Skip to main content

alloc/
str.rs

1//! Utilities for the `str` primitive type.
2//!
3//! *[See also the `str` primitive type](str).*
4
5#![stable(feature = "rust1", since = "1.0.0")]
6// Many of the usings in this module are only used in the test configuration.
7// It's cleaner to just turn off the unused_imports warning than to fix them.
8#![allow(unused_imports)]
9
10use core::borrow::{Borrow, BorrowMut};
11use core::iter::FusedIterator;
12use core::mem::MaybeUninit;
13#[stable(feature = "encode_utf16", since = "1.8.0")]
14pub use core::str::EncodeUtf16;
15#[stable(feature = "split_ascii_whitespace", since = "1.34.0")]
16pub use core::str::SplitAsciiWhitespace;
17#[stable(feature = "split_inclusive", since = "1.51.0")]
18pub use core::str::SplitInclusive;
19#[stable(feature = "rust1", since = "1.0.0")]
20pub use core::str::SplitWhitespace;
21#[stable(feature = "rust1", since = "1.0.0")]
22pub use core::str::pattern;
23use core::str::pattern::{DoubleEndedSearcher, Pattern, ReverseSearcher, Searcher, Utf8Pattern};
24#[stable(feature = "rust1", since = "1.0.0")]
25pub use core::str::{Bytes, CharIndices, Chars, from_utf8, from_utf8_mut};
26#[stable(feature = "str_escape", since = "1.34.0")]
27pub use core::str::{EscapeDebug, EscapeDefault, EscapeUnicode};
28#[stable(feature = "rust1", since = "1.0.0")]
29pub use core::str::{FromStr, Utf8Error};
30#[allow(deprecated)]
31#[stable(feature = "rust1", since = "1.0.0")]
32pub use core::str::{Lines, LinesAny};
33#[stable(feature = "rust1", since = "1.0.0")]
34pub use core::str::{MatchIndices, RMatchIndices};
35#[stable(feature = "rust1", since = "1.0.0")]
36pub use core::str::{Matches, RMatches};
37#[stable(feature = "rust1", since = "1.0.0")]
38pub use core::str::{ParseBoolError, from_utf8_unchecked, from_utf8_unchecked_mut};
39#[stable(feature = "rust1", since = "1.0.0")]
40pub use core::str::{RSplit, Split};
41#[stable(feature = "rust1", since = "1.0.0")]
42pub use core::str::{RSplitN, SplitN};
43#[stable(feature = "rust1", since = "1.0.0")]
44pub use core::str::{RSplitTerminator, SplitTerminator};
45#[stable(feature = "utf8_chunks", since = "1.79.0")]
46pub use core::str::{Utf8Chunk, Utf8Chunks};
47#[unstable(feature = "str_from_raw_parts", issue = "119206")]
48pub use core::str::{from_raw_parts, from_raw_parts_mut};
49use core::unicode::conversions;
50use core::{mem, ptr};
51
52use crate::borrow::ToOwned;
53use crate::boxed::Box;
54use crate::slice::{Concat, Join, SliceIndex};
55use crate::string::String;
56use crate::vec::Vec;
57
58/// Note: `str` in `Concat<str>` is not meaningful here.
59/// This type parameter of the trait only exists to enable another impl.
60#[cfg(not(no_global_oom_handling))]
61#[unstable(feature = "slice_concat_ext", issue = "27747")]
62impl<S: Borrow<str>> Concat<str> for [S] {
63    type Output = String;
64
65    fn concat(slice: &Self) -> String {
66        Join::join(slice, "")
67    }
68}
69
70#[cfg(not(no_global_oom_handling))]
71#[unstable(feature = "slice_concat_ext", issue = "27747")]
72impl<S: Borrow<str>> Join<&str> for [S] {
73    type Output = String;
74
75    fn join(slice: &Self, sep: &str) -> String {
76        // SAFETY: slice can be borrowed as `[&str]` and sep is `&str`, both are valid UTF-8,
77        // so the returned `Vec<u8>` of `join_generic_copy` is also valid UTF-8.
78        unsafe { String::from_utf8_unchecked(join_generic_copy(slice, sep.as_bytes())) }
79    }
80}
81
82#[cfg(not(no_global_oom_handling))]
83macro_rules! specialize_for_lengths {
84    ($separator:expr, $target:expr, $iter:expr; $($num:expr),*) => {{
85        let mut target = $target;
86        let iter = $iter;
87        let sep_bytes = $separator;
88        match $separator.len() {
89            $(
90                // loops with hardcoded sizes run much faster
91                // specialize the cases with small separator lengths
92                $num => {
93                    for s in iter {
94                        copy_slice_and_advance!(target, sep_bytes);
95                        let content_bytes = s.borrow().as_ref();
96                        copy_slice_and_advance!(target, content_bytes);
97                    }
98                },
99            )*
100            _ => {
101                // arbitrary non-zero size fallback
102                for s in iter {
103                    copy_slice_and_advance!(target, sep_bytes);
104                    let content_bytes = s.borrow().as_ref();
105                    copy_slice_and_advance!(target, content_bytes);
106                }
107            }
108        }
109        target
110    }}
111}
112
113#[cfg(not(no_global_oom_handling))]
114macro_rules! copy_slice_and_advance {
115    ($target:expr, $bytes:expr) => {
116        let len = $bytes.len();
117        let (head, tail) = { $target }.split_at_mut(len);
118        head.copy_from_slice($bytes);
119        $target = tail;
120    };
121}
122
123// Optimized join implementation that works for both Vec<T> (T: Copy) and String's inner vec
124// Currently (2018-05-13) there is a bug with type inference and specialization (see issue #36262)
125// For this reason SliceConcat<T> is not specialized for T: Copy and SliceConcat<str> is the
126// only user of this function. It is left in place for the time when that is fixed.
127//
128// the bounds for String-join are S: Borrow<str> and for Vec-join Borrow<[T]>
129// [T] and str both impl AsRef<[T]> for some T
130// => s.borrow().as_ref() and we always have slices
131//
132// # Safety notes
133//
134// `Borrow` is a safe trait, and implementations are not required
135// to be deterministic. An inconsistent `Borrow` implementation could return slices
136// of different lengths on consecutive calls (e.g. by using interior mutability).
137//
138// This implementation calls `borrow()` multiple times:
139// 1. To calculate `reserved_len`, all elements are borrowed once.
140// 2. All elements, except the first, are borrowed a second time when building the mapped iterator.
141//
142// Risks and Mitigations:
143// - If elements 2..N GROW on their second borrow, the target slice bounds set by `checked_sub`
144//   means that `split_at_mut` inside `copy_slice_and_advance!` will correctly panic.
145// - If elements SHRINK on their second borrow, the spare space is never written, and the final
146//   length set via `set_len` masks trailing uninitialized bytes.
147#[cfg(not(no_global_oom_handling))]
148fn join_generic_copy<B, T, S>(slice: &[S], sep: &[T]) -> Vec<T>
149where
150    T: Copy,
151    B: AsRef<[T]> + ?Sized,
152    S: Borrow<B>,
153{
154    let sep_len = sep.len();
155    let mut iter = slice.iter();
156
157    // the first slice is the only one without a separator preceding it
158    // we take care to only borrow this once during the length calculation
159    // to avoid inconsistent Borrow implementations from breaking our assumptions
160    let first = match iter.next() {
161        Some(first) => first.borrow().as_ref(),
162        None => return vec![],
163    };
164
165    // compute the exact total length of the joined Vec
166    // if the `len` calculation overflows, we'll panic
167    // we would have run out of memory anyway and the rest of the function requires
168    // the entire Vec pre-allocated for safety
169    let reserved_len = sep_len
170        .checked_mul(iter.len())
171        .and_then(|n| n.checked_add(first.len()))
172        .and_then(|n| {
173            // iter starts from the second element as we've already taken the first
174            // it's cloned so we can reuse the same iterator below
175            iter.clone().map(|s| s.borrow().as_ref().len()).try_fold(n, usize::checked_add)
176        })
177        .expect("attempt to join into collection with len > usize::MAX");
178
179    // prepare an uninitialized buffer
180    let mut result = Vec::with_capacity(reserved_len);
181    debug_assert!(result.capacity() >= reserved_len);
182
183    result.extend_from_slice(first);
184
185    let pos = result.len();
186    debug_assert!(reserved_len >= pos);
187
188    // SAFETY: The size of remaining spare is at least `reserved_len - pos`.
189    let target = unsafe { result.spare_capacity_mut().get_unchecked_mut(..reserved_len - pos) };
190
191    // Convert the separator and slices to slices of MaybeUninit
192    // to simplify implementation in specialize_for_lengths.
193    // SAFETY: `sep` is a slice of `T`, so `sep.as_ptr().cast()` is a valid pointer,
194    // and `sep.len()` is the number of elements in the slice, so `from_raw_parts` is safe.
195    let sep_uninit = unsafe { core::slice::from_raw_parts(sep.as_ptr().cast(), sep.len()) };
196    let iter_uninit = iter.map(|it| {
197        let it = it.borrow().as_ref();
198        // SAFETY: `it` is a slice of `T`, so `it.as_ptr().cast()` is a valid pointer,
199        // and `it.len()` is the number of elements in the slice, so `from_raw_parts` is safe.
200        unsafe { core::slice::from_raw_parts(it.as_ptr().cast(), it.len()) }
201    });
202
203    // copy separator and slices over without bounds checks.
204    // `specialize_for_lengths!` internally calls `s.borrow()`, but because it uses
205    // the bounds-checked `split_at_mut` any misbehaving implementation
206    // will not write out of bounds.
207    let remain = specialize_for_lengths!(sep_uninit, target, iter_uninit; 0, 1, 2, 3, 4);
208
209    // A weird borrow implementation may return different
210    // slices for the length calculation and the actual copy.
211    // Make sure we don't expose uninitialized bytes to the caller.
212    let result_len = reserved_len - remain.len();
213    // SAFETY: `result_len` is less than `reserved_len`, and all elements in `0..result_len` are initialized.
214    unsafe {
215        result.set_len(result_len);
216    }
217
218    result
219}
220
221/// Helper for final sigma lowercase
222#[cfg(not(no_global_oom_handling))]
223fn map_uppercase_sigma(from: &str, i: usize) -> char {
224    fn case_ignorable_then_cased<I: Iterator<Item = char>>(iter: I) -> bool {
225        match iter.skip_while(|&c| c.is_case_ignorable()).next() {
226            Some(c) => c.is_cased(),
227            None => false,
228        }
229    }
230
231    // See https://www.unicode.org/versions/latest/core-spec/chapter-3/#G54277
232    // for the definition of `Final_Sigma`.
233    let is_word_final = case_ignorable_then_cased(from[..i].chars().rev())
234        && !case_ignorable_then_cased(from[i + const { 'Σ'.len_utf8() }..].chars());
235    if is_word_final { 'ς' } else { 'σ' }
236}
237
238#[stable(feature = "rust1", since = "1.0.0")]
239impl Borrow<str> for String {
240    #[inline]
241    fn borrow(&self) -> &str {
242        &self[..]
243    }
244}
245
246#[stable(feature = "string_borrow_mut", since = "1.36.0")]
247impl BorrowMut<str> for String {
248    #[inline]
249    fn borrow_mut(&mut self) -> &mut str {
250        &mut self[..]
251    }
252}
253
254#[cfg(not(no_global_oom_handling))]
255#[stable(feature = "rust1", since = "1.0.0")]
256impl ToOwned for str {
257    type Owned = String;
258
259    #[inline]
260    fn to_owned(&self) -> String {
261        // SAFETY: `self` is a valid UTF-8 str.
262        unsafe { String::from_utf8_unchecked(self.as_bytes().to_owned()) }
263    }
264
265    #[inline]
266    fn clone_into(&self, target: &mut String) {
267        target.clear();
268        target.push_str(self);
269    }
270}
271
272/// Methods for string slices.
273impl str {
274    /// Converts a `Box<str>` into a `Box<[u8]>` without copying or allocating.
275    ///
276    /// # Examples
277    ///
278    /// ```
279    /// let s = "this is a string";
280    /// let boxed_str = s.to_owned().into_boxed_str();
281    /// let boxed_bytes = boxed_str.into_boxed_bytes();
282    /// assert_eq!(*boxed_bytes, *s.as_bytes());
283    /// ```
284    #[rustc_allow_incoherent_impl]
285    #[stable(feature = "str_box_extras", since = "1.20.0")]
286    #[must_use = "`self` will be dropped if the result is not used"]
287    #[inline]
288    pub fn into_boxed_bytes(self: Box<Self>) -> Box<[u8]> {
289        self.into()
290    }
291
292    /// Replaces all matches of a pattern with another string.
293    ///
294    /// `replace` creates a new [`String`], and copies the data from this string slice into it.
295    /// While doing so, it attempts to find matches of a pattern. If it finds any, it
296    /// replaces them with the replacement string slice.
297    ///
298    /// # Examples
299    ///
300    /// ```
301    /// let s = "this is old";
302    ///
303    /// assert_eq!("this is new", s.replace("old", "new"));
304    /// assert_eq!("than an old", s.replace("is", "an"));
305    /// ```
306    ///
307    /// When the pattern doesn't match, it returns this string slice as [`String`]:
308    ///
309    /// ```
310    /// let s = "this is old";
311    /// assert_eq!(s, s.replace("cookie monster", "little lamb"));
312    /// ```
313    #[cfg(not(no_global_oom_handling))]
314    #[rustc_allow_incoherent_impl]
315    #[must_use = "this returns the replaced string as a new allocation, \
316                  without modifying the original"]
317    #[stable(feature = "rust1", since = "1.0.0")]
318    #[inline]
319    pub fn replace<P: Pattern>(&self, from: P, to: &str) -> String {
320        // Fast path for replacing a single ASCII character with another.
321        if let Some(from_byte) = match from.as_utf8_pattern() {
322            Some(Utf8Pattern::StringPattern(s)) => match s.as_bytes() {
323                [from_byte] => Some(*from_byte),
324                _ => None,
325            },
326            Some(Utf8Pattern::CharPattern(c)) => c.as_ascii().map(|ascii_char| ascii_char.to_u8()),
327            _ => None,
328        } {
329            if let [to_byte] = to.as_bytes() {
330                // SAFETY: `self` is a valid UTF-8 str, `from_byte` and `to_byte` are ASCII bytes.
331                return unsafe { replace_ascii(self.as_bytes(), from_byte, *to_byte) };
332            }
333        }
334        // Set result capacity to self.len() when from.len() <= to.len()
335        let default_capacity = match from.as_utf8_pattern() {
336            Some(Utf8Pattern::StringPattern(s)) if s.len() <= to.len() => self.len(),
337            Some(Utf8Pattern::CharPattern(c)) if c.len_utf8() <= to.len() => self.len(),
338            _ => 0,
339        };
340        let mut result = String::with_capacity(default_capacity);
341        let mut last_end = 0;
342        for (start, part) in self.match_indices(from) {
343            // SAFETY: `last_end` does not exceed `start`, and `start` does not exceed `self.len()`.
344            // Therefore, `last_end..start` is within bounds of `self`.
345            // For each iteration, `last_end` and `start` lie on UTF-8 sequence boundaries.
346            result.push_str(unsafe { self.get_unchecked(last_end..start) });
347            result.push_str(to);
348            last_end = start + part.len();
349        }
350        // SAFETY: `last_end` is the start of the remaining unmatched suffix of `self`.
351        // It is 0 or the end of a match returned by `match_indices`, so it is
352        // a UTF-8 boundary within `self`. `self.len()` is also a UTF-8 boundary.
353        result.push_str(unsafe { self.get_unchecked(last_end..self.len()) });
354        result
355    }
356
357    /// Replaces first N matches of a pattern with another string.
358    ///
359    /// `replacen` creates a new [`String`], and copies the data from this string slice into it.
360    /// While doing so, it attempts to find matches of a pattern. If it finds any, it
361    /// replaces them with the replacement string slice at most `count` times.
362    ///
363    /// # Examples
364    ///
365    /// ```
366    /// let s = "foo foo 123 foo";
367    /// assert_eq!("new new 123 foo", s.replacen("foo", "new", 2));
368    /// assert_eq!("faa fao 123 foo", s.replacen('o', "a", 3));
369    /// assert_eq!("foo foo new23 foo", s.replacen(char::is_numeric, "new", 1));
370    /// ```
371    ///
372    /// When the pattern doesn't match, it returns this string slice as [`String`]:
373    ///
374    /// ```
375    /// let s = "this is old";
376    /// assert_eq!(s, s.replacen("cookie monster", "little lamb", 10));
377    /// ```
378    #[cfg(not(no_global_oom_handling))]
379    #[rustc_allow_incoherent_impl]
380    #[doc(alias = "replace_first")]
381    #[must_use = "this returns the replaced string as a new allocation, \
382                  without modifying the original"]
383    #[stable(feature = "str_replacen", since = "1.16.0")]
384    pub fn replacen<P: Pattern>(&self, pat: P, to: &str, count: usize) -> String {
385        // Hope to reduce the times of re-allocation
386        let mut result = String::with_capacity(32);
387        let mut last_end = 0;
388        for (start, part) in self.match_indices(pat).take(count) {
389            // SAFETY: `last_end` does not exceed `start`, and `start` does not exceed `self.len()`.
390            // Therefore, `last_end..start` is within bounds of `self`.
391            // For each iteration, `last_end` and `start` lie on UTF-8 sequence boundaries.
392            result.push_str(unsafe { self.get_unchecked(last_end..start) });
393            result.push_str(to);
394            last_end = start + part.len();
395        }
396        // SAFETY: `last_end` is the start of the remaining suffix of `self`.
397        // It is 0 or the end of a match returned by `match_indices`, so it is
398        // a UTF-8 boundary within `self`. `self.len()` is also a UTF-8 boundary.
399        result.push_str(unsafe { self.get_unchecked(last_end..self.len()) });
400        result
401    }
402
403    /// Returns the lowercase equivalent of this string slice, as a new [`String`].
404    ///
405    /// 'Lowercase' is defined according to the terms of
406    /// [Chapter 3 (Conformance)](https://www.unicode.org/versions/latest/core-spec/chapter-3/#G34432)
407    /// of the Unicode standard.
408    ///
409    /// Since some characters can expand into multiple characters when changing
410    /// the case, this function returns a [`String`] instead of modifying the
411    /// parameter in-place.
412    ///
413    /// Unlike [`char::to_lowercase()`], this method fully handles the context-dependent
414    /// casing of Greek sigma. However, like that method, it does not handle locale-specific
415    /// casing, like Turkish and Azeri I/ı/İ/i. See its documentation
416    /// for more information.
417    ///
418    /// # Examples
419    ///
420    /// Basic usage:
421    ///
422    /// ```
423    /// let s = "HELLO WORLD";
424    ///
425    /// assert_eq!("hello world", s.to_lowercase());
426    /// ```
427    ///
428    /// Tricky examples, with sigma:
429    ///
430    /// ```
431    /// let sigma = "Σ";
432    ///
433    /// assert_eq!("σ", sigma.to_lowercase());
434    ///
435    /// // but at the end of a word, it's ς, not σ:
436    /// let odysseus = "ὈΔΥΣΣΕΎΣ";
437    ///
438    /// assert_eq!("ὀδυσσεύς", odysseus.to_lowercase());
439    ///
440    /// let odysseus_king_of_ithaca = "Ο ΟΔΥΣΣΈΑΣ ΒΑΣΙΛΙΆΣ ΤΗΣ ΙΘΆΚΗΣ";
441    ///
442    /// assert_eq!("ο οδυσσέας βασιλιάς της ιθάκης", odysseus_king_of_ithaca.to_lowercase());
443    /// ```
444    ///
445    /// Languages without case are not changed:
446    ///
447    /// ```
448    /// let new_year = "农历新年";
449    ///
450    /// assert_eq!(new_year, new_year.to_lowercase());
451    /// ```
452    #[cfg(not(no_global_oom_handling))]
453    #[rustc_allow_incoherent_impl]
454    #[must_use = "this returns the lowercase string as a new String, \
455                  without modifying the original"]
456    #[stable(feature = "unicode_case_mapping", since = "1.2.0")]
457    pub fn to_lowercase(&self) -> String {
458        // SAFETY: `to_ascii_lowercase` preserves ASCII bytes, so the converted
459        // prefix remains valid UTF-8.
460        let (mut s, rest) = unsafe { convert_while_ascii(self, u8::to_ascii_lowercase) };
461
462        let prefix_len = s.len();
463
464        for (i, c) in rest.char_indices() {
465            if c == 'Σ' {
466                // Σ maps to σ, except at the end of a word where it maps to ς.
467                // This is the only conditional (contextual) but language-independent mapping
468                // in `SpecialCasing.txt`,
469                // so hard-code it rather than have a generic "condition" mechanism.
470                // See https://github.com/rust-lang/rust/issues/26035
471                let sigma_lowercase = map_uppercase_sigma(self, prefix_len + i);
472                s.push(sigma_lowercase);
473            } else {
474                match conversions::to_lower(c) {
475                    [a, '\0', _] => s.push(a),
476                    [a, b, '\0'] => {
477                        s.push(a);
478                        s.push(b);
479                    }
480                    [a, b, c] => {
481                        s.push(a);
482                        s.push(b);
483                        s.push(c);
484                    }
485                }
486            }
487        }
488        s
489    }
490
491    /// Returns the titlecase equivalent of this string slice,
492    /// which is assumed to represent a single word,
493    /// as a new [`String`].
494    ///
495    /// Essentially, this consists of uppercasing the first cased letter
496    /// (with [`char::to_titlecase()`]), and lowercasing everything that follows.
497    ///
498    /// 'Titlecase' is defined according to the terms of
499    /// [Chapter 3 (Conformance)](https://www.unicode.org/versions/latest/core-spec/chapter-3/#G34082)
500    /// of the Unicode standard.
501    ///
502    /// Since some characters can expand into multiple characters when changing
503    /// the case, this function returns a [`String`] instead of modifying the
504    /// parameter in-place.
505    ///
506    /// Unlike [`char::to_lowercase()`], this method fully handles the context-dependent
507    /// casing of Greek sigma. However, like that method, it does not handle locale-specific
508    /// casing, like Turkish and Azeri I/ı/İ/i. See its documentation
509    /// for more information.
510    ///
511    /// This method does not perform any kind of word segmentation.
512    ///
513    /// # Examples
514    ///
515    /// Basic usage:
516    ///
517    /// ```
518    /// #![feature(titlecase)]
519    /// let s = "HELLO WORLD";
520    ///
521    /// assert_eq!("Hello world", s.word_to_titlecase());
522    /// ```
523    ///
524    /// The first *cased* letter is uppercased:
525    ///
526    /// ```
527    /// #![feature(titlecase)]
528    /// let the_night_before_christmas = "'twas";
529    ///
530    /// assert_eq!("'Twas", the_night_before_christmas.word_to_titlecase());
531    /// ```
532    ///
533    /// Languages without case are not changed:
534    ///
535    /// ```
536    /// #![feature(titlecase)]
537    /// let new_year = "农历新年";
538    ///
539    /// assert_eq!(new_year, new_year.word_to_titlecase());
540    /// ```
541    ///
542    /// Georgian uppercase ("Mtavruli") letters are not used in titlecase:
543    ///
544    /// ```
545    /// #![feature(titlecase)]
546    /// let georgian = "ერთობაშია";
547    ///
548    /// assert_eq!(georgian, georgian.word_to_titlecase());
549    /// ```
550    ///
551    /// No word segmentation is performed,
552    /// so only the first cased letter in the whole string gets uppercased:
553    ///
554    /// ```
555    /// #![feature(titlecase)]
556    /// let blazingly_fast = "ferris and I";
557    ///
558    /// assert_eq!("Ferris and i", blazingly_fast.word_to_titlecase());
559    /// ```
560    ///
561    /// Tricky examples, with sigma:
562    ///
563    /// ```
564    /// #![feature(titlecase)]
565    /// let odysseus = "ὈΔΥΣΣΕΎΣ";
566    ///
567    /// assert_eq!("Ὀδυσσεύς", odysseus.word_to_titlecase());
568    ///
569    /// let odysseus_king_of_ithaca = "Ο ΟΔΥΣΣΈΑΣ ΒΑΣΙΛΙΆΣ ΤΗΣ ΙΘΆΚΗΣ";
570    ///
571    /// assert_eq!("Ο οδυσσέας βασιλιάς της ιθάκης", odysseus_king_of_ithaca.word_to_titlecase());
572    /// ```
573    #[cfg(not(no_global_oom_handling))]
574    #[rustc_allow_incoherent_impl]
575    #[must_use = "this returns the titlecase word as a new String, \
576                  without modifying the original"]
577    #[unstable(feature = "titlecase", issue = "153892")]
578    pub fn word_to_titlecase(&self) -> String {
579        let mut s = String::with_capacity(self.len());
580        let mut chars = self.char_indices();
581
582        // The first cased character is title-cased; leading uncased characters pass through.
583        'until_first_cased_char: for (_, c) in chars.by_ref() {
584            if c.is_cased() {
585                s.extend(c.to_titlecase());
586                break 'until_first_cased_char;
587            } else {
588                s.push(c);
589            }
590        }
591
592        // Everything after the first cased character is lower-cased. Use the ASCII fast
593        // path (auto-vectorized) for its ASCII prefix, mirroring `to_lowercase`.
594        let remainder = chars.as_str();
595        let rest_start = self.len() - remainder.len();
596        // SAFETY: `to_ascii_lowercase` preserves ASCII bytes, so the prefix stays valid UTF-8.
597        let (ascii, rest) = unsafe { convert_while_ascii(remainder, u8::to_ascii_lowercase) };
598        s.push_str(&ascii);
599        let prefix_len = rest_start + ascii.len();
600
601        for (i, c) in rest.char_indices() {
602            if c == 'Σ' {
603                // Σ maps to σ, except at the end of a word where it maps to ς.
604                // This is the only conditional (contextual) but language-independent mapping
605                // in `SpecialCasing.txt`,
606                // so hard-code it rather than have a generic "condition" mechanism.
607                // See https://github.com/rust-lang/rust/issues/26035
608                let sigma_lowercase = map_uppercase_sigma(self, prefix_len + i);
609                s.push(sigma_lowercase);
610            } else {
611                match conversions::to_lower(c) {
612                    [a, '\0', _] => s.push(a),
613                    [a, b, '\0'] => {
614                        s.push(a);
615                        s.push(b);
616                    }
617                    [a, b, c] => {
618                        s.push(a);
619                        s.push(b);
620                        s.push(c);
621                    }
622                }
623            }
624        }
625
626        s
627    }
628
629    /// Returns the uppercase equivalent of this string slice, as a new [`String`].
630    ///
631    /// 'Uppercase' is defined according to the terms of
632    /// [Chapter 3 (Conformance)](https://www.unicode.org/versions/latest/core-spec/chapter-3/#G34431)
633    /// of the Unicode standard.
634    ///
635    /// Since some characters can expand into multiple characters when changing
636    /// the case, this function returns a [`String`] instead of modifying the
637    /// parameter in-place.
638    ///
639    /// Like [`char::to_uppercase()`] this method does not handle language-specific
640    /// casing, like Turkish and Azeri I/ı/İ/i. See that method's documentation
641    /// for more information.
642    ///
643    /// # Examples
644    ///
645    /// Basic usage:
646    ///
647    /// ```
648    /// let s = "hello world";
649    ///
650    /// assert_eq!("HELLO WORLD", s.to_uppercase());
651    /// ```
652    ///
653    /// Scripts without case are not changed:
654    ///
655    /// ```
656    /// let new_year = "农历新年";
657    ///
658    /// assert_eq!(new_year, new_year.to_uppercase());
659    /// ```
660    ///
661    /// One character can become multiple:
662    /// ```
663    /// let s = "tschüß";
664    ///
665    /// assert_eq!("TSCHÜSS", s.to_uppercase());
666    /// ```
667    #[cfg(not(no_global_oom_handling))]
668    #[rustc_allow_incoherent_impl]
669    #[must_use = "this returns the uppercase string as a new String, \
670                  without modifying the original"]
671    #[stable(feature = "unicode_case_mapping", since = "1.2.0")]
672    pub fn to_uppercase(&self) -> String {
673        // SAFETY: `to_ascii_uppercase` preserves ASCII bytes, so the converted
674        // prefix remains valid UTF-8.
675        let (mut s, rest) = unsafe { convert_while_ascii(self, u8::to_ascii_uppercase) };
676
677        for c in rest.chars() {
678            match conversions::to_upper(c) {
679                [a, '\0', _] => s.push(a),
680                [a, b, '\0'] => {
681                    s.push(a);
682                    s.push(b);
683                }
684                [a, b, c] => {
685                    s.push(a);
686                    s.push(b);
687                    s.push(c);
688                }
689            }
690        }
691        s
692    }
693
694    /// Returns the case-folded equivalent of this string slice, as a new [`String`].
695    ///
696    /// Case folding is a transformation, mostly matching lowercase, that is meant to be used
697    /// for case-insensitive string comparisons. Case-folded strings should not usually
698    /// be exposed directly to users.
699    ///
700    /// For the precise specification of case folding, see
701    /// [Chapter 3 (Conformance)](https://www.unicode.org/versions/latest/core-spec/chapter-3/#G63737)
702    /// of the Unicode standard.
703    ///
704    /// Since some characters can expand into multiple characters when case folding,
705    /// this function returns a [`String`] instead of modifying the parameter in-place.
706    ///
707    /// No [normalization] (e.g. NFC) is performed, so visually and semantically identical strings
708    /// might still casefold differently. For example, `"Å"` (U+00C5 LATIN CAPITAL LETTER A WITH RING ABOVE)
709    /// is considered distinct from `"Å"` (A followed by U+030A COMBINING RING ABOVE),
710    /// even though Unicode considers them canonically equivalent.
711    ///
712    /// Like [`char::to_casefold_unnormalized()`] this method does not handle language-specific
713    /// casing, like Turkish and Azeri I/ı/İ/i. See that method's documentation
714    /// for more information.
715    ///
716    /// # Examples
717    ///
718    /// Basic usage:
719    ///
720    /// ```
721    /// #![feature(casefold)]
722    /// let s0 = "HELLO";
723    /// let s1 = "Hello";
724    ///
725    /// assert_eq!(s0.to_casefold_unnormalized(), s1.to_casefold_unnormalized());
726    /// assert_eq!(s0.to_casefold_unnormalized(), "hello")
727    /// ```
728    ///
729    /// Scripts without case are not changed:
730    ///
731    /// ```
732    /// #![feature(casefold)]
733    /// let new_year = "农历新年";
734    ///
735    /// assert_eq!(new_year, new_year.to_casefold_unnormalized());
736    /// ```
737    ///
738    /// One character can become multiple:
739    ///
740    /// ```
741    /// #![feature(casefold)]
742    /// let s0 = "TSCHÜẞ";
743    /// let s1 = "TSCHÜSS";
744    /// let s2 = "tschüß";
745    ///
746    /// assert_eq!(s0.to_casefold_unnormalized(), s1.to_casefold_unnormalized());
747    /// assert_eq!(s0.to_casefold_unnormalized(), s2.to_casefold_unnormalized());
748    /// assert_eq!(s0.to_casefold_unnormalized(), "tschüss");
749    /// ```
750    ///
751    /// No NFC [normalization] is performed:
752    ///
753    /// ```rust
754    /// #![feature(casefold)]
755    /// // These two strings are visually and semantically identical...
756    /// let comp = "Å";
757    /// let decomp = "Å";
758    ///
759    /// // ... but not codepoint-for-codepoint equal.
760    /// assert_eq!(comp, "\u{C5}");
761    /// assert_eq!(decomp, "A\u{030A}");
762    ///
763    /// // Their case-foldings are likewise unequal:
764    /// assert_eq!(comp.to_casefold_unnormalized(), "\u{E5}");
765    /// assert_eq!(decomp.to_casefold_unnormalized(), "a\u{030A}");
766    /// ```
767    ///
768    /// [normalization]: https://www.unicode.org/faq/normalization.html
769    #[cfg(not(no_global_oom_handling))]
770    #[rustc_allow_incoherent_impl]
771    #[must_use = "this returns the case-folded string as a new String, \
772                  without modifying the original"]
773    #[unstable(feature = "casefold", issue = "157000")]
774    pub fn to_casefold_unnormalized(&self) -> String {
775        // SAFETY: `to_ascii_lowercase` preserves ASCII bytes, so the converted
776        // prefix remains valid UTF-8.
777        let (mut s, rest) = unsafe { convert_while_ascii(self, u8::to_ascii_lowercase) };
778
779        for c in rest.chars() {
780            match conversions::to_casefold(c) {
781                [a, '\0', _] => s.push(a),
782                [a, b, '\0'] => {
783                    s.push(a);
784                    s.push(b);
785                }
786                [a, b, c] => {
787                    s.push(a);
788                    s.push(b);
789                    s.push(c);
790                }
791            }
792        }
793        s
794    }
795
796    /// Converts a [`Box<str>`] into a [`String`] without copying or allocating.
797    ///
798    /// # Examples
799    ///
800    /// ```
801    /// let string = String::from("birthday gift");
802    /// let boxed_str = string.clone().into_boxed_str();
803    ///
804    /// assert_eq!(boxed_str.into_string(), string);
805    /// ```
806    #[stable(feature = "box_str", since = "1.4.0")]
807    #[rustc_allow_incoherent_impl]
808    #[must_use = "`self` will be dropped if the result is not used"]
809    #[inline]
810    pub fn into_string(self: Box<Self>) -> String {
811        let slice = Box::<[u8]>::from(self);
812        // SAFETY: `slice` is a valid UTF-8 sequence because it is created from a `Box<str>`.
813        unsafe { String::from_utf8_unchecked(slice.into_vec()) }
814    }
815
816    /// Creates a new [`String`] by repeating a string `n` times.
817    ///
818    /// # Panics
819    ///
820    /// This function will panic if the capacity would overflow.
821    ///
822    /// # Examples
823    ///
824    /// Basic usage:
825    ///
826    /// ```
827    /// assert_eq!("abc".repeat(4), String::from("abcabcabcabc"));
828    /// ```
829    ///
830    /// A panic upon overflow:
831    ///
832    /// ```should_panic
833    /// // this will panic at runtime
834    /// let huge = "0123456789abcdef".repeat(usize::MAX);
835    /// ```
836    #[cfg(not(no_global_oom_handling))]
837    #[rustc_allow_incoherent_impl]
838    #[must_use]
839    #[stable(feature = "repeat_str", since = "1.16.0")]
840    #[inline]
841    pub fn repeat(&self, n: usize) -> String {
842        // SAFETY: The created Vec<u8> is valid UTF-8 because `self` is str.
843        unsafe { String::from_utf8_unchecked(self.as_bytes().repeat(n)) }
844    }
845
846    /// Returns a copy of this string where each character is mapped to its
847    /// ASCII upper case equivalent.
848    ///
849    /// ASCII letters 'a' to 'z' are mapped to 'A' to 'Z',
850    /// but non-ASCII letters are unchanged.
851    ///
852    /// To uppercase the value in-place, use [`make_ascii_uppercase`].
853    ///
854    /// To uppercase ASCII characters in addition to non-ASCII characters, use
855    /// [`to_uppercase`].
856    ///
857    /// # Examples
858    ///
859    /// ```
860    /// let s = "Grüße, Jürgen ❤";
861    ///
862    /// assert_eq!("GRüßE, JüRGEN ❤", s.to_ascii_uppercase());
863    /// ```
864    ///
865    /// [`make_ascii_uppercase`]: str::make_ascii_uppercase
866    /// [`to_uppercase`]: #method.to_uppercase
867    #[cfg(not(no_global_oom_handling))]
868    #[rustc_allow_incoherent_impl]
869    #[must_use = "to uppercase the value in-place, use `make_ascii_uppercase()`"]
870    #[stable(feature = "ascii_methods_on_intrinsics", since = "1.23.0")]
871    #[inline]
872    pub fn to_ascii_uppercase(&self) -> String {
873        let bytes = self.as_bytes().to_ascii_uppercase();
874        // SAFETY: ASCII case conversion only maps a-z to A-Z and leaves
875        // all other bytes unchanged as valid UTF-8
876        unsafe { String::from_utf8_unchecked(bytes) }
877    }
878
879    /// Returns a copy of this string where each character is mapped to its
880    /// ASCII lower case equivalent.
881    ///
882    /// ASCII letters 'A' to 'Z' are mapped to 'a' to 'z',
883    /// but non-ASCII letters are unchanged.
884    ///
885    /// To lowercase the value in-place, use [`make_ascii_lowercase`].
886    ///
887    /// To lowercase ASCII characters in addition to non-ASCII characters, use
888    /// [`to_lowercase`].
889    ///
890    /// # Examples
891    ///
892    /// ```
893    /// let s = "Grüße, Jürgen ❤";
894    ///
895    /// assert_eq!("grüße, jürgen ❤", s.to_ascii_lowercase());
896    /// ```
897    ///
898    /// [`make_ascii_lowercase`]: str::make_ascii_lowercase
899    /// [`to_lowercase`]: #method.to_lowercase
900    #[cfg(not(no_global_oom_handling))]
901    #[rustc_allow_incoherent_impl]
902    #[must_use = "to lowercase the value in-place, use `make_ascii_lowercase()`"]
903    #[stable(feature = "ascii_methods_on_intrinsics", since = "1.23.0")]
904    #[inline]
905    pub fn to_ascii_lowercase(&self) -> String {
906        let bytes = self.as_bytes().to_ascii_lowercase();
907        // SAFETY: ASCII case conversion only maps A-Z to a-z and leaves
908        // all other bytes unchanged as valid UTF-8
909        unsafe { String::from_utf8_unchecked(bytes) }
910    }
911}
912
913/// Converts a boxed slice of bytes to a boxed string slice without checking
914/// that the string contains valid UTF-8.
915///
916/// # Safety
917///
918/// * The provided bytes must contain a valid UTF-8 sequence.
919///
920/// # Examples
921///
922/// ```
923/// let smile_utf8 = Box::new([226, 152, 186]);
924/// let smile = unsafe { std::str::from_boxed_utf8_unchecked(smile_utf8) };
925///
926/// assert_eq!("☺", &*smile);
927/// ```
928#[stable(feature = "str_box_extras", since = "1.20.0")]
929#[must_use]
930#[inline]
931pub unsafe fn from_boxed_utf8_unchecked(v: Box<[u8]>) -> Box<str> {
932    // SAFETY: Upheld by caller.
933    unsafe { Box::from_raw(Box::into_raw(v) as *mut str) }
934}
935
936/// Internal; same as `from_boxed_utf8_unchecked` but allocator-generic. Name
937/// probably not suitable for being made `pub` as-is.
938#[must_use]
939#[inline]
940#[cfg(not(no_global_oom_handling))]
941pub(crate) unsafe fn from_boxed_utf8_unchecked_in<A: crate::alloc::Allocator>(
942    v: Box<[u8], A>,
943) -> Box<str, A> {
944    let (ptr, alloc) = Box::into_raw_with_allocator(v);
945    // SAFETY: Upheld by caller.
946    unsafe { Box::from_raw_in(ptr as *mut str, alloc) }
947}
948
949/// Converts leading ascii bytes in `s` by calling the `convert` function.
950///
951/// For better average performance, this happens in chunks of `2*size_of::<usize>()`.
952///
953/// Returns a tuple of the converted prefix and the remainder starting from
954/// the first non-ascii character.
955///
956/// This function is only public so that it can be verified in a codegen test,
957/// see `issue-123712-str-to-lower-autovectorization.rs`.
958///
959/// # Safety
960///
961/// `convert` must return an ASCII byte for every ASCII input byte.
962#[unstable(feature = "str_internals", issue = "none")]
963#[doc(hidden)]
964#[inline]
965#[cfg(not(no_global_oom_handling))]
966pub unsafe fn convert_while_ascii(s: &str, convert: fn(&u8) -> u8) -> (String, &str) {
967    // Process the input in chunks of 16 bytes to enable auto-vectorization.
968    // Previously the chunk size depended on the size of `usize`,
969    // but on 32-bit platforms with sse or neon is also the better choice.
970    // The only downside on other platforms would be a bit more loop-unrolling.
971    const N: usize = 16;
972
973    let mut slice = s.as_bytes();
974    let mut out = Vec::with_capacity(slice.len());
975    let mut out_slice = out.spare_capacity_mut();
976
977    let mut ascii_prefix_len = 0_usize;
978    let mut is_ascii = [false; N];
979
980    while slice.len() >= N {
981        // SAFETY: checked in loop condition
982        let chunk = unsafe { slice.get_unchecked(..N) };
983        // SAFETY: out_slice has at least same length as input slice and gets sliced with the same offsets
984        let out_chunk = unsafe { out_slice.get_unchecked_mut(..N) };
985
986        for j in 0..N {
987            is_ascii[j] = chunk[j] <= 127;
988        }
989
990        // Auto-vectorization for this check is a bit fragile, sum and comparing against the chunk
991        // size gives the best result, specifically a pmovmsk instruction on x86.
992        // See https://github.com/llvm/llvm-project/issues/96395 for why llvm currently does not
993        // currently recognize other similar idioms.
994        if is_ascii.iter().map(|x| *x as u8).sum::<u8>() as usize != N {
995            break;
996        }
997
998        for j in 0..N {
999            out_chunk[j] = MaybeUninit::new(convert(&chunk[j]));
1000        }
1001
1002        ascii_prefix_len += N;
1003        // SAFETY: checked in loop condition.
1004        slice = unsafe { slice.get_unchecked(N..) };
1005        // SAFETY: out_slice has at least same length as input slice.
1006        out_slice = unsafe { out_slice.get_unchecked_mut(N..) };
1007    }
1008
1009    // handle the remainder as individual bytes
1010    while !slice.is_empty() {
1011        let byte = slice[0];
1012        if byte > 127 {
1013            break;
1014        }
1015        // SAFETY: out_slice has at least same length as input slice
1016        unsafe {
1017            *out_slice.get_unchecked_mut(0) = MaybeUninit::new(convert(&byte));
1018        }
1019        ascii_prefix_len += 1;
1020        // SAFETY: slice has at least one byte, so slicing from 1.. is safe
1021        slice = unsafe { slice.get_unchecked(1..) };
1022        // SAFETY: out_slice has at least same length as input slice
1023        out_slice = unsafe { out_slice.get_unchecked_mut(1..) };
1024    }
1025
1026    // SAFETY: ascii_prefix_len bytes have been initialized above
1027    unsafe { out.set_len(ascii_prefix_len) };
1028
1029    // SAFETY: We have written only valid ascii to the output vec
1030    let ascii_string = unsafe { String::from_utf8_unchecked(out) };
1031
1032    // SAFETY: we know this is a valid char boundary
1033    // since we only skipped over leading ascii bytes
1034    let rest = unsafe { core::str::from_utf8_unchecked(slice) };
1035
1036    (ascii_string, rest)
1037}
1038#[inline]
1039#[cfg(not(no_global_oom_handling))]
1040#[allow(dead_code)]
1041/// Faster implementation of string replacement for ASCII to ASCII cases.
1042/// Should produce fast vectorized code.
1043///
1044/// # Safety
1045///
1046/// * `utf8_bytes` must contain valid UTF-8.
1047/// * Both `from` and `to` must be ASCII bytes (at most `0x7F`).
1048unsafe fn replace_ascii(utf8_bytes: &[u8], from: u8, to: u8) -> String {
1049    let result: Vec<u8> = utf8_bytes.iter().map(|b| if *b == from { to } else { *b }).collect();
1050    // SAFETY: We replaced ascii with ascii on valid utf8 strings.
1051    unsafe { String::from_utf8_unchecked(result) }
1052}