Expand description
Standard-library API call classification helpers.
Each classifier answers “what kind of operation is this call?” (pointer arithmetic, raw memory access, ownership transfer, …). Callers — the VM, the alias/hazard scanner, and the call-summary registry — use these to pick a modelling strategy or discharge a safety obligation.
§Matching mechanism
Every classifier takes a DefId — fn(Option<DefId>) -> bool for callee
matching, or fn(DefId) -> bool for ADT type matching — and answers via
exact set membership in crate::def_id rather than substring-matching a
def_path_str. crate::def_id resolves the well-known std/core/alloc
items (by lang/diagnostic item, explicit path, or — for the open-ended
groups and the std-challenge suites’ local re-implementations — by
name-scanning fn_defs() at init), so a call site is matched by identity
without the false positives of per-call-site name matching.
Functions§
- any_fn 🔒
- Whether
calleeisSomeand matches any resolved DefId in the slice. - any_of 🔒
- Whether
calleeisSomeand matches any item in the (Option) list. - is_abs
- is_
align_ offset - Whether
calleeisptr::align_offset/NonNull::align_offset/*const T::align_offset/*mut T::align_offset. - is_
align_ to_ local - is_
as_ ptr - Whether
calleeproduces a raw pointer (orNonNull) alias of its first argument:as_ptr/as_mut_ptr,into_raw, and pointercast(incl.cast_mut/cast_const).as_ptr_range/as_mut_ptr_rangeare excluded because they return aRangeof two pointers rather than a single pointer;NonNull::new_unchecked/as_ref/as_mutare excluded because they do not produce a raw pointer (andnew_uncheckedmust not mark its result non-null, or it would hidenew_unchecked(null)unsoundness). - is_
as_ ptr_ valid is_as_ptrrestricted to the pointer-validity-establishing subset:as_ptr/as_mut_ptr,into_raw, andNonNull::cast— which expose a non-null, aligned, initialized backing pointer. Raw-pointercast/cast_mut/cast_constare excluded because they only reinterpret the address (preserving null-ness) and are left to MIR inlining.- is_
benign_ origin_ use - Whether
calleeis a benign, read-only use of a raw-pointer origin (len,is_empty,is_null,addr,as_ptr/as_mut_ptr,cast). - is_
bit_ preserving_ nz - is_
box_ alloc_ ctor Box::new/new_in/new_uninit/new_uninit_in(andtry_variants) — fresh heap allocation constructors.- is_
byte_ 🔒ptr_ add - Byte-granular
byte_add/wrapping_byte_addand signedbyte_offset/wrapping_byte_offset(stride 1). - is_
byte_ ptr_ arith - Any byte-granular pointer arithmetic (stride 1), regardless of direction.
- is_
byte_ 🔒ptr_ sub - Byte-granular
byte_sub/wrapping_byte_sub(stride 1). - is_
capacity - Whether
calleeis acapacityquery method. - is_
checked_ add - is_
checked_ mul - is_
checked_ next_ pow2 - is_
checked_ nonzero_ iff - is_
clamp - is_
container_ as_ ptr - Whether
calleeis anas_ptr/as_mut_ptrmethod on a recognized pointer-container ADT (Vec/NonNull/Box/MaybeUninit/CString). - is_
cstr_ from_ ptr - is_
cstr_ unchecked_ constructor _uncheckedC-string constructors whose caller must guarantee NUL termination (CStr::from_bytes_with_nul_unchecked,CString::from_vec_with_nul_unchecked).- is_
drop_ in_ place - Whether
calleeisdrop_in_place::<T>— the MIR drop shim that drops the pointee in place and (for an owning pointee likeBox/Vec) frees its heap allocation. - is_
element_ 🔒ptr_ add - Element-strided
add/wrapping_addand signedoffset/wrapping_offset(stride =size_of::<T>()).offset_from/offset_from_unsignedare not matched (they subtract two pointers into anisize). - is_
element_ 🔒ptr_ sub - Element-strided
sub/wrapping_sub(stride =size_of::<T>()). - is_
exchange_ malloc alloc::alloc::exchange_malloc(Box::new’s allocator on some toolchains).- is_
from_ raw_ parts - Whether
calleeis afrom_raw_partsconstructor (slice/str/ptr/String/Vec/NonNull). Matched byDefIdviacrate::def_id::from_raw_parts_fns(resolved fromfn_defs(), including local re-implementations), instead of substring-matchingdef_path_str. - is_
from_ raw_ parts_ mut - Whether
calleeis afrom_raw_parts_mutconstructor. - is_
into_ boxed_ slice - is_
iter_ position - is_
layout_ align - is_
layout_ constant - Whether
calleeis the compile-time layout constantsize_of::<T>()oralign_of::<T>(). The runtime intrinsics (size_of_val,align_of_val,pref_align_of,*_val_raw, …) are not classified here. - is_len
- Whether
calleeis alenquery method. Matched byDefIdviacrate::def_id::len_fns, which resolves every::lenfn_defin the std crates and the local crate — so the std-challenge suites’ re-implementedlenmethods are modelled too, without substring-matching adef_path_str. - is_
manually_ drop_ drop - Whether
calleeisManuallyDrop::<T>::drop— the manual drop that frees the pointee’s allocation without theManuallyDropwrapper’s own (no-op) drop glue. - is_max
- is_
maybe_ uninit_ assume_ init - Whether
calleeis aMaybeUninit“assume initialized” accessor (assume_init,assume_init_read,assume_init_ref,assume_init_mut). - is_
maybe_ uninit_ ty - Whether
ty(peeling through&/*mut/*const/[T]/[T; N]) isMaybeUninit<...>, i.e. carries no validity invariant (any bit pattern is a valid value). Shared by the VM (init_parameters) and theTypedchecker. - is_
maybe_ uninit_ type - is_
maybe_ uninit_ uninit - Whether
calleeisMaybeUninit::uninit(a new uninitialized slot). - is_
maybe_ uninit_ write - Whether
calleeisMaybeUninit::write, which initializes the slot (unlike rawptr::write, handled byis_mem_copy_or_write). - is_
mem_ copy_ or_ write - Memory copy/write intrinsics that legitimately write through a raw pointer
without requiring the target bytes to be pre-initialized (e.g.
ptr::write,write_bytes,copy_nonoverlapping,ptr::copy). Used by the checker to dischargeInit/Typedobligations onMaybeUninittargets. - is_
mem_ replace - Whether
calleeismem::replace(dest, src)— returns*dest(the old value), so the summary must deref the reference argument. - is_
min_ like - is_neg
- is_
nonnull_ as_ mut - Whether
calleeisNonNull::as_mut(produces an exclusive&mut). - is_
nonnull_ as_ ref_ as_ mut - Whether
calleeisNonNull::as_reforNonNull::as_mut. - is_
nonnull_ 🔒checked_ new - Whether
calleeisNonNull::new(the null-checked constructor). - is_
nonnull_ 🔒new_ unchecked - Whether
calleeisNonNull::new_unchecked(the unchecked transparent wrapper). Modeled as a provenance-preserving alias so the pointer’s element offset survives inlined iterator bodies (post_inc_start’snew_unchecked(ptr.add(1))); non-nullness is inherited from the source, not asserted, sonew_unchecked(null)unsoundness is still caught. - is_
overflowing_ abs_ neg - is_
ownership_ reconstruction - Whether
calleereconstructs an owned value, taking ownership of the pointed-to memory: from a single raw pointer (Box::from_raw,CString::from_raw,Arc::from_raw,Rc::from_raw) or from aVec<u8>(CString::from_vec_with_nul_unchecked). Distinct fromis_from_raw_parts, which builds a slice/Vecfrom(ptr, len[, cap]). - is_
ownership_ return - Whether
calleereturns ownership of an allocation as a raw pointer (Box::into_raw,CString::into_raw,Arc::into_raw,Rc::into_raw, …). - is_
ownership_ transfer - is_
pointer_ add - Any pointer
add(element or byte).offset/byte_offsettake a signedisize, so a negative offset is still classified here (the sign lives in the argument); seeis_pointer_subfor the positive-countsubfamily. - is_
pointer_ sub - Any pointer
sub(element or byte): a positive count,base - count * stride. - is_
ptr_ read - Whether
calleereads through a raw pointer or copies memory (ptr::read/read_unaligned/read_volatile,copy_to/copy_from,MaybeUninit::assume_init_read, and intrinsicscopy/copy_nonoverlapping). - is_
ptr_ write - Whether
calleewrites through a raw pointer to its first argument (ptr::write,write_bytes,write_unaligned,write_volatile). - is_
raw_ 🔒ptr_ cast - Whether
calleeis a raw-pointercast/cast_mut/cast_const. These only reinterpret the address — they preserve null-ness and provenance, but do not establish that the result is non-null, aligned, or points at initialized memory. Distinguished fromis_as_ptrsois_as_ptr_validcan keep them on the MIR-inlining path rather than theReturnPointerFromArgmodel (which asserts those facts). - is_
sat_ unchecked_ add - is_
sat_ unchecked_ mul - is_
select_ 🔒unpredictable - Whether
calleeisselect_unpredictable(the intrinsic or itshint::/intrinsics::wrappers): returns one of two candidate values. - is_
slice_ get_ unchecked - is_
slice_ range - Whether
calleeisslice::range(range, bounds)— the range normalizer that returnsRange { start, end }with0 <= start <= end <= bounds.end. - is_
slice_ to_ vec slice::to_vec(<[T]>::to_vecviato_vec_in::ConvertVec::to_vec) — allocates a fresh buffer and copies the slice’s elements.- is_
sliceindex_ get_ unchecked - Whether
calleeisSliceIndex::get_unchecked/get_unchecked_mut(the trait method, whose receiver is the index and whose first argument is the slice pointer). Distinct fromis_slice_get_unchecked(the slice-side methods whose receiver is the slice): the result aliases argument 1, not argument 0. - is_
split_ at - is_
std_ box - is_
std_ cstring - is_
std_ drop - Whether
calleeisstd::mem::drop/core::mem::drop— the value drop that frees the argument’s heap allocation. - is_
std_ iter_ or_ itermut - is_
std_ nonnull - is_
std_ ordering - is_
std_ vec - is_
str_ as_ bytes str::as_bytes: reinterprets&stras&[u8]— same data pointer and byte length, so the result aliases the argument.- is_
strlen - is_
unwrap - is_
vec_ alloc_ constructor - is_
vec_ from_ box - is_
vec_ invalidating_ method - Whether
calleeis aVecmethod that may reallocate (invalidating any outstanding raw pointers derived from it). - is_
vec_ ownership_ transfer - is_
vec_ push_ or_ reserve - is_
vec_ with_ capacity Vec::with_capacity— matched byDefIdviacrate::def_id::with_capacity_fns.