> That means that impl Drop for Drain is responsible for making sure that Drain is sound.
This is _wrong_ the Drop impl _must not_ be responsible for making sure Drain is Sound. Drop is not guaranteed to run it must _never_ be relied on for soundness.
I emphasizes the wrong because that is one of the biggest pitfalls in current rust outside of doing some very clever/magic things.
In std the `drain` function guarantees soundness by setting len=0, i.e. making the vector forget about all it's content, i.e. semantically moves all of it's elements from the Vec into the Drain.
The Drop impl. semantically just moves the parts it didn't drain back into the Vec.
I.e. for Drain Drop it's isn't responsible for soundness but for not leaking the non drained elements.
EDIT: To be fair: Otherwise still a good article. Just misses one crucial paragraph.