725 lines
45 KiB
HTML
725 lines
45 KiB
HTML
<!DOCTYPE html>
|
||
<html lang="en">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<title>Validating References with Lifetimes</title>
|
||
</head>
|
||
<body>
|
||
<h2 id="validating-references-with-lifetimes"><a class="header" href="#validating-references-with-lifetimes">Validating References with Lifetimes</a></h2>
|
||
<p>Lifetimes are another kind of generic that we’ve already been using. Rather
|
||
than ensuring that a type has the behavior we want, lifetimes ensure that
|
||
references are valid as long as we need them to be.</p>
|
||
<p>One detail we didn’t discuss in the <a href="../ch04/ch04-02-references-and-borrowing.html#references-and-borrowing">“References and
|
||
Borrowing”</a><!-- ignore --> section in Chapter 4 is
|
||
that every reference in Rust has a lifetime, which is the scope for which
|
||
that reference is valid. Most of the time, lifetimes are implicit and inferred,
|
||
just like most of the time, types are inferred. We are only required to
|
||
annotate types when multiple types are possible. In a similar way, we must
|
||
annotate lifetimes when the lifetimes of references could be related in a few
|
||
different ways. Rust requires us to annotate the relationships using generic
|
||
lifetime parameters to ensure that the actual references used at runtime will
|
||
definitely be valid.</p>
|
||
<p>Annotating lifetimes is not even a concept most other programming languages
|
||
have, so this is going to feel unfamiliar. Although we won’t cover lifetimes in
|
||
their entirety in this chapter, we’ll discuss common ways you might encounter
|
||
lifetime syntax so that you can get comfortable with the concept.</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="preventing-dangling-references-with-lifetimes"></a></p>
|
||
<h3 id="dangling-references"><a class="header" href="#dangling-references">Dangling References</a></h3>
|
||
<p>The main aim of lifetimes is to prevent dangling references, which, if they
|
||
were allowed to exist, would cause a program to reference data other than the
|
||
data it’s intended to reference. Consider the program in Listing 10-16, which
|
||
has an outer scope and an inner scope.</p>
|
||
<figure class="listing" id="listing-10-16">
|
||
<pre><code class="language-rust ignore does_not_compile">fn main() {
|
||
let r;
|
||
|
||
{
|
||
let x = 5;
|
||
r = &x;
|
||
}
|
||
|
||
println!("r: {r}");
|
||
}</code></pre>
|
||
<figcaption><a href="#listing-10-16">Listing 10-16</a>: An attempt to use a reference whose value has gone out of scope</figcaption>
|
||
</figure>
|
||
<section class="note" aria-role="note">
|
||
<p>Note: The examples in Listings 10-16, 10-17, and 10-23 declare variables
|
||
without giving them an initial value, so the variable name exists in the outer
|
||
scope. At first glance, this might appear to be in conflict with Rust having
|
||
no null values. However, if we try to use a variable before giving it a value,
|
||
we’ll get a compile-time error, which shows that indeed Rust does not allow
|
||
null values.</p>
|
||
</section>
|
||
<p>The outer scope declares a variable named <code>r</code> with no initial value, and the
|
||
inner scope declares a variable named <code>x</code> with the initial value of <code>5</code>. Inside
|
||
the inner scope, we attempt to set the value of <code>r</code> as a reference to <code>x</code>.
|
||
Then, the inner scope ends, and we attempt to print the value in <code>r</code>. This code
|
||
won’t compile, because the value that <code>r</code> is referring to has gone out of scope
|
||
before we try to use it. Here is the error message:</p>
|
||
<pre><code class="language-console">$ cargo run
|
||
Compiling chapter10 v0.1.0 (file:///projects/chapter10)
|
||
error[E0597]: `x` does not live long enough
|
||
--> src/main.rs:6:13
|
||
|
|
||
5 | let x = 5;
|
||
| - binding `x` declared here
|
||
6 | r = &x;
|
||
| ^^ borrowed value does not live long enough
|
||
7 | }
|
||
| - `x` dropped here while still borrowed
|
||
8 |
|
||
9 | println!("r: {r}");
|
||
| - borrow later used here
|
||
|
||
For more information about this error, try `rustc --explain E0597`.
|
||
error: could not compile `chapter10` (bin "chapter10") due to 1 previous error
|
||
</code></pre>
|
||
<p>The error message says that the variable <code>x</code> “does not live long enough.” The
|
||
reason is that <code>x</code> will be out of scope when the inner scope ends on line 7.
|
||
But <code>r</code> is still valid for the outer scope; because its scope is larger, we say
|
||
that it “lives longer.” If Rust allowed this code to work, <code>r</code> would be
|
||
referencing memory that was deallocated when <code>x</code> went out of scope, and
|
||
anything we tried to do with <code>r</code> wouldn’t work correctly. So, how does Rust
|
||
determine that this code is invalid? It uses a borrow checker.</p>
|
||
<h3 id="the-borrow-checker"><a class="header" href="#the-borrow-checker">The Borrow Checker</a></h3>
|
||
<p>The Rust compiler has a <em>borrow checker</em> that compares scopes to determine
|
||
whether all borrows are valid. Listing 10-17 shows the same code as Listing
|
||
10-16 but with annotations showing the lifetimes of the variables.</p>
|
||
<figure class="listing" id="listing-10-17">
|
||
<pre><code class="language-rust ignore does_not_compile">fn main() {
|
||
let r; // ---------+-- 'a
|
||
// |
|
||
{ // |
|
||
let x = 5; // -+-- 'b |
|
||
r = &x; // | |
|
||
} // -+ |
|
||
// |
|
||
println!("r: {r}"); // |
|
||
} // ---------+</code></pre>
|
||
<figcaption><a href="#listing-10-17">Listing 10-17</a>: Annotations of the lifetimes of <code>r</code> and <code>x</code>, named <code>'a</code> and <code>'b</code>, respectively</figcaption>
|
||
</figure>
|
||
<p>Here, we’ve annotated the lifetime of <code>r</code> with <code>'a</code> and the lifetime of <code>x</code>
|
||
with <code>'b</code>. As you can see, the inner <code>'b</code> block is much smaller than the outer
|
||
<code>'a</code> lifetime block. At compile time, Rust compares the size of the two
|
||
lifetimes and sees that <code>r</code> has a lifetime of <code>'a</code> but that it refers to memory
|
||
with a lifetime of <code>'b</code>. The program is rejected because <code>'b</code> is shorter than
|
||
<code>'a</code>: The subject of the reference doesn’t live as long as the reference.</p>
|
||
<p>Listing 10-18 fixes the code so that it doesn’t have a dangling reference and
|
||
it compiles without any errors.</p>
|
||
<figure class="listing" id="listing-10-18">
|
||
<pre class="playground"><code class="language-rust edition2024">fn main() {
|
||
let x = 5; // ----------+-- 'b
|
||
// |
|
||
let r = &x; // --+-- 'a |
|
||
// | |
|
||
println!("r: {r}"); // | |
|
||
// --+ |
|
||
} // ----------+</code></pre>
|
||
<figcaption><a href="#listing-10-18">Listing 10-18</a>: A valid reference because the data has a longer lifetime than the reference</figcaption>
|
||
</figure>
|
||
<p>Here, <code>x</code> has the lifetime <code>'b</code>, which in this case is larger than <code>'a</code>. This
|
||
means <code>r</code> can reference <code>x</code> because Rust knows that the reference in <code>r</code> will
|
||
always be valid while <code>x</code> is valid.</p>
|
||
<p>Now that you know where the lifetimes of references are and how Rust analyzes
|
||
lifetimes to ensure that references will always be valid, let’s explore generic
|
||
lifetimes in function parameters and return values.</p>
|
||
<h3 id="generic-lifetimes-in-functions"><a class="header" href="#generic-lifetimes-in-functions">Generic Lifetimes in Functions</a></h3>
|
||
<p>We’ll write a function that returns the longer of two string slices. This
|
||
function will take two string slices and return a single string slice. After
|
||
we’ve implemented the <code>longest</code> function, the code in Listing 10-19 should
|
||
print <code>The longest string is abcd</code>.</p>
|
||
<figure class="listing" id="listing-10-19">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre><code class="language-rust ignore">fn main() {
|
||
let string1 = String::from("abcd");
|
||
let string2 = "xyz";
|
||
|
||
let result = longest(string1.as_str(), string2);
|
||
println!("The longest string is {result}");
|
||
}</code></pre>
|
||
<figcaption><a href="#listing-10-19">Listing 10-19</a>: A <code>main</code> function that calls the <code>longest</code> function to find the longer of two string slices</figcaption>
|
||
</figure>
|
||
<p>Note that we want the function to take string slices, which are references,
|
||
rather than strings, because we don’t want the <code>longest</code> function to take
|
||
ownership of its parameters. Refer to <a href="../ch04/ch04-03-slices.html#string-slices-as-parameters">“String Slices as
|
||
Parameters”</a><!-- ignore --> in Chapter 4 for more
|
||
discussion about why the parameters we use in Listing 10-19 are the ones we
|
||
want.</p>
|
||
<p>If we try to implement the <code>longest</code> function as shown in Listing 10-20, it
|
||
won’t compile.</p>
|
||
<figure class="listing" id="listing-10-20">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre><code class="language-rust ignore does_not_compile"><span class="boring">fn main() {
|
||
</span><span class="boring"> let string1 = String::from("abcd");
|
||
</span><span class="boring"> let string2 = "xyz";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let result = longest(string1.as_str(), string2);
|
||
</span><span class="boring"> println!("The longest string is {result}");
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>fn longest(x: &str, y: &str) -> &str {
|
||
if x.len() > y.len() { x } else { y }
|
||
}</code></pre>
|
||
<figcaption><a href="#listing-10-20">Listing 10-20</a>: An implementation of the <code>longest</code> function that returns the longer of two string slices but does not yet compile</figcaption>
|
||
</figure>
|
||
<p>Instead, we get the following error that talks about lifetimes:</p>
|
||
<pre><code class="language-console">$ cargo run
|
||
Compiling chapter10 v0.1.0 (file:///projects/chapter10)
|
||
error[E0106]: missing lifetime specifier
|
||
--> src/main.rs:9:33
|
||
|
|
||
9 | fn longest(x: &str, y: &str) -> &str {
|
||
| ---- ---- ^ expected named lifetime parameter
|
||
|
|
||
= help: this function's return type contains a borrowed value, but the signature does not say whether it is borrowed from `x` or `y`
|
||
help: consider introducing a named lifetime parameter
|
||
|
|
||
9 | fn longest<'a>(x: &'a str, y: &'a str) -> &'a str {
|
||
| ++++ ++ ++ ++
|
||
|
||
For more information about this error, try `rustc --explain E0106`.
|
||
error: could not compile `chapter10` (bin "chapter10") due to 1 previous error
|
||
</code></pre>
|
||
<p>The help text reveals that the return type needs a generic lifetime parameter
|
||
on it because Rust can’t tell whether the reference being returned refers to
|
||
<code>x</code> or <code>y</code>. Actually, we don’t know either, because the <code>if</code> block in the body
|
||
of this function returns a reference to <code>x</code> and the <code>else</code> block returns a
|
||
reference to <code>y</code>!</p>
|
||
<p>When we’re defining this function, we don’t know the concrete values that will
|
||
be passed into this function, so we don’t know whether the <code>if</code> case or the
|
||
<code>else</code> case will execute. We also don’t know the concrete lifetimes of the
|
||
references that will be passed in, so we can’t look at the scopes as we did in
|
||
Listings 10-17 and 10-18 to determine whether the reference we return will
|
||
always be valid. The borrow checker can’t determine this either, because it
|
||
doesn’t know how the lifetimes of <code>x</code> and <code>y</code> relate to the lifetime of the
|
||
return value. To fix this error, we’ll add generic lifetime parameters that
|
||
define the relationship between the references so that the borrow checker can
|
||
perform its analysis.</p>
|
||
<h3 id="lifetime-annotation-syntax"><a class="header" href="#lifetime-annotation-syntax">Lifetime Annotation Syntax</a></h3>
|
||
<p>Lifetime annotations don’t change how long any of the references live. Rather,
|
||
they describe the relationships of the lifetimes of multiple references to each
|
||
other without affecting the lifetimes. Just as functions can accept any type
|
||
when the signature specifies a generic type parameter, functions can accept
|
||
references with any lifetime by specifying a generic lifetime parameter.</p>
|
||
<p>Lifetime annotations have a slightly unusual syntax: The names of lifetime
|
||
parameters must start with an apostrophe (<code>'</code>) and are usually all lowercase
|
||
and very short, like generic types. Most people use the name <code>'a</code> for the first
|
||
lifetime annotation. We place lifetime parameter annotations after the <code>&</code> of a
|
||
reference, using a space to separate the annotation from the reference’s type.</p>
|
||
<p>Here are some examples—a reference to an <code>i32</code> without a lifetime parameter, a
|
||
reference to an <code>i32</code> that has a lifetime parameter named <code>'a</code>, and a mutable
|
||
reference to an <code>i32</code> that also has the lifetime <code>'a</code>:</p>
|
||
<pre><code class="language-rust ignore">&i32 // a reference
|
||
&'a i32 // a reference with an explicit lifetime
|
||
&'a mut i32 // a mutable reference with an explicit lifetime</code></pre>
|
||
<p>One lifetime annotation by itself doesn’t have much meaning, because the
|
||
annotations are meant to tell Rust how generic lifetime parameters of multiple
|
||
references relate to each other. Let’s examine how the lifetime annotations
|
||
relate to each other in the context of the <code>longest</code> function.</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="lifetime-annotations-in-function-signatures"></a></p>
|
||
<h3 id="in-function-signatures"><a class="header" href="#in-function-signatures">In Function Signatures</a></h3>
|
||
<p>To use lifetime annotations in function signatures, we need to declare the
|
||
generic lifetime parameters inside angle brackets between the function name and
|
||
the parameter list, just as we did with generic type parameters.</p>
|
||
<p>We want the signature to express the following constraint: The returned
|
||
reference will be valid as long as both of the parameters are valid. This is
|
||
the relationship between lifetimes of the parameters and the return value.
|
||
We’ll name the lifetime <code>'a</code> and then add it to each reference, as shown in
|
||
Listing 10-21.</p>
|
||
<figure class="listing" id="listing-10-21">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">fn main() {
|
||
</span><span class="boring"> let string1 = String::from("abcd");
|
||
</span><span class="boring"> let string2 = "xyz";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let result = longest(string1.as_str(), string2);
|
||
</span><span class="boring"> println!("The longest string is {result}");
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>fn longest<'a>(x: &'a str, y: &'a str) -> &'a str {
|
||
if x.len() > y.len() { x } else { y }
|
||
}</code></pre>
|
||
<figcaption><a href="#listing-10-21">Listing 10-21</a>: The <code>longest</code> function definition specifying that all the references in the signature must have the same lifetime <code>'a</code></figcaption>
|
||
</figure>
|
||
<p>This code should compile and produce the result we want when we use it with the
|
||
<code>main</code> function in Listing 10-19.</p>
|
||
<p>The function signature now tells Rust that for some lifetime <code>'a</code>, the function
|
||
takes two parameters, both of which are string slices that live at least as
|
||
long as lifetime <code>'a</code>. The function signature also tells Rust that the string
|
||
slice returned from the function will live at least as long as lifetime <code>'a</code>.
|
||
In practice, it means that the lifetime of the reference returned by the
|
||
<code>longest</code> function is the same as the smaller of the lifetimes of the values
|
||
referred to by the function arguments. These relationships are what we want
|
||
Rust to use when analyzing this code.</p>
|
||
<p>Remember, when we specify the lifetime parameters in this function signature,
|
||
we’re not changing the lifetimes of any values passed in or returned. Rather,
|
||
we’re specifying that the borrow checker should reject any values that don’t
|
||
adhere to these constraints. Note that the <code>longest</code> function doesn’t need to
|
||
know exactly how long <code>x</code> and <code>y</code> will live, only that some scope can be
|
||
substituted for <code>'a</code> that will satisfy this signature.</p>
|
||
<p>When annotating lifetimes in functions, the annotations go in the function
|
||
signature, not in the function body. The lifetime annotations become part of
|
||
the contract of the function, much like the types in the signature. Having
|
||
function signatures contain the lifetime contract means the analysis the Rust
|
||
compiler does can be simpler. If there’s a problem with the way a function is
|
||
annotated or the way it is called, the compiler errors can point to the part of
|
||
our code and the constraints more precisely. If, instead, the Rust compiler
|
||
made more inferences about what we intended the relationships of the lifetimes
|
||
to be, the compiler might only be able to point to a use of our code many steps
|
||
away from the cause of the problem.</p>
|
||
<p>When we pass concrete references to <code>longest</code>, the concrete lifetime that is
|
||
substituted for <code>'a</code> is the part of the scope of <code>x</code> that overlaps with the
|
||
scope of <code>y</code>. In other words, the generic lifetime <code>'a</code> will get the concrete
|
||
lifetime that is equal to the smaller of the lifetimes of <code>x</code> and <code>y</code>. Because
|
||
we’ve annotated the returned reference with the same lifetime parameter <code>'a</code>,
|
||
the returned reference will also be valid for the length of the smaller of the
|
||
lifetimes of <code>x</code> and <code>y</code>.</p>
|
||
<p>Let’s look at how the lifetime annotations restrict the <code>longest</code> function by
|
||
passing in references that have different concrete lifetimes. Listing 10-22 is
|
||
a straightforward example.</p>
|
||
<figure class="listing" id="listing-10-22">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre class="playground"><code class="language-rust edition2024">fn main() {
|
||
let string1 = String::from("long string is long");
|
||
|
||
{
|
||
let string2 = String::from("xyz");
|
||
let result = longest(string1.as_str(), string2.as_str());
|
||
println!("The longest string is {result}");
|
||
}
|
||
}
|
||
<span class="boring">
|
||
</span><span class="boring">fn longest<'a>(x: &'a str, y: &'a str) -> &'a str {
|
||
</span><span class="boring"> if x.len() > y.len() { x } else { y }
|
||
</span><span class="boring">}</span></code></pre>
|
||
<figcaption><a href="#listing-10-22">Listing 10-22</a>: Using the <code>longest</code> function with references to <code>String</code> values that have different concrete lifetimes</figcaption>
|
||
</figure>
|
||
<p>In this example, <code>string1</code> is valid until the end of the outer scope, <code>string2</code>
|
||
is valid until the end of the inner scope, and <code>result</code> references something
|
||
that is valid until the end of the inner scope. Run this code and you’ll see
|
||
that the borrow checker approves; it will compile and print <code>The longest string is long string is long</code>.</p>
|
||
<p>Next, let’s try an example that shows that the lifetime of the reference in
|
||
<code>result</code> must be the smaller lifetime of the two arguments. We’ll move the
|
||
declaration of the <code>result</code> variable outside the inner scope but leave the
|
||
assignment of the value to the <code>result</code> variable inside the scope with
|
||
<code>string2</code>. Then, we’ll move the <code>println!</code> that uses <code>result</code> to outside the
|
||
inner scope, after the inner scope has ended. The code in Listing 10-23 will
|
||
not compile.</p>
|
||
<figure class="listing" id="listing-10-23">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre><code class="language-rust ignore does_not_compile">fn main() {
|
||
let string1 = String::from("long string is long");
|
||
let result;
|
||
{
|
||
let string2 = String::from("xyz");
|
||
result = longest(string1.as_str(), string2.as_str());
|
||
}
|
||
println!("The longest string is {result}");
|
||
}
|
||
<span class="boring">
|
||
</span><span class="boring">fn longest<'a>(x: &'a str, y: &'a str) -> &'a str {
|
||
</span><span class="boring"> if x.len() > y.len() { x } else { y }
|
||
</span><span class="boring">}</span></code></pre>
|
||
<figcaption><a href="#listing-10-23">Listing 10-23</a>: Attempting to use <code>result</code> after <code>string2</code> has gone out of scope</figcaption>
|
||
</figure>
|
||
<p>When we try to compile this code, we get this error:</p>
|
||
<pre><code class="language-console">$ cargo run
|
||
Compiling chapter10 v0.1.0 (file:///projects/chapter10)
|
||
error[E0597]: `string2` does not live long enough
|
||
--> src/main.rs:6:44
|
||
|
|
||
5 | let string2 = String::from("xyz");
|
||
| ------- binding `string2` declared here
|
||
6 | result = longest(string1.as_str(), string2.as_str());
|
||
| ^^^^^^^ borrowed value does not live long enough
|
||
7 | }
|
||
| - `string2` dropped here while still borrowed
|
||
8 | println!("The longest string is {result}");
|
||
| ------ borrow later used here
|
||
|
||
For more information about this error, try `rustc --explain E0597`.
|
||
error: could not compile `chapter10` (bin "chapter10") due to 1 previous error
|
||
</code></pre>
|
||
<p>The error shows that for <code>result</code> to be valid for the <code>println!</code> statement,
|
||
<code>string2</code> would need to be valid until the end of the outer scope. Rust knows
|
||
this because we annotated the lifetimes of the function parameters and return
|
||
values using the same lifetime parameter <code>'a</code>.</p>
|
||
<p>As humans, we can look at this code and see that <code>string1</code> is longer than
|
||
<code>string2</code>, and therefore, <code>result</code> will contain a reference to <code>string1</code>.
|
||
Because <code>string1</code> has not gone out of scope yet, a reference to <code>string1</code> will
|
||
still be valid for the <code>println!</code> statement. However, the compiler can’t see
|
||
that the reference is valid in this case. We’ve told Rust that the lifetime of
|
||
the reference returned by the <code>longest</code> function is the same as the smaller of
|
||
the lifetimes of the references passed in. Therefore, the borrow checker
|
||
disallows the code in Listing 10-23 as possibly having an invalid reference.</p>
|
||
<p>Try designing more experiments that vary the values and lifetimes of the
|
||
references passed in to the <code>longest</code> function and how the returned reference
|
||
is used. Make hypotheses about whether or not your experiments will pass the
|
||
borrow checker before you compile; then, check to see if you’re right!</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="thinking-in-terms-of-lifetimes"></a></p>
|
||
<h3 id="relationships"><a class="header" href="#relationships">Relationships</a></h3>
|
||
<p>The way in which you need to specify lifetime parameters depends on what your
|
||
function is doing. For example, if we changed the implementation of the
|
||
<code>longest</code> function to always return the first parameter rather than the longest
|
||
string slice, we wouldn’t need to specify a lifetime on the <code>y</code> parameter. The
|
||
following code will compile:</p>
|
||
<figure class="listing">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">fn main() {
|
||
</span><span class="boring"> let string1 = String::from("abcd");
|
||
</span><span class="boring"> let string2 = "efghijklmnopqrstuvwxyz";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let result = longest(string1.as_str(), string2);
|
||
</span><span class="boring"> println!("The longest string is {result}");
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>fn longest<'a>(x: &'a str, y: &str) -> &'a str {
|
||
x
|
||
}</code></pre>
|
||
</figure>
|
||
<p>We’ve specified a lifetime parameter <code>'a</code> for the parameter <code>x</code> and the return
|
||
type, but not for the parameter <code>y</code>, because the lifetime of <code>y</code> does not have
|
||
any relationship with the lifetime of <code>x</code> or the return value.</p>
|
||
<p>When returning a reference from a function, the lifetime parameter for the
|
||
return type needs to match the lifetime parameter for one of the parameters. If
|
||
the reference returned does <em>not</em> refer to one of the parameters, it must refer
|
||
to a value created within this function. However, this would be a dangling
|
||
reference because the value will go out of scope at the end of the function.
|
||
Consider this attempted implementation of the <code>longest</code> function that won’t
|
||
compile:</p>
|
||
<figure class="listing">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre><code class="language-rust ignore does_not_compile"><span class="boring">fn main() {
|
||
</span><span class="boring"> let string1 = String::from("abcd");
|
||
</span><span class="boring"> let string2 = "xyz";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let result = longest(string1.as_str(), string2);
|
||
</span><span class="boring"> println!("The longest string is {result}");
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>fn longest<'a>(x: &str, y: &str) -> &'a str {
|
||
let result = String::from("really long string");
|
||
result.as_str()
|
||
}</code></pre>
|
||
</figure>
|
||
<p>Here, even though we’ve specified a lifetime parameter <code>'a</code> for the return
|
||
type, this implementation will fail to compile because the return value
|
||
lifetime is not related to the lifetime of the parameters at all. Here is the
|
||
error message we get:</p>
|
||
<pre><code class="language-console">$ cargo run
|
||
Compiling chapter10 v0.1.0 (file:///projects/chapter10)
|
||
error[E0515]: cannot return value referencing local variable `result`
|
||
--> src/main.rs:11:5
|
||
|
|
||
11 | result.as_str()
|
||
| ------^^^^^^^^^
|
||
| |
|
||
| returns a value referencing data owned by the current function
|
||
| `result` is borrowed here
|
||
|
||
For more information about this error, try `rustc --explain E0515`.
|
||
error: could not compile `chapter10` (bin "chapter10") due to 1 previous error
|
||
</code></pre>
|
||
<p>The problem is that <code>result</code> goes out of scope and gets cleaned up at the end
|
||
of the <code>longest</code> function. We’re also trying to return a reference to <code>result</code>
|
||
from the function. There is no way we can specify lifetime parameters that
|
||
would change the dangling reference, and Rust won’t let us create a dangling
|
||
reference. In this case, the best fix would be to return an owned data type
|
||
rather than a reference so that the calling function is then responsible for
|
||
cleaning up the value.</p>
|
||
<p>Ultimately, lifetime syntax is about connecting the lifetimes of various
|
||
parameters and return values of functions. Once they’re connected, Rust has
|
||
enough information to allow memory-safe operations and disallow operations that
|
||
would create dangling pointers or otherwise violate memory safety.</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="lifetime-annotations-in-struct-definitions"></a></p>
|
||
<h3 id="in-struct-definitions"><a class="header" href="#in-struct-definitions">In Struct Definitions</a></h3>
|
||
<p>So far, the structs we’ve defined all hold owned types. We can define structs
|
||
to hold references, but in that case, we would need to add a lifetime
|
||
annotation on every reference in the struct’s definition. Listing 10-24 has a
|
||
struct named <code>ImportantExcerpt</code> that holds a string slice.</p>
|
||
<figure class="listing" id="listing-10-24">
|
||
<span class="file-name">Filename: src/main.rs</span>
|
||
<pre class="playground"><code class="language-rust edition2024">struct ImportantExcerpt<'a> {
|
||
part: &'a str,
|
||
}
|
||
|
||
fn main() {
|
||
let novel = String::from("Call me Ishmael. Some years ago...");
|
||
let first_sentence = novel.split('.').next().unwrap();
|
||
let i = ImportantExcerpt {
|
||
part: first_sentence,
|
||
};
|
||
}</code></pre>
|
||
<figcaption><a href="#listing-10-24">Listing 10-24</a>: A struct that holds a reference, requiring a lifetime annotation</figcaption>
|
||
</figure>
|
||
<p>This struct has the single field <code>part</code> that holds a string slice, which is a
|
||
reference. As with generic data types, we declare the name of the generic
|
||
lifetime parameter inside angle brackets after the name of the struct so that
|
||
we can use the lifetime parameter in the body of the struct definition. This
|
||
annotation means an instance of <code>ImportantExcerpt</code> can’t outlive the reference
|
||
it holds in its <code>part</code> field.</p>
|
||
<p>The <code>main</code> function here creates an instance of the <code>ImportantExcerpt</code> struct
|
||
that holds a reference to the first sentence of the <code>String</code> owned by the
|
||
variable <code>novel</code>. The data in <code>novel</code> exists before the <code>ImportantExcerpt</code>
|
||
instance is created. In addition, <code>novel</code> doesn’t go out of scope until after
|
||
the <code>ImportantExcerpt</code> goes out of scope, so the reference in the
|
||
<code>ImportantExcerpt</code> instance is valid.</p>
|
||
<h3 id="lifetime-elision"><a class="header" href="#lifetime-elision">Lifetime Elision</a></h3>
|
||
<p>You’ve learned that every reference has a lifetime and that you need to specify
|
||
lifetime parameters for functions or structs that use references. However, we
|
||
had a function in Listing 4-9, shown again in Listing 10-25, that compiled
|
||
without lifetime annotations.</p>
|
||
<figure class="listing" id="listing-10-25">
|
||
<span class="file-name">Filename: src/lib.rs</span>
|
||
<pre class="playground"><code class="language-rust edition2024">fn first_word(s: &str) -> &str {
|
||
let bytes = s.as_bytes();
|
||
|
||
for (i, &item) in bytes.iter().enumerate() {
|
||
if item == b' ' {
|
||
return &s[0..i];
|
||
}
|
||
}
|
||
|
||
&s[..]
|
||
}
|
||
<span class="boring">
|
||
</span><span class="boring">fn main() {
|
||
</span><span class="boring"> let my_string = String::from("hello world");
|
||
</span><span class="boring">
|
||
</span><span class="boring"> // first_word works on slices of `String`s
|
||
</span><span class="boring"> let word = first_word(&my_string[..]);
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let my_string_literal = "hello world";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> // first_word works on slices of string literals
|
||
</span><span class="boring"> let word = first_word(&my_string_literal[..]);
|
||
</span><span class="boring">
|
||
</span><span class="boring"> // Because string literals *are* string slices already,
|
||
</span><span class="boring"> // this works too, without the slice syntax!
|
||
</span><span class="boring"> let word = first_word(my_string_literal);
|
||
</span><span class="boring">}</span></code></pre>
|
||
<figcaption><a href="#listing-10-25">Listing 10-25</a>: A function we defined in Listing 4-9 that compiled without lifetime annotations, even though the parameter and return type are references</figcaption>
|
||
</figure>
|
||
<p>The reason this function compiles without lifetime annotations is historical:
|
||
In early versions (pre-1.0) of Rust, this code wouldn’t have compiled, because
|
||
every reference needed an explicit lifetime. At that time, the function
|
||
signature would have been written like this:</p>
|
||
<pre><code class="language-rust ignore">fn first_word<'a>(s: &'a str) -> &'a str {</code></pre>
|
||
<p>After writing a lot of Rust code, the Rust team found that Rust programmers
|
||
were entering the same lifetime annotations over and over in particular
|
||
situations. These situations were predictable and followed a few deterministic
|
||
patterns. The developers programmed these patterns into the compiler’s code so
|
||
that the borrow checker could infer the lifetimes in these situations and
|
||
wouldn’t need explicit annotations.</p>
|
||
<p>This piece of Rust history is relevant because it’s possible that more
|
||
deterministic patterns will emerge and be added to the compiler. In the future,
|
||
even fewer lifetime annotations might be required.</p>
|
||
<p>The patterns programmed into Rust’s analysis of references are called the
|
||
<em>lifetime elision rules</em>. These aren’t rules for programmers to follow; they’re
|
||
a set of particular cases that the compiler will consider, and if your code
|
||
fits these cases, you don’t need to write the lifetimes explicitly.</p>
|
||
<p>The elision rules don’t provide full inference. If there is still ambiguity
|
||
about what lifetimes the references have after Rust applies the rules, the
|
||
compiler won’t guess what the lifetime of the remaining references should be.
|
||
Instead of guessing, the compiler will give you an error that you can resolve
|
||
by adding the lifetime annotations.</p>
|
||
<p>Lifetimes on function or method parameters are called <em>input lifetimes</em>, and
|
||
lifetimes on return values are called <em>output lifetimes</em>.</p>
|
||
<p>The compiler uses three rules to figure out the lifetimes of the references
|
||
when there aren’t explicit annotations. The first rule applies to input
|
||
lifetimes, and the second and third rules apply to output lifetimes. If the
|
||
compiler gets to the end of the three rules and there are still references for
|
||
which it can’t figure out lifetimes, the compiler will stop with an error.
|
||
These rules apply to <code>fn</code> definitions as well as <code>impl</code> blocks.</p>
|
||
<p>The first rule is that the compiler assigns a lifetime parameter to each
|
||
parameter that’s a reference. In other words, a function with one parameter
|
||
gets one lifetime parameter: <code>fn foo<'a>(x: &'a i32)</code>; a function with two
|
||
parameters gets two separate lifetime parameters: <code>fn foo<'a, 'b>(x: &'a i32, y: &'b i32)</code>; and so on.</p>
|
||
<p>The second rule is that, if there is exactly one input lifetime parameter, that
|
||
lifetime is assigned to all output lifetime parameters: <code>fn foo<'a>(x: &'a i32) -> &'a i32</code>.</p>
|
||
<p>The third rule is that, if there are multiple input lifetime parameters, but
|
||
one of them is <code>&self</code> or <code>&mut self</code> because this is a method, the lifetime of
|
||
<code>self</code> is assigned to all output lifetime parameters. This third rule makes
|
||
methods much nicer to read and write because fewer symbols are necessary.</p>
|
||
<p>Let’s pretend we’re the compiler. We’ll apply these rules to figure out the
|
||
lifetimes of the references in the signature of the <code>first_word</code> function in
|
||
Listing 10-25. The signature starts without any lifetimes associated with the
|
||
references:</p>
|
||
<pre><code class="language-rust ignore">fn first_word(s: &str) -> &str {</code></pre>
|
||
<p>Then, the compiler applies the first rule, which specifies that each parameter
|
||
gets its own lifetime. We’ll call it <code>'a</code> as usual, so now the signature is
|
||
this:</p>
|
||
<pre><code class="language-rust ignore">fn first_word<'a>(s: &'a str) -> &str {</code></pre>
|
||
<p>The second rule applies because there is exactly one input lifetime. The second
|
||
rule specifies that the lifetime of the one input parameter gets assigned to
|
||
the output lifetime, so the signature is now this:</p>
|
||
<pre><code class="language-rust ignore">fn first_word<'a>(s: &'a str) -> &'a str {</code></pre>
|
||
<p>Now all the references in this function signature have lifetimes, and the
|
||
compiler can continue its analysis without needing the programmer to annotate
|
||
the lifetimes in this function signature.</p>
|
||
<p>Let’s look at another example, this time using the <code>longest</code> function that had
|
||
no lifetime parameters when we started working with it in Listing 10-20:</p>
|
||
<pre><code class="language-rust ignore">fn longest(x: &str, y: &str) -> &str {</code></pre>
|
||
<p>Let’s apply the first rule: Each parameter gets its own lifetime. This time we
|
||
have two parameters instead of one, so we have two lifetimes:</p>
|
||
<pre><code class="language-rust ignore">fn longest<'a, 'b>(x: &'a str, y: &'b str) -> &str {</code></pre>
|
||
<p>You can see that the second rule doesn’t apply, because there is more than one
|
||
input lifetime. The third rule doesn’t apply either, because <code>longest</code> is a
|
||
function rather than a method, so none of the parameters are <code>self</code>. After
|
||
working through all three rules, we still haven’t figured out what the return
|
||
type’s lifetime is. This is why we got an error trying to compile the code in
|
||
Listing 10-20: The compiler worked through the lifetime elision rules but still
|
||
couldn’t figure out all the lifetimes of the references in the signature.</p>
|
||
<p>Because the third rule really only applies in method signatures, we’ll look at
|
||
lifetimes in that context next to see why the third rule means we don’t have to
|
||
annotate lifetimes in method signatures very often.</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="lifetime-annotations-in-method-definitions"></a></p>
|
||
<h3 id="in-method-definitions"><a class="header" href="#in-method-definitions">In Method Definitions</a></h3>
|
||
<p>When we implement methods on a struct with lifetimes, we use the same syntax as
|
||
that of generic type parameters, as shown in Listing 10-11. Where we declare
|
||
and use the lifetime parameters depends on whether they’re related to the
|
||
struct fields or the method parameters and return values.</p>
|
||
<p>Lifetime names for struct fields always need to be declared after the <code>impl</code>
|
||
keyword and then used after the struct’s name because those lifetimes are part
|
||
of the struct’s type.</p>
|
||
<p>In method signatures inside the <code>impl</code> block, references might be tied to the
|
||
lifetime of references in the struct’s fields, or they might be independent. In
|
||
addition, the lifetime elision rules often make it so that lifetime annotations
|
||
aren’t necessary in method signatures. Let’s look at some examples using the
|
||
struct named <code>ImportantExcerpt</code> that we defined in Listing 10-24.</p>
|
||
<p>First, we’ll use a method named <code>level</code> whose only parameter is a reference to
|
||
<code>self</code> and whose return value is an <code>i32</code>, which is not a reference to anything:</p>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">struct ImportantExcerpt<'a> {
|
||
</span><span class="boring"> part: &'a str,
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>impl<'a> ImportantExcerpt<'a> {
|
||
fn level(&self) -> i32 {
|
||
3
|
||
}
|
||
}
|
||
<span class="boring">
|
||
</span><span class="boring">impl<'a> ImportantExcerpt<'a> {
|
||
</span><span class="boring"> fn announce_and_return_part(&self, announcement: &str) -> &str {
|
||
</span><span class="boring"> println!("Attention please: {announcement}");
|
||
</span><span class="boring"> self.part
|
||
</span><span class="boring"> }
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span><span class="boring">fn main() {
|
||
</span><span class="boring"> let novel = String::from("Call me Ishmael. Some years ago...");
|
||
</span><span class="boring"> let first_sentence = novel.split('.').next().unwrap();
|
||
</span><span class="boring"> let i = ImportantExcerpt {
|
||
</span><span class="boring"> part: first_sentence,
|
||
</span><span class="boring"> };
|
||
</span><span class="boring">}</span></code></pre>
|
||
<p>The lifetime parameter declaration after <code>impl</code> and its use after the type name
|
||
are required, but because of the first elision rule, we’re not required to
|
||
annotate the lifetime of the reference to <code>self</code>.</p>
|
||
<p>Here is an example where the third lifetime elision rule applies:</p>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">struct ImportantExcerpt<'a> {
|
||
</span><span class="boring"> part: &'a str,
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span><span class="boring">impl<'a> ImportantExcerpt<'a> {
|
||
</span><span class="boring"> fn level(&self) -> i32 {
|
||
</span><span class="boring"> 3
|
||
</span><span class="boring"> }
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>impl<'a> ImportantExcerpt<'a> {
|
||
fn announce_and_return_part(&self, announcement: &str) -> &str {
|
||
println!("Attention please: {announcement}");
|
||
self.part
|
||
}
|
||
}
|
||
<span class="boring">
|
||
</span><span class="boring">fn main() {
|
||
</span><span class="boring"> let novel = String::from("Call me Ishmael. Some years ago...");
|
||
</span><span class="boring"> let first_sentence = novel.split('.').next().unwrap();
|
||
</span><span class="boring"> let i = ImportantExcerpt {
|
||
</span><span class="boring"> part: first_sentence,
|
||
</span><span class="boring"> };
|
||
</span><span class="boring">}</span></code></pre>
|
||
<p>There are two input lifetimes, so Rust applies the first lifetime elision rule
|
||
and gives both <code>&self</code> and <code>announcement</code> their own lifetimes. Then, because
|
||
one of the parameters is <code>&self</code>, the return type gets the lifetime of <code>&self</code>,
|
||
and all lifetimes have been accounted for.</p>
|
||
<h3 id="the-static-lifetime"><a class="header" href="#the-static-lifetime">The Static Lifetime</a></h3>
|
||
<p>One special lifetime we need to discuss is <code>'static</code>, which denotes that the
|
||
affected reference <em>can</em> live for the entire duration of the program. All
|
||
string literals have the <code>'static</code> lifetime, which we can annotate as follows:</p>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">#![allow(unused)]
|
||
</span><span class="boring">fn main() {
|
||
</span>let s: &'static str = "I have a static lifetime.";
|
||
<span class="boring">}</span></code></pre>
|
||
<p>The text of this string is stored directly in the program’s binary, which is
|
||
always available. Therefore, the lifetime of all string literals is <code>'static</code>.</p>
|
||
<p>You might see suggestions in error messages to use the <code>'static</code> lifetime. But
|
||
before specifying <code>'static</code> as the lifetime for a reference, think about
|
||
whether or not the reference you have actually lives the entire lifetime of
|
||
your program, and whether you want it to. Most of the time, an error message
|
||
suggesting the <code>'static</code> lifetime results from attempting to create a dangling
|
||
reference or a mismatch of the available lifetimes. In such cases, the solution
|
||
is to fix those problems, not to specify the <code>'static</code> lifetime.</p>
|
||
<!-- Old headings. Do not remove or links may break. -->
|
||
<p><a id="generic-type-parameters-trait-bounds-and-lifetimes-together"></a></p>
|
||
<h2 id="generic-type-parameters-trait-bounds-and-lifetimes"><a class="header" href="#generic-type-parameters-trait-bounds-and-lifetimes">Generic Type Parameters, Trait Bounds, and Lifetimes</a></h2>
|
||
<p>Let’s briefly look at the syntax of specifying generic type parameters, trait
|
||
bounds, and lifetimes all in one function!</p>
|
||
<pre class="playground"><code class="language-rust edition2024"><span class="boring">fn main() {
|
||
</span><span class="boring"> let string1 = String::from("abcd");
|
||
</span><span class="boring"> let string2 = "xyz";
|
||
</span><span class="boring">
|
||
</span><span class="boring"> let result = longest_with_an_announcement(
|
||
</span><span class="boring"> string1.as_str(),
|
||
</span><span class="boring"> string2,
|
||
</span><span class="boring"> "Today is someone's birthday!",
|
||
</span><span class="boring"> );
|
||
</span><span class="boring"> println!("The longest string is {result}");
|
||
</span><span class="boring">}
|
||
</span><span class="boring">
|
||
</span>use std::fmt::Display;
|
||
|
||
fn longest_with_an_announcement<'a, T>(
|
||
x: &'a str,
|
||
y: &'a str,
|
||
ann: T,
|
||
) -> &'a str
|
||
where
|
||
T: Display,
|
||
{
|
||
println!("Announcement! {ann}");
|
||
if x.len() > y.len() { x } else { y }
|
||
}</code></pre>
|
||
<p>This is the <code>longest</code> function from Listing 10-21 that returns the longer of
|
||
two string slices. But now it has an extra parameter named <code>ann</code> of the generic
|
||
type <code>T</code>, which can be filled in by any type that implements the <code>Display</code>
|
||
trait as specified by the <code>where</code> clause. This extra parameter will be printed
|
||
using <code>{}</code>, which is why the <code>Display</code> trait bound is necessary. Because
|
||
lifetimes are a type of generic, the declarations of the lifetime parameter
|
||
<code>'a</code> and the generic type parameter <code>T</code> go in the same list inside the angle
|
||
brackets after the function name.</p>
|
||
<h2 id="summary"><a class="header" href="#summary">Summary</a></h2>
|
||
<p>We covered a lot in this chapter! Now that you know about generic type
|
||
parameters, traits and trait bounds, and generic lifetime parameters, you’re
|
||
ready to write code without repetition that works in many different situations.
|
||
Generic type parameters let you apply the code to different types. Traits and
|
||
trait bounds ensure that even though the types are generic, they’ll have the
|
||
behavior the code needs. You learned how to use lifetime annotations to ensure
|
||
that this flexible code won’t have any dangling references. And all of this
|
||
analysis happens at compile time, which doesn’t affect runtime performance!</p>
|
||
<p>Believe it or not, there is much more to learn on the topics we discussed in
|
||
this chapter: Chapter 18 discusses trait objects, which are another way to use
|
||
traits. There are also more complex scenarios involving lifetime annotations
|
||
that you will only need in very advanced scenarios; for those, you should read
|
||
the <a href="../reference/trait-bounds.html">Rust Reference</a>. But next, you’ll learn how to write tests in
|
||
Rust so that you can make sure your code is working the way it should.</p>
|
||
</body>
|
||
</html>
|