1 //! Working with GC `array` objects.
2 
3 use crate::runtime::vm::VMGcRef;
4 use crate::store::StoreId;
5 use crate::vm::{VMArrayRef, VMGcHeader};
6 use crate::{AnyRef, FieldType};
7 use crate::{
8     ArrayType, AsContext, AsContextMut, EqRef, GcHeapOutOfMemory, GcRefImpl, GcRootIndex, HeapType,
9     ManuallyRooted, RefType, Rooted, Val, ValRaw, ValType, WasmTy,
10     prelude::*,
11     store::{AutoAssertNoGc, StoreContextMut, StoreOpaque},
12 };
13 use core::mem::{self, MaybeUninit};
14 use wasmtime_environ::{GcArrayLayout, GcLayout, VMGcKind, VMSharedTypeIndex};
15 
16 /// An allocator for a particular Wasm GC array type.
17 ///
18 /// Every `ArrayRefPre` is associated with a particular [`Store`][crate::Store]
19 /// and a particular [`ArrayType`][crate::ArrayType].
20 ///
21 /// Reusing an allocator across many allocations amortizes some per-type runtime
22 /// overheads inside Wasmtime. An `ArrayRefPre` is to `ArrayRef`s as an
23 /// `InstancePre` is to `Instance`s.
24 ///
25 /// # Example
26 ///
27 /// ```
28 /// use wasmtime::*;
29 ///
30 /// # fn foo() -> Result<()> {
31 /// let mut config = Config::new();
32 /// config.wasm_function_references(true);
33 /// config.wasm_gc(true);
34 ///
35 /// let engine = Engine::new(&config)?;
36 /// let mut store = Store::new(&engine, ());
37 ///
38 /// // Define an array type.
39 /// let array_ty = ArrayType::new(
40 ///    store.engine(),
41 ///    FieldType::new(Mutability::Var, ValType::I32.into()),
42 /// );
43 ///
44 /// // Create an allocator for the array type.
45 /// let allocator = ArrayRefPre::new(&mut store, array_ty);
46 ///
47 /// {
48 ///     let mut scope = RootScope::new(&mut store);
49 ///
50 ///     // Allocate a bunch of instances of our array type using the same
51 ///     // allocator! This is faster than creating a new allocator for each
52 ///     // instance we want to allocate.
53 ///     for i in 0..10 {
54 ///         let len = 42;
55 ///         let elem = Val::I32(36);
56 ///         ArrayRef::new(&mut scope, &allocator, &elem, len)?;
57 ///     }
58 /// }
59 /// # Ok(())
60 /// # }
61 /// # let _ = foo();
62 /// ```
63 pub struct ArrayRefPre {
64     store_id: StoreId,
65     ty: ArrayType,
66 }
67 
68 impl ArrayRefPre {
69     /// Create a new `ArrayRefPre` that is associated with the given store
70     /// and type.
71     pub fn new(mut store: impl AsContextMut, ty: ArrayType) -> Self {
72         Self::_new(store.as_context_mut().0, ty)
73     }
74 
75     pub(crate) fn _new(store: &mut StoreOpaque, ty: ArrayType) -> Self {
76         store.insert_gc_host_alloc_type(ty.registered_type().clone());
77         let store_id = store.id();
78         ArrayRefPre { store_id, ty }
79     }
80 
81     pub(crate) fn layout(&self) -> &GcArrayLayout {
82         self.ty
83             .registered_type()
84             .layout()
85             .expect("array types have a layout")
86             .unwrap_array()
87     }
88 
89     pub(crate) fn type_index(&self) -> VMSharedTypeIndex {
90         self.ty.registered_type().index()
91     }
92 }
93 
94 /// A reference to a GC-managed `array` instance.
95 ///
96 /// WebAssembly `array`s are a sequence of elements of some homogeneous
97 /// type. The elements length is determined at allocation time — two instances
98 /// of the same array type may have different lengths — but, once allocated, an
99 /// array's length can never be resized. An array's elements are mutable or
100 /// constant, depending on the array's type. This determines whether any array
101 /// element can be assigned a new value or not. Each element is either an
102 /// unpacked [`Val`][crate::Val] or a packed 8-/16-bit integer. Array elements
103 /// are dynamically accessed via indexing; out-of-bounds accesses result in
104 /// traps.
105 ///
106 /// Like all WebAssembly references, these are opaque and unforgeable to Wasm:
107 /// they cannot be faked and Wasm cannot, for example, cast the integer
108 /// `0x12345678` into a reference, pretend it is a valid `arrayref`, and trick
109 /// the host into dereferencing it and segfaulting or worse.
110 ///
111 /// Note that you can also use `Rooted<ArrayRef>` and `ManuallyRooted<ArrayRef>`
112 /// as a type parameter with [`Func::typed`][crate::Func::typed]- and
113 /// [`Func::wrap`][crate::Func::wrap]-style APIs.
114 ///
115 /// # Example
116 ///
117 /// ```
118 /// use wasmtime::*;
119 ///
120 /// # fn foo() -> Result<()> {
121 /// let mut config = Config::new();
122 /// config.wasm_function_references(true);
123 /// config.wasm_gc(true);
124 ///
125 /// let engine = Engine::new(&config)?;
126 /// let mut store = Store::new(&engine, ());
127 ///
128 /// // Define the type for an array of `i32`s.
129 /// let array_ty = ArrayType::new(
130 ///    store.engine(),
131 ///    FieldType::new(Mutability::Var, ValType::I32.into()),
132 /// );
133 ///
134 /// // Create an allocator for the array type.
135 /// let allocator = ArrayRefPre::new(&mut store, array_ty);
136 ///
137 /// {
138 ///     let mut scope = RootScope::new(&mut store);
139 ///
140 ///     // Allocate an instance of the array type.
141 ///     let len = 36;
142 ///     let elem = Val::I32(42);
143 ///     let my_array = match ArrayRef::new(&mut scope, &allocator, &elem, len) {
144 ///         Ok(s) => s,
145 ///         Err(e) => match e.downcast::<GcHeapOutOfMemory<()>>() {
146 ///             // If the heap is out of memory, then do a GC to free up some
147 ///             // space and try again.
148 ///             Ok(oom) => {
149 ///                 // Do a GC! Note: in an async context, you'd want to do
150 ///                 // `scope.as_context_mut().gc_async().await`.
151 ///                 scope.as_context_mut().gc(Some(&oom));
152 ///
153 ///                 // Try again. If the GC heap is still out of memory, then we
154 ///                 // weren't able to free up resources for this allocation, so
155 ///                 // propagate the error.
156 ///                 ArrayRef::new(&mut scope, &allocator, &elem, len)?
157 ///             }
158 ///             // Propagate any other kind of error.
159 ///             Err(e) => return Err(e),
160 ///         }
161 ///     };
162 ///
163 ///     // That instance's elements should have the initial value.
164 ///     for i in 0..len {
165 ///         let val = my_array.get(&mut scope, i)?.unwrap_i32();
166 ///         assert_eq!(val, 42);
167 ///     }
168 ///
169 ///     // We can set an element to a new value because the type was defined with
170 ///     // mutable elements (as opposed to const).
171 ///     my_array.set(&mut scope, 3, Val::I32(1234))?;
172 ///     let new_val = my_array.get(&mut scope, 3)?.unwrap_i32();
173 ///     assert_eq!(new_val, 1234);
174 /// }
175 /// # Ok(())
176 /// # }
177 /// # foo().unwrap();
178 /// ```
179 #[derive(Debug)]
180 #[repr(transparent)]
181 pub struct ArrayRef {
182     pub(super) inner: GcRootIndex,
183 }
184 
185 unsafe impl GcRefImpl for ArrayRef {
186     fn transmute_ref(index: &GcRootIndex) -> &Self {
187         // Safety: `ArrayRef` is a newtype of a `GcRootIndex`.
188         let me: &Self = unsafe { mem::transmute(index) };
189 
190         // Assert we really are just a newtype of a `GcRootIndex`.
191         assert!(matches!(
192             me,
193             Self {
194                 inner: GcRootIndex { .. },
195             }
196         ));
197 
198         me
199     }
200 }
201 
202 impl Rooted<ArrayRef> {
203     /// Upcast this `arrayref` into an `anyref`.
204     #[inline]
205     pub fn to_anyref(self) -> Rooted<AnyRef> {
206         self.unchecked_cast()
207     }
208 
209     /// Upcast this `arrayref` into an `eqref`.
210     #[inline]
211     pub fn to_eqref(self) -> Rooted<EqRef> {
212         self.unchecked_cast()
213     }
214 }
215 
216 impl ManuallyRooted<ArrayRef> {
217     /// Upcast this `arrayref` into an `anyref`.
218     #[inline]
219     pub fn to_anyref(self) -> ManuallyRooted<AnyRef> {
220         self.unchecked_cast()
221     }
222 
223     /// Upcast this `arrayref` into an `eqref`.
224     #[inline]
225     pub fn to_eqref(self) -> ManuallyRooted<EqRef> {
226         self.unchecked_cast()
227     }
228 }
229 
230 /// An iterator for elements in `ArrayRef::new[_async].
231 ///
232 /// NB: We can't use `iter::repeat(elem).take(len)` because that doesn't
233 /// implement `ExactSizeIterator`.
234 #[derive(Clone)]
235 struct RepeatN<'a>(&'a Val, u32);
236 
237 impl<'a> Iterator for RepeatN<'a> {
238     type Item = &'a Val;
239 
240     fn next(&mut self) -> Option<Self::Item> {
241         if self.1 == 0 {
242             None
243         } else {
244             self.1 -= 1;
245             Some(self.0)
246         }
247     }
248 
249     fn size_hint(&self) -> (usize, Option<usize>) {
250         let len = self.len();
251         (len, Some(len))
252     }
253 }
254 
255 impl ExactSizeIterator for RepeatN<'_> {
256     fn len(&self) -> usize {
257         usize::try_from(self.1).unwrap()
258     }
259 }
260 
261 impl ArrayRef {
262     /// Allocate a new `array` of the given length, with every element
263     /// initialized to `elem`.
264     ///
265     /// For example, `ArrayRef::new(ctx, pre, &Val::I64(9), 3)` allocates the
266     /// array `[9, 9, 9]`.
267     ///
268     /// This is similar to the `array.new` instruction.
269     ///
270     /// # Automatic Garbage Collection
271     ///
272     /// If the GC heap is at capacity, and there isn't room for allocating this
273     /// new array, then this method will automatically trigger a synchronous
274     /// collection in an attempt to free up space in the GC heap.
275     ///
276     /// # Errors
277     ///
278     /// If the given `elem` value's type does not match the `allocator`'s array
279     /// type's element type, an error is returned.
280     ///
281     /// If the allocation cannot be satisfied because the GC heap is currently
282     /// out of memory, then a [`GcHeapOutOfMemory<()>`][crate::GcHeapOutOfMemory]
283     /// error is returned. The allocation might succeed on a second attempt if
284     /// you drop some rooted GC references and try again.
285     ///
286     /// # Panics
287     ///
288     /// Panics if the `store` is configured for async; use
289     /// [`ArrayRef::new_async`][crate::ArrayRef::new_async] to perform
290     /// asynchronous allocation instead.
291     ///
292     /// Panics if either the allocator or the `elem` value is not associated
293     /// with the given store.
294     pub fn new(
295         mut store: impl AsContextMut,
296         allocator: &ArrayRefPre,
297         elem: &Val,
298         len: u32,
299     ) -> Result<Rooted<ArrayRef>> {
300         Self::_new(store.as_context_mut().0, allocator, elem, len)
301     }
302 
303     pub(crate) fn _new(
304         store: &mut StoreOpaque,
305         allocator: &ArrayRefPre,
306         elem: &Val,
307         len: u32,
308     ) -> Result<Rooted<ArrayRef>> {
309         store.retry_after_gc((), |store, ()| {
310             Self::new_from_iter(store, allocator, RepeatN(elem, len))
311         })
312     }
313 
314     /// Asynchronously allocate a new `array` of the given length, with every
315     /// element initialized to `elem`.
316     ///
317     /// For example, `ArrayRef::new(ctx, pre, &Val::I64(9), 3)` allocates the
318     /// array `[9, 9, 9]`.
319     ///
320     /// This is similar to the `array.new` instruction.
321     ///
322     /// # Automatic Garbage Collection
323     ///
324     /// If the GC heap is at capacity, and there isn't room for allocating this
325     /// new array, then this method will automatically trigger a asynchronous
326     /// collection in an attempt to free up space in the GC heap.
327     ///
328     /// # Errors
329     ///
330     /// If the given `elem` value's type does not match the `allocator`'s array
331     /// type's element type, an error is returned.
332     ///
333     /// If the allocation cannot be satisfied because the GC heap is currently
334     /// out of memory, then a [`GcHeapOutOfMemory<()>`][crate::GcHeapOutOfMemory]
335     /// error is returned. The allocation might succeed on a second attempt if
336     /// you drop some rooted GC references and try again.
337     ///
338     /// # Panics
339     ///
340     /// Panics if your engine is not configured for async; use
341     /// [`ArrayRef::new_async`][crate::ArrayRef::new_async] to perform
342     /// synchronous allocation instead.
343     ///
344     /// Panics if either the allocator or the `elem` value is not associated
345     /// with the given store.
346     #[cfg(feature = "async")]
347     pub async fn new_async(
348         mut store: impl AsContextMut,
349         allocator: &ArrayRefPre,
350         elem: &Val,
351         len: u32,
352     ) -> Result<Rooted<ArrayRef>> {
353         Self::_new_async(store.as_context_mut().0, allocator, elem, len).await
354     }
355 
356     pub(crate) async fn _new_async(
357         store: &mut StoreOpaque,
358         allocator: &ArrayRefPre,
359         elem: &Val,
360         len: u32,
361     ) -> Result<Rooted<ArrayRef>> {
362         store
363             .retry_after_gc_async((), |store, ()| {
364                 Self::new_from_iter(store, allocator, RepeatN(elem, len))
365             })
366             .await
367     }
368 
369     /// Allocate a new array of the given elements.
370     ///
371     /// Does not attempt a GC on OOM; leaves that to callers.
372     fn new_from_iter<'a>(
373         store: &mut StoreOpaque,
374         allocator: &ArrayRefPre,
375         elems: impl Clone + ExactSizeIterator<Item = &'a Val>,
376     ) -> Result<Rooted<ArrayRef>> {
377         assert_eq!(
378             store.id(),
379             allocator.store_id,
380             "attempted to use a `ArrayRefPre` with the wrong store"
381         );
382 
383         // Type check the elements against the element type.
384         for elem in elems.clone() {
385             elem.ensure_matches_ty(store, allocator.ty.element_type().unpack())
386                 .context("element type mismatch")?;
387         }
388 
389         let len = u32::try_from(elems.len()).unwrap();
390 
391         // Allocate the array and write each field value into the appropriate
392         // offset.
393         let arrayref = store
394             .require_gc_store_mut()?
395             .alloc_uninit_array(allocator.type_index(), len, allocator.layout())
396             .context("unrecoverable error when allocating new `arrayref`")?
397             .map_err(|n| GcHeapOutOfMemory::new((), n))?;
398 
399         // From this point on, if we get any errors, then the array is not
400         // fully initialized, so we need to eagerly deallocate it before the
401         // next GC where the collector might try to interpret one of the
402         // uninitialized fields as a GC reference.
403         let mut store = AutoAssertNoGc::new(store);
404         match (|| {
405             let elem_ty = allocator.ty.element_type();
406             for (i, elem) in elems.enumerate() {
407                 let i = u32::try_from(i).unwrap();
408                 debug_assert!(i < len);
409                 arrayref.initialize_elem(&mut store, allocator.layout(), &elem_ty, i, *elem)?;
410             }
411             Ok(())
412         })() {
413             Ok(()) => Ok(Rooted::new(&mut store, arrayref.into())),
414             Err(e) => {
415                 store.require_gc_store_mut()?.dealloc_uninit_array(arrayref);
416                 Err(e)
417             }
418         }
419     }
420 
421     /// Synchronously allocate a new `array` containing the given elements.
422     ///
423     /// For example, `ArrayRef::new_fixed(ctx, pre, &[Val::I64(4), Val::I64(5),
424     /// Val::I64(6)])` allocates the array `[4, 5, 6]`.
425     ///
426     /// This is similar to the `array.new_fixed` instruction.
427     ///
428     /// # Automatic Garbage Collection
429     ///
430     /// If the GC heap is at capacity, and there isn't room for allocating this
431     /// new array, then this method will automatically trigger a synchronous
432     /// collection in an attempt to free up space in the GC heap.
433     ///
434     /// # Errors
435     ///
436     /// If any of the `elems` values' type does not match the `allocator`'s
437     /// array type's element type, an error is returned.
438     ///
439     /// If the allocation cannot be satisfied because the GC heap is currently
440     /// out of memory, then a [`GcHeapOutOfMemory<()>`][crate::GcHeapOutOfMemory]
441     /// error is returned. The allocation might succeed on a second attempt if
442     /// you drop some rooted GC references and try again.
443     ///
444     /// # Panics
445     ///
446     /// Panics if the `store` is configured for async; use
447     /// [`ArrayRef::new_fixed_async`][crate::ArrayRef::new_fixed_async] to
448     /// perform asynchronous allocation instead.
449     ///
450     /// Panics if the allocator or any of the `elems` values are not associated
451     /// with the given store.
452     pub fn new_fixed(
453         mut store: impl AsContextMut,
454         allocator: &ArrayRefPre,
455         elems: &[Val],
456     ) -> Result<Rooted<ArrayRef>> {
457         Self::_new_fixed(store.as_context_mut().0, allocator, elems)
458     }
459 
460     pub(crate) fn _new_fixed(
461         store: &mut StoreOpaque,
462         allocator: &ArrayRefPre,
463         elems: &[Val],
464     ) -> Result<Rooted<ArrayRef>> {
465         store.retry_after_gc((), |store, ()| {
466             Self::new_from_iter(store, allocator, elems.iter())
467         })
468     }
469 
470     /// Asynchronously allocate a new `array` containing the given elements.
471     ///
472     /// For example, `ArrayRef::new_fixed_async(ctx, pre, &[Val::I64(4),
473     /// Val::I64(5), Val::I64(6)])` allocates the array `[4, 5, 6]`.
474     ///
475     /// This is similar to the `array.new_fixed` instruction.
476     ///
477     /// If your engine is not configured for async, use
478     /// [`ArrayRef::new_fixed`][crate::ArrayRef::new_fixed] to perform
479     /// synchronous allocation.
480     ///
481     /// # Automatic Garbage Collection
482     ///
483     /// If the GC heap is at capacity, and there isn't room for allocating this
484     /// new array, then this method will automatically trigger a synchronous
485     /// collection in an attempt to free up space in the GC heap.
486     ///
487     /// # Errors
488     ///
489     /// If any of the `elems` values' type does not match the `allocator`'s
490     /// array type's element type, an error is returned.
491     ///
492     /// If the allocation cannot be satisfied because the GC heap is currently
493     /// out of memory, then a [`GcHeapOutOfMemory<()>`][crate::GcHeapOutOfMemory]
494     /// error is returned. The allocation might succeed on a second attempt if
495     /// you drop some rooted GC references and try again.
496     ///
497     /// # Panics
498     ///
499     /// Panics if the `store` is not configured for async; use
500     /// [`ArrayRef::new_fixed`][crate::ArrayRef::new_fixed] to perform
501     /// synchronous allocation instead.
502     ///
503     /// Panics if the allocator or any of the `elems` values are not associated
504     /// with the given store.
505     #[cfg(feature = "async")]
506     pub async fn new_fixed_async(
507         mut store: impl AsContextMut,
508         allocator: &ArrayRefPre,
509         elems: &[Val],
510     ) -> Result<Rooted<ArrayRef>> {
511         Self::_new_fixed_async(store.as_context_mut().0, allocator, elems).await
512     }
513 
514     pub(crate) async fn _new_fixed_async(
515         store: &mut StoreOpaque,
516         allocator: &ArrayRefPre,
517         elems: &[Val],
518     ) -> Result<Rooted<ArrayRef>> {
519         store
520             .retry_after_gc_async((), |store, ()| {
521                 Self::new_from_iter(store, allocator, elems.iter())
522             })
523             .await
524     }
525 
526     #[inline]
527     pub(crate) fn comes_from_same_store(&self, store: &StoreOpaque) -> bool {
528         self.inner.comes_from_same_store(store)
529     }
530 
531     /// Get this `arrayref`'s type.
532     ///
533     /// # Errors
534     ///
535     /// Return an error if this reference has been unrooted.
536     ///
537     /// # Panics
538     ///
539     /// Panics if this reference is associated with a different store.
540     pub fn ty(&self, store: impl AsContext) -> Result<ArrayType> {
541         self._ty(store.as_context().0)
542     }
543 
544     pub(crate) fn _ty(&self, store: &StoreOpaque) -> Result<ArrayType> {
545         assert!(self.comes_from_same_store(store));
546         let index = self.type_index(store)?;
547         Ok(ArrayType::from_shared_type_index(store.engine(), index))
548     }
549 
550     /// Does this `arrayref` match the given type?
551     ///
552     /// That is, is this array's type a subtype of the given type?
553     ///
554     /// # Errors
555     ///
556     /// Return an error if this reference has been unrooted.
557     ///
558     /// # Panics
559     ///
560     /// Panics if this reference is associated with a different store or if the
561     /// type is not associated with the store's engine.
562     pub fn matches_ty(&self, store: impl AsContext, ty: &ArrayType) -> Result<bool> {
563         self._matches_ty(store.as_context().0, ty)
564     }
565 
566     pub(crate) fn _matches_ty(&self, store: &StoreOpaque, ty: &ArrayType) -> Result<bool> {
567         assert!(self.comes_from_same_store(store));
568         Ok(self._ty(store)?.matches(ty))
569     }
570 
571     pub(crate) fn ensure_matches_ty(&self, store: &StoreOpaque, ty: &ArrayType) -> Result<()> {
572         if !self.comes_from_same_store(store) {
573             bail!("function used with wrong store");
574         }
575         if self._matches_ty(store, ty)? {
576             Ok(())
577         } else {
578             let actual_ty = self._ty(store)?;
579             bail!("type mismatch: expected `(ref {ty})`, found `(ref {actual_ty})`")
580         }
581     }
582 
583     /// Get the length of this array.
584     ///
585     /// # Errors
586     ///
587     /// Return an error if this reference has been unrooted.
588     ///
589     /// # Panics
590     ///
591     /// Panics if this reference is associated with a different store.
592     pub fn len(&self, store: impl AsContext) -> Result<u32> {
593         self._len(store.as_context().0)
594     }
595 
596     pub(crate) fn _len(&self, store: &StoreOpaque) -> Result<u32> {
597         assert!(self.comes_from_same_store(store));
598         let gc_ref = self.inner.try_gc_ref(store)?;
599         debug_assert!({
600             let header = store.require_gc_store()?.header(gc_ref);
601             header.kind().matches(VMGcKind::ArrayRef)
602         });
603         let arrayref = gc_ref.as_arrayref_unchecked();
604         Ok(arrayref.len(store))
605     }
606 
607     /// Get the values of this array's elements.
608     ///
609     /// Note that `i8` and `i16` element values are zero-extended into
610     /// `Val::I32(_)`s.
611     ///
612     /// # Errors
613     ///
614     /// Return an error if this reference has been unrooted.
615     ///
616     /// # Panics
617     ///
618     /// Panics if this reference is associated with a different store.
619     pub fn elems<'a, T: 'static>(
620         &'a self,
621         store: impl Into<StoreContextMut<'a, T>>,
622     ) -> Result<impl ExactSizeIterator<Item = Val> + 'a> {
623         self._elems(store.into().0)
624     }
625 
626     pub(crate) fn _elems<'a>(
627         &'a self,
628         store: &'a mut StoreOpaque,
629     ) -> Result<impl ExactSizeIterator<Item = Val> + 'a> {
630         assert!(self.comes_from_same_store(store));
631         let store = AutoAssertNoGc::new(store);
632 
633         let gc_ref = self.inner.try_gc_ref(&store)?;
634         let header = store.require_gc_store()?.header(gc_ref);
635         debug_assert!(header.kind().matches(VMGcKind::ArrayRef));
636 
637         let len = self._len(&store)?;
638 
639         return Ok(Elems {
640             arrayref: self,
641             store,
642             index: 0,
643             len,
644         });
645 
646         struct Elems<'a, 'b> {
647             arrayref: &'a ArrayRef,
648             store: AutoAssertNoGc<'b>,
649             index: u32,
650             len: u32,
651         }
652 
653         impl Iterator for Elems<'_, '_> {
654             type Item = Val;
655 
656             #[inline]
657             fn next(&mut self) -> Option<Self::Item> {
658                 let i = self.index;
659                 debug_assert!(i <= self.len);
660                 if i >= self.len {
661                     return None;
662                 }
663                 self.index += 1;
664                 Some(self.arrayref._get(&mut self.store, i).unwrap())
665             }
666 
667             #[inline]
668             fn size_hint(&self) -> (usize, Option<usize>) {
669                 let len = self.len - self.index;
670                 let len = usize::try_from(len).unwrap();
671                 (len, Some(len))
672             }
673         }
674 
675         impl ExactSizeIterator for Elems<'_, '_> {
676             #[inline]
677             fn len(&self) -> usize {
678                 let len = self.len - self.index;
679                 usize::try_from(len).unwrap()
680             }
681         }
682     }
683 
684     fn header<'a>(&self, store: &'a AutoAssertNoGc<'_>) -> Result<&'a VMGcHeader> {
685         assert!(self.comes_from_same_store(&store));
686         let gc_ref = self.inner.try_gc_ref(store)?;
687         Ok(store.require_gc_store()?.header(gc_ref))
688     }
689 
690     fn arrayref<'a>(&self, store: &'a AutoAssertNoGc<'_>) -> Result<&'a VMArrayRef> {
691         assert!(self.comes_from_same_store(&store));
692         let gc_ref = self.inner.try_gc_ref(store)?;
693         debug_assert!(self.header(store)?.kind().matches(VMGcKind::ArrayRef));
694         Ok(gc_ref.as_arrayref_unchecked())
695     }
696 
697     pub(crate) fn layout(&self, store: &AutoAssertNoGc<'_>) -> Result<GcArrayLayout> {
698         assert!(self.comes_from_same_store(&store));
699         let type_index = self.type_index(store)?;
700         let layout = store
701             .engine()
702             .signatures()
703             .layout(type_index)
704             .expect("array types should have GC layouts");
705         match layout {
706             GcLayout::Array(a) => Ok(a),
707             GcLayout::Struct(_) => unreachable!(),
708             GcLayout::Exception(_) => unreachable!(),
709         }
710     }
711 
712     fn field_ty(&self, store: &StoreOpaque) -> Result<FieldType> {
713         let ty = self._ty(store)?;
714         Ok(ty.field_type())
715     }
716 
717     /// Get this array's `index`th element.
718     ///
719     /// Note that `i8` and `i16` field values are zero-extended into
720     /// `Val::I32(_)`s.
721     ///
722     /// # Errors
723     ///
724     /// Returns an `Err(_)` if the index is out of bounds or this reference has
725     /// been unrooted.
726     ///
727     /// # Panics
728     ///
729     /// Panics if this reference is associated with a different store.
730     pub fn get(&self, mut store: impl AsContextMut, index: u32) -> Result<Val> {
731         let mut store = AutoAssertNoGc::new(store.as_context_mut().0);
732         self._get(&mut store, index)
733     }
734 
735     pub(crate) fn _get(&self, store: &mut AutoAssertNoGc<'_>, index: u32) -> Result<Val> {
736         assert!(
737             self.comes_from_same_store(store),
738             "attempted to use an array with the wrong store",
739         );
740         let arrayref = self.arrayref(store)?.unchecked_copy();
741         let field_ty = self.field_ty(store)?;
742         let layout = self.layout(store)?;
743         let len = arrayref.len(store);
744         ensure!(
745             index < len,
746             "index out of bounds: the length is {len} but the index is {index}"
747         );
748         Ok(arrayref.read_elem(store, &layout, field_ty.element_type(), index))
749     }
750 
751     /// Set this array's `index`th element.
752     ///
753     /// # Errors
754     ///
755     /// Returns an error in the following scenarios:
756     ///
757     /// * When given a value of the wrong type, such as trying to write an `f32`
758     ///   value into an array of `i64` elements.
759     ///
760     /// * When the array elements are not mutable.
761     ///
762     /// * When `index` is not within the range `0..self.len(ctx)`.
763     ///
764     /// * When `value` is a GC reference that has since been unrooted.
765     ///
766     /// # Panics
767     ///
768     /// Panics if either this reference or the given `value` is associated with
769     /// a different store.
770     pub fn set(&self, mut store: impl AsContextMut, index: u32, value: Val) -> Result<()> {
771         self._set(store.as_context_mut().0, index, value)
772     }
773 
774     pub(crate) fn _set(&self, store: &mut StoreOpaque, index: u32, value: Val) -> Result<()> {
775         assert!(
776             self.comes_from_same_store(store),
777             "attempted to use an array with the wrong store",
778         );
779         assert!(
780             value.comes_from_same_store(store),
781             "attempted to use a value with the wrong store",
782         );
783 
784         let mut store = AutoAssertNoGc::new(store);
785 
786         let field_ty = self.field_ty(&store)?;
787         ensure!(
788             field_ty.mutability().is_var(),
789             "cannot set element {index}: array elements are not mutable"
790         );
791 
792         value
793             .ensure_matches_ty(&store, &field_ty.element_type().unpack())
794             .with_context(|| format!("cannot set element {index}: type mismatch"))?;
795 
796         let layout = self.layout(&store)?;
797         let arrayref = self.arrayref(&store)?.unchecked_copy();
798 
799         let len = arrayref.len(&store);
800         ensure!(
801             index < len,
802             "index out of bounds: the length is {len} but the index is {index}"
803         );
804 
805         arrayref.write_elem(&mut store, &layout, field_ty.element_type(), index, value)
806     }
807 
808     pub(crate) fn type_index(&self, store: &StoreOpaque) -> Result<VMSharedTypeIndex> {
809         let gc_ref = self.inner.try_gc_ref(store)?;
810         let header = store.require_gc_store()?.header(gc_ref);
811         debug_assert!(header.kind().matches(VMGcKind::ArrayRef));
812         Ok(header.ty().expect("arrayrefs should have concrete types"))
813     }
814 
815     /// Create a new `Rooted<ArrayRef>` from the given GC reference.
816     ///
817     /// `gc_ref` should point to a valid `arrayref` and should belong to the
818     /// store's GC heap. Failure to uphold these invariants is memory safe but
819     /// will lead to general incorrectness such as panics or wrong results.
820     pub(crate) fn from_cloned_gc_ref(
821         store: &mut AutoAssertNoGc<'_>,
822         gc_ref: VMGcRef,
823     ) -> Rooted<Self> {
824         debug_assert!(gc_ref.is_arrayref(&*store.unwrap_gc_store().gc_heap));
825         Rooted::new(store, gc_ref)
826     }
827 }
828 
829 unsafe impl WasmTy for Rooted<ArrayRef> {
830     #[inline]
831     fn valtype() -> ValType {
832         ValType::Ref(RefType::new(false, HeapType::Array))
833     }
834 
835     #[inline]
836     fn compatible_with_store(&self, store: &StoreOpaque) -> bool {
837         self.comes_from_same_store(store)
838     }
839 
840     #[inline]
841     fn dynamic_concrete_type_check(
842         &self,
843         store: &StoreOpaque,
844         _nullable: bool,
845         ty: &HeapType,
846     ) -> Result<()> {
847         match ty {
848             HeapType::Any | HeapType::Eq | HeapType::Array => Ok(()),
849             HeapType::ConcreteArray(ty) => self.ensure_matches_ty(store, ty),
850 
851             HeapType::Extern
852             | HeapType::NoExtern
853             | HeapType::Func
854             | HeapType::ConcreteFunc(_)
855             | HeapType::NoFunc
856             | HeapType::I31
857             | HeapType::Struct
858             | HeapType::ConcreteStruct(_)
859             | HeapType::Cont
860             | HeapType::NoCont
861             | HeapType::ConcreteCont(_)
862             | HeapType::Exn
863             | HeapType::NoExn
864             | HeapType::ConcreteExn(_)
865             | HeapType::None => bail!(
866                 "type mismatch: expected `(ref {ty})`, got `(ref {})`",
867                 self._ty(store)?,
868             ),
869         }
870     }
871 
872     fn store(self, store: &mut AutoAssertNoGc<'_>, ptr: &mut MaybeUninit<ValRaw>) -> Result<()> {
873         self.wasm_ty_store(store, ptr, ValRaw::anyref)
874     }
875 
876     unsafe fn load(store: &mut AutoAssertNoGc<'_>, ptr: &ValRaw) -> Self {
877         Self::wasm_ty_load(store, ptr.get_anyref(), ArrayRef::from_cloned_gc_ref)
878     }
879 }
880 
881 unsafe impl WasmTy for Option<Rooted<ArrayRef>> {
882     #[inline]
883     fn valtype() -> ValType {
884         ValType::ARRAYREF
885     }
886 
887     #[inline]
888     fn compatible_with_store(&self, store: &StoreOpaque) -> bool {
889         self.map_or(true, |x| x.comes_from_same_store(store))
890     }
891 
892     #[inline]
893     fn dynamic_concrete_type_check(
894         &self,
895         store: &StoreOpaque,
896         nullable: bool,
897         ty: &HeapType,
898     ) -> Result<()> {
899         match self {
900             Some(s) => Rooted::<ArrayRef>::dynamic_concrete_type_check(s, store, nullable, ty),
901             None => {
902                 ensure!(
903                     nullable,
904                     "expected a non-null reference, but found a null reference"
905                 );
906                 Ok(())
907             }
908         }
909     }
910 
911     #[inline]
912     fn is_vmgcref_and_points_to_object(&self) -> bool {
913         self.is_some()
914     }
915 
916     fn store(self, store: &mut AutoAssertNoGc<'_>, ptr: &mut MaybeUninit<ValRaw>) -> Result<()> {
917         <Rooted<ArrayRef>>::wasm_ty_option_store(self, store, ptr, ValRaw::anyref)
918     }
919 
920     unsafe fn load(store: &mut AutoAssertNoGc<'_>, ptr: &ValRaw) -> Self {
921         <Rooted<ArrayRef>>::wasm_ty_option_load(
922             store,
923             ptr.get_anyref(),
924             ArrayRef::from_cloned_gc_ref,
925         )
926     }
927 }
928 
929 unsafe impl WasmTy for ManuallyRooted<ArrayRef> {
930     #[inline]
931     fn valtype() -> ValType {
932         ValType::Ref(RefType::new(false, HeapType::Array))
933     }
934 
935     #[inline]
936     fn compatible_with_store(&self, store: &StoreOpaque) -> bool {
937         self.comes_from_same_store(store)
938     }
939 
940     #[inline]
941     fn dynamic_concrete_type_check(
942         &self,
943         store: &StoreOpaque,
944         _: bool,
945         ty: &HeapType,
946     ) -> Result<()> {
947         match ty {
948             HeapType::Any | HeapType::Eq | HeapType::Array => Ok(()),
949             HeapType::ConcreteArray(ty) => self.ensure_matches_ty(store, ty),
950 
951             HeapType::Extern
952             | HeapType::NoExtern
953             | HeapType::Func
954             | HeapType::ConcreteFunc(_)
955             | HeapType::NoFunc
956             | HeapType::I31
957             | HeapType::Struct
958             | HeapType::ConcreteStruct(_)
959             | HeapType::Cont
960             | HeapType::NoCont
961             | HeapType::ConcreteCont(_)
962             | HeapType::Exn
963             | HeapType::NoExn
964             | HeapType::ConcreteExn(_)
965             | HeapType::None => bail!(
966                 "type mismatch: expected `(ref {ty})`, got `(ref {})`",
967                 self._ty(store)?,
968             ),
969         }
970     }
971 
972     fn store(self, store: &mut AutoAssertNoGc<'_>, ptr: &mut MaybeUninit<ValRaw>) -> Result<()> {
973         self.wasm_ty_store(store, ptr, ValRaw::anyref)
974     }
975 
976     unsafe fn load(store: &mut AutoAssertNoGc<'_>, ptr: &ValRaw) -> Self {
977         Self::wasm_ty_load(store, ptr.get_anyref(), ArrayRef::from_cloned_gc_ref)
978     }
979 }
980 
981 unsafe impl WasmTy for Option<ManuallyRooted<ArrayRef>> {
982     #[inline]
983     fn valtype() -> ValType {
984         ValType::ARRAYREF
985     }
986 
987     #[inline]
988     fn compatible_with_store(&self, store: &StoreOpaque) -> bool {
989         self.as_ref()
990             .map_or(true, |x| x.comes_from_same_store(store))
991     }
992 
993     #[inline]
994     fn dynamic_concrete_type_check(
995         &self,
996         store: &StoreOpaque,
997         nullable: bool,
998         ty: &HeapType,
999     ) -> Result<()> {
1000         match self {
1001             Some(s) => {
1002                 ManuallyRooted::<ArrayRef>::dynamic_concrete_type_check(s, store, nullable, ty)
1003             }
1004             None => {
1005                 ensure!(
1006                     nullable,
1007                     "expected a non-null reference, but found a null reference"
1008                 );
1009                 Ok(())
1010             }
1011         }
1012     }
1013 
1014     #[inline]
1015     fn is_vmgcref_and_points_to_object(&self) -> bool {
1016         self.is_some()
1017     }
1018 
1019     fn store(self, store: &mut AutoAssertNoGc<'_>, ptr: &mut MaybeUninit<ValRaw>) -> Result<()> {
1020         <ManuallyRooted<ArrayRef>>::wasm_ty_option_store(self, store, ptr, ValRaw::anyref)
1021     }
1022 
1023     unsafe fn load(store: &mut AutoAssertNoGc<'_>, ptr: &ValRaw) -> Self {
1024         <ManuallyRooted<ArrayRef>>::wasm_ty_option_load(
1025             store,
1026             ptr.get_anyref(),
1027             ArrayRef::from_cloned_gc_ref,
1028         )
1029     }
1030 }
1031