FROMGIT: rust: alloc: refactor Vec::truncate using dec_len

Use `checked_sub` to satisfy the safety requirements of `dec_len` and
replace nearly the whole body of `truncate` with a call to `dec_len`.

Reviewed-by: Andrew Ballance <andrewjballance@gmail.com>
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Tamir Duberstein <tamird@gmail.com>
Link: https://lore.kernel.org/r/20250416-vec-set-len-v4-3-112b222604cd@gmail.com
[ Remove #[expect(unused)] from dec_len(). - Danilo ]
Signed-off-by: Danilo Krummrich <dakr@kernel.org>

Bug: 414994413
(cherry picked from commit 1b04b466c873f62413bf65a05a558f036660aedc
 https://github.com/Rust-for-Linux/linux.git alloc-next)
Change-Id: I7b1137306936289037bd315d32bb4ca893d38419
Signed-off-by: Alice Ryhl <aliceryhl@google.com>
This commit is contained in:
Tamir Duberstein
2025-04-16 13:15:42 -04:00
committed by Matthew Maurer
parent 8a1546ee71
commit 597ebe7c32

View File

@@ -209,7 +209,6 @@ where
/// # Safety
///
/// - `count` must be less than or equal to `self.len`.
#[expect(unused)]
unsafe fn dec_len(&mut self, count: usize) -> &mut [T] {
debug_assert!(count <= self.len());
// INVARIANT: We relinquish ownership of the elements within the range `[self.len - count,
@@ -489,23 +488,15 @@ where
/// # Ok::<(), Error>(())
/// ```
pub fn truncate(&mut self, len: usize) {
if len >= self.len() {
return;
if let Some(count) = self.len().checked_sub(len) {
// SAFETY: `count` is `self.len() - len` so it is guaranteed to be less than or
// equal to `self.len()`.
let ptr: *mut [T] = unsafe { self.dec_len(count) };
// SAFETY: the contract of `dec_len` guarantees that the elements in `ptr` are
// valid elements whose ownership has been transferred to the caller.
unsafe { ptr::drop_in_place(ptr) };
}
let drop_range = len..self.len();
// SAFETY: `drop_range` is a subrange of `[0, len)` by the bounds check above.
let ptr: *mut [T] = unsafe { self.get_unchecked_mut(drop_range) };
// SAFETY: By the above bounds check, it is guaranteed that `len < self.capacity()`.
unsafe { self.set_len(len) };
// SAFETY:
// - the dropped values are valid `T`s by the type invariant
// - we are allowed to invalidate [`new_len`, `old_len`) because we just changed the
// len, therefore we have exclusive access to [`new_len`, `old_len`)
unsafe { ptr::drop_in_place(ptr) };
}
}