, compare: F) -> bool where
    F: FnMut(&T, &T) -> Option<Ordering>, 

🔬 This is a nightly-only experimental API. (is_sorted)

new API

Checks if the elements of this slice are sorted using the given comparator function.

Instead of using PartialOrd::partial_cmp, this function uses the given compare function to determine the ordering of two elements. Apart from that, it's equivalent to is_sorted; see its documentation for more information.

pub fn is_sorted_by_key<F, K>(&self, f: F) -> bool where
    F: FnMut(&T) -> K,
    K: PartialOrd<K>, 

🔬 This is a nightly-only experimental API. (is_sorted)

new API

Checks if the elements of this slice are sorted using the given key extraction function.

Instead of comparing the slice's elements directly, this function compares the keys of the elements, as determined by f. Apart from that, it's equivalent to is_sorted; see its documentation for more information.



assert!(["c", "bb", "aaa"].is_sorted_by_key(|s| s.len()));
assert!(![-2i32, -1, 0, 3].is_sorted_by_key(|n| n.abs()));

pub fn is_ascii(&self) -> bool1.23.0[src]

Checks if all bytes in this slice are within the ASCII range.

pub fn eq_ignore_ascii_case(&self, other: &[u8]) -> bool1.23.0[src]

Checks that two slices are an ASCII case-insensitive match.

Same as to_ascii_lowercase(a) == to_ascii_lowercase(b), but without allocating and copying temporaries.

pub fn to_vec(&self) -> Vec<T> where
    T: Clone

Copies self into a new Vec.


let s = [10, 40, 30];
let x = s.to_vec();
// Here, `s` and `x` can be modified independently.

pub fn repeat(&self, n: usize) -> Vec<T> where
    T: Copy

Creates a vector by repeating a slice n times.


This function will panic if the capacity would overflow.


Basic usage:

assert_eq!([1, 2].repeat(3), vec![1, 2, 1, 2, 1, 2]);

A panic upon overflow:

// this will panic at runtime

pub fn concat<Item>(&self) -> <[T] as Concat<Item>>::Output where
    Item: ?Sized,
    [T]: Concat<Item>, 

Flattens a slice of T into a single value Self::Output.


assert_eq!(["hello", "world"].concat(), "helloworld");
assert_eq!([[1, 2], [3, 4]].concat(), [1, 2, 3, 4]);

pub fn join<Separator>(
    sep: Separator
) -> <[T] as Join<Separator>>::Output where
    [T]: Join<Separator>, 

Flattens a slice of T into a single value Self::Output, placing a given separator between each.


assert_eq!(["hello", "world"].join(" "), "hello world");
assert_eq!([[1, 2], [3, 4]].join(&0), [1, 2, 0, 3, 4]);
assert_eq!([[1, 2], [3, 4]].join(&[0, 0][..]), [1, 2, 0, 0, 3, 4]);

pub fn connect<Separator>(
    sep: Separator
) -> <[T] as Join<Separator>>::Output where
    [T]: Join<Separator>, 

👎 Deprecated since 1.3.0:

renamed to join

Flattens a slice of T into a single value Self::Output, placing a given separator between each.


assert_eq!(["hello", "world"].connect(" "), "hello world");
assert_eq!([[1, 2], [3, 4]].connect(&0), [1, 2, 0, 3, 4]);

pub fn to_ascii_uppercase(&self) -> Vec<u8>1.23.0[src]

Returns a vector containing a copy of this slice where each byte is mapped to its ASCII upper case equivalent.

ASCII letters 'a' to 'z' are mapped to 'A' to 'Z', but non-ASCII letters are unchanged.

To uppercase the value in-place, use make_ascii_uppercase.

pub fn to_ascii_lowercase(&self) -> Vec<u8>1.23.0[src]

Returns a vector containing a copy of this slice where each byte is mapped to its ASCII lower case equivalent.

ASCII letters 'A' to 'Z' are mapped to 'a' to 'z', but non-ASCII letters are unchanged.

To lowercase the value in-place, use make_ascii_lowercase.

Trait Implementations

impl<'out, T> Debug for Out<'out, T> where
    T: 'out + Debug + ?Sized

impl<'out, T> Default for Out<'out, [T]> where
    T: 'out, 

This can be useful to get a Out<'long ...> out of a &'short mut Out<'long ...> by [mem::replace]-ing with a Out::default() (e.g., to implement an Iterator).

impl<'out, T> Deref for Out<'out, [T]> where
    T: 'out, 

Deref into [MaybeUninit<T>] to get access to the slice length related getters.

type Target = [MaybeUninit<T>]

The resulting type after dereferencing.

impl<'out, T> From<&'out mut [ManuallyDrop<T>]> for Out<'out, [T]> where
    T: 'out, 

impl<'out, T> From<&'out mut [MaybeUninit<T>]> for Out<'out, [T]> where
    T: 'out, 

impl<'out, T> From<&'out mut [T]> for Out<'out, [T]> where
    T: 'out + Copy

impl<'out, T> From<&'out mut ManuallyDrop<T>> for Out<'out, T> where
    T: 'out, 

For non-Copy types, explicitely transmuting the mut reference into one that points to a ManuallyDrop is required, so as to express how likely it is that memory be leaked. This can be safely achieved by using the [ManuallyDropMut] helper.

impl<'out, T> From<&'out mut MaybeUninit<T>> for Out<'out, T> where
    T: 'out, 

impl<'out, T> From<&'out mut T> for Out<'out, T> where
    T: 'out + Copy

impl<'out, T> IntoIterator for Out<'out, [T]> where
    T: 'out, 

type Item = Out<'out, T>

The type of the elements being iterated over.

type IntoIter = IterOut<'out, T>

Which kind of iterator are we turning this into?

impl<'out, 'inner, T> IntoIterator for &'out mut Out<'inner, [T]> where
    'inner: 'out,
    T: 'inner, 

type Item = Out<'out, T>

The type of the elements being iterated over.

type IntoIter = IterOut<'out, T>

Which kind of iterator are we turning this into?

impl<'out, T: 'out + Sized + ReprC> ReprC for Out<'out, T>[src]

type CLayout = *mut T::CLayout

The CType having the same layout as Self.

impl<'out, T> Send for Out<'out, T> where
    T: 'out + ?Sized,
    &'out mut T: Send

impl<'out, T> Sync for Out<'out, T> where
    T: 'out + ?Sized,
    &'out mut T: Sync

Auto Trait Implementations

impl<'out, T: ?Sized> RefUnwindSafe for Out<'out, T> where
    T: RefUnwindSafe

impl<'out, T: ?Sized> Unpin for Out<'out, T>

impl<'out, T> !UnwindSafe for Out<'out, T>

Blanket Implementations

impl<T> Any for T where
    T: 'static + ?Sized

impl<T> Borrow<T> for T where
    T: ?Sized

impl<T> BorrowMut<T> for T where
    T: ?Sized

impl<T> From<T> for T[src]

impl<T, U> Into<U> for T where
    U: From<T>, 

impl<I> IntoIterator for I where
    I: Iterator

type Item = <I as Iterator>::Item

The type of the elements being iterated over.

type IntoIter = I

Which kind of iterator are we turning this into?

impl<T> ManuallyDropMut for T

type Ret = ManuallyDrop<T>

impl<T, U> TryFrom<U> for T where
    U: Into<T>, 

type Error = Infallible

The type returned in the event of a conversion error.

impl<T, U> TryInto<U> for T where
    U: TryFrom<T>, 

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.