Skip to main content

core/slice/
mod.rs

1//! Slice management and manipulation.
2//!
3//! For more details see [`std::slice`].
4//!
5//! [`std::slice`]: ../../std/slice/index.html
6
7#![stable(feature = "rust1", since = "1.0.0")]
8
9use crate::clone::TrivialClone;
10use crate::cmp::Ordering::{self, Equal, Greater, Less};
11use crate::intrinsics::{exact_div, unchecked_sub};
12use crate::marker::Destruct;
13use crate::mem::{self, MaybeUninit, SizedTypeProperties};
14use crate::num::NonZero;
15use crate::ops::{OneSidedRange, OneSidedRangeBound, Range, RangeBounds, RangeInclusive};
16use crate::panic::const_panic;
17use crate::simd::{self, Simd};
18use crate::ub_checks::assert_unsafe_precondition;
19use crate::{fmt, hint, ptr, range, slice};
20
21#[unstable(
22    feature = "slice_internals",
23    issue = "none",
24    reason = "exposed from core to be reused in std; use the memchr crate"
25)]
26#[doc(hidden)]
27/// Pure Rust memchr implementation, taken from rust-memchr
28pub mod memchr;
29
30#[unstable(
31    feature = "slice_internals",
32    issue = "none",
33    reason = "exposed from core to be reused in std;"
34)]
35#[doc(hidden)]
36pub mod sort;
37
38mod ascii;
39mod cmp;
40pub(crate) mod index;
41mod iter;
42mod raw;
43mod rotate;
44mod specialize;
45
46/// Ferrocene addition: Hidden module to test crate-internal functionality
47#[doc(hidden)]
48#[unstable(feature = "ferrocene_test", issue = "none")]
49pub mod ferrocene_test;
50
51#[stable(feature = "inherent_ascii_escape", since = "1.60.0")]
52pub use ascii::EscapeAscii;
53#[unstable(feature = "str_internals", issue = "none")]
54#[doc(hidden)]
55pub use ascii::is_ascii_simple;
56#[stable(feature = "slice_get_slice", since = "1.28.0")]
57pub use index::SliceIndex;
58#[unstable(feature = "slice_range", issue = "76393")]
59pub use index::{range, try_range};
60#[stable(feature = "array_windows", since = "1.94.0")]
61pub use iter::ArrayWindows;
62#[stable(feature = "slice_group_by", since = "1.77.0")]
63pub use iter::{ChunkBy, ChunkByMut};
64#[stable(feature = "rust1", since = "1.0.0")]
65pub use iter::{Chunks, ChunksMut, Windows};
66#[stable(feature = "chunks_exact", since = "1.31.0")]
67pub use iter::{ChunksExact, ChunksExactMut};
68#[stable(feature = "rust1", since = "1.0.0")]
69pub use iter::{Iter, IterMut};
70#[stable(feature = "rchunks", since = "1.31.0")]
71pub use iter::{RChunks, RChunksExact, RChunksExactMut, RChunksMut};
72#[stable(feature = "slice_rsplit", since = "1.27.0")]
73pub use iter::{RSplit, RSplitMut};
74#[stable(feature = "rust1", since = "1.0.0")]
75pub use iter::{RSplitN, RSplitNMut, Split, SplitMut, SplitN, SplitNMut};
76#[stable(feature = "split_inclusive", since = "1.51.0")]
77pub use iter::{SplitInclusive, SplitInclusiveMut};
78#[stable(feature = "from_ref", since = "1.28.0")]
79pub use raw::{from_mut, from_ref};
80#[unstable(feature = "slice_from_ptr_range", issue = "89792")]
81pub use raw::{from_mut_ptr_range, from_ptr_range};
82#[stable(feature = "rust1", since = "1.0.0")]
83pub use raw::{from_raw_parts, from_raw_parts_mut};
84
85/// Calculates the direction and split point of a one-sided range.
86///
87/// This is a helper function for `split_off` and `split_off_mut` that returns
88/// the direction of the split (front or back) as well as the index at
89/// which to split. Returns `None` if the split index would overflow.
90#[inline]
91fn split_point_of(range: impl OneSidedRange<usize>) -> Option<(Direction, usize)> {
92    use OneSidedRangeBound::{End, EndInclusive, StartInclusive};
93
94    Some(match range.bound() {
95        (StartInclusive, i) => (Direction::Back, i),
96        (End, i) => (Direction::Front, i),
97        (EndInclusive, i) => (Direction::Front, i.checked_add(1)?),
98    })
99}
100
101enum Direction {
102    Front,
103    Back,
104}
105
106impl<T> [T] {
107    /// Returns the number of elements in the slice.
108    ///
109    /// # Examples
110    ///
111    /// ```
112    /// let a = [1, 2, 3];
113    /// assert_eq!(a.len(), 3);
114    /// ```
115    #[lang = "slice_len_fn"]
116    #[stable(feature = "rust1", since = "1.0.0")]
117    #[rustc_const_stable(feature = "const_slice_len", since = "1.39.0")]
118    #[rustc_no_implicit_autorefs]
119    #[inline]
120    #[must_use]
121    #[ferrocene::annotation(
122        "this function is guaranteed to be constant-evaluated as the size of arrays is always available at compilation"
123    )]
124    #[ferrocene::prevalidated]
125    pub const fn len(&self) -> usize {
126        ptr::metadata(self)
127    }
128
129    /// Returns `true` if the slice has a length of 0.
130    ///
131    /// # Examples
132    ///
133    /// ```
134    /// let a = [1, 2, 3];
135    /// assert!(!a.is_empty());
136    ///
137    /// let b: &[i32] = &[];
138    /// assert!(b.is_empty());
139    /// ```
140    #[stable(feature = "rust1", since = "1.0.0")]
141    #[rustc_const_stable(feature = "const_slice_is_empty", since = "1.39.0")]
142    #[rustc_no_implicit_autorefs]
143    #[inline]
144    #[must_use]
145    #[ferrocene::prevalidated]
146    pub const fn is_empty(&self) -> bool {
147        self.len() == 0
148    }
149
150    /// Returns the first element of the slice, or `None` if it is empty.
151    ///
152    /// # Examples
153    ///
154    /// ```
155    /// let v = [10, 40, 30];
156    /// assert_eq!(Some(&10), v.first());
157    ///
158    /// let w: &[i32] = &[];
159    /// assert_eq!(None, w.first());
160    /// ```
161    #[stable(feature = "rust1", since = "1.0.0")]
162    #[rustc_const_stable(feature = "const_slice_first_last_not_mut", since = "1.56.0")]
163    #[inline]
164    #[must_use]
165    #[ferrocene::prevalidated]
166    pub const fn first(&self) -> Option<&T> {
167        if let [first, ..] = self { Some(first) } else { None }
168    }
169
170    /// Returns a mutable reference to the first element of the slice, or `None` if it is empty.
171    ///
172    /// # Examples
173    ///
174    /// ```
175    /// let x = &mut [0, 1, 2];
176    ///
177    /// if let Some(first) = x.first_mut() {
178    ///     *first = 5;
179    /// }
180    /// assert_eq!(x, &[5, 1, 2]);
181    ///
182    /// let y: &mut [i32] = &mut [];
183    /// assert_eq!(None, y.first_mut());
184    /// ```
185    #[stable(feature = "rust1", since = "1.0.0")]
186    #[rustc_const_stable(feature = "const_slice_first_last", since = "1.83.0")]
187    #[inline]
188    #[must_use]
189    #[ferrocene::prevalidated]
190    pub const fn first_mut(&mut self) -> Option<&mut T> {
191        if let [first, ..] = self { Some(first) } else { None }
192    }
193
194    /// Returns the first and all the rest of the elements of the slice, or `None` if it is empty.
195    ///
196    /// # Examples
197    ///
198    /// ```
199    /// let x = &[0, 1, 2];
200    ///
201    /// if let Some((first, elements)) = x.split_first() {
202    ///     assert_eq!(first, &0);
203    ///     assert_eq!(elements, &[1, 2]);
204    /// }
205    /// ```
206    #[stable(feature = "slice_splits", since = "1.5.0")]
207    #[rustc_const_stable(feature = "const_slice_first_last_not_mut", since = "1.56.0")]
208    #[inline]
209    #[must_use]
210    #[ferrocene::prevalidated]
211    pub const fn split_first(&self) -> Option<(&T, &[T])> {
212        if let [first, tail @ ..] = self { Some((first, tail)) } else { None }
213    }
214
215    /// Returns the first and all the rest of the elements of the slice, or `None` if it is empty.
216    ///
217    /// # Examples
218    ///
219    /// ```
220    /// let x = &mut [0, 1, 2];
221    ///
222    /// if let Some((first, elements)) = x.split_first_mut() {
223    ///     *first = 3;
224    ///     elements[0] = 4;
225    ///     elements[1] = 5;
226    /// }
227    /// assert_eq!(x, &[3, 4, 5]);
228    /// ```
229    #[stable(feature = "slice_splits", since = "1.5.0")]
230    #[rustc_const_stable(feature = "const_slice_first_last", since = "1.83.0")]
231    #[inline]
232    #[must_use]
233    #[ferrocene::prevalidated]
234    pub const fn split_first_mut(&mut self) -> Option<(&mut T, &mut [T])> {
235        if let [first, tail @ ..] = self { Some((first, tail)) } else { None }
236    }
237
238    /// Returns the last and all the rest of the elements of the slice, or `None` if it is empty.
239    ///
240    /// # Examples
241    ///
242    /// ```
243    /// let x = &[0, 1, 2];
244    ///
245    /// if let Some((last, elements)) = x.split_last() {
246    ///     assert_eq!(last, &2);
247    ///     assert_eq!(elements, &[0, 1]);
248    /// }
249    /// ```
250    #[stable(feature = "slice_splits", since = "1.5.0")]
251    #[rustc_const_stable(feature = "const_slice_first_last_not_mut", since = "1.56.0")]
252    #[inline]
253    #[must_use]
254    #[ferrocene::prevalidated]
255    pub const fn split_last(&self) -> Option<(&T, &[T])> {
256        if let [init @ .., last] = self { Some((last, init)) } else { None }
257    }
258
259    /// Returns the last and all the rest of the elements of the slice, or `None` if it is empty.
260    ///
261    /// # Examples
262    ///
263    /// ```
264    /// let x = &mut [0, 1, 2];
265    ///
266    /// if let Some((last, elements)) = x.split_last_mut() {
267    ///     *last = 3;
268    ///     elements[0] = 4;
269    ///     elements[1] = 5;
270    /// }
271    /// assert_eq!(x, &[4, 5, 3]);
272    /// ```
273    #[stable(feature = "slice_splits", since = "1.5.0")]
274    #[rustc_const_stable(feature = "const_slice_first_last", since = "1.83.0")]
275    #[inline]
276    #[must_use]
277    #[ferrocene::prevalidated]
278    pub const fn split_last_mut(&mut self) -> Option<(&mut T, &mut [T])> {
279        if let [init @ .., last] = self { Some((last, init)) } else { None }
280    }
281
282    /// Returns the last element of the slice, or `None` if it is empty.
283    ///
284    /// # Examples
285    ///
286    /// ```
287    /// let v = [10, 40, 30];
288    /// assert_eq!(Some(&30), v.last());
289    ///
290    /// let w: &[i32] = &[];
291    /// assert_eq!(None, w.last());
292    /// ```
293    #[stable(feature = "rust1", since = "1.0.0")]
294    #[rustc_const_stable(feature = "const_slice_first_last_not_mut", since = "1.56.0")]
295    #[inline]
296    #[must_use]
297    #[ferrocene::prevalidated]
298    pub const fn last(&self) -> Option<&T> {
299        if let [.., last] = self { Some(last) } else { None }
300    }
301
302    /// Returns a mutable reference to the last item in the slice, or `None` if it is empty.
303    ///
304    /// # Examples
305    ///
306    /// ```
307    /// let x = &mut [0, 1, 2];
308    ///
309    /// if let Some(last) = x.last_mut() {
310    ///     *last = 10;
311    /// }
312    /// assert_eq!(x, &[0, 1, 10]);
313    ///
314    /// let y: &mut [i32] = &mut [];
315    /// assert_eq!(None, y.last_mut());
316    /// ```
317    #[stable(feature = "rust1", since = "1.0.0")]
318    #[rustc_const_stable(feature = "const_slice_first_last", since = "1.83.0")]
319    #[inline]
320    #[must_use]
321    #[ferrocene::prevalidated]
322    pub const fn last_mut(&mut self) -> Option<&mut T> {
323        if let [.., last] = self { Some(last) } else { None }
324    }
325
326    /// Returns an array reference to the first `N` items in the slice.
327    ///
328    /// If the slice is not at least `N` in length, this will return `None`.
329    ///
330    /// # Examples
331    ///
332    /// ```
333    /// let u = [10, 40, 30];
334    /// assert_eq!(Some(&[10, 40]), u.first_chunk::<2>());
335    ///
336    /// let v: &[i32] = &[10];
337    /// assert_eq!(None, v.first_chunk::<2>());
338    ///
339    /// let w: &[i32] = &[];
340    /// assert_eq!(Some(&[]), w.first_chunk::<0>());
341    /// ```
342    #[inline]
343    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
344    #[rustc_const_stable(feature = "slice_first_last_chunk", since = "1.77.0")]
345    #[ferrocene::prevalidated]
346    pub const fn first_chunk<const N: usize>(&self) -> Option<&[T; N]> {
347        if self.len() < N {
348            None
349        } else {
350            // SAFETY: We explicitly check for the correct number of elements,
351            //   and do not let the reference outlive the slice.
352            Some(unsafe { &*(self.as_ptr().cast_array()) })
353        }
354    }
355
356    /// Returns a mutable array reference to the first `N` items in the slice.
357    ///
358    /// If the slice is not at least `N` in length, this will return `None`.
359    ///
360    /// # Examples
361    ///
362    /// ```
363    /// let x = &mut [0, 1, 2];
364    ///
365    /// if let Some(first) = x.first_chunk_mut::<2>() {
366    ///     first[0] = 5;
367    ///     first[1] = 4;
368    /// }
369    /// assert_eq!(x, &[5, 4, 2]);
370    ///
371    /// assert_eq!(None, x.first_chunk_mut::<4>());
372    /// ```
373    #[inline]
374    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
375    #[rustc_const_stable(feature = "const_slice_first_last_chunk", since = "1.83.0")]
376    #[ferrocene::prevalidated]
377    pub const fn first_chunk_mut<const N: usize>(&mut self) -> Option<&mut [T; N]> {
378        if self.len() < N {
379            None
380        } else {
381            // SAFETY: We explicitly check for the correct number of elements,
382            //   do not let the reference outlive the slice,
383            //   and require exclusive access to the entire slice to mutate the chunk.
384            Some(unsafe { &mut *(self.as_mut_ptr().cast_array()) })
385        }
386    }
387
388    /// Returns an array reference to the first `N` items in the slice and the remaining slice.
389    ///
390    /// If the slice is not at least `N` in length, this will return `None`.
391    ///
392    /// # Examples
393    ///
394    /// ```
395    /// let x = &[0, 1, 2];
396    ///
397    /// if let Some((first, elements)) = x.split_first_chunk::<2>() {
398    ///     assert_eq!(first, &[0, 1]);
399    ///     assert_eq!(elements, &[2]);
400    /// }
401    ///
402    /// assert_eq!(None, x.split_first_chunk::<4>());
403    /// ```
404    #[inline]
405    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
406    #[rustc_const_stable(feature = "slice_first_last_chunk", since = "1.77.0")]
407    #[ferrocene::prevalidated]
408    pub const fn split_first_chunk<const N: usize>(&self) -> Option<(&[T; N], &[T])> {
409        let Some((first, tail)) = self.split_at_checked(N) else { return None };
410
411        // SAFETY: We explicitly check for the correct number of elements,
412        //   and do not let the references outlive the slice.
413        Some((unsafe { &*(first.as_ptr().cast_array()) }, tail))
414    }
415
416    /// Returns a mutable array reference to the first `N` items in the slice and the remaining
417    /// slice.
418    ///
419    /// If the slice is not at least `N` in length, this will return `None`.
420    ///
421    /// # Examples
422    ///
423    /// ```
424    /// let x = &mut [0, 1, 2];
425    ///
426    /// if let Some((first, elements)) = x.split_first_chunk_mut::<2>() {
427    ///     first[0] = 3;
428    ///     first[1] = 4;
429    ///     elements[0] = 5;
430    /// }
431    /// assert_eq!(x, &[3, 4, 5]);
432    ///
433    /// assert_eq!(None, x.split_first_chunk_mut::<4>());
434    /// ```
435    #[inline]
436    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
437    #[rustc_const_stable(feature = "const_slice_first_last_chunk", since = "1.83.0")]
438    #[ferrocene::prevalidated]
439    pub const fn split_first_chunk_mut<const N: usize>(
440        &mut self,
441    ) -> Option<(&mut [T; N], &mut [T])> {
442        let Some((first, tail)) = self.split_at_mut_checked(N) else { return None };
443
444        // SAFETY: We explicitly check for the correct number of elements,
445        //   do not let the reference outlive the slice,
446        //   and enforce exclusive mutability of the chunk by the split.
447        Some((unsafe { &mut *(first.as_mut_ptr().cast_array()) }, tail))
448    }
449
450    /// Returns an array reference to the last `N` items in the slice and the remaining slice.
451    ///
452    /// If the slice is not at least `N` in length, this will return `None`.
453    ///
454    /// # Examples
455    ///
456    /// ```
457    /// let x = &[0, 1, 2];
458    ///
459    /// if let Some((elements, last)) = x.split_last_chunk::<2>() {
460    ///     assert_eq!(elements, &[0]);
461    ///     assert_eq!(last, &[1, 2]);
462    /// }
463    ///
464    /// assert_eq!(None, x.split_last_chunk::<4>());
465    /// ```
466    #[inline]
467    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
468    #[rustc_const_stable(feature = "slice_first_last_chunk", since = "1.77.0")]
469    pub const fn split_last_chunk<const N: usize>(&self) -> Option<(&[T], &[T; N])> {
470        let Some(index) = self.len().checked_sub(N) else { return None };
471        let (init, last) = self.split_at(index);
472
473        // SAFETY: We explicitly check for the correct number of elements,
474        //   and do not let the references outlive the slice.
475        Some((init, unsafe { &*(last.as_ptr().cast_array()) }))
476    }
477
478    /// Returns a mutable array reference to the last `N` items in the slice and the remaining
479    /// slice.
480    ///
481    /// If the slice is not at least `N` in length, this will return `None`.
482    ///
483    /// # Examples
484    ///
485    /// ```
486    /// let x = &mut [0, 1, 2];
487    ///
488    /// if let Some((elements, last)) = x.split_last_chunk_mut::<2>() {
489    ///     last[0] = 3;
490    ///     last[1] = 4;
491    ///     elements[0] = 5;
492    /// }
493    /// assert_eq!(x, &[5, 3, 4]);
494    ///
495    /// assert_eq!(None, x.split_last_chunk_mut::<4>());
496    /// ```
497    #[inline]
498    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
499    #[rustc_const_stable(feature = "const_slice_first_last_chunk", since = "1.83.0")]
500    pub const fn split_last_chunk_mut<const N: usize>(
501        &mut self,
502    ) -> Option<(&mut [T], &mut [T; N])> {
503        let Some(index) = self.len().checked_sub(N) else { return None };
504        let (init, last) = self.split_at_mut(index);
505
506        // SAFETY: We explicitly check for the correct number of elements,
507        //   do not let the reference outlive the slice,
508        //   and enforce exclusive mutability of the chunk by the split.
509        Some((init, unsafe { &mut *(last.as_mut_ptr().cast_array()) }))
510    }
511
512    /// Returns an array reference to the last `N` items in the slice.
513    ///
514    /// If the slice is not at least `N` in length, this will return `None`.
515    ///
516    /// # Examples
517    ///
518    /// ```
519    /// let u = [10, 40, 30];
520    /// assert_eq!(Some(&[40, 30]), u.last_chunk::<2>());
521    ///
522    /// let v: &[i32] = &[10];
523    /// assert_eq!(None, v.last_chunk::<2>());
524    ///
525    /// let w: &[i32] = &[];
526    /// assert_eq!(Some(&[]), w.last_chunk::<0>());
527    /// ```
528    #[ferrocene::prevalidated]
529    #[inline]
530    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
531    #[rustc_const_stable(feature = "const_slice_last_chunk", since = "1.80.0")]
532    pub const fn last_chunk<const N: usize>(&self) -> Option<&[T; N]> {
533        // FIXME(const-hack): Without const traits, we need this instead of `get`.
534        let Some(index) = self.len().checked_sub(N) else { return None };
535        let (_, last) = self.split_at(index);
536
537        // SAFETY: We explicitly check for the correct number of elements,
538        //   and do not let the references outlive the slice.
539        Some(unsafe { &*(last.as_ptr().cast_array()) })
540    }
541
542    /// Returns a mutable array reference to the last `N` items in the slice.
543    ///
544    /// If the slice is not at least `N` in length, this will return `None`.
545    ///
546    /// # Examples
547    ///
548    /// ```
549    /// let x = &mut [0, 1, 2];
550    ///
551    /// if let Some(last) = x.last_chunk_mut::<2>() {
552    ///     last[0] = 10;
553    ///     last[1] = 20;
554    /// }
555    /// assert_eq!(x, &[0, 10, 20]);
556    ///
557    /// assert_eq!(None, x.last_chunk_mut::<4>());
558    /// ```
559    #[inline]
560    #[stable(feature = "slice_first_last_chunk", since = "1.77.0")]
561    #[rustc_const_stable(feature = "const_slice_first_last_chunk", since = "1.83.0")]
562    pub const fn last_chunk_mut<const N: usize>(&mut self) -> Option<&mut [T; N]> {
563        // FIXME(const-hack): Without const traits, we need this instead of `get`.
564        let Some(index) = self.len().checked_sub(N) else { return None };
565        let (_, last) = self.split_at_mut(index);
566
567        // SAFETY: We explicitly check for the correct number of elements,
568        //   do not let the reference outlive the slice,
569        //   and require exclusive access to the entire slice to mutate the chunk.
570        Some(unsafe { &mut *(last.as_mut_ptr().cast_array()) })
571    }
572
573    /// Returns a reference to an element or subslice depending on the type of
574    /// index.
575    ///
576    /// - If given a position, returns a reference to the element at that
577    ///   position or `None` if out of bounds.
578    /// - If given a range, returns the subslice corresponding to that range,
579    ///   or `None` if out of bounds.
580    ///
581    /// # Examples
582    ///
583    /// ```
584    /// let v = [10, 40, 30];
585    /// assert_eq!(Some(&40), v.get(1));
586    /// assert_eq!(Some(&[10, 40][..]), v.get(0..2));
587    /// assert_eq!(None, v.get(3));
588    /// assert_eq!(None, v.get(0..4));
589    /// ```
590    #[stable(feature = "rust1", since = "1.0.0")]
591    #[rustc_no_implicit_autorefs]
592    #[inline]
593    #[must_use]
594    #[rustc_const_unstable(feature = "const_index", issue = "143775")]
595    #[ferrocene::prevalidated]
596    pub const fn get<I>(&self, index: I) -> Option<&I::Output>
597    where
598        I: [const] SliceIndex<Self>,
599    {
600        index.get(self)
601    }
602
603    /// Returns a mutable reference to an element or subslice depending on the
604    /// type of index (see [`get`]) or `None` if the index is out of bounds.
605    ///
606    /// [`get`]: slice::get
607    ///
608    /// # Examples
609    ///
610    /// ```
611    /// let x = &mut [0, 1, 2];
612    ///
613    /// if let Some(elem) = x.get_mut(1) {
614    ///     *elem = 42;
615    /// }
616    /// assert_eq!(x, &[0, 42, 2]);
617    /// ```
618    #[ferrocene::prevalidated]
619    #[stable(feature = "rust1", since = "1.0.0")]
620    #[rustc_no_implicit_autorefs]
621    #[inline]
622    #[must_use]
623    #[rustc_const_unstable(feature = "const_index", issue = "143775")]
624    #[rustc_no_writable]
625    pub const fn get_mut<I>(&mut self, index: I) -> Option<&mut I::Output>
626    where
627        I: [const] SliceIndex<Self>,
628    {
629        index.get_mut(self)
630    }
631
632    /// Returns a reference to an element or subslice, without doing bounds
633    /// checking.
634    ///
635    /// For a safe alternative see [`get`].
636    ///
637    /// # Safety
638    ///
639    /// Calling this method with an out-of-bounds index is *[undefined behavior]*
640    /// even if the resulting reference is not used.
641    ///
642    /// You can think of this like `.get(index).unwrap_unchecked()`.  It's UB
643    /// to call `.get_unchecked(len)`, even if you immediately convert to a
644    /// pointer.  And it's UB to call `.get_unchecked(..len + 1)`,
645    /// `.get_unchecked(..=len)`, or similar.
646    ///
647    /// [`get`]: slice::get
648    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
649    ///
650    /// # Examples
651    ///
652    /// ```
653    /// let x = &[1, 2, 4];
654    ///
655    /// unsafe {
656    ///     assert_eq!(x.get_unchecked(1), &2);
657    /// }
658    /// ```
659    #[stable(feature = "rust1", since = "1.0.0")]
660    #[rustc_no_implicit_autorefs]
661    #[inline]
662    #[must_use]
663    #[track_caller]
664    #[rustc_const_unstable(feature = "const_index", issue = "143775")]
665    #[ferrocene::prevalidated]
666    pub const unsafe fn get_unchecked<I>(&self, index: I) -> &I::Output
667    where
668        I: [const] SliceIndex<Self>,
669    {
670        // SAFETY: the caller must uphold most of the safety requirements for `get_unchecked`;
671        // the slice is dereferenceable because `self` is a safe reference.
672        // The returned pointer is safe because impls of `SliceIndex` have to guarantee that it is.
673        unsafe { &*index.get_unchecked(self) }
674    }
675
676    /// Returns a mutable reference to an element or subslice, without doing
677    /// bounds checking.
678    ///
679    /// For a safe alternative see [`get_mut`].
680    ///
681    /// # Safety
682    ///
683    /// Calling this method with an out-of-bounds index is *[undefined behavior]*
684    /// even if the resulting reference is not used.
685    ///
686    /// You can think of this like `.get_mut(index).unwrap_unchecked()`.  It's
687    /// UB to call `.get_unchecked_mut(len)`, even if you immediately convert
688    /// to a pointer.  And it's UB to call `.get_unchecked_mut(..len + 1)`,
689    /// `.get_unchecked_mut(..=len)`, or similar.
690    ///
691    /// [`get_mut`]: slice::get_mut
692    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
693    ///
694    /// # Examples
695    ///
696    /// ```
697    /// let x = &mut [1, 2, 4];
698    ///
699    /// unsafe {
700    ///     let elem = x.get_unchecked_mut(1);
701    ///     *elem = 13;
702    /// }
703    /// assert_eq!(x, &[1, 13, 4]);
704    /// ```
705    #[ferrocene::prevalidated]
706    #[stable(feature = "rust1", since = "1.0.0")]
707    #[rustc_no_implicit_autorefs]
708    #[inline]
709    #[must_use]
710    #[track_caller]
711    #[rustc_const_unstable(feature = "const_index", issue = "143775")]
712    #[rustc_no_writable]
713    pub const unsafe fn get_unchecked_mut<I>(&mut self, index: I) -> &mut I::Output
714    where
715        I: [const] SliceIndex<Self>,
716    {
717        // SAFETY: the caller must uphold the safety requirements for `get_unchecked_mut`;
718        // the slice is dereferenceable because `self` is a safe reference.
719        // The returned pointer is safe because impls of `SliceIndex` have to guarantee that it is.
720        unsafe { &mut *index.get_unchecked_mut(self) }
721    }
722
723    /// Returns a raw pointer to the slice's buffer.
724    ///
725    /// The caller must ensure that the slice outlives the pointer this
726    /// function returns, or else it will end up dangling.
727    ///
728    /// The caller must also ensure that the memory the pointer (non-transitively) points to
729    /// is never written to (except inside an `UnsafeCell`) using this pointer or any pointer
730    /// derived from it. If you need to mutate the contents of the slice, use [`as_mut_ptr`].
731    ///
732    /// Modifying the container referenced by this slice may cause its buffer
733    /// to be reallocated, which would also make any pointers to it invalid.
734    ///
735    /// # Examples
736    ///
737    /// ```
738    /// let x = &[1, 2, 4];
739    /// let x_ptr = x.as_ptr();
740    ///
741    /// unsafe {
742    ///     for i in 0..x.len() {
743    ///         assert_eq!(x.get_unchecked(i), &*x_ptr.add(i));
744    ///     }
745    /// }
746    /// ```
747    ///
748    /// [`as_mut_ptr`]: slice::as_mut_ptr
749    #[stable(feature = "rust1", since = "1.0.0")]
750    #[rustc_const_stable(feature = "const_slice_as_ptr", since = "1.32.0")]
751    #[rustc_never_returns_null_ptr]
752    #[rustc_as_ptr]
753    #[inline(always)]
754    #[must_use]
755    #[ferrocene::prevalidated]
756    pub const fn as_ptr(&self) -> *const T {
757        self as *const [T] as *const T
758    }
759
760    /// Returns an unsafe mutable pointer to the slice's buffer.
761    ///
762    /// The caller must ensure that the slice outlives the pointer this
763    /// function returns, or else it will end up dangling.
764    ///
765    /// Modifying the container referenced by this slice may cause its buffer
766    /// to be reallocated, which would also make any pointers to it invalid.
767    ///
768    /// # Examples
769    ///
770    /// ```
771    /// let x = &mut [1, 2, 4];
772    /// let x_ptr = x.as_mut_ptr();
773    ///
774    /// unsafe {
775    ///     for i in 0..x.len() {
776    ///         *x_ptr.add(i) += 2;
777    ///     }
778    /// }
779    /// assert_eq!(x, &[3, 4, 6]);
780    /// ```
781    #[ferrocene::prevalidated]
782    #[stable(feature = "rust1", since = "1.0.0")]
783    #[rustc_const_stable(feature = "const_ptr_offset", since = "1.61.0")]
784    #[rustc_never_returns_null_ptr]
785    #[rustc_as_ptr]
786    #[inline(always)]
787    #[must_use]
788    #[rustc_no_writable]
789    pub const fn as_mut_ptr(&mut self) -> *mut T {
790        self as *mut [T] as *mut T
791    }
792
793    /// Returns the two raw pointers spanning the slice.
794    ///
795    /// The returned range is half-open, which means that the end pointer
796    /// points *one past* the last element of the slice. This way, an empty
797    /// slice is represented by two equal pointers, and the difference between
798    /// the two pointers represents the size of the slice.
799    ///
800    /// See [`as_ptr`] for warnings on using these pointers. The end pointer
801    /// requires extra caution, as it does not point to a valid element in the
802    /// slice.
803    ///
804    /// This function is useful for interacting with foreign interfaces which
805    /// use two pointers to refer to a range of elements in memory, as is
806    /// common in C++.
807    ///
808    /// It can also be useful to check if a pointer to an element refers to an
809    /// element of this slice:
810    ///
811    /// ```
812    /// let a = [1, 2, 3];
813    /// let x = &a[1] as *const _;
814    /// let y = &5 as *const _;
815    ///
816    /// assert!(a.as_ptr_range().contains(&x));
817    /// assert!(!a.as_ptr_range().contains(&y));
818    /// ```
819    ///
820    /// [`as_ptr`]: slice::as_ptr
821    #[stable(feature = "slice_ptr_range", since = "1.48.0")]
822    #[rustc_const_stable(feature = "const_ptr_offset", since = "1.61.0")]
823    #[inline]
824    #[must_use]
825    pub const fn as_ptr_range(&self) -> Range<*const T> {
826        let start = self.as_ptr();
827        // SAFETY: The `add` here is safe, because:
828        //
829        //   - Both pointers are part of the same object, as pointing directly
830        //     past the object also counts.
831        //
832        //   - The size of the slice is never larger than `isize::MAX` bytes, as
833        //     noted here:
834        //       - https://github.com/rust-lang/unsafe-code-guidelines/issues/102#issuecomment-473340447
835        //       - https://doc.rust-lang.org/reference/behavior-considered-undefined.html
836        //       - https://doc.rust-lang.org/core/slice/fn.from_raw_parts.html#safety
837        //     (This doesn't seem normative yet, but the very same assumption is
838        //     made in many places, including the Index implementation of slices.)
839        //
840        //   - There is no wrapping around involved, as slices do not wrap past
841        //     the end of the address space.
842        //
843        // See the documentation of [`pointer::add`].
844        let end = unsafe { start.add(self.len()) };
845        start..end
846    }
847
848    /// Returns the two unsafe mutable pointers spanning the slice.
849    ///
850    /// The returned range is half-open, which means that the end pointer
851    /// points *one past* the last element of the slice. This way, an empty
852    /// slice is represented by two equal pointers, and the difference between
853    /// the two pointers represents the size of the slice.
854    ///
855    /// See [`as_mut_ptr`] for warnings on using these pointers. The end
856    /// pointer requires extra caution, as it does not point to a valid element
857    /// in the slice.
858    ///
859    /// This function is useful for interacting with foreign interfaces which
860    /// use two pointers to refer to a range of elements in memory, as is
861    /// common in C++.
862    ///
863    /// [`as_mut_ptr`]: slice::as_mut_ptr
864    #[stable(feature = "slice_ptr_range", since = "1.48.0")]
865    #[rustc_const_stable(feature = "const_ptr_offset", since = "1.61.0")]
866    #[inline]
867    #[must_use]
868    #[ferrocene::prevalidated]
869    pub const fn as_mut_ptr_range(&mut self) -> Range<*mut T> {
870        let start = self.as_mut_ptr();
871        // SAFETY: See as_ptr_range() above for why `add` here is safe.
872        let end = unsafe { start.add(self.len()) };
873        start..end
874    }
875
876    /// Gets a reference to the underlying array.
877    ///
878    /// If `N` is not exactly equal to the length of `self`, then this method returns `None`.
879    #[stable(feature = "core_slice_as_array", since = "1.93.0")]
880    #[rustc_const_stable(feature = "core_slice_as_array", since = "1.93.0")]
881    #[inline]
882    #[must_use]
883    #[ferrocene::prevalidated]
884    pub const fn as_array<const N: usize>(&self) -> Option<&[T; N]> {
885        if self.len() == N {
886            let ptr = self.as_ptr().cast_array();
887
888            // SAFETY: The underlying array of a slice can be reinterpreted as an actual array `[T; N]` if `N` is not greater than the slice's length.
889            let me = unsafe { &*ptr };
890            Some(me)
891        } else {
892            None
893        }
894    }
895
896    /// Gets a mutable reference to the slice's underlying array.
897    ///
898    /// If `N` is not exactly equal to the length of `self`, then this method returns `None`.
899    #[stable(feature = "core_slice_as_array", since = "1.93.0")]
900    #[rustc_const_stable(feature = "core_slice_as_array", since = "1.93.0")]
901    #[inline]
902    #[must_use]
903    #[ferrocene::prevalidated]
904    pub const fn as_mut_array<const N: usize>(&mut self) -> Option<&mut [T; N]> {
905        if self.len() == N {
906            let ptr = self.as_mut_ptr().cast_array();
907
908            // SAFETY: The underlying array of a slice can be reinterpreted as an actual array `[T; N]` if `N` is not greater than the slice's length.
909            let me = unsafe { &mut *ptr };
910            Some(me)
911        } else {
912            None
913        }
914    }
915
916    /// Swaps two elements in the slice.
917    ///
918    /// If `a` equals to `b`, it's guaranteed that elements won't change value.
919    ///
920    /// # Arguments
921    ///
922    /// * a - The index of the first element
923    /// * b - The index of the second element
924    ///
925    /// # Panics
926    ///
927    /// Panics if `a` or `b` are out of bounds.
928    ///
929    /// # Examples
930    ///
931    /// ```
932    /// let mut v = ["a", "b", "c", "d", "e"];
933    /// v.swap(2, 4);
934    /// assert!(v == ["a", "b", "e", "d", "c"]);
935    /// ```
936    #[stable(feature = "rust1", since = "1.0.0")]
937    #[rustc_const_stable(feature = "const_swap", since = "1.85.0")]
938    #[inline]
939    #[track_caller]
940    #[ferrocene::prevalidated]
941    pub const fn swap(&mut self, a: usize, b: usize) {
942        // Bounds checks that panic exactly like indexing would.
943        let _ = &self[a];
944        let _ = &self[b];
945        // SAFETY: `a` and `b` were checked to be in bounds above.
946        unsafe {
947            self.swap_unchecked(a, b);
948        }
949    }
950
951    /// Swaps two elements in the slice, without doing bounds checking.
952    ///
953    /// For a safe alternative see [`swap`].
954    ///
955    /// # Arguments
956    ///
957    /// * a - The index of the first element
958    /// * b - The index of the second element
959    ///
960    /// # Safety
961    ///
962    /// Calling this method with an out-of-bounds index is *[undefined behavior]*.
963    /// The caller has to ensure that `a < self.len()` and `b < self.len()`.
964    ///
965    /// # Examples
966    ///
967    /// ```
968    /// #![feature(slice_swap_unchecked)]
969    ///
970    /// let mut v = ["a", "b", "c", "d"];
971    /// // SAFETY: we know that 1 and 3 are both indices of the slice
972    /// unsafe { v.swap_unchecked(1, 3) };
973    /// assert!(v == ["a", "d", "c", "b"]);
974    /// ```
975    ///
976    /// [`swap`]: slice::swap
977    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
978    #[ferrocene::prevalidated]
979    #[unstable(feature = "slice_swap_unchecked", issue = "88539")]
980    #[track_caller]
981    pub const unsafe fn swap_unchecked(&mut self, a: usize, b: usize) {
982        assert_unsafe_precondition!(
983            check_library_ub,
984            "slice::swap_unchecked requires that the indices are within the slice",
985            (
986                len: usize = self.len(),
987                a: usize = a,
988                b: usize = b,
989            ) => a < len && b < len,
990        );
991
992        let ptr = self.as_mut_ptr();
993        // SAFETY: caller has to guarantee that `a < self.len()` and `b < self.len()`
994        unsafe {
995            ptr::swap(ptr.add(a), ptr.add(b));
996        }
997    }
998
999    /// Reverses the order of elements in the slice, in place.
1000    ///
1001    /// # Examples
1002    ///
1003    /// ```
1004    /// let mut v = [1, 2, 3];
1005    /// v.reverse();
1006    /// assert!(v == [3, 2, 1]);
1007    /// ```
1008    #[stable(feature = "rust1", since = "1.0.0")]
1009    #[rustc_const_stable(feature = "const_slice_reverse", since = "1.90.0")]
1010    #[inline]
1011    #[ferrocene::prevalidated]
1012    pub const fn reverse(&mut self) {
1013        let half_len = self.len() / 2;
1014        let Range { start, end } = self.as_mut_ptr_range();
1015
1016        // These slices will skip the middle item for an odd length,
1017        // since that one doesn't need to move.
1018        let (front_half, back_half) =
1019            // SAFETY: Both are subparts of the original slice, so the memory
1020            // range is valid, and they don't overlap because they're each only
1021            // half (or less) of the original slice.
1022            unsafe {
1023                (
1024                    slice::from_raw_parts_mut(start, half_len),
1025                    slice::from_raw_parts_mut(end.sub(half_len), half_len),
1026                )
1027            };
1028
1029        // Introducing a function boundary here means that the two halves
1030        // get `noalias` markers, allowing better optimization as LLVM
1031        // knows that they're disjoint, unlike in the original slice.
1032        revswap(front_half, back_half, half_len);
1033
1034        #[inline]
1035        #[ferrocene::prevalidated]
1036        const fn revswap<T>(a: &mut [T], b: &mut [T], n: usize) {
1037            debug_assert!(a.len() == n);
1038            debug_assert!(b.len() == n);
1039
1040            // Because this function is first compiled in isolation,
1041            // this check tells LLVM that the indexing below is
1042            // in-bounds. Then after inlining -- once the actual
1043            // lengths of the slices are known -- it's removed.
1044            // FIXME(const_trait_impl) replace with let (a, b) = (&mut a[..n], &mut b[..n]);
1045            let (a, _) = a.split_at_mut(n);
1046            let (b, _) = b.split_at_mut(n);
1047
1048            let mut i = 0;
1049            while i < n {
1050                mem::swap(&mut a[i], &mut b[n - 1 - i]);
1051                i += 1;
1052            }
1053        }
1054    }
1055
1056    /// Returns an iterator over the slice.
1057    ///
1058    /// The iterator yields all items from start to end.
1059    ///
1060    /// # Examples
1061    ///
1062    /// ```
1063    /// let x = &[1, 2, 4];
1064    /// let mut iterator = x.iter();
1065    ///
1066    /// assert_eq!(iterator.next(), Some(&1));
1067    /// assert_eq!(iterator.next(), Some(&2));
1068    /// assert_eq!(iterator.next(), Some(&4));
1069    /// assert_eq!(iterator.next(), None);
1070    /// ```
1071    #[stable(feature = "rust1", since = "1.0.0")]
1072    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1073    #[inline]
1074    #[rustc_diagnostic_item = "slice_iter"]
1075    #[ferrocene::prevalidated]
1076    pub const fn iter(&self) -> Iter<'_, T> {
1077        Iter::new(self)
1078    }
1079
1080    /// Returns an iterator that allows modifying each value.
1081    ///
1082    /// The iterator yields all items from start to end.
1083    ///
1084    /// # Examples
1085    ///
1086    /// ```
1087    /// let x = &mut [1, 2, 4];
1088    /// for elem in x.iter_mut() {
1089    ///     *elem += 2;
1090    /// }
1091    /// assert_eq!(x, &[3, 4, 6]);
1092    /// ```
1093    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1094    #[stable(feature = "rust1", since = "1.0.0")]
1095    #[inline]
1096    #[ferrocene::prevalidated]
1097    pub const fn iter_mut(&mut self) -> IterMut<'_, T> {
1098        IterMut::new(self)
1099    }
1100
1101    /// Returns an iterator over all contiguous windows of length
1102    /// `size`. The windows overlap. If the slice is shorter than
1103    /// `size`, the iterator returns no values.
1104    ///
1105    /// # Panics
1106    ///
1107    /// Panics if `size` is zero.
1108    ///
1109    /// # Examples
1110    ///
1111    /// ```
1112    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1113    /// let mut iter = slice.windows(3);
1114    /// assert_eq!(iter.next().unwrap(), &['l', 'o', 'r']);
1115    /// assert_eq!(iter.next().unwrap(), &['o', 'r', 'e']);
1116    /// assert_eq!(iter.next().unwrap(), &['r', 'e', 'm']);
1117    /// assert!(iter.next().is_none());
1118    /// ```
1119    ///
1120    /// If the slice is shorter than `size`:
1121    ///
1122    /// ```
1123    /// let slice = ['f', 'o', 'o'];
1124    /// let mut iter = slice.windows(4);
1125    /// assert!(iter.next().is_none());
1126    /// ```
1127    ///
1128    /// Because the [Iterator] trait cannot represent the required lifetimes,
1129    /// there is no `windows_mut` analog to `windows`;
1130    /// `[0,1,2].windows_mut(2).collect()` would violate [the rules of references]
1131    /// (though a [LendingIterator] analog is possible). You can sometimes use
1132    /// [`Cell::as_slice_of_cells`](crate::cell::Cell::as_slice_of_cells) in
1133    /// conjunction with `windows` instead:
1134    ///
1135    /// [the rules of references]: https://doc.rust-lang.org/book/ch04-02-references-and-borrowing.html#the-rules-of-references
1136    /// [LendingIterator]: https://blog.rust-lang.org/2022/10/28/gats-stabilization.html
1137    /// ```
1138    /// use std::cell::Cell;
1139    ///
1140    /// let mut array = ['R', 'u', 's', 't', ' ', '2', '0', '1', '5'];
1141    /// let slice = &mut array[..];
1142    /// let slice_of_cells: &[Cell<char>] = Cell::from_mut(slice).as_slice_of_cells();
1143    /// for w in slice_of_cells.windows(3) {
1144    ///     Cell::swap(&w[0], &w[2]);
1145    /// }
1146    /// assert_eq!(array, ['s', 't', ' ', '2', '0', '1', '5', 'u', 'R']);
1147    /// ```
1148    #[stable(feature = "rust1", since = "1.0.0")]
1149    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1150    #[inline]
1151    #[track_caller]
1152    #[ferrocene::prevalidated]
1153    pub const fn windows(&self, size: usize) -> Windows<'_, T> {
1154        let size = NonZero::new(size).expect("window size must be non-zero");
1155        Windows::new(self, size)
1156    }
1157
1158    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the
1159    /// beginning of the slice.
1160    ///
1161    /// The chunks are slices and do not overlap. If `chunk_size` does not divide the length of the
1162    /// slice, then the last chunk will not have length `chunk_size`.
1163    ///
1164    /// See [`chunks_exact`] for a variant of this iterator that returns chunks of always exactly
1165    /// `chunk_size` elements, and [`rchunks`] for the same iterator but starting at the end of the
1166    /// slice.
1167    ///
1168    /// If your `chunk_size` is a constant, consider using [`as_chunks`] instead, which will
1169    /// give references to arrays of exactly that length, rather than slices.
1170    ///
1171    /// # Panics
1172    ///
1173    /// Panics if `chunk_size` is zero.
1174    ///
1175    /// # Examples
1176    ///
1177    /// ```
1178    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1179    /// let mut iter = slice.chunks(2);
1180    /// assert_eq!(iter.next().unwrap(), &['l', 'o']);
1181    /// assert_eq!(iter.next().unwrap(), &['r', 'e']);
1182    /// assert_eq!(iter.next().unwrap(), &['m']);
1183    /// assert!(iter.next().is_none());
1184    /// ```
1185    ///
1186    /// [`chunks_exact`]: slice::chunks_exact
1187    /// [`rchunks`]: slice::rchunks
1188    /// [`as_chunks`]: slice::as_chunks
1189    #[stable(feature = "rust1", since = "1.0.0")]
1190    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1191    #[inline]
1192    #[track_caller]
1193    #[ferrocene::prevalidated]
1194    pub const fn chunks(&self, chunk_size: usize) -> Chunks<'_, T> {
1195        assert!(chunk_size != 0, "chunk size must be non-zero");
1196        Chunks::new(self, chunk_size)
1197    }
1198
1199    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the
1200    /// beginning of the slice.
1201    ///
1202    /// The chunks are mutable slices, and do not overlap. If `chunk_size` does not divide the
1203    /// length of the slice, then the last chunk will not have length `chunk_size`.
1204    ///
1205    /// See [`chunks_exact_mut`] for a variant of this iterator that returns chunks of always
1206    /// exactly `chunk_size` elements, and [`rchunks_mut`] for the same iterator but starting at
1207    /// the end of the slice.
1208    ///
1209    /// If your `chunk_size` is a constant, consider using [`as_chunks_mut`] instead, which will
1210    /// give references to arrays of exactly that length, rather than slices.
1211    ///
1212    /// # Panics
1213    ///
1214    /// Panics if `chunk_size` is zero.
1215    ///
1216    /// # Examples
1217    ///
1218    /// ```
1219    /// let v = &mut [0, 0, 0, 0, 0];
1220    /// let mut count = 1;
1221    ///
1222    /// for chunk in v.chunks_mut(2) {
1223    ///     for elem in chunk.iter_mut() {
1224    ///         *elem += count;
1225    ///     }
1226    ///     count += 1;
1227    /// }
1228    /// assert_eq!(v, &[1, 1, 2, 2, 3]);
1229    /// ```
1230    ///
1231    /// [`chunks_exact_mut`]: slice::chunks_exact_mut
1232    /// [`rchunks_mut`]: slice::rchunks_mut
1233    /// [`as_chunks_mut`]: slice::as_chunks_mut
1234    #[stable(feature = "rust1", since = "1.0.0")]
1235    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1236    #[inline]
1237    #[track_caller]
1238    #[ferrocene::prevalidated]
1239    pub const fn chunks_mut(&mut self, chunk_size: usize) -> ChunksMut<'_, T> {
1240        assert!(chunk_size != 0, "chunk size must be non-zero");
1241        ChunksMut::new(self, chunk_size)
1242    }
1243
1244    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the
1245    /// beginning of the slice.
1246    ///
1247    /// The chunks are slices and do not overlap. If `chunk_size` does not divide the length of the
1248    /// slice, then the last up to `chunk_size-1` elements will be omitted and can be retrieved
1249    /// from the `remainder` function of the iterator.
1250    ///
1251    /// Due to each chunk having exactly `chunk_size` elements, the compiler can often optimize the
1252    /// resulting code better than in the case of [`chunks`].
1253    ///
1254    /// See [`chunks`] for a variant of this iterator that also returns the remainder as a smaller
1255    /// chunk, and [`rchunks_exact`] for the same iterator but starting at the end of the slice.
1256    ///
1257    /// If your `chunk_size` is a constant, consider using [`as_chunks`] instead, which will
1258    /// give references to arrays of exactly that length, rather than slices.
1259    ///
1260    /// # Panics
1261    ///
1262    /// Panics if `chunk_size` is zero.
1263    ///
1264    /// # Examples
1265    ///
1266    /// ```
1267    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1268    /// let mut iter = slice.chunks_exact(2);
1269    /// assert_eq!(iter.next().unwrap(), &['l', 'o']);
1270    /// assert_eq!(iter.next().unwrap(), &['r', 'e']);
1271    /// assert!(iter.next().is_none());
1272    /// assert_eq!(iter.remainder(), &['m']);
1273    /// ```
1274    ///
1275    /// [`chunks`]: slice::chunks
1276    /// [`rchunks_exact`]: slice::rchunks_exact
1277    /// [`as_chunks`]: slice::as_chunks
1278    #[stable(feature = "chunks_exact", since = "1.31.0")]
1279    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1280    #[inline]
1281    #[track_caller]
1282    #[ferrocene::prevalidated]
1283    pub const fn chunks_exact(&self, chunk_size: usize) -> ChunksExact<'_, T> {
1284        assert!(chunk_size != 0, "chunk size must be non-zero");
1285        ChunksExact::new(self, chunk_size)
1286    }
1287
1288    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the
1289    /// beginning of the slice.
1290    ///
1291    /// The chunks are mutable slices, and do not overlap. If `chunk_size` does not divide the
1292    /// length of the slice, then the last up to `chunk_size-1` elements will be omitted and can be
1293    /// retrieved from the `into_remainder` function of the iterator.
1294    ///
1295    /// Due to each chunk having exactly `chunk_size` elements, the compiler can often optimize the
1296    /// resulting code better than in the case of [`chunks_mut`].
1297    ///
1298    /// See [`chunks_mut`] for a variant of this iterator that also returns the remainder as a
1299    /// smaller chunk, and [`rchunks_exact_mut`] for the same iterator but starting at the end of
1300    /// the slice.
1301    ///
1302    /// If your `chunk_size` is a constant, consider using [`as_chunks_mut`] instead, which will
1303    /// give references to arrays of exactly that length, rather than slices.
1304    ///
1305    /// # Panics
1306    ///
1307    /// Panics if `chunk_size` is zero.
1308    ///
1309    /// # Examples
1310    ///
1311    /// ```
1312    /// let v = &mut [0, 0, 0, 0, 0];
1313    /// let mut count = 1;
1314    ///
1315    /// for chunk in v.chunks_exact_mut(2) {
1316    ///     for elem in chunk.iter_mut() {
1317    ///         *elem += count;
1318    ///     }
1319    ///     count += 1;
1320    /// }
1321    /// assert_eq!(v, &[1, 1, 2, 2, 0]);
1322    /// ```
1323    ///
1324    /// [`chunks_mut`]: slice::chunks_mut
1325    /// [`rchunks_exact_mut`]: slice::rchunks_exact_mut
1326    /// [`as_chunks_mut`]: slice::as_chunks_mut
1327    #[stable(feature = "chunks_exact", since = "1.31.0")]
1328    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1329    #[inline]
1330    #[track_caller]
1331    #[ferrocene::prevalidated]
1332    pub const fn chunks_exact_mut(&mut self, chunk_size: usize) -> ChunksExactMut<'_, T> {
1333        assert!(chunk_size != 0, "chunk size must be non-zero");
1334        ChunksExactMut::new(self, chunk_size)
1335    }
1336
1337    /// Splits the slice into a slice of `N`-element arrays,
1338    /// assuming that there's no remainder.
1339    ///
1340    /// This is the inverse operation to [`as_flattened`].
1341    ///
1342    /// [`as_flattened`]: slice::as_flattened
1343    ///
1344    /// As this is `unsafe`, consider whether you could use [`as_chunks`] or
1345    /// [`as_rchunks`] instead, perhaps via something like
1346    /// `if let (chunks, []) = slice.as_chunks()` or
1347    /// `let (chunks, []) = slice.as_chunks() else { unreachable!() };`.
1348    ///
1349    /// [`as_chunks`]: slice::as_chunks
1350    /// [`as_rchunks`]: slice::as_rchunks
1351    ///
1352    /// # Safety
1353    ///
1354    /// This may only be called when
1355    /// - The slice splits exactly into `N`-element chunks (aka `self.len() % N == 0`).
1356    /// - `N != 0`.
1357    ///
1358    /// # Examples
1359    ///
1360    /// ```
1361    /// let slice: &[char] = &['l', 'o', 'r', 'e', 'm', '!'];
1362    /// let chunks: &[[char; 1]] =
1363    ///     // SAFETY: 1-element chunks never have remainder
1364    ///     unsafe { slice.as_chunks_unchecked() };
1365    /// assert_eq!(chunks, &[['l'], ['o'], ['r'], ['e'], ['m'], ['!']]);
1366    /// let chunks: &[[char; 3]] =
1367    ///     // SAFETY: The slice length (6) is a multiple of 3
1368    ///     unsafe { slice.as_chunks_unchecked() };
1369    /// assert_eq!(chunks, &[['l', 'o', 'r'], ['e', 'm', '!']]);
1370    ///
1371    /// // These would be unsound:
1372    /// // let chunks: &[[_; 5]] = slice.as_chunks_unchecked() // The slice length is not a multiple of 5
1373    /// // let chunks: &[[_; 0]] = slice.as_chunks_unchecked() // Zero-length chunks are never allowed
1374    /// ```
1375    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1376    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1377    #[inline]
1378    #[must_use]
1379    #[track_caller]
1380    #[ferrocene::prevalidated]
1381    pub const unsafe fn as_chunks_unchecked<const N: usize>(&self) -> &[[T; N]] {
1382        assert_unsafe_precondition!(
1383            check_language_ub,
1384            "slice::as_chunks_unchecked requires `N != 0` and the slice to split exactly into `N`-element chunks",
1385            (n: usize = N, len: usize = self.len()) => n != 0 && len.is_multiple_of(n),
1386        );
1387        // SAFETY: Caller must guarantee that `N` is nonzero and exactly divides the slice length
1388        let new_len = unsafe { exact_div(self.len(), N) };
1389        // SAFETY: We cast a slice of `new_len * N` elements into
1390        // a slice of `new_len` many `N` elements chunks.
1391        unsafe { from_raw_parts(self.as_ptr().cast(), new_len) }
1392    }
1393
1394    /// Splits the slice into a slice of `N`-element arrays,
1395    /// starting at the beginning of the slice,
1396    /// and a remainder slice with length strictly less than `N`.
1397    ///
1398    /// The remainder is meaningful in the division sense.  Given
1399    /// `let (chunks, remainder) = slice.as_chunks()`, then:
1400    /// - `chunks.len()` equals `slice.len() / N`,
1401    /// - `remainder.len()` equals `slice.len() % N`, and
1402    /// - `slice.len()` equals `chunks.len() * N + remainder.len()`.
1403    ///
1404    /// You can flatten the chunks back into a slice-of-`T` with [`as_flattened`].
1405    ///
1406    /// [`as_flattened`]: slice::as_flattened
1407    ///
1408    /// # Panics
1409    ///
1410    /// Panics if `N` is zero.
1411    ///
1412    /// Note that this check is against a const generic parameter, not a runtime
1413    /// value, and thus a particular monomorphization will either always panic
1414    /// or it will never panic.
1415    ///
1416    /// # Examples
1417    ///
1418    /// ```
1419    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1420    /// let (chunks, remainder) = slice.as_chunks();
1421    /// assert_eq!(chunks, &[['l', 'o'], ['r', 'e']]);
1422    /// assert_eq!(remainder, &['m']);
1423    /// ```
1424    ///
1425    /// If you expect the slice to be an exact multiple, you can combine
1426    /// `let`-`else` with an empty slice pattern:
1427    /// ```
1428    /// let slice = ['R', 'u', 's', 't'];
1429    /// let (chunks, []) = slice.as_chunks::<2>() else {
1430    ///     panic!("slice didn't have even length")
1431    /// };
1432    /// assert_eq!(chunks, &[['R', 'u'], ['s', 't']]);
1433    /// ```
1434    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1435    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1436    #[inline]
1437    #[track_caller]
1438    #[must_use]
1439    #[ferrocene::prevalidated]
1440    pub const fn as_chunks<const N: usize>(&self) -> (&[[T; N]], &[T]) {
1441        assert!(N != 0, "chunk size must be non-zero");
1442        let len_rounded_down = self.len() / N * N;
1443        // SAFETY: The rounded-down value is always the same or smaller than the
1444        // original length, and thus must be in-bounds of the slice.
1445        let (multiple_of_n, remainder) = unsafe { self.split_at_unchecked(len_rounded_down) };
1446        // SAFETY: We already panicked for zero, and ensured by construction
1447        // that the length of the subslice is a multiple of N.
1448        let array_slice = unsafe { multiple_of_n.as_chunks_unchecked() };
1449        (array_slice, remainder)
1450    }
1451
1452    /// Splits the slice into a slice of `N`-element arrays,
1453    /// starting at the end of the slice,
1454    /// and a remainder slice with length strictly less than `N`.
1455    ///
1456    /// The remainder is meaningful in the division sense.  Given
1457    /// `let (remainder, chunks) = slice.as_rchunks()`, then:
1458    /// - `remainder.len()` equals `slice.len() % N`,
1459    /// - `chunks.len()` equals `slice.len() / N`, and
1460    /// - `slice.len()` equals `chunks.len() * N + remainder.len()`.
1461    ///
1462    /// You can flatten the chunks back into a slice-of-`T` with [`as_flattened`].
1463    ///
1464    /// [`as_flattened`]: slice::as_flattened
1465    ///
1466    /// # Panics
1467    ///
1468    /// Panics if `N` is zero.
1469    ///
1470    /// Note that this check is against a const generic parameter, not a runtime
1471    /// value, and thus a particular monomorphization will either always panic
1472    /// or it will never panic.
1473    ///
1474    /// # Examples
1475    ///
1476    /// ```
1477    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1478    /// let (remainder, chunks) = slice.as_rchunks();
1479    /// assert_eq!(remainder, &['l']);
1480    /// assert_eq!(chunks, &[['o', 'r'], ['e', 'm']]);
1481    /// ```
1482    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1483    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1484    #[inline]
1485    #[track_caller]
1486    #[must_use]
1487    pub const fn as_rchunks<const N: usize>(&self) -> (&[T], &[[T; N]]) {
1488        assert!(N != 0, "chunk size must be non-zero");
1489        let len = self.len() / N;
1490        let (remainder, multiple_of_n) = self.split_at(self.len() - len * N);
1491        // SAFETY: We already panicked for zero, and ensured by construction
1492        // that the length of the subslice is a multiple of N.
1493        let array_slice = unsafe { multiple_of_n.as_chunks_unchecked() };
1494        (remainder, array_slice)
1495    }
1496
1497    /// Splits the slice into a slice of `N`-element arrays,
1498    /// assuming that there's no remainder.
1499    ///
1500    /// This is the inverse operation to [`as_flattened_mut`].
1501    ///
1502    /// [`as_flattened_mut`]: slice::as_flattened_mut
1503    ///
1504    /// As this is `unsafe`, consider whether you could use [`as_chunks_mut`] or
1505    /// [`as_rchunks_mut`] instead, perhaps via something like
1506    /// `if let (chunks, []) = slice.as_chunks_mut()` or
1507    /// `let (chunks, []) = slice.as_chunks_mut() else { unreachable!() };`.
1508    ///
1509    /// [`as_chunks_mut`]: slice::as_chunks_mut
1510    /// [`as_rchunks_mut`]: slice::as_rchunks_mut
1511    ///
1512    /// # Safety
1513    ///
1514    /// This may only be called when
1515    /// - The slice splits exactly into `N`-element chunks (aka `self.len() % N == 0`).
1516    /// - `N != 0`.
1517    ///
1518    /// # Examples
1519    ///
1520    /// ```
1521    /// let slice: &mut [char] = &mut ['l', 'o', 'r', 'e', 'm', '!'];
1522    /// let chunks: &mut [[char; 1]] =
1523    ///     // SAFETY: 1-element chunks never have remainder
1524    ///     unsafe { slice.as_chunks_unchecked_mut() };
1525    /// chunks[0] = ['L'];
1526    /// assert_eq!(chunks, &[['L'], ['o'], ['r'], ['e'], ['m'], ['!']]);
1527    /// let chunks: &mut [[char; 3]] =
1528    ///     // SAFETY: The slice length (6) is a multiple of 3
1529    ///     unsafe { slice.as_chunks_unchecked_mut() };
1530    /// chunks[1] = ['a', 'x', '?'];
1531    /// assert_eq!(slice, &['L', 'o', 'r', 'a', 'x', '?']);
1532    ///
1533    /// // These would be unsound:
1534    /// // let chunks: &[[_; 5]] = slice.as_chunks_unchecked_mut() // The slice length is not a multiple of 5
1535    /// // let chunks: &[[_; 0]] = slice.as_chunks_unchecked_mut() // Zero-length chunks are never allowed
1536    /// ```
1537    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1538    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1539    #[inline]
1540    #[must_use]
1541    #[track_caller]
1542    pub const unsafe fn as_chunks_unchecked_mut<const N: usize>(&mut self) -> &mut [[T; N]] {
1543        assert_unsafe_precondition!(
1544            check_language_ub,
1545            "slice::as_chunks_unchecked requires `N != 0` and the slice to split exactly into `N`-element chunks",
1546            (n: usize = N, len: usize = self.len()) => n != 0 && len.is_multiple_of(n)
1547        );
1548        // SAFETY: Caller must guarantee that `N` is nonzero and exactly divides the slice length
1549        let new_len = unsafe { exact_div(self.len(), N) };
1550        // SAFETY: We cast a slice of `new_len * N` elements into
1551        // a slice of `new_len` many `N` elements chunks.
1552        unsafe { from_raw_parts_mut(self.as_mut_ptr().cast(), new_len) }
1553    }
1554
1555    /// Splits the slice into a slice of `N`-element arrays,
1556    /// starting at the beginning of the slice,
1557    /// and a remainder slice with length strictly less than `N`.
1558    ///
1559    /// The remainder is meaningful in the division sense.  Given
1560    /// `let (chunks, remainder) = slice.as_chunks_mut()`, then:
1561    /// - `chunks.len()` equals `slice.len() / N`,
1562    /// - `remainder.len()` equals `slice.len() % N`, and
1563    /// - `slice.len()` equals `chunks.len() * N + remainder.len()`.
1564    ///
1565    /// You can flatten the chunks back into a slice-of-`T` with [`as_flattened_mut`].
1566    ///
1567    /// [`as_flattened_mut`]: slice::as_flattened_mut
1568    ///
1569    /// # Panics
1570    ///
1571    /// Panics if `N` is zero.
1572    ///
1573    /// Note that this check is against a const generic parameter, not a runtime
1574    /// value, and thus a particular monomorphization will either always panic
1575    /// or it will never panic.
1576    ///
1577    /// # Examples
1578    ///
1579    /// ```
1580    /// let v = &mut [0, 0, 0, 0, 0];
1581    /// let mut count = 1;
1582    ///
1583    /// let (chunks, remainder) = v.as_chunks_mut();
1584    /// remainder[0] = 9;
1585    /// for chunk in chunks {
1586    ///     *chunk = [count; 2];
1587    ///     count += 1;
1588    /// }
1589    /// assert_eq!(v, &[1, 1, 2, 2, 9]);
1590    /// ```
1591    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1592    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1593    #[inline]
1594    #[track_caller]
1595    #[must_use]
1596    pub const fn as_chunks_mut<const N: usize>(&mut self) -> (&mut [[T; N]], &mut [T]) {
1597        assert!(N != 0, "chunk size must be non-zero");
1598        let len_rounded_down = self.len() / N * N;
1599        // SAFETY: The rounded-down value is always the same or smaller than the
1600        // original length, and thus must be in-bounds of the slice.
1601        let (multiple_of_n, remainder) = unsafe { self.split_at_mut_unchecked(len_rounded_down) };
1602        // SAFETY: We already panicked for zero, and ensured by construction
1603        // that the length of the subslice is a multiple of N.
1604        let array_slice = unsafe { multiple_of_n.as_chunks_unchecked_mut() };
1605        (array_slice, remainder)
1606    }
1607
1608    /// Splits the slice into a slice of `N`-element arrays,
1609    /// starting at the end of the slice,
1610    /// and a remainder slice with length strictly less than `N`.
1611    ///
1612    /// The remainder is meaningful in the division sense.  Given
1613    /// `let (remainder, chunks) = slice.as_rchunks_mut()`, then:
1614    /// - `remainder.len()` equals `slice.len() % N`,
1615    /// - `chunks.len()` equals `slice.len() / N`, and
1616    /// - `slice.len()` equals `chunks.len() * N + remainder.len()`.
1617    ///
1618    /// You can flatten the chunks back into a slice-of-`T` with [`as_flattened_mut`].
1619    ///
1620    /// [`as_flattened_mut`]: slice::as_flattened_mut
1621    ///
1622    /// # Panics
1623    ///
1624    /// Panics if `N` is zero.
1625    ///
1626    /// Note that this check is against a const generic parameter, not a runtime
1627    /// value, and thus a particular monomorphization will either always panic
1628    /// or it will never panic.
1629    ///
1630    /// # Examples
1631    ///
1632    /// ```
1633    /// let v = &mut [0, 0, 0, 0, 0];
1634    /// let mut count = 1;
1635    ///
1636    /// let (remainder, chunks) = v.as_rchunks_mut();
1637    /// remainder[0] = 9;
1638    /// for chunk in chunks {
1639    ///     *chunk = [count; 2];
1640    ///     count += 1;
1641    /// }
1642    /// assert_eq!(v, &[9, 1, 1, 2, 2]);
1643    /// ```
1644    #[stable(feature = "slice_as_chunks", since = "1.88.0")]
1645    #[rustc_const_stable(feature = "slice_as_chunks", since = "1.88.0")]
1646    #[inline]
1647    #[track_caller]
1648    #[must_use]
1649    pub const fn as_rchunks_mut<const N: usize>(&mut self) -> (&mut [T], &mut [[T; N]]) {
1650        assert!(N != 0, "chunk size must be non-zero");
1651        let len = self.len() / N;
1652        let (remainder, multiple_of_n) = self.split_at_mut(self.len() - len * N);
1653        // SAFETY: We already panicked for zero, and ensured by construction
1654        // that the length of the subslice is a multiple of N.
1655        let array_slice = unsafe { multiple_of_n.as_chunks_unchecked_mut() };
1656        (remainder, array_slice)
1657    }
1658
1659    /// Returns an iterator over overlapping windows of `N` elements of a slice,
1660    /// starting at the beginning of the slice.
1661    ///
1662    /// This is the const generic equivalent of [`windows`].
1663    ///
1664    /// If `N` is greater than the size of the slice, it will return no windows.
1665    ///
1666    /// # Panics
1667    ///
1668    /// Panics if `N` is zero.
1669    ///
1670    /// Note that this check is against a const generic parameter, not a runtime
1671    /// value, and thus a particular monomorphization will either always panic
1672    /// or it will never panic.
1673    ///
1674    /// # Examples
1675    ///
1676    /// ```
1677    /// let slice = [0, 1, 2, 3];
1678    /// let mut iter = slice.array_windows();
1679    /// assert_eq!(iter.next().unwrap(), &[0, 1]);
1680    /// assert_eq!(iter.next().unwrap(), &[1, 2]);
1681    /// assert_eq!(iter.next().unwrap(), &[2, 3]);
1682    /// assert!(iter.next().is_none());
1683    /// ```
1684    ///
1685    /// [`windows`]: slice::windows
1686    #[stable(feature = "array_windows", since = "1.94.0")]
1687    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1688    #[inline]
1689    #[track_caller]
1690    pub const fn array_windows<const N: usize>(&self) -> ArrayWindows<'_, T, N> {
1691        assert!(N != 0, "window size must be non-zero");
1692        ArrayWindows::new(self)
1693    }
1694
1695    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the end
1696    /// of the slice.
1697    ///
1698    /// The chunks are slices and do not overlap. If `chunk_size` does not divide the length of the
1699    /// slice, then the last chunk will not have length `chunk_size`.
1700    ///
1701    /// See [`rchunks_exact`] for a variant of this iterator that returns chunks of always exactly
1702    /// `chunk_size` elements, and [`chunks`] for the same iterator but starting at the beginning
1703    /// of the slice.
1704    ///
1705    /// If your `chunk_size` is a constant, consider using [`as_rchunks`] instead, which will
1706    /// give references to arrays of exactly that length, rather than slices.
1707    ///
1708    /// # Panics
1709    ///
1710    /// Panics if `chunk_size` is zero.
1711    ///
1712    /// # Examples
1713    ///
1714    /// ```
1715    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1716    /// let mut iter = slice.rchunks(2);
1717    /// assert_eq!(iter.next().unwrap(), &['e', 'm']);
1718    /// assert_eq!(iter.next().unwrap(), &['o', 'r']);
1719    /// assert_eq!(iter.next().unwrap(), &['l']);
1720    /// assert!(iter.next().is_none());
1721    /// ```
1722    ///
1723    /// [`rchunks_exact`]: slice::rchunks_exact
1724    /// [`chunks`]: slice::chunks
1725    /// [`as_rchunks`]: slice::as_rchunks
1726    #[stable(feature = "rchunks", since = "1.31.0")]
1727    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1728    #[inline]
1729    #[track_caller]
1730    pub const fn rchunks(&self, chunk_size: usize) -> RChunks<'_, T> {
1731        assert!(chunk_size != 0, "chunk size must be non-zero");
1732        RChunks::new(self, chunk_size)
1733    }
1734
1735    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the end
1736    /// of the slice.
1737    ///
1738    /// The chunks are mutable slices, and do not overlap. If `chunk_size` does not divide the
1739    /// length of the slice, then the last chunk will not have length `chunk_size`.
1740    ///
1741    /// See [`rchunks_exact_mut`] for a variant of this iterator that returns chunks of always
1742    /// exactly `chunk_size` elements, and [`chunks_mut`] for the same iterator but starting at the
1743    /// beginning of the slice.
1744    ///
1745    /// If your `chunk_size` is a constant, consider using [`as_rchunks_mut`] instead, which will
1746    /// give references to arrays of exactly that length, rather than slices.
1747    ///
1748    /// # Panics
1749    ///
1750    /// Panics if `chunk_size` is zero.
1751    ///
1752    /// # Examples
1753    ///
1754    /// ```
1755    /// let v = &mut [0, 0, 0, 0, 0];
1756    /// let mut count = 1;
1757    ///
1758    /// for chunk in v.rchunks_mut(2) {
1759    ///     for elem in chunk.iter_mut() {
1760    ///         *elem += count;
1761    ///     }
1762    ///     count += 1;
1763    /// }
1764    /// assert_eq!(v, &[3, 2, 2, 1, 1]);
1765    /// ```
1766    ///
1767    /// [`rchunks_exact_mut`]: slice::rchunks_exact_mut
1768    /// [`chunks_mut`]: slice::chunks_mut
1769    /// [`as_rchunks_mut`]: slice::as_rchunks_mut
1770    #[stable(feature = "rchunks", since = "1.31.0")]
1771    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1772    #[inline]
1773    #[track_caller]
1774    pub const fn rchunks_mut(&mut self, chunk_size: usize) -> RChunksMut<'_, T> {
1775        assert!(chunk_size != 0, "chunk size must be non-zero");
1776        RChunksMut::new(self, chunk_size)
1777    }
1778
1779    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the
1780    /// end of the slice.
1781    ///
1782    /// The chunks are slices and do not overlap. If `chunk_size` does not divide the length of the
1783    /// slice, then the last up to `chunk_size-1` elements will be omitted and can be retrieved
1784    /// from the `remainder` function of the iterator.
1785    ///
1786    /// Due to each chunk having exactly `chunk_size` elements, the compiler can often optimize the
1787    /// resulting code better than in the case of [`rchunks`].
1788    ///
1789    /// See [`rchunks`] for a variant of this iterator that also returns the remainder as a smaller
1790    /// chunk, and [`chunks_exact`] for the same iterator but starting at the beginning of the
1791    /// slice.
1792    ///
1793    /// If your `chunk_size` is a constant, consider using [`as_rchunks`] instead, which will
1794    /// give references to arrays of exactly that length, rather than slices.
1795    ///
1796    /// # Panics
1797    ///
1798    /// Panics if `chunk_size` is zero.
1799    ///
1800    /// # Examples
1801    ///
1802    /// ```
1803    /// let slice = ['l', 'o', 'r', 'e', 'm'];
1804    /// let mut iter = slice.rchunks_exact(2);
1805    /// assert_eq!(iter.next().unwrap(), &['e', 'm']);
1806    /// assert_eq!(iter.next().unwrap(), &['o', 'r']);
1807    /// assert!(iter.next().is_none());
1808    /// assert_eq!(iter.remainder(), &['l']);
1809    /// ```
1810    ///
1811    /// [`chunks`]: slice::chunks
1812    /// [`rchunks`]: slice::rchunks
1813    /// [`chunks_exact`]: slice::chunks_exact
1814    /// [`as_rchunks`]: slice::as_rchunks
1815    #[stable(feature = "rchunks", since = "1.31.0")]
1816    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1817    #[inline]
1818    #[track_caller]
1819    pub const fn rchunks_exact(&self, chunk_size: usize) -> RChunksExact<'_, T> {
1820        assert!(chunk_size != 0, "chunk size must be non-zero");
1821        RChunksExact::new(self, chunk_size)
1822    }
1823
1824    /// Returns an iterator over `chunk_size` elements of the slice at a time, starting at the end
1825    /// of the slice.
1826    ///
1827    /// The chunks are mutable slices, and do not overlap. If `chunk_size` does not divide the
1828    /// length of the slice, then the last up to `chunk_size-1` elements will be omitted and can be
1829    /// retrieved from the `into_remainder` function of the iterator.
1830    ///
1831    /// Due to each chunk having exactly `chunk_size` elements, the compiler can often optimize the
1832    /// resulting code better than in the case of [`chunks_mut`].
1833    ///
1834    /// See [`rchunks_mut`] for a variant of this iterator that also returns the remainder as a
1835    /// smaller chunk, and [`chunks_exact_mut`] for the same iterator but starting at the beginning
1836    /// of the slice.
1837    ///
1838    /// If your `chunk_size` is a constant, consider using [`as_rchunks_mut`] instead, which will
1839    /// give references to arrays of exactly that length, rather than slices.
1840    ///
1841    /// # Panics
1842    ///
1843    /// Panics if `chunk_size` is zero.
1844    ///
1845    /// # Examples
1846    ///
1847    /// ```
1848    /// let v = &mut [0, 0, 0, 0, 0];
1849    /// let mut count = 1;
1850    ///
1851    /// for chunk in v.rchunks_exact_mut(2) {
1852    ///     for elem in chunk.iter_mut() {
1853    ///         *elem += count;
1854    ///     }
1855    ///     count += 1;
1856    /// }
1857    /// assert_eq!(v, &[0, 2, 2, 1, 1]);
1858    /// ```
1859    ///
1860    /// [`chunks_mut`]: slice::chunks_mut
1861    /// [`rchunks_mut`]: slice::rchunks_mut
1862    /// [`chunks_exact_mut`]: slice::chunks_exact_mut
1863    /// [`as_rchunks_mut`]: slice::as_rchunks_mut
1864    #[stable(feature = "rchunks", since = "1.31.0")]
1865    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1866    #[inline]
1867    #[track_caller]
1868    pub const fn rchunks_exact_mut(&mut self, chunk_size: usize) -> RChunksExactMut<'_, T> {
1869        assert!(chunk_size != 0, "chunk size must be non-zero");
1870        RChunksExactMut::new(self, chunk_size)
1871    }
1872
1873    /// Returns an iterator over the slice producing non-overlapping runs
1874    /// of elements using the predicate to separate them.
1875    ///
1876    /// The predicate is called for every pair of consecutive elements,
1877    /// meaning that it is called on `slice[0]` and `slice[1]`,
1878    /// followed by `slice[1]` and `slice[2]`, and so on.
1879    ///
1880    /// # Examples
1881    ///
1882    /// ```
1883    /// let slice = &[1, 1, 1, 3, 3, 2, 2, 2];
1884    ///
1885    /// let mut iter = slice.chunk_by(|a, b| a == b);
1886    ///
1887    /// assert_eq!(iter.next(), Some(&[1, 1, 1][..]));
1888    /// assert_eq!(iter.next(), Some(&[3, 3][..]));
1889    /// assert_eq!(iter.next(), Some(&[2, 2, 2][..]));
1890    /// assert_eq!(iter.next(), None);
1891    /// ```
1892    ///
1893    /// This method can be used to extract the sorted subslices:
1894    ///
1895    /// ```
1896    /// let slice = &[1, 1, 2, 3, 2, 3, 2, 3, 4];
1897    ///
1898    /// let mut iter = slice.chunk_by(|a, b| a <= b);
1899    ///
1900    /// assert_eq!(iter.next(), Some(&[1, 1, 2, 3][..]));
1901    /// assert_eq!(iter.next(), Some(&[2, 3][..]));
1902    /// assert_eq!(iter.next(), Some(&[2, 3, 4][..]));
1903    /// assert_eq!(iter.next(), None);
1904    /// ```
1905    #[stable(feature = "slice_group_by", since = "1.77.0")]
1906    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1907    #[inline]
1908    pub const fn chunk_by<F>(&self, pred: F) -> ChunkBy<'_, T, F>
1909    where
1910        F: FnMut(&T, &T) -> bool,
1911    {
1912        ChunkBy::new(self, pred)
1913    }
1914
1915    /// Returns an iterator over the slice producing non-overlapping mutable
1916    /// runs of elements using the predicate to separate them.
1917    ///
1918    /// The predicate is called for every pair of consecutive elements,
1919    /// meaning that it is called on `slice[0]` and `slice[1]`,
1920    /// followed by `slice[1]` and `slice[2]`, and so on.
1921    ///
1922    /// # Examples
1923    ///
1924    /// ```
1925    /// let slice = &mut [1, 1, 1, 3, 3, 2, 2, 2];
1926    ///
1927    /// let mut iter = slice.chunk_by_mut(|a, b| a == b);
1928    ///
1929    /// assert_eq!(iter.next(), Some(&mut [1, 1, 1][..]));
1930    /// assert_eq!(iter.next(), Some(&mut [3, 3][..]));
1931    /// assert_eq!(iter.next(), Some(&mut [2, 2, 2][..]));
1932    /// assert_eq!(iter.next(), None);
1933    /// ```
1934    ///
1935    /// This method can be used to extract the sorted subslices:
1936    ///
1937    /// ```
1938    /// let slice = &mut [1, 1, 2, 3, 2, 3, 2, 3, 4];
1939    ///
1940    /// let mut iter = slice.chunk_by_mut(|a, b| a <= b);
1941    ///
1942    /// assert_eq!(iter.next(), Some(&mut [1, 1, 2, 3][..]));
1943    /// assert_eq!(iter.next(), Some(&mut [2, 3][..]));
1944    /// assert_eq!(iter.next(), Some(&mut [2, 3, 4][..]));
1945    /// assert_eq!(iter.next(), None);
1946    /// ```
1947    #[stable(feature = "slice_group_by", since = "1.77.0")]
1948    #[rustc_const_unstable(feature = "const_slice_make_iter", issue = "137737")]
1949    #[inline]
1950    pub const fn chunk_by_mut<F>(&mut self, pred: F) -> ChunkByMut<'_, T, F>
1951    where
1952        F: FnMut(&T, &T) -> bool,
1953    {
1954        ChunkByMut::new(self, pred)
1955    }
1956
1957    /// Divides one slice into two at an index.
1958    ///
1959    /// The first will contain all indices from `[0, mid)` (excluding
1960    /// the index `mid` itself) and the second will contain all
1961    /// indices from `[mid, len)` (excluding the index `len` itself).
1962    ///
1963    /// # Panics
1964    ///
1965    /// Panics if `mid > len`.  For a non-panicking alternative see
1966    /// [`split_at_checked`](slice::split_at_checked).
1967    ///
1968    /// # Examples
1969    ///
1970    /// ```
1971    /// let v = ['a', 'b', 'c'];
1972    ///
1973    /// {
1974    ///    let (left, right) = v.split_at(0);
1975    ///    assert_eq!(left, []);
1976    ///    assert_eq!(right, ['a', 'b', 'c']);
1977    /// }
1978    ///
1979    /// {
1980    ///     let (left, right) = v.split_at(2);
1981    ///     assert_eq!(left, ['a', 'b']);
1982    ///     assert_eq!(right, ['c']);
1983    /// }
1984    ///
1985    /// {
1986    ///     let (left, right) = v.split_at(3);
1987    ///     assert_eq!(left, ['a', 'b', 'c']);
1988    ///     assert_eq!(right, []);
1989    /// }
1990    /// ```
1991    #[stable(feature = "rust1", since = "1.0.0")]
1992    #[rustc_const_stable(feature = "const_slice_split_at_not_mut", since = "1.71.0")]
1993    #[inline]
1994    #[track_caller]
1995    #[must_use]
1996    #[ferrocene::prevalidated]
1997    pub const fn split_at(&self, mid: usize) -> (&[T], &[T]) {
1998        match self.split_at_checked(mid) {
1999            Some(pair) => pair,
2000            None => panic!("mid > len"),
2001        }
2002    }
2003
2004    /// Divides one mutable slice into two at an index.
2005    ///
2006    /// The first will contain all indices from `[0, mid)` (excluding
2007    /// the index `mid` itself) and the second will contain all
2008    /// indices from `[mid, len)` (excluding the index `len` itself).
2009    ///
2010    /// # Panics
2011    ///
2012    /// Panics if `mid > len`.  For a non-panicking alternative see
2013    /// [`split_at_mut_checked`](slice::split_at_mut_checked).
2014    ///
2015    /// # Examples
2016    ///
2017    /// ```
2018    /// let mut v = [1, 0, 3, 0, 5, 6];
2019    /// let (left, right) = v.split_at_mut(2);
2020    /// assert_eq!(left, [1, 0]);
2021    /// assert_eq!(right, [3, 0, 5, 6]);
2022    /// left[1] = 2;
2023    /// right[1] = 4;
2024    /// assert_eq!(v, [1, 2, 3, 4, 5, 6]);
2025    /// ```
2026    #[stable(feature = "rust1", since = "1.0.0")]
2027    #[inline]
2028    #[track_caller]
2029    #[must_use]
2030    #[rustc_const_stable(feature = "const_slice_split_at_mut", since = "1.83.0")]
2031    #[ferrocene::prevalidated]
2032    pub const fn split_at_mut(&mut self, mid: usize) -> (&mut [T], &mut [T]) {
2033        match self.split_at_mut_checked(mid) {
2034            Some(pair) => pair,
2035            None => panic!("mid > len"),
2036        }
2037    }
2038
2039    /// Divides one slice into two at an index, without doing bounds checking.
2040    ///
2041    /// The first will contain all indices from `[0, mid)` (excluding
2042    /// the index `mid` itself) and the second will contain all
2043    /// indices from `[mid, len)` (excluding the index `len` itself).
2044    ///
2045    /// For a safe alternative see [`split_at`].
2046    ///
2047    /// # Safety
2048    ///
2049    /// Calling this method with an out-of-bounds index is *[undefined behavior]*
2050    /// even if the resulting reference is not used. The caller has to ensure that
2051    /// `0 <= mid <= self.len()`.
2052    ///
2053    /// [`split_at`]: slice::split_at
2054    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
2055    ///
2056    /// # Examples
2057    ///
2058    /// ```
2059    /// let v = ['a', 'b', 'c'];
2060    ///
2061    /// unsafe {
2062    ///    let (left, right) = v.split_at_unchecked(0);
2063    ///    assert_eq!(left, []);
2064    ///    assert_eq!(right, ['a', 'b', 'c']);
2065    /// }
2066    ///
2067    /// unsafe {
2068    ///     let (left, right) = v.split_at_unchecked(2);
2069    ///     assert_eq!(left, ['a', 'b']);
2070    ///     assert_eq!(right, ['c']);
2071    /// }
2072    ///
2073    /// unsafe {
2074    ///     let (left, right) = v.split_at_unchecked(3);
2075    ///     assert_eq!(left, ['a', 'b', 'c']);
2076    ///     assert_eq!(right, []);
2077    /// }
2078    /// ```
2079    #[stable(feature = "slice_split_at_unchecked", since = "1.79.0")]
2080    #[rustc_const_stable(feature = "const_slice_split_at_unchecked", since = "1.77.0")]
2081    #[inline]
2082    #[must_use]
2083    #[track_caller]
2084    #[ferrocene::prevalidated]
2085    pub const unsafe fn split_at_unchecked(&self, mid: usize) -> (&[T], &[T]) {
2086        // FIXME(const-hack): the const function `from_raw_parts` is used to make this
2087        // function const; previously the implementation used
2088        // `(self.get_unchecked(..mid), self.get_unchecked(mid..))`
2089
2090        let len = self.len();
2091        let ptr = self.as_ptr();
2092
2093        assert_unsafe_precondition!(
2094            check_library_ub,
2095            "slice::split_at_unchecked requires the index to be within the slice",
2096            (mid: usize = mid, len: usize = len) => mid <= len,
2097        );
2098
2099        // SAFETY: Caller has to check that `0 <= mid <= self.len()`
2100        unsafe { (from_raw_parts(ptr, mid), from_raw_parts(ptr.add(mid), unchecked_sub(len, mid))) }
2101    }
2102
2103    /// Divides one mutable slice into two at an index, without doing bounds checking.
2104    ///
2105    /// The first will contain all indices from `[0, mid)` (excluding
2106    /// the index `mid` itself) and the second will contain all
2107    /// indices from `[mid, len)` (excluding the index `len` itself).
2108    ///
2109    /// For a safe alternative see [`split_at_mut`].
2110    ///
2111    /// # Safety
2112    ///
2113    /// Calling this method with an out-of-bounds index is *[undefined behavior]*
2114    /// even if the resulting reference is not used. The caller has to ensure that
2115    /// `0 <= mid <= self.len()`.
2116    ///
2117    /// [`split_at_mut`]: slice::split_at_mut
2118    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
2119    ///
2120    /// # Examples
2121    ///
2122    /// ```
2123    /// let mut v = [1, 0, 3, 0, 5, 6];
2124    /// // scoped to restrict the lifetime of the borrows
2125    /// unsafe {
2126    ///     let (left, right) = v.split_at_mut_unchecked(2);
2127    ///     assert_eq!(left, [1, 0]);
2128    ///     assert_eq!(right, [3, 0, 5, 6]);
2129    ///     left[1] = 2;
2130    ///     right[1] = 4;
2131    /// }
2132    /// assert_eq!(v, [1, 2, 3, 4, 5, 6]);
2133    /// ```
2134    #[stable(feature = "slice_split_at_unchecked", since = "1.79.0")]
2135    #[rustc_const_stable(feature = "const_slice_split_at_mut", since = "1.83.0")]
2136    #[inline]
2137    #[must_use]
2138    #[track_caller]
2139    #[ferrocene::prevalidated]
2140    pub const unsafe fn split_at_mut_unchecked(&mut self, mid: usize) -> (&mut [T], &mut [T]) {
2141        let len = self.len();
2142        let ptr = self.as_mut_ptr();
2143
2144        assert_unsafe_precondition!(
2145            check_library_ub,
2146            "slice::split_at_mut_unchecked requires the index to be within the slice",
2147            (mid: usize = mid, len: usize = len) => mid <= len,
2148        );
2149
2150        // SAFETY: Caller has to check that `0 <= mid <= self.len()`.
2151        //
2152        // `[ptr; mid]` and `[mid; len]` are not overlapping, so returning a mutable reference
2153        // is fine.
2154        unsafe {
2155            (
2156                from_raw_parts_mut(ptr, mid),
2157                from_raw_parts_mut(ptr.add(mid), unchecked_sub(len, mid)),
2158            )
2159        }
2160    }
2161
2162    /// Divides one slice into two at an index, returning `None` if the slice is
2163    /// too short.
2164    ///
2165    /// If `mid ≤ len` returns a pair of slices where the first will contain all
2166    /// indices from `[0, mid)` (excluding the index `mid` itself) and the
2167    /// second will contain all indices from `[mid, len)` (excluding the index
2168    /// `len` itself).
2169    ///
2170    /// Otherwise, if `mid > len`, returns `None`.
2171    ///
2172    /// # Examples
2173    ///
2174    /// ```
2175    /// let v = [1, -2, 3, -4, 5, -6];
2176    ///
2177    /// {
2178    ///    let (left, right) = v.split_at_checked(0).unwrap();
2179    ///    assert_eq!(left, []);
2180    ///    assert_eq!(right, [1, -2, 3, -4, 5, -6]);
2181    /// }
2182    ///
2183    /// {
2184    ///     let (left, right) = v.split_at_checked(2).unwrap();
2185    ///     assert_eq!(left, [1, -2]);
2186    ///     assert_eq!(right, [3, -4, 5, -6]);
2187    /// }
2188    ///
2189    /// {
2190    ///     let (left, right) = v.split_at_checked(6).unwrap();
2191    ///     assert_eq!(left, [1, -2, 3, -4, 5, -6]);
2192    ///     assert_eq!(right, []);
2193    /// }
2194    ///
2195    /// assert_eq!(None, v.split_at_checked(7));
2196    /// ```
2197    #[stable(feature = "split_at_checked", since = "1.80.0")]
2198    #[rustc_const_stable(feature = "split_at_checked", since = "1.80.0")]
2199    #[inline]
2200    #[must_use]
2201    #[ferrocene::prevalidated]
2202    pub const fn split_at_checked(&self, mid: usize) -> Option<(&[T], &[T])> {
2203        if mid <= self.len() {
2204            // SAFETY: `[ptr; mid]` and `[mid; len]` are inside `self`, which
2205            // fulfills the requirements of `split_at_unchecked`.
2206            Some(unsafe { self.split_at_unchecked(mid) })
2207        } else {
2208            None
2209        }
2210    }
2211
2212    /// Divides one mutable slice into two at an index, returning `None` if the
2213    /// slice is too short.
2214    ///
2215    /// If `mid ≤ len` returns a pair of slices where the first will contain all
2216    /// indices from `[0, mid)` (excluding the index `mid` itself) and the
2217    /// second will contain all indices from `[mid, len)` (excluding the index
2218    /// `len` itself).
2219    ///
2220    /// Otherwise, if `mid > len`, returns `None`.
2221    ///
2222    /// # Examples
2223    ///
2224    /// ```
2225    /// let mut v = [1, 0, 3, 0, 5, 6];
2226    ///
2227    /// if let Some((left, right)) = v.split_at_mut_checked(2) {
2228    ///     assert_eq!(left, [1, 0]);
2229    ///     assert_eq!(right, [3, 0, 5, 6]);
2230    ///     left[1] = 2;
2231    ///     right[1] = 4;
2232    /// }
2233    /// assert_eq!(v, [1, 2, 3, 4, 5, 6]);
2234    ///
2235    /// assert_eq!(None, v.split_at_mut_checked(7));
2236    /// ```
2237    #[stable(feature = "split_at_checked", since = "1.80.0")]
2238    #[rustc_const_stable(feature = "const_slice_split_at_mut", since = "1.83.0")]
2239    #[inline]
2240    #[must_use]
2241    #[ferrocene::prevalidated]
2242    pub const fn split_at_mut_checked(&mut self, mid: usize) -> Option<(&mut [T], &mut [T])> {
2243        if mid <= self.len() {
2244            // SAFETY: `[ptr; mid]` and `[mid; len]` are inside `self`, which
2245            // fulfills the requirements of `split_at_unchecked`.
2246            Some(unsafe { self.split_at_mut_unchecked(mid) })
2247        } else {
2248            None
2249        }
2250    }
2251
2252    /// Returns an iterator over subslices separated by elements that match
2253    /// `pred`. The matched element is not contained in the subslices.
2254    ///
2255    /// # Examples
2256    ///
2257    /// ```
2258    /// let slice = [10, 40, 33, 20];
2259    /// let mut iter = slice.split(|num| num % 3 == 0);
2260    ///
2261    /// assert_eq!(iter.next().unwrap(), &[10, 40]);
2262    /// assert_eq!(iter.next().unwrap(), &[20]);
2263    /// assert!(iter.next().is_none());
2264    /// ```
2265    ///
2266    /// If the first element is matched, an empty slice will be the first item
2267    /// returned by the iterator. Similarly, if the last element in the slice
2268    /// is matched, an empty slice will be the last item returned by the
2269    /// iterator:
2270    ///
2271    /// ```
2272    /// let slice = [10, 40, 33];
2273    /// let mut iter = slice.split(|num| num % 3 == 0);
2274    ///
2275    /// assert_eq!(iter.next().unwrap(), &[10, 40]);
2276    /// assert_eq!(iter.next().unwrap(), &[]);
2277    /// assert!(iter.next().is_none());
2278    /// ```
2279    ///
2280    /// If two matched elements are directly adjacent, an empty slice will be
2281    /// present between them:
2282    ///
2283    /// ```
2284    /// let slice = [10, 6, 33, 20];
2285    /// let mut iter = slice.split(|num| num % 3 == 0);
2286    ///
2287    /// assert_eq!(iter.next().unwrap(), &[10]);
2288    /// assert_eq!(iter.next().unwrap(), &[]);
2289    /// assert_eq!(iter.next().unwrap(), &[20]);
2290    /// assert!(iter.next().is_none());
2291    /// ```
2292    #[stable(feature = "rust1", since = "1.0.0")]
2293    #[inline]
2294    pub fn split<F>(&self, pred: F) -> Split<'_, T, F>
2295    where
2296        F: FnMut(&T) -> bool,
2297    {
2298        Split::new(self, pred)
2299    }
2300
2301    /// Returns an iterator over mutable subslices separated by elements that
2302    /// match `pred`. The matched element is not contained in the subslices.
2303    ///
2304    /// # Examples
2305    ///
2306    /// ```
2307    /// let mut v = [10, 40, 30, 20, 60, 50];
2308    ///
2309    /// for group in v.split_mut(|num| *num % 3 == 0) {
2310    ///     group[0] = 1;
2311    /// }
2312    /// assert_eq!(v, [1, 40, 30, 1, 60, 1]);
2313    /// ```
2314    #[stable(feature = "rust1", since = "1.0.0")]
2315    #[inline]
2316    pub fn split_mut<F>(&mut self, pred: F) -> SplitMut<'_, T, F>
2317    where
2318        F: FnMut(&T) -> bool,
2319    {
2320        SplitMut::new(self, pred)
2321    }
2322
2323    /// Returns an iterator over subslices separated by elements that match
2324    /// `pred`. The matched element is contained in the end of the previous
2325    /// subslice as a terminator.
2326    ///
2327    /// # Examples
2328    ///
2329    /// ```
2330    /// let slice = [10, 40, 33, 20];
2331    /// let mut iter = slice.split_inclusive(|num| num % 3 == 0);
2332    ///
2333    /// assert_eq!(iter.next().unwrap(), &[10, 40, 33]);
2334    /// assert_eq!(iter.next().unwrap(), &[20]);
2335    /// assert!(iter.next().is_none());
2336    /// ```
2337    ///
2338    /// If the last element of the slice is matched,
2339    /// that element will be considered the terminator of the preceding slice.
2340    /// That slice will be the last item returned by the iterator.
2341    ///
2342    /// ```
2343    /// let slice = [3, 10, 40, 33];
2344    /// let mut iter = slice.split_inclusive(|num| num % 3 == 0);
2345    ///
2346    /// assert_eq!(iter.next().unwrap(), &[3]);
2347    /// assert_eq!(iter.next().unwrap(), &[10, 40, 33]);
2348    /// assert!(iter.next().is_none());
2349    /// ```
2350    #[stable(feature = "split_inclusive", since = "1.51.0")]
2351    #[inline]
2352    pub fn split_inclusive<F>(&self, pred: F) -> SplitInclusive<'_, T, F>
2353    where
2354        F: FnMut(&T) -> bool,
2355    {
2356        SplitInclusive::new(self, pred)
2357    }
2358
2359    /// Returns an iterator over mutable subslices separated by elements that
2360    /// match `pred`. The matched element is contained in the previous
2361    /// subslice as a terminator.
2362    ///
2363    /// # Examples
2364    ///
2365    /// ```
2366    /// let mut v = [10, 40, 30, 20, 60, 50];
2367    ///
2368    /// for group in v.split_inclusive_mut(|num| *num % 3 == 0) {
2369    ///     let terminator_idx = group.len()-1;
2370    ///     group[terminator_idx] = 1;
2371    /// }
2372    /// assert_eq!(v, [10, 40, 1, 20, 1, 1]);
2373    /// ```
2374    #[stable(feature = "split_inclusive", since = "1.51.0")]
2375    #[inline]
2376    pub fn split_inclusive_mut<F>(&mut self, pred: F) -> SplitInclusiveMut<'_, T, F>
2377    where
2378        F: FnMut(&T) -> bool,
2379    {
2380        SplitInclusiveMut::new(self, pred)
2381    }
2382
2383    /// Returns an iterator over subslices separated by elements that match
2384    /// `pred`, starting at the end of the slice and working backwards.
2385    /// The matched element is not contained in the subslices.
2386    ///
2387    /// # Examples
2388    ///
2389    /// ```
2390    /// let slice = [11, 22, 33, 0, 44, 55];
2391    /// let mut iter = slice.rsplit(|num| *num == 0);
2392    ///
2393    /// assert_eq!(iter.next().unwrap(), &[44, 55]);
2394    /// assert_eq!(iter.next().unwrap(), &[11, 22, 33]);
2395    /// assert_eq!(iter.next(), None);
2396    /// ```
2397    ///
2398    /// As with `split()`, if the first or last element is matched, an empty
2399    /// slice will be the first (or last) item returned by the iterator.
2400    ///
2401    /// ```
2402    /// let v = &[0, 1, 1, 2, 3, 5, 8];
2403    /// let mut it = v.rsplit(|n| *n % 2 == 0);
2404    /// assert_eq!(it.next().unwrap(), &[]);
2405    /// assert_eq!(it.next().unwrap(), &[3, 5]);
2406    /// assert_eq!(it.next().unwrap(), &[1, 1]);
2407    /// assert_eq!(it.next().unwrap(), &[]);
2408    /// assert_eq!(it.next(), None);
2409    /// ```
2410    #[stable(feature = "slice_rsplit", since = "1.27.0")]
2411    #[inline]
2412    pub fn rsplit<F>(&self, pred: F) -> RSplit<'_, T, F>
2413    where
2414        F: FnMut(&T) -> bool,
2415    {
2416        RSplit::new(self, pred)
2417    }
2418
2419    /// Returns an iterator over mutable subslices separated by elements that
2420    /// match `pred`, starting at the end of the slice and working
2421    /// backwards. The matched element is not contained in the subslices.
2422    ///
2423    /// # Examples
2424    ///
2425    /// ```
2426    /// let mut v = [100, 400, 300, 200, 600, 500];
2427    ///
2428    /// let mut count = 0;
2429    /// for group in v.rsplit_mut(|num| *num % 3 == 0) {
2430    ///     count += 1;
2431    ///     group[0] = count;
2432    /// }
2433    /// assert_eq!(v, [3, 400, 300, 2, 600, 1]);
2434    /// ```
2435    ///
2436    #[stable(feature = "slice_rsplit", since = "1.27.0")]
2437    #[inline]
2438    pub fn rsplit_mut<F>(&mut self, pred: F) -> RSplitMut<'_, T, F>
2439    where
2440        F: FnMut(&T) -> bool,
2441    {
2442        RSplitMut::new(self, pred)
2443    }
2444
2445    /// Returns an iterator over subslices separated by elements that match
2446    /// `pred`, limited to returning at most `n` items. The matched element is
2447    /// not contained in the subslices.
2448    ///
2449    /// The last element returned, if any, will contain the remainder of the
2450    /// slice.
2451    ///
2452    /// # Examples
2453    ///
2454    /// Print the slice split once by numbers divisible by 3 (i.e., `[10, 40]`,
2455    /// `[20, 60, 50]`):
2456    ///
2457    /// ```
2458    /// let v = [10, 40, 30, 20, 60, 50];
2459    ///
2460    /// for group in v.splitn(2, |num| *num % 3 == 0) {
2461    ///     println!("{group:?}");
2462    /// }
2463    /// ```
2464    #[stable(feature = "rust1", since = "1.0.0")]
2465    #[inline]
2466    pub fn splitn<F>(&self, n: usize, pred: F) -> SplitN<'_, T, F>
2467    where
2468        F: FnMut(&T) -> bool,
2469    {
2470        SplitN::new(self.split(pred), n)
2471    }
2472
2473    /// Returns an iterator over mutable subslices separated by elements that match
2474    /// `pred`, limited to returning at most `n` items. The matched element is
2475    /// not contained in the subslices.
2476    ///
2477    /// The last element returned, if any, will contain the remainder of the
2478    /// slice.
2479    ///
2480    /// # Examples
2481    ///
2482    /// ```
2483    /// let mut v = [10, 40, 30, 20, 60, 50];
2484    ///
2485    /// for group in v.splitn_mut(2, |num| *num % 3 == 0) {
2486    ///     group[0] = 1;
2487    /// }
2488    /// assert_eq!(v, [1, 40, 30, 1, 60, 50]);
2489    /// ```
2490    #[stable(feature = "rust1", since = "1.0.0")]
2491    #[inline]
2492    pub fn splitn_mut<F>(&mut self, n: usize, pred: F) -> SplitNMut<'_, T, F>
2493    where
2494        F: FnMut(&T) -> bool,
2495    {
2496        SplitNMut::new(self.split_mut(pred), n)
2497    }
2498
2499    /// Returns an iterator over subslices separated by elements that match
2500    /// `pred` limited to returning at most `n` items. This starts at the end of
2501    /// the slice and works backwards. The matched element is not contained in
2502    /// the subslices.
2503    ///
2504    /// The last element returned, if any, will contain the remainder of the
2505    /// slice.
2506    ///
2507    /// # Examples
2508    ///
2509    /// Print the slice split once, starting from the end, by numbers divisible
2510    /// by 3 (i.e., `[50]`, `[10, 40, 30, 20]`):
2511    ///
2512    /// ```
2513    /// let v = [10, 40, 30, 20, 60, 50];
2514    ///
2515    /// for group in v.rsplitn(2, |num| *num % 3 == 0) {
2516    ///     println!("{group:?}");
2517    /// }
2518    /// ```
2519    #[stable(feature = "rust1", since = "1.0.0")]
2520    #[inline]
2521    pub fn rsplitn<F>(&self, n: usize, pred: F) -> RSplitN<'_, T, F>
2522    where
2523        F: FnMut(&T) -> bool,
2524    {
2525        RSplitN::new(self.rsplit(pred), n)
2526    }
2527
2528    /// Returns an iterator over subslices separated by elements that match
2529    /// `pred` limited to returning at most `n` items. This starts at the end of
2530    /// the slice and works backwards. The matched element is not contained in
2531    /// the subslices.
2532    ///
2533    /// The last element returned, if any, will contain the remainder of the
2534    /// slice.
2535    ///
2536    /// # Examples
2537    ///
2538    /// ```
2539    /// let mut s = [10, 40, 30, 20, 60, 50];
2540    ///
2541    /// for group in s.rsplitn_mut(2, |num| *num % 3 == 0) {
2542    ///     group[0] = 1;
2543    /// }
2544    /// assert_eq!(s, [1, 40, 30, 20, 60, 1]);
2545    /// ```
2546    #[stable(feature = "rust1", since = "1.0.0")]
2547    #[inline]
2548    pub fn rsplitn_mut<F>(&mut self, n: usize, pred: F) -> RSplitNMut<'_, T, F>
2549    where
2550        F: FnMut(&T) -> bool,
2551    {
2552        RSplitNMut::new(self.rsplit_mut(pred), n)
2553    }
2554
2555    /// Splits the slice on the first element that matches the specified
2556    /// predicate.
2557    ///
2558    /// If any matching elements are present in the slice, returns the prefix
2559    /// before the match and suffix after. The matching element itself is not
2560    /// included. If no elements match, returns `None`.
2561    ///
2562    /// # Examples
2563    ///
2564    /// ```
2565    /// #![feature(slice_split_once)]
2566    /// let s = [1, 2, 3, 2, 4];
2567    /// assert_eq!(s.split_once(|&x| x == 2), Some((
2568    ///     &[1][..],
2569    ///     &[3, 2, 4][..]
2570    /// )));
2571    /// assert_eq!(s.split_once(|&x| x == 0), None);
2572    /// ```
2573    #[unstable(feature = "slice_split_once", issue = "112811")]
2574    #[inline]
2575    pub fn split_once<F>(&self, pred: F) -> Option<(&[T], &[T])>
2576    where
2577        F: FnMut(&T) -> bool,
2578    {
2579        let index = self.iter().position(pred)?;
2580        // Slice bounds checks optimized are away (as of June 2026)
2581        Some((&self[..index], &self[index + 1..]))
2582    }
2583
2584    /// Splits the slice on the last element that matches the specified
2585    /// predicate.
2586    ///
2587    /// If any matching elements are present in the slice, returns the prefix
2588    /// before the match and suffix after. The matching element itself is not
2589    /// included. If no elements match, returns `None`.
2590    ///
2591    /// # Examples
2592    ///
2593    /// ```
2594    /// #![feature(slice_split_once)]
2595    /// let s = [1, 2, 3, 2, 4];
2596    /// assert_eq!(s.rsplit_once(|&x| x == 2), Some((
2597    ///     &[1, 2, 3][..],
2598    ///     &[4][..]
2599    /// )));
2600    /// assert_eq!(s.rsplit_once(|&x| x == 0), None);
2601    /// ```
2602    #[unstable(feature = "slice_split_once", issue = "112811")]
2603    #[inline]
2604    pub fn rsplit_once<F>(&self, pred: F) -> Option<(&[T], &[T])>
2605    where
2606        F: FnMut(&T) -> bool,
2607    {
2608        let index = self.iter().rposition(pred)?;
2609        // Slice bounds checks optimized are away (as of June 2026)
2610        Some((&self[..index], &self[index + 1..]))
2611    }
2612
2613    /// Returns `true` if the slice contains an element with the given value.
2614    ///
2615    /// This operation is *O*(*n*).
2616    ///
2617    /// Note that if you have a sorted slice, [`binary_search`] may be faster.
2618    ///
2619    /// [`binary_search`]: slice::binary_search
2620    ///
2621    /// # Examples
2622    ///
2623    /// ```
2624    /// let v = [10, 40, 30];
2625    /// assert!(v.contains(&30));
2626    /// assert!(!v.contains(&50));
2627    /// ```
2628    ///
2629    /// If you do not have a `&T`, but some other value that you can compare
2630    /// with one (for example, `String` implements `PartialEq<str>`), you can
2631    /// use `iter().any`:
2632    ///
2633    /// ```
2634    /// let v = [String::from("hello"), String::from("world")]; // slice of `String`
2635    /// assert!(v.iter().any(|e| e == "hello")); // search with `&str`
2636    /// assert!(!v.iter().any(|e| e == "hi"));
2637    /// ```
2638    #[stable(feature = "rust1", since = "1.0.0")]
2639    #[inline]
2640    #[must_use]
2641    pub fn contains(&self, x: &T) -> bool
2642    where
2643        T: PartialEq,
2644    {
2645        cmp::SliceContains::slice_contains(x, self)
2646    }
2647
2648    /// Returns `true` if `needle` is a prefix of the slice or equal to the slice.
2649    ///
2650    /// # Examples
2651    ///
2652    /// ```
2653    /// let v = [10, 40, 30];
2654    /// assert!(v.starts_with(&[10]));
2655    /// assert!(v.starts_with(&[10, 40]));
2656    /// assert!(v.starts_with(&v));
2657    /// assert!(!v.starts_with(&[50]));
2658    /// assert!(!v.starts_with(&[10, 50]));
2659    /// ```
2660    ///
2661    /// Always returns `true` if `needle` is an empty slice:
2662    ///
2663    /// ```
2664    /// let v = &[10, 40, 30];
2665    /// assert!(v.starts_with(&[]));
2666    /// let v: &[u8] = &[];
2667    /// assert!(v.starts_with(&[]));
2668    /// ```
2669    #[stable(feature = "rust1", since = "1.0.0")]
2670    #[must_use]
2671    #[ferrocene::prevalidated]
2672    pub fn starts_with(&self, needle: &[T]) -> bool
2673    where
2674        T: PartialEq,
2675    {
2676        let n = needle.len();
2677        self.len() >= n && needle == &self[..n]
2678    }
2679
2680    /// Returns `true` if `needle` is a suffix of the slice or equal to the slice.
2681    ///
2682    /// # Examples
2683    ///
2684    /// ```
2685    /// let v = [10, 40, 30];
2686    /// assert!(v.ends_with(&[30]));
2687    /// assert!(v.ends_with(&[40, 30]));
2688    /// assert!(v.ends_with(&v));
2689    /// assert!(!v.ends_with(&[50]));
2690    /// assert!(!v.ends_with(&[50, 30]));
2691    /// ```
2692    ///
2693    /// Always returns `true` if `needle` is an empty slice:
2694    ///
2695    /// ```
2696    /// let v = &[10, 40, 30];
2697    /// assert!(v.ends_with(&[]));
2698    /// let v: &[u8] = &[];
2699    /// assert!(v.ends_with(&[]));
2700    /// ```
2701    #[stable(feature = "rust1", since = "1.0.0")]
2702    #[must_use]
2703    #[ferrocene::prevalidated]
2704    pub fn ends_with(&self, needle: &[T]) -> bool
2705    where
2706        T: PartialEq,
2707    {
2708        let (m, n) = (self.len(), needle.len());
2709        m >= n && needle == &self[m - n..]
2710    }
2711
2712    /// Returns a subslice with the prefix removed.
2713    ///
2714    /// If the slice starts with `prefix`, returns the subslice after the prefix, wrapped in `Some`.
2715    /// If `prefix` is empty, simply returns the original slice. If `prefix` is equal to the
2716    /// original slice, returns an empty slice.
2717    ///
2718    /// If the slice does not start with `prefix`, returns `None`.
2719    ///
2720    /// # Examples
2721    ///
2722    /// ```
2723    /// let v = &[10, 40, 30];
2724    /// assert_eq!(v.strip_prefix(&[10]), Some(&[40, 30][..]));
2725    /// assert_eq!(v.strip_prefix(&[10, 40]), Some(&[30][..]));
2726    /// assert_eq!(v.strip_prefix(&[10, 40, 30]), Some(&[][..]));
2727    /// assert_eq!(v.strip_prefix(&[50]), None);
2728    /// assert_eq!(v.strip_prefix(&[10, 50]), None);
2729    ///
2730    /// let prefix : &str = "he";
2731    /// assert_eq!(b"hello".strip_prefix(prefix.as_bytes()),
2732    ///            Some(b"llo".as_ref()));
2733    /// ```
2734    #[must_use = "returns the subslice without modifying the original"]
2735    #[stable(feature = "slice_strip", since = "1.51.0")]
2736    pub fn strip_prefix<P: SlicePattern<Item = T> + ?Sized>(&self, prefix: &P) -> Option<&[T]>
2737    where
2738        T: PartialEq,
2739    {
2740        // This function will need rewriting if and when SlicePattern becomes more sophisticated.
2741        let prefix = prefix.as_slice();
2742        let n = prefix.len();
2743        if n <= self.len() {
2744            let (head, tail) = self.split_at(n);
2745            if head == prefix {
2746                return Some(tail);
2747            }
2748        }
2749        None
2750    }
2751
2752    /// Returns a subslice with the suffix removed.
2753    ///
2754    /// If the slice ends with `suffix`, returns the subslice before the suffix, wrapped in `Some`.
2755    /// If `suffix` is empty, simply returns the original slice. If `suffix` is equal to the
2756    /// original slice, returns an empty slice.
2757    ///
2758    /// If the slice does not end with `suffix`, returns `None`.
2759    ///
2760    /// # Examples
2761    ///
2762    /// ```
2763    /// let v = &[10, 40, 30];
2764    /// assert_eq!(v.strip_suffix(&[30]), Some(&[10, 40][..]));
2765    /// assert_eq!(v.strip_suffix(&[40, 30]), Some(&[10][..]));
2766    /// assert_eq!(v.strip_suffix(&[10, 40, 30]), Some(&[][..]));
2767    /// assert_eq!(v.strip_suffix(&[50]), None);
2768    /// assert_eq!(v.strip_suffix(&[50, 30]), None);
2769    /// ```
2770    #[must_use = "returns the subslice without modifying the original"]
2771    #[stable(feature = "slice_strip", since = "1.51.0")]
2772    pub fn strip_suffix<P: SlicePattern<Item = T> + ?Sized>(&self, suffix: &P) -> Option<&[T]>
2773    where
2774        T: PartialEq,
2775    {
2776        // This function will need rewriting if and when SlicePattern becomes more sophisticated.
2777        let suffix = suffix.as_slice();
2778        let (len, n) = (self.len(), suffix.len());
2779        if n <= len {
2780            let (head, tail) = self.split_at(len - n);
2781            if tail == suffix {
2782                return Some(head);
2783            }
2784        }
2785        None
2786    }
2787
2788    /// Returns a subslice with the prefix and suffix removed.
2789    ///
2790    /// If the slice starts with `prefix`, ends with `suffix`, and
2791    /// the prefix and suffix don't overlap, returns the subslice after
2792    /// the prefix and before the suffix, wrapped in `Some`.
2793    ///
2794    /// If the slice does not start with `prefix`, does not end with `suffix`,
2795    /// or the prefix and suffix overlap in the slice, returns `None`.
2796    ///
2797    /// # Examples
2798    ///
2799    /// ```
2800    /// let v = &[10, 50, 40, 30];
2801    /// assert_eq!(v.strip_circumfix(&[10], &[30]), Some(&[50, 40][..]));
2802    /// assert_eq!(v.strip_circumfix(&[10], &[40, 30]), Some(&[50][..]));
2803    /// assert_eq!(v.strip_circumfix(&[10, 50], &[40, 30]), Some(&[][..]));
2804    /// assert_eq!(v.strip_circumfix(&[50], &[30]), None);
2805    /// assert_eq!(v.strip_circumfix(&[10], &[40]), None);
2806    /// assert_eq!(v.strip_circumfix(&[], &[40, 30]), Some(&[10, 50][..]));
2807    /// assert_eq!(v.strip_circumfix(&[10, 50], &[]), Some(&[40, 30][..]));
2808    /// assert_eq!(v.strip_circumfix(&[10, 50, 40], &[50, 40, 30]), None);
2809    /// ```
2810    #[must_use = "returns the subslice without modifying the original"]
2811    #[stable(feature = "strip_circumfix", since = "1.98.0")]
2812    pub fn strip_circumfix<S, P>(&self, prefix: &P, suffix: &S) -> Option<&[T]>
2813    where
2814        T: PartialEq,
2815        S: SlicePattern<Item = T> + ?Sized,
2816        P: SlicePattern<Item = T> + ?Sized,
2817    {
2818        self.strip_prefix(prefix)?.strip_suffix(suffix)
2819    }
2820
2821    /// Returns a subslice with the optional prefix removed.
2822    ///
2823    /// If the slice starts with `prefix`, returns the subslice after the prefix.  If `prefix`
2824    /// is empty or the slice does not start with `prefix`, simply returns the original slice.
2825    /// If `prefix` is equal to the original slice, returns an empty slice.
2826    ///
2827    /// # Examples
2828    ///
2829    /// ```
2830    /// #![feature(trim_prefix_suffix)]
2831    ///
2832    /// let v = &[10, 40, 30];
2833    ///
2834    /// // Prefix present - removes it
2835    /// assert_eq!(v.trim_prefix(&[10]), &[40, 30][..]);
2836    /// assert_eq!(v.trim_prefix(&[10, 40]), &[30][..]);
2837    /// assert_eq!(v.trim_prefix(&[10, 40, 30]), &[][..]);
2838    ///
2839    /// // Prefix absent - returns original slice
2840    /// assert_eq!(v.trim_prefix(&[50]), &[10, 40, 30][..]);
2841    /// assert_eq!(v.trim_prefix(&[10, 50]), &[10, 40, 30][..]);
2842    ///
2843    /// let prefix : &str = "he";
2844    /// assert_eq!(b"hello".trim_prefix(prefix.as_bytes()), b"llo".as_ref());
2845    /// ```
2846    #[must_use = "returns the subslice without modifying the original"]
2847    #[unstable(feature = "trim_prefix_suffix", issue = "142312")]
2848    pub fn trim_prefix<P: SlicePattern<Item = T> + ?Sized>(&self, prefix: &P) -> &[T]
2849    where
2850        T: PartialEq,
2851    {
2852        // This function will need rewriting if and when SlicePattern becomes more sophisticated.
2853        let prefix = prefix.as_slice();
2854        let n = prefix.len();
2855        if n <= self.len() {
2856            let (head, tail) = self.split_at(n);
2857            if head == prefix {
2858                return tail;
2859            }
2860        }
2861        self
2862    }
2863
2864    /// Returns a subslice with the optional suffix removed.
2865    ///
2866    /// If the slice ends with `suffix`, returns the subslice before the suffix.  If `suffix`
2867    /// is empty or the slice does not end with `suffix`, simply returns the original slice.
2868    /// If `suffix` is equal to the original slice, returns an empty slice.
2869    ///
2870    /// # Examples
2871    ///
2872    /// ```
2873    /// #![feature(trim_prefix_suffix)]
2874    ///
2875    /// let v = &[10, 40, 30];
2876    ///
2877    /// // Suffix present - removes it
2878    /// assert_eq!(v.trim_suffix(&[30]), &[10, 40][..]);
2879    /// assert_eq!(v.trim_suffix(&[40, 30]), &[10][..]);
2880    /// assert_eq!(v.trim_suffix(&[10, 40, 30]), &[][..]);
2881    ///
2882    /// // Suffix absent - returns original slice
2883    /// assert_eq!(v.trim_suffix(&[50]), &[10, 40, 30][..]);
2884    /// assert_eq!(v.trim_suffix(&[50, 30]), &[10, 40, 30][..]);
2885    /// ```
2886    #[must_use = "returns the subslice without modifying the original"]
2887    #[unstable(feature = "trim_prefix_suffix", issue = "142312")]
2888    pub fn trim_suffix<P: SlicePattern<Item = T> + ?Sized>(&self, suffix: &P) -> &[T]
2889    where
2890        T: PartialEq,
2891    {
2892        // This function will need rewriting if and when SlicePattern becomes more sophisticated.
2893        let suffix = suffix.as_slice();
2894        let (len, n) = (self.len(), suffix.len());
2895        if n <= len {
2896            let (head, tail) = self.split_at(len - n);
2897            if tail == suffix {
2898                return head;
2899            }
2900        }
2901        self
2902    }
2903
2904    /// Binary searches this slice for a given element.
2905    /// If the slice is not sorted, the returned result is unspecified and
2906    /// meaningless.
2907    ///
2908    /// If the value is found then [`Result::Ok`] is returned, containing the
2909    /// index of the matching element. If there are multiple matches, then any
2910    /// one of the matches could be returned. The index is chosen
2911    /// deterministically, but is subject to change in future versions of Rust.
2912    /// If the value is not found then [`Result::Err`] is returned, containing
2913    /// the index where a matching element could be inserted while maintaining
2914    /// sorted order.
2915    ///
2916    /// See also [`binary_search_by`], [`binary_search_by_key`], and [`partition_point`].
2917    ///
2918    /// [`binary_search_by`]: slice::binary_search_by
2919    /// [`binary_search_by_key`]: slice::binary_search_by_key
2920    /// [`partition_point`]: slice::partition_point
2921    ///
2922    /// # Examples
2923    ///
2924    /// Looks up a series of four elements. The first is found, with a
2925    /// uniquely determined position; the second and third are not
2926    /// found; the fourth could match any position in `[1, 4]`.
2927    ///
2928    /// ```
2929    /// let s = [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
2930    ///
2931    /// assert_eq!(s.binary_search(&13),  Ok(9));
2932    /// assert_eq!(s.binary_search(&4),   Err(7));
2933    /// assert_eq!(s.binary_search(&100), Err(13));
2934    /// let r = s.binary_search(&1);
2935    /// assert!(match r { Ok(1..=4) => true, _ => false, });
2936    /// ```
2937    ///
2938    /// If you want to find that whole *range* of matching items, rather than
2939    /// an arbitrary matching one, that can be done using [`partition_point`]:
2940    /// ```
2941    /// let s = [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
2942    ///
2943    /// let low = s.partition_point(|x| x < &1);
2944    /// assert_eq!(low, 1);
2945    /// let high = s.partition_point(|x| x <= &1);
2946    /// assert_eq!(high, 5);
2947    /// let r = s.binary_search(&1);
2948    /// assert!((low..high).contains(&r.unwrap()));
2949    ///
2950    /// assert!(s[..low].iter().all(|&x| x < 1));
2951    /// assert!(s[low..high].iter().all(|&x| x == 1));
2952    /// assert!(s[high..].iter().all(|&x| x > 1));
2953    ///
2954    /// // For something not found, the "range" of equal items is empty
2955    /// assert_eq!(s.partition_point(|x| x < &11), 9);
2956    /// assert_eq!(s.partition_point(|x| x <= &11), 9);
2957    /// assert_eq!(s.binary_search(&11), Err(9));
2958    /// ```
2959    ///
2960    /// If you want to insert an item to a sorted vector, while maintaining
2961    /// sort order, consider using [`partition_point`]:
2962    ///
2963    /// ```
2964    /// let mut s = vec![0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
2965    /// let num = 42;
2966    /// let idx = s.partition_point(|&x| x <= num);
2967    /// // If `num` is unique, `s.partition_point(|&x| x < num)` (with `<`) is equivalent to
2968    /// // `s.binary_search(&num).unwrap_or_else(|x| x)`, but using `<=` will allow `insert`
2969    /// // to shift less elements.
2970    /// s.insert(idx, num);
2971    /// assert_eq!(s, [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 42, 55]);
2972    /// ```
2973    #[rustc_const_unstable(feature = "const_binary_search", issue = "159532")]
2974    #[stable(feature = "rust1", since = "1.0.0")]
2975    pub const fn binary_search(&self, x: &T) -> Result<usize, usize>
2976    where
2977        T: [const] Ord,
2978    {
2979        self.binary_search_by(const |p| p.cmp(x))
2980    }
2981
2982    /// Binary searches this slice with a comparator function.
2983    ///
2984    /// The comparator function should return an order code that indicates
2985    /// whether its argument is `Less`, `Equal` or `Greater` the desired
2986    /// target.
2987    /// If the slice is not sorted or if the comparator function does not
2988    /// implement an order consistent with the sort order of the underlying
2989    /// slice, the returned result is unspecified and meaningless.
2990    ///
2991    /// If the value is found then [`Result::Ok`] is returned, containing the
2992    /// index of the matching element. If there are multiple matches, then any
2993    /// one of the matches could be returned. The index is chosen
2994    /// deterministically, but is subject to change in future versions of Rust.
2995    /// If the value is not found then [`Result::Err`] is returned, containing
2996    /// the index where a matching element could be inserted while maintaining
2997    /// sorted order.
2998    ///
2999    /// See also [`binary_search`], [`binary_search_by_key`], and [`partition_point`].
3000    ///
3001    /// [`binary_search`]: slice::binary_search
3002    /// [`binary_search_by_key`]: slice::binary_search_by_key
3003    /// [`partition_point`]: slice::partition_point
3004    ///
3005    /// # Examples
3006    ///
3007    /// Looks up a series of four elements. The first is found, with a
3008    /// uniquely determined position; the second and third are not
3009    /// found; the fourth could match any position in `[1, 4]`.
3010    ///
3011    /// ```
3012    /// let s = [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
3013    ///
3014    /// let seek = 13;
3015    /// assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Ok(9));
3016    /// let seek = 4;
3017    /// assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Err(7));
3018    /// let seek = 100;
3019    /// assert_eq!(s.binary_search_by(|probe| probe.cmp(&seek)), Err(13));
3020    /// let seek = 1;
3021    /// let r = s.binary_search_by(|probe| probe.cmp(&seek));
3022    /// assert!(match r { Ok(1..=4) => true, _ => false, });
3023    /// ```
3024    #[rustc_const_unstable(feature = "const_binary_search", issue = "159532")]
3025    #[stable(feature = "rust1", since = "1.0.0")]
3026    #[inline]
3027    #[ferrocene::prevalidated]
3028    pub const fn binary_search_by<'a, F>(&'a self, mut f: F) -> Result<usize, usize>
3029    where
3030        F: [const] FnMut(&'a T) -> Ordering + [const] Destruct,
3031    {
3032        let mut size = self.len();
3033        if size == 0 {
3034            return Err(0);
3035        }
3036        let mut base = 0usize;
3037
3038        // This loop intentionally doesn't have an early exit if the comparison
3039        // returns Equal. We want the number of loop iterations to depend *only*
3040        // on the size of the input slice so that the CPU can reliably predict
3041        // the loop count.
3042        while size > 1 {
3043            let half = size / 2;
3044            let mid = base + half;
3045
3046            // SAFETY: the call is made safe by the following invariants:
3047            // - `mid >= 0`: by definition
3048            // - `mid < size`: `mid = size / 2 + size / 4 + size / 8 ...`
3049            let cmp = f(unsafe { self.get_unchecked(mid) });
3050
3051            // Binary search interacts poorly with branch prediction, so force
3052            // the compiler to use conditional moves if supported by the target
3053            // architecture.
3054            base = hint::select_unpredictable(cmp == Greater, base, mid);
3055
3056            // This is imprecise in the case where `size` is odd and the
3057            // comparison returns Greater: the mid element still gets included
3058            // by `size` even though it's known to be larger than the element
3059            // being searched for.
3060            //
3061            // This is fine though: we gain more performance by keeping the
3062            // loop iteration count invariant (and thus predictable) than we
3063            // lose from considering one additional element.
3064            size -= half;
3065        }
3066
3067        // SAFETY: base is always in [0, size) because base <= mid.
3068        let cmp = f(unsafe { self.get_unchecked(base) });
3069        if cmp == Equal {
3070            // SAFETY: same as the `get_unchecked` above.
3071            unsafe { hint::assert_unchecked(base < self.len()) };
3072            Ok(base)
3073        } else {
3074            let result = base + (cmp == Less) as usize;
3075            // SAFETY: same as the `get_unchecked` above.
3076            // Note that this is `<=`, unlike the assume in the `Ok` path.
3077            unsafe { hint::assert_unchecked(result <= self.len()) };
3078            Err(result)
3079        }
3080    }
3081
3082    /// Binary searches this slice with a key extraction function.
3083    ///
3084    /// Assumes that the slice is sorted by the key, for instance with
3085    /// [`sort_by_key`] using the same key extraction function.
3086    /// If the slice is not sorted by the key, the returned result is
3087    /// unspecified and meaningless.
3088    ///
3089    /// If the value is found then [`Result::Ok`] is returned, containing the
3090    /// index of the matching element. If there are multiple matches, then any
3091    /// one of the matches could be returned. The index is chosen
3092    /// deterministically, but is subject to change in future versions of Rust.
3093    /// If the value is not found then [`Result::Err`] is returned, containing
3094    /// the index where a matching element could be inserted while maintaining
3095    /// sorted order.
3096    ///
3097    /// See also [`binary_search`], [`binary_search_by`], and [`partition_point`].
3098    ///
3099    /// [`sort_by_key`]: slice::sort_by_key
3100    /// [`binary_search`]: slice::binary_search
3101    /// [`binary_search_by`]: slice::binary_search_by
3102    /// [`partition_point`]: slice::partition_point
3103    ///
3104    /// # Examples
3105    ///
3106    /// Looks up a series of four elements in a slice of pairs sorted by
3107    /// their second elements. The first is found, with a uniquely
3108    /// determined position; the second and third are not found; the
3109    /// fourth could match any position in `[1, 4]`.
3110    ///
3111    /// ```
3112    /// let s = [(0, 0), (2, 1), (4, 1), (5, 1), (3, 1),
3113    ///          (1, 2), (2, 3), (4, 5), (5, 8), (3, 13),
3114    ///          (1, 21), (2, 34), (4, 55)];
3115    ///
3116    /// assert_eq!(s.binary_search_by_key(&13, |&(a, b)| b),  Ok(9));
3117    /// assert_eq!(s.binary_search_by_key(&4, |&(a, b)| b),   Err(7));
3118    /// assert_eq!(s.binary_search_by_key(&100, |&(a, b)| b), Err(13));
3119    /// let r = s.binary_search_by_key(&1, |&(a, b)| b);
3120    /// assert!(match r { Ok(1..=4) => true, _ => false, });
3121    /// ```
3122    // Lint rustdoc::broken_intra_doc_links is allowed as `slice::sort_by_key` is
3123    // in crate `alloc`, and as such doesn't exists yet when building `core`: #74481.
3124    // This breaks links when slice is displayed in core, but changing it to use relative links
3125    // would break when the item is re-exported. So allow the core links to be broken for now.
3126    #[allow(rustdoc::broken_intra_doc_links)]
3127    #[rustc_const_unstable(feature = "const_binary_search", issue = "159532")]
3128    #[stable(feature = "slice_binary_search_by_key", since = "1.10.0")]
3129    #[inline]
3130    #[ferrocene::prevalidated]
3131    pub const fn binary_search_by_key<'a, B, F>(&'a self, b: &B, mut f: F) -> Result<usize, usize>
3132    where
3133        F: [const] FnMut(&'a T) -> B + [const] Destruct,
3134        B: [const] Ord + [const] Destruct,
3135    {
3136        self.binary_search_by(const |k| f(k).cmp(b))
3137    }
3138
3139    /// Sorts the slice in ascending order **without** preserving the initial order of equal elements.
3140    ///
3141    /// This sort is unstable (i.e., may reorder equal elements), in-place (i.e., does not
3142    /// allocate), and *O*(*n* \* log(*n*)) worst-case.
3143    ///
3144    /// If the implementation of [`Ord`] for `T` does not implement a [total order], the function
3145    /// may panic; even if the function exits normally, the resulting order of elements in the slice
3146    /// is unspecified. See also the note on panicking below.
3147    ///
3148    /// For example `|a, b| (a - b).cmp(a)` is a comparison function that is neither transitive nor
3149    /// reflexive nor total, `a < b < c < a` with `a = 1, b = 2, c = 3`. For more information and
3150    /// examples see the [`Ord`] documentation.
3151    ///
3152    ///
3153    /// All original elements will remain in the slice and any possible modifications via interior
3154    /// mutability are observed in the input. Same is true if the implementation of [`Ord`] for `T` panics.
3155    ///
3156    /// Sorting types that only implement [`PartialOrd`] such as [`f32`] and [`f64`] require
3157    /// additional precautions. For example, `f32::NAN != f32::NAN`, which doesn't fulfill the
3158    /// reflexivity requirement of [`Ord`]. By using an alternative comparison function with
3159    /// `slice::sort_unstable_by` such as [`f32::total_cmp`] or [`f64::total_cmp`] that defines a
3160    /// [total order] users can sort slices containing floating-point values. Alternatively, if all
3161    /// values in the slice are guaranteed to be in a subset for which [`PartialOrd::partial_cmp`]
3162    /// forms a [total order], it's possible to sort the slice with `sort_unstable_by(|a, b|
3163    /// a.partial_cmp(b).unwrap())`.
3164    ///
3165    /// # Current implementation
3166    ///
3167    /// The current implementation is based on [ipnsort] by Lukas Bergdoll and Orson Peters, which
3168    /// combines the fast average case of quicksort with the fast worst case of heapsort, achieving
3169    /// linear time on fully sorted and reversed inputs. On inputs with k distinct elements, the
3170    /// expected time to sort the data is *O*(*n* \* log(*k*)).
3171    ///
3172    /// It is typically faster than stable sorting, except in a few special cases, e.g., when the
3173    /// slice is partially sorted.
3174    ///
3175    /// # Panics
3176    ///
3177    /// May panic if the implementation of [`Ord`] for `T` does not implement a [total order], or if
3178    /// the [`Ord`] implementation panics.
3179    ///
3180    /// # Examples
3181    ///
3182    /// ```
3183    /// let mut v = [4, -5, 1, -3, 2];
3184    ///
3185    /// v.sort_unstable();
3186    /// assert_eq!(v, [-5, -3, 1, 2, 4]);
3187    /// ```
3188    ///
3189    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3190    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3191    #[stable(feature = "sort_unstable", since = "1.20.0")]
3192    #[inline]
3193    pub fn sort_unstable(&mut self)
3194    where
3195        T: Ord,
3196    {
3197        sort::unstable::sort(self, &mut T::lt);
3198    }
3199
3200    /// Sorts the slice in ascending order with a comparison function, **without** preserving the
3201    /// initial order of equal elements.
3202    ///
3203    /// This sort is unstable (i.e., may reorder equal elements), in-place (i.e., does not
3204    /// allocate), and *O*(*n* \* log(*n*)) worst-case.
3205    ///
3206    /// If the comparison function `compare` does not implement a [total order], the function
3207    /// may panic; even if the function exits normally, the resulting order of elements in the slice
3208    /// is unspecified. See also the note on panicking below.
3209    ///
3210    /// For example `|a, b| (a - b).cmp(a)` is a comparison function that is neither transitive nor
3211    /// reflexive nor total, `a < b < c < a` with `a = 1, b = 2, c = 3`. For more information and
3212    /// examples see the [`Ord`] documentation.
3213    ///
3214    /// All original elements will remain in the slice and any possible modifications via interior
3215    /// mutability are observed in the input. Same is true if `compare` panics.
3216    ///
3217    /// # Current implementation
3218    ///
3219    /// The current implementation is based on [ipnsort] by Lukas Bergdoll and Orson Peters, which
3220    /// combines the fast average case of quicksort with the fast worst case of heapsort, achieving
3221    /// linear time on fully sorted and reversed inputs. On inputs with k distinct elements, the
3222    /// expected time to sort the data is *O*(*n* \* log(*k*)).
3223    ///
3224    /// It is typically faster than stable sorting, except in a few special cases, e.g., when the
3225    /// slice is partially sorted.
3226    ///
3227    /// # Panics
3228    ///
3229    /// May panic if the `compare` does not implement a [total order], or if
3230    /// the `compare` itself panics.
3231    ///
3232    /// # Examples
3233    ///
3234    /// ```
3235    /// let mut v = [4, -5, 1, -3, 2];
3236    /// v.sort_unstable_by(|a, b| a.cmp(b));
3237    /// assert_eq!(v, [-5, -3, 1, 2, 4]);
3238    ///
3239    /// // reverse sorting
3240    /// v.sort_unstable_by(|a, b| b.cmp(a));
3241    /// assert_eq!(v, [4, 2, 1, -3, -5]);
3242    /// ```
3243    ///
3244    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3245    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3246    #[stable(feature = "sort_unstable", since = "1.20.0")]
3247    #[inline]
3248    pub fn sort_unstable_by<F>(&mut self, mut compare: F)
3249    where
3250        F: FnMut(&T, &T) -> Ordering,
3251    {
3252        sort::unstable::sort(self, &mut |a, b| compare(a, b) == Ordering::Less);
3253    }
3254
3255    /// Sorts the slice in ascending order with a key extraction function, **without** preserving
3256    /// the initial order of equal elements.
3257    ///
3258    /// This sort is unstable (i.e., may reorder equal elements), in-place (i.e., does not
3259    /// allocate), and *O*(*n* \* log(*n*)) worst-case.
3260    ///
3261    /// If the implementation of [`Ord`] for `K` does not implement a [total order], the function
3262    /// may panic; even if the function exits normally, the resulting order of elements in the slice
3263    /// is unspecified. See also the note on panicking below.
3264    ///
3265    /// For example `|a, b| (a - b).cmp(a)` is a comparison function that is neither transitive nor
3266    /// reflexive nor total, `a < b < c < a` with `a = 1, b = 2, c = 3`. For more information and
3267    /// examples see the [`Ord`] documentation.
3268    ///
3269    /// All original elements will remain in the slice and any possible modifications via interior
3270    /// mutability are observed in the input. Same is true if the implementation of [`Ord`] for `K` panics.
3271    ///
3272    /// # Current implementation
3273    ///
3274    /// The current implementation is based on [ipnsort] by Lukas Bergdoll and Orson Peters, which
3275    /// combines the fast average case of quicksort with the fast worst case of heapsort, achieving
3276    /// linear time on fully sorted and reversed inputs. On inputs with k distinct elements, the
3277    /// expected time to sort the data is *O*(*n* \* log(*k*)).
3278    ///
3279    /// It is typically faster than stable sorting, except in a few special cases, e.g., when the
3280    /// slice is partially sorted.
3281    ///
3282    /// # Panics
3283    ///
3284    /// May panic if the implementation of [`Ord`] for `K` does not implement a [total order], or if
3285    /// the [`Ord`] implementation panics.
3286    ///
3287    /// # Examples
3288    ///
3289    /// ```
3290    /// let mut v = [4i32, -5, 1, -3, 2];
3291    ///
3292    /// v.sort_unstable_by_key(|k| k.abs());
3293    /// assert_eq!(v, [1, 2, -3, 4, -5]);
3294    /// ```
3295    ///
3296    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3297    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3298    #[stable(feature = "sort_unstable", since = "1.20.0")]
3299    #[inline]
3300    pub fn sort_unstable_by_key<K, F>(&mut self, mut f: F)
3301    where
3302        F: FnMut(&T) -> K,
3303        K: Ord,
3304    {
3305        sort::unstable::sort(self, &mut |a, b| f(a).lt(&f(b)));
3306    }
3307
3308    /// Partially sorts the slice in ascending order **without** preserving the initial order of equal elements.
3309    ///
3310    /// Upon completion, for the specified range `start..end`, it's guaranteed that:
3311    ///
3312    /// 1. Every element in `self[..start]` is smaller than or equal to
3313    /// 2. Every element in `self[start..end]`, which is sorted, and smaller than or equal to
3314    /// 3. Every element in `self[end..]`.
3315    ///
3316    /// This partial sort is unstable, meaning it may reorder equal elements in the specified range.
3317    /// It may reorder elements outside the specified range as well, but the guarantees above still hold.
3318    ///
3319    /// This partial sort is in-place (i.e., does not allocate), and *O*(*n* + *k* \* log(*k*)) worst-case,
3320    /// where *n* is the length of the slice and *k* is the length of the specified range.
3321    ///
3322    /// See the documentation of [`sort_unstable`] for implementation notes.
3323    ///
3324    /// # Panics
3325    ///
3326    /// May panic if the implementation of [`Ord`] for `T` does not implement a total order, or if
3327    /// the [`Ord`] implementation panics, or if the specified range is out of bounds.
3328    ///
3329    /// # Examples
3330    ///
3331    /// ```
3332    /// #![feature(slice_partial_sort_unstable)]
3333    ///
3334    /// let mut v = [4, -5, 1, -3, 2];
3335    ///
3336    /// // empty range at the beginning, nothing changed
3337    /// v.partial_sort_unstable(0..0);
3338    /// assert_eq!(v, [4, -5, 1, -3, 2]);
3339    ///
3340    /// // empty range in the middle, partitioning the slice
3341    /// v.partial_sort_unstable(2..2);
3342    /// for i in 0..2 {
3343    ///    assert!(v[i] <= v[2]);
3344    /// }
3345    /// for i in 3..v.len() {
3346    ///   assert!(v[2] <= v[i]);
3347    /// }
3348    ///
3349    /// // single element range, same as select_nth_unstable
3350    /// v.partial_sort_unstable(2..3);
3351    /// for i in 0..2 {
3352    ///    assert!(v[i] <= v[2]);
3353    /// }
3354    /// for i in 3..v.len() {
3355    ///   assert!(v[2] <= v[i]);
3356    /// }
3357    ///
3358    /// // partial sort a subrange
3359    /// v.partial_sort_unstable(1..4);
3360    /// assert_eq!(&v[1..4], [-3, 1, 2]);
3361    ///
3362    /// // partial sort the whole range, same as sort_unstable
3363    /// v.partial_sort_unstable(..);
3364    /// assert_eq!(v, [-5, -3, 1, 2, 4]);
3365    /// ```
3366    ///
3367    /// [`sort_unstable`]: slice::sort_unstable
3368    #[unstable(feature = "slice_partial_sort_unstable", issue = "149046")]
3369    #[inline]
3370    pub fn partial_sort_unstable<R>(&mut self, range: R)
3371    where
3372        T: Ord,
3373        R: RangeBounds<usize>,
3374    {
3375        sort::unstable::partial_sort(self, range, T::lt);
3376    }
3377
3378    /// Partially sorts the slice in ascending order with a comparison function, **without**
3379    /// preserving the initial order of equal elements.
3380    ///
3381    /// Upon completion, for the specified range `start..end`, it's guaranteed that:
3382    ///
3383    /// 1. Every element in `self[..start]` is smaller than or equal to
3384    /// 2. Every element in `self[start..end]`, which is sorted, and smaller than or equal to
3385    /// 3. Every element in `self[end..]`.
3386    ///
3387    /// This partial sort is unstable, meaning it may reorder equal elements in the specified range.
3388    /// It may reorder elements outside the specified range as well, but the guarantees above still hold.
3389    ///
3390    /// This partial sort is in-place (i.e., does not allocate), and *O*(*n* + *k* \* log(*k*)) worst-case,
3391    /// where *n* is the length of the slice and *k* is the length of the specified range.
3392    ///
3393    /// See the documentation of [`sort_unstable_by`] for implementation notes.
3394    ///
3395    /// # Panics
3396    ///
3397    /// May panic if the `compare` does not implement a total order, or if
3398    /// the `compare` itself panics, or if the specified range is out of bounds.
3399    ///
3400    /// # Examples
3401    ///
3402    /// ```
3403    /// #![feature(slice_partial_sort_unstable)]
3404    ///
3405    /// let mut v = [4, -5, 1, -3, 2];
3406    ///
3407    /// // empty range at the beginning, nothing changed
3408    /// v.partial_sort_unstable_by(0..0, |a, b| b.cmp(a));
3409    /// assert_eq!(v, [4, -5, 1, -3, 2]);
3410    ///
3411    /// // empty range in the middle, partitioning the slice
3412    /// v.partial_sort_unstable_by(2..2, |a, b| b.cmp(a));
3413    /// for i in 0..2 {
3414    ///    assert!(v[i] >= v[2]);
3415    /// }
3416    /// for i in 3..v.len() {
3417    ///   assert!(v[2] >= v[i]);
3418    /// }
3419    ///
3420    /// // single element range, same as select_nth_unstable
3421    /// v.partial_sort_unstable_by(2..3, |a, b| b.cmp(a));
3422    /// for i in 0..2 {
3423    ///    assert!(v[i] >= v[2]);
3424    /// }
3425    /// for i in 3..v.len() {
3426    ///   assert!(v[2] >= v[i]);
3427    /// }
3428    ///
3429    /// // partial sort a subrange
3430    /// v.partial_sort_unstable_by(1..4, |a, b| b.cmp(a));
3431    /// assert_eq!(&v[1..4], [2, 1, -3]);
3432    ///
3433    /// // partial sort the whole range, same as sort_unstable
3434    /// v.partial_sort_unstable_by(.., |a, b| b.cmp(a));
3435    /// assert_eq!(v, [4, 2, 1, -3, -5]);
3436    /// ```
3437    ///
3438    /// [`sort_unstable_by`]: slice::sort_unstable_by
3439    #[unstable(feature = "slice_partial_sort_unstable", issue = "149046")]
3440    #[inline]
3441    pub fn partial_sort_unstable_by<F, R>(&mut self, range: R, mut compare: F)
3442    where
3443        F: FnMut(&T, &T) -> Ordering,
3444        R: RangeBounds<usize>,
3445    {
3446        sort::unstable::partial_sort(self, range, |a, b| compare(a, b) == Less);
3447    }
3448
3449    /// Partially sorts the slice in ascending order with a key extraction function, **without**
3450    /// preserving the initial order of equal elements.
3451    ///
3452    /// Upon completion, for the specified range `start..end`, it's guaranteed that:
3453    ///
3454    /// 1. Every element in `self[..start]` is smaller than or equal to
3455    /// 2. Every element in `self[start..end]`, which is sorted, and smaller than or equal to
3456    /// 3. Every element in `self[end..]`.
3457    ///
3458    /// This partial sort is unstable, meaning it may reorder equal elements in the specified range.
3459    /// It may reorder elements outside the specified range as well, but the guarantees above still hold.
3460    ///
3461    /// This partial sort is in-place (i.e., does not allocate), and *O*(*n* + *k* \* log(*k*)) worst-case,
3462    /// where *n* is the length of the slice and *k* is the length of the specified range.
3463    ///
3464    /// See the documentation of [`sort_unstable_by_key`] for implementation notes.
3465    ///
3466    /// # Panics
3467    ///
3468    /// May panic if the implementation of [`Ord`] for `K` does not implement a total order, or if
3469    /// the [`Ord`] implementation panics, or if the specified range is out of bounds.
3470    ///
3471    /// # Examples
3472    ///
3473    /// ```
3474    /// #![feature(slice_partial_sort_unstable)]
3475    ///
3476    /// let mut v = [4i32, -5, 1, -3, 2];
3477    ///
3478    /// // empty range at the beginning, nothing changed
3479    /// v.partial_sort_unstable_by_key(0..0, |k| k.abs());
3480    /// assert_eq!(v, [4, -5, 1, -3, 2]);
3481    ///
3482    /// // empty range in the middle, partitioning the slice
3483    /// v.partial_sort_unstable_by_key(2..2, |k| k.abs());
3484    /// for i in 0..2 {
3485    ///    assert!(v[i].abs() <= v[2].abs());
3486    /// }
3487    /// for i in 3..v.len() {
3488    ///   assert!(v[2].abs() <= v[i].abs());
3489    /// }
3490    ///
3491    /// // single element range, same as select_nth_unstable
3492    /// v.partial_sort_unstable_by_key(2..3, |k| k.abs());
3493    /// for i in 0..2 {
3494    ///    assert!(v[i].abs() <= v[2].abs());
3495    /// }
3496    /// for i in 3..v.len() {
3497    ///   assert!(v[2].abs() <= v[i].abs());
3498    /// }
3499    ///
3500    /// // partial sort a subrange
3501    /// v.partial_sort_unstable_by_key(1..4, |k| k.abs());
3502    /// assert_eq!(&v[1..4], [2, -3, 4]);
3503    ///
3504    /// // partial sort the whole range, same as sort_unstable
3505    /// v.partial_sort_unstable_by_key(.., |k| k.abs());
3506    /// assert_eq!(v, [1, 2, -3, 4, -5]);
3507    /// ```
3508    ///
3509    /// [`sort_unstable_by_key`]: slice::sort_unstable_by_key
3510    #[unstable(feature = "slice_partial_sort_unstable", issue = "149046")]
3511    #[inline]
3512    pub fn partial_sort_unstable_by_key<K, F, R>(&mut self, range: R, mut f: F)
3513    where
3514        F: FnMut(&T) -> K,
3515        K: Ord,
3516        R: RangeBounds<usize>,
3517    {
3518        sort::unstable::partial_sort(self, range, |a, b| f(a).lt(&f(b)));
3519    }
3520
3521    /// Reorders the slice such that the element at `index` is at a sort-order position. All
3522    /// elements before `index` will be `<=` to this value, and all elements after will be `>=` to
3523    /// it.
3524    ///
3525    /// This reordering is unstable (i.e. any element that compares equal to the nth element may end
3526    /// up at that position), in-place (i.e.  does not allocate), and runs in *O*(*n*) time. This
3527    /// function is also known as "kth element" in other libraries.
3528    ///
3529    /// Returns a triple that partitions the reordered slice:
3530    ///
3531    /// * The unsorted subslice before `index`, whose elements all satisfy `x <= self[index]`.
3532    ///
3533    /// * The element at `index`.
3534    ///
3535    /// * The unsorted subslice after `index`, whose elements all satisfy `x >= self[index]`.
3536    ///
3537    /// # Current implementation
3538    ///
3539    /// The current algorithm is an introselect implementation based on [ipnsort] by Lukas Bergdoll
3540    /// and Orson Peters, which is also the basis for [`sort_unstable`]. The fallback algorithm is
3541    /// Median of Medians using Tukey's Ninther for pivot selection, which guarantees linear runtime
3542    /// for all inputs.
3543    ///
3544    /// [`sort_unstable`]: slice::sort_unstable
3545    ///
3546    /// # Panics
3547    ///
3548    /// Panics when `index >= len()`, and so always panics on empty slices.
3549    ///
3550    /// May panic if the implementation of [`Ord`] for `T` does not implement a [total order].
3551    ///
3552    /// # Examples
3553    ///
3554    /// ```
3555    /// let mut v = [-5i32, 4, 2, -3, 1];
3556    ///
3557    /// // Find the items `<=` to the median, the median itself, and the items `>=` to it.
3558    /// let (lesser, median, greater) = v.select_nth_unstable(2);
3559    ///
3560    /// assert!(lesser == [-3, -5] || lesser == [-5, -3]);
3561    /// assert_eq!(median, &mut 1);
3562    /// assert!(greater == [4, 2] || greater == [2, 4]);
3563    ///
3564    /// // We are only guaranteed the slice will be one of the following, based on the way we sort
3565    /// // about the specified index.
3566    /// assert!(v == [-3, -5, 1, 2, 4] ||
3567    ///         v == [-5, -3, 1, 2, 4] ||
3568    ///         v == [-3, -5, 1, 4, 2] ||
3569    ///         v == [-5, -3, 1, 4, 2]);
3570    /// ```
3571    ///
3572    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3573    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3574    #[stable(feature = "slice_select_nth_unstable", since = "1.49.0")]
3575    #[inline]
3576    pub fn select_nth_unstable(&mut self, index: usize) -> (&mut [T], &mut T, &mut [T])
3577    where
3578        T: Ord,
3579    {
3580        sort::select::partition_at_index(self, index, T::lt)
3581    }
3582
3583    /// Reorders the slice with a comparator function such that the element at `index` is at a
3584    /// sort-order position. All elements before `index` will be `<=` to this value, and all
3585    /// elements after will be `>=` to it, according to the comparator function.
3586    ///
3587    /// This reordering is unstable (i.e. any element that compares equal to the nth element may end
3588    /// up at that position), in-place (i.e.  does not allocate), and runs in *O*(*n*) time. This
3589    /// function is also known as "kth element" in other libraries.
3590    ///
3591    /// Returns a triple partitioning the reordered slice:
3592    ///
3593    /// * The unsorted subslice before `index`, whose elements all satisfy
3594    ///   `compare(x, self[index]).is_le()`.
3595    ///
3596    /// * The element at `index`.
3597    ///
3598    /// * The unsorted subslice after `index`, whose elements all satisfy
3599    ///   `compare(x, self[index]).is_ge()`.
3600    ///
3601    /// # Current implementation
3602    ///
3603    /// The current algorithm is an introselect implementation based on [ipnsort] by Lukas Bergdoll
3604    /// and Orson Peters, which is also the basis for [`sort_unstable`]. The fallback algorithm is
3605    /// Median of Medians using Tukey's Ninther for pivot selection, which guarantees linear runtime
3606    /// for all inputs.
3607    ///
3608    /// [`sort_unstable`]: slice::sort_unstable
3609    ///
3610    /// # Panics
3611    ///
3612    /// Panics when `index >= len()`, and so always panics on empty slices.
3613    ///
3614    /// May panic if `compare` does not implement a [total order].
3615    ///
3616    /// # Examples
3617    ///
3618    /// ```
3619    /// let mut v = [-5i32, 4, 2, -3, 1];
3620    ///
3621    /// // Find the items `>=` to the median, the median itself, and the items `<=` to it, by using
3622    /// // a reversed comparator.
3623    /// let (before, median, after) = v.select_nth_unstable_by(2, |a, b| b.cmp(a));
3624    ///
3625    /// assert!(before == [4, 2] || before == [2, 4]);
3626    /// assert_eq!(median, &mut 1);
3627    /// assert!(after == [-3, -5] || after == [-5, -3]);
3628    ///
3629    /// // We are only guaranteed the slice will be one of the following, based on the way we sort
3630    /// // about the specified index.
3631    /// assert!(v == [2, 4, 1, -5, -3] ||
3632    ///         v == [2, 4, 1, -3, -5] ||
3633    ///         v == [4, 2, 1, -5, -3] ||
3634    ///         v == [4, 2, 1, -3, -5]);
3635    /// ```
3636    ///
3637    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3638    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3639    #[stable(feature = "slice_select_nth_unstable", since = "1.49.0")]
3640    #[inline]
3641    pub fn select_nth_unstable_by<F>(
3642        &mut self,
3643        index: usize,
3644        mut compare: F,
3645    ) -> (&mut [T], &mut T, &mut [T])
3646    where
3647        F: FnMut(&T, &T) -> Ordering,
3648    {
3649        sort::select::partition_at_index(self, index, |a: &T, b: &T| compare(a, b) == Less)
3650    }
3651
3652    /// Reorders the slice with a key extraction function such that the element at `index` is at a
3653    /// sort-order position. All elements before `index` will have keys `<=` to the key at `index`,
3654    /// and all elements after will have keys `>=` to it.
3655    ///
3656    /// This reordering is unstable (i.e. any element that compares equal to the nth element may end
3657    /// up at that position), in-place (i.e.  does not allocate), and runs in *O*(*n*) time. This
3658    /// function is also known as "kth element" in other libraries.
3659    ///
3660    /// Returns a triple partitioning the reordered slice:
3661    ///
3662    /// * The unsorted subslice before `index`, whose elements all satisfy `f(x) <= f(self[index])`.
3663    ///
3664    /// * The element at `index`.
3665    ///
3666    /// * The unsorted subslice after `index`, whose elements all satisfy `f(x) >= f(self[index])`.
3667    ///
3668    /// # Current implementation
3669    ///
3670    /// The current algorithm is an introselect implementation based on [ipnsort] by Lukas Bergdoll
3671    /// and Orson Peters, which is also the basis for [`sort_unstable`]. The fallback algorithm is
3672    /// Median of Medians using Tukey's Ninther for pivot selection, which guarantees linear runtime
3673    /// for all inputs.
3674    ///
3675    /// [`sort_unstable`]: slice::sort_unstable
3676    ///
3677    /// # Panics
3678    ///
3679    /// Panics when `index >= len()`, meaning it always panics on empty slices.
3680    ///
3681    /// May panic if `K: Ord` does not implement a total order.
3682    ///
3683    /// # Examples
3684    ///
3685    /// ```
3686    /// let mut v = [-5i32, 4, 1, -3, 2];
3687    ///
3688    /// // Find the items `<=` to the absolute median, the absolute median itself, and the items
3689    /// // `>=` to it.
3690    /// let (lesser, median, greater) = v.select_nth_unstable_by_key(2, |a| a.abs());
3691    ///
3692    /// assert!(lesser == [1, 2] || lesser == [2, 1]);
3693    /// assert_eq!(median, &mut -3);
3694    /// assert!(greater == [4, -5] || greater == [-5, 4]);
3695    ///
3696    /// // We are only guaranteed the slice will be one of the following, based on the way we sort
3697    /// // about the specified index.
3698    /// assert!(v == [1, 2, -3, 4, -5] ||
3699    ///         v == [1, 2, -3, -5, 4] ||
3700    ///         v == [2, 1, -3, 4, -5] ||
3701    ///         v == [2, 1, -3, -5, 4]);
3702    /// ```
3703    ///
3704    /// [ipnsort]: https://github.com/Voultapher/sort-research-rs/tree/main/ipnsort
3705    /// [total order]: https://en.wikipedia.org/wiki/Total_order
3706    #[stable(feature = "slice_select_nth_unstable", since = "1.49.0")]
3707    #[inline]
3708    pub fn select_nth_unstable_by_key<K, F>(
3709        &mut self,
3710        index: usize,
3711        mut f: F,
3712    ) -> (&mut [T], &mut T, &mut [T])
3713    where
3714        F: FnMut(&T) -> K,
3715        K: Ord,
3716    {
3717        sort::select::partition_at_index(self, index, |a: &T, b: &T| f(a).lt(&f(b)))
3718    }
3719
3720    /// Moves all consecutive repeated elements to the end of the slice according to the
3721    /// [`PartialEq`] trait implementation.
3722    ///
3723    /// Returns two slices. The first contains no consecutive repeated elements.
3724    /// The second contains all the duplicates in no specified order.
3725    ///
3726    /// If the slice is sorted, the first returned slice contains no duplicates.
3727    ///
3728    /// # Examples
3729    ///
3730    /// ```
3731    /// #![feature(slice_partition_dedup)]
3732    ///
3733    /// let mut slice = [1, 2, 2, 3, 3, 2, 1, 1];
3734    ///
3735    /// let (dedup, duplicates) = slice.partition_dedup();
3736    ///
3737    /// assert_eq!(dedup, [1, 2, 3, 2, 1]);
3738    /// assert_eq!(duplicates, [2, 3, 1]);
3739    /// ```
3740    #[unstable(feature = "slice_partition_dedup", issue = "54279")]
3741    #[inline]
3742    pub fn partition_dedup(&mut self) -> (&mut [T], &mut [T])
3743    where
3744        T: PartialEq,
3745    {
3746        self.partition_dedup_by(|a, b| a == b)
3747    }
3748
3749    /// Moves all but the first of consecutive elements to the end of the slice that are
3750    /// "equal" according to the given predicate function.
3751    ///
3752    /// Returns two slices. The first contains no consecutive repeated elements.
3753    /// The second contains all the duplicates in no specified order.
3754    ///
3755    /// The predicate `same_bucket(x, p)` is passed references to two elements from
3756    /// the slice and must determine if the elements compare equal. The element `p` occurs
3757    /// *before* `x` in the slice (`[.., p, .., x, ..]`), so `same_bucket(x, p)`
3758    /// is receiving them in reversed order.
3759    ///
3760    /// If the slice is sorted, the first returned slice contains no duplicates. For more
3761    /// complicated predicates however, the order (ascending vs. descending) can matter.
3762    ///
3763    /// Both references passed to `same_bucket` are mutable.
3764    /// This allows merged elements in the first slice by mutating `p` and returning `true`.
3765    ///
3766    /// # Examples
3767    ///
3768    /// ```
3769    /// #![feature(slice_partition_dedup)]
3770    ///
3771    /// let mut slice = ["foo", "Foo", "BAZ", "Bar", "bar", "baz", "BAZ"];
3772    ///
3773    /// let (dedup, duplicates) = slice.partition_dedup_by(|x, p| x.eq_ignore_ascii_case(p));
3774    ///
3775    /// assert_eq!(dedup, ["foo", "BAZ", "Bar", "baz"]);
3776    /// assert_eq!(duplicates, ["bar", "Foo", "BAZ"]);
3777    /// ```
3778    #[unstable(feature = "slice_partition_dedup", issue = "54279")]
3779    #[inline]
3780    pub fn partition_dedup_by<F>(&mut self, mut same_bucket: F) -> (&mut [T], &mut [T])
3781    where
3782        F: FnMut(&mut T, &mut T) -> bool,
3783    {
3784        // Although we have a mutable reference to `self`, we cannot make
3785        // *arbitrary* changes. The `same_bucket` calls could panic, so we
3786        // must ensure that the slice is in a valid state at all times.
3787        //
3788        // The way that we handle this is by using swaps; we iterate
3789        // over all the elements, swapping as we go so that at the end
3790        // the elements we wish to keep are in the front, and those we
3791        // wish to reject are at the back. We can then split the slice.
3792        // This operation is still `O(n)`.
3793        //
3794        // Example: We start in this state, where `r` represents "next
3795        // read" and `w` represents "next_write".
3796        //
3797        //           r
3798        //     +---+---+---+---+---+---+
3799        //     | 0 | 1 | 1 | 2 | 3 | 3 |
3800        //     +---+---+---+---+---+---+
3801        //           w
3802        //
3803        // Comparing self[r] against self[w-1], this is not a duplicate, so
3804        // we swap self[r] and self[w] (no effect as r==w) and then increment both
3805        // r and w, leaving us with:
3806        //
3807        //               r
3808        //     +---+---+---+---+---+---+
3809        //     | 0 | 1 | 1 | 2 | 3 | 3 |
3810        //     +---+---+---+---+---+---+
3811        //               w
3812        //
3813        // Comparing self[r] against self[w-1], this value is a duplicate,
3814        // so we increment `r` but leave everything else unchanged:
3815        //
3816        //                   r
3817        //     +---+---+---+---+---+---+
3818        //     | 0 | 1 | 1 | 2 | 3 | 3 |
3819        //     +---+---+---+---+---+---+
3820        //               w
3821        //
3822        // Comparing self[r] against self[w-1], this is not a duplicate,
3823        // so swap self[r] and self[w] and advance r and w:
3824        //
3825        //                       r
3826        //     +---+---+---+---+---+---+
3827        //     | 0 | 1 | 2 | 1 | 3 | 3 |
3828        //     +---+---+---+---+---+---+
3829        //                   w
3830        //
3831        // Not a duplicate, repeat:
3832        //
3833        //                           r
3834        //     +---+---+---+---+---+---+
3835        //     | 0 | 1 | 2 | 3 | 1 | 3 |
3836        //     +---+---+---+---+---+---+
3837        //                       w
3838        //
3839        // Duplicate, advance r. End of slice. Split at w.
3840
3841        let len = self.len();
3842        if len <= 1 {
3843            return (self, &mut []);
3844        }
3845
3846        let ptr = self.as_mut_ptr();
3847        let mut next_read: usize = 1;
3848        let mut next_write: usize = 1;
3849
3850        // SAFETY: the `while` condition guarantees `next_read` and `next_write`
3851        // are less than `len`, thus are inside `self`. `prev_ptr_write` points to
3852        // one element before `ptr_write`, but `next_write` starts at 1, so
3853        // `prev_ptr_write` is never less than 0 and is inside the slice.
3854        // This fulfills the requirements for dereferencing `ptr_read`, `prev_ptr_write`
3855        // and `ptr_write`, and for using `ptr.add(next_read)`, `ptr.add(next_write - 1)`
3856        // and `prev_ptr_write.offset(1)`.
3857        //
3858        // `next_write` is also incremented at most once per loop at most meaning
3859        // no element is skipped when it may need to be swapped.
3860        //
3861        // `ptr_read` and `prev_ptr_write` never point to the same element. This
3862        // is required for `&mut *ptr_read`, `&mut *prev_ptr_write` to be safe.
3863        // The explanation is simply that `next_read >= next_write` is always true,
3864        // thus `next_read > next_write - 1` is too.
3865        unsafe {
3866            // Avoid bounds checks by using raw pointers.
3867            while next_read < len {
3868                let ptr_read = ptr.add(next_read);
3869                let prev_ptr_write = ptr.add(next_write - 1);
3870                if !same_bucket(&mut *ptr_read, &mut *prev_ptr_write) {
3871                    if next_read != next_write {
3872                        let ptr_write = prev_ptr_write.add(1);
3873                        mem::swap(&mut *ptr_read, &mut *ptr_write);
3874                    }
3875                    next_write += 1;
3876                }
3877                next_read += 1;
3878            }
3879        }
3880
3881        self.split_at_mut(next_write)
3882    }
3883
3884    /// Moves all but the first of consecutive elements to the end of the slice that resolve
3885    /// to the same key.
3886    ///
3887    /// Returns two slices. The first contains no consecutive repeated elements.
3888    /// The second contains all the duplicates in no specified order.
3889    ///
3890    /// If the slice is sorted, the first returned slice contains no duplicates.
3891    ///
3892    /// # Examples
3893    ///
3894    /// ```
3895    /// #![feature(slice_partition_dedup)]
3896    ///
3897    /// let mut slice = [10, 20, 21, 30, 30, 20, 11, 13];
3898    ///
3899    /// let (dedup, duplicates) = slice.partition_dedup_by_key(|i| *i / 10);
3900    ///
3901    /// assert_eq!(dedup, [10, 20, 30, 20, 11]);
3902    /// assert_eq!(duplicates, [21, 30, 13]);
3903    /// ```
3904    #[unstable(feature = "slice_partition_dedup", issue = "54279")]
3905    #[inline]
3906    pub fn partition_dedup_by_key<K, F>(&mut self, mut key: F) -> (&mut [T], &mut [T])
3907    where
3908        F: FnMut(&mut T) -> K,
3909        K: PartialEq,
3910    {
3911        self.partition_dedup_by(|a, b| key(a) == key(b))
3912    }
3913
3914    /// Rotates the slice in-place such that the first `mid` elements of the
3915    /// slice move to the end while the last `self.len() - mid` elements move to
3916    /// the front.
3917    ///
3918    /// After calling `rotate_left`, the element previously at index `mid` will
3919    /// become the first element in the slice.
3920    ///
3921    /// # Panics
3922    ///
3923    /// This function will panic if `mid` is greater than the length of the
3924    /// slice. Note that `mid == self.len()` does _not_ panic and is a no-op
3925    /// rotation.
3926    ///
3927    /// # Complexity
3928    ///
3929    /// Takes linear (in `self.len()`) time.
3930    ///
3931    /// # Examples
3932    ///
3933    /// ```
3934    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
3935    /// a.rotate_left(2);
3936    /// assert_eq!(a, ['c', 'd', 'e', 'f', 'a', 'b']);
3937    /// ```
3938    ///
3939    /// Rotating a subslice:
3940    ///
3941    /// ```
3942    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
3943    /// a[1..5].rotate_left(1);
3944    /// assert_eq!(a, ['a', 'c', 'd', 'e', 'b', 'f']);
3945    /// ```
3946    #[stable(feature = "slice_rotate", since = "1.26.0")]
3947    #[rustc_const_stable(feature = "const_slice_rotate", since = "1.92.0")]
3948    #[ferrocene::prevalidated]
3949    pub const fn rotate_left(&mut self, mid: usize) {
3950        assert!(mid <= self.len());
3951        let k = self.len() - mid;
3952        let p = self.as_mut_ptr();
3953
3954        // SAFETY: The range `[p.add(mid) - mid, p.add(mid) + k)` is trivially
3955        // valid for reading and writing, as required by `ptr_rotate`.
3956        unsafe {
3957            rotate::ptr_rotate(mid, p.add(mid), k);
3958        }
3959    }
3960
3961    /// Rotates the slice in-place such that the first `self.len() - k`
3962    /// elements of the slice move to the end while the last `k` elements move
3963    /// to the front.
3964    ///
3965    /// After calling `rotate_right`, the element previously at index
3966    /// `self.len() - k` will become the first element in the slice.
3967    ///
3968    /// # Panics
3969    ///
3970    /// This function will panic if `k` is greater than the length of the
3971    /// slice. Note that `k == self.len()` does _not_ panic and is a no-op
3972    /// rotation.
3973    ///
3974    /// # Complexity
3975    ///
3976    /// Takes linear (in `self.len()`) time.
3977    ///
3978    /// # Examples
3979    ///
3980    /// ```
3981    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
3982    /// a.rotate_right(2);
3983    /// assert_eq!(a, ['e', 'f', 'a', 'b', 'c', 'd']);
3984    /// ```
3985    ///
3986    /// Rotating a subslice:
3987    ///
3988    /// ```
3989    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
3990    /// a[1..5].rotate_right(1);
3991    /// assert_eq!(a, ['a', 'e', 'b', 'c', 'd', 'f']);
3992    /// ```
3993    #[stable(feature = "slice_rotate", since = "1.26.0")]
3994    #[rustc_const_stable(feature = "const_slice_rotate", since = "1.92.0")]
3995    #[ferrocene::prevalidated]
3996    pub const fn rotate_right(&mut self, k: usize) {
3997        assert!(k <= self.len());
3998        let mid = self.len() - k;
3999        let p = self.as_mut_ptr();
4000
4001        // SAFETY: The range `[p.add(mid) - mid, p.add(mid) + k)` is trivially
4002        // valid for reading and writing, as required by `ptr_rotate`.
4003        unsafe {
4004            rotate::ptr_rotate(mid, p.add(mid), k);
4005        }
4006    }
4007
4008    /// Moves the elements of this slice `N` places to the left, returning the ones
4009    /// that "fall off" the front, and putting `inserted` at the end.
4010    ///
4011    /// Equivalently, you can think of concatenating `self` and `inserted` into one
4012    /// long sequence, then returning the left-most `N` items and the rest into `self`:
4013    ///
4014    /// ```text
4015    ///           self (before)    inserted
4016    ///           vvvvvvvvvvvvvvv  vvv
4017    ///           [1, 2, 3, 4, 5]  [9]
4018    ///        ↙   ↙  ↙  ↙  ↙   ↙
4019    ///      [1]  [2, 3, 4, 5, 9]
4020    ///      ^^^  ^^^^^^^^^^^^^^^
4021    /// returned  self (after)
4022    /// ```
4023    ///
4024    /// See also [`Self::shift_right`] and compare [`Self::rotate_left`].
4025    ///
4026    /// # Examples
4027    ///
4028    /// ```
4029    /// #![feature(slice_shift)]
4030    ///
4031    /// // Same as the diagram above
4032    /// let mut a = [1, 2, 3, 4, 5];
4033    /// let inserted = [9];
4034    /// let returned = a.shift_left(inserted);
4035    /// assert_eq!(returned, [1]);
4036    /// assert_eq!(a, [2, 3, 4, 5, 9]);
4037    ///
4038    /// // You can shift multiple items at a time
4039    /// let mut a = *b"Hello world";
4040    /// assert_eq!(a.shift_left(*b" peace"), *b"Hello ");
4041    /// assert_eq!(a, *b"world peace");
4042    ///
4043    /// // The name comes from this operation's similarity to bitshifts
4044    /// let mut a: u8 = 0b10010110;
4045    /// a <<= 3;
4046    /// assert_eq!(a, 0b10110000_u8);
4047    /// let mut a: [_; 8] = [1, 0, 0, 1, 0, 1, 1, 0];
4048    /// a.shift_left([0; 3]);
4049    /// assert_eq!(a, [1, 0, 1, 1, 0, 0, 0, 0]);
4050    ///
4051    /// // Remember you can sub-slice to affect less that the whole slice.
4052    /// // For example, this is similar to `.remove(1)` + `.insert(4, 'Z')`
4053    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
4054    /// assert_eq!(a[1..=4].shift_left(['Z']), ['b']);
4055    /// assert_eq!(a, ['a', 'c', 'd', 'e', 'Z', 'f']);
4056    ///
4057    /// // If the size matches it's equivalent to `mem::replace`
4058    /// let mut a = [1, 2, 3];
4059    /// assert_eq!(a.shift_left([7, 8, 9]), [1, 2, 3]);
4060    /// assert_eq!(a, [7, 8, 9]);
4061    ///
4062    /// // Some of the "inserted" elements end up returned if the slice is too short
4063    /// let mut a = [];
4064    /// assert_eq!(a.shift_left([1, 2, 3]), [1, 2, 3]);
4065    /// let mut a = [9];
4066    /// assert_eq!(a.shift_left([1, 2, 3]), [9, 1, 2]);
4067    /// assert_eq!(a, [3]);
4068    /// ```
4069    #[unstable(feature = "slice_shift", issue = "151772")]
4070    pub const fn shift_left<const N: usize>(&mut self, inserted: [T; N]) -> [T; N] {
4071        if let Some(shift) = self.len().checked_sub(N) {
4072            // SAFETY: Having just checked that the inserted/returned arrays are
4073            // shorter than (or the same length as) the slice:
4074            // 1. The read for the items to return is in-bounds
4075            // 2. We can `memmove` the slice over to cover the items we're returning
4076            //    to ensure those aren't double-dropped
4077            // 3. Then we write (in-bounds for the same reason as the read) the
4078            //    inserted items atop the items of the slice that we just duplicated
4079            //
4080            // And none of this can panic, so there's no risk of intermediate unwinds.
4081            unsafe {
4082                let ptr = self.as_mut_ptr();
4083                let returned = ptr.cast_array::<N>().read();
4084                ptr.copy_from(ptr.add(N), shift);
4085                ptr.add(shift).cast_array::<N>().write(inserted);
4086                returned
4087            }
4088        } else {
4089            // SAFETY: Having checked that the slice is strictly shorter than the
4090            // inserted/returned arrays, it means we'll be copying the whole slice
4091            // into the returned array, but that's not enough on its own.  We also
4092            // need to copy some of the inserted array into the returned array,
4093            // with the rest going into the slice.  Because `&mut` is exclusive
4094            // and we own both `inserted` and `returned`, they're all disjoint
4095            // allocations from each other as we can use `nonoverlapping` copies.
4096            //
4097            // We avoid double-frees by `ManuallyDrop`ing the inserted items,
4098            // since we always copy them to other locations that will drop them
4099            // instead.  Plus nothing in here can panic -- it's just memcpy three
4100            // times -- so there's no intermediate unwinds to worry about.
4101            unsafe {
4102                let len = self.len();
4103                let slice = self.as_mut_ptr();
4104                let inserted = mem::ManuallyDrop::new(inserted);
4105                let inserted = (&raw const inserted).cast::<T>();
4106
4107                let mut returned = MaybeUninit::<[T; N]>::uninit();
4108                let ptr = returned.as_mut_ptr().cast::<T>();
4109                ptr.copy_from_nonoverlapping(slice, len);
4110                ptr.add(len).copy_from_nonoverlapping(inserted, N - len);
4111                slice.copy_from_nonoverlapping(inserted.add(N - len), len);
4112                returned.assume_init()
4113            }
4114        }
4115    }
4116
4117    /// Moves the elements of this slice `N` places to the right, returning the ones
4118    /// that "fall off" the back, and putting `inserted` at the beginning.
4119    ///
4120    /// Equivalently, you can think of concatenating `inserted` and `self` into one
4121    /// long sequence, then returning the right-most `N` items and the rest into `self`:
4122    ///
4123    /// ```text
4124    /// inserted  self (before)
4125    ///      vvv  vvvvvvvvvvvvvvv
4126    ///      [0]  [5, 6, 7, 8, 9]
4127    ///        ↘   ↘  ↘  ↘  ↘   ↘
4128    ///           [0, 5, 6, 7, 8]  [9]
4129    ///           ^^^^^^^^^^^^^^^  ^^^
4130    ///           self (after)     returned
4131    /// ```
4132    ///
4133    /// See also [`Self::shift_left`] and compare [`Self::rotate_right`].
4134    ///
4135    /// # Examples
4136    ///
4137    /// ```
4138    /// #![feature(slice_shift)]
4139    ///
4140    /// // Same as the diagram above
4141    /// let mut a = [5, 6, 7, 8, 9];
4142    /// let inserted = [0];
4143    /// let returned = a.shift_right(inserted);
4144    /// assert_eq!(returned, [9]);
4145    /// assert_eq!(a, [0, 5, 6, 7, 8]);
4146    ///
4147    /// // The name comes from this operation's similarity to bitshifts
4148    /// let mut a: u8 = 0b10010110;
4149    /// a >>= 3;
4150    /// assert_eq!(a, 0b00010010_u8);
4151    /// let mut a: [_; 8] = [1, 0, 0, 1, 0, 1, 1, 0];
4152    /// a.shift_right([0; 3]);
4153    /// assert_eq!(a, [0, 0, 0, 1, 0, 0, 1, 0]);
4154    ///
4155    /// // Remember you can sub-slice to affect less that the whole slice.
4156    /// // For example, this is similar to `.remove(4)` + `.insert(1, 'Z')`
4157    /// let mut a = ['a', 'b', 'c', 'd', 'e', 'f'];
4158    /// assert_eq!(a[1..=4].shift_right(['Z']), ['e']);
4159    /// assert_eq!(a, ['a', 'Z', 'b', 'c', 'd', 'f']);
4160    ///
4161    /// // If the size matches it's equivalent to `mem::replace`
4162    /// let mut a = [1, 2, 3];
4163    /// assert_eq!(a.shift_right([7, 8, 9]), [1, 2, 3]);
4164    /// assert_eq!(a, [7, 8, 9]);
4165    ///
4166    /// // Some of the "inserted" elements end up returned if the slice is too short
4167    /// let mut a = [];
4168    /// assert_eq!(a.shift_right([1, 2, 3]), [1, 2, 3]);
4169    /// let mut a = [9];
4170    /// assert_eq!(a.shift_right([1, 2, 3]), [2, 3, 9]);
4171    /// assert_eq!(a, [1]);
4172    /// ```
4173    #[unstable(feature = "slice_shift", issue = "151772")]
4174    pub const fn shift_right<const N: usize>(&mut self, inserted: [T; N]) -> [T; N] {
4175        if let Some(shift) = self.len().checked_sub(N) {
4176            // SAFETY: Having just checked that the inserted/returned arrays are
4177            // shorter than (or the same length as) the slice:
4178            // 1. The read for the items to return is in-bounds
4179            // 2. We can `memmove` the slice over to cover the items we're returning
4180            //    to ensure those aren't double-dropped
4181            // 3. Then we write (in-bounds for the same reason as the read) the
4182            //    inserted items atop the items of the slice that we just duplicated
4183            //
4184            // And none of this can panic, so there's no risk of intermediate unwinds.
4185            unsafe {
4186                let ptr = self.as_mut_ptr();
4187                let returned = ptr.add(shift).cast_array::<N>().read();
4188                ptr.add(N).copy_from(ptr, shift);
4189                ptr.cast_array::<N>().write(inserted);
4190                returned
4191            }
4192        } else {
4193            // SAFETY: Having checked that the slice is strictly shorter than the
4194            // inserted/returned arrays, it means we'll be copying the whole slice
4195            // into the returned array, but that's not enough on its own.  We also
4196            // need to copy some of the inserted array into the returned array,
4197            // with the rest going into the slice.  Because `&mut` is exclusive
4198            // and we own both `inserted` and `returned`, they're all disjoint
4199            // allocations from each other as we can use `nonoverlapping` copies.
4200            //
4201            // We avoid double-frees by `ManuallyDrop`ing the inserted items,
4202            // since we always copy them to other locations that will drop them
4203            // instead.  Plus nothing in here can panic -- it's just memcpy three
4204            // times -- so there's no intermediate unwinds to worry about.
4205            unsafe {
4206                let len = self.len();
4207                let slice = self.as_mut_ptr();
4208                let inserted = mem::ManuallyDrop::new(inserted);
4209                let inserted = (&raw const inserted).cast::<T>();
4210
4211                let mut returned = MaybeUninit::<[T; N]>::uninit();
4212                let ptr = returned.as_mut_ptr().cast::<T>();
4213                ptr.add(N - len).copy_from_nonoverlapping(slice, len);
4214                ptr.copy_from_nonoverlapping(inserted.add(len), N - len);
4215                slice.copy_from_nonoverlapping(inserted, len);
4216                returned.assume_init()
4217            }
4218        }
4219    }
4220
4221    /// Fills `self` with elements by cloning `value`.
4222    ///
4223    /// # Examples
4224    ///
4225    /// ```
4226    /// let mut buf = vec![0; 10];
4227    /// buf.fill(1);
4228    /// assert_eq!(buf, vec![1; 10]);
4229    /// ```
4230    #[doc(alias = "memset")]
4231    #[stable(feature = "slice_fill", since = "1.50.0")]
4232    #[ferrocene::prevalidated]
4233    pub fn fill(&mut self, value: T)
4234    where
4235        T: Clone,
4236    {
4237        specialize::SpecFill::spec_fill(self, value);
4238    }
4239
4240    /// Fills `self` with elements returned by calling a closure repeatedly.
4241    ///
4242    /// This method uses a closure to create new values. If you'd rather
4243    /// [`Clone`] a given value, use [`fill`]. If you want to use the [`Default`]
4244    /// trait to generate values, you can pass [`Default::default`] as the
4245    /// argument.
4246    ///
4247    /// [`fill`]: slice::fill
4248    ///
4249    /// # Examples
4250    ///
4251    /// ```
4252    /// let mut buf = vec![1; 10];
4253    /// buf.fill_with(Default::default);
4254    /// assert_eq!(buf, vec![0; 10]);
4255    /// ```
4256    #[stable(feature = "slice_fill_with", since = "1.51.0")]
4257    pub fn fill_with<F>(&mut self, mut f: F)
4258    where
4259        F: FnMut() -> T,
4260    {
4261        for el in self {
4262            *el = f();
4263        }
4264    }
4265
4266    /// Copies the elements from `src` into `self`.
4267    ///
4268    /// The length of `src` must be the same as `self`.
4269    ///
4270    /// # Panics
4271    ///
4272    /// This function will panic if the two slices have different lengths.
4273    ///
4274    /// # Examples
4275    ///
4276    /// Cloning two elements from a slice into another:
4277    ///
4278    /// ```
4279    /// let src = [1, 2, 3, 4];
4280    /// let mut dst = [0, 0];
4281    ///
4282    /// // Because the slices have to be the same length,
4283    /// // we slice the source slice from four elements
4284    /// // to two. It will panic if we don't do this.
4285    /// dst.clone_from_slice(&src[2..]);
4286    ///
4287    /// assert_eq!(src, [1, 2, 3, 4]);
4288    /// assert_eq!(dst, [3, 4]);
4289    /// ```
4290    ///
4291    /// Rust enforces that there can only be one mutable reference with no
4292    /// immutable references to a particular piece of data in a particular
4293    /// scope. Because of this, attempting to use `clone_from_slice` on a
4294    /// single slice will result in a compile failure:
4295    ///
4296    /// ```compile_fail
4297    /// let mut slice = [1, 2, 3, 4, 5];
4298    ///
4299    /// slice[..2].clone_from_slice(&slice[3..]); // compile fail!
4300    /// ```
4301    ///
4302    /// To work around this, we can use [`split_at_mut`] to create two distinct
4303    /// sub-slices from a slice:
4304    ///
4305    /// ```
4306    /// let mut slice = [1, 2, 3, 4, 5];
4307    ///
4308    /// {
4309    ///     let (left, right) = slice.split_at_mut(2);
4310    ///     left.clone_from_slice(&right[1..]);
4311    /// }
4312    ///
4313    /// assert_eq!(slice, [4, 5, 3, 4, 5]);
4314    /// ```
4315    ///
4316    /// [`copy_from_slice`]: slice::copy_from_slice
4317    /// [`split_at_mut`]: slice::split_at_mut
4318    #[stable(feature = "clone_from_slice", since = "1.7.0")]
4319    #[track_caller]
4320    #[rustc_const_unstable(feature = "const_clone", issue = "142757")]
4321    #[ferrocene::prevalidated]
4322    pub const fn clone_from_slice(&mut self, src: &[T])
4323    where
4324        T: [const] Clone + [const] Destruct,
4325    {
4326        self.spec_clone_from(src);
4327    }
4328
4329    /// Copies all elements from `src` into `self`, using a memcpy.
4330    ///
4331    /// The length of `src` must be the same as `self`.
4332    ///
4333    /// If `T` does not implement `Copy`, use [`clone_from_slice`].
4334    ///
4335    /// # Panics
4336    ///
4337    /// This function will panic if the two slices have different lengths.
4338    ///
4339    /// # Examples
4340    ///
4341    /// Copying two elements from a slice into another:
4342    ///
4343    /// ```
4344    /// let src = [1, 2, 3, 4];
4345    /// let mut dst = [0, 0];
4346    ///
4347    /// // Because the slices have to be the same length,
4348    /// // we slice the source slice from four elements
4349    /// // to two. It will panic if we don't do this.
4350    /// dst.copy_from_slice(&src[2..]);
4351    ///
4352    /// assert_eq!(src, [1, 2, 3, 4]);
4353    /// assert_eq!(dst, [3, 4]);
4354    /// ```
4355    ///
4356    /// Rust enforces that there can only be one mutable reference with no
4357    /// immutable references to a particular piece of data in a particular
4358    /// scope. Because of this, attempting to use `copy_from_slice` on a
4359    /// single slice will result in a compile failure:
4360    ///
4361    /// ```compile_fail
4362    /// let mut slice = [1, 2, 3, 4, 5];
4363    ///
4364    /// slice[..2].copy_from_slice(&slice[3..]); // compile fail!
4365    /// ```
4366    ///
4367    /// To work around this, we can use [`split_at_mut`] to create two distinct
4368    /// sub-slices from a slice:
4369    ///
4370    /// ```
4371    /// let mut slice = [1, 2, 3, 4, 5];
4372    ///
4373    /// {
4374    ///     let (left, right) = slice.split_at_mut(2);
4375    ///     left.copy_from_slice(&right[1..]);
4376    /// }
4377    ///
4378    /// assert_eq!(slice, [4, 5, 3, 4, 5]);
4379    /// ```
4380    ///
4381    /// [`clone_from_slice`]: slice::clone_from_slice
4382    /// [`split_at_mut`]: slice::split_at_mut
4383    #[doc(alias = "memcpy")]
4384    #[inline]
4385    #[stable(feature = "copy_from_slice", since = "1.9.0")]
4386    #[rustc_const_stable(feature = "const_copy_from_slice", since = "1.87.0")]
4387    #[track_caller]
4388    #[ferrocene::prevalidated]
4389    pub const fn copy_from_slice(&mut self, src: &[T])
4390    where
4391        T: Copy,
4392    {
4393        // SAFETY: `T` implements `Copy`.
4394        unsafe { copy_from_slice_impl(self, src) }
4395    }
4396
4397    /// Copies elements from one part of the slice to another part of itself,
4398    /// using a memmove.
4399    ///
4400    /// `src` is the range within `self` to copy from. `dest` is the starting
4401    /// index of the range within `self` to copy to, which will have the same
4402    /// length as `src`. The two ranges may overlap. The ends of the two ranges
4403    /// must be less than or equal to `self.len()`.
4404    ///
4405    /// # Panics
4406    ///
4407    /// This function will panic if either range exceeds the end of the slice,
4408    /// or if the end of `src` is before the start.
4409    ///
4410    /// # Examples
4411    ///
4412    /// Copying four bytes within a slice:
4413    ///
4414    /// ```
4415    /// let mut bytes = *b"Hello, World!";
4416    ///
4417    /// bytes.copy_within(1..5, 8);
4418    ///
4419    /// assert_eq!(&bytes, b"Hello, Wello!");
4420    /// ```
4421    #[inline]
4422    #[stable(feature = "copy_within", since = "1.37.0")]
4423    #[track_caller]
4424    pub fn copy_within<R: RangeBounds<usize>>(&mut self, src: R, dest: usize)
4425    where
4426        T: Copy,
4427    {
4428        let Range { start: src_start, end: src_end } = slice::range(src, ..self.len());
4429        let count = src_end - src_start;
4430        assert!(dest <= self.len() - count, "dest is out of bounds");
4431        // SAFETY: the conditions for `ptr::copy` have all been checked above,
4432        // as have those for `ptr::add`.
4433        unsafe {
4434            // Derive both `src_ptr` and `dest_ptr` from the same loan
4435            let ptr = self.as_mut_ptr();
4436            let src_ptr = ptr.add(src_start);
4437            let dest_ptr = ptr.add(dest);
4438            ptr::copy(src_ptr, dest_ptr, count);
4439        }
4440    }
4441
4442    /// Swaps all elements in `self` with those in `other`.
4443    ///
4444    /// The length of `other` must be the same as `self`.
4445    ///
4446    /// # Panics
4447    ///
4448    /// This function will panic if the two slices have different lengths.
4449    ///
4450    /// # Example
4451    ///
4452    /// Swapping two elements across slices:
4453    ///
4454    /// ```
4455    /// let mut slice1 = [0, 0];
4456    /// let mut slice2 = [1, 2, 3, 4];
4457    ///
4458    /// slice1.swap_with_slice(&mut slice2[2..]);
4459    ///
4460    /// assert_eq!(slice1, [3, 4]);
4461    /// assert_eq!(slice2, [1, 2, 0, 0]);
4462    /// ```
4463    ///
4464    /// Rust enforces that there can only be one mutable reference to a
4465    /// particular piece of data in a particular scope. Because of this,
4466    /// attempting to use `swap_with_slice` on a single slice will result in
4467    /// a compile failure:
4468    ///
4469    /// ```compile_fail
4470    /// let mut slice = [1, 2, 3, 4, 5];
4471    /// slice[..2].swap_with_slice(&mut slice[3..]); // compile fail!
4472    /// ```
4473    ///
4474    /// To work around this, we can use [`split_at_mut`] to create two distinct
4475    /// mutable sub-slices from a slice:
4476    ///
4477    /// ```
4478    /// let mut slice = [1, 2, 3, 4, 5];
4479    ///
4480    /// {
4481    ///     let (left, right) = slice.split_at_mut(2);
4482    ///     left.swap_with_slice(&mut right[1..]);
4483    /// }
4484    ///
4485    /// assert_eq!(slice, [4, 5, 3, 1, 2]);
4486    /// ```
4487    ///
4488    /// [`split_at_mut`]: slice::split_at_mut
4489    #[stable(feature = "swap_with_slice", since = "1.27.0")]
4490    #[rustc_const_unstable(feature = "const_swap_with_slice", issue = "142204")]
4491    #[track_caller]
4492    pub const fn swap_with_slice(&mut self, other: &mut [T]) {
4493        assert!(self.len() == other.len(), "destination and source slices have different lengths");
4494        // SAFETY: `self` is valid for `self.len()` elements by definition, and `src` was
4495        // checked to have the same length. The slices cannot overlap because
4496        // mutable references are exclusive.
4497        unsafe {
4498            ptr::swap_nonoverlapping(self.as_mut_ptr(), other.as_mut_ptr(), self.len());
4499        }
4500    }
4501
4502    /// Function to calculate lengths of the middle and trailing slice for `align_to{,_mut}`.
4503
4504    #[ferrocene::prevalidated]
4505    fn align_to_offsets<U>(&self) -> (usize, usize) {
4506        // What we gonna do about `rest` is figure out what multiple of `U`s we can put in a
4507        // lowest number of `T`s. And how many `T`s we need for each such "multiple".
4508        //
4509        // Consider for example T=u8 U=u16. Then we can put 1 U in 2 Ts. Simple. Now, consider
4510        // for example a case where size_of::<T> = 16, size_of::<U> = 24. We can put 2 Us in
4511        // place of every 3 Ts in the `rest` slice. A bit more complicated.
4512        //
4513        // Formula to calculate this is:
4514        //
4515        // Us = lcm(size_of::<T>, size_of::<U>) / size_of::<U>
4516        // Ts = lcm(size_of::<T>, size_of::<U>) / size_of::<T>
4517        //
4518        // Expanded and simplified:
4519        //
4520        // Us = size_of::<T> / gcd(size_of::<T>, size_of::<U>)
4521        // Ts = size_of::<U> / gcd(size_of::<T>, size_of::<U>)
4522        //
4523        // Luckily since all this is constant-evaluated... performance here matters not!
4524        #[ferrocene::annotation(
4525            "the only use of this function is in a const block, which means it cannot be reached during runtime"
4526        )]
4527        #[ferrocene::prevalidated]
4528        const fn gcd(a: usize, b: usize) -> usize {
4529            if b == 0 { a } else { gcd(b, a % b) }
4530        }
4531
4532        // Explicitly wrap the function call in a const block so it gets
4533        // constant-evaluated even in debug mode.
4534        let gcd: usize = const { gcd(size_of::<T>(), size_of::<U>()) };
4535        let ts: usize = size_of::<U>() / gcd;
4536        let us: usize = size_of::<T>() / gcd;
4537
4538        // Armed with this knowledge, we can find how many `U`s we can fit!
4539        let us_len = self.len() / ts * us;
4540        // And how many `T`s will be in the trailing slice!
4541        let ts_len = self.len() % ts;
4542        (us_len, ts_len)
4543    }
4544
4545    /// Transmutes the slice to a slice of another type, ensuring alignment of the types is
4546    /// maintained.
4547    ///
4548    /// This method splits the slice into three distinct slices: prefix, correctly aligned middle
4549    /// slice of a new type, and the suffix slice. The middle part will be as big as possible under
4550    /// the given alignment constraint and element size.
4551    ///
4552    /// This method has no purpose when either input element `T` or output element `U` are
4553    /// zero-sized and will return the original slice without splitting anything.
4554    ///
4555    /// # Safety
4556    ///
4557    /// This method is essentially a `transmute` with respect to the elements in the returned
4558    /// middle slice, so all the usual caveats pertaining to `transmute::<T, U>` also apply here.
4559    ///
4560    /// # Examples
4561    ///
4562    /// Basic usage:
4563    ///
4564    /// ```
4565    /// unsafe {
4566    ///     let bytes: [u8; 7] = [1, 2, 3, 4, 5, 6, 7];
4567    ///     let (prefix, shorts, suffix) = bytes.align_to::<u16>();
4568    ///     // less_efficient_algorithm_for_bytes(prefix);
4569    ///     // more_efficient_algorithm_for_aligned_shorts(shorts);
4570    ///     // less_efficient_algorithm_for_bytes(suffix);
4571    /// }
4572    /// ```
4573    #[stable(feature = "slice_align_to", since = "1.30.0")]
4574    #[must_use]
4575    #[ferrocene::prevalidated]
4576    pub unsafe fn align_to<U>(&self) -> (&[T], &[U], &[T]) {
4577        // Note that most of this function will be constant-evaluated,
4578        if U::IS_ZST || T::IS_ZST {
4579            // handle ZSTs specially, which is – don't handle them at all.
4580            return (self, &[], &[]);
4581        }
4582
4583        // First, find at what point do we split between the first and 2nd slice. Easy with
4584        // ptr.align_offset.
4585        let ptr = self.as_ptr();
4586        // SAFETY: See the `align_to_mut` method for the detailed safety comment.
4587        let offset = unsafe { crate::ptr::align_offset(ptr, align_of::<U>()) };
4588        if offset > self.len() {
4589            (self, &[], &[])
4590        } else {
4591            let (left, rest) = self.split_at(offset);
4592            let (us_len, ts_len) = rest.align_to_offsets::<U>();
4593            // Inform Miri that we want to consider the "middle" pointer to be suitably aligned.
4594            #[cfg(miri)]
4595            crate::intrinsics::miri_promise_symbolic_alignment(
4596                rest.as_ptr().cast(),
4597                align_of::<U>(),
4598            );
4599            // SAFETY: now `rest` is definitely aligned, so `from_raw_parts` below is okay,
4600            // since the caller guarantees that we can transmute `T` to `U` safely.
4601            unsafe {
4602                (
4603                    left,
4604                    from_raw_parts(rest.as_ptr() as *const U, us_len),
4605                    from_raw_parts(rest.as_ptr().add(rest.len() - ts_len), ts_len),
4606                )
4607            }
4608        }
4609    }
4610
4611    /// Transmutes the mutable slice to a mutable slice of another type, ensuring alignment of the
4612    /// types is maintained.
4613    ///
4614    /// This method splits the slice into three distinct slices: prefix, correctly aligned middle
4615    /// slice of a new type, and the suffix slice. The middle part will be as big as possible under
4616    /// the given alignment constraint and element size.
4617    ///
4618    /// This method has no purpose when either input element `T` or output element `U` are
4619    /// zero-sized and will return the original slice without splitting anything.
4620    ///
4621    /// # Safety
4622    ///
4623    /// This method is essentially a `transmute` with respect to the elements in the returned
4624    /// middle slice, so all the usual caveats pertaining to `transmute::<T, U>` also apply here.
4625    ///
4626    /// # Examples
4627    ///
4628    /// Basic usage:
4629    ///
4630    /// ```
4631    /// unsafe {
4632    ///     let mut bytes: [u8; 7] = [1, 2, 3, 4, 5, 6, 7];
4633    ///     let (prefix, shorts, suffix) = bytes.align_to_mut::<u16>();
4634    ///     // less_efficient_algorithm_for_bytes(prefix);
4635    ///     // more_efficient_algorithm_for_aligned_shorts(shorts);
4636    ///     // less_efficient_algorithm_for_bytes(suffix);
4637    /// }
4638    /// ```
4639    #[stable(feature = "slice_align_to", since = "1.30.0")]
4640    #[must_use]
4641    #[ferrocene::prevalidated]
4642    pub unsafe fn align_to_mut<U>(&mut self) -> (&mut [T], &mut [U], &mut [T]) {
4643        // Note that most of this function will be constant-evaluated,
4644        if U::IS_ZST || T::IS_ZST {
4645            // handle ZSTs specially, which is – don't handle them at all.
4646            return (self, &mut [], &mut []);
4647        }
4648
4649        // First, find at what point do we split between the first and 2nd slice. Easy with
4650        // ptr.align_offset.
4651        let ptr = self.as_ptr();
4652        // SAFETY: Here we are ensuring we will use aligned pointers for U for the
4653        // rest of the method. This is done by passing a pointer to &[T] with an
4654        // alignment targeted for U.
4655        // `crate::ptr::align_offset` is called with a correctly aligned and
4656        // valid pointer `ptr` (it comes from a reference to `self`) and with
4657        // a size that is a power of two (since it comes from the alignment for U),
4658        // satisfying its safety constraints.
4659        let offset = unsafe { crate::ptr::align_offset(ptr, align_of::<U>()) };
4660        if offset > self.len() {
4661            (self, &mut [], &mut [])
4662        } else {
4663            let (left, rest) = self.split_at_mut(offset);
4664            let (us_len, ts_len) = rest.align_to_offsets::<U>();
4665            let rest_len = rest.len();
4666            let mut_ptr = rest.as_mut_ptr();
4667            // Inform Miri that we want to consider the "middle" pointer to be suitably aligned.
4668            #[cfg(miri)]
4669            crate::intrinsics::miri_promise_symbolic_alignment(
4670                mut_ptr.cast() as *const (),
4671                align_of::<U>(),
4672            );
4673            // We can't use `rest` again after this, that would invalidate its alias `mut_ptr`!
4674            // SAFETY: see comments for `align_to`.
4675            unsafe {
4676                (
4677                    left,
4678                    from_raw_parts_mut(mut_ptr as *mut U, us_len),
4679                    from_raw_parts_mut(mut_ptr.add(rest_len - ts_len), ts_len),
4680                )
4681            }
4682        }
4683    }
4684
4685    /// Splits a slice into a prefix, a middle of aligned SIMD types, and a suffix.
4686    ///
4687    /// This is a safe wrapper around [`slice::align_to`], so inherits the same
4688    /// guarantees as that method.
4689    ///
4690    /// # Panics
4691    ///
4692    /// This will panic if the size of the SIMD type is different from
4693    /// `LANES` times that of the scalar.
4694    ///
4695    /// At the time of writing, the trait restrictions on `Simd<T, LANES>` keeps
4696    /// that from ever happening, as only power-of-two numbers of lanes are
4697    /// supported.  It's possible that, in the future, those restrictions might
4698    /// be lifted in a way that would make it possible to see panics from this
4699    /// method for something like `LANES == 3`.
4700    ///
4701    /// # Examples
4702    ///
4703    /// ```
4704    /// #![feature(portable_simd)]
4705    /// use core::simd::prelude::*;
4706    ///
4707    /// let short = &[1, 2, 3];
4708    /// let (prefix, middle, suffix) = short.as_simd::<4>();
4709    /// assert_eq!(middle, []); // Not enough elements for anything in the middle
4710    ///
4711    /// // They might be split in any possible way between prefix and suffix
4712    /// let it = prefix.iter().chain(suffix).copied();
4713    /// assert_eq!(it.collect::<Vec<_>>(), vec![1, 2, 3]);
4714    ///
4715    /// fn basic_simd_sum(x: &[f32]) -> f32 {
4716    ///     use std::ops::Add;
4717    ///     let (prefix, middle, suffix) = x.as_simd();
4718    ///     let sums = f32x4::from_array([
4719    ///         prefix.iter().copied().sum(),
4720    ///         0.0,
4721    ///         0.0,
4722    ///         suffix.iter().copied().sum(),
4723    ///     ]);
4724    ///     let sums = middle.iter().copied().fold(sums, f32x4::add);
4725    ///     sums.reduce_sum()
4726    /// }
4727    ///
4728    /// let numbers: Vec<f32> = (1..101).map(|x| x as _).collect();
4729    /// assert_eq!(basic_simd_sum(&numbers[1..99]), 4949.0);
4730    /// ```
4731    #[unstable(feature = "portable_simd", issue = "86656")]
4732    #[must_use]
4733    pub fn as_simd<const LANES: usize>(&self) -> (&[T], &[Simd<T, LANES>], &[T])
4734    where
4735        Simd<T, LANES>: AsRef<[T; LANES]>,
4736        T: simd::SimdElement,
4737    {
4738        // These are expected to always match, as vector types are laid out like
4739        // arrays per <https://llvm.org/docs/LangRef.html#vector-type>, but we
4740        // might as well double-check since it'll optimize away anyhow.
4741        assert_eq!(size_of::<Simd<T, LANES>>(), size_of::<[T; LANES]>());
4742
4743        // SAFETY: The simd types have the same layout as arrays, just with
4744        // potentially-higher alignment, so the de-facto transmutes are sound.
4745        unsafe { self.align_to() }
4746    }
4747
4748    /// Splits a mutable slice into a mutable prefix, a middle of aligned SIMD types,
4749    /// and a mutable suffix.
4750    ///
4751    /// This is a safe wrapper around [`slice::align_to_mut`], so inherits the same
4752    /// guarantees as that method.
4753    ///
4754    /// This is the mutable version of [`slice::as_simd`]; see that for examples.
4755    ///
4756    /// # Panics
4757    ///
4758    /// This will panic if the size of the SIMD type is different from
4759    /// `LANES` times that of the scalar.
4760    ///
4761    /// At the time of writing, the trait restrictions on `Simd<T, LANES>` keeps
4762    /// that from ever happening, as only power-of-two numbers of lanes are
4763    /// supported.  It's possible that, in the future, those restrictions might
4764    /// be lifted in a way that would make it possible to see panics from this
4765    /// method for something like `LANES == 3`.
4766    #[unstable(feature = "portable_simd", issue = "86656")]
4767    #[must_use]
4768    pub fn as_simd_mut<const LANES: usize>(&mut self) -> (&mut [T], &mut [Simd<T, LANES>], &mut [T])
4769    where
4770        Simd<T, LANES>: AsMut<[T; LANES]>,
4771        T: simd::SimdElement,
4772    {
4773        // These are expected to always match, as vector types are laid out like
4774        // arrays per <https://llvm.org/docs/LangRef.html#vector-type>, but we
4775        // might as well double-check since it'll optimize away anyhow.
4776        assert_eq!(size_of::<Simd<T, LANES>>(), size_of::<[T; LANES]>());
4777
4778        // SAFETY: The simd types have the same layout as arrays, just with
4779        // potentially-higher alignment, so the de-facto transmutes are sound.
4780        unsafe { self.align_to_mut() }
4781    }
4782
4783    /// Checks if the elements of this slice are sorted.
4784    ///
4785    /// That is, for each element `a` and its following element `b`, `a <= b` must hold. If the
4786    /// slice yields exactly zero or one element, `true` is returned.
4787    ///
4788    /// Note that if `Self::Item` is only `PartialOrd`, but not `Ord`, the above definition
4789    /// implies that this function returns `false` if any two consecutive items are not
4790    /// comparable.
4791    ///
4792    /// # Examples
4793    ///
4794    /// ```
4795    /// let empty: [i32; 0] = [];
4796    ///
4797    /// assert!([1, 2, 2, 9].is_sorted());
4798    /// assert!(![1, 3, 2, 4].is_sorted());
4799    /// assert!([0].is_sorted());
4800    /// assert!(empty.is_sorted());
4801    /// assert!(![0.0, 1.0, f32::NAN].is_sorted());
4802    /// ```
4803    #[inline]
4804    #[stable(feature = "is_sorted", since = "1.82.0")]
4805    #[must_use]
4806    pub fn is_sorted(&self) -> bool
4807    where
4808        T: PartialOrd,
4809    {
4810        // This odd number works the best. 32 + 1 extra due to overlapping chunk boundaries.
4811        const CHUNK_SIZE: usize = 33;
4812        if self.len() < CHUNK_SIZE {
4813            return self.windows(2).all(|w| w[0] <= w[1]);
4814        }
4815        let mut i = 0;
4816        // Check in chunks for autovectorization.
4817        while i < self.len() - CHUNK_SIZE {
4818            let chunk = &self[i..i + CHUNK_SIZE];
4819            if !chunk.windows(2).fold(true, |acc, w| acc & (w[0] <= w[1])) {
4820                return false;
4821            }
4822            // We need to ensure that chunk boundaries are also sorted.
4823            // Overlap the next chunk with the last element of our last chunk.
4824            i += CHUNK_SIZE - 1;
4825        }
4826        self[i..].windows(2).all(|w| w[0] <= w[1])
4827    }
4828
4829    /// Checks if the elements of this slice are sorted using the given comparator function.
4830    ///
4831    /// Instead of using `PartialOrd::partial_cmp`, this function uses the given `compare`
4832    /// function to determine whether two elements are to be considered in sorted order.
4833    ///
4834    /// # Examples
4835    ///
4836    /// ```
4837    /// assert!([1, 2, 2, 9].is_sorted_by(|a, b| a <= b));
4838    /// assert!(![1, 2, 2, 9].is_sorted_by(|a, b| a < b));
4839    ///
4840    /// assert!([0].is_sorted_by(|a, b| true));
4841    /// assert!([0].is_sorted_by(|a, b| false));
4842    ///
4843    /// let empty: [i32; 0] = [];
4844    /// assert!(empty.is_sorted_by(|a, b| false));
4845    /// assert!(empty.is_sorted_by(|a, b| true));
4846    /// ```
4847    #[stable(feature = "is_sorted", since = "1.82.0")]
4848    #[must_use]
4849    pub fn is_sorted_by<'a, F>(&'a self, mut compare: F) -> bool
4850    where
4851        F: FnMut(&'a T, &'a T) -> bool,
4852    {
4853        self.array_windows().all(|[a, b]| compare(a, b))
4854    }
4855
4856    /// Checks if the elements of this slice are sorted using the given key extraction function.
4857    ///
4858    /// Instead of comparing the slice's elements directly, this function compares the keys of the
4859    /// elements, as determined by `f`. Apart from that, it's equivalent to [`is_sorted`]; see its
4860    /// documentation for more information.
4861    ///
4862    /// [`is_sorted`]: slice::is_sorted
4863    ///
4864    /// # Examples
4865    ///
4866    /// ```
4867    /// assert!(["c", "bb", "aaa"].is_sorted_by_key(|s| s.len()));
4868    /// assert!(![-2i32, -1, 0, 3].is_sorted_by_key(|n| n.abs()));
4869    /// ```
4870    #[inline]
4871    #[stable(feature = "is_sorted", since = "1.82.0")]
4872    #[must_use]
4873    pub fn is_sorted_by_key<'a, F, K>(&'a self, f: F) -> bool
4874    where
4875        F: FnMut(&'a T) -> K,
4876        K: PartialOrd,
4877    {
4878        self.iter().is_sorted_by_key(f)
4879    }
4880
4881    /// Returns the index of the partition point according to the given predicate
4882    /// (the index of the first element of the second partition).
4883    ///
4884    /// The slice is assumed to be partitioned according to the given predicate.
4885    /// This means that all elements for which the predicate returns true are at the start of the slice
4886    /// and all elements for which the predicate returns false are at the end.
4887    /// For example, `[7, 15, 3, 5, 4, 12, 6]` is partitioned under the predicate `x % 2 != 0`
4888    /// (all odd numbers are at the start, all even at the end).
4889    ///
4890    /// If this slice is not partitioned, the returned result is unspecified and meaningless,
4891    /// as this method performs a kind of binary search.
4892    ///
4893    /// See also [`binary_search`], [`binary_search_by`], and [`binary_search_by_key`].
4894    ///
4895    /// [`binary_search`]: slice::binary_search
4896    /// [`binary_search_by`]: slice::binary_search_by
4897    /// [`binary_search_by_key`]: slice::binary_search_by_key
4898    ///
4899    /// # Examples
4900    ///
4901    /// ```
4902    /// let v = [1, 2, 3, 3, 5, 6, 7];
4903    /// let i = v.partition_point(|&x| x < 5);
4904    ///
4905    /// assert_eq!(i, 4);
4906    /// assert!(v[..i].iter().all(|&x| x < 5));
4907    /// assert!(v[i..].iter().all(|&x| !(x < 5)));
4908    /// ```
4909    ///
4910    /// If all elements of the slice match the predicate, including if the slice
4911    /// is empty, then the length of the slice will be returned:
4912    ///
4913    /// ```
4914    /// let a = [2, 4, 8];
4915    /// assert_eq!(a.partition_point(|x| x < &100), a.len());
4916    /// let a: [i32; 0] = [];
4917    /// assert_eq!(a.partition_point(|x| x < &100), 0);
4918    /// ```
4919    ///
4920    /// If you want to insert an item to a sorted vector, while maintaining
4921    /// sort order:
4922    ///
4923    /// ```
4924    /// let mut s = vec![0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 55];
4925    /// let num = 42;
4926    /// let idx = s.partition_point(|&x| x <= num);
4927    /// s.insert(idx, num);
4928    /// assert_eq!(s, [0, 1, 1, 1, 1, 2, 3, 5, 8, 13, 21, 34, 42, 55]);
4929    /// ```
4930    #[rustc_const_unstable(feature = "const_binary_search", issue = "159532")]
4931    #[stable(feature = "partition_point", since = "1.52.0")]
4932    #[must_use]
4933    pub const fn partition_point<P>(&self, mut pred: P) -> usize
4934    where
4935        P: [const] FnMut(&T) -> bool + [const] Destruct,
4936    {
4937        self.binary_search_by(const |x| if pred(x) { Less } else { Greater })
4938            .unwrap_or_else(const |i| i)
4939    }
4940
4941    /// Removes the subslice corresponding to the given range
4942    /// and returns a reference to it.
4943    ///
4944    /// Returns `None` and does not modify the slice if the given
4945    /// range is out of bounds.
4946    ///
4947    /// Note that this method only accepts one-sided ranges such as
4948    /// `2..` or `..6`, but not `2..6`.
4949    ///
4950    /// # Examples
4951    ///
4952    /// Splitting off the first three elements of a slice:
4953    ///
4954    /// ```
4955    /// let mut slice: &[_] = &['a', 'b', 'c', 'd'];
4956    /// let mut first_three = slice.split_off(..3).unwrap();
4957    ///
4958    /// assert_eq!(slice, &['d']);
4959    /// assert_eq!(first_three, &['a', 'b', 'c']);
4960    /// ```
4961    ///
4962    /// Splitting off a slice starting with the third element:
4963    ///
4964    /// ```
4965    /// let mut slice: &[_] = &['a', 'b', 'c', 'd'];
4966    /// let mut tail = slice.split_off(2..).unwrap();
4967    ///
4968    /// assert_eq!(slice, &['a', 'b']);
4969    /// assert_eq!(tail, &['c', 'd']);
4970    /// ```
4971    ///
4972    /// Getting `None` when `range` is out of bounds:
4973    ///
4974    /// ```
4975    /// let mut slice: &[_] = &['a', 'b', 'c', 'd'];
4976    ///
4977    /// assert_eq!(None, slice.split_off(5..));
4978    /// assert_eq!(None, slice.split_off(..5));
4979    /// assert_eq!(None, slice.split_off(..=4));
4980    /// let expected: &[char] = &['a', 'b', 'c', 'd'];
4981    /// assert_eq!(Some(expected), slice.split_off(..4));
4982    /// ```
4983    #[inline]
4984    #[must_use = "method does not modify the slice if the range is out of bounds"]
4985    #[stable(feature = "slice_take", since = "1.87.0")]
4986    pub fn split_off<'a, R: OneSidedRange<usize>>(
4987        self: &mut &'a Self,
4988        range: R,
4989    ) -> Option<&'a Self> {
4990        let (direction, split_index) = split_point_of(range)?;
4991        if split_index > self.len() {
4992            return None;
4993        }
4994        let (front, back) = self.split_at(split_index);
4995        match direction {
4996            Direction::Front => {
4997                *self = back;
4998                Some(front)
4999            }
5000            Direction::Back => {
5001                *self = front;
5002                Some(back)
5003            }
5004        }
5005    }
5006
5007    /// Removes the subslice corresponding to the given range
5008    /// and returns a mutable reference to it.
5009    ///
5010    /// Returns `None` and does not modify the slice if the given
5011    /// range is out of bounds.
5012    ///
5013    /// Note that this method only accepts one-sided ranges such as
5014    /// `2..` or `..6`, but not `2..6`.
5015    ///
5016    /// # Examples
5017    ///
5018    /// Splitting off the first three elements of a slice:
5019    ///
5020    /// ```
5021    /// let mut slice: &mut [_] = &mut ['a', 'b', 'c', 'd'];
5022    /// let mut first_three = slice.split_off_mut(..3).unwrap();
5023    ///
5024    /// assert_eq!(slice, &mut ['d']);
5025    /// assert_eq!(first_three, &mut ['a', 'b', 'c']);
5026    /// ```
5027    ///
5028    /// Splitting off a slice starting with the third element:
5029    ///
5030    /// ```
5031    /// let mut slice: &mut [_] = &mut ['a', 'b', 'c', 'd'];
5032    /// let mut tail = slice.split_off_mut(2..).unwrap();
5033    ///
5034    /// assert_eq!(slice, &mut ['a', 'b']);
5035    /// assert_eq!(tail, &mut ['c', 'd']);
5036    /// ```
5037    ///
5038    /// Getting `None` when `range` is out of bounds:
5039    ///
5040    /// ```
5041    /// let mut slice: &mut [_] = &mut ['a', 'b', 'c', 'd'];
5042    ///
5043    /// assert_eq!(None, slice.split_off_mut(5..));
5044    /// assert_eq!(None, slice.split_off_mut(..5));
5045    /// assert_eq!(None, slice.split_off_mut(..=4));
5046    /// let expected: &mut [_] = &mut ['a', 'b', 'c', 'd'];
5047    /// assert_eq!(Some(expected), slice.split_off_mut(..4));
5048    /// ```
5049    #[inline]
5050    #[must_use = "method does not modify the slice if the range is out of bounds"]
5051    #[stable(feature = "slice_take", since = "1.87.0")]
5052    pub fn split_off_mut<'a, R: OneSidedRange<usize>>(
5053        self: &mut &'a mut Self,
5054        range: R,
5055    ) -> Option<&'a mut Self> {
5056        let (direction, split_index) = split_point_of(range)?;
5057        if split_index > self.len() {
5058            return None;
5059        }
5060        let (front, back) = mem::take(self).split_at_mut(split_index);
5061        match direction {
5062            Direction::Front => {
5063                *self = back;
5064                Some(front)
5065            }
5066            Direction::Back => {
5067                *self = front;
5068                Some(back)
5069            }
5070        }
5071    }
5072
5073    /// Removes the first element of the slice and returns a reference
5074    /// to it.
5075    ///
5076    /// Returns `None` if the slice is empty.
5077    ///
5078    /// # Examples
5079    ///
5080    /// ```
5081    /// let mut slice: &[_] = &['a', 'b', 'c'];
5082    /// let first = slice.split_off_first().unwrap();
5083    ///
5084    /// assert_eq!(slice, &['b', 'c']);
5085    /// assert_eq!(first, &'a');
5086    /// ```
5087    #[inline]
5088    #[stable(feature = "slice_take", since = "1.87.0")]
5089    #[rustc_const_unstable(feature = "const_split_off_first_last", issue = "138539")]
5090    pub const fn split_off_first<'a>(self: &mut &'a Self) -> Option<&'a T> {
5091        // FIXME(const-hack): Use `?` when available in const instead of `let-else`.
5092        let Some((first, rem)) = self.split_first() else { return None };
5093        *self = rem;
5094        Some(first)
5095    }
5096
5097    /// Removes the first element of the slice and returns a mutable
5098    /// reference to it.
5099    ///
5100    /// Returns `None` if the slice is empty.
5101    ///
5102    /// # Examples
5103    ///
5104    /// ```
5105    /// let mut slice: &mut [_] = &mut ['a', 'b', 'c'];
5106    /// let first = slice.split_off_first_mut().unwrap();
5107    /// *first = 'd';
5108    ///
5109    /// assert_eq!(slice, &['b', 'c']);
5110    /// assert_eq!(first, &'d');
5111    /// ```
5112    #[inline]
5113    #[stable(feature = "slice_take", since = "1.87.0")]
5114    #[rustc_const_unstable(feature = "const_split_off_first_last", issue = "138539")]
5115    pub const fn split_off_first_mut<'a>(self: &mut &'a mut Self) -> Option<&'a mut T> {
5116        // FIXME(const-hack): Use `mem::take` and `?` when available in const.
5117        // Original: `mem::take(self).split_first_mut()?`
5118        let Some((first, rem)) = mem::replace(self, &mut []).split_first_mut() else { return None };
5119        *self = rem;
5120        Some(first)
5121    }
5122
5123    /// Removes the last element of the slice and returns a reference
5124    /// to it.
5125    ///
5126    /// Returns `None` if the slice is empty.
5127    ///
5128    /// # Examples
5129    ///
5130    /// ```
5131    /// let mut slice: &[_] = &['a', 'b', 'c'];
5132    /// let last = slice.split_off_last().unwrap();
5133    ///
5134    /// assert_eq!(slice, &['a', 'b']);
5135    /// assert_eq!(last, &'c');
5136    /// ```
5137    #[inline]
5138    #[stable(feature = "slice_take", since = "1.87.0")]
5139    #[rustc_const_unstable(feature = "const_split_off_first_last", issue = "138539")]
5140    pub const fn split_off_last<'a>(self: &mut &'a Self) -> Option<&'a T> {
5141        // FIXME(const-hack): Use `?` when available in const instead of `let-else`.
5142        let Some((last, rem)) = self.split_last() else { return None };
5143        *self = rem;
5144        Some(last)
5145    }
5146
5147    /// Removes the last element of the slice and returns a mutable
5148    /// reference to it.
5149    ///
5150    /// Returns `None` if the slice is empty.
5151    ///
5152    /// # Examples
5153    ///
5154    /// ```
5155    /// let mut slice: &mut [_] = &mut ['a', 'b', 'c'];
5156    /// let last = slice.split_off_last_mut().unwrap();
5157    /// *last = 'd';
5158    ///
5159    /// assert_eq!(slice, &['a', 'b']);
5160    /// assert_eq!(last, &'d');
5161    /// ```
5162    #[inline]
5163    #[stable(feature = "slice_take", since = "1.87.0")]
5164    #[rustc_const_unstable(feature = "const_split_off_first_last", issue = "138539")]
5165    pub const fn split_off_last_mut<'a>(self: &mut &'a mut Self) -> Option<&'a mut T> {
5166        // FIXME(const-hack): Use `mem::take` and `?` when available in const.
5167        // Original: `mem::take(self).split_last_mut()?`
5168        let Some((last, rem)) = mem::replace(self, &mut []).split_last_mut() else { return None };
5169        *self = rem;
5170        Some(last)
5171    }
5172
5173    /// Returns mutable references to many indices at once, without doing any checks.
5174    ///
5175    /// An index can be either a `usize`, a [`Range`] or a [`RangeInclusive`]. Note
5176    /// that this method takes an array, so all indices must be of the same type.
5177    /// If passed an array of `usize`s this method gives back an array of mutable references
5178    /// to single elements, while if passed an array of ranges it gives back an array of
5179    /// mutable references to slices.
5180    ///
5181    /// For a safe alternative see [`get_disjoint_mut`].
5182    ///
5183    /// # Safety
5184    ///
5185    /// Calling this method with overlapping or out-of-bounds indices is *[undefined behavior]*
5186    /// even if the resulting references are not used.
5187    ///
5188    /// # Examples
5189    ///
5190    /// ```
5191    /// let x = &mut [1, 2, 4];
5192    ///
5193    /// unsafe {
5194    ///     let [a, b] = x.get_disjoint_unchecked_mut([0, 2]);
5195    ///     *a *= 10;
5196    ///     *b *= 100;
5197    /// }
5198    /// assert_eq!(x, &[10, 2, 400]);
5199    ///
5200    /// unsafe {
5201    ///     let [a, b] = x.get_disjoint_unchecked_mut([0..1, 1..3]);
5202    ///     a[0] = 8;
5203    ///     b[0] = 88;
5204    ///     b[1] = 888;
5205    /// }
5206    /// assert_eq!(x, &[8, 88, 888]);
5207    ///
5208    /// unsafe {
5209    ///     let [a, b] = x.get_disjoint_unchecked_mut([1..=2, 0..=0]);
5210    ///     a[0] = 11;
5211    ///     a[1] = 111;
5212    ///     b[0] = 1;
5213    /// }
5214    /// assert_eq!(x, &[1, 11, 111]);
5215    /// ```
5216    ///
5217    /// [`get_disjoint_mut`]: slice::get_disjoint_mut
5218    /// [undefined behavior]: https://doc.rust-lang.org/reference/behavior-considered-undefined.html
5219    #[stable(feature = "get_many_mut", since = "1.86.0")]
5220    #[inline]
5221    #[track_caller]
5222    pub unsafe fn get_disjoint_unchecked_mut<I, const N: usize>(
5223        &mut self,
5224        indices: [I; N],
5225    ) -> [&mut I::Output; N]
5226    where
5227        I: GetDisjointMutIndex + SliceIndex<Self>,
5228    {
5229        // NB: This implementation is written as it is because any variation of
5230        // `indices.map(|i| self.get_unchecked_mut(i))` would make miri unhappy,
5231        // or generate worse code otherwise. This is also why we need to go
5232        // through a raw pointer here.
5233        let slice: *mut [T] = self;
5234        let mut arr: MaybeUninit<[&mut I::Output; N]> = MaybeUninit::uninit();
5235        let arr_ptr = arr.as_mut_ptr();
5236
5237        // SAFETY: We expect `indices` to contain disjunct values that are
5238        // in bounds of `self`.
5239        unsafe {
5240            for i in 0..N {
5241                let idx = indices.get_unchecked(i).clone();
5242                arr_ptr.cast::<&mut I::Output>().add(i).write(&mut *slice.get_unchecked_mut(idx));
5243            }
5244            arr.assume_init()
5245        }
5246    }
5247
5248    /// Returns mutable references to many indices at once.
5249    ///
5250    /// An index can be either a `usize`, a [`Range`] or a [`RangeInclusive`]. Note
5251    /// that this method takes an array, so all indices must be of the same type.
5252    /// If passed an array of `usize`s this method gives back an array of mutable references
5253    /// to single elements, while if passed an array of ranges it gives back an array of
5254    /// mutable references to slices.
5255    ///
5256    /// Returns an error if any index is out-of-bounds, or if there are overlapping indices.
5257    /// An empty range is not considered to overlap if it is located at the beginning or at
5258    /// the end of another range, but is considered to overlap if it is located in the middle.
5259    ///
5260    /// This method does a O(n^2) check to check that there are no overlapping indices, so be careful
5261    /// when passing many indices.
5262    ///
5263    /// # Examples
5264    ///
5265    /// ```
5266    /// let v = &mut [1, 2, 3];
5267    /// if let Ok([a, b]) = v.get_disjoint_mut([0, 2]) {
5268    ///     *a = 413;
5269    ///     *b = 612;
5270    /// }
5271    /// assert_eq!(v, &[413, 2, 612]);
5272    ///
5273    /// if let Ok([a, b]) = v.get_disjoint_mut([0..1, 1..3]) {
5274    ///     a[0] = 8;
5275    ///     b[0] = 88;
5276    ///     b[1] = 888;
5277    /// }
5278    /// assert_eq!(v, &[8, 88, 888]);
5279    ///
5280    /// if let Ok([a, b]) = v.get_disjoint_mut([1..=2, 0..=0]) {
5281    ///     a[0] = 11;
5282    ///     a[1] = 111;
5283    ///     b[0] = 1;
5284    /// }
5285    /// assert_eq!(v, &[1, 11, 111]);
5286    /// ```
5287    #[stable(feature = "get_many_mut", since = "1.86.0")]
5288    #[inline]
5289    pub fn get_disjoint_mut<I, const N: usize>(
5290        &mut self,
5291        indices: [I; N],
5292    ) -> Result<[&mut I::Output; N], GetDisjointMutError>
5293    where
5294        I: GetDisjointMutIndex + SliceIndex<Self>,
5295    {
5296        get_disjoint_check_valid(&indices, self.len())?;
5297        // SAFETY: The `get_disjoint_check_valid()` call checked that all indices
5298        // are disjunct and in bounds.
5299        unsafe { Ok(self.get_disjoint_unchecked_mut(indices)) }
5300    }
5301
5302    /// Returns the index that an element reference points to.
5303    ///
5304    /// Returns `None` if `element` does not point to the start of an element within the slice.
5305    ///
5306    /// This method is useful for extending slice iterators like [`slice::split`].
5307    ///
5308    /// Note that this uses pointer arithmetic and **does not compare elements**.
5309    /// To find the index of an element via comparison, use
5310    /// [`.iter().position()`](crate::iter::Iterator::position) instead.
5311    ///
5312    /// # Panics
5313    /// Panics if `T` is zero-sized.
5314    ///
5315    /// # Examples
5316    /// Basic usage:
5317    /// ```
5318    /// let nums: &[u32] = &[1, 7, 1, 1];
5319    /// let num = &nums[2];
5320    ///
5321    /// assert_eq!(num, &1);
5322    /// assert_eq!(nums.element_offset(num), Some(2));
5323    /// ```
5324    /// Returning `None` with an unaligned element:
5325    /// ```
5326    /// let arr: &[[u32; 2]] = &[[0, 1], [2, 3]];
5327    /// let flat_arr: &[u32] = arr.as_flattened();
5328    ///
5329    /// let ok_elm: &[u32; 2] = flat_arr[0..2].try_into().unwrap();
5330    /// let weird_elm: &[u32; 2] = flat_arr[1..3].try_into().unwrap();
5331    ///
5332    /// assert_eq!(ok_elm, &[0, 1]);
5333    /// assert_eq!(weird_elm, &[1, 2]);
5334    ///
5335    /// assert_eq!(arr.element_offset(ok_elm), Some(0)); // Points to element 0
5336    /// assert_eq!(arr.element_offset(weird_elm), None); // Points between element 0 and 1
5337    /// ```
5338    #[must_use]
5339    #[stable(feature = "element_offset", since = "1.94.0")]
5340    pub fn element_offset(&self, element: &T) -> Option<usize> {
5341        if T::IS_ZST {
5342            panic!("elements are zero-sized");
5343        }
5344
5345        let self_start = self.as_ptr().addr();
5346        let elem_start = ptr::from_ref(element).addr();
5347
5348        let byte_offset = elem_start.wrapping_sub(self_start);
5349
5350        if !byte_offset.is_multiple_of(size_of::<T>()) {
5351            return None;
5352        }
5353
5354        let offset = byte_offset / size_of::<T>();
5355
5356        if offset < self.len() { Some(offset) } else { None }
5357    }
5358
5359    /// Returns the range of indices that a subslice points to.
5360    ///
5361    /// Returns `None` if `subslice` does not point within the slice or if it is not aligned with the
5362    /// elements in the slice.
5363    ///
5364    /// This method **does not compare elements**. Instead, this method finds the location in the slice that
5365    /// `subslice` was obtained from. To find the index of a subslice via comparison, instead use
5366    /// [`.windows()`](slice::windows)[`.position()`](crate::iter::Iterator::position).
5367    ///
5368    /// This method is useful for extending slice iterators like [`slice::split`].
5369    ///
5370    /// Note that this may return a false positive (either `Some(0..0)` or `Some(self.len()..self.len())`)
5371    /// if `subslice` has a length of zero and points to the beginning or end of another, separate, slice.
5372    ///
5373    /// # Panics
5374    /// Panics if `T` is zero-sized.
5375    ///
5376    /// # Examples
5377    /// Basic usage:
5378    /// ```
5379    /// use core::range::Range;
5380    ///
5381    /// let nums = &[0, 5, 10, 0, 0, 5];
5382    ///
5383    /// let mut iter = nums
5384    ///     .split(|t| *t == 0)
5385    ///     .map(|n| nums.subslice_range(n).unwrap());
5386    ///
5387    /// assert_eq!(iter.next(), Some(Range { start: 0, end: 0 }));
5388    /// assert_eq!(iter.next(), Some(Range { start: 1, end: 3 }));
5389    /// assert_eq!(iter.next(), Some(Range { start: 4, end: 4 }));
5390    /// assert_eq!(iter.next(), Some(Range { start: 5, end: 6 }));
5391    /// ```
5392    #[must_use]
5393    #[stable(feature = "substr_range", since = "1.98.0")]
5394    pub fn subslice_range(&self, subslice: &[T]) -> Option<core::range::Range<usize>> {
5395        if T::IS_ZST {
5396            panic!("elements are zero-sized");
5397        }
5398
5399        let self_start = self.as_ptr().addr();
5400        let subslice_start = subslice.as_ptr().addr();
5401
5402        let byte_start = subslice_start.wrapping_sub(self_start);
5403
5404        if !byte_start.is_multiple_of(size_of::<T>()) {
5405            return None;
5406        }
5407
5408        let start = byte_start / size_of::<T>();
5409        let end = start.wrapping_add(subslice.len());
5410
5411        if start <= self.len() && end <= self.len() {
5412            Some(core::range::Range { start, end })
5413        } else {
5414            None
5415        }
5416    }
5417
5418    /// Returns the same slice `&[T]`.
5419    ///
5420    /// This method is redundant when used directly on `&[T]`, but
5421    /// it helps dereferencing other "container" types to slices,
5422    /// for example `Box<[T]>` or `Arc<[T]>`.
5423    #[inline]
5424    #[unstable(feature = "str_as_str", issue = "130366")]
5425    pub const fn as_slice(&self) -> &[T] {
5426        self
5427    }
5428
5429    /// Returns the same slice `&mut [T]`.
5430    ///
5431    /// This method is redundant when used directly on `&mut [T]`, but
5432    /// it helps dereferencing other "container" types to slices,
5433    /// for example `Box<[T]>` or `MutexGuard<[T]>`.
5434    #[inline]
5435    #[unstable(feature = "str_as_str", issue = "130366")]
5436    pub const fn as_mut_slice(&mut self) -> &mut [T] {
5437        self
5438    }
5439}
5440
5441impl<T> [MaybeUninit<T>] {
5442    /// Transmutes the mutable uninitialized slice to a mutable uninitialized slice of
5443    /// another type, ensuring alignment of the types is maintained.
5444    ///
5445    /// This is a safe wrapper around [`slice::align_to_mut`], so inherits the same
5446    /// guarantees as that method.
5447    ///
5448    /// # Examples
5449    ///
5450    /// ```
5451    /// #![feature(align_to_uninit_mut)]
5452    /// use std::mem::MaybeUninit;
5453    ///
5454    /// pub struct BumpAllocator<'scope> {
5455    ///     memory: &'scope mut [MaybeUninit<u8>],
5456    /// }
5457    ///
5458    /// impl<'scope> BumpAllocator<'scope> {
5459    ///     pub fn new(memory: &'scope mut [MaybeUninit<u8>]) -> Self {
5460    ///         Self { memory }
5461    ///     }
5462    ///     pub fn try_alloc_uninit<T>(&mut self) -> Option<&'scope mut MaybeUninit<T>> {
5463    ///         let first_end = self.memory.as_ptr().align_offset(align_of::<T>()) + size_of::<T>();
5464    ///         let prefix = self.memory.split_off_mut(..first_end)?;
5465    ///         Some(&mut prefix.align_to_uninit_mut::<T>().1[0])
5466    ///     }
5467    ///     pub fn try_alloc_u32(&mut self, value: u32) -> Option<&'scope mut u32> {
5468    ///         let uninit = self.try_alloc_uninit()?;
5469    ///         Some(uninit.write(value))
5470    ///     }
5471    /// }
5472    ///
5473    /// let mut memory = [MaybeUninit::<u8>::uninit(); 10];
5474    /// let mut allocator = BumpAllocator::new(&mut memory);
5475    /// let v = allocator.try_alloc_u32(42);
5476    /// assert_eq!(v, Some(&mut 42));
5477    /// ```
5478    #[unstable(feature = "align_to_uninit_mut", issue = "139062")]
5479    #[inline]
5480    #[must_use]
5481    pub fn align_to_uninit_mut<U>(&mut self) -> (&mut Self, &mut [MaybeUninit<U>], &mut Self) {
5482        // SAFETY: `MaybeUninit` is transparent. Correct size and alignment are guaranteed by
5483        // `align_to_mut` itself. Therefore the only thing that we have to ensure for a safe
5484        // `transmute` is that the values are valid for the types involved. But for `MaybeUninit`
5485        // any values are valid, so this operation is safe.
5486        unsafe { self.align_to_mut() }
5487    }
5488}
5489
5490impl<T, const N: usize> [[T; N]] {
5491    /// Takes a `&[[T; N]]`, and flattens it to a `&[T]`.
5492    ///
5493    /// For the opposite operation, see [`as_chunks`] and [`as_rchunks`].
5494    ///
5495    /// [`as_chunks`]: slice::as_chunks
5496    /// [`as_rchunks`]: slice::as_rchunks
5497    ///
5498    /// # Panics
5499    ///
5500    /// This panics if the length of the resulting slice would overflow a `usize`.
5501    ///
5502    /// This is only possible when flattening a slice of arrays of zero-sized
5503    /// types, and thus tends to be irrelevant in practice. If
5504    /// `size_of::<T>() > 0`, this will never panic.
5505    ///
5506    /// # Examples
5507    ///
5508    /// ```
5509    /// assert_eq!([[1, 2, 3], [4, 5, 6]].as_flattened(), &[1, 2, 3, 4, 5, 6]);
5510    ///
5511    /// assert_eq!(
5512    ///     [[1, 2, 3], [4, 5, 6]].as_flattened(),
5513    ///     [[1, 2], [3, 4], [5, 6]].as_flattened(),
5514    /// );
5515    ///
5516    /// let slice_of_empty_arrays: &[[i32; 0]] = &[[], [], [], [], []];
5517    /// assert!(slice_of_empty_arrays.as_flattened().is_empty());
5518    ///
5519    /// let empty_slice_of_arrays: &[[u32; 10]] = &[];
5520    /// assert!(empty_slice_of_arrays.as_flattened().is_empty());
5521    /// ```
5522    #[stable(feature = "slice_flatten", since = "1.80.0")]
5523    #[rustc_const_stable(feature = "const_slice_flatten", since = "1.87.0")]
5524    pub const fn as_flattened(&self) -> &[T] {
5525        let len = if T::IS_ZST {
5526            self.len().checked_mul(N).expect("slice len overflow")
5527        } else {
5528            // SAFETY: `self.len() * N` cannot overflow because `self` is
5529            // already in the address space.
5530            unsafe { self.len().unchecked_mul(N) }
5531        };
5532        // SAFETY: `[T]` is layout-identical to `[T; N]`
5533        unsafe { from_raw_parts(self.as_ptr().cast(), len) }
5534    }
5535
5536    /// Takes a `&mut [[T; N]]`, and flattens it to a `&mut [T]`.
5537    ///
5538    /// For the opposite operation, see [`as_chunks_mut`] and [`as_rchunks_mut`].
5539    ///
5540    /// [`as_chunks_mut`]: slice::as_chunks_mut
5541    /// [`as_rchunks_mut`]: slice::as_rchunks_mut
5542    ///
5543    /// # Panics
5544    ///
5545    /// This panics if the length of the resulting slice would overflow a `usize`.
5546    ///
5547    /// This is only possible when flattening a slice of arrays of zero-sized
5548    /// types, and thus tends to be irrelevant in practice. If
5549    /// `size_of::<T>() > 0`, this will never panic.
5550    ///
5551    /// # Examples
5552    ///
5553    /// ```
5554    /// fn add_5_to_all(slice: &mut [i32]) {
5555    ///     for i in slice {
5556    ///         *i += 5;
5557    ///     }
5558    /// }
5559    ///
5560    /// let mut array = [[1, 2, 3], [4, 5, 6], [7, 8, 9]];
5561    /// add_5_to_all(array.as_flattened_mut());
5562    /// assert_eq!(array, [[6, 7, 8], [9, 10, 11], [12, 13, 14]]);
5563    /// ```
5564    #[stable(feature = "slice_flatten", since = "1.80.0")]
5565    #[rustc_const_stable(feature = "const_slice_flatten", since = "1.87.0")]
5566    pub const fn as_flattened_mut(&mut self) -> &mut [T] {
5567        let len = if T::IS_ZST {
5568            self.len().checked_mul(N).expect("slice len overflow")
5569        } else {
5570            // SAFETY: `self.len() * N` cannot overflow because `self` is
5571            // already in the address space.
5572            unsafe { self.len().unchecked_mul(N) }
5573        };
5574        // SAFETY: `[T]` is layout-identical to `[T; N]`
5575        unsafe { from_raw_parts_mut(self.as_mut_ptr().cast(), len) }
5576    }
5577}
5578
5579impl [f32] {
5580    /// Sorts the slice of floats.
5581    ///
5582    /// This sort is in-place (i.e. does not allocate), *O*(*n* \* log(*n*)) worst-case, and uses
5583    /// the ordering defined by [`f32::total_cmp`].
5584    ///
5585    /// # Current implementation
5586    ///
5587    /// This uses the same sorting algorithm as [`sort_unstable_by`](slice::sort_unstable_by).
5588    ///
5589    /// # Examples
5590    ///
5591    /// ```
5592    /// #![feature(sort_floats)]
5593    /// let mut v = [2.6, -5e-8, f32::NAN, 8.29, f32::INFINITY, -1.0, 0.0, -f32::INFINITY, -0.0];
5594    ///
5595    /// v.sort_floats();
5596    /// let sorted = [-f32::INFINITY, -1.0, -5e-8, -0.0, 0.0, 2.6, 8.29, f32::INFINITY, f32::NAN];
5597    /// assert_eq!(&v[..8], &sorted[..8]);
5598    /// assert!(v[8].is_nan());
5599    /// ```
5600    #[unstable(feature = "sort_floats", issue = "93396")]
5601    #[inline]
5602    pub fn sort_floats(&mut self) {
5603        self.sort_unstable_by(f32::total_cmp);
5604    }
5605}
5606
5607impl [f64] {
5608    /// Sorts the slice of floats.
5609    ///
5610    /// This sort is in-place (i.e. does not allocate), *O*(*n* \* log(*n*)) worst-case, and uses
5611    /// the ordering defined by [`f64::total_cmp`].
5612    ///
5613    /// # Current implementation
5614    ///
5615    /// This uses the same sorting algorithm as [`sort_unstable_by`](slice::sort_unstable_by).
5616    ///
5617    /// # Examples
5618    ///
5619    /// ```
5620    /// #![feature(sort_floats)]
5621    /// let mut v = [2.6, -5e-8, f64::NAN, 8.29, f64::INFINITY, -1.0, 0.0, -f64::INFINITY, -0.0];
5622    ///
5623    /// v.sort_floats();
5624    /// let sorted = [-f64::INFINITY, -1.0, -5e-8, -0.0, 0.0, 2.6, 8.29, f64::INFINITY, f64::NAN];
5625    /// assert_eq!(&v[..8], &sorted[..8]);
5626    /// assert!(v[8].is_nan());
5627    /// ```
5628    #[unstable(feature = "sort_floats", issue = "93396")]
5629    #[inline]
5630    pub fn sort_floats(&mut self) {
5631        self.sort_unstable_by(f64::total_cmp);
5632    }
5633}
5634
5635/// Copies `src` to `dest`.
5636///
5637/// # Safety
5638/// `T` must implement one of `Copy` or `TrivialClone`.
5639#[track_caller]
5640#[ferrocene::prevalidated]
5641const unsafe fn copy_from_slice_impl<T: Clone>(dest: &mut [T], src: &[T]) {
5642    // The panic code path was put into a cold function to not bloat the
5643    // call site.
5644    #[cfg_attr(not(panic = "immediate-abort"), inline(never), cold)]
5645    #[cfg_attr(panic = "immediate-abort", inline)]
5646    #[track_caller]
5647    #[ferrocene::prevalidated]
5648    const fn len_mismatch_fail(dst_len: usize, src_len: usize) -> ! {
5649        const_panic!(
5650            "copy_from_slice: source slice length does not match destination slice length",
5651            "copy_from_slice: source slice length ({src_len}) does not match destination slice length ({dst_len})",
5652            src_len: usize,
5653            dst_len: usize,
5654        )
5655    }
5656
5657    if dest.len() != src.len() {
5658        len_mismatch_fail(dest.len(), src.len());
5659    }
5660
5661    // SAFETY: `self` is valid for `self.len()` elements by definition, and `src` was
5662    // checked to have the same length. The slices cannot overlap because
5663    // mutable references are exclusive.
5664    unsafe {
5665        ptr::copy_nonoverlapping(src.as_ptr(), dest.as_mut_ptr(), dest.len());
5666    }
5667}
5668
5669#[rustc_const_unstable(feature = "const_clone", issue = "142757")]
5670const trait CloneFromSpec<T> {
5671    fn spec_clone_from(&mut self, src: &[T])
5672    where
5673        T: [const] Destruct;
5674}
5675
5676#[rustc_const_unstable(feature = "const_clone", issue = "142757")]
5677const impl<T> CloneFromSpec<T> for [T]
5678where
5679    T: [const] Clone + [const] Destruct,
5680{
5681    #[track_caller]
5682    #[ferrocene::prevalidated]
5683    default fn spec_clone_from(&mut self, src: &[T]) {
5684        assert!(self.len() == src.len(), "destination and source slices have different lengths");
5685        // NOTE: We need to explicitly slice them to the same length
5686        // to make it easier for the optimizer to elide bounds checking.
5687        // But since it can't be relied on we also have an explicit specialization for T: Copy.
5688        let len = self.len();
5689        let src = &src[..len];
5690        // FIXME(const_hack): make this a `for idx in 0..self.len()` loop.
5691        let mut idx = 0;
5692        while idx < self.len() {
5693            self[idx].clone_from(&src[idx]);
5694            idx += 1;
5695        }
5696    }
5697}
5698
5699#[rustc_const_unstable(feature = "const_clone", issue = "142757")]
5700const impl<T> CloneFromSpec<T> for [T]
5701where
5702    T: [const] TrivialClone + [const] Destruct,
5703{
5704    #[track_caller]
5705    fn spec_clone_from(&mut self, src: &[T]) {
5706        // SAFETY: `T` implements `TrivialClone`.
5707        unsafe {
5708            copy_from_slice_impl(self, src);
5709        }
5710    }
5711}
5712
5713#[stable(feature = "rust1", since = "1.0.0")]
5714#[rustc_const_unstable(feature = "const_default", issue = "143894")]
5715const impl<T> Default for &[T] {
5716    /// Creates an empty slice.
5717    fn default() -> Self {
5718        &[]
5719    }
5720}
5721
5722#[stable(feature = "mut_slice_default", since = "1.5.0")]
5723#[rustc_const_unstable(feature = "const_default", issue = "143894")]
5724const impl<T> Default for &mut [T] {
5725    /// Creates a mutable empty slice.
5726    #[ferrocene::prevalidated]
5727    fn default() -> Self {
5728        &mut []
5729    }
5730}
5731
5732#[unstable(feature = "slice_pattern", reason = "stopgap trait for slice patterns", issue = "56345")]
5733/// Patterns in slices - currently, only used by `strip_prefix` and `strip_suffix`.  At a future
5734/// point, we hope to generalise `core::str::Pattern` (which at the time of writing is limited to
5735/// `str`) to slices, and then this trait will be replaced or abolished.
5736pub trait SlicePattern {
5737    /// The element type of the slice being matched on.
5738    type Item;
5739
5740    /// Currently, the consumers of `SlicePattern` need a slice.
5741    fn as_slice(&self) -> &[Self::Item];
5742}
5743
5744#[stable(feature = "slice_strip", since = "1.51.0")]
5745impl<T> SlicePattern for [T] {
5746    type Item = T;
5747
5748    #[inline]
5749    fn as_slice(&self) -> &[Self::Item] {
5750        self
5751    }
5752}
5753
5754#[stable(feature = "slice_strip", since = "1.51.0")]
5755impl<T, const N: usize> SlicePattern for [T; N] {
5756    type Item = T;
5757
5758    #[inline]
5759    fn as_slice(&self) -> &[Self::Item] {
5760        self
5761    }
5762}
5763
5764/// This checks every index against each other, and against `len`.
5765///
5766/// This will do `binomial(N + 1, 2) = N * (N + 1) / 2 = 0, 1, 3, 6, 10, ..`
5767/// comparison operations.
5768#[inline]
5769fn get_disjoint_check_valid<I: GetDisjointMutIndex, const N: usize>(
5770    indices: &[I; N],
5771    len: usize,
5772) -> Result<(), GetDisjointMutError> {
5773    // NB: The optimizer should inline the loops into a sequence
5774    // of instructions without additional branching.
5775    for (i, idx) in indices.iter().enumerate() {
5776        if !idx.is_in_bounds(len) {
5777            return Err(GetDisjointMutError::IndexOutOfBounds);
5778        }
5779        for idx2 in &indices[..i] {
5780            if idx.is_overlapping(idx2) {
5781                return Err(GetDisjointMutError::OverlappingIndices);
5782            }
5783        }
5784    }
5785    Ok(())
5786}
5787
5788/// The error type returned by [`get_disjoint_mut`][`slice::get_disjoint_mut`].
5789///
5790/// It indicates one of two possible errors:
5791/// - An index is out-of-bounds.
5792/// - The same index appeared multiple times in the array
5793///   (or different but overlapping indices when ranges are provided).
5794///
5795/// # Examples
5796///
5797/// ```
5798/// use std::slice::GetDisjointMutError;
5799///
5800/// let v = &mut [1, 2, 3];
5801/// assert_eq!(v.get_disjoint_mut([0, 999]), Err(GetDisjointMutError::IndexOutOfBounds));
5802/// assert_eq!(v.get_disjoint_mut([1, 1]), Err(GetDisjointMutError::OverlappingIndices));
5803/// ```
5804#[stable(feature = "get_many_mut", since = "1.86.0")]
5805#[derive(Debug, Clone, PartialEq, Eq)]
5806pub enum GetDisjointMutError {
5807    /// An index provided was out-of-bounds for the slice.
5808    IndexOutOfBounds,
5809    /// Two indices provided were overlapping.
5810    OverlappingIndices,
5811}
5812
5813#[stable(feature = "get_many_mut", since = "1.86.0")]
5814impl fmt::Display for GetDisjointMutError {
5815    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
5816        let msg = match self {
5817            GetDisjointMutError::IndexOutOfBounds => "an index is out of bounds",
5818            GetDisjointMutError::OverlappingIndices => "there were overlapping indices",
5819        };
5820        fmt::Display::fmt(msg, f)
5821    }
5822}
5823
5824/// A helper trait for `<[T]>::get_disjoint_mut()`.
5825///
5826/// # Safety
5827///
5828/// If `is_in_bounds()` returns `true` and `is_overlapping()` returns `false`,
5829/// it must be safe to index the slice with the indices.
5830#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5831pub impl(self) unsafe trait GetDisjointMutIndex: Clone {
5832    /// Returns `true` if `self` is in bounds for `len` slice elements.
5833    #[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5834    fn is_in_bounds(&self, len: usize) -> bool;
5835
5836    /// Returns `true` if `self` overlaps with `other`.
5837    ///
5838    /// Note that we don't consider zero-length ranges to overlap at the beginning or the end,
5839    /// but do consider them to overlap in the middle.
5840    #[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5841    fn is_overlapping(&self, other: &Self) -> bool;
5842}
5843
5844#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5845// SAFETY: We implement `is_in_bounds()` and `is_overlapping()` correctly.
5846unsafe impl GetDisjointMutIndex for usize {
5847    #[inline]
5848    fn is_in_bounds(&self, len: usize) -> bool {
5849        *self < len
5850    }
5851
5852    #[inline]
5853    fn is_overlapping(&self, other: &Self) -> bool {
5854        *self == *other
5855    }
5856}
5857
5858#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5859// SAFETY: We implement `is_in_bounds()` and `is_overlapping()` correctly.
5860unsafe impl GetDisjointMutIndex for Range<usize> {
5861    #[inline]
5862    fn is_in_bounds(&self, len: usize) -> bool {
5863        (self.start <= self.end) & (self.end <= len)
5864    }
5865
5866    #[inline]
5867    fn is_overlapping(&self, other: &Self) -> bool {
5868        (self.start < other.end) & (other.start < self.end)
5869    }
5870}
5871
5872#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5873// SAFETY: We implement `is_in_bounds()` and `is_overlapping()` correctly.
5874unsafe impl GetDisjointMutIndex for RangeInclusive<usize> {
5875    #[inline]
5876    fn is_in_bounds(&self, len: usize) -> bool {
5877        (self.start <= self.end) & (self.end < len)
5878    }
5879
5880    #[inline]
5881    fn is_overlapping(&self, other: &Self) -> bool {
5882        (self.start <= other.end) & (other.start <= self.end)
5883    }
5884}
5885
5886#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5887// SAFETY: We implement `is_in_bounds()` and `is_overlapping()` correctly.
5888unsafe impl GetDisjointMutIndex for range::Range<usize> {
5889    #[inline]
5890    fn is_in_bounds(&self, len: usize) -> bool {
5891        Range::from(*self).is_in_bounds(len)
5892    }
5893
5894    #[inline]
5895    fn is_overlapping(&self, other: &Self) -> bool {
5896        Range::from(*self).is_overlapping(&Range::from(*other))
5897    }
5898}
5899
5900#[unstable(feature = "get_disjoint_mut_helpers", issue = "none")]
5901// SAFETY: We implement `is_in_bounds()` and `is_overlapping()` correctly.
5902unsafe impl GetDisjointMutIndex for range::RangeInclusive<usize> {
5903    #[inline]
5904    fn is_in_bounds(&self, len: usize) -> bool {
5905        RangeInclusive::from(*self).is_in_bounds(len)
5906    }
5907
5908    #[inline]
5909    fn is_overlapping(&self, other: &Self) -> bool {
5910        RangeInclusive::from(*self).is_overlapping(&RangeInclusive::from(*other))
5911    }
5912}