Skip to main content

alloc/
string.rs

1//! A UTF-8โ€“encoded, growable string.
2//!
3//! This module contains the [`String`] type, the [`ToString`] trait for
4//! converting to strings, and several error types that may result from
5//! working with [`String`]s.
6//!
7//! # Examples
8//!
9//! There are multiple ways to create a new [`String`] from a string literal:
10//!
11//! ```
12//! let s = "Hello".to_string();
13//!
14//! let s = String::from("world");
15//! let s: String = "also this".into();
16//! ```
17//!
18//! You can create a new [`String`] from an existing one by concatenating with
19//! `+`:
20//!
21//! ```
22//! let s = "Hello".to_string();
23//!
24//! let message = s + " world!";
25//! ```
26//!
27//! If you have a vector of valid UTF-8 bytes, you can make a [`String`] out of
28//! it. You can do the reverse too.
29//!
30//! ```
31//! let sparkle_heart = vec![240, 159, 146, 150];
32//!
33//! // We know these bytes are valid, so we'll use `unwrap()`.
34//! let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
35//!
36//! assert_eq!("๐Ÿ’–", sparkle_heart);
37//!
38//! let bytes = sparkle_heart.into_bytes();
39//!
40//! assert_eq!(bytes, [240, 159, 146, 150]);
41//! ```
42
43#![stable(feature = "rust1", since = "1.0.0")]
44
45use core::error::Error;
46use core::iter::FusedIterator;
47#[cfg(not(no_global_oom_handling))]
48use core::iter::from_fn;
49#[cfg(not(no_global_oom_handling))]
50use core::num::Saturating;
51#[cfg(not(no_global_oom_handling))]
52use core::ops::Add;
53#[cfg(not(no_global_oom_handling))]
54use core::ops::AddAssign;
55use core::ops::{self, Range, RangeBounds};
56use core::str::pattern::{Pattern, Utf8Pattern};
57use core::{fmt, hash, ptr, slice};
58
59#[cfg(not(no_global_oom_handling))]
60use crate::alloc::Allocator;
61#[cfg(not(no_global_oom_handling))]
62use crate::borrow::{Cow, ToOwned};
63use crate::boxed::Box;
64use crate::collections::TryReserveError;
65use crate::str::{self, CharIndices, Chars, Utf8Error, from_utf8_unchecked_mut};
66#[cfg(not(no_global_oom_handling))]
67use crate::str::{FromStr, from_boxed_utf8_unchecked};
68use crate::vec::{self, Vec};
69
70/// A UTF-8โ€“encoded, growable string.
71///
72/// `String` is the most common string type. It has ownership over the contents
73/// of the string, stored in a heap-allocated buffer (see [Representation](#representation)).
74/// It is closely related to its borrowed counterpart, the primitive [`str`].
75///
76/// # Examples
77///
78/// You can create a `String` from [a literal string][`&str`] with [`String::from`]:
79///
80/// [`String::from`]: From::from
81///
82/// ```
83/// let hello = String::from("Hello, world!");
84/// ```
85///
86/// You can append a [`char`] to a `String` with the [`push`] method, and
87/// append a [`&str`] with the [`push_str`] method:
88///
89/// ```
90/// let mut hello = String::from("Hello, ");
91///
92/// hello.push('w');
93/// hello.push_str("orld!");
94/// ```
95///
96/// [`push`]: String::push
97/// [`push_str`]: String::push_str
98///
99/// If you have a vector of UTF-8 bytes, you can create a `String` from it with
100/// the [`from_utf8`] method:
101///
102/// ```
103/// // some bytes, in a vector
104/// let sparkle_heart = vec![240, 159, 146, 150];
105///
106/// // We know these bytes are valid, so we'll use `unwrap()`.
107/// let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
108///
109/// assert_eq!("๐Ÿ’–", sparkle_heart);
110/// ```
111///
112/// [`from_utf8`]: String::from_utf8
113///
114/// # UTF-8
115///
116/// `String`s are always valid UTF-8. If you need a non-UTF-8 string, consider
117/// [`OsString`]. It is similar, but without the UTF-8 constraint. Because UTF-8
118/// is a variable width encoding, `String`s are typically smaller than an array of
119/// the same `char`s:
120///
121/// ```
122/// // `s` is ASCII which represents each `char` as one byte
123/// let s = "hello";
124/// assert_eq!(s.len(), 5);
125///
126/// // A `char` array with the same contents would be longer because
127/// // every `char` is four bytes
128/// let s = ['h', 'e', 'l', 'l', 'o'];
129/// let size: usize = s.into_iter().map(|c| size_of_val(&c)).sum();
130/// assert_eq!(size, 20);
131///
132/// // However, for non-ASCII strings, the difference will be smaller
133/// // and sometimes they are the same
134/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
135/// assert_eq!(s.len(), 20);
136///
137/// let s = ['๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–'];
138/// let size: usize = s.into_iter().map(|c| size_of_val(&c)).sum();
139/// assert_eq!(size, 20);
140/// ```
141///
142/// This raises interesting questions as to how `s[i]` should work.
143/// What should `i` be here? Several options include byte indices and
144/// `char` indices but, because of UTF-8 encoding, only byte indices
145/// would provide constant time indexing. Getting the `i`th `char`, for
146/// example, is available using [`chars`]:
147///
148/// ```
149/// let s = "hello";
150/// let third_character = s.chars().nth(2);
151/// assert_eq!(third_character, Some('l'));
152///
153/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
154/// let third_character = s.chars().nth(2);
155/// assert_eq!(third_character, Some('๐Ÿ’–'));
156/// ```
157///
158/// Next, what should `s[i]` return? Because indexing returns a reference
159/// to underlying data it could be `&u8`, `&[u8]`, or something similar.
160/// Since we're only providing one index, `&u8` makes the most sense but that
161/// might not be what the user expects and can be explicitly achieved with
162/// [`as_bytes()`]:
163///
164/// ```
165/// // The first byte is 104 - the byte value of `'h'`
166/// let s = "hello";
167/// assert_eq!(s.as_bytes()[0], 104);
168/// // or
169/// assert_eq!(s.as_bytes()[0], b'h');
170///
171/// // The first byte is 240 which isn't obviously useful
172/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
173/// assert_eq!(s.as_bytes()[0], 240);
174/// ```
175///
176/// Due to these ambiguities/restrictions, indexing with a `usize` is simply
177/// forbidden:
178///
179/// ```compile_fail,E0277
180/// let s = "hello";
181///
182/// // The following will not compile!
183/// println!("The first letter of s is {}", s[0]);
184/// ```
185///
186/// It is more clear, however, how `&s[i..j]` should work (that is,
187/// indexing with a range). It should accept byte indices (to be constant-time)
188/// and return a `&str` which is UTF-8 encoded. This is also called "string slicing".
189/// Note this will panic if the byte indices provided are not character
190/// boundaries - see [`is_char_boundary`] for more details. See the implementations
191/// for [`SliceIndex<str>`] for more details on string slicing. For a non-panicking
192/// version of string slicing, see [`get`].
193///
194/// [`OsString`]: ../../std/ffi/struct.OsString.html "ffi::OsString"
195/// [`SliceIndex<str>`]: core::slice::SliceIndex
196/// [`as_bytes()`]: str::as_bytes
197/// [`get`]: str::get
198/// [`is_char_boundary`]: str::is_char_boundary
199///
200/// The [`bytes`] and [`chars`] methods return iterators over the bytes and
201/// codepoints of the string, respectively. To iterate over codepoints along
202/// with byte indices, use [`char_indices`].
203///
204/// [`bytes`]: str::bytes
205/// [`chars`]: str::chars
206/// [`char_indices`]: str::char_indices
207///
208/// # Deref
209///
210/// `String` implements <code>[Deref]<Target = [str]></code>, and so inherits all of [`str`]'s
211/// methods. In addition, this means that you can pass a `String` to a
212/// function which takes a [`&str`] by using an ampersand (`&`):
213///
214/// ```
215/// fn takes_str(s: &str) { }
216///
217/// let s = String::from("Hello");
218///
219/// takes_str(&s);
220/// ```
221///
222/// This will create a [`&str`] from the `String` and pass it in. This
223/// conversion is very inexpensive, and so generally, functions will accept
224/// [`&str`]s as arguments unless they need a `String` for some specific
225/// reason.
226///
227/// In certain cases Rust doesn't have enough information to make this
228/// conversion, known as [`Deref`] coercion. In the following example a string
229/// slice [`&'a str`][`&str`] implements the trait `TraitExample`, and the function
230/// `example_func` takes anything that implements the trait. In this case Rust
231/// would need to make two implicit conversions, which Rust doesn't have the
232/// means to do. For that reason, the following example will not compile.
233///
234/// ```compile_fail,E0277
235/// trait TraitExample {}
236///
237/// impl<'a> TraitExample for &'a str {}
238///
239/// fn example_func<A: TraitExample>(example_arg: A) {}
240///
241/// let example_string = String::from("example_string");
242/// example_func(&example_string);
243/// ```
244///
245/// There are two options that would work instead. The first would be to
246/// change the line `example_func(&example_string);` to
247/// `example_func(example_string.as_str());`, using the method [`as_str()`]
248/// to explicitly extract the string slice containing the string. The second
249/// way changes `example_func(&example_string);` to
250/// `example_func(&*example_string);`. In this case we are dereferencing a
251/// `String` to a [`str`], then referencing the [`str`] back to
252/// [`&str`]. The second way is more idiomatic, however both work to do the
253/// conversion explicitly rather than relying on the implicit conversion.
254///
255/// # Representation
256///
257/// A `String` is made up of three components: a pointer to some bytes, a
258/// length, and a capacity. The pointer points to the internal buffer which `String`
259/// uses to store its data. The length is the number of bytes currently stored
260/// in the buffer, and the capacity is the size of the buffer in bytes. As such,
261/// the length will always be less than or equal to the capacity.
262///
263/// This buffer is always stored on the heap.
264///
265/// You can look at these with the [`as_ptr`], [`len`], and [`capacity`]
266/// methods:
267///
268/// ```
269/// let story = String::from("Once upon a time...");
270///
271/// // Deconstruct the String into parts.
272/// let (ptr, len, capacity) = story.into_raw_parts();
273///
274/// // story has nineteen bytes
275/// assert_eq!(19, len);
276///
277/// // We can re-build a String out of ptr, len, and capacity. This is all
278/// // unsafe because we are responsible for making sure the components are
279/// // valid:
280/// let s = unsafe { String::from_raw_parts(ptr, len, capacity) } ;
281///
282/// assert_eq!(String::from("Once upon a time..."), s);
283/// ```
284///
285/// [`as_ptr`]: str::as_ptr
286/// [`len`]: String::len
287/// [`capacity`]: String::capacity
288///
289/// If a `String` has enough capacity, adding elements to it will not
290/// re-allocate. For example, consider this program:
291///
292/// ```
293/// let mut s = String::new();
294///
295/// println!("{}", s.capacity());
296///
297/// for _ in 0..5 {
298///     s.push_str("hello");
299///     println!("{}", s.capacity());
300/// }
301/// ```
302///
303/// This will output the following:
304///
305/// ```text
306/// 0
307/// 8
308/// 16
309/// 16
310/// 32
311/// 32
312/// ```
313///
314/// At first, we have no memory allocated at all, but as we append to the
315/// string, it increases its capacity appropriately. If we instead use the
316/// [`with_capacity`] method to allocate the correct capacity initially:
317///
318/// ```
319/// let mut s = String::with_capacity(25);
320///
321/// println!("{}", s.capacity());
322///
323/// for _ in 0..5 {
324///     s.push_str("hello");
325///     println!("{}", s.capacity());
326/// }
327/// ```
328///
329/// [`with_capacity`]: String::with_capacity
330///
331/// We end up with a different output:
332///
333/// ```text
334/// 25
335/// 25
336/// 25
337/// 25
338/// 25
339/// 25
340/// ```
341///
342/// Here, there's no need to allocate more memory inside the loop.
343///
344/// [str]: prim@str "str"
345/// [`str`]: prim@str "str"
346/// [`&str`]: prim@str "&str"
347/// [Deref]: core::ops::Deref "ops::Deref"
348/// [`Deref`]: core::ops::Deref "ops::Deref"
349/// [`as_str()`]: String::as_str
350#[derive(PartialEq, PartialOrd, Eq, Ord)]
351#[stable(feature = "rust1", since = "1.0.0")]
352#[lang = "String"]
353pub struct String {
354    vec: Vec<u8>,
355}
356
357/// A possible error value when converting a `String` from a UTF-8 byte vector.
358///
359/// This type is the error type for the [`from_utf8`] method on [`String`]. It
360/// is designed in such a way to carefully avoid reallocations: the
361/// [`into_bytes`] method will give back the byte vector that was used in the
362/// conversion attempt.
363///
364/// [`from_utf8`]: String::from_utf8
365/// [`into_bytes`]: FromUtf8Error::into_bytes
366///
367/// The [`Utf8Error`] type provided by [`std::str`] represents an error that may
368/// occur when converting a slice of [`u8`]s to a [`&str`]. In this sense, it's
369/// an analogue to `FromUtf8Error`, and you can get one from a `FromUtf8Error`
370/// through the [`utf8_error`] method.
371///
372/// [`Utf8Error`]: str::Utf8Error "std::str::Utf8Error"
373/// [`std::str`]: core::str "std::str"
374/// [`&str`]: prim@str "&str"
375/// [`utf8_error`]: FromUtf8Error::utf8_error
376///
377/// # Examples
378///
379/// ```
380/// // some invalid bytes, in a vector
381/// let bytes = vec![0, 159];
382///
383/// let value = String::from_utf8(bytes);
384///
385/// assert!(value.is_err());
386/// assert_eq!(vec![0, 159], value.unwrap_err().into_bytes());
387/// ```
388#[stable(feature = "rust1", since = "1.0.0")]
389#[cfg_attr(not(no_global_oom_handling), derive(Clone))]
390#[derive(Debug, PartialEq, Eq)]
391pub struct FromUtf8Error {
392    bytes: Vec<u8>,
393    error: Utf8Error,
394}
395
396/// A possible error value when converting a `String` from a UTF-16 byte slice.
397///
398/// This type is the error type for the [`from_utf16`] method on [`String`].
399///
400/// [`from_utf16`]: String::from_utf16
401///
402/// # Examples
403///
404/// ```
405/// // ๐„žmu<invalid>ic
406/// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
407///           0xD800, 0x0069, 0x0063];
408///
409/// assert!(String::from_utf16(v).is_err());
410/// ```
411#[stable(feature = "rust1", since = "1.0.0")]
412#[derive(Debug)]
413pub struct FromUtf16Error {
414    kind: FromUtf16ErrorKind,
415}
416
417#[cfg_attr(no_global_oom_handling, expect(dead_code))]
418#[derive(Clone, PartialEq, Eq, Debug)]
419enum FromUtf16ErrorKind {
420    LoneSurrogate,
421    OddBytes,
422}
423
424impl String {
425    /// Creates a new empty `String`.
426    ///
427    /// Given that the `String` is empty, this will not allocate any initial
428    /// buffer. While that means that this initial operation is very
429    /// inexpensive, it may cause excessive allocation later when you add
430    /// data. If you have an idea of how much data the `String` will hold,
431    /// consider the [`with_capacity`] method to prevent excessive
432    /// re-allocation.
433    ///
434    /// [`with_capacity`]: String::with_capacity
435    ///
436    /// # Examples
437    ///
438    /// ```
439    /// let s = String::new();
440    /// ```
441    #[inline]
442    #[rustc_const_stable(feature = "const_string_new", since = "1.39.0")]
443    #[rustc_diagnostic_item = "string_new"]
444    #[stable(feature = "rust1", since = "1.0.0")]
445    #[must_use]
446    pub const fn new() -> String {
447        String { vec: Vec::new() }
448    }
449
450    /// Creates a new empty `String` with at least the specified capacity.
451    ///
452    /// `String`s have an internal buffer to hold their data. The capacity is
453    /// the length of that buffer, and can be queried with the [`capacity`]
454    /// method. This method creates an empty `String`, but one with an initial
455    /// buffer that can hold at least `capacity` bytes. This is useful when you
456    /// may be appending a bunch of data to the `String`, reducing the number of
457    /// reallocations it needs to do.
458    ///
459    /// [`capacity`]: String::capacity
460    ///
461    /// If the given capacity is `0`, no allocation will occur, and this method
462    /// is identical to the [`new`] method.
463    ///
464    /// [`new`]: String::new
465    ///
466    /// # Panics
467    ///
468    /// Panics if the capacity exceeds `isize::MAX` _bytes_.
469    ///
470    /// # Examples
471    ///
472    /// ```
473    /// let mut s = String::with_capacity(10);
474    ///
475    /// // The String contains no chars, even though it has capacity for more
476    /// assert_eq!(s.len(), 0);
477    ///
478    /// // These are all done without reallocating...
479    /// let cap = s.capacity();
480    /// for _ in 0..10 {
481    ///     s.push('a');
482    /// }
483    ///
484    /// assert_eq!(s.capacity(), cap);
485    ///
486    /// // ...but this may make the string reallocate
487    /// s.push('a');
488    /// ```
489    #[cfg(not(no_global_oom_handling))]
490    #[inline]
491    #[stable(feature = "rust1", since = "1.0.0")]
492    #[must_use]
493    pub fn with_capacity(capacity: usize) -> String {
494        String { vec: Vec::with_capacity(capacity) }
495    }
496
497    /// Creates a new empty `String` with at least the specified capacity.
498    ///
499    /// # Errors
500    ///
501    /// Returns [`Err`] if the capacity exceeds `isize::MAX` bytes,
502    /// or if the memory allocator reports failure.
503    ///
504    #[inline]
505    #[unstable(feature = "try_with_capacity", issue = "91913")]
506    pub fn try_with_capacity(capacity: usize) -> Result<String, TryReserveError> {
507        Ok(String { vec: Vec::try_with_capacity(capacity)? })
508    }
509
510    /// Converts a vector of bytes to a `String`.
511    ///
512    /// A string ([`String`]) is made of bytes ([`u8`]), and a vector of bytes
513    /// ([`Vec<u8>`]) is made of bytes, so this function converts between the
514    /// two. Not all byte slices are valid `String`s, however: `String`
515    /// requires that it is valid UTF-8. `from_utf8()` checks to ensure that
516    /// the bytes are valid UTF-8, and then does the conversion.
517    ///
518    /// If you are sure that the byte slice is valid UTF-8, and you don't want
519    /// to incur the overhead of the validity check, there is an unsafe version
520    /// of this function, [`from_utf8_unchecked`], which has the same behavior
521    /// but skips the check.
522    ///
523    /// This method will take care to not copy the vector, for efficiency's
524    /// sake.
525    ///
526    /// If you need a [`&str`] instead of a `String`, consider
527    /// [`str::from_utf8`].
528    ///
529    /// The inverse of this method is [`into_bytes`].
530    ///
531    /// # Errors
532    ///
533    /// Returns [`Err`] if the slice is not UTF-8 with a description as to why the
534    /// provided bytes are not UTF-8. The vector you moved in is also included.
535    ///
536    /// # Examples
537    ///
538    /// Basic usage:
539    ///
540    /// ```
541    /// // some bytes, in a vector
542    /// let sparkle_heart = vec![240, 159, 146, 150];
543    ///
544    /// // We know these bytes are valid, so we'll use `unwrap()`.
545    /// let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
546    ///
547    /// assert_eq!("๐Ÿ’–", sparkle_heart);
548    /// ```
549    ///
550    /// Incorrect bytes:
551    ///
552    /// ```
553    /// // some invalid bytes, in a vector
554    /// let sparkle_heart = vec![0, 159, 146, 150];
555    ///
556    /// assert!(String::from_utf8(sparkle_heart).is_err());
557    /// ```
558    ///
559    /// See the docs for [`FromUtf8Error`] for more details on what you can do
560    /// with this error.
561    ///
562    /// [`from_utf8_unchecked`]: String::from_utf8_unchecked
563    /// [`Vec<u8>`]: crate::vec::Vec "Vec"
564    /// [`&str`]: prim@str "&str"
565    /// [`into_bytes`]: String::into_bytes
566    #[inline]
567    #[stable(feature = "rust1", since = "1.0.0")]
568    #[rustc_diagnostic_item = "string_from_utf8"]
569    pub fn from_utf8(vec: Vec<u8>) -> Result<String, FromUtf8Error> {
570        match str::from_utf8(&vec) {
571            Ok(..) => Ok(String { vec }),
572            Err(e) => Err(FromUtf8Error { bytes: vec, error: e }),
573        }
574    }
575
576    /// Converts a slice of bytes to a string, including invalid characters.
577    ///
578    /// Strings are made of bytes ([`u8`]), and a slice of bytes
579    /// ([`&[u8]`][byteslice]) is made of bytes, so this function converts
580    /// between the two. Not all byte slices are valid strings, however: strings
581    /// are required to be valid UTF-8. During this conversion,
582    /// `from_utf8_lossy()` will replace any invalid UTF-8 sequences with
583    /// [`U+FFFD REPLACEMENT CHARACTER`][U+FFFD], which looks like this: ๏ฟฝ
584    ///
585    /// [byteslice]: prim@slice
586    /// [U+FFFD]: core::char::REPLACEMENT_CHARACTER
587    ///
588    /// If you are sure that the byte slice is valid UTF-8, and you don't want
589    /// to incur the overhead of the conversion, there is an unsafe version
590    /// of this function, [`from_utf8_unchecked`], which has the same behavior
591    /// but skips the checks.
592    ///
593    /// [`from_utf8_unchecked`]: String::from_utf8_unchecked
594    ///
595    /// This function returns a [`Cow<'a, str>`]. If our byte slice is invalid
596    /// UTF-8, then we need to insert the replacement characters, which will
597    /// change the size of the string, and hence, require a `String`. But if
598    /// it's already valid UTF-8, we don't need a new allocation. This return
599    /// type allows us to handle both cases.
600    ///
601    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
602    ///
603    /// # Examples
604    ///
605    /// Basic usage:
606    ///
607    /// ```
608    /// // some bytes, in a vector
609    /// let sparkle_heart = vec![240, 159, 146, 150];
610    ///
611    /// let sparkle_heart = String::from_utf8_lossy(&sparkle_heart);
612    ///
613    /// assert_eq!("๐Ÿ’–", sparkle_heart);
614    /// ```
615    ///
616    /// Incorrect bytes:
617    ///
618    /// ```
619    /// // some invalid bytes
620    /// let input = b"Hello \xF0\x90\x80World";
621    /// let output = String::from_utf8_lossy(input);
622    ///
623    /// assert_eq!("Hello ๏ฟฝWorld", output);
624    /// ```
625    #[must_use]
626    #[cfg(not(no_global_oom_handling))]
627    #[stable(feature = "rust1", since = "1.0.0")]
628    pub fn from_utf8_lossy(v: &[u8]) -> Cow<'_, str> {
629        let mut iter = v.utf8_chunks();
630
631        let Some(chunk) = iter.next() else {
632            return Cow::Borrowed("");
633        };
634        let first_valid = chunk.valid();
635        if chunk.invalid().is_empty() {
636            debug_assert_eq!(first_valid.len(), v.len());
637            return Cow::Borrowed(first_valid);
638        }
639
640        const REPLACEMENT: &str = "\u{FFFD}";
641
642        let mut res = String::with_capacity(v.len());
643        res.push_str(first_valid);
644        res.push_str(REPLACEMENT);
645
646        for chunk in iter {
647            res.push_str(chunk.valid());
648            if !chunk.invalid().is_empty() {
649                res.push_str(REPLACEMENT);
650            }
651        }
652
653        Cow::Owned(res)
654    }
655
656    /// Converts a [`Vec<u8>`] to a `String`, substituting invalid UTF-8
657    /// sequences with replacement characters.
658    ///
659    /// See [`from_utf8_lossy`] for more details.
660    ///
661    /// [`from_utf8_lossy`]: String::from_utf8_lossy
662    ///
663    /// Note that this function does not guarantee reuse of the original `Vec`
664    /// allocation.
665    ///
666    /// # Examples
667    ///
668    /// Basic usage:
669    ///
670    /// ```
671    /// // some bytes, in a vector
672    /// let sparkle_heart = vec![240, 159, 146, 150];
673    ///
674    /// let sparkle_heart = String::from_utf8_lossy_owned(sparkle_heart);
675    ///
676    /// assert_eq!(String::from("๐Ÿ’–"), sparkle_heart);
677    /// ```
678    ///
679    /// Incorrect bytes:
680    ///
681    /// ```
682    /// // some invalid bytes
683    /// let input: Vec<u8> = b"Hello \xF0\x90\x80World".into();
684    /// let output = String::from_utf8_lossy_owned(input);
685    ///
686    /// assert_eq!(String::from("Hello ๏ฟฝWorld"), output);
687    /// ```
688    #[must_use]
689    #[cfg(not(no_global_oom_handling))]
690    #[stable(feature = "string_from_utf8_lossy_owned", since = "CURRENT_RUSTC_VERSION")]
691    pub fn from_utf8_lossy_owned(v: Vec<u8>) -> String {
692        if let Cow::Owned(string) = String::from_utf8_lossy(&v) {
693            string
694        } else {
695            // SAFETY: `String::from_utf8_lossy`'s contract ensures that if
696            // it returns a `Cow::Borrowed`, it is a valid UTF-8 string.
697            // Otherwise, it returns a new allocation of an owned `String`, with
698            // replacement characters for invalid sequences, which is returned
699            // above.
700            unsafe { String::from_utf8_unchecked(v) }
701        }
702    }
703
704    /// Decode a native endian UTF-16โ€“encoded vector `v` into a `String`,
705    /// returning [`Err`] if `v` contains any invalid data.
706    ///
707    /// # Examples
708    ///
709    /// ```
710    /// // ๐„žmusic
711    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
712    ///           0x0073, 0x0069, 0x0063];
713    /// assert_eq!(String::from("๐„žmusic"),
714    ///            String::from_utf16(v).unwrap());
715    ///
716    /// // ๐„žmu<invalid>ic
717    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
718    ///           0xD800, 0x0069, 0x0063];
719    /// assert!(String::from_utf16(v).is_err());
720    /// ```
721    #[cfg(not(no_global_oom_handling))]
722    #[stable(feature = "rust1", since = "1.0.0")]
723    pub fn from_utf16(v: &[u16]) -> Result<String, FromUtf16Error> {
724        // This isn't done via collect::<Result<_, _>>() for performance reasons.
725        // FIXME: the function can be simplified again when #48994 is closed.
726        let mut ret = String::with_capacity(v.len());
727        for c in char::decode_utf16(v.iter().cloned()) {
728            let Ok(c) = c else {
729                return Err(FromUtf16Error { kind: FromUtf16ErrorKind::LoneSurrogate });
730            };
731            ret.push(c);
732        }
733        Ok(ret)
734    }
735
736    /// Decode a native endian UTF-16โ€“encoded slice `v` into a `String`,
737    /// replacing invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
738    ///
739    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
740    /// `from_utf16_lossy` returns a `String` since the UTF-16 to UTF-8
741    /// conversion requires a memory allocation.
742    ///
743    /// [`from_utf8_lossy`]: String::from_utf8_lossy
744    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
745    /// [U+FFFD]: core::char::REPLACEMENT_CHARACTER
746    ///
747    /// # Examples
748    ///
749    /// ```
750    /// // ๐„žmus<invalid>ic<invalid>
751    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
752    ///           0x0073, 0xDD1E, 0x0069, 0x0063,
753    ///           0xD834];
754    ///
755    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
756    ///            String::from_utf16_lossy(v));
757    /// ```
758    #[cfg(not(no_global_oom_handling))]
759    #[must_use]
760    #[inline]
761    #[stable(feature = "rust1", since = "1.0.0")]
762    pub fn from_utf16_lossy(v: &[u16]) -> String {
763        char::decode_utf16(v.iter().cloned())
764            .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
765            .collect()
766    }
767
768    /// Decode a UTF-16LEโ€“encoded vector `v` into a `String`,
769    /// returning [`Err`] if `v` contains any invalid data.
770    ///
771    /// # Examples
772    ///
773    /// Basic usage:
774    ///
775    /// ```
776    /// // ๐„žmusic
777    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
778    ///           0x73, 0x00, 0x69, 0x00, 0x63, 0x00];
779    /// assert_eq!(String::from("๐„žmusic"),
780    ///            String::from_utf16le(v).unwrap());
781    ///
782    /// // ๐„žmu<invalid>ic
783    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
784    ///           0x00, 0xD8, 0x69, 0x00, 0x63, 0x00];
785    /// assert!(String::from_utf16le(v).is_err());
786    /// ```
787    #[cfg(not(no_global_oom_handling))]
788    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
789    pub fn from_utf16le(v: &[u8]) -> Result<String, FromUtf16Error> {
790        let (chunks, []) = v.as_chunks::<2>() else {
791            return Err(FromUtf16Error { kind: FromUtf16ErrorKind::OddBytes });
792        };
793        match (cfg!(target_endian = "little"), unsafe { v.align_to::<u16>() }) {
794            (true, ([], v, [])) => Self::from_utf16(v),
795            _ => char::decode_utf16(chunks.iter().copied().map(u16::from_le_bytes))
796                .collect::<Result<_, _>>()
797                .map_err(|_| FromUtf16Error { kind: FromUtf16ErrorKind::LoneSurrogate }),
798        }
799    }
800
801    /// Decode a UTF-16LEโ€“encoded slice `v` into a `String`, replacing
802    /// invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
803    ///
804    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
805    /// `from_utf16le_lossy` returns a `String` since the UTF-16 to UTF-8
806    /// conversion requires a memory allocation.
807    ///
808    /// [`from_utf8_lossy`]: String::from_utf8_lossy
809    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
810    /// [U+FFFD]: core::char::REPLACEMENT_CHARACTER
811    ///
812    /// # Examples
813    ///
814    /// Basic usage:
815    ///
816    /// ```
817    /// // ๐„žmus<invalid>ic<invalid>
818    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
819    ///           0x73, 0x00, 0x1E, 0xDD, 0x69, 0x00, 0x63, 0x00,
820    ///           0x34, 0xD8];
821    ///
822    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
823    ///            String::from_utf16le_lossy(v));
824    /// ```
825    #[cfg(not(no_global_oom_handling))]
826    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
827    pub fn from_utf16le_lossy(v: &[u8]) -> String {
828        match (cfg!(target_endian = "little"), unsafe { v.align_to::<u16>() }) {
829            (true, ([], v, [])) => Self::from_utf16_lossy(v),
830            (true, ([], v, [_remainder])) => Self::from_utf16_lossy(v) + "\u{FFFD}",
831            _ => {
832                let (chunks, remainder) = v.as_chunks::<2>();
833                let string = char::decode_utf16(chunks.iter().copied().map(u16::from_le_bytes))
834                    .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
835                    .collect();
836                if remainder.is_empty() { string } else { string + "\u{FFFD}" }
837            }
838        }
839    }
840
841    /// Decode a UTF-16BEโ€“encoded vector `v` into a `String`,
842    /// returning [`Err`] if `v` contains any invalid data.
843    ///
844    /// # Examples
845    ///
846    /// Basic usage:
847    ///
848    /// ```
849    /// // ๐„žmusic
850    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
851    ///           0x00, 0x73, 0x00, 0x69, 0x00, 0x63];
852    /// assert_eq!(String::from("๐„žmusic"),
853    ///            String::from_utf16be(v).unwrap());
854    ///
855    /// // ๐„žmu<invalid>ic
856    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
857    ///           0xD8, 0x00, 0x00, 0x69, 0x00, 0x63];
858    /// assert!(String::from_utf16be(v).is_err());
859    /// ```
860    #[cfg(not(no_global_oom_handling))]
861    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
862    pub fn from_utf16be(v: &[u8]) -> Result<String, FromUtf16Error> {
863        let (chunks, []) = v.as_chunks::<2>() else {
864            return Err(FromUtf16Error { kind: FromUtf16ErrorKind::OddBytes });
865        };
866        match (cfg!(target_endian = "big"), unsafe { v.align_to::<u16>() }) {
867            (true, ([], v, [])) => Self::from_utf16(v),
868            _ => char::decode_utf16(chunks.iter().copied().map(u16::from_be_bytes))
869                .collect::<Result<_, _>>()
870                .map_err(|_| FromUtf16Error { kind: FromUtf16ErrorKind::LoneSurrogate }),
871        }
872    }
873
874    /// Decode a UTF-16BEโ€“encoded slice `v` into a `String`, replacing
875    /// invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
876    ///
877    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
878    /// `from_utf16le_lossy` returns a `String` since the UTF-16 to UTF-8
879    /// conversion requires a memory allocation.
880    ///
881    /// [`from_utf8_lossy`]: String::from_utf8_lossy
882    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
883    /// [U+FFFD]: core::char::REPLACEMENT_CHARACTER
884    ///
885    /// # Examples
886    ///
887    /// Basic usage:
888    ///
889    /// ```
890    /// // ๐„žmus<invalid>ic<invalid>
891    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
892    ///           0x00, 0x73, 0xDD, 0x1E, 0x00, 0x69, 0x00, 0x63,
893    ///           0xD8, 0x34];
894    ///
895    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
896    ///            String::from_utf16be_lossy(v));
897    /// ```
898    #[cfg(not(no_global_oom_handling))]
899    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
900    pub fn from_utf16be_lossy(v: &[u8]) -> String {
901        match (cfg!(target_endian = "big"), unsafe { v.align_to::<u16>() }) {
902            (true, ([], v, [])) => Self::from_utf16_lossy(v),
903            (true, ([], v, [_remainder])) => Self::from_utf16_lossy(v) + "\u{FFFD}",
904            _ => {
905                let (chunks, remainder) = v.as_chunks::<2>();
906                let string = char::decode_utf16(chunks.iter().copied().map(u16::from_be_bytes))
907                    .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
908                    .collect();
909                if remainder.is_empty() { string } else { string + "\u{FFFD}" }
910            }
911        }
912    }
913
914    /// Decomposes a `String` into its raw components: `(pointer, length, capacity)`.
915    ///
916    /// Returns the raw pointer to the underlying data, the length of
917    /// the string (in bytes), and the allocated capacity of the data
918    /// (in bytes). These are the same arguments in the same order as
919    /// the arguments to [`from_raw_parts`].
920    ///
921    /// After calling this function, the caller is responsible for the
922    /// memory previously managed by the `String`. The only way to do
923    /// this is to convert the raw pointer, length, and capacity back
924    /// into a `String` with the [`from_raw_parts`] function, allowing
925    /// the destructor to perform the cleanup.
926    ///
927    /// [`from_raw_parts`]: String::from_raw_parts
928    ///
929    /// # Examples
930    ///
931    /// ```
932    /// let s = String::from("hello");
933    ///
934    /// let (ptr, len, cap) = s.into_raw_parts();
935    ///
936    /// let rebuilt = unsafe { String::from_raw_parts(ptr, len, cap) };
937    /// assert_eq!(rebuilt, "hello");
938    /// ```
939    #[must_use = "losing the pointer will leak memory"]
940    #[stable(feature = "vec_into_raw_parts", since = "1.93.0")]
941    pub fn into_raw_parts(self) -> (*mut u8, usize, usize) {
942        self.vec.into_raw_parts()
943    }
944
945    /// Creates a new `String` from a pointer, a length and a capacity.
946    ///
947    /// # Safety
948    ///
949    /// This is highly unsafe, due to the number of invariants that aren't
950    /// checked:
951    ///
952    /// * all safety requirements for [`Vec::<u8>::from_raw_parts`].
953    /// * all safety requirements for [`String::from_utf8_unchecked`].
954    ///
955    /// Violating these may cause problems like corrupting the allocator's
956    /// internal data structures. For example, it is normally **not** safe to
957    /// build a `String` from a pointer to a C `char` array containing UTF-8
958    /// _unless_ you are certain that array was originally allocated by the
959    /// Rust standard library's allocator.
960    ///
961    /// The ownership of `buf` is effectively transferred to the
962    /// `String` which may then deallocate, reallocate or change the
963    /// contents of memory pointed to by the pointer at will. Ensure
964    /// that nothing else uses the pointer after calling this
965    /// function.
966    ///
967    /// # Examples
968    ///
969    /// ```
970    /// unsafe {
971    ///     let s = String::from("hello");
972    ///
973    ///     // Deconstruct the String into parts.
974    ///     let (ptr, len, capacity) = s.into_raw_parts();
975    ///
976    ///     let s = String::from_raw_parts(ptr, len, capacity);
977    ///
978    ///     assert_eq!(String::from("hello"), s);
979    /// }
980    /// ```
981    #[inline]
982    #[stable(feature = "rust1", since = "1.0.0")]
983    pub unsafe fn from_raw_parts(buf: *mut u8, length: usize, capacity: usize) -> String {
984        unsafe { String { vec: Vec::from_raw_parts(buf, length, capacity) } }
985    }
986
987    /// Converts a vector of bytes to a `String` without checking that the
988    /// string contains valid UTF-8.
989    ///
990    /// See the safe version, [`from_utf8`], for more details.
991    ///
992    /// [`from_utf8`]: String::from_utf8
993    ///
994    /// # Safety
995    ///
996    /// This function is unsafe because it does not check that the bytes passed
997    /// to it are valid UTF-8. If this constraint is violated, it may cause
998    /// memory unsafety issues with future users of the `String`, as the rest of
999    /// the standard library assumes that `String`s are valid UTF-8.
1000    ///
1001    /// # Examples
1002    ///
1003    /// ```
1004    /// // some bytes, in a vector
1005    /// let sparkle_heart = vec![240, 159, 146, 150];
1006    ///
1007    /// let sparkle_heart = unsafe {
1008    ///     String::from_utf8_unchecked(sparkle_heart)
1009    /// };
1010    ///
1011    /// assert_eq!("๐Ÿ’–", sparkle_heart);
1012    /// ```
1013    #[inline]
1014    #[must_use]
1015    #[stable(feature = "rust1", since = "1.0.0")]
1016    pub unsafe fn from_utf8_unchecked(bytes: Vec<u8>) -> String {
1017        String { vec: bytes }
1018    }
1019
1020    /// Converts a `String` into a byte vector.
1021    ///
1022    /// This consumes the `String`, so we do not need to copy its contents.
1023    ///
1024    /// # Examples
1025    ///
1026    /// ```
1027    /// let s = String::from("hello");
1028    /// let bytes = s.into_bytes();
1029    ///
1030    /// assert_eq!(&[104, 101, 108, 108, 111][..], &bytes[..]);
1031    /// ```
1032    #[inline]
1033    #[must_use = "`self` will be dropped if the result is not used"]
1034    #[stable(feature = "rust1", since = "1.0.0")]
1035    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1036    #[rustc_allow_const_fn_unstable(const_precise_live_drops)]
1037    pub const fn into_bytes(self) -> Vec<u8> {
1038        self.vec
1039    }
1040
1041    /// Extracts a string slice containing the entire `String`.
1042    ///
1043    /// # Examples
1044    ///
1045    /// ```
1046    /// let s = String::from("foo");
1047    ///
1048    /// assert_eq!("foo", s.as_str());
1049    /// ```
1050    #[inline]
1051    #[must_use]
1052    #[stable(feature = "string_as_str", since = "1.7.0")]
1053    #[rustc_diagnostic_item = "string_as_str"]
1054    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1055    pub const fn as_str(&self) -> &str {
1056        // SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1057        // at construction.
1058        unsafe { str::from_utf8_unchecked(self.vec.as_slice()) }
1059    }
1060
1061    /// Converts a `String` into a mutable string slice.
1062    ///
1063    /// # Examples
1064    ///
1065    /// ```
1066    /// let mut s = String::from("foobar");
1067    /// let s_mut_str = s.as_mut_str();
1068    ///
1069    /// s_mut_str.make_ascii_uppercase();
1070    ///
1071    /// assert_eq!("FOOBAR", s_mut_str);
1072    /// ```
1073    #[inline]
1074    #[must_use]
1075    #[stable(feature = "string_as_str", since = "1.7.0")]
1076    #[rustc_diagnostic_item = "string_as_mut_str"]
1077    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1078    pub const fn as_mut_str(&mut self) -> &mut str {
1079        // SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1080        // at construction.
1081        unsafe { str::from_utf8_unchecked_mut(self.vec.as_mut_slice()) }
1082    }
1083
1084    /// Appends a given string slice onto the end of this `String`.
1085    ///
1086    /// # Panics
1087    ///
1088    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1089    ///
1090    /// # Examples
1091    ///
1092    /// ```
1093    /// let mut s = String::from("foo");
1094    ///
1095    /// s.push_str("bar");
1096    ///
1097    /// assert_eq!("foobar", s);
1098    /// ```
1099    #[cfg(not(no_global_oom_handling))]
1100    #[inline]
1101    #[stable(feature = "rust1", since = "1.0.0")]
1102    #[rustc_confusables("append", "push")]
1103    #[rustc_diagnostic_item = "string_push_str"]
1104    pub fn push_str(&mut self, string: &str) {
1105        self.vec.extend_from_slice(string.as_bytes())
1106    }
1107
1108    /// Appends a given string slice onto the end of this `String`, returning
1109    /// [`TryReserveError`] otherwise.
1110    #[cfg_attr(
1111        not(no_global_oom_handling),
1112        expect(
1113            dead_code,
1114            reason = "currently only used in IO module when global OOM handling is disabled"
1115        )
1116    )]
1117    pub(crate) fn try_push_str(&mut self, string: &str) -> Result<(), TryReserveError> {
1118        self.vec.try_extend_from_slice_of_bytes(string.as_bytes())
1119    }
1120
1121    #[cfg(not(no_global_oom_handling))]
1122    #[inline]
1123    fn push_str_slice(&mut self, slice: &[&str]) {
1124        // use saturating arithmetic to ensure that in the case of an overflow, reserve() throws OOM
1125        let additional: Saturating<usize> = slice.iter().map(|x| Saturating(x.len())).sum();
1126        self.reserve(additional.0);
1127        let (ptr, len, cap) = core::mem::take(self).into_raw_parts();
1128        unsafe {
1129            let mut dst = ptr.add(len);
1130            for new in slice {
1131                core::ptr::copy_nonoverlapping(new.as_ptr(), dst, new.len());
1132                dst = dst.add(new.len());
1133            }
1134            *self = String::from_raw_parts(ptr, len + additional.0, cap);
1135        }
1136    }
1137
1138    /// Copies elements from `src` range to the end of the string.
1139    ///
1140    /// # Panics
1141    ///
1142    /// Panics if the range has `start_bound > end_bound`, if the range is
1143    /// bounded on either end and does not lie on a [`char`] boundary, or if the
1144    /// new capacity exceeds `isize::MAX` bytes.
1145    ///
1146    /// # Examples
1147    ///
1148    /// ```
1149    /// let mut string = String::from("abcde");
1150    ///
1151    /// string.extend_from_within(2..);
1152    /// assert_eq!(string, "abcdecde");
1153    ///
1154    /// string.extend_from_within(..2);
1155    /// assert_eq!(string, "abcdecdeab");
1156    ///
1157    /// string.extend_from_within(4..8);
1158    /// assert_eq!(string, "abcdecdeabecde");
1159    /// ```
1160    #[cfg(not(no_global_oom_handling))]
1161    #[stable(feature = "string_extend_from_within", since = "1.87.0")]
1162    #[track_caller]
1163    pub fn extend_from_within<R>(&mut self, src: R)
1164    where
1165        R: RangeBounds<usize>,
1166    {
1167        let src @ Range { start, end } = slice::range(src, ..self.len());
1168
1169        assert!(self.is_char_boundary(start));
1170        assert!(self.is_char_boundary(end));
1171
1172        self.vec.extend_from_within(src);
1173    }
1174
1175    /// Returns this `String`'s capacity, in bytes.
1176    ///
1177    /// # Examples
1178    ///
1179    /// ```
1180    /// let s = String::with_capacity(10);
1181    ///
1182    /// assert!(s.capacity() >= 10);
1183    /// ```
1184    #[inline]
1185    #[must_use]
1186    #[stable(feature = "rust1", since = "1.0.0")]
1187    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1188    pub const fn capacity(&self) -> usize {
1189        self.vec.capacity()
1190    }
1191
1192    /// Reserves capacity for at least `additional` bytes more than the
1193    /// current length. The allocator may reserve more space to speculatively
1194    /// avoid frequent allocations. After calling `reserve`,
1195    /// capacity will be greater than or equal to `self.len() + additional`.
1196    /// Does nothing if capacity is already sufficient.
1197    ///
1198    /// # Panics
1199    ///
1200    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1201    ///
1202    /// # Examples
1203    ///
1204    /// Basic usage:
1205    ///
1206    /// ```
1207    /// let mut s = String::new();
1208    ///
1209    /// s.reserve(10);
1210    ///
1211    /// assert!(s.capacity() >= 10);
1212    /// ```
1213    ///
1214    /// This might not actually increase the capacity:
1215    ///
1216    /// ```
1217    /// let mut s = String::with_capacity(10);
1218    /// s.push('a');
1219    /// s.push('b');
1220    ///
1221    /// // s now has a length of 2 and a capacity of at least 10
1222    /// let capacity = s.capacity();
1223    /// assert_eq!(2, s.len());
1224    /// assert!(capacity >= 10);
1225    ///
1226    /// // Since we already have at least an extra 8 capacity, calling this...
1227    /// s.reserve(8);
1228    ///
1229    /// // ... doesn't actually increase.
1230    /// assert_eq!(capacity, s.capacity());
1231    /// ```
1232    #[cfg(not(no_global_oom_handling))]
1233    #[inline]
1234    #[stable(feature = "rust1", since = "1.0.0")]
1235    pub fn reserve(&mut self, additional: usize) {
1236        self.vec.reserve(additional)
1237    }
1238
1239    /// Reserves the minimum capacity for at least `additional` bytes more than
1240    /// the current length. Unlike [`reserve`], this will not
1241    /// deliberately over-allocate to speculatively avoid frequent allocations.
1242    /// After calling `reserve_exact`, capacity will be greater than or equal to
1243    /// `self.len() + additional`. Does nothing if the capacity is already
1244    /// sufficient.
1245    ///
1246    /// [`reserve`]: String::reserve
1247    ///
1248    /// # Panics
1249    ///
1250    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1251    ///
1252    /// # Examples
1253    ///
1254    /// Basic usage:
1255    ///
1256    /// ```
1257    /// let mut s = String::new();
1258    ///
1259    /// s.reserve_exact(10);
1260    ///
1261    /// assert!(s.capacity() >= 10);
1262    /// ```
1263    ///
1264    /// This might not actually increase the capacity:
1265    ///
1266    /// ```
1267    /// let mut s = String::with_capacity(10);
1268    /// s.push('a');
1269    /// s.push('b');
1270    ///
1271    /// // s now has a length of 2 and a capacity of at least 10
1272    /// let capacity = s.capacity();
1273    /// assert_eq!(2, s.len());
1274    /// assert!(capacity >= 10);
1275    ///
1276    /// // Since we already have at least an extra 8 capacity, calling this...
1277    /// s.reserve_exact(8);
1278    ///
1279    /// // ... doesn't actually increase.
1280    /// assert_eq!(capacity, s.capacity());
1281    /// ```
1282    #[cfg(not(no_global_oom_handling))]
1283    #[inline]
1284    #[stable(feature = "rust1", since = "1.0.0")]
1285    pub fn reserve_exact(&mut self, additional: usize) {
1286        self.vec.reserve_exact(additional)
1287    }
1288
1289    /// Tries to reserve capacity for at least `additional` bytes more than the
1290    /// current length. The allocator may reserve more space to speculatively
1291    /// avoid frequent allocations. After calling `try_reserve`, capacity will be
1292    /// greater than or equal to `self.len() + additional` if it returns
1293    /// `Ok(())`. Does nothing if capacity is already sufficient. This method
1294    /// preserves the contents even if an error occurs.
1295    ///
1296    /// # Errors
1297    ///
1298    /// If the capacity overflows, or the allocator reports a failure, then an error
1299    /// is returned.
1300    ///
1301    /// # Examples
1302    ///
1303    /// ```
1304    /// use std::collections::TryReserveError;
1305    ///
1306    /// fn process_data(data: &str) -> Result<String, TryReserveError> {
1307    ///     let mut output = String::new();
1308    ///
1309    ///     // Pre-reserve the memory, exiting if we can't
1310    ///     output.try_reserve(data.len())?;
1311    ///
1312    ///     // Now we know this can't OOM in the middle of our complex work
1313    ///     output.push_str(data);
1314    ///
1315    ///     Ok(output)
1316    /// }
1317    /// # process_data("rust").expect("why is the test harness OOMing on 4 bytes?");
1318    /// ```
1319    #[stable(feature = "try_reserve", since = "1.57.0")]
1320    pub fn try_reserve(&mut self, additional: usize) -> Result<(), TryReserveError> {
1321        self.vec.try_reserve(additional)
1322    }
1323
1324    /// Tries to reserve the minimum capacity for at least `additional` bytes
1325    /// more than the current length. Unlike [`try_reserve`], this will not
1326    /// deliberately over-allocate to speculatively avoid frequent allocations.
1327    /// After calling `try_reserve_exact`, capacity will be greater than or
1328    /// equal to `self.len() + additional` if it returns `Ok(())`.
1329    /// Does nothing if the capacity is already sufficient.
1330    ///
1331    /// Note that the allocator may give the collection more space than it
1332    /// requests. Therefore, capacity can not be relied upon to be precisely
1333    /// minimal. Prefer [`try_reserve`] if future insertions are expected.
1334    ///
1335    /// [`try_reserve`]: String::try_reserve
1336    ///
1337    /// # Errors
1338    ///
1339    /// If the capacity overflows, or the allocator reports a failure, then an error
1340    /// is returned.
1341    ///
1342    /// # Examples
1343    ///
1344    /// ```
1345    /// use std::collections::TryReserveError;
1346    ///
1347    /// fn process_data(data: &str) -> Result<String, TryReserveError> {
1348    ///     let mut output = String::new();
1349    ///
1350    ///     // Pre-reserve the memory, exiting if we can't
1351    ///     output.try_reserve_exact(data.len())?;
1352    ///
1353    ///     // Now we know this can't OOM in the middle of our complex work
1354    ///     output.push_str(data);
1355    ///
1356    ///     Ok(output)
1357    /// }
1358    /// # process_data("rust").expect("why is the test harness OOMing on 4 bytes?");
1359    /// ```
1360    #[stable(feature = "try_reserve", since = "1.57.0")]
1361    pub fn try_reserve_exact(&mut self, additional: usize) -> Result<(), TryReserveError> {
1362        self.vec.try_reserve_exact(additional)
1363    }
1364
1365    /// Shrinks the capacity of this `String` to match its length.
1366    ///
1367    /// # Examples
1368    ///
1369    /// ```
1370    /// let mut s = String::from("foo");
1371    ///
1372    /// s.reserve(100);
1373    /// assert!(s.capacity() >= 100);
1374    ///
1375    /// s.shrink_to_fit();
1376    /// assert_eq!(3, s.capacity());
1377    /// ```
1378    #[cfg(not(no_global_oom_handling))]
1379    #[inline]
1380    #[stable(feature = "rust1", since = "1.0.0")]
1381    pub fn shrink_to_fit(&mut self) {
1382        self.vec.shrink_to_fit()
1383    }
1384
1385    /// Shrinks the capacity of this `String` with a lower bound.
1386    ///
1387    /// The capacity will remain at least as large as both the length
1388    /// and the supplied value.
1389    ///
1390    /// If the current capacity is less than the lower limit, this is a no-op.
1391    ///
1392    /// # Examples
1393    ///
1394    /// ```
1395    /// let mut s = String::from("foo");
1396    ///
1397    /// s.reserve(100);
1398    /// assert!(s.capacity() >= 100);
1399    ///
1400    /// s.shrink_to(10);
1401    /// assert!(s.capacity() >= 10);
1402    /// s.shrink_to(0);
1403    /// assert!(s.capacity() >= 3);
1404    /// ```
1405    #[cfg(not(no_global_oom_handling))]
1406    #[inline]
1407    #[stable(feature = "shrink_to", since = "1.56.0")]
1408    pub fn shrink_to(&mut self, min_capacity: usize) {
1409        self.vec.shrink_to(min_capacity)
1410    }
1411
1412    /// Appends the given [`char`] to the end of this `String`.
1413    ///
1414    /// # Panics
1415    ///
1416    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1417    ///
1418    /// # Examples
1419    ///
1420    /// ```
1421    /// let mut s = String::from("abc");
1422    ///
1423    /// s.push('1');
1424    /// s.push('2');
1425    /// s.push('3');
1426    ///
1427    /// assert_eq!("abc123", s);
1428    /// ```
1429    #[cfg(not(no_global_oom_handling))]
1430    #[inline]
1431    #[stable(feature = "rust1", since = "1.0.0")]
1432    pub fn push(&mut self, ch: char) {
1433        let len = self.len();
1434        let ch_len = ch.len_utf8();
1435        self.reserve(ch_len);
1436
1437        // SAFETY: Just reserved capacity for at least the length needed to encode `ch`.
1438        unsafe {
1439            core::char::encode_utf8_raw_unchecked(ch as u32, self.vec.as_mut_ptr().add(len));
1440            self.vec.set_len(len + ch_len);
1441        }
1442    }
1443
1444    /// Returns a byte slice of this `String`'s contents.
1445    ///
1446    /// The inverse of this method is [`from_utf8`].
1447    ///
1448    /// [`from_utf8`]: String::from_utf8
1449    ///
1450    /// # Examples
1451    ///
1452    /// ```
1453    /// let s = String::from("hello");
1454    ///
1455    /// assert_eq!(&[104, 101, 108, 108, 111], s.as_bytes());
1456    /// ```
1457    #[inline]
1458    #[must_use]
1459    #[stable(feature = "rust1", since = "1.0.0")]
1460    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1461    pub const fn as_bytes(&self) -> &[u8] {
1462        self.vec.as_slice()
1463    }
1464
1465    /// Shortens this `String` to the specified length.
1466    ///
1467    /// If `new_len` is greater than or equal to the string's current length, this has no
1468    /// effect.
1469    ///
1470    /// Note that this method has no effect on the allocated capacity
1471    /// of the string
1472    ///
1473    /// # Panics
1474    ///
1475    /// Panics if `new_len` does not lie on a [`char`] boundary.
1476    ///
1477    /// # Examples
1478    ///
1479    /// ```
1480    /// let mut s = String::from("hello");
1481    ///
1482    /// s.truncate(2);
1483    ///
1484    /// assert_eq!("he", s);
1485    /// ```
1486    #[inline]
1487    #[stable(feature = "rust1", since = "1.0.0")]
1488    #[track_caller]
1489    pub fn truncate(&mut self, new_len: usize) {
1490        if new_len <= self.len() {
1491            assert!(self.is_char_boundary(new_len));
1492            self.vec.truncate(new_len)
1493        }
1494    }
1495
1496    /// Removes the last character from the string buffer and returns it.
1497    ///
1498    /// Returns [`None`] if this `String` is empty.
1499    ///
1500    /// # Examples
1501    ///
1502    /// ```
1503    /// let mut s = String::from("abฤ");
1504    ///
1505    /// assert_eq!(s.pop(), Some('ฤ'));
1506    /// assert_eq!(s.pop(), Some('b'));
1507    /// assert_eq!(s.pop(), Some('a'));
1508    ///
1509    /// assert_eq!(s.pop(), None);
1510    /// ```
1511    #[inline]
1512    #[stable(feature = "rust1", since = "1.0.0")]
1513    pub fn pop(&mut self) -> Option<char> {
1514        let ch = self.chars().rev().next()?;
1515        let newlen = self.len() - ch.len_utf8();
1516        unsafe {
1517            self.vec.set_len(newlen);
1518        }
1519        Some(ch)
1520    }
1521
1522    /// Removes a [`char`] from this `String` at byte position `idx` and returns it.
1523    ///
1524    /// Copies all bytes after the removed char to new positions.
1525    ///
1526    /// Note that calling this in a loop can result in quadratic behavior.
1527    ///
1528    /// # Panics
1529    ///
1530    /// Panics if `idx` is larger than or equal to the `String`'s length,
1531    /// or if it does not lie on a [`char`] boundary.
1532    ///
1533    /// # Examples
1534    ///
1535    /// ```
1536    /// let mut s = String::from("abรง");
1537    ///
1538    /// assert_eq!(s.remove(0), 'a');
1539    /// assert_eq!(s.remove(1), 'รง');
1540    /// assert_eq!(s.remove(0), 'b');
1541    /// ```
1542    #[inline]
1543    #[stable(feature = "rust1", since = "1.0.0")]
1544    #[track_caller]
1545    #[rustc_confusables("delete", "take")]
1546    pub fn remove(&mut self, idx: usize) -> char {
1547        let ch = match self[idx..].chars().next() {
1548            Some(ch) => ch,
1549            None => panic!("cannot remove a char from the end of a string"),
1550        };
1551
1552        let next = idx + ch.len_utf8();
1553        let len = self.len();
1554        unsafe {
1555            ptr::copy(self.vec.as_ptr().add(next), self.vec.as_mut_ptr().add(idx), len - next);
1556            self.vec.set_len(len - (next - idx));
1557        }
1558        ch
1559    }
1560
1561    /// Remove all matches of pattern `pat` in the `String`.
1562    ///
1563    /// # Examples
1564    ///
1565    /// ```
1566    /// #![feature(string_remove_matches)]
1567    /// let mut s = String::from("Trees are not green, the sky is not blue.");
1568    /// s.remove_matches("not ");
1569    /// assert_eq!("Trees are green, the sky is blue.", s);
1570    /// ```
1571    ///
1572    /// Matches will be detected and removed iteratively, so in cases where
1573    /// patterns overlap, only the first pattern will be removed:
1574    ///
1575    /// ```
1576    /// #![feature(string_remove_matches)]
1577    /// let mut s = String::from("banana");
1578    /// s.remove_matches("ana");
1579    /// assert_eq!("bna", s);
1580    /// ```
1581    #[cfg(not(no_global_oom_handling))]
1582    #[unstable(feature = "string_remove_matches", issue = "72826")]
1583    pub fn remove_matches<P: Pattern>(&mut self, pat: P) {
1584        use core::str::pattern::Searcher;
1585
1586        let rejections = {
1587            let mut searcher = pat.into_searcher(self);
1588            // Per Searcher::next:
1589            //
1590            // A Match result needs to contain the whole matched pattern,
1591            // however Reject results may be split up into arbitrary many
1592            // adjacent fragments. Both ranges may have zero length.
1593            //
1594            // In practice the implementation of Searcher::next_match tends to
1595            // be more efficient, so we use it here and do some work to invert
1596            // matches into rejections since that's what we want to copy below.
1597            let mut front = 0;
1598            let rejections: Vec<_> = from_fn(|| {
1599                let (start, end) = searcher.next_match()?;
1600                let prev_front = front;
1601                front = end;
1602                Some((prev_front, start))
1603            })
1604            .collect();
1605            rejections.into_iter().chain(core::iter::once((front, self.len())))
1606        };
1607
1608        let mut len = 0;
1609        let ptr = self.vec.as_mut_ptr();
1610
1611        for (start, end) in rejections {
1612            let count = end - start;
1613            if start != len {
1614                // SAFETY: per Searcher::next:
1615                //
1616                // The stream of Match and Reject values up to a Done will
1617                // contain index ranges that are adjacent, non-overlapping,
1618                // covering the whole haystack, and laying on utf8
1619                // boundaries.
1620                unsafe {
1621                    ptr::copy(ptr.add(start), ptr.add(len), count);
1622                }
1623            }
1624            len += count;
1625        }
1626
1627        unsafe {
1628            self.vec.set_len(len);
1629        }
1630    }
1631
1632    /// Retains only the characters specified by the predicate.
1633    ///
1634    /// In other words, remove all characters `c` such that `f(c)` returns `false`.
1635    /// This method operates in place, visiting each character exactly once in the
1636    /// original order, and preserves the order of the retained characters.
1637    ///
1638    /// # Examples
1639    ///
1640    /// ```
1641    /// let mut s = String::from("f_o_ob_ar");
1642    ///
1643    /// s.retain(|c| c != '_');
1644    ///
1645    /// assert_eq!(s, "foobar");
1646    /// ```
1647    ///
1648    /// Because the elements are visited exactly once in the original order,
1649    /// external state may be used to decide which elements to keep.
1650    ///
1651    /// ```
1652    /// let mut s = String::from("abcde");
1653    /// let keep = [false, true, true, false, true];
1654    /// let mut iter = keep.iter();
1655    /// s.retain(|_| *iter.next().unwrap());
1656    /// assert_eq!(s, "bce");
1657    /// ```
1658    #[inline]
1659    #[stable(feature = "string_retain", since = "1.26.0")]
1660    pub fn retain<F>(&mut self, mut f: F)
1661    where
1662        F: FnMut(char) -> bool,
1663    {
1664        struct SetLenOnDrop<'a> {
1665            s: &'a mut String,
1666            idx: usize,
1667            del_bytes: usize,
1668        }
1669
1670        impl<'a> Drop for SetLenOnDrop<'a> {
1671            fn drop(&mut self) {
1672                let new_len = self.idx - self.del_bytes;
1673                debug_assert!(new_len <= self.s.len());
1674                unsafe { self.s.vec.set_len(new_len) };
1675            }
1676        }
1677
1678        let len = self.len();
1679        let mut guard = SetLenOnDrop { s: self, idx: 0, del_bytes: 0 };
1680
1681        while guard.idx < len {
1682            let ch =
1683                // SAFETY: `guard.idx` is positive-or-zero and less that len so the `get_unchecked`
1684                // is in bound. `self` is valid UTF-8 like string and the returned slice starts at
1685                // a unicode code point so the `Chars` always return one character.
1686                unsafe { guard.s.get_unchecked(guard.idx..len).chars().next().unwrap_unchecked() };
1687            let ch_len = ch.len_utf8();
1688
1689            if !f(ch) {
1690                guard.del_bytes += ch_len;
1691            } else if guard.del_bytes > 0 {
1692                // SAFETY: `guard.idx` is in bound and `guard.del_bytes` represent the number of
1693                // bytes that are erased from the string so the resulting `guard.idx -
1694                // guard.del_bytes` always represent a valid unicode code point.
1695                //
1696                // `guard.del_bytes` >= `ch.len_utf8()`, so taking a slice with `ch.len_utf8()` len
1697                // is safe.
1698                ch.encode_utf8(unsafe {
1699                    crate::slice::from_raw_parts_mut(
1700                        guard.s.as_mut_ptr().add(guard.idx - guard.del_bytes),
1701                        ch.len_utf8(),
1702                    )
1703                });
1704            }
1705
1706            // Point idx to the next char
1707            guard.idx += ch_len;
1708        }
1709
1710        drop(guard);
1711    }
1712
1713    /// Inserts a character into this `String` at byte position `idx`.
1714    ///
1715    /// Reallocates if `self.capacity()` is insufficient, which may involve copying all
1716    /// `self.capacity()` bytes. Makes space for the insertion by copying all bytes of
1717    /// `&self[idx..]` to new positions.
1718    ///
1719    /// Note that calling this in a loop can result in quadratic behavior.
1720    ///
1721    /// # Panics
1722    ///
1723    /// Panics if `idx` is larger than the `String`'s length, or if it does not
1724    /// lie on a [`char`] boundary.
1725    ///
1726    /// # Examples
1727    ///
1728    /// ```
1729    /// let mut s = String::with_capacity(3);
1730    ///
1731    /// s.insert(0, 'f');
1732    /// s.insert(1, 'o');
1733    /// s.insert(2, 'o');
1734    ///
1735    /// assert_eq!("foo", s);
1736    /// ```
1737    #[cfg(not(no_global_oom_handling))]
1738    #[inline]
1739    #[track_caller]
1740    #[stable(feature = "rust1", since = "1.0.0")]
1741    #[rustc_confusables("set")]
1742    pub fn insert(&mut self, idx: usize, ch: char) {
1743        assert!(self.is_char_boundary(idx));
1744
1745        let len = self.len();
1746        let ch_len = ch.len_utf8();
1747        self.reserve(ch_len);
1748
1749        // SAFETY: Move the bytes starting from `idx` to their new location `ch_len`
1750        // bytes ahead. This is safe because sufficient capacity was reserved, and `idx`
1751        // is a char boundary.
1752        unsafe {
1753            ptr::copy(
1754                self.vec.as_ptr().add(idx),
1755                self.vec.as_mut_ptr().add(idx + ch_len),
1756                len - idx,
1757            );
1758        }
1759
1760        // SAFETY: Encode the character into the vacated region if `idx != len`,
1761        // or into the uninitialized spare capacity otherwise.
1762        unsafe {
1763            core::char::encode_utf8_raw_unchecked(ch as u32, self.vec.as_mut_ptr().add(idx));
1764        }
1765
1766        // SAFETY: Update the length to include the newly added bytes.
1767        unsafe {
1768            self.vec.set_len(len + ch_len);
1769        }
1770    }
1771
1772    /// Inserts a string slice into this `String` at byte position `idx`.
1773    ///
1774    /// Reallocates if `self.capacity()` is insufficient, which may involve copying all
1775    /// `self.capacity()` bytes. Makes space for the insertion by copying all bytes of
1776    /// `&self[idx..]` to new positions.
1777    ///
1778    /// Note that calling this in a loop can result in quadratic behavior.
1779    ///
1780    /// # Panics
1781    ///
1782    /// Panics if `idx` is larger than the `String`'s length, or if it does not
1783    /// lie on a [`char`] boundary.
1784    ///
1785    /// # Examples
1786    ///
1787    /// ```
1788    /// let mut s = String::from("bar");
1789    ///
1790    /// s.insert_str(0, "foo");
1791    ///
1792    /// assert_eq!("foobar", s);
1793    /// ```
1794    #[cfg(not(no_global_oom_handling))]
1795    #[inline]
1796    #[track_caller]
1797    #[stable(feature = "insert_str", since = "1.16.0")]
1798    #[rustc_diagnostic_item = "string_insert_str"]
1799    pub fn insert_str(&mut self, idx: usize, string: &str) {
1800        assert!(self.is_char_boundary(idx));
1801
1802        let len = self.len();
1803        let amt = string.len();
1804        self.reserve(amt);
1805
1806        // SAFETY: Move the bytes starting from `idx` to their new location `amt` bytes
1807        // ahead. This is safe because sufficient capacity was just reserved, and `idx`
1808        // is a char boundary.
1809        unsafe {
1810            ptr::copy(self.vec.as_ptr().add(idx), self.vec.as_mut_ptr().add(idx + amt), len - idx);
1811        }
1812
1813        // SAFETY: Copy the new string slice into the vacated region if `idx != len`,
1814        // or into the uninitialized spare capacity otherwise. The borrow checker
1815        // ensures that the source and destination do not overlap.
1816        unsafe {
1817            ptr::copy_nonoverlapping(string.as_ptr(), self.vec.as_mut_ptr().add(idx), amt);
1818        }
1819
1820        // SAFETY: Update the length to include the newly added bytes.
1821        unsafe {
1822            self.vec.set_len(len + amt);
1823        }
1824    }
1825
1826    /// Returns a mutable reference to the contents of this `String`.
1827    ///
1828    /// # Safety
1829    ///
1830    /// This function is unsafe because the returned `&mut Vec` allows writing
1831    /// bytes which are not valid UTF-8. If this constraint is violated, using
1832    /// the original `String` after dropping the `&mut Vec` may violate memory
1833    /// safety, as the rest of the standard library assumes that `String`s are
1834    /// valid UTF-8.
1835    ///
1836    /// # Examples
1837    ///
1838    /// ```
1839    /// let mut s = String::from("hello");
1840    ///
1841    /// unsafe {
1842    ///     let vec = s.as_mut_vec();
1843    ///     assert_eq!(&[104, 101, 108, 108, 111][..], &vec[..]);
1844    ///
1845    ///     vec.reverse();
1846    /// }
1847    /// assert_eq!(s, "olleh");
1848    /// ```
1849    #[inline]
1850    #[stable(feature = "rust1", since = "1.0.0")]
1851    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1852    pub const unsafe fn as_mut_vec(&mut self) -> &mut Vec<u8> {
1853        &mut self.vec
1854    }
1855
1856    /// Returns the length of this `String`, in bytes, not [`char`]s or
1857    /// graphemes. In other words, it might not be what a human considers the
1858    /// length of the string.
1859    ///
1860    /// # Examples
1861    ///
1862    /// ```
1863    /// let a = String::from("foo");
1864    /// assert_eq!(a.len(), 3);
1865    ///
1866    /// let fancy_f = String::from("ฦ’oo");
1867    /// assert_eq!(fancy_f.len(), 4);
1868    /// assert_eq!(fancy_f.chars().count(), 3);
1869    /// ```
1870    #[inline]
1871    #[must_use]
1872    #[stable(feature = "rust1", since = "1.0.0")]
1873    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1874    #[rustc_confusables("length", "size")]
1875    #[rustc_no_implicit_autorefs]
1876    pub const fn len(&self) -> usize {
1877        self.vec.len()
1878    }
1879
1880    /// Returns `true` if this `String` has a length of zero, and `false` otherwise.
1881    ///
1882    /// # Examples
1883    ///
1884    /// ```
1885    /// let mut v = String::new();
1886    /// assert!(v.is_empty());
1887    ///
1888    /// v.push('a');
1889    /// assert!(!v.is_empty());
1890    /// ```
1891    #[inline]
1892    #[must_use]
1893    #[stable(feature = "rust1", since = "1.0.0")]
1894    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1895    #[rustc_no_implicit_autorefs]
1896    pub const fn is_empty(&self) -> bool {
1897        self.len() == 0
1898    }
1899
1900    /// Splits the string into two at the given byte index.
1901    ///
1902    /// Returns a newly allocated `String`. `self` contains bytes `[0, at)`, and
1903    /// the returned `String` contains bytes `[at, len)`. `at` must be on the
1904    /// boundary of a UTF-8 code point.
1905    ///
1906    /// Note that the capacity of `self` does not change.
1907    ///
1908    /// # Panics
1909    ///
1910    /// Panics if `at` is not on a `UTF-8` code point boundary, or if it is beyond the last
1911    /// code point of the string.
1912    ///
1913    /// # Examples
1914    ///
1915    /// ```
1916    /// # fn main() {
1917    /// let mut hello = String::from("Hello, World!");
1918    /// let world = hello.split_off(7);
1919    /// assert_eq!(hello, "Hello, ");
1920    /// assert_eq!(world, "World!");
1921    /// # }
1922    /// ```
1923    #[cfg(not(no_global_oom_handling))]
1924    #[inline]
1925    #[track_caller]
1926    #[stable(feature = "string_split_off", since = "1.16.0")]
1927    #[must_use = "use `.truncate()` if you don't need the other half"]
1928    pub fn split_off(&mut self, at: usize) -> String {
1929        assert!(self.is_char_boundary(at));
1930        let other = self.vec.split_off(at);
1931        unsafe { String::from_utf8_unchecked(other) }
1932    }
1933
1934    /// Truncates this `String`, removing all contents.
1935    ///
1936    /// While this means the `String` will have a length of zero, it does not
1937    /// touch its capacity.
1938    ///
1939    /// # Examples
1940    ///
1941    /// ```
1942    /// let mut s = String::from("foo");
1943    ///
1944    /// s.clear();
1945    ///
1946    /// assert!(s.is_empty());
1947    /// assert_eq!(0, s.len());
1948    /// assert_eq!(3, s.capacity());
1949    /// ```
1950    #[inline]
1951    #[stable(feature = "rust1", since = "1.0.0")]
1952    pub fn clear(&mut self) {
1953        self.vec.clear()
1954    }
1955
1956    /// Removes the specified range from the string in bulk, returning all
1957    /// removed characters as an iterator.
1958    ///
1959    /// The returned iterator keeps a mutable borrow on the string to optimize
1960    /// its implementation.
1961    ///
1962    /// # Panics
1963    ///
1964    /// Panics if the range has `start_bound > end_bound`, or, if the range is
1965    /// bounded on either end and does not lie on a [`char`] boundary.
1966    ///
1967    /// # Leaking
1968    ///
1969    /// If the returned iterator goes out of scope without being dropped (due to
1970    /// [`core::mem::forget`], for example), the string may still contain a copy
1971    /// of any drained characters, or may have lost characters arbitrarily,
1972    /// including characters outside the range.
1973    ///
1974    /// # Examples
1975    ///
1976    /// ```
1977    /// let mut s = String::from("ฮฑ is alpha, ฮฒ is beta");
1978    /// let beta_offset = s.find('ฮฒ').unwrap_or(s.len());
1979    ///
1980    /// // Remove the range up until the ฮฒ from the string
1981    /// let t: String = s.drain(..beta_offset).collect();
1982    /// assert_eq!(t, "ฮฑ is alpha, ");
1983    /// assert_eq!(s, "ฮฒ is beta");
1984    ///
1985    /// // A full range clears the string, like `clear()` does
1986    /// s.drain(..);
1987    /// assert_eq!(s, "");
1988    /// ```
1989    #[stable(feature = "drain", since = "1.6.0")]
1990    #[track_caller]
1991    pub fn drain<R>(&mut self, range: R) -> Drain<'_>
1992    where
1993        R: RangeBounds<usize>,
1994    {
1995        // Memory safety
1996        //
1997        // The String version of Drain does not have the memory safety issues
1998        // of the vector version. The data is just plain bytes.
1999        // Because the range removal happens in Drop, if the Drain iterator is leaked,
2000        // the removal will not happen.
2001        let Range { start, end } = slice::range(range, ..self.len());
2002        assert!(self.is_char_boundary(start));
2003        assert!(self.is_char_boundary(end));
2004
2005        // Take out two simultaneous borrows. The &mut String won't be accessed
2006        // until iteration is over, in Drop.
2007        let self_ptr = self as *mut _;
2008        // SAFETY: `slice::range` and `is_char_boundary` do the appropriate bounds checks.
2009        let chars_iter = unsafe { self.get_unchecked(start..end) }.chars();
2010
2011        Drain { start, end, iter: chars_iter, string: self_ptr }
2012    }
2013
2014    /// Converts a `String` into an iterator over the [`char`]s of the string.
2015    ///
2016    /// As a string consists of valid UTF-8, we can iterate through a string
2017    /// by [`char`]. This method returns such an iterator.
2018    ///
2019    /// It's important to remember that [`char`] represents a Unicode Scalar
2020    /// Value, and might not match your idea of what a 'character' is. Iteration
2021    /// over grapheme clusters may be what you actually want. That functionality
2022    /// is not provided by Rust's standard library, check crates.io instead.
2023    ///
2024    /// # Examples
2025    ///
2026    /// Basic usage:
2027    ///
2028    /// ```
2029    /// #![feature(string_into_chars)]
2030    ///
2031    /// let word = String::from("goodbye");
2032    ///
2033    /// let mut chars = word.into_chars();
2034    ///
2035    /// assert_eq!(Some('g'), chars.next());
2036    /// assert_eq!(Some('o'), chars.next());
2037    /// assert_eq!(Some('o'), chars.next());
2038    /// assert_eq!(Some('d'), chars.next());
2039    /// assert_eq!(Some('b'), chars.next());
2040    /// assert_eq!(Some('y'), chars.next());
2041    /// assert_eq!(Some('e'), chars.next());
2042    ///
2043    /// assert_eq!(None, chars.next());
2044    /// ```
2045    ///
2046    /// Remember, [`char`]s might not match your intuition about characters:
2047    ///
2048    /// ```
2049    /// #![feature(string_into_chars)]
2050    ///
2051    /// let y = String::from("yฬ†");
2052    ///
2053    /// let mut chars = y.into_chars();
2054    ///
2055    /// assert_eq!(Some('y'), chars.next()); // not 'yฬ†'
2056    /// assert_eq!(Some('\u{0306}'), chars.next());
2057    ///
2058    /// assert_eq!(None, chars.next());
2059    /// ```
2060    ///
2061    /// [`char`]: prim@char
2062    #[inline]
2063    #[must_use = "`self` will be dropped if the result is not used"]
2064    #[unstable(feature = "string_into_chars", issue = "133125")]
2065    pub fn into_chars(self) -> IntoChars {
2066        IntoChars { bytes: self.into_bytes().into_iter() }
2067    }
2068
2069    /// Removes the specified range in the string,
2070    /// and replaces it with the given string.
2071    /// The given string doesn't need to be the same length as the range.
2072    ///
2073    /// # Panics
2074    ///
2075    /// Panics if the range has `start_bound > end_bound`, or, if the range is
2076    /// bounded on either end and does not lie on a [`char`] boundary.
2077    ///
2078    /// # Examples
2079    ///
2080    /// ```
2081    /// let mut s = String::from("ฮฑ is alpha, ฮฒ is beta");
2082    /// let beta_offset = s.find('ฮฒ').unwrap_or(s.len());
2083    ///
2084    /// // Replace the range up until the ฮฒ from the string
2085    /// s.replace_range(..beta_offset, "ฮ‘ is capital alpha; ");
2086    /// assert_eq!(s, "ฮ‘ is capital alpha; ฮฒ is beta");
2087    /// ```
2088    #[cfg(not(no_global_oom_handling))]
2089    #[stable(feature = "splice", since = "1.27.0")]
2090    #[track_caller]
2091    pub fn replace_range<R>(&mut self, range: R, replace_with: &str)
2092    where
2093        R: RangeBounds<usize>,
2094    {
2095        // We avoid #81138 (nondeterministic RangeBounds impls) because we only use `range` once, here.
2096        let checked_range = slice::range(range, ..self.len());
2097
2098        assert!(
2099            self.is_char_boundary(checked_range.start),
2100            "start of range should be a character boundary"
2101        );
2102        assert!(
2103            self.is_char_boundary(checked_range.end),
2104            "end of range should be a character boundary"
2105        );
2106
2107        unsafe { self.as_mut_vec() }.splice(checked_range, replace_with.bytes());
2108    }
2109
2110    /// Replaces the leftmost occurrence of a pattern with another string, in-place.
2111    ///
2112    /// This method can be preferred over [`string = string.replacen(..., 1);`][replacen],
2113    /// as it can use the `String`'s existing capacity to prevent a reallocation if
2114    /// sufficient space is available.
2115    ///
2116    /// # Examples
2117    ///
2118    /// Basic usage:
2119    ///
2120    /// ```
2121    /// #![feature(string_replace_in_place)]
2122    ///
2123    /// let mut s = String::from("Test Results: โŒโŒโŒ");
2124    ///
2125    /// // Replace the leftmost โŒ with a โœ…
2126    /// s.replace_first('โŒ', "โœ…");
2127    /// assert_eq!(s, "Test Results: โœ…โŒโŒ");
2128    /// ```
2129    ///
2130    /// [replacen]: ../../std/primitive.str.html#method.replacen
2131    #[cfg(not(no_global_oom_handling))]
2132    #[unstable(feature = "string_replace_in_place", issue = "147949")]
2133    pub fn replace_first<P: Pattern>(&mut self, from: P, to: &str) {
2134        let range = match self.match_indices(from).next() {
2135            Some((start, match_str)) => start..start + match_str.len(),
2136            None => return,
2137        };
2138
2139        self.replace_range(range, to);
2140    }
2141
2142    /// Replaces the rightmost occurrence of a pattern with another string, in-place.
2143    ///
2144    /// # Examples
2145    ///
2146    /// Basic usage:
2147    ///
2148    /// ```
2149    /// #![feature(string_replace_in_place)]
2150    ///
2151    /// let mut s = String::from("Test Results: โŒโŒโŒ");
2152    ///
2153    /// // Replace the rightmost โŒ with a โœ…
2154    /// s.replace_last('โŒ', "โœ…");
2155    /// assert_eq!(s, "Test Results: โŒโŒโœ…");
2156    /// ```
2157    #[cfg(not(no_global_oom_handling))]
2158    #[unstable(feature = "string_replace_in_place", issue = "147949")]
2159    pub fn replace_last<P: Pattern>(&mut self, from: P, to: &str)
2160    where
2161        for<'a> P::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2162    {
2163        let range = match self.rmatch_indices(from).next() {
2164            Some((start, match_str)) => start..start + match_str.len(),
2165            None => return,
2166        };
2167
2168        self.replace_range(range, to);
2169    }
2170
2171    /// Converts this `String` into a <code>[Box]<[str]></code>.
2172    ///
2173    /// Before doing the conversion, this method discards excess capacity like [`shrink_to_fit`].
2174    /// Note that this call may reallocate and copy the bytes of the string.
2175    ///
2176    /// [`shrink_to_fit`]: String::shrink_to_fit
2177    /// [str]: prim@str "str"
2178    ///
2179    /// # Examples
2180    ///
2181    /// ```
2182    /// let s = String::from("hello");
2183    ///
2184    /// let b = s.into_boxed_str();
2185    /// ```
2186    #[cfg(not(no_global_oom_handling))]
2187    #[stable(feature = "box_str", since = "1.4.0")]
2188    #[must_use = "`self` will be dropped if the result is not used"]
2189    #[inline]
2190    pub fn into_boxed_str(self) -> Box<str> {
2191        let slice = self.vec.into_boxed_slice();
2192        unsafe { from_boxed_utf8_unchecked(slice) }
2193    }
2194
2195    /// Consumes and leaks the `String`, returning a mutable reference to the contents,
2196    /// `&'a mut str`.
2197    ///
2198    /// The caller has free choice over the returned lifetime, including `'static`. Indeed,
2199    /// this function is ideally used for data that lives for the remainder of the program's life,
2200    /// as dropping the returned reference will cause a memory leak.
2201    ///
2202    /// It does not reallocate or shrink the `String`, so the leaked allocation may include unused
2203    /// capacity that is not part of the returned slice. If you want to discard excess capacity,
2204    /// call [`into_boxed_str`], and then [`Box::leak`] instead. However, keep in mind that
2205    /// trimming the capacity may result in a reallocation and copy.
2206    ///
2207    /// [`into_boxed_str`]: Self::into_boxed_str
2208    ///
2209    /// # Examples
2210    ///
2211    /// ```
2212    /// let x = String::from("bucket");
2213    /// let static_ref: &'static mut str = x.leak();
2214    /// assert_eq!(static_ref, "bucket");
2215    /// # // FIXME(https://github.com/rust-lang/miri/issues/3670):
2216    /// # // use -Zmiri-disable-leak-check instead of unleaking in tests meant to leak.
2217    /// # drop(unsafe { Box::from_raw(static_ref) });
2218    /// ```
2219    #[stable(feature = "string_leak", since = "1.72.0")]
2220    #[inline]
2221    pub fn leak<'a>(self) -> &'a mut str {
2222        let slice = self.vec.leak();
2223        unsafe { from_utf8_unchecked_mut(slice) }
2224    }
2225}
2226
2227impl FromUtf8Error {
2228    /// Returns a slice of [`u8`]s bytes that were attempted to convert to a `String`.
2229    ///
2230    /// # Examples
2231    ///
2232    /// ```
2233    /// // some invalid bytes, in a vector
2234    /// let bytes = vec![0, 159];
2235    ///
2236    /// let value = String::from_utf8(bytes);
2237    ///
2238    /// assert_eq!(&[0, 159], value.unwrap_err().as_bytes());
2239    /// ```
2240    #[must_use]
2241    #[stable(feature = "from_utf8_error_as_bytes", since = "1.26.0")]
2242    pub fn as_bytes(&self) -> &[u8] {
2243        &self.bytes[..]
2244    }
2245
2246    /// Converts the bytes into a `String` lossily, substituting invalid UTF-8
2247    /// sequences with replacement characters.
2248    ///
2249    /// See [`String::from_utf8_lossy`] for more details on replacement of
2250    /// invalid sequences, and [`String::from_utf8_lossy_owned`] for the
2251    /// `String` function which corresponds to this function.
2252    ///
2253    /// This is useful in conjunction with [`String::from_utf8`] when you need
2254    /// to branch on whether the bytes are valid UTF-8, but still want to
2255    /// recover a lossily converted `String` in the error case. Use
2256    /// [`String::from_utf8_lossy_owned`] if you always need a lossily converted
2257    /// `String`.
2258    ///
2259    /// Since the original [`String::from_utf8`] error records where validation
2260    /// stopped, this method does not need to re-check the already valid prefix
2261    /// of the byte sequence.
2262    ///
2263    /// # Examples
2264    ///
2265    /// ```
2266    /// // some invalid bytes
2267    /// let input: Vec<u8> = b"Hello \xF0\x90\x80World".into();
2268    ///
2269    /// let (output, had_invalid_utf8) = match String::from_utf8(input) {
2270    ///     Ok(output) => (output, false),
2271    ///     Err(error) => {
2272    ///         // The bytes were not valid UTF-8, but we can still recover a string.
2273    ///         (error.into_utf8_lossy(), true)
2274    ///     }
2275    /// };
2276    ///
2277    /// assert_eq!(String::from("Hello ๏ฟฝWorld"), output);
2278    /// assert!(had_invalid_utf8);
2279    /// ```
2280    #[must_use]
2281    #[cfg(not(no_global_oom_handling))]
2282    #[stable(feature = "string_from_utf8_lossy_owned", since = "CURRENT_RUSTC_VERSION")]
2283    pub fn into_utf8_lossy(self) -> String {
2284        const REPLACEMENT: &str = "\u{FFFD}";
2285
2286        let mut res = {
2287            let mut v = Vec::with_capacity(self.bytes.len());
2288
2289            // `Utf8Error::valid_up_to` returns the maximum index of validated
2290            // UTF-8 bytes. Copy the valid bytes into the output buffer.
2291            v.extend_from_slice(&self.bytes[..self.error.valid_up_to()]);
2292
2293            // SAFETY: This is safe because the only bytes present in the buffer
2294            // were validated as UTF-8 by the call to `String::from_utf8` which
2295            // produced this `FromUtf8Error`.
2296            unsafe { String::from_utf8_unchecked(v) }
2297        };
2298
2299        let iter = self.bytes[self.error.valid_up_to()..].utf8_chunks();
2300
2301        for chunk in iter {
2302            res.push_str(chunk.valid());
2303            if !chunk.invalid().is_empty() {
2304                res.push_str(REPLACEMENT);
2305            }
2306        }
2307
2308        res
2309    }
2310
2311    /// Returns the bytes that were attempted to convert to a `String`.
2312    ///
2313    /// This method is carefully constructed to avoid allocation. It will
2314    /// consume the error, moving out the bytes, so that a copy of the bytes
2315    /// does not need to be made.
2316    ///
2317    /// # Examples
2318    ///
2319    /// ```
2320    /// // some invalid bytes, in a vector
2321    /// let bytes = vec![0, 159];
2322    ///
2323    /// let value = String::from_utf8(bytes);
2324    ///
2325    /// assert_eq!(vec![0, 159], value.unwrap_err().into_bytes());
2326    /// ```
2327    #[must_use = "`self` will be dropped if the result is not used"]
2328    #[stable(feature = "rust1", since = "1.0.0")]
2329    pub fn into_bytes(self) -> Vec<u8> {
2330        self.bytes
2331    }
2332
2333    /// Fetch a `Utf8Error` to get more details about the conversion failure.
2334    ///
2335    /// The [`Utf8Error`] type provided by [`std::str`] represents an error that may
2336    /// occur when converting a slice of [`u8`]s to a [`&str`]. In this sense, it's
2337    /// an analogue to `FromUtf8Error`. See its documentation for more details
2338    /// on using it.
2339    ///
2340    /// [`std::str`]: core::str "std::str"
2341    /// [`&str`]: prim@str "&str"
2342    ///
2343    /// # Examples
2344    ///
2345    /// ```
2346    /// // some invalid bytes, in a vector
2347    /// let bytes = vec![0, 159];
2348    ///
2349    /// let error = String::from_utf8(bytes).unwrap_err().utf8_error();
2350    ///
2351    /// // the first byte is invalid here
2352    /// assert_eq!(1, error.valid_up_to());
2353    /// ```
2354    #[must_use]
2355    #[stable(feature = "rust1", since = "1.0.0")]
2356    pub fn utf8_error(&self) -> Utf8Error {
2357        self.error
2358    }
2359}
2360
2361#[stable(feature = "rust1", since = "1.0.0")]
2362impl fmt::Display for FromUtf8Error {
2363    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2364        fmt::Display::fmt(&self.error, f)
2365    }
2366}
2367
2368#[stable(feature = "rust1", since = "1.0.0")]
2369impl fmt::Display for FromUtf16Error {
2370    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2371        match self.kind {
2372            FromUtf16ErrorKind::LoneSurrogate => "invalid utf-16: lone surrogate found",
2373            FromUtf16ErrorKind::OddBytes => "invalid utf-16: odd number of bytes",
2374        }
2375        .fmt(f)
2376    }
2377}
2378
2379#[stable(feature = "rust1", since = "1.0.0")]
2380impl Error for FromUtf8Error {}
2381
2382#[stable(feature = "rust1", since = "1.0.0")]
2383impl Error for FromUtf16Error {}
2384
2385#[cfg(not(no_global_oom_handling))]
2386#[stable(feature = "rust1", since = "1.0.0")]
2387impl Clone for String {
2388    fn clone(&self) -> Self {
2389        String { vec: self.vec.clone() }
2390    }
2391
2392    /// Clones the contents of `source` into `self`.
2393    ///
2394    /// This method is preferred over simply assigning `source.clone()` to `self`,
2395    /// as it avoids reallocation if possible.
2396    fn clone_from(&mut self, source: &Self) {
2397        self.vec.clone_from(&source.vec);
2398    }
2399}
2400
2401#[cfg(not(no_global_oom_handling))]
2402#[stable(feature = "rust1", since = "1.0.0")]
2403impl FromIterator<char> for String {
2404    fn from_iter<I: IntoIterator<Item = char>>(iter: I) -> String {
2405        let mut buf = String::new();
2406        buf.extend(iter);
2407        buf
2408    }
2409}
2410
2411#[cfg(not(no_global_oom_handling))]
2412#[stable(feature = "string_from_iter_by_ref", since = "1.17.0")]
2413impl<'a> FromIterator<&'a char> for String {
2414    fn from_iter<I: IntoIterator<Item = &'a char>>(iter: I) -> String {
2415        let mut buf = String::new();
2416        buf.extend(iter);
2417        buf
2418    }
2419}
2420
2421#[cfg(not(no_global_oom_handling))]
2422#[stable(feature = "rust1", since = "1.0.0")]
2423impl<'a> FromIterator<&'a str> for String {
2424    fn from_iter<I: IntoIterator<Item = &'a str>>(iter: I) -> String {
2425        let mut buf = String::new();
2426        buf.extend(iter);
2427        buf
2428    }
2429}
2430
2431#[cfg(not(no_global_oom_handling))]
2432#[stable(feature = "extend_string", since = "1.4.0")]
2433impl FromIterator<String> for String {
2434    fn from_iter<I: IntoIterator<Item = String>>(iter: I) -> String {
2435        let mut iterator = iter.into_iter();
2436
2437        // Because we're iterating over `String`s, we can avoid at least
2438        // one allocation by getting the first string from the iterator
2439        // and appending to it all the subsequent strings.
2440        match iterator.next() {
2441            None => String::new(),
2442            Some(mut buf) => {
2443                buf.extend(iterator);
2444                buf
2445            }
2446        }
2447    }
2448}
2449
2450#[cfg(not(no_global_oom_handling))]
2451#[stable(feature = "box_str2", since = "1.45.0")]
2452impl<A: Allocator> FromIterator<Box<str, A>> for String {
2453    fn from_iter<I: IntoIterator<Item = Box<str, A>>>(iter: I) -> String {
2454        let mut buf = String::new();
2455        buf.extend(iter);
2456        buf
2457    }
2458}
2459
2460#[cfg(not(no_global_oom_handling))]
2461#[stable(feature = "herd_cows", since = "1.19.0")]
2462impl<'a> FromIterator<Cow<'a, str>> for String {
2463    fn from_iter<I: IntoIterator<Item = Cow<'a, str>>>(iter: I) -> String {
2464        let mut iterator = iter.into_iter();
2465
2466        // Because we're iterating over CoWs, we can (potentially) avoid at least
2467        // one allocation by getting the first item and appending to it all the
2468        // subsequent items.
2469        match iterator.next() {
2470            None => String::new(),
2471            Some(cow) => {
2472                let mut buf = cow.into_owned();
2473                buf.extend(iterator);
2474                buf
2475            }
2476        }
2477    }
2478}
2479
2480#[cfg(not(no_global_oom_handling))]
2481#[unstable(feature = "ascii_char", issue = "110998")]
2482impl FromIterator<core::ascii::Char> for String {
2483    fn from_iter<T: IntoIterator<Item = core::ascii::Char>>(iter: T) -> Self {
2484        let buf = iter.into_iter().map(core::ascii::Char::to_u8).collect();
2485        // SAFETY: `buf` is guaranteed to be valid UTF-8 because the `core::ascii::Char` type
2486        // only contains ASCII values (0x00-0x7F), which are valid UTF-8.
2487        unsafe { String::from_utf8_unchecked(buf) }
2488    }
2489}
2490
2491#[cfg(not(no_global_oom_handling))]
2492#[unstable(feature = "ascii_char", issue = "110998")]
2493impl<'a> FromIterator<&'a core::ascii::Char> for String {
2494    fn from_iter<T: IntoIterator<Item = &'a core::ascii::Char>>(iter: T) -> Self {
2495        let buf = iter.into_iter().copied().map(core::ascii::Char::to_u8).collect();
2496        // SAFETY: `buf` is guaranteed to be valid UTF-8 because the `core::ascii::Char` type
2497        // only contains ASCII values (0x00-0x7F), which are valid UTF-8.
2498        unsafe { String::from_utf8_unchecked(buf) }
2499    }
2500}
2501
2502#[cfg(not(no_global_oom_handling))]
2503#[stable(feature = "rust1", since = "1.0.0")]
2504impl Extend<char> for String {
2505    fn extend<I: IntoIterator<Item = char>>(&mut self, iter: I) {
2506        let iterator = iter.into_iter();
2507        let (lower_bound, _) = iterator.size_hint();
2508        self.reserve(lower_bound);
2509        iterator.for_each(move |c| self.push(c));
2510    }
2511
2512    #[inline]
2513    fn extend_one(&mut self, c: char) {
2514        self.push(c);
2515    }
2516
2517    #[inline]
2518    fn extend_reserve(&mut self, additional: usize) {
2519        self.reserve(additional);
2520    }
2521}
2522
2523#[cfg(not(no_global_oom_handling))]
2524#[stable(feature = "extend_ref", since = "1.2.0")]
2525impl<'a> Extend<&'a char> for String {
2526    fn extend<I: IntoIterator<Item = &'a char>>(&mut self, iter: I) {
2527        self.extend(iter.into_iter().cloned());
2528    }
2529
2530    #[inline]
2531    fn extend_one(&mut self, &c: &'a char) {
2532        self.push(c);
2533    }
2534
2535    #[inline]
2536    fn extend_reserve(&mut self, additional: usize) {
2537        self.reserve(additional);
2538    }
2539}
2540
2541#[cfg(not(no_global_oom_handling))]
2542#[stable(feature = "rust1", since = "1.0.0")]
2543impl<'a> Extend<&'a str> for String {
2544    fn extend<I: IntoIterator<Item = &'a str>>(&mut self, iter: I) {
2545        <I as SpecExtendStr>::spec_extend_into(iter, self)
2546    }
2547
2548    #[inline]
2549    fn extend_one(&mut self, s: &'a str) {
2550        self.push_str(s);
2551    }
2552}
2553
2554#[cfg(not(no_global_oom_handling))]
2555trait SpecExtendStr {
2556    fn spec_extend_into(self, s: &mut String);
2557}
2558
2559#[cfg(not(no_global_oom_handling))]
2560impl<'a, T: IntoIterator<Item = &'a str>> SpecExtendStr for T {
2561    default fn spec_extend_into(self, target: &mut String) {
2562        self.into_iter().for_each(move |s| target.push_str(s));
2563    }
2564}
2565
2566#[cfg(not(no_global_oom_handling))]
2567impl SpecExtendStr for [&str] {
2568    fn spec_extend_into(self, target: &mut String) {
2569        target.push_str_slice(&self);
2570    }
2571}
2572
2573#[cfg(not(no_global_oom_handling))]
2574impl<const N: usize> SpecExtendStr for [&str; N] {
2575    fn spec_extend_into(self, target: &mut String) {
2576        target.push_str_slice(&self[..]);
2577    }
2578}
2579
2580#[cfg(not(no_global_oom_handling))]
2581#[stable(feature = "box_str2", since = "1.45.0")]
2582impl<A: Allocator> Extend<Box<str, A>> for String {
2583    fn extend<I: IntoIterator<Item = Box<str, A>>>(&mut self, iter: I) {
2584        iter.into_iter().for_each(move |s| self.push_str(&s));
2585    }
2586}
2587
2588#[cfg(not(no_global_oom_handling))]
2589#[stable(feature = "extend_string", since = "1.4.0")]
2590impl Extend<String> for String {
2591    fn extend<I: IntoIterator<Item = String>>(&mut self, iter: I) {
2592        iter.into_iter().for_each(move |s| self.push_str(&s));
2593    }
2594
2595    #[inline]
2596    fn extend_one(&mut self, s: String) {
2597        self.push_str(&s);
2598    }
2599}
2600
2601#[cfg(not(no_global_oom_handling))]
2602#[stable(feature = "herd_cows", since = "1.19.0")]
2603impl<'a> Extend<Cow<'a, str>> for String {
2604    fn extend<I: IntoIterator<Item = Cow<'a, str>>>(&mut self, iter: I) {
2605        iter.into_iter().for_each(move |s| self.push_str(&s));
2606    }
2607
2608    #[inline]
2609    fn extend_one(&mut self, s: Cow<'a, str>) {
2610        self.push_str(&s);
2611    }
2612}
2613
2614#[cfg(not(no_global_oom_handling))]
2615#[unstable(feature = "ascii_char", issue = "110998")]
2616impl Extend<core::ascii::Char> for String {
2617    #[inline]
2618    fn extend<I: IntoIterator<Item = core::ascii::Char>>(&mut self, iter: I) {
2619        self.vec.extend(iter.into_iter().map(|c| c.to_u8()));
2620    }
2621
2622    #[inline]
2623    fn extend_one(&mut self, c: core::ascii::Char) {
2624        self.vec.push(c.to_u8());
2625    }
2626}
2627
2628#[cfg(not(no_global_oom_handling))]
2629#[unstable(feature = "ascii_char", issue = "110998")]
2630impl<'a> Extend<&'a core::ascii::Char> for String {
2631    #[inline]
2632    fn extend<I: IntoIterator<Item = &'a core::ascii::Char>>(&mut self, iter: I) {
2633        self.extend(iter.into_iter().cloned());
2634    }
2635
2636    #[inline]
2637    fn extend_one(&mut self, c: &'a core::ascii::Char) {
2638        self.vec.push(c.to_u8());
2639    }
2640}
2641
2642/// A convenience impl that delegates to the impl for `&str`.
2643///
2644/// # Examples
2645///
2646/// ```
2647/// assert_eq!(String::from("Hello world").find("world"), Some(6));
2648/// ```
2649#[unstable(
2650    feature = "pattern",
2651    reason = "API not fully fleshed out and ready to be stabilized",
2652    issue = "27721"
2653)]
2654impl<'b> Pattern for &'b String {
2655    type Searcher<'a> = <&'b str as Pattern>::Searcher<'a>;
2656
2657    fn into_searcher(self, haystack: &str) -> <&'b str as Pattern>::Searcher<'_> {
2658        self[..].into_searcher(haystack)
2659    }
2660
2661    #[inline]
2662    fn is_contained_in(self, haystack: &str) -> bool {
2663        self[..].is_contained_in(haystack)
2664    }
2665
2666    #[inline]
2667    fn is_prefix_of(self, haystack: &str) -> bool {
2668        self[..].is_prefix_of(haystack)
2669    }
2670
2671    #[inline]
2672    fn strip_prefix_of(self, haystack: &str) -> Option<&str> {
2673        self[..].strip_prefix_of(haystack)
2674    }
2675
2676    #[inline]
2677    fn is_suffix_of<'a>(self, haystack: &'a str) -> bool
2678    where
2679        Self::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2680    {
2681        self[..].is_suffix_of(haystack)
2682    }
2683
2684    #[inline]
2685    fn strip_suffix_of<'a>(self, haystack: &'a str) -> Option<&'a str>
2686    where
2687        Self::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2688    {
2689        self[..].strip_suffix_of(haystack)
2690    }
2691
2692    #[inline]
2693    fn as_utf8_pattern(&self) -> Option<Utf8Pattern<'_>> {
2694        Some(Utf8Pattern::StringPattern(self.as_str()))
2695    }
2696}
2697
2698macro_rules! impl_eq {
2699    ($lhs:ty, $rhs: ty) => {
2700        #[stable(feature = "rust1", since = "1.0.0")]
2701        impl PartialEq<$rhs> for $lhs {
2702            #[inline]
2703            fn eq(&self, other: &$rhs) -> bool {
2704                PartialEq::eq(&self[..], &other[..])
2705            }
2706            #[inline]
2707            fn ne(&self, other: &$rhs) -> bool {
2708                PartialEq::ne(&self[..], &other[..])
2709            }
2710        }
2711
2712        #[stable(feature = "rust1", since = "1.0.0")]
2713        impl PartialEq<$lhs> for $rhs {
2714            #[inline]
2715            fn eq(&self, other: &$lhs) -> bool {
2716                PartialEq::eq(&self[..], &other[..])
2717            }
2718            #[inline]
2719            fn ne(&self, other: &$lhs) -> bool {
2720                PartialEq::ne(&self[..], &other[..])
2721            }
2722        }
2723    };
2724}
2725
2726impl_eq! { String, str }
2727impl_eq! { String, &str }
2728#[cfg(not(no_global_oom_handling))]
2729impl_eq! { Cow<'_, str>, str }
2730#[cfg(not(no_global_oom_handling))]
2731impl_eq! { Cow<'_, str>, &'_ str }
2732#[cfg(not(no_global_oom_handling))]
2733impl_eq! { Cow<'_, str>, String }
2734
2735#[stable(feature = "rust1", since = "1.0.0")]
2736#[rustc_const_unstable(feature = "const_default", issue = "143894")]
2737const impl Default for String {
2738    /// Creates an empty `String`.
2739    #[inline]
2740    fn default() -> String {
2741        String::new()
2742    }
2743}
2744
2745#[stable(feature = "rust1", since = "1.0.0")]
2746impl fmt::Display for String {
2747    #[inline]
2748    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2749        fmt::Display::fmt(&**self, f)
2750    }
2751}
2752
2753#[stable(feature = "rust1", since = "1.0.0")]
2754impl fmt::Debug for String {
2755    #[inline]
2756    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2757        fmt::Debug::fmt(&**self, f)
2758    }
2759}
2760
2761#[stable(feature = "rust1", since = "1.0.0")]
2762impl hash::Hash for String {
2763    #[inline]
2764    fn hash<H: hash::Hasher>(&self, hasher: &mut H) {
2765        (**self).hash(hasher)
2766    }
2767}
2768
2769/// Implements the `+` operator for concatenating two strings.
2770///
2771/// This consumes the `String` on the left-hand side and re-uses its buffer (growing it if
2772/// necessary). This is done to avoid allocating a new `String` and copying the entire contents on
2773/// every operation, which would lead to *O*(*n*^2) running time when building an *n*-byte string by
2774/// repeated concatenation.
2775///
2776/// The string on the right-hand side is only borrowed; its contents are copied into the returned
2777/// `String`.
2778///
2779/// # Examples
2780///
2781/// Concatenating two `String`s takes the first by value and borrows the second:
2782///
2783/// ```
2784/// let a = String::from("hello");
2785/// let b = String::from(" world");
2786/// let c = a + &b;
2787/// // `a` is moved and can no longer be used here.
2788/// ```
2789///
2790/// If you want to keep using the first `String`, you can clone it and append to the clone instead:
2791///
2792/// ```
2793/// let a = String::from("hello");
2794/// let b = String::from(" world");
2795/// let c = a.clone() + &b;
2796/// // `a` is still valid here.
2797/// ```
2798///
2799/// Concatenating `&str` slices can be done by converting the first to a `String`:
2800///
2801/// ```
2802/// let a = "hello";
2803/// let b = " world";
2804/// let c = a.to_string() + b;
2805/// ```
2806#[cfg(not(no_global_oom_handling))]
2807#[stable(feature = "rust1", since = "1.0.0")]
2808impl Add<&str> for String {
2809    type Output = String;
2810
2811    #[inline]
2812    fn add(mut self, other: &str) -> String {
2813        self.push_str(other);
2814        self
2815    }
2816}
2817
2818/// Implements the `+=` operator for appending to a `String`.
2819///
2820/// This has the same behavior as the [`push_str`][String::push_str] method.
2821#[cfg(not(no_global_oom_handling))]
2822#[stable(feature = "stringaddassign", since = "1.12.0")]
2823impl AddAssign<&str> for String {
2824    #[inline]
2825    fn add_assign(&mut self, other: &str) {
2826        self.push_str(other);
2827    }
2828}
2829
2830#[stable(feature = "rust1", since = "1.0.0")]
2831impl<I> ops::Index<I> for String
2832where
2833    I: slice::SliceIndex<str>,
2834{
2835    type Output = I::Output;
2836
2837    #[inline]
2838    fn index(&self, index: I) -> &I::Output {
2839        index.index(self.as_str())
2840    }
2841}
2842
2843#[stable(feature = "rust1", since = "1.0.0")]
2844impl<I> ops::IndexMut<I> for String
2845where
2846    I: slice::SliceIndex<str>,
2847{
2848    #[inline]
2849    fn index_mut(&mut self, index: I) -> &mut I::Output {
2850        index.index_mut(self.as_mut_str())
2851    }
2852}
2853
2854#[stable(feature = "rust1", since = "1.0.0")]
2855impl ops::Deref for String {
2856    type Target = str;
2857
2858    #[inline]
2859    fn deref(&self) -> &str {
2860        self.as_str()
2861    }
2862}
2863
2864#[unstable(feature = "deref_pure_trait", issue = "87121")]
2865unsafe impl ops::DerefPure for String {}
2866
2867#[stable(feature = "derefmut_for_string", since = "1.3.0")]
2868impl ops::DerefMut for String {
2869    #[inline]
2870    fn deref_mut(&mut self) -> &mut str {
2871        self.as_mut_str()
2872    }
2873}
2874
2875/// A type alias for [`Infallible`].
2876///
2877/// This alias exists for backwards compatibility, and may be eventually deprecated.
2878///
2879/// [`Infallible`]: core::convert::Infallible "convert::Infallible"
2880#[stable(feature = "str_parse_error", since = "1.5.0")]
2881pub type ParseError = core::convert::Infallible;
2882
2883#[cfg(not(no_global_oom_handling))]
2884#[stable(feature = "rust1", since = "1.0.0")]
2885impl FromStr for String {
2886    type Err = core::convert::Infallible;
2887    #[inline]
2888    fn from_str(s: &str) -> Result<String, Self::Err> {
2889        Ok(String::from(s))
2890    }
2891}
2892
2893/// A trait for converting a value to a `String`.
2894///
2895/// This trait is automatically implemented for any type which implements the
2896/// [`Display`] trait. As such, `ToString` shouldn't be implemented directly:
2897/// [`Display`] should be implemented instead, and you get the `ToString`
2898/// implementation for free.
2899///
2900/// [`Display`]: fmt::Display
2901#[rustc_diagnostic_item = "ToString"]
2902#[stable(feature = "rust1", since = "1.0.0")]
2903pub trait ToString {
2904    /// Converts the given value to a `String`.
2905    ///
2906    /// # Examples
2907    ///
2908    /// ```
2909    /// let i = 5;
2910    /// let five = String::from("5");
2911    ///
2912    /// assert_eq!(five, i.to_string());
2913    /// ```
2914    #[rustc_conversion_suggestion]
2915    #[stable(feature = "rust1", since = "1.0.0")]
2916    #[rustc_diagnostic_item = "to_string_method"]
2917    fn to_string(&self) -> String;
2918}
2919
2920/// # Panics
2921///
2922/// In this implementation, the `to_string` method panics
2923/// if the `Display` implementation returns an error.
2924/// This indicates an incorrect `Display` implementation
2925/// since `fmt::Write for String` never returns an error itself.
2926#[cfg(not(no_global_oom_handling))]
2927#[stable(feature = "rust1", since = "1.0.0")]
2928impl<T: fmt::Display + ?Sized> ToString for T {
2929    #[inline]
2930    fn to_string(&self) -> String {
2931        <Self as SpecToString>::spec_to_string(self)
2932    }
2933}
2934
2935#[cfg(not(no_global_oom_handling))]
2936trait SpecToString {
2937    fn spec_to_string(&self) -> String;
2938}
2939
2940#[cfg(not(no_global_oom_handling))]
2941impl<T: fmt::Display + ?Sized> SpecToString for T {
2942    // A common guideline is to not inline generic functions. However,
2943    // removing `#[inline]` from this method causes non-negligible regressions.
2944    // See <https://github.com/rust-lang/rust/pull/74852>, the last attempt
2945    // to try to remove it.
2946    #[inline]
2947    default fn spec_to_string(&self) -> String {
2948        let mut buf = String::new();
2949        let mut formatter =
2950            core::fmt::Formatter::new(&mut buf, core::fmt::FormattingOptions::new());
2951        // Bypass format_args!() to avoid write_str with zero-length strs
2952        fmt::Display::fmt(self, &mut formatter)
2953            .expect("a Display implementation returned an error unexpectedly");
2954        buf
2955    }
2956}
2957
2958#[cfg(not(no_global_oom_handling))]
2959impl SpecToString for core::ascii::Char {
2960    #[inline]
2961    fn spec_to_string(&self) -> String {
2962        self.as_str().to_owned()
2963    }
2964}
2965
2966#[cfg(not(no_global_oom_handling))]
2967impl SpecToString for char {
2968    #[inline]
2969    fn spec_to_string(&self) -> String {
2970        String::from(self.encode_utf8(&mut [0; char::MAX_LEN_UTF8]))
2971    }
2972}
2973
2974#[cfg(not(no_global_oom_handling))]
2975impl SpecToString for bool {
2976    #[inline]
2977    fn spec_to_string(&self) -> String {
2978        String::from(if *self { "true" } else { "false" })
2979    }
2980}
2981
2982macro_rules! impl_to_string {
2983    ($($signed:ident, $unsigned:ident,)*) => {
2984        $(
2985        #[cfg(not(no_global_oom_handling))]
2986        #[cfg(not(feature = "optimize_for_size"))]
2987        impl SpecToString for $signed {
2988            #[inline]
2989            fn spec_to_string(&self) -> String {
2990                const SIZE: usize = $signed::MAX.ilog10() as usize + 1;
2991                let mut buf = [core::mem::MaybeUninit::<u8>::uninit(); SIZE];
2992                // Only difference between signed and unsigned are these 8 lines.
2993                let mut out;
2994                if *self < 0 {
2995                    out = String::with_capacity(SIZE + 1);
2996                    out.push('-');
2997                } else {
2998                    out = String::with_capacity(SIZE);
2999                }
3000
3001                // SAFETY: `buf` is always big enough to contain all the digits.
3002                unsafe { out.push_str(self.unsigned_abs()._fmt(&mut buf)); }
3003                out
3004            }
3005        }
3006        #[cfg(not(no_global_oom_handling))]
3007        #[cfg(not(feature = "optimize_for_size"))]
3008        impl SpecToString for $unsigned {
3009            #[inline]
3010            fn spec_to_string(&self) -> String {
3011                const SIZE: usize = $unsigned::MAX.ilog10() as usize + 1;
3012                let mut buf = [core::mem::MaybeUninit::<u8>::uninit(); SIZE];
3013
3014                // SAFETY: `buf` is always big enough to contain all the digits.
3015                unsafe { self._fmt(&mut buf).to_string() }
3016            }
3017        }
3018        )*
3019    }
3020}
3021
3022impl_to_string! {
3023    i8, u8,
3024    i16, u16,
3025    i32, u32,
3026    i64, u64,
3027    isize, usize,
3028    i128, u128,
3029}
3030
3031#[cfg(not(no_global_oom_handling))]
3032#[cfg(feature = "optimize_for_size")]
3033impl SpecToString for u8 {
3034    #[inline]
3035    fn spec_to_string(&self) -> String {
3036        let mut buf = String::with_capacity(3);
3037        let mut n = *self;
3038        if n >= 10 {
3039            if n >= 100 {
3040                buf.push((b'0' + n / 100) as char);
3041                n %= 100;
3042            }
3043            buf.push((b'0' + n / 10) as char);
3044            n %= 10;
3045        }
3046        buf.push((b'0' + n) as char);
3047        buf
3048    }
3049}
3050
3051#[cfg(not(no_global_oom_handling))]
3052#[cfg(feature = "optimize_for_size")]
3053impl SpecToString for i8 {
3054    #[inline]
3055    fn spec_to_string(&self) -> String {
3056        let mut buf = String::with_capacity(4);
3057        if self.is_negative() {
3058            buf.push('-');
3059        }
3060        let mut n = self.unsigned_abs();
3061        if n >= 10 {
3062            if n >= 100 {
3063                buf.push('1');
3064                n -= 100;
3065            }
3066            buf.push((b'0' + n / 10) as char);
3067            n %= 10;
3068        }
3069        buf.push((b'0' + n) as char);
3070        buf
3071    }
3072}
3073
3074#[cfg(not(no_global_oom_handling))]
3075macro_rules! to_string_str {
3076    {$($type:ty,)*} => {
3077        $(
3078            impl SpecToString for $type {
3079                #[inline]
3080                fn spec_to_string(&self) -> String {
3081                    let s: &str = self;
3082                    String::from(s)
3083                }
3084            }
3085        )*
3086    };
3087}
3088
3089#[cfg(not(no_global_oom_handling))]
3090to_string_str! {
3091    Cow<'_, str>,
3092    String,
3093    // Generic/generated code can sometimes have multiple, nested references
3094    // for strings, including `&&&str`s that would never be written
3095    // by hand.
3096    &&&&&&&&&&&&str,
3097    &&&&&&&&&&&str,
3098    &&&&&&&&&&str,
3099    &&&&&&&&&str,
3100    &&&&&&&&str,
3101    &&&&&&&str,
3102    &&&&&&str,
3103    &&&&&str,
3104    &&&&str,
3105    &&&str,
3106    &&str,
3107    &str,
3108    str,
3109}
3110
3111#[cfg(not(no_global_oom_handling))]
3112impl SpecToString for fmt::Arguments<'_> {
3113    #[inline]
3114    fn spec_to_string(&self) -> String {
3115        crate::fmt::format(*self)
3116    }
3117}
3118
3119#[stable(feature = "rust1", since = "1.0.0")]
3120impl AsRef<str> for String {
3121    #[inline]
3122    fn as_ref(&self) -> &str {
3123        self
3124    }
3125}
3126
3127#[stable(feature = "string_as_mut", since = "1.43.0")]
3128impl AsMut<str> for String {
3129    #[inline]
3130    fn as_mut(&mut self) -> &mut str {
3131        self
3132    }
3133}
3134
3135#[stable(feature = "rust1", since = "1.0.0")]
3136impl AsRef<[u8]> for String {
3137    #[inline]
3138    fn as_ref(&self) -> &[u8] {
3139        self.as_bytes()
3140    }
3141}
3142
3143#[cfg(not(no_global_oom_handling))]
3144#[stable(feature = "rust1", since = "1.0.0")]
3145impl From<&str> for String {
3146    /// Converts a `&str` into a [`String`].
3147    ///
3148    /// The result is allocated on the heap.
3149    #[inline]
3150    fn from(s: &str) -> String {
3151        s.to_owned()
3152    }
3153}
3154
3155#[cfg(not(no_global_oom_handling))]
3156#[stable(feature = "from_mut_str_for_string", since = "1.44.0")]
3157impl From<&mut str> for String {
3158    /// Converts a `&mut str` into a [`String`].
3159    ///
3160    /// The result is allocated on the heap.
3161    #[inline]
3162    fn from(s: &mut str) -> String {
3163        s.to_owned()
3164    }
3165}
3166
3167#[cfg(not(no_global_oom_handling))]
3168#[stable(feature = "from_ref_string", since = "1.35.0")]
3169impl From<&String> for String {
3170    /// Converts a `&String` into a [`String`].
3171    ///
3172    /// This clones `s` and returns the clone.
3173    #[inline]
3174    fn from(s: &String) -> String {
3175        s.clone()
3176    }
3177}
3178
3179// note: test pulls in std, which causes errors here
3180#[stable(feature = "string_from_box", since = "1.18.0")]
3181impl From<Box<str>> for String {
3182    /// Converts the given boxed `str` slice to a [`String`].
3183    /// It is notable that the `str` slice is owned.
3184    ///
3185    /// # Examples
3186    ///
3187    /// ```
3188    /// let s1: String = String::from("hello world");
3189    /// let s2: Box<str> = s1.into_boxed_str();
3190    /// let s3: String = String::from(s2);
3191    ///
3192    /// assert_eq!("hello world", s3)
3193    /// ```
3194    fn from(s: Box<str>) -> String {
3195        s.into_string()
3196    }
3197}
3198
3199#[cfg(not(no_global_oom_handling))]
3200#[stable(feature = "box_from_str", since = "1.20.0")]
3201impl From<String> for Box<str> {
3202    /// Converts the given [`String`] to a boxed `str` slice that is owned.
3203    ///
3204    /// # Examples
3205    ///
3206    /// ```
3207    /// let s1: String = String::from("hello world");
3208    /// let s2: Box<str> = Box::from(s1);
3209    /// let s3: String = String::from(s2);
3210    ///
3211    /// assert_eq!("hello world", s3)
3212    /// ```
3213    fn from(s: String) -> Box<str> {
3214        s.into_boxed_str()
3215    }
3216}
3217
3218#[cfg(not(no_global_oom_handling))]
3219#[stable(feature = "string_from_cow_str", since = "1.14.0")]
3220impl<'a> From<Cow<'a, str>> for String {
3221    /// Converts a clone-on-write string to an owned
3222    /// instance of [`String`].
3223    ///
3224    /// This extracts the owned string,
3225    /// clones the string if it is not already owned.
3226    ///
3227    /// # Example
3228    ///
3229    /// ```
3230    /// # use std::borrow::Cow;
3231    /// // If the string is not owned...
3232    /// let cow: Cow<'_, str> = Cow::Borrowed("eggplant");
3233    /// // It will allocate on the heap and copy the string.
3234    /// let owned: String = String::from(cow);
3235    /// assert_eq!(&owned[..], "eggplant");
3236    /// ```
3237    fn from(s: Cow<'a, str>) -> String {
3238        s.into_owned()
3239    }
3240}
3241
3242#[cfg(not(no_global_oom_handling))]
3243#[stable(feature = "rust1", since = "1.0.0")]
3244impl<'a> From<&'a str> for Cow<'a, str> {
3245    /// Converts a string slice into a [`Borrowed`] variant.
3246    /// No heap allocation is performed, and the string
3247    /// is not copied.
3248    ///
3249    /// # Example
3250    ///
3251    /// ```
3252    /// # use std::borrow::Cow;
3253    /// assert_eq!(Cow::from("eggplant"), Cow::Borrowed("eggplant"));
3254    /// ```
3255    ///
3256    /// [`Borrowed`]: crate::borrow::Cow::Borrowed "borrow::Cow::Borrowed"
3257    #[inline]
3258    fn from(s: &'a str) -> Cow<'a, str> {
3259        Cow::Borrowed(s)
3260    }
3261}
3262
3263#[cfg(not(no_global_oom_handling))]
3264#[stable(feature = "rust1", since = "1.0.0")]
3265impl<'a> From<String> for Cow<'a, str> {
3266    /// Converts a [`String`] into an [`Owned`] variant.
3267    /// No heap allocation is performed, and the string
3268    /// is not copied.
3269    ///
3270    /// # Example
3271    ///
3272    /// ```
3273    /// # use std::borrow::Cow;
3274    /// let s = "eggplant".to_string();
3275    /// let s2 = "eggplant".to_string();
3276    /// assert_eq!(Cow::from(s), Cow::<'static, str>::Owned(s2));
3277    /// ```
3278    ///
3279    /// [`Owned`]: crate::borrow::Cow::Owned "borrow::Cow::Owned"
3280    #[inline]
3281    fn from(s: String) -> Cow<'a, str> {
3282        Cow::Owned(s)
3283    }
3284}
3285
3286#[cfg(not(no_global_oom_handling))]
3287#[stable(feature = "cow_from_string_ref", since = "1.28.0")]
3288impl<'a> From<&'a String> for Cow<'a, str> {
3289    /// Converts a [`String`] reference into a [`Borrowed`] variant.
3290    /// No heap allocation is performed, and the string
3291    /// is not copied.
3292    ///
3293    /// # Example
3294    ///
3295    /// ```
3296    /// # use std::borrow::Cow;
3297    /// let s = "eggplant".to_string();
3298    /// assert_eq!(Cow::from(&s), Cow::Borrowed("eggplant"));
3299    /// ```
3300    ///
3301    /// [`Borrowed`]: crate::borrow::Cow::Borrowed "borrow::Cow::Borrowed"
3302    #[inline]
3303    fn from(s: &'a String) -> Cow<'a, str> {
3304        Cow::Borrowed(s.as_str())
3305    }
3306}
3307
3308#[cfg(not(no_global_oom_handling))]
3309#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3310impl<'a> FromIterator<char> for Cow<'a, str> {
3311    fn from_iter<I: IntoIterator<Item = char>>(it: I) -> Cow<'a, str> {
3312        Cow::Owned(FromIterator::from_iter(it))
3313    }
3314}
3315
3316#[cfg(not(no_global_oom_handling))]
3317#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3318impl<'a, 'b> FromIterator<&'b str> for Cow<'a, str> {
3319    fn from_iter<I: IntoIterator<Item = &'b str>>(it: I) -> Cow<'a, str> {
3320        Cow::Owned(FromIterator::from_iter(it))
3321    }
3322}
3323
3324#[cfg(not(no_global_oom_handling))]
3325#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3326impl<'a> FromIterator<String> for Cow<'a, str> {
3327    fn from_iter<I: IntoIterator<Item = String>>(it: I) -> Cow<'a, str> {
3328        Cow::Owned(FromIterator::from_iter(it))
3329    }
3330}
3331
3332#[cfg(not(no_global_oom_handling))]
3333#[unstable(feature = "ascii_char", issue = "110998")]
3334impl<'a> FromIterator<core::ascii::Char> for Cow<'a, str> {
3335    fn from_iter<T: IntoIterator<Item = core::ascii::Char>>(it: T) -> Self {
3336        Cow::Owned(FromIterator::from_iter(it))
3337    }
3338}
3339
3340#[stable(feature = "from_string_for_vec_u8", since = "1.14.0")]
3341impl From<String> for Vec<u8> {
3342    /// Converts the given [`String`] to a vector [`Vec`] that holds values of type [`u8`].
3343    ///
3344    /// # Examples
3345    ///
3346    /// ```
3347    /// let s1 = String::from("hello world");
3348    /// let v1 = Vec::from(s1);
3349    ///
3350    /// for b in v1 {
3351    ///     println!("{b}");
3352    /// }
3353    /// ```
3354    fn from(string: String) -> Vec<u8> {
3355        string.into_bytes()
3356    }
3357}
3358
3359#[stable(feature = "try_from_vec_u8_for_string", since = "1.87.0")]
3360impl TryFrom<Vec<u8>> for String {
3361    type Error = FromUtf8Error;
3362    /// Converts the given [`Vec<u8>`] into a  [`String`] if it contains valid UTF-8 data.
3363    ///
3364    /// # Examples
3365    ///
3366    /// ```
3367    /// let s1 = b"hello world".to_vec();
3368    /// let v1 = String::try_from(s1).unwrap();
3369    /// assert_eq!(v1, "hello world");
3370    ///
3371    /// ```
3372    fn try_from(bytes: Vec<u8>) -> Result<Self, Self::Error> {
3373        Self::from_utf8(bytes)
3374    }
3375}
3376
3377#[cfg(not(no_global_oom_handling))]
3378#[stable(feature = "rust1", since = "1.0.0")]
3379impl fmt::Write for String {
3380    #[inline]
3381    fn write_str(&mut self, s: &str) -> fmt::Result {
3382        self.push_str(s);
3383        Ok(())
3384    }
3385
3386    #[inline]
3387    fn write_char(&mut self, c: char) -> fmt::Result {
3388        self.push(c);
3389        Ok(())
3390    }
3391}
3392
3393/// An iterator over the [`char`]s of a string.
3394///
3395/// This struct is created by the [`into_chars`] method on [`String`].
3396/// See its documentation for more.
3397///
3398/// [`char`]: prim@char
3399/// [`into_chars`]: String::into_chars
3400#[cfg_attr(not(no_global_oom_handling), derive(Clone))]
3401#[must_use = "iterators are lazy and do nothing unless consumed"]
3402#[unstable(feature = "string_into_chars", issue = "133125")]
3403pub struct IntoChars {
3404    bytes: vec::IntoIter<u8>,
3405}
3406
3407#[unstable(feature = "string_into_chars", issue = "133125")]
3408impl fmt::Debug for IntoChars {
3409    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
3410        f.debug_tuple("IntoChars").field(&self.as_str()).finish()
3411    }
3412}
3413
3414impl IntoChars {
3415    /// Views the underlying data as a subslice of the original data.
3416    ///
3417    /// # Examples
3418    ///
3419    /// ```
3420    /// #![feature(string_into_chars)]
3421    ///
3422    /// let mut chars = String::from("abc").into_chars();
3423    ///
3424    /// assert_eq!(chars.as_str(), "abc");
3425    /// chars.next();
3426    /// assert_eq!(chars.as_str(), "bc");
3427    /// chars.next();
3428    /// chars.next();
3429    /// assert_eq!(chars.as_str(), "");
3430    /// ```
3431    #[unstable(feature = "string_into_chars", issue = "133125")]
3432    #[must_use]
3433    #[inline]
3434    pub fn as_str(&self) -> &str {
3435        // SAFETY: `bytes` is a valid UTF-8 string.
3436        unsafe { str::from_utf8_unchecked(self.bytes.as_slice()) }
3437    }
3438
3439    /// Consumes the `IntoChars`, returning the remaining string.
3440    ///
3441    /// # Examples
3442    ///
3443    /// ```
3444    /// #![feature(string_into_chars)]
3445    ///
3446    /// let chars = String::from("abc").into_chars();
3447    /// assert_eq!(chars.into_string(), "abc");
3448    ///
3449    /// let mut chars = String::from("def").into_chars();
3450    /// chars.next();
3451    /// assert_eq!(chars.into_string(), "ef");
3452    /// ```
3453    #[cfg(not(no_global_oom_handling))]
3454    #[unstable(feature = "string_into_chars", issue = "133125")]
3455    #[inline]
3456    pub fn into_string(self) -> String {
3457        // Safety: `bytes` are kept in UTF-8 form, only removing whole `char`s at a time.
3458        unsafe { String::from_utf8_unchecked(self.bytes.collect()) }
3459    }
3460
3461    #[inline]
3462    fn iter(&self) -> CharIndices<'_> {
3463        self.as_str().char_indices()
3464    }
3465}
3466
3467#[unstable(feature = "string_into_chars", issue = "133125")]
3468impl Iterator for IntoChars {
3469    type Item = char;
3470
3471    #[inline]
3472    fn next(&mut self) -> Option<char> {
3473        let mut iter = self.iter();
3474        match iter.next() {
3475            None => None,
3476            Some((_, ch)) => {
3477                let offset = iter.offset();
3478                // `offset` is a valid index.
3479                let _ = self.bytes.advance_by(offset);
3480                Some(ch)
3481            }
3482        }
3483    }
3484
3485    #[inline]
3486    fn count(self) -> usize {
3487        self.iter().count()
3488    }
3489
3490    #[inline]
3491    fn size_hint(&self) -> (usize, Option<usize>) {
3492        self.iter().size_hint()
3493    }
3494
3495    #[inline]
3496    fn last(mut self) -> Option<char> {
3497        self.next_back()
3498    }
3499}
3500
3501#[unstable(feature = "string_into_chars", issue = "133125")]
3502impl DoubleEndedIterator for IntoChars {
3503    #[inline]
3504    fn next_back(&mut self) -> Option<char> {
3505        let len = self.as_str().len();
3506        let mut iter = self.iter();
3507        match iter.next_back() {
3508            None => None,
3509            Some((idx, ch)) => {
3510                // `idx` is a valid index.
3511                let _ = self.bytes.advance_back_by(len - idx);
3512                Some(ch)
3513            }
3514        }
3515    }
3516}
3517
3518#[unstable(feature = "string_into_chars", issue = "133125")]
3519impl FusedIterator for IntoChars {}
3520
3521/// A draining iterator for `String`.
3522///
3523/// This struct is created by the [`drain`] method on [`String`]. See its
3524/// documentation for more.
3525///
3526/// [`drain`]: String::drain
3527#[stable(feature = "drain", since = "1.6.0")]
3528pub struct Drain<'a> {
3529    /// Will be used as &'a mut String in the destructor
3530    string: *mut String,
3531    /// Start of part to remove
3532    start: usize,
3533    /// End of part to remove
3534    end: usize,
3535    /// Current remaining range to remove
3536    iter: Chars<'a>,
3537}
3538
3539#[stable(feature = "collection_debug", since = "1.17.0")]
3540impl fmt::Debug for Drain<'_> {
3541    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
3542        f.debug_tuple("Drain").field(&self.as_str()).finish()
3543    }
3544}
3545
3546#[stable(feature = "drain", since = "1.6.0")]
3547unsafe impl Sync for Drain<'_> {}
3548#[stable(feature = "drain", since = "1.6.0")]
3549unsafe impl Send for Drain<'_> {}
3550
3551#[stable(feature = "drain", since = "1.6.0")]
3552impl Drop for Drain<'_> {
3553    fn drop(&mut self) {
3554        unsafe {
3555            // Use Vec::drain. "Reaffirm" the bounds checks to avoid
3556            // panic code being inserted again.
3557            let self_vec = (*self.string).as_mut_vec();
3558            if self.start <= self.end && self.end <= self_vec.len() {
3559                self_vec.drain(self.start..self.end);
3560            }
3561        }
3562    }
3563}
3564
3565impl<'a> Drain<'a> {
3566    /// Returns the remaining (sub)string of this iterator as a slice.
3567    ///
3568    /// # Examples
3569    ///
3570    /// ```
3571    /// let mut s = String::from("abc");
3572    /// let mut drain = s.drain(..);
3573    /// assert_eq!(drain.as_str(), "abc");
3574    /// let _ = drain.next().unwrap();
3575    /// assert_eq!(drain.as_str(), "bc");
3576    /// ```
3577    #[must_use]
3578    #[stable(feature = "string_drain_as_str", since = "1.55.0")]
3579    pub fn as_str(&self) -> &str {
3580        self.iter.as_str()
3581    }
3582}
3583
3584#[stable(feature = "string_drain_as_str", since = "1.55.0")]
3585impl<'a> AsRef<str> for Drain<'a> {
3586    fn as_ref(&self) -> &str {
3587        self.as_str()
3588    }
3589}
3590
3591#[stable(feature = "string_drain_as_str", since = "1.55.0")]
3592impl<'a> AsRef<[u8]> for Drain<'a> {
3593    fn as_ref(&self) -> &[u8] {
3594        self.as_str().as_bytes()
3595    }
3596}
3597
3598#[stable(feature = "drain", since = "1.6.0")]
3599impl Iterator for Drain<'_> {
3600    type Item = char;
3601
3602    #[inline]
3603    fn next(&mut self) -> Option<char> {
3604        self.iter.next()
3605    }
3606
3607    fn size_hint(&self) -> (usize, Option<usize>) {
3608        self.iter.size_hint()
3609    }
3610
3611    #[inline]
3612    fn last(mut self) -> Option<char> {
3613        self.next_back()
3614    }
3615}
3616
3617#[stable(feature = "drain", since = "1.6.0")]
3618impl DoubleEndedIterator for Drain<'_> {
3619    #[inline]
3620    fn next_back(&mut self) -> Option<char> {
3621        self.iter.next_back()
3622    }
3623}
3624
3625#[stable(feature = "fused", since = "1.26.0")]
3626impl FusedIterator for Drain<'_> {}
3627
3628#[cfg(not(no_global_oom_handling))]
3629#[stable(feature = "from_char_for_string", since = "1.46.0")]
3630impl From<char> for String {
3631    /// Allocates an owned [`String`] from a single character.
3632    ///
3633    /// # Example
3634    /// ```rust
3635    /// let c: char = 'a';
3636    /// let s: String = String::from(c);
3637    /// assert_eq!("a", &s[..]);
3638    /// ```
3639    #[inline]
3640    fn from(c: char) -> Self {
3641        c.to_string()
3642    }
3643}