Skip to main content

alloc/
string.rs

1//! A UTF-8โ€“encoded, growable string.
2//!
3//! This module contains the [`String`] type, the [`ToString`] trait for
4//! converting to strings, and several error types that may result from
5//! working with [`String`]s.
6//!
7//! # Examples
8//!
9//! There are multiple ways to create a new [`String`] from a string literal:
10//!
11//! ```
12//! let s = "Hello".to_string();
13//!
14//! let s = String::from("world");
15//! let s: String = "also this".into();
16//! ```
17//!
18//! You can create a new [`String`] from an existing one by concatenating with
19//! `+`:
20//!
21//! ```
22//! let s = "Hello".to_string();
23//!
24//! let message = s + " world!";
25//! ```
26//!
27//! If you have a vector of valid UTF-8 bytes, you can make a [`String`] out of
28//! it. You can do the reverse too.
29//!
30//! ```
31//! let sparkle_heart = vec![240, 159, 146, 150];
32//!
33//! // We know these bytes are valid, so we'll use `unwrap()`.
34//! let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
35//!
36//! assert_eq!("๐Ÿ’–", sparkle_heart);
37//!
38//! let bytes = sparkle_heart.into_bytes();
39//!
40//! assert_eq!(bytes, [240, 159, 146, 150]);
41//! ```
42
43#![stable(feature = "rust1", since = "1.0.0")]
44
45use core::error::Error;
46use core::iter::FusedIterator;
47#[cfg(not(no_global_oom_handling))]
48use core::iter::from_fn;
49#[cfg(not(no_global_oom_handling))]
50use core::num::Saturating;
51#[cfg(not(no_global_oom_handling))]
52use core::ops::Add;
53#[cfg(not(no_global_oom_handling))]
54use core::ops::AddAssign;
55use core::ops::{self, Range, RangeBounds};
56use core::str::pattern::{Pattern, Utf8Pattern};
57use core::{fmt, hash, hint, ptr, slice};
58
59#[cfg(not(no_global_oom_handling))]
60use crate::alloc::Allocator;
61#[cfg(not(no_global_oom_handling))]
62use crate::borrow::{Cow, ToOwned};
63use crate::boxed::Box;
64use crate::collections::TryReserveError;
65use crate::str::{self, CharIndices, Chars, Utf8Error, from_utf8_unchecked_mut};
66#[cfg(not(no_global_oom_handling))]
67use crate::str::{FromStr, from_boxed_utf8_unchecked};
68use crate::vec::{self, Vec};
69
70/// A UTF-8โ€“encoded, growable string.
71///
72/// `String` is the most common string type. It has ownership over the contents
73/// of the string, stored in a heap-allocated buffer (see [Representation](#representation)).
74/// It is closely related to its borrowed counterpart, the primitive [`str`].
75///
76/// # Examples
77///
78/// You can create a `String` from [a literal string][`&str`] with [`String::from`]:
79///
80/// [`String::from`]: From::from
81///
82/// ```
83/// let hello = String::from("Hello, world!");
84/// ```
85///
86/// You can append a [`char`] to a `String` with the [`push`] method, and
87/// append a [`&str`] with the [`push_str`] method:
88///
89/// ```
90/// let mut hello = String::from("Hello, ");
91///
92/// hello.push('w');
93/// hello.push_str("orld!");
94/// ```
95///
96/// [`push`]: String::push
97/// [`push_str`]: String::push_str
98///
99/// If you have a vector of UTF-8 bytes, you can create a `String` from it with
100/// the [`from_utf8`] method:
101///
102/// ```
103/// // some bytes, in a vector
104/// let sparkle_heart = vec![240, 159, 146, 150];
105///
106/// // We know these bytes are valid, so we'll use `unwrap()`.
107/// let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
108///
109/// assert_eq!("๐Ÿ’–", sparkle_heart);
110/// ```
111///
112/// [`from_utf8`]: String::from_utf8
113///
114/// # UTF-8
115///
116/// `String`s are always valid UTF-8. If you need a non-UTF-8 string, consider
117/// [`OsString`]. It is similar, but without the UTF-8 constraint. Because UTF-8
118/// is a variable width encoding, `String`s are typically smaller than an array of
119/// the same `char`s:
120///
121/// ```
122/// // `s` is ASCII which represents each `char` as one byte
123/// let s = "hello";
124/// assert_eq!(s.len(), 5);
125///
126/// // A `char` array with the same contents would be longer because
127/// // every `char` is four bytes
128/// let s = ['h', 'e', 'l', 'l', 'o'];
129/// let size: usize = s.into_iter().map(|c| size_of_val(&c)).sum();
130/// assert_eq!(size, 20);
131///
132/// // However, for non-ASCII strings, the difference will be smaller
133/// // and sometimes they are the same
134/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
135/// assert_eq!(s.len(), 20);
136///
137/// let s = ['๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–', '๐Ÿ’–'];
138/// let size: usize = s.into_iter().map(|c| size_of_val(&c)).sum();
139/// assert_eq!(size, 20);
140/// ```
141///
142/// This raises interesting questions as to how `s[i]` should work.
143/// What should `i` be here? Several options include byte indices and
144/// `char` indices but, because of UTF-8 encoding, only byte indices
145/// would provide constant time indexing. Getting the `i`th `char`, for
146/// example, is available using [`chars`]:
147///
148/// ```
149/// let s = "hello";
150/// let third_character = s.chars().nth(2);
151/// assert_eq!(third_character, Some('l'));
152///
153/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
154/// let third_character = s.chars().nth(2);
155/// assert_eq!(third_character, Some('๐Ÿ’–'));
156/// ```
157///
158/// Next, what should `s[i]` return? Because indexing returns a reference
159/// to underlying data it could be `&u8`, `&[u8]`, or something similar.
160/// Since we're only providing one index, `&u8` makes the most sense but that
161/// might not be what the user expects and can be explicitly achieved with
162/// [`as_bytes()`]:
163///
164/// ```
165/// // The first byte is 104 - the byte value of `'h'`
166/// let s = "hello";
167/// assert_eq!(s.as_bytes()[0], 104);
168/// // or
169/// assert_eq!(s.as_bytes()[0], b'h');
170///
171/// // The first byte is 240 which isn't obviously useful
172/// let s = "๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–๐Ÿ’–";
173/// assert_eq!(s.as_bytes()[0], 240);
174/// ```
175///
176/// Due to these ambiguities/restrictions, indexing with a `usize` is simply
177/// forbidden:
178///
179/// ```compile_fail,E0277
180/// let s = "hello";
181///
182/// // The following will not compile!
183/// println!("The first letter of s is {}", s[0]);
184/// ```
185///
186/// It is more clear, however, how `&s[i..j]` should work (that is,
187/// indexing with a range). It should accept byte indices (to be constant-time)
188/// and return a `&str` which is UTF-8 encoded. This is also called "string slicing".
189/// Note this will panic if the byte indices provided are not character
190/// boundaries - see [`is_char_boundary`] for more details. See the implementations
191/// for [`SliceIndex<str>`] for more details on string slicing. For a non-panicking
192/// version of string slicing, see [`get`].
193///
194/// [`OsString`]: ../../std/ffi/struct.OsString.html "ffi::OsString"
195/// [`SliceIndex<str>`]: core::slice::SliceIndex
196/// [`as_bytes()`]: str::as_bytes
197/// [`get`]: str::get
198/// [`is_char_boundary`]: str::is_char_boundary
199///
200/// The [`bytes`] and [`chars`] methods return iterators over the bytes and
201/// codepoints of the string, respectively. To iterate over codepoints along
202/// with byte indices, use [`char_indices`].
203///
204/// [`bytes`]: str::bytes
205/// [`chars`]: str::chars
206/// [`char_indices`]: str::char_indices
207///
208/// # Deref
209///
210/// `String` implements <code>[Deref]<Target = [str]></code>, and so inherits all of [`str`]'s
211/// methods. In addition, this means that you can pass a `String` to a
212/// function which takes a [`&str`] by using an ampersand (`&`):
213///
214/// ```
215/// fn takes_str(s: &str) { }
216///
217/// let s = String::from("Hello");
218///
219/// takes_str(&s);
220/// ```
221///
222/// This will create a [`&str`] from the `String` and pass it in. This
223/// conversion is very inexpensive, and so generally, functions will accept
224/// [`&str`]s as arguments unless they need a `String` for some specific
225/// reason.
226///
227/// In certain cases Rust doesn't have enough information to make this
228/// conversion, known as [`Deref`] coercion. In the following example a string
229/// slice [`&'a str`][`&str`] implements the trait `TraitExample`, and the function
230/// `example_func` takes anything that implements the trait. In this case Rust
231/// would need to make two implicit conversions, which Rust doesn't have the
232/// means to do. For that reason, the following example will not compile.
233///
234/// ```compile_fail,E0277
235/// trait TraitExample {}
236///
237/// impl<'a> TraitExample for &'a str {}
238///
239/// fn example_func<A: TraitExample>(example_arg: A) {}
240///
241/// let example_string = String::from("example_string");
242/// example_func(&example_string);
243/// ```
244///
245/// There are two options that would work instead. The first would be to
246/// change the line `example_func(&example_string);` to
247/// `example_func(example_string.as_str());`, using the method [`as_str()`]
248/// to explicitly extract the string slice containing the string. The second
249/// way changes `example_func(&example_string);` to
250/// `example_func(&*example_string);`. In this case we are dereferencing a
251/// `String` to a [`str`], then referencing the [`str`] back to
252/// [`&str`]. The second way is more idiomatic, however both work to do the
253/// conversion explicitly rather than relying on the implicit conversion.
254///
255/// # Representation
256///
257/// A `String` is made up of three components: a pointer to some bytes, a
258/// length, and a capacity. The pointer points to the internal buffer which `String`
259/// uses to store its data. The length is the number of bytes currently stored
260/// in the buffer, and the capacity is the size of the buffer in bytes. As such,
261/// the length will always be less than or equal to the capacity.
262///
263/// This buffer is always stored on the heap.
264///
265/// You can look at these with the [`as_ptr`], [`len`], and [`capacity`]
266/// methods:
267///
268/// ```
269/// let story = String::from("Once upon a time...");
270///
271/// // Deconstruct the String into parts.
272/// let (ptr, len, capacity) = story.into_raw_parts();
273///
274/// // story has nineteen bytes
275/// assert_eq!(19, len);
276///
277/// // We can re-build a String out of ptr, len, and capacity. This is all
278/// // unsafe because we are responsible for making sure the components are
279/// // valid:
280/// let s = unsafe { String::from_raw_parts(ptr, len, capacity) } ;
281///
282/// assert_eq!(String::from("Once upon a time..."), s);
283/// ```
284///
285/// [`as_ptr`]: str::as_ptr
286/// [`len`]: String::len
287/// [`capacity`]: String::capacity
288///
289/// If a `String` has enough capacity, adding elements to it will not
290/// re-allocate. For example, consider this program:
291///
292/// ```
293/// let mut s = String::new();
294///
295/// println!("{}", s.capacity());
296///
297/// for _ in 0..5 {
298///     s.push_str("hello");
299///     println!("{}", s.capacity());
300/// }
301/// ```
302///
303/// This will output the following:
304///
305/// ```text
306/// 0
307/// 8
308/// 16
309/// 16
310/// 32
311/// 32
312/// ```
313///
314/// At first, we have no memory allocated at all, but as we append to the
315/// string, it increases its capacity appropriately. If we instead use the
316/// [`with_capacity`] method to allocate the correct capacity initially:
317///
318/// ```
319/// let mut s = String::with_capacity(25);
320///
321/// println!("{}", s.capacity());
322///
323/// for _ in 0..5 {
324///     s.push_str("hello");
325///     println!("{}", s.capacity());
326/// }
327/// ```
328///
329/// [`with_capacity`]: String::with_capacity
330///
331/// We end up with a different output:
332///
333/// ```text
334/// 25
335/// 25
336/// 25
337/// 25
338/// 25
339/// 25
340/// ```
341///
342/// Here, there's no need to allocate more memory inside the loop.
343///
344/// [str]: prim@str "str"
345/// [`str`]: prim@str "str"
346/// [`&str`]: prim@str "&str"
347/// [Deref]: core::ops::Deref "ops::Deref"
348/// [`Deref`]: core::ops::Deref "ops::Deref"
349/// [`as_str()`]: String::as_str
350#[derive(PartialEq, PartialOrd, Eq, Ord)]
351#[stable(feature = "rust1", since = "1.0.0")]
352#[lang = "String"]
353pub struct String {
354    vec: Vec<u8>,
355}
356
357/// A possible error value when converting a `String` from a UTF-8 byte vector.
358///
359/// This type is the error type for the [`from_utf8`] method on [`String`]. It
360/// is designed in such a way to carefully avoid reallocations: the
361/// [`into_bytes`] method will give back the byte vector that was used in the
362/// conversion attempt.
363///
364/// [`from_utf8`]: String::from_utf8
365/// [`into_bytes`]: FromUtf8Error::into_bytes
366///
367/// The [`Utf8Error`] type provided by [`std::str`] represents an error that may
368/// occur when converting a slice of [`u8`]s to a [`&str`]. In this sense, it's
369/// an analogue to `FromUtf8Error`, and you can get one from a `FromUtf8Error`
370/// through the [`utf8_error`] method.
371///
372/// [`Utf8Error`]: str::Utf8Error "std::str::Utf8Error"
373/// [`std::str`]: core::str "std::str"
374/// [`&str`]: prim@str "&str"
375/// [`utf8_error`]: FromUtf8Error::utf8_error
376///
377/// # Examples
378///
379/// ```
380/// // some invalid bytes, in a vector
381/// let bytes = vec![0, 159];
382///
383/// let value = String::from_utf8(bytes);
384///
385/// assert!(value.is_err());
386/// assert_eq!(vec![0, 159], value.unwrap_err().into_bytes());
387/// ```
388#[stable(feature = "rust1", since = "1.0.0")]
389#[cfg_attr(not(no_global_oom_handling), derive(Clone))]
390#[derive(Debug, PartialEq, Eq)]
391pub struct FromUtf8Error {
392    bytes: Vec<u8>,
393    error: Utf8Error,
394}
395
396/// A possible error value when converting a `String` from a UTF-16 byte slice.
397///
398/// This type is the error type for the [`from_utf16`] method on [`String`].
399///
400/// [`from_utf16`]: String::from_utf16
401///
402/// # Examples
403///
404/// ```
405/// // ๐„žmu<invalid>ic
406/// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
407///           0xD800, 0x0069, 0x0063];
408///
409/// assert!(String::from_utf16(v).is_err());
410/// ```
411#[stable(feature = "rust1", since = "1.0.0")]
412#[derive(Debug)]
413pub struct FromUtf16Error {
414    kind: FromUtf16ErrorKind,
415}
416
417#[cfg_attr(no_global_oom_handling, expect(dead_code))]
418#[derive(Clone, PartialEq, Eq, Debug)]
419enum FromUtf16ErrorKind {
420    LoneSurrogate,
421    OddBytes,
422}
423
424impl String {
425    /// Creates a new empty `String`.
426    ///
427    /// Given that the `String` is empty, this will not allocate any initial
428    /// buffer. While that means that this initial operation is very
429    /// inexpensive, it may cause excessive allocation later when you add
430    /// data. If you have an idea of how much data the `String` will hold,
431    /// consider the [`with_capacity`] method to prevent excessive
432    /// re-allocation.
433    ///
434    /// [`with_capacity`]: String::with_capacity
435    ///
436    /// # Examples
437    ///
438    /// ```
439    /// let s = String::new();
440    /// ```
441    #[inline]
442    #[rustc_const_stable(feature = "const_string_new", since = "1.39.0")]
443    #[rustc_diagnostic_item = "string_new"]
444    #[stable(feature = "rust1", since = "1.0.0")]
445    #[must_use]
446    pub const fn new() -> String {
447        String { vec: Vec::new() }
448    }
449
450    /// Creates a new empty `String` with at least the specified capacity.
451    ///
452    /// `String`s have an internal buffer to hold their data. The capacity is
453    /// the length of that buffer, and can be queried with the [`capacity`]
454    /// method. This method creates an empty `String`, but one with an initial
455    /// buffer that can hold at least `capacity` bytes. This is useful when you
456    /// may be appending a bunch of data to the `String`, reducing the number of
457    /// reallocations it needs to do.
458    ///
459    /// [`capacity`]: String::capacity
460    ///
461    /// If the given capacity is `0`, no allocation will occur, and this method
462    /// is identical to the [`new`] method.
463    ///
464    /// [`new`]: String::new
465    ///
466    /// # Panics
467    ///
468    /// Panics if the capacity exceeds `isize::MAX` _bytes_.
469    ///
470    /// # Examples
471    ///
472    /// ```
473    /// let mut s = String::with_capacity(10);
474    ///
475    /// // The String contains no chars, even though it has capacity for more
476    /// assert_eq!(s.len(), 0);
477    ///
478    /// // These are all done without reallocating...
479    /// let cap = s.capacity();
480    /// for _ in 0..10 {
481    ///     s.push('a');
482    /// }
483    ///
484    /// assert_eq!(s.capacity(), cap);
485    ///
486    /// // ...but this may make the string reallocate
487    /// s.push('a');
488    /// ```
489    #[cfg(not(no_global_oom_handling))]
490    #[inline]
491    #[stable(feature = "rust1", since = "1.0.0")]
492    #[must_use]
493    pub fn with_capacity(capacity: usize) -> String {
494        String { vec: Vec::with_capacity(capacity) }
495    }
496
497    /// Creates a new empty `String` with at least the specified capacity.
498    ///
499    /// # Errors
500    ///
501    /// Returns [`Err`] if the capacity exceeds `isize::MAX` bytes,
502    /// or if the memory allocator reports failure.
503    ///
504    #[inline]
505    #[unstable(feature = "try_with_capacity", issue = "91913")]
506    pub fn try_with_capacity(capacity: usize) -> Result<String, TryReserveError> {
507        Ok(String { vec: Vec::try_with_capacity(capacity)? })
508    }
509
510    /// Converts a vector of bytes to a `String`.
511    ///
512    /// A string ([`String`]) is made of bytes ([`u8`]), and a vector of bytes
513    /// ([`Vec<u8>`]) is made of bytes, so this function converts between the
514    /// two. Not all byte slices are valid `String`s, however: `String`
515    /// requires that it is valid UTF-8. `from_utf8()` checks to ensure that
516    /// the bytes are valid UTF-8, and then does the conversion.
517    ///
518    /// If you are sure that the byte slice is valid UTF-8, and you don't want
519    /// to incur the overhead of the validity check, there is an unsafe version
520    /// of this function, [`from_utf8_unchecked`], which has the same behavior
521    /// but skips the check.
522    ///
523    /// This method will take care to not copy the vector, for efficiency's
524    /// sake.
525    ///
526    /// If you need a [`&str`] instead of a `String`, consider
527    /// [`str::from_utf8`].
528    ///
529    /// The inverse of this method is [`into_bytes`].
530    ///
531    /// # Errors
532    ///
533    /// Returns [`Err`] if the slice is not UTF-8 with a description as to why the
534    /// provided bytes are not UTF-8. The vector you moved in is also included.
535    ///
536    /// # Examples
537    ///
538    /// Basic usage:
539    ///
540    /// ```
541    /// // some bytes, in a vector
542    /// let sparkle_heart = vec![240, 159, 146, 150];
543    ///
544    /// // We know these bytes are valid, so we'll use `unwrap()`.
545    /// let sparkle_heart = String::from_utf8(sparkle_heart).unwrap();
546    ///
547    /// assert_eq!("๐Ÿ’–", sparkle_heart);
548    /// ```
549    ///
550    /// Incorrect bytes:
551    ///
552    /// ```
553    /// // some invalid bytes, in a vector
554    /// let sparkle_heart = vec![0, 159, 146, 150];
555    ///
556    /// assert!(String::from_utf8(sparkle_heart).is_err());
557    /// ```
558    ///
559    /// See the docs for [`FromUtf8Error`] for more details on what you can do
560    /// with this error.
561    ///
562    /// [`from_utf8_unchecked`]: String::from_utf8_unchecked
563    /// [`Vec<u8>`]: crate::vec::Vec "Vec"
564    /// [`&str`]: prim@str "&str"
565    /// [`into_bytes`]: String::into_bytes
566    #[inline]
567    #[stable(feature = "rust1", since = "1.0.0")]
568    #[rustc_diagnostic_item = "string_from_utf8"]
569    pub fn from_utf8(vec: Vec<u8>) -> Result<String, FromUtf8Error> {
570        match str::from_utf8(&vec) {
571            Ok(..) => Ok(String { vec }),
572            Err(e) => Err(FromUtf8Error { bytes: vec, error: e }),
573        }
574    }
575
576    /// Converts a slice of bytes to a string, including invalid characters.
577    ///
578    /// Strings are made of bytes ([`u8`]), and a slice of bytes
579    /// ([`&[u8]`][byteslice]) is made of bytes, so this function converts
580    /// between the two. Not all byte slices are valid strings, however: strings
581    /// are required to be valid UTF-8. During this conversion,
582    /// `from_utf8_lossy()` will replace any invalid UTF-8 sequences with
583    /// [`U+FFFD REPLACEMENT CHARACTER`][U+FFFD], which looks like this: ๏ฟฝ
584    ///
585    /// [byteslice]: prim@slice
586    /// [U+FFFD]: char::REPLACEMENT_CHARACTER
587    ///
588    /// If you are sure that the byte slice is valid UTF-8, and you don't want
589    /// to incur the overhead of the conversion, there is an unsafe version
590    /// of this function, [`from_utf8_unchecked`], which has the same behavior
591    /// but skips the checks.
592    ///
593    /// [`from_utf8_unchecked`]: String::from_utf8_unchecked
594    ///
595    /// This function returns a [`Cow<'a, str>`]. If our byte slice is invalid
596    /// UTF-8, then we need to insert the replacement characters, which will
597    /// change the size of the string, and hence, require a `String`. But if
598    /// it's already valid UTF-8, we don't need a new allocation. This return
599    /// type allows us to handle both cases.
600    ///
601    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
602    ///
603    /// # Examples
604    ///
605    /// Basic usage:
606    ///
607    /// ```
608    /// // some bytes, in a vector
609    /// let sparkle_heart = vec![240, 159, 146, 150];
610    ///
611    /// let sparkle_heart = String::from_utf8_lossy(&sparkle_heart);
612    ///
613    /// assert_eq!("๐Ÿ’–", sparkle_heart);
614    /// ```
615    ///
616    /// Incorrect bytes:
617    ///
618    /// ```
619    /// // some invalid bytes
620    /// let input = b"Hello \xF0\x90\x80World";
621    /// let output = String::from_utf8_lossy(input);
622    ///
623    /// assert_eq!("Hello ๏ฟฝWorld", output);
624    /// ```
625    #[must_use]
626    #[cfg(not(no_global_oom_handling))]
627    #[stable(feature = "rust1", since = "1.0.0")]
628    pub fn from_utf8_lossy(v: &[u8]) -> Cow<'_, str> {
629        let mut iter = v.utf8_chunks();
630
631        let Some(chunk) = iter.next() else {
632            return Cow::Borrowed("");
633        };
634        let first_valid = chunk.valid();
635        if chunk.invalid().is_empty() {
636            debug_assert_eq!(first_valid.len(), v.len());
637            return Cow::Borrowed(first_valid);
638        }
639
640        const REPLACEMENT: &str = "\u{FFFD}";
641
642        let mut res = String::with_capacity(v.len());
643        res.push_str(first_valid);
644        res.push_str(REPLACEMENT);
645
646        for chunk in iter {
647            res.push_str(chunk.valid());
648            if !chunk.invalid().is_empty() {
649                res.push_str(REPLACEMENT);
650            }
651        }
652
653        Cow::Owned(res)
654    }
655
656    /// Converts a [`Vec<u8>`] to a `String`, substituting invalid UTF-8
657    /// sequences with replacement characters.
658    ///
659    /// See [`from_utf8_lossy`] for more details.
660    ///
661    /// [`from_utf8_lossy`]: String::from_utf8_lossy
662    ///
663    /// Note that this function does not guarantee reuse of the original `Vec`
664    /// allocation.
665    ///
666    /// # Examples
667    ///
668    /// Basic usage:
669    ///
670    /// ```
671    /// // some bytes, in a vector
672    /// let sparkle_heart = vec![240, 159, 146, 150];
673    ///
674    /// let sparkle_heart = String::from_utf8_lossy_owned(sparkle_heart);
675    ///
676    /// assert_eq!(String::from("๐Ÿ’–"), sparkle_heart);
677    /// ```
678    ///
679    /// Incorrect bytes:
680    ///
681    /// ```
682    /// // some invalid bytes
683    /// let input: Vec<u8> = b"Hello \xF0\x90\x80World".into();
684    /// let output = String::from_utf8_lossy_owned(input);
685    ///
686    /// assert_eq!(String::from("Hello ๏ฟฝWorld"), output);
687    /// ```
688    #[must_use]
689    #[cfg(not(no_global_oom_handling))]
690    #[stable(feature = "string_from_utf8_lossy_owned", since = "1.99.0")]
691    pub fn from_utf8_lossy_owned(v: Vec<u8>) -> String {
692        if let Cow::Owned(string) = String::from_utf8_lossy(&v) {
693            string
694        } else {
695            // SAFETY: `String::from_utf8_lossy`'s contract ensures that if
696            // it returns a `Cow::Borrowed`, it is a valid UTF-8 string.
697            // Otherwise, it returns a new allocation of an owned `String`, with
698            // replacement characters for invalid sequences, which is returned
699            // above.
700            unsafe { String::from_utf8_unchecked(v) }
701        }
702    }
703
704    /// Decode a native endian UTF-16โ€“encoded vector `v` into a `String`,
705    /// returning [`Err`] if `v` contains any invalid data.
706    ///
707    /// # Examples
708    ///
709    /// ```
710    /// // ๐„žmusic
711    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
712    ///           0x0073, 0x0069, 0x0063];
713    /// assert_eq!(String::from("๐„žmusic"),
714    ///            String::from_utf16(v).unwrap());
715    ///
716    /// // ๐„žmu<invalid>ic
717    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
718    ///           0xD800, 0x0069, 0x0063];
719    /// assert!(String::from_utf16(v).is_err());
720    /// ```
721    #[cfg(not(no_global_oom_handling))]
722    #[stable(feature = "rust1", since = "1.0.0")]
723    pub fn from_utf16(v: &[u16]) -> Result<String, FromUtf16Error> {
724        Self::from_utf16_units(v.iter().cloned(), v.len())
725    }
726
727    /// Decodes an iterator of UTF-16 code units into a `String`, returning
728    /// [`Err`] on the first lone surrogate. `capacity` should be the number of
729    /// code units, which is used to preallocate the output buffer.
730    // This isn't done via collect::<Result<_, _>>() for performance reasons.
731    // FIXME: the function can be simplified again when #48994 is closed.
732    #[cfg(not(no_global_oom_handling))]
733    #[inline]
734    fn from_utf16_units(
735        units: impl Iterator<Item = u16>,
736        capacity: usize,
737    ) -> Result<String, FromUtf16Error> {
738        let mut ret = String::with_capacity(capacity);
739        for c in char::decode_utf16(units) {
740            let Ok(c) = c else {
741                return Err(FromUtf16Error { kind: FromUtf16ErrorKind::LoneSurrogate });
742            };
743            ret.push(c);
744        }
745        Ok(ret)
746    }
747
748    /// Decode a native endian UTF-16โ€“encoded slice `v` into a `String`,
749    /// replacing invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
750    ///
751    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
752    /// `from_utf16_lossy` returns a `String` since the UTF-16 to UTF-8
753    /// conversion requires a memory allocation.
754    ///
755    /// [`from_utf8_lossy`]: String::from_utf8_lossy
756    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
757    /// [U+FFFD]: char::REPLACEMENT_CHARACTER
758    ///
759    /// # Examples
760    ///
761    /// ```
762    /// // ๐„žmus<invalid>ic<invalid>
763    /// let v = &[0xD834, 0xDD1E, 0x006d, 0x0075,
764    ///           0x0073, 0xDD1E, 0x0069, 0x0063,
765    ///           0xD834];
766    ///
767    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
768    ///            String::from_utf16_lossy(v));
769    /// ```
770    #[cfg(not(no_global_oom_handling))]
771    #[must_use]
772    #[inline]
773    #[stable(feature = "rust1", since = "1.0.0")]
774    pub fn from_utf16_lossy(v: &[u16]) -> String {
775        char::decode_utf16(v.iter().cloned())
776            .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
777            .collect()
778    }
779
780    /// Decode a UTF-16LEโ€“encoded vector `v` into a `String`,
781    /// returning [`Err`] if `v` contains any invalid data.
782    ///
783    /// # Examples
784    ///
785    /// Basic usage:
786    ///
787    /// ```
788    /// // ๐„žmusic
789    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
790    ///           0x73, 0x00, 0x69, 0x00, 0x63, 0x00];
791    /// assert_eq!(String::from("๐„žmusic"),
792    ///            String::from_utf16le(v).unwrap());
793    ///
794    /// // ๐„žmu<invalid>ic
795    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
796    ///           0x00, 0xD8, 0x69, 0x00, 0x63, 0x00];
797    /// assert!(String::from_utf16le(v).is_err());
798    /// ```
799    #[cfg(not(no_global_oom_handling))]
800    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
801    pub fn from_utf16le(v: &[u8]) -> Result<String, FromUtf16Error> {
802        let (chunks, []) = v.as_chunks::<2>() else {
803            return Err(FromUtf16Error { kind: FromUtf16ErrorKind::OddBytes });
804        };
805        // SAFETY: The aligned part of `v` can be transmuted into a valid u16 slice.
806        match (cfg!(target_endian = "little"), unsafe { v.align_to::<u16>() }) {
807            (true, ([], v, [])) => Self::from_utf16(v),
808            _ => {
809                Self::from_utf16_units(chunks.iter().copied().map(u16::from_le_bytes), chunks.len())
810            }
811        }
812    }
813
814    /// Decode a UTF-16LEโ€“encoded slice `v` into a `String`, replacing
815    /// invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
816    ///
817    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
818    /// `from_utf16le_lossy` returns a `String` since the UTF-16 to UTF-8
819    /// conversion requires a memory allocation.
820    ///
821    /// [`from_utf8_lossy`]: String::from_utf8_lossy
822    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
823    /// [U+FFFD]: char::REPLACEMENT_CHARACTER
824    ///
825    /// # Examples
826    ///
827    /// Basic usage:
828    ///
829    /// ```
830    /// // ๐„žmus<invalid>ic<invalid>
831    /// let v = &[0x34, 0xD8, 0x1E, 0xDD, 0x6d, 0x00, 0x75, 0x00,
832    ///           0x73, 0x00, 0x1E, 0xDD, 0x69, 0x00, 0x63, 0x00,
833    ///           0x34, 0xD8];
834    ///
835    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
836    ///            String::from_utf16le_lossy(v));
837    /// ```
838    #[cfg(not(no_global_oom_handling))]
839    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
840    pub fn from_utf16le_lossy(v: &[u8]) -> String {
841        // SAFETY: The aligned part of `v` can be transmuted into a valid u16 slice.
842        match (cfg!(target_endian = "little"), unsafe { v.align_to::<u16>() }) {
843            (true, ([], v, [])) => Self::from_utf16_lossy(v),
844            (true, ([], v, [_remainder])) => Self::from_utf16_lossy(v) + "\u{FFFD}",
845            _ => {
846                let (chunks, remainder) = v.as_chunks::<2>();
847                let string = char::decode_utf16(chunks.iter().copied().map(u16::from_le_bytes))
848                    .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
849                    .collect();
850                if remainder.is_empty() { string } else { string + "\u{FFFD}" }
851            }
852        }
853    }
854
855    /// Decode a UTF-16BEโ€“encoded vector `v` into a `String`,
856    /// returning [`Err`] if `v` contains any invalid data.
857    ///
858    /// # Examples
859    ///
860    /// Basic usage:
861    ///
862    /// ```
863    /// // ๐„žmusic
864    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
865    ///           0x00, 0x73, 0x00, 0x69, 0x00, 0x63];
866    /// assert_eq!(String::from("๐„žmusic"),
867    ///            String::from_utf16be(v).unwrap());
868    ///
869    /// // ๐„žmu<invalid>ic
870    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
871    ///           0xD8, 0x00, 0x00, 0x69, 0x00, 0x63];
872    /// assert!(String::from_utf16be(v).is_err());
873    /// ```
874    #[cfg(not(no_global_oom_handling))]
875    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
876    pub fn from_utf16be(v: &[u8]) -> Result<String, FromUtf16Error> {
877        let (chunks, []) = v.as_chunks::<2>() else {
878            return Err(FromUtf16Error { kind: FromUtf16ErrorKind::OddBytes });
879        };
880        // SAFETY: The aligned part of `v` can be transmuted into a valid u16 slice.
881        match (cfg!(target_endian = "big"), unsafe { v.align_to::<u16>() }) {
882            (true, ([], v, [])) => Self::from_utf16(v),
883            _ => {
884                Self::from_utf16_units(chunks.iter().copied().map(u16::from_be_bytes), chunks.len())
885            }
886        }
887    }
888
889    /// Decode a UTF-16BEโ€“encoded slice `v` into a `String`, replacing
890    /// invalid data with [the replacement character (`U+FFFD`)][U+FFFD].
891    ///
892    /// Unlike [`from_utf8_lossy`] which returns a [`Cow<'a, str>`],
893    /// `from_utf16le_lossy` returns a `String` since the UTF-16 to UTF-8
894    /// conversion requires a memory allocation.
895    ///
896    /// [`from_utf8_lossy`]: String::from_utf8_lossy
897    /// [`Cow<'a, str>`]: crate::borrow::Cow "borrow::Cow"
898    /// [U+FFFD]: char::REPLACEMENT_CHARACTER
899    ///
900    /// # Examples
901    ///
902    /// Basic usage:
903    ///
904    /// ```
905    /// // ๐„žmus<invalid>ic<invalid>
906    /// let v = &[0xD8, 0x34, 0xDD, 0x1E, 0x00, 0x6d, 0x00, 0x75,
907    ///           0x00, 0x73, 0xDD, 0x1E, 0x00, 0x69, 0x00, 0x63,
908    ///           0xD8, 0x34];
909    ///
910    /// assert_eq!(String::from("๐„žmus\u{FFFD}ic\u{FFFD}"),
911    ///            String::from_utf16be_lossy(v));
912    /// ```
913    #[cfg(not(no_global_oom_handling))]
914    #[stable(feature = "str_from_utf16_endian", since = "1.98.0")]
915    pub fn from_utf16be_lossy(v: &[u8]) -> String {
916        // SAFETY: The aligned part of `v` can be transmuted into a valid u16 slice.
917        match (cfg!(target_endian = "big"), unsafe { v.align_to::<u16>() }) {
918            (true, ([], v, [])) => Self::from_utf16_lossy(v),
919            (true, ([], v, [_remainder])) => Self::from_utf16_lossy(v) + "\u{FFFD}",
920            _ => {
921                let (chunks, remainder) = v.as_chunks::<2>();
922                let string = char::decode_utf16(chunks.iter().copied().map(u16::from_be_bytes))
923                    .map(|r| r.unwrap_or(char::REPLACEMENT_CHARACTER))
924                    .collect();
925                if remainder.is_empty() { string } else { string + "\u{FFFD}" }
926            }
927        }
928    }
929
930    /// Decomposes a `String` into its raw components: `(pointer, length, capacity)`.
931    ///
932    /// Returns the raw pointer to the underlying data, the length of
933    /// the string (in bytes), and the allocated capacity of the data
934    /// (in bytes). These are the same arguments in the same order as
935    /// the arguments to [`from_raw_parts`].
936    ///
937    /// After calling this function, the caller is responsible for the
938    /// memory previously managed by the `String`. The only way to do
939    /// this is to convert the raw pointer, length, and capacity back
940    /// into a `String` with the [`from_raw_parts`] function, allowing
941    /// the destructor to perform the cleanup.
942    ///
943    /// [`from_raw_parts`]: String::from_raw_parts
944    ///
945    /// # Examples
946    ///
947    /// ```
948    /// let s = String::from("hello");
949    ///
950    /// let (ptr, len, cap) = s.into_raw_parts();
951    ///
952    /// let rebuilt = unsafe { String::from_raw_parts(ptr, len, cap) };
953    /// assert_eq!(rebuilt, "hello");
954    /// ```
955    #[must_use = "losing the pointer will leak memory"]
956    #[stable(feature = "vec_into_raw_parts", since = "1.93.0")]
957    #[inline]
958    pub fn into_raw_parts(self) -> (*mut u8, usize, usize) {
959        self.vec.into_raw_parts()
960    }
961
962    /// Creates a new `String` from a pointer, a length and a capacity.
963    ///
964    /// # Safety
965    ///
966    /// This is highly unsafe, due to the number of invariants that aren't
967    /// checked:
968    ///
969    /// * all safety requirements for [`Vec::<u8>::from_raw_parts`].
970    /// * all safety requirements for [`String::from_utf8_unchecked`].
971    ///
972    /// Violating these may cause problems like corrupting the allocator's
973    /// internal data structures. For example, it is normally **not** safe to
974    /// build a `String` from a pointer to a C `char` array containing UTF-8
975    /// _unless_ you are certain that array was originally allocated by the
976    /// Rust standard library's allocator.
977    ///
978    /// The ownership of `buf` is effectively transferred to the
979    /// `String` which may then deallocate, reallocate or change the
980    /// contents of memory pointed to by the pointer at will. Ensure
981    /// that nothing else uses the pointer after calling this
982    /// function.
983    ///
984    /// # Examples
985    ///
986    /// ```
987    /// unsafe {
988    ///     let s = String::from("hello");
989    ///
990    ///     // Deconstruct the String into parts.
991    ///     let (ptr, len, capacity) = s.into_raw_parts();
992    ///
993    ///     let s = String::from_raw_parts(ptr, len, capacity);
994    ///
995    ///     assert_eq!(String::from("hello"), s);
996    /// }
997    /// ```
998    #[inline]
999    #[stable(feature = "rust1", since = "1.0.0")]
1000    pub unsafe fn from_raw_parts(buf: *mut u8, length: usize, capacity: usize) -> String {
1001        // SAFETY: Upheld by caller.
1002        unsafe { String { vec: Vec::from_raw_parts(buf, length, capacity) } }
1003    }
1004
1005    /// Converts a vector of bytes to a `String` without checking that the
1006    /// string contains valid UTF-8.
1007    ///
1008    /// See the safe version, [`from_utf8`], for more details.
1009    ///
1010    /// [`from_utf8`]: String::from_utf8
1011    ///
1012    /// # Safety
1013    ///
1014    /// This function is unsafe because it does not check that the bytes passed
1015    /// to it are valid UTF-8. If this constraint is violated, it may cause
1016    /// memory unsafety issues with future users of the `String`, as the rest of
1017    /// the standard library assumes that `String`s are valid UTF-8.
1018    ///
1019    /// # Examples
1020    ///
1021    /// ```
1022    /// // some bytes, in a vector
1023    /// let sparkle_heart = vec![240, 159, 146, 150];
1024    ///
1025    /// let sparkle_heart = unsafe {
1026    ///     String::from_utf8_unchecked(sparkle_heart)
1027    /// };
1028    ///
1029    /// assert_eq!("๐Ÿ’–", sparkle_heart);
1030    /// ```
1031    #[inline]
1032    #[must_use]
1033    #[stable(feature = "rust1", since = "1.0.0")]
1034    pub unsafe fn from_utf8_unchecked(bytes: Vec<u8>) -> String {
1035        String { vec: bytes }
1036    }
1037
1038    /// Converts a `String` into a byte vector.
1039    ///
1040    /// This consumes the `String`, so we do not need to copy its contents.
1041    ///
1042    /// # Examples
1043    ///
1044    /// ```
1045    /// let s = String::from("hello");
1046    /// let bytes = s.into_bytes();
1047    ///
1048    /// assert_eq!(&[104, 101, 108, 108, 111][..], &bytes[..]);
1049    /// ```
1050    #[inline]
1051    #[must_use = "`self` will be dropped if the result is not used"]
1052    #[stable(feature = "rust1", since = "1.0.0")]
1053    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1054    #[rustc_allow_const_fn_unstable(const_precise_live_drops)]
1055    pub const fn into_bytes(self) -> Vec<u8> {
1056        self.vec
1057    }
1058
1059    /// Extracts a string slice containing the entire `String`.
1060    ///
1061    /// # Examples
1062    ///
1063    /// ```
1064    /// let s = String::from("foo");
1065    ///
1066    /// assert_eq!("foo", s.as_str());
1067    /// ```
1068    #[inline]
1069    #[must_use]
1070    #[stable(feature = "string_as_str", since = "1.7.0")]
1071    #[rustc_diagnostic_item = "string_as_str"]
1072    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1073    pub const fn as_str(&self) -> &str {
1074        // SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1075        // at construction.
1076        unsafe { str::from_utf8_unchecked(self.vec.as_slice()) }
1077    }
1078
1079    /// Converts a `String` into a mutable string slice.
1080    ///
1081    /// # Examples
1082    ///
1083    /// ```
1084    /// let mut s = String::from("foobar");
1085    /// let s_mut_str = s.as_mut_str();
1086    ///
1087    /// s_mut_str.make_ascii_uppercase();
1088    ///
1089    /// assert_eq!("FOOBAR", s_mut_str);
1090    /// ```
1091    #[inline]
1092    #[must_use]
1093    #[stable(feature = "string_as_str", since = "1.7.0")]
1094    #[rustc_diagnostic_item = "string_as_mut_str"]
1095    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1096    pub const fn as_mut_str(&mut self) -> &mut str {
1097        // SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1098        // at construction.
1099        unsafe { str::from_utf8_unchecked_mut(self.vec.as_mut_slice()) }
1100    }
1101
1102    /// Appends a given string slice onto the end of this `String`.
1103    ///
1104    /// # Panics
1105    ///
1106    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1107    ///
1108    /// # Examples
1109    ///
1110    /// ```
1111    /// let mut s = String::from("foo");
1112    ///
1113    /// s.push_str("bar");
1114    ///
1115    /// assert_eq!("foobar", s);
1116    /// ```
1117    #[cfg(not(no_global_oom_handling))]
1118    #[inline]
1119    #[stable(feature = "rust1", since = "1.0.0")]
1120    #[rustc_confusables("append", "push")]
1121    #[rustc_diagnostic_item = "string_push_str"]
1122    pub fn push_str(&mut self, string: &str) {
1123        self.vec.extend_from_slice(string.as_bytes())
1124    }
1125
1126    /// Appends a given string slice onto the end of this `String`, returning
1127    /// [`TryReserveError`] otherwise.
1128    #[cfg_attr(
1129        not(no_global_oom_handling),
1130        expect(
1131            dead_code,
1132            reason = "currently only used in IO module when global OOM handling is disabled"
1133        )
1134    )]
1135    pub(crate) fn try_push_str(&mut self, string: &str) -> Result<(), TryReserveError> {
1136        self.vec.try_extend_from_slice_of_bytes(string.as_bytes())
1137    }
1138
1139    #[cfg(not(no_global_oom_handling))]
1140    #[inline]
1141    fn push_str_slice(&mut self, slice: &[&str]) {
1142        // use saturating arithmetic to ensure that in the case of an overflow, reserve() throws OOM
1143        let additional: Saturating<usize> = slice.iter().map(|x| Saturating(x.len())).sum();
1144        self.reserve(additional.0);
1145        let (ptr, len, cap) = core::mem::take(self).into_raw_parts();
1146        // SAFETY: `self` have reserved enough space for strs in `slice`, and we are copying from valid UTF-8 slices.
1147        // Therefore all unsafe operations are safe.
1148        unsafe {
1149            let mut dst = ptr.add(len);
1150            for new in slice {
1151                core::ptr::copy_nonoverlapping(new.as_ptr(), dst, new.len());
1152                dst = dst.add(new.len());
1153            }
1154            *self = String::from_raw_parts(ptr, len + additional.0, cap);
1155        }
1156    }
1157
1158    /// Copies elements from `src` range to the end of the string.
1159    ///
1160    /// # Panics
1161    ///
1162    /// Panics if the range has `start_bound > end_bound`, if the range is
1163    /// bounded on either end and does not lie on a [`char`] boundary, or if the
1164    /// new capacity exceeds `isize::MAX` bytes.
1165    ///
1166    /// # Examples
1167    ///
1168    /// ```
1169    /// let mut string = String::from("abcde");
1170    ///
1171    /// string.extend_from_within(2..);
1172    /// assert_eq!(string, "abcdecde");
1173    ///
1174    /// string.extend_from_within(..2);
1175    /// assert_eq!(string, "abcdecdeab");
1176    ///
1177    /// string.extend_from_within(4..8);
1178    /// assert_eq!(string, "abcdecdeabecde");
1179    /// ```
1180    #[cfg(not(no_global_oom_handling))]
1181    #[stable(feature = "string_extend_from_within", since = "1.87.0")]
1182    #[track_caller]
1183    pub fn extend_from_within<R>(&mut self, src: R)
1184    where
1185        R: RangeBounds<usize>,
1186    {
1187        let src @ Range { start, end } = slice::range(src, ..self.len());
1188
1189        assert!(self.is_char_boundary(start));
1190        assert!(self.is_char_boundary(end));
1191
1192        self.vec.extend_from_within(src);
1193    }
1194
1195    /// Returns this `String`'s capacity, in bytes.
1196    ///
1197    /// # Examples
1198    ///
1199    /// ```
1200    /// let s = String::with_capacity(10);
1201    ///
1202    /// assert!(s.capacity() >= 10);
1203    /// ```
1204    #[inline]
1205    #[must_use]
1206    #[stable(feature = "rust1", since = "1.0.0")]
1207    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1208    pub const fn capacity(&self) -> usize {
1209        self.vec.capacity()
1210    }
1211
1212    /// Reserves capacity for at least `additional` bytes more than the
1213    /// current length. The allocator may reserve more space to speculatively
1214    /// avoid frequent allocations. After calling `reserve`,
1215    /// capacity will be greater than or equal to `self.len() + additional`.
1216    /// Does nothing if capacity is already sufficient.
1217    ///
1218    /// # Panics
1219    ///
1220    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1221    ///
1222    /// # Examples
1223    ///
1224    /// Basic usage:
1225    ///
1226    /// ```
1227    /// let mut s = String::new();
1228    ///
1229    /// s.reserve(10);
1230    ///
1231    /// assert!(s.capacity() >= 10);
1232    /// ```
1233    ///
1234    /// This might not actually increase the capacity:
1235    ///
1236    /// ```
1237    /// let mut s = String::with_capacity(10);
1238    /// s.push('a');
1239    /// s.push('b');
1240    ///
1241    /// // s now has a length of 2 and a capacity of at least 10
1242    /// let capacity = s.capacity();
1243    /// assert_eq!(2, s.len());
1244    /// assert!(capacity >= 10);
1245    ///
1246    /// // Since we already have at least an extra 8 capacity, calling this...
1247    /// s.reserve(8);
1248    ///
1249    /// // ... doesn't actually increase.
1250    /// assert_eq!(capacity, s.capacity());
1251    /// ```
1252    #[cfg(not(no_global_oom_handling))]
1253    #[inline]
1254    #[stable(feature = "rust1", since = "1.0.0")]
1255    pub fn reserve(&mut self, additional: usize) {
1256        self.vec.reserve(additional)
1257    }
1258
1259    /// Reserves the minimum capacity for at least `additional` bytes more than
1260    /// the current length. Unlike [`reserve`], this will not
1261    /// deliberately over-allocate to speculatively avoid frequent allocations.
1262    /// After calling `reserve_exact`, capacity will be greater than or equal to
1263    /// `self.len() + additional`. Does nothing if the capacity is already
1264    /// sufficient.
1265    ///
1266    /// [`reserve`]: String::reserve
1267    ///
1268    /// # Panics
1269    ///
1270    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1271    ///
1272    /// # Examples
1273    ///
1274    /// Basic usage:
1275    ///
1276    /// ```
1277    /// let mut s = String::new();
1278    ///
1279    /// s.reserve_exact(10);
1280    ///
1281    /// assert!(s.capacity() >= 10);
1282    /// ```
1283    ///
1284    /// This might not actually increase the capacity:
1285    ///
1286    /// ```
1287    /// let mut s = String::with_capacity(10);
1288    /// s.push('a');
1289    /// s.push('b');
1290    ///
1291    /// // s now has a length of 2 and a capacity of at least 10
1292    /// let capacity = s.capacity();
1293    /// assert_eq!(2, s.len());
1294    /// assert!(capacity >= 10);
1295    ///
1296    /// // Since we already have at least an extra 8 capacity, calling this...
1297    /// s.reserve_exact(8);
1298    ///
1299    /// // ... doesn't actually increase.
1300    /// assert_eq!(capacity, s.capacity());
1301    /// ```
1302    #[cfg(not(no_global_oom_handling))]
1303    #[inline]
1304    #[stable(feature = "rust1", since = "1.0.0")]
1305    pub fn reserve_exact(&mut self, additional: usize) {
1306        self.vec.reserve_exact(additional)
1307    }
1308
1309    /// Tries to reserve capacity for at least `additional` bytes more than the
1310    /// current length. The allocator may reserve more space to speculatively
1311    /// avoid frequent allocations. After calling `try_reserve`, capacity will be
1312    /// greater than or equal to `self.len() + additional` if it returns
1313    /// `Ok(())`. Does nothing if capacity is already sufficient. This method
1314    /// preserves the contents even if an error occurs.
1315    ///
1316    /// # Errors
1317    ///
1318    /// If the capacity overflows, or the allocator reports a failure, then an error
1319    /// is returned.
1320    ///
1321    /// # Examples
1322    ///
1323    /// ```
1324    /// use std::collections::TryReserveError;
1325    ///
1326    /// fn process_data(data: &str) -> Result<String, TryReserveError> {
1327    ///     let mut output = String::new();
1328    ///
1329    ///     // Pre-reserve the memory, exiting if we can't
1330    ///     output.try_reserve(data.len())?;
1331    ///
1332    ///     // Now we know this can't OOM in the middle of our complex work
1333    ///     output.push_str(data);
1334    ///
1335    ///     Ok(output)
1336    /// }
1337    /// # process_data("rust").expect("reserving capacity for 12 bytes should never fail");
1338    /// ```
1339    #[stable(feature = "try_reserve", since = "1.57.0")]
1340    pub fn try_reserve(&mut self, additional: usize) -> Result<(), TryReserveError> {
1341        self.vec.try_reserve(additional)
1342    }
1343
1344    /// Tries to reserve the minimum capacity for at least `additional` bytes
1345    /// more than the current length. Unlike [`try_reserve`], this will not
1346    /// deliberately over-allocate to speculatively avoid frequent allocations.
1347    /// After calling `try_reserve_exact`, capacity will be greater than or
1348    /// equal to `self.len() + additional` if it returns `Ok(())`.
1349    /// Does nothing if the capacity is already sufficient.
1350    ///
1351    /// Note that the allocator may give the collection more space than it
1352    /// requests. Therefore, capacity can not be relied upon to be precisely
1353    /// minimal. Prefer [`try_reserve`] if future insertions are expected.
1354    ///
1355    /// [`try_reserve`]: String::try_reserve
1356    ///
1357    /// # Errors
1358    ///
1359    /// If the capacity overflows, or the allocator reports a failure, then an error
1360    /// is returned.
1361    ///
1362    /// # Examples
1363    ///
1364    /// ```
1365    /// use std::collections::TryReserveError;
1366    ///
1367    /// fn process_data(data: &str) -> Result<String, TryReserveError> {
1368    ///     let mut output = String::new();
1369    ///
1370    ///     // Pre-reserve the memory, exiting if we can't
1371    ///     output.try_reserve_exact(data.len())?;
1372    ///
1373    ///     // Now we know this can't OOM in the middle of our complex work
1374    ///     output.push_str(data);
1375    ///
1376    ///     Ok(output)
1377    /// }
1378    /// # process_data("rust").expect("reserving capacity for 12 bytes should never fail");
1379    /// ```
1380    #[stable(feature = "try_reserve", since = "1.57.0")]
1381    pub fn try_reserve_exact(&mut self, additional: usize) -> Result<(), TryReserveError> {
1382        self.vec.try_reserve_exact(additional)
1383    }
1384
1385    /// Shrinks the capacity of this `String` to match its length.
1386    ///
1387    /// # Examples
1388    ///
1389    /// ```
1390    /// let mut s = String::from("foo");
1391    ///
1392    /// s.reserve(100);
1393    /// assert!(s.capacity() >= 100);
1394    ///
1395    /// s.shrink_to_fit();
1396    /// assert_eq!(3, s.capacity());
1397    /// ```
1398    #[cfg(not(no_global_oom_handling))]
1399    #[inline]
1400    #[stable(feature = "rust1", since = "1.0.0")]
1401    pub fn shrink_to_fit(&mut self) {
1402        self.vec.shrink_to_fit()
1403    }
1404
1405    /// Shrinks the capacity of this `String` with a lower bound.
1406    ///
1407    /// The capacity will remain at least as large as both the length
1408    /// and the supplied value.
1409    ///
1410    /// If the current capacity is less than the lower limit, this is a no-op.
1411    ///
1412    /// # Examples
1413    ///
1414    /// ```
1415    /// let mut s = String::from("foo");
1416    ///
1417    /// s.reserve(100);
1418    /// assert!(s.capacity() >= 100);
1419    ///
1420    /// s.shrink_to(10);
1421    /// assert!(s.capacity() >= 10);
1422    /// s.shrink_to(0);
1423    /// assert!(s.capacity() >= 3);
1424    /// ```
1425    #[cfg(not(no_global_oom_handling))]
1426    #[inline]
1427    #[stable(feature = "shrink_to", since = "1.56.0")]
1428    pub fn shrink_to(&mut self, min_capacity: usize) {
1429        self.vec.shrink_to(min_capacity)
1430    }
1431
1432    /// Appends the given [`char`] to the end of this `String`.
1433    ///
1434    /// # Panics
1435    ///
1436    /// Panics if the new capacity exceeds `isize::MAX` _bytes_.
1437    ///
1438    /// # Examples
1439    ///
1440    /// ```
1441    /// let mut s = String::from("abc");
1442    ///
1443    /// s.push('1');
1444    /// s.push('2');
1445    /// s.push('3');
1446    ///
1447    /// assert_eq!("abc123", s);
1448    /// ```
1449    #[cfg(not(no_global_oom_handling))]
1450    #[inline]
1451    #[stable(feature = "rust1", since = "1.0.0")]
1452    pub fn push(&mut self, ch: char) {
1453        let len = self.len();
1454        let ch_len = ch.len_utf8();
1455        self.reserve(ch_len);
1456
1457        // SAFETY: Just reserved capacity for at least the length needed to encode `ch`.
1458        unsafe {
1459            core::char::encode_utf8_raw_unchecked(ch as u32, self.vec.as_mut_ptr().add(len));
1460            self.vec.set_len(len + ch_len);
1461        }
1462    }
1463
1464    /// Returns a byte slice of this `String`'s contents.
1465    ///
1466    /// The inverse of this method is [`from_utf8`].
1467    ///
1468    /// [`from_utf8`]: String::from_utf8
1469    ///
1470    /// # Examples
1471    ///
1472    /// ```
1473    /// let s = String::from("hello");
1474    ///
1475    /// assert_eq!(&[104, 101, 108, 108, 111], s.as_bytes());
1476    /// ```
1477    #[inline]
1478    #[must_use]
1479    #[stable(feature = "rust1", since = "1.0.0")]
1480    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1481    pub const fn as_bytes(&self) -> &[u8] {
1482        self.vec.as_slice()
1483    }
1484
1485    /// Shortens this `String` to the specified length.
1486    ///
1487    /// If `new_len` is greater than or equal to the string's current length, this has no
1488    /// effect.
1489    ///
1490    /// Note that this method has no effect on the allocated capacity
1491    /// of the string
1492    ///
1493    /// # Panics
1494    ///
1495    /// Panics if `new_len` does not lie on a [`char`] boundary.
1496    ///
1497    /// # Examples
1498    ///
1499    /// ```
1500    /// let mut s = String::from("hello");
1501    ///
1502    /// s.truncate(2);
1503    ///
1504    /// assert_eq!("he", s);
1505    /// ```
1506    #[inline]
1507    #[stable(feature = "rust1", since = "1.0.0")]
1508    #[track_caller]
1509    pub fn truncate(&mut self, new_len: usize) {
1510        if new_len <= self.len() {
1511            assert!(self.is_char_boundary(new_len));
1512            self.vec.truncate(new_len)
1513        }
1514    }
1515
1516    /// Removes the last character from the string buffer and returns it.
1517    ///
1518    /// Returns [`None`] if this `String` is empty.
1519    ///
1520    /// # Examples
1521    ///
1522    /// ```
1523    /// let mut s = String::from("abฤ");
1524    ///
1525    /// assert_eq!(s.pop(), Some('ฤ'));
1526    /// assert_eq!(s.pop(), Some('b'));
1527    /// assert_eq!(s.pop(), Some('a'));
1528    ///
1529    /// assert_eq!(s.pop(), None);
1530    /// ```
1531    #[inline]
1532    #[stable(feature = "rust1", since = "1.0.0")]
1533    pub fn pop(&mut self) -> Option<char> {
1534        let ch = self.chars().rev().next()?;
1535        let newlen = self.len() - ch.len_utf8();
1536        // SAFETY: `newlen` is less than old length.
1537        unsafe {
1538            self.vec.set_len(newlen);
1539        }
1540        Some(ch)
1541    }
1542
1543    /// Removes a [`char`] from this `String` at byte position `idx` and returns it.
1544    ///
1545    /// Copies all bytes after the removed char to new positions.
1546    ///
1547    /// Note that calling this in a loop can result in quadratic behavior.
1548    ///
1549    /// # Panics
1550    ///
1551    /// Panics if `idx` is larger than or equal to the `String`'s length,
1552    /// or if it does not lie on a [`char`] boundary.
1553    ///
1554    /// # Examples
1555    ///
1556    /// ```
1557    /// let mut s = String::from("abรง");
1558    ///
1559    /// assert_eq!(s.remove(0), 'a');
1560    /// assert_eq!(s.remove(1), 'รง');
1561    /// assert_eq!(s.remove(0), 'b');
1562    /// ```
1563    #[inline]
1564    #[stable(feature = "rust1", since = "1.0.0")]
1565    #[track_caller]
1566    #[rustc_confusables("delete", "take")]
1567    pub fn remove(&mut self, idx: usize) -> char {
1568        let ch = match self[idx..].chars().next() {
1569            Some(ch) => ch,
1570            None => panic!("cannot remove a char from the end of a string"),
1571        };
1572
1573        let next = idx + ch.len_utf8();
1574        let len = self.len();
1575        // SAFETY:
1576        // * Since `next` is not bigger than `len`, `self.vec.as_ptr().add(next)`
1577        //   is valid for reads and `self.vec.as_mut_ptr().add(idx)` is valid for writes.
1578        //   Both pointers are valid for `len - next` bytes.
1579        // * new length is less than old length.
1580        unsafe {
1581            ptr::copy(self.vec.as_ptr().add(next), self.vec.as_mut_ptr().add(idx), len - next);
1582            self.vec.set_len(len - (next - idx));
1583        }
1584        ch
1585    }
1586
1587    /// Remove all matches of pattern `pat` in the `String`.
1588    ///
1589    /// # Examples
1590    ///
1591    /// ```
1592    /// #![feature(string_remove_matches)]
1593    /// let mut s = String::from("Trees are not green, the sky is not blue.");
1594    /// s.remove_matches("not ");
1595    /// assert_eq!("Trees are green, the sky is blue.", s);
1596    /// ```
1597    ///
1598    /// Matches will be detected and removed iteratively, so in cases where
1599    /// patterns overlap, only the first pattern will be removed:
1600    ///
1601    /// ```
1602    /// #![feature(string_remove_matches)]
1603    /// let mut s = String::from("banana");
1604    /// s.remove_matches("ana");
1605    /// assert_eq!("bna", s);
1606    /// ```
1607    #[cfg(not(no_global_oom_handling))]
1608    #[unstable(feature = "string_remove_matches", issue = "72826")]
1609    pub fn remove_matches<P: Pattern>(&mut self, pat: P) {
1610        use core::str::pattern::Searcher;
1611
1612        let rejections = {
1613            let mut searcher = pat.into_searcher(self);
1614            // Per Searcher::next:
1615            //
1616            // A Match result needs to contain the whole matched pattern,
1617            // however Reject results may be split up into arbitrary many
1618            // adjacent fragments. Both ranges may have zero length.
1619            //
1620            // In practice the implementation of Searcher::next_match tends to
1621            // be more efficient, so we use it here and do some work to invert
1622            // matches into rejections since that's what we want to copy below.
1623            let mut front = 0;
1624            let rejections: Vec<_> = from_fn(|| {
1625                let (start, end) = searcher.next_match()?;
1626                let prev_front = front;
1627                front = end;
1628                Some((prev_front, start))
1629            })
1630            .collect();
1631            rejections.into_iter().chain(core::iter::once((front, self.len())))
1632        };
1633
1634        let mut len = 0;
1635        let ptr = self.vec.as_mut_ptr();
1636
1637        for (start, end) in rejections {
1638            let count = end - start;
1639            if start != len {
1640                // SAFETY: per Searcher::next:
1641                //
1642                // The stream of Match and Reject values up to a Done will
1643                // contain index ranges that are adjacent, non-overlapping,
1644                // covering the whole haystack, and laying on utf8
1645                // boundaries.
1646                unsafe {
1647                    ptr::copy(ptr.add(start), ptr.add(len), count);
1648                }
1649            }
1650            len += count;
1651        }
1652
1653        // SAFETY: `len` is less than or equal to the original length of the string.
1654        unsafe {
1655            self.vec.set_len(len);
1656        }
1657    }
1658
1659    /// Retains only the characters specified by the predicate.
1660    ///
1661    /// In other words, remove all characters `c` such that `f(c)` returns `false`.
1662    /// This method operates in place, visiting each character exactly once in the
1663    /// original order, and preserves the order of the retained characters.
1664    ///
1665    /// # Examples
1666    ///
1667    /// ```
1668    /// let mut s = String::from("f_o_ob_ar");
1669    ///
1670    /// s.retain(|c| c != '_');
1671    ///
1672    /// assert_eq!(s, "foobar");
1673    /// ```
1674    ///
1675    /// Because the elements are visited exactly once in the original order,
1676    /// external state may be used to decide which elements to keep.
1677    ///
1678    /// ```
1679    /// let mut s = String::from("abcde");
1680    /// let keep = [false, true, true, false, true];
1681    /// let mut iter = keep.iter();
1682    /// s.retain(|_| *iter.next().unwrap());
1683    /// assert_eq!(s, "bce");
1684    /// ```
1685    #[inline]
1686    #[stable(feature = "string_retain", since = "1.26.0")]
1687    pub fn retain<F>(&mut self, mut f: F)
1688    where
1689        F: FnMut(char) -> bool,
1690    {
1691        let len = self.len();
1692        if len == 0 {
1693            // Explicit check results in better optimization
1694            return;
1695        }
1696
1697        struct PanicGuard<'a> {
1698            s: &'a mut String,
1699            write: usize,
1700        }
1701
1702        impl Drop for PanicGuard<'_> {
1703            fn drop(&mut self) {
1704                debug_assert!(self.write <= self.s.len());
1705                debug_assert!(str::from_utf8(&self.s.vec[..self.write]).is_ok());
1706                // SAFETY: Restore the string length to the number of bytes written so far.
1707                unsafe { self.s.vec.set_len(self.write) }
1708            }
1709        }
1710
1711        // Fast path: find the first character that should be removed or return early.
1712        let mut chars = self.char_indices();
1713        let (mut read, write) = loop {
1714            let Some((idx, ch)) = chars.next() else { return };
1715            if hint::unlikely(!f(ch)) {
1716                break (idx + ch.len_utf8(), idx);
1717            }
1718        };
1719        drop(chars);
1720
1721        // Slow path: at least one character is going to be removed.
1722        let mut g = PanicGuard { s: self, write };
1723        while read < len {
1724            // SAFETY: `read` is within bound because `read` < `len`, so taking
1725            // a slice with `len` is safe.
1726            let ch = unsafe { g.s.get_unchecked(read..len).chars().next().unwrap_unchecked() };
1727            let ch_len = ch.len_utf8();
1728            if f(ch) {
1729                // SAFETY: `read` is on a char boundary, as guaranteed above; `g.write` is
1730                // within bounds because it is always behind `read`.
1731                unsafe {
1732                    let ptr = g.s.vec.as_mut_ptr();
1733                    ptr::copy(ptr.add(read), ptr.add(g.write), ch_len);
1734                }
1735                g.write += ch_len;
1736            }
1737            read += ch_len;
1738        }
1739
1740        // All bytes processed; commit the final length by dropping the guard.
1741        drop(g);
1742    }
1743
1744    /// Inserts a character into this `String` at byte position `idx`.
1745    ///
1746    /// Reallocates if `self.capacity()` is insufficient, which may involve copying all
1747    /// `self.capacity()` bytes. Makes space for the insertion by copying all bytes of
1748    /// `&self[idx..]` to new positions.
1749    ///
1750    /// Note that calling this in a loop can result in quadratic behavior.
1751    ///
1752    /// # Panics
1753    ///
1754    /// Panics if `idx` is larger than the `String`'s length, or if it does not
1755    /// lie on a [`char`] boundary.
1756    ///
1757    /// # Examples
1758    ///
1759    /// ```
1760    /// let mut s = String::with_capacity(3);
1761    ///
1762    /// s.insert(0, 'f');
1763    /// s.insert(1, 'o');
1764    /// s.insert(2, 'o');
1765    ///
1766    /// assert_eq!("foo", s);
1767    /// ```
1768    #[cfg(not(no_global_oom_handling))]
1769    #[inline]
1770    #[track_caller]
1771    #[stable(feature = "rust1", since = "1.0.0")]
1772    #[rustc_confusables("set")]
1773    pub fn insert(&mut self, idx: usize, ch: char) {
1774        assert!(self.is_char_boundary(idx));
1775
1776        let len = self.len();
1777        let ch_len = ch.len_utf8();
1778        self.reserve(ch_len);
1779
1780        // SAFETY: Move the bytes starting from `idx` to their new location `ch_len`
1781        // bytes ahead. This is safe because sufficient capacity was reserved, and `idx`
1782        // is a char boundary.
1783        unsafe {
1784            ptr::copy(
1785                self.vec.as_ptr().add(idx),
1786                self.vec.as_mut_ptr().add(idx + ch_len),
1787                len - idx,
1788            );
1789        }
1790
1791        // SAFETY: Encode the character into the vacated region if `idx != len`,
1792        // or into the uninitialized spare capacity otherwise.
1793        unsafe {
1794            core::char::encode_utf8_raw_unchecked(ch as u32, self.vec.as_mut_ptr().add(idx));
1795        }
1796
1797        // SAFETY: Update the length to include the newly added bytes.
1798        unsafe {
1799            self.vec.set_len(len + ch_len);
1800        }
1801    }
1802
1803    /// Inserts a string slice into this `String` at byte position `idx`.
1804    ///
1805    /// Reallocates if `self.capacity()` is insufficient, which may involve copying all
1806    /// `self.capacity()` bytes. Makes space for the insertion by copying all bytes of
1807    /// `&self[idx..]` to new positions.
1808    ///
1809    /// Note that calling this in a loop can result in quadratic behavior.
1810    ///
1811    /// # Panics
1812    ///
1813    /// Panics if `idx` is larger than the `String`'s length, or if it does not
1814    /// lie on a [`char`] boundary.
1815    ///
1816    /// # Examples
1817    ///
1818    /// ```
1819    /// let mut s = String::from("bar");
1820    ///
1821    /// s.insert_str(0, "foo");
1822    ///
1823    /// assert_eq!("foobar", s);
1824    /// ```
1825    #[cfg(not(no_global_oom_handling))]
1826    #[inline]
1827    #[track_caller]
1828    #[stable(feature = "insert_str", since = "1.16.0")]
1829    #[rustc_diagnostic_item = "string_insert_str"]
1830    pub fn insert_str(&mut self, idx: usize, string: &str) {
1831        assert!(self.is_char_boundary(idx));
1832
1833        let len = self.len();
1834        let amt = string.len();
1835        self.reserve(amt);
1836
1837        // SAFETY: Move the bytes starting from `idx` to their new location `amt` bytes
1838        // ahead. This is safe because sufficient capacity was just reserved, and `idx`
1839        // is a char boundary.
1840        unsafe {
1841            ptr::copy(self.vec.as_ptr().add(idx), self.vec.as_mut_ptr().add(idx + amt), len - idx);
1842        }
1843
1844        // SAFETY: Copy the new string slice into the vacated region if `idx != len`,
1845        // or into the uninitialized spare capacity otherwise. The borrow checker
1846        // ensures that the source and destination do not overlap.
1847        unsafe {
1848            ptr::copy_nonoverlapping(string.as_ptr(), self.vec.as_mut_ptr().add(idx), amt);
1849        }
1850
1851        // SAFETY: Update the length to include the newly added bytes.
1852        unsafe {
1853            self.vec.set_len(len + amt);
1854        }
1855    }
1856
1857    /// Returns a mutable reference to the contents of this `String`.
1858    ///
1859    /// # Safety
1860    ///
1861    /// This function is unsafe because the returned `&mut Vec` allows writing
1862    /// bytes which are not valid UTF-8. If this constraint is violated, using
1863    /// the original `String` after dropping the `&mut Vec` may violate memory
1864    /// safety, as the rest of the standard library assumes that `String`s are
1865    /// valid UTF-8.
1866    ///
1867    /// # Examples
1868    ///
1869    /// ```
1870    /// let mut s = String::from("hello");
1871    ///
1872    /// unsafe {
1873    ///     let vec = s.as_mut_vec();
1874    ///     assert_eq!(&[104, 101, 108, 108, 111][..], &vec[..]);
1875    ///
1876    ///     vec.reverse();
1877    /// }
1878    /// assert_eq!(s, "olleh");
1879    /// ```
1880    #[inline]
1881    #[stable(feature = "rust1", since = "1.0.0")]
1882    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1883    pub const unsafe fn as_mut_vec(&mut self) -> &mut Vec<u8> {
1884        &mut self.vec
1885    }
1886
1887    /// Returns the length of this `String`, in bytes, not [`char`]s or
1888    /// graphemes. In other words, it might not be what a human considers the
1889    /// length of the string.
1890    ///
1891    /// # Examples
1892    ///
1893    /// ```
1894    /// let a = String::from("foo");
1895    /// assert_eq!(a.len(), 3);
1896    ///
1897    /// let fancy_f = String::from("ฦ’oo");
1898    /// assert_eq!(fancy_f.len(), 4);
1899    /// assert_eq!(fancy_f.chars().count(), 3);
1900    /// ```
1901    #[inline]
1902    #[must_use]
1903    #[stable(feature = "rust1", since = "1.0.0")]
1904    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1905    #[rustc_confusables("length", "size")]
1906    #[rustc_no_implicit_autorefs]
1907    pub const fn len(&self) -> usize {
1908        self.vec.len()
1909    }
1910
1911    /// Returns `true` if this `String` has a length of zero, and `false` otherwise.
1912    ///
1913    /// # Examples
1914    ///
1915    /// ```
1916    /// let mut v = String::new();
1917    /// assert!(v.is_empty());
1918    ///
1919    /// v.push('a');
1920    /// assert!(!v.is_empty());
1921    /// ```
1922    #[inline]
1923    #[must_use]
1924    #[stable(feature = "rust1", since = "1.0.0")]
1925    #[rustc_const_stable(feature = "const_vec_string_slice", since = "1.87.0")]
1926    #[rustc_no_implicit_autorefs]
1927    pub const fn is_empty(&self) -> bool {
1928        self.len() == 0
1929    }
1930
1931    /// Splits the string into two at the given byte index.
1932    ///
1933    /// Returns a newly allocated `String`. `self` contains bytes `[0, at)`, and
1934    /// the returned `String` contains bytes `[at, len)`. `at` must be on the
1935    /// boundary of a UTF-8 code point.
1936    ///
1937    /// Note that the capacity of `self` does not change.
1938    ///
1939    /// # Panics
1940    ///
1941    /// Panics if `at` is not on a `UTF-8` code point boundary, or if it is beyond the last
1942    /// code point of the string.
1943    ///
1944    /// # Examples
1945    ///
1946    /// ```
1947    /// # fn main() {
1948    /// let mut hello = String::from("Hello, World!");
1949    /// let world = hello.split_off(7);
1950    /// assert_eq!(hello, "Hello, ");
1951    /// assert_eq!(world, "World!");
1952    /// # }
1953    /// ```
1954    #[cfg(not(no_global_oom_handling))]
1955    #[inline]
1956    #[track_caller]
1957    #[stable(feature = "string_split_off", since = "1.16.0")]
1958    #[must_use = "use `.truncate()` if you don't need the other half"]
1959    pub fn split_off(&mut self, at: usize) -> String {
1960        assert!(self.is_char_boundary(at));
1961        let other = self.vec.split_off(at);
1962        // SAFETY: `other` contains only valid UTF-8 because `at` is on a `UTF-8` code point boundary.
1963        unsafe { String::from_utf8_unchecked(other) }
1964    }
1965
1966    /// Truncates this `String`, removing all contents.
1967    ///
1968    /// While this means the `String` will have a length of zero, it does not
1969    /// touch its capacity.
1970    ///
1971    /// # Examples
1972    ///
1973    /// ```
1974    /// let mut s = String::from("foo");
1975    ///
1976    /// s.clear();
1977    ///
1978    /// assert!(s.is_empty());
1979    /// assert_eq!(0, s.len());
1980    /// assert_eq!(3, s.capacity());
1981    /// ```
1982    #[inline]
1983    #[stable(feature = "rust1", since = "1.0.0")]
1984    pub fn clear(&mut self) {
1985        self.vec.clear()
1986    }
1987
1988    /// Removes the specified range from the string in bulk, returning all
1989    /// removed characters as an iterator.
1990    ///
1991    /// The returned iterator keeps a mutable borrow on the string to optimize
1992    /// its implementation.
1993    ///
1994    /// # Panics
1995    ///
1996    /// Panics if the range has `start_bound > end_bound`, or, if the range is
1997    /// bounded on either end and does not lie on a [`char`] boundary.
1998    ///
1999    /// # Leaking
2000    ///
2001    /// If the returned iterator goes out of scope without being dropped (due to
2002    /// [`core::mem::forget`], for example), the string may still contain a copy
2003    /// of any drained characters, or may have lost characters arbitrarily,
2004    /// including characters outside the range.
2005    ///
2006    /// # Examples
2007    ///
2008    /// ```
2009    /// let mut s = String::from("ฮฑ is alpha, ฮฒ is beta");
2010    /// let beta_offset = s.find('ฮฒ').unwrap_or(s.len());
2011    ///
2012    /// // Remove the range up until the ฮฒ from the string
2013    /// let t: String = s.drain(..beta_offset).collect();
2014    /// assert_eq!(t, "ฮฑ is alpha, ");
2015    /// assert_eq!(s, "ฮฒ is beta");
2016    ///
2017    /// // A full range clears the string, like `clear()` does
2018    /// s.drain(..);
2019    /// assert_eq!(s, "");
2020    /// ```
2021    #[stable(feature = "drain", since = "1.6.0")]
2022    #[track_caller]
2023    pub fn drain<R>(&mut self, range: R) -> Drain<'_>
2024    where
2025        R: RangeBounds<usize>,
2026    {
2027        // Memory safety
2028        //
2029        // The String version of Drain does not have the memory safety issues
2030        // of the vector version. The data is just plain bytes.
2031        // Because the range removal happens in Drop, if the Drain iterator is leaked,
2032        // the removal will not happen.
2033        let Range { start, end } = slice::range(range, ..self.len());
2034        assert!(self.is_char_boundary(start));
2035        assert!(self.is_char_boundary(end));
2036
2037        // Take out two simultaneous borrows. The &mut String won't be accessed
2038        // until iteration is over, in Drop.
2039        let self_ptr = self as *mut _;
2040        // SAFETY: `slice::range` and `is_char_boundary` do the appropriate bounds checks.
2041        let chars_iter = unsafe { self.get_unchecked(start..end) }.chars();
2042
2043        Drain { start, end, iter: chars_iter, string: self_ptr }
2044    }
2045
2046    /// Converts a `String` into an iterator over the [`char`]s of the string.
2047    ///
2048    /// As a string consists of valid UTF-8, we can iterate through a string
2049    /// by [`char`]. This method returns such an iterator.
2050    ///
2051    /// It's important to remember that [`char`] represents a Unicode Scalar
2052    /// Value, and might not match your idea of what a 'character' is. Iteration
2053    /// over grapheme clusters may be what you actually want. That functionality
2054    /// is not provided by Rust's standard library, check crates.io instead.
2055    ///
2056    /// # Examples
2057    ///
2058    /// Basic usage:
2059    ///
2060    /// ```
2061    /// #![feature(string_into_chars)]
2062    ///
2063    /// let word = String::from("goodbye");
2064    ///
2065    /// let mut chars = word.into_chars();
2066    ///
2067    /// assert_eq!(Some('g'), chars.next());
2068    /// assert_eq!(Some('o'), chars.next());
2069    /// assert_eq!(Some('o'), chars.next());
2070    /// assert_eq!(Some('d'), chars.next());
2071    /// assert_eq!(Some('b'), chars.next());
2072    /// assert_eq!(Some('y'), chars.next());
2073    /// assert_eq!(Some('e'), chars.next());
2074    ///
2075    /// assert_eq!(None, chars.next());
2076    /// ```
2077    ///
2078    /// Remember, [`char`]s might not match your intuition about characters:
2079    ///
2080    /// ```
2081    /// #![feature(string_into_chars)]
2082    ///
2083    /// let y = String::from("yฬ†");
2084    ///
2085    /// let mut chars = y.into_chars();
2086    ///
2087    /// assert_eq!(Some('y'), chars.next()); // not 'yฬ†'
2088    /// assert_eq!(Some('\u{0306}'), chars.next());
2089    ///
2090    /// assert_eq!(None, chars.next());
2091    /// ```
2092    ///
2093    /// [`char`]: prim@char
2094    #[inline]
2095    #[must_use = "`self` will be dropped if the result is not used"]
2096    #[unstable(feature = "string_into_chars", issue = "133125")]
2097    pub fn into_chars(self) -> IntoChars {
2098        IntoChars { bytes: self.into_bytes().into_iter() }
2099    }
2100
2101    /// Removes the specified range in the string,
2102    /// and replaces it with the given string.
2103    /// The given string doesn't need to be the same length as the range.
2104    ///
2105    /// # Panics
2106    ///
2107    /// Panics if the range has `start_bound > end_bound`, or, if the range is
2108    /// bounded on either end and does not lie on a [`char`] boundary.
2109    ///
2110    /// # Examples
2111    ///
2112    /// ```
2113    /// let mut s = String::from("ฮฑ is alpha, ฮฒ is beta");
2114    /// let beta_offset = s.find('ฮฒ').unwrap_or(s.len());
2115    ///
2116    /// // Replace the range up until the ฮฒ from the string
2117    /// s.replace_range(..beta_offset, "ฮ‘ is capital alpha; ");
2118    /// assert_eq!(s, "ฮ‘ is capital alpha; ฮฒ is beta");
2119    /// ```
2120    #[cfg(not(no_global_oom_handling))]
2121    #[stable(feature = "splice", since = "1.27.0")]
2122    #[track_caller]
2123    pub fn replace_range<R>(&mut self, range: R, replace_with: &str)
2124    where
2125        R: RangeBounds<usize>,
2126    {
2127        // We avoid #81138 (nondeterministic RangeBounds impls) because we only use `range` once, here.
2128        let checked_range = slice::range(range, ..self.len());
2129
2130        assert!(
2131            self.is_char_boundary(checked_range.start),
2132            "start of range should be a character boundary"
2133        );
2134        assert!(
2135            self.is_char_boundary(checked_range.end),
2136            "end of range should be a character boundary"
2137        );
2138
2139        if replace_with.len() > checked_range.len() {
2140            self.reserve(replace_with.len() - checked_range.len());
2141        }
2142        // SAFETY: We ensure that we're not replacing across a char boundary and
2143        // that the new contents are valid UTF-8. The only potentially-unsound
2144        // unwind from `splice` that would leave the string in an invalid state
2145        // would be from an error growing the allocation, which we protect against
2146        // by reserving it preemptively.
2147        unsafe { self.as_mut_vec() }.splice(checked_range, replace_with.bytes());
2148    }
2149
2150    /// Replaces the leftmost occurrence of a pattern with another string, in-place.
2151    ///
2152    /// This method can be preferred over [`string = string.replacen(..., 1);`][replacen],
2153    /// as it can use the `String`'s existing capacity to prevent a reallocation if
2154    /// sufficient space is available.
2155    ///
2156    /// # Examples
2157    ///
2158    /// Basic usage:
2159    ///
2160    /// ```
2161    /// #![feature(string_replace_in_place)]
2162    ///
2163    /// let mut s = String::from("Test Results: โŒโŒโŒ");
2164    ///
2165    /// // Replace the leftmost โŒ with a โœ…
2166    /// s.replace_first('โŒ', "โœ…");
2167    /// assert_eq!(s, "Test Results: โœ…โŒโŒ");
2168    /// ```
2169    ///
2170    /// [replacen]: ../../std/primitive.str.html#method.replacen
2171    #[cfg(not(no_global_oom_handling))]
2172    #[unstable(feature = "string_replace_in_place", issue = "147949")]
2173    pub fn replace_first<P: Pattern>(&mut self, from: P, to: &str) {
2174        let range = match self.match_indices(from).next() {
2175            Some((start, match_str)) => start..start + match_str.len(),
2176            None => return,
2177        };
2178
2179        self.replace_range(range, to);
2180    }
2181
2182    /// Replaces the rightmost occurrence of a pattern with another string, in-place.
2183    ///
2184    /// # Examples
2185    ///
2186    /// Basic usage:
2187    ///
2188    /// ```
2189    /// #![feature(string_replace_in_place)]
2190    ///
2191    /// let mut s = String::from("Test Results: โŒโŒโŒ");
2192    ///
2193    /// // Replace the rightmost โŒ with a โœ…
2194    /// s.replace_last('โŒ', "โœ…");
2195    /// assert_eq!(s, "Test Results: โŒโŒโœ…");
2196    /// ```
2197    #[cfg(not(no_global_oom_handling))]
2198    #[unstable(feature = "string_replace_in_place", issue = "147949")]
2199    pub fn replace_last<P: Pattern>(&mut self, from: P, to: &str)
2200    where
2201        for<'a> P::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2202    {
2203        let range = match self.rmatch_indices(from).next() {
2204            Some((start, match_str)) => start..start + match_str.len(),
2205            None => return,
2206        };
2207
2208        self.replace_range(range, to);
2209    }
2210
2211    /// Converts this `String` into a <code>[Box]<[str]></code>.
2212    ///
2213    /// Before doing the conversion, this method discards excess capacity like [`shrink_to_fit`].
2214    /// Note that this call may reallocate and copy the bytes of the string.
2215    ///
2216    /// [`shrink_to_fit`]: String::shrink_to_fit
2217    /// [str]: prim@str "str"
2218    ///
2219    /// # Examples
2220    ///
2221    /// ```
2222    /// let s = String::from("hello");
2223    ///
2224    /// let b = s.into_boxed_str();
2225    /// ```
2226    #[cfg(not(no_global_oom_handling))]
2227    #[stable(feature = "box_str", since = "1.4.0")]
2228    #[must_use = "`self` will be dropped if the result is not used"]
2229    #[inline]
2230    pub fn into_boxed_str(self) -> Box<str> {
2231        let slice = self.vec.into_boxed_slice();
2232        // SAFETY: `slice` contains only valid UTF-8 because `String` is guaranteed to be valid UTF-8.
2233        unsafe { from_boxed_utf8_unchecked(slice) }
2234    }
2235
2236    /// Consumes and leaks the `String`, returning a mutable reference to the contents,
2237    /// `&'a mut str`.
2238    ///
2239    /// The caller has free choice over the returned lifetime, including `'static`. Indeed,
2240    /// this function is ideally used for data that lives for the remainder of the program's life,
2241    /// as dropping the returned reference will cause a memory leak.
2242    ///
2243    /// It does not reallocate or shrink the `String`, so the leaked allocation may include unused
2244    /// capacity that is not part of the returned slice. If you want to discard excess capacity,
2245    /// call [`into_boxed_str`], and then [`Box::leak`] instead. However, keep in mind that
2246    /// trimming the capacity may result in a reallocation and copy.
2247    ///
2248    /// [`into_boxed_str`]: Self::into_boxed_str
2249    ///
2250    /// # Examples
2251    ///
2252    /// ```
2253    /// let x = String::from("bucket");
2254    /// let static_ref: &'static mut str = x.leak();
2255    /// assert_eq!(static_ref, "bucket");
2256    /// # // FIXME(https://github.com/rust-lang/miri/issues/3670):
2257    /// # // use -Zmiri-disable-leak-check instead of unleaking in tests meant to leak.
2258    /// # drop(unsafe { Box::from_raw(static_ref) });
2259    /// ```
2260    #[stable(feature = "string_leak", since = "1.72.0")]
2261    #[inline]
2262    pub fn leak<'a>(self) -> &'a mut str {
2263        let slice = self.vec.leak();
2264        // SAFETY: `slice` contains only valid UTF-8 because `String` is guaranteed to be valid UTF-8.
2265        unsafe { from_utf8_unchecked_mut(slice) }
2266    }
2267}
2268
2269impl FromUtf8Error {
2270    /// Returns a slice of [`u8`]s bytes that were attempted to convert to a `String`.
2271    ///
2272    /// # Examples
2273    ///
2274    /// ```
2275    /// // some invalid bytes, in a vector
2276    /// let bytes = vec![0, 159];
2277    ///
2278    /// let value = String::from_utf8(bytes);
2279    ///
2280    /// assert_eq!(&[0, 159], value.unwrap_err().as_bytes());
2281    /// ```
2282    #[must_use]
2283    #[stable(feature = "from_utf8_error_as_bytes", since = "1.26.0")]
2284    pub fn as_bytes(&self) -> &[u8] {
2285        &self.bytes[..]
2286    }
2287
2288    /// Converts the bytes into a `String` lossily, substituting invalid UTF-8
2289    /// sequences with replacement characters.
2290    ///
2291    /// See [`String::from_utf8_lossy`] for more details on replacement of
2292    /// invalid sequences, and [`String::from_utf8_lossy_owned`] for the
2293    /// `String` function which corresponds to this function.
2294    ///
2295    /// This is useful in conjunction with [`String::from_utf8`] when you need
2296    /// to branch on whether the bytes are valid UTF-8, but still want to
2297    /// recover a lossily converted `String` in the error case. Use
2298    /// [`String::from_utf8_lossy_owned`] if you always need a lossily converted
2299    /// `String`.
2300    ///
2301    /// Since the original [`String::from_utf8`] error records where validation
2302    /// stopped, this method does not need to re-check the already valid prefix
2303    /// of the byte sequence.
2304    ///
2305    /// # Examples
2306    ///
2307    /// ```
2308    /// // some invalid bytes
2309    /// let input: Vec<u8> = b"Hello \xF0\x90\x80World".into();
2310    ///
2311    /// let (output, had_invalid_utf8) = match String::from_utf8(input) {
2312    ///     Ok(output) => (output, false),
2313    ///     Err(error) => {
2314    ///         // The bytes were not valid UTF-8, but we can still recover a string.
2315    ///         (error.into_utf8_lossy(), true)
2316    ///     }
2317    /// };
2318    ///
2319    /// assert_eq!(String::from("Hello ๏ฟฝWorld"), output);
2320    /// assert!(had_invalid_utf8);
2321    /// ```
2322    #[must_use]
2323    #[cfg(not(no_global_oom_handling))]
2324    #[stable(feature = "string_from_utf8_lossy_owned", since = "1.99.0")]
2325    pub fn into_utf8_lossy(self) -> String {
2326        const REPLACEMENT: &str = "\u{FFFD}";
2327
2328        let mut res = {
2329            let mut v = Vec::with_capacity(self.bytes.len());
2330
2331            // `Utf8Error::valid_up_to` returns the maximum index of validated
2332            // UTF-8 bytes. Copy the valid bytes into the output buffer.
2333            v.extend_from_slice(&self.bytes[..self.error.valid_up_to()]);
2334
2335            // SAFETY: This is safe because the only bytes present in the buffer
2336            // were validated as UTF-8 by the call to `String::from_utf8` which
2337            // produced this `FromUtf8Error`.
2338            unsafe { String::from_utf8_unchecked(v) }
2339        };
2340
2341        let iter = self.bytes[self.error.valid_up_to()..].utf8_chunks();
2342
2343        for chunk in iter {
2344            res.push_str(chunk.valid());
2345            if !chunk.invalid().is_empty() {
2346                res.push_str(REPLACEMENT);
2347            }
2348        }
2349
2350        res
2351    }
2352
2353    /// Returns the bytes that were attempted to convert to a `String`.
2354    ///
2355    /// This method is carefully constructed to avoid allocation. It will
2356    /// consume the error, moving out the bytes, so that a copy of the bytes
2357    /// does not need to be made.
2358    ///
2359    /// # Examples
2360    ///
2361    /// ```
2362    /// // some invalid bytes, in a vector
2363    /// let bytes = vec![0, 159];
2364    ///
2365    /// let value = String::from_utf8(bytes);
2366    ///
2367    /// assert_eq!(vec![0, 159], value.unwrap_err().into_bytes());
2368    /// ```
2369    #[must_use = "`self` will be dropped if the result is not used"]
2370    #[stable(feature = "rust1", since = "1.0.0")]
2371    pub fn into_bytes(self) -> Vec<u8> {
2372        self.bytes
2373    }
2374
2375    /// Fetch a `Utf8Error` to get more details about the conversion failure.
2376    ///
2377    /// The [`Utf8Error`] type provided by [`std::str`] represents an error that may
2378    /// occur when converting a slice of [`u8`]s to a [`&str`]. In this sense, it's
2379    /// an analogue to `FromUtf8Error`. See its documentation for more details
2380    /// on using it.
2381    ///
2382    /// [`std::str`]: core::str "std::str"
2383    /// [`&str`]: prim@str "&str"
2384    ///
2385    /// # Examples
2386    ///
2387    /// ```
2388    /// // some invalid bytes, in a vector
2389    /// let bytes = vec![0, 159];
2390    ///
2391    /// let error = String::from_utf8(bytes).unwrap_err().utf8_error();
2392    ///
2393    /// // the first byte is invalid here
2394    /// assert_eq!(1, error.valid_up_to());
2395    /// ```
2396    #[must_use]
2397    #[stable(feature = "rust1", since = "1.0.0")]
2398    pub fn utf8_error(&self) -> Utf8Error {
2399        self.error
2400    }
2401}
2402
2403#[stable(feature = "rust1", since = "1.0.0")]
2404impl fmt::Display for FromUtf8Error {
2405    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2406        fmt::Display::fmt(&self.error, f)
2407    }
2408}
2409
2410#[stable(feature = "rust1", since = "1.0.0")]
2411impl fmt::Display for FromUtf16Error {
2412    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2413        match self.kind {
2414            FromUtf16ErrorKind::LoneSurrogate => "invalid utf-16: lone surrogate found",
2415            FromUtf16ErrorKind::OddBytes => "invalid utf-16: odd number of bytes",
2416        }
2417        .fmt(f)
2418    }
2419}
2420
2421#[stable(feature = "rust1", since = "1.0.0")]
2422impl Error for FromUtf8Error {}
2423
2424#[stable(feature = "rust1", since = "1.0.0")]
2425impl Error for FromUtf16Error {}
2426
2427#[cfg(not(no_global_oom_handling))]
2428#[stable(feature = "rust1", since = "1.0.0")]
2429impl Clone for String {
2430    fn clone(&self) -> Self {
2431        String { vec: self.vec.clone() }
2432    }
2433
2434    /// Clones the contents of `source` into `self`.
2435    ///
2436    /// This method is preferred over simply assigning `source.clone()` to `self`,
2437    /// as it avoids reallocation if possible.
2438    fn clone_from(&mut self, source: &Self) {
2439        self.vec.clone_from(&source.vec);
2440    }
2441}
2442
2443#[cfg(not(no_global_oom_handling))]
2444#[stable(feature = "rust1", since = "1.0.0")]
2445impl FromIterator<char> for String {
2446    fn from_iter<I: IntoIterator<Item = char>>(iter: I) -> String {
2447        let mut buf = String::new();
2448        buf.extend(iter);
2449        buf
2450    }
2451}
2452
2453#[cfg(not(no_global_oom_handling))]
2454#[stable(feature = "string_from_iter_by_ref", since = "1.17.0")]
2455impl<'a> FromIterator<&'a char> for String {
2456    fn from_iter<I: IntoIterator<Item = &'a char>>(iter: I) -> String {
2457        let mut buf = String::new();
2458        buf.extend(iter);
2459        buf
2460    }
2461}
2462
2463#[cfg(not(no_global_oom_handling))]
2464#[stable(feature = "rust1", since = "1.0.0")]
2465impl<'a> FromIterator<&'a str> for String {
2466    fn from_iter<I: IntoIterator<Item = &'a str>>(iter: I) -> String {
2467        let mut buf = String::new();
2468        buf.extend(iter);
2469        buf
2470    }
2471}
2472
2473#[cfg(not(no_global_oom_handling))]
2474#[stable(feature = "extend_string", since = "1.4.0")]
2475impl FromIterator<String> for String {
2476    fn from_iter<I: IntoIterator<Item = String>>(iter: I) -> String {
2477        let mut iterator = iter.into_iter();
2478
2479        // Because we're iterating over `String`s, we can avoid at least
2480        // one allocation by getting the first string from the iterator
2481        // and appending to it all the subsequent strings.
2482        match iterator.next() {
2483            None => String::new(),
2484            Some(mut buf) => {
2485                buf.extend(iterator);
2486                buf
2487            }
2488        }
2489    }
2490}
2491
2492#[cfg(not(no_global_oom_handling))]
2493#[stable(feature = "box_str2", since = "1.45.0")]
2494impl<A: Allocator> FromIterator<Box<str, A>> for String {
2495    fn from_iter<I: IntoIterator<Item = Box<str, A>>>(iter: I) -> String {
2496        let mut buf = String::new();
2497        buf.extend(iter);
2498        buf
2499    }
2500}
2501
2502#[cfg(not(no_global_oom_handling))]
2503#[stable(feature = "herd_cows", since = "1.19.0")]
2504impl<'a> FromIterator<Cow<'a, str>> for String {
2505    fn from_iter<I: IntoIterator<Item = Cow<'a, str>>>(iter: I) -> String {
2506        let mut iterator = iter.into_iter();
2507
2508        // Because we're iterating over CoWs, we can (potentially) avoid at least
2509        // one allocation by getting the first item and appending to it all the
2510        // subsequent items.
2511        match iterator.next() {
2512            None => String::new(),
2513            Some(cow) => {
2514                let mut buf = cow.into_owned();
2515                buf.extend(iterator);
2516                buf
2517            }
2518        }
2519    }
2520}
2521
2522#[cfg(not(no_global_oom_handling))]
2523#[unstable(feature = "ascii_char", issue = "110998")]
2524impl FromIterator<core::ascii::Char> for String {
2525    fn from_iter<I: IntoIterator<Item = core::ascii::Char>>(iter: I) -> Self {
2526        let buf = iter.into_iter().map(core::ascii::Char::to_u8).collect();
2527        // SAFETY: `buf` is guaranteed to be valid UTF-8 because the `core::ascii::Char` type
2528        // only contains ASCII values (0x00-0x7F), which are valid UTF-8.
2529        unsafe { String::from_utf8_unchecked(buf) }
2530    }
2531}
2532
2533#[cfg(not(no_global_oom_handling))]
2534#[unstable(feature = "ascii_char", issue = "110998")]
2535impl<'a> FromIterator<&'a core::ascii::Char> for String {
2536    fn from_iter<I: IntoIterator<Item = &'a core::ascii::Char>>(iter: I) -> Self {
2537        let buf = iter.into_iter().copied().map(core::ascii::Char::to_u8).collect();
2538        // SAFETY: `buf` is guaranteed to be valid UTF-8 because the `core::ascii::Char` type
2539        // only contains ASCII values (0x00-0x7F), which are valid UTF-8.
2540        unsafe { String::from_utf8_unchecked(buf) }
2541    }
2542}
2543
2544#[cfg(not(no_global_oom_handling))]
2545#[stable(feature = "rust1", since = "1.0.0")]
2546impl Extend<char> for String {
2547    fn extend<I: IntoIterator<Item = char>>(&mut self, iter: I) {
2548        let iterator = iter.into_iter();
2549        let (lower_bound, _) = iterator.size_hint();
2550        self.reserve(lower_bound);
2551        iterator.for_each(move |c| self.push(c));
2552    }
2553
2554    #[inline]
2555    fn extend_one(&mut self, c: char) {
2556        self.push(c);
2557    }
2558
2559    #[inline]
2560    fn extend_reserve(&mut self, additional: usize) {
2561        self.reserve(additional);
2562    }
2563}
2564
2565#[cfg(not(no_global_oom_handling))]
2566#[stable(feature = "extend_ref", since = "1.2.0")]
2567impl<'a> Extend<&'a char> for String {
2568    fn extend<I: IntoIterator<Item = &'a char>>(&mut self, iter: I) {
2569        self.extend(iter.into_iter().cloned());
2570    }
2571
2572    #[inline]
2573    fn extend_one(&mut self, &c: &'a char) {
2574        self.push(c);
2575    }
2576
2577    #[inline]
2578    fn extend_reserve(&mut self, additional: usize) {
2579        self.reserve(additional);
2580    }
2581}
2582
2583#[cfg(not(no_global_oom_handling))]
2584#[stable(feature = "rust1", since = "1.0.0")]
2585impl<'a> Extend<&'a str> for String {
2586    fn extend<I: IntoIterator<Item = &'a str>>(&mut self, iter: I) {
2587        <I as SpecExtendStr>::spec_extend_into(iter, self)
2588    }
2589
2590    #[inline]
2591    fn extend_one(&mut self, s: &'a str) {
2592        self.push_str(s);
2593    }
2594}
2595
2596#[cfg(not(no_global_oom_handling))]
2597trait SpecExtendStr {
2598    fn spec_extend_into(self, s: &mut String);
2599}
2600
2601#[cfg(not(no_global_oom_handling))]
2602impl<'a, T: IntoIterator<Item = &'a str>> SpecExtendStr for T {
2603    default fn spec_extend_into(self, target: &mut String) {
2604        self.into_iter().for_each(move |s| target.push_str(s));
2605    }
2606}
2607
2608#[cfg(not(no_global_oom_handling))]
2609impl SpecExtendStr for [&str] {
2610    fn spec_extend_into(self, target: &mut String) {
2611        target.push_str_slice(&self);
2612    }
2613}
2614
2615#[cfg(not(no_global_oom_handling))]
2616impl<const N: usize> SpecExtendStr for [&str; N] {
2617    fn spec_extend_into(self, target: &mut String) {
2618        target.push_str_slice(&self[..]);
2619    }
2620}
2621
2622#[cfg(not(no_global_oom_handling))]
2623#[stable(feature = "box_str2", since = "1.45.0")]
2624impl<A: Allocator> Extend<Box<str, A>> for String {
2625    fn extend<I: IntoIterator<Item = Box<str, A>>>(&mut self, iter: I) {
2626        iter.into_iter().for_each(move |s| self.push_str(&s));
2627    }
2628}
2629
2630#[cfg(not(no_global_oom_handling))]
2631#[stable(feature = "extend_string", since = "1.4.0")]
2632impl Extend<String> for String {
2633    fn extend<I: IntoIterator<Item = String>>(&mut self, iter: I) {
2634        iter.into_iter().for_each(move |s| self.push_str(&s));
2635    }
2636
2637    #[inline]
2638    fn extend_one(&mut self, s: String) {
2639        self.push_str(&s);
2640    }
2641}
2642
2643#[cfg(not(no_global_oom_handling))]
2644#[stable(feature = "herd_cows", since = "1.19.0")]
2645impl<'a> Extend<Cow<'a, str>> for String {
2646    fn extend<I: IntoIterator<Item = Cow<'a, str>>>(&mut self, iter: I) {
2647        iter.into_iter().for_each(move |s| self.push_str(&s));
2648    }
2649
2650    #[inline]
2651    fn extend_one(&mut self, s: Cow<'a, str>) {
2652        self.push_str(&s);
2653    }
2654}
2655
2656#[cfg(not(no_global_oom_handling))]
2657#[unstable(feature = "ascii_char", issue = "110998")]
2658impl Extend<core::ascii::Char> for String {
2659    #[inline]
2660    fn extend<I: IntoIterator<Item = core::ascii::Char>>(&mut self, iter: I) {
2661        self.vec.extend(iter.into_iter().map(|c| c.to_u8()));
2662    }
2663
2664    #[inline]
2665    fn extend_one(&mut self, c: core::ascii::Char) {
2666        self.vec.push(c.to_u8());
2667    }
2668}
2669
2670#[cfg(not(no_global_oom_handling))]
2671#[unstable(feature = "ascii_char", issue = "110998")]
2672impl<'a> Extend<&'a core::ascii::Char> for String {
2673    #[inline]
2674    fn extend<I: IntoIterator<Item = &'a core::ascii::Char>>(&mut self, iter: I) {
2675        self.extend(iter.into_iter().cloned());
2676    }
2677
2678    #[inline]
2679    fn extend_one(&mut self, c: &'a core::ascii::Char) {
2680        self.vec.push(c.to_u8());
2681    }
2682}
2683
2684/// A convenience impl that delegates to the impl for `&str`.
2685///
2686/// # Examples
2687///
2688/// ```
2689/// assert_eq!(String::from("Hello world").find("world"), Some(6));
2690/// ```
2691#[unstable(
2692    feature = "pattern",
2693    reason = "API not fully fleshed out and ready to be stabilized",
2694    issue = "27721"
2695)]
2696impl<'b> Pattern for &'b String {
2697    type Searcher<'a> = <&'b str as Pattern>::Searcher<'a>;
2698
2699    fn into_searcher(self, haystack: &str) -> <&'b str as Pattern>::Searcher<'_> {
2700        self[..].into_searcher(haystack)
2701    }
2702
2703    #[inline]
2704    fn is_contained_in(self, haystack: &str) -> bool {
2705        self[..].is_contained_in(haystack)
2706    }
2707
2708    #[inline]
2709    fn is_prefix_of(self, haystack: &str) -> bool {
2710        self[..].is_prefix_of(haystack)
2711    }
2712
2713    #[inline]
2714    fn strip_prefix_of(self, haystack: &str) -> Option<&str> {
2715        self[..].strip_prefix_of(haystack)
2716    }
2717
2718    #[inline]
2719    fn is_suffix_of<'a>(self, haystack: &'a str) -> bool
2720    where
2721        Self::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2722    {
2723        self[..].is_suffix_of(haystack)
2724    }
2725
2726    #[inline]
2727    fn strip_suffix_of<'a>(self, haystack: &'a str) -> Option<&'a str>
2728    where
2729        Self::Searcher<'a>: core::str::pattern::ReverseSearcher<'a>,
2730    {
2731        self[..].strip_suffix_of(haystack)
2732    }
2733
2734    #[inline]
2735    fn as_utf8_pattern(&self) -> Option<Utf8Pattern<'_>> {
2736        Some(Utf8Pattern::StringPattern(self.as_str()))
2737    }
2738}
2739
2740macro_rules! impl_eq {
2741    ($lhs:ty, $rhs: ty) => {
2742        #[stable(feature = "rust1", since = "1.0.0")]
2743        impl PartialEq<$rhs> for $lhs {
2744            #[inline]
2745            fn eq(&self, other: &$rhs) -> bool {
2746                PartialEq::eq(&self[..], &other[..])
2747            }
2748            #[inline]
2749            fn ne(&self, other: &$rhs) -> bool {
2750                PartialEq::ne(&self[..], &other[..])
2751            }
2752        }
2753
2754        #[stable(feature = "rust1", since = "1.0.0")]
2755        impl PartialEq<$lhs> for $rhs {
2756            #[inline]
2757            fn eq(&self, other: &$lhs) -> bool {
2758                PartialEq::eq(&self[..], &other[..])
2759            }
2760            #[inline]
2761            fn ne(&self, other: &$lhs) -> bool {
2762                PartialEq::ne(&self[..], &other[..])
2763            }
2764        }
2765    };
2766}
2767
2768impl_eq! { String, str }
2769impl_eq! { String, &str }
2770#[cfg(not(no_global_oom_handling))]
2771impl_eq! { Cow<'_, str>, str }
2772#[cfg(not(no_global_oom_handling))]
2773impl_eq! { Cow<'_, str>, &'_ str }
2774#[cfg(not(no_global_oom_handling))]
2775impl_eq! { Cow<'_, str>, String }
2776
2777#[stable(feature = "rust1", since = "1.0.0")]
2778#[rustc_const_unstable(feature = "const_default", issue = "143894")]
2779const impl Default for String {
2780    /// Creates an empty `String`.
2781    #[inline]
2782    fn default() -> String {
2783        String::new()
2784    }
2785}
2786
2787#[stable(feature = "rust1", since = "1.0.0")]
2788impl fmt::Display for String {
2789    #[inline]
2790    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2791        fmt::Display::fmt(&**self, f)
2792    }
2793}
2794
2795#[stable(feature = "rust1", since = "1.0.0")]
2796impl fmt::Debug for String {
2797    #[inline]
2798    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
2799        fmt::Debug::fmt(&**self, f)
2800    }
2801}
2802
2803#[stable(feature = "rust1", since = "1.0.0")]
2804impl hash::Hash for String {
2805    #[inline]
2806    fn hash<H: hash::Hasher>(&self, hasher: &mut H) {
2807        (**self).hash(hasher)
2808    }
2809}
2810
2811/// Implements the `+` operator for concatenating two strings.
2812///
2813/// This consumes the `String` on the left-hand side and re-uses its buffer (growing it if
2814/// necessary). This is done to avoid allocating a new `String` and copying the entire contents on
2815/// every operation, which would lead to *O*(*n*^2) running time when building an *n*-byte string by
2816/// repeated concatenation.
2817///
2818/// The string on the right-hand side is only borrowed; its contents are copied into the returned
2819/// `String`.
2820///
2821/// # Examples
2822///
2823/// Concatenating two `String`s takes the first by value and borrows the second:
2824///
2825/// ```
2826/// let a = String::from("hello");
2827/// let b = String::from(" world");
2828/// let c = a + &b;
2829/// // `a` is moved and can no longer be used here.
2830/// ```
2831///
2832/// If you want to keep using the first `String`, you can clone it and append to the clone instead:
2833///
2834/// ```
2835/// let a = String::from("hello");
2836/// let b = String::from(" world");
2837/// let c = a.clone() + &b;
2838/// // `a` is still valid here.
2839/// ```
2840///
2841/// Concatenating `&str` slices can be done by converting the first to a `String`:
2842///
2843/// ```
2844/// let a = "hello";
2845/// let b = " world";
2846/// let c = a.to_string() + b;
2847/// ```
2848#[cfg(not(no_global_oom_handling))]
2849#[stable(feature = "rust1", since = "1.0.0")]
2850impl Add<&str> for String {
2851    type Output = String;
2852
2853    #[inline]
2854    fn add(mut self, other: &str) -> String {
2855        self.push_str(other);
2856        self
2857    }
2858}
2859
2860/// Implements the `+=` operator for appending to a `String`.
2861///
2862/// This has the same behavior as the [`push_str`][String::push_str] method.
2863#[cfg(not(no_global_oom_handling))]
2864#[stable(feature = "stringaddassign", since = "1.12.0")]
2865impl AddAssign<&str> for String {
2866    #[inline]
2867    fn add_assign(&mut self, other: &str) {
2868        self.push_str(other);
2869    }
2870}
2871
2872#[stable(feature = "rust1", since = "1.0.0")]
2873impl<I> ops::Index<I> for String
2874where
2875    I: slice::SliceIndex<str>,
2876{
2877    type Output = I::Output;
2878
2879    #[inline]
2880    fn index(&self, index: I) -> &I::Output {
2881        index.index(self.as_str())
2882    }
2883}
2884
2885#[stable(feature = "rust1", since = "1.0.0")]
2886impl<I> ops::IndexMut<I> for String
2887where
2888    I: slice::SliceIndex<str>,
2889{
2890    #[inline]
2891    fn index_mut(&mut self, index: I) -> &mut I::Output {
2892        index.index_mut(self.as_mut_str())
2893    }
2894}
2895
2896#[stable(feature = "rust1", since = "1.0.0")]
2897impl ops::Deref for String {
2898    type Target = str;
2899
2900    #[inline]
2901    fn deref(&self) -> &str {
2902        self.as_str()
2903    }
2904}
2905
2906#[unstable(feature = "deref_pure_trait", issue = "87121")]
2907unsafe impl ops::DerefPure for String {}
2908
2909#[stable(feature = "derefmut_for_string", since = "1.3.0")]
2910impl ops::DerefMut for String {
2911    #[inline]
2912    fn deref_mut(&mut self) -> &mut str {
2913        self.as_mut_str()
2914    }
2915}
2916
2917/// A type alias for [`!`].
2918///
2919/// This alias exists for backwards compatibility, and may be eventually deprecated.
2920#[stable(feature = "str_parse_error", since = "1.5.0")]
2921pub type ParseError = !;
2922
2923#[cfg(not(no_global_oom_handling))]
2924#[stable(feature = "rust1", since = "1.0.0")]
2925impl FromStr for String {
2926    type Err = !;
2927    #[inline]
2928    fn from_str(s: &str) -> Result<String, !> {
2929        Ok(String::from(s))
2930    }
2931}
2932
2933/// A trait for converting a value to a `String`.
2934///
2935/// This trait is automatically implemented for any type which implements the
2936/// [`Display`] trait. As such, `ToString` shouldn't be implemented directly:
2937/// [`Display`] should be implemented instead, and you get the `ToString`
2938/// implementation for free.
2939///
2940/// [`Display`]: fmt::Display
2941#[rustc_diagnostic_item = "ToString"]
2942#[stable(feature = "rust1", since = "1.0.0")]
2943pub trait ToString {
2944    /// Converts the given value to a `String`.
2945    ///
2946    /// # Examples
2947    ///
2948    /// ```
2949    /// let i = 5;
2950    /// let five = String::from("5");
2951    ///
2952    /// assert_eq!(five, i.to_string());
2953    /// ```
2954    #[rustc_conversion_suggestion]
2955    #[stable(feature = "rust1", since = "1.0.0")]
2956    #[rustc_diagnostic_item = "to_string_method"]
2957    fn to_string(&self) -> String;
2958}
2959
2960/// # Panics
2961///
2962/// In this implementation, the `to_string` method panics
2963/// if the `Display` implementation returns an error.
2964/// This indicates an incorrect `Display` implementation
2965/// since `fmt::Write for String` never returns an error itself.
2966#[cfg(not(no_global_oom_handling))]
2967#[stable(feature = "rust1", since = "1.0.0")]
2968impl<T: fmt::Display + ?Sized> ToString for T {
2969    #[inline]
2970    fn to_string(&self) -> String {
2971        <Self as SpecToString>::spec_to_string(self)
2972    }
2973}
2974
2975#[cfg(not(no_global_oom_handling))]
2976trait SpecToString {
2977    fn spec_to_string(&self) -> String;
2978}
2979
2980#[cfg(not(no_global_oom_handling))]
2981impl<T: fmt::Display + ?Sized> SpecToString for T {
2982    // A common guideline is to not inline generic functions. However,
2983    // removing `#[inline]` from this method causes non-negligible regressions.
2984    // See <https://github.com/rust-lang/rust/pull/74852>, the last attempt
2985    // to try to remove it.
2986    #[inline]
2987    default fn spec_to_string(&self) -> String {
2988        let mut buf = String::new();
2989        let mut formatter =
2990            core::fmt::Formatter::new(&mut buf, core::fmt::FormattingOptions::new());
2991        // Bypass format_args!() to avoid write_str with zero-length strs
2992        fmt::Display::fmt(self, &mut formatter)
2993            .expect("a Display implementation returned an error unexpectedly");
2994        buf
2995    }
2996}
2997
2998#[cfg(not(no_global_oom_handling))]
2999impl SpecToString for core::ascii::Char {
3000    #[inline]
3001    fn spec_to_string(&self) -> String {
3002        self.as_str().to_owned()
3003    }
3004}
3005
3006#[cfg(not(no_global_oom_handling))]
3007impl SpecToString for char {
3008    #[inline]
3009    fn spec_to_string(&self) -> String {
3010        String::from(self.encode_utf8(&mut [0; char::MAX_LEN_UTF8]))
3011    }
3012}
3013
3014#[cfg(not(no_global_oom_handling))]
3015impl SpecToString for bool {
3016    #[inline]
3017    fn spec_to_string(&self) -> String {
3018        String::from(if *self { "true" } else { "false" })
3019    }
3020}
3021
3022macro_rules! impl_to_string {
3023    ($($signed:ident, $unsigned:ident,)*) => {
3024        $(
3025        #[cfg(not(no_global_oom_handling))]
3026        #[cfg(not(feature = "optimize_for_size"))]
3027        impl SpecToString for $signed {
3028            #[inline]
3029            fn spec_to_string(&self) -> String {
3030                const SIZE: usize = $signed::MAX.ilog10() as usize + 1;
3031                let mut buf = [core::mem::MaybeUninit::<u8>::uninit(); SIZE];
3032                // Only difference between signed and unsigned are these 8 lines.
3033                let mut out;
3034                if *self < 0 {
3035                    out = String::with_capacity(SIZE + 1);
3036                    out.push('-');
3037                } else {
3038                    out = String::with_capacity(SIZE);
3039                }
3040
3041                // SAFETY: `buf` is always big enough to contain all the digits.
3042                unsafe { out.push_str(self.unsigned_abs()._fmt(&mut buf)); }
3043                out
3044            }
3045        }
3046        #[cfg(not(no_global_oom_handling))]
3047        #[cfg(not(feature = "optimize_for_size"))]
3048        impl SpecToString for $unsigned {
3049            #[inline]
3050            fn spec_to_string(&self) -> String {
3051                const SIZE: usize = $unsigned::MAX.ilog10() as usize + 1;
3052                let mut buf = [core::mem::MaybeUninit::<u8>::uninit(); SIZE];
3053
3054                // SAFETY: `buf` is always big enough to contain all the digits.
3055                unsafe { self._fmt(&mut buf).to_string() }
3056            }
3057        }
3058        )*
3059    }
3060}
3061
3062impl_to_string! {
3063    i8, u8,
3064    i16, u16,
3065    i32, u32,
3066    i64, u64,
3067    isize, usize,
3068    i128, u128,
3069}
3070
3071#[cfg(not(no_global_oom_handling))]
3072#[cfg(feature = "optimize_for_size")]
3073impl SpecToString for u8 {
3074    #[inline]
3075    fn spec_to_string(&self) -> String {
3076        let mut buf = String::with_capacity(3);
3077        let mut n = *self;
3078        if n >= 10 {
3079            if n >= 100 {
3080                buf.push((b'0' + n / 100) as char);
3081                n %= 100;
3082            }
3083            buf.push((b'0' + n / 10) as char);
3084            n %= 10;
3085        }
3086        buf.push((b'0' + n) as char);
3087        buf
3088    }
3089}
3090
3091#[cfg(not(no_global_oom_handling))]
3092#[cfg(feature = "optimize_for_size")]
3093impl SpecToString for i8 {
3094    #[inline]
3095    fn spec_to_string(&self) -> String {
3096        let mut buf = String::with_capacity(4);
3097        if self.is_negative() {
3098            buf.push('-');
3099        }
3100        let mut n = self.unsigned_abs();
3101        if n >= 10 {
3102            if n >= 100 {
3103                buf.push('1');
3104                n -= 100;
3105            }
3106            buf.push((b'0' + n / 10) as char);
3107            n %= 10;
3108        }
3109        buf.push((b'0' + n) as char);
3110        buf
3111    }
3112}
3113
3114#[cfg(not(no_global_oom_handling))]
3115macro_rules! to_string_str {
3116    {$($type:ty,)*} => {
3117        $(
3118            impl SpecToString for $type {
3119                #[inline]
3120                fn spec_to_string(&self) -> String {
3121                    let s: &str = self;
3122                    String::from(s)
3123                }
3124            }
3125        )*
3126    };
3127}
3128
3129#[cfg(not(no_global_oom_handling))]
3130to_string_str! {
3131    Cow<'_, str>,
3132    String,
3133    // Generic/generated code can sometimes have multiple, nested references
3134    // for strings, including `&&&str`s that would never be written
3135    // by hand.
3136    &&&&&&&&&&&&str,
3137    &&&&&&&&&&&str,
3138    &&&&&&&&&&str,
3139    &&&&&&&&&str,
3140    &&&&&&&&str,
3141    &&&&&&&str,
3142    &&&&&&str,
3143    &&&&&str,
3144    &&&&str,
3145    &&&str,
3146    &&str,
3147    &str,
3148    str,
3149}
3150
3151#[cfg(not(no_global_oom_handling))]
3152impl SpecToString for fmt::Arguments<'_> {
3153    #[inline]
3154    fn spec_to_string(&self) -> String {
3155        crate::fmt::format(*self)
3156    }
3157}
3158
3159#[stable(feature = "rust1", since = "1.0.0")]
3160impl AsRef<str> for String {
3161    #[inline]
3162    fn as_ref(&self) -> &str {
3163        self
3164    }
3165}
3166
3167#[stable(feature = "string_as_mut", since = "1.43.0")]
3168impl AsMut<str> for String {
3169    #[inline]
3170    fn as_mut(&mut self) -> &mut str {
3171        self
3172    }
3173}
3174
3175#[stable(feature = "rust1", since = "1.0.0")]
3176impl AsRef<[u8]> for String {
3177    #[inline]
3178    fn as_ref(&self) -> &[u8] {
3179        self.as_bytes()
3180    }
3181}
3182
3183#[cfg(not(no_global_oom_handling))]
3184#[stable(feature = "rust1", since = "1.0.0")]
3185impl From<&str> for String {
3186    /// Converts a `&str` into a [`String`].
3187    ///
3188    /// The result is allocated on the heap.
3189    #[inline]
3190    fn from(s: &str) -> String {
3191        s.to_owned()
3192    }
3193}
3194
3195#[cfg(not(no_global_oom_handling))]
3196#[stable(feature = "from_mut_str_for_string", since = "1.44.0")]
3197impl From<&mut str> for String {
3198    /// Converts a `&mut str` into a [`String`].
3199    ///
3200    /// The result is allocated on the heap.
3201    #[inline]
3202    fn from(s: &mut str) -> String {
3203        s.to_owned()
3204    }
3205}
3206
3207#[cfg(not(no_global_oom_handling))]
3208#[stable(feature = "from_ref_string", since = "1.35.0")]
3209impl From<&String> for String {
3210    /// Converts a `&String` into a [`String`].
3211    ///
3212    /// This clones `s` and returns the clone.
3213    #[inline]
3214    fn from(s: &String) -> String {
3215        s.clone()
3216    }
3217}
3218
3219// note: test pulls in std, which causes errors here
3220#[stable(feature = "string_from_box", since = "1.18.0")]
3221impl From<Box<str>> for String {
3222    /// Converts the given boxed `str` slice to a [`String`].
3223    /// It is notable that the `str` slice is owned.
3224    ///
3225    /// # Examples
3226    ///
3227    /// ```
3228    /// let s1: String = String::from("hello world");
3229    /// let s2: Box<str> = s1.into_boxed_str();
3230    /// let s3: String = String::from(s2);
3231    ///
3232    /// assert_eq!("hello world", s3)
3233    /// ```
3234    fn from(s: Box<str>) -> String {
3235        s.into_string()
3236    }
3237}
3238
3239#[cfg(not(no_global_oom_handling))]
3240#[stable(feature = "box_from_str", since = "1.20.0")]
3241impl From<String> for Box<str> {
3242    /// Converts the given [`String`] to a boxed `str` slice that is owned.
3243    ///
3244    /// # Examples
3245    ///
3246    /// ```
3247    /// let s1: String = String::from("hello world");
3248    /// let s2: Box<str> = Box::from(s1);
3249    /// let s3: String = String::from(s2);
3250    ///
3251    /// assert_eq!("hello world", s3)
3252    /// ```
3253    fn from(s: String) -> Box<str> {
3254        s.into_boxed_str()
3255    }
3256}
3257
3258#[cfg(not(no_global_oom_handling))]
3259#[stable(feature = "string_from_cow_str", since = "1.14.0")]
3260impl<'a> From<Cow<'a, str>> for String {
3261    /// Converts a clone-on-write string to an owned
3262    /// instance of [`String`].
3263    ///
3264    /// This extracts the owned string,
3265    /// clones the string if it is not already owned.
3266    ///
3267    /// # Example
3268    ///
3269    /// ```
3270    /// # use std::borrow::Cow;
3271    /// // If the string is not owned...
3272    /// let cow: Cow<'_, str> = Cow::Borrowed("eggplant");
3273    /// // It will allocate on the heap and copy the string.
3274    /// let owned: String = String::from(cow);
3275    /// assert_eq!(&owned[..], "eggplant");
3276    /// ```
3277    fn from(s: Cow<'a, str>) -> String {
3278        s.into_owned()
3279    }
3280}
3281
3282#[cfg(not(no_global_oom_handling))]
3283#[stable(feature = "rust1", since = "1.0.0")]
3284impl<'a> From<&'a str> for Cow<'a, str> {
3285    /// Converts a string slice into a [`Borrowed`] variant.
3286    /// No heap allocation is performed, and the string
3287    /// is not copied.
3288    ///
3289    /// # Example
3290    ///
3291    /// ```
3292    /// # use std::borrow::Cow;
3293    /// assert_eq!(Cow::from("eggplant"), Cow::Borrowed("eggplant"));
3294    /// ```
3295    ///
3296    /// [`Borrowed`]: crate::borrow::Cow::Borrowed "borrow::Cow::Borrowed"
3297    #[inline]
3298    fn from(s: &'a str) -> Cow<'a, str> {
3299        Cow::Borrowed(s)
3300    }
3301}
3302
3303#[cfg(not(no_global_oom_handling))]
3304#[stable(feature = "rust1", since = "1.0.0")]
3305impl<'a> From<String> for Cow<'a, str> {
3306    /// Converts a [`String`] into an [`Owned`] variant.
3307    /// No heap allocation is performed, and the string
3308    /// is not copied.
3309    ///
3310    /// # Example
3311    ///
3312    /// ```
3313    /// # use std::borrow::Cow;
3314    /// let s = "eggplant".to_string();
3315    /// let s2 = "eggplant".to_string();
3316    /// assert_eq!(Cow::from(s), Cow::<'static, str>::Owned(s2));
3317    /// ```
3318    ///
3319    /// [`Owned`]: crate::borrow::Cow::Owned "borrow::Cow::Owned"
3320    #[inline]
3321    fn from(s: String) -> Cow<'a, str> {
3322        Cow::Owned(s)
3323    }
3324}
3325
3326#[cfg(not(no_global_oom_handling))]
3327#[stable(feature = "cow_from_string_ref", since = "1.28.0")]
3328impl<'a> From<&'a String> for Cow<'a, str> {
3329    /// Converts a [`String`] reference into a [`Borrowed`] variant.
3330    /// No heap allocation is performed, and the string
3331    /// is not copied.
3332    ///
3333    /// # Example
3334    ///
3335    /// ```
3336    /// # use std::borrow::Cow;
3337    /// let s = "eggplant".to_string();
3338    /// assert_eq!(Cow::from(&s), Cow::Borrowed("eggplant"));
3339    /// ```
3340    ///
3341    /// [`Borrowed`]: crate::borrow::Cow::Borrowed "borrow::Cow::Borrowed"
3342    #[inline]
3343    fn from(s: &'a String) -> Cow<'a, str> {
3344        Cow::Borrowed(s.as_str())
3345    }
3346}
3347
3348#[cfg(not(no_global_oom_handling))]
3349#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3350impl<'a> FromIterator<char> for Cow<'a, str> {
3351    fn from_iter<I: IntoIterator<Item = char>>(it: I) -> Cow<'a, str> {
3352        Cow::Owned(FromIterator::from_iter(it))
3353    }
3354}
3355
3356#[cfg(not(no_global_oom_handling))]
3357#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3358impl<'a, 'b> FromIterator<&'b str> for Cow<'a, str> {
3359    fn from_iter<I: IntoIterator<Item = &'b str>>(it: I) -> Cow<'a, str> {
3360        Cow::Owned(FromIterator::from_iter(it))
3361    }
3362}
3363
3364#[cfg(not(no_global_oom_handling))]
3365#[stable(feature = "cow_str_from_iter", since = "1.12.0")]
3366impl<'a> FromIterator<String> for Cow<'a, str> {
3367    fn from_iter<I: IntoIterator<Item = String>>(it: I) -> Cow<'a, str> {
3368        Cow::Owned(FromIterator::from_iter(it))
3369    }
3370}
3371
3372#[cfg(not(no_global_oom_handling))]
3373#[unstable(feature = "ascii_char", issue = "110998")]
3374impl<'a> FromIterator<core::ascii::Char> for Cow<'a, str> {
3375    fn from_iter<I: IntoIterator<Item = core::ascii::Char>>(it: I) -> Self {
3376        Cow::Owned(FromIterator::from_iter(it))
3377    }
3378}
3379
3380#[stable(feature = "from_string_for_vec_u8", since = "1.14.0")]
3381impl From<String> for Vec<u8> {
3382    /// Converts the given [`String`] to a vector [`Vec`] that holds values of type [`u8`].
3383    ///
3384    /// # Examples
3385    ///
3386    /// ```
3387    /// let s1 = String::from("hello world");
3388    /// let v1 = Vec::from(s1);
3389    ///
3390    /// for b in v1 {
3391    ///     println!("{b}");
3392    /// }
3393    /// ```
3394    fn from(string: String) -> Vec<u8> {
3395        string.into_bytes()
3396    }
3397}
3398
3399#[stable(feature = "try_from_vec_u8_for_string", since = "1.87.0")]
3400impl TryFrom<Vec<u8>> for String {
3401    type Error = FromUtf8Error;
3402    /// Converts the given [`Vec<u8>`] into a  [`String`] if it contains valid UTF-8 data.
3403    ///
3404    /// # Examples
3405    ///
3406    /// ```
3407    /// let s1 = b"hello world".to_vec();
3408    /// let v1 = String::try_from(s1).unwrap();
3409    /// assert_eq!(v1, "hello world");
3410    ///
3411    /// ```
3412    fn try_from(bytes: Vec<u8>) -> Result<Self, Self::Error> {
3413        Self::from_utf8(bytes)
3414    }
3415}
3416
3417#[cfg(not(no_global_oom_handling))]
3418#[stable(feature = "rust1", since = "1.0.0")]
3419impl fmt::Write for String {
3420    #[inline]
3421    fn write_str(&mut self, s: &str) -> fmt::Result {
3422        self.push_str(s);
3423        Ok(())
3424    }
3425
3426    #[inline]
3427    fn write_char(&mut self, c: char) -> fmt::Result {
3428        self.push(c);
3429        Ok(())
3430    }
3431}
3432
3433/// An iterator over the [`char`]s of a string.
3434///
3435/// This struct is created by the [`into_chars`] method on [`String`].
3436/// See its documentation for more.
3437///
3438/// [`char`]: prim@char
3439/// [`into_chars`]: String::into_chars
3440#[cfg_attr(not(no_global_oom_handling), derive(Clone))]
3441#[must_use = "iterators are lazy and do nothing unless consumed"]
3442#[unstable(feature = "string_into_chars", issue = "133125")]
3443pub struct IntoChars {
3444    bytes: vec::IntoIter<u8>,
3445}
3446
3447#[unstable(feature = "string_into_chars", issue = "133125")]
3448impl fmt::Debug for IntoChars {
3449    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
3450        f.debug_tuple("IntoChars").field(&self.as_str()).finish()
3451    }
3452}
3453
3454impl IntoChars {
3455    /// Views the underlying data as a subslice of the original data.
3456    ///
3457    /// # Examples
3458    ///
3459    /// ```
3460    /// #![feature(string_into_chars)]
3461    ///
3462    /// let mut chars = String::from("abc").into_chars();
3463    ///
3464    /// assert_eq!(chars.as_str(), "abc");
3465    /// chars.next();
3466    /// assert_eq!(chars.as_str(), "bc");
3467    /// chars.next();
3468    /// chars.next();
3469    /// assert_eq!(chars.as_str(), "");
3470    /// ```
3471    #[unstable(feature = "string_into_chars", issue = "133125")]
3472    #[must_use]
3473    #[inline]
3474    pub fn as_str(&self) -> &str {
3475        // SAFETY: `bytes` is a valid UTF-8 string.
3476        unsafe { str::from_utf8_unchecked(self.bytes.as_slice()) }
3477    }
3478
3479    /// Consumes the `IntoChars`, returning the remaining string.
3480    ///
3481    /// # Examples
3482    ///
3483    /// ```
3484    /// #![feature(string_into_chars)]
3485    ///
3486    /// let chars = String::from("abc").into_chars();
3487    /// assert_eq!(chars.into_string(), "abc");
3488    ///
3489    /// let mut chars = String::from("def").into_chars();
3490    /// chars.next();
3491    /// assert_eq!(chars.into_string(), "ef");
3492    /// ```
3493    #[cfg(not(no_global_oom_handling))]
3494    #[unstable(feature = "string_into_chars", issue = "133125")]
3495    #[inline]
3496    pub fn into_string(self) -> String {
3497        // SAFETY: `bytes` are kept in UTF-8 form, only removing whole `char`s at a time.
3498        unsafe { String::from_utf8_unchecked(self.bytes.collect()) }
3499    }
3500
3501    #[inline]
3502    fn iter(&self) -> CharIndices<'_> {
3503        self.as_str().char_indices()
3504    }
3505}
3506
3507#[unstable(feature = "string_into_chars", issue = "133125")]
3508impl Iterator for IntoChars {
3509    type Item = char;
3510
3511    #[inline]
3512    fn next(&mut self) -> Option<char> {
3513        let mut iter = self.iter();
3514        match iter.next() {
3515            None => None,
3516            Some((_, ch)) => {
3517                let offset = iter.offset();
3518                // `offset` is a valid index.
3519                let _ = self.bytes.advance_by(offset);
3520                Some(ch)
3521            }
3522        }
3523    }
3524
3525    #[inline]
3526    fn count(self) -> usize {
3527        self.iter().count()
3528    }
3529
3530    #[inline]
3531    fn size_hint(&self) -> (usize, Option<usize>) {
3532        self.iter().size_hint()
3533    }
3534
3535    #[inline]
3536    fn last(mut self) -> Option<char> {
3537        self.next_back()
3538    }
3539}
3540
3541#[unstable(feature = "string_into_chars", issue = "133125")]
3542impl DoubleEndedIterator for IntoChars {
3543    #[inline]
3544    fn next_back(&mut self) -> Option<char> {
3545        let len = self.as_str().len();
3546        let mut iter = self.iter();
3547        match iter.next_back() {
3548            None => None,
3549            Some((idx, ch)) => {
3550                // `idx` is a valid index.
3551                let _ = self.bytes.advance_back_by(len - idx);
3552                Some(ch)
3553            }
3554        }
3555    }
3556}
3557
3558#[unstable(feature = "string_into_chars", issue = "133125")]
3559impl FusedIterator for IntoChars {}
3560
3561/// A draining iterator for `String`.
3562///
3563/// This struct is created by the [`drain`] method on [`String`]. See its
3564/// documentation for more.
3565///
3566/// [`drain`]: String::drain
3567#[stable(feature = "drain", since = "1.6.0")]
3568pub struct Drain<'a> {
3569    /// Will be used as &'a mut String in the destructor
3570    string: *mut String,
3571    /// Start of part to remove
3572    start: usize,
3573    /// End of part to remove
3574    end: usize,
3575    /// Current remaining range to remove
3576    iter: Chars<'a>,
3577}
3578
3579#[stable(feature = "collection_debug", since = "1.17.0")]
3580impl fmt::Debug for Drain<'_> {
3581    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
3582        f.debug_tuple("Drain").field(&self.as_str()).finish()
3583    }
3584}
3585
3586#[stable(feature = "drain", since = "1.6.0")]
3587unsafe impl Sync for Drain<'_> {}
3588#[stable(feature = "drain", since = "1.6.0")]
3589unsafe impl Send for Drain<'_> {}
3590
3591#[stable(feature = "drain", since = "1.6.0")]
3592impl Drop for Drain<'_> {
3593    fn drop(&mut self) {
3594        // Use Vec::drain. "Reaffirm" the bounds checks to avoid
3595        // panic code being inserted again.
3596        // SAFETY: We only use the returned Vec to call drain.
3597        let self_vec = unsafe { &mut *(*self.string).as_mut_vec() };
3598        if self.start <= self.end && self.end <= self_vec.len() {
3599            self_vec.drain(self.start..self.end);
3600        }
3601    }
3602}
3603
3604impl<'a> Drain<'a> {
3605    /// Returns the remaining (sub)string of this iterator as a slice.
3606    ///
3607    /// # Examples
3608    ///
3609    /// ```
3610    /// let mut s = String::from("abc");
3611    /// let mut drain = s.drain(..);
3612    /// assert_eq!(drain.as_str(), "abc");
3613    /// let _ = drain.next().unwrap();
3614    /// assert_eq!(drain.as_str(), "bc");
3615    /// ```
3616    #[must_use]
3617    #[stable(feature = "string_drain_as_str", since = "1.55.0")]
3618    pub fn as_str(&self) -> &str {
3619        self.iter.as_str()
3620    }
3621}
3622
3623#[stable(feature = "string_drain_as_str", since = "1.55.0")]
3624impl<'a> AsRef<str> for Drain<'a> {
3625    fn as_ref(&self) -> &str {
3626        self.as_str()
3627    }
3628}
3629
3630#[stable(feature = "string_drain_as_str", since = "1.55.0")]
3631impl<'a> AsRef<[u8]> for Drain<'a> {
3632    fn as_ref(&self) -> &[u8] {
3633        self.as_str().as_bytes()
3634    }
3635}
3636
3637#[stable(feature = "drain", since = "1.6.0")]
3638impl Iterator for Drain<'_> {
3639    type Item = char;
3640
3641    #[inline]
3642    fn next(&mut self) -> Option<char> {
3643        self.iter.next()
3644    }
3645
3646    fn size_hint(&self) -> (usize, Option<usize>) {
3647        self.iter.size_hint()
3648    }
3649
3650    #[inline]
3651    fn last(mut self) -> Option<char> {
3652        self.next_back()
3653    }
3654}
3655
3656#[stable(feature = "drain", since = "1.6.0")]
3657impl DoubleEndedIterator for Drain<'_> {
3658    #[inline]
3659    fn next_back(&mut self) -> Option<char> {
3660        self.iter.next_back()
3661    }
3662}
3663
3664#[stable(feature = "fused", since = "1.26.0")]
3665impl FusedIterator for Drain<'_> {}
3666
3667#[cfg(not(no_global_oom_handling))]
3668#[stable(feature = "from_char_for_string", since = "1.46.0")]
3669impl From<char> for String {
3670    /// Allocates an owned [`String`] from a single character.
3671    ///
3672    /// # Example
3673    /// ```rust
3674    /// let c: char = 'a';
3675    /// let s: String = String::from(c);
3676    /// assert_eq!("a", &s[..]);
3677    /// ```
3678    #[inline]
3679    fn from(c: char) -> Self {
3680        c.to_string()
3681    }
3682}