Documentation
Zero-Unsafe Architecture
Designed for maximum memory safety and performance: `#![forbid(unsafe_code)]`, arena allocation, and SIMD scanning.
Zero Unsafe Rule
oxml strictly enforces #![forbid(unsafe_code)] at crate root across all crates in the workspace. There are zero exceptions:
- No raw pointer arithmetic
- No unverified memory transmutes
- No unchecked slice access
Every boundary check is verified at compile-time or hardware-accelerated without compromising memory safety.
Arena Allocation
oxml::Document backs its DOM with a generational slot-recycling node arena:
- O(1) Node Lookup: Nodes are addressed via lightweight, copyable
NodeIdtokens. - Generational Recycling: Deleted nodes increment their slot generation counter. Accessing a stale
NodeIdsafely fails rather than pointing to dangling or reallocated memory. - Cache Locality: Nodes are stored in contiguous vectors, maximizing CPU L1/L2 cache hit rates.
SWAR Acceleration
Safe delimiter scanning uses SIMD Within A Register (SWAR) across 8-byte chunks to scan character data and attribute values, delivering over +149% throughput vs scalar scanning without unsafe intrinsics.