caixa_core/dialeto.rs
1//! `defcaixa` is spoken by two unrelated declarations. This module makes that
2//! a **typed fact** instead of an anonymous parse failure.
3//!
4//! # The finding
5//!
6//! Measured 2026-07-31 over the pleme-io org checkout (270 `caixa.lisp` /
7//! `*.caixa.lisp` files found with `rg --no-ignore`; a bare `rg` from the org
8//! root returns 0, which is how this stayed invisible), the corpus splits into
9//! two schemas that share zero required slots:
10//!
11//! * [`CaixaDialeto::Pacote`] — this crate's [`crate::Caixa`]. `:nome
12//! :versao :kind :deps :bibliotecas :exe :servicos` + the supervisor/mesh
13//! slots. It declares a **tatara-lisp package**: the thing `feira` resolves,
14//! builds, links and publishes.
15//! * [`CaixaDialeto::Molde`] — `:name :kind :ecosystem :package {…} :workflows
16//! […] :ci-config {…} :files […]`. It declares a **repo's generated
17//! surface**: which foreign ecosystem (rust / go / python / …), that
18//! ecosystem's own package metadata, the CI shims to emit, and byte-captured
19//! file bodies. Read by `pleme-doc-gen`, never by `feira`.
20//!
21//! `:package`, `:ecosystem`, `:supports` and `:profile` have no counterpart in
22//! [`crate::Caixa`] at all — the theory doc's own D4 note records the same
23//! thing: those manifests "are authored against a schema that does not exist in
24//! Rust". They are not two spellings of one declaration. They are two domains
25//! that collided on one word, because *caixa* names a box and both are boxes.
26//!
27//! # Why this is not a bug report about broken files
28//!
29//! The Molde-dialect files are not malformed. They are correct inputs to their
30//! own consumer, and nothing in the shipped `feira` reads them, so nothing is
31//! failing today. The hazard is **latent and certain**: any new declarative
32//! surface written against "a `.caixa.lisp` is a [`crate::Caixa`]" meets a
33//! corpus where that is false for the large majority of files, and gets a flat
34//! unknown-keyword rejection that reads as "this manifest is broken" rather
35//! than "this manifest is not yours".
36//!
37//! # What this module does about it
38//!
39//! [`classify`] is total: every `(defcaixa …)` form lands in exactly one
40//! [`CaixaDialeto`], including [`CaixaDialeto::Desconhecido`] for one that
41//! matches neither. [`crate::Caixa::from_lisp`] runs it first, so a foreign
42//! dialect is [`crate::ManifestError::DialetoEstrangeiro`] — an error that
43//! names the dialect it found and the consumer that speaks it — rather than an
44//! unknown-kwarg error indistinguishable from a typo.
45//!
46//! Tier-honest: this is **parse-time rejection with a named cause**, not
47//! unrepresentability. A caller that ignores the `Err` still gets nothing
48//! useful; what it can no longer do is mistake "wrong dialect" for "bad file".
49
50use tatara_lisp::{Atom, Sexp};
51
52/// Which `(defcaixa …)` declaration a source speaks.
53///
54/// The [`gen_platform::IsVariant`] derive emits per-arm arm-discriminator
55/// predicates (`is_pacote` / `is_molde` / `is_molde_posicional` /
56/// `is_desconhecido`) as substrate-side typed dispatches on the closed
57/// four-arm dialect-classification discriminator. Peer of the sibling
58/// closed-set fieldless typed enums' [`crate::CaixaKind`] /
59/// [`crate::supervisor::RestartStrategy`] /
60/// [`crate::supervisor::RestartPolicy`] /
61/// [`crate::aplicacao::PlacementStrategy`] /
62/// [`crate::aplicacao::RateLimitUnit`] /
63/// [`crate::dep::DepList`] `IsVariant` derives on the sibling
64/// closed-set typed-enum discriminator axes.
65///
66/// The pre-lift `is_molde_family` predicate hand-rolled its own
67/// `matches!(self, Self::Molde | Self::MoldePosicional)` two-arm literal
68/// with no compile-time link back to the closed set — post-lift it routes
69/// through `self.is_molde() || self.is_molde_posicional()` so a future
70/// arm rename (e.g. `Molde → MoldeKW` under an M4 vocabulary shift) trips
71/// exhaustively at every derive-generated predicate site rather than
72/// leaving the hand-rolled `matches!` silently drifting.
73#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, gen_platform::IsVariant)]
74pub enum CaixaDialeto {
75 /// This crate's [`crate::Caixa`] — a tatara-lisp package manifest.
76 /// Keyword-argument form headed by `:nome`.
77 Pacote,
78 /// `pleme-doc-gen`'s repo-surface declaration, keyword-argument form
79 /// headed by `:name` (plus `:ecosystem` / `:package`).
80 Molde,
81 /// The same declaration as [`Self::Molde`], written with the package name
82 /// as a bare positional symbol — `(defcaixa todoku-go :kind :Biblioteca
83 /// :ecosystem :go …)`. `pleme-doc-gen`'s parser reads the first token
84 /// after the head as the name, so this is one arity of one declaration,
85 /// not a third schema.
86 MoldePosicional,
87 /// A `(defcaixa …)` form matching neither. Kept as a variant rather than
88 /// an error so [`classify`] is total and a census can COUNT the residue —
89 /// a classifier that threw here would report "0 unknown" by construction.
90 Desconhecido,
91}
92
93impl CaixaDialeto {
94 /// Exhaustive iteration surface for every consumer that walks the
95 /// closed four-arm [`CaixaDialeto`] discriminator set — the
96 /// [`feira dialeto`](../../caixa_feira/cmd/dialeto/index.html)
97 /// census counter's per-arm accept-set, a future
98 /// `feira dialeto --list-dialects` CLI listing of the accepted
99 /// classifications, a future M4 `mesh.pleme.io/v1alpha1/Manifesto`
100 /// CR materializer's admission-webhook rejection body naming the
101 /// accepted-dialect set, any future census-report shape probe that
102 /// sweeps every arm to compute per-arm coverage. A future arm
103 /// addition (a fifth dialect the [`crate::dialeto`] module doc's
104 /// "third dialect" hazard actualises — the module explicitly frames
105 /// its purpose as "what stops a third dialect appearing", and this
106 /// slice is the substrate-side answer: the arm-set is one edit and
107 /// every consumer picks up the new entry by construction) extends
108 /// this slice as one edit and every downstream consumer picks up
109 /// the new entry through the shared iteration; the compiler-checked
110 /// exhaustiveness on the sibling method `match` arms
111 /// ([`Self::palavra_canonica`] / [`Self::consumidor`] /
112 /// [`Self::descricao`] / [`std::fmt::Display`]) is the build-time
113 /// guarantee that no arm forgets to grow.
114 ///
115 /// Peer of the sibling closed-set typed enums'
116 /// [`crate::CaixaKind::ALL`] (6b1f4fb) /
117 /// [`crate::aplicacao::PlacementStrategy::ALL`] (18c7342) /
118 /// [`crate::aplicacao::RateLimitUnit::ALL`] (6bce03d) /
119 /// [`crate::dep::DepList::ALL`] (45ee563) /
120 /// [`crate::supervisor::RestartStrategy::ALL`] (4eec29c) /
121 /// [`crate::supervisor::RestartPolicy::ALL`] (dd32ccf)
122 /// exhaustive-iteration surfaces — the seventh closed-set typed
123 /// enum on the caixa surface to converge onto the same
124 /// one-canonical-arm-list-per-enum discipline, and the first
125 /// dialect-classification axis (as distinct from an OTP-shape M2
126 /// slot or an M3 mesh slot) to reach it. Order matches variant
127 /// declaration order verbatim (`Pacote` → `Molde` →
128 /// `MoldePosicional` → `Desconhecido`) so the slice is the
129 /// canonical ordering every listing / rendering consumer defers to.
130 pub const ALL: &'static [Self] = &[
131 Self::Pacote,
132 Self::Molde,
133 Self::MoldePosicional,
134 Self::Desconhecido,
135 ];
136
137 /// Substrate-canonical `PascalCase` variant-name byte-string every consumer
138 /// that formats the dialect as census-facing text lands on. Returns the
139 /// per-arm `PascalCase` name of the variant (`"Pacote"` / `"Molde"` /
140 /// `"MoldePosicional"` / `"Desconhecido"`) — the one canonical
141 /// byte-string the paired [`std::fmt::Display`] impl routes through so
142 /// every downstream consumer (the `feira dialeto` census counter output
143 /// line, a future `feira dialeto --list-dialects` CLI enumeration, a
144 /// future M4 `mesh.pleme.io/v1alpha1/Manifesto` CR materializer's
145 /// admission-webhook rejection body naming the accepted-dialect set)
146 /// reaches for the same substrate primitive rather than the pre-lift
147 /// hand-rolled four-arm literal-string match every [`std::fmt::Display`]
148 /// call previously routed through in place.
149 ///
150 /// Peer of the sibling closed-set typed enums'
151 /// [`crate::CaixaKind::as_str`] / [`crate::supervisor::RestartStrategy::as_str`]
152 /// / [`crate::supervisor::RestartPolicy::as_str`] /
153 /// [`crate::aplicacao::PlacementStrategy::as_str`] /
154 /// [`crate::dep::DepList::as_str`] projections on the sibling closed-set
155 /// typed-enum discriminator axes — the seventh (and last unlifted)
156 /// closed-set fieldless typed enum on the caixa surface to converge
157 /// onto the same one-canonical-byte-string-per-arm-through-`as_str`
158 /// discipline the six siblings already carry. Unlike [`crate::CaixaKind`]
159 /// (which carries two axes: `as_str` returning lowercase Portuguese
160 /// diagnostic form vs `wire_name` returning `PascalCase` tatara-lisp
161 /// author-surface bytes), [`CaixaDialeto`] is an internal
162 /// classification with no wire surface — the `PascalCase` variant name
163 /// is the census-facing form every consumer reads, so `as_str`
164 /// suffices without a paired `wire_name` axis.
165 #[must_use]
166 pub const fn as_str(self) -> &'static str {
167 match self {
168 Self::Pacote => "Pacote",
169 Self::Molde => "Molde",
170 Self::MoldePosicional => "MoldePosicional",
171 Self::Desconhecido => "Desconhecido",
172 }
173 }
174
175 /// Substrate-canonical reverse projection on the [`CaixaDialeto`]
176 /// closed-set dialect-classification axis — parses the `PascalCase`
177 /// variant-name byte-string back to the typed variant, or `None` when
178 /// `s` is outside the closed-set arm-string set [`Self::as_str`]
179 /// emits. Walks the same four `"Pacote"` / `"Molde"` /
180 /// `"MoldePosicional"` / `"Desconhecido"` byte-strings the sibling
181 /// [`Self::as_str`] emitter returns, so the parse and emit halves of
182 /// the round-trip migrate through one caixa-core edit on any future
183 /// arm addition (the module doc's "third dialect" hazard actualising
184 /// as a fifth arm) — the compiler-checked exhaustiveness on
185 /// [`Self::as_str`]'s `match self` arms and the round-trip pin
186 /// [`tests::caixa_dialeto_round_trips_through_as_str_and_from_wire`]
187 /// together lock the two halves mutually.
188 ///
189 /// Prior to this lift the substrate carried only the forward
190 /// `Self → &str` projection on the dialect-classification axis (the
191 /// [`Self::as_str`] emitter, the [`std::fmt::Display`] impl routed
192 /// through it, the [`AsRef<str>`] impl routed through it) — every
193 /// future consumer that wanted to promote the census-facing text back
194 /// to the typed enum (a future `feira dialeto --filter
195 /// <Pacote|Molde|MoldePosicional|Desconhecido>` CLI arg-parse that
196 /// binds the wire form into the typed enum before dispatching to the
197 /// per-arm counter, a future M4 `mesh.pleme.io/v1alpha1/Manifesto`
198 /// CR materializer's admission-time re-parse of the per-dialect
199 /// audit body, a future audit-report re-loader that binds a prior
200 /// [`Self::as_str`] output back to the typed enum for cross-run
201 /// comparison) would have had to re-inline a four-arm `match s`
202 /// cascade that expressed no compile-time link back to the typed
203 /// [`CaixaDialeto`] enum.
204 ///
205 /// Same closed-set-reverse-projection discipline the sibling
206 /// [`crate::CaixaKind::from_wire`] (2aa6d23) /
207 /// [`crate::supervisor::RestartStrategy::from_wire`] (4eec29c) /
208 /// [`crate::supervisor::RestartPolicy::from_wire`] (dd32ccf) /
209 /// [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342) /
210 /// [`crate::dep::DepList::from_wire`] (45ee563) typed enums carry on
211 /// the peer wire-side `str → Self` axes — extends the family onto
212 /// the seventh closed-set fieldless typed enum on the caixa surface
213 /// (the dialect-classification axis), matching the same
214 /// two-way `str ↔ Self` round-trip every sibling closed-set enum
215 /// already carries. Method-named `from_wire` (not `from_str`) to
216 /// match the peer shapes verbatim and side-step the derived
217 /// [`std::str::FromStr`] impls the sibling
218 /// [`gen_platform::FromStrKind`]-carrying axes install on their
219 /// kebab-case dispatcher-catalog identity. Returns `Option<Self>`
220 /// (rather than `Result<Self, _>`) to match the peer shapes: the
221 /// caller picks the diagnostic form appropriate for its use site.
222 #[must_use]
223 pub fn from_wire(s: &str) -> Option<Self> {
224 match s {
225 "Pacote" => Some(Self::Pacote),
226 "Molde" => Some(Self::Molde),
227 "MoldePosicional" => Some(Self::MoldePosicional),
228 "Desconhecido" => Some(Self::Desconhecido),
229 _ => None,
230 }
231 }
232
233 /// The keyword an author should write for this dialect, once the
234 /// migration named in [`Self::consumidor`] completes.
235 #[must_use]
236 pub const fn palavra_canonica(self) -> &'static str {
237 match self {
238 Self::Pacote => "defcaixa",
239 Self::Molde | Self::MoldePosicional => "defmolde",
240 Self::Desconhecido => "?",
241 }
242 }
243
244 /// Who reads this dialect.
245 #[must_use]
246 pub const fn consumidor(self) -> &'static str {
247 match self {
248 Self::Pacote => "caixa-core / feira",
249 Self::Molde | Self::MoldePosicional => "pleme-doc-gen",
250 Self::Desconhecido => "nobody known",
251 }
252 }
253
254 /// A one-line description for a census row or an error message.
255 #[must_use]
256 pub const fn descricao(self) -> &'static str {
257 match self {
258 Self::Pacote => "tatara-lisp package manifest (:nome :versao :kind :deps …)",
259 Self::Molde => "repo-surface declaration (:name :ecosystem :package {…} …)",
260 Self::MoldePosicional => {
261 "repo-surface declaration, positional name (defcaixa <nome> :kind …)"
262 }
263 Self::Desconhecido => "unrecognised — matches no known defcaixa schema",
264 }
265 }
266
267 /// True when this arm belongs to the `defmolde` declaration family —
268 /// the two-arity closure of [`Self::Molde`] and [`Self::MoldePosicional`]
269 /// under the shared `defmolde` head keyword the sibling
270 /// [`Self::palavra_canonica`] projection already collapses onto
271 /// `"defmolde"` for both arms (and the sibling [`Self::consumidor`]
272 /// projection collapses onto `"pleme-doc-gen"` for the same two arms).
273 /// False on [`Self::Pacote`] (the sibling `defcaixa` tatara-lisp
274 /// package manifest, [`Self::palavra_canonica`] `→ "defcaixa"`) and
275 /// on [`Self::Desconhecido`] (the residue that names no known
276 /// declaration, [`Self::palavra_canonica`] `→ "?"`).
277 ///
278 /// The [`Self::Molde`] / [`Self::MoldePosicional`] split is one
279 /// declaration written two ways ([`Self::MoldePosicional`]'s
280 /// variant-declaration docstring at [`Self::MoldePosicional`] frames
281 /// it exactly: "the same declaration as [`Self::Molde`], written with
282 /// the package name as a bare positional symbol … this is one arity
283 /// of one declaration, not a third schema"). Every downstream gate
284 /// that keys off "does this dialect belong to the `defmolde` family"
285 /// (as distinct from the four-arm-per-arm census-counter axis the
286 /// sibling `feira dialeto` verb already fans on separately at
287 /// `caixa-feira/src/cmd/dialeto.rs:110-127`) previously hand-rolled
288 /// the two-arm collapse inline as `matches!(d, CaixaDialeto::Molde |
289 /// CaixaDialeto::MoldePosicional)` — a compile-time-anonymous
290 /// two-arm literal set with no link back to the [`CaixaDialeto`]
291 /// variant declaration nor to the sibling
292 /// [`Self::palavra_canonica`] / [`Self::consumidor`] projections
293 /// that already carry the same two-arm collapse under the shared
294 /// `defmolde` / `pleme-doc-gen` axis. The `feira dialeto` verb's
295 /// [`caixa-feira/src/cmd/dialeto.rs`] carried the same
296 /// `matches!` twice — once in the `--strict-palavra` gate that
297 /// refuses a repo-surface declaration still written as
298 /// `(defcaixa …)`, once in the wrong-declaration-under-`caixa.lisp`
299 /// gate that refuses a repo-surface declaration under the filename
300 /// `feira` loads as a package manifest — with no compile-time link
301 /// between the two hand-rolled arm sets. A future arm addition (the
302 /// module doc's "third dialect" hazard actualises as a fifth arm
303 /// [`CaixaDialeto`] that belongs to the `defmolde` declaration
304 /// family — a third arity variant, an alias-declaration family
305 /// pleme-doc-gen sharpens as its schema evolves) would silently
306 /// split the two hand-rolled `matches!` arm-sets from each other
307 /// and from the paired [`Self::palavra_canonica`] projection: one
308 /// call site picks up the new arm, one does not, and the disagreement
309 /// surfaces far from the arm-addition commit as a `feira dialeto`
310 /// consumer reporting a repo-surface declaration under one gate but
311 /// not the other. Routing every "belongs to the `defmolde` family"
312 /// predicate through this one substrate primitive closes the axis:
313 /// a future arm addition lands one match arm here (a compile-time
314 /// exhaustiveness error otherwise), not a coordinated per-`matches!`
315 /// rewrite across every caller.
316 ///
317 /// Peer of the sibling [`crate::CaixaKind::requires_lib`] (0421c22)
318 /// per-arm-set predicate on the [`crate::CaixaKind`] closed-set
319 /// discriminator's "kind requires a `lib/` surface" axis — extends
320 /// the same "one canonical typed predicate per per-arm-set gate,
321 /// one dispatch on the substrate primitive" discipline onto the
322 /// [`CaixaDialeto`] closed-set discriminator's "belongs to the
323 /// `defmolde` declaration family" axis. The dialect-classification
324 /// axis's second per-arm-set predicate (first being the implicit
325 /// palavra_canonica-through-consumidor-through-descricao arm-set
326 /// collapse already carried on the sibling projections) — the first
327 /// explicitly-typed per-arm-set predicate on the axis, matching the
328 /// discipline the sibling M2 [`crate::CaixaKind`] closed-set
329 /// discriminator already carries with `requires_lib`.
330 ///
331 /// Three consumers now route through this one typed dispatch: the
332 /// [`caixa-feira`](../../caixa_feira/cmd/dialeto/index.html) verb's
333 /// `--strict-palavra` gate (refusing a repo-surface declaration
334 /// still written as `(defcaixa …)`), the same verb's wrong-
335 /// declaration-under-`caixa.lisp` gate (refusing a repo-surface
336 /// declaration under the filename `feira` loads as a package
337 /// manifest), and [`crate::Caixa::from_lisp`]'s foreign-dialect
338 /// gate (raising [`crate::ManifestError::DialetoEstrangeiro`] before
339 /// the derive's `parse_kwargs_strict` walk on any `defmolde`-family
340 /// classification — the pre-lift hand-rolled three-arm
341 /// `match { Pacote => {}, Desconhecido => {}, foreign => Err(…) }`
342 /// literal whose `foreign =>` wildcard silently absorbed anything
343 /// non-Pacote-non-Desconhecido, now the third external consumer of
344 /// the `defmolde`-family partition).
345 #[must_use]
346 pub const fn is_molde_family(self) -> bool {
347 // Routed through the derive-generated per-arm predicates
348 // [`Self::is_molde`] + [`Self::is_molde_posicional`] so the
349 // two-arm collapse links compile-time back to the closed-set
350 // typed dispatch every peer arm-set predicate on the caixa
351 // surface (e.g. [`crate::CaixaKind::requires_lib`] on the
352 // sibling `:kind` axis) now carries. Byte-equivalent to the
353 // pre-lift `matches!(self, Self::Molde | Self::MoldePosicional)`
354 // form (the derived `is_*` predicates each expand to the same
355 // `matches!(self, Self::X)` shape by construction), but a
356 // future arm rename or IsVariant `#[is_variant(name = "…")]`
357 // override lands at exactly one dispatch on the substrate
358 // primitive rather than a hand-rolled two-arm literal.
359 self.is_molde() || self.is_molde_posicional()
360 }
361}
362
363/// [`std::fmt::Display`] routed through [`CaixaDialeto::as_str`], so the
364/// pretty-printed byte-string every consumer that formats the dialect as
365/// user-facing / census text lands on (the `feira dialeto` per-manifest
366/// `--list` row, the `feira dialeto` census summary line's per-arm
367/// counters, a future M4 admission-webhook's rejection body naming the
368/// accepted-dialect set) reaches for the same `PascalCase` per-arm
369/// byte-string the [`CaixaDialeto::as_str`] helper returns.
370///
371/// Prior to this lift the [`std::fmt::Display`] impl hand-rolled its own
372/// four-arm literal-string match — the one hand-rolled per-arm dispatch
373/// on the closed [`CaixaDialeto`] discriminator that had NO substrate
374/// primitive accessor to defer to (the sibling [`CaixaDialeto::palavra_canonica`] /
375/// [`CaixaDialeto::consumidor`] / [`CaixaDialeto::descricao`] projections
376/// carry distinct byte-shapes per axis, so none of them could serve as
377/// the Display source). A future variant addition (a fifth dialect the
378/// module doc's "third dialect" hazard actualises) would land one arm at
379/// the enum and per-arm returns at the paired accessors, but a hand-rolled
380/// [`std::fmt::Display`] match would silently drop the new arm to compile-
381/// fail-at-the-match-arm-site rather than through the shared substrate
382/// primitive. Routing [`std::fmt::Display`] through [`CaixaDialeto::as_str`]
383/// closes the last unlifted per-arm `PascalCase`-name projection on the
384/// caixa surface — the seventh (and last unlifted) closed-set fieldless
385/// typed enum on the caixa surface to converge onto the same
386/// `Display`-through-`as_str` discipline the six siblings
387/// ([`crate::CaixaKind`] / [`crate::supervisor::RestartStrategy`] /
388/// [`crate::supervisor::RestartPolicy`] /
389/// [`crate::aplicacao::PlacementStrategy`] / [`crate::aplicacao::RateLimitUnit`]
390/// / [`crate::dep::DepList`]) already carry.
391impl std::fmt::Display for CaixaDialeto {
392 fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
393 f.write_str(self.as_str())
394 }
395}
396
397/// Substrate-canonical [`AsRef<str>`] projection on the [`CaixaDialeto`]
398/// closed-set fieldless typed dialect-classification enum — routes through
399/// the same [`CaixaDialeto::as_str`] `pub const fn` scalar accessor the
400/// paired [`std::fmt::Display`] impl already delegates through, so any
401/// future consumer that binds a [`CaixaDialeto`] through the standard-
402/// library `impl AsRef<str>` bound (a [`std::process::Command::arg`]
403/// shell-out that composes the canonical `PascalCase` variant-name into a
404/// `feira dialeto --strict-palavra <Pacote|Molde|MoldePosicional|Desconhecido>`
405/// diagnostic overlay, a `tracing::field::Value::Str`-arm structured-log
406/// recorder on the [`crate::Caixa::from_lisp`] foreign-dialect
407/// [`crate::ManifestError::DialetoEstrangeiro`] refusal path, a
408/// [`std::collections::HashMap`] lookup keyed on the canonical name
409/// through `map.get::<str>(dialeto.as_ref())` on a future M4 admission-
410/// webhook's per-dialect rejection-body composition table) reaches the
411/// paired `"Pacote"` / `"Molde"` / `"MoldePosicional"` / `"Desconhecido"`
412/// byte-string through one substrate-primitive dispatch rather than an
413/// open-coded `.as_str()` re-inlining at every wire-up.
414///
415/// Same "route the trait impl through the substrate-primitive accessor"
416/// discipline the sibling [`crate::CaixaVersion`] [`AsRef<str>`] impl
417/// (16d5c7e), the paired M2 [`crate::supervisor::RestartStrategy`]
418/// [`AsRef<str>`] impl (63eb1a4), the paired M2
419/// [`crate::supervisor::RestartPolicy`] [`AsRef<str>`] impl (419ea81),
420/// the M3 [`crate::aplicacao::PlacementStrategy`] [`AsRef<str>`] impl
421/// (d86edd2), the M3 [`crate::aplicacao::RateLimitUnit`] [`AsRef<str>`]
422/// impl (d8136db), and the top-level [`crate::CaixaKind`] [`AsRef<str>`]
423/// impl (cd2091f) carry — extends the substrate primitive's
424/// [`AsRef<str>`] projection axis onto the seventh closed-set typed enum
425/// on the caixa surface: the dialect-classification axis previously
426/// carried [`fmt::Display`]-through-`as_str` but not yet the paired
427/// [`AsRef<str>`] impl, so a downstream consumer that bound the enum
428/// through the standard-library `AsRef<str>` trait had to reach the
429/// canonical byte-string through an open-coded `.as_str()` call rather
430/// than the trait-idiomatic `.as_ref()` the peer closed-set typed enums
431/// already admit.
432///
433/// Pinned load-bearing by
434/// [`tests::caixa_dialeto_as_ref_str_routes_through_as_str_accessor`]
435/// (byte-parity pin against [`CaixaDialeto::as_str`] across the four-arm
436/// closed set) and
437/// [`tests::caixa_dialeto_as_ref_str_routes_through_display_via_shared_accessor`]
438/// (three-path convergence: `AsRef<str>` + `Display` + `as_str` all
439/// resolve to the same byte-string per arm) — any future silent detour
440/// that routes the impl through a divergent projection (a per-arm inline
441/// `match self { CaixaDialeto::Pacote => "Pacote", … }` re-inlining that
442/// opens a compile-time link to the un-lifted arm-literal, a swap onto
443/// the second-axis [`CaixaDialeto::palavra_canonica`] /
444/// [`CaixaDialeto::consumidor`] / [`CaixaDialeto::descricao`] accessors
445/// that carry distinct byte-shapes per axis) trips at caixa-core test
446/// time under `assert_eq!` rather than at a downstream
447/// `impl AsRef<str>`-bound consumer's silent split.
448impl AsRef<str> for CaixaDialeto {
449 fn as_ref(&self) -> &str {
450 self.as_str()
451 }
452}
453
454/// Trait-idiomatic reverse projection on the [`CaixaDialeto`] closed-set
455/// dialect-classification typed enum — routes byte-for-byte through the
456/// paired substrate-primitive [`CaixaDialeto::from_wire`] `Option<Self>`
457/// accessor so every future consumer that binds a `PascalCase` variant-
458/// name byte-string through the standard-library `.try_into()` /
459/// [`TryFrom`] axis (a future `feira dialeto --filter
460/// <Pacote|Molde|MoldePosicional|Desconhecido>` CLI arg-parse that
461/// composes into `let d: CaixaDialeto = s.try_into()?`, a future audit-
462/// report re-loader binding a prior [`CaixaDialeto::as_str`] output
463/// through `CaixaDialeto::try_from(&s)?`, a generic
464/// `<T: TryFrom<&str>>`-bound loader over any of the substrate's closed-
465/// set typed enums) reaches the same four-arm accept-set the sibling
466/// [`CaixaDialeto::from_wire`] parses through and the sibling
467/// [`CaixaDialeto::as_str`] emits, rather than an open-coded per-arm
468/// `match s { "Pacote" => …, … }` cascade whose arm-set has no
469/// compile-time link back to the substrate primitive.
470///
471/// Complements the pre-existing forward-projection triple
472/// ([`std::fmt::Display`], [`AsRef<str>`], [`CaixaDialeto::as_str`]) with
473/// the paired trait-idiomatic reverse-projection axis: Rust-side
474/// newtype/typed-enum convention pairs [`AsRef<str>`] with either
475/// [`std::str::FromStr`] or [`TryFrom<&str>`] on the same primitive so a
476/// caller who can project *out to* a `&str` can also project *in from*
477/// one. The [`TryFrom<&str>`] axis is deliberately chosen over
478/// [`std::str::FromStr`] to sidestep the `clippy::should_implement_trait`
479/// lint that the sibling method-named `from_wire` would trigger under a
480/// `FromStr` impl (the same design tradeoff the peer
481/// [`crate::CaixaKind`] `TryFrom<&str>` impl (3c83606) and the peer
482/// [`crate::provedor::ferrite::FerriteRuntime::from_wire`] block note)
483/// — this impl closes the trait-idiomatic reverse axis without disturbing
484/// the method-named `from_wire` shape every sibling closed-set typed
485/// enum on the substrate already carries.
486///
487/// `type Error = ()` matches the sibling [`CaixaDialeto::from_wire`]'s
488/// `Option<Self>` return-shape's deliberate deferral of error typing:
489/// the caller picks the diagnostic form appropriate for its use site
490/// (a future `feira dialeto --filter` arg-parse composes its own per-verb
491/// "unknown dialect: <arg> — accepted: {…}" message enumerating
492/// [`CaixaDialeto::ALL`], a future admission-webhook rejection body
493/// wraps the `Err(())` outcome with the accepted-set enumeration for
494/// operator diagnostics, a `Result::map_err` at the call site lifts the
495/// unit-error to a per-verb error type). Same shape the peer
496/// [`crate::CaixaKind`] `TryFrom<&str>` impl (3c83606) and the peer
497/// [`FerriteRuntime::from_wire`] doc block motivate on the sibling
498/// closed-set typed enums' reverse projections.
499///
500/// The paired [`TryFrom<&str>`] impl reaches the same four-arm accept-
501/// set the [`CaixaDialeto::from_wire`] resolver dispatches through, so
502/// any future arm addition (the module doc's "third dialect" hazard
503/// actualises as a fifth arm belonging to the `defmolde` family or a
504/// wholly new declaration) grows the trait-idiomatic axis by
505/// construction — one caixa-core edit on [`CaixaDialeto::from_wire`]
506/// extends both the method-named reverse projection every existing
507/// consumer keys off and the trait-idiomatic reverse projection this
508/// impl exposes, without a coordinated rewrite across every future
509/// `TryFrom<&str>`-bound consumer's arm-set.
510///
511/// Pinned load-bearing by
512/// [`tests::caixa_dialeto_try_from_str_routes_through_from_wire_accessor`]
513/// (byte-parity pin against [`CaixaDialeto::from_wire`] across the four-
514/// arm accept-set) and
515/// [`tests::caixa_dialeto_try_from_str_rejects_unknown_byte_strings`]
516/// (rejection witness against silent accept-set widening).
517impl TryFrom<&str> for CaixaDialeto {
518 type Error = ();
519
520 fn try_from(s: &str) -> Result<Self, Self::Error> {
521 Self::from_wire(s).ok_or(())
522 }
523}
524
525/// Trait-idiomatic forward projection on the [`CaixaDialeto`] closed-set
526/// dialect-classification typed enum — routes byte-for-byte through the
527/// sibling substrate-primitive [`CaixaDialeto::as_str`] `pub const fn`
528/// accessor so every future consumer that needs `&'static str` lifetime
529/// bytes on the dialect-classification axis (a
530/// `tracing::field::valuable::Value::Str` recording where the `Str` arm's
531/// typing demands `&'static str`, a
532/// `Cow::Borrowed::<'static, str>(dialeto.into())` composer on the future
533/// M4 admission-webhook rejection body where the `Cow<'static, str>`
534/// typing rules out the sibling [`AsRef<str>`] borrowed return, a generic
535/// `<T: Into<&'static str>>`-bound serializer or error formatter that
536/// requires the `'static` bound) reaches the same four `"Pacote"` /
537/// `"Molde"` / `"MoldePosicional"` / `"Desconhecido"` byte-strings the
538/// sibling [`CaixaDialeto::as_str`] emitter returns, rather than an
539/// open-coded per-arm literal cascade whose arm-set has no compile-time
540/// link back to the substrate primitive.
541///
542/// Return type is `&'static str` by construction — every
543/// [`CaixaDialeto::as_str`] arm resolves to a compile-time `pub const fn`
544/// return of a `&'static str` literal, so the trait's return-type promise
545/// is upheld structurally without a `String::leak()` cast or a per-arm
546/// inline literal.
547///
548/// Complements the pre-existing reverse-projection axis pair
549/// ([`TryFrom<&str>`] above + method-named [`CaixaDialeto::from_wire`])
550/// with the trait-idiomatic forward-projection axis: Rust-side
551/// newtype/typed-enum convention pairs [`TryFrom<&str>`] with the mirror-
552/// image [`From<Self> for &'static str`] on the same primitive so a
553/// caller who can project *in from* a `&str` can also project *out to*
554/// one under a `'static`-lifetime bound. The
555/// [`AsRef<str>`] impl already carries the same emit-set on the borrowed
556/// return path; this impl closes the trait-idiomatic axis pair with the
557/// stricter `&'static str` lifetime the sibling `AsRef<str>` cannot
558/// promise (its return borrows from `&self`, not from the
559/// [`CaixaDialeto::as_str`] `pub const fn`'s static-string result).
560///
561/// Same "route the trait impl through the substrate-primitive accessor"
562/// discipline the sibling [`crate::supervisor::RestartStrategy`]
563/// `From<Self> for &'static str` impl (523157d — first-mover on this
564/// forward-projection family), [`crate::supervisor::RestartPolicy`]
565/// `From<Self> for &'static str` impl (9fb37d0 — second peer, closing
566/// the M2 OTP-shape sibling pair), and [`crate::CaixaKind`]
567/// `From<Self> for &'static str` impl (edb827b — third peer, opening
568/// the campaign onto the top-level caixa surface) carry — extends the
569/// substrate primitive's trait-idiomatic forward-projection axis onto
570/// the fourth closed-set fieldless typed enum on the caixa surface: the
571/// dialect-classification axis, previously carrying the paired
572/// [`std::fmt::Display`] / [`AsRef<str>`] / [`CaixaDialeto::as_str`] /
573/// [`TryFrom<&str>`] / [`CaixaDialeto::from_wire`] forward+reverse
574/// projections but not yet the trait-idiomatic forward projection with
575/// the `&'static str` lifetime bound.
576///
577/// Unlike the peer [`crate::CaixaKind`] impl (which carries a two-axis
578/// split between the lowercase Portuguese `as_str` diagnostic axis and
579/// the `PascalCase` `wire_name` author-surface axis, so the trait's
580/// round-trip witness must cross through the wire axis rather than
581/// composing the two trait impls directly), [`CaixaDialeto`] is an
582/// internal classification whose [`CaixaDialeto::as_str`] output and
583/// [`CaixaDialeto::from_wire`] input share the same `PascalCase`
584/// vocabulary by construction — the trait-idiomatic axis pair
585/// ([`From<Self> for &'static str`] + [`TryFrom<&str> for Self`])
586/// therefore round-trips directly, without an intermediate wire-vocab
587/// hop.
588///
589/// The paired [`CaixaDialeto::as_str`] accessor's four-arm emit-set is
590/// the single source of truth — every future arm addition (the module
591/// doc's "third dialect" hazard actualises as a fifth arm belonging to
592/// the `defmolde` family or a wholly new declaration) grows the trait-
593/// idiomatic forward axis by construction: one caixa-core edit on
594/// [`CaixaDialeto::as_str`] extends every one of the sibling forward-
595/// projection paths ([`std::fmt::Display`], [`AsRef<str>`],
596/// [`CaixaDialeto::as_str`] itself, and this
597/// [`From<Self> for &'static str`]) without a coordinated rewrite across
598/// every future `Into<&'static str>`-bound consumer's arm-set. This lift
599/// closes the fourth peer on the trait-idiomatic forward-projection
600/// campaign the recently-landed peer commits opened; the remaining ten
601/// closed-set typed enums on the caixa substrate surface
602/// (`PlacementStrategy`, `WitShape`, `RateLimitUnit`,
603/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
604/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets
605/// of this campaign.
606///
607/// Pinned load-bearing by
608/// [`tests::caixa_dialeto_from_into_static_str_routes_through_as_str_accessor`]
609/// (byte-parity pin against [`CaixaDialeto::as_str`] across the four-arm
610/// emit-set, plus a `const`-context materialization witness for the
611/// `&'static str` lifetime promise, plus a paired `.into()` shape
612/// assertion covering the blanket-derived `Into<&'static str>` shape)
613/// and
614/// [`tests::caixa_dialeto_from_into_static_str_and_as_str_partition_the_emit_set`]
615/// (partition pin asserting `<&'static str as From<CaixaDialeto>>::from`
616/// and [`CaixaDialeto::as_str`] agree on every arm, plus a two-way
617/// direct round-trip witness through the paired trait-idiomatic
618/// [`TryFrom<&str>`] axis that closes the two-way `Self ↔ &'static str`
619/// round-trip on the trait-idiomatic axis pair without the wire-vocab
620/// intermediate the peer [`crate::CaixaKind`] axis pair requires).
621impl From<CaixaDialeto> for &'static str {
622 fn from(dialeto: CaixaDialeto) -> &'static str {
623 dialeto.as_str()
624 }
625}
626
627/// Trait-idiomatic *forward* projection on [`CaixaDialeto`] from a
628/// *borrowed* input onto the `&'static str` axis — the borrowed-input
629/// companion to the paired owned-input [`From<CaixaDialeto> for &'static
630/// str`] impl immediately above. Routes byte-for-byte through the same
631/// substrate-primitive [`CaixaDialeto::as_str`] `pub const fn` accessor so
632/// every consumer that binds a `&CaixaDialeto` through the standard-
633/// library `.into()` / [`From<&Self> for &'static str`] axis (a
634/// `CaixaDialeto::ALL.iter().map(<&'static str>::from).collect::<Vec<_>>()`
635/// per-arm accept-set materializer — whose iterator over
636/// `&'static [CaixaDialeto]` yields `&CaixaDialeto`, not `CaixaDialeto`,
637/// so the owned-input [`From<CaixaDialeto>`] axis alone forces every call
638/// site through an explicit `.copied()` / dereference / [`Copy`]-bound
639/// restatement rather than the direct trait-idiomatic projection; a
640/// future generic `<T: Copy + for<'a> Into<&'static str>>`-bound
641/// diagnostic column that walks the `iter().map(Into::into)` shape
642/// verbatim over any of the substrate's closed-set typed enums; the
643/// future M4 admission-webhook rejection body composer's per-dialect
644/// accepted-set enumeration built from an iterated
645/// `CaixaDialeto::ALL.iter().map(|d| d.into())` pipe rather than a
646/// per-arm `match d { … }` cascade; a
647/// `HashMap::<&'static str, CaixaDialeto>::from_iter(
648/// CaixaDialeto::ALL.iter().map(|d| (d.into(), *d)))`-style
649/// per-dialect reverse-lookup table the sibling [`TryFrom<&str>`] impl
650/// cannot compose without this borrowed-input axis in place) reaches the
651/// same four `"Pacote"` / `"Molde"` / `"MoldePosicional"` /
652/// `"Desconhecido"` byte-strings the paired owned-input
653/// [`From<CaixaDialeto> for &'static str`], the sibling
654/// [`std::fmt::Display`], [`AsRef<str>`], and [`CaixaDialeto::as_str`]
655/// surfaces already return.
656///
657/// Third peer on the substrate-wide trait-idiomatic *borrowed-input*
658/// forward-projection family opened on
659/// [`crate::dep::DepList`] (64aa742) and extended onto
660/// [`crate::CaixaKind`] (5ab993a). Rust's `From` trait does not
661/// auto-derive the `From<&Self>` sibling from a `From<Self>` impl (the
662/// blanket `impl<T, U> From<&T> for U where T: Copy, U: From<T>` does
663/// not exist in `core`), so every closed-set typed enum that carries
664/// the owned-input axis but not the borrowed-input axis forces every
665/// borrowed-input call site through a `.copied()` /
666/// `<&'static str>::from(*dialeto)` / `dialeto.as_str()` detour whose
667/// type bounds have no compile-time link to the substrate primitive.
668///
669/// Unlike the peer [`crate::CaixaKind`] impl (which carries a two-axis
670/// split between the lowercase Portuguese `as_str` diagnostic axis and
671/// the `PascalCase` `wire_name` author-surface axis, so a `.into()`
672/// pipe over `CaixaKind::ALL` yields the diagnostic vocabulary rather
673/// than the wire vocabulary), [`CaixaDialeto`]'s [`CaixaDialeto::as_str`]
674/// and [`CaixaDialeto::from_wire`] share the same `PascalCase`
675/// vocabulary by construction — the borrowed-input projection this impl
676/// exposes therefore composes directly with the sibling
677/// [`TryFrom<&str>`] axis to build reverse-lookup tables without the
678/// wire-vocab intermediate hop the peer axis pair requires.
679///
680/// Pinned load-bearing by
681/// [`tests::caixa_dialeto_from_borrowed_into_static_str_routes_through_as_str_accessor`]
682/// (byte-parity pin against [`CaixaDialeto::as_str`] across the four-arm
683/// emit-set via a borrowed input, plus a `const`-context materialization
684/// witness for the `&'static str` lifetime promise, plus a blanket
685/// `.into()` shape assertion) and
686/// [`tests::caixa_dialeto_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
687/// (cross-axis partition pin against the paired owned-input
688/// [`From<CaixaDialeto> for &'static str`] impl, plus a
689/// `.iter().map(Into::into)` pipe witness over [`CaixaDialeto::ALL`]
690/// that materializes the four-arm accept-set through the borrowed-input
691/// axis alone, plus a direct round-trip witness through the paired
692/// trait-idiomatic [`TryFrom<&str>`] axis that closes the two-way
693/// `&Self → &'static str → Self` round-trip on the borrowed-input axis
694/// without the wire-vocab intermediate the peer [`crate::CaixaKind`]
695/// axis pair requires).
696impl From<&CaixaDialeto> for &'static str {
697 fn from(dialeto: &CaixaDialeto) -> &'static str {
698 dialeto.as_str()
699 }
700}
701
702/// Trait-idiomatic *forward* projection on [`CaixaDialeto`] from an *owned*
703/// input onto the owned-[`String`] axis — routes byte-for-byte through the
704/// substrate-primitive [`CaixaDialeto::as_str`] `pub const fn` accessor so
705/// every consumer that binds a [`CaixaDialeto`] through the standard-library
706/// `.into()` / [`From<Self> for String`] (equivalently [`Into<String>`]) axis
707/// reaches the same four `"Pacote"` / `"Molde"` / `"MoldePosicional"` /
708/// `"Desconhecido"` byte-strings the paired owned-input
709/// [`From<CaixaDialeto> for &'static str`], the borrowed-input
710/// [`From<&CaixaDialeto> for &'static str`], the sibling [`std::fmt::Display`],
711/// [`AsRef<str>`], and [`CaixaDialeto::as_str`] surfaces already return.
712///
713/// Extends the trait-idiomatic *owned-[`String`]* forward-projection family
714/// (opened on [`crate::supervisor::RestartStrategy`] — 7baa18a — the first-
715/// mover on the M2 OTP-shape sibling-restart-strategy axis, extended onto
716/// [`crate::supervisor::RestartPolicy`] — 7851725 — the second-of-two-in-M2
717/// per-child restart-decision axis, then onto [`crate::CaixaKind`] — 231a18c
718/// — the structurally most fundamental closed-set fieldless typed enum on
719/// the caixa surface) onto the fourth peer: the dialect-classification axis
720/// [`CaixaDialeto`] carries. Rust's standard library does not carry a blanket
721/// `impl<T: AsRef<str>> From<T> for String` (nor an
722/// `impl<T: fmt::Display> From<T> for String`), so every closed-set typed
723/// enum that carries the paired `AsRef<str>` / `Display` /
724/// `From<Self> for &'static str` triple but not the owned-[`String`] axis
725/// forces every owned-string call site through a `.to_string()` /
726/// `.as_str().to_owned()` / `String::from(dialeto.as_str())` detour whose
727/// type bounds have no compile-time link to the substrate primitive.
728///
729/// Unlike the peer [`crate::CaixaKind`] enum (which carries a two-axis split
730/// between the lowercase Portuguese [`crate::CaixaKind::as_str`] diagnostic
731/// axis and the `PascalCase` [`crate::CaixaKind::wire_name`] author-surface
732/// axis, so the owned-[`String`] forward emit and the reverse
733/// [`TryFrom<&str>`] parse land on disjoint vocabularies and the round-trip
734/// crosses through [`crate::CaixaKind::wire_name`] as the reverse-axis
735/// vocabulary rather than composing the owned-[`String`] emit directly),
736/// [`CaixaDialeto`]'s [`CaixaDialeto::as_str`] emit and
737/// [`CaixaDialeto::from_wire`] parse share the same `PascalCase` vocabulary
738/// by construction (there is no wire/diagnostic axis split on this enum —
739/// it is an internal classification with no wire surface), so the
740/// owned-[`String`] forward projection this impl exposes composes directly
741/// with the sibling [`TryFrom<&str>`] axis on the owned-[`String`]'s
742/// [`String::as_str`] borrow, byte-identically to the peer
743/// [`crate::supervisor::RestartStrategy`] /
744/// [`crate::supervisor::RestartPolicy`] owned-[`String`] axis pairs
745/// (whose forward emit and reverse parse also share one `PascalCase`
746/// vocabulary by construction).
747///
748/// The remaining ten closed-set typed enums on the caixa substrate surface
749/// (`DepList`, `PlacementStrategy`, `WitShape`, `RateLimitUnit`,
750/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
751/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets of
752/// this campaign — each carries the same paired `AsRef<str>` / `Display` /
753/// `From<Self> for &'static str` / `From<&Self> for &'static str` quadruple
754/// that this owned-[`String`] axis extends onto.
755///
756/// Pinned load-bearing by
757/// [`tests::caixa_dialeto_from_into_owned_string_routes_through_as_str_accessor`]
758/// (byte-parity pin against [`CaixaDialeto::as_str`] across the four-arm
759/// emit-set, plus a blanket `.into::<String>()` shape witness) and
760/// [`tests::caixa_dialeto_from_into_owned_string_and_static_str_agree_on_every_arm`]
761/// (cross-axis partition pin against the paired owned-input
762/// [`From<CaixaDialeto> for &'static str`] impl and the sibling
763/// [`ToString::to_string`] surface routed through [`std::fmt::Display`],
764/// plus a `.iter().copied().map(String::from)` pipe witness over
765/// [`CaixaDialeto::ALL`], plus a direct round-trip witness through
766/// [`TryFrom<&str>`] on the owned-[`String`]'s [`String::as_str`] borrow
767/// that closes the two-way `Self → String → Self` round-trip on the
768/// trait-idiomatic owned-[`String`] forward + reverse axis pair without
769/// the wire-vocab intermediate hop the peer [`crate::CaixaKind`] axis pair
770/// requires).
771impl From<CaixaDialeto> for String {
772 fn from(dialeto: CaixaDialeto) -> String {
773 dialeto.as_str().to_owned()
774 }
775}
776
777/// Trait-idiomatic *borrowed-input, owned-`String` output* forward
778/// projection on the dialect-classification [`CaixaDialeto`] closed-set
779/// typed enum — the fourth (and closing) corner of the
780/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
781/// projection family on this enum, mirror of the peer M2 OTP-shape
782/// [`From<&crate::supervisor::RestartStrategy> for String`] (579385f) /
783/// [`From<&crate::supervisor::RestartPolicy> for String`] (8465740),
784/// the two-list dep-graph [`From<&crate::dep::DepList> for String`]
785/// (e0cb617), and the top-level [`From<&crate::CaixaKind> for String`]
786/// (e76436d) that opened and extended the corner off the M2 OTP-shape
787/// sibling axis pair onto the sibling closed-set fieldless typed enum
788/// peers. Routes byte-for-byte through the substrate-primitive
789/// [`CaixaDialeto::as_str`] `pub const fn` accessor (via
790/// [`str::to_owned`]) so every consumer that holds a borrowed
791/// [`&CaixaDialeto`] and needs an owned [`String`] — a future
792/// `serde_json::Value::String(String::from(&dialeto))` structured-
793/// payload composer over a borrowed field, a future `Iterator::map`
794/// over `&[CaixaDialeto]` that projects to owned keys through
795/// `.iter().map(String::from)` (whose iterator yields `&CaixaDialeto`,
796/// not `CaixaDialeto`, so the owned-input
797/// [`From<CaixaDialeto> for String`] axis alone forces every call site
798/// through an explicit `.copied()` / spurious [`Copy`] deref restatement
799/// rather than the direct trait-idiomatic projection), a future
800/// `HashMap::<String, CaixaDialeto>::from_iter` that keys off a
801/// borrowed-iteration axis where dereferencing the dialect would force
802/// an unnecessary [`Copy`] at every step, the future
803/// `feira dialeto --list-dialects` CLI enumeration that walks
804/// [`CaixaDialeto::ALL`] through the borrowed-iteration axis by
805/// construction, the future M4
806/// `mesh.pleme.io/v1alpha1/Manifesto` CR materializer's admission-
807/// webhook rejection body composer that names the accepted-dialect
808/// set through an iterated `.iter().map(String::from).collect()`
809/// pipe rather than a per-arm cascade — reaches the same four
810/// `"Pacote"` / `"Molde"` / `"MoldePosicional"` / `"Desconhecido"`
811/// byte-strings the paired [`std::fmt::Display`], [`AsRef<str>`],
812/// [`CaixaDialeto::as_str`], and the three other trait-idiomatic
813/// forward-projection impls ([`From<CaixaDialeto> for &'static str`],
814/// [`From<&CaixaDialeto> for &'static str`],
815/// [`From<CaixaDialeto> for String`]) already return.
816///
817/// Fifth peer on the substrate-wide trait-idiomatic *borrowed-input,
818/// owned-`String` output* forward-projection family opened on
819/// [`crate::supervisor::RestartStrategy`] (579385f), closed on the M2
820/// OTP-shape sibling axis pair by
821/// [`crate::supervisor::RestartPolicy`] (8465740), extended onto the
822/// two-list dep-graph peer by [`crate::dep::DepList`] (e0cb617) and
823/// onto the top-level [`crate::CaixaKind`] (e76436d) — extends the
824/// `{Self, &Self} × {&'static str, String}` 2×2 projection corner off
825/// the top-level `:kind` axis onto the dialect-classification axis
826/// (the fourth closed-set fieldless typed enum on the caixa surface;
827/// second peer outside the M2 OTP-shape sibling pair to reach the
828/// 2×2-completion corner). Rust's standard library does not carry a
829/// blanket `impl<T: AsRef<str>> From<&T> for String` (nor an
830/// `impl<T: fmt::Display> From<&T> for String`), so every closed-set
831/// typed enum that carries the paired `AsRef<str>` / `Display` /
832/// `From<Self> for &'static str` / `From<&Self> for &'static str` /
833/// `From<Self> for String` quintuple but not the borrowed-input
834/// owned-[`String`] axis forces every borrowed-input owned-string call
835/// site through a `dialeto.as_str().to_owned()` /
836/// `String::from(*dialeto)` (with a spurious [`Copy`]) /
837/// `dialeto.to_string()` (through [`std::fmt::Display`]) detour whose
838/// type bounds have no compile-time link to the substrate primitive.
839///
840/// Same as the peer [`crate::supervisor::RestartStrategy`] /
841/// [`crate::supervisor::RestartPolicy`] / [`crate::dep::DepList`]
842/// borrowed-input owned-[`String`] axis pairs (whose forward emit and
843/// reverse parse share one vocabulary by construction — `PascalCase`
844/// on the M2 OTP-shape peers, the lifted
845/// [`crate::render::DEP_AUTHOR_KEY_DEPS`] /
846/// [`crate::render::DEP_AUTHOR_KEY_DEPS_DEV`] consts on the two-list
847/// dep-graph peer) and unlike the peer [`crate::CaixaKind`] pair
848/// (whose forward emit lands on the lowercase Portuguese
849/// diagnostic vocabulary while the reverse parse lands on the
850/// `PascalCase` wire vocabulary, forcing the round-trip through an
851/// intermediate [`crate::CaixaKind::wire_name`] hop), [`CaixaDialeto`]
852/// is an internal classification with no wire surface — the
853/// [`CaixaDialeto::as_str`] emit and [`CaixaDialeto::from_wire`] parse
854/// share the same `PascalCase` vocabulary by construction (there is
855/// no wire/diagnostic axis split on this enum), so the borrowed-
856/// input owned-[`String`] projection this impl exposes composes
857/// directly with the paired trait-idiomatic reverse [`TryFrom<&str>`]
858/// axis on the owned-[`String`]'s [`String::as_str`] borrow — no
859/// intermediate wire-vocab hop required.
860///
861/// The remaining nine closed-set typed enums on the caixa substrate
862/// surface (`PlacementStrategy`, `WitShape`, `RateLimitUnit`,
863/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
864/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets
865/// of this 2×2-completion campaign — each carries the same paired
866/// quintuple that this borrowed-input owned-[`String`] axis extends
867/// onto.
868///
869/// Pinned load-bearing by
870/// [`tests::caixa_dialeto_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
871/// (byte-parity pin against [`CaixaDialeto::as_str`] across the
872/// four-arm emit-set through the borrowed-input surface) and
873/// [`tests::caixa_dialeto_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
874/// (cross-axis partition pin against the paired owned-input owned-
875/// [`String`] [`From<CaixaDialeto> for String`] impl, the paired
876/// borrowed-input owned-[`&'static str`]
877/// [`From<&CaixaDialeto> for &'static str`] impl, the paired owned-
878/// input owned-[`&'static str`] [`From<CaixaDialeto> for &'static str`]
879/// impl, and the sibling [`ToString::to_string`] surface routed
880/// through [`std::fmt::Display`], plus a `.iter().map(String::from)`
881/// pipe witness over [`CaixaDialeto::ALL`] (whose iterator yields
882/// `&CaixaDialeto` by construction, so the borrowed-input owned-
883/// [`String`] axis is what routes the pipe through the substrate-
884/// primitive [`CaixaDialeto::as_str`] accessor without a spurious
885/// [`Copy`] deref), plus a direct round-trip witness through
886/// [`TryFrom<&str>`] on the owned-[`String`]'s [`String::as_str`]
887/// borrow that closes the two-way `&Self → String → Self` round-trip
888/// on the trait-idiomatic borrowed-input owned-[`String`] forward +
889/// reverse axis pair — no intermediate wire-vocab hop like the peer
890/// [`crate::CaixaKind`] axis pair requires).
891impl From<&CaixaDialeto> for String {
892 fn from(dialeto: &CaixaDialeto) -> String {
893 dialeto.as_str().to_owned()
894 }
895}
896
897/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, str>`]
898/// output* forward projection on the dialect-classification
899/// [`CaixaDialeto`] closed-set typed enum — routes byte-for-byte
900/// through the substrate-primitive [`CaixaDialeto::as_str`]
901/// `pub const fn` accessor (via [`std::borrow::Cow::Borrowed`]) so
902/// every consumer that binds a [`CaixaDialeto`] through the
903/// standard-library `.into()` /
904/// [`From<Self> for std::borrow::Cow<'static, str>`] (equivalently
905/// [`Into<std::borrow::Cow<'static, str>>`]) axis — a future
906/// `axum::response::IntoResponse` body composer whose typing folds a
907/// per-arm rejection line into a [`std::borrow::Cow<'static, str>`]
908/// boundary, a future M4 `mesh.pleme.io/v1alpha1/Manifesto` CR
909/// materializer's admission-webhook rejection body composer whose
910/// typing rules out the sibling [`AsRef<str>`] borrowed return and
911/// the sibling [`From<Self> for &'static str`] axis's non-
912/// [`std::borrow::Cow`]-parameterized shape, a future substrate-wide
913/// per-arm diagnostic surface that folds either the zero-alloc
914/// [`std::borrow::Cow::Borrowed`] arm (for the closed-set arms whose
915/// byte-string is build-time-lifted) or the [`std::borrow::Cow::Owned`]
916/// arm (for a caller that mutates the projection) through one uniform
917/// trait dispatch, a future generic
918/// `<T: Into<std::borrow::Cow<'static, str>>>`-bound emitter on a
919/// per-dialect structured-log or admission-webhook rejection body —
920/// reaches the same four `"Pacote"` / `"Molde"` / `"MoldePosicional"` /
921/// `"Desconhecido"` byte-strings the paired [`std::fmt::Display`],
922/// [`AsRef<str>`], [`CaixaDialeto::as_str`], and the four
923/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
924/// forward-projection corners
925/// ([`From<CaixaDialeto> for &'static str`],
926/// [`From<&CaixaDialeto> for &'static str`],
927/// [`From<CaixaDialeto> for String`],
928/// [`From<&CaixaDialeto> for String`]) already return, rather than an
929/// open-coded per-call-site
930/// `std::borrow::Cow::Borrowed(dialeto.as_str())` /
931/// `std::borrow::Cow::Owned(dialeto.to_string())` /
932/// `String::from(dialeto).into()` composition whose type bounds have
933/// no compile-time link back to the substrate primitive.
934///
935/// Deliberately returns [`std::borrow::Cow::Borrowed`] rather than
936/// [`std::borrow::Cow::Owned`] — the substrate-primitive
937/// [`CaixaDialeto::as_str`] accessor's return carries the
938/// `&'static str` lifetime by construction (each `match` arm resolves
939/// to a `pub const &'static str` literal with static lifetime), so the
940/// zero-alloc borrowed arm is the type-correct projection with no
941/// runtime allocation. The paired [`std::borrow::Cow::Owned`] arm
942/// stays reachable at the call site through the existing
943/// [`From<CaixaDialeto> for String`] axis composed with
944/// [`std::borrow::Cow::from`] on the resulting owned [`String`] — a
945/// caller who chose to mutate the projection lands on the owned arm
946/// by their own composition, not by the substrate-primitive
947/// projection silently allocating on their behalf.
948///
949/// Same as the sibling [`crate::CaixaKind`] /
950/// [`crate::supervisor::RestartStrategy`] /
951/// [`crate::supervisor::RestartPolicy`] /
952/// [`crate::aplicacao::WitShape`] /
953/// [`crate::aplicacao::PlacementStrategy`] /
954/// [`crate::aplicacao::RateLimitUnit`] /
955/// [`crate::dep::DepList`] peers on the substrate-wide trait-idiomatic
956/// [`std::borrow::Cow<'static, str>`] forward-projection campaign,
957/// unlike the peer [`crate::CaixaKind`] pair (whose forward emit
958/// lands on the lowercase Portuguese diagnostic vocabulary while the
959/// reverse parse lands on the `PascalCase` wire vocabulary, forcing
960/// the round-trip through an intermediate
961/// [`crate::CaixaKind::wire_name`] hop), [`CaixaDialeto`] is an
962/// internal classification with no wire surface — the
963/// [`CaixaDialeto::as_str`] emit and [`CaixaDialeto::from_wire`]
964/// parse share the same `PascalCase` vocabulary by construction (no
965/// wire/diagnostic axis split on this enum), so the
966/// [`std::borrow::Cow<'static, str>`] projection this impl exposes
967/// composes directly with the paired trait-idiomatic reverse
968/// [`TryFrom<&str>`] axis on the projection's
969/// [`std::borrow::Cow::as_ref`] borrow — no intermediate wire-vocab
970/// hop required.
971///
972/// Eighth peer on the substrate-wide trait-idiomatic
973/// [`std::borrow::Cow<'static, str>`] forward-projection family
974/// opened on the top-level [`crate::CaixaKind`] by 99c1735 (extended
975/// off the closed `{Self, &Self} × {&'static str, String}` 2×2
976/// corner closed on the last outside-caixa-core enum peer by
977/// 29f8af3), closed on the `{Self, &Self}` input-shape corner on
978/// [`crate::CaixaKind`] by d45c409, extended onto the M2 OTP-shape
979/// tier by 7dd28b3 / 9b3e4b3 (opens/closes on
980/// [`crate::supervisor::RestartStrategy`]) and 0612398 / ee577fd
981/// (opens/closes on [`crate::supervisor::RestartPolicy`], closing the
982/// M2 OTP-shape tier), extended onto the M3 mesh-shape tier by
983/// 8634dec / 25690ef (opens/closes on [`crate::aplicacao::WitShape`])
984/// and eee504d / afdf0f4 (opens/closes on
985/// [`crate::aplicacao::PlacementStrategy`]) and 1d59925 (closes M3
986/// mesh-shape tier on [`crate::aplicacao::RateLimitUnit`]), extended
987/// onto the outside-M3 caixa-core tier by 6858bac / 702cdf4
988/// (opens/closes on [`crate::dep::DepList`]) — extends the axis onto
989/// the dialect-classification [`CaixaDialeto`] closed-set fieldless
990/// typed enum (the second outside-M3 caixa-core peer, and the sole
991/// remaining internal-classification enum on the caixa-core surface).
992/// Rust's standard library does not carry a blanket
993/// `impl<T: AsRef<str>> From<T> for std::borrow::Cow<'static, str>`
994/// (nor an `impl<T: fmt::Display> From<T> for
995/// std::borrow::Cow<'static, str>`), so every closed-set fieldless
996/// typed enum peer on the substrate that carries the paired
997/// [`AsRef<str>`] / [`std::fmt::Display`] /
998/// [`From<Self> for &'static str`] / [`From<&Self> for &'static str`]
999/// / [`From<Self> for String`] / [`From<&Self> for String`] sextet but
1000/// not the [`std::borrow::Cow<'static, str>`] axis forces every
1001/// [`std::borrow::Cow<'static, str>`]-parameterized call site through
1002/// a `std::borrow::Cow::Borrowed(dialeto.as_str())` /
1003/// `std::borrow::Cow::Owned(dialeto.to_string())` /
1004/// `String::from(dialeto).into()` detour whose type bounds have no
1005/// compile-time link to the substrate primitive.
1006///
1007/// The remaining outside-`caixa-core` closed-set fieldless typed
1008/// enum peers on the substrate surface (`PathShapeViolation`,
1009/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`,
1010/// `Semantic`, `FerriteRuntime`) are the future targets of this
1011/// campaign — each carries the same paired sextet that this axis
1012/// extends onto.
1013///
1014/// Pinned load-bearing by
1015/// [`tests::caixa_dialeto_from_into_static_cow_str_routes_through_as_str_accessor`]
1016/// (byte-parity pin against [`CaixaDialeto::as_str`] across the
1017/// four-arm emit-set through the [`std::borrow::Cow<'static, str>`]
1018/// surface, plus a [`std::borrow::Cow::Borrowed`] discriminator
1019/// witness that the projection lands on the zero-alloc arm rather
1020/// than silently allocating through [`std::borrow::Cow::Owned`],
1021/// plus a blanket-derived [`Into<std::borrow::Cow<'static, str>>`]
1022/// shape witness that also lands on [`std::borrow::Cow::Borrowed`])
1023/// and
1024/// [`tests::caixa_dialeto_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
1025/// (cross-axis partition pin against the paired owned-input
1026/// [`From<CaixaDialeto> for &'static str`] and
1027/// [`From<CaixaDialeto> for String`] forward-projection corners plus
1028/// the sibling [`ToString::to_string`]-through-[`std::fmt::Display`]
1029/// surface, plus a `.iter().copied().map(std::borrow::Cow::from)`
1030/// pipe witness over [`CaixaDialeto::ALL`] whose zero-alloc
1031/// [`std::borrow::Cow::Borrowed`] outcome is load-bearing on every
1032/// arm, plus a direct round-trip witness through [`TryFrom<&str>`]
1033/// on the projection's [`std::borrow::Cow::as_ref`] borrow that
1034/// closes the two-way `Self → Cow<'static, str> → Self` round-trip
1035/// on the trait-idiomatic [`std::borrow::Cow<'static, str>`]
1036/// forward + reverse axis pair without the wire-vocab intermediate
1037/// hop the peer [`crate::CaixaKind`] axis pair requires).
1038impl From<CaixaDialeto> for std::borrow::Cow<'static, str> {
1039 fn from(dialeto: CaixaDialeto) -> std::borrow::Cow<'static, str> {
1040 std::borrow::Cow::Borrowed(dialeto.as_str())
1041 }
1042}
1043
1044/// A source that is not a `(defcaixa …)` / `(defmolde …)` form at all.
1045#[derive(Debug, Clone, PartialEq, Eq, thiserror::Error)]
1046pub enum DialetoError {
1047 #[error("source has no top-level form")]
1048 Vazio,
1049 #[error("top-level form is not a list — a manifest is `(defcaixa …)`")]
1050 NaoEhLista,
1051 #[error(
1052 "top-level form is headed by `{encontrado}`, not `defcaixa` or `defmolde` \
1053 (a manifest's first form must be the declaration itself)"
1054 )]
1055 CabecaErrada { encontrado: String },
1056 #[error("manifest does not parse as tatara-lisp: {0}")]
1057 Leitura(String),
1058}
1059
1060impl DialetoError {
1061 /// Construct a [`DialetoError::CabecaErrada`] naming the offending
1062 /// head symbol found at the top-level form.
1063 ///
1064 /// Substrate primitive every [`classify_form`] wrong-head fallthrough
1065 /// wire-up site now routes through, folding the pre-lift uniform
1066 /// three-line `Self::CabecaErrada { encontrado: <head>.to_string() }`
1067 /// one-field struct-literal onto one substrate primitive matching the
1068 /// peer `LimitsError::unknown_byte_unit(unit: &str)` /
1069 /// `LimitsError::unknown_duration_unit(unit: &str)`
1070 /// (`limits_codec_unit_only_ctors!` — 29fac09) single-slot
1071 /// discipline on the sibling one-field `{ <field>: String }` envelope
1072 /// axis, and matching the peer `ManifestError::code_path_empty` /
1073 /// `BehaviorError::empty_path` / `UpgradeError::duplicate_from` /
1074 /// `AplicacaoError::placement_cluster_duplicate` (94dabc8 / 0e33b37 /
1075 /// 7e52aec / 92b1c92) single-slot inherent-ctor discipline every
1076 /// sibling `{ <field>: <T> }` error-envelope variant on caixa-core's
1077 /// error surface now carries.
1078 ///
1079 /// The one open-coded wire-up site — `classify_form`'s wrong-head
1080 /// fallthrough arm on the `head: &str` binding read from the
1081 /// top-level form via [`tatara_lisp::Sexp::as_symbol`] — opened the
1082 /// identical three-line
1083 /// `Self::CabecaErrada { encontrado: <head>.to_string() }` block
1084 /// against the codec-scoped `<head>: &str` binding. Now routes
1085 /// through `DialetoError::cabeca_errada(head)`, byte-equal to the
1086 /// pre-lift struct-literal on the same `&str` fixture, so any future
1087 /// widening of the diagnostic shape (e.g. carrying the source-file
1088 /// path alongside the head symbol, carrying the head symbol's
1089 /// position offset for an authoring-surface caret pointer) lands at
1090 /// exactly one dispatch on the substrate primitive rather than re-
1091 /// inlining the struct-literal at every wrong-head fallthrough
1092 /// consumer.
1093 #[must_use]
1094 pub fn cabeca_errada(encontrado: &str) -> Self {
1095 Self::CabecaErrada {
1096 encontrado: encontrado.to_string(),
1097 }
1098 }
1099
1100 /// Construct a [`DialetoError::Leitura`] carrying the offending
1101 /// tatara-lisp reader-error message `reason` verbatim in the
1102 /// variant's tuple-newtype payload.
1103 ///
1104 /// Substrate primitive every [`classify`] tatara-lisp-reader
1105 /// map-err wire-up site now routes through, folding the pre-lift
1106 /// uniform `Self::Leitura(<into-String-expr>)` tuple-newtype
1107 /// construction onto one substrate primitive matching the peer
1108 /// `LimitsError::empty_byte_size` / `LimitsError::empty_duration`
1109 /// (7a4b003 / 319216c) `(String)` single-slot tuple-newtype
1110 /// discipline on the sibling
1111 /// [`crate::limits::LimitsError`] envelope's empty-shape axis of
1112 /// the paired codec-magnitude family. Peer to the sibling
1113 /// [`DialetoError::cabeca_errada`] ctor on the same envelope's
1114 /// wrong-head axis but on the tatara-lisp-reader axis rather than
1115 /// the classifier-fallthrough axis. Closes the last un-lifted
1116 /// variant on [`DialetoError`] — every one of the sole wire-up
1117 /// sites (the [`classify`] tatara-lisp-reader `.map_err(|e|
1118 /// Self::Leitura(e.to_string()))` arm) opened the identical
1119 /// `DialetoError::Leitura(<into-String-expr>)` block against the
1120 /// codec-scoped `String` (`e.to_string()`) binding, so the fold
1121 /// routes the site through one dispatch on a uniform
1122 /// `impl Into<String>` param, byte-equal to the pre-lift
1123 /// tuple-newtype construction on the same argument.
1124 ///
1125 /// The `impl Into<String>` bound covers both wire-up shapes on
1126 /// [`classify`] — a `String` binding (`e.to_string()` on the
1127 /// [`tatara_lisp::Error`]-carrying `e` binding) and a `&str`
1128 /// binding (a future admission-webhook consumer probing a
1129 /// caller-scoped `&'static str` fixture, a future
1130 /// `feira lint --tatara-reader-round-trip` verb sweeping every
1131 /// `tatara_lisp::read` return through the same shape gate) —
1132 /// without forcing the caller to spell the conversion at the
1133 /// wire-up site. Same shape the peer
1134 /// [`crate::limits::LimitsError::empty_byte_size`] /
1135 /// [`crate::limits::LimitsError::empty_duration`] /
1136 /// [`crate::limits::LimitsError::bad_millicores`] /
1137 /// [`crate::limits::LimitsError::bad_byte_magnitude`] /
1138 /// [`crate::limits::LimitsError::bad_duration_magnitude`] folds
1139 /// carry on the peer bad-magnitude and empty-shape axes of the
1140 /// same paired `(String)` tuple-newtype codec-magnitude family.
1141 /// `#[must_use]` fires a compile warning at any wire-up that
1142 /// mistakenly discards the constructed error.
1143 ///
1144 /// Every future consumer that wants to construct this variant
1145 /// outside [`classify`] (a deferred `feira lint --tatara-reader-
1146 /// round-trip` per-caixa admission verb probing each authored
1147 /// manifest against the tatara-lisp-reader shape gate, an M4
1148 /// typed `mesh.pleme.io/v1alpha1/Servico` CR materializer's
1149 /// per-manifest admission validator re-checking one edited
1150 /// `caixa.lisp` against the reader floor, a per-`caixa.lisp`
1151 /// value-shape pre-emitter probing each declared manifest ahead
1152 /// of the operator's admit-cycle) now reaches the variant
1153 /// through one call rather than re-inlining the tuple-newtype
1154 /// block in lockstep with the pre-existing wire-up.
1155 #[must_use]
1156 pub fn leitura(reason: impl Into<String>) -> Self {
1157 Self::Leitura(reason.into())
1158 }
1159}
1160
1161/// Classify a manifest source without committing to either schema.
1162///
1163/// Deliberately reads only the head symbol and the set of top-level keywords —
1164/// enough to route, never enough to half-parse. A classifier that started
1165/// validating would grow into a third parser, which is the shape of the problem
1166/// it exists to name.
1167///
1168/// # Errors
1169/// [`DialetoError`] when the source is not a manifest declaration at all.
1170pub fn classify(src: &str) -> Result<CaixaDialeto, DialetoError> {
1171 let forms = tatara_lisp::read(src).map_err(|e| DialetoError::leitura(e.to_string()))?;
1172 let first = forms.first().ok_or(DialetoError::Vazio)?;
1173 classify_form(first)
1174}
1175
1176/// [`classify`] over an already-read form.
1177///
1178/// # Errors
1179/// [`DialetoError`] when the form is not a manifest declaration.
1180pub fn classify_form(form: &Sexp) -> Result<CaixaDialeto, DialetoError> {
1181 let list = form.as_list().ok_or(DialetoError::NaoEhLista)?;
1182 let head = list
1183 .first()
1184 .and_then(Sexp::as_symbol)
1185 .ok_or(DialetoError::NaoEhLista)?;
1186
1187 match head {
1188 // `defmolde` is unambiguous by construction — it exists precisely so a
1189 // consumer never has to infer which declaration it holds. Both arities
1190 // are the same declaration; the positional one keeps its own variant
1191 // only so a census can report the split.
1192 "defmolde" => {
1193 return Ok(if starts_with_positional_name(&list[1..]) {
1194 CaixaDialeto::MoldePosicional
1195 } else {
1196 CaixaDialeto::Molde
1197 });
1198 }
1199 "defcaixa" => {}
1200 other => {
1201 return Err(DialetoError::cabeca_errada(other));
1202 }
1203 }
1204
1205 let args = &list[1..];
1206
1207 // `(defcaixa <symbol> :kind … :ecosystem …)`. Only the Molde dialect has a
1208 // positional arity; `Caixa` is keyword-only, so a leading bare symbol
1209 // settles it without looking further.
1210 if starts_with_positional_name(args) {
1211 return Ok(CaixaDialeto::MoldePosicional);
1212 }
1213
1214 let keys = top_level_keywords(args);
1215 let has = |k: &str| keys.iter().any(|s| s == k);
1216
1217 // Order matters, and it is not arbitrary: `:nome` and `:name` are the two
1218 // required head slots and no file in the measured corpus carries both.
1219 // Checking them FIRST means the decision rests on the one slot each schema
1220 // makes mandatory, rather than on optional evidence like `:ecosystem`.
1221 if has("nome") {
1222 return Ok(CaixaDialeto::Pacote);
1223 }
1224 if has("name") || has("ecosystem") || has("package") {
1225 return Ok(CaixaDialeto::Molde);
1226 }
1227 Ok(CaixaDialeto::Desconhecido)
1228}
1229
1230/// True when the first argument is a bare symbol rather than a keyword — the
1231/// positional-name arity.
1232fn starts_with_positional_name(args: &[Sexp]) -> bool {
1233 matches!(args.first(), Some(Sexp::Atom(Atom::Symbol(_))))
1234}
1235
1236/// The top-level keyword names (without the leading `:`) of a kwarg list.
1237///
1238/// Steps in pairs so a keyword appearing as a VALUE — `:kind :Biblioteca`, or a
1239/// nested `(:nome "dep" :versao "^0.1")` inside `:deps` — is never counted as a
1240/// top-level slot. A naive scan for `:nome` anywhere in the source classifies
1241/// every Molde manifest with a `:deps` list as a Pacote.
1242fn top_level_keywords(args: &[Sexp]) -> Vec<String> {
1243 let mut out = Vec::new();
1244 let mut i = 0;
1245 while i < args.len() {
1246 if let Sexp::Atom(Atom::Keyword(k)) = &args[i] {
1247 out.push(k.clone());
1248 i += 2;
1249 } else {
1250 i += 1;
1251 }
1252 }
1253 out
1254}
1255
1256#[cfg(test)]
1257mod tests {
1258 use super::*;
1259
1260 const PACOTE: &str = r#"
1261 (defcaixa
1262 :nome "checkout"
1263 :versao "0.1.0"
1264 :kind Servico
1265 :deps ((:nome "caixa-teia" :versao "^0.1")))
1266 "#;
1267
1268 const MOLDE: &str = r#"
1269 (defcaixa
1270 :name "base64"
1271 :kind :Biblioteca
1272 :ecosystem :rust-single-crate
1273 :package {:name "base64" :version "0.22.1"}
1274 :workflows [:auto-release])
1275 "#;
1276
1277 const MOLDE_POSICIONAL: &str = r#"
1278 (defcaixa todoku-go
1279 :kind :Biblioteca
1280 :ecosystem :go
1281 :package {:name "todoku-go" :version "0.3.0"})
1282 "#;
1283
1284 #[test]
1285 fn the_package_dialect_is_recognised() {
1286 assert_eq!(classify(PACOTE), Ok(CaixaDialeto::Pacote));
1287 }
1288
1289 #[test]
1290 fn the_repo_surface_dialect_is_recognised() {
1291 assert_eq!(classify(MOLDE), Ok(CaixaDialeto::Molde));
1292 }
1293
1294 #[test]
1295 fn the_positional_arity_is_recognised() {
1296 assert_eq!(
1297 classify(MOLDE_POSICIONAL),
1298 Ok(CaixaDialeto::MoldePosicional)
1299 );
1300 }
1301
1302 #[test]
1303 fn defmolde_classifies_without_inference() {
1304 // The whole point of the new keyword: no schema sniffing required.
1305 let src = r#"(defmolde :name "x" :kind :Biblioteca :ecosystem :go)"#;
1306 assert_eq!(classify(src), Ok(CaixaDialeto::Molde));
1307 let pos = r"(defmolde todoku-go :kind :Biblioteca :ecosystem :go)";
1308 assert_eq!(classify(pos), Ok(CaixaDialeto::MoldePosicional));
1309 }
1310
1311 #[test]
1312 fn a_nested_nome_does_not_make_a_repo_surface_look_like_a_package() {
1313 // The exact failure a substring scan produces: `:deps ((:nome …))`
1314 // contains `:nome`, but not as a top-level slot.
1315 let src = r#"
1316 (defcaixa
1317 :name "x"
1318 :ecosystem :rust-single-crate
1319 :deps ((:nome "inner" :versao "^0.1")))
1320 "#;
1321 assert_eq!(classify(src), Ok(CaixaDialeto::Molde));
1322 }
1323
1324 #[test]
1325 fn a_keyword_in_value_position_is_not_a_slot() {
1326 // `:kind :Biblioteca` — the value is itself a keyword. Stepping one at
1327 // a time would read `:Biblioteca` as a top-level slot.
1328 let src = r#"(defcaixa :kind :Biblioteca :name "x")"#;
1329 assert_eq!(classify(src), Ok(CaixaDialeto::Molde));
1330 }
1331
1332 #[test]
1333 fn an_unrecognised_defcaixa_is_reported_not_guessed() {
1334 let src = r#"(defcaixa :licenca "MIT")"#;
1335 assert_eq!(classify(src), Ok(CaixaDialeto::Desconhecido));
1336 }
1337
1338 #[test]
1339 fn a_form_that_is_not_a_manifest_is_an_error_not_a_dialect() {
1340 assert_eq!(
1341 classify("(defflake :nome \"x\")"),
1342 Err(DialetoError::cabeca_errada("defflake"))
1343 );
1344 assert_eq!(classify(""), Err(DialetoError::Vazio));
1345 }
1346
1347 #[test]
1348 fn every_dialect_names_its_consumer_and_its_canonical_keyword() {
1349 // Guards the routing table itself: a new variant added without an arm
1350 // here is a compile error in the match, and a variant that claims
1351 // `defcaixa` while being read by pleme-doc-gen would re-open the
1352 // collision this module closes. Sweeps [`CaixaDialeto::ALL`] rather
1353 // than the pre-lift open-coded four-arm literal list — a future arm
1354 // addition extends the slice as one edit and this pin picks it up
1355 // by construction.
1356 for &d in CaixaDialeto::ALL {
1357 assert!(!d.descricao().is_empty(), "{d}");
1358 assert!(!d.consumidor().is_empty(), "{d}");
1359 }
1360 assert_eq!(CaixaDialeto::Pacote.palavra_canonica(), "defcaixa");
1361 assert_eq!(CaixaDialeto::Molde.palavra_canonica(), "defmolde");
1362 assert_ne!(
1363 CaixaDialeto::Pacote.palavra_canonica(),
1364 CaixaDialeto::Molde.palavra_canonica(),
1365 "the two dialects must not share a canonical keyword — that IS the defect"
1366 );
1367 }
1368
1369 #[test]
1370 fn caixa_dialeto_all_enumerates_every_variant_exactly_once() {
1371 // Three-legged exhaustiveness pin, peer of the sibling
1372 // `caixa_kind_all_enumerates_every_variant_exactly_once`
1373 // (caixa-core/src/kind.rs) /
1374 // `restart_strategy_all_enumerates_every_variant_exactly_once`
1375 // (caixa-core/src/supervisor.rs) shape.
1376 //
1377 // 1. arm-count invariant: `ALL.len()` matches the declared arm
1378 // count (four — a fifth arm added without extending `ALL`
1379 // fails this pin at caixa-core test time);
1380 // 2. pairwise-distinctness invariant: every variant appears at
1381 // most once in the slice (a duplicate arm would silently
1382 // double-count in the census consumer, so the pin rejects
1383 // duplicates outright);
1384 // 3. coverage invariant: every literal `CaixaDialeto::X` is in
1385 // the slice (the compiler-checked exhaustiveness on the peer
1386 // per-arm `match self` in the accessors keeps the enum arm
1387 // set and the `ALL` slice mutually aligned).
1388 assert_eq!(
1389 CaixaDialeto::ALL.len(),
1390 4,
1391 "ALL must list every arm exactly once; a fifth arm added \
1392 without extending ALL fails this pin — extend ALL alongside \
1393 the new variant"
1394 );
1395
1396 let mut seen: Vec<CaixaDialeto> = Vec::new();
1397 for &d in CaixaDialeto::ALL {
1398 assert!(
1399 !seen.contains(&d),
1400 "ALL contains a duplicate arm: {d}. Every variant appears \
1401 exactly once — a duplicate would double-count in every \
1402 iteration consumer"
1403 );
1404 seen.push(d);
1405 }
1406
1407 // Coverage: exhaustively assert every literal variant is somewhere
1408 // in the slice. Written as an exhaustive `match` so a future arm
1409 // addition fails to compile here (missing match arm) until the
1410 // corresponding `assert` is added — the compiler enforces the pin's
1411 // completeness rather than a hand-maintained variant list.
1412 for variant in [
1413 CaixaDialeto::Pacote,
1414 CaixaDialeto::Molde,
1415 CaixaDialeto::MoldePosicional,
1416 CaixaDialeto::Desconhecido,
1417 ] {
1418 let coverage_probe = match variant {
1419 CaixaDialeto::Pacote
1420 | CaixaDialeto::Molde
1421 | CaixaDialeto::MoldePosicional
1422 | CaixaDialeto::Desconhecido => variant,
1423 };
1424 assert!(
1425 CaixaDialeto::ALL.contains(&coverage_probe),
1426 "ALL is missing variant {coverage_probe} — extend the slice"
1427 );
1428 }
1429 }
1430
1431 #[test]
1432 fn caixa_dialeto_all_is_const_and_matches_iteration_count() {
1433 // Pins the const-ness of the slice at const-fold time. A future
1434 // change that promoted `ALL` to a non-const initializer (a lazy-
1435 // static, a runtime-computed Vec) would fail to compile here —
1436 // the pin locks in the compile-time-known iteration surface
1437 // every consumer builds against. Peer of the sibling
1438 // `caixa_kind_all_is_const_and_matches_iteration_count` (kind.rs)
1439 // / `restart_strategy_all_is_const_and_matches_iteration_count`
1440 // (supervisor.rs) shape.
1441 const ALL: &[CaixaDialeto] = CaixaDialeto::ALL;
1442 assert_eq!(ALL.len(), CaixaDialeto::ALL.len());
1443 // Sweep the iterator without collapsing to `.len()` so a future
1444 // change to `ALL`'s carrier that decouples `.len()` from the
1445 // iteration count (a lazy-computed shape, an alias `impl Iterator`
1446 // return, a wrapper newtype) still passes here iff the two agree
1447 // arm-for-arm; the `#[allow]` opts this local pin out of the
1448 // clippy `iter_count` collapse that would defeat the intent.
1449 #[allow(clippy::iter_count)]
1450 let iterated = ALL.iter().count();
1451 assert_eq!(iterated, CaixaDialeto::ALL.len());
1452 }
1453
1454 #[test]
1455 fn caixa_dialeto_all_covers_every_variant_by_display_probe() {
1456 // Fanning `Display` over the slice sweeps the paired accessors
1457 // ([`CaixaDialeto::palavra_canonica`] / [`CaixaDialeto::consumidor`]
1458 // / [`CaixaDialeto::descricao`]) at every arm — every returned
1459 // byte-string is non-empty (the accessors' contract). A future
1460 // arm added without extending its per-arm `match self` return
1461 // would compile-fail at the accessor call inside the loop;
1462 // together with the `ALL.len() == 4` pin above, this locks the
1463 // accessor arm-set and the `ALL` slice mutually.
1464 for &d in CaixaDialeto::ALL {
1465 let display_form = d.to_string();
1466 assert!(
1467 !display_form.is_empty(),
1468 "Display must render a non-empty byte-string for every \
1469 arm; empty: {d:?}"
1470 );
1471 // Consumidor / descricao / palavra-canonica must each surface
1472 // a non-empty scalar; every downstream diagnostic consumer
1473 // reaches through these accessors.
1474 assert!(!d.palavra_canonica().is_empty(), "{d}");
1475 assert!(!d.consumidor().is_empty(), "{d}");
1476 assert!(!d.descricao().is_empty(), "{d}");
1477 }
1478 }
1479
1480 #[test]
1481 fn caixa_dialeto_as_str_returns_pascal_case_variant_name() {
1482 // Fail-before-pass-after per-arm shape pin: the four
1483 // [`CaixaDialeto::as_str`] arms must return the canonical
1484 // `PascalCase` byte-string that names the variant. Pre-lift this
1485 // byte-string existed only inside the hand-rolled Display impl's
1486 // four-arm literal-string match — every consumer that wanted the
1487 // `PascalCase` name reached through `format!("{d}")`'s allocation
1488 // path. Pinning the four arms explicitly here refuses a future
1489 // regression that ever reroutes an arm to a distinct spelling
1490 // (`"pacote"` lowercase, `"MoldePositional"` English rebrand,
1491 // `"Unknown"` for `Desconhecido`) — the census output and the
1492 // typed accessor would silently disagree until a downstream
1493 // consumer surfaced the drift at census time. Peer of the sibling
1494 // [`crate::supervisor::tests::restart_strategy_variants_serialize_to_lifted_scalar_values`]
1495 // / `placement_strategy_variants_serialize_to_lifted_scalar_values`
1496 // / `caixa_kind_as_str_returns_lifted_peer_const` shape on the
1497 // sibling closed-set typed-enum discriminator axes — the seventh
1498 // (and last unlifted) closed-set typed enum on the caixa surface
1499 // to converge onto the same per-arm-shape-pin discipline.
1500 for (variant, expected) in [
1501 (CaixaDialeto::Pacote, "Pacote"),
1502 (CaixaDialeto::Molde, "Molde"),
1503 (CaixaDialeto::MoldePosicional, "MoldePosicional"),
1504 (CaixaDialeto::Desconhecido, "Desconhecido"),
1505 ] {
1506 assert_eq!(
1507 variant.as_str(),
1508 expected,
1509 "CaixaDialeto::{variant:?}.as_str() must return the \
1510 canonical `PascalCase` variant-name byte-string; drift here \
1511 splits the census-facing text from the substrate \
1512 primitive every downstream consumer will read"
1513 );
1514 }
1515 }
1516
1517 #[test]
1518 fn caixa_dialeto_display_routes_through_as_str_helper() {
1519 // Fail-before-pass-after convergence pin: for every arm in
1520 // [`CaixaDialeto::ALL`], the [`std::fmt::Display`] rendered form
1521 // must byte-equal [`CaixaDialeto::as_str`]'s return value. Pre-
1522 // lift these two paths were structurally independent — the
1523 // Display impl hand-rolled its own four-arm literal-string
1524 // match with no compile-time link back to any substrate accessor
1525 // — so a future variant rename could land at `Display` without
1526 // touching a paired accessor (or vice versa), silently splitting
1527 // the two paths on the renamed arm. Pinning the byte-equality
1528 // here makes any such split a caixa-core build-time failure at
1529 // this test rather than surfacing far from the rename commit as
1530 // a downstream census consumer emitting one spelling while the
1531 // typed accessor returned another. Peer of the sibling
1532 // [`crate::kind::tests::caixa_kind_display_routes_through_as_str_helper`]
1533 // (which pins the same convergence on the [`crate::CaixaKind`]
1534 // closed-set axis) — extends the discipline onto the seventh
1535 // (and last unlifted) closed-set fieldless typed enum on the
1536 // caixa surface.
1537 for &variant in CaixaDialeto::ALL {
1538 assert_eq!(
1539 variant.to_string(),
1540 variant.as_str(),
1541 "CaixaDialeto::{variant:?} Display must route through \
1542 CaixaDialeto::as_str (single source of truth: the \
1543 lifted per-arm `PascalCase` variant-name byte-string)"
1544 );
1545 }
1546 }
1547
1548 #[test]
1549 fn caixa_dialeto_as_ref_str_routes_through_as_str_accessor() {
1550 // Fail-before-pass-after byte-parity pin on the lifted
1551 // `impl AsRef<str> for CaixaDialeto` — asserts the standard-
1552 // library trait impl and the substrate-primitive
1553 // [`CaixaDialeto::as_str`] `pub const fn` accessor resolve to
1554 // the same `&str` per instance across the four-arm closed set,
1555 // so any future silent detour that routes the impl through a
1556 // divergent projection (a per-arm inline
1557 // `match self { CaixaDialeto::Pacote => "Pacote", … }` re-inlining
1558 // that opens a compile-time link to the un-lifted arm-literal,
1559 // a swap onto the second-axis
1560 // [`CaixaDialeto::palavra_canonica`] /
1561 // [`CaixaDialeto::consumidor`] / [`CaixaDialeto::descricao`]
1562 // accessors that carry distinct byte-shapes per axis) trips at
1563 // caixa-core test time under `PartialEq` rather than at a
1564 // downstream `impl AsRef<str>`-bound consumer's silent split.
1565 // Sweeps every one of the four arms [`CaixaDialeto::ALL`]
1566 // carries so no arm's projection is covered only by the sibling
1567 // `Display` path. Peer of the sibling
1568 // `rate_limit_unit_as_ref_str_routes_through_as_suffix_accessor`
1569 // (d8136db) on the M3 `:politicas :rate-limit` closed-set typed
1570 // enum, and the peer
1571 // [`crate::kind::tests::caixa_kind_as_ref_str_routes_through_as_str_accessor`]
1572 // (cd2091f) pin on the top-level closed-set typed
1573 // discriminator — the pins together close the substrate
1574 // primitive's `AsRef<str>` projection axis onto the seventh
1575 // closed-set fieldless typed enum on the caixa surface.
1576 for &variant in CaixaDialeto::ALL {
1577 assert_eq!(
1578 <CaixaDialeto as AsRef<str>>::as_ref(&variant),
1579 variant.as_str(),
1580 "AsRef<str> impl on CaixaDialeto::{variant:?} must \
1581 byte-equal CaixaDialeto::as_str on the same instance \
1582 — divergence signals a silent detour off the \
1583 substrate-primitive accessor"
1584 );
1585 }
1586 }
1587
1588 #[test]
1589 fn caixa_dialeto_as_ref_str_routes_through_display_via_shared_accessor() {
1590 // Fail-before-pass-after byte-parity pin on the three-path
1591 // convergence discipline the [`CaixaDialeto`] closed-set
1592 // dialect-classification enum now carries on the `&str`-
1593 // projection axis: `<CaixaDialeto as AsRef<str>>::as_ref(&v)`
1594 // (the newly lifted impl), `format!("{v}")` (the pre-existing
1595 // [`fmt::Display`] impl), and `v.as_str()` (the substrate-
1596 // primitive `pub const fn` accessor both trait impls delegate
1597 // through) must resolve to the same byte-string on every
1598 // instance across the four-arm closed set. Refuses any future
1599 // divergence between the two trait impls (a stray
1600 // [`fmt::Display::fmt`] rewrite that hand-rolls the arms
1601 // rather than delegating through the shared accessor; a
1602 // hypothetical `AsRef<str>` rewrite that inlines a per-arm
1603 // literal cascade) that would silently split the two
1604 // projection paths of the same closed-set typed enum. Mirrors
1605 // the sibling three-path-convergence discipline the peer
1606 // [`crate::aplicacao::RateLimitUnit`] typed enum carries
1607 // (`rate_limit_unit_as_ref_str_routes_through_display_via_shared_accessor`,
1608 // d8136db), the peer [`crate::CaixaKind`] triple
1609 // (`caixa_kind_as_ref_str_routes_through_display_via_shared_accessor`,
1610 // cd2091f), and the [`crate::CaixaVersion`] typed newtype
1611 // triple (`caixa_version_as_ref_str_routes_through_display_via_shared_accessor`,
1612 // 16d5c7e).
1613 for &variant in CaixaDialeto::ALL {
1614 let via_as_ref: &str = <CaixaDialeto as AsRef<str>>::as_ref(&variant);
1615 let via_display: String = format!("{variant}");
1616 let via_accessor: &str = variant.as_str();
1617 assert_eq!(via_as_ref, via_accessor);
1618 assert_eq!(via_display, via_accessor);
1619 assert_eq!(via_as_ref, via_display.as_str());
1620 }
1621 }
1622
1623 #[test]
1624 fn caixa_dialeto_is_molde_family_returns_true_on_molde_and_positional_arms() {
1625 // Fail-before-pass-after per-arm shape pin on the two `defmolde`
1626 // declaration-family arms: [`CaixaDialeto::is_molde_family`] must
1627 // return `true` for [`CaixaDialeto::Molde`] and
1628 // [`CaixaDialeto::MoldePosicional`] — the two-arity closure of
1629 // one declaration ([`CaixaDialeto::MoldePosicional`]'s docstring:
1630 // "same declaration as [`Self::Molde`], written with the package
1631 // name as a bare positional symbol … one arity of one
1632 // declaration, not a third schema"). A future accidental flip that
1633 // reversed a per-arm arm's return without touching the paired
1634 // false-arm pin would silently open the substrate primitive to
1635 // false-positive on either arm — the `feira dialeto` verb's
1636 // `--strict-palavra` gate would then silently accept
1637 // repo-surface declarations under `(defcaixa …)` on one arm and
1638 // reject them on the other. Pinning the two true arms explicitly
1639 // here refuses that split at caixa-core build time.
1640 assert!(
1641 CaixaDialeto::Molde.is_molde_family(),
1642 "CaixaDialeto::Molde.is_molde_family() must return true — \
1643 Molde is the primary `defmolde` arm"
1644 );
1645 assert!(
1646 CaixaDialeto::MoldePosicional.is_molde_family(),
1647 "CaixaDialeto::MoldePosicional.is_molde_family() must return \
1648 true — MoldePosicional is the positional-arity form of the \
1649 same `defmolde` declaration Molde carries"
1650 );
1651 }
1652
1653 #[test]
1654 fn caixa_dialeto_is_molde_family_returns_false_on_pacote_and_desconhecido_arms() {
1655 // Fail-before-pass-after per-arm shape pin on the two non-`defmolde`
1656 // arms: [`CaixaDialeto::is_molde_family`] must return `false` for
1657 // [`CaixaDialeto::Pacote`] (the sibling `defcaixa` tatara-lisp
1658 // package manifest, `palavra_canonica → "defcaixa"`) and for
1659 // [`CaixaDialeto::Desconhecido`] (the residue that names no
1660 // known declaration, `palavra_canonica → "?"`). Pinning the two
1661 // false arms explicitly here refuses a future accidental flip
1662 // that let the predicate widen to include either arm — the
1663 // `feira dialeto` verb's `--strict-palavra` gate would then
1664 // spuriously refuse every `(defcaixa …)` package manifest as if
1665 // it were a repo-surface declaration.
1666 assert!(
1667 !CaixaDialeto::Pacote.is_molde_family(),
1668 "CaixaDialeto::Pacote.is_molde_family() must return false — \
1669 Pacote is the `defcaixa` tatara-lisp package manifest, not \
1670 the `defmolde` repo-surface declaration"
1671 );
1672 assert!(
1673 !CaixaDialeto::Desconhecido.is_molde_family(),
1674 "CaixaDialeto::Desconhecido.is_molde_family() must return \
1675 false — the residue arm names no known declaration; it is \
1676 not silently promoted into the `defmolde` family"
1677 );
1678 }
1679
1680 #[test]
1681 fn caixa_dialeto_is_molde_family_agrees_with_palavra_canonica_defmolde_projection() {
1682 // Load-bearing pin: for every arm in [`CaixaDialeto::ALL`], the
1683 // typed [`CaixaDialeto::is_molde_family`] predicate must agree
1684 // byte-for-byte with the paired [`CaixaDialeto::palavra_canonica`]
1685 // projection's `== "defmolde"` classifier — i.e. the two paths
1686 // partition the four-arm discriminator set into the same
1687 // `{Molde, MoldePosicional}` and `{Pacote, Desconhecido}` halves.
1688 // Pre-lift the sibling [`CaixaDialeto::palavra_canonica`] projection
1689 // (which returns `"defmolde"` for `Molde | MoldePosicional`,
1690 // `"defcaixa"` for `Pacote`, `"?"` for `Desconhecido`) was the
1691 // only substrate-side surface carrying the two-arm collapse; the
1692 // hand-rolled `matches!(d, CaixaDialeto::Molde |
1693 // CaixaDialeto::MoldePosicional)` sites in the `feira dialeto`
1694 // verb expressed no compile-time link back to it. A future arm
1695 // addition — the module doc's "third dialect" hazard actualises
1696 // as a fifth arm belonging to the `defmolde` family — would land
1697 // one match arm at [`Self::palavra_canonica`]'s `defmolde` return
1698 // (extending the sibling projection) but silently split the
1699 // hand-rolled two-arm `matches!` predicate sites if the new arm's
1700 // `is_molde_family` return were forgotten. Pinning byte-equality
1701 // between the two paths here makes any such split a caixa-core
1702 // build-time failure at this test rather than surfacing far from
1703 // the arm-addition commit as a downstream `--strict-palavra` /
1704 // `caixa.lisp`-holds-wrong-declaration gate silently ignoring the
1705 // new arm.
1706 for &d in CaixaDialeto::ALL {
1707 let via_palavra_canonica = d.palavra_canonica() == "defmolde";
1708 let via_is_molde_family = d.is_molde_family();
1709 assert_eq!(
1710 via_is_molde_family, via_palavra_canonica,
1711 "CaixaDialeto::{d:?}.is_molde_family() ({via_is_molde_family}) \
1712 must agree with CaixaDialeto::{d:?}.palavra_canonica() == \
1713 \"defmolde\" ({via_palavra_canonica}) — a split between the \
1714 typed predicate and the sibling keyword projection would let \
1715 a future arm addition land at one path and drift at the other, \
1716 which is exactly the drift this pin refuses"
1717 );
1718 }
1719 }
1720
1721 #[test]
1722 fn caixa_dialeto_is_molde_family_is_const_fn() {
1723 // Const-context pin: [`CaixaDialeto::is_molde_family`] must remain
1724 // `const fn` (its match is a fieldless-arm literal-pattern
1725 // discriminator, so no non-const operation exists on the resolution
1726 // path). Downstream consumers reaching for the predicate from a
1727 // `const` context (a future substrate-wide const-fold-driven audit
1728 // table that materializes per-arm gate-membership at build time,
1729 // a per-arm CR-admission-webhook gate registration in a `const`
1730 // context) rely on the const-ness. A future accidental downgrade
1731 // to non-`const` (an added runtime helper reachable only from a
1732 // non-`const` context) trips at caixa-core build time rather than
1733 // surfacing as a downstream `const`-context regression far from
1734 // the predicate declaration. Peer of the sibling
1735 // [`caixa_dialeto_as_str_is_const_fn`] pin on the paired
1736 // [`CaixaDialeto::as_str`] byte-string axis.
1737 const ARMS: [(CaixaDialeto, bool); 4] = [
1738 (CaixaDialeto::Pacote, CaixaDialeto::Pacote.is_molde_family()),
1739 (CaixaDialeto::Molde, CaixaDialeto::Molde.is_molde_family()),
1740 (
1741 CaixaDialeto::MoldePosicional,
1742 CaixaDialeto::MoldePosicional.is_molde_family(),
1743 ),
1744 (
1745 CaixaDialeto::Desconhecido,
1746 CaixaDialeto::Desconhecido.is_molde_family(),
1747 ),
1748 ];
1749 // Materialize the const-fold-evaluated table into a runtime slice
1750 // assertion — carries the same `bool = const fn call` shape a raw
1751 // `assert!(const_bool)` would, without tripping the
1752 // `assertions_on_constants` clippy lint that a per-arm
1753 // `assert!(CONST)` on a `const bool` triggers when the arm-count
1754 // is enumerated flat rather than compared as a whole-table shape.
1755 assert_eq!(
1756 ARMS,
1757 [
1758 (CaixaDialeto::Pacote, false),
1759 (CaixaDialeto::Molde, true),
1760 (CaixaDialeto::MoldePosicional, true),
1761 (CaixaDialeto::Desconhecido, false),
1762 ],
1763 "CaixaDialeto::is_molde_family() must evaluate in const context \
1764 for every arm and land on the {{false, true, true, false}} \
1765 partition — a future accidental downgrade to non-`const` \
1766 would trip the const-context array-initializer here"
1767 );
1768 }
1769
1770 #[test]
1771 fn caixa_dialeto_as_str_is_const_fn() {
1772 // Const-context pin: [`CaixaDialeto::as_str`] must remain
1773 // `const fn` (its match arms return `pub const` byte-strings, so
1774 // no non-const operation exists on the resolution path).
1775 // Downstream consumers reaching for the accessor from a `const`
1776 // context (a future substrate-wide const-fold-driven audit table
1777 // that materializes every dialect's census label at build time,
1778 // a per-arm CR-admission-webhook message registration in a
1779 // `const` gate) rely on the const-ness. A future accidental
1780 // downgrade to non-`const` (an added runtime helper reachable
1781 // only from a non-`const` context, a manual hand-rolled `impl`
1782 // that shadows this method) trips at caixa-core build time
1783 // rather than surfacing as a downstream `const`-context
1784 // regression far from the accessor declaration. Peer of the
1785 // sibling [`crate::kind::tests::caixa_kind_wire_name_is_const_fn`]
1786 // pin on the paired [`crate::CaixaKind`] byte-string axis.
1787 const PACOTE: &str = CaixaDialeto::Pacote.as_str();
1788 const MOLDE: &str = CaixaDialeto::Molde.as_str();
1789 const MOLDE_POSICIONAL: &str = CaixaDialeto::MoldePosicional.as_str();
1790 const DESCONHECIDO: &str = CaixaDialeto::Desconhecido.as_str();
1791 assert_eq!(PACOTE, "Pacote");
1792 assert_eq!(MOLDE, "Molde");
1793 assert_eq!(MOLDE_POSICIONAL, "MoldePosicional");
1794 assert_eq!(DESCONHECIDO, "Desconhecido");
1795 }
1796
1797 #[test]
1798 fn caixa_dialeto_is_variant_predicates_partition_the_arm_set() {
1799 // Fail-before-pass-after pin on the [`gen_platform::IsVariant`]
1800 // derive: for each of the four variants at [`CaixaDialeto::ALL`]`[idx]`
1801 // the observed four-slot predicate row must equal a one-hot row
1802 // with the `true` at exactly `idx`. Pre-derive the closed four-arm
1803 // dialect-classification partition lived only inside the paired
1804 // per-arm projections' four-arm match resolvers ([`Self::as_str`] /
1805 // [`Self::palavra_canonica`] / [`Self::consumidor`] /
1806 // [`Self::descricao`]) plus the two-arm [`Self::is_molde_family`]
1807 // hand-rolled `matches!` (now routed through the derived
1808 // predicates); a future rebrand (an accidental
1809 // `#[is_variant(name = "…")]` drift, a manual hand-rolled `impl`
1810 // that shadows the derive-generated method, an arm rename that
1811 // reroutes one arm through the wrong predicate lane) trips this
1812 // pin at caixa-core build time rather than surfacing far from the
1813 // derive declaration as a downstream [`Self::is_molde_family`]
1814 // consumer accepting the wrong arm-set. The expected row is
1815 // generated live from the [`Self::ALL`] declaration order rather
1816 // than transcribed by hand so a copy-paste flip reroutes at the
1817 // identity-diagonal assertion.
1818 //
1819 // Peer of the sibling
1820 // [`crate::kind::tests::caixa_kind_is_variant_predicates_partition_the_arm_set`]
1821 // / [`crate::supervisor::tests::restart_strategy_is_variant_predicates_partition_the_arm_set`]
1822 // / [`crate::aplicacao::tests::placement_strategy_is_variant_predicates_partition_the_arm_set`]
1823 // / [`crate::upgrade::tests::upgrade_instruction_is_variant_predicates_partition_the_arm_set`]
1824 // pins on the sibling closed-set typed-enum discriminator axes.
1825 for (idx, &variant) in CaixaDialeto::ALL.iter().enumerate() {
1826 let observed = [
1827 variant.is_pacote(),
1828 variant.is_molde(),
1829 variant.is_molde_posicional(),
1830 variant.is_desconhecido(),
1831 ];
1832 let mut expected = [false; 4];
1833 expected[idx] = true;
1834 assert_eq!(
1835 observed, expected,
1836 "CaixaDialeto::{variant:?} at ALL[{idx}] is_* predicates \
1837 must fire only on their own arm lane (identity diagonal); \
1838 got {observed:?}",
1839 );
1840 }
1841 }
1842
1843 #[test]
1844 fn caixa_dialeto_is_variant_predicates_are_const_fn() {
1845 // The [`gen_platform::IsVariant`] derive emits `const fn`
1846 // predicates on the peer [`crate::CaixaKind`] +
1847 // [`crate::upgrade::UpgradeInstruction`] +
1848 // [`crate::supervisor::RestartStrategy`] +
1849 // [`crate::supervisor::RestartPolicy`] +
1850 // [`crate::aplicacao::PlacementStrategy`] +
1851 // [`crate::aplicacao::RateLimitUnit`] +
1852 // [`crate::dep::DepList`] closed-set typed enums — pin the same
1853 // posture on [`CaixaDialeto`] so a future accidental downgrade
1854 // to non-`const` (an added runtime helper reachable only from a
1855 // non-`const` context, a manual hand-rolled `impl` that shadows
1856 // the derive-generated method) trips at caixa-core build time
1857 // rather than surfacing as a downstream `const`-context
1858 // regression far from the derive declaration.
1859 // Use `const { assert!(…) }` (peer of the sibling
1860 // [`crate::render::PathShapeViolation`] +
1861 // [`crate::aplicacao::RateLimitUnit`] +
1862 // [`caixa_theme::style::Semantic`] const-fn pins) so the
1863 // const-context evaluation trips at const-fold time without
1864 // opening a per-`const bool` `assertions_on_constants` clippy
1865 // debt row this crate does not carry today for `dialeto.rs`.
1866 const { assert!(CaixaDialeto::Pacote.is_pacote()) };
1867 const { assert!(CaixaDialeto::Molde.is_molde()) };
1868 const { assert!(CaixaDialeto::MoldePosicional.is_molde_posicional()) };
1869 const { assert!(CaixaDialeto::Desconhecido.is_desconhecido()) };
1870 }
1871
1872 #[test]
1873 fn caixa_dialeto_from_wire_accepts_every_as_str_output() {
1874 // Fail-before-pass-after per-arm accept pin on the newly lifted
1875 // [`CaixaDialeto::from_wire`] reverse projection: every arm in
1876 // [`CaixaDialeto::ALL`] must parse back through `from_wire` when
1877 // fed its own [`CaixaDialeto::as_str`] output, landing on
1878 // `Some(same_variant)` — a regression that hand-rolled either
1879 // side's per-arm match without threading through the shared
1880 // four-string closed set would silently disagree on any future
1881 // arm rename and this pin flags it at caixa-core build time.
1882 // Peer of the sibling
1883 // [`crate::kind::tests::caixa_kind_wire_round_trips_through_from_wire`]
1884 // (2aa6d23) /
1885 // `placement_strategy_from_wire_accepts_every_lifted_constant`
1886 // (18c7342) /
1887 // `dep_list_round_trips_through_as_str_and_from_wire` (45ee563)
1888 // shape on the sibling closed-set typed-enum reverse-projection
1889 // axes.
1890 for &variant in CaixaDialeto::ALL {
1891 let wire = variant.as_str();
1892 let parsed = CaixaDialeto::from_wire(wire).unwrap_or_else(|| {
1893 panic!(
1894 "CaixaDialeto::from_wire({wire:?}) must accept every \
1895 CaixaDialeto::as_str output — got None for the \
1896 wire byte-string of {variant:?}"
1897 )
1898 });
1899 assert_eq!(
1900 parsed, variant,
1901 "CaixaDialeto::from_wire(CaixaDialeto::{variant:?}.as_str()) \
1902 must return CaixaDialeto::{variant:?} — the (as_str, \
1903 from_wire) pair must form a total round-trip on the \
1904 closed four-arm CaixaDialeto arm-set"
1905 );
1906 }
1907 }
1908
1909 #[test]
1910 fn caixa_dialeto_from_wire_rejects_unknown_byte_strings() {
1911 // Rejection pin on the parser's accept-set: any string outside
1912 // the four-arm [`CaixaDialeto::as_str`] output set must return
1913 // `None`. A future accidental widening of the accept-set (a
1914 // case-insensitive match that accepts `"pacote"` on the wire
1915 // axis, a hand-rolled Levenshtein-forgiving arm-lookup that
1916 // admits `"Pacotee"` typos, a silent acceptance of the sibling
1917 // [`Self::palavra_canonica`] `"defcaixa"` / `"defmolde"`
1918 // byte-shapes on this axis) would silently drift the parser's
1919 // accept-set from the emitter's — a downstream audit-report
1920 // re-loader that bound a prior audit's [`Self::as_str`] output
1921 // back to the typed enum through this parser would then bind a
1922 // malformed byte-string to a plausibly-wrong typed arm the
1923 // caller does not route through any fallback, silently
1924 // misclassifying the reloaded row. Also rejects the sibling
1925 // [`Self::palavra_canonica`] (`"defcaixa"` / `"defmolde"`) and
1926 // the sibling [`Self::consumidor`] (`"caixa-core / feira"`,
1927 // `"pleme-doc-gen"`, `"nobody known"`) byte-shapes, which are
1928 // the substrate's *distinct-axis* projections on the same enum
1929 // — the two-axis split the sibling
1930 // [`Self::palavra_canonica`] / [`Self::consumidor`] /
1931 // [`Self::descricao`] docstrings explicitly frame forbids
1932 // accepting one axis's byte-shapes as parseable on the other
1933 // axis. Peer of the sibling
1934 // [`crate::kind::tests::caixa_kind_from_wire_rejects_unknown_byte_strings`]
1935 // (2aa6d23) /
1936 // `placement_strategy_from_wire_rejects_unknown_byte_strings`
1937 // (18c7342) /
1938 // `dep_list_from_wire_returns_none_on_unknown_wire_scalar`
1939 // (45ee563) rejection pins on the sibling closed-set typed-enum
1940 // reverse-projection axes.
1941 for bad in [
1942 "",
1943 " ",
1944 "pacote",
1945 "PACOTE",
1946 "molde",
1947 "MoldePositional",
1948 "desconhecido",
1949 "Unknown",
1950 "defcaixa",
1951 "defmolde",
1952 "?",
1953 "caixa-core / feira",
1954 "pleme-doc-gen",
1955 "nobody known",
1956 "Pacote ",
1957 " Pacote",
1958 ] {
1959 assert!(
1960 CaixaDialeto::from_wire(bad).is_none(),
1961 "CaixaDialeto::from_wire({bad:?}) must return None — the \
1962 parser's accept-set is exactly the four CaixaDialeto::as_str \
1963 outputs; a widening would silently split the parser's \
1964 accept-set from the emitter's arm-set"
1965 );
1966 }
1967 }
1968
1969 #[test]
1970 fn cabeca_errada_ctor_matches_struct_literal_wrap() {
1971 // Fail-before-pass-after byte-identity pin: the lifted
1972 // [`DialetoError::cabeca_errada`] ctor MUST land on the exact
1973 // same struct-literal shape the pre-lift open-coded wire-up
1974 // block wrote by hand — `DialetoError::CabecaErrada {
1975 // encontrado: <head>.to_string() }`. A future accidental
1976 // divergence (`.into()` swap, per-arm constant substitution, an
1977 // added default field, an `.to_ascii_lowercase()` normalization
1978 // silently injected into the ctor body, a rebrand of the
1979 // `encontrado` field carrying a distinct byte-shape) trips this
1980 // pin at caixa-core build time rather than surfacing far from
1981 // the ctor declaration as a downstream `classify_form`
1982 // wrong-head consumer emitting one diagnostic shape while a
1983 // hand-written test peer opens another. Peer of the sibling
1984 // `unknown_byte_unit_ctor_matches_struct_literal_wrap`
1985 // (limits.rs; 29fac09) / `duplicate_from_ctor_matches_struct_
1986 // literal_wrap` (upgrade.rs; 7e52aec) shape on the sibling
1987 // single-slot `{ <field>: String }` envelope constructors.
1988 assert_eq!(
1989 DialetoError::cabeca_errada("defflake"),
1990 DialetoError::CabecaErrada {
1991 encontrado: "defflake".to_string(),
1992 },
1993 "DialetoError::cabeca_errada must byte-equal the pre-lift \
1994 open-coded struct-literal — a drift here means the ctor \
1995 stopped being a substrate primitive for the wrong-head \
1996 fallthrough site"
1997 );
1998 }
1999
2000 #[test]
2001 fn cabeca_errada_routes_encontrado_verbatim_across_boundary_inputs() {
2002 // Fail-before-pass-after boundary-sweep pin: the lifted
2003 // [`DialetoError::cabeca_errada`] ctor MUST route its
2004 // `encontrado: &str` argument verbatim into the
2005 // [`DialetoError::CabecaErrada`] `encontrado: String` field
2006 // for every boundary-covering `&str` input — empty string, a
2007 // canonical `defcaixa`-adjacent head, a non-ASCII head, a
2008 // whitespace-carrying head, a Unicode-full-width head. Any
2009 // wrapper-side truncation, silent `.trim()`, accidental
2010 // `.to_ascii_lowercase()` normalization, or `.into()` divergence
2011 // on the ctor body surfaces here as a byte-mismatch against the
2012 // input rather than at a downstream
2013 // [`DialetoError::to_string()`] diagnostic-shape drift at a
2014 // wrong-head fallthrough consumer far from the ctor declaration.
2015 // Peer of the sibling `limits_codec_unit_only_ctors_route_unit_
2016 // verbatim_across_every_variant` (limits.rs; 29fac09) shape on
2017 // the sibling single-slot `{ <field>: String }` envelope
2018 // boundary-sweep discipline.
2019 for encontrado in [
2020 "",
2021 "defflake",
2022 "def-molde",
2023 "defcaixa ",
2024 " defcaixa",
2025 "μdefcaixa",
2026 "\u{00A0}defcaixa",
2027 "\u{3000}defcaixa",
2028 "def\u{2028}caixa",
2029 ] {
2030 let via_ctor = DialetoError::cabeca_errada(encontrado);
2031 let via_literal = DialetoError::CabecaErrada {
2032 encontrado: encontrado.to_string(),
2033 };
2034 assert_eq!(
2035 via_ctor, via_literal,
2036 "DialetoError::cabeca_errada({encontrado:?}) must byte- \
2037 equal the open-coded struct-literal on the same input — \
2038 a drift here would let the ctor silently normalize / \
2039 truncate the head symbol before it reached the \
2040 CabecaErrada envelope"
2041 );
2042 let DialetoError::CabecaErrada { encontrado: routed } = via_ctor else {
2043 panic!(
2044 "DialetoError::cabeca_errada must construct the \
2045 CabecaErrada arm — got a different variant on \
2046 input {encontrado:?}"
2047 );
2048 };
2049 assert_eq!(
2050 routed, encontrado,
2051 "DialetoError::cabeca_errada must route the input \
2052 {encontrado:?} verbatim into the encontrado field — \
2053 any wrapper-side truncation / normalization surfaces \
2054 here rather than at a downstream diagnostic shape drift"
2055 );
2056 }
2057 }
2058
2059 #[test]
2060 fn classify_form_wrong_head_routes_through_cabeca_errada_ctor() {
2061 // Fail-before-pass-after routing pin: [`classify`]'s wrong-head
2062 // fallthrough site MUST construct its `Err(DialetoError::…)`
2063 // through the substrate-primitive [`DialetoError::cabeca_errada`]
2064 // ctor rather than through an open-coded struct-literal. Pre-
2065 // lift the wire-up hand-rolled a three-line
2066 // `Self::CabecaErrada { encontrado: other.to_string() }` block
2067 // with no compile-time link back to the substrate primitive; a
2068 // future accidental rebrand of the ctor body (an added
2069 // `.trim()` on `encontrado`, a per-arm constant prefix like
2070 // `"unknown-head:"`, a widening of the field into a
2071 // `(String, usize)` tuple carrying a caret offset) would then
2072 // silently split the two paths — the ctor consumers pick up
2073 // the new shape, the open-coded wire-up does not. Pinning
2074 // byte-equality between the observed `Err` and the ctor-
2075 // constructed `Err` refuses that split at caixa-core build
2076 // time rather than surfacing far from the wire-up commit as a
2077 // downstream diagnostic-consumer split.
2078 for head in ["defflake", "deffoobar", "defcaixaz", "let", "defmoldez"] {
2079 let src = format!("({head} :nome \"x\")");
2080 let observed = classify(&src);
2081 let via_ctor = Err(DialetoError::cabeca_errada(head));
2082 assert_eq!(
2083 observed, via_ctor,
2084 "classify({src:?}) must return the same Err shape as \
2085 DialetoError::cabeca_errada({head:?}) — a drift here \
2086 means the wire-up de-lifted its wrong-head fallthrough \
2087 arm off the substrate primitive"
2088 );
2089 }
2090 }
2091
2092 #[test]
2093 fn leitura_ctor_matches_tuple_literal_wrap_on_str_binding() {
2094 // Fail-before-pass-after byte-identity pin: the lifted
2095 // [`DialetoError::leitura`] ctor MUST land on the exact same
2096 // tuple-newtype wrap the pre-lift open-coded wire-up block wrote by
2097 // hand — `DialetoError::Leitura(<into-String-expr>)`. A future
2098 // accidental divergence (an added `.trim()` on the reader reason,
2099 // a per-arm constant prefix like `"tatara-lisp:"`, a widening of
2100 // the tuple carrying a caret offset, a rebrand of the payload
2101 // carrying a distinct byte-shape) trips this pin at caixa-core
2102 // build time rather than surfacing far from the ctor declaration
2103 // as a downstream [`classify`] tatara-lisp-reader consumer
2104 // emitting one diagnostic shape while a hand-written test peer
2105 // opens another. Peer of the sibling
2106 // `cabeca_errada_ctor_matches_struct_literal_wrap` pin above on
2107 // the same [`DialetoError`] envelope's wrong-head axis, and of
2108 // the peer `LimitsError::empty_byte_size` /
2109 // `LimitsError::empty_duration` (7a4b003 / 319216c) shape on the
2110 // sibling `(String)` single-slot tuple-newtype envelope
2111 // constructors.
2112 let reason: &str = "unclosed paren at 1:12";
2113 assert_eq!(
2114 DialetoError::leitura(reason),
2115 DialetoError::Leitura(reason.to_string()),
2116 "DialetoError::leitura must byte-equal the pre-lift open-coded \
2117 tuple-newtype wrap — a drift here means the ctor stopped \
2118 being a substrate primitive for the tatara-lisp-reader \
2119 fallthrough site"
2120 );
2121 }
2122
2123 #[test]
2124 fn leitura_ctor_matches_tuple_literal_wrap_on_string_binding() {
2125 // Fail-before-pass-after byte-identity pin on the `String` wire-up
2126 // shape: the lifted [`DialetoError::leitura`] ctor MUST land on
2127 // the same tuple-newtype wrap when the caller passes an owned
2128 // `String` (the actual [`classify`] wire-up shape — `e.to_string()`
2129 // on a [`tatara_lisp::Error`]-carrying binding). Pins that the
2130 // `impl Into<String>` param covers the owned-`String` path with no
2131 // silent double-allocation or intermediate `&str` reslicing. Peer
2132 // of the sibling `_on_str_binding` pin above — together they close
2133 // the `impl Into<String>` bound's two authored wire-up shapes on
2134 // the ctor's substrate primitive.
2135 let reason: String = String::from("read: unexpected EOF at 3:1");
2136 let via_ctor = DialetoError::leitura(reason.clone());
2137 let via_literal = DialetoError::Leitura(reason.clone());
2138 assert_eq!(
2139 via_ctor, via_literal,
2140 "DialetoError::leitura must byte-equal the pre-lift open-coded \
2141 tuple-newtype wrap on the same owned-String fixture — a drift \
2142 here would let the ctor silently reshape the reader reason \
2143 before it reached the Leitura envelope"
2144 );
2145 let DialetoError::Leitura(routed) = via_ctor else {
2146 panic!(
2147 "DialetoError::leitura must construct the Leitura arm — \
2148 got a different variant on input {reason:?}"
2149 );
2150 };
2151 assert_eq!(
2152 routed, reason,
2153 "DialetoError::leitura must route the input {reason:?} \
2154 verbatim into the tuple-newtype payload — any wrapper-side \
2155 truncation / normalization surfaces here rather than at a \
2156 downstream diagnostic shape drift"
2157 );
2158 }
2159
2160 #[test]
2161 fn leitura_routes_reason_verbatim_across_boundary_inputs() {
2162 // Fail-before-pass-after boundary-sweep pin: the lifted
2163 // [`DialetoError::leitura`] ctor MUST route its
2164 // `reason: impl Into<String>` argument verbatim into the
2165 // [`DialetoError::Leitura`] tuple-newtype `String` payload for
2166 // every boundary-covering input — empty string, a canonical
2167 // tatara-lisp reader error, a non-ASCII reason, a
2168 // whitespace-carrying reason, a Unicode-full-width reason. Any
2169 // wrapper-side truncation, silent `.trim()`, accidental
2170 // `.to_ascii_lowercase()` normalization, or `.into()` divergence
2171 // on the ctor body surfaces here as a byte-mismatch against the
2172 // input rather than at a downstream [`DialetoError::to_string()`]
2173 // diagnostic-shape drift at a tatara-lisp-reader fallthrough
2174 // consumer far from the ctor declaration. Peer of the sibling
2175 // `cabeca_errada_routes_encontrado_verbatim_across_boundary_inputs`
2176 // pin above on the same [`DialetoError`] envelope's wrong-head
2177 // axis.
2178 for reason in [
2179 "",
2180 "unclosed paren at 1:12",
2181 "unexpected token ')'",
2182 "read: eof",
2183 " leading whitespace",
2184 "trailing whitespace ",
2185 "μnicode reason",
2186 "\u{00A0}NBSP-prefixed reason",
2187 "\u{3000}ideographic-space reason",
2188 "reason\u{2028}with-line-separator",
2189 ] {
2190 let via_ctor = DialetoError::leitura(reason);
2191 let via_literal = DialetoError::Leitura(reason.to_string());
2192 assert_eq!(
2193 via_ctor, via_literal,
2194 "DialetoError::leitura({reason:?}) must byte-equal the \
2195 open-coded tuple-newtype wrap on the same input — a \
2196 drift here would let the ctor silently normalize / \
2197 truncate the reader reason before it reached the \
2198 Leitura envelope"
2199 );
2200 let DialetoError::Leitura(routed) = via_ctor else {
2201 panic!(
2202 "DialetoError::leitura must construct the Leitura \
2203 arm — got a different variant on input {reason:?}"
2204 );
2205 };
2206 assert_eq!(
2207 routed, reason,
2208 "DialetoError::leitura must route the input {reason:?} \
2209 verbatim into the tuple-newtype payload — any \
2210 wrapper-side truncation / normalization surfaces here \
2211 rather than at a downstream diagnostic shape drift"
2212 );
2213 }
2214 }
2215
2216 #[test]
2217 fn classify_reader_error_routes_through_leitura_ctor() {
2218 // Fail-before-pass-after routing pin: [`classify`]'s
2219 // tatara-lisp-reader map-err site MUST construct its
2220 // `Err(DialetoError::…)` through the substrate-primitive
2221 // [`DialetoError::leitura`] ctor rather than through an
2222 // open-coded tuple-newtype wrap. Pre-lift the wire-up hand-rolled
2223 // a `Self::Leitura(e.to_string())` block with no compile-time
2224 // link back to the substrate primitive; a future accidental
2225 // rebrand of the ctor body (an added `.trim()` on the reader
2226 // reason, a per-arm constant prefix like `"tatara-lisp:"`, a
2227 // widening of the payload into a `(String, usize)` tuple
2228 // carrying a caret offset) would then silently split the two
2229 // paths — the ctor consumers pick up the new shape, the
2230 // open-coded wire-up does not. Pinning byte-equality between
2231 // the observed `Err` and the ctor-constructed `Err` refuses
2232 // that split at caixa-core build time rather than surfacing far
2233 // from the wire-up commit as a downstream diagnostic-consumer
2234 // split. Peer of the sibling
2235 // `classify_form_wrong_head_routes_through_cabeca_errada_ctor`
2236 // pin above on the same [`DialetoError`] envelope's wrong-head
2237 // fallthrough axis.
2238 //
2239 // The malformed sources below each name a distinct
2240 // tatara-lisp-reader failure shape (unclosed paren, stray close
2241 // paren, unterminated string), so together they sweep the
2242 // reader's rejection surface rather than pinning against one
2243 // specific error message the reader upstream is free to reword.
2244 for src in [
2245 "(defcaixa :nome \"x\"",
2246 "defcaixa :nome \"x\")",
2247 "(defcaixa :nome \"unterminated",
2248 ] {
2249 let observed = classify(src);
2250 let Err(DialetoError::Leitura(reason)) = observed.clone() else {
2251 panic!(
2252 "classify({src:?}) must return the Leitura arm — got \
2253 {observed:?}"
2254 );
2255 };
2256 let via_ctor: Result<CaixaDialeto, DialetoError> =
2257 Err(DialetoError::leitura(reason.clone()));
2258 assert_eq!(
2259 observed, via_ctor,
2260 "classify({src:?}) must return the same Err shape as \
2261 DialetoError::leitura({reason:?}) — a drift here means \
2262 the wire-up de-lifted its tatara-lisp-reader fallthrough \
2263 arm off the substrate primitive"
2264 );
2265 }
2266 }
2267
2268 #[test]
2269 fn caixa_dialeto_try_from_str_routes_through_from_wire_accessor() {
2270 // Fail-before-pass-after byte-parity pin on the lifted
2271 // `impl TryFrom<&str> for CaixaDialeto`: for every arm in
2272 // [`CaixaDialeto::ALL`], the `.try_into()` / `TryFrom::try_from`
2273 // path must resolve to the same variant the sibling
2274 // [`CaixaDialeto::from_wire`] resolver returns on the same
2275 // [`CaixaDialeto::as_str`] wire byte-string input. Pins the
2276 // three-path convergence discipline the [`CaixaDialeto`] closed-
2277 // set typed enum now carries on the `str → Self` reverse-
2278 // projection axis: `<CaixaDialeto as TryFrom<&str>>::try_from(s)`
2279 // (the newly lifted trait-idiomatic reverse projection),
2280 // `CaixaDialeto::from_wire(s)` (the substrate-primitive method-
2281 // named `Option<Self>` accessor the trait impl delegates through),
2282 // and the round-trip identity `variant.as_str() → variant`
2283 // (the four-arm closed accept-set shared between the emitter and
2284 // both reverse-projection consumers) must resolve to the same
2285 // typed [`CaixaDialeto`] discriminator on every arm.
2286 //
2287 // A future silent detour that routes the impl through a
2288 // divergent projection (a per-arm inline
2289 // `match s { "Pacote" => …, … }` re-inlining that opens a
2290 // compile-time link to the un-lifted arm-literal, a swap onto
2291 // the second-axis [`CaixaDialeto::palavra_canonica`] /
2292 // [`CaixaDialeto::consumidor`] / [`CaixaDialeto::descricao`]
2293 // accessors that carry distinct byte-shapes per axis, an accept-
2294 // set widening that silently accepts one axis's byte-shapes as
2295 // parseable on the other axis) trips at caixa-core test time
2296 // under `assert_eq!` rather than at a downstream
2297 // `TryFrom<&str>`-bound consumer's silent split. Peer of the
2298 // sibling
2299 // [`crate::kind::tests::caixa_kind_try_from_str_routes_through_from_wire_accessor`]
2300 // (3c83606) on the top-level [`crate::CaixaKind`] closed-set
2301 // discriminator's reverse-projection axis — extends the trait-
2302 // idiomatic reverse-projection axis onto the seventh closed-set
2303 // fieldless typed enum on the caixa surface (the second one to
2304 // carry the paired `TryFrom<&str>` impl).
2305 for &variant in CaixaDialeto::ALL {
2306 let wire = variant.as_str();
2307 let via_try_from: CaixaDialeto = <CaixaDialeto as TryFrom<&str>>::try_from(wire)
2308 .unwrap_or_else(|()| {
2309 panic!(
2310 "CaixaDialeto::try_from({wire:?}) must accept every \
2311 CaixaDialeto::as_str output — got Err(()) for the \
2312 wire byte-string of {variant:?}"
2313 )
2314 });
2315 let via_from_wire: CaixaDialeto = CaixaDialeto::from_wire(wire).unwrap_or_else(|| {
2316 panic!(
2317 "CaixaDialeto::from_wire({wire:?}) must accept every \
2318 CaixaDialeto::as_str output — got None for the wire \
2319 byte-string of {variant:?}"
2320 )
2321 });
2322 assert_eq!(
2323 via_try_from, variant,
2324 "CaixaDialeto::try_from(CaixaDialeto::{variant:?}.as_str()) \
2325 must return CaixaDialeto::{variant:?} — the trait-idiomatic \
2326 reverse projection must land on the same arm the method-named \
2327 from_wire resolver does",
2328 );
2329 assert_eq!(
2330 via_try_from, via_from_wire,
2331 "CaixaDialeto::try_from({wire:?}) ({via_try_from:?}) must \
2332 byte-equal CaixaDialeto::from_wire({wire:?}) ({via_from_wire:?}) \
2333 on the same input — divergence signals a silent detour off the \
2334 shared substrate-primitive resolver",
2335 );
2336 assert_eq!(
2337 <CaixaDialeto as TryFrom<&str>>::try_from(wire).ok(),
2338 CaixaDialeto::from_wire(wire),
2339 "the Result::ok() projection of TryFrom<&str> must byte-equal \
2340 the sibling from_wire Option<Self> output on {wire:?} — the \
2341 two accessors must share the same accept-set and typed \
2342 outcome per arm",
2343 );
2344 }
2345 }
2346
2347 #[test]
2348 fn caixa_dialeto_try_from_str_rejects_unknown_byte_strings() {
2349 // Rejection witness on the trait-idiomatic reverse-projection
2350 // axis: any string outside the four-arm [`CaixaDialeto::as_str`]
2351 // output set must resolve to `Err(())` through the lifted
2352 // [`impl TryFrom<&str> for CaixaDialeto`]. A future accidental
2353 // widening of the accept-set (a case-insensitive match that
2354 // accepts `"pacote"` on the wire axis, a hand-rolled Levenshtein-
2355 // forgiving arm-lookup that admits `"Pacotee"` typos, a silent
2356 // acceptance of the sibling [`CaixaDialeto::palavra_canonica`]
2357 // `"defcaixa"` / `"defmolde"` byte-shapes on this axis, a swap
2358 // onto the [`CaixaDialeto::consumidor`] `"pleme-doc-gen"` /
2359 // `"caixa-core / feira"` / `"nobody known"` byte-shapes) would
2360 // silently drift the trait-idiomatic parser's accept-set from
2361 // the sibling [`CaixaDialeto::from_wire`] resolver's — a
2362 // downstream `TryFrom<&str>`-bound consumer binding a malformed
2363 // byte-string through this impl would then bind a plausibly-
2364 // wrong typed arm the caller does not route through any fallback,
2365 // silently misclassifying the reloaded row.
2366 //
2367 // Sweeps the same rejection set the sibling
2368 // [`caixa_dialeto_from_wire_rejects_unknown_byte_strings`] pin
2369 // walks (the shared `from_wire` resolver both accessors delegate
2370 // through) so the trait-idiomatic axis and the method-named axis
2371 // stay locked to the same accept-set by construction. Peer of the
2372 // sibling
2373 // [`crate::kind::tests::caixa_kind_try_from_str_rejects_unknown_byte_strings`]
2374 // (3c83606) on the top-level [`crate::CaixaKind`] closed-set
2375 // discriminator's trait-idiomatic reverse-projection axis.
2376 for bad in [
2377 "",
2378 " ",
2379 "pacote",
2380 "PACOTE",
2381 "molde",
2382 "MoldePositional",
2383 "desconhecido",
2384 "Unknown",
2385 "defcaixa",
2386 "defmolde",
2387 "?",
2388 "caixa-core / feira",
2389 "pleme-doc-gen",
2390 "nobody known",
2391 "Pacote ",
2392 " Pacote",
2393 ] {
2394 assert_eq!(
2395 <CaixaDialeto as TryFrom<&str>>::try_from(bad),
2396 Err(()),
2397 "CaixaDialeto::try_from({bad:?}) must return Err(()) — the \
2398 trait-idiomatic parser's accept-set is exactly the four \
2399 CaixaDialeto::as_str outputs; a widening would silently \
2400 split the trait-idiomatic reverse-projection axis from the \
2401 sibling from_wire resolver's arm-set"
2402 );
2403 }
2404 }
2405
2406 #[test]
2407 fn caixa_dialeto_from_into_static_str_routes_through_as_str_accessor() {
2408 // Fail-before-pass-after byte-parity pin on the newly lifted
2409 // `impl From<CaixaDialeto> for &'static str` — asserts the
2410 // standard-library trait impl and the substrate-primitive
2411 // [`CaixaDialeto::as_str`] `pub const fn` accessor resolve to
2412 // the same four-arm emit-set across every arm the exhaustive
2413 // [`CaixaDialeto::ALL`] slice enumerates. Any future silent
2414 // detour that routes the trait impl through a divergent
2415 // projection (a per-arm inline `match dialeto { Pacote =>
2416 // "Pacote", … }` re-inlining that opens a compile-time link to
2417 // the un-lifted arm-literal, an accidental swap onto the second-
2418 // axis [`CaixaDialeto::palavra_canonica`] /
2419 // [`CaixaDialeto::consumidor`] / [`CaixaDialeto::descricao`]
2420 // accessors that carry distinct byte-shapes per axis) trips at
2421 // caixa-core test time under `assert_eq!` rather than at a
2422 // downstream `impl Into<&'static str>`-bound consumer's silent
2423 // split. Sweeps every one of the four arms [`CaixaDialeto::ALL`]
2424 // carries so no arm's projection is covered only by the sibling
2425 // method-named `as_str` / [`std::fmt::Display`] / [`AsRef<str>`]
2426 // paths. Materializes the `<&'static str as
2427 // From<CaixaDialeto>>::from` output in a `const`-shape binding
2428 // to make the `'static` lifetime promise a build-time invariant
2429 // — a future accidental downgrade of any of the four arms'
2430 // returned literals to a non-`&'static str` (a `String::leak()`-
2431 // produced return, a `Box::leak`-cast, an intermediate lifetime-
2432 // erasing helper) trips at caixa-core build time rather than at
2433 // a downstream `'static`-bound consumer. Peer of the sibling
2434 // [`crate::supervisor::tests::restart_strategy_from_into_static_str_routes_through_as_str_accessor`]
2435 // (523157d) /
2436 // [`crate::supervisor::tests::restart_policy_from_into_static_str_routes_through_as_str_accessor`]
2437 // (9fb37d0) /
2438 // [`crate::kind::tests::caixa_kind_from_into_static_str_routes_through_as_str_accessor`]
2439 // (edb827b) pins on the sibling closed-set typed-enum forward-
2440 // projection axes — extends the trait-idiomatic forward-
2441 // projection axis onto the fourth closed-set fieldless typed
2442 // enum on the caixa surface (the dialect-classification axis,
2443 // second-of-two closed-set typed enums in caixa-core outside
2444 // the OTP-shape M2 slot).
2445 const PACOTE: &str = CaixaDialeto::Pacote.as_str();
2446 const MOLDE: &str = CaixaDialeto::Molde.as_str();
2447 const MOLDE_POSICIONAL: &str = CaixaDialeto::MoldePosicional.as_str();
2448 const DESCONHECIDO: &str = CaixaDialeto::Desconhecido.as_str();
2449 for &variant in CaixaDialeto::ALL {
2450 let via_trait: &'static str = <&'static str as From<CaixaDialeto>>::from(variant);
2451 let via_method: &'static str = variant.as_str();
2452 assert_eq!(
2453 via_trait, via_method,
2454 "From<CaixaDialeto> for &'static str impl must round-trip \
2455 CaixaDialeto::{variant:?} to the same `PascalCase` byte-string \
2456 CaixaDialeto::as_str returns — divergence signals a silent \
2457 detour off the substrate-primitive accessor"
2458 );
2459 let via_into: &'static str = variant.into();
2460 assert_eq!(
2461 via_into, via_method,
2462 "Into<&'static str>::into on CaixaDialeto::{variant:?} must \
2463 byte-equal CaixaDialeto::as_str on the same input — the \
2464 blanket-derived Into shape must resolve to the same as_str \
2465 dispatch as the explicit From impl"
2466 );
2467 }
2468 assert_eq!(
2469 [PACOTE, MOLDE, MOLDE_POSICIONAL, DESCONHECIDO],
2470 ["Pacote", "Molde", "MoldePosicional", "Desconhecido"],
2471 "const-context CaixaDialeto::as_str must resolve to the four \
2472 `PascalCase` variant-name byte-strings — a future accidental \
2473 downgrade of any arm to a non-const or non-static byte-string \
2474 breaks the `&'static str`-lifetime promise the paired \
2475 From<CaixaDialeto> for &'static str impl carries by \
2476 construction"
2477 );
2478 }
2479
2480 #[test]
2481 fn caixa_dialeto_from_into_static_str_and_as_str_partition_the_emit_set() {
2482 // Cross-axis partition pin: the paired trait-idiomatic
2483 // `From<CaixaDialeto> for &'static str` forward projection and
2484 // the method-named [`CaixaDialeto::as_str`] forward projection
2485 // must resolve identically on *every* arm, not just the ones
2486 // named in the primary byte-parity pin above. Sweeps every
2487 // [`CaixaDialeto::ALL`] arm and asserts the trait's `From::from`
2488 // output byte-equals the method-named accessor's return-value on
2489 // each, locking the two forward-projection paths together by
2490 // construction so any future detour (a stray `From` special-case
2491 // that lands on a divergent per-arm literal outside the paired
2492 // `as_str` dispatch, a hypothetical rebrand touching one axis
2493 // without the other) trips at caixa-core test time. Peer of the
2494 // sibling forward-projection partition pins
2495 // [`crate::supervisor::tests::restart_strategy_from_into_static_str_and_as_str_partition_the_emit_set`]
2496 // (523157d) /
2497 // [`crate::supervisor::tests::restart_policy_from_into_static_str_and_as_str_partition_the_emit_set`]
2498 // (9fb37d0) /
2499 // [`crate::kind::tests::caixa_kind_from_into_static_str_and_as_str_partition_the_emit_set`]
2500 // (edb827b) — extends the round-trip discipline onto the fourth
2501 // closed-set typed enum on the caixa surface, closing the two-way
2502 // `Self ↔ &'static str` round-trip on the trait-idiomatic pair
2503 // (`From<Self> for &'static str` + `TryFrom<&str> for Self`) as
2504 // well as the pre-existing method-named pair (`as_str` +
2505 // `from_wire`).
2506 for &variant in CaixaDialeto::ALL {
2507 let via_trait: &'static str = <&'static str as From<CaixaDialeto>>::from(variant);
2508 let via_method: &'static str = variant.as_str();
2509 assert_eq!(
2510 via_trait, via_method,
2511 "From<CaixaDialeto> for &'static str and \
2512 CaixaDialeto::as_str must resolve identically on \
2513 CaixaDialeto::{variant:?} — divergence signals the \
2514 two forward-projection paths have drifted onto different \
2515 emit-sets"
2516 );
2517 }
2518 // Round-trip witness: every arm's forward `From` output re-parses
2519 // through the paired trait-idiomatic reverse `TryFrom<&str>` back
2520 // to the original variant. Closes the two-way `CaixaDialeto ↔
2521 // &'static str` round-trip on the trait-idiomatic axis pair
2522 // directly (no wire-vocab intermediate the peer [`CaixaKind`]
2523 // axis pair requires — the emit-side [`CaixaDialeto::as_str`]
2524 // and the parse-side [`CaixaDialeto::from_wire`] share the same
2525 // `PascalCase` byte-string vocabulary by construction), mirroring
2526 // the pre-existing method-named `as_str` + `from_wire` round-trip
2527 // on the substrate-primitive axis pair.
2528 for &variant in CaixaDialeto::ALL {
2529 let emitted: &'static str = variant.into();
2530 let re_parsed: Result<CaixaDialeto, ()> =
2531 <CaixaDialeto as TryFrom<&str>>::try_from(emitted);
2532 assert_eq!(
2533 re_parsed,
2534 Ok(variant),
2535 "trait-idiomatic axis pair must round-trip \
2536 CaixaDialeto::{variant:?} through `.into::<&'static \
2537 str>()` and back through `TryFrom<&str>` — a break signals \
2538 the forward-emit and reverse-parse axes have drifted onto \
2539 different vocabularies"
2540 );
2541 }
2542 }
2543
2544 #[test]
2545 fn caixa_dialeto_is_molde_family_routes_through_is_variant_derived_predicates() {
2546 // Byte-parity pin on the post-lift [`CaixaDialeto::is_molde_family`]
2547 // convergence: for every arm in [`CaixaDialeto::ALL`], the typed
2548 // predicate must byte-equal the direct
2549 // `self.is_molde() || self.is_molde_posicional()` composition of
2550 // the two derived per-arm predicates. Pre-lift the predicate
2551 // hand-rolled `matches!(self, Self::Molde | Self::MoldePosicional)`
2552 // with no compile-time link back to the closed-set typed dispatch;
2553 // post-lift it routes through the derived predicates so a future
2554 // arm rename or `#[is_variant(name = "…")]` override lands at
2555 // exactly one dispatch on the substrate primitive. Pinning the
2556 // byte-equality here refuses a future accidental split between
2557 // the composed predicate and the paired derived predicates
2558 // (a hand-rolled shadow `impl` that overrides one path but not
2559 // the other, an accidental rebrand of `is_molde_family`'s body
2560 // back to the pre-lift `matches!` form) at caixa-core build time.
2561 for &d in CaixaDialeto::ALL {
2562 let via_derived = d.is_molde() || d.is_molde_posicional();
2563 let via_is_molde_family = d.is_molde_family();
2564 assert_eq!(
2565 via_is_molde_family, via_derived,
2566 "CaixaDialeto::{d:?}.is_molde_family() ({via_is_molde_family}) \
2567 must byte-equal the composed derived predicates \
2568 is_molde() || is_molde_posicional() ({via_derived}) — a \
2569 split between the composed predicate and its derived \
2570 building blocks would let a future arm rename land at one \
2571 path and drift at the other, which is exactly the drift \
2572 the IsVariant lift refuses"
2573 );
2574 }
2575 }
2576
2577 #[test]
2578 fn caixa_dialeto_from_borrowed_into_static_str_routes_through_as_str_accessor() {
2579 // Fail-before-pass-after byte-parity pin on the newly lifted
2580 // `impl From<&CaixaDialeto> for &'static str` — asserts the
2581 // borrowed-input standard-library trait impl and the substrate-
2582 // primitive [`CaixaDialeto::as_str`] `pub const fn` accessor
2583 // resolve to the same four-arm emit-set across every arm the
2584 // exhaustive [`CaixaDialeto::ALL`] slice enumerates. Rust's
2585 // `From` trait does not auto-derive the borrowed-input sibling
2586 // from a paired owned-input impl (no `impl<T, U> From<&T> for U
2587 // where T: Copy, U: From<T>` blanket in `core`), so the
2588 // borrowed-input axis is a distinct trait-idiomatic surface that
2589 // a `.iter().map(Into::into)` shape over [`CaixaDialeto::ALL`]
2590 // (whose iterator yields `&CaixaDialeto`, not `CaixaDialeto`)
2591 // reaches through this impl and no other — the paired owned-
2592 // input [`From<CaixaDialeto>`] impl requires an explicit
2593 // `.copied()` / dereference before the trait fires.
2594 // Materializes the `<&'static str as From<&CaixaDialeto>>::from`
2595 // output in a `const`-shape binding to make the `'static`
2596 // lifetime promise a build-time invariant — a future accidental
2597 // downgrade of any of the four arms' returned literals to a
2598 // non-`&'static str` trips at caixa-core build time rather than
2599 // at a downstream `'static`-bound consumer. Peer of the sibling
2600 // [`crate::dep::tests::dep_list_from_borrowed_into_static_str_routes_through_as_str_accessor`]
2601 // (64aa742) /
2602 // [`crate::kind::tests::caixa_kind_from_borrowed_into_static_str_routes_through_as_str_accessor`]
2603 // (5ab993a) pins on the sibling closed-set typed-enum borrowed-
2604 // input forward-projection axes — extends the borrowed-input
2605 // axis discipline onto the third peer on the substrate-wide
2606 // campaign, the dialect-classification axis.
2607 const PACOTE: &str = CaixaDialeto::Pacote.as_str();
2608 const MOLDE: &str = CaixaDialeto::Molde.as_str();
2609 const MOLDE_POSICIONAL: &str = CaixaDialeto::MoldePosicional.as_str();
2610 const DESCONHECIDO: &str = CaixaDialeto::Desconhecido.as_str();
2611 for variant in CaixaDialeto::ALL {
2612 let via_trait: &'static str = <&'static str as From<&CaixaDialeto>>::from(variant);
2613 let via_method: &'static str = variant.as_str();
2614 assert_eq!(
2615 via_trait, via_method,
2616 "From<&CaixaDialeto> for &'static str impl must round-trip \
2617 &CaixaDialeto::{variant:?} to the same `PascalCase` byte-\
2618 string CaixaDialeto::as_str returns — divergence signals a \
2619 silent detour off the substrate-primitive accessor"
2620 );
2621 let via_into: &'static str = variant.into();
2622 assert_eq!(
2623 via_into, via_method,
2624 "Into<&'static str>::into on &CaixaDialeto::{variant:?} must \
2625 byte-equal CaixaDialeto::as_str on the same input — the \
2626 blanket-derived Into shape must resolve to the same as_str \
2627 dispatch as the explicit From impl"
2628 );
2629 }
2630 assert_eq!(
2631 [PACOTE, MOLDE, MOLDE_POSICIONAL, DESCONHECIDO],
2632 ["Pacote", "Molde", "MoldePosicional", "Desconhecido"],
2633 "const-context CaixaDialeto::as_str must resolve to the four \
2634 `PascalCase` variant-name byte-strings — the borrowed-input \
2635 From<&CaixaDialeto> for &'static str impl inherits its \
2636 `'static` lifetime promise from the same accessor the owned-\
2637 input sibling routes through"
2638 );
2639 }
2640
2641 #[test]
2642 fn caixa_dialeto_from_owned_and_borrowed_into_static_str_agree_on_every_arm() {
2643 // Cross-axis partition pin: the paired trait-idiomatic
2644 // owned-input `From<CaixaDialeto> for &'static str` and
2645 // borrowed-input `From<&CaixaDialeto> for &'static str` (this
2646 // lift) forward projections must resolve identically on every
2647 // arm, locking the two input-shape paths together so any future
2648 // detour trips at caixa-core test time. Then a witness that a
2649 // `.iter().map(Into::into)` pipe over [`CaixaDialeto::ALL`]
2650 // (whose iterator yields `&CaixaDialeto`) materializes the four-
2651 // arm accept-set through the borrowed-input axis alone — the
2652 // exact shape a future M4 admission-webhook rejection body
2653 // composer, a future substrate-wide per-arm diagnostic column,
2654 // or a `HashMap::<&'static str, CaixaDialeto>::from_iter(
2655 // CaixaDialeto::ALL.iter().map(|d| (d.into(), *d)))`-style
2656 // per-dialect lookup reaches through — closing the two-way
2657 // owned/borrowed input-shape symmetry on the forward-projection
2658 // trait-idiomatic axis. Peer of the sibling
2659 // [`crate::dep::tests::dep_list_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
2660 // (64aa742) /
2661 // [`crate::kind::tests::caixa_kind_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
2662 // (5ab993a) partition pins — extends the borrowed-input axis
2663 // discipline onto the third peer on the substrate-wide campaign.
2664 for &variant in CaixaDialeto::ALL {
2665 let owned: &'static str = <&'static str as From<CaixaDialeto>>::from(variant);
2666 let borrowed: &'static str = <&'static str as From<&CaixaDialeto>>::from(&variant);
2667 assert_eq!(
2668 owned, borrowed,
2669 "From<CaixaDialeto> and From<&CaixaDialeto> for &'static str \
2670 must resolve identically on CaixaDialeto::{variant:?} — \
2671 divergence signals the owned-input and borrowed-input \
2672 forward-projection paths have drifted onto different \
2673 emit-sets"
2674 );
2675 }
2676 let via_iter: Vec<&'static str> = CaixaDialeto::ALL.iter().map(Into::into).collect();
2677 let via_method: Vec<&'static str> = CaixaDialeto::ALL.iter().map(|d| d.as_str()).collect();
2678 assert_eq!(
2679 via_iter, via_method,
2680 "`.iter().map(Into::into)` over CaixaDialeto::ALL must byte-\
2681 equal `.iter().map(|d| d.as_str())` on every arm — the \
2682 borrowed-input `From<&CaixaDialeto> for &'static str` axis \
2683 is what makes the `.iter().map(Into::into)` shape route \
2684 through the substrate-primitive `CaixaDialeto::as_str` \
2685 accessor rather than through a per-call-site `.copied()` / \
2686 dereference detour"
2687 );
2688 // Direct round-trip witness on the borrowed-input axis: every
2689 // arm's borrowed `From` output re-parses through the paired
2690 // trait-idiomatic reverse `TryFrom<&str>` back to the original
2691 // variant. Unlike the peer [`crate::CaixaKind`] axis pair
2692 // (whose forward `From<Self> for &'static str` emits the
2693 // lowercase Portuguese `as_str` diagnostic vocabulary while
2694 // the reverse `TryFrom<&str>` parses the `PascalCase`
2695 // `wire_name` author-surface vocabulary, forcing the round-trip
2696 // through an intermediate wire-vocab hop), [`CaixaDialeto`]'s
2697 // [`CaixaDialeto::as_str`] emit and [`CaixaDialeto::from_wire`]
2698 // parse share the same `PascalCase` vocabulary by construction,
2699 // so the borrowed-input forward axis and the reverse axis
2700 // compose directly.
2701 for &variant in CaixaDialeto::ALL {
2702 let borrowed: &'static str = <&'static str as From<&CaixaDialeto>>::from(&variant);
2703 let re_parsed: Result<CaixaDialeto, ()> =
2704 <CaixaDialeto as TryFrom<&str>>::try_from(borrowed);
2705 assert_eq!(
2706 re_parsed,
2707 Ok(variant),
2708 "trait-idiomatic borrowed-input round-trip must project \
2709 &CaixaDialeto::{variant:?} through \
2710 `<&'static str>::from(&variant)` and back through \
2711 `TryFrom<&str>` — a break signals the borrowed-input \
2712 forward-emit axis and the reverse-parse axis have \
2713 drifted onto different vocabularies"
2714 );
2715 }
2716 }
2717
2718 #[test]
2719 fn caixa_dialeto_from_into_owned_string_routes_through_as_str_accessor() {
2720 // Fail-before-pass-after byte-parity pin on the newly lifted
2721 // `impl From<CaixaDialeto> for String` — asserts the owned-`String`
2722 // -returning standard-library trait impl and the substrate-
2723 // primitive [`CaixaDialeto::as_str`] `pub const fn` accessor
2724 // resolve to the same four-arm emit-set across every arm the
2725 // exhaustive [`CaixaDialeto::ALL`] slice enumerates. Rust's
2726 // standard library does not carry a blanket
2727 // `impl<T: AsRef<str>> From<T> for String` (nor an
2728 // `impl<T: fmt::Display> From<T> for String`), so the
2729 // owned-`String` forward-projection axis is a distinct trait-
2730 // idiomatic surface that a `let key: String = dialeto.into();`-
2731 // shaped call site reaches through this impl and no other — the
2732 // paired sibling `From<CaixaDialeto> for &'static str` impl
2733 // forces every owned-`String` call site through an explicit
2734 // `.to_owned()` / `String::from` restatement. Peer of the
2735 // first-mover
2736 // [`crate::supervisor::tests::restart_strategy_from_into_owned_string_routes_through_as_str_accessor`]
2737 // (7baa18a), the second-peer
2738 // [`crate::supervisor::tests::restart_policy_from_into_owned_string_routes_through_as_str_accessor`]
2739 // (7851725), and the third-peer
2740 // [`crate::kind::tests::caixa_kind_from_into_owned_string_routes_through_as_str_accessor`]
2741 // (231a18c) — extends the trait-idiomatic owned-`String`
2742 // forward-projection axis onto the fourth closed-set fieldless
2743 // typed enum on the caixa surface (the dialect-classification
2744 // axis, second peer outside the M2 OTP-shape sibling axis).
2745 for &variant in CaixaDialeto::ALL {
2746 let via_trait: String = <String as From<CaixaDialeto>>::from(variant);
2747 let via_method: &'static str = variant.as_str();
2748 assert_eq!(
2749 via_trait.as_str(),
2750 via_method,
2751 "From<CaixaDialeto> for String impl must round-trip \
2752 CaixaDialeto::{variant:?} to the same `PascalCase` \
2753 arm-string CaixaDialeto::as_str returns — divergence \
2754 signals a silent detour off the substrate-primitive \
2755 accessor"
2756 );
2757 let via_into: String = variant.into();
2758 assert_eq!(
2759 via_into.as_str(),
2760 via_method,
2761 "Into<String>::into on CaixaDialeto::{variant:?} must \
2762 byte-equal CaixaDialeto::as_str on the same input — the \
2763 blanket-derived Into shape must resolve to the same \
2764 as_str dispatch as the explicit From impl"
2765 );
2766 }
2767 }
2768
2769 #[test]
2770 fn caixa_dialeto_from_into_owned_string_and_static_str_agree_on_every_arm() {
2771 // Cross-axis partition pin: the paired trait-idiomatic
2772 // owned-`String` `From<CaixaDialeto> for String` (this lift) and
2773 // owned-`&'static str` `From<CaixaDialeto> for &'static str`
2774 // (c189a6f) forward projections must resolve identically on
2775 // every arm, locking the two return-type-shape paths together
2776 // so any future detour trips at caixa-core test time. Also
2777 // byte-parity witness against the sibling
2778 // [`ToString::to_string`] surface routed through
2779 // [`std::fmt::Display`] — the three owned-heap-string paths
2780 // (`.into::<String>()`, `String::from`, `.to_string()`) must
2781 // resolve identically on every arm so a future consumer that
2782 // picks any of the three lands on the same four-arm
2783 // `PascalCase` accept-set. Then a `.iter().copied()
2784 // .map(String::from)` pipe witness over [`CaixaDialeto::ALL`]
2785 // that materializes the four-arm accept-set through the
2786 // owned-`String` axis alone — the exact shape a future M4
2787 // admission-webhook rejection body composer or a
2788 // `HashMap::<String, CaixaDialeto>::from_iter(
2789 // CaixaDialeto::ALL.iter().copied().map(|d| (d.into(), d)))`-
2790 // style owned-key per-dialect lookup reaches through — closing
2791 // the owned-`String` forward-projection axis's iterator-pipe
2792 // shape. Then a direct round-trip witness through the paired
2793 // trait-idiomatic reverse [`TryFrom<&str>`] axis on the
2794 // owned-`String`'s [`String::as_str`] borrow that closes the
2795 // two-way `Self → String → Self` round-trip on the trait-
2796 // idiomatic owned-`String` forward + reverse axis pair.
2797 //
2798 // Unlike the peer [`crate::CaixaKind`] axis pair (whose forward
2799 // `From` emit lands on the lowercase Portuguese `as_str`
2800 // diagnostic vocabulary while the reverse `TryFrom<&str>` parses
2801 // the `PascalCase` `wire_name` author-surface vocabulary,
2802 // forcing the round-trip through an intermediate
2803 // [`crate::CaixaKind::wire_name`] hop), [`CaixaDialeto`]'s
2804 // [`CaixaDialeto::as_str`] emit and [`CaixaDialeto::from_wire`]
2805 // parse share the same `PascalCase` vocabulary by construction
2806 // (there is no wire/diagnostic axis split on this enum), so
2807 // the owned-`String` forward axis and the reverse axis compose
2808 // directly — matching the peer
2809 // [`crate::supervisor::RestartStrategy`] /
2810 // [`crate::supervisor::RestartPolicy`] owned-`String` axis
2811 // pairs (whose forward emit and reverse parse also share one
2812 // `PascalCase` vocabulary by construction).
2813 for &variant in CaixaDialeto::ALL {
2814 let owned_string: String = <String as From<CaixaDialeto>>::from(variant);
2815 let owned_static: &'static str = <&'static str as From<CaixaDialeto>>::from(variant);
2816 assert_eq!(
2817 owned_string.as_str(),
2818 owned_static,
2819 "From<CaixaDialeto> for String and From<CaixaDialeto> for \
2820 &'static str must resolve identically on \
2821 CaixaDialeto::{variant:?} — divergence signals the \
2822 owned-`String` and owned-`&'static str` forward-\
2823 projection return-type-shape paths have drifted onto \
2824 different emit-sets"
2825 );
2826 let via_to_string: String = variant.to_string();
2827 assert_eq!(
2828 owned_string, via_to_string,
2829 "From<CaixaDialeto> for String must byte-equal \
2830 CaixaDialeto::to_string on CaixaDialeto::{variant:?} — \
2831 divergence signals the trait-idiomatic owned-`String` \
2832 forward-projection axis and the ToString-through-\
2833 Display axis have drifted onto different emit-sets"
2834 );
2835 }
2836 let via_iter: Vec<String> = CaixaDialeto::ALL
2837 .iter()
2838 .copied()
2839 .map(String::from)
2840 .collect();
2841 let via_method: Vec<String> = CaixaDialeto::ALL
2842 .iter()
2843 .map(|d| d.as_str().to_owned())
2844 .collect();
2845 assert_eq!(
2846 via_iter, via_method,
2847 "`.iter().copied().map(String::from)` over CaixaDialeto::ALL \
2848 must byte-equal `.iter().map(|d| d.as_str().to_owned())` on \
2849 every arm — the owned-`String` `From<CaixaDialeto> for \
2850 String` axis is what makes the `String::from` composition \
2851 route through the substrate-primitive `CaixaDialeto::as_str` \
2852 accessor rather than through a per-call-site `.to_owned()` / \
2853 `String::from(dialeto.as_str())` detour"
2854 );
2855 for &variant in CaixaDialeto::ALL {
2856 let emitted: String = variant.into();
2857 let re_parsed: Result<CaixaDialeto, ()> =
2858 <CaixaDialeto as TryFrom<&str>>::try_from(emitted.as_str());
2859 assert_eq!(
2860 re_parsed,
2861 Ok(variant),
2862 "trait-idiomatic owned-`String` forward-projection + \
2863 reverse-projection axis pair must round-trip \
2864 CaixaDialeto::{variant:?} through `.into::<String>()` \
2865 and back through `TryFrom<&str>` on the owned-`String`'s \
2866 String::as_str borrow — a break signals the owned-\
2867 `String` forward-emit and reverse-parse axes have \
2868 drifted onto different vocabularies (unlike the peer \
2869 CaixaKind axis pair, CaixaDialeto's forward emit and \
2870 reverse parse share one PascalCase vocabulary by \
2871 construction, so the round-trip composes directly)"
2872 );
2873 }
2874 }
2875
2876 #[test]
2877 fn caixa_dialeto_from_into_borrowed_owned_string_routes_through_as_str_accessor() {
2878 // Fail-before-pass-after byte-parity pin on the newly lifted
2879 // `impl From<&CaixaDialeto> for String` — asserts the borrowed-
2880 // input owned-`String`-returning standard-library trait impl and
2881 // the substrate-primitive [`super::CaixaDialeto::as_str`]
2882 // `pub const fn` accessor resolve to the same four-arm emit-set
2883 // across every arm the exhaustive [`super::CaixaDialeto::ALL`]
2884 // slice enumerates. Rust's standard library does not carry a
2885 // blanket `impl<T: AsRef<str>> From<&T> for String` (nor an
2886 // `impl<T: fmt::Display> From<&T> for String`), so the
2887 // borrowed-input owned-`String` forward-projection axis is a
2888 // distinct trait-idiomatic surface that a
2889 // `let key: String = (&dialeto).into();`-shaped call site
2890 // reaches through this impl and no other — the paired sibling
2891 // `From<CaixaDialeto> for String` impl forces every borrowed-
2892 // input call site through an explicit `Copy` deref
2893 // (`String::from(*dialeto)`) or an `.as_str().to_owned()` /
2894 // `.to_string()` detour. Peer of the first-mover
2895 // [`crate::supervisor::tests::restart_strategy_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
2896 // (579385f), the second-peer
2897 // [`crate::supervisor::tests::restart_policy_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
2898 // (8465740), the third-peer
2899 // [`crate::dep::tests::dep_list_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
2900 // (e0cb617), and the fourth-peer
2901 // [`crate::kind::tests::caixa_kind_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
2902 // (e76436d) — extends the trait-idiomatic borrowed-input owned-
2903 // `String` forward-projection axis onto the fourth closed-set
2904 // fieldless typed enum on the caixa surface (the dialect-
2905 // classification axis, second peer outside the M2 OTP-shape
2906 // sibling axis to reach the 2×2-completion corner).
2907 for &variant in CaixaDialeto::ALL {
2908 let via_trait: String = <String as From<&CaixaDialeto>>::from(&variant);
2909 let via_method: &'static str = variant.as_str();
2910 assert_eq!(
2911 via_trait.as_str(),
2912 via_method,
2913 "From<&CaixaDialeto> for String impl must round-trip \
2914 &CaixaDialeto::{variant:?} to the same `PascalCase` \
2915 arm-string CaixaDialeto::as_str returns — divergence \
2916 signals a silent detour off the substrate-primitive \
2917 accessor"
2918 );
2919 let via_into: String = (&variant).into();
2920 assert_eq!(
2921 via_into.as_str(),
2922 via_method,
2923 "Into<String>::into on &CaixaDialeto::{variant:?} must \
2924 byte-equal CaixaDialeto::as_str on the same input — \
2925 the blanket-derived Into shape must resolve to the \
2926 same as_str dispatch as the explicit From impl"
2927 );
2928 }
2929 }
2930
2931 #[test]
2932 fn caixa_dialeto_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm() {
2933 // Cross-axis partition pin: the newly lifted trait-idiomatic
2934 // borrowed-input owned-`String` `From<&CaixaDialeto> for String`
2935 // (this lift), the paired owned-input owned-`String`
2936 // `From<CaixaDialeto> for String` (88942cd), the paired
2937 // borrowed-input owned-`&'static str`
2938 // `From<&CaixaDialeto> for &'static str` (807b0b5), and the
2939 // paired owned-input owned-`&'static str`
2940 // `From<CaixaDialeto> for &'static str` (c189a6f) — every corner
2941 // of the `{Self, &Self} × {&'static str, String}` 2×2 trait-
2942 // idiomatic projection family — must resolve identically on
2943 // every arm, locking the four return-shape × input-shape paths
2944 // together so any future detour trips at caixa-core test time.
2945 // Also byte-parity witness against the sibling
2946 // [`ToString::to_string`] surface routed through
2947 // [`std::fmt::Display`] and a direct round-trip witness through
2948 // the paired trait-idiomatic reverse [`TryFrom<&str>`] axis on
2949 // the owned-`String`'s [`String::as_str`] borrow that closes
2950 // the two-way `&Self → String → Self` round-trip on the trait-
2951 // idiomatic borrowed-input owned-`String` forward + reverse
2952 // axis pair. Peer of the first-mover
2953 // [`crate::supervisor::tests::restart_strategy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
2954 // (579385f), the second-peer
2955 // [`crate::supervisor::tests::restart_policy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
2956 // (8465740), the third-peer
2957 // [`crate::dep::tests::dep_list_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
2958 // (e0cb617), and the fourth-peer
2959 // [`crate::kind::tests::caixa_kind_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
2960 // (e76436d) — closes the whole `{Self, &Self} × {&'static str,
2961 // String}` 2×2 projection corner on the fifth substrate-wide
2962 // closed-set fieldless typed enum peer (the dialect-
2963 // classification axis, second peer outside the M2 OTP-shape
2964 // sibling pair).
2965 //
2966 // Unlike the peer [`crate::CaixaKind`] axis pair (whose forward
2967 // `From` emit lands on the lowercase Portuguese `as_str`
2968 // diagnostic vocabulary while the reverse `TryFrom<&str>`
2969 // parses the `PascalCase` `wire_name` author-surface vocabulary,
2970 // forcing the round-trip through an intermediate
2971 // [`crate::CaixaKind::wire_name`] hop), [`super::CaixaDialeto`]'s
2972 // [`super::CaixaDialeto::as_str`] emit and
2973 // [`super::CaixaDialeto::from_wire`] parse share the same
2974 // `PascalCase` vocabulary by construction (there is no
2975 // wire/diagnostic axis split on this enum), so the borrowed-
2976 // input owned-`String` forward axis and the reverse axis compose
2977 // directly — matching the peer
2978 // [`crate::supervisor::RestartStrategy`] /
2979 // [`crate::supervisor::RestartPolicy`] / [`crate::dep::DepList`]
2980 // borrowed-input owned-`String` axis pairs.
2981 for &dialeto in CaixaDialeto::ALL {
2982 let borrowed_string: String = <String as From<&CaixaDialeto>>::from(&dialeto);
2983 let owned_string: String = <String as From<CaixaDialeto>>::from(dialeto);
2984 let borrowed_static: &'static str =
2985 <&'static str as From<&CaixaDialeto>>::from(&dialeto);
2986 let owned_static: &'static str = <&'static str as From<CaixaDialeto>>::from(dialeto);
2987 assert_eq!(
2988 borrowed_string, owned_string,
2989 "From<&CaixaDialeto> for String and From<CaixaDialeto> \
2990 for String must resolve identically on \
2991 CaixaDialeto::{dialeto:?} — divergence signals the \
2992 borrowed-input and owned-input owned-`String` forward-\
2993 projection input-shape paths have drifted onto \
2994 different emit-sets"
2995 );
2996 assert_eq!(
2997 borrowed_string.as_str(),
2998 borrowed_static,
2999 "From<&CaixaDialeto> for String and From<&CaixaDialeto> \
3000 for &'static str must resolve identically on \
3001 CaixaDialeto::{dialeto:?} — divergence signals the \
3002 borrowed-input `&'static str` and owned-`String` \
3003 return-shape paths have drifted onto different \
3004 emit-sets"
3005 );
3006 assert_eq!(
3007 borrowed_string.as_str(),
3008 owned_static,
3009 "From<&CaixaDialeto> for String and From<CaixaDialeto> \
3010 for &'static str must resolve identically on \
3011 CaixaDialeto::{dialeto:?} — divergence signals a break \
3012 in the diagonal corner of the {{Self, &Self}} × \
3013 {{&'static str, String}} 2×2 trait-idiomatic \
3014 projection family"
3015 );
3016 let via_to_string: String = dialeto.to_string();
3017 assert_eq!(
3018 borrowed_string, via_to_string,
3019 "From<&CaixaDialeto> for String must byte-equal \
3020 CaixaDialeto::to_string on CaixaDialeto::{dialeto:?} — \
3021 divergence signals the trait-idiomatic borrowed-input \
3022 owned-`String` forward-projection axis and the \
3023 ToString-through-Display axis have drifted onto \
3024 different emit-sets"
3025 );
3026 }
3027 let via_iter: Vec<String> = CaixaDialeto::ALL.iter().map(String::from).collect();
3028 let via_method: Vec<String> = CaixaDialeto::ALL
3029 .iter()
3030 .map(|d| d.as_str().to_owned())
3031 .collect();
3032 assert_eq!(
3033 via_iter, via_method,
3034 "`.iter().map(String::from)` over CaixaDialeto::ALL — a \
3035 call site whose iteration axis holds `&CaixaDialeto` by \
3036 construction — must byte-equal `.iter().map(|d| \
3037 d.as_str().to_owned())` on every arm — the borrowed-input \
3038 owned-`String` `From<&CaixaDialeto> for String` axis is \
3039 what makes the `String::from` composition route through \
3040 the substrate-primitive `CaixaDialeto::as_str` accessor \
3041 without a spurious `Copy` deref (which would only be \
3042 reachable through the owned-input `From<CaixaDialeto> for \
3043 String` axis by first calling `.copied()` on the iterator)"
3044 );
3045 for &variant in CaixaDialeto::ALL {
3046 let emitted: String = (&variant).into();
3047 let re_parsed: Result<CaixaDialeto, ()> =
3048 <CaixaDialeto as TryFrom<&str>>::try_from(emitted.as_str());
3049 assert_eq!(
3050 re_parsed,
3051 Ok(variant),
3052 "trait-idiomatic borrowed-input owned-`String` \
3053 forward-projection + reverse-projection axis pair \
3054 must round-trip &CaixaDialeto::{variant:?} through \
3055 `.into::<String>()` on the borrowed-input surface and \
3056 back through `TryFrom<&str>` on the owned-`String`'s \
3057 String::as_str borrow — a break signals the \
3058 borrowed-input owned-`String` forward-emit and \
3059 reverse-parse axes have drifted onto different \
3060 vocabularies (unlike the peer CaixaKind axis pair, \
3061 CaixaDialeto's forward emit and reverse parse share \
3062 one PascalCase vocabulary by construction, so the \
3063 round-trip composes directly)"
3064 );
3065 }
3066 }
3067
3068 #[test]
3069 fn caixa_dialeto_from_into_static_cow_str_routes_through_as_str_accessor() {
3070 // Fail-before-pass-after byte-parity pin on the newly lifted
3071 // `impl From<CaixaDialeto> for std::borrow::Cow<'static, str>`
3072 // — asserts the standard-library trait impl and the
3073 // substrate-primitive [`super::CaixaDialeto::as_str`]
3074 // `pub const fn` accessor resolve to the same four-arm
3075 // emit-set across every arm the exhaustive
3076 // [`super::CaixaDialeto::ALL`] slice enumerates. Rust's
3077 // standard library does not carry a blanket
3078 // `impl<T: AsRef<str>> From<T> for std::borrow::Cow<'static,
3079 // str>` (nor an `impl<T: fmt::Display> From<T> for
3080 // std::borrow::Cow<'static, str>`), so the
3081 // [`std::borrow::Cow<'static, str>`] forward-projection axis
3082 // is a distinct trait-idiomatic surface that a
3083 // `let key: std::borrow::Cow<'static, str> = dialeto.into();`-
3084 // shaped call site reaches through this impl and no other —
3085 // the paired sibling `From<CaixaDialeto> for &'static str`
3086 // and `From<CaixaDialeto> for String` impls force every
3087 // [`std::borrow::Cow<'static, str>`]-parameterized call site
3088 // through a `std::borrow::Cow::Borrowed(dialeto.as_str())` /
3089 // `std::borrow::Cow::Owned(dialeto.to_string())` /
3090 // `String::from(dialeto).into()` composition whose type
3091 // bounds have no compile-time link back to the substrate
3092 // primitive.
3093 //
3094 // Also asserts the projection lands on the zero-alloc
3095 // [`std::borrow::Cow::Borrowed`] arm (not the
3096 // [`std::borrow::Cow::Owned`] arm) — the substrate-primitive
3097 // [`super::CaixaDialeto::as_str`] accessor's `&'static str`
3098 // return lifetime by construction makes the borrowed arm the
3099 // type-correct projection with no runtime allocation. Any
3100 // future silent detour that routes the impl through the
3101 // owned arm (an accidental
3102 // `std::borrow::Cow::Owned(dialeto.to_string())` rewrite that
3103 // would allocate on every call site where the `&'static str`
3104 // return of [`super::CaixaDialeto::as_str`] makes the
3105 // zero-alloc borrowed projection type-correct) trips at
3106 // caixa-core test time under the
3107 // [`std::borrow::Cow::Borrowed`] discriminator witness rather
3108 // than at a downstream
3109 // [`std::borrow::Cow<'static, str>`]-bound consumer's silent
3110 // allocation.
3111 //
3112 // Second peer on the outside-M3 caixa-core tier of the
3113 // substrate-wide trait-idiomatic
3114 // [`std::borrow::Cow<'static, str>`] forward-projection
3115 // family — extends the axis off the two-list dep-graph
3116 // [`crate::dep::DepList`] pair (6858bac / 702cdf4) that
3117 // opened + closed the tier onto the dialect-classification
3118 // [`super::CaixaDialeto`] enum (the sole remaining
3119 // internal-classification peer on the caixa-core surface).
3120 // Every future closed-set fieldless typed enum peer on the
3121 // substrate is a future target of the campaign.
3122 for &variant in CaixaDialeto::ALL {
3123 let via_trait: std::borrow::Cow<'static, str> =
3124 <std::borrow::Cow<'static, str> as From<CaixaDialeto>>::from(variant);
3125 let via_method: &'static str = variant.as_str();
3126 assert_eq!(
3127 via_trait.as_ref(),
3128 via_method,
3129 "From<CaixaDialeto> for Cow<'static, str> impl must \
3130 round-trip CaixaDialeto::{variant:?} to the same \
3131 PascalCase byte-string CaixaDialeto::as_str returns \
3132 — divergence signals a silent detour off the \
3133 substrate-primitive accessor"
3134 );
3135 assert!(
3136 matches!(via_trait, std::borrow::Cow::Borrowed(_)),
3137 "From<CaixaDialeto> for Cow<'static, str> impl must \
3138 land on the zero-alloc Cow::Borrowed arm on \
3139 CaixaDialeto::{variant:?} — a Cow::Owned outcome \
3140 signals the projection has silently allocated where \
3141 the substrate-primitive CaixaDialeto::as_str \
3142 `&'static str` return makes the borrowed arm the \
3143 type-correct projection"
3144 );
3145 let via_into: std::borrow::Cow<'static, str> = variant.into();
3146 assert_eq!(
3147 via_into.as_ref(),
3148 via_method,
3149 "Into<Cow<'static, str>>::into on \
3150 CaixaDialeto::{variant:?} must byte-equal \
3151 CaixaDialeto::as_str on the same input — the \
3152 blanket-derived Into shape must resolve to the same \
3153 as_str dispatch as the explicit From impl"
3154 );
3155 assert!(
3156 matches!(via_into, std::borrow::Cow::Borrowed(_)),
3157 "Into<Cow<'static, str>>::into on \
3158 CaixaDialeto::{variant:?} must land on the zero-alloc \
3159 Cow::Borrowed arm — the blanket-derived Into shape \
3160 must resolve to the same Cow::Borrowed dispatch as \
3161 the explicit From impl"
3162 );
3163 }
3164 }
3165
3166 #[test]
3167 fn caixa_dialeto_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm() {
3168 // Cross-axis partition pin: the newly lifted trait-idiomatic
3169 // `From<CaixaDialeto> for std::borrow::Cow<'static, str>`
3170 // (this lift), the paired owned-input
3171 // `From<CaixaDialeto> for &'static str`, and the paired
3172 // owned-input `From<CaixaDialeto> for String` forward
3173 // projections must resolve identically on every arm, locking
3174 // the three return-shape paths together by construction so
3175 // any future detour trips at caixa-core test time. Also
3176 // byte-parity witness against the sibling
3177 // [`ToString::to_string`] surface routed through
3178 // [`std::fmt::Display`] — every owned-heap-string path (the
3179 // [`std::borrow::Cow::Owned`] promotion of this axis's
3180 // `.into_owned()`, `From<CaixaDialeto> for String`, and
3181 // `.to_string()`) resolves to the same PascalCase byte-string
3182 // per arm.
3183 //
3184 // Then a `.iter().copied().map(std::borrow::Cow::from)` pipe
3185 // witness over [`super::CaixaDialeto::ALL`] that materializes
3186 // the four-arm accept-set through the
3187 // [`std::borrow::Cow<'static, str>`] axis alone — the exact
3188 // shape a future `axum::response::IntoResponse` per-arm
3189 // rejection-body composer, a future M4
3190 // `mesh.pleme.io/v1alpha1/Manifesto` CR materializer's
3191 // admission-webhook per-arm rejection-reason emitter whose
3192 // typing rules out the sibling [`AsRef<str>`] borrowed
3193 // return, or a future substrate-wide per-arm diagnostic
3194 // surface that binds through a
3195 // [`std::borrow::Cow<'static, str>`] boundary reaches through
3196 // — closing the composable-projection axis on the dialect-
3197 // classification closed-set fieldless typed enum peer. The
3198 // pipe witness also pins the zero-alloc discipline: every
3199 // element in the collected vector satisfies the
3200 // [`std::borrow::Cow::Borrowed`] arm predicate, so a future
3201 // accidental silent-allocation regression on the pipe's
3202 // iteration axis is a caixa-core-test-time failure.
3203 //
3204 // Then a direct round-trip witness through
3205 // [`TryFrom<&str>`] on the projection's
3206 // [`std::borrow::Cow::as_ref`] borrow — unlike the peer
3207 // [`crate::CaixaKind`] axis pair (whose forward emit lands
3208 // on the lowercase Portuguese diagnostic vocabulary while
3209 // the reverse parse lands on the `PascalCase` wire
3210 // vocabulary, forcing the round-trip through an intermediate
3211 // [`crate::CaixaKind::wire_name`] hop),
3212 // [`super::CaixaDialeto`]'s forward emit and reverse parse
3213 // share one `PascalCase` vocabulary by construction, so the
3214 // [`std::borrow::Cow<'static, str>`] projection composes
3215 // directly with the trait-idiomatic reverse [`TryFrom<&str>`]
3216 // axis without the wire-vocab intermediate hop.
3217 for &variant in CaixaDialeto::ALL {
3218 let via_cow: std::borrow::Cow<'static, str> =
3219 <std::borrow::Cow<'static, str> as From<CaixaDialeto>>::from(variant);
3220 let via_static: &'static str = <&'static str as From<CaixaDialeto>>::from(variant);
3221 let via_string: String = <String as From<CaixaDialeto>>::from(variant);
3222 assert_eq!(
3223 via_cow.as_ref(),
3224 via_static,
3225 "From<CaixaDialeto> for Cow<'static, str> and \
3226 From<CaixaDialeto> for &'static str must resolve \
3227 identically on CaixaDialeto::{variant:?} — \
3228 divergence signals the Cow<'static, str> and \
3229 &'static str return-shape paths have drifted onto \
3230 different emit-sets"
3231 );
3232 assert_eq!(
3233 via_cow.as_ref(),
3234 via_string.as_str(),
3235 "From<CaixaDialeto> for Cow<'static, str> and \
3236 From<CaixaDialeto> for String must resolve \
3237 identically on CaixaDialeto::{variant:?} — \
3238 divergence signals the Cow<'static, str> and String \
3239 return-shape paths have drifted onto different \
3240 emit-sets"
3241 );
3242 let via_to_string: String = variant.to_string();
3243 assert_eq!(
3244 via_cow.as_ref(),
3245 via_to_string.as_str(),
3246 "From<CaixaDialeto> for Cow<'static, str> must \
3247 byte-equal CaixaDialeto::to_string on \
3248 CaixaDialeto::{variant:?} — divergence signals the \
3249 trait-idiomatic Cow<'static, str> forward-projection \
3250 axis and the ToString-through-Display axis have \
3251 drifted onto different emit-sets"
3252 );
3253 }
3254 let via_iter: Vec<std::borrow::Cow<'static, str>> = CaixaDialeto::ALL
3255 .iter()
3256 .copied()
3257 .map(std::borrow::Cow::from)
3258 .collect();
3259 let via_method: Vec<std::borrow::Cow<'static, str>> = CaixaDialeto::ALL
3260 .iter()
3261 .map(|d| std::borrow::Cow::Borrowed(d.as_str()))
3262 .collect();
3263 assert_eq!(
3264 via_iter, via_method,
3265 "`.iter().copied().map(Cow::from)` over \
3266 CaixaDialeto::ALL must byte-equal `.iter().map(|d| \
3267 Cow::Borrowed(d.as_str()))` on every arm — the \
3268 trait-idiomatic `From<CaixaDialeto> for Cow<'static, \
3269 str>` axis is what makes the `Cow::from` composition \
3270 route through the substrate-primitive \
3271 CaixaDialeto::as_str accessor rather than a per-call-\
3272 site open-code"
3273 );
3274 for cow in &via_iter {
3275 assert!(
3276 matches!(cow, std::borrow::Cow::Borrowed(_)),
3277 "`.iter().copied().map(Cow::from)` over \
3278 CaixaDialeto::ALL must land on the zero-alloc \
3279 Cow::Borrowed arm on every element — a Cow::Owned \
3280 outcome signals the pipe has silently allocated \
3281 where the substrate-primitive \
3282 CaixaDialeto::as_str `&'static str` return makes \
3283 the borrowed arm the type-correct projection"
3284 );
3285 }
3286 for &variant in CaixaDialeto::ALL {
3287 let via_cow: std::borrow::Cow<'static, str> =
3288 <std::borrow::Cow<'static, str> as From<CaixaDialeto>>::from(variant);
3289 let re_parsed: Result<CaixaDialeto, ()> =
3290 <CaixaDialeto as TryFrom<&str>>::try_from(via_cow.as_ref());
3291 assert_eq!(
3292 re_parsed,
3293 Ok(variant),
3294 "trait-idiomatic Cow<'static, str> forward-projection \
3295 + reverse-projection axis pair must round-trip \
3296 CaixaDialeto::{variant:?} through `.into::<Cow<\
3297 'static, str>>()` on the owned-input surface and \
3298 back through `TryFrom<&str>` on the projection's \
3299 Cow::as_ref borrow — a break signals the \
3300 Cow<'static, str> forward-emit and reverse-parse \
3301 axes have drifted onto different vocabularies \
3302 (unlike the peer CaixaKind axis pair, CaixaDialeto's \
3303 forward emit and reverse parse share one PascalCase \
3304 vocabulary by construction, so the round-trip \
3305 composes directly)"
3306 );
3307 }
3308 }
3309}