@@ -43,6 +43,8 @@ impl Alignment {
43
43
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
44
44
#[ inline]
45
45
#[ must_use]
46
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
47
+ |result: & Alignment | result. as_usize( ) . is_power_of_two( ) ) ) ]
46
48
pub const fn of < T > ( ) -> Self {
47
49
// This can't actually panic since type alignment is always a power of two.
48
50
const { Alignment :: new ( mem:: align_of :: < T > ( ) ) . unwrap ( ) }
@@ -54,6 +56,9 @@ impl Alignment {
54
56
/// Note that `0` is not a power of two, nor a valid alignment.
55
57
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
56
58
#[ inline]
59
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
60
+ |result: & Option <Alignment >| align. is_power_of_two( ) == result. is_some( ) &&
61
+ ( result. is_none( ) || result. unwrap( ) . as_usize( ) == align) ) ) ]
57
62
pub const fn new ( align : usize ) -> Option < Self > {
58
63
if align. is_power_of_two ( ) {
59
64
// SAFETY: Just checked it only has one bit set
@@ -73,6 +78,10 @@ impl Alignment {
73
78
/// It must *not* be zero.
74
79
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
75
80
#[ inline]
81
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: requires( align > 0 && ( align & ( align - 1 ) ) == 0 ) ) ]
82
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
83
+ |result: & Alignment | result. as_usize( ) == align &&
84
+ result. as_usize( ) . is_power_of_two( ) ) ) ]
76
85
pub const unsafe fn new_unchecked ( align : usize ) -> Self {
77
86
assert_unsafe_precondition ! (
78
87
check_language_ub,
@@ -88,13 +97,18 @@ impl Alignment {
88
97
/// Returns the alignment as a [`usize`].
89
98
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
90
99
#[ inline]
100
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
101
+ |result: & usize | result. is_power_of_two( ) ) ) ]
91
102
pub const fn as_usize ( self ) -> usize {
92
103
self . 0 as usize
93
104
}
94
105
95
106
/// Returns the alignment as a <code>[NonZero]<[usize]></code>.
96
107
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
97
108
#[ inline]
109
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
110
+ |result: & NonZero <usize >| result. get( ) . is_power_of_two( ) &&
111
+ result. get( ) == self . as_usize( ) ) ) ]
98
112
pub const fn as_nonzero ( self ) -> NonZero < usize > {
99
113
// This transmutes directly to avoid the UbCheck in `NonZero::new_unchecked`
100
114
// since there's no way for the user to trip that check anyway -- the
@@ -120,6 +134,10 @@ impl Alignment {
120
134
/// ```
121
135
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
122
136
#[ inline]
137
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: requires( self . as_usize( ) . is_power_of_two( ) ) ) ]
138
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
139
+ |result: & u32 | * result < usize :: BITS &&
140
+ ( 1usize << * result) == self . as_usize( ) ) ) ]
123
141
pub const fn log2 ( self ) -> u32 {
124
142
self . as_nonzero ( ) . trailing_zeros ( )
125
143
}
@@ -149,6 +167,10 @@ impl Alignment {
149
167
/// ```
150
168
#[ unstable( feature = "ptr_alignment_type" , issue = "102070" ) ]
151
169
#[ inline]
170
+ #[ cfg_attr( not( bootstrap) , core:: contracts:: ensures(
171
+ |result: & usize | * result > 0 &&
172
+ * result == !( self . as_usize( ) -1 ) &&
173
+ self . as_usize( ) & * result == self . as_usize( ) ) ) ]
152
174
pub const fn mask ( self ) -> usize {
153
175
// SAFETY: The alignment is always nonzero, and therefore decrementing won't overflow.
154
176
!( unsafe { self . as_usize ( ) . unchecked_sub ( 1 ) } )
0 commit comments