14 releases

0.1.13 Oct 10, 2023
0.1.11 Aug 14, 2023
0.1.10 Apr 24, 2023
0.1.9 Jan 3, 2023
0.1.0 Jan 3, 2017

#1 in #refcell

Download history 41369/week @ 2023-10-31 36004/week @ 2023-11-07 47571/week @ 2023-11-14 33201/week @ 2023-11-21 36707/week @ 2023-11-28 34245/week @ 2023-12-05 30312/week @ 2023-12-12 32175/week @ 2023-12-19 13893/week @ 2023-12-26 26240/week @ 2024-01-02 29139/week @ 2024-01-09 29883/week @ 2024-01-16 33629/week @ 2024-01-23 31343/week @ 2024-01-30 34478/week @ 2024-02-06 28404/week @ 2024-02-13

132,956 downloads per month
Used in 480 crates (59 directly)


365 lines


Threadsafe RefCell for Rust.


Implements a container type providing RefCell-like semantics for objects shared across threads.

RwLock is traditionally considered to be the |Sync| analogue of RefCell. However, for consumers that can guarantee that they will never mutably borrow the contents concurrently with immutable borrows, an RwLock is overkill, and has key disadvantages:

  • Performance: Even the fastest existing implementation of RwLock (that of parking_lot) performs at least two atomic operations during immutable borrows. This makes mutable borrows significantly cheaper than immutable borrows, leading to weird incentives when writing performance-critical code.
  • Features: Implementing AtomicRefCell on top of RwLock makes it impossible to implement useful things like AtomicRef{,Mut}::map.

As such, we re-implement RefCell semantics from scratch with a single atomic reference count. The primary complication of this scheme relates to keeping things in a consistent state when one thread performs an illegal borrow and panics. Since an AtomicRefCell can be accessed by multiple threads, and since panics are recoverable, we need to ensure that an illegal (panicking) access by one thread does not lead to undefined behavior on other, still-running threads.

So we represent things as follows:

  • Any value with the high bit set (so half the total refcount space) indicates a mutable borrow.
  • Mutable borrows perform an atomic compare-and-swap, swapping in the high bit if the current value is zero. If the current value is non-zero, the thread panics and the value is left undisturbed.
  • Immutable borrows perform an atomic increment. If the new value has the high bit set, the thread panics. The incremented refcount is left as-is, since it still represents a valid mutable borrow. When the mutable borrow is released, the refcount is set unconditionally to zero, clearing any stray increments by panicked threads.

There are a few additional purely-academic complications to handle overflow, which are documented in the implementation.

The rest of this module is mostly derived by copy-pasting the implementation of RefCell and fixing things up as appropriate. Certain non-threadsafe methods have been removed. We segment the concurrency logic from the rest of the code to keep the tricky parts small and easy to audit.