Skip to main content

caixa_core/
version.rs

1use std::fmt;
2
3use serde::{Deserialize, Serialize};
4use thiserror::Error;
5
6/// A caixa's pinned version — a thin typed wrapper over a String that parses
7/// as [`semver::Version`] on demand.
8///
9/// Stored as a String at rest so authoring a `caixa.lisp` stays a single
10/// quoted literal. The typed form is reached through [`Self::parse`].
11#[derive(Serialize, Deserialize, Debug, Clone, PartialEq, Eq, Hash)]
12#[serde(transparent)]
13pub struct CaixaVersion(pub String);
14
15impl CaixaVersion {
16    /// Parse and validate the wrapped string as semver.
17    pub fn parse(&self) -> Result<semver::Version, VersionError> {
18        semver::Version::parse(&self.0)
19            .map_err(|e| VersionError::semver(self.0.clone(), e.to_string()))
20    }
21
22    /// Borrow the string form.
23    #[must_use]
24    pub const fn as_str(&self) -> &str {
25        self.0.as_str()
26    }
27}
28
29impl fmt::Display for CaixaVersion {
30    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
31        f.write_str(&self.0)
32    }
33}
34
35impl From<String> for CaixaVersion {
36    fn from(s: String) -> Self {
37        Self(s)
38    }
39}
40
41impl From<&str> for CaixaVersion {
42    fn from(s: &str) -> Self {
43        Self(s.to_string())
44    }
45}
46
47/// Substrate-canonical stdlib [`std::str::FromStr`] parse-set entry point on
48/// the [`CaixaVersion`] newtype primitive — closes the canonical
49/// `str::parse::<CaixaVersion>()` axis on the paired [`From<&str> for
50/// CaixaVersion`] / [`From<String> for CaixaVersion`] infallible
51/// forward-projection constructors. Delegates byte-for-byte through the
52/// paired borrowed-input `impl From<&str> for CaixaVersion` immediately
53/// above (which wraps `s.to_string()` into the newtype's inner `String`
54/// slot), so every consumer that reaches [`CaixaVersion`] through the
55/// stdlib `T: FromStr`-bounded parse surface (`str::parse::<CaixaVersion>`,
56/// a `clap::Parser`-derived `#[arg(value_parser)]` on a future `feira
57/// publish --versao <ver>` arg-parse, a `serde_with::DisplayFromStr`
58/// wrapper on the [`crate::Caixa::versao`] field in a downstream typed-YAML
59/// derive, or any generic `fn parse_versao<T: FromStr>(s: &str) -> Result<T,
60/// T::Err>` receiver) routes through the same [`String::to_string`]-shaped
61/// wrap the paired `From<&str>` constructor already exercises. `type Err =
62/// std::convert::Infallible` because the paired `From<&str>` constructor is
63/// total — [`CaixaVersion`] stores the wrapped string raw at rest (the
64/// author surface's single-quoted `:versao "…"` literal round-trips
65/// byte-for-byte) and defers semver validation to the paired
66/// [`CaixaVersion::parse`] `Result<semver::Version, VersionError>`
67/// accessor, so no byte-string the standard-library parse-set entry point
68/// receives can fail construction on this axis (any `&str` is a valid
69/// `CaixaVersion` body at rest; only `.parse::<semver::Version>()` on the
70/// wrapped body can reject a shape the semver grammar refuses). Peer of
71/// the paired `impl FromStr for String` stdlib impl on the standard-library
72/// `String` newtype (whose `Err = Infallible` covers the same "any `&str` is
73/// a valid `String` body" total-wrap discipline the [`CaixaVersion`]
74/// newtype installs on the caixa-core surface). The first standard-library
75/// stdlib-parse-set entry point on the [`CaixaVersion`] newtype beyond the
76/// paired forward-projection [`From<&str>`] / [`From<String>`]
77/// constructors and the sibling [`fmt::Display`] / [`AsRef<str>`] /
78/// [`std::borrow::Borrow<str>`] projections the newtype already carries.
79///
80/// # Compounding
81///
82/// The stdlib parse-set entry point is the canonical Rust-idiomatic axis
83/// generic bounds compose against: `str::parse::<T>()` is a `T: FromStr`-
84/// bounded generic (not a `T: for<'a> TryFrom<&'a str>`-bounded one), so
85/// lifting the axis onto [`CaixaVersion`] unlocks the `.parse::<CaixaVersion>()`
86/// short-form on every future stdlib-shaped consumer without forcing the
87/// caller to spell the paired `From<&str>` constructor at the wire-up site.
88/// A future `clap::Args`-derived `feira publish --versao <ver>` arg-parse
89/// composes `arg.parse::<CaixaVersion>()` directly through the
90/// `#[arg(value_parser = clap::value_parser!(CaixaVersion))]` short-form
91/// (which resolves through the `T: FromStr` bound `clap::value_parser!`
92/// installs on any type carrying the trait), a `serde_with::DisplayFromStr`
93/// wrapper on a future typed-YAML [`crate::Caixa::versao`] field routes
94/// through the same `T: FromStr` bound `serde_with` keys off, and any
95/// generic per-authored-string coalescer over a mixed newtype family
96/// (`Result<T, T::Err>` on a `T: FromStr` bound) picks up
97/// [`CaixaVersion`] as one of its arms by construction.
98///
99/// # Round-trip discipline
100///
101/// The `Err = Infallible` shape witnesses the round-trip discipline the
102/// paired forward-projection [`fmt::Display`] impl closes at compile time:
103/// `s.parse::<CaixaVersion>().unwrap().to_string() == s` for every `&str`
104/// (the fail-before-pass-after pin
105/// [`caixa_version_from_str_round_trips_through_display_on_every_input`]
106/// witnesses this against the sibling `caret_matches_minor_range` /
107/// `star_is_any` / `caixa_version_as_str_accessor_is_const_fn` fixture
108/// bodies covering the semver-shape, prerelease-shape, empty-body,
109/// requirement-shape, and non-semver-junk corners). Any future accidental
110/// narrowing (a stray `parse_semver_first` validation gate slipping onto
111/// the wrap path, a normalization step that would drop whitespace or
112/// canonicalize a prerelease tag) trips the pin at caixa-core build time
113/// under the byte-equality assertion, refusing the divergent shape ahead
114/// of the downstream materializer's admit cycle.
115impl std::str::FromStr for CaixaVersion {
116    type Err = std::convert::Infallible;
117
118    fn from_str(s: &str) -> Result<Self, Self::Err> {
119        // Delegate byte-for-byte through the paired borrowed-input
120        // `impl From<&str> for CaixaVersion` constructor above — the
121        // total-wrap axis every stdlib `T: FromStr`-bounded consumer
122        // reaches [`CaixaVersion`] through resolves to the same
123        // [`String::to_string`]-shaped body the sibling forward-
124        // projection constructor already installs. `type Err =
125        // Infallible` because the paired constructor is total; `Ok`
126        // is the only reachable arm on this axis.
127        Ok(<Self as From<&str>>::from(s))
128    }
129}
130
131/// Substrate-canonical [`AsRef<str>`] projection on the [`CaixaVersion`]
132/// typed newtype — routes through the same [`CaixaVersion::as_str`]
133/// `pub const fn` scalar accessor the sibling [`fmt::Display`] impl
134/// and every downstream `&str`-shaped consumer already keys off, so
135/// any future consumer that binds a [`CaixaVersion`] through the
136/// standard-library `impl AsRef<str>` bound (a `Path`-shaped file-
137/// system reader on the operator side that accepts the version body
138/// as one segment of a per-caixa `versao/<v>/...` on-disk cache path,
139/// a builder-shaped API on the future `feira publish` writer verb
140/// that composes `<prefix><versao>` through a git-tag builder crate's
141/// `impl AsRef<str>` join step, a `HashMap<CaixaVersion, _>` lookup
142/// through the `map.get::<str>(v.as_ref())` shape a future
143/// version-keyed dispatch table lands on) reaches the wrapped
144/// [`String`] through one substrate-primitive dispatch rather than
145/// through the pre-lift `.as_str()` open-coded projection at every
146/// wire-up.
147///
148/// Peer of the sibling [`fmt::Display`] impl on the same primitive —
149/// both delegate to the shared [`CaixaVersion::as_str`] `pub const
150/// fn` accessor, so [`format!("{v}")`], `v.as_str()`, and
151/// `<CaixaVersion as AsRef<str>>::as_ref(&v)` resolve to the same
152/// byte-string per instance by construction. A future rebrand of the
153/// wrapped storage (a hypothetical widening to a typed [`semver::Version`]
154/// slot the roadmap acknowledges once eager parse-on-construct
155/// discipline lands, an internal normalization step that trims
156/// leading zeroes off pre-release identifiers, a per-cluster overlay
157/// the operator pins through a future `:versao-overrides` slot) that
158/// changes what [`CaixaVersion::as_str`] returns migrates every
159/// consumer of every one of the three paths in lockstep.
160///
161/// Same "route the trait impl through the substrate-primitive
162/// accessor" discipline the sibling [`fmt::Display`] impl on this
163/// type already carries — extends it onto the standard-library
164/// [`AsRef<str>`] projection axis every third-party API that takes
165/// `impl AsRef<str>` (the [`std::path::Path::new`] / [`std::fs`]
166/// interop surface, [`std::process::Command::arg`], the peer
167/// `tracing::field::Value` recorder's `Str`-arm, every `clap`-side
168/// `value_parser!` fold that accepts an owned newtype through
169/// `impl AsRef<str>`) already binds through. Rust-side newtype
170/// convention pairs `AsRef<str>` and [`fmt::Display`] on the same
171/// primitive so a caller who has one has both; before this lift,
172/// [`CaixaVersion`] carried [`fmt::Display`] but not the paired
173/// [`AsRef<str>`] impl the convention names.
174///
175/// The first standard-library trait added to [`CaixaVersion`] beyond
176/// the pre-existing [`serde::Serialize`] / [`serde::Deserialize`] /
177/// [`Debug`] / [`Clone`] / [`PartialEq`] / [`Eq`] / [`Hash`] derives
178/// and the paired [`fmt::Display`] / [`From<String>`] / [`From<&str>`]
179/// hand-written impls. Pinned load-bearing by
180/// [`tests::caixa_version_as_ref_str_routes_through_as_str_accessor`]
181/// (byte-parity pin against [`CaixaVersion::as_str`]) — any future
182/// silent detour that routes the impl through a divergent projection
183/// (a `Cow<'_, str>` intermediate, a stray `.to_lowercase()`
184/// normalization, a swap onto a per-arm inline `&self.0.as_str()`
185/// re-inlining) trips at caixa-core test time under `assert_eq!`
186/// rather than at a downstream `impl AsRef<str>`-bound consumer's
187/// silent split.
188impl AsRef<str> for CaixaVersion {
189    fn as_ref(&self) -> &str {
190        self.as_str()
191    }
192}
193
194/// Trait-idiomatic *HashMap-key-shaped* borrow projection on the
195/// [`CaixaVersion`] newtype primitive — the standard-library
196/// [`std::borrow::Borrow<str>`] companion to the paired sibling
197/// [`AsRef<str>`] impl (a086 lift) on the same borrow-projection axis of
198/// this primitive. Routes byte-for-byte through the substrate-primitive
199/// [`CaixaVersion::as_str`] `pub const fn` accessor — the same accessor
200/// the paired [`AsRef<str>`] and [`fmt::Display`] impls already delegate
201/// through — so every consumer that binds a [`CaixaVersion`] through the
202/// standard-library `Borrow<str>` bound reaches the wrapped byte-string
203/// through one substrate-primitive dispatch rather than through a
204/// pre-lift `.as_str()` open-coded projection at every wire-up.
205///
206/// A future consumer that wants to key a map or set by
207/// [`CaixaVersion`] and look up entries by a borrowed [`&str`] — a
208/// per-`:versao` compatibility matrix `HashMap<CaixaVersion, PolicyRow>`
209/// where the reconciliation loop's per-cycle `.get(current_versao_str)`
210/// probes the map with the raw `&str` view of the current cluster
211/// snapshot's version body (the `HashMap::get<Q: ?Sized>` signature is
212/// `where K: Borrow<Q>, Q: Hash + Eq`; without this impl the caller must
213/// wrap the borrowed `&str` in a fresh [`CaixaVersion`] allocation on
214/// every probe), a future `BTreeMap<CaixaVersion, _>::range(..)` sweep
215/// over a per-versao index that accepts a borrowed `&str` range bound
216/// through the same `Borrow<str>` bound, a
217/// `HashSet<CaixaVersion>::contains(&str)` membership probe on a
218/// per-versao denylist keyed by owned [`CaixaVersion`] but queried by
219/// the borrowed view — reaches the wrapped byte-string through this one
220/// dispatch on the substrate primitive, without the pre-lift
221/// `CaixaVersion::from(<&str>)` per-probe allocation the paired forward
222/// [`From<&str> for CaixaVersion`] constructor would otherwise force at
223/// every lookup site.
224///
225/// Peer of the sibling [`AsRef<str>`] impl on the same borrow-projection
226/// axis — both project a borrowed `&self` binding onto a borrowed `&str`
227/// via the shared substrate-primitive [`CaixaVersion::as_str`] accessor.
228/// Rust's standard library deliberately splits the two trait axes on the
229/// two bounds they carry: [`AsRef<str>`] is the *conversion* bound used
230/// by APIs that accept `impl AsRef<str>` and view the input as a `&str`
231/// projection (the [`std::path::Path::new`] / [`std::fs`] interop
232/// surface, [`std::process::Command::arg`], [`clap`]-side
233/// `value_parser!` folds), while [`std::borrow::Borrow<str>`] is the
234/// stricter *identity* bound the collection APIs
235/// ([`std::collections::HashMap`], [`std::collections::BTreeMap`],
236/// [`std::collections::HashSet`], [`std::collections::BTreeSet`]) key
237/// their lookup surfaces off — [`std::borrow::Borrow`] additionally
238/// promises that a borrowed view produced through [`Borrow::borrow`]
239/// hashes and compares byte-identically to the owned form, which is the
240/// contract [`std::collections::HashMap::get`] relies on when it hashes
241/// the query key through `Q` (`str`) and matches against slot keys
242/// hashed through `K` ([`CaixaVersion`]). The [`CaixaVersion`] newtype
243/// meets that contract by construction: the derived [`Hash`] impl hashes
244/// the wrapped [`String`] field, which (through the standard-library
245/// `impl Hash for String { fn hash(...) { (**self).hash(...) } }`
246/// pass-through) dispatches to [`str::hash`] on the raw bytes — the same
247/// dispatch a direct `.hash()` on the `&str` returned by
248/// [`Self::borrow`] would take. The derived [`PartialEq`] and [`Eq`]
249/// impls compare field-wise (byte-equal on the wrapped [`String`]), so
250/// `cv1 == cv2` reduces to `cv1.borrow() == cv2.borrow()` at the
251/// `&str`-projection axis. Both invariants — hash-agrees and
252/// eq-agrees — hold structurally, so this impl is sound under the
253/// [`std::borrow::Borrow`] documented safety contract.
254///
255/// Same "one substrate-primitive dispatch, one shared accessor" discipline
256/// the paired [`AsRef<str>`] impl on this primitive already carries —
257/// extends it onto the [`std::borrow::Borrow<str>`] projection axis the
258/// standard-library collection APIs key their `.get::<Q>` /
259/// `.contains::<Q>` / `.range::<R, T>` / `.remove::<Q>` lookup surfaces
260/// off. Rust's standard library mirrors this exact pairing on its own
261/// [`String`] primitive (`impl AsRef<str> for String` +
262/// `impl Borrow<str> for String`), so a newtype that carries one axis
263/// but not the other splits off the convention that lets every
264/// [`String`]-shaped consumer swap the newtype in without re-shaping
265/// its bounds.
266///
267/// Pinned load-bearing by
268/// [`tests::caixa_version_borrow_str_routes_through_as_str_accessor`]
269/// (byte-parity pin against [`CaixaVersion::as_str`] on the same
270/// instance),
271/// [`tests::caixa_version_borrow_str_and_as_ref_str_agree_on_every_shape`]
272/// (cross-axis partition pin against the paired [`AsRef<str>`] impl,
273/// closing the "borrow-axis two-corner split" bifurcation on the same
274/// wrapped body), and
275/// [`tests::caixa_version_borrow_str_enables_hashmap_lookup_by_borrowed_key`]
276/// (contract-witness pin routing a [`std::collections::HashMap::get`]
277/// probe against a `&str` key through the `Borrow<str>` bound on a map
278/// keyed by owned [`CaixaVersion`], asserting the collection APIs reach
279/// the same slot the borrowed and owned forms compose the same hash for).
280impl std::borrow::Borrow<str> for CaixaVersion {
281    fn borrow(&self) -> &str {
282        self.as_str()
283    }
284}
285
286/// Trait-idiomatic *owned-`String`* reverse projection on the
287/// [`CaixaVersion`] newtype primitive — the owned-heap-string inverse
288/// of the pre-existing [`From<String> for CaixaVersion`] /
289/// [`From<&str> for CaixaVersion`] forward-projection pair on this
290/// primitive. Returns the wrapped [`String`] verbatim ([`Self::0`],
291/// a move of the pre-existing heap allocation — no re-copy of the
292/// per-instance version body's bytes), so every consumer that binds a
293/// [`CaixaVersion`] through the standard-library `.into()` /
294/// [`From<Self> for String`] (equivalently [`Into<String>`]) axis
295/// reaches the wrapped byte-string through one substrate-primitive
296/// dispatch rather than through a `.as_str().to_owned()` /
297/// `.to_string()` allocating detour whose bounds have no compile-time
298/// link back to the newtype's storage.
299///
300/// A future consumer that wants to unwrap a [`CaixaVersion`] into an
301/// owned [`String`] — a `serde_json::Value::String(versao.into())`
302/// structured-payload composer where the `Value::String` arm typing
303/// demands an owned [`String`] and the sibling
304/// [`AsRef<str>`]-borrowed axis forces an explicit `.to_owned()`
305/// restatement at every call site, a future
306/// `HashMap::<String, _>::from_iter([(versao.into(), _)])` per-versao
307/// lookup where the map's key type is owned [`String`] rather than
308/// [`&str`] borrowed from a stashed [`CaixaVersion`], a future
309/// `Cow::<'static, str>::Owned(versao.into())` composer where the
310/// owned arm typing rules out the borrowed [`AsRef<str>`] return —
311/// reaches the wrapped [`String`] through this one dispatch, avoiding
312/// the pre-lift double-allocation (`.as_str().to_owned()` on the owned
313/// path would allocate a fresh [`String`] rather than reuse the
314/// wrapper's own heap allocation).
315///
316/// Opens the trait-idiomatic *owned-`String`* reverse-projection axis
317/// on the substrate's core String-wrapper newtype primitive
318/// [`CaixaVersion`], mirroring the paired owned-`String` forward-
319/// projection family the sibling closed-set fieldless typed enums
320/// ([`crate::supervisor::RestartStrategy`] (7baa18a, first-mover),
321/// [`crate::supervisor::RestartPolicy`] (7851725),
322/// [`crate::CaixaKind`] (per its own doc block, third peer), plus the
323/// remaining twelve closed-set enums) already carry — Rust's standard
324/// library does not derive `From<Self> for String` from `From<String>
325/// for Self`, so every newtype that carries a forward `From<String>`
326/// constructor but not the paired reverse-unwrap axis forces every
327/// call site through a `.to_string()` / `.as_str().to_owned()` detour
328/// that allocates fresh bytes rather than moving the wrapper's own
329/// heap allocation.
330///
331/// Preserves the two-path split on the wrapped byte-string: the paired
332/// [`AsRef<str>`] and [`fmt::Display`] impls stay reachable for the
333/// borrowed `&str` and formatter-output paths, this impl closes the
334/// owned-`String` reverse axis. Same "one dispatch on the substrate
335/// primitive" discipline the peer forward `From<String> for
336/// CaixaVersion` / `From<&str> for CaixaVersion` constructors carry,
337/// now extended onto the owned-heap-string reverse projection.
338///
339/// Pinned load-bearing by
340/// [`tests::caixa_version_from_into_owned_string_returns_wrapped_body`]
341/// (byte-parity pin against [`CaixaVersion::as_str`] on the same
342/// instance) and
343/// [`tests::caixa_version_from_into_owned_string_and_as_str_agree_on_every_shape`]
344/// (cross-axis partition pin against the paired borrowed
345/// [`AsRef<str>`] impl and the sibling [`fmt::Display`]-routed
346/// [`ToString::to_string`] surface, plus a round-trip witness through
347/// the paired forward [`From<String> for CaixaVersion`] constructor
348/// closing the two-way `Self → String → Self` cycle by construction).
349impl From<CaixaVersion> for String {
350    fn from(v: CaixaVersion) -> String {
351        v.0
352    }
353}
354
355/// Trait-idiomatic *borrowed-input, owned-`String` output* reverse
356/// projection on the [`CaixaVersion`] newtype primitive — the
357/// borrowed-input companion to the paired owned-input
358/// [`From<CaixaVersion> for String`] impl immediately above. Routes
359/// byte-for-byte through the substrate-primitive
360/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
361/// [`str::to_owned`]) so every consumer that holds a
362/// borrowed [`&CaixaVersion`] and needs an owned [`String`] — a
363/// `[…].iter().map(String::from).collect::<Vec<_>>()` per-instance
364/// materializer over `&[CaixaVersion]` (whose iterator yields
365/// `&CaixaVersion`, not `CaixaVersion`, so the owned-input
366/// [`From<CaixaVersion> for String`] axis alone forces every call site
367/// through an explicit `.clone()` / dereference restatement), a future
368/// `HashMap::<String, _>::from_iter` that keys off a borrowed-
369/// iteration axis where cloning the wrapper would allocate one
370/// [`String`] beyond the map entry's own, a future
371/// `serde_json::Value::String(String::from(&caixa.versao))`
372/// structured-payload composer that owns the emit-path without moving
373/// out of a borrowed field — reaches the wrapped byte-string through
374/// this one dispatch on the substrate primitive.
375///
376/// Second corner on the `{Self, &Self} → String` reverse-projection
377/// family opened on the paired owned-input
378/// [`From<CaixaVersion> for String`] impl immediately above. Rust's
379/// `From` trait does not derive the `From<&Self>` sibling from a
380/// `From<Self>` impl (the blanket
381/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not
382/// exist in `core`), so every newtype that carries the owned-input
383/// reverse axis but not the borrowed-input axis forces every borrowed
384/// call site through a `.clone()` / `<String>::from(v.clone())` detour
385/// whose type bounds have no compile-time link back to the newtype.
386///
387/// Pinned load-bearing by
388/// [`tests::caixa_version_from_borrowed_into_owned_string_routes_through_as_str_accessor`]
389/// (byte-parity pin against [`CaixaVersion::as_str`] via a borrowed
390/// input) and
391/// [`tests::caixa_version_from_owned_and_borrowed_into_string_agree_on_every_shape`]
392/// (cross-axis partition pin against the paired owned-input
393/// [`From<CaixaVersion> for String`] impl on the same instance,
394/// closing the "owned-input move vs. borrowed-input clone" bifurcation
395/// on the same wrapped body).
396impl From<&CaixaVersion> for String {
397    fn from(v: &CaixaVersion) -> String {
398        v.as_str().to_owned()
399    }
400}
401
402/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, str>`]
403/// output* reverse projection on the [`CaixaVersion`] newtype
404/// primitive — the [`Cow<'static, str>`] companion to the paired
405/// owned-input [`From<CaixaVersion> for String`] impl (999a310) on
406/// the same primitive. Routes through
407/// [`std::borrow::Cow::Owned`]`(v.0)`, moving the wrapper's own heap
408/// allocation through verbatim (no re-copy of the per-instance version
409/// body's bytes, no allocating detour through
410/// [`CaixaVersion::as_str`] + [`str::to_owned`]) — so every consumer
411/// that binds a [`CaixaVersion`] through the standard-library `.into()`
412/// / [`From<Self> for Cow<'static, str>`] axis reaches the wrapped
413/// byte-string through one substrate-primitive dispatch on the exact
414/// same heap allocation the manifest-parse forward
415/// [`From<String> for CaixaVersion`] constructor accepted.
416///
417/// A future consumer that wants a [`Cow<'static, str>`]-typed handle
418/// on a [`CaixaVersion`] — a
419/// `metric_label: Cow<'static, str> = versao.into()` structured-log
420/// key on a future per-caixa `caixa-operator` reconciliation counter
421/// (whose emit surface types metric keys as `Cow<'static, str>` so
422/// static compile-time literals and dynamic version bodies share the
423/// same key-slot without an unconditional heap allocation on the
424/// literal path), a future
425/// `HashMap::<Cow<'static, str>, _>::from_iter([(versao.into(), _)])`
426/// per-versao lookup where the map's key type is
427/// [`Cow<'static, str>`] rather than owned [`String`] so
428/// literal-lifetime keys can share the same map without wrapping in an
429/// extra [`String`] allocation, a future M4 admission-webhook
430/// rejection body whose per-arm error message composes through
431/// `format!("{}", Cow::<'static, str>::from(caixa.versao))` where the
432/// [`Cow<'static, str>`] intermediate is what the sibling error-frame
433/// composer accepts — reaches the wrapped byte-string through this
434/// one dispatch, without the pre-lift `.to_string().into()` /
435/// `Cow::Owned(String::from(v))` double-hop that would allocate a
436/// fresh intermediary [`String`] on the way to the same
437/// [`Cow::Owned`] arm.
438///
439/// Deliberately returns [`std::borrow::Cow::Owned`] rather than
440/// [`std::borrow::Cow::Borrowed`] — the substrate-primitive
441/// [`CaixaVersion::as_str`] accessor's return does not carry the
442/// `&'static str` lifetime by construction (the wrapped [`String`]
443/// storage is a runtime heap allocation, not a compile-time literal),
444/// so the [`Cow<'static, str>`] output shape rules out the borrowed
445/// arm and the owned arm is the type-correct projection. Peer of the
446/// paired owned-input [`From<CaixaVersion> for String`] impl on the
447/// same primitive — both route through the wrapper's own heap
448/// allocation via a move on `v.0`, preserving the zero-copy
449/// discipline the substrate opens on its String-wrapper newtype
450/// primitive.
451///
452/// Opens the trait-idiomatic *owned-input, [`Cow<'static, str>`]*
453/// reverse-projection axis on the substrate's core String-wrapper
454/// newtype primitive [`CaixaVersion`], mirroring the paired
455/// [`Cow<'static, str>`] *forward*-projection family the sibling
456/// closed-set fieldless typed enums (via
457/// [`crate::supervisor::RestartStrategy`],
458/// [`crate::supervisor::RestartPolicy`], and the remaining twelve
459/// closed-set enums) already carry — on the enum peers, the paired
460/// axis returns [`Cow::Borrowed`] because the accessor returns
461/// `&'static str`; on this newtype the paired axis returns
462/// [`Cow::Owned`] because the wrapped storage is runtime-allocated.
463/// Rust's standard library does not derive `From<Self> for
464/// Cow<'static, str>` from `From<Self> for String` (nor derive
465/// `From<&Self>` from `From<Self>`), so every newtype that carries a
466/// reverse `From<Self> for String` unwrap axis but not the paired
467/// [`Cow<'static, str>`] axis forces every
468/// [`Cow<'static, str>`]-typed call site through a `.to_string().into()`
469/// double-allocation detour that heap-allocates a fresh intermediary
470/// [`String`] between the wrapper and the [`Cow::Owned`] arm.
471///
472/// Pinned load-bearing by
473/// [`tests::caixa_version_from_into_owned_cow_str_returns_owned_wrapped_body`]
474/// (byte-parity + [`Cow::Owned`]-arm pin against
475/// [`CaixaVersion::as_str`] on the same instance, plus a round-trip
476/// witness through the paired [`From<String> for CaixaVersion`]
477/// constructor) and
478/// [`tests::caixa_version_from_into_owned_cow_str_and_string_agree_on_every_shape`]
479/// (cross-axis partition pin against the paired owned-input
480/// [`From<CaixaVersion> for String`] impl on the same instance,
481/// closing the "owned-input into [`String`] vs. owned-input into
482/// [`Cow<'static, str>`]" bifurcation on the same wrapped body).
483impl From<CaixaVersion> for std::borrow::Cow<'static, str> {
484    fn from(v: CaixaVersion) -> std::borrow::Cow<'static, str> {
485        std::borrow::Cow::Owned(v.0)
486    }
487}
488
489/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, str>`]
490/// output* reverse projection on the [`CaixaVersion`] newtype
491/// primitive — the borrowed-input companion to the paired owned-input
492/// [`From<CaixaVersion> for std::borrow::Cow<'static, str>`] impl
493/// immediately above. Routes byte-for-byte through the
494/// substrate-primitive [`CaixaVersion::as_str`] `pub const fn`
495/// accessor (via [`str::to_owned`] wrapped in
496/// [`std::borrow::Cow::Owned`]) so every consumer that holds a
497/// borrowed [`&CaixaVersion`] and needs a [`Cow<'static, str>`] —
498/// a `[…].iter().map(Cow::<'static, str>::from).collect::<Vec<_>>()`
499/// per-instance materializer over `&[CaixaVersion]` (whose iterator
500/// yields `&CaixaVersion`, not `CaixaVersion`, so the paired
501/// owned-input [`From<CaixaVersion> for Cow<'static, str>`] axis
502/// alone forces every call site through an explicit `.clone()` /
503/// dereference restatement), a future
504/// `HashMap::<Cow<'static, str>, _>::from_iter` that keys off a
505/// borrowed-iteration axis where cloning the wrapper would allocate
506/// one [`String`] beyond the eventual [`Cow::Owned`] arm's own, a
507/// future generic
508/// `<T: for<'a> Into<Cow<'static, str>>>`-bound emitter on a
509/// per-caixa diagnostic column that walks the
510/// `iter().map(Into::into)` shape verbatim — reaches the wrapped
511/// byte-string through this one dispatch on the substrate primitive.
512///
513/// Deliberately returns [`std::borrow::Cow::Owned`] rather than
514/// [`std::borrow::Cow::Borrowed`] — the substrate-primitive
515/// [`CaixaVersion::as_str`] accessor's return does not carry the
516/// `&'static str` lifetime by construction, so the
517/// [`Cow<'static, str>`] output shape rules out the borrowed arm and
518/// the owned arm is the type-correct projection (mirroring the paired
519/// owned-input impl's own [`Cow::Owned`] discipline). Second corner
520/// on the `{Self, &Self} → Cow<'static, str>` reverse-projection
521/// family opened on the paired owned-input impl immediately above.
522/// Rust's `From` trait does not derive the `From<&Self>` sibling from
523/// a `From<Self>` impl (the blanket
524/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not
525/// exist in `core`), so every newtype that carries the owned-input
526/// reverse [`Cow<'static, str>`] axis but not the borrowed-input axis
527/// forces every borrowed call site through a `.clone()` /
528/// `<Cow<'static, str>>::from(v.clone())` detour whose type bounds
529/// have no compile-time link back to the newtype.
530///
531/// Pinned load-bearing by
532/// [`tests::caixa_version_from_borrowed_into_owned_cow_str_routes_through_as_str_accessor`]
533/// (byte-parity + [`Cow::Owned`]-arm pin against
534/// [`CaixaVersion::as_str`] via a borrowed input, plus a
535/// source-survival witness against silent move-out) and
536/// [`tests::caixa_version_from_owned_and_borrowed_into_cow_str_agree_on_every_shape`]
537/// (cross-axis partition pin against the paired owned-input impl on
538/// the same instance, closing the "owned-input move vs. borrowed-input
539/// clone" bifurcation on the same wrapped body through the
540/// [`Cow<'static, str>`] axis).
541impl From<&CaixaVersion> for std::borrow::Cow<'static, str> {
542    fn from(v: &CaixaVersion) -> std::borrow::Cow<'static, str> {
543        std::borrow::Cow::Owned(v.as_str().to_owned())
544    }
545}
546
547/// Trait-idiomatic *owned-input, [`Box<str>`] output* reverse projection
548/// on the [`CaixaVersion`] newtype primitive — the [`Box<str>`] companion
549/// to the paired owned-input [`From<CaixaVersion> for String`] (999a310)
550/// and [`From<CaixaVersion> for std::borrow::Cow<'static, str>`] (55532e5)
551/// impls on the same primitive. Routes through
552/// [`String::into_boxed_str`]`(v.0)`, shrinking the wrapper's own heap
553/// allocation to a fit-to-length boxed slice — no re-copy of the
554/// per-instance version body's bytes on the fixed-capacity path
555/// (`String::into_boxed_str` reuses the underlying `Vec<u8>` buffer
556/// verbatim when the length matches its capacity; when the [`String`]
557/// carries slack it reallocates once to shrink), so every consumer that
558/// binds a [`CaixaVersion`] through the standard-library `.into()` /
559/// [`From<Self> for Box<str>`] axis reaches the wrapped byte-string
560/// through one substrate-primitive dispatch on the same underlying heap
561/// storage the manifest-parse forward [`From<String> for CaixaVersion`]
562/// constructor accepted.
563///
564/// A future consumer that wants a [`Box<str>`]-typed handle on a
565/// [`CaixaVersion`] — a per-caixa struct field typed `Box<str>` rather
566/// than [`String`] to trim the sixteen-byte length + capacity header
567/// down to eight bytes on the pointer + length pair (a shape the
568/// substrate acknowledges as the natural fixed-length storage for
569/// once-written-never-mutated version strings held across the whole
570/// operator reconciliation cycle), a future
571/// `HashMap::<Box<str>, _>::from_iter([(versao.into(), _)])` per-versao
572/// lookup where the map's key type is [`Box<str>`] rather than owned
573/// [`String`] so the map's per-entry key-slot carries the sixteen-byte
574/// [`Box<str>`] header instead of the twenty-four-byte [`String`]
575/// header, a future M4 admission-webhook rejection body whose per-arm
576/// error-frame composer accepts a [`Box<str>`] intermediate for the
577/// same reason — reaches the wrapped byte-string through this one
578/// dispatch, without the pre-lift `.to_string().into_boxed_str()`
579/// double-hop that would allocate a fresh intermediary [`String`] on
580/// the way to the same [`Box<str>`] slot.
581///
582/// Peer of the paired owned-input [`From<CaixaVersion> for String`]
583/// (999a310) and [`From<CaixaVersion> for Cow<'static, str>`] (55532e5)
584/// impls on the same primitive — all three route through `v.0`
585/// (the [`String`] axis returns the wrapped buffer verbatim; the
586/// [`Cow<'static, str>`] axis wraps it in [`Cow::Owned`]; this axis
587/// shrinks it to a fit-to-length boxed slice via [`String::into_boxed_str`]),
588/// preserving the zero-copy discipline the substrate opens on its
589/// String-wrapper newtype primitive across the three reverse-projection
590/// axes. Rust's standard library does not derive `From<Self> for
591/// Box<str>` from `From<Self> for String` (nor from `From<Self> for
592/// Cow<'static, str>`), so every newtype that carries the paired
593/// reverse `From<Self> for String` axis but not the paired
594/// [`Box<str>`] axis forces every [`Box<str>`]-typed call site through
595/// a `.to_string().into_boxed_str()` double-allocation detour that
596/// heap-allocates a fresh intermediary [`String`] between the wrapper
597/// and the [`Box<str>`] slot.
598///
599/// Opens the trait-idiomatic *owned-input, [`Box<str>`]*
600/// reverse-projection axis on the substrate's core String-wrapper
601/// newtype primitive [`CaixaVersion`], extending the reverse-projection
602/// matrix from the two axes already opened on this primitive (999a310
603/// on the [`String`] axis, 55532e5 on the [`Cow<'static, str>`] axis)
604/// onto the third. The fourth and final axis on the matrix
605/// ([`std::sync::Arc<str>`]) is closed by the sibling paired
606/// [`From<CaixaVersion> for std::sync::Arc<str>`] +
607/// [`From<&CaixaVersion> for std::sync::Arc<str>`] impls immediately below.
608///
609/// Pinned load-bearing by
610/// [`tests::caixa_version_from_into_owned_box_str_returns_wrapped_body`]
611/// (byte-parity pin against [`CaixaVersion::as_str`] on the same
612/// instance, plus a round-trip witness through the paired
613/// [`From<String> for CaixaVersion`] constructor closing the two-way
614/// `Self → Box<str> → Self` cycle by construction) and
615/// [`tests::caixa_version_from_into_owned_box_str_and_string_agree_on_every_shape`]
616/// (cross-axis partition pin against the paired owned-input
617/// [`From<CaixaVersion> for String`] and
618/// [`From<CaixaVersion> for Cow<'static, str>`] impls on the same
619/// instance, closing the "owned-input into [`String`] vs. owned-input
620/// into [`Cow<'static, str>`] vs. owned-input into [`Box<str>`]"
621/// three-corner bifurcation on the same wrapped body).
622impl From<CaixaVersion> for Box<str> {
623    fn from(v: CaixaVersion) -> Box<str> {
624        v.0.into_boxed_str()
625    }
626}
627
628/// Trait-idiomatic *borrowed-input, [`Box<str>`] output* reverse
629/// projection on the [`CaixaVersion`] newtype primitive — the
630/// borrowed-input companion to the paired owned-input
631/// [`From<CaixaVersion> for Box<str>`] impl immediately above. Routes
632/// byte-for-byte through the substrate-primitive
633/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
634/// [`Box::<str>::from`]`(&str)`, which allocates a fit-to-length boxed
635/// slice from the borrowed `&str` in one heap allocation without an
636/// intermediary [`String`]) so every consumer that holds a borrowed
637/// [`&CaixaVersion`] and needs a [`Box<str>`] — a
638/// `[…].iter().map(Box::<str>::from).collect::<Vec<_>>()` per-instance
639/// materializer over `&[CaixaVersion]` (whose iterator yields
640/// `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
641/// [`From<CaixaVersion> for Box<str>`] axis alone forces every call
642/// site through an explicit `.clone()` / dereference restatement), a
643/// future `HashMap::<Box<str>, _>::from_iter` that keys off a
644/// borrowed-iteration axis, a future generic
645/// `<T: for<'a> Into<Box<str>>>`-bound emitter on a per-caixa
646/// diagnostic column that walks the `iter().map(Into::into)` shape
647/// verbatim — reaches the wrapped byte-string through this one dispatch
648/// on the substrate primitive.
649///
650/// Second corner on the `{Self, &Self} → Box<str>` reverse-projection
651/// family opened on the paired owned-input impl immediately above.
652/// Rust's `From` trait does not derive the `From<&Self>` sibling from
653/// a `From<Self>` impl (the blanket
654/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not
655/// exist in `core`), so every newtype that carries the owned-input
656/// reverse [`Box<str>`] axis but not the borrowed-input axis forces
657/// every borrowed call site through a `.clone()` /
658/// `<Box<str>>::from(v.clone())` detour whose type bounds have no
659/// compile-time link back to the newtype.
660///
661/// Pinned load-bearing by
662/// [`tests::caixa_version_from_borrowed_into_owned_box_str_routes_through_as_str_accessor`]
663/// (byte-parity pin against [`CaixaVersion::as_str`] via a borrowed
664/// input, plus a source-survival witness against silent move-out) and
665/// [`tests::caixa_version_from_owned_and_borrowed_into_box_str_agree_on_every_shape`]
666/// (cross-corner partition pin between owned-input move and
667/// borrowed-input clone on the same wrapped body through the
668/// [`Box<str>`] axis).
669impl From<&CaixaVersion> for Box<str> {
670    fn from(v: &CaixaVersion) -> Box<str> {
671        Box::<str>::from(v.as_str())
672    }
673}
674
675/// Trait-idiomatic *owned-input, [`std::sync::Arc<str>`] output* reverse
676/// projection on the [`CaixaVersion`] newtype primitive — the
677/// [`std::sync::Arc<str>`] companion to the paired owned-input
678/// [`From<CaixaVersion> for String`] (999a310),
679/// [`From<CaixaVersion> for std::borrow::Cow<'static, str>`] (55532e5),
680/// and [`From<CaixaVersion> for Box<str>`] (32d861a) impls on the same
681/// primitive. Routes through [`std::sync::Arc::<str>::from`]`(v.0)`,
682/// which allocates a fresh atomically-refcounted heap slab whose data
683/// slot byte-equals the wrapper's own [`String`] storage — the wrapped
684/// bytes move through by value into the `Arc<str>` layout in one heap
685/// allocation (the [`std::sync::Arc<str>`] layout carries a strong
686/// count + weak count header ahead of the byte slice, so a copy is
687/// required regardless of the input axis; no intermediary [`String`]
688/// or [`Box<str>`] is materialized on the owned-input path).
689///
690/// A future consumer that wants a [`std::sync::Arc<str>`]-typed handle
691/// on a [`CaixaVersion`] — a share-through-clone version body held
692/// across a per-caixa `caixa-operator` reconcile task where every
693/// spawn point wants a cheap `.clone()` on the version handle without
694/// each task re-allocating its own [`String`] copy (the
695/// [`std::sync::Arc::clone`] path bumps the atomic refcount in place
696/// and returns a pointer-width handle), a future
697/// `HashMap::<std::sync::Arc<str>, _>::from_iter` per-versao lookup
698/// where the map's key type is [`std::sync::Arc<str>`] so the same
699/// version-body pointer can key both the map and the payload without a
700/// second heap allocation, a future M4 admission-webhook decoder that
701/// materializes decoded version strings as [`std::sync::Arc<str>`]
702/// slices so downstream verdict-composer tasks running on separate
703/// worker threads can share the immutable body without a
704/// per-consumer [`String::clone`] — reaches the wrapped byte-string
705/// through this one dispatch, without the pre-lift
706/// `.to_string().into::<std::sync::Arc<str>>()` double-hop that would
707/// still allocate the same [`Arc<str>`] slab plus one intermediary
708/// [`String`] between the wrapper and the [`std::sync::Arc<str>`] slot.
709///
710/// Peer of the paired owned-input [`From<CaixaVersion> for String`]
711/// (999a310), [`From<CaixaVersion> for Cow<'static, str>`] (55532e5),
712/// and [`From<CaixaVersion> for Box<str>`] (32d861a) impls on the same
713/// primitive — all four route through `v.0` (the [`String`] axis
714/// returns the wrapped buffer verbatim; the [`Cow<'static, str>`] axis
715/// wraps it in [`Cow::Owned`]; the [`Box<str>`] axis shrinks it to a
716/// fit-to-length boxed slice; this axis copies the bytes into a fresh
717/// atomically-refcounted slab whose header carries the atomic strong +
718/// weak counters the [`std::sync::Arc<str>`] layout requires),
719/// preserving the substrate's single-dispatch reverse-projection
720/// discipline across the four axes. Rust's standard library does not
721/// derive `From<Self> for Arc<str>` from `From<Self> for String` (nor
722/// from `From<Self> for Box<str>` or `From<Self> for Cow<'static, str>`),
723/// so every newtype that carries the paired reverse `From<Self> for
724/// String` / `Box<str>` / `Cow<'static, str>` axes but not the paired
725/// [`std::sync::Arc<str>`] axis forces every
726/// [`std::sync::Arc<str>`]-typed call site through a
727/// `.to_string().into()` / `Arc::<str>::from(v.to_string())`
728/// double-allocation detour that heap-allocates a fresh intermediary
729/// [`String`] between the wrapper and the [`std::sync::Arc<str>`] slot.
730///
731/// Closes the trait-idiomatic *owned-input, [`std::sync::Arc<str>`]*
732/// reverse-projection axis on the substrate's core String-wrapper
733/// newtype primitive [`CaixaVersion`], completing the reverse-projection
734/// matrix on this primitive across the full `{String, Cow<'static, str>,
735/// Box<str>, Arc<str>}` roster — the fourth and final axis (999a310 on
736/// the [`String`] axis, 55532e5 on the [`Cow<'static, str>`] axis,
737/// 32d861a on the [`Box<str>`] axis, this axis on the
738/// [`std::sync::Arc<str>`] axis).
739///
740/// Pinned load-bearing by
741/// [`tests::caixa_version_from_into_owned_arc_str_returns_wrapped_body`]
742/// (byte-parity pin against [`CaixaVersion::as_str`] on the same
743/// instance, plus a round-trip witness through the paired
744/// [`From<String> for CaixaVersion`] constructor closing the two-way
745/// `Self → Arc<str> → Self` cycle by construction) and
746/// [`tests::caixa_version_from_into_owned_arc_str_and_string_agree_on_every_shape`]
747/// (cross-axis partition pin against the paired owned-input
748/// [`From<CaixaVersion> for String`], [`From<CaixaVersion> for Cow<'static, str>`],
749/// and [`From<CaixaVersion> for Box<str>`] impls on the same instance,
750/// closing the four-corner "owned-input into `String` vs. `Cow<'static, str>`
751/// vs. `Box<str>` vs. `Arc<str>`" partition on the same wrapped body).
752impl From<CaixaVersion> for std::sync::Arc<str> {
753    fn from(v: CaixaVersion) -> std::sync::Arc<str> {
754        std::sync::Arc::<str>::from(v.0)
755    }
756}
757
758/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<str>`] output*
759/// reverse projection on the [`CaixaVersion`] newtype primitive — the
760/// borrowed-input companion to the paired owned-input
761/// [`From<CaixaVersion> for std::sync::Arc<str>`] impl immediately
762/// above. Routes byte-for-byte through the substrate-primitive
763/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
764/// [`std::sync::Arc::<str>::from`]`(&str)`, which allocates a fresh
765/// atomically-refcounted heap slab from the borrowed `&str` in one
766/// heap allocation without an intermediary [`String`] or [`Box<str>`])
767/// so every consumer that holds a borrowed [`&CaixaVersion`] and needs
768/// a [`std::sync::Arc<str>`] — a
769/// `[…].iter().map(std::sync::Arc::<str>::from).collect::<Vec<_>>()`
770/// per-instance materializer over `&[CaixaVersion]` (whose iterator
771/// yields `&CaixaVersion`, not `CaixaVersion`, so the paired
772/// owned-input [`From<CaixaVersion> for std::sync::Arc<str>`] axis
773/// alone forces every call site through an explicit `.clone()` /
774/// dereference restatement), a future
775/// `HashMap::<std::sync::Arc<str>, _>::from_iter` that keys off a
776/// borrowed-iteration axis, a future generic
777/// `<T: for<'a> Into<std::sync::Arc<str>>>`-bound emitter on a
778/// per-caixa diagnostic column that walks the
779/// `iter().map(Into::into)` shape verbatim — reaches the wrapped
780/// byte-string through this one dispatch on the substrate primitive.
781///
782/// Second corner on the `{Self, &Self} → std::sync::Arc<str>`
783/// reverse-projection family opened on the paired owned-input impl
784/// immediately above. Rust's `From` trait does not derive the
785/// `From<&Self>` sibling from a `From<Self>` impl (the blanket
786/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not
787/// exist in `core`), so every newtype that carries the owned-input
788/// reverse [`std::sync::Arc<str>`] axis but not the borrowed-input
789/// axis forces every borrowed call site through a `.clone()` /
790/// `<std::sync::Arc<str>>::from(v.clone())` detour whose type bounds
791/// have no compile-time link back to the newtype.
792///
793/// Pinned load-bearing by
794/// [`tests::caixa_version_from_borrowed_into_owned_arc_str_routes_through_as_str_accessor`]
795/// (byte-parity pin against [`CaixaVersion::as_str`] via a borrowed
796/// input, plus a source-survival witness against silent move-out) and
797/// [`tests::caixa_version_from_owned_and_borrowed_into_arc_str_agree_on_every_shape`]
798/// (cross-corner partition pin between owned-input move and
799/// borrowed-input clone on the same wrapped body through the
800/// [`std::sync::Arc<str>`] axis).
801impl From<&CaixaVersion> for std::sync::Arc<str> {
802    fn from(v: &CaixaVersion) -> std::sync::Arc<str> {
803        std::sync::Arc::<str>::from(v.as_str())
804    }
805}
806
807/// Trait-idiomatic *owned-input, [`std::rc::Rc<str>`] output* reverse
808/// projection on the [`CaixaVersion`] newtype primitive — the owned-heap-
809/// string, single-threaded-reference-counted inverse of the pre-existing
810/// [`From<String> for CaixaVersion`] / [`From<&str> for CaixaVersion`]
811/// forward-projection pair on this primitive. Consumes the owned wrapper
812/// by value, moves the wrapped [`String`] into the [`std::rc::Rc<str>`]
813/// layout in one heap allocation (the [`std::rc::Rc<str>`] layout carries
814/// a strong count + weak count header ahead of the byte slice, so the copy
815/// is required regardless of the input axis; no intermediary [`String`] or
816/// [`Box<str>`] is materialized on the owned-input path) — the exact
817/// single-threaded mirror of the paired
818/// [`From<CaixaVersion> for std::sync::Arc<str>`] impl (3e67756) on the
819/// atomically-refcounted axis.
820///
821/// A future consumer that wants a [`std::rc::Rc<str>`]-typed handle on a
822/// [`CaixaVersion`] — a per-`feira` verb's single-threaded diagnostic
823/// composer that clones the version body across a chain of Nord-themed
824/// column emitters without paying either the [`String::clone`]
825/// full-allocation cost (every step re-allocates its own buffer) or the
826/// atomic-refcount overhead the paired [`std::sync::Arc<str>`] axis
827/// forces (the [`std::rc::Rc::clone`] path bumps a non-atomic refcount in
828/// place and returns a pointer-width handle, cheaper than the paired
829/// atomic increment on the sibling [`std::sync::Arc<str>`] axis by a
830/// measurable margin on hot single-threaded call sites), a future single-
831/// threaded `HashMap::<std::rc::Rc<str>, _>::from_iter` per-versao lookup
832/// where the map's key type is [`std::rc::Rc<str>`] so the same version-
833/// body pointer can key both the map and the payload without a second heap
834/// allocation, a future `feira lint` per-caixa diagnostic table whose
835/// per-column `Cell<std::rc::Rc<str>>` payload carries the version body
836/// across the row-composer + column-composer + wrapper phases through the
837/// pointer-width handle rather than a [`String`] per phase — reaches the
838/// wrapped byte-string through this one dispatch, without the pre-lift
839/// `.to_string().into::<std::rc::Rc<str>>()` double-hop that would still
840/// allocate the same [`Rc<str>`] slab plus one intermediary [`String`]
841/// between the wrapper and the [`std::rc::Rc<str>`] slot.
842///
843/// Peer of the paired owned-input [`From<CaixaVersion> for String`]
844/// (999a310), [`From<CaixaVersion> for Cow<'static, str>`] (55532e5),
845/// [`From<CaixaVersion> for Box<str>`] (32d861a), and
846/// [`From<CaixaVersion> for std::sync::Arc<str>`] (3e67756) impls on the
847/// same primitive — all five route through `v.0` (the [`String`] axis
848/// returns the wrapped buffer verbatim; the [`Cow<'static, str>`] axis
849/// wraps it in [`Cow::Owned`]; the [`Box<str>`] axis shrinks it to a
850/// fit-to-length boxed slice; the [`Arc<str>`] axis copies the bytes into
851/// a fresh atomically-refcounted slab; this axis copies the bytes into a
852/// fresh single-threaded-refcounted slab whose header carries the non-
853/// atomic strong + weak counters the [`std::rc::Rc<str>`] layout
854/// requires), preserving the substrate's single-dispatch reverse-
855/// projection discipline across the five axes. Rust's standard library
856/// does not derive `From<Self> for Rc<str>` from `From<Self> for Arc<str>`
857/// (the [`std::sync::Arc<str>`] and [`std::rc::Rc<str>`] layouts share the
858/// same on-disk shape but the trait tables are disjoint, and no blanket
859/// `impl<T> From<T> for Rc<str> where Arc<str>: From<T>` exists in
860/// `core`), so every newtype that carries the paired
861/// [`std::sync::Arc<str>`] axis but not the paired [`std::rc::Rc<str>`]
862/// axis forces every single-threaded [`std::rc::Rc<str>`]-typed call site
863/// through a `.to_string().into()` / `Rc::<str>::from(v.to_string())`
864/// double-allocation detour that heap-allocates a fresh intermediary
865/// [`String`] between the wrapper and the [`std::rc::Rc<str>`] slot.
866///
867/// Extends the trait-idiomatic *owned-input* reverse-projection matrix on
868/// the substrate's core String-wrapper newtype primitive [`CaixaVersion`]
869/// onto the single-threaded reference-counted axis — the fifth axis
870/// (999a310 on [`String`], 55532e5 on [`Cow<'static, str>`], 32d861a on
871/// [`Box<str>`], 3e67756 on [`std::sync::Arc<str>`], this axis on
872/// [`std::rc::Rc<str>`]).
873///
874/// Pinned load-bearing by
875/// [`tests::caixa_version_from_into_owned_rc_str_returns_wrapped_body`]
876/// (byte-parity pin against [`CaixaVersion::as_str`] on the same instance,
877/// plus a round-trip witness through the paired [`From<String> for
878/// CaixaVersion`] constructor closing the two-way `Self → Rc<str> → Self`
879/// cycle by construction) and
880/// [`tests::caixa_version_from_into_owned_rc_str_and_arc_str_agree_on_every_shape`]
881/// (cross-axis partition pin against the paired owned-input
882/// [`From<CaixaVersion> for String`],
883/// [`From<CaixaVersion> for Cow<'static, str>`],
884/// [`From<CaixaVersion> for Box<str>`], and
885/// [`From<CaixaVersion> for std::sync::Arc<str>`] impls on the same
886/// instance, closing the five-corner "owned-input into `String` vs.
887/// `Cow<'static, str>` vs. `Box<str>` vs. `Arc<str>` vs. `Rc<str>`"
888/// partition on the same wrapped body).
889impl From<CaixaVersion> for std::rc::Rc<str> {
890    fn from(v: CaixaVersion) -> std::rc::Rc<str> {
891        std::rc::Rc::<str>::from(v.0)
892    }
893}
894
895/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<str>`] output* reverse
896/// projection on the [`CaixaVersion`] newtype primitive — the borrowed-
897/// input companion to the paired owned-input
898/// [`From<CaixaVersion> for std::rc::Rc<str>`] impl immediately above.
899/// Routes byte-for-byte through the substrate-primitive
900/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
901/// [`std::rc::Rc::<str>::from`]`(&str)`, which allocates a fresh
902/// single-threaded-refcounted heap slab from the borrowed `&str` in one
903/// heap allocation without an intermediary [`String`] or [`Box<str>`]) so
904/// every consumer that holds a borrowed [`&CaixaVersion`] and needs a
905/// [`std::rc::Rc<str>`] — a
906/// `[…].iter().map(std::rc::Rc::<str>::from).collect::<Vec<_>>()`
907/// per-instance materializer over `&[CaixaVersion]` (whose iterator yields
908/// `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
909/// [`From<CaixaVersion> for std::rc::Rc<str>`] axis alone forces every
910/// call site through an explicit `.clone()` / dereference restatement), a
911/// future single-threaded `HashMap::<std::rc::Rc<str>, _>::from_iter` that
912/// keys off a borrowed-iteration axis, a future generic
913/// `<T: for<'a> Into<std::rc::Rc<str>>>`-bound emitter on a per-caixa
914/// diagnostic column that walks the `iter().map(Into::into)` shape
915/// verbatim — reaches the wrapped byte-string through this one dispatch on
916/// the substrate primitive.
917///
918/// Second corner on the `{Self, &Self} → std::rc::Rc<str>` reverse-
919/// projection family opened on the paired owned-input impl immediately
920/// above. Rust's `From` trait does not derive the `From<&Self>` sibling
921/// from a `From<Self>` impl (the blanket `impl<T, U> From<&T> for U where
922/// T: Clone, U: From<T>` does not exist in `core`), so every newtype that
923/// carries the owned-input reverse [`std::rc::Rc<str>`] axis but not the
924/// borrowed-input axis forces every borrowed call site through a
925/// `.clone()` / `<std::rc::Rc<str>>::from(v.clone())` detour whose type
926/// bounds have no compile-time link back to the newtype.
927///
928/// Pinned load-bearing by
929/// [`tests::caixa_version_from_borrowed_into_owned_rc_str_routes_through_as_str_accessor`]
930/// (byte-parity pin against [`CaixaVersion::as_str`] via a borrowed input,
931/// plus a source-survival witness against silent move-out) and
932/// [`tests::caixa_version_from_owned_and_borrowed_into_rc_str_agree_on_every_shape`]
933/// (cross-corner partition pin between owned-input move and borrowed-
934/// input clone on the same wrapped body through the [`std::rc::Rc<str>`]
935/// axis).
936impl From<&CaixaVersion> for std::rc::Rc<str> {
937    fn from(v: &CaixaVersion) -> std::rc::Rc<str> {
938        std::rc::Rc::<str>::from(v.as_str())
939    }
940}
941
942/// Trait-idiomatic *byte-view* borrow projection on the [`CaixaVersion`]
943/// newtype primitive — the byte-view mirror of the pre-existing sibling
944/// [`AsRef<str>`] str-view borrow projection on this same primitive.
945/// Routes byte-for-byte through the substrate-primitive
946/// [`CaixaVersion::as_str`] `pub const fn` accessor via [`str::as_bytes`]
947/// so every consumer that binds a [`CaixaVersion`] through the standard-
948/// library `impl AsRef<[u8]>` bound reaches the wrapped [`String`]'s
949/// byte-tail through one substrate-primitive dispatch rather than through
950/// the pre-lift open-coded `v.as_str().as_bytes()` /
951/// `<CaixaVersion as AsRef<str>>::as_ref(&v).as_bytes()` two-hop
952/// composition whose bounds carry no compile-time link back to the
953/// newtype's storage.
954///
955/// The primary compounding target is the [`crate`]-adjacent
956/// [`caixa-lacre`](../../caixa-lacre/) BLAKE3 content-address closure:
957/// [`blake3::hash`] and [`blake3::Hasher::update`] both bind their input
958/// through `impl AsRef<[u8]>`, so any future per-caixa content-address
959/// tag that folds a `:versao` byte-tail into the [`crate::Lacre`] closure
960/// (a hypothetical `hasher.update(caixa.versao());`-shape composition on
961/// the per-caixa BLAKE3 closure builder, a future per-`Membro :versao`
962/// requirement fold on the M3-mesh lacre snapshot the operator's
963/// admission cycle pins each Aplicacao's `:membros :versao` accept-set
964/// against, a future per-`ChildSpec :versao-requirement` fold on the
965/// M2-OTP-shape supervisor-tree lacre snapshot) reaches the substrate-
966/// primitive [`CaixaVersion::as_str`] accessor through this impl and no
967/// other. Peer consumer paths on the byte-view axis: any future
968/// [`std::io::Write::write_all`]-bound diagnostic sink (whose input binds
969/// through `impl AsRef<[u8]>`), any future byte-keyed
970/// [`std::collections::HashMap`] `<K: AsRef<[u8]>, V>` lookup whose entry-
971/// key trait bound rules out the sibling [`AsRef<str>`] str-view
972/// projection, and any future `ring::digest::Context::update` /
973/// `sha2::Sha256::update` / `blake3::Hasher::update` byte-input surface
974/// on any future per-`:versao` content-address digest.
975///
976/// Rust's standard library carries `impl AsRef<[u8]> for str` and
977/// `impl AsRef<[u8]> for String`, so the two-hop composition
978/// `v.as_str().as_bytes()` (equivalently
979/// `AsRef::<str>::as_ref(&v).as_bytes()`) is reachable through the pre-
980/// existing str-view axis alone. But that two-hop shape has no compile-
981/// time link back to the byte-projection axis, forces every downstream
982/// `<T: AsRef<[u8]>>`-bound consumer to open-code the two-hop composition
983/// at every call site rather than pass a [`CaixaVersion`] through the
984/// trait bound directly, and admits a silent split whenever a future call
985/// site takes a sibling reverse-projection axis (a `String::from(v)`
986/// unwrap, a `Box::<str>::from(&v)` fit-to-length boxed slice, a
987/// `Cow::<'static, str>::from(v)` owned-arm wrap) whose `.as_bytes()`
988/// byte-tail byte-equals `as_str`'s by construction but carries no
989/// compile-time byte-view surface. The lifted single-hop impl closes the
990/// byte-view axis so every future `<T: AsRef<[u8]>>`-bound consumer
991/// reaches the substrate primitive through one trait dispatch, and any
992/// future rebrand of the wrapped storage (a hypothetical widening to a
993/// typed [`semver::Version`] slot once eager parse-on-construct
994/// discipline lands) migrates the byte-view surface in lockstep with the
995/// paired [`AsRef<str>`] / [`fmt::Display`] / [`std::borrow::Borrow<str>`]
996/// projections at the shared [`CaixaVersion::as_str`] accessor.
997///
998/// Rust-side newtype convention pairs [`AsRef<str>`] and [`AsRef<[u8]>`]
999/// on the same primitive (the standard library's own [`String`] carries
1000/// both — `impl AsRef<str> for String` + `impl AsRef<[u8]> for String` —
1001/// on the same borrow-projection axis), so a newtype that carries one but
1002/// not the other splits off the convention that lets every
1003/// [`String`]-shaped consumer swap the newtype in without re-shaping its
1004/// bounds. This impl closes that split on [`CaixaVersion`], mirroring the
1005/// paired [`AsRef<[u8]>`] byte-view axis every closed-set fieldless typed
1006/// enum peer on the substrate already carries
1007/// ([`crate::CaixaKind`] at kind.rs:1791, [`crate::CaixaDialeto`] at
1008/// dialeto.rs:1885, [`crate::dep::DepList`] at dep.rs:4616,
1009/// [`crate::supervisor::RestartStrategy`] at supervisor.rs:1518,
1010/// [`crate::supervisor::RestartPolicy`] at supervisor.rs:3385,
1011/// [`crate::aplicacao::WitShape`] at aplicacao.rs:1955,
1012/// [`crate::aplicacao::RateLimitUnit`] at aplicacao.rs:8900,
1013/// [`crate::aplicacao::PlacementStrategy`] at aplicacao.rs:12231), now
1014/// extended onto the substrate's core String-wrapper newtype primitive.
1015/// The str-view axes stay reachable for the borrowed `&str` and
1016/// formatter-output paths, this impl closes the byte-view axis at the
1017/// same shared substrate-primitive accessor.
1018///
1019/// Pinned load-bearing by
1020/// [`tests::caixa_version_as_ref_bytes_routes_through_as_str_accessor`]
1021/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()`, plus
1022/// cross-axis witness against the paired [`AsRef<str>`] and
1023/// [`fmt::Display`] axes' `.as_bytes()` byte-tails, plus a
1024/// `<T: AsRef<[u8]>>`-bound-consumer witness that a generic byte-input
1025/// function accepts a [`CaixaVersion`] directly through the trait bound
1026/// and reaches the wrapped body without the caller open-coding the
1027/// two-hop projection). Any future silent detour that routes the byte-
1028/// view impl off the substrate-primitive [`CaixaVersion::as_str`]
1029/// accessor (a swap onto `self.0.as_bytes()` re-inlining that bypasses
1030/// the shared `pub const fn` dispatch, a stray normalization step that
1031/// would drop whitespace or canonicalize a prerelease tag ahead of the
1032/// byte-view emit, a swap onto a hypothetical future [`semver::Version`]
1033/// re-serialization that would strip the raw at-rest storage discipline
1034/// [`CaixaVersion`] carries by construction) trips at caixa-core test
1035/// time under `assert_eq!` rather than at a downstream `impl AsRef<[u8]>`-
1036/// bound consumer's silent split.
1037impl AsRef<[u8]> for CaixaVersion {
1038    fn as_ref(&self) -> &[u8] {
1039        self.as_str().as_bytes()
1040    }
1041}
1042
1043/// Trait-idiomatic *owned-input, owned-[`Vec<u8>`] output* byte-owned
1044/// forward projection on the [`CaixaVersion`] newtype primitive — the
1045/// byte-mirror of the pre-existing owned-input [`From<CaixaVersion> for
1046/// String`] str-owned forward-projection axis and the owned-heap peer of
1047/// the borrow-projection [`AsRef<[u8]>`] byte-view axis (the prior lift on
1048/// this same primitive) that only surfaces a `&[u8]` view without an
1049/// owned-heap byte-tail.
1050///
1051/// Routes the wrapped [`String`] storage through
1052/// [`String::into_bytes`] verbatim ([`Self::0`], a move of the pre-existing
1053/// heap allocation reused byte-for-byte as the [`Vec<u8>`] backing buffer —
1054/// no re-copy of the per-instance version body's bytes, no allocating
1055/// detour through `.as_str().as_bytes().to_vec()`), so every consumer
1056/// that binds a [`CaixaVersion`] through the standard-library `.into()` /
1057/// [`From<Self> for Vec<u8>`] (equivalently [`Into<Vec<u8>>`]) axis
1058/// reaches the wrapped byte-string through one substrate-primitive
1059/// dispatch on the exact same heap allocation the manifest-parse forward
1060/// [`From<String> for CaixaVersion`] constructor accepted.
1061///
1062/// A future consumer that wants an owned [`Vec<u8>`] byte-tail on a
1063/// [`CaixaVersion`] — a future
1064/// [`std::io::Write::write_all`]-shape per-caixa `:versao` audit-log
1065/// byte-sink whose input parameter is an owned [`Vec<u8>`] payload, a
1066/// future `bytes::Bytes::from(Vec::<u8>::from(v))` composer folding the
1067/// canonical `SemVer` wire form into a [`bytes::Bytes`] framing surface,
1068/// a future `hasher.update(&Vec::<u8>::from(v))`-shape BLAKE3 content-
1069/// address closure that needs the owned byte-tail buffered before folding
1070/// into the per-caixa [`crate::Lacre`] closure body, a future per-caixa
1071/// protobuf/CBOR/msgpack payload composer whose framer takes an owned
1072/// [`Vec<u8>`] rather than a borrowed byte-slice, a future M4 admission-
1073/// webhook rejection body composer that emits the offending
1074/// [`CaixaVersion`] as a raw byte-tail through an
1075/// [`std::io::Write`]-shape sink — reaches the substrate primitive
1076/// through one trait dispatch, avoiding the pre-lift open-coded
1077/// `v.as_str().as_bytes().to_vec()` two-hop composition (a fresh heap
1078/// allocation copied byte-by-byte off the wrapper's own storage) or the
1079/// `String::from(v).into_bytes()` two-hop reverse-then-move shape whose
1080/// intermediate `String` step carries no compile-time link back to the
1081/// byte-view axis.
1082///
1083/// Peer of the pre-existing byte-view [`AsRef<[u8]>`] impl on the same
1084/// primitive — both project the wrapped [`String`] onto its byte-tail,
1085/// but the [`AsRef<[u8]>`] axis surfaces a borrowed `&[u8]` view for
1086/// consumers that never take ownership while this impl surfaces an owned
1087/// [`Vec<u8>`] for consumers whose framing / sink / hasher / channel
1088/// surfaces demand a heap-owned buffer. Rust's standard library
1089/// deliberately splits the two axes on the two bounds they carry
1090/// (`impl AsRef<[u8]> for String` for the borrowed-view surface,
1091/// `impl From<String> for Vec<u8>` via [`String::into_bytes`] for the
1092/// owned-heap surface), so a newtype that carries one but not the other
1093/// splits off the convention that lets every [`String`]-shaped consumer
1094/// swap the newtype in without re-shaping its bounds.
1095///
1096/// Opens the trait-idiomatic *owned-input, [`Vec<u8>`]* byte-owned
1097/// forward-projection axis on the substrate's core String-wrapper newtype
1098/// primitive [`CaixaVersion`], mirroring the paired
1099/// `From<{Self, &Self}> for Vec<u8>` axis every sibling closed-set
1100/// fieldless typed enum peer on the substrate already carries
1101/// ([`crate::CaixaKind`], [`crate::CaixaDialeto`], [`crate::dep::DepList`],
1102/// [`crate::supervisor::RestartStrategy`],
1103/// [`crate::supervisor::RestartPolicy`], [`crate::aplicacao::WitShape`],
1104/// [`crate::aplicacao::RateLimitUnit`],
1105/// [`crate::aplicacao::PlacementStrategy`], and the compound sibling
1106/// [`crate::aplicacao::RateLimit`] at aplicacao.rs:6743 which routes
1107/// through its paired [`fmt::Display`] via `.to_string().into_bytes()`),
1108/// now extended onto the substrate's core String-wrapper newtype
1109/// primitive.
1110///
1111/// Pinned load-bearing by
1112/// [`tests::caixa_version_from_into_owned_vec_bytes_returns_wrapped_body`]
1113/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` on the
1114/// same instance, plus a round-trip witness through the paired
1115/// [`From<String> for CaixaVersion`] constructor after re-materializing
1116/// the [`Vec<u8>`] through [`String::from_utf8`]) and
1117/// [`tests::caixa_version_from_owned_and_borrowed_into_vec_bytes_agree_on_every_shape`]
1118/// (cross-axis partition pin against the paired borrowed-input impl and
1119/// against the pre-existing byte-view [`AsRef<[u8]>`] axis on the same
1120/// instance, closing the "owned-input move vs. borrowed-input clone" and
1121/// "owned-heap vs. borrowed-view" bifurcations on the same wrapped body).
1122impl From<CaixaVersion> for Vec<u8> {
1123    fn from(v: CaixaVersion) -> Vec<u8> {
1124        v.0.into_bytes()
1125    }
1126}
1127
1128/// Trait-idiomatic *borrowed-input, owned-[`Vec<u8>`] output* byte-owned
1129/// forward projection on the [`CaixaVersion`] newtype primitive — the
1130/// borrowed-input companion to the paired owned-input
1131/// [`From<CaixaVersion> for Vec<u8>`] impl immediately above. Routes
1132/// byte-for-byte through the substrate-primitive
1133/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
1134/// [`str::as_bytes`] + [`slice::to_vec`]) so every consumer that holds a
1135/// borrowed [`&CaixaVersion`] and needs an owned [`Vec<u8>`] — a
1136/// `[…].iter().map(Vec::<u8>::from).collect::<Vec<_>>()` per-instance
1137/// materializer over `&[CaixaVersion]` (whose iterator yields
1138/// `&CaixaVersion`, not `CaixaVersion`, so the owned-input
1139/// [`From<CaixaVersion> for Vec<u8>`] axis alone forces every call site
1140/// through an explicit `.clone()` restatement whose intermediate
1141/// [`CaixaVersion`] allocation is discarded on the very next call), a
1142/// future admission-webhook diagnostic body composer that walks a
1143/// `&Vec<CaixaVersion>` overlay through an [`Into<Vec<u8>>`]-bound per-
1144/// arm byte-writer to surface each offending `:versao` wire form, a
1145/// future per-`Membro :versao`-shape audit-log byte-writer that folds
1146/// each Aplicacao's member-versao byte-tail into an owned [`Vec<u8>`]
1147/// sink without moving out of the borrowed [`AplicacaoSpec::membros`]
1148/// slice — reaches the wrapped byte-string through this one dispatch on
1149/// the substrate primitive.
1150///
1151/// Second corner on the `{Self, &Self} → Vec<u8>` byte-owned forward-
1152/// projection family opened on the paired owned-input
1153/// [`From<CaixaVersion> for Vec<u8>`] impl immediately above. Rust's
1154/// `From` trait does not derive the `From<&Self>` sibling from a
1155/// `From<Self>` impl (the blanket
1156/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not exist
1157/// in `core`), so every newtype that carries the owned-input byte-owned
1158/// forward axis but not the borrowed-input axis forces every borrowed
1159/// call site through a `.clone()` / `<Vec<u8>>::from(v.clone())` detour
1160/// whose type bounds have no compile-time link back to the newtype.
1161///
1162/// Pinned load-bearing by
1163/// [`tests::caixa_version_from_borrowed_into_owned_vec_bytes_routes_through_as_str_accessor`]
1164/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` via a
1165/// borrowed input, plus a source-survival witness against silent move-
1166/// out) and
1167/// [`tests::caixa_version_from_owned_and_borrowed_into_vec_bytes_agree_on_every_shape`]
1168/// (cross-corner partition pin between owned-input move and borrowed-
1169/// input clone on the same wrapped body through the [`Vec<u8>`] axis).
1170impl From<&CaixaVersion> for Vec<u8> {
1171    fn from(v: &CaixaVersion) -> Vec<u8> {
1172        v.as_str().as_bytes().to_vec()
1173    }
1174}
1175
1176/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, [u8]>`]
1177/// output* byte-owned reverse projection on the [`CaixaVersion`] newtype
1178/// primitive — the [`Cow<'static, [u8]>`] companion to the paired owned-
1179/// input [`From<CaixaVersion> for Vec<u8>`] impl (98d38ed) on the same
1180/// primitive, mirroring the sibling str-family [`From<CaixaVersion> for
1181/// std::borrow::Cow<'static, str>`] axis (55532e5) onto the byte-family
1182/// side of the reverse-projection matrix. Routes through
1183/// [`std::borrow::Cow::Owned`]`(v.0.into_bytes())`, moving the wrapper's
1184/// own heap allocation through [`String::into_bytes`] verbatim — no
1185/// re-copy of the per-instance version body's bytes on the owned-input
1186/// path, no allocating detour through [`CaixaVersion::as_str`] +
1187/// [`slice::to_vec`], no mis-routing onto [`Cow::Borrowed`] on a
1188/// runtime byte-string that cannot promise the `&'static [u8]` lifetime
1189/// the borrowed arm requires.
1190///
1191/// A future consumer that wants a [`Cow<'static, [u8]>`]-typed handle
1192/// on a [`CaixaVersion`] — a
1193/// `tracing::field::Value::Bytes(caixa.versao.into())`-shape structured-
1194/// log key on a future per-caixa `caixa-operator` reconciliation counter
1195/// (whose byte-tail emit surface types byte-keys as
1196/// [`Cow<'static, [u8]>`] so static compile-time literals and dynamic
1197/// version bodies share the same key-slot without an unconditional heap
1198/// allocation on the literal path), a future
1199/// `HashMap::<Cow<'static, [u8]>, _>::from_iter([(versao.into(), _)])`
1200/// per-versao lookup where the map's key type is [`Cow<'static, [u8]>`]
1201/// rather than owned [`Vec<u8>`] so literal-lifetime byte-keys can share
1202/// the same map without wrapping in an extra [`Vec<u8>`] allocation, a
1203/// future M4 admission-webhook rejection body whose per-arm error-frame
1204/// composer accepts a [`Cow<'static, [u8]>`] intermediate for the same
1205/// reason — reaches the wrapped byte-string through this one dispatch,
1206/// without the pre-lift `Vec::<u8>::from(v).into()` /
1207/// `Cow::Owned(Vec::from(v))` double-hop that would still allocate the
1208/// same [`Cow::Owned`] arm through the sibling byte-owned axis.
1209///
1210/// Deliberately returns [`std::borrow::Cow::Owned`] rather than
1211/// [`std::borrow::Cow::Borrowed`] — the substrate-primitive
1212/// [`CaixaVersion::as_str`] accessor's `.as_bytes()` return does not
1213/// carry the `&'static [u8]` lifetime by construction (the wrapped
1214/// [`String`] storage is a runtime heap allocation, not a compile-time
1215/// literal), so the [`Cow<'static, [u8]>`] output shape rules out the
1216/// borrowed arm and the owned arm is the type-correct projection
1217/// (mirroring the paired sibling [`From<CaixaVersion> for
1218/// std::borrow::Cow<'static, str>`] axis's own [`Cow::Owned`] discipline
1219/// at 55532e5). Peer of the paired owned-input
1220/// [`From<CaixaVersion> for Vec<u8>`] impl (98d38ed) on the same
1221/// primitive — both route through the wrapper's own heap allocation via
1222/// a move on `v.0.into_bytes()`, preserving the zero-copy discipline the
1223/// substrate opens on its String-wrapper newtype primitive across the
1224/// byte-family reverse-projection matrix.
1225///
1226/// Extends the trait-idiomatic *owned-input* byte-family reverse-
1227/// projection matrix on the substrate's core String-wrapper newtype
1228/// primitive [`CaixaVersion`] onto the [`Cow<'static, [u8]>`] axis —
1229/// the second corner (98d38ed on [`Vec<u8>`], this axis on
1230/// [`Cow<'static, [u8]>`]) on the byte-family side, mirroring the
1231/// paired str-family axis at 55532e5 on [`Cow<'static, str>`]. Rust's
1232/// standard library does not derive `From<Self> for Cow<'static, [u8]>`
1233/// from `From<Self> for Vec<u8>` (nor from `From<Self> for Cow<'static,
1234/// str>`), so every newtype that carries a byte-owned [`Vec<u8>`]
1235/// reverse axis but not the paired [`Cow<'static, [u8]>`] axis forces
1236/// every [`Cow<'static, [u8]>`]-typed call site through a
1237/// `Vec::<u8>::from(v).into()` intermediary allocation whose bounds
1238/// carry no compile-time link back to the newtype's storage.
1239///
1240/// Pinned load-bearing by
1241/// [`tests::caixa_version_from_into_owned_cow_bytes_returns_owned_wrapped_body`]
1242/// (byte-parity + [`Cow::Owned`]-arm pin against
1243/// [`CaixaVersion::as_str`] `.as_bytes()` on the same instance, plus a
1244/// round-trip witness through the paired [`From<String> for
1245/// CaixaVersion`] constructor after re-materializing the byte-tail
1246/// through [`String::from_utf8`]) and
1247/// [`tests::caixa_version_from_into_owned_cow_bytes_and_vec_bytes_agree_on_every_shape`]
1248/// (cross-axis partition pin against the paired owned-input
1249/// [`From<CaixaVersion> for Vec<u8>`] and pre-existing byte-view
1250/// [`AsRef<[u8]>`] impls on the same instance, closing the "owned-input
1251/// into [`Vec<u8>`] vs. owned-input into [`Cow<'static, [u8]>`]"
1252/// bifurcation on the same wrapped body).
1253impl From<CaixaVersion> for std::borrow::Cow<'static, [u8]> {
1254    fn from(v: CaixaVersion) -> std::borrow::Cow<'static, [u8]> {
1255        std::borrow::Cow::Owned(v.0.into_bytes())
1256    }
1257}
1258
1259/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, [u8]>`]
1260/// output* byte-owned reverse projection on the [`CaixaVersion`] newtype
1261/// primitive — the borrowed-input companion to the paired owned-input
1262/// [`From<CaixaVersion> for std::borrow::Cow<'static, [u8]>`] impl
1263/// immediately above. Routes byte-for-byte through the substrate-
1264/// primitive [`CaixaVersion::as_str`] `pub const fn` accessor (via
1265/// [`str::as_bytes`] + [`slice::to_vec`] wrapped in
1266/// [`std::borrow::Cow::Owned`]) so every consumer that holds a borrowed
1267/// [`&CaixaVersion`] and needs a [`Cow<'static, [u8]>`] — a
1268/// `[…].iter().map(Cow::<'static, [u8]>::from).collect::<Vec<_>>()`
1269/// per-instance materializer over `&[CaixaVersion]` (whose iterator
1270/// yields `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
1271/// [`From<CaixaVersion> for Cow<'static, [u8]>`] axis alone forces every
1272/// call site through an explicit `.clone()` / dereference restatement),
1273/// a future `HashMap::<Cow<'static, [u8]>, _>::from_iter` that keys off
1274/// a borrowed-iteration axis where cloning the wrapper would allocate
1275/// one [`String`] beyond the eventual [`Cow::Owned`] arm's own, a future
1276/// generic `<T: for<'a> Into<Cow<'static, [u8]>>>`-bound byte-writer on
1277/// a per-caixa diagnostic column that walks the
1278/// `iter().map(Into::into)` shape verbatim — reaches the wrapped
1279/// byte-string through this one dispatch on the substrate primitive.
1280///
1281/// Deliberately returns [`std::borrow::Cow::Owned`] rather than
1282/// [`std::borrow::Cow::Borrowed`] — the substrate-primitive
1283/// [`CaixaVersion::as_str`] accessor's `.as_bytes()` return does not
1284/// carry the `&'static [u8]` lifetime by construction, so the
1285/// [`Cow<'static, [u8]>`] output shape rules out the borrowed arm and
1286/// the owned arm is the type-correct projection (mirroring the paired
1287/// owned-input impl's own [`Cow::Owned`] discipline). Second corner on
1288/// the `{Self, &Self} → Cow<'static, [u8]>` byte-owned reverse-
1289/// projection family opened on the paired owned-input impl immediately
1290/// above. Rust's `From` trait does not derive the `From<&Self>` sibling
1291/// from a `From<Self>` impl (the blanket
1292/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not exist
1293/// in `core`), so every newtype that carries the owned-input byte-owned
1294/// reverse [`Cow<'static, [u8]>`] axis but not the borrowed-input axis
1295/// forces every borrowed call site through a `.clone()` /
1296/// `<Cow<'static, [u8]>>::from(v.clone())` detour whose type bounds
1297/// have no compile-time link back to the newtype.
1298///
1299/// Pinned load-bearing by
1300/// [`tests::caixa_version_from_borrowed_into_owned_cow_bytes_routes_through_as_str_accessor`]
1301/// (byte-parity + [`Cow::Owned`]-arm pin against
1302/// [`CaixaVersion::as_str`] `.as_bytes()` via a borrowed input, plus a
1303/// source-survival witness against silent move-out) and
1304/// [`tests::caixa_version_from_owned_and_borrowed_into_cow_bytes_agree_on_every_shape`]
1305/// (cross-corner partition pin between owned-input move and borrowed-
1306/// input clone on the same wrapped body through the [`Cow<'static,
1307/// [u8]>`] axis).
1308impl From<&CaixaVersion> for std::borrow::Cow<'static, [u8]> {
1309    fn from(v: &CaixaVersion) -> std::borrow::Cow<'static, [u8]> {
1310        std::borrow::Cow::Owned(v.as_str().as_bytes().to_vec())
1311    }
1312}
1313
1314/// Trait-idiomatic *owned-input, [`Box<[u8]>`] output* byte-owned reverse
1315/// projection on the [`CaixaVersion`] newtype primitive — the [`Box<[u8]>`]
1316/// companion to the paired owned-input [`From<CaixaVersion> for Vec<u8>`]
1317/// (98d38ed) and [`From<CaixaVersion> for std::borrow::Cow<'static, [u8]>`]
1318/// (baf7537) impls on the same primitive, mirroring the sibling str-family
1319/// [`From<CaixaVersion> for Box<str>`] axis (32d861a) onto the byte-family
1320/// side of the reverse-projection matrix. Routes through
1321/// [`Vec::<u8>::into_boxed_slice`]`(v.0.into_bytes())`, moving the wrapper's
1322/// own heap allocation into a fit-to-length boxed byte slice — no re-copy of
1323/// the per-instance version body's bytes on the fixed-capacity path
1324/// ([`Vec::<u8>::into_boxed_slice`] reuses the underlying buffer verbatim
1325/// when the length matches its capacity; when the [`Vec<u8>`] carries slack
1326/// it reallocates once to shrink), so every consumer that binds a
1327/// [`CaixaVersion`] through the standard-library `.into()` /
1328/// [`From<Self> for Box<[u8]>`] axis reaches the wrapped byte-string through
1329/// one substrate-primitive dispatch on the same underlying heap storage the
1330/// manifest-parse forward [`From<String> for CaixaVersion`] constructor
1331/// accepted.
1332///
1333/// A future consumer that wants a [`Box<[u8]>`]-typed handle on a
1334/// [`CaixaVersion`] — a per-caixa struct field typed `Box<[u8]>` rather than
1335/// [`Vec<u8>`] to trim the twenty-four-byte pointer + length + capacity
1336/// header down to sixteen bytes on the pointer + length pair (a shape the
1337/// substrate acknowledges as the natural fixed-length storage for
1338/// once-written-never-mutated version byte-tails held across the whole
1339/// operator reconciliation cycle), a future
1340/// `HashMap::<Box<[u8]>, _>::from_iter([(versao.into(), _)])` per-versao
1341/// lookup where the map's key type is [`Box<[u8]>`] rather than owned
1342/// [`Vec<u8>`] so the map's per-entry key-slot carries the sixteen-byte
1343/// [`Box<[u8]>`] header instead of the twenty-four-byte [`Vec<u8>`] header,
1344/// a future M4 admission-webhook rejection body whose per-arm error-frame
1345/// composer accepts a [`Box<[u8]>`] intermediate for the same reason —
1346/// reaches the wrapped byte-string through this one dispatch, without the
1347/// pre-lift `Vec::<u8>::from(v).into_boxed_slice()` double-hop that would
1348/// still allocate through the same [`Vec<u8>`] intermediary on the way to
1349/// the same [`Box<[u8]>`] slot but with one extra header-slot round-trip.
1350///
1351/// Peer of the paired owned-input [`From<CaixaVersion> for Vec<u8>`]
1352/// (98d38ed) and [`From<CaixaVersion> for std::borrow::Cow<'static, [u8]>`]
1353/// (baf7537) impls on the same primitive — all three route through
1354/// `v.0.into_bytes()` (the [`Vec<u8>`] axis returns the wrapped buffer
1355/// verbatim; the [`Cow<'static, [u8]>`] axis wraps it in [`Cow::Owned`];
1356/// this axis shrinks it to a fit-to-length boxed byte slice via
1357/// [`Vec::<u8>::into_boxed_slice`]), preserving the zero-copy discipline
1358/// the substrate opens on its String-wrapper newtype primitive across the
1359/// byte-family reverse-projection matrix. Rust's standard library does not
1360/// derive `From<Self> for Box<[u8]>` from `From<Self> for Vec<u8>` (nor
1361/// from `From<Self> for Cow<'static, [u8]>`), so every newtype that carries
1362/// the paired reverse [`Vec<u8>`] axis but not the paired [`Box<[u8]>`] axis
1363/// forces every [`Box<[u8]>`]-typed call site through a
1364/// `Vec::<u8>::from(v).into_boxed_slice()` intermediary allocation whose
1365/// bounds carry no compile-time link back to the newtype's storage.
1366///
1367/// Extends the trait-idiomatic *owned-input* byte-family reverse-projection
1368/// matrix on the substrate's core String-wrapper newtype primitive
1369/// [`CaixaVersion`] onto the [`Box<[u8]>`] axis — the third corner (98d38ed
1370/// on [`Vec<u8>`], baf7537 on [`Cow<'static, [u8]>`], this axis on
1371/// [`Box<[u8]>`]) on the byte-family side, mirroring the paired str-family
1372/// axis at 32d861a on [`Box<str>`].
1373///
1374/// Pinned load-bearing by
1375/// [`tests::caixa_version_from_into_owned_box_bytes_returns_wrapped_body`]
1376/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` on the
1377/// same instance, plus a round-trip witness through the paired
1378/// [`From<String> for CaixaVersion`] constructor closing the two-way
1379/// `Self → Box<[u8]> → Vec<u8> → String → Self` cycle for the UTF-8-valid
1380/// bodies every `SemVer`-shaped `:versao` is by construction) and
1381/// [`tests::caixa_version_from_into_owned_box_bytes_and_vec_bytes_agree_on_every_shape`]
1382/// (cross-axis partition pin against the paired owned-input
1383/// [`From<CaixaVersion> for Vec<u8>`],
1384/// [`From<CaixaVersion> for Cow<'static, [u8]>`], and the pre-existing
1385/// borrowed [`AsRef<[u8]>`] byte-view impls on the same instance, closing
1386/// the "owned-input into `Vec<u8>` vs. `Cow<'static, [u8]>` vs. `Box<[u8]>`"
1387/// three-corner partition on the same wrapped body).
1388impl From<CaixaVersion> for Box<[u8]> {
1389    fn from(v: CaixaVersion) -> Box<[u8]> {
1390        v.0.into_bytes().into_boxed_slice()
1391    }
1392}
1393
1394/// Trait-idiomatic *borrowed-input, [`Box<[u8]>`] output* byte-owned reverse
1395/// projection on the [`CaixaVersion`] newtype primitive — the borrowed-input
1396/// companion to the paired owned-input [`From<CaixaVersion> for Box<[u8]>`]
1397/// impl immediately above. Routes byte-for-byte through the substrate-
1398/// primitive [`CaixaVersion::as_str`] `pub const fn` accessor (via
1399/// [`str::as_bytes`] + [`Box::<[u8]>::from`]`(&[u8])`, which allocates a
1400/// fit-to-length boxed byte slice from the borrowed `&[u8]` in one heap
1401/// allocation without an intermediary [`Vec<u8>`]) so every consumer that
1402/// holds a borrowed [`&CaixaVersion`] and needs a [`Box<[u8]>`] — a
1403/// `[…].iter().map(Box::<[u8]>::from).collect::<Vec<_>>()` per-instance
1404/// materializer over `&[CaixaVersion]` (whose iterator yields
1405/// `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
1406/// [`From<CaixaVersion> for Box<[u8]>`] axis alone forces every call site
1407/// through an explicit `.clone()` / dereference restatement), a future
1408/// `HashMap::<Box<[u8]>, _>::from_iter` that keys off a borrowed-iteration
1409/// axis, a future generic `<T: for<'a> Into<Box<[u8]>>>`-bound byte-writer
1410/// on a per-caixa diagnostic column that walks the
1411/// `iter().map(Into::into)` shape verbatim — reaches the wrapped byte-
1412/// string through this one dispatch on the substrate primitive.
1413///
1414/// Second corner on the `{Self, &Self} → Box<[u8]>` byte-owned reverse-
1415/// projection family opened on the paired owned-input impl immediately
1416/// above. Rust's `From` trait does not derive the `From<&Self>` sibling
1417/// from a `From<Self>` impl (the blanket
1418/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not exist in
1419/// `core`), so every newtype that carries the owned-input byte-owned
1420/// reverse [`Box<[u8]>`] axis but not the borrowed-input axis forces every
1421/// borrowed call site through a `.clone()` /
1422/// `<Box<[u8]>>::from(v.clone())` detour whose type bounds have no
1423/// compile-time link back to the newtype.
1424///
1425/// Pinned load-bearing by
1426/// [`tests::caixa_version_from_borrowed_into_owned_box_bytes_routes_through_as_str_accessor`]
1427/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` via a
1428/// borrowed input, plus a source-survival witness against silent move-out)
1429/// and
1430/// [`tests::caixa_version_from_owned_and_borrowed_into_box_bytes_agree_on_every_shape`]
1431/// (cross-corner partition pin between owned-input move and borrowed-input
1432/// clone on the same wrapped body through the [`Box<[u8]>`] axis).
1433impl From<&CaixaVersion> for Box<[u8]> {
1434    fn from(v: &CaixaVersion) -> Box<[u8]> {
1435        Box::<[u8]>::from(v.as_str().as_bytes())
1436    }
1437}
1438
1439/// Trait-idiomatic *owned-input, [`std::sync::Arc<[u8]>`] output* byte-owned
1440/// reverse projection on the [`CaixaVersion`] newtype primitive — the
1441/// atomically-refcounted byte-slice mirror of the paired owned-input
1442/// [`From<CaixaVersion> for std::sync::Arc<str>`] (3e67756) impl on the
1443/// string-side reverse-projection matrix, and the fourth axis in the
1444/// byte-side reverse-projection matrix that already carries
1445/// [`From<CaixaVersion> for Vec<u8>`] (98d38ed),
1446/// [`From<CaixaVersion> for std::borrow::Cow<'static, [u8]>`] (baf7537),
1447/// and [`From<CaixaVersion> for Box<[u8]>`] (703b2fd). Routes through
1448/// [`std::sync::Arc::<[u8]>::from`]`(v.0.into_bytes())`, which moves the
1449/// wrapper's own [`String`] heap allocation into a [`Vec<u8>`] verbatim
1450/// (`String::into_bytes` is a niche-swap on the same buffer, no re-copy)
1451/// and then copies the bytes once into a fresh atomically-refcounted heap
1452/// slab whose header carries the strong + weak counters the
1453/// [`std::sync::Arc<[u8]>`] layout requires — one heap allocation on the
1454/// owned-input path, mirroring the paired [`std::sync::Arc<str>`] axis.
1455///
1456/// A future consumer that wants a [`std::sync::Arc<[u8]>`]-typed handle on
1457/// a [`CaixaVersion`] — a share-through-clone byte-tail held across a
1458/// per-caixa `caixa-operator` reconcile task where every spawn point wants
1459/// a cheap `.clone()` on the version body's byte view without each task
1460/// re-allocating its own [`Vec<u8>`] copy (the [`std::sync::Arc::clone`]
1461/// path bumps the atomic refcount in place and returns a pointer-width
1462/// handle), a future `HashMap::<std::sync::Arc<[u8]>, _>::from_iter`
1463/// per-versao lookup keyed by the byte-tail across worker threads, a
1464/// future M4 admission-webhook decoder that materializes decoded version
1465/// bodies as [`std::sync::Arc<[u8]>`] slices so downstream verdict-composer
1466/// tasks share the immutable byte-tail without a per-consumer
1467/// [`Vec::<u8>::clone`] — reaches the wrapped byte-tail through this one
1468/// dispatch, without the pre-lift `Vec::<u8>::from(v).into::<Arc<[u8]>>()`
1469/// double-hop that would still allocate the same [`Arc<[u8]>`] slab plus
1470/// one intermediary [`Vec<u8>`] between the wrapper and the
1471/// [`std::sync::Arc<[u8]>`] slot.
1472///
1473/// Pinned load-bearing by
1474/// [`tests::caixa_version_from_into_owned_arc_bytes_returns_wrapped_body`]
1475/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` on the
1476/// same instance, plus a round-trip witness through the paired
1477/// [`From<String> for CaixaVersion`] constructor closing the two-way
1478/// `Self → Arc<[u8]> → Vec<u8> → String → Self` cycle on UTF-8-valid
1479/// bodies) and
1480/// [`tests::caixa_version_from_into_owned_arc_bytes_and_box_bytes_agree_on_every_shape`]
1481/// (cross-axis partition pin against the paired owned-input
1482/// [`From<CaixaVersion> for Vec<u8>`],
1483/// [`From<CaixaVersion> for Cow<'static, [u8]>`], and
1484/// [`From<CaixaVersion> for Box<[u8]>`] impls on the same instance,
1485/// closing the four-corner "owned-input into `Vec<u8>` vs. `Cow<'static, [u8]>`
1486/// vs. `Box<[u8]>` vs. `Arc<[u8]>`" partition on the same wrapped body).
1487impl From<CaixaVersion> for std::sync::Arc<[u8]> {
1488    fn from(v: CaixaVersion) -> std::sync::Arc<[u8]> {
1489        std::sync::Arc::<[u8]>::from(v.0.into_bytes())
1490    }
1491}
1492
1493/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<[u8]>`] output*
1494/// byte-owned reverse projection on the [`CaixaVersion`] newtype primitive
1495/// — the borrowed-input companion to the paired owned-input
1496/// [`From<CaixaVersion> for std::sync::Arc<[u8]>`] impl immediately above.
1497/// Routes byte-for-byte through the substrate-primitive
1498/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
1499/// [`str::as_bytes`] + [`std::sync::Arc::<[u8]>::from`]`(&[u8])`, which
1500/// allocates a fresh atomically-refcounted heap slab from the borrowed
1501/// `&[u8]` in one heap allocation without an intermediary [`Vec<u8>`] or
1502/// [`Box<[u8]>`]) so every consumer that holds a borrowed
1503/// [`&CaixaVersion`] and needs a [`std::sync::Arc<[u8]>`] —
1504/// a `[…].iter().map(std::sync::Arc::<[u8]>::from).collect::<Vec<_>>()`
1505/// per-instance materializer over `&[CaixaVersion]` (whose iterator yields
1506/// `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
1507/// [`From<CaixaVersion> for std::sync::Arc<[u8]>`] axis alone forces every
1508/// call site through an explicit `.clone()` / dereference restatement), a
1509/// future `HashMap::<std::sync::Arc<[u8]>, _>::from_iter` that keys off a
1510/// borrowed-iteration axis, a future generic
1511/// `<T: for<'a> Into<std::sync::Arc<[u8]>>>`-bound byte-writer on a
1512/// per-caixa diagnostic column that walks the `iter().map(Into::into)`
1513/// shape verbatim — reaches the wrapped byte-tail through this one
1514/// dispatch on the substrate primitive.
1515///
1516/// Second corner on the `{Self, &Self} → std::sync::Arc<[u8]>` byte-owned
1517/// reverse-projection family opened on the paired owned-input impl
1518/// immediately above. Rust's `From` trait does not derive the
1519/// `From<&Self>` sibling from a `From<Self>` impl (the blanket
1520/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not exist
1521/// in `core`), so every newtype that carries the owned-input byte-owned
1522/// reverse [`std::sync::Arc<[u8]>`] axis but not the borrowed-input axis
1523/// forces every borrowed call site through a `.clone()` /
1524/// `<std::sync::Arc<[u8]>>::from(v.clone())` detour whose type bounds have
1525/// no compile-time link back to the newtype.
1526///
1527/// Pinned load-bearing by
1528/// [`tests::caixa_version_from_borrowed_into_owned_arc_bytes_routes_through_as_str_accessor`]
1529/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` via a
1530/// borrowed input, plus a source-survival witness against silent move-out)
1531/// and
1532/// [`tests::caixa_version_from_owned_and_borrowed_into_arc_bytes_agree_on_every_shape`]
1533/// (cross-corner partition pin between owned-input move and borrowed-input
1534/// clone on the same wrapped body through the [`std::sync::Arc<[u8]>`]
1535/// axis).
1536impl From<&CaixaVersion> for std::sync::Arc<[u8]> {
1537    fn from(v: &CaixaVersion) -> std::sync::Arc<[u8]> {
1538        std::sync::Arc::<[u8]>::from(v.as_str().as_bytes())
1539    }
1540}
1541
1542/// Trait-idiomatic *owned-input, [`std::rc::Rc<[u8]>`] output* byte-owned
1543/// reverse projection on the [`CaixaVersion`] newtype primitive — the
1544/// single-threaded-reference-counted byte-slice mirror of the paired
1545/// owned-input [`From<CaixaVersion> for std::rc::Rc<str>`] impl on the
1546/// string-side reverse-projection matrix, and the fifth (and final) axis in
1547/// the byte-side reverse-projection matrix that already carries
1548/// [`From<CaixaVersion> for Vec<u8>`] (98d38ed),
1549/// [`From<CaixaVersion> for std::borrow::Cow<'static, [u8]>`] (baf7537),
1550/// [`From<CaixaVersion> for Box<[u8]>`] (703b2fd), and
1551/// [`From<CaixaVersion> for std::sync::Arc<[u8]>`] (3d5fc43). Routes through
1552/// [`std::rc::Rc::<[u8]>::from`]`(v.0.into_bytes())`, which moves the
1553/// wrapper's own [`String`] heap allocation into a [`Vec<u8>`] verbatim
1554/// (`String::into_bytes` is a niche-swap on the same buffer, no re-copy) and
1555/// then copies the bytes once into a fresh single-threaded-refcounted heap
1556/// slab whose header carries the non-atomic strong + weak counters the
1557/// [`std::rc::Rc<[u8]>`] layout requires — one heap allocation on the
1558/// owned-input path, mirroring the paired [`std::rc::Rc<str>`] axis on the
1559/// string-side matrix and the sibling [`std::sync::Arc<[u8]>`] axis on the
1560/// byte-side matrix.
1561///
1562/// A future consumer that wants a [`std::rc::Rc<[u8]>`]-typed handle on a
1563/// [`CaixaVersion`] — a per-`feira` verb's single-threaded byte-tail
1564/// composer that clones the version body's byte view across a chain of
1565/// Nord-themed diagnostic emitters without paying either the
1566/// [`Vec::<u8>::clone`] full-allocation cost (every step re-allocates its
1567/// own buffer) or the atomic-refcount overhead the paired
1568/// [`std::sync::Arc<[u8]>`] axis forces (the [`std::rc::Rc::clone`] path
1569/// bumps a non-atomic refcount in place and returns a pointer-width handle,
1570/// cheaper than the paired atomic increment on the sibling
1571/// [`std::sync::Arc<[u8]>`] axis by a measurable margin on hot
1572/// single-threaded call sites), a future single-threaded
1573/// `HashMap::<std::rc::Rc<[u8]>, _>::from_iter` per-versao lookup keyed by
1574/// the byte-tail rather than the string-tail so the map's per-entry
1575/// key-slot carries the pointer-width [`Rc<[u8]>`] handle instead of the
1576/// twenty-four-byte [`Vec<u8>`] header, a future `feira lint` per-caixa
1577/// byte-diagnostic table whose per-column `Cell<std::rc::Rc<[u8]>>` payload
1578/// carries the version body's byte tail across the row-composer +
1579/// column-composer + wrapper phases through the pointer-width handle
1580/// rather than a [`Vec<u8>`] per phase — reaches the wrapped byte-string
1581/// through this one dispatch, without the pre-lift
1582/// `Vec::<u8>::from(v).into::<Rc<[u8]>>()` double-hop that would still
1583/// allocate the same [`Rc<[u8]>`] slab plus one intermediary [`Vec<u8>`]
1584/// between the wrapper and the [`std::rc::Rc<[u8]>`] slot.
1585///
1586/// Peer of the paired owned-input [`From<CaixaVersion> for Vec<u8>`]
1587/// (98d38ed), [`From<CaixaVersion> for Cow<'static, [u8]>`] (baf7537),
1588/// [`From<CaixaVersion> for Box<[u8]>`] (703b2fd), and
1589/// [`From<CaixaVersion> for std::sync::Arc<[u8]>`] (3d5fc43) impls on the
1590/// same primitive — all five route through `v.0.into_bytes()` (the
1591/// [`Vec<u8>`] axis returns the niche-swap buffer verbatim; the
1592/// [`Cow<'static, [u8]>`] axis wraps it in [`Cow::Owned`]; the
1593/// [`Box<[u8]>`] axis shrinks it to a fit-to-length boxed byte slice; the
1594/// [`Arc<[u8]>`] axis copies the bytes into a fresh atomically-refcounted
1595/// slab; this axis copies the bytes into a fresh single-threaded-refcounted
1596/// slab whose header carries the non-atomic strong + weak counters the
1597/// [`std::rc::Rc<[u8]>`] layout requires), preserving the substrate's
1598/// single-dispatch reverse-projection discipline across the five byte-owned
1599/// axes. Rust's standard library does not derive `From<Self> for Rc<[u8]>`
1600/// from `From<Self> for Arc<[u8]>` (the [`std::sync::Arc<[u8]>`] and
1601/// [`std::rc::Rc<[u8]>`] layouts share the same on-disk shape but the trait
1602/// tables are disjoint, and no blanket
1603/// `impl<T> From<T> for Rc<[u8]> where Arc<[u8]>: From<T>` exists in
1604/// `core`), so every newtype that carries the paired [`std::sync::Arc<[u8]>`]
1605/// axis but not the paired [`std::rc::Rc<[u8]>`] axis forces every
1606/// single-threaded [`std::rc::Rc<[u8]>`]-typed call site through a
1607/// `Vec::<u8>::from(v).into()` / `Rc::<[u8]>::from(v.to_string().into_bytes())`
1608/// double-allocation detour that heap-allocates a fresh intermediary
1609/// [`Vec<u8>`] between the wrapper and the [`std::rc::Rc<[u8]>`] slot.
1610///
1611/// Closes the trait-idiomatic *owned-input, byte-owned* reverse-projection
1612/// matrix on the substrate's core String-wrapper newtype primitive
1613/// [`CaixaVersion`] across the full `{Vec<u8>, Cow<'static, [u8]>,
1614/// Box<[u8]>, Arc<[u8]>, Rc<[u8]>}` roster — the fifth and final axis
1615/// (98d38ed on [`Vec<u8>`], baf7537 on [`Cow<'static, [u8]>`], 703b2fd on
1616/// [`Box<[u8]>`], 3d5fc43 on [`std::sync::Arc<[u8]>`], this axis on
1617/// [`std::rc::Rc<[u8]>`]).
1618///
1619/// Pinned load-bearing by
1620/// [`tests::caixa_version_from_into_owned_rc_bytes_returns_wrapped_body`]
1621/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` on the
1622/// same instance, plus a round-trip witness through the paired
1623/// [`From<String> for CaixaVersion`] constructor closing the two-way
1624/// `Self → Rc<[u8]> → Vec<u8> → String → Self` cycle on UTF-8-valid bodies)
1625/// and
1626/// [`tests::caixa_version_from_into_owned_rc_bytes_and_arc_bytes_agree_on_every_shape`]
1627/// (cross-axis partition pin against the paired owned-input
1628/// [`From<CaixaVersion> for Vec<u8>`],
1629/// [`From<CaixaVersion> for Cow<'static, [u8]>`],
1630/// [`From<CaixaVersion> for Box<[u8]>`], and
1631/// [`From<CaixaVersion> for std::sync::Arc<[u8]>`] impls on the same
1632/// instance, closing the five-corner "owned-input into `Vec<u8>` vs.
1633/// `Cow<'static, [u8]>` vs. `Box<[u8]>` vs. `Arc<[u8]>` vs. `Rc<[u8]>`"
1634/// partition on the same wrapped body).
1635impl From<CaixaVersion> for std::rc::Rc<[u8]> {
1636    fn from(v: CaixaVersion) -> std::rc::Rc<[u8]> {
1637        std::rc::Rc::<[u8]>::from(v.0.into_bytes())
1638    }
1639}
1640
1641/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<[u8]>`] output* byte-owned
1642/// reverse projection on the [`CaixaVersion`] newtype primitive — the
1643/// borrowed-input companion to the paired owned-input
1644/// [`From<CaixaVersion> for std::rc::Rc<[u8]>`] impl immediately above.
1645/// Routes byte-for-byte through the substrate-primitive
1646/// [`CaixaVersion::as_str`] `pub const fn` accessor (via
1647/// [`str::as_bytes`] + [`std::rc::Rc::<[u8]>::from`]`(&[u8])`, which
1648/// allocates a fresh single-threaded-refcounted heap slab from the
1649/// borrowed `&[u8]` in one heap allocation without an intermediary
1650/// [`Vec<u8>`] or [`Box<[u8]>`]) so every consumer that holds a borrowed
1651/// [`&CaixaVersion`] and needs a [`std::rc::Rc<[u8]>`] —
1652/// a `[…].iter().map(std::rc::Rc::<[u8]>::from).collect::<Vec<_>>()`
1653/// per-instance materializer over `&[CaixaVersion]` (whose iterator yields
1654/// `&CaixaVersion`, not `CaixaVersion`, so the paired owned-input
1655/// [`From<CaixaVersion> for std::rc::Rc<[u8]>`] axis alone forces every
1656/// call site through an explicit `.clone()` / dereference restatement), a
1657/// future single-threaded `HashMap::<std::rc::Rc<[u8]>, _>::from_iter` that
1658/// keys off a borrowed-iteration axis, a future generic
1659/// `<T: for<'a> Into<std::rc::Rc<[u8]>>>`-bound byte-writer on a per-caixa
1660/// diagnostic column that walks the `iter().map(Into::into)` shape
1661/// verbatim — reaches the wrapped byte-tail through this one dispatch on
1662/// the substrate primitive.
1663///
1664/// Second corner on the `{Self, &Self} → std::rc::Rc<[u8]>` byte-owned
1665/// reverse-projection family opened on the paired owned-input impl
1666/// immediately above. Rust's `From` trait does not derive the
1667/// `From<&Self>` sibling from a `From<Self>` impl (the blanket
1668/// `impl<T, U> From<&T> for U where T: Clone, U: From<T>` does not exist
1669/// in `core`), so every newtype that carries the owned-input byte-owned
1670/// reverse [`std::rc::Rc<[u8]>`] axis but not the borrowed-input axis
1671/// forces every borrowed call site through a `.clone()` /
1672/// `<std::rc::Rc<[u8]>>::from(v.clone())` detour whose type bounds have
1673/// no compile-time link back to the newtype.
1674///
1675/// Pinned load-bearing by
1676/// [`tests::caixa_version_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor`]
1677/// (byte-parity pin against [`CaixaVersion::as_str`] `.as_bytes()` via a
1678/// borrowed input, plus a source-survival witness against silent move-out)
1679/// and
1680/// [`tests::caixa_version_from_owned_and_borrowed_into_rc_bytes_agree_on_every_shape`]
1681/// (cross-corner partition pin between owned-input move and borrowed-input
1682/// clone on the same wrapped body through the [`std::rc::Rc<[u8]>`]
1683/// axis).
1684impl From<&CaixaVersion> for std::rc::Rc<[u8]> {
1685    fn from(v: &CaixaVersion) -> std::rc::Rc<[u8]> {
1686        std::rc::Rc::<[u8]>::from(v.as_str().as_bytes())
1687    }
1688}
1689
1690/// Canonical Zig-style git-tag prefix every `feira publish` run writes
1691/// and every downstream consumer of a published caixa reads. A caixa
1692/// published at `:versao "0.1.0"` lands as a git tag `v0.1.0` on the
1693/// source repo's `origin` remote — the [`crate::CaixaVersion`] value
1694/// gates the version body, this constant gates the prefix the body
1695/// composes under.
1696///
1697/// Two production-code consumers carry this prefix on the same git
1698/// remote axis:
1699///
1700/// 1. [`caixa-feira`]'s `feira publish` verb (caixa-feira/src/cmd/publish.rs)
1701///    — the writer. Its `--prefix` clap flag defaults to this string
1702///    and the verb computes the tag as `format!("{prefix}{versao}")`
1703///    before `git tag -a <tag>` + `git push origin <tag>`.
1704/// 2. [`caixa-flux`]'s [`caixa-flux::cluster_bundle`] renderer
1705///    (caixa-flux/src/lib.rs) — the reader. Its
1706///    `ClusterBundleOpts::for_caixa` constructor defaults
1707///    `git_ref: GitRefSpec::Tag(...)` to `<prefix><versao>` so the
1708///    rendered `gitrepository.yaml` carries `ref: { tag: v<versao> }`
1709///    pointing `FluxCD`'s `GitRepository` reconciler at the exact tag
1710///    the publisher just wrote.
1711///
1712/// Until this lift landed both consumers carried the bare `"v"` byte
1713/// inline — `caixa-feira/src/cmd/publish.rs:22`'s clap
1714/// `default_value = "v"` and `caixa-flux/src/lib.rs:335`'s
1715/// `format!("v{}", caixa.versao)` literal. A future Zig-style-tag
1716/// convention rebrand (the substrate moving to plain `<versao>` tags
1717/// once the GitHub releases UI normalizes around the bare form, to
1718/// `release/<versao>` once a sibling forge convention adopts the
1719/// `<type>/<value>` slash-namespaced shape, or to a per-edition
1720/// override the operator pins through a future `:placement
1721/// :tag-prefix` slot) without a coordinated edit on both sides would
1722/// silently emit a `feira publish`-side tag at one shape (e.g.
1723/// `release/0.1.0`) and a `cluster_bundle`-side `ref: { tag: v0.1.0 }`
1724/// pointing at the prior shape — Flux's `GitRepository` reconciler
1725/// would loop forever looking for an upstream `v0.1.0` ref the publish
1726/// remote no longer carries, the dependent `HelmRelease`'s `chart:
1727/// sourceRef` would never resolve, every per-Servico apply would
1728/// silently come up with the prior reconciled state, and the failure
1729/// would surface at `kubectl describe gitrepository` time (the
1730/// `Status: Stalled` / `Reason: Failed` arm) far from the rebrand
1731/// commit's source.
1732///
1733/// Lifting the literal to one `&'static str` constant closes the drift
1734/// footgun structurally — both consumers read from the same memory,
1735/// so any future rebrand reaches both sites by construction and a CI
1736/// build that re-introduces a sibling inline `"v"` literal trips the
1737/// peer pinning tests
1738/// ([`caixa-feira`]'s `publish_prefix_default_pins_lifted_caixa_core_constant`,
1739/// [`caixa-flux`]'s `cluster_bundle_default_git_tag_uses_lifted_caixa_core_prefix`)
1740/// at the build-time fail-before-deploy posture every prior
1741/// load-bearing-string lift on this surface
1742/// ([`crate::DEFAULT_NAMESPACE`] a085b26,
1743/// [`crate::DEFAULT_LIBRARY_NAME`] 41438dc,
1744/// [`crate::DEFAULT_SERVICO_PORT`] 1e22add) establishes.
1745///
1746/// Authoring-side `:versao` gates already refuse the `"v"`-prefixed
1747/// publish tag shape leaking back into a version body — every typed
1748/// `:versao` surface (top-level `:versao`, `:upgrade-from :from`,
1749/// `:deps :versao`, `:deps-dev :versao`, `:membros :versao`,
1750/// `:children :versao`) routes through `semver::Version::parse` /
1751/// [`parse_requirement`], both of which reject the `v`-prefix as
1752/// invalid `SemVer`. The split — bare `SemVer` at the `:versao` slot,
1753/// `v<versao>` at the published git-tag axis — is the convention this
1754/// constant pins.
1755pub const DEFAULT_PUBLISH_TAG_PREFIX: &str = "v";
1756
1757/// Canonical git remote name every `feira` writer-side verb pushes to —
1758/// the destination handle the operator-out-of-the-loop publish + deploy
1759/// chain (`feira publish`, `feira deploy --apply`, `feira app deploy
1760/// --apply`) names when it invokes `git push <remote> <ref>` against
1761/// the local clone of the source / k8s GitOps repo.
1762///
1763/// Three production-code consumers carry this remote name on the same
1764/// `git push` axis:
1765///
1766/// 1. [`caixa-feira`]'s `feira publish` verb (caixa-feira/src/cmd/publish.rs)
1767///    — the writer-side publish path. Its `--remote` clap flag defaults
1768///    to this string and the verb runs `git push <remote> <tag>` to push
1769///    the freshly written `v<versao>` tag upstream.
1770/// 2. [`caixa-feira`]'s `feira deploy --apply` verb
1771///    (caixa-feira/src/cmd/deploy.rs) — the writer-side Servico cluster-
1772///    deploy path. Its `push_origin` helper runs `git push origin HEAD`
1773///    against the k8s GitOps repo's working tree after upserting the
1774///    Servico's entry into the cluster's lareira-fleet-programs
1775///    HelmRelease values.
1776/// 3. [`caixa-feira`]'s `feira app deploy --apply` verb
1777///    (caixa-feira/src/cmd/app.rs) — the writer-side Aplicacao
1778///    cluster-deploy path. Its `push_origin` helper runs the same
1779///    `git push origin HEAD` against the k8s GitOps repo after writing
1780///    the rendered multi-doc YAML (programs.yaml entries + Cilium
1781///    NetworkPolicies + Gateway/HTTPRoute) to the cluster's tree.
1782///
1783/// Until this lift landed all three consumers carried the bare
1784/// `"origin"` byte inline — `publish.rs`'s clap `default_value = "origin"`,
1785/// `deploy.rs`'s `git(repo, ["push", "origin", "HEAD"])`, and
1786/// `app.rs`'s `git(repo, ["push", "origin", "HEAD"])`. A future
1787/// remote-naming-convention rebrand on any one side (the substrate
1788/// moving to `upstream` for forge-mirror clusters, to a per-tenant
1789/// remote naming convention once the operator-flux pipeline grows the
1790/// `:placement :remote` slot, or to the canonical multi-remote
1791/// `release` + `mirror` split every Erlang/OTP `release_handler` /
1792/// `relup` shop converges on once their git surface grows past one
1793/// upstream) without a coordinated edit on the other two would have
1794/// silently emitted a `git push` against a remote that doesn't exist
1795/// on the operator's clone (`fatal: '<remote>' does not appear to be
1796/// a git repository`) on one writer verb while the other two still
1797/// pushed to the old remote — operator-observed symptom: the publish
1798/// landed but the deploy didn't, or vice-versa, with the failure
1799/// surfacing as a partial-state rollout far from the rebrand commit's
1800/// source.
1801///
1802/// Lifting the literal to one `&'static str` constant closes the drift
1803/// footgun structurally — all three consumers read from the same
1804/// memory, so any future remote-naming rebrand reaches every writer
1805/// verb by construction and a CI build that re-introduces a sibling
1806/// inline `"origin"` literal trips the peer pinning tests
1807/// ([`caixa-feira`]'s `publish_remote_default_pins_lifted_caixa_core_constant`
1808/// on the clap-default axis, the sibling structural pins on the two
1809/// `push_origin` helpers) at the build-time fail-before-deploy
1810/// posture every prior load-bearing-string lift on this surface
1811/// ([`crate::DEFAULT_NAMESPACE`] a085b26, [`crate::DEFAULT_LIBRARY_NAME`]
1812/// 41438dc, [`crate::DEFAULT_SERVICO_PORT`] 1e22add,
1813/// [`crate::DEFAULT_PUBLISH_TAG_PREFIX`] 0a6a602,
1814/// [`crate::DEFAULT_FLUX_SYSTEM_NAMESPACE`] 7197d38) establishes.
1815///
1816/// Pairs with [`DEFAULT_PUBLISH_TAG_PREFIX`] on the same git remote
1817/// axis — `feira publish` runs `git push <DEFAULT_GIT_REMOTE>
1818/// <DEFAULT_PUBLISH_TAG_PREFIX><versao>` to push the typed `:versao`
1819/// body composed under the canonical prefix to the canonical remote.
1820/// Both halves of the publish-side convention now live in one place.
1821pub const DEFAULT_GIT_REMOTE: &str = "origin";
1822
1823/// Canonical GitHub org name the pleme-io substrate defaults every un-
1824/// pinned caixa's source repo to — the org handle the two substrate-side
1825/// "no `:repositorio` / no `:fonte` declared, fall back to the canonical
1826/// org" paths compose their `github:<org>/<nome>` shorthand + full
1827/// `https://github.com/<org>/<nome>` URL under.
1828///
1829/// Two production-code consumers carry this org name on the same
1830/// canonical-substrate-default-git-org axis:
1831///
1832/// 1. [`caixa-feira`]'s `feira lock` verb's `resolve_stub` (caixa-feira/src/cmd/lock.rs)
1833///    — the resolver-side default. When a declared dep has no
1834///    `:fonte` block the stub resolver composes
1835///    `caixa_core::DepSource::default_github(<org>, &dep.nome)` to fill
1836///    the shorthand `github:<org>/<nome>` fallback the phase 1.B
1837///    `feira resolve` walker will resolve against upstream.
1838/// 2. [`caixa-flux`]'s [`caixa-flux::cluster_bundle`] renderer
1839///    (caixa-flux/src/lib.rs) — the renderer-side default. Its
1840///    `ClusterBundleOpts::for_caixa` constructor defaults
1841///    `git_url` to `format!("https://github.com/{org}/{}", caixa.nome)`
1842///    when the caixa carries no `:repositorio`, so the rendered
1843///    `gitrepository.yaml` points `FluxCD`'s `GitRepository`
1844///    reconciler at the substrate's canonical git host for un-pinned
1845///    caixas.
1846///
1847/// Until this lift landed both consumers carried the bare `"pleme-io"`
1848/// byte inline — `caixa-feira/src/cmd/lock.rs:61`'s
1849/// `default_github("pleme-io", …)` call and `caixa-flux/src/lib.rs`'s
1850/// `format!("https://github.com/pleme-io/{}", …)` literal. A future
1851/// substrate-side git-org migration (the pleme-io org renaming to a
1852/// short form, forking to a per-tenant `<org>-<tenant>` shape once the
1853/// operator-flux pipeline grows a `:placement :org` slot, or moving to
1854/// a self-hosted forge under a wholly-owned org name once the
1855/// substrate's forge-gen roadmap graduates past GitHub) without a
1856/// coordinated edit on both sides would silently emit a `feira lock`-
1857/// side `github:<old-org>/<nome>` fallback shorthand while the
1858/// `cluster_bundle`-side `gitrepository.yaml` pointed at the new org's
1859/// `<nome>` — the phase 1.B `feira resolve` walker would probe the
1860/// prior org's git host for a repo that migrated with the org, or vice-
1861/// versa: Flux's `GitRepository` reconciler would loop forever looking
1862/// for an upstream repo the old org handle no longer maps to, the
1863/// dependent `HelmRelease`'s `chart: sourceRef` would never resolve,
1864/// every per-Servico apply would silently come up with the prior
1865/// reconciled state, and the failure would surface at `kubectl describe
1866/// gitrepository` time (the `Status: Stalled` / `Reason: Failed` arm)
1867/// far from the org-migration commit's source.
1868///
1869/// Lifting the literal to one `&'static str` constant closes the drift
1870/// footgun structurally — both consumers read from the same memory, so
1871/// any future org migration reaches both sites by construction and a CI
1872/// build that re-introduces a sibling inline `"pleme-io"` literal trips
1873/// the peer pinning tests at the build-time fail-before-deploy posture
1874/// every prior load-bearing-string lift on this surface
1875/// ([`crate::DEFAULT_NAMESPACE`] a085b26,
1876/// [`crate::DEFAULT_LIBRARY_NAME`] 41438dc,
1877/// [`crate::DEFAULT_SERVICO_PORT`] 1e22add,
1878/// [`DEFAULT_PUBLISH_TAG_PREFIX`] 0a6a602,
1879/// [`DEFAULT_GIT_REMOTE`],
1880/// [`crate::DEFAULT_FLUX_SYSTEM_NAMESPACE`] 7197d38) establishes.
1881///
1882/// Distinct from the [`crate::PLEME_LABEL_PREFIX`] canonical pleme-io
1883/// label-namespace prefix (`"pleme.pleme.io"`, the K8s label-namespace
1884/// axis every substrate-emitted cluster object's `LABEL_APLICACAO` /
1885/// `LABEL_PROGRAM` / `LABEL_CONTRATO` axis shares) — these constants
1886/// sit on separate schema-contract surfaces (the git-host org handle
1887/// vs. the K8s label-namespace prefix) governed by independent rebrand
1888/// cycles, so a git-org rename must not couple the K8s label-namespace
1889/// axis to the git-host axis (or vice-versa). Splitting the two lets
1890/// each schema's future rebrand land independently at its canonical
1891/// const definition without silently coupling the surfaces — same
1892/// "byte-distinct, semantically distinct" discipline the
1893/// [`crate::PLEME_LABEL_PREFIX`] / [`crate::LABEL_APLICACAO`] /
1894/// [`crate::LABEL_PROGRAM`] / [`crate::LABEL_CONTRATO`] set establishes
1895/// on the peer per-K8s-label-namespace canonical-string surface.
1896pub const DEFAULT_PLEME_GIT_ORG: &str = "pleme-io";
1897
1898/// Parse a dep's `:versao` string as a [`semver::VersionReq`].
1899///
1900/// Treats the literal `"*"` as "any version" (semver's wildcard).
1901pub fn parse_requirement(s: &str) -> Result<semver::VersionReq, VersionError> {
1902    if s == "*" {
1903        return Ok(semver::VersionReq::STAR);
1904    }
1905    semver::VersionReq::parse(s).map_err(|e| VersionError::requirement(s, e.to_string()))
1906}
1907
1908#[derive(Debug, Error, PartialEq, Eq)]
1909pub enum VersionError {
1910    #[error("invalid version '{0}': {1}")]
1911    Semver(String, String),
1912    #[error("invalid version requirement '{0}': {1}")]
1913    Requirement(String, String),
1914}
1915
1916// Fold the sole `VersionError::Semver(<into-String-expr>, <into-String-expr>)`
1917// wire-up site on [`CaixaVersion::parse`]'s [`semver::Version::parse`]
1918// `map_err` arm onto one substrate primitive — the paired
1919// `(String, String)` two-slot tuple-newtype [`VersionError::Semver`] on
1920// the [`CaixaVersion`] parser surface, the first of the two variants on
1921// the [`VersionError`] envelope's paired `(String, String)` tuple-newtype
1922// codec-magnitude family (its peer is [`VersionError::Requirement`] on
1923// the sibling [`parse_requirement`] surface). Same discipline the peer
1924// per-variant lifts on [`AplicacaoError`] / [`SupervisorError`] /
1925// [`UpgradeError`] / [`LayoutError`] / [`DepError`] / [`ManifestError`]
1926// / [`LimitsError`] / [`BehaviorError`] / [`DialetoError`] have
1927// converged through the "one substrate primitive per emit-site variant"
1928// ratchet: the sole wire-up site opens the identical
1929// `VersionError::Semver(<into-String-expr>, <into-String-expr>)` block
1930// against the parser-scoped `String` binding (`self.0.clone()`) and the
1931// derived `String` binding (`e.to_string()`) on the failing
1932// [`semver::Version::parse`] arm, so the fold routes the site through
1933// one dispatch on a uniform pair of `impl Into<String>` params,
1934// byte-equal to the pre-lift tuple-newtype construction on the same
1935// arguments. The `impl Into<String>` bound covers both the pre-lift
1936// `String` bindings and any future `&str` binding a downstream consumer
1937// might carry without forcing the caller to spell the `.into()`
1938// conversion at the wire-up site — the same shape the peer
1939// [`LimitsError::empty_byte_size`] / [`LimitsError::empty_duration`] /
1940// [`DialetoError::leitura`] folds carry on the single-slot `(String)`
1941// tuple-newtype cousins of the same tuple-newtype error-envelope family
1942// on the sibling parser surfaces. `#[must_use]` fires a compile warning
1943// at any wire-up that mistakenly discards the constructed error. The
1944// added [`PartialEq`] / [`Eq`] derives on the envelope (peer with the
1945// sibling [`LimitsError`] / [`DialetoError`] / [`DepError`] envelopes
1946// on the same axis) let the fail-before-pass-after byte-equality pins
1947// below trip a de-lift regression at caixa-core test time under
1948// `PartialEq` rather than at a downstream diagnostic shape drift.
1949//
1950// Every future consumer that wants to construct this variant outside
1951// [`CaixaVersion::parse`] (a deferred `feira lint --canonical-versao`
1952// per-caixa admission verb probing each authored top-level `:versao`
1953// value against the same [`semver::Version::parse`] gate, an M4 typed
1954// `mesh.pleme.io/v1alpha1/Servico` CR materializer's per-manifest
1955// admission validator re-checking one edited `:versao` slot against
1956// the [`CaixaVersion::parse`] semver floor, a per-`caixa.lisp` value-
1957// shape pre-emitter probing each declared `:versao` magnitude ahead of
1958// the operator's admit-cycle) now reaches the variant through one call
1959// rather than re-inlining the two-slot tuple-newtype block in lockstep.
1960impl VersionError {
1961    /// Construct a [`VersionError::Semver`] carrying the offending
1962    /// authoring string `value` and the underlying [`semver::Version::parse`]
1963    /// `reason` verbatim in the variant's two-slot tuple-newtype payload.
1964    /// Folds the uniform `Self::Semver(value.into(), reason.into())`
1965    /// tuple-newtype construction onto one substrate primitive so every
1966    /// wire-up on the variant reads through one dispatch rather than the
1967    /// pre-lift open-coded
1968    /// `VersionError::Semver(<into-String-expr>, <into-String-expr>)`
1969    /// block. The paired `impl Into<String>` bounds cover the pre-lift
1970    /// `String` wire-up shape on [`CaixaVersion::parse`]
1971    /// (`self.0.clone()` on the parser-scoped `String` field, `e.to_string()`
1972    /// on the derived `String` from the failing
1973    /// [`semver::Version::parse`] arm) without forcing the caller to
1974    /// spell the conversion at the wire-up site. Peer to the sibling
1975    /// [`VersionError::Requirement`] variant on the [`parse_requirement`]
1976    /// surface — the same `(String, String)` two-slot tuple-newtype axis
1977    /// of the paired [`VersionError`] envelope, but on the `SemVer`
1978    /// version-body parser surface rather than the version-requirement
1979    /// parser surface.
1980    #[must_use]
1981    pub fn semver(value: impl Into<String>, reason: impl Into<String>) -> Self {
1982        Self::Semver(value.into(), reason.into())
1983    }
1984
1985    /// Construct a [`VersionError::Requirement`] carrying the offending
1986    /// authoring string `value` and the underlying
1987    /// [`semver::VersionReq::parse`] `reason` verbatim in the variant's
1988    /// two-slot tuple-newtype payload. Folds the uniform
1989    /// `Self::Requirement(value.into(), reason.into())` tuple-newtype
1990    /// construction onto one substrate primitive so every wire-up on the
1991    /// variant reads through one dispatch rather than the pre-lift open-
1992    /// coded `VersionError::Requirement(<into-String-expr>,
1993    /// <into-String-expr>)` block. Peer to the sibling
1994    /// [`VersionError::semver`] ctor on the [`CaixaVersion::parse`]
1995    /// surface — the same `(String, String)` two-slot tuple-newtype axis
1996    /// of the paired [`VersionError`] envelope, but on the version-
1997    /// requirement parser surface rather than the semver-version-body
1998    /// parser surface. Closes the last un-lifted variant on the
1999    /// [`VersionError`] envelope: every arm now reaches its emit site
2000    /// through one substrate-primitive dispatch, matching the "one
2001    /// substrate primitive per emit-site variant" ratchet the peer per-
2002    /// variant lifts on [`crate::AplicacaoError`] /
2003    /// [`crate::SupervisorError`] / [`crate::UpgradeError`] /
2004    /// [`crate::LayoutError`] / [`crate::DepError`] /
2005    /// [`crate::ManifestError`] / [`crate::LimitsError`] /
2006    /// [`crate::BehaviorError`] / [`crate::DialetoError`] have converged
2007    /// onto.
2008    #[must_use]
2009    pub fn requirement(value: impl Into<String>, reason: impl Into<String>) -> Self {
2010        Self::Requirement(value.into(), reason.into())
2011    }
2012}
2013
2014#[cfg(test)]
2015mod tests {
2016    use super::*;
2017
2018    #[test]
2019    fn version_round_trip() {
2020        let v: CaixaVersion = "1.2.3".into();
2021        assert_eq!(v.as_str(), "1.2.3");
2022        assert_eq!(v.parse().unwrap().to_string(), "1.2.3");
2023    }
2024
2025    #[test]
2026    fn caixa_version_as_str_accessor_is_const_fn() {
2027        // Fail-before-pass-after pin on [`CaixaVersion::as_str`]'s
2028        // `const`-eval-surface posture. The accessor projects the typed
2029        // newtype's inner [`String`] through the `pub const fn`
2030        // [`String::as_str`] (const-stable since Rust 1.87, well within
2031        // the workspace MSRV) — any future accidental downgrade to
2032        // non-`const` fails `as_str_via_const_fn` at caixa-core build
2033        // time with E0015 (`cannot call non-const method`), strictly
2034        // stronger than a runtime `assert!`. Sibling of the peer
2035        // per-M2/M3/universal-axis `String → &str` scalar-accessor
2036        // family pins on the sibling `const`-eval-surface passes
2037        // ([`crate::Caixa::nome`] / [`crate::Caixa::versao`] at the
2038        // top-level manifest, [`crate::aplicacao::Membro::nome`] /
2039        // [`crate::aplicacao::Membro::versao_requirement`] at the M3
2040        // membership axis, [`crate::aplicacao::Entrada::hostname`] /
2041        // [`crate::aplicacao::Entrada::destination`] at the M3 ingress
2042        // axis, [`crate::supervisor::ChildSpec::nome`] /
2043        // [`crate::supervisor::ChildSpec::versao_requirement`] at the
2044        // M2 supervisor-tree axis,
2045        // [`crate::upgrade::UpgradeFromEntry::prior_versao`] at the M2
2046        // upgrade axis, [`crate::dep::Dep::nome`] /
2047        // [`crate::dep::Dep::versao_requirement`] at the dep-graph
2048        // axis, and the peer per-`:contratos` [`crate::aplicacao::WitContract::source`] /
2049        // [`crate::aplicacao::WitContract::destination`] /
2050        // [`crate::aplicacao::WitContract::world_ref`] trio the
2051        // sibling pin at 279823b already anchors).
2052        const fn as_str_via_const_fn(v: &CaixaVersion) -> &str {
2053            v.as_str()
2054        }
2055        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2056            let v: CaixaVersion = versao.into();
2057            assert_eq!(as_str_via_const_fn(&v), v.as_str());
2058            assert_eq!(v.as_str(), versao);
2059        }
2060    }
2061
2062    #[test]
2063    fn star_is_any() {
2064        let r = parse_requirement("*").unwrap();
2065        assert!(r.matches(&"0.1.0".parse().unwrap()));
2066        assert!(r.matches(&"99.0.0".parse().unwrap()));
2067    }
2068
2069    #[test]
2070    fn caret_matches_minor_range() {
2071        let r = parse_requirement("^0.1").unwrap();
2072        assert!(r.matches(&"0.1.0".parse().unwrap()));
2073        assert!(r.matches(&"0.1.99".parse().unwrap()));
2074        assert!(!r.matches(&"0.2.0".parse().unwrap()));
2075    }
2076
2077    #[test]
2078    fn invalid_version_errors() {
2079        let v: CaixaVersion = "not-a-version".into();
2080        assert!(v.parse().is_err());
2081    }
2082
2083    #[test]
2084    fn semver_ctor_matches_tuple_literal_wrap_on_str_binding() {
2085        // Fail-before-pass-after byte-equality pin: the lifted
2086        // [`VersionError::semver`] inherent ctor projects a `&str`
2087        // binding pair through the paired `impl Into<String>` bounds
2088        // byte-equal to the pre-lift open-coded
2089        // `VersionError::Semver(<into-String-expr>, <into-String-expr>)`
2090        // tuple-literal on the same fixture, so any future silent
2091        // regression that swaps `.into()` for a divergent conversion
2092        // (a stray `String::from(str::trim(v))` normalization, a
2093        // parity-lossy `.to_lowercase()` fold, a `Cow<'_, str>` detour)
2094        // trips at caixa-core test time under `PartialEq` rather than
2095        // at a downstream diagnostic-shape drift on a consumer surface.
2096        // Same shape the peer
2097        // [`crate::LimitsError::empty_byte_size_ctor_matches_tuple_literal_wrap_on_str_binding`]
2098        // / [`crate::DialetoError::leitura_ctor_matches_tuple_literal_wrap_on_str_binding`]
2099        // pins carry on the sibling single-slot `(String)` tuple-newtype
2100        // cousins of the same tuple-newtype error-envelope family on the
2101        // sibling parser surfaces.
2102        let value: &str = "not-a-version";
2103        let reason: &str = "unexpected character 'n' while parsing major version number";
2104        assert_eq!(
2105            VersionError::semver(value, reason),
2106            VersionError::Semver(value.to_string(), reason.to_string()),
2107            "generated semver ctor over `&str` bindings must match \
2108             the pre-lift tuple-literal wrap on the same fixture",
2109        );
2110    }
2111
2112    #[test]
2113    fn semver_ctor_matches_tuple_literal_wrap_on_string_binding() {
2114        // Fail-before-pass-after byte-equality pin on the paired owned-
2115        // `String` shape — the actual wire-up shape on
2116        // [`CaixaVersion::parse`] (`self.0.clone()` +
2117        // `e.to_string()`). Peer to the `&str` variant above; refuses
2118        // any future de-lift that inlines a divergent construction on
2119        // the owned-`String` path (a stray `.trim().to_string()`
2120        // normalization on either slot, a swap that routes the ctor
2121        // through the sibling [`VersionError::Requirement`] variant on
2122        // the paired parser surface).
2123        let value: String = String::from("1.2");
2124        let reason: String =
2125            String::from("unexpected end of input while parsing minor version number");
2126        assert_eq!(
2127            VersionError::semver(value.clone(), reason.clone()),
2128            VersionError::Semver(value, reason),
2129            "generated semver ctor over owned-`String` bindings must \
2130             match the pre-lift tuple-literal wrap on the same fixture",
2131        );
2132    }
2133
2134    #[test]
2135    fn parse_semver_error_routes_through_semver_ctor() {
2136        // Fail-before-pass-after routes-through pin: refuses any future
2137        // de-lift of [`CaixaVersion::parse`]'s
2138        // [`semver::Version::parse`] `map_err` arm off the substrate
2139        // primitive. Sweeps three malformed authoring shapes (a bare
2140        // non-numeric, a partial `major.minor` shape, a stray leading
2141        // `v`-prefix that the [`DEFAULT_PUBLISH_TAG_PREFIX`] git-tag
2142        // convention rejects at the version-body slot) through the
2143        // parser and asserts the emitted [`VersionError`] equals the
2144        // ctor-built error verbatim under `PartialEq`, so any future
2145        // swap of the wire-up (an inline `Self::Semver(...)`
2146        // re-inlining, a routing detour through the sibling
2147        // [`VersionError::Requirement`] variant on the paired parser
2148        // surface, a swap of the ordering on the paired arguments)
2149        // trips at caixa-core test time rather than at a downstream
2150        // diagnostic drift on a `feira lint` / operator admission
2151        // callsite.
2152        for bad in ["not-a-version", "1.2", "v0.1.0"] {
2153            let v: CaixaVersion = bad.into();
2154            let err = v
2155                .parse()
2156                .expect_err("malformed versao fixture must fail semver parsing");
2157            let semver_reason = match semver::Version::parse(bad) {
2158                Err(e) => e.to_string(),
2159                Ok(_) => unreachable!(
2160                    "fixture `{bad}` is documented as a `SemVer` \
2161                     rejection but parsed cleanly — the pin's oracle \
2162                     drifted from `semver`'s current shape",
2163                ),
2164            };
2165            assert_eq!(
2166                err,
2167                VersionError::semver(bad, semver_reason),
2168                "CaixaVersion::parse must route its semver `map_err` \
2169                 arm through the lifted VersionError::semver ctor on \
2170                 the same offending value and semver reason",
2171            );
2172        }
2173    }
2174
2175    #[test]
2176    fn default_git_remote_pins_canonical_origin_byte() {
2177        // Bridge-arm pin: [`DEFAULT_GIT_REMOTE`] resolves to the
2178        // canonical `"origin"` byte today, the same remote-handle every
2179        // `git clone <url>` invocation populates by default and every
2180        // peer `feira` writer-side verb (`feira publish`, `feira deploy
2181        // --apply`, `feira app deploy --apply`) names when it invokes
2182        // `git push <remote> <ref>` against the local clone. Pin the
2183        // literal here (peer with the
2184        // [`DEFAULT_PUBLISH_TAG_PREFIX`] / [`crate::DEFAULT_SERVICO_PORT`]
2185        // / [`crate::DEFAULT_NAMESPACE`] / [`crate::DEFAULT_LIBRARY_NAME`]
2186        // / [`crate::DEFAULT_FLUX_SYSTEM_NAMESPACE`] canonical-literal
2187        // pins on the sibling lifted-constant surfaces) so a future
2188        // remote-naming rebrand surfaces here as a coordinated edit-
2189        // point: the sibling [`caixa-feira`]
2190        // `publish_remote_default_pins_lifted_caixa_core_constant`
2191        // pinning test already pins the equality at the clap-default
2192        // axis; this pin closes the second coordinate of the
2193        // triangle by anchoring the lifted constant's current byte
2194        // to the canonical git-default-remote convention's documented
2195        // shape.
2196        assert_eq!(DEFAULT_GIT_REMOTE, "origin");
2197    }
2198
2199    #[test]
2200    fn default_pleme_git_org_pins_canonical_pleme_io_byte() {
2201        // Bridge-arm pin: [`DEFAULT_PLEME_GIT_ORG`] resolves to the
2202        // canonical `"pleme-io"` GitHub-org-handle today, the same org
2203        // name every peer substrate-side default-git-source consumer
2204        // ([`caixa-feira`]'s `feira lock` `resolve_stub` for the
2205        // per-dep `:fonte`-elided `github:<org>/<nome>` fallback,
2206        // [`caixa-flux`]'s `ClusterBundleOpts::for_caixa` constructor
2207        // for the per-caixa `:repositorio`-elided
2208        // `https://github.com/<org>/<nome>` fallback) fills into its
2209        // per-consumer render/resolve compose site. Pin the literal
2210        // here (peer with the [`DEFAULT_PUBLISH_TAG_PREFIX`] /
2211        // [`DEFAULT_GIT_REMOTE`] canonical-literal pins on the sibling
2212        // lifted-constant surfaces) so a future substrate-side git-org
2213        // migration surfaces here as a coordinated edit-point: both
2214        // sibling consumer sites already thread through the same
2215        // `&'static str`, this pin anchors the lifted constant's
2216        // current byte to the canonical substrate-git-org convention's
2217        // documented shape.
2218        assert_eq!(DEFAULT_PLEME_GIT_ORG, "pleme-io");
2219    }
2220
2221    #[test]
2222    fn requirement_ctor_matches_tuple_literal_wrap_on_str_binding() {
2223        // Fail-before-pass-after byte-equality pin: the lifted
2224        // [`VersionError::requirement`] inherent ctor projects a `&str`
2225        // binding pair through the paired `impl Into<String>` bounds
2226        // byte-equal to the pre-lift open-coded
2227        // `VersionError::Requirement(<into-String-expr>, <into-String-expr>)`
2228        // tuple-literal on the same fixture. Same shape the peer
2229        // [`VersionError::semver_ctor_matches_tuple_literal_wrap_on_str_binding`]
2230        // pin carries on the sibling [`VersionError::Semver`] variant of
2231        // the same `(String, String)` two-slot tuple-newtype envelope.
2232        let value: &str = "not-a-req";
2233        let reason: &str = "unexpected character 'n' while parsing major version number";
2234        assert_eq!(
2235            VersionError::requirement(value, reason),
2236            VersionError::Requirement(value.to_string(), reason.to_string()),
2237            "generated requirement ctor over `&str` bindings must match \
2238             the pre-lift tuple-literal wrap on the same fixture",
2239        );
2240    }
2241
2242    #[test]
2243    fn requirement_ctor_matches_tuple_literal_wrap_on_string_binding() {
2244        // Fail-before-pass-after byte-equality pin on the paired owned-
2245        // `String` shape. Peer to the `&str` variant above; refuses any
2246        // future de-lift that inlines a divergent construction on the
2247        // owned-`String` path (a stray `.trim().to_string()` normalization
2248        // on either slot, a swap that routes the ctor through the sibling
2249        // [`VersionError::Semver`] variant on the paired parser surface,
2250        // an argument-ordering swap on the paired slots).
2251        let value: String = String::from("^bogus");
2252        let reason: String = String::from("unexpected character while parsing requirement");
2253        assert_eq!(
2254            VersionError::requirement(value.clone(), reason.clone()),
2255            VersionError::Requirement(value, reason),
2256            "generated requirement ctor over owned-`String` bindings must \
2257             match the pre-lift tuple-literal wrap on the same fixture",
2258        );
2259    }
2260
2261    #[test]
2262    fn parse_requirement_error_routes_through_requirement_ctor() {
2263        // Fail-before-pass-after routes-through pin: refuses any future
2264        // de-lift of [`parse_requirement`]'s
2265        // [`semver::VersionReq::parse`] `map_err` arm off the substrate
2266        // primitive. Sweeps three malformed authoring shapes (a bare
2267        // non-numeric, a stray operator with no version body, a
2268        // caret-prefixed non-numeric that the [`semver::VersionReq`]
2269        // grammar rejects at the operator-body slot) through the parser
2270        // and asserts the emitted [`VersionError`] equals the ctor-built
2271        // error verbatim under `PartialEq`, so any future swap of the
2272        // wire-up (an inline `Self::Requirement(...)` re-inlining, a
2273        // routing detour through the sibling [`VersionError::Semver`]
2274        // variant on the paired parser surface, an argument-ordering
2275        // swap on the paired slots) trips at caixa-core test time rather
2276        // than at a downstream diagnostic drift on a `feira lock` /
2277        // resolver admission callsite. The `"*"` wildcard short-circuit
2278        // is deliberately excluded from the sweep — it returns
2279        // [`semver::VersionReq::STAR`] before reaching the parser arm.
2280        for bad in ["not-a-req", "^", "^bogus"] {
2281            let err = parse_requirement(bad)
2282                .expect_err("malformed requirement fixture must fail parsing");
2283            let semver_reason = match semver::VersionReq::parse(bad) {
2284                Err(e) => e.to_string(),
2285                Ok(_) => unreachable!(
2286                    "fixture `{bad}` is documented as a `VersionReq` \
2287                     rejection but parsed cleanly — the pin's oracle \
2288                     drifted from `semver`'s current shape",
2289                ),
2290            };
2291            assert_eq!(
2292                err,
2293                VersionError::requirement(bad, semver_reason),
2294                "parse_requirement must route its `map_err` arm through \
2295                 the lifted VersionError::requirement ctor on the same \
2296                 offending value and semver reason",
2297            );
2298        }
2299    }
2300
2301    #[test]
2302    fn default_publish_tag_prefix_pins_canonical_v_byte() {
2303        // Bridge-arm pin: [`DEFAULT_PUBLISH_TAG_PREFIX`] resolves to the
2304        // canonical Zig-style `"v"` byte today, the same prefix every
2305        // peer doc-comment on the typed `:versao` surfaces (the
2306        // top-level `:versao` `validate_versao` cascade at
2307        // caixa-core/src/manifest.rs:646, the four sibling per-axis
2308        // `:versao` requirement gates that name the publish-side
2309        // `v<versao>` tag inline in their bodies) cites as the
2310        // canonical convention. Pin the literal here (peer with the
2311        // [`crate::DEFAULT_SERVICO_PORT`] / [`crate::DEFAULT_NAMESPACE`]
2312        // / [`crate::DEFAULT_LIBRARY_NAME`] canonical-literal pins on
2313        // the sibling lifted-constant surfaces) so a future rebrand of
2314        // the constant surfaces here as a coordinated edit-point: both
2315        // sibling pinning tests on the two consumer crates
2316        // ([`caixa-feira`] `publish_prefix_default_pins_lifted_caixa_core_constant`,
2317        // [`caixa-flux`] `cluster_bundle_default_git_tag_uses_lifted_caixa_core_prefix`)
2318        // already pin the equality at the consumer-default axis; this
2319        // pin closes the third coordinate of the triangle by anchoring
2320        // the lifted constant's current byte to the canonical Zig-style
2321        // convention's documented shape.
2322        assert_eq!(DEFAULT_PUBLISH_TAG_PREFIX, "v");
2323    }
2324
2325    #[test]
2326    fn caixa_version_as_ref_str_routes_through_as_str_accessor() {
2327        // Fail-before-pass-after byte-parity pin on the lifted
2328        // `impl AsRef<str> for CaixaVersion` — asserts the standard-
2329        // library trait impl and the substrate-primitive
2330        // [`CaixaVersion::as_str`] `pub const fn` accessor resolve to
2331        // the same `&str` per instance, so any future silent detour
2332        // that routes the impl through a divergent projection (a
2333        // `Cow<'_, str>` intermediate, a stray `.to_lowercase()`
2334        // normalization, a swap onto a per-arm inline `&self.0.as_str()`
2335        // re-inlining, a swap onto a divergent [`String::trim`]
2336        // fold) trips at caixa-core test time under `PartialEq`
2337        // rather than at a downstream `impl AsRef<str>`-bound
2338        // consumer's silent split. Sweeps four authoring shapes (a
2339        // canonical release version, a pre-release build-metadata
2340        // version, the zero-version canonical unset baseline, and
2341        // the empty-string byte the caller-side default-construct
2342        // path composes) so every non-degenerate arm of the wrapped
2343        // `String` storage is covered. Peer of the sibling
2344        // [`caixa_version_as_str_accessor_is_const_fn`] const-eval
2345        // pin on the same [`CaixaVersion::as_str`] primitive — the
2346        // two pins together cover the const-eval axis (the pin above)
2347        // and the trait-projection axis (this pin) of the same
2348        // substrate-primitive scalar accessor.
2349        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2350            let v: CaixaVersion = versao.into();
2351            assert_eq!(
2352                <CaixaVersion as AsRef<str>>::as_ref(&v),
2353                v.as_str(),
2354                "AsRef<str> impl must byte-equal CaixaVersion::as_str \
2355                 on the same instance — divergence signals a silent \
2356                 detour off the substrate-primitive accessor",
2357            );
2358            assert_eq!(
2359                <CaixaVersion as AsRef<str>>::as_ref(&v),
2360                versao,
2361                "AsRef<str> impl must byte-equal the pre-lift wrapped \
2362                 String storage on round-trip through the From<&str> \
2363                 constructor — divergence signals a normalization \
2364                 detour on either the constructor or the accessor",
2365            );
2366        }
2367    }
2368
2369    #[test]
2370    fn caixa_version_as_ref_str_routes_through_display_via_shared_accessor() {
2371        // Fail-before-pass-after byte-parity pin on the three-path
2372        // convergence discipline the substrate primitive now carries
2373        // on the `&str`-projection axis: `<CaixaVersion as
2374        // AsRef<str>>::as_ref(&v)` (the newly lifted impl),
2375        // `format!("{v}")` (the pre-existing [`fmt::Display`] impl),
2376        // and `v.as_str()` (the substrate-primitive `pub const fn`
2377        // accessor both trait impls delegate through) must resolve to
2378        // the same byte-string on every instance. Refuses any future
2379        // divergence between the two trait impls (a stray
2380        // [`fmt::Display::fmt`] rewrite that inlines
2381        // `f.write_str(&self.0)` on the wrapped `String` directly,
2382        // bypassing the shared accessor; a hypothetical `AsRef<str>`
2383        // rewrite that inlines the same `&self.0` field-access) that
2384        // would silently split the two projection paths of the same
2385        // typed newtype. Mirrors the sibling three-path-convergence
2386        // discipline the peer [`RestartStrategy`] typed enum carries
2387        // on its `Display` / `as_str` / `Serialize` triple (aplicacao.rs
2388        // pin `restart_strategy_display_matches_serialized_wire_byte_string`).
2389        for versao in ["0.1.0", "1.2.3-alpha.1", ""] {
2390            let v: CaixaVersion = versao.into();
2391            let via_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
2392            let via_display: String = format!("{v}");
2393            let via_accessor: &str = v.as_str();
2394            assert_eq!(via_as_ref, via_accessor);
2395            assert_eq!(via_display, via_accessor);
2396            assert_eq!(via_as_ref, via_display.as_str());
2397        }
2398    }
2399
2400    #[test]
2401    fn caixa_version_borrow_str_routes_through_as_str_accessor() {
2402        // Fail-before-pass-after byte-parity pin on the lifted
2403        // `impl std::borrow::Borrow<str> for CaixaVersion` — asserts the
2404        // standard-library trait impl and the substrate-primitive
2405        // [`CaixaVersion::as_str`] `pub const fn` accessor resolve to
2406        // the same `&str` per instance, so any future silent detour
2407        // that routes the impl through a divergent projection (a
2408        // `Cow<'_, str>` intermediate, a stray `.to_lowercase()`
2409        // normalization, a swap onto a per-arm inline `&self.0.as_str()`
2410        // re-inlining that bypasses the shared accessor) trips at
2411        // caixa-core test time under `PartialEq` rather than at a
2412        // downstream `Borrow<str>`-bound collection API's silent
2413        // hash-mismatch on the load-bearing HashMap-key axis. Peer of
2414        // the sibling
2415        // [`caixa_version_as_ref_str_routes_through_as_str_accessor`]
2416        // byte-parity pin on the paired [`AsRef<str>`] impl — both cover
2417        // the borrow-projection axis of the same substrate primitive.
2418        use std::borrow::Borrow;
2419        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2420            let v: CaixaVersion = versao.into();
2421            assert_eq!(
2422                <CaixaVersion as Borrow<str>>::borrow(&v),
2423                v.as_str(),
2424                "Borrow<str> impl must byte-equal CaixaVersion::as_str \
2425                 on the same instance — divergence signals a silent \
2426                 detour off the substrate-primitive accessor",
2427            );
2428            assert_eq!(
2429                <CaixaVersion as Borrow<str>>::borrow(&v),
2430                versao,
2431                "Borrow<str> impl must byte-equal the pre-lift wrapped \
2432                 String storage on round-trip through the From<&str> \
2433                 constructor",
2434            );
2435        }
2436    }
2437
2438    #[test]
2439    fn caixa_version_borrow_str_and_as_ref_str_agree_on_every_shape() {
2440        // Fail-before-pass-after cross-axis partition pin on the two
2441        // trait impls on the same borrow-projection axis: the lifted
2442        // [`std::borrow::Borrow<str>`] impl (this commit) and the paired
2443        // [`AsRef<str>`] impl (a086 lift) must resolve to the same `&str`
2444        // per instance, both routing through the shared substrate-
2445        // primitive [`CaixaVersion::as_str`] accessor. Refuses any future
2446        // silent split between the two trait impls (a stray
2447        // [`AsRef::as_ref`] rewrite that inlines `&self.0.as_str()` on
2448        // the wrapped [`String`] directly, bypassing the shared
2449        // accessor; a hypothetical [`Borrow::borrow`] rewrite that
2450        // inlines the same `&self.0` field-access) that would silently
2451        // split the two projection paths of the same typed newtype and
2452        // break the [`std::borrow::Borrow`] safety contract's
2453        // "hash-agrees on the borrowed view" invariant the collection
2454        // APIs rely on. Mirrors the sibling three-path convergence
2455        // discipline the peer
2456        // [`caixa_version_as_ref_str_routes_through_display_via_shared_accessor`]
2457        // pin carries on the `AsRef<str>` / `Display` / `as_str` triple.
2458        use std::borrow::Borrow;
2459        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2460            let v: CaixaVersion = versao.into();
2461            let via_borrow: &str = <CaixaVersion as Borrow<str>>::borrow(&v);
2462            let via_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
2463            let via_accessor: &str = v.as_str();
2464            assert_eq!(via_borrow, via_accessor);
2465            assert_eq!(via_as_ref, via_accessor);
2466            assert_eq!(via_borrow, via_as_ref);
2467        }
2468    }
2469
2470    #[test]
2471    fn caixa_version_borrow_str_enables_hashmap_lookup_by_borrowed_key() {
2472        // Fail-before-pass-after contract-witness pin on the
2473        // [`std::borrow::Borrow<str>`] safety contract: a
2474        // [`std::collections::HashMap`] keyed by owned [`CaixaVersion`]
2475        // must resolve `.get::<str>("<versao>")` probes through the
2476        // borrowed `&str` view of a stored key to the same slot, and
2477        // (`String::hash` calls `str::hash` on bytes, and the
2478        // [`CaixaVersion`] derived [`Hash`] impl hashes the wrapped
2479        // [`String`] field) the borrowed and owned hash must agree on
2480        // every fixture. Refuses any future silent regression that would
2481        // break the hash-agrees invariant (a
2482        // [`Hash for CaixaVersion`] hand-written impl that diverges from
2483        // the derived shape, a [`Borrow<str>::borrow`] rewrite that
2484        // routes through a normalization detour, an `Eq` hand-written
2485        // impl that diverges from field-wise equality) —
2486        // [`HashMap::get<Q>`] would return [`None`] on a key that
2487        // structurally lives in the map, which is the exact silent
2488        // failure the [`std::borrow::Borrow`] documented safety contract
2489        // rules out. The load-bearing use-case this impl was added for:
2490        // per-`:versao` collection APIs must be probed by borrowed
2491        // `&str` without a per-probe [`CaixaVersion::from(&str)`]
2492        // allocation.
2493        use std::collections::HashMap;
2494        let mut map: HashMap<CaixaVersion, u32> = HashMap::new();
2495        for (i, versao) in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""].iter().enumerate() {
2496            let key: CaixaVersion = (*versao).into();
2497            map.insert(key, u32::try_from(i).unwrap());
2498        }
2499        for (i, versao) in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""].iter().enumerate() {
2500            let hit = map.get(*versao).unwrap_or_else(|| {
2501                panic!(
2502                    "HashMap<CaixaVersion, _>::get(&str) must reach the \
2503                     slot inserted under CaixaVersion::from({versao:?}) \
2504                     through the Borrow<str> bound — a miss signals the \
2505                     borrowed-vs-owned hash-agrees invariant broke",
2506                )
2507            });
2508            assert_eq!(*hit, u32::try_from(i).unwrap());
2509        }
2510        assert!(
2511            !map.contains_key("does-not-exist"),
2512            "HashMap<CaixaVersion, _>::contains_key(&str) on an absent \
2513             key must return false, not accidentally hash-collide onto \
2514             a stored slot — the miss path must respect the same \
2515             invariant as the hit path",
2516        );
2517    }
2518
2519    #[test]
2520    fn caixa_version_from_into_owned_string_returns_wrapped_body() {
2521        // Fail-before-pass-after byte-parity pin on the lifted
2522        // `impl From<CaixaVersion> for String` — asserts the owned-input
2523        // reverse-projection routes the wrapper's own heap allocation
2524        // through verbatim (no re-copy, no normalization detour) so
2525        // `String::from(v)` returns the same bytes `v.as_str()`
2526        // borrows. Refuses any future silent detour that would swap
2527        // the move on `v.0` for an allocating `.as_str().to_owned()` /
2528        // `.to_string()` cascade (the pre-lift compose shape), a stray
2529        // `.trim().to_owned()` normalization, or a routing through the
2530        // sibling [`fmt::Display`] emitter that would introduce a
2531        // formatter round-trip.
2532        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2533            let v: CaixaVersion = versao.into();
2534            let expected = v.as_str().to_owned();
2535            let owned: String = String::from(v);
2536            assert_eq!(
2537                owned, expected,
2538                "String::from(v) must return the wrapper's own bytes verbatim",
2539            );
2540            assert_eq!(
2541                owned, versao,
2542                "String::from(v) must round-trip byte-equal through the From<&str> constructor",
2543            );
2544        }
2545    }
2546
2547    #[test]
2548    fn caixa_version_from_into_owned_string_and_as_str_agree_on_every_shape() {
2549        // Fail-before-pass-after cross-axis partition pin: the owned-
2550        // input [`From<CaixaVersion> for String`] reverse projection
2551        // and the borrowed [`AsRef<str>`] projection resolve to the
2552        // same bytes on every instance, and the paired forward
2553        // [`From<String> for CaixaVersion`] constructor closes the
2554        // `Self → String → Self` round-trip by construction. Refuses
2555        // any future silent split between the owned-move reverse axis
2556        // and the borrowed-clone AsRef axis (a stray normalization on
2557        // one path only) that would let `String::from(v)` and
2558        // `v.as_ref::<str>()` diverge on the same instance.
2559        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2560            let v: CaixaVersion = versao.into();
2561            let via_as_ref: String = <CaixaVersion as AsRef<str>>::as_ref(&v).to_owned();
2562            let via_to_string: String = v.to_string();
2563            let via_from: String = String::from(v.clone());
2564            assert_eq!(via_from, via_as_ref);
2565            assert_eq!(via_from, via_to_string);
2566            let round_trip: CaixaVersion = via_from.clone().into();
2567            assert_eq!(round_trip, v);
2568        }
2569    }
2570
2571    #[test]
2572    fn caixa_version_from_borrowed_into_owned_string_routes_through_as_str_accessor() {
2573        // Fail-before-pass-after byte-parity pin on the lifted
2574        // `impl From<&CaixaVersion> for String` — asserts the
2575        // borrowed-input reverse projection allocates a fresh
2576        // [`String`] whose bytes byte-equal the substrate-primitive
2577        // [`CaixaVersion::as_str`] accessor on the same instance,
2578        // preserving the source [`CaixaVersion`] intact (no move-out).
2579        // Refuses any future silent detour that would route the impl
2580        // through a divergent projection (a stray normalization step,
2581        // a swap onto the sibling [`fmt::Display`]-routed
2582        // [`ToString::to_string`] surface, a re-inlining that
2583        // dereferences `&self.0` outside the shared accessor).
2584        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2585            let v: CaixaVersion = versao.into();
2586            let via_borrowed: String = String::from(&v);
2587            assert_eq!(
2588                via_borrowed,
2589                v.as_str(),
2590                "String::from(&v) must byte-equal CaixaVersion::as_str",
2591            );
2592            // The borrowed-input impl must not move out of the source.
2593            assert_eq!(
2594                v.as_str(),
2595                versao,
2596                "source CaixaVersion must survive borrowed-input projection"
2597            );
2598        }
2599    }
2600
2601    #[test]
2602    fn caixa_version_from_owned_and_borrowed_into_string_agree_on_every_shape() {
2603        // Fail-before-pass-after cross-axis partition pin: the paired
2604        // owned-input [`From<CaixaVersion> for String`] and
2605        // borrowed-input [`From<&CaixaVersion> for String`] impls
2606        // resolve to the same bytes on every instance, closing the
2607        // "owned-input move vs. borrowed-input clone" bifurcation on
2608        // the same wrapped body. Refuses any future silent split
2609        // between the two corners (a normalization on one path only, a
2610        // divergent routing that would let `String::from(v.clone())`
2611        // and `String::from(&v)` disagree on the same body).
2612        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2613            let v: CaixaVersion = versao.into();
2614            let via_borrowed: String = String::from(&v);
2615            let via_owned: String = String::from(v.clone());
2616            assert_eq!(via_owned, via_borrowed);
2617            assert_eq!(via_borrowed, versao);
2618        }
2619    }
2620
2621    #[test]
2622    fn caixa_version_from_into_owned_cow_str_returns_owned_wrapped_body() {
2623        // Fail-before-pass-after byte-parity + [`Cow::Owned`]-arm pin
2624        // on the lifted `impl From<CaixaVersion> for
2625        // std::borrow::Cow<'static, str>` — asserts the owned-input
2626        // reverse projection routes the wrapper's own heap allocation
2627        // through `Cow::Owned(v.0)` verbatim (no re-copy, no
2628        // normalization detour, no `Cow::Borrowed` misclassification
2629        // that would demand a `&'static str` the runtime wrapper cannot
2630        // carry), so the emitted [`Cow`] byte-equals the substrate-
2631        // primitive [`CaixaVersion::as_str`] accessor on the same
2632        // instance and round-trips byte-equal through the paired
2633        // forward [`From<String> for CaixaVersion`] constructor.
2634        // Refuses any future silent detour: a swap of the move on
2635        // `v.0` for an allocating `.as_str().to_owned()` cascade (the
2636        // pre-lift compose shape would double-allocate a fresh
2637        // intermediary [`String`] on the way to the same
2638        // [`Cow::Owned`] arm), a stray `.trim().to_owned()`
2639        // normalization, or a mis-routing through
2640        // [`Cow::Borrowed`] on a non-`'static` byte-string that would
2641        // not type-check.
2642        use std::borrow::Cow;
2643        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2644            let v: CaixaVersion = versao.into();
2645            let expected = v.as_str().to_owned();
2646            let cow: Cow<'static, str> = Cow::from(v.clone());
2647            assert!(
2648                matches!(cow, Cow::Owned(_)),
2649                "From<CaixaVersion> for Cow<'static, str> must land on \
2650                 the Cow::Owned arm — a runtime String wrapper cannot \
2651                 promise the 'static lifetime the Cow::Borrowed arm \
2652                 requires",
2653            );
2654            assert_eq!(
2655                cow.as_ref(),
2656                expected,
2657                "Cow::from(v) must return the wrapper's own bytes verbatim",
2658            );
2659            let round_trip: CaixaVersion = cow.into_owned().into();
2660            assert_eq!(
2661                round_trip, v,
2662                "Cow::from(v).into_owned() must round-trip byte-equal \
2663                 through the From<String> constructor",
2664            );
2665        }
2666    }
2667
2668    #[test]
2669    fn caixa_version_from_into_owned_cow_str_and_string_agree_on_every_shape() {
2670        // Fail-before-pass-after cross-axis partition pin: the owned-
2671        // input [`From<CaixaVersion> for Cow<'static, str>`] reverse
2672        // projection and the paired owned-input
2673        // [`From<CaixaVersion> for String`] reverse projection resolve
2674        // to the same bytes on every instance, and both agree with the
2675        // borrowed [`AsRef<str>`] surface on the same wrapped body.
2676        // Refuses any future silent split between the two owned-input
2677        // reverse-projection axes (a stray normalization on one path
2678        // only, a divergent routing that would let
2679        // `Cow::from(v.clone())` and `String::from(v.clone())` disagree
2680        // on the same body) that would silently split the same-shape
2681        // owned-move discipline across the two reverse-projection
2682        // targets.
2683        use std::borrow::Cow;
2684        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2685            let v: CaixaVersion = versao.into();
2686            let via_string: String = String::from(v.clone());
2687            let via_cow: Cow<'static, str> = Cow::from(v.clone());
2688            let via_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
2689            assert_eq!(via_cow.as_ref(), via_string.as_str());
2690            assert_eq!(via_cow.as_ref(), via_as_ref);
2691            assert_eq!(via_cow.as_ref(), versao);
2692        }
2693    }
2694
2695    #[test]
2696    fn caixa_version_from_borrowed_into_owned_cow_str_routes_through_as_str_accessor() {
2697        // Fail-before-pass-after byte-parity + [`Cow::Owned`]-arm pin
2698        // on the lifted `impl From<&CaixaVersion> for
2699        // std::borrow::Cow<'static, str>` — asserts the borrowed-input
2700        // reverse projection allocates a fresh [`Cow::Owned`] whose
2701        // bytes byte-equal the substrate-primitive
2702        // [`CaixaVersion::as_str`] accessor on the same instance,
2703        // preserving the source [`CaixaVersion`] intact (no move-out).
2704        // Refuses any future silent detour that would route the impl
2705        // through a divergent projection (a stray normalization step,
2706        // a mis-routing onto [`Cow::Borrowed`] on a non-`'static`
2707        // byte-string that would not type-check, a re-inlining that
2708        // dereferences `&self.0` outside the shared accessor).
2709        use std::borrow::Cow;
2710        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2711            let v: CaixaVersion = versao.into();
2712            let via_borrowed: Cow<'static, str> = Cow::from(&v);
2713            assert!(
2714                matches!(via_borrowed, Cow::Owned(_)),
2715                "From<&CaixaVersion> for Cow<'static, str> must land on \
2716                 the Cow::Owned arm — a runtime String wrapper cannot \
2717                 promise the 'static lifetime the Cow::Borrowed arm \
2718                 requires",
2719            );
2720            assert_eq!(
2721                via_borrowed.as_ref(),
2722                v.as_str(),
2723                "Cow::from(&v) must byte-equal CaixaVersion::as_str",
2724            );
2725            // The borrowed-input impl must not move out of the source.
2726            assert_eq!(
2727                v.as_str(),
2728                versao,
2729                "source CaixaVersion must survive borrowed-input projection",
2730            );
2731        }
2732    }
2733
2734    #[test]
2735    fn caixa_version_from_owned_and_borrowed_into_cow_str_agree_on_every_shape() {
2736        // Fail-before-pass-after cross-axis partition pin: the paired
2737        // owned-input [`From<CaixaVersion> for Cow<'static, str>`] and
2738        // borrowed-input [`From<&CaixaVersion> for Cow<'static, str>`]
2739        // impls resolve to the same bytes on every instance, closing
2740        // the "owned-input move vs. borrowed-input clone" bifurcation
2741        // on the same wrapped body through the [`Cow<'static, str>`]
2742        // axis. Refuses any future silent split between the two
2743        // corners (a normalization on one path only, a divergent
2744        // routing that would let `Cow::from(v.clone())` and
2745        // `Cow::from(&v)` disagree on the same body). Both corners
2746        // must land on [`Cow::Owned`] — the runtime wrapper's storage
2747        // rules out the borrowed arm on both input shapes alike.
2748        use std::borrow::Cow;
2749        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2750            let v: CaixaVersion = versao.into();
2751            let via_borrowed: Cow<'static, str> = Cow::from(&v);
2752            let via_owned: Cow<'static, str> = Cow::from(v.clone());
2753            assert!(matches!(via_borrowed, Cow::Owned(_)));
2754            assert!(matches!(via_owned, Cow::Owned(_)));
2755            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
2756            assert_eq!(via_borrowed.as_ref(), versao);
2757        }
2758    }
2759
2760    #[test]
2761    fn caixa_version_from_into_owned_box_str_returns_wrapped_body() {
2762        // Fail-before-pass-after byte-parity pin on the lifted
2763        // `impl From<CaixaVersion> for Box<str>` — asserts the owned-
2764        // input reverse projection routes the wrapper's own heap
2765        // allocation through [`String::into_boxed_str`] verbatim (no
2766        // re-copy of the underlying bytes on the fixed-capacity path;
2767        // `String::into_boxed_str` reuses the same `Vec<u8>` buffer
2768        // when length matches capacity), so `Box::<str>::from(v)`
2769        // returns the same bytes `v.as_str()` borrows and round-trips
2770        // byte-equal through the paired forward
2771        // [`From<String> for CaixaVersion`] constructor closing the
2772        // two-way `Self → Box<str> → Self` cycle by construction.
2773        // Refuses any future silent detour that would swap
2774        // `v.0.into_boxed_str()` for an allocating
2775        // `.as_str().to_owned().into_boxed_str()` cascade (the pre-lift
2776        // compose shape would double-allocate a fresh intermediary
2777        // [`String`] on the way to the same [`Box<str>`] slot), a
2778        // stray `.trim().to_owned().into_boxed_str()` normalization,
2779        // or a routing through the sibling [`fmt::Display`] emitter
2780        // that would introduce a formatter round-trip.
2781        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2782            let v: CaixaVersion = versao.into();
2783            let expected = v.as_str().to_owned();
2784            let boxed: Box<str> = Box::<str>::from(v.clone());
2785            assert_eq!(
2786                boxed.as_ref(),
2787                expected.as_str(),
2788                "Box::<str>::from(v) must return the wrapper's own bytes verbatim",
2789            );
2790            let round_trip: CaixaVersion = boxed.into_string().into();
2791            assert_eq!(
2792                round_trip, v,
2793                "Box::<str>::from(v).into_string() must round-trip byte-equal \
2794                 through the From<String> constructor",
2795            );
2796        }
2797    }
2798
2799    #[test]
2800    fn caixa_version_from_into_owned_box_str_and_string_agree_on_every_shape() {
2801        // Fail-before-pass-after cross-axis partition pin: the owned-
2802        // input [`From<CaixaVersion> for Box<str>`] reverse projection
2803        // and the paired owned-input [`From<CaixaVersion> for String`]
2804        // and [`From<CaixaVersion> for Cow<'static, str>`] reverse
2805        // projections resolve to the same bytes on every instance, and
2806        // all three agree with the borrowed [`AsRef<str>`] surface on
2807        // the same wrapped body. Refuses any future silent split
2808        // between the three owned-input reverse-projection axes (a
2809        // stray normalization on one path only, a divergent routing
2810        // that would let `Box::<str>::from(v.clone())`,
2811        // `String::from(v.clone())`, and `Cow::from(v.clone())`
2812        // disagree on the same body) that would silently split the
2813        // same-shape owned-move discipline across the three
2814        // reverse-projection targets.
2815        use std::borrow::Cow;
2816        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2817            let v: CaixaVersion = versao.into();
2818            let via_string: String = String::from(v.clone());
2819            let via_cow: Cow<'static, str> = Cow::from(v.clone());
2820            let via_box: Box<str> = Box::<str>::from(v.clone());
2821            let via_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
2822            assert_eq!(via_box.as_ref(), via_string.as_str());
2823            assert_eq!(via_box.as_ref(), via_cow.as_ref());
2824            assert_eq!(via_box.as_ref(), via_as_ref);
2825            assert_eq!(via_box.as_ref(), versao);
2826        }
2827    }
2828
2829    #[test]
2830    fn caixa_version_from_borrowed_into_owned_box_str_routes_through_as_str_accessor() {
2831        // Fail-before-pass-after byte-parity pin on the lifted
2832        // `impl From<&CaixaVersion> for Box<str>` — asserts the
2833        // borrowed-input reverse projection allocates a fresh
2834        // [`Box<str>`] whose bytes byte-equal the substrate-primitive
2835        // [`CaixaVersion::as_str`] accessor on the same instance,
2836        // preserving the source [`CaixaVersion`] intact (no move-out).
2837        // Refuses any future silent detour that would route the impl
2838        // through a divergent projection (a stray normalization step,
2839        // a swap onto the sibling [`fmt::Display`]-routed
2840        // [`ToString::to_string`] surface followed by
2841        // `.into_boxed_str()`, a re-inlining that dereferences
2842        // `&self.0` outside the shared accessor).
2843        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2844            let v: CaixaVersion = versao.into();
2845            let via_borrowed: Box<str> = Box::<str>::from(&v);
2846            assert_eq!(
2847                via_borrowed.as_ref(),
2848                v.as_str(),
2849                "Box::<str>::from(&v) must byte-equal CaixaVersion::as_str",
2850            );
2851            // The borrowed-input impl must not move out of the source.
2852            assert_eq!(
2853                v.as_str(),
2854                versao,
2855                "source CaixaVersion must survive borrowed-input projection",
2856            );
2857        }
2858    }
2859
2860    #[test]
2861    fn caixa_version_from_owned_and_borrowed_into_box_str_agree_on_every_shape() {
2862        // Fail-before-pass-after cross-corner partition pin: the paired
2863        // owned-input [`From<CaixaVersion> for Box<str>`] and
2864        // borrowed-input [`From<&CaixaVersion> for Box<str>`] impls
2865        // resolve to the same bytes on every instance, closing the
2866        // "owned-input move vs. borrowed-input clone" bifurcation on
2867        // the same wrapped body through the [`Box<str>`] axis. Refuses
2868        // any future silent split between the two corners (a
2869        // normalization on one path only, a divergent routing that
2870        // would let `Box::<str>::from(v.clone())` and
2871        // `Box::<str>::from(&v)` disagree on the same body).
2872        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2873            let v: CaixaVersion = versao.into();
2874            let via_borrowed: Box<str> = Box::<str>::from(&v);
2875            let via_owned: Box<str> = Box::<str>::from(v.clone());
2876            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
2877            assert_eq!(via_borrowed.as_ref(), versao);
2878        }
2879    }
2880
2881    #[test]
2882    fn caixa_version_from_into_owned_arc_str_returns_wrapped_body() {
2883        // Fail-before-pass-after byte-parity pin on the lifted
2884        // `impl From<CaixaVersion> for std::sync::Arc<str>` — asserts
2885        // the owned-input reverse projection routes the wrapper's own
2886        // [`String`] body through [`std::sync::Arc::<str>::from`]
2887        // verbatim (one heap allocation of the atomically-refcounted
2888        // slab, no intermediary [`String`] or [`Box<str>`] on the
2889        // owned-input path), so `Arc::<str>::from(v)` returns the same
2890        // bytes `v.as_str()` borrows and round-trips byte-equal through
2891        // the paired forward [`From<String> for CaixaVersion`]
2892        // constructor closing the two-way `Self → Arc<str> → Self`
2893        // cycle by construction. Refuses any future silent detour that
2894        // would swap `Arc::<str>::from(v.0)` for an allocating
2895        // `.as_str().to_owned().into()` cascade (the pre-lift compose
2896        // shape would double-allocate a fresh intermediary [`String`]
2897        // on the way to the same [`Arc<str>`] slot), a stray
2898        // `.trim().to_owned().into()` normalization, or a routing
2899        // through the sibling [`fmt::Display`] emitter that would
2900        // introduce a formatter round-trip.
2901        use std::sync::Arc;
2902        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2903            let v: CaixaVersion = versao.into();
2904            let expected = v.as_str().to_owned();
2905            let arced: Arc<str> = Arc::<str>::from(v.clone());
2906            assert_eq!(
2907                arced.as_ref(),
2908                expected.as_str(),
2909                "Arc::<str>::from(v) must return the wrapper's own bytes verbatim",
2910            );
2911            let round_trip: CaixaVersion = arced.as_ref().to_owned().into();
2912            assert_eq!(
2913                round_trip, v,
2914                "Arc::<str>::from(v) must round-trip byte-equal through \
2915                 the From<String> constructor",
2916            );
2917        }
2918    }
2919
2920    #[test]
2921    fn caixa_version_from_into_owned_arc_str_and_string_agree_on_every_shape() {
2922        // Fail-before-pass-after cross-axis partition pin: the owned-
2923        // input [`From<CaixaVersion> for std::sync::Arc<str>`] reverse
2924        // projection and the paired owned-input
2925        // [`From<CaixaVersion> for String`],
2926        // [`From<CaixaVersion> for Cow<'static, str>`], and
2927        // [`From<CaixaVersion> for Box<str>`] reverse projections
2928        // resolve to the same bytes on every instance, and all four
2929        // agree with the borrowed [`AsRef<str>`] surface on the same
2930        // wrapped body. Refuses any future silent split between the
2931        // four owned-input reverse-projection axes (a stray
2932        // normalization on one path only, a divergent routing that
2933        // would let `Arc::<str>::from(v.clone())`,
2934        // `Box::<str>::from(v.clone())`, `String::from(v.clone())`,
2935        // and `Cow::from(v.clone())` disagree on the same body) that
2936        // would silently split the same-shape owned-move discipline
2937        // across the four reverse-projection targets.
2938        use std::borrow::Cow;
2939        use std::sync::Arc;
2940        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2941            let v: CaixaVersion = versao.into();
2942            let via_string: String = String::from(v.clone());
2943            let via_cow: Cow<'static, str> = Cow::from(v.clone());
2944            let via_box: Box<str> = Box::<str>::from(v.clone());
2945            let via_arc: Arc<str> = Arc::<str>::from(v.clone());
2946            let via_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
2947            assert_eq!(via_arc.as_ref(), via_string.as_str());
2948            assert_eq!(via_arc.as_ref(), via_cow.as_ref());
2949            assert_eq!(via_arc.as_ref(), via_box.as_ref());
2950            assert_eq!(via_arc.as_ref(), via_as_ref);
2951            assert_eq!(via_arc.as_ref(), versao);
2952        }
2953    }
2954
2955    #[test]
2956    fn caixa_version_from_borrowed_into_owned_arc_str_routes_through_as_str_accessor() {
2957        // Fail-before-pass-after byte-parity pin on the lifted
2958        // `impl From<&CaixaVersion> for std::sync::Arc<str>` — asserts
2959        // the borrowed-input reverse projection allocates a fresh
2960        // [`std::sync::Arc<str>`] whose bytes byte-equal the
2961        // substrate-primitive [`CaixaVersion::as_str`] accessor on the
2962        // same instance, preserving the source [`CaixaVersion`] intact
2963        // (no move-out). Refuses any future silent detour that would
2964        // route the impl through a divergent projection (a stray
2965        // normalization step, a swap onto the sibling [`fmt::Display`]-
2966        // routed [`ToString::to_string`] surface followed by
2967        // `.into()`, a re-inlining that dereferences `&self.0` outside
2968        // the shared accessor).
2969        use std::sync::Arc;
2970        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
2971            let v: CaixaVersion = versao.into();
2972            let via_borrowed: Arc<str> = Arc::<str>::from(&v);
2973            assert_eq!(
2974                via_borrowed.as_ref(),
2975                v.as_str(),
2976                "Arc::<str>::from(&v) must byte-equal CaixaVersion::as_str",
2977            );
2978            // The borrowed-input impl must not move out of the source.
2979            assert_eq!(
2980                v.as_str(),
2981                versao,
2982                "source CaixaVersion must survive borrowed-input projection",
2983            );
2984        }
2985    }
2986
2987    #[test]
2988    fn caixa_version_from_owned_and_borrowed_into_arc_str_agree_on_every_shape() {
2989        // Fail-before-pass-after cross-corner partition pin: the paired
2990        // owned-input [`From<CaixaVersion> for std::sync::Arc<str>`]
2991        // and borrowed-input [`From<&CaixaVersion> for std::sync::Arc<str>`]
2992        // impls resolve to the same bytes on every instance, closing
2993        // the "owned-input move vs. borrowed-input clone" bifurcation
2994        // on the same wrapped body through the [`std::sync::Arc<str>`]
2995        // axis. Refuses any future silent split between the two
2996        // corners (a normalization on one path only, a divergent
2997        // routing that would let `Arc::<str>::from(v.clone())` and
2998        // `Arc::<str>::from(&v)` disagree on the same body).
2999        use std::sync::Arc;
3000        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
3001            let v: CaixaVersion = versao.into();
3002            let via_borrowed: Arc<str> = Arc::<str>::from(&v);
3003            let via_owned: Arc<str> = Arc::<str>::from(v.clone());
3004            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
3005            assert_eq!(via_borrowed.as_ref(), versao);
3006        }
3007    }
3008
3009    #[test]
3010    fn caixa_version_from_into_owned_rc_str_returns_wrapped_body() {
3011        // Fail-before-pass-after byte-parity pin on the lifted
3012        // `impl From<CaixaVersion> for std::rc::Rc<str>` — asserts the
3013        // owned-input reverse projection routes the wrapper's own
3014        // [`String`] body through [`std::rc::Rc::<str>::from`] verbatim
3015        // (one heap allocation of the single-threaded-refcounted slab, no
3016        // intermediary [`String`] or [`Box<str>`] on the owned-input
3017        // path), so `Rc::<str>::from(v)` returns the same bytes
3018        // `v.as_str()` borrows and round-trips byte-equal through the
3019        // paired forward [`From<String> for CaixaVersion`] constructor
3020        // closing the two-way `Self → Rc<str> → Self` cycle by
3021        // construction. Refuses any future silent detour that would swap
3022        // `Rc::<str>::from(v.0)` for an allocating
3023        // `.as_str().to_owned().into()` cascade (the pre-lift compose
3024        // shape would double-allocate a fresh intermediary [`String`] on
3025        // the way to the same [`Rc<str>`] slot), a stray
3026        // `.trim().to_owned().into()` normalization, or a routing through
3027        // the sibling [`fmt::Display`] emitter that would introduce a
3028        // formatter round-trip.
3029        use std::rc::Rc;
3030        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
3031            let v: CaixaVersion = versao.into();
3032            let expected = v.as_str().to_owned();
3033            let rced: Rc<str> = Rc::<str>::from(v.clone());
3034            assert_eq!(
3035                rced.as_ref(),
3036                expected.as_str(),
3037                "Rc::<str>::from(v) must return the wrapper's own bytes verbatim",
3038            );
3039            let round_trip: CaixaVersion = rced.as_ref().to_owned().into();
3040            assert_eq!(
3041                round_trip, v,
3042                "Rc::<str>::from(v) must round-trip byte-equal through \
3043                 the From<String> constructor",
3044            );
3045        }
3046    }
3047
3048    #[test]
3049    fn caixa_version_from_into_owned_rc_str_and_arc_str_agree_on_every_shape() {
3050        // Fail-before-pass-after cross-axis partition pin: the owned-
3051        // input [`From<CaixaVersion> for std::rc::Rc<str>`] reverse
3052        // projection and the paired owned-input
3053        // [`From<CaixaVersion> for String`],
3054        // [`From<CaixaVersion> for Cow<'static, str>`],
3055        // [`From<CaixaVersion> for Box<str>`], and
3056        // [`From<CaixaVersion> for std::sync::Arc<str>`] reverse
3057        // projections resolve to the same bytes on every instance, and
3058        // all five agree with the borrowed [`AsRef<str>`] surface on the
3059        // same wrapped body. Refuses any future silent split between the
3060        // five owned-input reverse-projection axes (a stray normalization
3061        // on one path only, a divergent routing that would let
3062        // `Rc::<str>::from(v.clone())`, `Arc::<str>::from(v.clone())`,
3063        // `Box::<str>::from(v.clone())`, `String::from(v.clone())`, and
3064        // `Cow::from(v.clone())` disagree on the same body) that would
3065        // silently split the same-shape owned-move discipline across the
3066        // five reverse-projection targets.
3067        use std::borrow::Cow;
3068        use std::rc::Rc;
3069        use std::sync::Arc;
3070        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
3071            let v: CaixaVersion = versao.into();
3072            let owned_string: String = String::from(v.clone());
3073            let owned_cow: Cow<'static, str> = Cow::from(v.clone());
3074            let owned_box: Box<str> = Box::<str>::from(v.clone());
3075            let atomic_handle: Arc<str> = Arc::<str>::from(v.clone());
3076            let single_handle: Rc<str> = Rc::<str>::from(v.clone());
3077            let borrowed_as_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
3078            assert_eq!(single_handle.as_ref(), owned_string.as_str());
3079            assert_eq!(single_handle.as_ref(), owned_cow.as_ref());
3080            assert_eq!(single_handle.as_ref(), owned_box.as_ref());
3081            assert_eq!(single_handle.as_ref(), atomic_handle.as_ref());
3082            assert_eq!(single_handle.as_ref(), borrowed_as_ref);
3083            assert_eq!(single_handle.as_ref(), versao);
3084        }
3085    }
3086
3087    #[test]
3088    fn caixa_version_from_borrowed_into_owned_rc_str_routes_through_as_str_accessor() {
3089        // Fail-before-pass-after byte-parity pin on the lifted
3090        // `impl From<&CaixaVersion> for std::rc::Rc<str>` — asserts the
3091        // borrowed-input reverse projection allocates a fresh
3092        // [`std::rc::Rc<str>`] whose bytes byte-equal the substrate-
3093        // primitive [`CaixaVersion::as_str`] accessor on the same
3094        // instance, preserving the source [`CaixaVersion`] intact (no
3095        // move-out). Refuses any future silent detour that would route
3096        // the impl through a divergent projection (a stray normalization
3097        // step, a swap onto the sibling [`fmt::Display`]-routed
3098        // [`ToString::to_string`] surface followed by `.into()`, a
3099        // re-inlining that dereferences `&self.0` outside the shared
3100        // accessor).
3101        use std::rc::Rc;
3102        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
3103            let v: CaixaVersion = versao.into();
3104            let via_borrowed: Rc<str> = Rc::<str>::from(&v);
3105            assert_eq!(
3106                via_borrowed.as_ref(),
3107                v.as_str(),
3108                "Rc::<str>::from(&v) must byte-equal CaixaVersion::as_str",
3109            );
3110            // The borrowed-input impl must not move out of the source.
3111            assert_eq!(
3112                v.as_str(),
3113                versao,
3114                "source CaixaVersion must survive borrowed-input projection",
3115            );
3116        }
3117    }
3118
3119    #[test]
3120    fn caixa_version_from_owned_and_borrowed_into_rc_str_agree_on_every_shape() {
3121        // Fail-before-pass-after cross-corner partition pin: the paired
3122        // owned-input [`From<CaixaVersion> for std::rc::Rc<str>`] and
3123        // borrowed-input [`From<&CaixaVersion> for std::rc::Rc<str>`]
3124        // impls resolve to the same bytes on every instance, closing the
3125        // "owned-input move vs. borrowed-input clone" bifurcation on the
3126        // same wrapped body through the [`std::rc::Rc<str>`] axis.
3127        // Refuses any future silent split between the two corners (a
3128        // normalization on one path only, a divergent routing that would
3129        // let `Rc::<str>::from(v.clone())` and `Rc::<str>::from(&v)`
3130        // disagree on the same body).
3131        use std::rc::Rc;
3132        for versao in ["0.1.0", "1.2.3-alpha.1", "0.0.0", ""] {
3133            let v: CaixaVersion = versao.into();
3134            let via_borrowed: Rc<str> = Rc::<str>::from(&v);
3135            let via_owned: Rc<str> = Rc::<str>::from(v.clone());
3136            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
3137            assert_eq!(via_borrowed.as_ref(), versao);
3138        }
3139    }
3140
3141    #[test]
3142    fn caixa_version_from_str_routes_through_from_str_reference_impl() {
3143        // Fail-before-pass-after byte-parity pin on the lifted
3144        // `impl std::str::FromStr for CaixaVersion` — asserts the
3145        // stdlib parse-set entry point delegates byte-for-byte through
3146        // the paired borrowed-input `impl From<&str> for CaixaVersion`
3147        // constructor above (which wraps `s.to_string()` into the
3148        // newtype's inner `String` slot), so every consumer that reaches
3149        // [`CaixaVersion`] through the standard-library `T: FromStr`-
3150        // bounded parse surface (`str::parse::<CaixaVersion>`, the
3151        // `<CaixaVersion as std::str::FromStr>::from_str` explicit-trait
3152        // spelling on a generic bound, a `clap::value_parser!(CaixaVersion)`
3153        // short-form on a future arg-parse, a `serde_with::DisplayFromStr`
3154        // wrapper on a downstream typed-YAML derive) routes through the
3155        // same wrap the sibling `From<&str>` forward-projection already
3156        // installs. Refuses any future silent detour that would route
3157        // the stdlib entry point through a divergent projection (a stray
3158        // `parse_semver_first` validation gate slipping onto the wrap
3159        // path, a normalization step that would drop whitespace or
3160        // canonicalize a prerelease tag, a swap onto the paired
3161        // [`CaixaVersion::parse`] `Result<semver::Version, VersionError>`
3162        // accessor that would narrow the accept-set to the semver
3163        // grammar's shape ahead of the wrap). Also witnesses the
3164        // `Err = Infallible` type-level shape at compile time under the
3165        // explicit `Result<CaixaVersion, std::convert::Infallible>`
3166        // annotation the loop body binds against — any future accidental
3167        // widening of the error type (a swap onto `type Err =
3168        // VersionError`) trips the annotation at caixa-core build time
3169        // with E0308 (`expected Infallible, found <T>`), strictly stronger
3170        // than a runtime `.unwrap()` on the sibling `.parse()` short-form.
3171        //
3172        // Sweeps the same fixture bodies the sibling
3173        // `caixa_version_as_str_accessor_is_const_fn` /
3174        // `caixa_version_from_owned_and_borrowed_into_rc_str_agree_on_every_shape`
3175        // pins already cover on the paired scalar-accessor and
3176        // owned-vs-borrowed axes: canonical semver, prerelease-shape,
3177        // zero-body, and empty-string corners. Extends the sweep with a
3178        // requirement-shape (`^0.1`), a star (`*`), and a non-semver junk
3179        // body (`not-a-version`) so the total-wrap discipline the
3180        // `Err = Infallible` shape witnesses is asserted across the four
3181        // canonical axes of the input space: semver-shaped bodies the
3182        // paired [`CaixaVersion::parse`] accessor would accept, semver-
3183        // requirement-shaped bodies the sibling [`parse_requirement`]
3184        // surface consumes, empty bodies (which the wrap accepts but
3185        // downstream semver rejects), and non-semver junk (which the
3186        // wrap accepts and downstream semver rejects).
3187        use std::str::FromStr;
3188        for versao in [
3189            "0.1.0",
3190            "1.2.3-alpha.1",
3191            "0.0.0",
3192            "",
3193            "^0.1",
3194            "*",
3195            "not-a-version",
3196        ] {
3197            let via_parse_short_form: Result<CaixaVersion, std::convert::Infallible> =
3198                versao.parse::<CaixaVersion>();
3199            let via_from_str_explicit: Result<CaixaVersion, std::convert::Infallible> =
3200                <CaixaVersion as FromStr>::from_str(versao);
3201            let via_from_ref: CaixaVersion = <CaixaVersion as From<&str>>::from(versao);
3202            let via_parse_ok: CaixaVersion = via_parse_short_form.unwrap();
3203            let via_from_str_ok: CaixaVersion = via_from_str_explicit.unwrap();
3204            assert_eq!(
3205                via_parse_ok.as_str(),
3206                versao,
3207                "str::parse::<CaixaVersion>() must byte-equal the input",
3208            );
3209            assert_eq!(
3210                via_from_str_ok.as_str(),
3211                versao,
3212                "<CaixaVersion as FromStr>::from_str must byte-equal the input",
3213            );
3214            assert_eq!(
3215                via_parse_ok, via_from_ref,
3216                "str::parse::<CaixaVersion>() must byte-equal From<&str>",
3217            );
3218            assert_eq!(
3219                via_from_str_ok, via_from_ref,
3220                "<CaixaVersion as FromStr>::from_str must byte-equal From<&str>",
3221            );
3222        }
3223    }
3224
3225    #[test]
3226    fn caixa_version_from_str_round_trips_through_display_on_every_input() {
3227        // Fail-before-pass-after round-trip pin: the lifted
3228        // `impl std::str::FromStr for CaixaVersion` closes the two-way
3229        // canonical wire-form axis with the paired forward-projection
3230        // [`fmt::Display`] impl at line 29 —
3231        // `s.parse::<CaixaVersion>().unwrap().to_string() == s` for every
3232        // `&str` on the total-wrap axis the newtype installs at rest.
3233        // Refuses any future silent narrowing on either half (a stray
3234        // normalization step slipping onto the [`fmt::Display`] impl that
3235        // would canonicalize the wrapped body ahead of `f.write_str`, a
3236        // divergent wrap on the `FromStr` impl that would swap the paired
3237        // `From<&str>` constructor for a fresh `String::from(s).trim()`-
3238        // style body-mutating projection) so the round-trip theorem the
3239        // pin states remains machine-checked at caixa-core test time.
3240        //
3241        // Peer of the sibling `caixa_version_from_str_routes_through_from_str_reference_impl`
3242        // pin immediately above (which witnesses the byte-parity axis
3243        // against the paired `From<&str>` forward-projection); this pin
3244        // witnesses the same axis against the paired `fmt::Display`
3245        // forward-projection instead, closing the two-way round-trip
3246        // through the standard-library [`fmt::Display`] / [`FromStr`]
3247        // pair the substrate reaches [`CaixaVersion`] through on the
3248        // canonical wire-form axis.
3249        for versao in [
3250            "0.1.0",
3251            "1.2.3-alpha.1",
3252            "0.0.0",
3253            "",
3254            "^0.1",
3255            "*",
3256            "not-a-version",
3257            "1.2.3+build.42",
3258        ] {
3259            let parsed: CaixaVersion = versao.parse::<CaixaVersion>().unwrap();
3260            let displayed: String = parsed.to_string();
3261            assert_eq!(
3262                displayed, versao,
3263                "CaixaVersion::from_str + Display must round-trip byte-for-byte",
3264            );
3265        }
3266    }
3267
3268    #[test]
3269    fn caixa_version_as_ref_bytes_routes_through_as_str_accessor() {
3270        // `<T: AsRef<[u8]>>`-bound-consumer witness helper: a generic
3271        // byte-input function accepts a [`CaixaVersion`] directly through
3272        // the trait bound, without the caller open-coding the two-hop
3273        // `v.as_str().as_bytes()` composition. Lifted to the top of the
3274        // function per `clippy::items_after_statements`.
3275        fn generic_bytes_sink<T: AsRef<[u8]>>(t: T) -> Vec<u8> {
3276            t.as_ref().to_vec()
3277        }
3278        // `blake3::Hasher::update`-shape byte-input surface mock: mirrors
3279        // `blake3::Hasher::update` / `ring::digest::Context::update` /
3280        // `sha2::Sha256::update`'s `impl AsRef<[u8]>`-bound `update`
3281        // signature so a per-`:versao` BLAKE3 content-address closure
3282        // that composes `hasher.update(caixa.versao())` on the
3283        // [`crate::Lacre`] closure builder reaches the substrate-
3284        // primitive [`CaixaVersion::as_str`] accessor through this axis
3285        // and no other.
3286        struct MockHasher(Vec<u8>);
3287        impl MockHasher {
3288            fn new() -> Self {
3289                Self(Vec::new())
3290            }
3291            fn update(&mut self, bytes: impl AsRef<[u8]>) -> &mut Self {
3292                self.0.extend_from_slice(bytes.as_ref());
3293                self
3294            }
3295            fn finalize(self) -> Vec<u8> {
3296                self.0
3297            }
3298        }
3299
3300        // Fail-before-pass-after byte-parity pin on the newly lifted
3301        // `impl AsRef<[u8]> for CaixaVersion` — asserts the trait-
3302        // idiomatic byte-view standard-library impl and the substrate-
3303        // primitive [`CaixaVersion::as_str`] `pub const fn` accessor's
3304        // `.as_bytes()` byte-tail resolve to the same byte-string across
3305        // every canonical `:versao`-shaped input the sibling
3306        // `caixa_version_as_str_accessor_is_const_fn` and
3307        // `caixa_version_from_str_round_trips_through_display_on_every_input`
3308        // pins already sweep (canonical semver, prerelease-shape, zero-
3309        // body, empty-string, requirement-shape, star, non-semver junk,
3310        // build-metadata-tail). Opens the trait-idiomatic byte-view axis
3311        // on the substrate's core String-wrapper newtype primitive
3312        // [`CaixaVersion`], mirroring the paired [`AsRef<[u8]>`] axis
3313        // every closed-set fieldless typed enum peer already carries.
3314        for versao in [
3315            "0.1.0",
3316            "1.2.3-alpha.1",
3317            "0.0.0",
3318            "",
3319            "^0.1",
3320            "*",
3321            "not-a-version",
3322            "1.2.3+build.42",
3323        ] {
3324            let v: CaixaVersion = versao.into();
3325            let via_trait: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3326            let via_method_bytes: &[u8] = v.as_str().as_bytes();
3327            assert_eq!(
3328                via_trait, via_method_bytes,
3329                "AsRef<[u8]> for CaixaVersion impl must byte-equal \
3330                 CaixaVersion::as_str().as_bytes() on {versao:?} — \
3331                 divergence signals a silent detour off the substrate-\
3332                 primitive accessor",
3333            );
3334            // Cross-axis witness against the paired str-view axes'
3335            // `.as_bytes()` byte-tails: the newly lifted byte-view
3336            // impl and every str-view axis on the same primitive
3337            // ([`AsRef<str>`], [`fmt::Display`], [`CaixaVersion::as_str`])
3338            // must resolve to the same byte-tail by construction — any
3339            // future silent split at the substrate-primitive accessor
3340            // trips here rather than at a downstream consumer.
3341            let str_view_ref: &str = <CaixaVersion as AsRef<str>>::as_ref(&v);
3342            assert_eq!(
3343                via_trait,
3344                str_view_ref.as_bytes(),
3345                "AsRef<[u8]> and AsRef<str> for CaixaVersion must resolve \
3346                 to byte-equal byte-tails on {versao:?}",
3347            );
3348            let display_bytes = v.to_string();
3349            assert_eq!(
3350                via_trait,
3351                display_bytes.as_bytes(),
3352                "AsRef<[u8]> and <CaixaVersion as fmt::Display>::to_string \
3353                 must resolve to byte-equal byte-tails on {versao:?}",
3354            );
3355            let borrow_view: &str = <CaixaVersion as std::borrow::Borrow<str>>::borrow(&v);
3356            assert_eq!(
3357                via_trait,
3358                borrow_view.as_bytes(),
3359                "AsRef<[u8]> and Borrow<str> for CaixaVersion must resolve \
3360                 to byte-equal byte-tails on {versao:?}",
3361            );
3362            // `<T: AsRef<[u8]>>`-bound-consumer witness: a generic
3363            // byte-input function accepts the wrapper directly and
3364            // returns the same bytes the substrate-primitive accessor's
3365            // `.as_bytes()` byte-tail carries.
3366            let sunk_owned: Vec<u8> = generic_bytes_sink(v.clone());
3367            assert_eq!(sunk_owned, via_method_bytes);
3368            let sunk_borrowed: Vec<u8> = generic_bytes_sink(&v);
3369            assert_eq!(sunk_borrowed, via_method_bytes);
3370            // `blake3::Hasher::update`-shape witness: the
3371            // per-`:versao` BLAKE3 content-address closure builder reaches
3372            // the substrate-primitive accessor through the byte-view axis
3373            // and folds the same bytes the paired str-view axes surface.
3374            let mut mock_hasher = MockHasher::new();
3375            mock_hasher.update(&v);
3376            let folded_bytes = mock_hasher.finalize();
3377            assert_eq!(folded_bytes, via_method_bytes);
3378        }
3379    }
3380
3381    #[test]
3382    fn caixa_version_from_into_owned_vec_bytes_returns_wrapped_body() {
3383        // Fail-before-pass-after byte-parity pin on the lifted
3384        // `impl From<CaixaVersion> for Vec<u8>` — asserts the owned-input
3385        // byte-owned forward-projection routes the wrapper's own heap
3386        // allocation through [`String::into_bytes`] verbatim (no re-copy
3387        // of the wrapped body's bytes, no normalization detour) so
3388        // `Vec::<u8>::from(v)` returns the same bytes `v.as_str()`
3389        // borrows via `.as_bytes()`. Refuses any future silent detour
3390        // that would swap the move on `v.0.into_bytes()` for an
3391        // allocating `.as_str().as_bytes().to_vec()` cascade (the
3392        // pre-lift compose shape), a `String::from(v).into_bytes()`
3393        // two-hop reverse-then-move shape, a stray
3394        // `.trim().as_bytes().to_vec()` normalization, or a routing
3395        // through the sibling [`fmt::Display`] emitter that would
3396        // introduce a formatter round-trip. Closes the byte-owned
3397        // forward-projection axis in lockstep with the paired str-owned
3398        // [`From<CaixaVersion> for String`] axis (which routes through
3399        // `v.0`).
3400        for versao in [
3401            "0.1.0",
3402            "1.2.3-alpha.1",
3403            "0.0.0",
3404            "",
3405            "^0.1",
3406            "*",
3407            "not-a-version",
3408            "1.2.3+build.42",
3409        ] {
3410            let v: CaixaVersion = versao.into();
3411            let expected: Vec<u8> = v.as_str().as_bytes().to_vec();
3412            let owned: Vec<u8> = Vec::<u8>::from(v);
3413            assert_eq!(
3414                owned, expected,
3415                "Vec::<u8>::from(v) must return the wrapper's own bytes verbatim on {versao:?}",
3416            );
3417            assert_eq!(
3418                owned,
3419                versao.as_bytes(),
3420                "Vec::<u8>::from(v) must byte-equal the pre-lift wrapped \
3421                 String storage on round-trip through the From<&str> constructor",
3422            );
3423            // Round-trip witness through the paired forward constructor:
3424            // the emitted owned byte-tail rematerializes into a
3425            // [`String`] via [`String::from_utf8`] and folds through
3426            // the paired [`From<String> for CaixaVersion`] constructor
3427            // to the same [`CaixaVersion`] value — closes the
3428            // `Self → Vec<u8> → String → Self` round-trip whenever the
3429            // wrapped body is valid UTF-8, which every `SemVer`-shaped
3430            // `:versao` body is by construction (semver's grammar is
3431            // ASCII-only).
3432            if let Ok(round) = String::from_utf8(owned) {
3433                let back: CaixaVersion = round.into();
3434                assert_eq!(back.as_str(), versao);
3435            }
3436        }
3437    }
3438
3439    #[test]
3440    fn caixa_version_from_borrowed_into_owned_vec_bytes_routes_through_as_str_accessor() {
3441        // Fail-before-pass-after byte-parity pin on the lifted
3442        // `impl From<&CaixaVersion> for Vec<u8>` — asserts the
3443        // borrowed-input byte-owned forward-projection allocates a fresh
3444        // [`Vec<u8>`] whose bytes byte-equal the substrate-primitive
3445        // [`CaixaVersion::as_str`] accessor's `.as_bytes()` byte-tail
3446        // (via [`slice::to_vec`]) so `Vec::<u8>::from(&v)` returns the
3447        // same bytes without consuming the source wrapper. Refuses any
3448        // future silent detour: a stray normalization step that would
3449        // drop whitespace or canonicalize a prerelease tag ahead of the
3450        // byte-owned emit, a swap onto `String::from(v.clone()).into_bytes()`
3451        // that would spuriously clone the intermediate [`String`], or a
3452        // routing through the sibling [`fmt::Display`] emitter that
3453        // would introduce a formatter round-trip. Includes a source-
3454        // survival witness — the borrowed input remains readable after
3455        // the projection returns, confirming the impl takes only a
3456        // borrow and does not silently move out of the source.
3457        for versao in [
3458            "0.1.0",
3459            "1.2.3-alpha.1",
3460            "0.0.0",
3461            "",
3462            "^0.1",
3463            "*",
3464            "not-a-version",
3465            "1.2.3+build.42",
3466        ] {
3467            let v: CaixaVersion = versao.into();
3468            let via_borrowed: Vec<u8> = Vec::<u8>::from(&v);
3469            assert_eq!(
3470                via_borrowed,
3471                v.as_str().as_bytes(),
3472                "Vec::<u8>::from(&v) must byte-equal CaixaVersion::as_str().as_bytes() \
3473                 on {versao:?} — divergence signals a silent detour off \
3474                 the substrate-primitive accessor",
3475            );
3476            // Source-survival witness: `v` is borrowed, not moved, so
3477            // the pre-existing borrow-projection axes stay reachable
3478            // through the same instance after the byte-owned projection
3479            // returns.
3480            assert_eq!(v.as_str(), versao);
3481        }
3482    }
3483
3484    #[test]
3485    fn caixa_version_from_owned_and_borrowed_into_vec_bytes_agree_on_every_shape() {
3486        // Fail-before-pass-after cross-axis partition pin: the paired
3487        // owned-input [`From<CaixaVersion> for Vec<u8>`] and
3488        // borrowed-input [`From<&CaixaVersion> for Vec<u8>`] impls
3489        // resolve to the same byte-tail on every instance, and both
3490        // agree byte-for-byte with the pre-existing byte-view
3491        // [`AsRef<[u8]>`] axis on the same primitive. Closes the
3492        // "owned-input move vs. borrowed-input clone" bifurcation on
3493        // the [`Vec<u8>`] axis and the "owned-heap vs. borrowed-view"
3494        // bifurcation between the byte-owned forward-projection and the
3495        // pre-existing borrow-projection byte-view axis. Refuses any
3496        // future silent split between the two corners (a normalization
3497        // on one path only, a divergent routing that would let
3498        // `Vec::<u8>::from(v.clone())` and `Vec::<u8>::from(&v)`
3499        // disagree, or a swap on `AsRef::<[u8]>::as_ref` that would
3500        // diverge from either projection).
3501        for versao in [
3502            "0.1.0",
3503            "1.2.3-alpha.1",
3504            "0.0.0",
3505            "",
3506            "^0.1",
3507            "*",
3508            "not-a-version",
3509            "1.2.3+build.42",
3510        ] {
3511            let v: CaixaVersion = versao.into();
3512            let via_owned: Vec<u8> = Vec::<u8>::from(v.clone());
3513            let via_borrowed: Vec<u8> = Vec::<u8>::from(&v);
3514            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3515            assert_eq!(via_owned, via_borrowed);
3516            assert_eq!(via_borrowed.as_slice(), via_as_ref);
3517            assert_eq!(via_borrowed, versao.as_bytes());
3518        }
3519    }
3520
3521    #[test]
3522    fn caixa_version_from_into_owned_cow_bytes_returns_owned_wrapped_body() {
3523        // Fail-before-pass-after byte-parity + [`Cow::Owned`]-arm pin
3524        // on the lifted `impl From<CaixaVersion> for
3525        // std::borrow::Cow<'static, [u8]>` — asserts the owned-input
3526        // byte-owned reverse projection routes the wrapper's own heap
3527        // allocation through `Cow::Owned(v.0.into_bytes())` verbatim
3528        // (no re-copy, no normalization detour, no `Cow::Borrowed`
3529        // misclassification that would demand a `&'static [u8]` the
3530        // runtime wrapper cannot carry), so the emitted [`Cow`] byte-
3531        // equals the substrate-primitive [`CaixaVersion::as_str`]
3532        // accessor's `.as_bytes()` byte-tail on the same instance and
3533        // round-trips byte-equal through the paired forward
3534        // [`From<String> for CaixaVersion`] constructor after
3535        // re-materializing through [`String::from_utf8`]. Refuses any
3536        // future silent detour: a swap of the move on `v.0.into_bytes()`
3537        // for an allocating `.as_str().as_bytes().to_vec()` cascade
3538        // (the pre-lift compose shape would double-allocate a fresh
3539        // intermediary [`Vec<u8>`] on the way to the same
3540        // [`Cow::Owned`] arm), a stray `.trim().as_bytes().to_vec()`
3541        // normalization, or a mis-routing through [`Cow::Borrowed`] on
3542        // a non-`'static` byte-string that would not type-check.
3543        use std::borrow::Cow;
3544        for versao in [
3545            "0.1.0",
3546            "1.2.3-alpha.1",
3547            "0.0.0",
3548            "",
3549            "^0.1",
3550            "*",
3551            "not-a-version",
3552            "1.2.3+build.42",
3553        ] {
3554            let v: CaixaVersion = versao.into();
3555            let expected: Vec<u8> = v.as_str().as_bytes().to_vec();
3556            let cow: Cow<'static, [u8]> = Cow::from(v.clone());
3557            assert!(
3558                matches!(cow, Cow::Owned(_)),
3559                "From<CaixaVersion> for Cow<'static, [u8]> must land on \
3560                 the Cow::Owned arm — a runtime String wrapper cannot \
3561                 promise the 'static lifetime the Cow::Borrowed arm \
3562                 requires on {versao:?}",
3563            );
3564            assert_eq!(
3565                cow.as_ref(),
3566                expected.as_slice(),
3567                "Cow::from(v) must return the wrapper's own bytes verbatim on {versao:?}",
3568            );
3569            assert_eq!(
3570                cow.as_ref(),
3571                versao.as_bytes(),
3572                "Cow::from(v) must byte-equal the pre-lift wrapped String \
3573                 storage on round-trip through the From<&str> constructor",
3574            );
3575            // Round-trip witness through the paired forward constructor:
3576            // the emitted owned byte-tail rematerializes into a
3577            // [`String`] via [`String::from_utf8`] and folds through
3578            // the paired [`From<String> for CaixaVersion`] constructor
3579            // to the same [`CaixaVersion`] value — closes the
3580            // `Self → Cow<'static, [u8]> → Vec<u8> → String → Self`
3581            // round-trip whenever the wrapped body is valid UTF-8, which
3582            // every `SemVer`-shaped `:versao` body is by construction
3583            // (semver's grammar is ASCII-only).
3584            if let Ok(round) = String::from_utf8(cow.into_owned()) {
3585                let back: CaixaVersion = round.into();
3586                assert_eq!(back.as_str(), versao);
3587            }
3588        }
3589    }
3590
3591    #[test]
3592    fn caixa_version_from_into_owned_cow_bytes_and_vec_bytes_agree_on_every_shape() {
3593        // Fail-before-pass-after cross-axis partition pin: the owned-
3594        // input [`From<CaixaVersion> for Cow<'static, [u8]>`] byte-owned
3595        // reverse projection and the paired owned-input
3596        // [`From<CaixaVersion> for Vec<u8>`] byte-owned reverse
3597        // projection resolve to the same bytes on every instance, and
3598        // both agree with the pre-existing borrowed [`AsRef<[u8]>`]
3599        // byte-view axis on the same wrapped body. Refuses any future
3600        // silent split between the two owned-input byte-owned reverse-
3601        // projection axes (a stray normalization on one path only, a
3602        // divergent routing that would let `Cow::from(v.clone())` and
3603        // `Vec::<u8>::from(v.clone())` disagree on the same body) that
3604        // would silently split the same-shape owned-move discipline
3605        // across the two byte-family reverse-projection targets.
3606        use std::borrow::Cow;
3607        for versao in [
3608            "0.1.0",
3609            "1.2.3-alpha.1",
3610            "0.0.0",
3611            "",
3612            "^0.1",
3613            "*",
3614            "not-a-version",
3615            "1.2.3+build.42",
3616        ] {
3617            let v: CaixaVersion = versao.into();
3618            let via_vec: Vec<u8> = Vec::<u8>::from(v.clone());
3619            let via_cow: Cow<'static, [u8]> = Cow::from(v.clone());
3620            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3621            assert_eq!(via_cow.as_ref(), via_vec.as_slice());
3622            assert_eq!(via_cow.as_ref(), via_as_ref);
3623            assert_eq!(via_cow.as_ref(), versao.as_bytes());
3624        }
3625    }
3626
3627    #[test]
3628    fn caixa_version_from_borrowed_into_owned_cow_bytes_routes_through_as_str_accessor() {
3629        // Fail-before-pass-after byte-parity + [`Cow::Owned`]-arm pin
3630        // on the lifted `impl From<&CaixaVersion> for
3631        // std::borrow::Cow<'static, [u8]>` — asserts the borrowed-input
3632        // byte-owned reverse projection allocates a fresh
3633        // [`Cow::Owned`] whose bytes byte-equal the substrate-primitive
3634        // [`CaixaVersion::as_str`] accessor's `.as_bytes()` byte-tail
3635        // on the same instance (via [`slice::to_vec`]), preserving the
3636        // source [`CaixaVersion`] intact (no move-out). Refuses any
3637        // future silent detour that would route the impl through a
3638        // divergent projection (a stray normalization step that would
3639        // drop whitespace or canonicalize a prerelease tag ahead of the
3640        // byte-owned emit, a mis-routing onto [`Cow::Borrowed`] on a
3641        // non-`'static` byte-string that would not type-check, a
3642        // re-inlining that dereferences `&self.0` outside the shared
3643        // accessor).
3644        use std::borrow::Cow;
3645        for versao in [
3646            "0.1.0",
3647            "1.2.3-alpha.1",
3648            "0.0.0",
3649            "",
3650            "^0.1",
3651            "*",
3652            "not-a-version",
3653            "1.2.3+build.42",
3654        ] {
3655            let v: CaixaVersion = versao.into();
3656            let via_borrowed: Cow<'static, [u8]> = Cow::from(&v);
3657            assert!(
3658                matches!(via_borrowed, Cow::Owned(_)),
3659                "From<&CaixaVersion> for Cow<'static, [u8]> must land on \
3660                 the Cow::Owned arm — a runtime String wrapper cannot \
3661                 promise the 'static lifetime the Cow::Borrowed arm \
3662                 requires on {versao:?}",
3663            );
3664            assert_eq!(
3665                via_borrowed.as_ref(),
3666                v.as_str().as_bytes(),
3667                "Cow::from(&v) must byte-equal CaixaVersion::as_str().as_bytes() \
3668                 on {versao:?} — divergence signals a silent detour off \
3669                 the substrate-primitive accessor",
3670            );
3671            // The borrowed-input impl must not move out of the source.
3672            assert_eq!(
3673                v.as_str(),
3674                versao,
3675                "source CaixaVersion must survive borrowed-input projection",
3676            );
3677        }
3678    }
3679
3680    #[test]
3681    fn caixa_version_from_owned_and_borrowed_into_cow_bytes_agree_on_every_shape() {
3682        // Fail-before-pass-after cross-axis partition pin: the paired
3683        // owned-input [`From<CaixaVersion> for Cow<'static, [u8]>`] and
3684        // borrowed-input [`From<&CaixaVersion> for Cow<'static, [u8]>`]
3685        // impls resolve to the same bytes on every instance, closing
3686        // the "owned-input move vs. borrowed-input clone" bifurcation
3687        // on the same wrapped body through the [`Cow<'static, [u8]>`]
3688        // axis. Refuses any future silent split between the two corners
3689        // (a normalization on one path only, a divergent routing that
3690        // would let `Cow::from(v.clone())` and `Cow::from(&v)` disagree
3691        // on the same body). Both corners must land on [`Cow::Owned`]
3692        // — the runtime wrapper's storage rules out the borrowed arm
3693        // on both input shapes alike.
3694        use std::borrow::Cow;
3695        for versao in [
3696            "0.1.0",
3697            "1.2.3-alpha.1",
3698            "0.0.0",
3699            "",
3700            "^0.1",
3701            "*",
3702            "not-a-version",
3703            "1.2.3+build.42",
3704        ] {
3705            let v: CaixaVersion = versao.into();
3706            let via_borrowed: Cow<'static, [u8]> = Cow::from(&v);
3707            let via_owned: Cow<'static, [u8]> = Cow::from(v.clone());
3708            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3709            assert!(matches!(via_borrowed, Cow::Owned(_)));
3710            assert!(matches!(via_owned, Cow::Owned(_)));
3711            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
3712            assert_eq!(via_borrowed.as_ref(), via_as_ref);
3713            assert_eq!(via_borrowed.as_ref(), versao.as_bytes());
3714        }
3715    }
3716
3717    #[test]
3718    fn caixa_version_from_into_owned_box_bytes_returns_wrapped_body() {
3719        // Fail-before-pass-after byte-parity pin on the lifted
3720        // `impl From<CaixaVersion> for Box<[u8]>` — asserts the owned-
3721        // input byte-owned reverse projection routes the wrapper's own
3722        // heap allocation through
3723        // `v.0.into_bytes().into_boxed_slice()` verbatim (no re-copy of
3724        // the underlying bytes on the fixed-capacity path;
3725        // `Vec::<u8>::into_boxed_slice` reuses the same allocation when
3726        // length matches capacity), so `Box::<[u8]>::from(v)` returns
3727        // the same bytes `v.as_str().as_bytes()` borrows and round-trips
3728        // byte-equal through the paired forward
3729        // [`From<String> for CaixaVersion`] constructor after re-
3730        // materializing the boxed byte-tail through
3731        // [`String::from_utf8`] on every UTF-8-valid `:versao` body
3732        // (which every `SemVer`-shaped body is by construction).
3733        // Refuses any future silent detour that would swap
3734        // `v.0.into_bytes().into_boxed_slice()` for an allocating
3735        // `.as_str().as_bytes().to_vec().into_boxed_slice()` cascade
3736        // (the pre-lift compose shape would double-allocate a fresh
3737        // intermediary [`Vec<u8>`] on the way to the same
3738        // [`Box<[u8]>`] slot), a stray `.trim().as_bytes()...`
3739        // normalization, or a routing through the sibling
3740        // [`fmt::Display`] emitter that would introduce a formatter
3741        // round-trip.
3742        for versao in [
3743            "0.1.0",
3744            "1.2.3-alpha.1",
3745            "0.0.0",
3746            "",
3747            "^0.1",
3748            "*",
3749            "not-a-version",
3750            "1.2.3+build.42",
3751        ] {
3752            let v: CaixaVersion = versao.into();
3753            let expected: Vec<u8> = v.as_str().as_bytes().to_vec();
3754            let boxed: Box<[u8]> = Box::<[u8]>::from(v.clone());
3755            assert_eq!(
3756                boxed.as_ref(),
3757                expected.as_slice(),
3758                "Box::<[u8]>::from(v) must return the wrapper's own bytes verbatim on {versao:?}",
3759            );
3760            assert_eq!(
3761                boxed.as_ref(),
3762                versao.as_bytes(),
3763                "Box::<[u8]>::from(v) must byte-equal the pre-lift wrapped \
3764                 String storage on round-trip through the From<&str> constructor",
3765            );
3766            // Round-trip witness through the paired forward constructor:
3767            // the emitted boxed byte-tail rematerializes into a
3768            // [`Vec<u8>`] via [`Box::<[u8]>::into_vec`], folds through
3769            // [`String::from_utf8`], and lands back on the same
3770            // [`CaixaVersion`] value via the paired
3771            // [`From<String> for CaixaVersion`] constructor — closing
3772            // the `Self → Box<[u8]> → Vec<u8> → String → Self`
3773            // round-trip whenever the wrapped body is valid UTF-8.
3774            if let Ok(round) = String::from_utf8(boxed.into_vec()) {
3775                let back: CaixaVersion = round.into();
3776                assert_eq!(back.as_str(), versao);
3777            }
3778        }
3779    }
3780
3781    #[test]
3782    fn caixa_version_from_into_owned_box_bytes_and_vec_bytes_agree_on_every_shape() {
3783        // Fail-before-pass-after cross-axis partition pin: the owned-
3784        // input [`From<CaixaVersion> for Box<[u8]>`] byte-owned reverse
3785        // projection and the paired owned-input
3786        // [`From<CaixaVersion> for Vec<u8>`] and
3787        // [`From<CaixaVersion> for Cow<'static, [u8]>`] byte-owned
3788        // reverse projections resolve to the same bytes on every
3789        // instance, and all three agree with the pre-existing borrowed
3790        // [`AsRef<[u8]>`] byte-view axis on the same wrapped body.
3791        // Refuses any future silent split between the three owned-input
3792        // byte-owned reverse-projection axes (a stray normalization on
3793        // one path only, a divergent routing that would let
3794        // `Box::<[u8]>::from(v.clone())`, `Vec::<u8>::from(v.clone())`,
3795        // and `Cow::from(v.clone())` disagree on the same body) that
3796        // would silently split the same-shape owned-move discipline
3797        // across the three byte-family reverse-projection targets.
3798        use std::borrow::Cow;
3799        for versao in [
3800            "0.1.0",
3801            "1.2.3-alpha.1",
3802            "0.0.0",
3803            "",
3804            "^0.1",
3805            "*",
3806            "not-a-version",
3807            "1.2.3+build.42",
3808        ] {
3809            let v: CaixaVersion = versao.into();
3810            let via_vec: Vec<u8> = Vec::<u8>::from(v.clone());
3811            let via_cow: Cow<'static, [u8]> = Cow::from(v.clone());
3812            let via_box: Box<[u8]> = Box::<[u8]>::from(v.clone());
3813            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3814            assert_eq!(via_box.as_ref(), via_vec.as_slice());
3815            assert_eq!(via_box.as_ref(), via_cow.as_ref());
3816            assert_eq!(via_box.as_ref(), via_as_ref);
3817            assert_eq!(via_box.as_ref(), versao.as_bytes());
3818        }
3819    }
3820
3821    #[test]
3822    fn caixa_version_from_borrowed_into_owned_box_bytes_routes_through_as_str_accessor() {
3823        // Fail-before-pass-after byte-parity pin on the lifted
3824        // `impl From<&CaixaVersion> for Box<[u8]>` — asserts the
3825        // borrowed-input byte-owned reverse projection allocates a
3826        // fresh [`Box<[u8]>`] whose bytes byte-equal the substrate-
3827        // primitive [`CaixaVersion::as_str`] accessor's `.as_bytes()`
3828        // byte-tail on the same instance (via
3829        // [`Box::<[u8]>::from`]`(&[u8])`, which allocates a fit-to-
3830        // length boxed byte slice from the borrowed `&[u8]` in one
3831        // heap allocation without an intermediary [`Vec<u8>`]),
3832        // preserving the source [`CaixaVersion`] intact (no move-out).
3833        // Refuses any future silent detour that would route the impl
3834        // through a divergent projection (a stray normalization step
3835        // that would drop whitespace or canonicalize a prerelease tag
3836        // ahead of the byte-owned emit, a swap onto the sibling
3837        // [`fmt::Display`]-routed [`ToString::to_string`] surface
3838        // followed by `.into_bytes().into_boxed_slice()`, a re-inlining
3839        // that dereferences `&self.0` outside the shared accessor).
3840        for versao in [
3841            "0.1.0",
3842            "1.2.3-alpha.1",
3843            "0.0.0",
3844            "",
3845            "^0.1",
3846            "*",
3847            "not-a-version",
3848            "1.2.3+build.42",
3849        ] {
3850            let v: CaixaVersion = versao.into();
3851            let via_borrowed: Box<[u8]> = Box::<[u8]>::from(&v);
3852            assert_eq!(
3853                via_borrowed.as_ref(),
3854                v.as_str().as_bytes(),
3855                "Box::<[u8]>::from(&v) must byte-equal CaixaVersion::as_str().as_bytes() \
3856                 on {versao:?} — divergence signals a silent detour off \
3857                 the substrate-primitive accessor",
3858            );
3859            // The borrowed-input impl must not move out of the source.
3860            assert_eq!(
3861                v.as_str(),
3862                versao,
3863                "source CaixaVersion must survive borrowed-input projection",
3864            );
3865        }
3866    }
3867
3868    #[test]
3869    fn caixa_version_from_owned_and_borrowed_into_box_bytes_agree_on_every_shape() {
3870        // Fail-before-pass-after cross-corner partition pin: the paired
3871        // owned-input [`From<CaixaVersion> for Box<[u8]>`] and
3872        // borrowed-input [`From<&CaixaVersion> for Box<[u8]>`] impls
3873        // resolve to the same bytes on every instance, closing the
3874        // "owned-input move vs. borrowed-input clone" bifurcation on
3875        // the same wrapped body through the [`Box<[u8]>`] axis.
3876        // Refuses any future silent split between the two corners (a
3877        // normalization on one path only, a divergent routing that
3878        // would let `Box::<[u8]>::from(v.clone())` and
3879        // `Box::<[u8]>::from(&v)` disagree on the same body).
3880        for versao in [
3881            "0.1.0",
3882            "1.2.3-alpha.1",
3883            "0.0.0",
3884            "",
3885            "^0.1",
3886            "*",
3887            "not-a-version",
3888            "1.2.3+build.42",
3889        ] {
3890            let v: CaixaVersion = versao.into();
3891            let via_borrowed: Box<[u8]> = Box::<[u8]>::from(&v);
3892            let via_owned: Box<[u8]> = Box::<[u8]>::from(v.clone());
3893            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3894            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
3895            assert_eq!(via_borrowed.as_ref(), via_as_ref);
3896            assert_eq!(via_borrowed.as_ref(), versao.as_bytes());
3897        }
3898    }
3899
3900    #[test]
3901    fn caixa_version_from_into_owned_arc_bytes_returns_wrapped_body() {
3902        // Fail-before-pass-after byte-parity pin on the lifted
3903        // `impl From<CaixaVersion> for std::sync::Arc<[u8]>` — asserts
3904        // the owned-input byte-owned reverse projection routes the
3905        // wrapper's own heap allocation through
3906        // `std::sync::Arc::<[u8]>::from(v.0.into_bytes())` verbatim
3907        // (`String::into_bytes` is a niche-swap on the same buffer, no
3908        // re-copy; the [`std::sync::Arc<[u8]>`] layout then copies the
3909        // bytes once into a fresh atomically-refcounted heap slab whose
3910        // header carries the strong + weak counters), so
3911        // `std::sync::Arc::<[u8]>::from(v)` returns the same bytes
3912        // `v.as_str().as_bytes()` borrows and round-trips byte-equal
3913        // through the paired forward [`From<String> for CaixaVersion`]
3914        // constructor after re-materializing the Arc-borrowed byte-tail
3915        // through [`String::from_utf8`] on every UTF-8-valid `:versao`
3916        // body (which every `SemVer`-shaped body is by construction).
3917        // Refuses any future silent detour that would swap
3918        // `Arc::<[u8]>::from(v.0.into_bytes())` for an allocating
3919        // `.as_str().as_bytes().to_vec().into::<Arc<[u8]>>()` cascade or
3920        // a routing through the sibling [`fmt::Display`] emitter.
3921        for versao in [
3922            "0.1.0",
3923            "1.2.3-alpha.1",
3924            "0.0.0",
3925            "",
3926            "^0.1",
3927            "*",
3928            "not-a-version",
3929            "1.2.3+build.42",
3930        ] {
3931            let v: CaixaVersion = versao.into();
3932            let expected: Vec<u8> = v.as_str().as_bytes().to_vec();
3933            let arc: std::sync::Arc<[u8]> = std::sync::Arc::<[u8]>::from(v.clone());
3934            assert_eq!(
3935                arc.as_ref(),
3936                expected.as_slice(),
3937                "Arc::<[u8]>::from(v) must return the wrapper's own bytes verbatim on {versao:?}",
3938            );
3939            assert_eq!(
3940                arc.as_ref(),
3941                versao.as_bytes(),
3942                "Arc::<[u8]>::from(v) must byte-equal the pre-lift wrapped \
3943                 String storage on round-trip through the From<&str> constructor",
3944            );
3945            // Round-trip witness through the paired forward constructor:
3946            // the emitted Arc-borrowed byte-tail rematerializes into a
3947            // [`Vec<u8>`] via `.to_vec()`, folds through
3948            // [`String::from_utf8`], and lands back on the same
3949            // [`CaixaVersion`] value via the paired
3950            // [`From<String> for CaixaVersion`] constructor — closing
3951            // the `Self → Arc<[u8]> → Vec<u8> → String → Self`
3952            // round-trip whenever the wrapped body is valid UTF-8.
3953            if let Ok(round) = String::from_utf8(arc.to_vec()) {
3954                let back: CaixaVersion = round.into();
3955                assert_eq!(back.as_str(), versao);
3956            }
3957        }
3958    }
3959
3960    #[test]
3961    fn caixa_version_from_into_owned_arc_bytes_and_box_bytes_agree_on_every_shape() {
3962        // Fail-before-pass-after cross-axis partition pin: the owned-
3963        // input [`From<CaixaVersion> for std::sync::Arc<[u8]>`] byte-
3964        // owned reverse projection and the paired owned-input
3965        // [`From<CaixaVersion> for Vec<u8>`],
3966        // [`From<CaixaVersion> for Cow<'static, [u8]>`], and
3967        // [`From<CaixaVersion> for Box<[u8]>`] byte-owned reverse
3968        // projections resolve to the same bytes on every instance, and
3969        // all four agree with the pre-existing borrowed
3970        // [`AsRef<[u8]>`] byte-view axis on the same wrapped body.
3971        // Refuses any future silent split between the four owned-input
3972        // byte-owned reverse-projection axes.
3973        use std::borrow::Cow;
3974        for versao in [
3975            "0.1.0",
3976            "1.2.3-alpha.1",
3977            "0.0.0",
3978            "",
3979            "^0.1",
3980            "*",
3981            "not-a-version",
3982            "1.2.3+build.42",
3983        ] {
3984            let v: CaixaVersion = versao.into();
3985            let via_vec: Vec<u8> = Vec::<u8>::from(v.clone());
3986            let via_cow: Cow<'static, [u8]> = Cow::from(v.clone());
3987            let via_box: Box<[u8]> = Box::<[u8]>::from(v.clone());
3988            let via_arc: std::sync::Arc<[u8]> = std::sync::Arc::<[u8]>::from(v.clone());
3989            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
3990            assert_eq!(via_arc.as_ref(), via_vec.as_slice());
3991            assert_eq!(via_arc.as_ref(), via_cow.as_ref());
3992            assert_eq!(via_arc.as_ref(), via_box.as_ref());
3993            assert_eq!(via_arc.as_ref(), via_as_ref);
3994            assert_eq!(via_arc.as_ref(), versao.as_bytes());
3995        }
3996    }
3997
3998    #[test]
3999    fn caixa_version_from_borrowed_into_owned_arc_bytes_routes_through_as_str_accessor() {
4000        // Fail-before-pass-after byte-parity pin on the lifted
4001        // `impl From<&CaixaVersion> for std::sync::Arc<[u8]>` — asserts
4002        // the borrowed-input byte-owned reverse projection allocates a
4003        // fresh [`std::sync::Arc<[u8]>`] whose bytes byte-equal the
4004        // substrate-primitive [`CaixaVersion::as_str`] accessor's
4005        // `.as_bytes()` byte-tail on the same instance (via
4006        // [`std::sync::Arc::<[u8]>::from`]`(&[u8])`, which allocates a
4007        // fresh atomically-refcounted heap slab from the borrowed
4008        // `&[u8]` in one heap allocation without an intermediary
4009        // [`Vec<u8>`] or [`Box<[u8]>`]), preserving the source
4010        // [`CaixaVersion`] intact (no move-out). Refuses any future
4011        // silent detour that would route the impl through a divergent
4012        // projection.
4013        for versao in [
4014            "0.1.0",
4015            "1.2.3-alpha.1",
4016            "0.0.0",
4017            "",
4018            "^0.1",
4019            "*",
4020            "not-a-version",
4021            "1.2.3+build.42",
4022        ] {
4023            let v: CaixaVersion = versao.into();
4024            let via_borrowed: std::sync::Arc<[u8]> = std::sync::Arc::<[u8]>::from(&v);
4025            assert_eq!(
4026                via_borrowed.as_ref(),
4027                v.as_str().as_bytes(),
4028                "Arc::<[u8]>::from(&v) must byte-equal CaixaVersion::as_str().as_bytes() \
4029                 on {versao:?} — divergence signals a silent detour off \
4030                 the substrate-primitive accessor",
4031            );
4032            // The borrowed-input impl must not move out of the source.
4033            assert_eq!(
4034                v.as_str(),
4035                versao,
4036                "source CaixaVersion must survive borrowed-input projection",
4037            );
4038        }
4039    }
4040
4041    #[test]
4042    fn caixa_version_from_owned_and_borrowed_into_arc_bytes_agree_on_every_shape() {
4043        // Fail-before-pass-after cross-corner partition pin: the paired
4044        // owned-input [`From<CaixaVersion> for std::sync::Arc<[u8]>`]
4045        // and borrowed-input [`From<&CaixaVersion> for std::sync::Arc<[u8]>`]
4046        // impls resolve to the same bytes on every instance, closing
4047        // the "owned-input move vs. borrowed-input clone" bifurcation
4048        // on the same wrapped body through the [`std::sync::Arc<[u8]>`]
4049        // axis.
4050        for versao in [
4051            "0.1.0",
4052            "1.2.3-alpha.1",
4053            "0.0.0",
4054            "",
4055            "^0.1",
4056            "*",
4057            "not-a-version",
4058            "1.2.3+build.42",
4059        ] {
4060            let v: CaixaVersion = versao.into();
4061            let via_borrowed: std::sync::Arc<[u8]> = std::sync::Arc::<[u8]>::from(&v);
4062            let via_owned: std::sync::Arc<[u8]> = std::sync::Arc::<[u8]>::from(v.clone());
4063            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
4064            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
4065            assert_eq!(via_borrowed.as_ref(), via_as_ref);
4066            assert_eq!(via_borrowed.as_ref(), versao.as_bytes());
4067        }
4068    }
4069
4070    #[test]
4071    fn caixa_version_from_into_owned_rc_bytes_returns_wrapped_body() {
4072        // Fail-before-pass-after byte-parity pin on the lifted
4073        // `impl From<CaixaVersion> for std::rc::Rc<[u8]>` — asserts the
4074        // owned-input byte-owned reverse projection routes the wrapper's
4075        // own heap allocation through `std::rc::Rc::<[u8]>::from(v.0.into_bytes())`
4076        // verbatim (`String::into_bytes` is a niche-swap on the same buffer,
4077        // no re-copy; the [`std::rc::Rc<[u8]>`] layout then copies the bytes
4078        // once into a fresh single-threaded-refcounted heap slab whose
4079        // header carries the non-atomic strong + weak counters), so
4080        // `std::rc::Rc::<[u8]>::from(v)` returns the same bytes
4081        // `v.as_str().as_bytes()` borrows and round-trips byte-equal
4082        // through the paired forward [`From<String> for CaixaVersion`]
4083        // constructor after re-materializing the Rc-borrowed byte-tail
4084        // through [`String::from_utf8`] on every UTF-8-valid `:versao`
4085        // body (which every `SemVer`-shaped body is by construction).
4086        // Refuses any future silent detour that would swap
4087        // `Rc::<[u8]>::from(v.0.into_bytes())` for an allocating
4088        // `.as_str().as_bytes().to_vec().into::<Rc<[u8]>>()` cascade or
4089        // a routing through the sibling [`fmt::Display`] emitter.
4090        for versao in [
4091            "0.1.0",
4092            "1.2.3-alpha.1",
4093            "0.0.0",
4094            "",
4095            "^0.1",
4096            "*",
4097            "not-a-version",
4098            "1.2.3+build.42",
4099        ] {
4100            let v: CaixaVersion = versao.into();
4101            let expected: Vec<u8> = v.as_str().as_bytes().to_vec();
4102            let rc: std::rc::Rc<[u8]> = std::rc::Rc::<[u8]>::from(v.clone());
4103            assert_eq!(
4104                rc.as_ref(),
4105                expected.as_slice(),
4106                "Rc::<[u8]>::from(v) must return the wrapper's own bytes verbatim on {versao:?}",
4107            );
4108            assert_eq!(
4109                rc.as_ref(),
4110                versao.as_bytes(),
4111                "Rc::<[u8]>::from(v) must byte-equal the pre-lift wrapped \
4112                 String storage on round-trip through the From<&str> constructor",
4113            );
4114            // Round-trip witness through the paired forward constructor:
4115            // the emitted Rc-borrowed byte-tail rematerializes into a
4116            // [`Vec<u8>`] via `.to_vec()`, folds through
4117            // [`String::from_utf8`], and lands back on the same
4118            // [`CaixaVersion`] value via the paired
4119            // [`From<String> for CaixaVersion`] constructor — closing
4120            // the `Self → Rc<[u8]> → Vec<u8> → String → Self` round-trip
4121            // whenever the wrapped body is valid UTF-8.
4122            if let Ok(round) = String::from_utf8(rc.to_vec()) {
4123                let back: CaixaVersion = round.into();
4124                assert_eq!(back.as_str(), versao);
4125            }
4126        }
4127    }
4128
4129    #[test]
4130    fn caixa_version_from_into_owned_rc_bytes_and_arc_bytes_agree_on_every_shape() {
4131        // Fail-before-pass-after cross-axis partition pin: the owned-
4132        // input [`From<CaixaVersion> for std::rc::Rc<[u8]>`] byte-owned
4133        // reverse projection and the paired owned-input
4134        // [`From<CaixaVersion> for Vec<u8>`],
4135        // [`From<CaixaVersion> for Cow<'static, [u8]>`],
4136        // [`From<CaixaVersion> for Box<[u8]>`], and
4137        // [`From<CaixaVersion> for std::sync::Arc<[u8]>`] byte-owned
4138        // reverse projections resolve to the same bytes on every
4139        // instance, and all five agree with the pre-existing borrowed
4140        // [`AsRef<[u8]>`] byte-view axis on the same wrapped body.
4141        // Refuses any future silent split between the five owned-input
4142        // byte-owned reverse-projection axes.
4143        use std::borrow::Cow;
4144        use std::rc::Rc;
4145        use std::sync::Arc;
4146        for versao in [
4147            "0.1.0",
4148            "1.2.3-alpha.1",
4149            "0.0.0",
4150            "",
4151            "^0.1",
4152            "*",
4153            "not-a-version",
4154            "1.2.3+build.42",
4155        ] {
4156            let v: CaixaVersion = versao.into();
4157            let owned_vec: Vec<u8> = Vec::<u8>::from(v.clone());
4158            let owned_cow: Cow<'static, [u8]> = Cow::from(v.clone());
4159            let owned_box: Box<[u8]> = Box::<[u8]>::from(v.clone());
4160            let atomic_handle: Arc<[u8]> = Arc::<[u8]>::from(v.clone());
4161            let single_handle: Rc<[u8]> = Rc::<[u8]>::from(v.clone());
4162            let borrowed_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
4163            assert_eq!(single_handle.as_ref(), owned_vec.as_slice());
4164            assert_eq!(single_handle.as_ref(), owned_cow.as_ref());
4165            assert_eq!(single_handle.as_ref(), owned_box.as_ref());
4166            assert_eq!(single_handle.as_ref(), atomic_handle.as_ref());
4167            assert_eq!(single_handle.as_ref(), borrowed_as_ref);
4168            assert_eq!(single_handle.as_ref(), versao.as_bytes());
4169        }
4170    }
4171
4172    #[test]
4173    fn caixa_version_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor() {
4174        // Fail-before-pass-after byte-parity pin on the lifted
4175        // `impl From<&CaixaVersion> for std::rc::Rc<[u8]>` — asserts the
4176        // borrowed-input byte-owned reverse projection allocates a fresh
4177        // [`std::rc::Rc<[u8]>`] whose bytes byte-equal the substrate-
4178        // primitive [`CaixaVersion::as_str`] accessor's `.as_bytes()`
4179        // byte-tail on the same instance (via
4180        // [`std::rc::Rc::<[u8]>::from`]`(&[u8])`, which allocates a fresh
4181        // single-threaded-refcounted heap slab from the borrowed `&[u8]`
4182        // in one heap allocation without an intermediary [`Vec<u8>`] or
4183        // [`Box<[u8]>`]), preserving the source [`CaixaVersion`] intact
4184        // (no move-out). Refuses any future silent detour that would
4185        // route the impl through a divergent projection.
4186        for versao in [
4187            "0.1.0",
4188            "1.2.3-alpha.1",
4189            "0.0.0",
4190            "",
4191            "^0.1",
4192            "*",
4193            "not-a-version",
4194            "1.2.3+build.42",
4195        ] {
4196            let v: CaixaVersion = versao.into();
4197            let via_borrowed: std::rc::Rc<[u8]> = std::rc::Rc::<[u8]>::from(&v);
4198            assert_eq!(
4199                via_borrowed.as_ref(),
4200                v.as_str().as_bytes(),
4201                "Rc::<[u8]>::from(&v) must byte-equal CaixaVersion::as_str().as_bytes() \
4202                 on {versao:?} — divergence signals a silent detour off \
4203                 the substrate-primitive accessor",
4204            );
4205            // The borrowed-input impl must not move out of the source.
4206            assert_eq!(
4207                v.as_str(),
4208                versao,
4209                "source CaixaVersion must survive borrowed-input projection",
4210            );
4211        }
4212    }
4213
4214    #[test]
4215    fn caixa_version_from_owned_and_borrowed_into_rc_bytes_agree_on_every_shape() {
4216        // Fail-before-pass-after cross-corner partition pin: the paired
4217        // owned-input [`From<CaixaVersion> for std::rc::Rc<[u8]>`] and
4218        // borrowed-input [`From<&CaixaVersion> for std::rc::Rc<[u8]>`]
4219        // impls resolve to the same bytes on every instance, closing the
4220        // "owned-input move vs. borrowed-input clone" bifurcation on the
4221        // same wrapped body through the [`std::rc::Rc<[u8]>`] axis.
4222        for versao in [
4223            "0.1.0",
4224            "1.2.3-alpha.1",
4225            "0.0.0",
4226            "",
4227            "^0.1",
4228            "*",
4229            "not-a-version",
4230            "1.2.3+build.42",
4231        ] {
4232            let v: CaixaVersion = versao.into();
4233            let via_borrowed: std::rc::Rc<[u8]> = std::rc::Rc::<[u8]>::from(&v);
4234            let via_owned: std::rc::Rc<[u8]> = std::rc::Rc::<[u8]>::from(v.clone());
4235            let via_as_ref: &[u8] = <CaixaVersion as AsRef<[u8]>>::as_ref(&v);
4236            assert_eq!(via_owned.as_ref(), via_borrowed.as_ref());
4237            assert_eq!(via_borrowed.as_ref(), via_as_ref);
4238            assert_eq!(via_borrowed.as_ref(), versao.as_bytes());
4239        }
4240    }
4241}