Skip to main content

caixa_core/
supervisor.rs

1//! OTP-shaped supervisor trees, encoded as a typed `:kind Supervisor`
2//! caixa with a strategy + restart-policy children list.
3//!
4//! See `theory/INSPIRATIONS.md` §II.2 + §III.2 for the prior-art frame
5//! (Erlang OTP supervisor + Lunatic supervisor strategies as Rust types).
6//!
7//! ```lisp
8//! (defcaixa
9//!   :nome           "my-app-root"
10//!   :versao         "0.1.0"
11//!   :kind           Supervisor
12//!   :estrategia     OneForOne
13//!   :max-restarts   5
14//!   :restart-window "60s"
15//!   :children       ((:caixa "worker"       :versao "^0.1" :restart Permanent)
16//!                    (:caixa "cache-server" :versao "^0.1" :restart Transient)
17//!                    (:caixa "scratch-job"  :versao "^0.1" :restart Temporary)))
18//! ```
19//!
20//! wasm-operator (M3) walks the tree, materializes one ComputeUnit per
21//! child, and applies the strategy on child failure. The Rust types
22//! here are the typed contract; the runtime owns lifecycle.
23
24use std::time::Duration;
25
26use serde::{Deserialize, Serialize};
27use thiserror::Error;
28
29/// One of the four canonical Erlang/OTP restart strategies.
30///
31/// The strategy decides what happens to *sibling* children when one
32/// child dies. Per-child behaviour is governed by [`RestartPolicy`].
33#[derive(
34    Serialize,
35    Deserialize,
36    Debug,
37    Clone,
38    Copy,
39    PartialEq,
40    Eq,
41    Hash,
42    gen_platform::TypedDispatcher,
43    gen_platform::Discriminant,
44    gen_platform::IsVariant,
45    gen_platform::FromStrKind,
46)]
47pub enum RestartStrategy {
48    /// On child failure, restart only that child. Default; matches
49    /// most "tree of independent workers" use cases.
50    OneForOne,
51    /// On child failure, restart every child. Used when children
52    /// share state and must be in sync.
53    OneForAll,
54    /// On child failure, restart the failed child and every child
55    /// started *after* it (preserving startup order). Used when later
56    /// children depend on earlier ones.
57    RestForOne,
58    /// Dynamic children of the same shape, started on demand. The
59    /// supervisor doesn't know its children at boot; they're added as
60    /// they're needed (e.g. one child per session).
61    SimpleOneForOne,
62}
63
64impl Default for RestartStrategy {
65    fn default() -> Self {
66        // Route the [`Default for RestartStrategy`] impl through the
67        // substrate-canonical [`SUPERVISOR_ESTRATEGIA_DEFAULT`] typed
68        // `pub const` rather than a raw `Self::OneForOne` arm — one
69        // source of truth for the Erlang/OTP `one_for_one` half of Learn
70        // You Some Erlang's `{one_for_one, intensity, 5, 60}` worker-
71        // supervisor canonical default, paired with the sibling
72        // `SUPERVISOR_MAX_RESTARTS_DEFAULT` `MaxIntensity` half (b698ec0)
73        // and `SUPERVISOR_RESTART_WINDOW_DEFAULT` `Period` half (f7dcd0e).
74        // Pinned by `restart_strategy_default_routes_through_lifted_default`.
75        SUPERVISOR_ESTRATEGIA_DEFAULT
76    }
77}
78
79impl RestartStrategy {
80    /// Exhaustive iteration surface for every consumer that walks the
81    /// closed four-arm [`RestartStrategy`] discriminator set (the future
82    /// M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
83    /// admission-webhook rejection body naming the accepted-`:estrategia`
84    /// list, a future `feira supervisor --estrategia …` CLI arg-parse's
85    /// "did you mean" hint via a [`Self::from_wire`]-scan over the slice,
86    /// the future `feira app graph` per-supervisor `:estrategia` column,
87    /// any future round-trip fuzz harness that sweeps every arm). A
88    /// future arm addition (an OTP-`rest_for_all` arm the theory
89    /// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
90    /// might reach for once the four canonical OTP strategies stop
91    /// covering the substrate's discovered load-shape) extends this
92    /// slice as one edit and every consumer picks up the new entry by
93    /// construction; the compiler-checked exhaustiveness on the sibling
94    /// method `match` arms ([`Self::as_str`] / [`Self::from_wire`]) is
95    /// the build-time guarantee that no arm forgets to grow.
96    ///
97    /// Peer of the sibling closed-set typed enums'
98    /// [`crate::CaixaKind::ALL`] (6b1f4fb) /
99    /// [`crate::aplicacao::PlacementStrategy::ALL`] (18c7342) /
100    /// [`crate::aplicacao::RateLimitUnit::ALL`] (6bce03d) /
101    /// [`crate::dep::DepList::ALL`] (45ee563) exhaustive-iteration
102    /// surfaces — the fifth (and the first M2 OTP-shape) closed-set
103    /// typed enum on the caixa surface to converge onto the same
104    /// one-canonical-arm-list-per-enum discipline.
105    pub const ALL: &'static [Self] = &[
106        Self::OneForOne,
107        Self::OneForAll,
108        Self::RestForOne,
109        Self::SimpleOneForOne,
110    ];
111
112    /// Substrate-canonical exhaustive accept-set on the
113    /// [`RestartStrategy`] `PascalCase` wire byte-string axis — the
114    /// closed four-arm roster of every byte-string [`Self::as_str`]
115    /// returns, routed byte-for-byte through the paired
116    /// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
117    /// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
118    /// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
119    /// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`]
120    /// lifted `pub const` roster the [`Self::as_str`] emitter (and the
121    /// [`std::fmt::Display`] / [`AsRef<str>`] /
122    /// `From<{Self,&Self}> for {&'static str, String, Cow<'static, str>,
123    /// Box<str>, Arc<str>}` trait triple + quintuple routed through it)
124    /// walks — and byte-for-byte the same four strings the un-`rename`d
125    /// `Serialize` derive emits under the paired
126    /// [`crate::render::SUPERVISOR_KEY_ESTRATEGIA`] tag key on every
127    /// JSON / YAML CR round-trip.
128    ///
129    /// Peer of the sibling [`crate::CaixaKind::WIRE_NAMES`] (bd708bd)
130    /// roster on the top-level typed-kind discriminator's `PascalCase`
131    /// wire byte-string axis, and of the sibling
132    /// [`crate::upgrade::UpgradeInstruction::WIRE_FORMS`] (cc42c0e) /
133    /// [`crate::upgrade::UpgradeInstruction::LISP_FORMS`] (1898d77)
134    /// rosters on the OTP-appup discriminator's two-axis roster split —
135    /// the same closed-set exhaustive-accept-set roster discipline
136    /// extended here onto the first M2 OTP-shape sibling-restart
137    /// closed-set typed enum. The sibling
138    /// [`crate::aplicacao::PlacementStrategy`] M3 mesh-shape distribution
139    /// strategy enum is the next natural peer on the same axis, still
140    /// carrying only [`crate::aplicacao::PlacementStrategy::ALL`].
141    ///
142    /// Downstream consumers of the closed accepted-wire-form set — a
143    /// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook
144    /// rejection body enumerating the accepted JSON `:estrategia` values
145    /// verbatim (as distinct from the kebab-case dispatcher-catalog
146    /// enumeration [`Self::discriminant`] serves, whose per-arm form
147    /// `"one-for-one"` / `"one-for-all"` / `"rest-for-one"` /
148    /// `"simple-one-for-one"` structurally disagrees with the wire byte-
149    /// string these `PascalCase` entries carry), a future `feira
150    /// supervisor --estrategia …` CLI-side "did you mean" hint whose
151    /// candidate-list must byte-match the wire form the operator's
152    /// per-strategy dispatch keys off (rather than the kebab
153    /// dispatcher-catalog identity), a future `feira app graph`
154    /// per-supervisor `:estrategia`-histogram column that renders
155    /// zero-count arms, a future wasm-operator per-reconcile-step
156    /// diagnostic log line enumerating accepted wire forms on an
157    /// unknown-strategy rejection, a future
158    /// `tracing::field::valuable::Value::List` structured-log accepted-
159    /// wire-form emit — now reach for one lifted substrate-primitive
160    /// roster rather than open-coding a four-string array-literal
161    /// (`["OneForOne", "OneForAll", "RestForOne", "SimpleOneForOne"]`)
162    /// whose arm-set has no compile-time link back to the typed
163    /// [`RestartStrategy`] enum. A future arm addition (an OTP-`rest_for_all`
164    /// arm the theory
165    /// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
166    /// might reach for once the four canonical OTP strategies stop
167    /// covering the substrate's discovered load-shape) extends this
168    /// roster as a single edit — paired with the [`Self::as_str`]
169    /// match's compiler-checked exhaustiveness on the new arm — and
170    /// every consumer picks up the new wire form by construction rather
171    /// than a coordinated array-literal rewrite across every downstream
172    /// site.
173    ///
174    /// Length is pinned load-bearing at `RestartStrategy::ALL.len()`
175    /// (four) by
176    /// [`tests::restart_strategy_wire_names_covers_every_arm`], every
177    /// variant's [`Self::as_str`] projection is pinned to a member of
178    /// the roster so a silent skew between the emitter's arm-set and
179    /// this const's arm-set trips at caixa-core test time rather than
180    /// at a downstream consumer's accepted-set enumeration miss, and
181    /// every entry is further pinned to open with an ASCII uppercase
182    /// byte so a silent collapse of the wire-form axis with the peer
183    /// kebab-case dispatcher-catalog axis (an entry byte-identical to a
184    /// sibling [`Self::discriminant`] kebab byte-string that would let
185    /// a wire-axis consumer accept the dispatcher-catalog vocabulary)
186    /// trips here rather than at a downstream K8s-CR round-trip miss.
187    pub const WIRE_NAMES: &'static [&'static str] = &[
188        crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
189        crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
190        crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
191        crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
192    ];
193
194    /// Canonical PascalCase discriminator scalar this variant serializes
195    /// as under [`crate::render::SUPERVISOR_KEY_ESTRATEGIA`]. The four arms
196    /// return the paired [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`]
197    /// / [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
198    /// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
199    /// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] lifted
200    /// constants so every substrate consumer that dispatches on the
201    /// per-supervisor sibling-restart strategy (the future
202    /// wasm-operator's per-supervisor sibling-restart branch, the future
203    /// M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
204    /// admission-time enum-arm bind, the `caixa-operator`'s hierarchical
205    /// reconciliation scheduler's per-strategy fan-out) reads the same
206    /// byte-string the `Serialize` derive emits — the pin test in
207    /// [`tests::restart_strategy_variants_serialize_to_lifted_scalar_values`]
208    /// asserts the two paths agree, peer of the M3
209    /// `PlacementStrategy::as_str` (cc8f749) on the sibling per-Aplicacao
210    /// distribution-strategy axis.
211    #[must_use]
212    pub const fn as_str(self) -> &'static str {
213        match self {
214            Self::OneForOne => crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
215            Self::OneForAll => crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
216            Self::RestForOne => crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
217            Self::SimpleOneForOne => crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
218        }
219    }
220
221    /// Substrate-canonical reverse projection on the `:supervisor
222    /// :estrategia` closed-set axis — parses the `PascalCase`
223    /// discriminator scalar back to the typed variant, or `None` when
224    /// `s` is outside
225    /// the closed-set arm-string set [`Self::as_str`] emits. Dispatches
226    /// on the same lifted
227    /// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
228    /// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
229    /// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
230    /// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`]
231    /// constants the [`Self::as_str`] emitter walks, so the parse and
232    /// emit halves of the round-trip migrate through one caixa-core
233    /// edit on any future arm addition.
234    ///
235    /// Prior to this lift the substrate carried only the forward
236    /// `Self → &str` projection on the OTP sibling-restart axis (the
237    /// [`Self::as_str`] emitter, the [`std::fmt::Display`] impl routed
238    /// through it, the `Serialize` derive that emits the same
239    /// byte-string under [`crate::render::SUPERVISOR_KEY_ESTRATEGIA`])
240    /// plus the kebab-case dispatcher-catalog identity via
241    /// [`Self::discriminant`] — every non-serde consumer that wanted to
242    /// parse a wire-form `PascalCase` strategy scalar had to re-inline
243    /// a four-arm `match s { "OneForOne" => …, "OneForAll" => …,
244    /// "RestForOne" => …, "SimpleOneForOne" => …, _ => … }` cascade
245    /// that expressed no compile-time link back to the typed variant's
246    /// canonical lifted constant. A future variant rename or per-arm
247    /// serde-attribute drift would silently split the wire byte-string
248    /// one non-serde consumer parsed from the one the emitter wrote,
249    /// with the failure surfacing at parse time far from the rebrand
250    /// commit.
251    ///
252    /// Distinct axis from the [`std::str::FromStr`] impl the
253    /// [`gen_platform::FromStrKind`] derive already installs on this
254    /// enum by design, not by drift: `FromStr` parses the *kebab-case*
255    /// dispatcher-catalog identity (`"one-for-one"` / `"one-for-all"` /
256    /// `"rest-for-one"` / `"simple-one-for-one"` — the inverse of
257    /// [`Self::discriminant`]), while this method inverts the
258    /// `PascalCase` wire byte-string [`Self::as_str`] emits. The
259    /// two-axis split lets the dispatcher-catalog identity live in
260    /// kebab-case
261    /// (where every peer catalog identifier already lives) without
262    /// forcing a wire-format rename on the tatara-lisp author surface
263    /// (`:estrategia OneForOne`, `PascalCase`) — the same two-axis
264    /// distinction the sibling [`crate::CaixaKind::from_wire`] (2aa6d23)
265    /// / [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342)
266    /// carry on their peer closed-set typed-enum wire round-trips.
267    ///
268    /// Same closed-set-reverse-projection discipline the sibling
269    /// [`crate::CaixaKind::from_wire`] (2aa6d23) /
270    /// [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342) /
271    /// [`crate::aplicacao::RateLimitUnit::from_suffix`] typed enums
272    /// carry on the peer wire-side `str → Self` axes — extended onto
273    /// the M2 OTP-shape sibling-restart-strategy closed-set axis, the
274    /// fifth substrate-side closed-set typed enum to converge on the
275    /// two-way `str ↔ Self` round-trip. Method-named `from_wire` (not
276    /// `from_str`) to match the peer [`crate::CaixaKind::from_wire`]
277    /// shape verbatim and side-step the [`std::str::FromStr`] impl the
278    /// derive already installs on the sibling kebab-case axis. Returns
279    /// `Option<Self>` (rather than `Result<Self, _>`) to match the peer
280    /// shapes: the caller picks the diagnostic form appropriate for
281    /// its use site.
282    #[must_use]
283    pub fn from_wire(s: &str) -> Option<Self> {
284        match s {
285            crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE => Some(Self::OneForOne),
286            crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL => Some(Self::OneForAll),
287            crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE => Some(Self::RestForOne),
288            crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE => Some(Self::SimpleOneForOne),
289            _ => None,
290        }
291    }
292}
293
294/// [`std::fmt::Display`] routed through [`RestartStrategy::as_str`], so the
295/// pretty-printed byte-string every consumer that formats the strategy as
296/// user-facing text lands on (the future wasm-operator's per-supervisor
297/// sibling-restart-strategy diagnostic line, the future `feira app graph`
298/// per-supervisor strategy line, the future M4
299/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission-webhook
300/// rejection body) reaches for the same lifted
301/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
302/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
303/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
304/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const the
305/// wire-format `Serialize` derive already emits under
306/// [`crate::render::SUPERVISOR_KEY_ESTRATEGIA`] and the
307/// [`RestartStrategy::as_str`] helper already returns.
308///
309/// Pre-convergence the two paths structurally disagreed — the
310/// `#[derive(gen_platform::Discriminant)]` + `#[discriminant(also_display)]`
311/// route (now retired here) sent [`std::fmt::Display`] through the
312/// gen-platform discriminant catalog string, which arrives kebab-case as
313/// `"one-for-one"` / `"one-for-all"` / `"rest-for-one"` /
314/// `"simple-one-for-one"`, while the wire format ran as `PascalCase`
315/// `"OneForOne"` / `"OneForAll"` / `"RestForOne"` / `"SimpleOneForOne"`
316/// through the un-`rename`d serde derive. Every consumer that formatted
317/// the strategy for a diagnostic line, a graph, or a rejection body under
318/// `format!("{v}")` therefore landed under a different byte-string than
319/// the wire format the operator's per-strategy dispatch keyed off — a
320/// silent split whose apply-time symptom (a `format!("{v}")`-carrying
321/// diagnostic quoting `"one-for-one"` while the wire scalar the operator
322/// probed was `"OneForOne"`) surfaced as a confused correlate at
323/// operator-log time far from the two-declaration site.
324///
325/// Routing `Display` through [`RestartStrategy::as_str`] closes the third
326/// path: every `format!("{v}")` call reaches the same lifted
327/// [`crate::render::SUPERVISOR_ESTRATEGIA_*`] const the wire format and
328/// the [`RestartStrategy::as_str`] helper route through — `Debug` (the
329/// compiler-derived variant name), `Display` (via `as_str`), and `Serialize`
330/// (via the un-`rename`d derive) all resolve to the same `PascalCase`
331/// byte-string per variant. A future variant rename or
332/// `#[serde(rename_all = "kebab-case")]` attribute reaches every path at
333/// exactly one place, structurally.
334///
335/// The dispatcher-catalog identity remains kebab-case — [`Self::discriminant`]
336/// (from `#[derive(gen_platform::Discriminant)]`) still returns
337/// `"one-for-one"` / etc., and the fleet-wide
338/// [`gen_platform::register_dispatcher!("caixa.restart-strategy", …)`]
339/// registration keys the catalog off the same kebab identity. The two
340/// naming worlds now live on separate typed methods (`Display` /
341/// `as_str` for the wire byte-string, `discriminant` for the catalog
342/// identity) rather than sharing one `Display` route that structurally
343/// disagrees with the wire format.
344///
345/// Pin tests
346/// [`tests::restart_strategy_display_routes_through_as_str_helper`]
347/// and
348/// [`tests::restart_strategy_display_matches_serialized_wire_byte_string`]
349/// assert the three paths agree byte-for-byte on every variant, so a
350/// future variant rename or per-arm serde attribute drift is a build
351/// error visible at caixa-core test time, not a silent per-consumer
352/// dispatch miss at apply / reconcile time.
353///
354/// Mirrors the M3 [`crate::aplicacao::PlacementStrategy`] `Display` impl
355/// (aplicacao.rs:2306) on the sibling per-Aplicacao distribution-strategy
356/// axis — same three-path-convergence discipline, extended to close the
357/// second of three OTP-shaped closed-enum discriminator axes on the
358/// caixa typed surface.
359impl std::fmt::Display for RestartStrategy {
360    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
361        f.write_str(self.as_str())
362    }
363}
364
365/// Substrate-canonical [`AsRef<str>`] projection on the M2
366/// per-supervisor sibling-restart [`RestartStrategy`] closed-set typed
367/// enum — routes through the same [`RestartStrategy::as_str`]
368/// `pub const fn` scalar accessor the paired [`std::fmt::Display`]
369/// impl and the un-`rename`d [`serde::Serialize`] derive already key
370/// off, so any future consumer that binds a [`RestartStrategy`]
371/// through the standard-library `impl AsRef<str>` bound (a future
372/// [`caixa-feira`] `feira supervisor --estrategia <arm>` verb that
373/// composes the emitted `PascalCase` wire scalar into a
374/// [`std::process::Command::arg`] shell-out of the future
375/// wasm-operator's admission gate, a per-supervisor structured-log
376/// recorder on the future `caixa-operator`'s hierarchical
377/// reconciliation surface that accepts `impl AsRef<str>` at the
378/// `tracing::field::Value` `Str`-arm, a [`std::collections::HashMap`]
379/// lookup keyed on the estrategia wire byte through
380/// `map.get::<str>(strategy.as_ref())` on a future per-strategy
381/// dispatch table) reaches the paired [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`]
382/// / [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
383/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
384/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`]
385/// lifted-const through one substrate-primitive dispatch rather
386/// than an open-coded `.as_str()` projection at every wire-up.
387///
388/// Peer of the sibling [`std::fmt::Display`] impl on the same
389/// primitive — both delegate to the shared
390/// [`RestartStrategy::as_str`] `pub const fn` accessor, so
391/// [`format!("{s}")`], `s.as_str()`, and
392/// `<RestartStrategy as AsRef<str>>::as_ref(&s)` resolve to the same
393/// byte-string per instance by construction. A future variant rename
394/// or `#[serde(rename_all = "kebab-case")]` attribute-drift on the
395/// enum reaches every one of the three paths (plus the wire-format
396/// `Serialize` derive that already routes through the same lifted
397/// const) through exactly one caixa-core edit.
398///
399/// Same "route the trait impl through the substrate-primitive
400/// accessor" discipline the sibling [`crate::CaixaVersion`]
401/// [`AsRef<str>`] impl (16d5c7e) carries on the paired top-level
402/// `:versao` typed newtype — extends it onto the second `AsRef<str>`
403/// axis on the caixa typed surface (the first M2 OTP-shape
404/// closed-set typed enum to converge onto the standard-library
405/// [`AsRef<str>`] projection). Rust-side newtype/typed-enum
406/// convention pairs [`AsRef<str>`] and [`fmt::Display`] on the same
407/// primitive so a caller who has one has both; before this lift,
408/// [`RestartStrategy`] carried [`fmt::Display`] but not the paired
409/// [`AsRef<str>`] impl the convention names.
410///
411/// Pinned load-bearing by
412/// [`tests::restart_strategy_as_ref_str_routes_through_as_str_accessor`]
413/// (byte-parity pin against [`RestartStrategy::as_str`] across the
414/// four-arm closed set) — any future silent detour that routes the
415/// impl through a divergent projection (a per-arm inline
416/// `match self { … }` re-inlining that opens a compile-time link to
417/// the un-lifted arm-literal, a swap onto the kebab-case
418/// [`gen_platform::Discriminant`] catalog identity that would collide
419/// the wire axis with the dispatcher-catalog axis) trips at
420/// caixa-core test time under `assert_eq!` rather than at a
421/// downstream `impl AsRef<str>`-bound consumer's silent split.
422impl AsRef<str> for RestartStrategy {
423    fn as_ref(&self) -> &str {
424        self.as_str()
425    }
426}
427
428/// Trait-idiomatic reverse projection on the M2-OTP-shape sibling-restart
429/// [`RestartStrategy`] closed-set typed enum — routes byte-for-byte through
430/// the paired substrate-primitive [`RestartStrategy::from_wire`]
431/// `Option<Self>` accessor so every future consumer that binds a
432/// `PascalCase` `:supervisor :estrategia` wire byte-string through the
433/// standard-library `.try_into()` / [`TryFrom`] axis (a future
434/// [`caixa-feira`] `feira supervisor --estrategia <OneForOne|OneForAll|
435/// RestForOne|SimpleOneForOne>` CLI arg-parse that composes into
436/// `let estrategia: RestartStrategy = s.try_into()?`, a future
437/// `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook that folds a
438/// `spec.estrategia: String` field through
439/// `RestartStrategy::try_from(&s)?`, a generic
440/// `<T: TryFrom<&str>>`-bound loader over any of the substrate's closed-
441/// set typed enums) reaches the same four-arm accept-set the sibling
442/// [`RestartStrategy::from_wire`] resolver parses through and the sibling
443/// [`RestartStrategy::as_str`] emits, rather than an open-coded per-arm
444/// `match s { "OneForOne" => …, "OneForAll" => …, "RestForOne" => …,
445/// "SimpleOneForOne" => …, _ => … }` cascade whose arm-set has no
446/// compile-time link back to the substrate primitive.
447///
448/// Complements the pre-existing forward-projection triple
449/// ([`std::fmt::Display`], [`AsRef<str>`], [`RestartStrategy::as_str`])
450/// with the paired trait-idiomatic reverse-projection axis: Rust-side
451/// newtype/typed-enum convention pairs [`AsRef<str>`] with either
452/// [`std::str::FromStr`] or [`TryFrom<&str>`] on the same primitive so a
453/// caller who can project *out to* a `&str` can also project *in from*
454/// one. The [`TryFrom<&str>`] axis is deliberately chosen over
455/// [`std::str::FromStr`] to sidestep the `clippy::should_implement_trait`
456/// lint the sibling method-named [`RestartStrategy::from_wire`] would
457/// trigger under a `FromStr` impl and to avoid colliding with the
458/// [`std::str::FromStr`] impl the [`gen_platform::FromStrKind`] derive
459/// already installs on the paired *kebab-case dispatcher-catalog* axis
460/// (which parses `"one-for-one"` / `"one-for-all"` / `"rest-for-one"` /
461/// `"simple-one-for-one"`, the inverse of [`Self::discriminant`]) — this
462/// impl closes the trait-idiomatic reverse axis on the *`PascalCase` wire*
463/// half without disturbing either the method-named `from_wire` shape every
464/// sibling closed-set typed enum on the substrate already carries or the
465/// pre-existing `FromStr` on the dispatcher-catalog half, keeping the
466/// two-axis split the sibling [`Self::from_wire`] doc block motivates.
467///
468/// `type Error = ()` matches the sibling [`RestartStrategy::from_wire`]'s
469/// `Option<Self>` return-shape's deliberate deferral of error typing: the
470/// caller picks the diagnostic form appropriate for its use site (a future
471/// `feira supervisor --estrategia` arg-parse composes its own per-verb
472/// "unknown strategy: <arg> — accepted: {…}" message enumerating
473/// [`RestartStrategy::ALL`], a future M4 admission-webhook rejection body
474/// wraps the `Err(())` outcome with the accepted-set enumeration for
475/// operator diagnostics, a `Result::map_err` at the call site lifts the
476/// unit-error to a per-verb error type). Same shape the peer
477/// [`crate::CaixaKind`] (3c83606), [`crate::CaixaDialeto`] (bf33136),
478/// [`crate::aplicacao::PlacementStrategy`] (6fd00cd), and
479/// [`crate::provedor::ferrite::FerriteRuntime::from_wire`] blocks motivate
480/// on their peer closed-set typed enums' reverse projections.
481///
482/// The paired [`TryFrom<&str>`] impl reaches the same four-arm accept-set
483/// the [`RestartStrategy::from_wire`] resolver dispatches through, so any
484/// future arm addition (an OTP-`rest_for_all` fifth arm the theory
485/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
486/// might reach for once the four canonical OTP strategies stop covering
487/// the substrate's discovered load-shape) grows the trait-idiomatic axis
488/// by construction — one caixa-core edit on
489/// [`RestartStrategy::from_wire`] extends both the method-named reverse
490/// projection every existing consumer keys off and the trait-idiomatic
491/// reverse projection this impl exposes, without a coordinated rewrite
492/// across every future `TryFrom<&str>`-bound consumer's arm-set.
493///
494/// Extends the substrate-wide closed-set-enum reverse-projection family
495/// ([`crate::CaixaKind`] via 3c83606, [`crate::CaixaDialeto`] via bf33136,
496/// [`crate::aplicacao::PlacementStrategy`] via 6fd00cd) onto the first
497/// M2-OTP-shape closed-set typed enum on the caixa surface — the
498/// `:supervisor :estrategia` closed set the future wasm-operator's
499/// hierarchical reconciliation scheduler keys off end-to-end.
500///
501/// Pinned load-bearing by
502/// [`tests::restart_strategy_try_from_str_routes_through_from_wire_accessor`]
503/// (byte-parity pin against [`RestartStrategy::from_wire`] across the
504/// four-arm accept-set) and
505/// [`tests::restart_strategy_try_from_str_rejects_unknown_byte_strings`]
506/// (rejection witness against silent accept-set widening).
507impl TryFrom<&str> for RestartStrategy {
508    type Error = ();
509
510    fn try_from(s: &str) -> Result<Self, Self::Error> {
511        Self::from_wire(s).ok_or(())
512    }
513}
514
515/// Trait-idiomatic *forward* projection on the M2-OTP-shape sibling-restart
516/// [`RestartStrategy`] closed-set typed enum onto the `&'static str` axis —
517/// routes byte-for-byte through the paired substrate-primitive
518/// [`RestartStrategy::as_str`] `pub const fn` accessor so every future
519/// consumer that binds a [`RestartStrategy`] through the standard-library
520/// `.into()` / [`From<Self> for &'static str`] (equivalently
521/// [`Into<&'static str>`]) axis (a future
522/// `tracing::field::valuable::Value::Str(strategy.into())` structured-log
523/// recorder where the `Str` arm typing demands `&'static str` and the
524/// sibling [`AsRef<str>`] impl's borrowed `&str` return-type does not
525/// satisfy the bound, a future `Cow::Borrowed::<'static, str>(strategy.into())`
526/// composer on the future M4 admission-webhook rejection body where the
527/// `Cow<'static, str>` typing rules out the sibling [`AsRef<str>`] borrowed
528/// return, a generic `<T: Into<&'static str>>`-bound serializer on a
529/// per-strategy diagnostic column) reaches the same lifted
530/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
531/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
532/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
533/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const the
534/// paired [`std::fmt::Display`], [`AsRef<str>`], and
535/// [`RestartStrategy::as_str`] surfaces already return, rather than an
536/// open-coded per-arm `match s { OneForOne => "OneForOne", … }` cascade
537/// whose arm-set has no compile-time link back to the substrate primitive.
538///
539/// Complements the pre-existing quadruple
540/// ([`std::fmt::Display`], [`AsRef<str>`], [`RestartStrategy::as_str`],
541/// [`TryFrom<&str>`] via 5b828ed) with the paired trait-idiomatic
542/// forward-projection axis: Rust-side newtype/typed-enum convention pairs
543/// [`TryFrom<&str>`] (trait-idiomatic reverse) with [`From<Self> for
544/// &'static str`] (trait-idiomatic forward) on the same primitive so a
545/// caller who can project *in from* a `&str` via the trait axis can also
546/// project *out to* one — mirroring the `strum::IntoStaticStr` /
547/// `serde::Serialize`-shape idiom where both projection halves share one
548/// trait-driven vocabulary. Before this lift the substrate carried a
549/// `&str`-returning [`AsRef<str>`] but not the paired `&'static str`-
550/// returning [`From<Self> for &'static str`] axis every downstream
551/// generic that specifically needs `'static` byte-string bytes reaches for.
552///
553/// The paired [`RestartStrategy::as_str`] returns `&'static str` by
554/// construction (each `match` arm resolves to a
555/// [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &str` with static
556/// lifetime), so the trait's return-type promise is upheld structurally.
557/// Any future silent detour that routes the impl through a non-static
558/// projection (a per-arm inline `String::from("OneForOne")`-shaped
559/// re-inlining that would `.leak()`-cast for the `'static` bound, a
560/// hypothetical rebrand of one arm's [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
561/// const to a non-`const &str`) is a caixa-core-build-time failure through
562/// the `pub const fn as_str` signature the trait routes through.
563///
564/// The paired impl reaches the same four-arm emit-set the
565/// [`RestartStrategy::as_str`] accessor dispatches through, so any future
566/// arm addition (an OTP-`rest_for_all` fifth arm the theory
567/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
568/// might reach for once the four canonical OTP strategies stop covering
569/// the substrate's discovered load-shape) grows the trait-idiomatic
570/// forward axis by construction — one caixa-core edit on
571/// [`RestartStrategy::as_str`] extends every one of the five sibling
572/// forward-projection paths ([`std::fmt::Display`], [`AsRef<str>`],
573/// [`RestartStrategy::as_str`] itself, this [`From<Self> for &'static str`],
574/// and the un-`rename`d [`serde::Serialize`] derive that also emits
575/// [`Self::as_str`]'s bytes) without a coordinated rewrite across every
576/// future `Into<&'static str>`-bound consumer's arm-set.
577///
578/// Opens the substrate-wide trait-idiomatic *forward*-projection family on
579/// closed-set fieldless typed enums — the mirror of the recently-closed
580/// trait-idiomatic *reverse*-projection family ([`crate::CaixaKind`] via
581/// 3c83606, [`crate::CaixaDialeto`] via bf33136,
582/// [`crate::aplicacao::PlacementStrategy`] via 6fd00cd, this enum via
583/// 5b828ed, [`crate::supervisor::RestartPolicy`] via 6fdd0d9,
584/// [`crate::aplicacao::WitShape`] via 5472902,
585/// [`crate::aplicacao::RateLimitUnit`] via bf78400,
586/// [`crate::render::PathShapeViolation`] via e67e48a, and the four
587/// downstream-crate peers — [`caixa_arch::InvariantKind`] via e21a857,
588/// [`caixa_arch::ArchVerdict`] via 0a4cc45, [`caixa_lint::Severity`] via
589/// a7bf74c, [`caixa_lint::FixSafety`] via df86c94,
590/// [`caixa_theme::Semantic`] via bd7da69, and
591/// [`caixa_provedor::ferrite::FerriteRuntime`] via 42ab951). This lift
592/// picks [`RestartStrategy`] as the first-mover on the forward-projection
593/// family because its wire byte-string (`PascalCase`) and diagnostic
594/// byte-string ([`as_str`] return) coincide by construction — the sibling
595/// [`crate::CaixaKind`] two-axis split (lowercase Portuguese diagnostic
596/// vs `PascalCase` wire) would leave a first-mover peer arbitrarily
597/// picking one axis; on [`RestartStrategy`] the choice is unambiguous.
598///
599/// Pinned load-bearing by
600/// [`tests::restart_strategy_from_into_static_str_routes_through_as_str_accessor`]
601/// (byte-parity pin against [`RestartStrategy::as_str`] across the
602/// four-arm emit-set, plus a `const`-context materialization witness for
603/// the `&'static str` lifetime promise) and
604/// [`tests::restart_strategy_from_into_static_str_and_as_str_partition_the_emit_set`]
605/// (partition pin asserting `<&'static str as From<RestartStrategy>>::from`
606/// and [`RestartStrategy::as_str`] agree on every arm, so no future
607/// silent bifurcation of the two forward-projection paths can land
608/// silently).
609impl From<RestartStrategy> for &'static str {
610    fn from(strategy: RestartStrategy) -> &'static str {
611        strategy.as_str()
612    }
613}
614
615/// Trait-idiomatic *forward* projection on [`RestartStrategy`] from a
616/// *borrowed* input onto the `&'static str` axis — the borrowed-input
617/// companion to the paired owned-input [`From<RestartStrategy> for
618/// &'static str`] impl immediately above. Routes byte-for-byte through
619/// the same substrate-primitive [`RestartStrategy::as_str`] `pub const
620/// fn` accessor so every consumer that binds a `&RestartStrategy`
621/// through the standard-library `.into()` / [`From<&Self> for &'static
622/// str`] axis (a `RestartStrategy::ALL.iter().map(<&'static
623/// str>::from).collect::<Vec<_>>()` per-arm accept-set materializer —
624/// whose iterator over `&'static [RestartStrategy]` yields
625/// `&RestartStrategy`, not `RestartStrategy`, so the owned-input
626/// [`From<RestartStrategy>`] axis alone forces every call site through
627/// an explicit `.copied()` / dereference / [`Copy`]-bound restatement
628/// rather than the direct trait-idiomatic projection; a future generic
629/// `<T: Copy + for<'a> Into<&'static str>>`-bound diagnostic column
630/// that walks the `iter().map(Into::into)` shape verbatim across every
631/// substrate-wide closed-set typed enum; the future wasm-operator's
632/// per-supervisor sibling-restart-strategy diagnostic line that
633/// composes the accepted-set enumeration from an iterated
634/// `RestartStrategy::ALL.iter().map(|s| s.into())` pipe rather than a
635/// per-arm `match s { … }` cascade; a future
636/// `HashMap::<&'static str, RestartStrategy>::from_iter(
637///     RestartStrategy::ALL.iter().map(|s| (s.into(), *s)))`-style
638/// per-strategy reverse-lookup table the sibling [`TryFrom<&str>`]
639/// impl cannot compose without this borrowed-input axis in place)
640/// reaches the same four-arm lifted
641/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
642/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
643/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
644/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
645/// the paired owned-input [`From<RestartStrategy> for &'static str`],
646/// the sibling [`std::fmt::Display`], [`AsRef<str>`], and
647/// [`RestartStrategy::as_str`] surfaces already return.
648///
649/// Fourth peer on the substrate-wide trait-idiomatic *borrowed-input*
650/// forward-projection family opened on [`crate::dep::DepList`]
651/// (64aa742) and extended onto [`crate::CaixaKind`] (5ab993a) and
652/// [`crate::CaixaDialeto`] (807b0b5). Rust's `From` trait does not
653/// auto-derive the `From<&Self>` sibling from a `From<Self>` impl (the
654/// blanket `impl<T, U> From<&T> for U where T: Copy, U: From<T>` does
655/// not exist in `core`), so every closed-set typed enum that carries
656/// the owned-input axis but not the borrowed-input axis forces every
657/// borrowed-input call site through a `.copied()` /
658/// `<&'static str>::from(*strategy)` / `strategy.as_str()` detour whose
659/// type bounds have no compile-time link to the substrate primitive.
660/// [`RestartStrategy`] is the first M2 OTP-shape peer to converge onto
661/// this campaign (mirroring the first-mover role it played on the
662/// owned-input axis in 523157d); the remaining eleven substrate-wide
663/// closed-set fieldless typed enum peers (`RestartPolicy`, `WitShape`,
664/// `RateLimitUnit`, `PlacementStrategy`, `PathShapeViolation`,
665/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`, `Semantic`,
666/// `FerriteRuntime`) are the future targets of this campaign.
667///
668/// Unlike the peer [`crate::CaixaKind`] axis pair (whose forward
669/// [`From<Self> for &'static str`] emits the lowercase Portuguese
670/// [`Self::as_str`] diagnostic vocabulary while the reverse
671/// [`TryFrom<&str>`] parses the `PascalCase` [`Self::wire_name`]
672/// author-surface vocabulary, forcing the round-trip through an
673/// intermediate wire-vocab hop), [`RestartStrategy`]'s
674/// [`Self::as_str`] emit and [`Self::from_wire`] parse share the same
675/// `PascalCase` vocabulary by construction, so the borrowed-input
676/// forward axis and the reverse axis compose directly — the round-trip
677/// witness pin below locks this direct composition without the
678/// intermediate hop the peer axis requires.
679///
680/// Pinned load-bearing by
681/// [`tests::restart_strategy_from_borrowed_into_static_str_routes_through_as_str_accessor`]
682/// (byte-parity pin against [`RestartStrategy::as_str`] across the
683/// four-arm emit-set via a borrowed input, plus a `const`-context
684/// materialization witness for the `&'static str` lifetime promise,
685/// plus a blanket `.into()` shape) and
686/// [`tests::restart_strategy_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
687/// (cross-axis partition pin against the paired owned-input
688/// [`From<RestartStrategy> for &'static str`] impl, plus a
689/// `.iter().map(Into::into)` pipe witness over
690/// [`RestartStrategy::ALL`], plus a direct round-trip witness through
691/// [`TryFrom<&str>`] that closes the two-way `&Self → &'static str →
692/// Self` round-trip without the wire-vocab intermediate the peer
693/// [`crate::CaixaKind`] axis pair requires).
694impl From<&RestartStrategy> for &'static str {
695    fn from(strategy: &RestartStrategy) -> &'static str {
696        strategy.as_str()
697    }
698}
699
700/// Trait-idiomatic *owned-`String`* forward projection on the M2
701/// OTP-shape sibling-restart-strategy closed-set typed enum — the
702/// owned-heap-string companion to the paired `&'static str`-returning
703/// [`From<RestartStrategy> for &'static str`] / [`From<&RestartStrategy>
704/// for &'static str`] impls immediately above. Routes byte-for-byte
705/// through the substrate-primitive [`RestartStrategy::as_str`]
706/// `pub const fn` accessor (via [`str::to_owned`]) so every consumer
707/// that binds a [`RestartStrategy`] through the standard-library
708/// `.into()` / [`From<Self> for String`] (equivalently
709/// [`Into<String>`]) axis — a future
710/// `serde_json::Value::String(strategy.into())` structured-payload
711/// composer where the `Value::String` arm typing demands an owned
712/// [`String`] and the sibling [`&'static str`]-returning axis forces an
713/// explicit `.to_owned()` / `String::from` restatement at every call
714/// site, a future
715/// `HashMap::<String, RestartStrategy>::from_iter(RestartStrategy::ALL
716/// .iter().map(|s| (s.into(), *s)))` per-strategy lookup where the
717/// map's key type is owned [`String`] rather than [`&'static str`], a
718/// future `Cow::<'static, str>::Owned(strategy.into())` composer on
719/// the future M4 admission-webhook rejection body's owned-arm, the
720/// future wasm-operator's per-supervisor `serde_json::json!({
721/// "estrategia": strategy })` diagnostic emit where the JSON
722/// serializer's `Serialize` impl on [`String`] owns the emit-path — reaches
723/// the same four-arm lifted
724/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
725/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
726/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
727/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const the
728/// paired [`std::fmt::Display`], [`AsRef<str>`],
729/// [`RestartStrategy::as_str`], and the two `&'static str`-returning
730/// forward-projection impls already return.
731///
732/// Opens the trait-idiomatic *owned-`String`* forward-projection axis
733/// on the closed-set fieldless typed enum surface — first-mover on the
734/// M2 OTP-shape sibling-restart-strategy axis, mirror of the
735/// [`crate::supervisor::RestartStrategy`] first-mover position that
736/// opened the paired owned-`&'static str` axis (523157d) and the
737/// borrowed-input `&'static str` axis on
738/// [`crate::dep::DepList`] (64aa742). Rust's standard library does not
739/// carry a blanket `impl<T: AsRef<str>> From<T> for String` (nor an
740/// `impl<T: fmt::Display> From<T> for String`), so every closed-set
741/// typed enum that carries the paired `AsRef<str>` / `Display` /
742/// `From<Self> for &'static str` triple but not the owned-[`String`]
743/// axis forces every owned-string call site through a `.to_string()` /
744/// `.as_str().to_owned()` / `String::from(strategy.as_str())` detour
745/// whose type bounds have no compile-time link to the substrate
746/// primitive.
747///
748/// Deliberately routes through the human-readable
749/// [`RestartStrategy::as_str`] axis — for this enum the wire format
750/// (`PascalCase`, tatara-lisp author surface `:estrategia OneForOne`)
751/// and the diagnostic byte-string share the same vocabulary by
752/// construction (unlike the sibling [`crate::CaixaKind`] enum whose two
753/// axes diverge), so the owned-[`String`] projection lands
754/// byte-identically on both the wire vocabulary the paired
755/// [`serde::Serialize`] derive emits and the diagnostic vocabulary the
756/// [`RestartStrategy::as_str`] helper returns.
757///
758/// The remaining fourteen closed-set typed enums on the caixa
759/// substrate surface (`RestartPolicy`, `CaixaKind`, `CaixaDialeto`,
760/// `DepList`, `PlacementStrategy`, `WitShape`, `RateLimitUnit`,
761/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
762/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets of
763/// this campaign — each carries the same paired `AsRef<str>` /
764/// `Display` / `From<Self> for &'static str` / `From<&Self> for
765/// &'static str` quadruple that this owned-[`String`] axis extends onto.
766///
767/// Pinned load-bearing by
768/// [`tests::restart_strategy_from_into_owned_string_routes_through_as_str_accessor`]
769/// (byte-parity pin against [`RestartStrategy::as_str`] across the
770/// four-arm emit-set, plus a blanket `.into::<String>()` shape witness)
771/// and
772/// [`tests::restart_strategy_from_into_owned_string_and_static_str_agree_on_every_arm`]
773/// (cross-axis partition pin against the paired owned-input
774/// [`From<RestartStrategy> for &'static str`] impl and the sibling
775/// [`ToString::to_string`] surface routed through [`std::fmt::Display`],
776/// plus a direct round-trip witness through [`TryFrom<&str>`] on the
777/// owned-[`String`]'s [`String::as_str`] borrow that closes the two-way
778/// `Self → String → Self` round-trip on the trait-idiomatic
779/// owned-[`String`] forward + reverse axis pair).
780impl From<RestartStrategy> for String {
781    fn from(strategy: RestartStrategy) -> String {
782        strategy.as_str().to_owned()
783    }
784}
785
786/// Trait-idiomatic *borrowed-input, owned-`String` output* forward
787/// projection on the M2 OTP-shape sibling-restart-strategy closed-set
788/// typed enum — the fourth (and closing) corner of the
789/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
790/// projection family. Routes byte-for-byte through the
791/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
792/// accessor (via [`str::to_owned`]) so every consumer that holds a
793/// borrowed [`&RestartStrategy`] and needs an owned [`String`] — a
794/// future `serde_json::Value::String(String::from(&strategy))`
795/// structured-payload composer over a borrowed field, a future
796/// `Iterator::map` over `&[RestartStrategy]` that projects to owned
797/// keys through `.iter().map(String::from)`, a future
798/// `HashMap::<String, RestartStrategy>::from_iter` that keys off a
799/// borrowed-iteration axis where dereferencing the strategy would force
800/// an unnecessary `Copy` at every step, the future wasm-operator's
801/// per-supervisor `strategies.iter().map(String::from).collect()`
802/// diagnostic emit whose iteration axis is borrowed by construction —
803/// reaches the same four-arm lifted
804/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
805/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
806/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
807/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const the
808/// paired [`std::fmt::Display`], [`AsRef<str>`],
809/// [`RestartStrategy::as_str`], and the three other trait-idiomatic
810/// forward-projection impls
811/// ([`From<RestartStrategy> for &'static str`],
812/// [`From<&RestartStrategy> for &'static str`],
813/// [`From<RestartStrategy> for String`]) already return.
814///
815/// Opens the trait-idiomatic *borrowed-input, owned-`String` output*
816/// forward-projection axis on closed-set fieldless typed enums —
817/// first-mover on the 2×2 completion corner, mirror of the
818/// [`crate::supervisor::RestartStrategy`] first-mover position that
819/// opened the paired owned-input owned-`String` axis (7baa18a), the
820/// owned-input owned-`&'static str` axis (523157d), and the paired
821/// [`crate::dep::DepList`] first-mover position that opened the
822/// borrowed-input `&'static str` axis (64aa742). Rust's standard
823/// library does not carry a blanket `impl<T: AsRef<str>> From<&T> for
824/// String` (nor an `impl<T: fmt::Display> From<&T> for String`), so
825/// every closed-set typed enum that carries the paired `AsRef<str>` /
826/// `Display` / `From<Self> for &'static str` / `From<&Self> for
827/// &'static str` / `From<Self> for String` quintuple but not the
828/// borrowed-input owned-[`String`] axis forces every borrowed-input
829/// owned-string call site through a `strategy.as_str().to_owned()` /
830/// `String::from(*strategy)` (with a spurious `Copy`) /
831/// `strategy.to_string()` (through `Display`) detour whose type bounds
832/// have no compile-time link to the substrate primitive.
833///
834/// Deliberately routes through the human-readable
835/// [`RestartStrategy::as_str`] axis — for this enum the wire format
836/// (`PascalCase`, tatara-lisp author surface `:estrategia OneForOne`)
837/// and the diagnostic byte-string share the same vocabulary by
838/// construction (unlike the sibling [`crate::CaixaKind`] enum whose two
839/// axes diverge), so the borrowed-input owned-[`String`] projection
840/// lands byte-identically on both the wire vocabulary the paired
841/// [`serde::Serialize`] derive emits and the diagnostic vocabulary the
842/// [`RestartStrategy::as_str`] helper returns.
843///
844/// The remaining fourteen closed-set typed enums on the caixa
845/// substrate surface (`RestartPolicy`, `CaixaKind`, `CaixaDialeto`,
846/// `DepList`, `PlacementStrategy`, `WitShape`, `RateLimitUnit`,
847/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
848/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets of
849/// this 2×2-completion campaign — each carries the same paired
850/// quintuple that this borrowed-input owned-[`String`] axis extends onto.
851///
852/// Pinned load-bearing by
853/// [`tests::restart_strategy_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
854/// (byte-parity pin against [`RestartStrategy::as_str`] across the
855/// four-arm emit-set through the borrowed-input surface) and
856/// [`tests::restart_strategy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
857/// (cross-axis partition pin against the paired owned-input owned-
858/// [`String`] [`From<RestartStrategy> for String`] impl, the paired
859/// borrowed-input owned-[`&'static str`] [`From<&RestartStrategy> for
860/// &'static str`] impl, and the sibling [`ToString::to_string`] surface
861/// routed through [`std::fmt::Display`], plus a direct round-trip
862/// witness through [`TryFrom<&str>`] on the owned-[`String`]'s
863/// [`String::as_str`] borrow that closes the two-way
864/// `&Self → String → Self` round-trip on the trait-idiomatic
865/// borrowed-input owned-[`String`] forward + reverse axis pair).
866impl From<&RestartStrategy> for String {
867    fn from(strategy: &RestartStrategy) -> String {
868        strategy.as_str().to_owned()
869    }
870}
871
872/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, str>`]
873/// output* forward projection on the M2 OTP-shape sibling-restart
874/// [`RestartStrategy`] closed-set typed enum — extends the substrate-
875/// wide [`std::borrow::Cow<'static, str>`] forward-projection family
876/// opened on [`crate::CaixaKind`] (99c1735) onto the first M2 OTP-
877/// shape closed-set fieldless typed enum peer on the caixa surface
878/// (`:supervisor :estrategia`). Routes byte-for-byte through the
879/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
880/// accessor (via [`std::borrow::Cow::Borrowed`]) so every consumer
881/// that binds a [`RestartStrategy`] through the trait-idiomatic
882/// [`std::borrow::Cow<'static, str>`] axis — a future
883/// `axum::response::IntoResponse` composer whose per-strategy
884/// diagnostic-body typing rules out the sibling [`AsRef<str>`]
885/// borrowed return, a future M4 admission-webhook rejection body
886/// that composes the accepted-strategy enumeration through the same
887/// `RestartStrategy::ALL.iter().map(Cow::from)` shape [`CaixaKind`]
888/// already routes through, a generic `<T: for<'a>
889/// Into<std::borrow::Cow<'static, str>>>`-bound structured-log
890/// emitter on a per-supervisor diagnostic column — reaches the same
891/// four-arm lifted [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`]
892/// / [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
893/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
894/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
895/// the paired [`std::fmt::Display`], [`AsRef<str>`],
896/// [`RestartStrategy::as_str`], and the four
897/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
898/// forward-projection corners already return.
899///
900/// Deliberately returns [`std::borrow::Cow::Borrowed`] rather than
901/// [`std::borrow::Cow::Owned`] — the substrate-primitive
902/// [`RestartStrategy::as_str`] accessor's return carries the
903/// `&'static str` lifetime by construction (each `match` arm resolves
904/// to a [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &str`
905/// with static lifetime), so the zero-alloc borrowed arm is the
906/// type-correct projection with no runtime allocation.
907///
908/// Rust's standard library carries no blanket `impl<T: AsRef<str>>
909/// From<T> for Cow<'static, str>` (nor an `impl<T: fmt::Display>
910/// From<T> for Cow<'static, str>`), so the paired sibling
911/// [`From<RestartStrategy> for &'static str`],
912/// [`From<RestartStrategy> for String`], [`AsRef<str>`], and
913/// [`std::fmt::Display`] surfaces do not implicitly extend to a
914/// [`Cow<'static, str>`]-bound call site — every such site is forced
915/// through a `Cow::Borrowed(strategy.as_str())` /
916/// `Cow::Owned(strategy.to_string())` open-code whose type bounds
917/// have no compile-time link back to the substrate primitive until
918/// this lift.
919///
920/// First peer to extend the substrate-wide trait-idiomatic
921/// [`std::borrow::Cow<'static, str>`] forward-projection axis off the
922/// top-level [`crate::CaixaKind`] enum (99c1735 owned-input,
923/// d45c409 borrowed-input) onto the wider substrate — the remaining
924/// twelve peers (`RestartPolicy`, `PlacementStrategy`, `RateLimitUnit`,
925/// `DepList`, `CaixaDialeto`, and the outside-`caixa-core` peers
926/// `WitShape`, `PathShapeViolation`, `InvariantKind`, `ArchVerdict`,
927/// `Severity`, `FixSafety`, `Semantic`, `FerriteRuntime`) are the
928/// future targets of this campaign.
929///
930/// Pinned load-bearing by
931/// [`tests::restart_strategy_from_into_static_cow_str_routes_through_as_str_accessor`]
932/// (byte-parity + zero-alloc [`std::borrow::Cow::Borrowed`]-arm pin
933/// against [`RestartStrategy::as_str`] across the four-arm
934/// [`RestartStrategy::ALL`]) and
935/// [`tests::restart_strategy_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
936/// (cross-axis partition pin against the paired [`From<RestartStrategy>
937/// for &'static str`], [`From<RestartStrategy> for String`], and
938/// [`ToString`]-through-[`std::fmt::Display`] axes, plus a
939/// `.iter().copied().map(Cow::from)` pipe witness over
940/// [`RestartStrategy::ALL`] that materializes the four-arm accept-set
941/// through the [`Cow<'static, str>`] axis alone and pins the
942/// zero-alloc discipline on every element).
943impl From<RestartStrategy> for std::borrow::Cow<'static, str> {
944    fn from(strategy: RestartStrategy) -> std::borrow::Cow<'static, str> {
945        std::borrow::Cow::Borrowed(strategy.as_str())
946    }
947}
948
949/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, str>`]
950/// output* forward projection on the M2 OTP-shape sibling-restart
951/// [`RestartStrategy`] closed-set typed enum — the borrowed-input
952/// companion to the paired owned-input
953/// [`From<RestartStrategy> for std::borrow::Cow<'static, str>`] impl
954/// immediately above (7dd28b3). Routes byte-for-byte through the same
955/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
956/// accessor (via [`std::borrow::Cow::Borrowed`]) so every consumer
957/// that holds a `&RestartStrategy` and needs a
958/// [`std::borrow::Cow<'static, str>`] — a
959/// `RestartStrategy::ALL.iter().map(std::borrow::Cow::from).collect::<Vec<_>>()`
960/// per-arm accept-set materializer (whose iterator over
961/// `&'static [RestartStrategy]` yields `&RestartStrategy`, not
962/// `RestartStrategy`, so the paired owned-input
963/// [`From<RestartStrategy> for std::borrow::Cow<'static, str>`] axis
964/// alone forces every call site through an explicit `.copied()` /
965/// dereference / [`Copy`]-bound restatement rather than the direct
966/// trait-idiomatic projection), a future generic
967/// `<T: for<'a> Into<std::borrow::Cow<'static, str>>>`-bound emitter
968/// on a per-strategy diagnostic column that walks the
969/// `iter().map(Into::into)` shape verbatim, the future M4 admission-
970/// webhook rejection body that composes the accepted-strategy
971/// enumeration from an iterated
972/// `RestartStrategy::ALL.iter().map(|s| s.into())` pipe rather than a
973/// per-arm `match s { … }` cascade — reaches the same four-arm lifted
974/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
975/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
976/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
977/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
978/// the paired [`std::fmt::Display`], [`AsRef<str>`],
979/// [`RestartStrategy::as_str`], the four
980/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
981/// forward-projection corners, and the paired owned-input
982/// [`From<RestartStrategy> for std::borrow::Cow<'static, str>`] impl
983/// already return.
984///
985/// Deliberately returns [`std::borrow::Cow::Borrowed`] rather than
986/// [`std::borrow::Cow::Owned`] — the substrate-primitive
987/// [`RestartStrategy::as_str`] accessor's return carries the
988/// `&'static str` lifetime by construction (each `match` arm resolves
989/// to a [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &str`
990/// with static lifetime), so the zero-alloc borrowed arm is the
991/// type-correct projection with no runtime allocation.
992///
993/// Second peer on the substrate-wide trait-idiomatic
994/// [`std::borrow::Cow<'static, str>`] forward-projection family
995/// opened one commit prior (7dd28b3) on the paired owned-input
996/// [`From<RestartStrategy> for std::borrow::Cow<'static, str>`] impl
997/// — closes the `{Self, &Self}` input-shape corner of the
998/// [`Cow<'static, str>`] axis on the first M2 OTP-shape closed-set
999/// fieldless typed enum peer on the caixa surface, exactly as
1000/// d45c409 closed it on the top-level [`crate::CaixaKind`] one commit
1001/// after the owning half (99c1735) landed. Rust's standard library
1002/// does not carry a blanket `impl<T: AsRef<str>> From<&T> for
1003/// Cow<'static, str>` (nor an `impl<T: fmt::Display> From<&T> for
1004/// Cow<'static, str>`), so every closed-set fieldless typed enum peer
1005/// on the substrate that carries the paired owned-input
1006/// [`Cow<'static, str>`] axis but not the borrowed-input axis forces
1007/// every borrowed-input [`Cow<'static, str>`]-parameterized call site
1008/// through a spurious [`Copy`] deref
1009/// (`std::borrow::Cow::from(*strategy)`) or a
1010/// `std::borrow::Cow::Borrowed(strategy.as_str())` open-code whose
1011/// type bounds have no compile-time link to the substrate primitive.
1012///
1013/// Pinned load-bearing by
1014/// [`tests::restart_strategy_from_borrowed_into_static_cow_str_routes_through_as_str_accessor`]
1015/// (byte-parity + zero-alloc [`std::borrow::Cow::Borrowed`]-arm pin
1016/// against [`RestartStrategy::as_str`] across the four-arm
1017/// [`RestartStrategy::ALL`] through the borrowed-input surface) and
1018/// [`tests::restart_strategy_from_borrowed_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
1019/// (cross-axis partition pin against the paired owned-input
1020/// [`From<RestartStrategy> for std::borrow::Cow<'static, str>`], the
1021/// paired borrowed-input owned-`&'static str`
1022/// [`From<&RestartStrategy> for &'static str`], and the paired
1023/// borrowed-input owned-`String` [`From<&RestartStrategy> for String`]
1024/// impls, plus a `.iter().map(std::borrow::Cow::from)` pipe witness
1025/// over [`RestartStrategy::ALL`] — whose iterator yields
1026/// `&RestartStrategy` by construction, so the borrowed-input
1027/// [`Cow<'static, str>`] axis is what routes the pipe through the
1028/// substrate-primitive [`RestartStrategy::as_str`] accessor with the
1029/// zero-alloc [`Cow::Borrowed`] arm by construction and without a
1030/// spurious [`Copy`] deref).
1031impl From<&RestartStrategy> for std::borrow::Cow<'static, str> {
1032    fn from(strategy: &RestartStrategy) -> std::borrow::Cow<'static, str> {
1033        std::borrow::Cow::Borrowed(strategy.as_str())
1034    }
1035}
1036
1037/// Trait-idiomatic *owned-input, [`Box<str>`] output* forward
1038/// projection on the M2 OTP-shape sibling-restart [`RestartStrategy`]
1039/// closed-set fieldless typed enum — opens a fresh
1040/// substrate-wide `Box<str>` forward-projection campaign tier on the
1041/// first M2 OTP-shape closed-set fieldless typed enum peer on the
1042/// caixa surface, immediately after the paired `Cow<'static, str>`
1043/// axis (7dd28b3 / ee577fd) closed the
1044/// `{Self, &Self} × {&'static str, String, Cow<'static, str>}` 2×3
1045/// corner on this enum. Routes byte-for-byte through the
1046/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
1047/// accessor via [`Box::<str>::from`] on the returned `&'static str`,
1048/// so every consumer that binds a
1049/// `let key: Box<str> = strategy.into();`-shaped call site — a
1050/// per-supervisor metric-key materializer that stashes the strategy
1051/// discriminator in a `Box<str>`-typed heap-owned scalar for cheap
1052/// clone (a shared-nothing per-strategy accept-set the
1053/// `caixa-operator` reconciliation scheduler carries), a future
1054/// admission-webhook rejection body whose per-arm `Box<str>` field
1055/// composes from an owned `RestartStrategy` handle — reaches the
1056/// same four-arm lifted
1057/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1058/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1059/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1060/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
1061/// the sibling
1062/// `{Self, &Self} × {&'static str, String, Cow<'static, str>}`
1063/// forward-projection corner already returns. Rust's standard
1064/// library carries `impl From<&str> for Box<str>` and
1065/// `impl From<String> for Box<str>` but no blanket
1066/// `impl<T: AsRef<str>> From<T> for Box<str>`, so this axis is a
1067/// distinct trait-idiomatic surface that a downstream
1068/// `RestartStrategy → Box<str>` `.into()` reaches through this impl
1069/// and no other — without a
1070/// `Box::from(strategy.as_str())` open-code whose type bounds have
1071/// no compile-time link back to the substrate primitive.
1072///
1073/// Pinned load-bearing by
1074/// [`tests::restart_strategy_from_into_box_str_routes_through_as_str_accessor`]
1075/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1076/// four-arm [`RestartStrategy::ALL`] emit-set on the owned-input
1077/// surface, plus a blanket-derived [`Into`] shape witness).
1078impl From<RestartStrategy> for Box<str> {
1079    fn from(strategy: RestartStrategy) -> Box<str> {
1080        Box::<str>::from(strategy.as_str())
1081    }
1082}
1083
1084/// Trait-idiomatic *borrowed-input, [`Box<str>`] output* forward
1085/// projection on the M2 OTP-shape sibling-restart [`RestartStrategy`]
1086/// closed-set fieldless typed enum — closes the `{Self, &Self}`
1087/// input-shape corner of the substrate-wide `Box<str>`
1088/// forward-projection axis opened one commit prior (69ef45c) on the
1089/// paired owned-input [`From<RestartStrategy> for Box<str>`] impl.
1090/// Routes byte-for-byte through the same substrate-primitive
1091/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1092/// [`Box::<str>::from`] on the returned `&'static str`, so every
1093/// consumer that holds a `&RestartStrategy` and needs a
1094/// [`Box<str>`] — a
1095/// `RestartStrategy::ALL.iter().map(Box::<str>::from).collect::<Vec<_>>()`
1096/// per-arm accept-set materializer (whose iterator over
1097/// `&'static [RestartStrategy]` yields `&RestartStrategy`, not
1098/// `RestartStrategy`, so the paired owned-input
1099/// [`From<RestartStrategy> for Box<str>`] axis alone forces every
1100/// call site through an explicit `.copied()` / dereference /
1101/// [`Copy`]-bound restatement rather than the direct trait-idiomatic
1102/// projection), a per-supervisor metric-key materializer holding
1103/// `&RestartStrategy` through a `caixa-operator` reconciliation
1104/// scheduler's borrow lifetime, a future admission-webhook rejection
1105/// body whose per-arm `Box<str>` field composes from a borrowed
1106/// `&RestartStrategy` handle without a spurious [`Copy`] deref —
1107/// reaches the same four-arm lifted
1108/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1109/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1110/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1111/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
1112/// the paired owned-input [`From<RestartStrategy> for Box<str>`] and
1113/// the sibling
1114/// `{Self, &Self} × {&'static str, String, Cow<'static, str>}`
1115/// forward-projection corner already return.
1116///
1117/// Second peer on the substrate-wide trait-idiomatic
1118/// [`Box<str>`] forward-projection family opened one commit prior
1119/// (69ef45c) on the paired owned-input
1120/// [`From<RestartStrategy> for Box<str>`] impl — closes the
1121/// `{Self, &Self}` input-shape corner of the [`Box<str>`] axis on
1122/// the first M2 OTP-shape closed-set fieldless typed enum peer on
1123/// the caixa surface (`:supervisor :estrategia`), exactly as
1124/// ee577fd closed the paired [`Cow<'static, str>`] axis one commit
1125/// after its owning half (7dd28b3) landed. Rust's standard library
1126/// carries `impl From<&str> for Box<str>` and
1127/// `impl From<String> for Box<str>` but no blanket
1128/// `impl<T: AsRef<str>> From<&T> for Box<str>` (nor a
1129/// `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`), so
1130/// every closed-set fieldless typed enum peer on the substrate that
1131/// carries the paired owned-input `Box<str>` axis but not the
1132/// borrowed-input axis forces every borrowed-input
1133/// `Box<str>`-parameterized call site through a spurious [`Copy`]
1134/// deref (`Box::<str>::from((*strategy).as_str())`) or a
1135/// `Box::<str>::from(strategy.as_str())` open-code whose type bounds
1136/// have no compile-time link back to the substrate primitive.
1137///
1138/// Pinned load-bearing by
1139/// [`tests::restart_strategy_from_borrowed_into_box_str_routes_through_as_str_accessor`]
1140/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1141/// four-arm [`RestartStrategy::ALL`] emit-set on the borrowed-input
1142/// surface, plus a blanket-derived [`Into`] shape witness and a
1143/// cross-axis pin against the paired owned-input
1144/// [`From<RestartStrategy> for Box<str>`] and the sibling
1145/// borrowed-input `{&'static str, String, Cow<'static, str>}`
1146/// return-shape axes).
1147impl From<&RestartStrategy> for Box<str> {
1148    fn from(strategy: &RestartStrategy) -> Box<str> {
1149        Box::<str>::from(strategy.as_str())
1150    }
1151}
1152
1153/// Trait-idiomatic *owned-input, [`std::sync::Arc<str>`] output*
1154/// forward projection on the M2 OTP-shape sibling-restart
1155/// [`RestartStrategy`] closed-set fieldless typed enum — opens the
1156/// substrate-wide [`std::sync::Arc<str>`] forward-projection campaign
1157/// tier on the first M2 OTP-shape closed-set fieldless typed enum peer
1158/// on the caixa surface (`:supervisor :estrategia`), immediately after
1159/// the paired [`Box<str>`] axis (69ef45c / 59ae5dc) closed the
1160/// `{Self, &Self} × {&'static str, String, Cow<'static, str>, Box<str>}`
1161/// 2×4 corner on this enum. Routes byte-for-byte through the
1162/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
1163/// accessor (via [`std::sync::Arc::<str>::from`] on the returned
1164/// `&'static str`), so every consumer that binds a
1165/// [`RestartStrategy`] through the standard-library `.into()` /
1166/// [`From<Self> for std::sync::Arc<str>`] (equivalently
1167/// [`Into<std::sync::Arc<str>>`]) axis — a future admission-webhook
1168/// running under `axum` + `tokio` whose per-arm structured-log field
1169/// crosses an `.await` boundary and demands the [`Sync`] +
1170/// [`Send`]-safe shared-ownership envelope [`std::sync::Arc<str>`]
1171/// provides (the sibling [`Box<str>`] axis's owned-move return-shape
1172/// forces every downstream `.clone()` through a heap allocation, while
1173/// [`std::sync::Arc<str>`]'s reference-counted shared-ownership
1174/// resolves the same `.clone()` through a refcount bump), a future
1175/// wasm-operator's per-supervisor reconciliation scheduler that
1176/// dispatches the same per-strategy diagnostic key onto multiple
1177/// concurrent reconcile-loop tasks holding shared-ownership through
1178/// [`std::sync::Arc<str>`], a future
1179/// `tracing::field::valuable::Value::Str(strategy.into())` structured-
1180/// log recorder whose typing folds a shared-ownership envelope onto
1181/// the span-context axis, a generic
1182/// `<T: Into<std::sync::Arc<str>>>`-bound diagnostic column on a
1183/// shared-ownership per-strategy cache — reaches the same four-arm
1184/// lifted [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1185/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1186/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1187/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
1188/// the sibling
1189/// `{Self, &Self} × {&'static str, String, Cow<'static, str>, Box<str>}`
1190/// forward-projection corner already returns.
1191///
1192/// First-mover on the substrate-wide trait-idiomatic
1193/// [`std::sync::Arc<str>`] forward-projection family — Rust's
1194/// standard library carries `impl From<&str> for std::sync::Arc<str>`
1195/// and `impl From<String> for std::sync::Arc<str>` but no blanket
1196/// `impl<T: AsRef<str>> From<T> for std::sync::Arc<str>` (nor an
1197/// `impl<T: fmt::Display> From<T> for std::sync::Arc<str>`), so every
1198/// closed-set fieldless typed enum on the substrate that carries the
1199/// paired [`AsRef<str>`] / [`std::fmt::Display`] /
1200/// [`From<Self> for &'static str`] / [`From<&Self> for &'static str`] /
1201/// [`From<Self> for String`] / [`From<&Self> for String`] /
1202/// [`From<Self> for Cow<'static, str>`] /
1203/// [`From<&Self> for Cow<'static, str>`] /
1204/// [`From<Self> for Box<str>`] / [`From<&Self> for Box<str>`] decet
1205/// but not the [`std::sync::Arc<str>`] axis forces every
1206/// `std::sync::Arc<str>`-parameterized call site through a
1207/// `std::sync::Arc::<str>::from(strategy.as_str())` open-code (or a
1208/// `std::sync::Arc::<str>::from(String::from(strategy))` two-step
1209/// composition through the owned-`String` axis that allocates
1210/// twice — once into the intermediate `String`, once into the
1211/// [`Arc<str>`] on the `From<String>` conversion) whose type bounds
1212/// have no compile-time link back to the substrate primitive. Opening
1213/// the axis on the first M2 OTP-shape closed-set fieldless typed enum
1214/// peer on the caixa substrate surface establishes the "route through
1215/// `as_str` via [`std::sync::Arc::<str>::from`] on the returned
1216/// `&'static str`" discipline; every future closed-set fieldless
1217/// typed enum peer on the substrate ([`RestartPolicy`],
1218/// [`crate::aplicacao::PlacementStrategy`],
1219/// [`crate::aplicacao::RateLimitUnit`], [`crate::aplicacao::WitShape`],
1220/// [`crate::dep::DepList`], [`crate::dialeto::CaixaDialeto`],
1221/// [`crate::kind::CaixaKind`],
1222/// [`crate::render::PathShapeViolation`], and the outside-`caixa-core`
1223/// peers `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`,
1224/// `Semantic`, `FerriteRuntime`) is a future target of the campaign,
1225/// tracking the same 14-peer emit-set every prior projection tier
1226/// ([`&'static str`], [`String`], [`Cow<'static, str>`], [`Box<str>`])
1227/// converged onto.
1228///
1229/// Peer of the sibling [`Box<str>`] forward-projection first-mover
1230/// (69ef45c) — same "opens a new substrate-wide projection tier"
1231/// discipline, extended onto the [`std::sync::Arc<str>`] axis whose
1232/// shared-ownership + [`Sync`] + [`Send`] contract is the distinct
1233/// value the [`Box<str>`] axis's owned-move return-shape cannot
1234/// provide.
1235///
1236/// Pinned load-bearing by
1237/// [`tests::restart_strategy_from_into_arc_str_routes_through_as_str_accessor`]
1238/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1239/// four-arm [`RestartStrategy::ALL`] emit-set on the owned-input
1240/// surface, plus a blanket-derived [`Into`] shape witness and cross-
1241/// axis byte-parity pins against the sibling owned-input
1242/// `{&'static str, String, Cow<'static, str>, Box<str>}` return-shape
1243/// axes).
1244impl From<RestartStrategy> for std::sync::Arc<str> {
1245    fn from(strategy: RestartStrategy) -> std::sync::Arc<str> {
1246        std::sync::Arc::<str>::from(strategy.as_str())
1247    }
1248}
1249
1250/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<str>`] output*
1251/// forward projection on the M2 OTP-shape sibling-restart
1252/// [`RestartStrategy`] closed-set fieldless typed enum — closes the
1253/// `{Self, &Self}` input-shape corner of the [`std::sync::Arc<str>`]
1254/// forward-projection axis on the first M2 OTP-shape closed-set
1255/// fieldless typed enum peer on the caixa surface
1256/// (`:supervisor :estrategia`), companion to the paired owned-input
1257/// [`From<RestartStrategy> for std::sync::Arc<str>`] impl one commit
1258/// prior (bca2ec8). Routes byte-for-byte through the
1259/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
1260/// accessor (via [`std::sync::Arc::<str>::from`] on the returned
1261/// `&'static str`), so every consumer that binds a
1262/// [`&RestartStrategy`] through the standard-library `.into()` /
1263/// [`From<&Self> for std::sync::Arc<str>`] (equivalently
1264/// [`Into<std::sync::Arc<str>>`]) axis — a future admission-webhook's
1265/// per-request borrowed-`&RestartStrategy` handle rendering a per-arm
1266/// `Sync` + `Send`-safe structured-log field across an `.await`
1267/// boundary through a `<T: Into<std::sync::Arc<str>>>`-bound
1268/// diagnostic-column dispatch, a future wasm-operator's per-
1269/// supervisor reconciliation pipeline whose
1270/// `.iter().map(std::sync::Arc::<str>::from)` collector reaches into
1271/// the shared-ownership per-strategy key without a spurious [`Copy`]
1272/// deref (which would only be reachable through the owned-input
1273/// [`From<RestartStrategy> for std::sync::Arc<str>`] axis by first
1274/// calling `.copied()` on the iterator), a future
1275/// `<T: Into<std::sync::Arc<str>>>`-bound `tracing`-span attributes
1276/// collector recording a borrowed-`&RestartStrategy` per-arm field
1277/// onto the parent span's shared-ownership context — reaches the
1278/// same four-arm lifted
1279/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1280/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1281/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1282/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
1283/// the paired owned-input
1284/// [`From<RestartStrategy> for std::sync::Arc<str>`] impl and the
1285/// sibling `{&'static str, String, Cow<'static, str>, Box<str>}`
1286/// forward-projection corner already return.
1287///
1288/// Second peer on the substrate-wide trait-idiomatic
1289/// [`std::sync::Arc<str>`] forward-projection family opened one
1290/// commit prior (bca2ec8) on the paired owned-input
1291/// [`From<RestartStrategy> for std::sync::Arc<str>`] impl — closes
1292/// the `{Self, &Self}` input-shape corner of the
1293/// [`std::sync::Arc<str>`] axis on the first M2 OTP-shape closed-set
1294/// fieldless typed enum peer on the caixa surface, exactly as
1295/// 59ae5dc closed the paired [`Box<str>`] axis one commit after its
1296/// owning half (69ef45c) landed. Rust's standard library carries
1297/// `impl From<&str> for std::sync::Arc<str>` and
1298/// `impl From<String> for std::sync::Arc<str>` but no blanket
1299/// `impl<T: AsRef<str>> From<&T> for std::sync::Arc<str>` (nor a
1300/// `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`), so
1301/// every closed-set fieldless typed enum peer on the substrate that
1302/// carries the paired owned-input [`std::sync::Arc<str>`] axis but
1303/// not the borrowed-input axis forces every borrowed-input
1304/// [`std::sync::Arc<str>`]-parameterized call site through a
1305/// spurious [`Copy`] deref
1306/// (`std::sync::Arc::<str>::from((*strategy).as_str())`) or a
1307/// `std::sync::Arc::<str>::from(strategy.as_str())` open-code whose
1308/// type bounds have no compile-time link back to the substrate
1309/// primitive.
1310///
1311/// Pinned load-bearing by
1312/// [`tests::restart_strategy_from_borrowed_into_arc_str_routes_through_as_str_accessor`]
1313/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1314/// four-arm [`RestartStrategy::ALL`] emit-set on the borrowed-input
1315/// surface, plus a blanket-derived [`Into`] shape witness and a
1316/// cross-axis pin against the paired owned-input
1317/// [`From<RestartStrategy> for std::sync::Arc<str>`] and the sibling
1318/// borrowed-input `{&'static str, String, Cow<'static, str>,
1319/// Box<str>}` return-shape axes).
1320impl From<&RestartStrategy> for std::sync::Arc<str> {
1321    fn from(strategy: &RestartStrategy) -> std::sync::Arc<str> {
1322        std::sync::Arc::<str>::from(strategy.as_str())
1323    }
1324}
1325
1326/// Trait-idiomatic *owned-input, [`std::rc::Rc<str>`] output* forward
1327/// projection on the M2 OTP-shape sibling-restart [`RestartStrategy`]
1328/// closed-set fieldless typed enum — the single-threaded reference-
1329/// counted peer of the paired owned-input
1330/// [`From<RestartStrategy> for std::sync::Arc<str>`] impl (bca2ec8) on
1331/// the sibling atomically-reference-counted [`std::sync::Arc<str>`] axis.
1332/// Routes byte-for-byte through the substrate-primitive
1333/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1334/// [`std::rc::Rc::<str>::from`] on the returned `&'static str`.
1335///
1336/// Rust's standard library carries `impl From<&str> for std::rc::Rc<str>`
1337/// and `impl From<String> for std::rc::Rc<str>` but no blanket
1338/// `impl<T: AsRef<str>> From<T> for std::rc::Rc<str>` (nor a `From<&T>`
1339/// blanket), and the [`std::sync::Arc<str>`] and [`std::rc::Rc<str>`]
1340/// trait tables are disjoint — so a single-threaded caixa-operator
1341/// reconciliation pass that shares the `:supervisor :estrategia` wire
1342/// byte-string across intra-reconcile-loop tree nodes through the cheaper
1343/// non-atomic [`std::rc::Rc<str>`] refcount (the atomically-reference-
1344/// counted [`std::sync::Arc<str>`] return-shape cannot provide within a
1345/// single-threaded reconciliation pass without paying the atomic-fence
1346/// cost the [`std::rc::Rc<str>`] axis skips by construction) reaches
1347/// the substrate primitive through this impl and no other.
1348///
1349/// Extends the trait-idiomatic [`std::rc::Rc<str>`] forward-projection
1350/// axis onto the first M2 OTP-shape closed-set fieldless typed enum peer
1351/// on the caixa surface (`:supervisor :estrategia`), matching the
1352/// trajectory the M3-mesh-primitive-defining
1353/// [`crate::aplicacao::PlacementStrategy`],
1354/// [`crate::aplicacao::RateLimitUnit`], and
1355/// [`crate::aplicacao::WitShape`] (1afb5f4) peers established, and the
1356/// eighth in-caixa-core closed-set fieldless typed-enum peer to pick up
1357/// the axis (after [`crate::CaixaKind`],
1358/// [`crate::dialeto::CaixaDialeto`], [`crate::dep::DepList`],
1359/// [`crate::version::CaixaVersion`], [`crate::render::PathShapeViolation`],
1360/// and the three M3-mesh-primitive-defining peers above).
1361///
1362/// Pinned load-bearing by
1363/// [`tests::restart_strategy_from_into_rc_str_routes_through_as_str_accessor`]
1364/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1365/// four-arm [`RestartStrategy::ALL`] emit-set on the owned-input
1366/// surface, plus a blanket-derived [`Into`] shape witness and cross-
1367/// axis byte-parity pins against the sibling owned-input `{&'static
1368/// str, String, Cow<'static, str>, Box<str>, std::sync::Arc<str>}`
1369/// return-shape axes).
1370impl From<RestartStrategy> for std::rc::Rc<str> {
1371    fn from(strategy: RestartStrategy) -> std::rc::Rc<str> {
1372        std::rc::Rc::<str>::from(strategy.as_str())
1373    }
1374}
1375
1376/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<str>`] output* forward
1377/// projection on the M2 OTP-shape sibling-restart [`RestartStrategy`]
1378/// closed-set fieldless typed enum — the borrowed-input companion to the
1379/// paired owned-input [`From<RestartStrategy> for std::rc::Rc<str>`]
1380/// impl immediately above, closing the `{Self, &Self}` input-shape
1381/// corner of the [`std::rc::Rc<str>`] axis on the first M2 OTP-shape
1382/// closed-set fieldless typed enum peer on the caixa surface. Routes
1383/// byte-for-byte through the substrate-primitive
1384/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1385/// [`std::rc::Rc::<str>::from`] on the returned `&'static str`, so a
1386/// `RestartStrategy::ALL.iter().map(std::rc::Rc::<str>::from)`-shaped
1387/// pipe (whose iterator over `&'static [RestartStrategy]` yields
1388/// `&RestartStrategy` by construction) reaches the same four-arm lifted
1389/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1390/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1391/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1392/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`] const
1393/// roster the paired owned-input axis and the sibling `{Self, &Self} ×
1394/// {&'static str, String, Cow<'static, str>, Box<str>,
1395/// std::sync::Arc<str>}` forward-projection corner already return.
1396///
1397/// Rust's standard library carries no blanket
1398/// `impl<T: AsRef<str>> From<&T> for std::rc::Rc<str>` (nor a `Copy`-
1399/// based `impl<T: Copy, U: From<T>> From<&T> for U`), so this borrowed-
1400/// input axis is a distinct trait-idiomatic surface — without it, the
1401/// `.iter().map(std::rc::Rc::<str>::from)` pipe would force a spurious
1402/// [`Copy`] deref or a `.copied()` restatement whose type bounds have
1403/// no compile-time link back to the substrate primitive.
1404///
1405/// Pinned load-bearing by
1406/// [`tests::restart_strategy_from_borrowed_into_rc_str_routes_through_as_str_accessor`]
1407/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1408/// four-arm [`RestartStrategy::ALL`] emit-set on the borrowed-input
1409/// surface, plus a blanket-derived [`Into`] shape witness, a cross-axis
1410/// partition pin against the paired owned-input
1411/// [`From<RestartStrategy> for std::rc::Rc<str>`] and the sibling
1412/// borrowed-input `{&'static str, String, Cow<'static, str>, Box<str>,
1413/// std::sync::Arc<str>}` return-shape axes, and a
1414/// `.iter().map(std::rc::Rc::<str>::from)` pipe witness over
1415/// [`RestartStrategy::ALL`] that resolves through the borrowed-input
1416/// axis without a spurious [`Copy`] deref).
1417impl From<&RestartStrategy> for std::rc::Rc<str> {
1418    fn from(strategy: &RestartStrategy) -> std::rc::Rc<str> {
1419        std::rc::Rc::<str>::from(strategy.as_str())
1420    }
1421}
1422
1423/// Substrate-canonical [`AsRef<[u8]>`] byte-view projection on the M2
1424/// OTP-shape sibling-restart [`RestartStrategy`] closed-set fieldless
1425/// typed enum — routes byte-for-byte through the substrate-primitive
1426/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1427/// [`str::as_bytes`] on the returned `&'static str`, so any future
1428/// consumer that binds a [`RestartStrategy`] through a standard-library
1429/// `<T: AsRef<[u8]>>` trait bound reaches the same four-arm lifted
1430/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
1431/// [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
1432/// [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
1433/// [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`]
1434/// `PascalCase` wire byte-string emit-set the paired sibling
1435/// [`AsRef<str>`] (5b828ed) / [`std::fmt::Display`] /
1436/// [`RestartStrategy::as_str`] str-view surfaces and every
1437/// `{Self, &Self} × {&'static str, String, Cow<'static, str>, Box<str>,
1438/// std::sync::Arc<str>}` reverse-projection corner already return —
1439/// through the byte-view axis, which the str-view axes cannot express.
1440///
1441/// Rust's standard library carries `impl AsRef<[u8]> for str` and
1442/// `impl AsRef<[u8]> for String`, so the two-hop composition
1443/// `strategy.as_str().as_bytes()` (or, equivalently,
1444/// `AsRef::<str>::as_ref(&strategy).as_bytes()`) is reachable through
1445/// the pre-existing str-view axis alone. But that two-hop shape has no
1446/// compile-time link back to the byte-projection axis, forces every
1447/// downstream `<T: AsRef<[u8]>>`-bound consumer to open-code the
1448/// two-hop composition at every call site, and admits a silent split
1449/// whenever a future call site takes a sibling reverse-projection axis
1450/// whose `.as_bytes()` byte-tail carries no compile-time byte-view
1451/// surface (`Display` returns a formatter, `String` / `Box<str>` /
1452/// `Arc<str>` allocate). The lifted single-hop impl closes the
1453/// byte-view axis so every future `<T: AsRef<[u8]>>`-bound consumer
1454/// reaches the substrate primitive through one trait dispatch, and
1455/// every future arm addition (an OTP-`rest_for_all` fifth arm the
1456/// theory
1457/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
1458/// might reach for once the four canonical OTP strategies stop covering
1459/// the substrate's discovered load-shape) grows the byte-view axis
1460/// through one edit on the substrate-primitive `as_str` accessor, not a
1461/// coordinated rewrite across every future `<T: AsRef<[u8]>>`-bound
1462/// consumer's arm-set.
1463///
1464/// The primary compounding target is the same `caixa-lacre` BLAKE3
1465/// content-address closure the peer [`crate::CaixaKind`] (69d8d86),
1466/// [`crate::dialeto::CaixaDialeto`] (8151347),
1467/// [`crate::dep::DepList`] (05ffaca),
1468/// [`crate::aplicacao::PlacementStrategy`] (daa8705), and
1469/// [`crate::aplicacao::RateLimitUnit`] (4867e0f) `AsRef<[u8]>` impls
1470/// open onto: [`blake3::hash`] and [`blake3::Hasher::update`] both bind
1471/// their input through `impl AsRef<[u8]>`, so any future per-supervisor
1472/// content-address tag that folds an `:estrategia` discriminator
1473/// byte-tag into the [`crate::Lacre`] closure (a hypothetical
1474/// `hasher.update(estrategia);`-shape composition partitioning the
1475/// four OTP restart-topology closures at content-address time so
1476/// downstream `Lacre` consumers key per-strategy reconciliation caches
1477/// off the typed discriminator rather than the sibling `&'static str`
1478/// wire scalar) reaches the substrate-primitive `as_str` accessor
1479/// through this impl and no other.
1480///
1481/// Opens the trait-idiomatic byte-view axis on the first M2 OTP-shape
1482/// closed-set fieldless typed enum peer on the caixa surface
1483/// (`:supervisor :estrategia`), extending the substrate-wide byte-view
1484/// campaign the sibling [`crate::CaixaKind`] first-mover (69d8d86)
1485/// opened onto the fifth in-caixa-core enum peer. The remaining
1486/// in-caixa-core closed-set fieldless typed-enum peers
1487/// ([`RestartPolicy`], [`crate::aplicacao::WitShape`],
1488/// [`crate::upgrade::UpgradeInstruction`],
1489/// [`crate::render::PathShapeViolation`]) each carry the same
1490/// [`AsRef<str>`] + `pub const fn as_str` substrate-primitive accessor
1491/// discipline, so a future extension of the byte-view axis onto each
1492/// peer reaches through one impl per enum keyed to that peer's
1493/// substrate-primitive accessor.
1494///
1495/// Pinned load-bearing by
1496/// [`tests::restart_strategy_as_ref_bytes_routes_through_as_str_accessor`]
1497/// (fail-before-pass-after byte-parity pin against
1498/// [`RestartStrategy::as_str`] `.as_bytes()` across the four-arm
1499/// [`RestartStrategy::ALL`] emit-set, cross-axis witness against the
1500/// paired str-view [`AsRef<str>`] / [`std::fmt::Display`] /
1501/// [`RestartStrategy::as_str`] axes' `.as_bytes()` byte-tails,
1502/// cross-axis witness against the paired reverse-projection
1503/// `{&'static str, String, Cow<'static, str>, Box<str>,
1504/// std::sync::Arc<str>}` return-shape axes' `.as_bytes()` byte-tails,
1505/// a `<T: AsRef<[u8]>>`-bound-consumer witness that a generic
1506/// byte-input function accepts a [`RestartStrategy`] directly through
1507/// the trait bound, and a `blake3::Hasher::update`-shape byte-input
1508/// surface witness routed through the `<T: AsRef<[u8]>>`-bound
1509/// consumer axis to reach the caixa-lacre compounding target). Any
1510/// future silent detour that routes the byte-view impl off the
1511/// substrate-primitive [`RestartStrategy::as_str`] accessor (a per-arm
1512/// inline `b"OneForOne".as_slice()`-shaped re-inlining that opens a
1513/// compile-time link to the un-lifted arm-literal, a swap onto the
1514/// kebab-case [`gen_platform::Discriminant`] catalog identity that
1515/// would collide the wire axis with the dispatcher-catalog axis) trips
1516/// at caixa-core test time rather than at a downstream byte-consumer's
1517/// silent split.
1518impl AsRef<[u8]> for RestartStrategy {
1519    fn as_ref(&self) -> &[u8] {
1520        self.as_str().as_bytes()
1521    }
1522}
1523
1524/// Trait-idiomatic *owned-input, owned-`Vec<u8>` output* byte-owned
1525/// reverse projection on the first M2 OTP-shape closed-set fieldless
1526/// typed enum peer on the caixa surface ([`RestartStrategy`]) — the
1527/// byte-mirror of the [`From<RestartStrategy> for String`] str-owned
1528/// reverse-projection axis and the owned-`Vec<u8>` reverse-projection
1529/// sibling of the paired [`AsRef<[u8]>`] borrowed byte-view axis
1530/// (cd4c4e0) lifted on this same enum. Routes byte-for-byte through
1531/// the substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
1532/// accessor via [`str::as_bytes`] + [`slice::to_vec`] so every
1533/// consumer that binds a [`RestartStrategy`] through the standard-
1534/// library `impl From<RestartStrategy> for Vec<u8>` axis
1535/// (equivalently `<T: Into<Vec<u8>>>`) — a future
1536/// [`std::io::Write::write_all`]-shape per-supervisor audit-log byte-
1537/// sink whose input parameter is an owned [`Vec<u8>`] payload, a
1538/// future `bytes::Bytes::from(Vec::<u8>::from(strategy))` composer
1539/// folding the per-arm sibling-restart-topology byte-tag into the
1540/// [`bytes::Bytes`] framing surface, a future
1541/// `hasher.update(&Vec::<u8>::from(strategy))`-shape BLAKE3 content-
1542/// address closure that needs the owned byte-tail buffered before
1543/// folding into the [`crate::Lacre`] closure body, a future per-
1544/// strategy protobuf/CBOR/msgpack payload composer whose framer takes
1545/// an owned [`Vec<u8>`] rather than a borrowed byte-slice — reaches
1546/// the substrate primitive through one trait dispatch rather than an
1547/// open-coded per-call-site `strategy.as_str().as_bytes().to_vec()`
1548/// composition whose type bounds have no compile-time link back to
1549/// the substrate primitive.
1550///
1551/// Extends the substrate-wide trait-idiomatic byte-owned reverse-
1552/// projection axis onto the first M2-OTP-shape closed-set fieldless
1553/// typed-enum peer, matching the trajectory the first-mover
1554/// [`crate::CaixaKind`] `From<{Self, &Self}> for Vec<u8>` lift
1555/// (b245fd6), the second-mover [`crate::dialeto::CaixaDialeto`] lift
1556/// (4cceaf5), and the third-mover [`crate::dep::DepList`] lift
1557/// (e974ca2) established across the caixa-core-internal tier. Every
1558/// future arm addition (an OTP-`rest_for_all` fifth arm the theory
1559/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
1560/// might reach for once the four canonical OTP strategies stop
1561/// covering the substrate's discovered load-shape) grows the byte-
1562/// owned axis through one edit on the substrate-primitive
1563/// [`RestartStrategy::as_str`] accessor, mirroring the discipline the
1564/// paired [`AsRef<[u8]>`] borrowed byte-view axis campaign already
1565/// tracked across every closed-set fieldless typed enum peer on the
1566/// substrate.
1567///
1568/// Pinned load-bearing by
1569/// [`tests::restart_strategy_from_into_owned_vec_bytes_routes_through_as_str_accessor`]
1570/// (byte-parity pin against [`RestartStrategy::as_str`] across the
1571/// four-arm [`RestartStrategy::ALL`] emit-set binding the byte-owned
1572/// reverse-projection axis against the paired [`AsRef<[u8]>`]
1573/// borrowed byte-view axis and the str-owned reverse-projection
1574/// family (`String`, `Cow<'static, str>`, `Box<str>`,
1575/// `std::sync::Arc<str>`) `.into_bytes()` / `.as_bytes().to_vec()`
1576/// byte-tails, a `<T: Into<Vec<u8>>>`-bound generic-consumer witness,
1577/// and a `std::io::Write::write_all`-shape owned-byte-sink surface
1578/// witness on both owned and borrowed input shapes).
1579impl From<RestartStrategy> for Vec<u8> {
1580    fn from(strategy: RestartStrategy) -> Vec<u8> {
1581        strategy.as_str().as_bytes().to_vec()
1582    }
1583}
1584
1585/// Trait-idiomatic *borrowed-input, owned-`Vec<u8>` output* byte-
1586/// owned reverse projection on the first M2 OTP-shape closed-set
1587/// fieldless typed enum peer on the caixa surface
1588/// ([`RestartStrategy`]) — the borrowed-input peer of
1589/// [`From<RestartStrategy> for Vec<u8>`], closing the
1590/// `{Self, &Self} → Vec<u8>` pair on the byte-owned reverse-projection
1591/// axis in one lift. Routes byte-for-byte through the substrate-
1592/// primitive [`RestartStrategy::as_str`] `pub const fn` accessor so
1593/// every consumer that holds a borrowed [`&RestartStrategy`] and
1594/// needs an owned [`Vec<u8>`] — a future
1595/// `.iter().map(Vec::<u8>::from).collect()` pipe over
1596/// `&[RestartStrategy]` (whose iterator yields `&RestartStrategy`,
1597/// not `RestartStrategy`, so the owned-input axis alone forces every
1598/// call site through an explicit `.copied()` / spurious [`Copy`]
1599/// deref restatement rather than the direct trait-idiomatic
1600/// projection), a future admission-webhook rejection body composer
1601/// that walks [`RestartStrategy::ALL`] through an `Into<Vec<u8>>`-
1602/// bound per-arm byte-writer to surface the accepted `:estrategia`
1603/// set — reaches the substrate primitive through one trait dispatch
1604/// rather than a `Vec::<u8>::from(*strategy)` spurious-`Copy`-deref
1605/// restatement.
1606impl From<&RestartStrategy> for Vec<u8> {
1607    fn from(strategy: &RestartStrategy) -> Vec<u8> {
1608        strategy.as_str().as_bytes().to_vec()
1609    }
1610}
1611
1612/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, [u8]>`]
1613/// output* byte-owned reverse projection on the first M2 OTP-shape
1614/// closed-set fieldless typed enum peer on the caixa surface
1615/// ([`RestartStrategy`]) — the [`std::borrow::Cow<'static, [u8]>`] byte-
1616/// mirror of the paired [`From<RestartStrategy> for
1617/// std::borrow::Cow<'static, str>`] str-side impl (7dd28b3) and the
1618/// [`std::borrow::Cow<'static, [u8]>`] companion of the paired byte-
1619/// owned [`From<RestartStrategy> for Vec<u8>`] reverse-projection axis
1620/// immediately above. Routes byte-for-byte through the substrate-
1621/// primitive [`RestartStrategy::as_str`] `pub const fn` accessor via
1622/// [`std::borrow::Cow::Borrowed`]`(strategy.as_str().as_bytes())` — the
1623/// four `match` arms in [`Self::as_str`] resolve to
1624/// [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &'static str`
1625/// bodies, so `.as_bytes()` on each returns `&'static [u8]` by
1626/// construction, and the zero-alloc [`Cow::Borrowed`] arm is the
1627/// type-correct projection with no runtime allocation (mirroring the
1628/// paired [`Cow<'static, str>`] axis's own [`Cow::Borrowed`]
1629/// discipline on this same primitive; contrasts with the sibling
1630/// [`crate::CaixaVersion`] [`Cow<'static, [u8]>`] impl (baf7537), whose
1631/// wrapped [`String`] storage is a runtime heap allocation with no
1632/// `&'static [u8]` lifetime, forcing the [`Cow::Owned`] arm there).
1633///
1634/// Extends the substrate-wide trait-idiomatic byte-owned reverse-
1635/// projection matrix onto the first M2-OTP-shape closed-set fieldless
1636/// typed-enum peer at the second byte-owned axis, following the
1637/// trajectory the same axis walked on [`crate::CaixaVersion`]
1638/// (98d38ed on the `Vec<u8>` axis, baf7537 on the `Cow<'static, [u8]>`
1639/// axis).
1640impl From<RestartStrategy> for std::borrow::Cow<'static, [u8]> {
1641    fn from(strategy: RestartStrategy) -> std::borrow::Cow<'static, [u8]> {
1642        std::borrow::Cow::Borrowed(strategy.as_str().as_bytes())
1643    }
1644}
1645
1646/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, [u8]>`]
1647/// output* byte-owned reverse projection on the first M2 OTP-shape
1648/// closed-set fieldless typed enum peer on the caixa surface
1649/// ([`RestartStrategy`]) — the borrowed-input companion to the paired
1650/// owned-input [`From<RestartStrategy> for
1651/// std::borrow::Cow<'static, [u8]>`] impl immediately above, closing
1652/// the `{Self, &Self} → Cow<'static, [u8]>` byte-owned reverse-
1653/// projection family on this primitive at the borrowed-input corner.
1654/// Routes byte-for-byte through the same substrate-primitive
1655/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1656/// [`std::borrow::Cow::Borrowed`]`(strategy.as_str().as_bytes())` —
1657/// the [`Cow::Borrowed`] arm is reachable on both input axes because
1658/// [`Self::as_str`] returns `&'static str` regardless of the input
1659/// shape, so no runtime allocation is forced on either corner.
1660/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U
1661/// where U: From<T>` (nor an
1662/// `impl<T: AsRef<[u8]>> From<&T> for Cow<'static, [u8]>`), so every
1663/// closed-set fieldless typed enum peer that carries the paired
1664/// owned-input axis but not the borrowed-input axis forces every
1665/// borrowed call site through a spurious [`Copy`] deref
1666/// (`Cow::<'static, [u8]>::from(*strategy)`) or an open-coded
1667/// `Cow::Borrowed(strategy.as_str().as_bytes())` whose type bounds
1668/// have no compile-time link to the substrate primitive.
1669impl From<&RestartStrategy> for std::borrow::Cow<'static, [u8]> {
1670    fn from(strategy: &RestartStrategy) -> std::borrow::Cow<'static, [u8]> {
1671        std::borrow::Cow::Borrowed(strategy.as_str().as_bytes())
1672    }
1673}
1674
1675/// Trait-idiomatic *owned-input, [`Box<[u8]>`] output* byte-owned reverse
1676/// projection on the first M2-OTP-shape closed-set fieldless typed enum peer
1677/// on the caixa surface ([`RestartStrategy`]) — the [`Box<[u8]>`] companion
1678/// to the paired owned-input [`From<RestartStrategy> for Vec<u8>`] (98d38ed)
1679/// and [`From<RestartStrategy> for std::borrow::Cow<'static, [u8]>`]
1680/// (7f81539) reverse-projection impls on this same primitive, mirroring the
1681/// paired string-side [`From<RestartStrategy> for Box<str>`] (69ef45c)
1682/// forward-projection axis onto the byte-family side of the reverse-
1683/// projection matrix, and tracking the trajectory the same axis walked on
1684/// the sibling [`crate::CaixaVersion`] String-wrapper newtype primitive
1685/// (703b2fd on the [`Box<[u8]>`] corner). Routes byte-for-byte through the
1686/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn` accessor
1687/// via [`Box::<[u8]>::from`] on the returned `&'static str`'s
1688/// [`str::as_bytes`] — the four `match` arms in [`Self::as_str`] resolve to
1689/// [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &'static str`
1690/// bodies, so `.as_bytes()` returns `&'static [u8]` by construction, and
1691/// the standard-library [`Box::<[u8]>::from(&[u8])`] impl allocates a fit-
1692/// to-length boxed byte slice in one heap allocation without an
1693/// intermediary [`Vec<u8>`].
1694///
1695/// A future consumer that wants a [`Box<[u8]>`]-typed handle on a
1696/// [`RestartStrategy`] — a per-supervisor struct field typed [`Box<[u8]>`]
1697/// rather than [`Vec<u8>`] to trim the twenty-four-byte pointer + length +
1698/// capacity header down to the sixteen-byte pointer + length pair (a shape
1699/// the substrate acknowledges as the natural fixed-length storage for
1700/// once-written-never-mutated wire-scalar byte-tails held across the whole
1701/// operator reconciliation cycle), a future
1702/// `HashMap::<Box<[u8]>, _>::from_iter([(estrategia.into(), _)])`
1703/// per-strategy lookup where the map's key type is [`Box<[u8]>`] rather than
1704/// owned [`Vec<u8>`] so the map's per-entry key-slot carries the sixteen-
1705/// byte [`Box<[u8]>`] header instead of the twenty-four-byte [`Vec<u8>`]
1706/// header, a future M4 admission-webhook rejection body whose per-arm
1707/// error-frame composer accepts a [`Box<[u8]>`] intermediate for the same
1708/// reason — reaches the wire byte-string through this one dispatch, without
1709/// the pre-lift `Vec::<u8>::from(strategy).into_boxed_slice()` double-hop
1710/// that would still allocate through the same [`Vec<u8>`] intermediary on
1711/// the way to the same [`Box<[u8]>`] slot but with one extra header-slot
1712/// round-trip.
1713///
1714/// Peer of the paired owned-input [`From<RestartStrategy> for Vec<u8>`]
1715/// (98d38ed) and [`From<RestartStrategy> for std::borrow::Cow<'static,
1716/// [u8]>`] (7f81539) impls on the same primitive — the sibling
1717/// [`Vec<u8>`] axis returns a fresh heap allocation via
1718/// [`str::as_bytes`]`.to_vec()`; the sibling [`Cow<'static, [u8]>`] axis
1719/// binds the zero-alloc [`Cow::Borrowed`] arm on the same `&'static [u8]`
1720/// byte-tail; this axis allocates a fit-to-length boxed byte slice via
1721/// [`Box::<[u8]>::from(&[u8])`], preserving the fixed-length-storage
1722/// discipline the substrate opens on its byte-family reverse-projection
1723/// matrix across every closed-set fieldless typed enum peer.
1724///
1725/// Extends the substrate-wide trait-idiomatic *owned-input* byte-family
1726/// reverse-projection matrix onto the first M2-OTP-shape closed-set
1727/// fieldless typed enum peer at the [`Box<[u8]>`] corner — mirroring the
1728/// trajectory the same axis walked on the sibling [`crate::CaixaVersion`]
1729/// String-wrapper newtype primitive (98d38ed on [`Vec<u8>`], baf7537 on
1730/// [`Cow<'static, [u8]>`], 703b2fd on [`Box<[u8]>`], 3d5fc43 on
1731/// [`std::sync::Arc<[u8]>`], 6034943 on [`std::rc::Rc<[u8]>`]) and the
1732/// paired string-family [`Box<str>`] axis (69ef45c on the string-side).
1733/// Rust's standard library does not derive `From<Self> for Box<[u8]>` from
1734/// `From<Self> for Vec<u8>` (nor from `From<Self> for Cow<'static, [u8]>`),
1735/// so every closed-set fieldless typed enum peer that carries the paired
1736/// reverse [`Vec<u8>`] axis but not the paired [`Box<[u8]>`] axis forces
1737/// every [`Box<[u8]>`]-typed call site through a
1738/// `Vec::<u8>::from(strategy).into_boxed_slice()` intermediary allocation
1739/// whose bounds carry no compile-time link back to the substrate primitive.
1740///
1741/// Pinned load-bearing by
1742/// [`tests::restart_strategy_from_into_owned_box_bytes_routes_through_as_str_accessor`]
1743/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()`
1744/// across the four-arm [`RestartStrategy::ALL`] accept-set on the owned-
1745/// input surface, plus a cross-axis witness against the paired owned-input
1746/// [`From<RestartStrategy> for Vec<u8>`] and
1747/// [`From<RestartStrategy> for Cow<'static, [u8]>`] byte-owned reverse-
1748/// projection axes and the paired string-side [`Box<str>`] axis on every
1749/// canonical `PascalCase` scalar, closing the "owned-input into `Vec<u8>`
1750/// vs. `Cow<'static, [u8]>` vs. `Box<[u8]>`" three-corner partition on the
1751/// same wire byte-string).
1752impl From<RestartStrategy> for Box<[u8]> {
1753    fn from(strategy: RestartStrategy) -> Box<[u8]> {
1754        Box::<[u8]>::from(strategy.as_str().as_bytes())
1755    }
1756}
1757
1758/// Trait-idiomatic *borrowed-input, [`Box<[u8]>`] output* byte-owned reverse
1759/// projection on the first M2-OTP-shape closed-set fieldless typed enum peer
1760/// on the caixa surface ([`RestartStrategy`]) — the borrowed-input companion
1761/// to the paired owned-input [`From<RestartStrategy> for Box<[u8]>`] impl
1762/// immediately above, closing the `{Self, &Self} → Box<[u8]>` byte-owned
1763/// reverse-projection family on this primitive at the borrowed-input corner.
1764/// Routes byte-for-byte through the same substrate-primitive
1765/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1766/// [`Box::<[u8]>::from`] on the returned `&'static str`'s [`str::as_bytes`]
1767/// — the [`Box<[u8]>`] allocation happens on both input axes because
1768/// [`Self::as_str`] returns `&'static str` regardless of the input shape,
1769/// so the borrowed-input peer reaches the same wire byte-string through the
1770/// same one-heap-allocation path the owned-input peer already carries.
1771///
1772/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
1773/// U: From<T>` (nor a `Copy`-based
1774/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
1775/// fieldless typed enum peer that carries the paired owned-input
1776/// [`Box<[u8]>`] axis but not the borrowed-input axis forces every borrowed
1777/// call site through a spurious [`Copy`] deref
1778/// (`Box::<[u8]>::from(*strategy)`) or an open-coded
1779/// `Box::<[u8]>::from(strategy.as_str().as_bytes())` whose type bounds have
1780/// no compile-time link to the substrate primitive.
1781///
1782/// Pinned load-bearing by
1783/// [`tests::restart_strategy_from_borrowed_into_owned_box_bytes_routes_through_as_str_accessor`]
1784/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()` via a
1785/// borrowed input across the four-arm [`RestartStrategy::ALL`] accept-set,
1786/// plus a source-survival witness against silent move-out and a cross-
1787/// corner partition pin between owned-input and borrowed-input on the same
1788/// wire byte-string through the [`Box<[u8]>`] axis).
1789impl From<&RestartStrategy> for Box<[u8]> {
1790    fn from(strategy: &RestartStrategy) -> Box<[u8]> {
1791        Box::<[u8]>::from(strategy.as_str().as_bytes())
1792    }
1793}
1794
1795/// Trait-idiomatic *owned-input, [`std::sync::Arc<[u8]>`] output* byte-owned
1796/// reverse projection on the first M2-OTP-shape closed-set fieldless typed
1797/// enum peer on the caixa surface ([`RestartStrategy`]) — the
1798/// atomically-refcounted byte-slice mirror of the paired owned-input
1799/// [`From<RestartStrategy> for std::sync::Arc<str>`] (1244+ str-side) impl on
1800/// the string-side reverse-projection matrix, and the fourth axis in the
1801/// byte-side reverse-projection matrix that already carries
1802/// [`From<RestartStrategy> for Vec<u8>`] (98d38ed-pair on this enum),
1803/// [`From<RestartStrategy> for std::borrow::Cow<'static, [u8]>`] (7f81539),
1804/// and [`From<RestartStrategy> for Box<[u8]>`] (e11150e). Routes byte-for-
1805/// byte through the substrate-primitive [`RestartStrategy::as_str`]
1806/// `pub const fn` accessor via [`std::sync::Arc::<[u8]>::from`] on the
1807/// returned `&'static str`'s [`str::as_bytes`] — the four `match` arms in
1808/// [`Self::as_str`] resolve to [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
1809/// `pub const &'static str` bodies, so `.as_bytes()` returns `&'static [u8]`
1810/// by construction, and the standard-library
1811/// [`std::sync::Arc::<[u8]>::from(&[u8])`] impl allocates a fresh
1812/// atomically-refcounted heap slab whose header carries the strong + weak
1813/// counters the [`std::sync::Arc<[u8]>`] layout requires in one heap
1814/// allocation without an intermediary [`Vec<u8>`] or [`Box<[u8]>`].
1815///
1816/// A future consumer that wants a [`std::sync::Arc<[u8]>`]-typed handle on
1817/// a [`RestartStrategy`] — a share-through-clone byte-tail held across a
1818/// per-supervisor `caixa-operator` reconcile task where every spawn point
1819/// wants a cheap `.clone()` on the strategy's byte view without each task
1820/// re-allocating its own [`Vec<u8>`] copy (the [`std::sync::Arc::clone`]
1821/// path bumps the atomic refcount in place and returns a pointer-width
1822/// handle), a future `HashMap::<std::sync::Arc<[u8]>, _>::from_iter`
1823/// per-strategy lookup keyed by the byte-tail across worker threads, a
1824/// future M4 admission-webhook decoder that materializes decoded
1825/// `spec.estrategia` byte-tails as [`std::sync::Arc<[u8]>`] slices so
1826/// downstream verdict-composer tasks share the immutable byte-tail without
1827/// a per-consumer [`Vec::<u8>::clone`] — reaches the wire byte-string
1828/// through this one dispatch, without the pre-lift
1829/// `Box::<[u8]>::from(strategy).into::<Arc<[u8]>>()` double-hop that would
1830/// still allocate the same [`Arc<[u8]>`] slab plus one intermediary
1831/// [`Box<[u8]>`] between the enum peer and the [`std::sync::Arc<[u8]>`]
1832/// slot.
1833///
1834/// Peer of the paired owned-input [`From<RestartStrategy> for Vec<u8>`],
1835/// [`From<RestartStrategy> for Cow<'static, [u8]>`], and
1836/// [`From<RestartStrategy> for Box<[u8]>`] impls on the same primitive —
1837/// the sibling [`Vec<u8>`] axis returns a fresh heap allocation via
1838/// [`str::as_bytes`]`.to_vec()`; the sibling [`Cow<'static, [u8]>`] axis
1839/// binds the zero-alloc [`Cow::Borrowed`] arm on the same `&'static [u8]`
1840/// byte-tail; the sibling [`Box<[u8]>`] axis allocates a fit-to-length
1841/// boxed byte slice via [`Box::<[u8]>::from(&[u8])`]; this axis allocates
1842/// an atomically-refcounted heap slab whose header carries the strong +
1843/// weak counters the [`std::sync::Arc<[u8]>`] layout requires. Rust's
1844/// standard library does not derive `From<Self> for Arc<[u8]>` from
1845/// `From<Self> for Box<[u8]>` (nor from `From<Self> for Vec<u8>`), so every
1846/// closed-set fieldless typed enum peer that carries the paired
1847/// [`Box<[u8]>`] axis but not the paired [`Arc<[u8]>`] axis forces every
1848/// [`Arc<[u8]>`]-typed call site through a
1849/// `Box::<[u8]>::from(strategy).into()` /
1850/// `Arc::<[u8]>::from(Vec::<u8>::from(strategy))` intermediary allocation
1851/// whose bounds carry no compile-time link back to the substrate primitive.
1852///
1853/// Extends the substrate-wide trait-idiomatic *owned-input* byte-family
1854/// reverse-projection matrix onto the first M2-OTP-shape closed-set
1855/// fieldless typed enum peer at the [`std::sync::Arc<[u8]>`] corner —
1856/// mirroring the trajectory the same axis walked on the sibling
1857/// [`crate::CaixaVersion`] String-wrapper newtype primitive (98d38ed on
1858/// [`Vec<u8>`], baf7537 on [`Cow<'static, [u8]>`], 703b2fd on [`Box<[u8]>`],
1859/// 3d5fc43 on [`std::sync::Arc<[u8]>`], 6034943 on [`std::rc::Rc<[u8]>`]).
1860///
1861/// Pinned load-bearing by
1862/// [`tests::restart_strategy_from_into_owned_arc_bytes_routes_through_as_str_accessor`]
1863/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()`
1864/// across the four-arm [`RestartStrategy::ALL`] accept-set on the owned-
1865/// input surface, plus a cross-axis witness against the paired owned-input
1866/// [`From<RestartStrategy> for Vec<u8>`],
1867/// [`From<RestartStrategy> for Cow<'static, [u8]>`], and
1868/// [`From<RestartStrategy> for Box<[u8]>`] byte-owned reverse-projection
1869/// axes on every canonical `PascalCase` scalar, closing the "owned-input
1870/// into `Vec<u8>` vs. `Cow<'static, [u8]>` vs. `Box<[u8]>` vs. `Arc<[u8]>`"
1871/// four-corner partition on the same wire byte-string).
1872impl From<RestartStrategy> for std::sync::Arc<[u8]> {
1873    fn from(strategy: RestartStrategy) -> std::sync::Arc<[u8]> {
1874        std::sync::Arc::<[u8]>::from(strategy.as_str().as_bytes())
1875    }
1876}
1877
1878/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<[u8]>`] output*
1879/// byte-owned reverse projection on the first M2-OTP-shape closed-set
1880/// fieldless typed enum peer on the caixa surface ([`RestartStrategy`]) —
1881/// the borrowed-input companion to the paired owned-input
1882/// [`From<RestartStrategy> for std::sync::Arc<[u8]>`] impl immediately
1883/// above, closing the `{Self, &Self} → std::sync::Arc<[u8]>` byte-owned
1884/// reverse-projection family on this primitive at the borrowed-input
1885/// corner. Routes byte-for-byte through the same substrate-primitive
1886/// [`RestartStrategy::as_str`] `pub const fn` accessor via
1887/// [`std::sync::Arc::<[u8]>::from`] on the returned `&'static str`'s
1888/// [`str::as_bytes`] — the [`std::sync::Arc<[u8]>`] allocation happens on
1889/// both input axes because [`Self::as_str`] returns `&'static str`
1890/// regardless of the input shape, so the borrowed-input peer reaches the
1891/// same wire byte-string through the same one-heap-allocation path the
1892/// owned-input peer already carries.
1893///
1894/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
1895/// U: From<T>` (nor a `Copy`-based
1896/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
1897/// fieldless typed enum peer that carries the paired owned-input
1898/// [`std::sync::Arc<[u8]>`] axis but not the borrowed-input axis forces
1899/// every borrowed call site through a spurious [`Copy`] deref
1900/// (`std::sync::Arc::<[u8]>::from(*strategy)`) or an open-coded
1901/// `std::sync::Arc::<[u8]>::from(strategy.as_str().as_bytes())` whose type
1902/// bounds have no compile-time link to the substrate primitive.
1903///
1904/// Pinned load-bearing by
1905/// [`tests::restart_strategy_from_borrowed_into_owned_arc_bytes_routes_through_as_str_accessor`]
1906/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()` via a
1907/// borrowed input across the four-arm [`RestartStrategy::ALL`] accept-set,
1908/// plus a source-survival witness against silent move-out and a cross-
1909/// corner partition pin between owned-input and borrowed-input on the same
1910/// wire byte-string through the [`std::sync::Arc<[u8]>`] axis).
1911impl From<&RestartStrategy> for std::sync::Arc<[u8]> {
1912    fn from(strategy: &RestartStrategy) -> std::sync::Arc<[u8]> {
1913        std::sync::Arc::<[u8]>::from(strategy.as_str().as_bytes())
1914    }
1915}
1916
1917/// Trait-idiomatic *owned-input, [`std::rc::Rc<[u8]>`] output* byte-owned
1918/// reverse projection on the first M2-OTP-shape closed-set fieldless typed
1919/// enum peer on the caixa surface ([`RestartStrategy`]) — the
1920/// single-threaded-refcounted byte-slice mirror of the paired owned-input
1921/// [`From<RestartStrategy> for std::rc::Rc<str>`] (1370+ str-side) impl on
1922/// the string-side reverse-projection matrix, and the fifth (and final)
1923/// axis on the byte-side reverse-projection matrix that already carries
1924/// [`From<RestartStrategy> for Vec<u8>`], [`From<RestartStrategy> for
1925/// std::borrow::Cow<'static, [u8]>`] (7f81539), [`From<RestartStrategy>
1926/// for Box<[u8]>`] (e11150e), and [`From<RestartStrategy> for
1927/// std::sync::Arc<[u8]>`] (98da8f6). Routes byte-for-byte through the
1928/// substrate-primitive [`RestartStrategy::as_str`] `pub const fn` accessor
1929/// via [`std::rc::Rc::<[u8]>::from`] on the returned `&'static str`'s
1930/// [`str::as_bytes`] — the four `match` arms in [`Self::as_str`] resolve
1931/// to [`crate::render::SUPERVISOR_ESTRATEGIA_*`] `pub const &'static str`
1932/// bodies, so `.as_bytes()` returns `&'static [u8]` by construction, and
1933/// the standard-library [`std::rc::Rc::<[u8]>::from(&[u8])`] impl allocates
1934/// a fresh single-threaded-refcounted heap slab whose header carries the
1935/// non-atomic strong + weak counters the [`std::rc::Rc<[u8]>`] layout
1936/// requires in one heap allocation without an intermediary [`Vec<u8>`],
1937/// [`Box<[u8]>`], or [`std::sync::Arc<[u8]>`].
1938///
1939/// A future consumer that wants a [`std::rc::Rc<[u8]>`]-typed handle on
1940/// a [`RestartStrategy`] — a single-threaded `feira lint` per-caixa
1941/// diagnostic table whose per-column payload carries the strategy's
1942/// byte-view through a chain of Nord-themed emitters via the pointer-
1943/// width [`std::rc::Rc::clone`] handle (a non-atomic refcount bump,
1944/// cheaper than the paired atomic increment on the sibling
1945/// [`std::sync::Arc<[u8]>`] axis by a measurable margin on hot
1946/// single-threaded call sites), a future single-threaded
1947/// `HashMap::<std::rc::Rc<[u8]>, _>::from_iter` per-strategy lookup keyed
1948/// by the byte-tail across the `feira supervisor --estrategia …`
1949/// composer's per-arg cache, a future non-`Send` planner that
1950/// materializes decoded `spec.estrategia` byte-tails as
1951/// [`std::rc::Rc<[u8]>`] slices so downstream single-threaded verdict
1952/// composers share the immutable byte-tail without a per-consumer
1953/// [`Vec::<u8>::clone`] — reaches the wire byte-string through this one
1954/// dispatch, without the pre-lift
1955/// `Box::<[u8]>::from(strategy).into::<Rc<[u8]>>()` /
1956/// `Rc::<[u8]>::from(Vec::<u8>::from(strategy))` double-hop that would
1957/// still allocate the same [`Rc<[u8]>`] slab plus one intermediary
1958/// [`Box<[u8]>`] or [`Vec<u8>`] between the enum peer and the
1959/// [`std::rc::Rc<[u8]>`] slot.
1960///
1961/// Peer of the paired owned-input [`From<RestartStrategy> for Vec<u8>`],
1962/// [`From<RestartStrategy> for Cow<'static, [u8]>`],
1963/// [`From<RestartStrategy> for Box<[u8]>`], and
1964/// [`From<RestartStrategy> for std::sync::Arc<[u8]>`] impls on the same
1965/// primitive — the sibling [`Vec<u8>`] axis returns a fresh heap
1966/// allocation via [`str::as_bytes`]`.to_vec()`; the sibling
1967/// [`Cow<'static, [u8]>`] axis binds the zero-alloc [`Cow::Borrowed`]
1968/// arm on the same `&'static [u8]` byte-tail; the sibling [`Box<[u8]>`]
1969/// axis allocates a fit-to-length boxed byte slice via
1970/// [`Box::<[u8]>::from(&[u8])`]; the sibling [`std::sync::Arc<[u8]>`]
1971/// axis allocates an atomically-refcounted heap slab; this axis
1972/// allocates a single-threaded-refcounted heap slab whose header carries
1973/// the non-atomic strong + weak counters the [`std::rc::Rc<[u8]>`]
1974/// layout requires. Rust's standard library does not derive
1975/// `From<Self> for Rc<[u8]>` from `From<Self> for Arc<[u8]>` (the two
1976/// layouts share the same on-disk shape but the trait tables are
1977/// disjoint, and no blanket `impl<T> From<T> for Rc<[u8]> where
1978/// Arc<[u8]>: From<T>` exists in `core`), so every closed-set fieldless
1979/// typed enum peer that carries the paired [`Arc<[u8]>`] axis but not
1980/// the paired [`Rc<[u8]>`] axis forces every single-threaded
1981/// [`Rc<[u8]>`]-typed call site through a
1982/// `Arc::<[u8]>::from(strategy).into()` /
1983/// `Rc::<[u8]>::from(Vec::<u8>::from(strategy))` double-allocation
1984/// detour whose bounds carry no compile-time link back to the substrate
1985/// primitive.
1986///
1987/// Closes the trait-idiomatic *owned-input* byte-family reverse-
1988/// projection matrix on the first M2-OTP-shape closed-set fieldless
1989/// typed enum peer at the [`std::rc::Rc<[u8]>`] corner — completing the
1990/// full `{Vec<u8>, Cow<'static, [u8]>, Box<[u8]>, Arc<[u8]>, Rc<[u8]>}`
1991/// five-corner partition on [`RestartStrategy`], mirroring the trajectory
1992/// the same axis walked on the sibling [`crate::CaixaVersion`]
1993/// String-wrapper newtype primitive (98d38ed on [`Vec<u8>`], baf7537 on
1994/// [`Cow<'static, [u8]>`], 703b2fd on [`Box<[u8]>`], 3d5fc43 on
1995/// [`std::sync::Arc<[u8]>`], 6034943 on [`std::rc::Rc<[u8]>`]).
1996///
1997/// Pinned load-bearing by
1998/// [`tests::restart_strategy_from_into_owned_rc_bytes_routes_through_as_str_accessor`]
1999/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()`
2000/// across the four-arm [`RestartStrategy::ALL`] accept-set on the owned-
2001/// input surface, plus a cross-axis witness against the paired owned-
2002/// input [`From<RestartStrategy> for Vec<u8>`], [`From<RestartStrategy>
2003/// for Cow<'static, [u8]>`], [`From<RestartStrategy> for Box<[u8]>`],
2004/// and [`From<RestartStrategy> for std::sync::Arc<[u8]>`] byte-owned
2005/// reverse-projection axes on every canonical `PascalCase` scalar,
2006/// closing the "owned-input into `Vec<u8>` vs. `Cow<'static, [u8]>` vs.
2007/// `Box<[u8]>` vs. `Arc<[u8]>` vs. `Rc<[u8]>`" five-corner partition on
2008/// the same wire byte-string).
2009impl From<RestartStrategy> for std::rc::Rc<[u8]> {
2010    fn from(strategy: RestartStrategy) -> std::rc::Rc<[u8]> {
2011        std::rc::Rc::<[u8]>::from(strategy.as_str().as_bytes())
2012    }
2013}
2014
2015/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<[u8]>`] output*
2016/// byte-owned reverse projection on the first M2-OTP-shape closed-set
2017/// fieldless typed enum peer on the caixa surface ([`RestartStrategy`]) —
2018/// the borrowed-input companion to the paired owned-input
2019/// [`From<RestartStrategy> for std::rc::Rc<[u8]>`] impl immediately
2020/// above, closing the `{Self, &Self} → std::rc::Rc<[u8]>` byte-owned
2021/// reverse-projection family on this primitive at the borrowed-input
2022/// corner. Routes byte-for-byte through the same substrate-primitive
2023/// [`RestartStrategy::as_str`] `pub const fn` accessor via
2024/// [`std::rc::Rc::<[u8]>::from`] on the returned `&'static str`'s
2025/// [`str::as_bytes`] — the [`std::rc::Rc<[u8]>`] allocation happens on
2026/// both input axes because [`Self::as_str`] returns `&'static str`
2027/// regardless of the input shape, so the borrowed-input peer reaches the
2028/// same wire byte-string through the same one-heap-allocation path the
2029/// owned-input peer already carries.
2030///
2031/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
2032/// U: From<T>` (nor a `Copy`-based
2033/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
2034/// fieldless typed enum peer that carries the paired owned-input
2035/// [`std::rc::Rc<[u8]>`] axis but not the borrowed-input axis forces
2036/// every borrowed call site through a spurious [`Copy`] deref
2037/// (`std::rc::Rc::<[u8]>::from(*strategy)`) or an open-coded
2038/// `std::rc::Rc::<[u8]>::from(strategy.as_str().as_bytes())` whose type
2039/// bounds have no compile-time link to the substrate primitive.
2040///
2041/// Pinned load-bearing by
2042/// [`tests::restart_strategy_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor`]
2043/// (byte-parity pin against [`RestartStrategy::as_str`] `.as_bytes()` via a
2044/// borrowed input across the four-arm [`RestartStrategy::ALL`] accept-set,
2045/// plus a source-survival witness against silent move-out and a cross-
2046/// corner partition pin between owned-input and borrowed-input on the same
2047/// wire byte-string through the [`std::rc::Rc<[u8]>`] axis).
2048impl From<&RestartStrategy> for std::rc::Rc<[u8]> {
2049    fn from(strategy: &RestartStrategy) -> std::rc::Rc<[u8]> {
2050        std::rc::Rc::<[u8]>::from(strategy.as_str().as_bytes())
2051    }
2052}
2053
2054/// Trait-idiomatic *borrowed byte-slice input* reverse projection on the
2055/// first M2-OTP-shape closed-set fieldless typed enum peer on the caixa
2056/// surface ([`RestartStrategy`]) — the byte-view mirror of the str-view
2057/// reverse-projection axis carried by the paired
2058/// [`TryFrom<&str> for RestartStrategy`] impl (which routes through the
2059/// substrate-primitive [`RestartStrategy::from_wire`] `Option<Self>`
2060/// accessor on the four-arm `PascalCase` accept-set the sibling
2061/// [`RestartStrategy::as_str`] emitter returns). Routes byte-for-byte
2062/// through the standard-library [`std::str::from_utf8`] UTF-8 validator
2063/// and then through [`RestartStrategy::from_wire`] so every consumer that
2064/// holds a borrowed [`&[u8]`] and needs to project it back into a typed
2065/// [`RestartStrategy`] — a future `bytes::Bytes::as_ref()`-fed reader
2066/// that parses a per-supervisor `:estrategia` `PascalCase` wire scalar
2067/// from an already-borrowed framing byte-tail (a
2068/// `tracing::field::valuable::Value::Bytes` recorder on the future
2069/// wasm-operator's per-supervisor sibling-restart-strategy diagnostic
2070/// emission path, a future audit-report re-loader binding a prior
2071/// [`RestartStrategy::as_str`] output from a mmap'd byte-slice back
2072/// through the typed enum for cross-run comparison), a future M4
2073/// `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook rejection
2074/// body that reads a `spec.estrategia` field off a raw HTTP body byte-
2075/// slice before UTF-8 validation commits allocation, a future generic
2076/// `<T: for<'a> TryFrom<&'a [u8]>>`-bound loader over any of the
2077/// substrate's closed-set typed enums — reaches the same four-arm
2078/// `PascalCase` wire accept-set the sibling method-named
2079/// [`RestartStrategy::from_wire`] resolver and the paired trait-idiomatic
2080/// [`TryFrom<&str>`] axis already resolve against, rather than an open-
2081/// coded per-call-site
2082/// `std::str::from_utf8(bytes).ok().and_then(RestartStrategy::from_wire)`
2083/// composition or a
2084/// `<RestartStrategy as TryFrom<&str>>::try_from(std::str::from_utf8(bytes)?)`
2085/// two-hop shape whose type bounds have no compile-time link to the
2086/// substrate primitive.
2087///
2088/// Extends the substrate-wide trait-idiomatic *byte-view reverse-
2089/// projection* family — opened on the structurally most fundamental
2090/// closed-set fieldless typed enum peer ([`crate::CaixaKind`], commit
2091/// 18d1940), extended onto the second caixa-core-internal peer
2092/// ([`crate::CaixaDialeto`], commit d102cb8) and the third
2093/// ([`crate::dep::DepList`], commit b8f25d5) — onto the first
2094/// M2-OTP-shape supervisor-slot closed-set fieldless typed enum peer,
2095/// tracking the "route through `from_wire` via `std::str::from_utf8`"
2096/// discipline the first-mover established. Rust's standard library
2097/// carries no blanket
2098/// `impl<T: for<'a> TryFrom<&'a str>> TryFrom<&[u8]> for T`, so a two-
2099/// hop composition through [`std::str::from_utf8`] + the paired
2100/// [`TryFrom<&str>`] axis is reachable at every call site but has no
2101/// compile-time link back to the byte-view reverse-projection axis.
2102/// Every remaining closed-set fieldless typed enum peer on the substrate
2103/// ([`RestartPolicy`], [`crate::aplicacao::PlacementStrategy`],
2104/// [`crate::aplicacao::RateLimitUnit`], [`crate::aplicacao::WitShape`],
2105/// and the outside-`caixa-core` peers `PathShapeViolation`,
2106/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`, `Semantic`,
2107/// `FerriteRuntime`) is a future target of the campaign, mirroring the
2108/// trajectory the closed byte-owned reverse-projection family walked
2109/// arm-by-arm onto each peer.
2110///
2111/// `type Error = ()` matches the sibling [`RestartStrategy::from_wire`]'s
2112/// `Option<Self>` return-shape's deliberate deferral of error typing and
2113/// the paired trait-idiomatic [`TryFrom<&str>`] axis's unit-error shape —
2114/// the caller picks the diagnostic form appropriate for its use site (a
2115/// future `feira supervisor --estrategia …` arg-parse composes its own
2116/// per-verb "unknown strategy: <arg> — accepted: {…}" message enumerating
2117/// [`RestartStrategy::WIRE_NAMES`]; a future admission-webhook rejection
2118/// body wraps the `Err(())` outcome with the accepted-set enumeration for
2119/// operator diagnostics; a `Result::map_err` at the call site lifts the
2120/// unit-error to a per-verb error type). Two rejection paths route
2121/// through the single unit-error: an invalid UTF-8 byte-sequence
2122/// ([`std::str::from_utf8`] returns `Err`) and a valid UTF-8 byte-string
2123/// that falls outside the four-arm `PascalCase` accept-set
2124/// ([`RestartStrategy::from_wire`] returns `None`) — both collapse onto
2125/// `Err(())` so the trait signature stays consistent with the sibling
2126/// str-view reverse axis, and a caller that needs to distinguish the two
2127/// failure modes composes [`std::str::from_utf8`] +
2128/// [`RestartStrategy::from_wire`] explicitly.
2129///
2130/// Pinned load-bearing by
2131/// [`tests::restart_strategy_try_from_bytes_routes_through_from_wire_accessor`]
2132/// (byte-parity pin against [`RestartStrategy::from_wire`] across the
2133/// four-arm [`RestartStrategy::ALL`] accept-set on the borrowed byte-
2134/// slice surface, plus a cross-axis witness that the byte-view reverse
2135/// projection agrees with the paired [`TryFrom<&str>`] str-view reverse
2136/// axis on every accepted arm) and
2137/// [`tests::restart_strategy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
2138/// (rejection witness against silent accept-set widening on both the
2139/// non-UTF-8 byte-sequence rejection path and the unknown-wire-vocabulary
2140/// rejection path — the latter includes the sibling kebab-case
2141/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so
2142/// a caller that confuses the two axes trips here rather than at a
2143/// downstream K8s-CR round-trip miss).
2144impl TryFrom<&[u8]> for RestartStrategy {
2145    type Error = ();
2146
2147    fn try_from(bytes: &[u8]) -> Result<Self, Self::Error> {
2148        std::str::from_utf8(bytes)
2149            .ok()
2150            .and_then(Self::from_wire)
2151            .ok_or(())
2152    }
2153}
2154
2155/// Trait-idiomatic *owned byte-vec input* reverse projection on the first
2156/// M2-OTP-shape supervisor-slot closed-set fieldless typed enum peer on the
2157/// caixa surface ([`RestartStrategy`]) — the owned-input peer of
2158/// [`TryFrom<&[u8]> for RestartStrategy`], mirroring the closed
2159/// [`From<RestartStrategy> for Vec<u8>`] + [`From<&RestartStrategy> for
2160/// Vec<u8>`] byte-owned *forward*-projection pair on this same enum onto
2161/// the byte-owned *reverse*-projection axis. Routes byte-for-byte through
2162/// [`<Self as TryFrom<&[u8]>>::try_from`] on the [`Vec<u8>::as_slice`]
2163/// borrow, so the owned-input surface reaches the same
2164/// [`std::str::from_utf8`] + [`RestartStrategy::from_wire`] resolution
2165/// chain the borrowed-input peer already carries — one substrate-primitive
2166/// accessor, one trait dispatch, no per-consumer detour.
2167///
2168/// Rust's standard library carries no blanket
2169/// `impl<T: for<'a> TryFrom<&'a [u8]>> TryFrom<Vec<u8>> for T`, so a
2170/// consumer that holds an owned [`Vec<u8>`] and needs a typed
2171/// [`RestartStrategy`] otherwise picks between (a) an open-coded
2172/// `<RestartStrategy as TryFrom<&[u8]>>::try_from(bytes.as_slice())` at
2173/// every call site (whose type bounds have no compile-time link to the
2174/// byte-owned reverse-projection axis), (b) a two-hop
2175/// `String::from_utf8(bytes)` + [`RestartStrategy::from_wire`] composition
2176/// whose error surface leaks the standard-library
2177/// [`std::string::FromUtf8Error`] (widening the sibling [`TryFrom<&[u8]>`]
2178/// axis's unit-error) and silently allocates a [`String`] on inputs that
2179/// will never make it past the wire vocabulary, or (c) an intermediate
2180/// `<RestartStrategy as TryFrom<&str>>::try_from(std::str::from_utf8(&bytes)?)`
2181/// three-hop shape. This impl closes the owned-byte-vec reverse-projection
2182/// axis at the substrate-primitive [`RestartStrategy::from_wire`] accessor
2183/// so every future `<T: TryFrom<Vec<u8>>>`-bound owned-byte-vec consumer —
2184/// a future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook
2185/// body reader that hands the `spec.estrategia` byte-tail off as a
2186/// [`Vec<u8>`] before UTF-8 validation commits allocation, a
2187/// `bytes::Bytes::to_vec()`-shape wire-body composer walking a prior
2188/// audit's per-supervisor rejection payload back to the typed enum, a
2189/// `std::io::Read::read_to_end`-shape audit-log source whose framing
2190/// yields an owned byte-vec per per-strategy scalar, an
2191/// `<T: TryFrom<Vec<u8>>>`-bound generic loader over any of the
2192/// substrate's closed-set typed enums — reaches the same four-arm
2193/// `PascalCase` wire accept-set through one trait dispatch.
2194///
2195/// Extends the substrate-wide trait-idiomatic *byte-owned reverse-
2196/// projection* family — opened on the structurally most fundamental
2197/// closed-set fieldless typed enum peer ([`crate::CaixaKind`], commit
2198/// 99c2849), extended onto the second caixa-core-internal peer
2199/// ([`crate::CaixaDialeto`], commit 83a1526) and the third
2200/// ([`crate::dep::DepList`], commit 42091cb) — onto the first M2-OTP-shape
2201/// supervisor-slot closed-set fieldless typed enum peer, tracking the
2202/// "delegate through `TryFrom<&[u8]>` on the `Vec<u8>::as_slice` borrow"
2203/// discipline the first-mover established. Every remaining closed-set
2204/// fieldless typed enum peer on the substrate ([`RestartPolicy`],
2205/// [`crate::aplicacao::PlacementStrategy`],
2206/// [`crate::aplicacao::RateLimitUnit`], [`crate::aplicacao::WitShape`],
2207/// [`crate::render::PathShapeViolation`], and the outside-`caixa-core`
2208/// peers `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`,
2209/// `Semantic`, `FerriteRuntime`) is a future target of the campaign,
2210/// mirroring the trajectory the closed byte-view reverse-projection
2211/// family (`TryFrom<&[u8]>`) and the closed byte-owned forward-projection
2212/// family (`From<{Self, &Self}> for Vec<u8>`) already walked.
2213///
2214/// `type Error = ()` matches the sibling [`TryFrom<&[u8]> for
2215/// RestartStrategy`] unit-error shape, preserving the trait-family
2216/// consistency across the borrowed-and-owned byte-view reverse-projection
2217/// pair. The owned [`Vec<u8>`] input is dropped on the error path (the
2218/// standard-library `String::from_utf8` convention of returning the input
2219/// in the error deliberately declined — a caller that needs the bytes
2220/// back holds a clone before the call, and the closed-set-enum use site
2221/// rarely wants the raw bytes back past a "did you mean" diagnostic that
2222/// operates on the wire vocabulary rather than the input).
2223///
2224/// Pinned load-bearing by
2225/// [`tests::restart_strategy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
2226/// (byte-parity pin against the paired borrowed [`TryFrom<&[u8]>`] axis
2227/// across the four-arm [`RestartStrategy::ALL`] accept-set on the owned
2228/// byte-vec surface, cross-axis witness that the byte-owned reverse
2229/// projection agrees with the paired str-view reverse-projection axis
2230/// ([`TryFrom<&str>`]) on every accepted arm through the shared
2231/// substrate-primitive [`RestartStrategy::from_wire`] accessor, and a
2232/// four-corner {owned-input, borrowed-input} × {`From<Self>` → `Vec<u8>`,
2233/// `From<&Self>` → `Vec<u8>`} round-trip witness available on this enum
2234/// because [`RestartStrategy::as_str`] and [`RestartStrategy::from_wire`]
2235/// share one `PascalCase` byte-vocabulary — unlike the sibling
2236/// [`crate::CaixaKind`] which its peer test deliberately declines the
2237/// four-corner witness on because the wire/diagnostic split makes the
2238/// forward and reverse pairs speak different byte-strings) and
2239/// [`tests::restart_strategy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
2240/// (rejection witness against silent accept-set widening on both the
2241/// non-UTF-8 byte-sequence rejection path and the unknown-wire-vocabulary
2242/// rejection path — the latter includes the sibling kebab-case
2243/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so
2244/// a caller that confuses the two axes trips here rather than at a
2245/// downstream K8s-CR round-trip miss, plus a cross-axis witness that the
2246/// owned byte-vec reverse-projection axis agrees with the borrowed byte-
2247/// slice reverse-projection axis on every rejected input).
2248impl TryFrom<Vec<u8>> for RestartStrategy {
2249    type Error = ();
2250
2251    fn try_from(bytes: Vec<u8>) -> Result<Self, Self::Error> {
2252        <Self as TryFrom<&[u8]>>::try_from(bytes.as_slice())
2253    }
2254}
2255
2256/// Trait-idiomatic *owned-`String` input, `Result<Self, ()>` output*
2257/// string-owned reverse projection on the first M2-OTP-shape supervisor-slot
2258/// closed-set fieldless typed enum peer on the caixa surface
2259/// ([`RestartStrategy`]) — the owned-input peer of the paired
2260/// [`TryFrom<&str> for RestartStrategy`] str-view reverse-projection axis, and
2261/// the string-owned reverse companion of the pre-existing string-owned
2262/// *forward* pair ([`From<RestartStrategy> for String`],
2263/// [`From<&RestartStrategy> for String`]) already lifted on this same enum.
2264/// Routes owned [`String`] input through the paired borrowed-input
2265/// [`TryFrom<&str>`] axis via [`String::as_str`] so every consumer that holds
2266/// an owned `String` — a future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
2267/// admission-webhook body reader that hands the `spec.estrategia`
2268/// `PascalCase` scalar off as an owned [`String`] after UTF-8 validation, a
2269/// `serde_yaml::from_str` / `serde_json::from_str` de-serialize round-trip
2270/// whose composer surfaces the `:estrategia` scalar as an owned [`String`]
2271/// typed field, a `feira supervisor --estrategia <OneForOne|OneForAll|
2272/// RestForOne|SimpleOneForOne>` `clap`-derived arg-parse whose owned-`String`
2273/// positional lands the canonical arm at the typed dispatch, a
2274/// per-`:supervisor`-slot overlay resolver reading an owned [`String`] out of
2275/// a `ConfigMap` `data.supervisor-estrategia` scalar, an
2276/// `<T: TryFrom<String>>`-bound generic loader over any of the substrate's
2277/// closed-set typed enums — reaches the same four-arm `PascalCase` accept-set
2278/// through one trait dispatch.
2279///
2280/// Extends the substrate-wide trait-idiomatic *string-owned reverse-
2281/// projection* family — opened on the compound M3-mesh
2282/// `:politicas :rate-limit` primitive [`crate::aplicacao::RateLimit`]
2283/// (a2e6f02), lifted onto the first closed-set fieldless typed-enum peer
2284/// [`crate::aplicacao::WitShape`] (e6aac29), extended onto the second closed-
2285/// set fieldless typed-enum peer [`crate::aplicacao::RateLimitUnit`]
2286/// (94a9c5e), extended onto the third closed-set fieldless typed-enum peer
2287/// [`crate::aplicacao::PlacementStrategy`] (d81a70a) — onto the first
2288/// M2-OTP-shape supervisor-slot closed-set fieldless typed-enum peer, the
2289/// per-`:supervisor` sibling-restart-strategy discriminator. The peers
2290/// [`RestartPolicy`], [`crate::CaixaKind`], [`crate::CaixaDialeto`], and
2291/// [`crate::dep::DepList`] remain the next targets of the campaign, mirroring
2292/// the trajectory the closed byte-view / byte-owned reverse-projection
2293/// families already walked across the same closed-set peers.
2294///
2295/// Rust's standard library carries no blanket
2296/// `impl<T: for<'a> TryFrom<&'a str>> TryFrom<String> for T`, so a consumer
2297/// that holds an owned [`String`] and needs a typed [`RestartStrategy`]
2298/// otherwise picks between (a) an open-coded
2299/// `<RestartStrategy as TryFrom<&str>>::try_from(s.as_str())` at every call
2300/// site whose type bounds have no compile-time link back to the string-owned
2301/// reverse-projection axis, (b) a `let s: &str = &s;
2302/// RestartStrategy::try_from(s)` two-step whose borrow arithmetic leaks a
2303/// per-call-site lifetime dance rather than a single trait dispatch, or (c) a
2304/// `String::into_bytes` + [`TryFrom<Vec<u8>>`] detour that reaches the
2305/// substrate-primitive `from_wire` accessor through a UTF-8 re-validation hop
2306/// the owned-`String` axis already knows to skip. This impl closes the
2307/// string-owned reverse-projection axis at the substrate-primitive
2308/// [`RestartStrategy::from_wire`] accessor so every future
2309/// `<T: TryFrom<String>>`-bound owned-string consumer reaches the same
2310/// four-arm `PascalCase` accept-set through one trait dispatch.
2311///
2312/// `type Error = ()` matches the sibling [`TryFrom<&str> for
2313/// RestartStrategy`], [`TryFrom<&[u8]> for RestartStrategy`], and
2314/// [`TryFrom<Vec<u8>> for RestartStrategy`] unit-error shapes, preserving the
2315/// trait-family consistency across the {str-view, byte-view, byte-owned,
2316/// string-owned} reverse-projection square. The owned [`String`] input is
2317/// dropped on the error path (the standard-library `String::from_utf8`
2318/// convention of returning the input in the error deliberately declined — a
2319/// caller that needs the string back holds a clone before the call, and the
2320/// closed-set-enum use site rarely wants the raw string back past a "did you
2321/// mean" diagnostic that operates on the wire vocabulary rather than the
2322/// input).
2323///
2324/// Pinned load-bearing by
2325/// [`tests::restart_strategy_try_from_owned_string_routes_through_borrowed_str_view_axis`]
2326/// (byte-parity pin against the paired borrowed [`TryFrom<&str>`] axis across
2327/// the four-arm [`RestartStrategy::ALL`] accept-set on the owned-`String`
2328/// surface, cross-axis witness that the string-owned reverse projection
2329/// agrees with the sibling byte-view / byte-owned reverse-projection axes on
2330/// every accepted arm through the shared substrate-primitive
2331/// [`RestartStrategy::from_wire`] accessor, and a closed-cycle witness
2332/// against the paired string-owned forward-projection pair — `Self → String
2333/// → TryFrom<String> → Self` round-trips to the originating arm on every
2334/// canonical `PascalCase` scalar) and
2335/// [`tests::restart_strategy_try_from_owned_string_rejects_unknown_wire_strings`]
2336/// (rejection witness against silent accept-set widening — mirrors the
2337/// corpus the paired [`TryFrom<&str>`] rejection witness already pins,
2338/// including empty / whitespace-only inputs, the sibling kebab-case
2339/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so a
2340/// caller that confuses the two axes trips here rather than at a downstream
2341/// K8s-CR round-trip miss, case-fold rebrand candidates, whitespace-padded /
2342/// trailing-newline / quote-wrapped forms, and English-rebrand candidates,
2343/// with per-input cross-axis parity against the borrowed [`TryFrom<&str>`]
2344/// reverse-projection axis).
2345impl TryFrom<String> for RestartStrategy {
2346    type Error = ();
2347
2348    fn try_from(s: String) -> Result<Self, Self::Error> {
2349        <Self as TryFrom<&str>>::try_from(s.as_str())
2350    }
2351}
2352
2353/// Per-child restart policy.
2354///
2355/// Permanent / Temporary / Transient match Erlang/OTP semantics 1:1.
2356#[derive(
2357    Serialize,
2358    Deserialize,
2359    Debug,
2360    Clone,
2361    Copy,
2362    PartialEq,
2363    Eq,
2364    Hash,
2365    gen_platform::TypedDispatcher,
2366    gen_platform::Discriminant,
2367    gen_platform::IsVariant,
2368    gen_platform::FromStrKind,
2369)]
2370pub enum RestartPolicy {
2371    /// Always restart the child, regardless of how it died. Used for
2372    /// long-running services that must always be up.
2373    Permanent,
2374    /// Never restart. Used for one-shot work whose completion is
2375    /// itself the success signal (`oneShot` triggers map here).
2376    Temporary,
2377    /// Restart only when the child died *abnormally* (non-zero exit
2378    /// or unhandled exception). A clean exit completes the child.
2379    Transient,
2380}
2381
2382impl Default for RestartPolicy {
2383    fn default() -> Self {
2384        // Route the [`Default for RestartPolicy`] impl's return arm through
2385        // the substrate-canonical [`SUPERVISOR_CHILD_RESTART_DEFAULT`] typed
2386        // `pub const` rather than a raw `Self::Permanent` arm — one source
2387        // of truth for the Erlang/OTP-canonical `permanent` worker-child
2388        // default across the two production consumers that currently
2389        // dispatch on it (this impl at the [`RestartPolicy::default`] call
2390        // and the serde-side `#[serde(default)]` on
2391        // [`ChildSpec::restart`] that resolves an author-omitted
2392        // `:children :restart` slot through `RestartPolicy::default()`).
2393        // Peer of the sibling per-`:supervisor` axis
2394        // [`Default for RestartStrategy`] → [`SUPERVISOR_ESTRATEGIA_DEFAULT`]
2395        // route (95ffacc) — the two impls now share one substrate-primitive
2396        // lift discipline, so any future coherent rebrand of the OTP-shape
2397        // supervisor+child default set migrates through typed constants in
2398        // lockstep instead of splitting a lifted supervisor half against
2399        // an open-coded child half. Pinned by
2400        // `restart_policy_default_routes_through_lifted_default` +
2401        // `child_spec_serde_default_restart_routes_through_lifted_default`
2402        // in the tests module.
2403        SUPERVISOR_CHILD_RESTART_DEFAULT
2404    }
2405}
2406
2407impl RestartPolicy {
2408    /// Exhaustive iteration surface for every consumer that walks the
2409    /// closed three-arm [`RestartPolicy`] discriminator set (the future
2410    /// M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
2411    /// per-child admission-webhook rejection body naming the accepted-
2412    /// `:restart` list, a future `feira supervisor --restart …` CLI
2413    /// arg-parse's "did you mean" hint via a [`Self::from_wire`]-scan
2414    /// over the slice, the future `feira app graph` per-child restart
2415    /// column, any future round-trip fuzz harness that sweeps every
2416    /// arm). A future arm addition (an OTP-`intrinsic` fourth arm the
2417    /// theory
2418    /// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
2419    /// might reach for once the three canonical OTP restart policies
2420    /// stop covering the substrate's discovered load-shape) extends
2421    /// this slice as one edit and every consumer picks up the new entry
2422    /// by construction; the compiler-checked exhaustiveness on the
2423    /// sibling method `match` arms ([`Self::as_str`] / [`Self::from_wire`])
2424    /// is the build-time guarantee that no arm forgets to grow.
2425    ///
2426    /// Peer of the sibling closed-set typed enums'
2427    /// [`RestartStrategy::ALL`] (4eec29c) /
2428    /// [`crate::CaixaKind::ALL`] (6b1f4fb) /
2429    /// [`crate::aplicacao::PlacementStrategy::ALL`] (18c7342) /
2430    /// [`crate::aplicacao::RateLimitUnit::ALL`] (6bce03d) /
2431    /// [`crate::dep::DepList::ALL`] (45ee563) exhaustive-iteration
2432    /// surfaces — the sixth (and the third and final M2 OTP-shape)
2433    /// closed-set typed enum on the caixa surface to converge onto the
2434    /// same one-canonical-arm-list-per-enum discipline. Sibling axis to
2435    /// the peer [`RestartStrategy::ALL`] on the per-supervisor
2436    /// sibling-restart-strategy axis; this closes the per-child
2437    /// restart-decision-policy axis on the same M2 `:supervisor` slot.
2438    pub const ALL: &'static [Self] = &[Self::Permanent, Self::Temporary, Self::Transient];
2439
2440    /// Substrate-canonical exhaustive accept-set on the [`RestartPolicy`]
2441    /// `PascalCase` wire byte-string axis — the closed three-arm roster
2442    /// of every byte-string [`Self::as_str`] returns, routed byte-for-byte
2443    /// through the paired
2444    /// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2445    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2446    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] lifted
2447    /// `pub const` roster the [`Self::as_str`] emitter (and the
2448    /// [`std::fmt::Display`] impl / `Serialize` derive routed through it)
2449    /// walks — and byte-for-byte the same three strings the un-`rename`d
2450    /// `Serialize` derive emits under the paired
2451    /// [`crate::render::SUPERVISOR_CHILD_KEY_RESTART`] tag key on every
2452    /// JSON / YAML CR round-trip.
2453    ///
2454    /// Peer of the sibling [`crate::CaixaKind::WIRE_NAMES`] (bd708bd)
2455    /// roster on the top-level typed-kind discriminator's `PascalCase`
2456    /// wire byte-string axis, the sibling
2457    /// [`RestartStrategy::WIRE_NAMES`] (3033f45) roster on the per-
2458    /// supervisor sibling-restart-strategy axis (the first M2 OTP-shape
2459    /// closed-set typed enum to converge onto the paired-roster
2460    /// discipline), the sibling
2461    /// [`crate::aplicacao::PlacementStrategy::WIRE_NAMES`] (3e5b194)
2462    /// roster on the first M3 mesh-shape distribution-strategy closed-
2463    /// set typed enum, and the sibling
2464    /// [`crate::upgrade::UpgradeInstruction::WIRE_FORMS`] (cc42c0e) /
2465    /// [`crate::upgrade::UpgradeInstruction::LISP_FORMS`] (1898d77)
2466    /// rosters on the OTP-appup discriminator's two-axis roster split —
2467    /// the same closed-set exhaustive-accept-set roster discipline
2468    /// extended here onto the second and final M2 OTP-shape sibling-
2469    /// enum on the caixa surface, closing the per-child restart-decision-
2470    /// policy axis paired with the peer [`RestartStrategy::WIRE_NAMES`]
2471    /// per-supervisor sibling-restart-strategy axis on the same M2
2472    /// `:supervisor` slot.
2473    ///
2474    /// Downstream consumers of the closed accepted-wire-form set — a
2475    /// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR admission-
2476    /// webhook rejection body enumerating the accepted JSON `:restart`
2477    /// values verbatim (as distinct from the kebab-case dispatcher-
2478    /// catalog enumeration [`Self::discriminant`] serves, whose per-arm
2479    /// form `"permanent"` / `"temporary"` / `"transient"` structurally
2480    /// disagrees with the wire byte-string these `PascalCase` entries
2481    /// carry — the split the sibling
2482    /// [`tests::restart_policy_display_matches_serialized_wire_byte_string`]
2483    /// pin already makes load-bearing), a future `feira supervisor
2484    /// --restart …` CLI-side "did you mean" hint whose candidate-list
2485    /// must byte-match the wire form the operator's per-child dispatch
2486    /// keys off, a future `feira app graph` per-child `:restart`-
2487    /// histogram column that renders zero-count arms, a future
2488    /// `caixa-operator` per-reconcile-step diagnostic log line
2489    /// enumerating accepted wire forms on an unknown-policy rejection,
2490    /// a future
2491    /// `tracing::field::valuable::Value::List` structured-log accepted-
2492    /// wire-form emit — now reach for one lifted substrate-primitive
2493    /// roster rather than open-coding a three-string array-literal
2494    /// (`["Permanent", "Temporary", "Transient"]`) whose arm-set has no
2495    /// compile-time link back to the typed [`RestartPolicy`] enum. A
2496    /// future arm addition (an OTP-`intrinsic` fourth arm the theory
2497    /// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
2498    /// might reach for once the three canonical OTP restart policies
2499    /// stop covering the substrate's discovered load-shape) extends
2500    /// this roster as a single edit — paired with the [`Self::as_str`]
2501    /// match's compiler-checked exhaustiveness on the new arm — and
2502    /// every consumer picks up the new wire form by construction rather
2503    /// than a coordinated array-literal rewrite across every downstream
2504    /// site.
2505    ///
2506    /// Length is pinned load-bearing at `RestartPolicy::ALL.len()`
2507    /// (three) by
2508    /// [`tests::restart_policy_wire_names_covers_every_arm`], every
2509    /// variant's [`Self::as_str`] projection is pinned to a member of
2510    /// the roster so a silent skew between the emitter's arm-set and
2511    /// this const's arm-set trips at caixa-core test time rather than at
2512    /// a downstream consumer's accepted-set enumeration miss, and every
2513    /// entry is further pinned to open with an ASCII uppercase byte so
2514    /// a silent collapse of the `PascalCase` wire-form axis with the
2515    /// peer kebab-case dispatcher-catalog axis (an entry byte-identical
2516    /// to a sibling [`Self::discriminant`] kebab byte-string that would
2517    /// let a wire-axis consumer accept the dispatcher-catalog
2518    /// vocabulary) trips here rather than at a downstream K8s-CR round-
2519    /// trip miss.
2520    pub const WIRE_NAMES: &'static [&'static str] = &[
2521        crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
2522        crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
2523        crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
2524    ];
2525
2526    /// Canonical PascalCase discriminator scalar this variant serializes
2527    /// as under [`crate::render::SUPERVISOR_CHILD_KEY_RESTART`]. The three
2528    /// arms return the paired
2529    /// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2530    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2531    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] lifted
2532    /// constants so every substrate consumer that dispatches on the
2533    /// per-child restart-decision policy (the future wasm-operator's
2534    /// per-child post-exit restart-decision branch, the future M4
2535    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
2536    /// admission-time enum-arm bind, the `caixa-operator`'s hierarchical
2537    /// reconciliation scheduler's per-child-policy fan-out) reads the
2538    /// same byte-string the `Serialize` derive emits — the pin test in
2539    /// [`tests::restart_policy_variants_serialize_to_lifted_scalar_values`]
2540    /// asserts the two paths agree, peer of the M2
2541    /// [`RestartStrategy::as_str`] (09ffb2d) on the sibling per-supervisor
2542    /// sibling-restart-strategy axis and the M3
2543    /// [`crate::aplicacao::PlacementStrategy::as_str`] (cc8f749) on the
2544    /// per-Aplicacao distribution-strategy axis — the third of three
2545    /// OTP-shaped closed-enum discriminator axes on the caixa typed
2546    /// surface to converge onto the same three-path-convergence
2547    /// (`Serialize` derive → `as_str` helper → lifted constant)
2548    /// drift-detection posture.
2549    #[must_use]
2550    pub const fn as_str(self) -> &'static str {
2551        match self {
2552            Self::Permanent => crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
2553            Self::Temporary => crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
2554            Self::Transient => crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
2555        }
2556    }
2557
2558    /// Substrate-canonical reverse projection on the `:children :restart`
2559    /// closed-set axis — parses the `PascalCase` discriminator scalar
2560    /// back to the typed variant, or `None` when `s` is outside the
2561    /// closed-set arm-string set [`Self::as_str`] emits. Dispatches on
2562    /// the same lifted
2563    /// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2564    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2565    /// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] constants
2566    /// the [`Self::as_str`] emitter walks, so the parse and emit halves
2567    /// of the round-trip migrate through one caixa-core edit on any
2568    /// future arm addition.
2569    ///
2570    /// Prior to this lift the substrate carried only the forward
2571    /// `Self → &str` projection on the OTP per-child restart-policy
2572    /// axis (the [`Self::as_str`] emitter, the [`std::fmt::Display`]
2573    /// impl routed through it, the `Serialize` derive that emits the
2574    /// same byte-string under [`crate::render::SUPERVISOR_CHILD_KEY_RESTART`])
2575    /// plus the kebab-case dispatcher-catalog identity via
2576    /// [`Self::discriminant`] — every non-serde consumer that wanted to
2577    /// parse a wire-form `PascalCase` policy scalar had to re-inline a
2578    /// three-arm `match s { "Permanent" => …, "Temporary" => …,
2579    /// "Transient" => …, _ => … }` cascade that expressed no
2580    /// compile-time link back to the typed variant's canonical lifted
2581    /// constant. A future variant rename or per-arm serde-attribute
2582    /// drift would silently split the wire byte-string one non-serde
2583    /// consumer parsed from the one the emitter wrote, with the failure
2584    /// surfacing at the operator's reconcile posture (a `:temporary`
2585    /// `oneShot` child being restarted on clean exit, treating the
2586    /// successful-completion signal as failure and re-running the
2587    /// completion-terminal one-shot indefinitely; a `:transient` child
2588    /// that clean-exited being restarted, masking the clean-completion
2589    /// contract) far from the rebrand commit and with no field naming
2590    /// the drift.
2591    ///
2592    /// Distinct axis from the [`std::str::FromStr`] impl the
2593    /// [`gen_platform::FromStrKind`] derive already installs on this
2594    /// enum by design, not by drift: `FromStr` parses the *kebab-case*
2595    /// dispatcher-catalog identity (`"permanent"` / `"temporary"` /
2596    /// `"transient"` — the inverse of [`Self::discriminant`]), while
2597    /// this method inverts the `PascalCase` wire byte-string
2598    /// [`Self::as_str`] emits. The two-axis split lets the dispatcher-
2599    /// catalog identity live in kebab-case (where every peer catalog
2600    /// identifier already lives) without forcing a wire-format rename
2601    /// on the tatara-lisp author surface (`:restart Permanent`,
2602    /// `PascalCase`) — the same two-axis distinction the sibling
2603    /// [`RestartStrategy::from_wire`] (4eec29c) /
2604    /// [`crate::CaixaKind::from_wire`] (2aa6d23) /
2605    /// [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342)
2606    /// carry on their peer closed-set typed-enum wire round-trips.
2607    ///
2608    /// Same closed-set-reverse-projection discipline the sibling
2609    /// [`RestartStrategy::from_wire`] (4eec29c) /
2610    /// [`crate::CaixaKind::from_wire`] (2aa6d23) /
2611    /// [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342) /
2612    /// [`crate::aplicacao::RateLimitUnit::from_suffix`] typed enums
2613    /// carry on the peer wire-side `str → Self` axes — extended onto
2614    /// the M2 OTP-shape per-child restart-policy closed-set axis, the
2615    /// sixth substrate-side closed-set typed enum (and the third and
2616    /// final OTP-shape closed-enum discriminator axis) to converge on
2617    /// the two-way `str ↔ Self` round-trip. Method-named `from_wire`
2618    /// (not `from_str`) to match the peer [`RestartStrategy::from_wire`]
2619    /// shape verbatim and side-step the [`std::str::FromStr`] impl the
2620    /// derive already installs on the sibling kebab-case axis. Returns
2621    /// `Option<Self>` (rather than `Result<Self, _>`) to match the peer
2622    /// shapes: the caller picks the diagnostic form appropriate for
2623    /// its use site.
2624    #[must_use]
2625    pub fn from_wire(s: &str) -> Option<Self> {
2626        match s {
2627            crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT => Some(Self::Permanent),
2628            crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY => Some(Self::Temporary),
2629            crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT => Some(Self::Transient),
2630            _ => None,
2631        }
2632    }
2633}
2634
2635/// [`std::fmt::Display`] routed through [`RestartPolicy::as_str`], so the
2636/// pretty-printed byte-string every consumer that formats the policy as
2637/// user-facing text lands on (the future wasm-operator's per-child
2638/// post-exit restart-decision diagnostic line, the future `feira app
2639/// graph` per-child restart column, the future M4
2640/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-child
2641/// admission-webhook rejection body) reaches for the same lifted
2642/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2643/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2644/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
2645/// wire-format `Serialize` derive already emits under
2646/// [`crate::render::SUPERVISOR_CHILD_KEY_RESTART`] and the
2647/// [`RestartPolicy::as_str`] helper already returns.
2648///
2649/// Pre-convergence the two paths structurally disagreed — the
2650/// `#[derive(gen_platform::Discriminant)]` + `#[discriminant(also_display)]`
2651/// route (now retired here) sent [`std::fmt::Display`] through the
2652/// gen-platform discriminant catalog string, which arrives kebab-case as
2653/// `"permanent"` / `"temporary"` / `"transient"` on this three-arm enum
2654/// (whose variant names each collapse to their own lowercase form under
2655/// the kebab-case transform), while the wire format ran as `PascalCase`
2656/// `"Permanent"` / `"Temporary"` / `"Transient"` through the un-`rename`d
2657/// serde derive. Every consumer that formatted the policy for a
2658/// diagnostic line, a graph column, or a rejection body under
2659/// `format!("{v}")` therefore landed under a different byte-string than
2660/// the wire format the operator's per-child-policy dispatch keyed off —
2661/// a silent split whose apply-time symptom (a `format!("{v}")`-carrying
2662/// diagnostic quoting `"permanent"` while the wire scalar the operator
2663/// probed was `"Permanent"`) surfaced as a confused correlate at
2664/// operator-log time far from the two-declaration site.
2665///
2666/// Routing `Display` through [`RestartPolicy::as_str`] closes the third
2667/// path: every `format!("{v}")` call reaches the same lifted
2668/// [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const the wire format
2669/// and the [`RestartPolicy::as_str`] helper route through — `Debug` (the
2670/// compiler-derived variant name), `Display` (via `as_str`), and `Serialize`
2671/// (via the un-`rename`d derive) all resolve to the same `PascalCase`
2672/// byte-string per variant. A future variant rename or
2673/// `#[serde(rename_all = "kebab-case")]` attribute reaches every path at
2674/// exactly one place, structurally.
2675///
2676/// The dispatcher-catalog identity remains kebab-case — [`Self::discriminant`]
2677/// (from `#[derive(gen_platform::Discriminant)]`) still returns
2678/// `"permanent"` / `"temporary"` / `"transient"`, and the fleet-wide
2679/// [`gen_platform::register_dispatcher!("caixa.restart-policy", …)`]
2680/// registration keys the catalog off the same kebab identity. The two
2681/// naming worlds now live on separate typed methods (`Display` /
2682/// `as_str` for the wire byte-string, `discriminant` for the catalog
2683/// identity) rather than sharing one `Display` route that structurally
2684/// disagrees with the wire format.
2685///
2686/// Pin tests
2687/// [`tests::restart_policy_display_routes_through_as_str_helper`]
2688/// and
2689/// [`tests::restart_policy_display_matches_serialized_wire_byte_string`]
2690/// assert the three paths agree byte-for-byte on every variant, so a
2691/// future variant rename or per-arm serde attribute drift is a build
2692/// error visible at caixa-core test time, not a silent per-consumer
2693/// dispatch miss at apply / reconcile time.
2694///
2695/// Mirrors the M3 [`crate::aplicacao::PlacementStrategy`] `Display` impl
2696/// (aplicacao.rs:2306) on the per-Aplicacao distribution-strategy axis
2697/// and the sibling [`RestartStrategy`] `Display` impl on the
2698/// per-supervisor sibling-restart-strategy axis — same three-path-
2699/// convergence discipline, extended to close the third and final of
2700/// three OTP-shaped closed-enum discriminator axes on the caixa typed
2701/// surface.
2702impl std::fmt::Display for RestartPolicy {
2703    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
2704        f.write_str(self.as_str())
2705    }
2706}
2707
2708/// Substrate-canonical [`AsRef<str>`] projection on the M2
2709/// per-child-restart-policy [`RestartPolicy`] closed-set typed enum —
2710/// routes through the same [`RestartPolicy::as_str`] `pub const fn`
2711/// scalar accessor the paired [`std::fmt::Display`] impl and the
2712/// un-`rename`d [`serde::Serialize`] derive already key off, so any
2713/// future consumer that binds a [`RestartPolicy`] through the
2714/// standard-library `impl AsRef<str>` bound (a future
2715/// [`caixa-feira`] `feira supervisor --restart <arm>` verb that
2716/// composes the emitted `PascalCase` wire scalar into a
2717/// [`std::process::Command::arg`] shell-out of the future
2718/// wasm-operator's per-child admission gate, a per-child structured-
2719/// log recorder on the future `caixa-operator`'s hierarchical
2720/// reconciliation surface that accepts `impl AsRef<str>` at the
2721/// `tracing::field::Value` `Str`-arm, a [`std::collections::HashMap`]
2722/// lookup keyed on the restart-policy wire byte through
2723/// `map.get::<str>(policy.as_ref())` on a future per-policy
2724/// dispatch table) reaches the paired
2725/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2726/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2727/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`]
2728/// lifted-const through one substrate-primitive dispatch rather
2729/// than an open-coded `.as_str()` projection at every wire-up.
2730///
2731/// Peer of the sibling [`std::fmt::Display`] impl on the same
2732/// primitive — both delegate to the shared [`RestartPolicy::as_str`]
2733/// `pub const fn` accessor, so [`format!("{v}")`], `v.as_str()`, and
2734/// `<RestartPolicy as AsRef<str>>::as_ref(&v)` resolve to the same
2735/// byte-string per instance by construction. A future variant rename
2736/// or `#[serde(rename_all = "kebab-case")]` attribute-drift on the
2737/// enum reaches every one of the three paths (plus the wire-format
2738/// `Serialize` derive that already routes through the same lifted
2739/// const) through exactly one caixa-core edit.
2740///
2741/// Same "route the trait impl through the substrate-primitive
2742/// accessor" discipline the sibling [`crate::CaixaVersion`]
2743/// [`AsRef<str>`] impl (16d5c7e) and the paired M2
2744/// [`RestartStrategy`] [`AsRef<str>`] impl (63eb1a4) carry — extends
2745/// the axis onto the paired per-child-restart-decision-policy
2746/// sibling on the same M2 `:supervisor` slot (the second M2
2747/// OTP-shape closed-set typed enum to converge onto the standard-
2748/// library [`AsRef<str>`] projection). Rust-side newtype/typed-enum
2749/// convention pairs [`AsRef<str>`] and [`fmt::Display`] on the same
2750/// primitive so a caller who has one has both; before this lift,
2751/// [`RestartPolicy`] carried [`fmt::Display`] but not the paired
2752/// [`AsRef<str>`] impl the convention names.
2753///
2754/// Pinned load-bearing by
2755/// [`tests::restart_policy_as_ref_str_routes_through_as_str_accessor`]
2756/// (byte-parity pin against [`RestartPolicy::as_str`] across the
2757/// three-arm closed set) and
2758/// [`tests::restart_policy_as_ref_str_routes_through_display_via_shared_accessor`]
2759/// (three-path convergence: `AsRef<str>` + `Display` + `as_str` all
2760/// resolve to the same lifted `SUPERVISOR_CHILD_RESTART_*` const per
2761/// arm) — any future silent detour that routes the impl through a
2762/// divergent projection (a per-arm inline `match self { … }`
2763/// re-inlining that opens a compile-time link to the un-lifted
2764/// arm-literal, a swap onto the kebab-case
2765/// [`gen_platform::Discriminant`] catalog identity that would
2766/// collide the wire axis with the dispatcher-catalog axis) trips at
2767/// caixa-core test time under `assert_eq!` rather than at a
2768/// downstream `impl AsRef<str>`-bound consumer's silent split.
2769impl AsRef<str> for RestartPolicy {
2770    fn as_ref(&self) -> &str {
2771        self.as_str()
2772    }
2773}
2774
2775/// Trait-idiomatic reverse projection on the M2-OTP-shape per-child
2776/// restart-policy [`RestartPolicy`] closed-set typed enum — routes
2777/// byte-for-byte through the paired substrate-primitive
2778/// [`RestartPolicy::from_wire`] `Option<Self>` accessor so every future
2779/// consumer that binds a `PascalCase` `:children :restart` wire
2780/// byte-string through the standard-library `.try_into()` / [`TryFrom`]
2781/// axis (a future [`caixa-feira`] `feira supervisor --restart
2782/// <Permanent|Temporary|Transient>` CLI arg-parse that composes into
2783/// `let restart: RestartPolicy = s.try_into()?`, a future
2784/// `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook that folds a
2785/// `spec.children[*].restart: String` field through
2786/// `RestartPolicy::try_from(&s)?`, a generic
2787/// `<T: TryFrom<&str>>`-bound loader over any of the substrate's closed-
2788/// set typed enums) reaches the same three-arm accept-set the sibling
2789/// [`RestartPolicy::from_wire`] resolver parses through and the sibling
2790/// [`RestartPolicy::as_str`] emits, rather than an open-coded per-arm
2791/// `match s { "Permanent" => …, "Temporary" => …, "Transient" => …, _ =>
2792/// … }` cascade whose arm-set has no compile-time link back to the
2793/// substrate primitive.
2794///
2795/// Complements the pre-existing forward-projection triple
2796/// ([`std::fmt::Display`], [`AsRef<str>`], [`RestartPolicy::as_str`])
2797/// with the paired trait-idiomatic reverse-projection axis: Rust-side
2798/// newtype/typed-enum convention pairs [`AsRef<str>`] with either
2799/// [`std::str::FromStr`] or [`TryFrom<&str>`] on the same primitive so a
2800/// caller who can project *out to* a `&str` can also project *in from*
2801/// one. The [`TryFrom<&str>`] axis is deliberately chosen over
2802/// [`std::str::FromStr`] to sidestep the `clippy::should_implement_trait`
2803/// lint the sibling method-named [`RestartPolicy::from_wire`] would
2804/// trigger under a `FromStr` impl and to avoid colliding with the
2805/// [`std::str::FromStr`] impl the [`gen_platform::FromStrKind`] derive
2806/// already installs on the paired *kebab-case dispatcher-catalog* axis
2807/// (which parses `"permanent"` / `"temporary"` / `"transient"`, the
2808/// inverse of [`Self::discriminant`]) — this impl closes the trait-
2809/// idiomatic reverse axis on the *`PascalCase` wire* half without
2810/// disturbing either the method-named `from_wire` shape every sibling
2811/// closed-set typed enum on the substrate already carries or the
2812/// pre-existing `FromStr` on the dispatcher-catalog half, keeping the
2813/// two-axis split the sibling [`Self::from_wire`] doc block motivates.
2814///
2815/// `type Error = ()` matches the sibling [`RestartPolicy::from_wire`]'s
2816/// `Option<Self>` return-shape's deliberate deferral of error typing: the
2817/// caller picks the diagnostic form appropriate for its use site (a
2818/// future `feira supervisor --restart` arg-parse composes its own
2819/// per-verb "unknown restart: <arg> — accepted: {…}" message enumerating
2820/// [`RestartPolicy::ALL`], a future M4 admission-webhook rejection body
2821/// wraps the `Err(())` outcome with the accepted-set enumeration for
2822/// operator diagnostics, a `Result::map_err` at the call site lifts the
2823/// unit-error to a per-verb error type). Same shape the peer
2824/// [`RestartStrategy`] (5b828ed) on the sibling per-supervisor axis,
2825/// [`crate::CaixaKind`] (3c83606), [`crate::CaixaDialeto`] (bf33136), and
2826/// [`crate::aplicacao::PlacementStrategy`] (6fd00cd) blocks motivate on
2827/// their peer closed-set typed enums' reverse projections.
2828///
2829/// The paired [`TryFrom<&str>`] impl reaches the same three-arm accept-
2830/// set the [`RestartPolicy::from_wire`] resolver dispatches through, so
2831/// any future arm addition (an OTP-`intrinsic` fourth arm the theory
2832/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
2833/// might reach for once the three canonical OTP restart policies stop
2834/// covering the substrate's discovered load-shape) grows the trait-
2835/// idiomatic axis by construction — one caixa-core edit on
2836/// [`RestartPolicy::from_wire`] extends both the method-named reverse
2837/// projection every existing consumer keys off and the trait-idiomatic
2838/// reverse projection this impl exposes, without a coordinated rewrite
2839/// across every future `TryFrom<&str>`-bound consumer's arm-set.
2840///
2841/// Extends the substrate-wide closed-set-enum reverse-projection family
2842/// ([`crate::CaixaKind`] via 3c83606, [`crate::CaixaDialeto`] via
2843/// bf33136, [`crate::aplicacao::PlacementStrategy`] via 6fd00cd, and
2844/// [`RestartStrategy`] via 5b828ed) onto the third and final OTP-shape
2845/// closed-enum discriminator axis on the caixa surface — the paired
2846/// per-child `:children :restart` closed set the future wasm-operator's
2847/// hierarchical reconciliation scheduler's per-child post-exit
2848/// restart-decision branch keys off end-to-end.
2849///
2850/// Pinned load-bearing by
2851/// [`tests::restart_policy_try_from_str_routes_through_from_wire_accessor`]
2852/// (byte-parity pin against [`RestartPolicy::from_wire`] across the
2853/// three-arm accept-set),
2854/// [`tests::restart_policy_try_from_str_rejects_unknown_byte_strings`]
2855/// (rejection witness against silent accept-set widening), and
2856/// [`tests::restart_policy_try_from_str_and_from_wire_partition_the_accept_set`]
2857/// (cross-axis partition pin locking the trait and method-named
2858/// projections onto one accept-set).
2859impl TryFrom<&str> for RestartPolicy {
2860    type Error = ();
2861
2862    fn try_from(s: &str) -> Result<Self, Self::Error> {
2863        Self::from_wire(s).ok_or(())
2864    }
2865}
2866
2867/// Trait-idiomatic forward projection on the M2-OTP-shape per-child
2868/// restart-policy [`RestartPolicy`] closed-set typed enum — routes
2869/// byte-for-byte through the paired substrate-primitive
2870/// [`RestartPolicy::as_str`] `pub const fn` accessor. Return type is
2871/// `&'static str` by construction — every [`RestartPolicy::as_str`] arm
2872/// resolves to a [`crate::render::SUPERVISOR_CHILD_RESTART_*`] `pub const
2873/// &str` with `'static` lifetime, so the trait's return-type promise is
2874/// upheld structurally without a [`String::leak`] cast or a per-arm inline
2875/// literal.
2876///
2877/// Every future consumer that specifically needs `&'static str` lifetime
2878/// bytes on the per-child restart-decision axis (a
2879/// [`tracing::field::valuable::Value::Str`] recording where the `Str`
2880/// arm's typing demands `&'static str`, a
2881/// [`std::borrow::Cow::Borrowed`]`::<'static, str>(policy.into())` composer
2882/// on the future M4 admission-webhook rejection body where the
2883/// `Cow<'static, str>` typing rules out the sibling [`AsRef<str>`]
2884/// borrowed return, a generic `<T: Into<&'static str>>`-bound serializer
2885/// or error formatter that requires the `'static` bound) reaches the same
2886/// lifted [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2887/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2888/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] substrate-
2889/// primitive dispatch rather than an open-coded per-arm literal cascade
2890/// whose arm-set has no compile-time link back to the substrate primitive.
2891///
2892/// Peer of the sibling M2-OTP-shape [`RestartStrategy`] forward-projection
2893/// impl (523157d) on the per-supervisor sibling-restart-strategy axis —
2894/// the second (and second-of-two-in-M2) closed-set typed enum on the
2895/// caixa surface to converge onto the paired trait-idiomatic forward-
2896/// projection axis. With this lift the paired per-child
2897/// `:children :restart` closed-set typed enum carries the full sibling
2898/// quintet ([`std::fmt::Display`], [`AsRef<str>`], [`Self::as_str`],
2899/// [`TryFrom<&str>`] via 6fdd0d9, `From<Self> for &'static str` via this
2900/// lift) plus the round-trip witness through both the trait-idiomatic
2901/// (`From<Self> for &'static str` + `TryFrom<&str>`) and the method-named
2902/// (`as_str` + `from_wire`) axis pairs — mirrors the sibling
2903/// [`RestartStrategy`] surface arm-for-arm, so every future arm addition
2904/// (an OTP-`intrinsic` fourth arm the theory
2905/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
2906/// might reach for once the three canonical OTP restart policies stop
2907/// covering the substrate's discovered load-shape) grows the trait-
2908/// idiomatic forward axis by construction: one caixa-core edit on
2909/// [`RestartPolicy::as_str`] extends every one of the five sibling
2910/// forward-projection paths ([`std::fmt::Display`], [`AsRef<str>`],
2911/// [`Self::as_str`] itself, this `From<Self> for &'static str`, and the
2912/// un-`rename`d [`serde::Serialize`] derive that also emits `as_str`'s
2913/// bytes) without a coordinated rewrite across every future
2914/// `Into<&'static str>`-bound consumer's arm-set.
2915///
2916/// Pinned load-bearing by
2917/// [`tests::restart_policy_from_into_static_str_routes_through_as_str_accessor`]
2918/// (byte-parity pin against [`RestartPolicy::as_str`] across the
2919/// three-arm emit-set, plus a `const`-context materialization witness for
2920/// the `&'static str` lifetime promise) and
2921/// [`tests::restart_policy_from_into_static_str_and_as_str_partition_the_emit_set`]
2922/// (partition pin asserting `<&'static str as From<RestartPolicy>>::from`
2923/// and [`RestartPolicy::as_str`] agree on every arm, plus a two-way
2924/// round-trip witness through the paired trait-idiomatic reverse-
2925/// projection axis [`TryFrom<&str>`] (6fdd0d9): every
2926/// `policy.into::<&'static str>()` output re-parses back through
2927/// [`RestartPolicy::try_from`] to the original variant, closing the two-
2928/// way `Self ↔ &'static str` round-trip on the trait-idiomatic axis pair).
2929impl From<RestartPolicy> for &'static str {
2930    fn from(policy: RestartPolicy) -> &'static str {
2931        policy.as_str()
2932    }
2933}
2934
2935/// Trait-idiomatic *forward* projection on [`RestartPolicy`] from a
2936/// *borrowed* input onto the `&'static str` axis — the borrowed-input
2937/// companion to the paired owned-input [`From<RestartPolicy> for
2938/// &'static str`] impl immediately above. Routes byte-for-byte through
2939/// the same substrate-primitive [`RestartPolicy::as_str`] `pub const
2940/// fn` accessor so every consumer that binds a `&RestartPolicy`
2941/// through the standard-library `.into()` / [`From<&Self> for &'static
2942/// str`] axis (a `RestartPolicy::ALL.iter().map(<&'static
2943/// str>::from).collect::<Vec<_>>()` per-arm accept-set materializer —
2944/// whose iterator over `&'static [RestartPolicy]` yields
2945/// `&RestartPolicy`, not `RestartPolicy`, so the owned-input
2946/// [`From<RestartPolicy>`] axis alone forces every call site through
2947/// an explicit `.copied()` / dereference / [`Copy`]-bound restatement
2948/// rather than the direct trait-idiomatic projection; a future generic
2949/// `<T: Copy + for<'a> Into<&'static str>>`-bound diagnostic column
2950/// that walks the `iter().map(Into::into)` shape verbatim across every
2951/// substrate-wide closed-set typed enum; the future wasm-operator's
2952/// per-child post-exit restart-decision diagnostic line that composes
2953/// the accepted-set enumeration from an iterated
2954/// `RestartPolicy::ALL.iter().map(|p| p.into())` pipe rather than a
2955/// per-arm `match p { … }` cascade; a future
2956/// `HashMap::<&'static str, RestartPolicy>::from_iter(
2957///     RestartPolicy::ALL.iter().map(|p| (p.into(), *p)))`-style
2958/// per-policy reverse-lookup table the sibling [`TryFrom<&str>`] impl
2959/// cannot compose without this borrowed-input axis in place) reaches
2960/// the same three-arm lifted
2961/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
2962/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
2963/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
2964/// paired owned-input [`From<RestartPolicy> for &'static str`], the
2965/// sibling [`std::fmt::Display`], [`AsRef<str>`], and
2966/// [`RestartPolicy::as_str`] surfaces already return.
2967///
2968/// Fifth peer on the substrate-wide trait-idiomatic *borrowed-input*
2969/// forward-projection family opened on [`crate::dep::DepList`]
2970/// (64aa742) and extended onto [`crate::CaixaKind`] (5ab993a),
2971/// [`crate::CaixaDialeto`] (807b0b5), and the paired
2972/// per-supervisor sibling-restart-strategy [`RestartStrategy`]
2973/// (e941836). Rust's `From` trait does not auto-derive the
2974/// `From<&Self>` sibling from a `From<Self>` impl (the blanket
2975/// `impl<T, U> From<&T> for U where T: Copy, U: From<T>` does not
2976/// exist in `core`), so every closed-set typed enum that carries the
2977/// owned-input axis but not the borrowed-input axis forces every
2978/// borrowed-input call site through a `.copied()` /
2979/// `<&'static str>::from(*policy)` / `policy.as_str()` detour whose
2980/// type bounds have no compile-time link to the substrate primitive.
2981/// [`RestartPolicy`] is the second (and second-of-two-in-M2)
2982/// OTP-shape peer to converge onto this campaign — sibling of the
2983/// paired per-supervisor [`RestartStrategy`] borrowed-input axis, so
2984/// with this lift both closed-set typed enums on the M2 `:supervisor`
2985/// slot now carry the full sibling quintet ([`std::fmt::Display`],
2986/// [`AsRef<str>`], [`Self::as_str`], `From<Self> for &'static str`,
2987/// `From<&Self> for &'static str`) plus the paired trait-idiomatic
2988/// reverse projection [`TryFrom<&str>`], closing the borrowed-input
2989/// forward-projection axis on the M2 OTP-shape slot as a unit.
2990///
2991/// Same three-path convergence discipline as the paired owned-input
2992/// impl (this borrowed-input axis, the paired owned-input
2993/// [`From<RestartPolicy> for &'static str`], and
2994/// [`RestartPolicy::as_str`] all route through the same lifted
2995/// [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const), so a future
2996/// variant rename or per-arm serde-attribute drift reaches every one
2997/// of the six sibling forward-projection paths
2998/// ([`std::fmt::Display`], [`AsRef<str>`], [`Self::as_str`],
2999/// [`From<Self> for &'static str`], this [`From<&Self> for &'static
3000/// str`], and the un-`rename`d [`serde::Serialize`] derive that also
3001/// emits [`Self::as_str`]'s bytes) through exactly one caixa-core
3002/// edit.
3003///
3004/// The [`RestartPolicy::as_str`] emit and [`RestartPolicy::from_wire`]
3005/// parse share the same `PascalCase` vocabulary by construction, so
3006/// the borrowed-input forward axis and the reverse axis compose
3007/// directly — the round-trip witness pin below locks this direct
3008/// composition without the intermediate wire-vocab hop the peer
3009/// [`crate::CaixaKind`] axis pair requires.
3010///
3011/// Pinned load-bearing by
3012/// [`tests::restart_policy_from_borrowed_into_static_str_routes_through_as_str_accessor`]
3013/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3014/// three-arm emit-set via a borrowed input, plus a `const`-context
3015/// materialization witness for the `&'static str` lifetime promise,
3016/// plus a blanket `.into()` shape) and
3017/// [`tests::restart_policy_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
3018/// (cross-axis partition pin against the paired owned-input
3019/// [`From<RestartPolicy> for &'static str`] impl, plus a
3020/// `.iter().map(Into::into)` pipe witness over
3021/// [`RestartPolicy::ALL`], plus a direct round-trip witness through
3022/// [`TryFrom<&str>`] that closes the two-way `&Self → &'static str →
3023/// Self` round-trip without the wire-vocab intermediate the peer
3024/// [`crate::CaixaKind`] axis pair requires).
3025impl From<&RestartPolicy> for &'static str {
3026    fn from(policy: &RestartPolicy) -> &'static str {
3027        policy.as_str()
3028    }
3029}
3030
3031/// Trait-idiomatic *owned-`String`* forward projection on the second
3032/// M2 OTP-shape closed-set typed enum ([`RestartPolicy`]) — the
3033/// owned-heap-string companion to the paired `&'static str`-returning
3034/// [`From<RestartPolicy> for &'static str`] / [`From<&RestartPolicy>
3035/// for &'static str`] impls immediately above. Routes byte-for-byte
3036/// through the substrate-primitive [`RestartPolicy::as_str`] `pub
3037/// const fn` accessor (via [`str::to_owned`]) so every consumer that
3038/// binds a [`RestartPolicy`] through the standard-library `.into()` /
3039/// [`From<Self> for String`] (equivalently [`Into<String>`]) axis — a
3040/// future `serde_json::Value::String(policy.into())` structured-payload
3041/// composer where the `Value::String` arm typing demands an owned
3042/// [`String`] and the sibling [`&'static str`]-returning axis forces
3043/// an explicit `.to_owned()` / `String::from` restatement at every
3044/// call site, a future `HashMap::<String, RestartPolicy>::from_iter(
3045/// RestartPolicy::ALL.iter().map(|p| (p.into(), *p)))` per-policy
3046/// lookup where the map's key type is owned [`String`] rather than
3047/// [`&'static str`], a future `Cow::<'static, str>::Owned(policy.into())`
3048/// composer on the future M4 admission-webhook rejection body's
3049/// owned-arm, the future wasm-operator's per-child post-exit
3050/// diagnostic emit `serde_json::json!({ "restart": policy })` where the
3051/// JSON serializer's `Serialize` impl on [`String`] owns the emit-path
3052/// — reaches the same three-arm lifted
3053/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3054/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3055/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3056/// paired [`std::fmt::Display`], [`AsRef<str>`],
3057/// [`RestartPolicy::as_str`], and the two `&'static str`-returning
3058/// forward-projection impls already return.
3059///
3060/// Extends the trait-idiomatic *owned-`String`* forward-projection
3061/// axis onto the second-of-two M2 OTP-shape closed-set typed enums on
3062/// the caixa surface — mirror of the first-mover
3063/// [`From<RestartStrategy> for String`] (7baa18a) that opened this
3064/// axis on the sibling supervisor-level strategy enum. Rust's standard
3065/// library does not carry a blanket `impl<T: AsRef<str>> From<T> for
3066/// String` (nor an `impl<T: fmt::Display> From<T> for String`), so
3067/// every closed-set typed enum that carries the paired `AsRef<str>` /
3068/// `Display` / `From<Self> for &'static str` triple but not the
3069/// owned-[`String`] axis forces every owned-string call site through a
3070/// `.to_string()` / `.as_str().to_owned()` / `String::from(policy.as_str())`
3071/// detour whose type bounds have no compile-time link to the
3072/// substrate primitive.
3073///
3074/// Deliberately routes through the human-readable
3075/// [`RestartPolicy::as_str`] axis — for this enum the wire format
3076/// (`PascalCase`, tatara-lisp author surface `:restart Permanent`) and
3077/// the diagnostic byte-string share the same vocabulary by
3078/// construction (unlike the sibling [`crate::CaixaKind`] enum whose
3079/// two axes diverge), so the owned-[`String`] projection lands
3080/// byte-identically on both the wire vocabulary the paired
3081/// [`serde::Serialize`] derive emits and the diagnostic vocabulary the
3082/// [`RestartPolicy::as_str`] helper returns, and — because the paired
3083/// [`TryFrom<&str>`] / [`RestartPolicy::from_wire`] reverse-projection
3084/// axis parses the same `PascalCase` vocabulary — the direct two-way
3085/// `Self → String → Self` round-trip composes without the wire-vocab
3086/// intermediate hop the peer [`crate::CaixaKind`] owned-[`String`]
3087/// axis pair requires.
3088///
3089/// Pinned load-bearing by
3090/// [`tests::restart_policy_from_into_owned_string_routes_through_as_str_accessor`]
3091/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3092/// three-arm emit-set, plus a blanket `.into::<String>()` shape
3093/// witness) and
3094/// [`tests::restart_policy_from_into_owned_string_and_static_str_agree_on_every_arm`]
3095/// (cross-axis partition pin against the paired owned-input
3096/// [`From<RestartPolicy> for &'static str`] impl and the sibling
3097/// [`ToString::to_string`] surface routed through [`std::fmt::Display`],
3098/// plus a `.iter().copied().map(String::from)` pipe witness over
3099/// [`RestartPolicy::ALL`], plus a direct round-trip witness through
3100/// [`TryFrom<&str>`] on the owned-[`String`]'s [`String::as_str`]
3101/// borrow that closes the two-way `Self → String → Self` round-trip
3102/// on the trait-idiomatic owned-[`String`] forward + reverse axis
3103/// pair).
3104impl From<RestartPolicy> for String {
3105    fn from(policy: RestartPolicy) -> String {
3106        policy.as_str().to_owned()
3107    }
3108}
3109
3110/// Trait-idiomatic *borrowed-input, owned-`String` output* forward
3111/// projection on the second-of-two M2 OTP-shape closed-set typed enum
3112/// ([`RestartPolicy`]) — the fourth (and closing) corner of the
3113/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
3114/// projection family on this enum, mirror of the first-mover
3115/// [`From<&RestartStrategy> for String`] (579385f) that opened the
3116/// 2×2-completion corner on the sibling supervisor-level strategy
3117/// enum. Routes byte-for-byte through the substrate-primitive
3118/// [`RestartPolicy::as_str`] `pub const fn` accessor (via
3119/// [`str::to_owned`]) so every consumer that holds a borrowed
3120/// [`&RestartPolicy`] and needs an owned [`String`] — a future
3121/// `serde_json::Value::String(String::from(&policy))` structured-payload
3122/// composer over a borrowed field, a future `Iterator::map` over
3123/// `&[RestartPolicy]` that projects to owned keys through
3124/// `.iter().map(String::from)`, a future `HashMap::<String,
3125/// RestartPolicy>::from_iter` that keys off a borrowed-iteration axis
3126/// where dereferencing the policy would force an unnecessary `Copy` at
3127/// every step, the future wasm-operator's per-supervisor
3128/// `child_policies.iter().map(String::from).collect()` per-child post-
3129/// exit restart-decision diagnostic emit whose iteration axis is
3130/// borrowed by construction — reaches the same three-arm lifted
3131/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3132/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3133/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3134/// paired [`std::fmt::Display`], [`AsRef<str>`],
3135/// [`RestartPolicy::as_str`], and the three other trait-idiomatic
3136/// forward-projection impls
3137/// ([`From<RestartPolicy> for &'static str`],
3138/// [`From<&RestartPolicy> for &'static str`],
3139/// [`From<RestartPolicy> for String`]) already return.
3140///
3141/// Second peer on the substrate-wide trait-idiomatic *borrowed-input,
3142/// owned-`String` output* forward-projection family opened on
3143/// [`crate::supervisor::RestartStrategy`] (579385f) — closes the
3144/// `{Self, &Self} × {&'static str, String}` 2×2 projection corner on
3145/// both M2 OTP-shape sibling peers (the paired supervisor-level
3146/// sibling-restart-strategy axis and the per-child restart-decision-
3147/// policy axis), so the whole M2 OTP-shape axis pair now carries the
3148/// full four-corner family by construction. Rust's standard library
3149/// does not carry a blanket `impl<T: AsRef<str>> From<&T> for String`
3150/// (nor an `impl<T: fmt::Display> From<&T> for String`), so every
3151/// closed-set typed enum that carries the paired `AsRef<str>` /
3152/// `Display` / `From<Self> for &'static str` / `From<&Self> for
3153/// &'static str` / `From<Self> for String` quintuple but not the
3154/// borrowed-input owned-[`String`] axis forces every borrowed-input
3155/// owned-string call site through a `policy.as_str().to_owned()` /
3156/// `String::from(*policy)` (with a spurious `Copy`) /
3157/// `policy.to_string()` (through `Display`) detour whose type bounds
3158/// have no compile-time link to the substrate primitive.
3159///
3160/// Deliberately routes through the human-readable
3161/// [`RestartPolicy::as_str`] axis — for this enum the wire format
3162/// (`PascalCase`, tatara-lisp author surface `:restart Permanent`) and
3163/// the diagnostic byte-string share the same vocabulary by
3164/// construction (unlike the sibling [`crate::CaixaKind`] enum whose
3165/// two axes diverge), so the borrowed-input owned-[`String`]
3166/// projection lands byte-identically on both the wire vocabulary the
3167/// paired [`serde::Serialize`] derive emits and the diagnostic
3168/// vocabulary the [`RestartPolicy::as_str`] helper returns, and —
3169/// because the paired [`TryFrom<&str>`] / [`RestartPolicy::from_wire`]
3170/// reverse-projection axis parses the same `PascalCase` vocabulary —
3171/// the direct two-way `&Self → String → Self` round-trip composes
3172/// without the wire-vocab intermediate hop the peer
3173/// [`crate::CaixaKind`] axis pair requires.
3174///
3175/// The remaining thirteen closed-set typed enums on the caixa
3176/// substrate surface (`CaixaKind`, `CaixaDialeto`, `DepList`,
3177/// `PlacementStrategy`, `WitShape`, `RateLimitUnit`,
3178/// `PathShapeViolation`, `InvariantKind`, `ArchVerdict`, `Severity`,
3179/// `FixSafety`, `Semantic`, `FerriteRuntime`) are the future targets
3180/// of this 2×2-completion campaign — each carries the same paired
3181/// quintuple that this borrowed-input owned-[`String`] axis extends
3182/// onto.
3183///
3184/// Pinned load-bearing by
3185/// [`tests::restart_policy_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
3186/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3187/// three-arm emit-set through the borrowed-input surface) and
3188/// [`tests::restart_policy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
3189/// (cross-axis partition pin against the paired owned-input owned-
3190/// [`String`] [`From<RestartPolicy> for String`] impl, the paired
3191/// borrowed-input owned-[`&'static str`] [`From<&RestartPolicy> for
3192/// &'static str`] impl, and the sibling [`ToString::to_string`]
3193/// surface routed through [`std::fmt::Display`], plus a direct round-
3194/// trip witness through [`TryFrom<&str>`] on the owned-[`String`]'s
3195/// [`String::as_str`] borrow that closes the two-way
3196/// `&Self → String → Self` round-trip on the trait-idiomatic
3197/// borrowed-input owned-[`String`] forward + reverse axis pair).
3198impl From<&RestartPolicy> for String {
3199    fn from(policy: &RestartPolicy) -> String {
3200        policy.as_str().to_owned()
3201    }
3202}
3203
3204/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, str>`]
3205/// output* forward projection on the M2 OTP-shape per-child-restart
3206/// [`RestartPolicy`] closed-set typed enum — extends the substrate-
3207/// wide [`std::borrow::Cow<'static, str>`] forward-projection family
3208/// opened on [`crate::CaixaKind`] (99c1735 owned-input, d45c409
3209/// borrowed-input) and first extended off it onto the sibling M2
3210/// OTP-shape sibling-restart [`RestartStrategy`] (7dd28b3 owned-input,
3211/// 9b3e4b3 borrowed-input) onto the second (and second-of-two-in-M2)
3212/// M2 OTP-shape closed-set fieldless typed enum peer on the caixa
3213/// surface (`:children :restart`). Routes byte-for-byte through the
3214/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3215/// accessor (via [`std::borrow::Cow::Borrowed`]) so every consumer
3216/// that binds a [`RestartPolicy`] through the trait-idiomatic
3217/// [`std::borrow::Cow<'static, str>`] axis — a future
3218/// `axum::response::IntoResponse` composer whose per-policy
3219/// diagnostic-body typing rules out the sibling [`AsRef<str>`]
3220/// borrowed return, a future M4 admission-webhook rejection body
3221/// that composes the accepted-policy enumeration through the same
3222/// `RestartPolicy::ALL.iter().map(Cow::from)` shape [`crate::CaixaKind`]
3223/// and [`RestartStrategy`] already route through, a generic `<T: for<'a>
3224/// Into<std::borrow::Cow<'static, str>>>`-bound structured-log
3225/// emitter on a per-child-policy diagnostic column — reaches the same
3226/// three-arm lifted [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`]
3227/// / [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3228/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3229/// paired [`std::fmt::Display`], [`AsRef<str>`],
3230/// [`RestartPolicy::as_str`], and the four
3231/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
3232/// forward-projection corners already return.
3233///
3234/// Deliberately returns [`std::borrow::Cow::Borrowed`] rather than
3235/// [`std::borrow::Cow::Owned`] — the substrate-primitive
3236/// [`RestartPolicy::as_str`] accessor's return carries the `&'static
3237/// str` lifetime by construction (each `match` arm resolves to a
3238/// [`crate::render::SUPERVISOR_CHILD_RESTART_*`] `pub const &str`
3239/// with static lifetime), so the zero-alloc borrowed arm is the
3240/// type-correct projection with no runtime allocation.
3241///
3242/// Rust's standard library carries no blanket `impl<T: AsRef<str>>
3243/// From<T> for Cow<'static, str>` (nor an `impl<T: fmt::Display>
3244/// From<T> for Cow<'static, str>`), so the paired sibling
3245/// [`From<RestartPolicy> for &'static str`] (9fb37d0),
3246/// [`From<RestartPolicy> for String`] (7851725), [`AsRef<str>`], and
3247/// [`std::fmt::Display`] surfaces do not implicitly extend to a
3248/// [`Cow<'static, str>`]-bound call site — every such site is forced
3249/// through a `Cow::Borrowed(policy.as_str())` /
3250/// `Cow::Owned(policy.to_string())` open-code whose type bounds have
3251/// no compile-time link back to the substrate primitive until this
3252/// lift.
3253///
3254/// Second peer to extend the substrate-wide trait-idiomatic
3255/// [`std::borrow::Cow<'static, str>`] forward-projection axis off the
3256/// top-level [`crate::CaixaKind`] enum (99c1735 owned-input, d45c409
3257/// borrowed-input) onto the wider substrate — closes the M2 OTP-shape
3258/// tier of the campaign (both sibling peers, `RestartStrategy` and
3259/// `RestartPolicy`, now carry the owned-input Cow<'static, str>
3260/// forward projection) so the remaining eleven peers
3261/// (`PlacementStrategy`, `RateLimitUnit`, `DepList`, `CaixaDialeto`,
3262/// and the outside-`caixa-core` peers `WitShape`, `PathShapeViolation`,
3263/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`, `Semantic`,
3264/// `FerriteRuntime`) are the future targets. Every future arm addition
3265/// (an OTP-`intrinsic` fourth restart policy the ABSORPTION-ROADMAP
3266/// might reach for once the three canonical OTP restart policies stop
3267/// covering the substrate's discovered load-shape) grows the
3268/// Cow<'static, str> axis by construction through one caixa-core edit
3269/// on [`RestartPolicy::as_str`] — rather than a coordinated rewrite
3270/// across every future Cow<'static, str>-bound consumer site.
3271///
3272/// Pinned load-bearing by
3273/// [`tests::restart_policy_from_into_static_cow_str_routes_through_as_str_accessor`]
3274/// (byte-parity + zero-alloc [`std::borrow::Cow::Borrowed`]-arm pin
3275/// against [`RestartPolicy::as_str`] across the three-arm
3276/// [`RestartPolicy::ALL`]) and
3277/// [`tests::restart_policy_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
3278/// (cross-axis partition pin against the paired [`From<RestartPolicy>
3279/// for &'static str`], [`From<RestartPolicy> for String`], and
3280/// [`ToString`]-through-[`std::fmt::Display`] axes, plus a
3281/// `.iter().copied().map(Cow::from)` pipe witness over
3282/// [`RestartPolicy::ALL`] that materializes the three-arm accept-set
3283/// through the [`Cow<'static, str>`] axis alone and pins the
3284/// zero-alloc discipline on every element).
3285impl From<RestartPolicy> for std::borrow::Cow<'static, str> {
3286    fn from(policy: RestartPolicy) -> std::borrow::Cow<'static, str> {
3287        std::borrow::Cow::Borrowed(policy.as_str())
3288    }
3289}
3290
3291/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, str>`]
3292/// output* forward projection on the M2 OTP-shape per-child-restart
3293/// [`RestartPolicy`] closed-set typed enum — the borrowed-input
3294/// companion to the paired owned-input
3295/// [`From<RestartPolicy> for std::borrow::Cow<'static, str>`] impl
3296/// immediately above (0612398). Routes byte-for-byte through the same
3297/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3298/// accessor (via [`std::borrow::Cow::Borrowed`]) so every consumer
3299/// that holds a `&RestartPolicy` and needs a
3300/// [`std::borrow::Cow<'static, str>`] — a
3301/// `RestartPolicy::ALL.iter().map(std::borrow::Cow::from).collect::<Vec<_>>()`
3302/// per-arm accept-set materializer (whose iterator over
3303/// `&'static [RestartPolicy]` yields `&RestartPolicy`, not
3304/// `RestartPolicy`, so the paired owned-input
3305/// [`From<RestartPolicy> for std::borrow::Cow<'static, str>`] axis
3306/// alone forces every call site through an explicit `.copied()` /
3307/// dereference / [`Copy`]-bound restatement rather than the direct
3308/// trait-idiomatic projection), a future generic
3309/// `<T: for<'a> Into<std::borrow::Cow<'static, str>>>`-bound emitter
3310/// on a per-child-policy diagnostic column that walks the
3311/// `iter().map(Into::into)` shape verbatim, the future M4 admission-
3312/// webhook rejection body that composes the accepted-policy
3313/// enumeration from an iterated
3314/// `RestartPolicy::ALL.iter().map(|p| p.into())` pipe rather than a
3315/// per-arm `match p { … }` cascade — reaches the same three-arm
3316/// lifted [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3317/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3318/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3319/// paired [`std::fmt::Display`], [`AsRef<str>`],
3320/// [`RestartPolicy::as_str`], the four
3321/// `{Self, &Self} × {&'static str, String}` 2×2 trait-idiomatic
3322/// forward-projection corners, and the paired owned-input
3323/// [`From<RestartPolicy> for std::borrow::Cow<'static, str>`] impl
3324/// already return.
3325///
3326/// Deliberately returns [`std::borrow::Cow::Borrowed`] rather than
3327/// [`std::borrow::Cow::Owned`] — the substrate-primitive
3328/// [`RestartPolicy::as_str`] accessor's return carries the
3329/// `&'static str` lifetime by construction (each `match` arm resolves
3330/// to a [`crate::render::SUPERVISOR_CHILD_RESTART_*`] `pub const &str`
3331/// with static lifetime), so the zero-alloc borrowed arm is the
3332/// type-correct projection with no runtime allocation.
3333///
3334/// Closes the `{Self, &Self}` input-shape corner on the M2 OTP-shape
3335/// per-child-restart [`std::borrow::Cow<'static, str>`] axis opened
3336/// one commit prior (0612398) on the paired owned-input
3337/// [`From<RestartPolicy> for std::borrow::Cow<'static, str>`] impl —
3338/// second-of-two-in-M2 closed-set fieldless typed enum peer on the
3339/// caixa surface (paired with the sibling-restart [`RestartStrategy`]
3340/// which carries both {Self, &Self} × Cow<'static, str> corners since
3341/// 7dd28b3 owned-input, 9b3e4b3 borrowed-input), exactly as d45c409
3342/// closed it on the top-level [`crate::CaixaKind`] one commit after
3343/// the owning half (99c1735) landed. This lift closes the whole M2
3344/// OTP-shape tier of the substrate-wide [`Cow<'static, str>`]
3345/// forward-projection campaign on both input-shape corners
3346/// ({Self, &Self}) of both M2 OTP-shape sibling peers
3347/// ([`RestartStrategy`] and [`RestartPolicy`]), so the remaining
3348/// eleven substrate-wide peers (`PlacementStrategy`, `RateLimitUnit`,
3349/// `DepList`, `CaixaDialeto`, `WitShape`, `PathShapeViolation`,
3350/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`, `Semantic`,
3351/// `FerriteRuntime`) become the future targets of the campaign. Rust's
3352/// standard library does not carry a blanket
3353/// `impl<T: AsRef<str>> From<&T> for Cow<'static, str>` (nor an
3354/// `impl<T: fmt::Display> From<&T> for Cow<'static, str>`), so every
3355/// closed-set fieldless typed enum peer on the substrate that carries
3356/// the paired owned-input [`Cow<'static, str>`] axis but not the
3357/// borrowed-input axis forces every borrowed-input
3358/// [`Cow<'static, str>`]-parameterized call site through a spurious
3359/// [`Copy`] deref (`std::borrow::Cow::from(*policy)`) or a
3360/// `std::borrow::Cow::Borrowed(policy.as_str())` open-code whose type
3361/// bounds have no compile-time link to the substrate primitive.
3362///
3363/// Pinned load-bearing by
3364/// [`tests::restart_policy_from_borrowed_into_static_cow_str_routes_through_as_str_accessor`]
3365/// (byte-parity + zero-alloc [`std::borrow::Cow::Borrowed`]-arm pin
3366/// against [`RestartPolicy::as_str`] across the three-arm
3367/// [`RestartPolicy::ALL`] through the borrowed-input surface) and
3368/// [`tests::restart_policy_from_borrowed_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
3369/// (cross-axis partition pin against the paired owned-input
3370/// [`From<RestartPolicy> for std::borrow::Cow<'static, str>`], the
3371/// paired borrowed-input owned-`&'static str`
3372/// [`From<&RestartPolicy> for &'static str`], and the paired
3373/// borrowed-input owned-`String` [`From<&RestartPolicy> for String`]
3374/// impls, plus a `.iter().map(std::borrow::Cow::from)` pipe witness
3375/// over [`RestartPolicy::ALL`] — whose iterator yields
3376/// `&RestartPolicy` by construction, so the borrowed-input
3377/// [`Cow<'static, str>`] axis is what routes the pipe through the
3378/// substrate-primitive [`RestartPolicy::as_str`] accessor with the
3379/// zero-alloc [`Cow::Borrowed`] arm by construction and without a
3380/// spurious [`Copy`] deref).
3381impl From<&RestartPolicy> for std::borrow::Cow<'static, str> {
3382    fn from(policy: &RestartPolicy) -> std::borrow::Cow<'static, str> {
3383        std::borrow::Cow::Borrowed(policy.as_str())
3384    }
3385}
3386
3387/// Trait-idiomatic *owned-input, [`Box<str>`] output* forward
3388/// projection on the M2 OTP-shape per-child-restart [`RestartPolicy`]
3389/// closed-set fieldless typed enum — extends the substrate-wide
3390/// `Box<str>` forward-projection campaign tier opened one commit prior
3391/// (69ef45c) on the paired sibling-restart [`RestartStrategy`] onto
3392/// the second (and third-and-final) M2 OTP-shape closed-set fieldless
3393/// typed enum peer on the caixa surface (`:children :restart`),
3394/// immediately after the paired `Cow<'static, str>` axis (0612398 /
3395/// b4dc55c) closed the
3396/// `{Self, &Self} × {&'static str, String, Cow<'static, str>}` 2×3
3397/// corner on this enum. Routes byte-for-byte through the
3398/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3399/// accessor via [`Box::<str>::from`] on the returned `&'static str`,
3400/// so every consumer that binds a
3401/// `let key: Box<str> = policy.into();`-shaped call site — a
3402/// per-child metric-key materializer that stashes the policy
3403/// discriminator in a `Box<str>`-typed heap-owned scalar for cheap
3404/// clone (a shared-nothing per-policy accept-set the `caixa-operator`
3405/// hierarchical reconciliation scheduler's per-child restart-decision
3406/// fan-out carries), a future admission-webhook rejection body whose
3407/// per-arm `Box<str>` field composes from an owned `RestartPolicy`
3408/// handle — reaches the same three-arm lifted
3409/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3410/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3411/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3412/// sibling
3413/// `{Self, &Self} × {&'static str, String, Cow<'static, str>}`
3414/// forward-projection corner already returns. Rust's standard library
3415/// carries `impl From<&str> for Box<str>` and
3416/// `impl From<String> for Box<str>` but no blanket
3417/// `impl<T: AsRef<str>> From<T> for Box<str>` (nor any
3418/// `impl<T: Copy, U: From<T>> From<T> for U` route from the enum), so
3419/// this axis is a distinct trait-idiomatic surface that a downstream
3420/// `RestartPolicy → Box<str>` `.into()` reaches through this impl and
3421/// no other — without a `Box::from(policy.as_str())` open-code whose
3422/// type bounds have no compile-time link back to the substrate
3423/// primitive.
3424///
3425/// Second peer on the substrate-wide trait-idiomatic [`Box<str>`]
3426/// forward-projection family opened on the sibling-restart
3427/// [`RestartStrategy`] (69ef45c / 59ae5dc) — closes the whole M2
3428/// OTP-shape tier of the substrate-wide [`Box<str>`] forward-
3429/// projection campaign's owned-input corner on both M2 OTP-shape
3430/// sibling peers ([`RestartStrategy`] and [`RestartPolicy`]), the
3431/// paired borrowed-input `From<&RestartPolicy> for Box<str>` closer
3432/// and the remaining fieldless-enum peers on the M3 mesh-shape /
3433/// outside-M3 caixa-core / render-side / outside-caixa-core tiers
3434/// are the future targets of the campaign.
3435///
3436/// Pinned load-bearing by
3437/// [`tests::restart_policy_from_into_box_str_routes_through_as_str_accessor`]
3438/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3439/// three-arm [`RestartPolicy::ALL`] emit-set on the owned-input
3440/// surface, plus a blanket-derived [`Into`] shape witness).
3441impl From<RestartPolicy> for Box<str> {
3442    fn from(policy: RestartPolicy) -> Box<str> {
3443        Box::<str>::from(policy.as_str())
3444    }
3445}
3446
3447/// Trait-idiomatic *borrowed-input, [`Box<str>`] output* forward
3448/// projection on the M2 OTP-shape per-child-restart [`RestartPolicy`]
3449/// closed-set fieldless typed enum — the borrowed-input companion to
3450/// the paired owned-input [`From<RestartPolicy> for Box<str>`] impl
3451/// (0a1b313, one commit prior) that closes the `{Self, &Self}`
3452/// input-shape corner of the substrate-wide [`Box<str>`] forward-
3453/// projection axis on the second (and third-and-final) M2 OTP-shape
3454/// closed-set fieldless typed enum peer on the caixa surface
3455/// (`:children :restart`), routing byte-for-byte through the
3456/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3457/// accessor via [`Box::<str>::from`] on the returned `&'static str`.
3458/// Every consumer that holds a `&RestartPolicy` and needs a
3459/// [`Box<str>`] — a
3460/// `RestartPolicy::ALL.iter().map(Box::<str>::from).collect::<Vec<_>>()`
3461/// per-arm accept-set materializer (whose iterator over
3462/// `&'static [RestartPolicy]` yields `&RestartPolicy`, not
3463/// `RestartPolicy`, so the paired owned-input
3464/// [`From<RestartPolicy> for Box<str>`] axis alone forces every
3465/// call site through an explicit [`Copy`] deref or a
3466/// `.copied()` restatement rather than the direct trait-idiomatic
3467/// projection), a per-child metric-key materializer holding
3468/// `&RestartPolicy` through a `caixa-operator` hierarchical
3469/// reconciliation scheduler's borrow lifetime, a future admission-
3470/// webhook rejection body whose per-arm `Box<str>` field composes
3471/// from a borrowed `&RestartPolicy` handle — reaches the
3472/// substrate-primitive [`RestartPolicy::as_str`] accessor through
3473/// this impl and no other, without a
3474/// `Box::<str>::from(policy.as_str())` open-code whose type bounds
3475/// have no compile-time link back to the substrate primitive.
3476///
3477/// Rust's standard library carries `impl From<&str> for Box<str>`
3478/// and `impl From<String> for Box<str>` but no blanket
3479/// `impl<T: AsRef<str>> From<&T> for Box<str>` (nor a
3480/// `Copy`-based `impl<T: Copy, U: From<&T> for U`), so every closed-
3481/// set fieldless typed enum peer on the substrate that carries the
3482/// paired owned-input `Box<str>` axis but not the borrowed-input
3483/// axis forces every borrowed-input `Box<str>`-parameterized call
3484/// site through a spurious [`Copy`] deref
3485/// (`Box::<str>::from((*policy).as_str())`) or a
3486/// `Box::<str>::from(policy.as_str())` open-code whose type bounds
3487/// have no compile-time link back to the substrate primitive.
3488///
3489/// Fourth (and closing) peer on the substrate-wide trait-idiomatic
3490/// [`Box<str>`] forward-projection family on the M2 OTP-shape tier
3491/// — closes the whole `{Self, &Self}` input-shape corner of the
3492/// [`Box<str>`] axis on both M2 OTP-shape sibling peers
3493/// ([`RestartStrategy`] and [`RestartPolicy`]), exactly as b4dc55c
3494/// closed the paired [`Cow<'static, str>`] axis one commit after
3495/// its owning half (0612398) landed on this enum. The remaining
3496/// fieldless-enum peers on the M3 mesh-shape / outside-M3 caixa-
3497/// core / render-side / outside-caixa-core tiers are the future
3498/// targets of the [`Box<str>`] campaign.
3499///
3500/// Pinned load-bearing by
3501/// [`tests::restart_policy_from_borrowed_into_box_str_routes_through_as_str_accessor`]
3502/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3503/// three-arm [`RestartPolicy::ALL`] emit-set on the borrowed-input
3504/// surface, plus a blanket-derived [`Into`] shape witness, a
3505/// cross-axis partition pin against the paired owned-input
3506/// [`From<RestartPolicy> for Box<str>`] and the sibling borrowed-
3507/// input `{&'static str, String, Cow<'static, str>}` return-shape
3508/// axes, and a `.iter().map(Box::<str>::from)` pipe witness over
3509/// [`RestartPolicy::ALL`] — whose iterator yields `&RestartPolicy`
3510/// by construction, so the borrowed-input [`Box<str>`] axis is
3511/// what routes the pipe through the substrate-primitive
3512/// [`RestartPolicy::as_str`] accessor without a spurious [`Copy`]
3513/// deref).
3514impl From<&RestartPolicy> for Box<str> {
3515    fn from(policy: &RestartPolicy) -> Box<str> {
3516        Box::<str>::from(policy.as_str())
3517    }
3518}
3519
3520/// Trait-idiomatic *owned-input, [`std::sync::Arc<str>`] output*
3521/// forward projection on the M2 OTP-shape per-child-restart
3522/// [`RestartPolicy`] closed-set fieldless typed enum — routes byte-
3523/// for-byte through the substrate-primitive [`RestartPolicy::as_str`]
3524/// `pub const fn` accessor via [`std::sync::Arc::<str>::from`] on the
3525/// returned `&'static str`, so every consumer that binds a
3526/// [`RestartPolicy`] through the standard-library `.into()` /
3527/// [`From<Self> for std::sync::Arc<str>`] (equivalently
3528/// [`Into<std::sync::Arc<str>>`]) axis — a future admission-webhook's
3529/// per-request `Sync` + `Send`-safe structured-log field composed
3530/// across an `.await` boundary through a
3531/// `<T: Into<std::sync::Arc<str>>>`-bound diagnostic-column dispatch,
3532/// a future wasm-operator's per-child post-exit restart-decision
3533/// pipeline holding a shared-ownership per-arm cache key, a
3534/// `<T: Into<std::sync::Arc<str>>>`-bound `tracing`-span attributes
3535/// collector recording a per-child-policy field onto the parent
3536/// span's shared-ownership context — reaches the same three-arm
3537/// lifted [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3538/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3539/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3540/// sibling
3541/// `{Self, &Self} × {&'static str, String, Cow<'static, str>, Box<str>}`
3542/// forward-projection corner already returns.
3543///
3544/// Second peer on the substrate-wide trait-idiomatic
3545/// [`std::sync::Arc<str>`] forward-projection family opened one
3546/// projection tier prior (bca2ec8) on the paired sibling-restart
3547/// [`RestartStrategy`] owned-input first-mover — extends the tier
3548/// onto the second (and third-and-final) M2 OTP-shape closed-set
3549/// fieldless typed enum peer on the caixa surface
3550/// (`:children :restart`), immediately after the paired [`Box<str>`]
3551/// axis (0a1b313 / cb1d068) closed the whole
3552/// `{Self, &Self} × {&'static str, String, Cow<'static, str>, Box<str>}`
3553/// 2×4 corner on this enum. Rust's standard library carries
3554/// `impl From<&str> for std::sync::Arc<str>` and
3555/// `impl From<String> for std::sync::Arc<str>` but no blanket
3556/// `impl<T: AsRef<str>> From<T> for std::sync::Arc<str>` (nor an
3557/// `impl<T: fmt::Display> From<T> for std::sync::Arc<str>`), so this
3558/// axis is a distinct trait-idiomatic surface that a
3559/// `let key: std::sync::Arc<str> = policy.into();`-shaped call site
3560/// reaches through this impl and no other — a paired
3561/// `std::sync::Arc::<str>::from(policy.as_str())` open-code has no
3562/// compile-time link back to the substrate primitive, and a two-step
3563/// `std::sync::Arc::<str>::from(String::from(policy))` composition
3564/// through the owned-`String` axis allocates twice (once into the
3565/// intermediate `String`, once into the [`Arc<str>`] on the
3566/// `From<String>` conversion) where the single-step trait impl
3567/// allocates once.
3568///
3569/// Peer of the sibling [`Box<str>`] second-tier extender (0a1b313) —
3570/// same "extends the substrate-wide projection tier onto the next
3571/// M2 OTP-shape peer" discipline, extended onto the
3572/// [`std::sync::Arc<str>`] axis whose shared-ownership + [`Sync`] +
3573/// [`Send`] contract is the distinct value the [`Box<str>`] axis's
3574/// owned-move return-shape cannot provide.
3575///
3576/// Pinned load-bearing by
3577/// [`tests::restart_policy_from_into_arc_str_routes_through_as_str_accessor`]
3578/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3579/// three-arm [`RestartPolicy::ALL`] emit-set on the owned-input
3580/// surface, plus a blanket-derived [`Into`] shape witness and cross-
3581/// axis byte-parity pins against the sibling owned-input
3582/// `{&'static str, String, Cow<'static, str>, Box<str>}` return-shape
3583/// axes).
3584impl From<RestartPolicy> for std::sync::Arc<str> {
3585    fn from(policy: RestartPolicy) -> std::sync::Arc<str> {
3586        std::sync::Arc::<str>::from(policy.as_str())
3587    }
3588}
3589
3590/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<str>`] output*
3591/// forward projection on the M2 OTP-shape per-child-restart
3592/// [`RestartPolicy`] closed-set fieldless typed enum — closes the
3593/// `{Self, &Self}` input-shape corner of the [`std::sync::Arc<str>`]
3594/// forward-projection axis on the second (and third-and-final) M2
3595/// OTP-shape closed-set fieldless typed enum peer on the caixa
3596/// surface (`:children :restart`), companion to the paired
3597/// owned-input [`From<RestartPolicy> for std::sync::Arc<str>`] impl
3598/// one commit prior (b05724e). Routes byte-for-byte through the
3599/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3600/// accessor (via [`std::sync::Arc::<str>::from`] on the returned
3601/// `&'static str`), so every consumer that binds a
3602/// [`&RestartPolicy`] through the standard-library `.into()` /
3603/// [`From<&Self> for std::sync::Arc<str>`] (equivalently
3604/// [`Into<std::sync::Arc<str>>`]) axis — a future admission-webhook's
3605/// per-request borrowed-`&RestartPolicy` handle rendering a per-arm
3606/// `Sync` + `Send`-safe structured-log field across an `.await`
3607/// boundary through a `<T: Into<std::sync::Arc<str>>>`-bound
3608/// diagnostic-column dispatch, a future wasm-operator's per-child
3609/// post-exit restart-decision pipeline whose
3610/// `.iter().map(std::sync::Arc::<str>::from)` collector reaches
3611/// into the shared-ownership per-arm key without a spurious [`Copy`]
3612/// deref (which would only be reachable through the owned-input
3613/// [`From<RestartPolicy> for std::sync::Arc<str>`] axis by first
3614/// calling `.copied()` on the iterator), a future
3615/// `<T: Into<std::sync::Arc<str>>>`-bound `tracing`-span attributes
3616/// collector recording a borrowed-`&RestartPolicy` per-arm field
3617/// onto the parent span's shared-ownership context — reaches the
3618/// same three-arm lifted
3619/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3620/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3621/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const the
3622/// paired owned-input [`From<RestartPolicy> for std::sync::Arc<str>`]
3623/// impl and the sibling `{&'static str, String, Cow<'static, str>,
3624/// Box<str>}` forward-projection corner already return.
3625///
3626/// Closes the substrate-wide trait-idiomatic
3627/// [`std::sync::Arc<str>`] forward-projection family opened one
3628/// commit prior (b05724e) on the paired owned-input
3629/// [`From<RestartPolicy> for std::sync::Arc<str>`] impl — closes
3630/// the `{Self, &Self}` input-shape corner of the
3631/// [`std::sync::Arc<str>`] axis on the second (and third-and-final)
3632/// M2 OTP-shape closed-set fieldless typed enum peer on the caixa
3633/// surface, exactly as b3e72d7 closed the paired
3634/// [`std::sync::Arc<str>`] corner on the sibling-restart
3635/// [`RestartStrategy`] first-mover one commit after its owning half
3636/// (bca2ec8) landed, and as cb1d068 closed the paired [`Box<str>`]
3637/// corner on this enum one commit after its owning half (0a1b313)
3638/// landed. Rust's standard library carries `impl From<&str> for
3639/// std::sync::Arc<str>` and `impl From<String> for
3640/// std::sync::Arc<str>` but no blanket `impl<T: AsRef<str>> From<&T>
3641/// for std::sync::Arc<str>` (nor a `Copy`-based `impl<T: Copy,
3642/// U: From<T>> From<&T> for U`), so every closed-set fieldless typed
3643/// enum peer on the substrate that carries the paired owned-input
3644/// [`std::sync::Arc<str>`] axis but not the borrowed-input axis
3645/// forces every borrowed-input [`std::sync::Arc<str>`]-parameterized
3646/// call site through a spurious [`Copy`] deref
3647/// (`std::sync::Arc::<str>::from((*policy).as_str())`) or a
3648/// `std::sync::Arc::<str>::from(policy.as_str())` open-code whose
3649/// type bounds have no compile-time link back to the substrate
3650/// primitive.
3651///
3652/// Pinned load-bearing by
3653/// [`tests::restart_policy_from_borrowed_into_arc_str_routes_through_as_str_accessor`]
3654/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3655/// three-arm [`RestartPolicy::ALL`] emit-set on the borrowed-input
3656/// surface, plus a blanket-derived [`Into`] shape witness, a
3657/// cross-axis pin against the paired owned-input
3658/// [`From<RestartPolicy> for std::sync::Arc<str>`] and the sibling
3659/// borrowed-input `{&'static str, String, Cow<'static, str>,
3660/// Box<str>}` return-shape axes, and a
3661/// `.iter().map(std::sync::Arc::<str>::from)` pipe witness over
3662/// [`RestartPolicy::ALL`]).
3663impl From<&RestartPolicy> for std::sync::Arc<str> {
3664    fn from(policy: &RestartPolicy) -> std::sync::Arc<str> {
3665        std::sync::Arc::<str>::from(policy.as_str())
3666    }
3667}
3668
3669/// Trait-idiomatic *owned-input, [`std::rc::Rc<str>`] output* forward
3670/// projection on the M2 OTP-shape per-child-restart [`RestartPolicy`]
3671/// closed-set fieldless typed enum — the single-threaded reference-
3672/// counted peer of the paired owned-input
3673/// [`From<RestartPolicy> for std::sync::Arc<str>`] impl (b05724e) on the
3674/// sibling atomically-reference-counted [`std::sync::Arc<str>`] axis.
3675/// Routes byte-for-byte through the substrate-primitive
3676/// [`RestartPolicy::as_str`] `pub const fn` accessor via
3677/// [`std::rc::Rc::<str>::from`] on the returned `&'static str`.
3678///
3679/// Rust's standard library carries `impl From<&str> for std::rc::Rc<str>`
3680/// and `impl From<String> for std::rc::Rc<str>` but no blanket
3681/// `impl<T: AsRef<str>> From<T> for std::rc::Rc<str>` (nor a `From<&T>`
3682/// blanket), and the [`std::sync::Arc<str>`] and [`std::rc::Rc<str>`]
3683/// trait tables are disjoint — so a single-threaded caixa-operator
3684/// reconciliation pass that shares the `:children :restart` wire
3685/// byte-string across intra-reconcile-loop tree nodes through the cheaper
3686/// non-atomic [`std::rc::Rc<str>`] refcount (the atomically-reference-
3687/// counted [`std::sync::Arc<str>`] return-shape cannot provide within a
3688/// single-threaded reconciliation pass without paying the atomic-fence
3689/// cost the [`std::rc::Rc<str>`] axis skips by construction) reaches
3690/// the substrate primitive through this impl and no other.
3691///
3692/// Closes the substrate-wide trait-idiomatic [`std::rc::Rc<str>`]
3693/// forward-projection axis on the M2-OTP-shape `:supervisor
3694/// :estrategia` and `:children :restart` slot pair the sibling-restart
3695/// [`RestartStrategy`] first-mover (71ad8f4) opened one projection tier
3696/// prior on the paired sibling enum — closes the paired axis on the
3697/// second (and third-and-final) M2 OTP-shape closed-set fieldless typed
3698/// enum peer on the caixa surface, matching the discipline the paired
3699/// [`std::sync::Arc<str>`] forward-projection axis campaign already
3700/// carried across the same slot pair (bca2ec8 → b3e72d7 on
3701/// [`RestartStrategy`]; b05724e → borrowed-close on this enum).
3702///
3703/// Pinned load-bearing by
3704/// [`tests::restart_policy_from_into_rc_str_routes_through_as_str_accessor`]
3705/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3706/// three-arm [`RestartPolicy::ALL`] emit-set on the owned-input
3707/// surface, plus a blanket-derived [`Into`] shape witness and cross-
3708/// axis byte-parity pins against the sibling owned-input `{&'static
3709/// str, String, Cow<'static, str>, Box<str>, std::sync::Arc<str>}`
3710/// return-shape axes).
3711impl From<RestartPolicy> for std::rc::Rc<str> {
3712    fn from(policy: RestartPolicy) -> std::rc::Rc<str> {
3713        std::rc::Rc::<str>::from(policy.as_str())
3714    }
3715}
3716
3717/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<str>`] output* forward
3718/// projection on the M2 OTP-shape per-child-restart [`RestartPolicy`]
3719/// closed-set fieldless typed enum — the borrowed-input companion to
3720/// the paired owned-input [`From<RestartPolicy> for std::rc::Rc<str>`]
3721/// impl immediately above, closing the `{Self, &Self}` input-shape
3722/// corner of the [`std::rc::Rc<str>`] axis on the second (and third-
3723/// and-final) M2 OTP-shape closed-set fieldless typed enum peer on the
3724/// caixa surface. Routes byte-for-byte through the substrate-primitive
3725/// [`RestartPolicy::as_str`] `pub const fn` accessor via
3726/// [`std::rc::Rc::<str>::from`] on the returned `&'static str`, so a
3727/// `RestartPolicy::ALL.iter().map(std::rc::Rc::<str>::from)`-shaped
3728/// pipe (whose iterator over `&'static [RestartPolicy]` yields
3729/// `&RestartPolicy` by construction) reaches the same three-arm lifted
3730/// [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
3731/// [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
3732/// [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`] const roster
3733/// the paired owned-input axis and the sibling `{Self, &Self} ×
3734/// {&'static str, String, Cow<'static, str>, Box<str>,
3735/// std::sync::Arc<str>}` forward-projection corner already return.
3736///
3737/// Rust's standard library carries no blanket
3738/// `impl<T: AsRef<str>> From<&T> for std::rc::Rc<str>` (nor a `Copy`-
3739/// based `impl<T: Copy, U: From<T>> From<&T> for U`), so this borrowed-
3740/// input axis is a distinct trait-idiomatic surface — without it, the
3741/// `.iter().map(std::rc::Rc::<str>::from)` pipe would force a spurious
3742/// [`Copy`] deref or a `.copied()` restatement whose type bounds have
3743/// no compile-time link back to the substrate primitive.
3744///
3745/// Closes the substrate-wide trait-idiomatic [`std::rc::Rc<str>`]
3746/// forward-projection family on the M2-OTP-shape `:supervisor
3747/// :estrategia` + `:children :restart` slot pair — the sibling
3748/// [`RestartStrategy`] first-mover (71ad8f4) opened + closed the pair
3749/// on the sibling `:supervisor :estrategia` half one projection tier
3750/// prior, and the paired owned-input [`From<RestartPolicy> for
3751/// std::rc::Rc<str>`] impl immediately above opens the same axis on
3752/// this half — this borrowed-input impl closes it.
3753///
3754/// Pinned load-bearing by
3755/// [`tests::restart_policy_from_borrowed_into_rc_str_routes_through_as_str_accessor`]
3756/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3757/// three-arm [`RestartPolicy::ALL`] emit-set on the borrowed-input
3758/// surface, plus a blanket-derived [`Into`] shape witness, a cross-
3759/// axis partition pin against the paired owned-input
3760/// [`From<RestartPolicy> for std::rc::Rc<str>`] and the sibling
3761/// borrowed-input `{&'static str, String, Cow<'static, str>, Box<str>,
3762/// std::sync::Arc<str>}` return-shape axes, and a
3763/// `.iter().map(std::rc::Rc::<str>::from)` pipe witness over
3764/// [`RestartPolicy::ALL`] that resolves through the borrowed-input
3765/// axis without a spurious [`Copy`] deref).
3766impl From<&RestartPolicy> for std::rc::Rc<str> {
3767    fn from(policy: &RestartPolicy) -> std::rc::Rc<str> {
3768        std::rc::Rc::<str>::from(policy.as_str())
3769    }
3770}
3771
3772/// Trait-idiomatic byte-view surface on the per-child restart-decision
3773/// policy typed enum.
3774///
3775/// Every consumer that binds its input through the standard-library
3776/// [`AsRef<[u8]>`] trait bound — a byte-keyed
3777/// `HashMap<K: AsRef<[u8]>, V>` per-policy reconciliation-decision
3778/// table lookup on the future wasm-operator supervisor scheduler; a
3779/// `blake3::Hasher::update` / `ring::digest::Context::update` /
3780/// `sha2::Sha256::update` byte-input surface on any future per-child
3781/// content-address digest folded into the [`crate::Lacre`] closure so
3782/// downstream cache-keys partition on the three OTP restart policies
3783/// (`Permanent`, `Temporary`, `Transient`) at content-address time; an
3784/// `std::io::Write::write_all`-bound structured-log per-arm byte-sink —
3785/// reaches the substrate primitive through one trait dispatch rather
3786/// than open-coding the two-hop `restart.as_str().as_bytes()`
3787/// composition at every call site. Routed byte-for-byte through the
3788/// [`RestartPolicy::as_str`] `pub const fn` accessor the paired
3789/// str-view ([`AsRef<str>`], [`std::fmt::Display`],
3790/// [`RestartPolicy::as_str`]) and the five reverse-projection
3791/// (`&'static str`, `String`, `Cow<'static, str>`, `Box<str>`,
3792/// `std::sync::Arc<str>`) return-shape axes already resolve through,
3793/// so any future divergence between the byte-view and str-view axes
3794/// trips at caixa-core test time rather than at a downstream byte-
3795/// consumer's silent split.
3796///
3797/// Peer of the sibling per-supervisor-restart-strategy axis
3798/// [`AsRef<[u8]> for RestartStrategy`] (cd4c4e0, the first M2-OTP-
3799/// shape supervisor slot enum to open this axis) — the sixth
3800/// closed-set fieldless typed enum on the caixa surface to converge
3801/// onto the trait-idiomatic byte-view discipline, and the second (and
3802/// final) M2-OTP-shape sibling to pick it up, closing the byte-view
3803/// axis across the paired `:supervisor :estrategia` +
3804/// `:children :restart` M2 slot pair. Pin load-bearing by the paired
3805/// [`tests::restart_policy_as_ref_bytes_routes_through_as_str_accessor`]
3806/// (fail-before-pass-after byte-parity pin against
3807/// [`RestartPolicy::as_str`] `.as_bytes()` across the three-arm
3808/// [`RestartPolicy::ALL`] emit-set, cross-axis witness against the
3809/// paired str-view [`AsRef<str>`] / [`std::fmt::Display`] /
3810/// [`RestartPolicy::as_str`] axes' `.as_bytes()` byte-tails,
3811/// cross-axis witness against the paired reverse-projection
3812/// `{&'static str, String, Cow<'static, str>, Box<str>,
3813/// std::sync::Arc<str>}` return-shape axes' `.as_bytes()` byte-tails,
3814/// a `<T: AsRef<[u8]>>`-bound-consumer witness that a generic
3815/// byte-input function accepts a [`RestartPolicy`] directly through
3816/// the trait bound, and a `blake3::Hasher::update`-shape byte-input
3817/// surface witness routed through the `<T: AsRef<[u8]>>`-bound
3818/// consumer axis to reach the caixa-lacre compounding target). Any
3819/// future silent detour that routes the byte-view impl off the
3820/// substrate-primitive [`RestartPolicy::as_str`] accessor (a per-arm
3821/// inline `b"Permanent".as_slice()`-shaped re-inlining that opens a
3822/// compile-time link to the un-lifted arm-literal, a swap onto the
3823/// kebab-case [`gen_platform::Discriminant`] catalog identity that
3824/// would collide the wire axis with the dispatcher-catalog axis) trips
3825/// at caixa-core test time rather than at a downstream byte-consumer's
3826/// silent split.
3827impl AsRef<[u8]> for RestartPolicy {
3828    fn as_ref(&self) -> &[u8] {
3829        self.as_str().as_bytes()
3830    }
3831}
3832
3833/// Trait-idiomatic *owned-input, owned-`Vec<u8>` output* byte-owned
3834/// reverse projection on the second (and final) M2 OTP-shape closed-set
3835/// fieldless typed enum peer on the caixa surface ([`RestartPolicy`]) —
3836/// the byte-mirror of the [`From<RestartPolicy> for String`] str-owned
3837/// reverse-projection axis and the owned-`Vec<u8>` reverse-projection
3838/// sibling of the paired [`AsRef<[u8]>`] borrowed byte-view axis
3839/// (98b08fa) lifted on this same enum. Routes byte-for-byte through
3840/// the substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3841/// accessor via [`str::as_bytes`] + [`slice::to_vec`] so every
3842/// consumer that binds a [`RestartPolicy`] through the standard-
3843/// library `impl From<RestartPolicy> for Vec<u8>` axis
3844/// (equivalently `<T: Into<Vec<u8>>>`) — a future
3845/// [`std::io::Write::write_all`]-shape per-child audit-log byte-sink
3846/// whose input parameter is an owned [`Vec<u8>`] payload, a future
3847/// `bytes::Bytes::from(Vec::<u8>::from(restart))` composer folding
3848/// the per-arm restart-decision-policy byte-tag into the
3849/// [`bytes::Bytes`] framing surface, a future
3850/// `hasher.update(&Vec::<u8>::from(restart))`-shape BLAKE3 content-
3851/// address closure that needs the owned byte-tail buffered before
3852/// folding into the [`crate::Lacre`] closure body, a future per-child
3853/// protobuf/CBOR/msgpack payload composer whose framer takes an owned
3854/// [`Vec<u8>`] rather than a borrowed byte-slice — reaches the
3855/// substrate primitive through one trait dispatch rather than an
3856/// open-coded per-call-site `restart.as_str().as_bytes().to_vec()`
3857/// composition whose type bounds have no compile-time link back to
3858/// the substrate primitive.
3859///
3860/// Closes the substrate-wide trait-idiomatic byte-owned reverse-
3861/// projection axis on the M2-OTP-shape `:supervisor :estrategia` +
3862/// `:children :restart` slot pair the sibling
3863/// [`RestartStrategy`] first-mover (63e5dd0) opened one commit prior,
3864/// matching the discipline the paired [`AsRef<[u8]>`] borrowed byte-
3865/// view axis campaign already carried across the same slot pair
3866/// (cd4c4e0 → 98b08fa). Every future arm addition (an OTP-
3867/// `intrinsic` fourth arm the theory
3868/// [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
3869/// might reach for once the three canonical OTP restart policies
3870/// stop covering the substrate's discovered load-shape) grows the
3871/// byte-owned axis through one edit on the substrate-primitive
3872/// [`RestartPolicy::as_str`] accessor.
3873///
3874/// Pinned load-bearing by
3875/// [`tests::restart_policy_from_into_owned_vec_bytes_routes_through_as_str_accessor`]
3876/// (byte-parity pin against [`RestartPolicy::as_str`] across the
3877/// three-arm [`RestartPolicy::ALL`] emit-set binding the byte-owned
3878/// reverse-projection axis against the paired [`AsRef<[u8]>`]
3879/// borrowed byte-view axis and the str-owned reverse-projection
3880/// family (`String`, `Cow<'static, str>`, `Box<str>`,
3881/// `std::sync::Arc<str>`) `.into_bytes()` / `.as_bytes().to_vec()`
3882/// byte-tails, a `<T: Into<Vec<u8>>>`-bound generic-consumer witness,
3883/// and a `std::io::Write::write_all`-shape owned-byte-sink surface
3884/// witness on both owned and borrowed input shapes).
3885impl From<RestartPolicy> for Vec<u8> {
3886    fn from(policy: RestartPolicy) -> Vec<u8> {
3887        policy.as_str().as_bytes().to_vec()
3888    }
3889}
3890
3891/// Trait-idiomatic *borrowed-input, owned-`Vec<u8>` output* byte-
3892/// owned reverse projection on the second (and final) M2 OTP-shape
3893/// closed-set fieldless typed enum peer on the caixa surface
3894/// ([`RestartPolicy`]) — the borrowed-input peer of
3895/// [`From<RestartPolicy> for Vec<u8>`], closing the
3896/// `{Self, &Self} → Vec<u8>` pair on the byte-owned reverse-projection
3897/// axis in one lift. Routes byte-for-byte through the substrate-
3898/// primitive [`RestartPolicy::as_str`] `pub const fn` accessor so
3899/// every consumer that holds a borrowed [`&RestartPolicy`] and needs
3900/// an owned [`Vec<u8>`] — a future
3901/// `.iter().map(Vec::<u8>::from).collect()` pipe over
3902/// `&[RestartPolicy]` (whose iterator yields `&RestartPolicy`,
3903/// not `RestartPolicy`, so the owned-input axis alone forces every
3904/// call site through an explicit `.copied()` / spurious [`Copy`]
3905/// deref restatement rather than the direct trait-idiomatic
3906/// projection), a future admission-webhook rejection body composer
3907/// that walks [`RestartPolicy::ALL`] through an `Into<Vec<u8>>`-
3908/// bound per-arm byte-writer to surface the accepted `:children
3909/// :restart` set — reaches the substrate primitive through one
3910/// trait dispatch rather than a `Vec::<u8>::from(*policy)` spurious-
3911/// [`Copy`]-deref restatement.
3912impl From<&RestartPolicy> for Vec<u8> {
3913    fn from(policy: &RestartPolicy) -> Vec<u8> {
3914        policy.as_str().as_bytes().to_vec()
3915    }
3916}
3917
3918/// Trait-idiomatic *owned-input, [`std::borrow::Cow<'static, [u8]>`]
3919/// output* byte-owned reverse projection on the second (and final) M2
3920/// OTP-shape closed-set fieldless typed enum peer on the caixa surface
3921/// ([`RestartPolicy`]) — the [`std::borrow::Cow<'static, [u8]>`] byte-
3922/// mirror of the paired [`From<RestartPolicy> for
3923/// std::borrow::Cow<'static, str>`] str-side impl and the
3924/// [`std::borrow::Cow<'static, [u8]>`] companion of the paired byte-
3925/// owned [`From<RestartPolicy> for Vec<u8>`] reverse-projection axis
3926/// immediately above. Routes byte-for-byte through the substrate-
3927/// primitive [`RestartPolicy::as_str`] `pub const fn` accessor via
3928/// [`std::borrow::Cow::Borrowed`]`(policy.as_str().as_bytes())` — the
3929/// three `match` arms in [`Self::as_str`] resolve to
3930/// [`crate::render::SUPERVISOR_RESTART_*`] `pub const &'static str`
3931/// bodies, so `.as_bytes()` on each returns `&'static [u8]` by
3932/// construction, and the zero-alloc [`Cow::Borrowed`] arm is the
3933/// type-correct projection with no runtime allocation (mirroring the
3934/// paired [`Cow<'static, str>`] axis's own [`Cow::Borrowed`] discipline
3935/// on this same primitive; contrasts with the sibling
3936/// [`crate::CaixaVersion`] [`Cow<'static, [u8]>`] impl, whose wrapped
3937/// [`String`] storage is a runtime heap allocation with no
3938/// `&'static [u8]` lifetime, forcing the [`Cow::Owned`] arm there).
3939///
3940/// Extends the substrate-wide trait-idiomatic byte-owned reverse-
3941/// projection matrix onto the second (and final) M2-OTP-shape closed-
3942/// set fieldless typed-enum peer at the [`Cow<'static, [u8]>`] corner,
3943/// following the trajectory the sibling [`RestartStrategy`] first-mover
3944/// (7f81539) opened one axis prior on the paired M2-OTP-shape enum, and
3945/// mirroring the discipline the paired byte-owned [`Vec<u8>`] axis
3946/// campaign already tracked onto this primitive one commit sequence
3947/// prior.
3948impl From<RestartPolicy> for std::borrow::Cow<'static, [u8]> {
3949    fn from(policy: RestartPolicy) -> std::borrow::Cow<'static, [u8]> {
3950        std::borrow::Cow::Borrowed(policy.as_str().as_bytes())
3951    }
3952}
3953
3954/// Trait-idiomatic *borrowed-input, [`std::borrow::Cow<'static, [u8]>`]
3955/// output* byte-owned reverse projection on the second (and final) M2
3956/// OTP-shape closed-set fieldless typed enum peer on the caixa surface
3957/// ([`RestartPolicy`]) — the borrowed-input companion to the paired
3958/// owned-input [`From<RestartPolicy> for std::borrow::Cow<'static, [u8]>`]
3959/// impl immediately above, closing the `{Self, &Self} → Cow<'static, [u8]>`
3960/// byte-owned reverse-projection family on this primitive at the
3961/// borrowed-input corner. Routes byte-for-byte through the same
3962/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn` accessor
3963/// via [`std::borrow::Cow::Borrowed`]`(policy.as_str().as_bytes())` —
3964/// the [`Cow::Borrowed`] arm is reachable on both input axes because
3965/// [`Self::as_str`] returns `&'static str` regardless of the input shape,
3966/// so no runtime allocation is forced on either corner. Rust's `From`
3967/// trait carries no blanket `impl<T> From<&T> for U where U: From<T>`
3968/// (nor an `impl<T: AsRef<[u8]>> From<&T> for Cow<'static, [u8]>`), so
3969/// every closed-set fieldless typed enum peer that carries the paired
3970/// owned-input axis but not the borrowed-input axis forces every
3971/// borrowed call site through a spurious [`Copy`] deref
3972/// (`Cow::<'static, [u8]>::from(*policy)`) or an open-coded
3973/// `Cow::Borrowed(policy.as_str().as_bytes())` whose type bounds have no
3974/// compile-time link to the substrate primitive.
3975impl From<&RestartPolicy> for std::borrow::Cow<'static, [u8]> {
3976    fn from(policy: &RestartPolicy) -> std::borrow::Cow<'static, [u8]> {
3977        std::borrow::Cow::Borrowed(policy.as_str().as_bytes())
3978    }
3979}
3980
3981/// Trait-idiomatic *owned-input, [`Box<[u8]>`] output* byte-owned reverse
3982/// projection on the second (and final) M2-OTP-shape closed-set fieldless
3983/// typed enum peer on the caixa surface ([`RestartPolicy`]) — the
3984/// [`Box<[u8]>`] companion to the paired owned-input
3985/// [`From<RestartPolicy> for Vec<u8>`] and
3986/// [`From<RestartPolicy> for std::borrow::Cow<'static, [u8]>`] reverse-
3987/// projection impls on this same primitive, mirroring the paired string-
3988/// side [`From<RestartPolicy> for Box<str>`] forward-projection axis onto
3989/// the byte-family side of the reverse-projection matrix and tracking the
3990/// trajectory the sibling [`RestartStrategy`] first-mover (e11150e) opened
3991/// one axis prior on the paired M2-OTP-shape enum. Routes byte-for-byte
3992/// through the substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
3993/// accessor via [`Box::<[u8]>::from`] on the returned `&'static str`'s
3994/// [`str::as_bytes`] — the three `match` arms in [`Self::as_str`] resolve
3995/// to [`crate::render::SUPERVISOR_CHILD_RESTART_*`] `pub const &'static str`
3996/// bodies, so `.as_bytes()` returns `&'static [u8]` by construction, and
3997/// the standard-library [`Box::<[u8]>::from(&[u8])`] impl allocates a fit-
3998/// to-length boxed byte slice in one heap allocation without an
3999/// intermediary [`Vec<u8>`].
4000///
4001/// Extends the substrate-wide trait-idiomatic *owned-input* byte-family
4002/// reverse-projection matrix onto the second (and final) M2-OTP-shape
4003/// closed-set fieldless typed enum peer at the [`Box<[u8]>`] corner,
4004/// closing the `{Vec<u8>, Cow<'static, [u8]>, Box<[u8]>}` three-corner
4005/// partition on the same wire byte-string this primitive already carries
4006/// on the paired [`Vec<u8>`] and [`Cow<'static, [u8]>`] axes. Rust's
4007/// standard library does not derive `From<Self> for Box<[u8]>` from
4008/// `From<Self> for Vec<u8>` (nor from `From<Self> for Cow<'static, [u8]>`),
4009/// so every closed-set fieldless typed enum peer that carries the paired
4010/// reverse [`Vec<u8>`] axis but not the paired [`Box<[u8]>`] axis forces
4011/// every [`Box<[u8]>`]-typed call site through a
4012/// `Vec::<u8>::from(policy).into_boxed_slice()` intermediary allocation
4013/// whose bounds carry no compile-time link back to the substrate primitive.
4014impl From<RestartPolicy> for Box<[u8]> {
4015    fn from(policy: RestartPolicy) -> Box<[u8]> {
4016        Box::<[u8]>::from(policy.as_str().as_bytes())
4017    }
4018}
4019
4020/// Trait-idiomatic *borrowed-input, [`Box<[u8]>`] output* byte-owned
4021/// reverse projection on the second (and final) M2-OTP-shape closed-set
4022/// fieldless typed enum peer on the caixa surface ([`RestartPolicy`]) —
4023/// the borrowed-input companion to the paired owned-input
4024/// [`From<RestartPolicy> for Box<[u8]>`] impl immediately above, closing
4025/// the `{Self, &Self} → Box<[u8]>` byte-owned reverse-projection family on
4026/// this primitive at the borrowed-input corner. Routes byte-for-byte
4027/// through the same substrate-primitive [`RestartPolicy::as_str`]
4028/// `pub const fn` accessor via [`Box::<[u8]>::from`] on the returned
4029/// `&'static str`'s [`str::as_bytes`] — the [`Box<[u8]>`] allocation
4030/// happens on both input axes because [`Self::as_str`] returns
4031/// `&'static str` regardless of the input shape, so the borrowed-input
4032/// peer reaches the same wire byte-string through the same one-heap-
4033/// allocation path the owned-input peer already carries.
4034///
4035/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
4036/// U: From<T>` (nor a `Copy`-based
4037/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
4038/// fieldless typed enum peer that carries the paired owned-input
4039/// [`Box<[u8]>`] axis but not the borrowed-input axis forces every
4040/// borrowed call site through a spurious [`Copy`] deref
4041/// (`Box::<[u8]>::from(*policy)`) or an open-coded
4042/// `Box::<[u8]>::from(policy.as_str().as_bytes())` whose type bounds
4043/// have no compile-time link to the substrate primitive.
4044impl From<&RestartPolicy> for Box<[u8]> {
4045    fn from(policy: &RestartPolicy) -> Box<[u8]> {
4046        Box::<[u8]>::from(policy.as_str().as_bytes())
4047    }
4048}
4049
4050/// Trait-idiomatic *owned-input, [`std::sync::Arc<[u8]>`] output* byte-owned
4051/// reverse projection on the second (and final) M2-OTP-shape closed-set
4052/// fieldless typed enum peer on the caixa surface ([`RestartPolicy`]) — the
4053/// atomically-refcounted byte-slice mirror of the paired owned-input
4054/// [`From<RestartPolicy> for std::sync::Arc<str>`] impl on the string-side
4055/// reverse-projection matrix, and the fourth axis on the byte-side reverse-
4056/// projection matrix that already carries
4057/// [`From<RestartPolicy> for Vec<u8>`],
4058/// [`From<RestartPolicy> for std::borrow::Cow<'static, [u8]>`] (65f381b),
4059/// and [`From<RestartPolicy> for Box<[u8]>`] (6bc74c9). Routes byte-for-
4060/// byte through the substrate-primitive [`RestartPolicy::as_str`]
4061/// `pub const fn` accessor via [`std::sync::Arc::<[u8]>::from`] on the
4062/// returned `&'static str`'s [`str::as_bytes`] — the three `match` arms in
4063/// [`Self::as_str`] resolve to [`crate::render::SUPERVISOR_CHILD_RESTART_*`]
4064/// `pub const &'static str` bodies, so `.as_bytes()` returns `&'static [u8]`
4065/// by construction, and the standard-library
4066/// [`std::sync::Arc::<[u8]>::from(&[u8])`] impl allocates an atomically-
4067/// refcounted heap slab in one heap allocation without an intermediary
4068/// [`Vec<u8>`] or [`Box<[u8]>`].
4069///
4070/// Rust's standard library does not derive `From<Self> for Arc<[u8]>` from
4071/// `From<Self> for Vec<u8>` (nor from `From<Self> for Box<[u8]>`), so every
4072/// closed-set fieldless typed enum peer that carries the paired reverse
4073/// [`Vec<u8>`] or [`Box<[u8]>`] axis but not the paired [`Arc<[u8]>`] axis
4074/// forces every [`Arc<[u8]>`]-typed call site through a
4075/// `Vec::<u8>::from(policy).into()` / `Box::<[u8]>::from(policy).into()`
4076/// double-allocation detour whose bounds carry no compile-time link back
4077/// to the substrate primitive.
4078///
4079/// Extends the substrate-wide trait-idiomatic *owned-input* byte-family
4080/// reverse-projection matrix onto the second (and final) M2-OTP-shape
4081/// closed-set fieldless typed enum peer at the [`std::sync::Arc<[u8]>`]
4082/// corner, tracking the trajectory the sibling [`RestartStrategy`] first-
4083/// mover (98da8f6) walked one axis prior on the paired M2-OTP-shape enum.
4084impl From<RestartPolicy> for std::sync::Arc<[u8]> {
4085    fn from(policy: RestartPolicy) -> std::sync::Arc<[u8]> {
4086        std::sync::Arc::<[u8]>::from(policy.as_str().as_bytes())
4087    }
4088}
4089
4090/// Trait-idiomatic *borrowed-input, [`std::sync::Arc<[u8]>`] output*
4091/// byte-owned reverse projection on the second (and final) M2-OTP-shape
4092/// closed-set fieldless typed enum peer on the caixa surface
4093/// ([`RestartPolicy`]) — the borrowed-input companion to the paired owned-
4094/// input [`From<RestartPolicy> for std::sync::Arc<[u8]>`] impl immediately
4095/// above, closing the `{Self, &Self} → std::sync::Arc<[u8]>` byte-owned
4096/// reverse-projection family on this primitive at the borrowed-input
4097/// corner. Routes byte-for-byte through the same substrate-primitive
4098/// [`RestartPolicy::as_str`] `pub const fn` accessor via
4099/// [`std::sync::Arc::<[u8]>::from`] on the returned `&'static str`'s
4100/// [`str::as_bytes`] — the [`std::sync::Arc<[u8]>`] allocation happens on
4101/// both input axes because [`Self::as_str`] returns `&'static str`
4102/// regardless of the input shape, so the borrowed-input peer reaches the
4103/// same wire byte-string through the same one-heap-allocation path the
4104/// owned-input peer already carries.
4105///
4106/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
4107/// U: From<T>` (nor a `Copy`-based
4108/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
4109/// fieldless typed enum peer that carries the paired owned-input
4110/// [`std::sync::Arc<[u8]>`] axis but not the borrowed-input axis forces
4111/// every borrowed call site through a spurious [`Copy`] deref
4112/// (`std::sync::Arc::<[u8]>::from(*policy)`) or an open-coded
4113/// `std::sync::Arc::<[u8]>::from(policy.as_str().as_bytes())` whose type
4114/// bounds have no compile-time link to the substrate primitive.
4115impl From<&RestartPolicy> for std::sync::Arc<[u8]> {
4116    fn from(policy: &RestartPolicy) -> std::sync::Arc<[u8]> {
4117        std::sync::Arc::<[u8]>::from(policy.as_str().as_bytes())
4118    }
4119}
4120
4121/// Trait-idiomatic *owned-input, [`std::rc::Rc<[u8]>`] output* byte-owned
4122/// reverse projection on the second (and final) M2-OTP-shape closed-set
4123/// fieldless typed enum peer on the caixa surface ([`RestartPolicy`]) —
4124/// the single-threaded-refcounted byte-slice mirror of the paired owned-
4125/// input [`From<RestartPolicy> for std::rc::Rc<str>`] impl on the string-
4126/// side reverse-projection matrix, and the fifth (and final) axis on the
4127/// byte-side reverse-projection matrix that already carries
4128/// [`From<RestartPolicy> for Vec<u8>`], [`From<RestartPolicy> for
4129/// std::borrow::Cow<'static, [u8]>`] (65f381b), [`From<RestartPolicy> for
4130/// Box<[u8]>`] (6bc74c9), and [`From<RestartPolicy> for
4131/// std::sync::Arc<[u8]>`] (bbb78ee). Routes byte-for-byte through the
4132/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn` accessor
4133/// via [`std::rc::Rc::<[u8]>::from`] on the returned `&'static str`'s
4134/// [`str::as_bytes`] — the three `match` arms in [`Self::as_str`] resolve
4135/// to [`crate::render::SUPERVISOR_CHILD_RESTART_*`] `pub const &'static
4136/// str` bodies, so `.as_bytes()` returns `&'static [u8]` by construction,
4137/// and the standard-library [`std::rc::Rc::<[u8]>::from(&[u8])`] impl
4138/// allocates a fresh single-threaded-refcounted heap slab whose header
4139/// carries the non-atomic strong + weak counters the [`std::rc::Rc<[u8]>`]
4140/// layout requires in one heap allocation without an intermediary
4141/// [`Vec<u8>`], [`Box<[u8]>`], or [`std::sync::Arc<[u8]>`].
4142///
4143/// A future consumer that wants a [`std::rc::Rc<[u8]>`]-typed handle on
4144/// a [`RestartPolicy`] — a single-threaded `feira lint` per-caixa
4145/// diagnostic table whose per-column payload carries the policy's
4146/// byte-view through a chain of Nord-themed emitters via the pointer-
4147/// width [`std::rc::Rc::clone`] handle (a non-atomic refcount bump,
4148/// cheaper than the paired atomic increment on the sibling
4149/// [`std::sync::Arc<[u8]>`] axis by a measurable margin on hot
4150/// single-threaded call sites), a future single-threaded
4151/// `HashMap::<std::rc::Rc<[u8]>, _>::from_iter` per-policy lookup keyed
4152/// by the byte-tail across the `feira supervisor --restart …` composer's
4153/// per-arg cache, a future non-`Send` planner that materializes decoded
4154/// `spec.children[].restart` byte-tails as [`std::rc::Rc<[u8]>`] slices
4155/// so downstream single-threaded verdict composers share the immutable
4156/// byte-tail without a per-consumer [`Vec::<u8>::clone`] — reaches the
4157/// wire byte-string through this one dispatch, without the pre-lift
4158/// `Box::<[u8]>::from(policy).into::<Rc<[u8]>>()` /
4159/// `Rc::<[u8]>::from(Vec::<u8>::from(policy))` double-hop that would
4160/// still allocate the same [`Rc<[u8]>`] slab plus one intermediary
4161/// [`Box<[u8]>`] or [`Vec<u8>`] between the enum peer and the
4162/// [`std::rc::Rc<[u8]>`] slot.
4163///
4164/// Peer of the paired owned-input [`From<RestartPolicy> for Vec<u8>`],
4165/// [`From<RestartPolicy> for Cow<'static, [u8]>`],
4166/// [`From<RestartPolicy> for Box<[u8]>`], and
4167/// [`From<RestartPolicy> for std::sync::Arc<[u8]>`] impls on the same
4168/// primitive — the sibling [`Vec<u8>`] axis returns a fresh heap
4169/// allocation via [`str::as_bytes`]`.to_vec()`; the sibling
4170/// [`Cow<'static, [u8]>`] axis binds the zero-alloc [`Cow::Borrowed`]
4171/// arm on the same `&'static [u8]` byte-tail; the sibling [`Box<[u8]>`]
4172/// axis allocates a fit-to-length boxed byte slice via
4173/// [`Box::<[u8]>::from(&[u8])`]; the sibling [`std::sync::Arc<[u8]>`]
4174/// axis allocates an atomically-refcounted heap slab; this axis
4175/// allocates a single-threaded-refcounted heap slab whose header carries
4176/// the non-atomic strong + weak counters the [`std::rc::Rc<[u8]>`]
4177/// layout requires. Rust's standard library does not derive
4178/// `From<Self> for Rc<[u8]>` from `From<Self> for Arc<[u8]>` (the two
4179/// layouts share the same on-disk shape but the trait tables are
4180/// disjoint, and no blanket `impl<T> From<T> for Rc<[u8]> where
4181/// Arc<[u8]>: From<T>` exists in `core`), so every closed-set fieldless
4182/// typed enum peer that carries the paired [`Arc<[u8]>`] axis but not
4183/// the paired [`Rc<[u8]>`] axis forces every single-threaded
4184/// [`Rc<[u8]>`]-typed call site through a
4185/// `Arc::<[u8]>::from(policy).into()` /
4186/// `Rc::<[u8]>::from(Vec::<u8>::from(policy))` double-allocation detour
4187/// whose bounds carry no compile-time link back to the substrate
4188/// primitive.
4189///
4190/// Closes the trait-idiomatic *owned-input* byte-family reverse-
4191/// projection matrix on the second (and final) M2-OTP-shape closed-set
4192/// fieldless typed enum peer at the [`std::rc::Rc<[u8]>`] corner —
4193/// completing the full `{Vec<u8>, Cow<'static, [u8]>, Box<[u8]>,
4194/// Arc<[u8]>, Rc<[u8]>}` five-corner partition on [`RestartPolicy`],
4195/// mirroring the trajectory the paired first-mover [`RestartStrategy`]
4196/// closed one axis prior (2620e42) on the same M2-OTP-shape supervisor-
4197/// slot pair.
4198///
4199/// Pinned load-bearing by
4200/// [`tests::restart_policy_from_into_owned_rc_bytes_routes_through_as_str_accessor`]
4201/// (byte-parity pin against [`RestartPolicy::as_str`] `.as_bytes()`
4202/// across the three-arm [`RestartPolicy::ALL`] accept-set on the owned-
4203/// input surface, plus a cross-axis witness against the paired owned-
4204/// input [`From<RestartPolicy> for Vec<u8>`], [`From<RestartPolicy> for
4205/// Cow<'static, [u8]>`], [`From<RestartPolicy> for Box<[u8]>`], and
4206/// [`From<RestartPolicy> for std::sync::Arc<[u8]>`] byte-owned reverse-
4207/// projection axes on every canonical `PascalCase` scalar, closing the
4208/// "owned-input into `Vec<u8>` vs. `Cow<'static, [u8]>` vs. `Box<[u8]>`
4209/// vs. `Arc<[u8]>` vs. `Rc<[u8]>`" five-corner partition on the same
4210/// wire byte-string).
4211impl From<RestartPolicy> for std::rc::Rc<[u8]> {
4212    fn from(policy: RestartPolicy) -> std::rc::Rc<[u8]> {
4213        std::rc::Rc::<[u8]>::from(policy.as_str().as_bytes())
4214    }
4215}
4216
4217/// Trait-idiomatic *borrowed-input, [`std::rc::Rc<[u8]>`] output*
4218/// byte-owned reverse projection on the second (and final) M2-OTP-shape
4219/// closed-set fieldless typed enum peer on the caixa surface
4220/// ([`RestartPolicy`]) — the borrowed-input companion to the paired
4221/// owned-input [`From<RestartPolicy> for std::rc::Rc<[u8]>`] impl
4222/// immediately above, closing the `{Self, &Self} → std::rc::Rc<[u8]>`
4223/// byte-owned reverse-projection family on this primitive at the
4224/// borrowed-input corner. Routes byte-for-byte through the same
4225/// substrate-primitive [`RestartPolicy::as_str`] `pub const fn` accessor
4226/// via [`std::rc::Rc::<[u8]>::from`] on the returned `&'static str`'s
4227/// [`str::as_bytes`] — the [`std::rc::Rc<[u8]>`] allocation happens on
4228/// both input axes because [`Self::as_str`] returns `&'static str`
4229/// regardless of the input shape, so the borrowed-input peer reaches the
4230/// same wire byte-string through the same one-heap-allocation path the
4231/// owned-input peer already carries.
4232///
4233/// Rust's `From` trait carries no blanket `impl<T> From<&T> for U where
4234/// U: From<T>` (nor a `Copy`-based
4235/// `impl<T: Copy, U: From<T>> From<&T> for U`), so every closed-set
4236/// fieldless typed enum peer that carries the paired owned-input
4237/// [`std::rc::Rc<[u8]>`] axis but not the borrowed-input axis forces
4238/// every borrowed call site through a spurious [`Copy`] deref
4239/// (`std::rc::Rc::<[u8]>::from(*policy)`) or an open-coded
4240/// `std::rc::Rc::<[u8]>::from(policy.as_str().as_bytes())` whose type
4241/// bounds have no compile-time link to the substrate primitive.
4242///
4243/// Pinned load-bearing by
4244/// [`tests::restart_policy_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor`]
4245/// (byte-parity pin against [`RestartPolicy::as_str`] `.as_bytes()` via a
4246/// borrowed input across the three-arm [`RestartPolicy::ALL`] accept-set,
4247/// plus a source-survival witness against silent move-out and a cross-
4248/// corner partition pin between owned-input and borrowed-input on the
4249/// same wire byte-string through the [`std::rc::Rc<[u8]>`] axis).
4250impl From<&RestartPolicy> for std::rc::Rc<[u8]> {
4251    fn from(policy: &RestartPolicy) -> std::rc::Rc<[u8]> {
4252        std::rc::Rc::<[u8]>::from(policy.as_str().as_bytes())
4253    }
4254}
4255
4256/// Trait-idiomatic *borrowed byte-slice input* reverse projection on the
4257/// second (and final) M2-OTP-shape closed-set fieldless typed enum peer on
4258/// the caixa surface ([`RestartPolicy`]) — the byte-view mirror of the
4259/// str-view reverse-projection axis carried by the paired
4260/// [`TryFrom<&str> for RestartPolicy`] impl (which routes through the
4261/// substrate-primitive [`RestartPolicy::from_wire`] `Option<Self>` accessor
4262/// on the three-arm `PascalCase` accept-set the sibling
4263/// [`RestartPolicy::as_str`] emitter returns). Routes byte-for-byte through
4264/// the standard-library [`std::str::from_utf8`] UTF-8 validator and then
4265/// through [`RestartPolicy::from_wire`] so every consumer that holds a
4266/// borrowed [`&[u8]`] and needs to project it back into a typed
4267/// [`RestartPolicy`] — a future `bytes::Bytes::as_ref()`-fed reader that
4268/// parses a per-child `:restart` `PascalCase` wire scalar from an
4269/// already-borrowed framing byte-tail (a
4270/// `tracing::field::valuable::Value::Bytes` recorder on the future
4271/// wasm-operator's per-child restart-decision diagnostic emission path, a
4272/// future audit-report re-loader binding a prior
4273/// [`RestartPolicy::as_str`] output from a mmap'd byte-slice back through
4274/// the typed enum for cross-run comparison), a future M4
4275/// `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook rejection body
4276/// that reads a `spec.children[].restart` field off a raw HTTP body
4277/// byte-slice before UTF-8 validation commits allocation, a future generic
4278/// `<T: for<'a> TryFrom<&'a [u8]>>`-bound loader over any of the
4279/// substrate's closed-set typed enums — reaches the same three-arm
4280/// `PascalCase` wire accept-set the sibling method-named
4281/// [`RestartPolicy::from_wire`] resolver and the paired trait-idiomatic
4282/// [`TryFrom<&str>`] axis already resolve against, rather than an open-
4283/// coded per-call-site
4284/// `std::str::from_utf8(bytes).ok().and_then(RestartPolicy::from_wire)`
4285/// composition or a
4286/// `<RestartPolicy as TryFrom<&str>>::try_from(std::str::from_utf8(bytes)?)`
4287/// two-hop shape whose type bounds have no compile-time link to the
4288/// substrate primitive.
4289///
4290/// Closes the substrate-wide trait-idiomatic *byte-view reverse-projection*
4291/// family on the M2-OTP-shape `:supervisor :estrategia` + `:children
4292/// :restart` slot pair the sibling [`RestartStrategy`] first-mover
4293/// (c699a83) opened one commit prior — extends the family from
4294/// [`crate::CaixaKind`] (18d1940), [`crate::CaixaDialeto`] (d102cb8),
4295/// [`crate::dep::DepList`] (b8f25d5), and [`RestartStrategy`] (c699a83)
4296/// onto the second (and final) M2-OTP-shape closed-set fieldless typed
4297/// enum peer on the caixa surface, matching the trajectory the paired
4298/// byte-owned reverse-projection axis campaign already walked across the
4299/// same slot pair (63e5dd0 → 96a522a). Rust's standard library carries no
4300/// blanket `impl<T: for<'a> TryFrom<&'a str>> TryFrom<&[u8]> for T`, so a
4301/// two-hop composition through [`std::str::from_utf8`] + the paired
4302/// [`TryFrom<&str>`] axis is reachable at every call site but has no
4303/// compile-time link back to the byte-view reverse-projection axis. Every
4304/// remaining closed-set fieldless typed enum peer on the substrate
4305/// ([`crate::aplicacao::PlacementStrategy`],
4306/// [`crate::aplicacao::RateLimitUnit`], [`crate::aplicacao::WitShape`],
4307/// and the outside-`caixa-core` peers `PathShapeViolation`,
4308/// `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`, `Semantic`,
4309/// `FerriteRuntime`) is a future target of the campaign.
4310///
4311/// `type Error = ()` matches the sibling [`RestartPolicy::from_wire`]'s
4312/// `Option<Self>` return-shape's deliberate deferral of error typing and
4313/// the paired trait-idiomatic [`TryFrom<&str>`] axis's unit-error shape —
4314/// the caller picks the diagnostic form appropriate for its use site (a
4315/// future `feira supervisor --restart …` arg-parse composes its own
4316/// per-verb "unknown restart policy: <arg> — accepted: {…}" message
4317/// enumerating [`RestartPolicy::WIRE_NAMES`]; a future admission-webhook
4318/// rejection body wraps the `Err(())` outcome with the accepted-set
4319/// enumeration for operator diagnostics; a `Result::map_err` at the call
4320/// site lifts the unit-error to a per-verb error type). Two rejection
4321/// paths route through the single unit-error: an invalid UTF-8
4322/// byte-sequence ([`std::str::from_utf8`] returns `Err`) and a valid UTF-8
4323/// byte-string that falls outside the three-arm `PascalCase` accept-set
4324/// ([`RestartPolicy::from_wire`] returns `None`) — both collapse onto
4325/// `Err(())` so the trait signature stays consistent with the sibling
4326/// str-view reverse axis, and a caller that needs to distinguish the two
4327/// failure modes composes [`std::str::from_utf8`] +
4328/// [`RestartPolicy::from_wire`] explicitly.
4329///
4330/// Pinned load-bearing by
4331/// [`tests::restart_policy_try_from_bytes_routes_through_from_wire_accessor`]
4332/// (byte-parity pin against [`RestartPolicy::from_wire`] across the
4333/// three-arm [`RestartPolicy::ALL`] accept-set on the borrowed byte-slice
4334/// surface, plus a cross-axis witness that the byte-view reverse
4335/// projection agrees with the paired [`TryFrom<&str>`] str-view reverse
4336/// axis on every accepted arm, and a forward/reverse byte-view cross-axis
4337/// witness that feeding the paired [`AsRef<[u8]>`] byte-tail back through
4338/// the new impl round-trips to the originating arm) and
4339/// [`tests::restart_policy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
4340/// (rejection witness against silent accept-set widening on both the
4341/// non-UTF-8 byte-sequence rejection path and the unknown-wire-vocabulary
4342/// rejection path — the latter includes the sibling kebab-case
4343/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so
4344/// a caller that confuses the two axes trips here rather than at a
4345/// downstream K8s-CR round-trip miss).
4346impl TryFrom<&[u8]> for RestartPolicy {
4347    type Error = ();
4348
4349    fn try_from(bytes: &[u8]) -> Result<Self, Self::Error> {
4350        std::str::from_utf8(bytes)
4351            .ok()
4352            .and_then(Self::from_wire)
4353            .ok_or(())
4354    }
4355}
4356
4357/// Trait-idiomatic *owned byte-vec input* reverse projection on the second
4358/// (and final) M2-OTP-shape supervisor-slot closed-set fieldless typed enum
4359/// peer on the caixa surface ([`RestartPolicy`]) — the owned-input peer of
4360/// [`TryFrom<&[u8]> for RestartPolicy`], closing the byte-view reverse-
4361/// projection *square* ({owned-input, borrowed-input} × {owned-output
4362/// byte-vec, borrowed-output byte-slice}) on the M2-OTP-shape
4363/// `:supervisor :estrategia` + `:children :restart` slot pair the sibling
4364/// [`RestartStrategy`] first-mover (34951fe) opened on the byte-owned
4365/// reverse-input axis one commit-window prior. Routes byte-for-byte through
4366/// [`<Self as TryFrom<&[u8]>>::try_from`] on the [`Vec<u8>::as_slice`]
4367/// borrow so the owned-input surface reaches the same
4368/// [`std::str::from_utf8`] + [`RestartPolicy::from_wire`] resolution chain
4369/// the borrowed-input peer already carries — one substrate-primitive
4370/// accessor, one trait dispatch, no per-consumer detour.
4371///
4372/// Rust's standard library carries no blanket
4373/// `impl<T: for<'a> TryFrom<&'a [u8]>> TryFrom<Vec<u8>> for T`, so a
4374/// consumer that holds an owned [`Vec<u8>`] and needs a typed
4375/// [`RestartPolicy`] otherwise picks between (a) an open-coded
4376/// `<RestartPolicy as TryFrom<&[u8]>>::try_from(bytes.as_slice())` at every
4377/// call site (whose type bounds have no compile-time link to the byte-
4378/// owned reverse-projection axis), (b) a two-hop
4379/// `String::from_utf8(bytes)` + [`RestartPolicy::from_wire`] composition
4380/// whose error surface leaks the standard-library
4381/// [`std::string::FromUtf8Error`] (widening the sibling [`TryFrom<&[u8]>`]
4382/// axis's unit-error) and silently allocates a [`String`] on inputs that
4383/// will never make it past the wire vocabulary, or (c) an intermediate
4384/// `<RestartPolicy as TryFrom<&str>>::try_from(std::str::from_utf8(&bytes)?)`
4385/// three-hop shape. This impl closes the owned-byte-vec reverse-projection
4386/// axis at the substrate-primitive [`RestartPolicy::from_wire`] accessor so
4387/// every future `<T: TryFrom<Vec<u8>>>`-bound owned-byte-vec consumer — a
4388/// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook body
4389/// reader that hands the `spec.children[].restart` byte-tail off as a
4390/// [`Vec<u8>`] before UTF-8 validation commits allocation, a
4391/// `bytes::Bytes::to_vec()`-shape wire-body composer walking a prior
4392/// audit's per-child rejection payload back to the typed enum, a
4393/// `std::io::Read::read_to_end`-shape audit-log source whose framing yields
4394/// an owned byte-vec per per-policy scalar, an
4395/// `<T: TryFrom<Vec<u8>>>`-bound generic loader over any of the
4396/// substrate's closed-set typed enums — reaches the same three-arm
4397/// `PascalCase` wire accept-set through one trait dispatch.
4398///
4399/// Extends the substrate-wide trait-idiomatic *byte-owned reverse-
4400/// projection* family — opened on the structurally most fundamental
4401/// closed-set fieldless typed enum peer ([`crate::CaixaKind`], commit
4402/// 99c2849), extended onto the second caixa-core-internal peer
4403/// ([`crate::CaixaDialeto`], commit 83a1526), the third
4404/// ([`crate::dep::DepList`], commit 42091cb), and the first M2-OTP-shape
4405/// supervisor-slot peer ([`RestartStrategy`], commit 34951fe) — onto the
4406/// second (and final) M2-OTP-shape supervisor-slot closed-set fieldless
4407/// typed enum peer, tracking the "delegate through `TryFrom<&[u8]>` on the
4408/// `Vec<u8>::as_slice` borrow" discipline the first-mover established.
4409/// Every remaining closed-set fieldless typed enum peer on the substrate
4410/// ([`crate::aplicacao::PlacementStrategy`],
4411/// [`crate::aplicacao::RateLimitUnit`], [`crate::aplicacao::WitShape`],
4412/// [`crate::render::PathShapeViolation`], and the outside-`caixa-core`
4413/// peers `InvariantKind`, `ArchVerdict`, `Severity`, `FixSafety`,
4414/// `Semantic`, `FerriteRuntime`) is a future target of the campaign,
4415/// mirroring the trajectory the closed byte-view reverse-projection
4416/// family (`TryFrom<&[u8]>`) and the closed byte-owned forward-projection
4417/// family (`From<{Self, &Self}> for Vec<u8>`) already walked across the
4418/// same slot pair.
4419///
4420/// `type Error = ()` matches the sibling [`TryFrom<&[u8]> for
4421/// RestartPolicy`] unit-error shape, preserving the trait-family
4422/// consistency across the borrowed-and-owned byte-view reverse-projection
4423/// pair. The owned [`Vec<u8>`] input is dropped on the error path (the
4424/// standard-library `String::from_utf8` convention of returning the input
4425/// in the error deliberately declined — a caller that needs the bytes back
4426/// holds a clone before the call, and the closed-set-enum use site rarely
4427/// wants the raw bytes back past a "did you mean" diagnostic that operates
4428/// on the wire vocabulary rather than the input).
4429///
4430/// Pinned load-bearing by
4431/// [`tests::restart_policy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
4432/// (byte-parity pin against the paired borrowed [`TryFrom<&[u8]>`] axis
4433/// across the three-arm [`RestartPolicy::ALL`] accept-set on the owned
4434/// byte-vec surface, cross-axis witness that the byte-owned reverse
4435/// projection agrees with the paired str-view reverse-projection axis
4436/// ([`TryFrom<&str>`]) on every accepted arm through the shared substrate-
4437/// primitive [`RestartPolicy::from_wire`] accessor, and a four-corner
4438/// {owned-input, borrowed-input} × {`From<Self>` → `Vec<u8>`,
4439/// `From<&Self>` → `Vec<u8>`} round-trip witness available on this enum
4440/// because [`RestartPolicy::as_str`] and [`RestartPolicy::from_wire`]
4441/// share one `PascalCase` byte-vocabulary — like the sibling
4442/// [`RestartStrategy`] and unlike the sibling [`crate::CaixaKind`] which
4443/// its peer test deliberately declines the four-corner witness on because
4444/// the wire/diagnostic split makes the forward and reverse pairs speak
4445/// different byte-strings) and
4446/// [`tests::restart_policy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
4447/// (rejection witness against silent accept-set widening on both the
4448/// non-UTF-8 byte-sequence rejection path and the unknown-wire-vocabulary
4449/// rejection path — the latter includes the sibling kebab-case
4450/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so
4451/// a caller that confuses the two axes trips here rather than at a
4452/// downstream K8s-CR round-trip miss, plus a cross-axis witness that the
4453/// owned byte-vec reverse-projection axis agrees with the borrowed byte-
4454/// slice reverse-projection axis on every rejected input).
4455impl TryFrom<Vec<u8>> for RestartPolicy {
4456    type Error = ();
4457
4458    fn try_from(bytes: Vec<u8>) -> Result<Self, Self::Error> {
4459        <Self as TryFrom<&[u8]>>::try_from(bytes.as_slice())
4460    }
4461}
4462
4463/// Trait-idiomatic *owned-`String` input, `Result<Self, ()>` output*
4464/// string-owned reverse projection on the second (and final) M2-OTP-shape
4465/// supervisor-slot closed-set fieldless typed enum peer on the caixa
4466/// surface ([`RestartPolicy`]) — the owned-input peer of the paired
4467/// [`TryFrom<&str> for RestartPolicy`] str-view reverse-projection axis,
4468/// and the string-owned reverse companion of the pre-existing string-owned
4469/// *forward* pair ([`From<RestartPolicy> for String`],
4470/// [`From<&RestartPolicy> for String`]) already lifted on this same enum.
4471/// Routes owned [`String`] input through the paired borrowed-input
4472/// [`TryFrom<&str>`] axis via [`String::as_str`] so every consumer that
4473/// holds an owned `String` — a future M4 `mesh.pleme.io/v1alpha1/Supervisor`
4474/// CR admission-webhook body reader that hands the
4475/// `spec.children[].restart` `PascalCase` scalar off as an owned [`String`]
4476/// after UTF-8 validation, a `serde_yaml::from_str` / `serde_json::from_str`
4477/// de-serialize round-trip whose composer surfaces the `:children :restart`
4478/// scalar as an owned [`String`] typed field, a
4479/// `feira supervisor --restart <Permanent|Temporary|Transient>`
4480/// `clap`-derived arg-parse whose owned-`String` positional lands the
4481/// canonical arm at the typed dispatch, a per-`:children`-slot overlay
4482/// resolver reading an owned [`String`] out of a `ConfigMap`
4483/// `data.children-restart` scalar, an `<T: TryFrom<String>>`-bound generic
4484/// loader over any of the substrate's closed-set typed enums — reaches the
4485/// same three-arm `PascalCase` accept-set through one trait dispatch.
4486///
4487/// Extends the substrate-wide trait-idiomatic *string-owned reverse-
4488/// projection* family — opened on the compound M3-mesh
4489/// `:politicas :rate-limit` primitive [`crate::aplicacao::RateLimit`]
4490/// (a2e6f02), lifted onto the first closed-set fieldless typed-enum peer
4491/// [`crate::aplicacao::WitShape`] (e6aac29), extended onto the second
4492/// closed-set fieldless typed-enum peer [`crate::aplicacao::RateLimitUnit`]
4493/// (94a9c5e), extended onto the third closed-set fieldless typed-enum peer
4494/// [`crate::aplicacao::PlacementStrategy`] (d81a70a), extended onto the
4495/// first M2-OTP-shape supervisor-slot closed-set fieldless typed-enum peer
4496/// [`RestartStrategy`] (78fe8c8) — onto the second (and final) M2-OTP-shape
4497/// supervisor-slot closed-set fieldless typed-enum peer, the per-`:children`
4498/// restart-decision-policy discriminator. This closes the string-owned
4499/// reverse-projection axis on the M2-OTP-shape `:supervisor :estrategia` +
4500/// `:children :restart` slot pair, mirroring the trajectory the byte-view
4501/// / byte-owned / str-view reverse-projection families already walked
4502/// across the same slot pair. The peers [`crate::CaixaKind`],
4503/// [`crate::CaixaDialeto`], and [`crate::dep::DepList`] remain the next
4504/// targets of the campaign.
4505///
4506/// Rust's standard library carries no blanket
4507/// `impl<T: for<'a> TryFrom<&'a str>> TryFrom<String> for T`, so a consumer
4508/// that holds an owned [`String`] and needs a typed [`RestartPolicy`]
4509/// otherwise picks between (a) an open-coded
4510/// `<RestartPolicy as TryFrom<&str>>::try_from(s.as_str())` at every call
4511/// site whose type bounds have no compile-time link back to the string-
4512/// owned reverse-projection axis, (b) a `let s: &str = &s;
4513/// RestartPolicy::try_from(s)` two-step whose borrow arithmetic leaks a
4514/// per-call-site lifetime dance rather than a single trait dispatch, or
4515/// (c) a `String::into_bytes` + [`TryFrom<Vec<u8>>`] detour that reaches
4516/// the substrate-primitive `from_wire` accessor through a UTF-8 re-
4517/// validation hop the owned-`String` axis already knows to skip. This
4518/// impl closes the string-owned reverse-projection axis at the substrate-
4519/// primitive [`RestartPolicy::from_wire`] accessor so every future
4520/// `<T: TryFrom<String>>`-bound owned-string consumer reaches the same
4521/// three-arm `PascalCase` accept-set through one trait dispatch.
4522///
4523/// `type Error = ()` matches the sibling [`TryFrom<&str> for
4524/// RestartPolicy`], [`TryFrom<&[u8]> for RestartPolicy`], and
4525/// [`TryFrom<Vec<u8>> for RestartPolicy`] unit-error shapes, preserving
4526/// the trait-family consistency across the {str-view, byte-view, byte-
4527/// owned, string-owned} reverse-projection square. The owned [`String`]
4528/// input is dropped on the error path (the standard-library
4529/// `String::from_utf8` convention of returning the input in the error
4530/// deliberately declined — a caller that needs the string back holds a
4531/// clone before the call, and the closed-set-enum use site rarely wants
4532/// the raw string back past a "did you mean" diagnostic that operates on
4533/// the wire vocabulary rather than the input).
4534///
4535/// Pinned load-bearing by
4536/// [`tests::restart_policy_try_from_owned_string_routes_through_borrowed_str_view_axis`]
4537/// (byte-parity pin against the paired borrowed [`TryFrom<&str>`] axis
4538/// across the three-arm [`RestartPolicy::ALL`] accept-set on the owned-
4539/// `String` surface, cross-axis witness that the string-owned reverse
4540/// projection agrees with the sibling byte-view / byte-owned reverse-
4541/// projection axes on every accepted arm through the shared substrate-
4542/// primitive [`RestartPolicy::from_wire`] accessor, and a closed-cycle
4543/// witness against the paired string-owned forward-projection pair —
4544/// `Self → String → TryFrom<String> → Self` round-trips to the
4545/// originating arm on every canonical `PascalCase` scalar) and
4546/// [`tests::restart_policy_try_from_owned_string_rejects_unknown_wire_strings`]
4547/// (rejection witness against silent accept-set widening — mirrors the
4548/// corpus the paired [`TryFrom<&str>`] rejection witness already pins,
4549/// including empty / whitespace-only inputs, the sibling kebab-case
4550/// dispatcher-catalog byte-strings on the two-axis wire/catalog split so
4551/// a caller that confuses the two axes trips here rather than at a
4552/// downstream K8s-CR round-trip miss, case-fold rebrand candidates,
4553/// whitespace-padded / trailing-newline / quote-wrapped forms, and
4554/// English-rebrand candidates, with per-input cross-axis parity against
4555/// the borrowed [`TryFrom<&str>`] reverse-projection axis).
4556impl TryFrom<String> for RestartPolicy {
4557    type Error = ();
4558
4559    fn try_from(s: String) -> Result<Self, Self::Error> {
4560        <Self as TryFrom<&str>>::try_from(s.as_str())
4561    }
4562}
4563
4564// Fleet-wide dispatcher-catalog registrations for caixa's OTP
4565// supervisor surface — two more typed shadows over Erlang/OTP
4566// primitives the substrate now mechanically tracks (see
4567// theory/UNIFIED-COMPUTING-MODEL.md §VI for the roadmap +
4568// theory/TYPED-ABSORPTION.md for the absorption arc).
4569gen_platform::register_dispatcher!("caixa.restart-strategy", RestartStrategy);
4570gen_platform::register_dispatcher!("caixa.restart-policy", RestartPolicy);
4571
4572/// One child entry in the supervisor's `:children` list.
4573///
4574/// Every child references another caixa by `:caixa <nome>` + version
4575/// constraint. The supervisor materializes one ComputeUnit per entry.
4576#[derive(Serialize, Deserialize, Debug, Clone, PartialEq, Eq)]
4577#[serde(rename_all = "camelCase")]
4578pub struct ChildSpec {
4579    /// The child caixa's `:nome`. Must resolve via the same dependency
4580    /// resolution path as `:deps` (caixa-resolver).
4581    pub caixa: String,
4582
4583    /// Semver constraint (`"^0.1"`, `"~0.1.2"`, etc.) — same shape as
4584    /// [`crate::dep::Dep::versao`].
4585    pub versao: String,
4586
4587    /// Restart policy — an author-omitted slot degrades onto the
4588    /// substrate-canonical [`SUPERVISOR_CHILD_RESTART_DEFAULT`]
4589    /// (`permanent`, the Erlang/OTP worker-child default) through the
4590    /// [`Default for RestartPolicy`] impl this `#[serde(default)]` routes
4591    /// to.
4592    #[serde(default)]
4593    pub restart: RestartPolicy,
4594}
4595
4596impl ChildSpec {
4597    /// Substrate-canonical per-`:children` child-caixa `:nome` scalar
4598    /// accessor every consumer that reads the OTP-shape supervised
4599    /// child's identity keys off — returns the author-declared
4600    /// `:children :caixa` byte-string verbatim as a `&str`, borrowed
4601    /// from the typed slot's own [`String`] storage.
4602    ///
4603    /// The `:children :caixa` slot carries the DNS-1123 label — the
4604    /// child caixa's `:nome` — that every emitted cluster artifact
4605    /// derives its `metadata.name` from verbatim: the rendered
4606    /// `wasm.pleme.io/v1alpha1/ComputeUnit.metadata.name` per child, the
4607    /// [`crate::LABEL_PROGRAM`] label value on every child's pod
4608    /// identity, and the per-child K8s Service `metadata.name` the
4609    /// future wasm-operator (M3) provisions for inter-child supervision-
4610    /// tree wiring. Every downstream consumer that fans on the child's
4611    /// caixa-name keys off this scalar (the [`SupervisorSpec::validate`]
4612    /// per-child DNS-1123 gate at
4613    /// `require_valid_dns_1123_label(child.nome(), …)`, the per-child
4614    /// duplicate-detection [`crate::render::insert_first_seen`] key, the
4615    /// [`validate_no_self_supervision`] cross-slot equality check
4616    /// against the parent's `:nome`, every `SupervisorError` variant
4617    /// carrying the offending child caixa verbatim for `feira lint`
4618    /// rendering, the future wasm-operator's hierarchical reconciliation
4619    /// scheduler's per-child ComputeUnit-name projection, the future M4
4620    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-child
4621    /// admission webhook).
4622    ///
4623    /// Prior to this lift the `.caixa` byte-string was accessed inline
4624    /// at seven sites in `supervisor.rs` — the DNS-1123 gate's
4625    /// `&child.caixa`, the four `SupervisorError::{ChildCaixaInvalid,
4626    /// EmptyChildVersion, ChildVersaoInvalid, DuplicateChildCaixa}`
4627    /// carriers' `child.caixa.clone()`, the dedup key's
4628    /// `child.caixa.as_str()`, and the [`validate_no_self_supervision`]
4629    /// `child.caixa == parent_nome` cross-slot check — seven open-coded
4630    /// field-accesses that expressed no compile-time link back to the
4631    /// typed slot. A future extension of the `:children :caixa` axis to
4632    /// a richer author surface (a per-cluster alias table the operator
4633    /// pins through a future `:placement`-scoped slot on the supervisor
4634    /// tree, a namespace-qualified rewrite the M4 CR materializer
4635    /// applies per-CR, a per-child overlay from the future `:children
4636    /// :nome-suffix` slot the MESH-COMPOSITION §III.2 roadmap
4637    /// acknowledges) would have had to be threaded through every
4638    /// open-coded copy in lockstep or one consumer would silently
4639    /// disagree with the peers on which caixa a given child resolves to
4640    /// — a child-set lookup that treated the name as `"cart-worker"`
4641    /// while the peer duplicate-detector treated it as
4642    /// `"tenant-a/cart-worker"` would silently split the
4643    /// `DuplicateChildCaixa` membership-lookup diagnostic from the
4644    /// self-supervision detector's parent-equality check, a two-consumer
4645    /// split at the validator far from the source `caixa.lisp` with no
4646    /// field naming the identity-drift root cause. Lifting the resolution
4647    /// rule to a typed method on the substrate primitive means every
4648    /// downstream consumer of the Supervisor's per-`:children` identity
4649    /// surface reaches for exactly one typed dispatch — the resolver's
4650    /// accept-set migrates as a unit on any future axis addition.
4651    ///
4652    /// Sibling of the peer per-`:membros` [`crate::Membro::nome`]
4653    /// (4a32abf) member-caixa `:nome` scalar accessor on the M3
4654    /// mesh-slot surface — same "one typed dispatch on the substrate
4655    /// primitive, thin projections at each consumer" discipline extended
4656    /// onto the M2 supervisor-tree per-`:children` child-identity axis.
4657    /// The two typed axes (`Membro::nome` on the M3 Aplicacao side,
4658    /// `ChildSpec::nome` on the M2 Supervisor side) now share one
4659    /// accessor discipline for the shared substrate concept "another
4660    /// caixa referenced by `:nome`". Peer of the second M2 slot scalar
4661    /// accessor [`crate::UpgradeFromEntry::prior_versao`] (75d27a8) on
4662    /// the sibling per-`:upgrade-from :from` OTP-appup axis — the M2
4663    /// slot family's typed-accessor discipline now spans both the
4664    /// upgrade axis (`:upgrade-from`) and the supervision axis
4665    /// (`:children`), matching the closed M3 mesh-slot accessor family's
4666    /// shape. Named `nome()` to match the tatara-lisp author-surface
4667    /// term the field's docstring already reaches for ("The child
4668    /// caixa's `:nome`") and the peer [`crate::Membro::nome`] /
4669    /// [`crate::Caixa::nome`] / [`crate::dep::Dep::nome`] field-name
4670    /// discipline the substrate already carries — the accessor's name
4671    /// maps directly onto the canonical caixa-identity vocabulary rather
4672    /// than shadowing the field's storage-side `caixa` label.
4673    #[must_use]
4674    pub const fn nome(&self) -> &str {
4675        self.caixa.as_str()
4676    }
4677
4678    /// Substrate-canonical per-`:children` child-caixa `:versao` semver-
4679    /// requirement scalar accessor every consumer that reads the OTP-shape
4680    /// supervised child's version pin keys off — returns the author-declared
4681    /// `:children :versao` byte-string verbatim as a `&str`, borrowed from
4682    /// the typed slot's own [`String`] storage.
4683    ///
4684    /// The `:children :versao` slot carries the Cargo-shaped semver
4685    /// requirement string (`"^0.1"`, `"~0.1.2"`, `"0.1.0"`, `"*"`) that pins
4686    /// which release of the supervised child caixa the OTP-shape supervisor
4687    /// tree materializes against — the same requirement grammar the peer
4688    /// `:deps :versao` / `:membros :versao` axes carry, resolved through the
4689    /// shared [`crate::render::require_valid_versao_requirement`] cascade
4690    /// and the shared [`crate::version::parse_requirement`] parser. Every
4691    /// downstream consumer that fans on the child's version pin keys off
4692    /// this scalar (the [`SupervisorSpec::validate`] per-child requirement
4693    /// gate at `require_valid_versao_requirement(child.versao_requirement(),
4694    /// …)`, the [`SupervisorError::ChildVersaoInvalid`] variant's carrier
4695    /// for `feira lint` rendering, every future per-cluster version-lock
4696    /// overlay the caixa-operator's hierarchical reconciliation scheduler
4697    /// pins through a future `:placement`-scoped supervisor-tree slot, the
4698    /// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
4699    /// per-child version resolver, the future wasm-operator's per-child
4700    /// lacre BLAKE3-closure lookup at `ComputeUnit` materialization time).
4701    ///
4702    /// Prior to this lift the `.versao` byte-string was accessed inline at
4703    /// two `&str`-shaped sites in `caixa-core/src/supervisor.rs` — the
4704    /// [`SupervisorSpec::validate`] requirement-gate call
4705    /// `require_valid_versao_requirement(&child.versao, …)` and the
4706    /// [`SupervisorError::ChildVersaoInvalid`] carrier at
4707    /// `versao: child.versao.clone()` — two open-coded field-accesses that
4708    /// expressed no compile-time link back to the typed slot. A future
4709    /// extension of the `:children :versao` axis to a richer author surface
4710    /// (a per-cluster version-pin overlay per MESH-COMPOSITION §III.2 canary
4711    /// flow, a lacre-projected concrete-version rewrite the operator
4712    /// materializes at CR-admission time, a future `:children :versao-lock`
4713    /// per-cluster override slot the wasm-operator's hierarchical
4714    /// reconciliation scheduler authors per-CR) would have had to be
4715    /// threaded through both open-coded copies in lockstep or one consumer
4716    /// would silently disagree with the peer on which release constraint a
4717    /// given child resolves to — the requirement-gate call reading
4718    /// `"^0.1"` while the error-body carrier read `"tenant-a-pin/^0.1"`
4719    /// would silently split the `ChildVersaoInvalid` diagnostic quote from
4720    /// the actual gate rejection input, a two-consumer split at the
4721    /// validator far from the source `caixa.lisp` with no field naming the
4722    /// version-pin drift root cause. Lifting the resolution rule to a typed
4723    /// method on the substrate primitive means every downstream
4724    /// requirement-facing consumer of the Supervisor's per-`:children`
4725    /// version-pin surface reaches for exactly one typed dispatch — the
4726    /// resolver's accept-set migrates as a unit on any future axis addition.
4727    ///
4728    /// Sibling of the peer per-`:membros` [`crate::Membro::versao_requirement`]
4729    /// (a40b0e3) member-caixa `:versao` scalar accessor on the M3 mesh-slot
4730    /// surface — same "one typed dispatch on the substrate primitive, thin
4731    /// projections at each consumer" discipline extended onto the M2
4732    /// supervisor-tree per-`:children` child-version-pin axis. The two typed
4733    /// axes (`Membro::versao_requirement` on the M3 Aplicacao side,
4734    /// `ChildSpec::versao_requirement` on the M2 Supervisor side) now share
4735    /// one accessor discipline for the shared substrate concept "another
4736    /// caixa referenced by a Cargo-shaped semver requirement". Peer of the
4737    /// sibling per-`:children` [`ChildSpec::nome`] (57c61d0) child-caixa
4738    /// `:nome` scalar accessor — the pair
4739    /// `(nome(), versao_requirement())` jointly projects the
4740    /// `(caixa, versao)` field pair every OTP-shape supervisor-tree consumer
4741    /// that fans on per-child identity + version pin keys off, closing the
4742    /// last unlifted per-`:children` `String`-carry axis so every downstream
4743    /// per-`:children` reader now routes through a typed dispatch on the
4744    /// substrate primitive. Named `versao_requirement()` rather than
4745    /// `versao()` because the field's storage-side `.versao` label is
4746    /// already the author-surface term (`:versao`); the accessor's name
4747    /// carries the semantic role — the semver *requirement* string the
4748    /// shared [`crate::version::parse_requirement`] entry-point consumes —
4749    /// so a raw field access and a typed dispatch read differently at every
4750    /// consumer site. Matches the peer [`crate::Membro::versao_requirement`]
4751    /// naming discipline verbatim.
4752    #[must_use]
4753    pub const fn versao_requirement(&self) -> &str {
4754        self.versao.as_str()
4755    }
4756
4757    /// Substrate-canonical per-`:children` `:restart` OTP-shaped
4758    /// per-child post-exit restart-decision policy scalar accessor every
4759    /// consumer that dispatches on the supervised child's post-exit
4760    /// reconcile posture keys off — returns the author-declared
4761    /// `:children :restart` variant verbatim as a [`RestartPolicy`],
4762    /// `Copy`-projected from the typed slot's own [`RestartPolicy`]
4763    /// storage.
4764    ///
4765    /// The `:children :restart` slot carries the closed-set OTP-shaped
4766    /// per-child restart-decision policy discriminator
4767    /// ([`RestartPolicy::Permanent`] — always restart, the OTP `permanent`
4768    /// worker-child default; [`RestartPolicy::Transient`] — restart only
4769    /// on abnormal exit, the OTP `transient` clean-completion-aware
4770    /// default; [`RestartPolicy::Temporary`] — never restart, the OTP
4771    /// `temporary` one-shot default) that every downstream consumer of
4772    /// the Supervisor's per-child post-exit reconcile branch keys off.
4773    /// Every future downstream consumer that fans on the per-child
4774    /// restart-decision keys off this scalar (the future `feira app
4775    /// graph` per-child restart column, the future wasm-operator's
4776    /// per-child post-exit restart-decision branch, the future M4
4777    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-child
4778    /// admission webhook, the `caixa-operator`'s hierarchical
4779    /// reconciliation scheduler's per-child post-exit reconcile branch,
4780    /// the [`RestartPolicy::as_str`] `Serialize`-derive-pinning path the
4781    /// [`tests::restart_policy_variants_serialize_to_lifted_scalar_values`]
4782    /// pin threads through).
4783    ///
4784    /// Peer of the sibling per-`:supervisor` [`SupervisorSpec::estrategia`]
4785    /// (eafb619) `Copy`-return [`RestartStrategy`] sibling-restart-strategy
4786    /// scalar accessor and the M3 mesh-slot
4787    /// [`crate::Placement::estrategia`] (921fe1b) `Copy`-return
4788    /// [`crate::PlacementStrategy`] distribution-strategy scalar accessor
4789    /// — same "one typed dispatch on the substrate primitive,
4790    /// `Copy`-projected closed-set enum-arm discriminator that partitions
4791    /// the downstream renderer's per-arm fan-out" discipline extended
4792    /// onto the M2 supervisor-slot per-`:children` restart-decision-policy
4793    /// `Copy`-composite-enum scalar axis. Third axis on the per-`:children`
4794    /// [`ChildSpec`] type — companion to the sibling per-`:children`
4795    /// [`ChildSpec::nome`] (57c61d0) child-caixa `:nome` scalar accessor
4796    /// and the per-`:children` [`ChildSpec::versao_requirement`]
4797    /// (2c053c8) child-caixa `:versao` semver-requirement scalar accessor
4798    /// on the sibling `String`-carry axes. The triple
4799    /// `(nome(), versao_requirement(), restart())` jointly projects the
4800    /// `(caixa, versao, restart)` field trio every OTP-shape supervisor-
4801    /// tree consumer that fans on per-child identity + version pin +
4802    /// restart-decision keys off, closing the last unlifted per-`:children`
4803    /// axis so every downstream per-`:children` reader now routes through
4804    /// a typed dispatch on the substrate primitive. Named `restart()` to
4805    /// match the storage field's name and the author-surface
4806    /// `:children :restart` slot term verbatim; the accessor's identity
4807    /// name maps onto the canonical OTP-shape per-child restart-decision-
4808    /// policy vocabulary the [`RestartPolicy`] enum's docstring already
4809    /// carries.
4810    ///
4811    /// Declared `pub const fn` to close the last non-`const`
4812    /// `Copy`-return raw-field-getter posture on the M2
4813    /// per-`:children` [`ChildSpec`] substrate-primitive surface — peer
4814    /// of the sibling M2 per-`:supervisor`
4815    /// [`SupervisorSpec::estrategia`] (converted in this commit)
4816    /// `Copy`-composite-enum accessor, the sibling M2 per-`:supervisor`
4817    /// [`SupervisorSpec::max_restarts`] (b698ec0) `Copy`-`u32` accessor
4818    /// already lifted, and the peer M3 mesh-slot per-`:entrada`
4819    /// [`crate::Entrada::port`] (bafa004) / per-`:placement`
4820    /// [`crate::Placement::estrategia`] (bafa004) `Copy`-return
4821    /// `pub const fn` scalar accessors on the sibling M3 surface. Every
4822    /// downstream substrate-side `const`-context consumer of the
4823    /// per-`:children` restart-decision-policy scalar (a future
4824    /// module-scope `const _:() = assert!(matches!(child.restart(),
4825    /// RestartPolicy::Permanent))` invariant pin on a typed fixture, a
4826    /// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer
4827    /// admission-webhook `const fn` per-child restart-decision floor
4828    /// over a typed [`ChildSpec`], any future `const fn` supervisor-tree
4829    /// composer over the substrate primitive that fans on the per-child
4830    /// restart-decision policy at compile time) now reaches through the
4831    /// same typed dispatch on the substrate primitive at const-eval
4832    /// time as at runtime. A future non-`Copy`-return promotion of the
4833    /// scalar (an `Option<RestartPolicy>`-shape migration on the
4834    /// per-child restart-decision axis once heterogeneous per-cluster
4835    /// restart-policy overlays land, a per-tenant restart-policy-alias
4836    /// table the M4 CR materializer resolves per-CR) that would drop
4837    /// the `const` qualifier fails the fail-before-pass-after pin
4838    /// [`tests::child_spec_restart_accessor_is_const_fn`] at caixa-core
4839    /// build time rather than surfacing as a downstream consumer
4840    /// regression.
4841    #[must_use]
4842    pub const fn restart(&self) -> RestartPolicy {
4843        self.restart
4844    }
4845}
4846
4847/// Supervisor-typed slots that live alongside the standard Caixa
4848/// fields when `:kind Supervisor`. Held flat in [`crate::Caixa`] so
4849/// the manifest stays a single typed form; this struct exists for
4850/// validation + conversion.
4851#[derive(Serialize, Deserialize, Debug, Clone, PartialEq, Eq)]
4852#[serde(rename_all = "camelCase")]
4853pub struct SupervisorSpec {
4854    /// Restart strategy. Defaults to [`RestartStrategy::OneForOne`].
4855    #[serde(default)]
4856    pub estrategia: RestartStrategy,
4857
4858    /// Max restarts within [`Self::restart_window`] before the
4859    /// supervisor itself terminates (and its parent supervisor decides
4860    /// what to do). Default 5.
4861    #[serde(default = "default_max_restarts")]
4862    pub max_restarts: u32,
4863
4864    /// Sliding window for `max_restarts`. Authored as a duration
4865    /// string (`"60s"`, `"5m"`); absent = "never reset". A `Some(0s)`
4866    /// is rejected by [`Self::validate`] — Erlang/OTP's
4867    /// `MaxIntensity / Period` invariant requires a positive window
4868    /// (a zero-period supervisor either trips on the first failure or
4869    /// never trips, depending on operator interpretation, neither of
4870    /// which is the author's intent). Omit the slot to express "no
4871    /// reset"; carry a positive duration to express the sliding window.
4872    #[serde(
4873        default,
4874        skip_serializing_if = "Option::is_none",
4875        with = "duration_codec"
4876    )]
4877    pub restart_window: Option<Duration>,
4878
4879    /// Static children. Empty for `SimpleOneForOne` (children added
4880    /// dynamically); required for the other three strategies.
4881    #[serde(default)]
4882    pub children: Vec<ChildSpec>,
4883}
4884
4885const fn default_max_restarts() -> u32 {
4886    // Route the private serde-`#[serde(default = "…")]` helper through
4887    // the substrate-canonical [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] typed
4888    // `pub const` rather than the raw `5` literal — one source of truth
4889    // for the Erlang/OTP-canonical `{intensity, 5, 60}` `MaxIntensity`
4890    // default across the two production consumers that currently
4891    // dispatch on it (this helper via `#[serde(default = "…")]` on
4892    // `SupervisorSpec::max_restarts` and the [`Default for SupervisorSpec`]
4893    // impl at line 962). Pinned by
4894    // `default_max_restarts_helper_routes_through_lifted_default` +
4895    // `supervisor_spec_default_max_restarts_routes_through_lifted_default`
4896    // in the tests module; peer of the sibling caixa-core
4897    // [`crate::manifest::Caixa::supervisor_view`] `unwrap_or(…)` fold
4898    // that now routes its author-omitted `:max-restarts` arm through
4899    // the same lifted constant.
4900    SUPERVISOR_MAX_RESTARTS_DEFAULT
4901}
4902
4903/// Substrate-canonical Erlang/OTP-shaped `MaxIntensity` restart-budget-
4904/// count default for the `:supervisor :max-restarts` axis — the
4905/// canonical `{intensity, 5, 60}` `MaxIntensity` half of Learn You Some
4906/// Erlang's worker-supervisor default, extracted as a typed `pub const`
4907/// so every substrate-side consumer that resolves "what
4908/// [`SupervisorSpec::max_restarts`] value does an author-omitted
4909/// `:max-restarts` slot degrade onto?" reaches for exactly one
4910/// substrate-primitive `u32`.
4911///
4912/// The `:max-restarts` default axis has two production consumers on the
4913/// substrate side today (both prior to this lift folded onto raw `5`
4914/// literals with no compile-time link back to a shared truth): the
4915/// serde-`#[serde(default = "default_max_restarts")]` helper on
4916/// [`SupervisorSpec::max_restarts`] that every author-omitted
4917/// `:supervisor :max-restarts` slot lands in past the derive-macro's
4918/// wire-format compose, and the [`crate::manifest::Caixa::supervisor_view`]
4919/// `.max_restarts().unwrap_or(5)` fold that every downstream consumer of
4920/// the composed [`SupervisorSpec`] altitude reaches through
4921/// (`feira app graph`, the future wasm-operator's per-supervisor
4922/// restart-intensity counter, the future M4
4923/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission
4924/// webhook, the caixa-operator's hierarchical reconciliation scheduler).
4925/// A pair of open-coded `5`s across two files that expressed no
4926/// compile-time link back to the shared OTP-canonical default — a
4927/// future rebrand of the default (a tightening to Elixir's
4928/// `Supervisor.max_restarts: 3`, a widening to a per-cluster overlay
4929/// the operator pins through a future
4930/// `:supervisor :max-restarts-overrides` slot the MESH-COMPOSITION
4931/// §III.2 supervision-canary roadmap acknowledges, a promotion of the
4932/// plain `u32` count to a richer `{MaxR, MaxT}` per-child-cohort
4933/// restart-budget-partition once the INSPIRATIONS §II.2 Erlang/OTP
4934/// per-child-cohort roadmap lands) would have had to be threaded
4935/// through both open-coded copies in lockstep or the wire-format
4936/// author-omitted arm and the view-construction author-omitted arm
4937/// would silently disagree on which restart-budget an omitted
4938/// `:max-restarts` resolves to (an author writing `:supervisor
4939/// (:max-restarts ())` would round-trip through serde with the new
4940/// default while `supervisor_view` silently continued to compose the
4941/// stale `5`, or vice versa), a two-consumer split at the composition
4942/// boundary far from the source `caixa.lisp` with no field naming the
4943/// default-drift root cause. Lifting the resolution rule to a typed
4944/// `pub const` on the substrate primitive means every downstream
4945/// consumer of the per-Supervisor default-restart-budget-count surface
4946/// reaches for exactly one substrate-primitive `u32` — the resolver's
4947/// accepted value migrates as a unit on any future axis change.
4948///
4949/// The `5` value pins Learn You Some Erlang's `{intensity, 5, 60}`
4950/// worker-supervisor default (the closest canonical OTP-shape
4951/// production reference the substrate carries, matching the sibling
4952/// `60s` `Period` default the [`Default for SupervisorSpec`] impl pairs
4953/// this constant with on the paired sliding-window axis). Two orders of
4954/// magnitude below the [`SUPERVISOR_MAX_RESTARTS_MAX`] `1000` ceiling
4955/// (the upper bracket on the same axis, sibling of this lower default;
4956/// both are typed `u32` const bounds on the `:supervisor :max-restarts`
4957/// axis and now share one accessor discipline on the substrate) and
4958/// above the OTP-`supervisor` callback-module `MaxR = 1` minimum-
4959/// restart floor — the "one restart, then escalate" default is
4960/// deliberately loose enough to absorb a short burst of transient
4961/// child failures without escalating past the supervisor's parent
4962/// while remaining tight enough to trip the `MaxIntensity / Period`
4963/// ratio's escalation on a genuinely-stuck child within the sibling
4964/// `60s` sliding window.
4965///
4966/// Lifted as a typed `pub const` so the bound has exactly one source
4967/// of truth — the serde-side wire-format author-omitted arm at
4968/// [`default_max_restarts`], the [`Default for SupervisorSpec`] impl's
4969/// struct-literal default field, and the caixa-core
4970/// [`crate::manifest::Caixa::supervisor_view`] fold's author-omitted
4971/// arm all read from one place. Same shape every other typed default
4972/// in this crate carries (the sibling
4973/// [`SUPERVISOR_MAX_RESTARTS_MAX`] upper cap on the same axis, the
4974/// paired [`SUPERVISOR_RESTART_WINDOW_MAX`] upper cap on the
4975/// sibling `:restart-window` axis, and the peer
4976/// [`crate::render::DEFAULT_NAMESPACE`] / [`crate::render::DEFAULT_LIBRARY_NAME`]
4977/// per-renderer defaults on the caixa-flux / caixa-helm rendering
4978/// axes).
4979pub const SUPERVISOR_MAX_RESTARTS_DEFAULT: u32 = 5;
4980
4981/// Upper-bound ceiling on the `:supervisor :max-restarts` axis — every
4982/// validated [`SupervisorSpec::max_restarts`] past
4983/// [`SupervisorSpec::validate`] lies in `1..=SUPERVISOR_MAX_RESTARTS_MAX`.
4984///
4985/// The typed field is `u32` (the zero-floor arm
4986/// [`SupervisorError::ZeroMaxRestarts`] already brackets the bottom edge),
4987/// so a programmatic struct literal
4988/// (`SupervisorSpec { max_restarts: u32::MAX, .. }`) and the equivalent
4989/// author-surface form (`:max-restarts 4294967295` or any
4990/// `:max-restarts 100000`-shape typo landing in the slot) both round-trip
4991/// cleanly through serde — a structurally unbounded `u32` ceiling. The
4992/// runtime substrate consuming the value (Erlang/OTP's
4993/// `MaxIntensity / Period` ratio, the future wasm-operator's
4994/// per-supervisor restart-intensity counter, the M4
4995/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission webhook)
4996/// then turned a typed `:max-restarts` policy into a no-op supervisor: the
4997/// escalation threshold is structurally so high that no realistic
4998/// restarts-per-`:restart-window` traffic shape can reach it, the
4999/// supervisor never escalates to its parent, and a bad child can loop
5000/// inside the window indefinitely with the parent supervisor structurally
5001/// never receiving the "this subtree has exceeded its restart budget"
5002/// signal the typed slot is meant to express — the canonical
5003/// "supervisor intensity declared, no escalation" footgun, exactly the
5004/// peer of the [`crate::aplicacao::POLICY_BREAKER_MAX_FAILURES_MAX`] cap
5005/// on the `:politicas :circuit-breaker :max-failures` axis (both are
5006/// "trip the next-higher protection layer after N events in a rolling
5007/// window" counters with identical degenerate-at-the-high-end shape).
5008///
5009/// The `1000` ceiling matches the sibling
5010/// [`crate::aplicacao::POLICY_BREAKER_MAX_FAILURES_MAX`] (the closest
5011/// peer — same "events-per-window trip threshold" semantics, same `u32`
5012/// type, same no-op-at-the-high-end failure mode) so the M4
5013/// `mesh.pleme.io/v1alpha1/Supervisor` / `.../Aplicacao` CR materializers
5014/// and the future wasm-operator's per-supervisor restart-intensity
5015/// counter reach for either field knowing the value is in `1..=1000`
5016/// without re-validating at the reconciler layer. The cap sits two
5017/// orders of magnitude above every documented Erlang/OTP production
5018/// playbook recommendation (Learn You Some Erlang's
5019/// `{intensity, 5, 60}` worker-supervisor default, Elixir's `Supervisor`
5020/// `max_restarts: 3` default, OTP's `supervisor` callback module
5021/// `MaxR = 1` / `MaxT = 5` "minimal-restart" default, Riak Core's
5022/// typical `MaxR ∈ 5..=100`, RabbitMQ's broker-supervisor `MaxR = 5`
5023/// default) and below the clearly-pathological "effectively no
5024/// escalation" floor (`10_000`, `100_000`, `u32::MAX`): a value the
5025/// author can plausibly want at hyperscale (a long-running supervisor
5026/// over a very-flaky pool tolerating thousands of transient restarts
5027/// before escalating), but a hard wall above which the typed policy is
5028/// structurally a no-op carried verbatim on every emitted child-restart
5029/// reconciliation contract.
5030///
5031/// Lifted as a typed `pub const` so the bound has exactly one source of
5032/// truth — the future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
5033/// materializer's admission webhook and the wasm-operator-side
5034/// per-supervisor restart-intensity reconciler read from one place. Same
5035/// shape every other typed upper bound in this crate carries
5036/// ([`crate::aplicacao::POLICY_BREAKER_MAX_FAILURES_MAX`],
5037/// [`crate::aplicacao::POLICY_RETRIES_MAX`],
5038/// [`crate::aplicacao::POLICY_RATE_LIMIT_MAX`],
5039/// [`crate::LIMITS_MEMORY_WASM32_MAX_BYTES`],
5040/// [`crate::render::DNS_1123_LABEL_MAX_LEN`],
5041/// [`crate::render::NATS_SUBJECT_MAX_LEN`]).
5042pub const SUPERVISOR_MAX_RESTARTS_MAX: u32 = 1000;
5043
5044/// Upper-bound ceiling on the `:supervisor :restart-window` axis —
5045/// every validated `Some(`[`SupervisorSpec::restart_window`]`)` past
5046/// [`SupervisorSpec::validate`] lies in `1ms..=SUPERVISOR_RESTART_WINDOW_MAX`
5047/// (inclusive on both ends, integer-millisecond magnitudes by the
5048/// canonical-form gate immediately preceding).
5049///
5050/// The typed field is `Option<Duration>` (the zero-floor arm
5051/// [`SupervisorError::RestartWindowZero`] already rejects
5052/// `Some(Duration::ZERO)`, and the canonical-form arm
5053/// [`SupervisorError::RestartWindowNotCanonical`] already rejects
5054/// sub-millisecond residue), so a programmatic struct literal
5055/// (`SupervisorSpec { restart_window: Some(Duration::from_secs(86_400)),
5056/// .. }` — 24h) and the equivalent author-surface form
5057/// (`(:supervisor (:restart-window "24h"))` — the shared duration codec
5058/// emits `"<n>h"` for any integer-hour magnitude) both round-trip
5059/// cleanly through serde — a structurally unbounded `Duration` ceiling.
5060/// A `:restart-window` value far above the documented Erlang/OTP
5061/// `MaxIntensity / Period` production-playbook band (Learn You Some
5062/// Erlang's `{intensity, 5, 60}` worker-supervisor `Period = 60s`
5063/// default, Elixir's `Supervisor` `max_seconds: 5` default, OTP's
5064/// `supervisor` callback module `MaxT = 5..=60` typical, Riak Core's
5065/// `MaxT ∈ 10s..=300s`, RabbitMQ broker-supervisor `MaxT = 5s` default)
5066/// degenerates the supervisor's restart-intensity counter into a
5067/// lifetime counter: the rolling failure-counting window is structurally
5068/// so long that transient restarts are never forgotten, so the
5069/// `MaxIntensity / Period` ratio degenerates from "trip the parent
5070/// supervisor when the child has exceeded its restart budget *within
5071/// the recent window*" to "trip the parent when the child has exceeded
5072/// its restart budget *over its lifetime*" — every transient restart
5073/// counts against the budget forever, the supervisor's reset semantic
5074/// never reaches the child, and the typed `:restart-window` slot
5075/// becomes a no-op rolling window carried on every emitted hierarchical
5076/// reconciliation contract. The canonical
5077/// rolling-window-degenerates-to-lifetime-counter footgun the sibling
5078/// [`crate::POLICY_BREAKER_WINDOW_MAX`] cap closes on the peer
5079/// `:politicas :circuit-breaker :window` axis with identical shape (both
5080/// are "rolling failure-counting window with a per-`Period` reset" Duration
5081/// axes whose lifetime-counter degenerate at the high end is the same
5082/// "the reset semantic never fires" CSE invariant violation).
5083///
5084/// The `1h` (3600s = `3_600_000` ms) ceiling matches the largest unit
5085/// the shared duration codec emits (`"<n>h"` for any integer-hour
5086/// magnitude) — every value in the canonical authoring form's
5087/// `<integer><unit>` grammar at or below this cap renders to a clean
5088/// canonical string — and matches the three sibling typed-`Duration`
5089/// caps already lifted to this surface
5090/// ([`crate::LIMITS_WALL_CLOCK_MAX`], [`crate::POLICY_TIMEOUT_MAX`],
5091/// [`crate::POLICY_BREAKER_WINDOW_MAX`]). All four typed-`Duration`
5092/// axes — per-process `:limits :wall-clock`, per-edge `:politicas
5093/// :timeout`, per-breaker `:politicas :circuit-breaker :window`, and
5094/// per-supervisor `:supervisor :restart-window` — now share a single
5095/// uniform top edge at the codec's largest emitted unit so the next
5096/// typed-slot wiring (the future wasm-operator's per-supervisor
5097/// `MaxIntensity / Period` reconciler, the M4
5098/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission
5099/// webhook, the `caixa-operator`'s hierarchical reconciliation
5100/// scheduler) reaches for any of the four knowing the value is in
5101/// `1ms..=1h` without re-validating at the renderer layer. The cap sits
5102/// two orders of magnitude above every documented Erlang/OTP / Elixir /
5103/// Riak Core / RabbitMQ production-playbook recommendation band
5104/// (`5s..=300s`) and below the clearly-pathological "rolling window
5105/// degenerates to lifetime counter" floor (`24h`, `7d`, `Duration::MAX`):
5106/// a value the author can plausibly want for a very-low-traffic
5107/// long-tail failure-restart window over a hyperscale-flaky child pool,
5108/// but a hard wall above which the rolling-window contract is
5109/// structurally a lifetime-counter contract.
5110///
5111/// Lifted as a typed `pub const` so the bound has exactly one source
5112/// of truth — the future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
5113/// materializer's admission webhook, the wasm-operator-side
5114/// per-supervisor `MaxIntensity / Period` reconciler, and the
5115/// `caixa-operator`'s hierarchical reconciliation scheduler all read
5116/// from one place. Same shape every other typed upper bound in this
5117/// crate carries ([`SUPERVISOR_MAX_RESTARTS_MAX`],
5118/// [`crate::aplicacao::POLICY_BREAKER_MAX_FAILURES_MAX`],
5119/// [`crate::aplicacao::POLICY_RETRIES_MAX`],
5120/// [`crate::aplicacao::POLICY_RATE_LIMIT_MAX`],
5121/// [`crate::LIMITS_MEMORY_WASM32_MAX_BYTES`],
5122/// [`crate::LIMITS_WALL_CLOCK_MAX`], [`crate::POLICY_TIMEOUT_MAX`],
5123/// [`crate::POLICY_BREAKER_WINDOW_MAX`],
5124/// [`crate::render::DNS_1123_LABEL_MAX_LEN`],
5125/// [`crate::render::NATS_SUBJECT_MAX_LEN`]).
5126pub const SUPERVISOR_RESTART_WINDOW_MAX: Duration = Duration::from_secs(3600);
5127
5128/// Substrate-canonical Erlang/OTP-shaped `Period` sliding-window-duration
5129/// default for the `:supervisor :restart-window` axis — the canonical
5130/// `{intensity, 5, 60}` `Period` half of Learn You Some Erlang's
5131/// worker-supervisor default, extracted as a typed `pub const` so every
5132/// substrate-side consumer that resolves "what
5133/// [`SupervisorSpec::restart_window`] value does an author-omitted
5134/// `:restart-window` slot degrade onto?" reaches for exactly one
5135/// substrate-primitive [`Duration`].
5136///
5137/// The `:restart-window` default axis has one production consumer on the
5138/// substrate side today: the [`Default for SupervisorSpec`] impl's
5139/// struct-literal `restart_window` field, which prior to this lift folded
5140/// onto a raw `Duration::from_secs(60)` literal with no compile-time link
5141/// back to the paired [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `MaxIntensity`
5142/// half of the same `{intensity, 5, 60}` OTP-canonical default. The
5143/// [`crate::manifest::Caixa::supervisor_view`] fold deliberately does
5144/// *not* fall back to this default on the sibling `:restart-window` axis
5145/// — an author-omitted `:supervisor :restart-window` composes to
5146/// `restart_window: None` (the shared codec's soft-swallow shape),
5147/// keeping author-declared intent ("no reset — never escalate on rolling
5148/// window") distinct from the [`Default for SupervisorSpec`] "canonical
5149/// 60s Period" arm every programmatic `SupervisorSpec::default()` caller
5150/// resolves to. Prior to this lift the paired `{intensity, 5, 60}` OTP
5151/// default was split across two files with no compile-time link between
5152/// the halves: [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] pinned the
5153/// `MaxIntensity` half at the substrate primitive while the `Period`
5154/// half rode as an open-coded literal at the composition site, so a
5155/// future coherent rebrand of the paired canonical (a tightening to
5156/// Elixir's `{max_restarts: 3, max_seconds: 5}`, a widening to a
5157/// per-cluster overlay the operator pins through a future
5158/// `:supervisor :restart-window-overrides` slot the MESH-COMPOSITION
5159/// §III.2 supervision-canary roadmap acknowledges, a promotion of the
5160/// paired constants to a per-child-cohort `{MaxR, MaxT}` restart-budget-
5161/// partition once the INSPIRATIONS §II.2 Erlang/OTP per-child-cohort
5162/// roadmap lands) would have had to migrate the `MaxIntensity` half
5163/// through the lifted constant and the `Period` half through a raw
5164/// literal in lockstep or the two halves of the same OTP-canonical
5165/// default would silently drift out of pairing. Lifting the resolution
5166/// rule to a typed `pub const` on the substrate primitive means the
5167/// paired OTP-canonical default migrates as one unit on any future
5168/// axis change.
5169///
5170/// The `60s` value pins Learn You Some Erlang's `{intensity, 5, 60}`
5171/// worker-supervisor default (the closest canonical OTP-shape
5172/// production reference the substrate carries, matching the paired
5173/// [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `5` `MaxIntensity` half this
5174/// constant is the `Period` denominator of on the same
5175/// `MaxIntensity / Period` restart-intensity ratio). Two orders of
5176/// magnitude below the [`SUPERVISOR_RESTART_WINDOW_MAX`] `3600s`
5177/// (`1h`) ceiling (the upper bracket on the same axis, sibling of
5178/// this lower default; both are typed [`Duration`] const bounds on the
5179/// `:supervisor :restart-window` axis and now share one accessor
5180/// discipline on the substrate) and above the OTP-`supervisor`
5181/// callback-module `MaxT = 5` seconds "minimal-window" floor — the "60s
5182/// rolling window" default is deliberately loose enough to absorb a
5183/// short burst of transient child failures without escalating past the
5184/// supervisor's parent while remaining tight enough for the paired
5185/// `MaxIntensity / Period` ratio's escalation to trip on a genuinely-
5186/// stuck child within a human-scale observation window.
5187///
5188/// Lifted as a typed `pub const` so the paired OTP-canonical default has
5189/// exactly one source of truth on each half — the sibling
5190/// [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `MaxIntensity` `5` half and this
5191/// `Period` `60s` half now share the same substrate-primitive lift
5192/// discipline. Same shape every other typed default in this crate
5193/// carries (the sibling [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] paired
5194/// `MaxIntensity` half on the same OTP-canonical `{intensity, 5, 60}`,
5195/// the sibling [`SUPERVISOR_RESTART_WINDOW_MAX`] upper cap on the same
5196/// axis, and the peer [`crate::render::DEFAULT_NAMESPACE`] /
5197/// [`crate::render::DEFAULT_LIBRARY_NAME`] per-renderer defaults on the
5198/// caixa-flux / caixa-helm rendering axes).
5199pub const SUPERVISOR_RESTART_WINDOW_DEFAULT: Duration = Duration::from_secs(60);
5200
5201/// Substrate-canonical Erlang/OTP-shaped sibling-restart-strategy default
5202/// for the `:supervisor :estrategia` axis — the canonical `one_for_one`
5203/// half of Learn You Some Erlang's `{one_for_one, intensity, 5, 60}`
5204/// worker-supervisor default, extracted as a typed `pub const` so every
5205/// substrate-side consumer that resolves "what
5206/// [`SupervisorSpec::estrategia`] variant does an author-omitted
5207/// `:estrategia` slot degrade onto?" reaches for exactly one substrate-
5208/// primitive [`RestartStrategy`].
5209///
5210/// The `:estrategia` default axis has three production consumers on the
5211/// substrate side today: the [`Default for RestartStrategy`] impl's
5212/// return arm, the [`Default for SupervisorSpec`] impl's struct-literal
5213/// `estrategia` field, and the
5214/// [`crate::manifest::Caixa::supervisor_view`] fold's
5215/// `.unwrap_or(SUPERVISOR_ESTRATEGIA_DEFAULT)` `Option<RestartStrategy>`
5216/// collapse arm — three entry points onto the same OTP-canonical
5217/// `one_for_one` value that prior to this lift folded onto a raw
5218/// `Self::OneForOne` arm at the [`Default for RestartStrategy`] impl and
5219/// implicit `RestartStrategy::default()` routes at the sibling consumers,
5220/// with no compile-time link back to the paired
5221/// [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `MaxIntensity` half + the paired
5222/// [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] `Period` half of the same
5223/// `{one_for_one, intensity, 5, 60}` OTP-canonical default. The paired
5224/// triple was split across three altitudes with no compile-time link
5225/// between the halves: the `MaxIntensity` half rode through the lifted
5226/// [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] constant (b698ec0) and the `Period`
5227/// half rode through the lifted [`SUPERVISOR_RESTART_WINDOW_DEFAULT`]
5228/// constant (f7dcd0e) while the `one_for_one` half rode as an open-coded
5229/// discriminator at the [`Default for RestartStrategy`] impl, so a future
5230/// coherent rebrand of the triple (Elixir's `{:one_for_one,
5231/// max_restarts: 3, max_seconds: 5}` — same strategy, different
5232/// intensity/period; an OTP `rest_for_one` widening once the substrate
5233/// discovers startup-order-coupled child cohorts as the more common
5234/// worker-supervisor default; a per-cluster overlay the operator pins
5235/// through a future `:estrategia-overrides` slot the MESH-COMPOSITION
5236/// §III.2 supervision-canary roadmap acknowledges) would have had to
5237/// migrate the `MaxIntensity` + `Period` halves through the lifted
5238/// constants and the `one_for_one` half through an open-coded arm in
5239/// lockstep or the three halves of the same OTP-canonical default would
5240/// silently drift out of pairing. Lifting the resolution rule to a typed
5241/// `pub const` on the substrate primitive means the paired OTP-canonical
5242/// worker-supervisor default migrates as one unit on any future axis
5243/// change.
5244///
5245/// The [`RestartStrategy::OneForOne`] value pins Learn You Some Erlang's
5246/// `{one_for_one, intensity, 5, 60}` worker-supervisor default (the
5247/// closest canonical OTP-shape production reference the substrate
5248/// carries, matching the paired [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `5`
5249/// `MaxIntensity` half and the paired [`SUPERVISOR_RESTART_WINDOW_DEFAULT`]
5250/// `60s` `Period` half). The `one_for_one` strategy — restart only the
5251/// failed child, leaving siblings untouched — is the default for tree-of-
5252/// independent-workers use cases the substrate's [`RestartStrategy`]
5253/// discriminator's own docstring already carries as the default arm; it
5254/// composes with the `{5, 60}` restart-intensity ratio to name the same
5255/// substrate-canonical "canonical worker-supervisor" shape the paired
5256/// halves close on their respective axes.
5257///
5258/// Lifted as a typed `pub const` so the paired OTP-canonical default has
5259/// exactly one source of truth on each of its three halves — the sibling
5260/// [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] `MaxIntensity` `5` half, the
5261/// sibling [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] `Period` `60s` half, and
5262/// this `one_for_one` strategy half now share the same substrate-
5263/// primitive lift discipline. Same shape every other typed default in
5264/// this crate carries (the sibling [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] +
5265/// [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] paired halves on the same OTP-
5266/// canonical `{one_for_one, intensity, 5, 60}`, the sibling
5267/// [`SUPERVISOR_MAX_RESTARTS_MAX`] + [`SUPERVISOR_RESTART_WINDOW_MAX`]
5268/// upper caps on the paired sibling axes, and the peer
5269/// [`crate::render::DEFAULT_NAMESPACE`] / [`crate::render::DEFAULT_LIBRARY_NAME`]
5270/// per-renderer defaults on the caixa-flux / caixa-helm rendering axes).
5271pub const SUPERVISOR_ESTRATEGIA_DEFAULT: RestartStrategy = RestartStrategy::OneForOne;
5272
5273/// Substrate-canonical Erlang/OTP-shaped per-child restart-decision-policy
5274/// default for the `:children :restart` axis — the OTP `permanent`
5275/// worker-child default (`{ChildId, StartFunc, permanent, …}` in a
5276/// `supervisor`'s `init/1` child-spec tuple), extracted as a typed
5277/// `pub const` so every substrate-side consumer that resolves "what
5278/// [`ChildSpec::restart`] variant does an author-omitted `:children
5279/// :restart` slot degrade onto?" reaches for exactly one substrate-
5280/// primitive [`RestartPolicy`].
5281///
5282/// Completes the OTP-shape supervisor-tree default set at the substrate
5283/// primitive. The per-`:supervisor` axis already carries all three of its
5284/// halves as lifted typed constants — [`SUPERVISOR_ESTRATEGIA_DEFAULT`]
5285/// (`one_for_one`, 95ffacc), [`SUPERVISOR_MAX_RESTARTS_DEFAULT`]
5286/// (`MaxIntensity` `5`, b698ec0), [`SUPERVISOR_RESTART_WINDOW_DEFAULT`]
5287/// (`Period` `60s`, f7dcd0e) — while the per-`:children` axis's own
5288/// OTP-canonical default rode as an open-coded `Self::Permanent` arm in
5289/// the [`Default for RestartPolicy`] impl, the last un-lifted default on
5290/// the M2 `:supervisor` slot family. The split mattered because the two
5291/// axes resolve *together* on every author-omitted supervisor: a
5292/// `(defcaixa :kind Supervisor :children ((:caixa "worker" :versao
5293/// "^0.1")))` with no `:estrategia` and no per-child `:restart` degrades
5294/// onto `{one_for_one, 5, 60}` through three lifted constants and onto
5295/// `permanent` through an open-coded enum arm, so a future coherent
5296/// rebrand of the OTP-shape default set (an Elixir-shaped
5297/// `{:one_for_one, max_restarts: 3, max_seconds: 5}` tightening, a
5298/// per-cluster overlay the operator pins through the MESH-COMPOSITION
5299/// §III.2 supervision-canary roadmap slots, an OTP-`transient` widening
5300/// once the substrate discovers clean-completion-aware children as the
5301/// more common child shape) would have had to migrate three halves
5302/// through typed constants and the fourth through a raw enum arm in
5303/// lockstep or the supervisor-level and child-level defaults would
5304/// silently drift apart.
5305///
5306/// The `:children :restart` default axis has two production consumers on
5307/// the substrate side today: the [`Default for RestartPolicy`] impl's
5308/// return arm, and the serde-side `#[serde(default)]` on
5309/// [`ChildSpec::restart`] that resolves an author-omitted `:children
5310/// :restart` slot through that same impl. Both now key off this one
5311/// substrate primitive, so the future wasm-operator's per-child post-exit
5312/// restart-decision branch, the future M4
5313/// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-child
5314/// admission webhook, and the `caixa-operator`'s hierarchical
5315/// reconciliation scheduler's per-child fan-out all reach for one typed
5316/// identifier when they resolve an omitted per-child restart posture.
5317///
5318/// The [`RestartPolicy::Permanent`] value pins Erlang/OTP's `permanent`
5319/// worker-child restart type — always restart the child regardless of how
5320/// it died, the canonical posture for long-running services that must
5321/// always be up, matching the sibling [`SUPERVISOR_ESTRATEGIA_DEFAULT`]
5322/// `one_for_one` tree-of-independent-workers strategy this constant pairs
5323/// with under the same `{one_for_one, intensity, 5, 60}` worker-supervisor
5324/// shape. The two alternatives the closed [`RestartPolicy::ALL`] accept-set
5325/// carries ([`RestartPolicy::Transient`] — restart only on abnormal exit;
5326/// [`RestartPolicy::Temporary`] — never restart) express deliberate
5327/// one-shot / clean-completion-aware postures an author declares
5328/// explicitly, never a posture an omitted slot should silently assume.
5329pub const SUPERVISOR_CHILD_RESTART_DEFAULT: RestartPolicy = RestartPolicy::Permanent;
5330
5331/// Route the manually-authored [`Default`] impl on [`SupervisorSpec`]
5332/// through the substrate-canonical [`SupervisorSpec::otp_canonical`]
5333/// `pub const fn` constructor rather than a struct-literal cascade over
5334/// the paired [`SUPERVISOR_ESTRATEGIA_DEFAULT`] /
5335/// [`default_max_restarts`] / [`SUPERVISOR_RESTART_WINDOW_DEFAULT`]
5336/// lifted consts — one source of truth for the Erlang/OTP-canonical
5337/// `{one_for_one, 5, 60}` worker-supervisor baseline across the two
5338/// paths every downstream consumer already reaches through (the
5339/// hand-authored-until-now [`Default::default`] the
5340/// `..SupervisorSpec::default()` struct-update-syntax on every
5341/// one-axis-under-test fixture in this crate's test module rests on,
5342/// and the `pub const fn` [`SupervisorSpec::otp_canonical`] constructor
5343/// every `const`-context consumer reaches through).
5344///
5345/// Extends the [`Default`]-through-const-ctor fold discipline the
5346/// [`crate::LimitsSpec`] [`Default`]-through-[`crate::LimitsSpec::empty`]
5347/// (abd52c2), [`crate::aplicacao::MeshPolicy`]
5348/// [`Default`]-through-[`crate::aplicacao::MeshPolicy::empty`] (91641a4),
5349/// and [`crate::BehaviorSpec`]
5350/// [`Default`]-through-[`crate::BehaviorSpec::empty`] (0c1752c) folds
5351/// closed on the M2 / M3 `Option`-only "canonical unset baseline"
5352/// typed-slot spec family — extended here onto the M2 supervisor-slot
5353/// [`SupervisorSpec`] whose canonical baseline is not "everything
5354/// `None`" but the OTP-canonical `{one_for_one, 5, 60}` worker-
5355/// supervisor triple. The `empty()` peer's naming did not fit
5356/// (`SupervisorSpec` carries a discriminator-shaped `estrategia` field
5357/// and a non-zero `max_restarts`/`restart_window` pair whose canonical
5358/// shape is Erlang/OTP-descended, not the "no axis declared" bottom
5359/// the sibling `Option`-only slots fold to), so this peer is named
5360/// [`SupervisorSpec::otp_canonical`] instead — the same phrasing the
5361/// existing per-arm pin tests
5362/// [`tests::supervisor_estrategia_default_pins_otp_canonical_value`] /
5363/// [`tests::supervisor_max_restarts_default_pins_otp_canonical_value`] /
5364/// [`tests::supervisor_restart_window_default_pins_otp_canonical_value`]
5365/// already reach for. Pinned load-bearing by
5366/// [`tests::supervisor_spec_default_routes_through_otp_canonical_ctor`]
5367/// (byte-parity pin against [`SupervisorSpec::otp_canonical`] under
5368/// [`PartialEq`], sharpening the sibling
5369/// `supervisor_spec_default_*_routes_through_lifted_default` per-arm
5370/// pins from a per-field lift into a whole-struct one-source-of-truth
5371/// pin — the derived-until-now [`Default::default`] and the
5372/// [`SupervisorSpec::otp_canonical`] constructor are byte-equal by
5373/// construction, not by coincidence).
5374impl Default for SupervisorSpec {
5375    #[inline]
5376    fn default() -> Self {
5377        Self::otp_canonical()
5378    }
5379}
5380
5381impl SupervisorSpec {
5382    /// `const`-context peer of the [`Default for SupervisorSpec`]
5383    /// impl (which routes through this constructor) — returns the
5384    /// Erlang/OTP-canonical `{one_for_one, 5, 60}` worker-supervisor
5385    /// baseline this crate reaches for in every fixture-builder
5386    /// `..SupervisorSpec::default()` struct-update expression and
5387    /// every downstream `SupervisorSpec::default()` seed.
5388    ///
5389    /// Each field routes through the same substrate-canonical
5390    /// [`SUPERVISOR_ESTRATEGIA_DEFAULT`] / [`default_max_restarts`] /
5391    /// [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] lifted consts the
5392    /// per-arm pin tests
5393    /// [`tests::supervisor_estrategia_default_pins_otp_canonical_value`]
5394    /// / [`tests::supervisor_max_restarts_default_pins_otp_canonical_value`]
5395    /// / [`tests::supervisor_restart_window_default_pins_otp_canonical_value`]
5396    /// already assert, so a future coherent rebrand of the OTP-canonical
5397    /// triple (Elixir's `{max_restarts: 3, max_seconds: 5}`, a per-
5398    /// cluster overlay via a future `:restart-window-overrides` slot, a
5399    /// per-child-cohort promotion the INSPIRATIONS.md §II.2 Erlang/OTP
5400    /// absorption roadmap acknowledges) migrates through three typed
5401    /// constants in lockstep, and the paired [`Default`] impl inherits
5402    /// every future extension by construction.
5403    ///
5404    /// `pub const fn` rather than the derived-style `Default::default`
5405    /// or a `pub const SUPERVISOR_SPEC_DEFAULT: SupervisorSpec` item —
5406    /// [`Default::default`] is not `const` on stable Rust, and
5407    /// `SupervisorSpec` is non-`Copy` so a `pub const` item would force
5408    /// every consumer through a [`Clone::clone`]. The `pub const fn`
5409    /// discipline lets `const`-context callers construct the OTP-
5410    /// canonical baseline at compile time without runtime dispatch on
5411    /// the derived [`Default::default`], the same posture the sibling
5412    /// [`crate::LimitsSpec::empty`] (9739971) /
5413    /// [`crate::aplicacao::MeshPolicy::empty`] (6df969b) /
5414    /// [`crate::BehaviorSpec::empty`] (f9b18e3) `Option`-only typed-slot
5415    /// spec `pub const fn` constructors carry on the sibling
5416    /// "everything `None`" baseline axis.
5417    ///
5418    /// Fourth peer on the M2 / M3 typed-slot-spec "const-context peer
5419    /// of the derived-style [`Default`]" family — sibling of the
5420    /// [`crate::LimitsSpec::empty`] / [`crate::aplicacao::MeshPolicy::empty`]
5421    /// / [`crate::BehaviorSpec::empty`] `Option`-only "canonical unset
5422    /// baseline" trio, extended here onto the M2 supervisor-slot
5423    /// [`SupervisorSpec`] whose canonical baseline is not "everything
5424    /// `None`" but the Erlang/OTP-canonical `{one_for_one, 5, 60}`
5425    /// worker-supervisor triple. Named [`Self::otp_canonical`] rather
5426    /// than `empty()` to name the actual invariant the return value
5427    /// pins — the same phrasing already used in the per-arm pin tests
5428    /// on this file. Pinned load-bearing by
5429    /// [`tests::supervisor_spec_otp_canonical_byte_equals_default`] and
5430    /// [`tests::supervisor_spec_otp_canonical_is_usable_in_const_context`].
5431    #[must_use]
5432    pub const fn otp_canonical() -> Self {
5433        Self {
5434            estrategia: SUPERVISOR_ESTRATEGIA_DEFAULT,
5435            max_restarts: default_max_restarts(),
5436            restart_window: Some(SUPERVISOR_RESTART_WINDOW_DEFAULT),
5437            children: Vec::new(),
5438        }
5439    }
5440
5441    /// Substrate-canonical per-`:supervisor` `:estrategia` OTP-shaped
5442    /// sibling-restart-strategy scalar accessor every consumer that
5443    /// dispatches on the supervisor's per-sibling restart-decision shape
5444    /// keys off — returns the author-declared `:supervisor :estrategia`
5445    /// variant verbatim as a [`RestartStrategy`], `Copy`-projected from
5446    /// the typed slot's own [`RestartStrategy`] storage.
5447    ///
5448    /// The `:supervisor :estrategia` slot carries the closed-set
5449    /// OTP-shaped sibling-restart-strategy discriminator ([`RestartStrategy::OneForOne`]
5450    /// — restart only the failed child, the Erlang/OTP `one_for_one` default;
5451    /// [`RestartStrategy::OneForAll`] — restart every child on any child
5452    /// failure, the Erlang/OTP `one_for_all` shared-state cohort default;
5453    /// [`RestartStrategy::RestForOne`] — restart the failed child and
5454    /// every child started after it, the Erlang/OTP `rest_for_one`
5455    /// startup-order default; [`RestartStrategy::SimpleOneForOne`] —
5456    /// dynamic children of the same shape, the Erlang/OTP
5457    /// `simple_one_for_one` per-session default) that every downstream
5458    /// consumer of the Supervisor's per-sibling restart-decision fan-out
5459    /// shape keys off. Validated by [`SupervisorSpec::validate`] to be
5460    /// paired coherently with the sibling `:children` axis
5461    /// (`SimpleOneForOne ↔ children.is_empty()` — the cross-slot
5462    /// partition the strategy-arm's [`SupervisorError::SimpleOneForOneWithStaticChildren`]
5463    /// / [`SupervisorError::NoChildren`] refusal cascade pins), and every
5464    /// downstream consumer that reads the strategy keys off this scalar
5465    /// (the [`SupervisorSpec::validate`] `SimpleOneForOne ↔ non-SimpleOneForOne`
5466    /// partition-dispatch `match` arm, the non-`SimpleOneForOne`-arm
5467    /// declared-but-empty [`SupervisorError::NoChildren`] error carrier's
5468    /// `estrategia:` field, the future `feira app graph` per-Supervisor
5469    /// strategy print line, the future wasm-operator's per-supervisor
5470    /// sibling-restart-strategy branch, the future M4
5471    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-strategy
5472    /// admission-webhook resolver, the `caixa-operator`'s hierarchical
5473    /// reconciliation scheduler's per-strategy fan-out).
5474    ///
5475    /// Prior to this lift the `.estrategia` field was accessed inline at
5476    /// two production sites in `caixa-core/src/supervisor.rs` — the
5477    /// [`SupervisorSpec::validate`] `SimpleOneForOne ↔ non-SimpleOneForOne`
5478    /// `match self.estrategia { … }` partition dispatch, and the
5479    /// non-`SimpleOneForOne`-arm [`SupervisorError::NoChildren`] error
5480    /// carrier at `estrategia: self.estrategia` — two open-coded
5481    /// field-accesses that expressed no compile-time link back to the
5482    /// typed slot. A future extension of the `:supervisor :estrategia`
5483    /// axis to a richer author surface (a per-cluster strategy override
5484    /// the operator pins through a future `:supervisor :estrategia-overrides`
5485    /// slot the MESH-COMPOSITION §III.2 supervision-canary roadmap
5486    /// acknowledges, a per-tenant strategy-alias table the M4 CR
5487    /// materializer resolves per-CR, a per-Supervisor dynamic strategy
5488    /// derivation the future adaptive-supervision engine computes from
5489    /// child-failure-history topology, a per-child-cohort strategy split
5490    /// the future `RestForCohort` extension acknowledged by the
5491    /// INSPIRATIONS.md §II.2 Erlang/OTP absorption roadmap acknowledges)
5492    /// would have had to be threaded through every open-coded copy in
5493    /// lockstep — one consumer reading the raw variant while a peer read
5494    /// the operator-resolved variant would silently split the
5495    /// [`SupervisorError::NoChildren`] diagnostic's quoted strategy from
5496    /// the actual partition-dispatch input the empty-children refusal
5497    /// arm reached under, a two-consumer split at the validator far from
5498    /// the source `caixa.lisp` with no field naming the strategy-drift
5499    /// root cause. Lifting the resolution rule to a typed method on the
5500    /// substrate primitive means every downstream consumer of the
5501    /// Supervisor's per-`:supervisor` sibling-restart-strategy surface
5502    /// reaches for exactly one typed dispatch — the resolver's accept-set
5503    /// migrates as a unit on any future axis addition.
5504    ///
5505    /// Peer of the sibling M3 mesh-slot [`crate::Placement::estrategia`]
5506    /// (921fe1b) `Copy`-return `PlacementStrategy` scalar accessor on the
5507    /// per-`:placement` distribution-strategy axis — same "one typed
5508    /// dispatch on the substrate primitive, thin projections at each
5509    /// consumer" discipline extended onto the M2 supervisor-slot
5510    /// per-`:supervisor` sibling-restart-strategy `Copy`-composite-enum
5511    /// scalar axis. The two typed axes (`Placement::estrategia` on the
5512    /// M3 Aplicacao side, `SupervisorSpec::estrategia` on the M2
5513    /// Supervisor side) now share one accessor discipline for the shared
5514    /// substrate concept "a `Copy`-projected closed-set enum-arm
5515    /// discriminator that partitions the downstream renderer's per-arm
5516    /// fan-out". First `Copy`-return accessor on the M2 supervisor-slot
5517    /// `SupervisorSpec` type — companion to the sibling per-`:children`
5518    /// [`crate::ChildSpec::nome`] (57c61d0) /
5519    /// [`crate::ChildSpec::versao_requirement`] (2c053c8) child-caixa
5520    /// scalar accessors on the sibling per-`:children` `String`-carry
5521    /// axes. Named `estrategia()` to match the storage field's name and
5522    /// the peer [`crate::Placement::estrategia`] method-name discipline
5523    /// verbatim; the accessor's identity name maps onto the canonical
5524    /// OTP-shape supervision vocabulary the [`RestartStrategy`] enum's
5525    /// docstring already carries.
5526    ///
5527    /// Declared `pub const fn` to close the M2 supervisor-slot
5528    /// `Copy`-return raw-field-getter `const`-eval-surface pass —
5529    /// sibling of the peer M2 per-`:children` [`ChildSpec::restart`]
5530    /// (converted in this commit) `Copy`-composite-enum accessor, peer
5531    /// of the sibling M2 per-`:supervisor`
5532    /// [`SupervisorSpec::max_restarts`] (b698ec0) `Copy`-`u32` accessor
5533    /// already lifted, and mirror of the peer M3 mesh-slot
5534    /// per-`:placement` [`crate::Placement::estrategia`] (bafa004)
5535    /// `Copy`-return `pub const fn` scalar accessor whose method-name
5536    /// discipline this accessor was authored to match. Every downstream
5537    /// substrate-side `const`-context consumer of the per-`:supervisor`
5538    /// sibling-restart-strategy scalar (a future module-scope `const
5539    /// _:() = assert!(matches!(sup.estrategia(),
5540    /// RestartStrategy::OneForOne))` invariant pin on a typed fixture,
5541    /// a future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer
5542    /// admission-webhook `const fn` per-supervisor strategy-arm floor
5543    /// over a typed [`SupervisorSpec`], any future `const fn`
5544    /// supervisor-tree composer over the substrate primitive that fans
5545    /// on the sibling-restart-strategy at compile time) now reaches
5546    /// through the same typed dispatch on the substrate primitive at
5547    /// const-eval time as at runtime. A future non-`Copy`-return
5548    /// promotion of the scalar (an `Option<RestartStrategy>`-shape
5549    /// migration once the substrate grows per-cluster strategy overlays
5550    /// the [`SupervisorSpec`] docstring already anticipates, a
5551    /// per-tenant strategy-alias table the M4 CR materializer resolves
5552    /// per-CR) that would drop the `const` qualifier fails the
5553    /// fail-before-pass-after pin
5554    /// [`tests::supervisor_spec_estrategia_accessor_is_const_fn`] at
5555    /// caixa-core build time rather than surfacing as a downstream
5556    /// consumer regression.
5557    #[must_use]
5558    pub const fn estrategia(&self) -> RestartStrategy {
5559        self.estrategia
5560    }
5561
5562    /// Substrate-canonical per-`:supervisor` `:max-restarts` OTP-shaped
5563    /// `MaxIntensity` restart-budget scalar accessor every consumer that
5564    /// reads the supervisor's per-`:restart-window` restart-budget count
5565    /// keys off — returns the author-declared `:supervisor :max-restarts`
5566    /// typed `u32` verbatim, `Copy`-projected from the typed slot's own
5567    /// `u32` storage (`u32` is `Copy`, so the accessor returns by value; no
5568    /// borrow of `&self` past the call). Non-optional (the `u32` field
5569    /// carries the restart-budget count as a required axis with a
5570    /// [`default_max_restarts`]-supplied default; the zero-floor arm
5571    /// [`SupervisorError::ZeroMaxRestarts`] and the cap arm
5572    /// [`SupervisorError::MaxRestartsExceedsCap`] jointly bracket the
5573    /// accept-set to `1..=SUPERVISOR_MAX_RESTARTS_MAX`).
5574    ///
5575    /// The `:supervisor :max-restarts` slot carries the Erlang/OTP
5576    /// `MaxIntensity` restart-budget count that pairs with the sibling
5577    /// `:restart-window` `Period` to form the `MaxIntensity / Period`
5578    /// restart-intensity ratio the supervisor trips its own escalation on
5579    /// (`theory/RUNTIME-PATTERNS.md` §II.2, Learn You Some Erlang's
5580    /// `{intensity, 5, 60}` worker-supervisor default). Every downstream
5581    /// consumer of the Supervisor's per-`:supervisor` restart-budget count
5582    /// keys off this scalar (the [`SupervisorSpec::validate`] zero-floor +
5583    /// upper-cap bracket at
5584    /// `require_positive_bounded_u32(self.max_restarts(), …)`, the future
5585    /// wasm-operator's per-supervisor restart-intensity counter's
5586    /// budget-vs-count comparator, the future M4
5587    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission
5588    /// webhook, the `caixa-operator`'s hierarchical reconciliation
5589    /// scheduler's per-supervisor escalation-decision branch, every
5590    /// `SupervisorError::MaxRestartsExceedsCap` variant carrying the
5591    /// offending count verbatim for `feira lint` rendering).
5592    ///
5593    /// Prior to this lift the `.max_restarts` field was accessed inline at
5594    /// one production site in `caixa-core/src/supervisor.rs` — the
5595    /// [`SupervisorSpec::validate`] `require_positive_bounded_u32(self
5596    /// .max_restarts, …)` bracket-gate call — one open-coded field-access
5597    /// that expressed no compile-time link back to the typed slot. A
5598    /// future extension of the `:max-restarts` axis to a richer author
5599    /// surface (a per-cluster restart-budget override the operator pins
5600    /// through a future `:supervisor :max-restarts-overrides` slot the
5601    /// MESH-COMPOSITION §III.2 supervision-canary roadmap acknowledges,
5602    /// a per-tenant restart-budget-alias table the M4 CR materializer
5603    /// resolves per-CR, a per-supervisor dynamic restart-budget derivation
5604    /// the future adaptive-supervision engine computes from child-failure-
5605    /// history topology, a promotion of the plain `u32` count to a richer
5606    /// `{MaxR, MaxT}` tuple once Erlang/OTP's per-child-cohort restart-
5607    /// budget-partition slot comes into scope) would have had to be
5608    /// threaded through every open-coded copy in lockstep or the validate
5609    /// gate and the future M4 emit path would silently disagree on which
5610    /// restart-budget count a given supervisor resolves to — an author's
5611    /// `:max-restarts 5` would satisfy validate while the emit path
5612    /// silently read a drifted other value (a `:max-restarts 10000`
5613    /// no-op supervisor at the emit boundary would carry the author's
5614    /// declared `5` verbatim in `feira lint` output while the future
5615    /// wasm-operator's restart-intensity counter operated under the
5616    /// drifted count), a two-consumer split at the validator far from the
5617    /// source `caixa.lisp` with no field naming the restart-budget-drift
5618    /// root cause. Lifting the resolution rule to a typed method on the
5619    /// substrate primitive means every downstream consumer of the
5620    /// Supervisor's per-`:supervisor` restart-budget-count surface reaches
5621    /// for exactly one typed dispatch — the resolver's accept-set migrates
5622    /// as a unit on any future axis addition.
5623    ///
5624    /// Peer of the sibling M3 mesh-slot [`crate::CircuitBreaker::max_failures`]
5625    /// (3a74062) `Copy`-return `u32` sub-struct required-scalar accessor
5626    /// on the per-`:politicas :circuit-breaker :max-failures` Envoy-
5627    /// outlier-detection trip-threshold axis — same "one typed dispatch on
5628    /// the substrate primitive, thin projections at each consumer"
5629    /// discipline extended onto the M2 supervisor-slot per-`:supervisor`
5630    /// restart-budget-count `Copy`-`u32` scalar axis. The two typed axes
5631    /// (`CircuitBreaker::max_failures` on the M3 Aplicacao side,
5632    /// `SupervisorSpec::max_restarts` on the M2 Supervisor side) now share
5633    /// one accessor discipline for the shared substrate concept "a
5634    /// `Copy`-projected required `u32` count that trips the next-higher
5635    /// protection layer after N events in a rolling window" — both are
5636    /// counters with identical degenerate-at-the-high-end shape and share
5637    /// the paired [`crate::POLICY_BREAKER_MAX_FAILURES_MAX`] /
5638    /// [`SUPERVISOR_MAX_RESTARTS_MAX`] `1000` cap. Second `Copy`-return
5639    /// accessor on the M2 supervisor-slot `SupervisorSpec` type, sibling
5640    /// to the [`SupervisorSpec::estrategia`] (eafb619) `Copy`-composite-
5641    /// enum `RestartStrategy` accessor. Named `max_restarts()` to match
5642    /// the storage field's name verbatim and the peer
5643    /// [`crate::CircuitBreaker::max_failures`] method-name discipline; the
5644    /// accessor's identity maps onto the canonical OTP-shape supervision
5645    /// vocabulary the [`SupervisorSpec::max_restarts`] field's docstring
5646    /// already carries.
5647    #[must_use]
5648    pub const fn max_restarts(&self) -> u32 {
5649        self.max_restarts
5650    }
5651
5652    /// Substrate-canonical per-`:supervisor` `:restart-window` OTP-shaped
5653    /// `Period` sliding-window scalar accessor every consumer of the
5654    /// supervisor's `MaxIntensity / Period` restart-intensity denominator
5655    /// keys off — returns the author-declared `:supervisor :restart-window`
5656    /// typed [`Duration`] verbatim as an `Option<Duration>`, copied out of
5657    /// the typed slot's own `Option<Duration>` storage (`Duration` is
5658    /// `Copy`, so `Option<Duration>` is `Copy` and the accessor returns by
5659    /// value; no borrow of `&self` past the call). `None` when the slot is
5660    /// absent (the canonical "never reset — every restart across the
5661    /// supervisor's lifetime counts against the sibling `:max-restarts`
5662    /// budget" sentinel the field's own docstring names and the peer
5663    /// `validate_accepts_none_restart_window` pin locks in on the
5664    /// [`SupervisorSpec::validate`] entry-side).
5665    ///
5666    /// The `:supervisor :restart-window` slot carries the Erlang/OTP
5667    /// `Period` sliding-observation-interval that pairs with the sibling
5668    /// `:max-restarts` `MaxIntensity` restart-budget count to form the
5669    /// `MaxIntensity / Period` restart-intensity ratio the supervisor
5670    /// trips its own escalation on (`theory/RUNTIME-PATTERNS.md` §II.2,
5671    /// Learn You Some Erlang's `{intensity, 5, 60}` worker-supervisor
5672    /// default). The typed slot's `Option<Duration>` accept-set —
5673    /// zero-floor rejected through [`SupervisorError::RestartWindowZero`]
5674    /// (Erlang/OTP's `MaxIntensity / Period` invariant requires
5675    /// `Period > 0`; a zero period either trips on the first failure or
5676    /// never trips depending on operator interpretation, neither of which
5677    /// is the author's intent — omit the slot to express "no reset";
5678    /// carry a positive duration to express the sliding window),
5679    /// integer-millisecond canonical form enforced through
5680    /// [`SupervisorError::RestartWindowNotCanonical`] (the duration
5681    /// codec's canonical form emits `"1500ms"` not `"1.5s"` and the
5682    /// future wasm-operator's per-supervisor restart-intensity counter
5683    /// quantizes at milliseconds), upper-bounded by
5684    /// [`SUPERVISOR_RESTART_WINDOW_MAX`] (1h — the coarsest per-
5685    /// supervisor rolling window any operationally-reachable supervisor
5686    /// can honor without spanning multiple scheduler epochs the
5687    /// hierarchical-reconciliation scheduler treats as independent) —
5688    /// maps onto the future wasm-operator (M3) per-supervisor
5689    /// restart-intensity counter's rolling-observation-interval, the
5690    /// future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
5691    /// per-`spec.restartWindow` admission webhook, and the sibling
5692    /// `duration_codec`-serialized wire scalar every downstream consumer
5693    /// of the supervisor's per-`:supervisor` restart-intensity denominator
5694    /// keys off.
5695    ///
5696    /// Prior to this lift the `.restart_window` field was accessed inline
5697    /// at one production site in `caixa-core/src/supervisor.rs` — the
5698    /// [`SupervisorSpec::validate`] `if let Some(w) = self.restart_window {
5699    /// … }` zero-floor + canonical-form + upper-cap bracket arm — one
5700    /// open-coded field-access that expressed no compile-time link back to
5701    /// the typed slot. A future extension of the `:restart-window` axis to
5702    /// a richer author surface (a per-cluster restart-window override the
5703    /// operator pins through a future `:supervisor :restart-window-overrides`
5704    /// slot the MESH-COMPOSITION §III.2 supervision-canary roadmap
5705    /// acknowledges, a per-tenant restart-window-alias table the M4 CR
5706    /// materializer resolves per-CR, a per-supervisor dynamic
5707    /// restart-window derivation the future adaptive-supervision engine
5708    /// computes from child-failure-history topology, a promotion of the
5709    /// plain `Option<Duration>` window to a richer `{observation, cooldown}`
5710    /// pair once Erlang/OTP's per-child-cohort observation-interval-
5711    /// partition slot comes into scope) would have had to be threaded
5712    /// through every open-coded copy in lockstep or the validate gate and
5713    /// the future M4 emit path would silently disagree on which
5714    /// restart-window a given supervisor resolves to — an author's
5715    /// `:restart-window "60s"` would satisfy validate while the emit path
5716    /// silently read a drifted other value (a `Some(Duration::from_secs(60))`
5717    /// authored slot at the emit boundary would carry the author's
5718    /// declared window verbatim in `feira lint` output while the future
5719    /// wasm-operator's restart-intensity counter operated under a
5720    /// drifted window, or vice versa: an author's `:restart-window ()`
5721    /// would carry the "never reset" sentinel through validate while the
5722    /// emit path silently substituted a default sliding window), a
5723    /// two-consumer split at the validator far from the source
5724    /// `caixa.lisp` with no field naming the restart-window-drift root
5725    /// cause. Lifting the resolution rule to a typed method on the
5726    /// substrate primitive means every downstream consumer of the
5727    /// Supervisor's per-`:supervisor` restart-intensity-denominator
5728    /// surface reaches for exactly one typed dispatch — the resolver's
5729    /// accept-set migrates as a unit on any future axis addition.
5730    ///
5731    /// Third `Copy`-return accessor on the M2 supervisor-slot
5732    /// `SupervisorSpec` type, closing the last unlifted per-`:supervisor`
5733    /// scalar-value axis (`children: Vec<ChildSpec>` carries a `Vec`
5734    /// payload rather than a `Copy`-scalar, and the per-`:children`
5735    /// [`crate::ChildSpec::nome`] (57c61d0) /
5736    /// [`crate::ChildSpec::versao_requirement`] (2c053c8) child-caixa
5737    /// scalar accessors already close the per-element `String`-carry
5738    /// axes). Sibling to the peer M2 [`crate::LimitsSpec::wall_clock`]
5739    /// (8cb717b) `Option<Duration>` accessor on the `:limits` slot's
5740    /// per-outermost-call wall-clock-deadline axis and the peer M3
5741    /// [`crate::MeshPolicy::timeout`] (7073d0f) `Option<Duration>`
5742    /// accessor on the `:politicas` slot's per-call-deadline axis — all
5743    /// three share the shared substrate concept "a `Copy`-projected
5744    /// optional `Duration` that carries a positive integer-millisecond
5745    /// canonical value with a `1ms..=<axis-specific>_MAX` accept-set and
5746    /// the paired zero-floor / non-canonical / above-cap refusal cascade"
5747    /// through the same [`crate::render::require_positive_canonical_bounded_duration`]
5748    /// bracket-helper the three axes each route through. Named
5749    /// `restart_window()` to match the storage field's name verbatim and
5750    /// the peer [`crate::LimitsSpec::wall_clock`] /
5751    /// [`crate::MeshPolicy::timeout`] method-name discipline; the
5752    /// accessor's identity maps onto the canonical OTP-shape supervision
5753    /// vocabulary the [`SupervisorSpec::restart_window`] field's docstring
5754    /// already carries.
5755    #[must_use]
5756    pub const fn restart_window(&self) -> Option<Duration> {
5757        self.restart_window
5758    }
5759
5760    /// Substrate-canonical per-`:supervisor` `:children` OTP-shaped
5761    /// static-child-list slice accessor every consumer that walks the
5762    /// supervisor's declared child set keys off — returns the author-
5763    /// declared `:supervisor :children` `Vec<ChildSpec>` verbatim as a
5764    /// `&[ChildSpec]` slice-view, borrowed from the typed slot's own
5765    /// `Vec<ChildSpec>` storage (a zero-copy slice-view over the same
5766    /// backing buffer the `Serialize`/`Deserialize` derives round-trip
5767    /// through). Non-optional: an empty slice is the load-bearing
5768    /// "author declared `:children ()`" sentinel every consumer of the
5769    /// cross-slot `SimpleOneForOne ↔ children.is_empty()` partition
5770    /// keys off (`SimpleOneForOne` requires the empty slice; the peer
5771    /// three strategies require a non-empty slice — the paired
5772    /// [`SupervisorError::SimpleOneForOneWithStaticChildren`] /
5773    /// [`SupervisorError::NoChildren`] refusal cascade pins the
5774    /// partition on both arms).
5775    ///
5776    /// The `:supervisor :children` slot carries the OTP-shaped static
5777    /// child list the supervisor materializes one ComputeUnit per
5778    /// entry from — the Erlang/OTP `supervisor:init/1`'s
5779    /// `{ok, {SupFlags, ChildSpecs}}` `ChildSpecs` list, projected
5780    /// through the tatara-lisp `:children` author surface onto a typed
5781    /// `Vec<ChildSpec>` whose per-element `(nome(),
5782    /// versao_requirement(), restart)` triple the per-child
5783    /// [`SupervisorSpec::validate`] loop already gates through the
5784    /// lifted [`ChildSpec::nome`] (57c61d0) /
5785    /// [`ChildSpec::versao_requirement`] (2c053c8) scalar accessors.
5786    /// Every downstream consumer that fans on the static child list
5787    /// keys off this slice (the [`SupervisorSpec::validate`]
5788    /// `SimpleOneForOne ↔ non-SimpleOneForOne` partition dispatch's
5789    /// `.is_empty()` probe on both arms, the [`SupervisorSpec::validate`]
5790    /// per-child DNS-1123 / semver-requirement / duplicate-detection
5791    /// fan-out loop, every future wasm-operator (M3) per-supervisor
5792    /// hierarchical-reconciliation scheduler's per-child ComputeUnit
5793    /// materialization loop, the future M4
5794    /// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's per-child
5795    /// admission-webhook fan-out, the future `feira app graph`
5796    /// per-supervisor tree-print traversal).
5797    ///
5798    /// Prior to this lift the `.children` `Vec<ChildSpec>` was accessed
5799    /// inline at three production sites in `caixa-core/src/supervisor.rs`
5800    /// — the [`SupervisorSpec::validate`] `SimpleOneForOne`-arm
5801    /// `!self.children.is_empty()` cross-slot refusal probe, the peer
5802    /// non-`SimpleOneForOne`-arm `self.children.is_empty()`
5803    /// [`SupervisorError::NoChildren`] refusal probe, and the per-child
5804    /// validate loop's `for child in &self.children` traversal head —
5805    /// three open-coded field-accesses that expressed no compile-time
5806    /// link back to the typed slot. A future extension of the
5807    /// `:supervisor :children` axis to a richer author surface (a
5808    /// per-cluster child-set overlay the operator pins through a future
5809    /// `:supervisor :children-overrides` slot the MESH-COMPOSITION §III.2
5810    /// supervision-canary roadmap acknowledges, a per-tenant
5811    /// child-set-alias table the M4 CR materializer resolves per-CR,
5812    /// a per-supervisor dynamic-child derivation the future adaptive-
5813    /// supervision engine computes from child-failure-history topology,
5814    /// a promotion of the plain `Vec<ChildSpec>` to a richer
5815    /// `{static, dynamic}` partition once Erlang/OTP's
5816    /// `simple_one_for_one` dynamic-child slot comes into typed scope)
5817    /// would have had to be threaded through all three open-coded copies
5818    /// in lockstep or one consumer would silently disagree with the
5819    /// peers on which child-set a given supervisor resolves to — the
5820    /// `SimpleOneForOne`-arm probe reading the raw slot while the peer
5821    /// non-`SimpleOneForOne`-arm probe read an operator-resolved slot
5822    /// would silently split the partition-dispatch's two-arm coherence
5823    /// (a supervisor that satisfies neither arm's precondition, or that
5824    /// satisfies both, at the cost of the paired
5825    /// `SimpleOneForOneWithStaticChildren`/`NoChildren` refusal cascade
5826    /// silently drifting from the per-child validate loop's actual
5827    /// traversal input), a three-consumer split at the validator far
5828    /// from the source `caixa.lisp` with no field naming the
5829    /// child-set-drift root cause. Lifting the resolution rule to a
5830    /// typed method on the substrate primitive means every downstream
5831    /// consumer of the Supervisor's per-`:supervisor` static-child-list
5832    /// surface reaches for exactly one typed dispatch — the resolver's
5833    /// accept-set migrates as a unit on any future axis addition.
5834    ///
5835    /// First slice-return (`&[T]`) accessor on any M2 or M3 typed slot
5836    /// — the seed for the same "one typed dispatch on the substrate
5837    /// primitive, thin projections at each consumer" discipline the
5838    /// closed [`crate::LimitsSpec`] / [`BehaviorSpec`] /
5839    /// [`crate::UpgradeFromEntry`] scalar-accessor families each carry
5840    /// on their `Copy` / `Option<Copy>` / `Option<&str>` axes, extended
5841    /// onto the first `Vec`-carry axis on the substrate. The four peer
5842    /// `Vec`-carry axes still unlifted at the time of this seed —
5843    /// [`crate::Placement::clusters`] (`Vec<String>` per-cluster
5844    /// distribution-target list), [`crate::AplicacaoSpec::membros`]
5845    /// (`Vec<Membro>` per-Aplicacao member list),
5846    /// [`crate::AplicacaoSpec::contratos`] (`Vec<WitContract>`
5847    /// per-Aplicacao WIT-typed edge list),
5848    /// [`crate::UpgradeFromEntry::instructions`]
5849    /// (`Vec<UpgradeInstruction>` per-appup migration-instruction list)
5850    /// — inherit this accessor's discipline as future compounding runs
5851    /// migrate their consumers onto the shared slice-return shape.
5852    /// Fourth (and final) accessor on the M2 supervisor-slot
5853    /// `SupervisorSpec` type, sibling to the three `Copy`-return
5854    /// [`SupervisorSpec::estrategia`] (eafb619) /
5855    /// [`SupervisorSpec::max_restarts`] (7844f4e) /
5856    /// [`SupervisorSpec::restart_window`] (7e7b32f) accessors — closes
5857    /// the last unlifted per-`:supervisor` field axis (the
5858    /// `Vec<ChildSpec>` static-child-list carrier) so every downstream
5859    /// per-`:supervisor` reader now routes through a typed dispatch on
5860    /// the substrate primitive. Named `children()` to match the storage
5861    /// field's name verbatim and the tatara-lisp author-surface term
5862    /// (`:children`) the field's own docstring already carries; the
5863    /// accessor's identity maps onto the canonical OTP-shape
5864    /// supervision vocabulary the [`SupervisorSpec::children`] field's
5865    /// docstring already reaches for ("Static children ..."). Returns
5866    /// `&[ChildSpec]` (not `&Vec<ChildSpec>`) because every downstream
5867    /// consumer of the child list treats it as a read-only sequence —
5868    /// the slice-view is the narrowest borrow that supports every
5869    /// present + roadmapped consumer (`.is_empty()`, `.iter()`,
5870    /// index, `.len()`) without leaking the backing `Vec`'s
5871    /// grow/push/reserve surface that no consumer of the typed view
5872    /// reaches for (the storage-side `Vec` remains reachable through
5873    /// the `pub children` field for the mutation-carrying
5874    /// `Caixa::supervisor_view` fold-in path in
5875    /// `manifest.rs:supervisor_view`).
5876    #[must_use]
5877    pub const fn children(&self) -> &[ChildSpec] {
5878        self.children.as_slice()
5879    }
5880
5881    /// Validate the supervisor's typed shape — strategy ↔ children
5882    /// invariants, max_restarts > 0, restart_window > 0 when set,
5883    /// per-child non-empty + duplicate-free names.
5884    ///
5885    /// Mirrors the value-shape discipline applied to every other
5886    /// typed slot:
5887    ///
5888    ///   - `Some(Duration::ZERO)` on a Duration-bearing axis is the
5889    ///     same "0 means the opposite of what you think" footgun
5890    ///     closed for `:politicas :timeout` (Envoy interprets a zero
5891    ///     timeout as `infinite`), `:politicas :circuit-breaker
5892    ///     :window`, and `:limits :wall-clock`. The
5893    ///     `MaxIntensity / Period` ratio in Erlang/OTP's
5894    ///     `supervisor` requires `Period > 0`; a zero period either
5895    ///     trips on the first failure or never trips depending on
5896    ///     operator interpretation, neither of which is the
5897    ///     author's intent. Omit `:restart-window` to express "no
5898    ///     reset"; carry a positive duration to express the window.
5899    ///   - duplicate `:children` `:caixa` names are the same
5900    ///     graph-node-set / multiset distinction closed for
5901    ///     `:membros` (4bb3f3d), `:placement :clusters` (c7c7799),
5902    ///     and `:entrada :paths` (eb3456d). Two children with the
5903    ///     same `:caixa` materialize as two ComputeUnits with the
5904    ///     same name in the cluster's HelmRelease values, one
5905    ///     silently overwriting the other. Erlang/OTP's
5906    ///     `child_spec.id` is required-unique per supervisor;
5907    ///     pleme-io enforces the same set-not-multiset shape on
5908    ///     `:caixa` (the load-bearing identity in our renderer).
5909    pub fn validate(&self) -> Result<(), SupervisorError> {
5910        // Route the `SimpleOneForOne ↔ non-SimpleOneForOne` partition
5911        // dispatch and the non-`SimpleOneForOne`-arm [`SupervisorError::NoChildren`]
5912        // error carrier's `estrategia:` field through the lifted
5913        // [`SupervisorSpec::estrategia`] accessor rather than the raw
5914        // `self.estrategia` field access — the two production consumers
5915        // of the per-`:supervisor` sibling-restart-strategy scalar now
5916        // key off exactly one typed dispatch on the substrate primitive,
5917        // so any future rebrand on the axis (a per-cluster strategy
5918        // override the operator pins through a future `:supervisor
5919        // :estrategia-overrides` slot, a per-tenant strategy-alias table
5920        // the M4 CR materializer resolves per-CR) migrates as a single
5921        // caixa-core edit rather than a coordinated rewrite of the two
5922        // call sites — sibling of the peer M3 [`crate::Placement::estrategia`]
5923        // (921fe1b) four-consumer migration on the per-`:placement`
5924        // distribution-strategy axis.
5925        // Route the `SimpleOneForOne ↔ non-SimpleOneForOne` partition-
5926        // dispatch's paired `.is_empty()` cross-slot refusal probes
5927        // (the `SimpleOneForOne`-arm
5928        // [`SupervisorError::SimpleOneForOneWithStaticChildren`] refusal
5929        // and the non-`SimpleOneForOne`-arm [`SupervisorError::NoChildren`]
5930        // refusal) through the lifted [`SupervisorSpec::children`]
5931        // slice-return accessor rather than the raw `self.children`
5932        // field access — the two paired production consumers of the
5933        // per-`:supervisor` static-child-list scalar-shape now key off
5934        // exactly one typed dispatch on the substrate primitive, so any
5935        // future rebrand on the axis (a per-cluster child-set overlay
5936        // the operator pins through a future `:supervisor
5937        // :children-overrides` slot, a per-tenant child-set-alias table
5938        // the M4 CR materializer resolves per-CR) migrates as a single
5939        // caixa-core edit rather than a coordinated rewrite of the
5940        // paired arms — first slice-return migration on any typed slot,
5941        // seed for the peer per-`:placement :clusters`,
5942        // per-`:membros`, per-`:contratos`, and per-`:upgrade-from
5943        // :instructions` `Vec`-carry axes.
5944        match self.estrategia() {
5945            RestartStrategy::SimpleOneForOne => {
5946                // SimpleOneForOne: children added at runtime. Static
5947                // list must be empty (one shape declared elsewhere).
5948                if !self.children().is_empty() {
5949                    return Err(SupervisorError::SimpleOneForOneWithStaticChildren);
5950                }
5951            }
5952            _ => {
5953                if self.children().is_empty() {
5954                    return Err(SupervisorError::no_children(self.estrategia()));
5955                }
5956            }
5957        }
5958        // Zero-floor + upper-cap bracket on the typed `:max-restarts`
5959        // axis. See [`crate::render::require_positive_bounded_u32`] for
5960        // the ordering discipline (zero-floor arm strictly precedes cap
5961        // arm so `0` surfaces the self-locating `ZeroMaxRestarts`
5962        // diagnostic with its counter-axis remediation directly named,
5963        // not the misleading `0 > SUPERVISOR_MAX_RESTARTS_MAX == false`
5964        // cap-arm miss). Until this bracket landed the top edge ran all
5965        // the way to `u32::MAX` and a struct-literal
5966        // `SupervisorSpec { max_restarts: 100_000, .. }` (or the
5967        // equivalent author-surface `:max-restarts 100000` /
5968        // `:max-restarts 4294967295` typo landing in the slot) silently
5969        // passed validate. The runtime substrate consuming the value
5970        // (Erlang/OTP's `MaxIntensity / Period` ratio, the future
5971        // wasm-operator's per-supervisor restart-intensity counter, the
5972        // M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
5973        // admission webhook) then turned a typed `:max-restarts`
5974        // policy into a no-op supervisor: the escalation threshold is
5975        // structurally so high that no realistic
5976        // restarts-per-`:restart-window` traffic shape can reach it,
5977        // the supervisor never escalates to its parent, and a bad
5978        // child can loop inside the window indefinitely with the
5979        // parent supervisor structurally never receiving the "this
5980        // subtree has exceeded its restart budget" signal the typed
5981        // slot is meant to express. The bracket set is
5982        // `1..=SUPERVISOR_MAX_RESTARTS_MAX`, peer with the
5983        // [`crate::aplicacao::POLICY_BREAKER_MAX_FAILURES_MAX`] cap on
5984        // the sibling `:politicas :circuit-breaker :max-failures` axis:
5985        // both are "trip the next-higher protection layer after N
5986        // events in a rolling window" counters with identical
5987        // degenerate-at-the-high-end shape and now share one canonical
5988        // bracket helper. The bracket precedes the sibling
5989        // `:restart-window` zero-floor / canonical-millisecond arms so
5990        // an over-cap `max_restarts` paired with a structurally invalid
5991        // window surfaces the bracket diagnostic first, mirroring the
5992        // `PolicyBreakerMaxFailuresExceedsCap` / window-axis cross-arm
5993        // ordering on the peer `:politicas :circuit-breaker` slot.
5994        // Route the [`SupervisorSpec::validate`] `:max-restarts` zero-floor +
5995        // upper-cap bracket-gate through the lifted [`SupervisorSpec::max_restarts`]
5996        // accessor rather than the raw `self.max_restarts` field access —
5997        // the one production consumer of the per-`:supervisor`
5998        // restart-budget-count scalar now keys off exactly one typed
5999        // dispatch on the substrate primitive, so any future rebrand on
6000        // the axis (a per-cluster restart-budget override the operator
6001        // pins through a future `:supervisor :max-restarts-overrides`
6002        // slot, a per-tenant restart-budget-alias table the M4 CR
6003        // materializer resolves per-CR) migrates as a single caixa-core
6004        // edit rather than a coordinated rewrite — sibling of the peer M3
6005        // [`crate::CircuitBreaker::max_failures`] (3a74062) migration on
6006        // the per-`:politicas :circuit-breaker :max-failures` axis.
6007        crate::render::require_positive_bounded_u32(
6008            self.max_restarts(),
6009            SUPERVISOR_MAX_RESTARTS_MAX,
6010            || SupervisorError::ZeroMaxRestarts,
6011            SupervisorError::max_restarts_exceeds_cap,
6012        )?;
6013        // Route the [`SupervisorSpec::validate`] `:restart-window`
6014        // zero-floor + integer-millisecond canonical-form + upper-cap
6015        // bracket-gate through the lifted [`SupervisorSpec::restart_window`]
6016        // accessor rather than the raw `self.restart_window` field access —
6017        // the one production consumer of the per-`:supervisor`
6018        // restart-intensity-denominator scalar now keys off exactly one
6019        // typed dispatch on the substrate primitive, so any future rebrand
6020        // on the axis (a per-cluster restart-window override the operator
6021        // pins through a future `:supervisor :restart-window-overrides`
6022        // slot, a per-tenant restart-window-alias table the M4 CR
6023        // materializer resolves per-CR) migrates as a single caixa-core
6024        // edit rather than a coordinated rewrite — sibling of the peer M2
6025        // [`crate::LimitsSpec::wall_clock`] (8cb717b) validate-arm-route
6026        // on the per-`:limits :wall-clock` axis and the peer M3
6027        // [`crate::MeshPolicy::timeout`] (7073d0f) accessor-route on the
6028        // per-`:politicas :timeout` axis.
6029        if let Some(w) = self.restart_window() {
6030            // Zero-floor + integer-millisecond canonical-form +
6031            // upper-cap bracket on the typed `:restart-window` axis.
6032            // See
6033            // [`crate::render::require_positive_canonical_bounded_duration`]
6034            // for the full three-arm ordering discipline (zero-floor
6035            // strictly precedes canonical-form so `Duration::ZERO`
6036            // surfaces the self-locating `RestartWindowZero`
6037            // diagnostic; canonical-form strictly precedes the cap arm
6038            // so a sub-millisecond above-cap value surfaces the more
6039            // fundamental round-trip-shape diagnostic first) and the
6040            // three peer typed-`Duration` sites that share this
6041            // canonical bracket ([`crate::MeshPolicy::timeout`],
6042            // [`crate::CircuitBreaker::window`],
6043            // [`crate::LimitsSpec::wall_clock`]). Every validated
6044            // value lies in `1ms..=SUPERVISOR_RESTART_WINDOW_MAX`
6045            // (1ms..=1h), integer-millisecond granularity.
6046            crate::render::require_positive_canonical_bounded_duration(
6047                w,
6048                SUPERVISOR_RESTART_WINDOW_MAX,
6049                || SupervisorError::RestartWindowZero,
6050                SupervisorError::restart_window_not_canonical,
6051                SupervisorError::restart_window_exceeds_cap,
6052            )?;
6053        }
6054        // Route the per-child DNS-1123 / semver-requirement / duplicate-
6055        // detection fan-out loop through the lifted named per-slot gate
6056        // [`SupervisorSpec::validate_children`] rather than an inline
6057        // three-per-child cascade — every future consumer that wants to
6058        // re-check only the `:children` slot's per-entry axes (the M4
6059        // `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
6060        // admission webhook re-validating one added/renamed child, the
6061        // future wasm-operator's per-child dynamic-add re-validator on
6062        // the `SimpleOneForOne` runtime-add path once dynamic-children
6063        // graduate to a typed slot, a future partial re-validator on a
6064        // per-`:children`-entry patch) reaches every per-entry axis
6065        // through one dispatch rather than re-inlining the three-arm
6066        // cascade in lockstep with `validate` or paying the peer
6067        // `:estrategia`/`:max-restarts`/`:restart-window` gates to
6068        // reach one entry check. Sibling of the peer M3 mesh-slot
6069        // per-slot gate family (`validate_membros` — the exact peer on
6070        // the M3 side, [`crate::AplicacaoSpec::validate_membros`];
6071        // `validate_contratos` — 906a5c6; `validate_entrada` — 20cd523;
6072        // `validate_placement`; `validate_politicas` routing through
6073        // `MeshPolicy::validate` — f03a154) — the M2 supervisor-slot
6074        // per-slot gate discipline now spans both the M3 mesh-slot
6075        // family and the M2 `:children` per-child-cascade axis on one
6076        // shape: one named per-slot gate per typed per-entry loop.
6077        self.validate_children()?;
6078        Ok(())
6079    }
6080
6081    /// Named per-slot gate on the M2 `:supervisor :children` per-entry
6082    /// axis — folds the per-child DNS-1123 name gate, semver-requirement
6083    /// gate, and duplicate-`:caixa` dedup arm into one call every
6084    /// consumer that wants to re-validate one `:children` entry (or the
6085    /// whole list) against the same accept-set [`SupervisorSpec::validate`]
6086    /// admits reaches through.
6087    ///
6088    /// Peer of the M3 mesh-slot [`crate::AplicacaoSpec::validate_membros`]
6089    /// per-slot gate on the analogous per-entry axis (`:membros`) — same
6090    /// three-per-entry shape (DNS-1123 name + semver-requirement +
6091    /// duplicate-`:caixa` dedup), lifted to one named substrate
6092    /// primitive per slot. The M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
6093    /// materializer's admission webhook re-checking one added or renamed
6094    /// child, the future wasm-operator's per-child dynamic-add
6095    /// re-validator on the `SimpleOneForOne` runtime-add path once
6096    /// dynamic-children graduate to a typed slot, a future partial
6097    /// re-validator on a per-`:children`-entry patch — each reaches the
6098    /// three per-entry axes through this one dispatch rather than
6099    /// re-inlining the three-arm cascade in lockstep with `validate`
6100    /// (the duplication the PRIME DIRECTIVE names as a bug) or paying
6101    /// the peer `:estrategia`/`:max-restarts`/`:restart-window` gates to
6102    /// reach one entry check.
6103    ///
6104    /// Self-contained on `&self` — resolves its own dedup `HashSet`
6105    /// through [`SupervisorSpec::children`] rather than borrowing one
6106    /// threaded down from `validate`, the same posture the peer M3
6107    /// mesh-slot per-slot gates ([`crate::AplicacaoSpec::validate_membros`],
6108    /// [`crate::AplicacaoSpec::validate_contratos`],
6109    /// [`crate::AplicacaoSpec::validate_entrada`],
6110    /// [`crate::AplicacaoSpec::validate_placement`]) each carry, so a
6111    /// consumer that reaches this gate directly (without first calling
6112    /// `validate`) still runs the full per-child cascade — pinned by
6113    /// `validate_children_matches_gate_on_per_axis_refusal_shapes` +
6114    /// `validate_children_matches_gate_on_versao_invalid_and_clean_pass`
6115    /// + `validate_children_is_self_contained_on_children_slot`.
6116    ///
6117    /// The three per-entry arms run in the same canonical order the
6118    /// pre-lift inline cascade encoded (DNS-1123 → semver → dedup), so
6119    /// the diagnostic every author-declared per-`:children` entry surfaces
6120    /// through `validate` is byte-equal to the diagnostic this gate
6121    /// surfaces when called directly — the equivalence-pin pair
6122    /// `validate_children_matches_gate_on_per_axis_refusal_shapes` +
6123    /// `validate_children_matches_gate_on_versao_invalid_and_clean_pass`
6124    /// asserts the two altitudes discriminate the same set on every
6125    /// per-entry-covered input.
6126    pub fn validate_children(&self) -> Result<(), SupervisorError> {
6127        let mut seen = std::collections::HashSet::new();
6128        for child in self.children() {
6129            // Every emitted cluster artifact's `metadata.name` for a
6130            // supervised child derives from this `:children :caixa` value
6131            // verbatim — the rendered `wasm.pleme.io/v1alpha1/ComputeUnit
6132            // .metadata.name` per child, the [`crate::LABEL_PROGRAM`]
6133            // label value on every child's pod identity, and the per-
6134            // child K8s [`Service`][svc] `metadata.name` the future
6135            // wasm-operator (M3) provisions for inter-child supervision
6136            // tree wiring. Each apiserver-side schema on each landing
6137            // site enforces the DNS-1123 label rule on admission; a
6138            // structurally invalid child name (`"Worker"`, `"my_worker"`,
6139            // `"team.worker"`, `"-worker"`, `"worker-"`, the >63-byte
6140            // UUID-shaped mistaken-identity slug) silently passes the
6141            // prior empty-/duplicate-only gate and the failure surfaces
6142            // at `kubectl apply` time as a `metadata.name: Invalid value`
6143            // rejection, far from the source caixa.lisp, with no field
6144            // naming the offending `:children` entry. Lifting the gate
6145            // to caixa-build time mirrors the `:membros :caixa` value-
6146            // shape trajectory (3f9d7a0) and the `:placement :clusters`
6147            // trajectory (6cbb900) onto the third DNS-1123-label-shaped
6148            // identifier axis — the supervisor tree's child names —
6149            // through the lifted
6150            // [`crate::render::require_valid_dns_1123_label`] gate the
6151            // seven peer name axes (`:membros :caixa`, `:placement
6152            // :clusters`, `:placement :affinity`, `:contratos :de`/`:para`,
6153            // `:entrada :para`, `:nome`, `:upgrade-from :module`) each
6154            // route through, so drift between the eight axes' accepted
6155            // DNS-1123-label sets is structurally impossible.
6156            //
6157            // [svc]: https://kubernetes.io/docs/concepts/services-networking/service/
6158            crate::render::require_valid_dns_1123_label(
6159                child.nome(),
6160                || SupervisorError::EmptyChildName,
6161                |reason| SupervisorError::child_caixa_invalid(child.nome(), reason),
6162            )?;
6163            // The author surface for `:children :versao` is the same
6164            // Cargo-shaped semver requirement string `:deps :versao` and
6165            // `:membros :versao` carry — and the lacre pipeline resolves
6166            // all three axes through the same
6167            // [`crate::version::parse_requirement`] entry-point. The
6168            // shared [`crate::render::require_valid_versao_requirement`]
6169            // helper brackets the empty-first + parse cascade both peer
6170            // axes ([`crate::dep::Dep::validate`] on `:deps :versao`,
6171            // [`crate::AplicacaoSpec::validate_membros`] on `:membros
6172            // :versao`) route through, so drift between the three axes'
6173            // accepted requirement sets is structurally impossible and
6174            // the parse-side no-op the empty-first arm closes (semver's
6175            // empty parse yields an implicit `*`) lives in exactly one
6176            // predicate. Every `ChildSpec::versao` past validate is
6177            // round-trippable through [`crate::parse_requirement`]
6178            // without re-checking at the resolver layer, and the three
6179            // `:versao` typed surfaces (`:deps`, `:membros`, `:children`)
6180            // are now structurally equivalent by construction.
6181            crate::render::require_valid_versao_requirement(
6182                child.versao_requirement(),
6183                || SupervisorError::empty_child_version(child.nome()),
6184                |reason| {
6185                    SupervisorError::child_versao_invalid(
6186                        child.nome(),
6187                        child.versao_requirement(),
6188                        reason,
6189                    )
6190                },
6191            )?;
6192            crate::render::insert_first_seen(&mut seen, child.nome(), || {
6193                SupervisorError::duplicate_child_caixa(child.nome())
6194            })?;
6195        }
6196        Ok(())
6197    }
6198}
6199
6200/// Cross-slot coherence gate on the supervision tree: no
6201/// `:children :caixa` entry may name the supervisor's own `:nome`.
6202///
6203/// A supervisor that lists itself as a child is a degenerate self-parent
6204/// — the supervision tree is a DAG rooted at the supervisor (OTP child
6205/// specs reference *distinct* child processes; a supervisor is never its
6206/// own child), and the wasm-operator's hierarchical reconciliation would
6207/// otherwise be handed a node that is its own parent: a one-node cycle it
6208/// either rejects far from the source `caixa.lisp` or recurses on. Because
6209/// every `:nome` is a globally-unique substrate identity (DNS-1123 label +
6210/// lacre closure root), a child whose `:caixa` equals the supervisor's
6211/// `:nome` *is* the supervisor itself, not a coincidentally-named peer.
6212///
6213/// Lives outside [`SupervisorSpec::validate`] because the typed view
6214/// carries the children but not the parent `:nome`; mirrors the
6215/// cross-slot precedence gate `validate_upgrade_from_against_versao`
6216/// (which likewise reads one slot against another at the
6217/// [`crate::layout`] wire-up site) and the mesh self-edge gate
6218/// `AplicacaoSpec`'s `ContratoSelfLoop` — the same "an edge from a graph
6219/// node to itself is structurally not a tree/mesh edge" discipline, here
6220/// on the supervision-tree axis.
6221pub fn validate_no_self_supervision(
6222    children: &[ChildSpec],
6223    parent_nome: &str,
6224) -> Result<(), SupervisorError> {
6225    for child in children {
6226        if child.nome() == parent_nome {
6227            return Err(SupervisorError::child_supervises_self(parent_nome));
6228        }
6229    }
6230    Ok(())
6231}
6232
6233#[derive(Debug, Error, PartialEq, Eq)]
6234pub enum SupervisorError {
6235    #[error("supervisor :estrategia {estrategia:?} requires at least one :children entry")]
6236    NoChildren { estrategia: RestartStrategy },
6237    #[error(
6238        "SimpleOneForOne supervisors must declare zero static children (children spawn dynamically)"
6239    )]
6240    SimpleOneForOneWithStaticChildren,
6241    #[error(":max-restarts must be > 0")]
6242    ZeroMaxRestarts,
6243    #[error(
6244        ":supervisor :max-restarts ({max_restarts}) exceeds the supervisor-policy ceiling \
6245         (SUPERVISOR_MAX_RESTARTS_MAX = 1000) — a value above this cap turns the typed \
6246         restart-intensity policy into a no-op supervisor: the escalation threshold is \
6247         structurally so high that no realistic restarts-per-:restart-window traffic shape \
6248         can reach it, so the supervisor never escalates to its parent and a bad child can \
6249         loop inside the window indefinitely. Every typed-slot consumer (Erlang/OTP's \
6250         MaxIntensity/Period ratio, the future wasm-operator's per-supervisor \
6251         restart-intensity counter, the M4 mesh.pleme.io/v1alpha1/Supervisor CR \
6252         materializer's admission webhook) emits a `:max-restarts` declaration that is \
6253         structurally never reached. Pin a value in 1..=1000 (Erlang/OTP / Elixir / Riak \
6254         Core / RabbitMQ production playbooks recommend 3..=100; the OTP `supervisor` \
6255         callback module's `MaxR = 1` minimal-restart default sits at the bottom of the \
6256         band) or restructure the supervision tree (split the flaky child into its own \
6257         sub-supervisor with a tighter budget) if you need a higher restart tolerance."
6258    )]
6259    MaxRestartsExceedsCap { max_restarts: u32 },
6260    #[error(
6261        ":restart-window must be > 0 when set — Erlang/OTP's MaxIntensity/Period \
6262         requires Period > 0; a zero window either trips on the first failure or \
6263         never trips depending on operator interpretation. Omit :restart-window to \
6264         express `never reset`; carry a positive duration to express the window."
6265    )]
6266    RestartWindowZero,
6267    #[error(
6268        ":supervisor :restart-window ({window:?}) carries a sub-millisecond residue the shared `duration_codec` cannot round-trip — \
6269         the codec truncates to `as_millis()` before picking the canonical unit, so a value with `subsec_nanos() % 1_000_000 != 0` either \
6270         truncates on first serialize (e.g. `Duration::from_micros(1500)` → \"1ms\" → `Duration::from_millis(1)` ≠ original) or renders \
6271         as \"0s\" the `RestartWindowZero` arm then rejects on re-validate. Pin an integer-millisecond magnitude in the canonical authoring form \
6272         (`<integer><unit>` for unit ∈ {{ms, s, m, h}}, e.g. `\"500ms\"`, `\"30s\"`, `\"2m\"`, `\"1h\"`) or omit the field for `never reset`"
6273    )]
6274    RestartWindowNotCanonical { window: Duration },
6275    #[error(
6276        ":supervisor :restart-window ({window:?}) exceeds the supervisor-policy ceiling \
6277         (SUPERVISOR_RESTART_WINDOW_MAX = 1h = 3600s) — a value above this cap turns the typed \
6278         per-supervisor rolling-window restart-intensity counter into a lifetime counter: the \
6279         failure-counting window is structurally so long that transient restarts are never \
6280         forgotten, the MaxIntensity/Period ratio degenerates from `trip the parent supervisor \
6281         when the child has exceeded its restart budget within the recent window` to `trip the \
6282         parent when the child has exceeded its restart budget over its lifetime`, and the \
6283         supervisor's reset semantic never reaches the child — every typed-slot consumer \
6284         (Erlang/OTP's MaxIntensity/Period reconciler, the future wasm-operator's \
6285         per-supervisor restart-intensity counter, the M4 mesh.pleme.io/v1alpha1/Supervisor CR \
6286         materializer's admission webhook, the caixa-operator's hierarchical reconciliation \
6287         scheduler) emits a `:restart-window` declaration that is structurally a no-op rolling \
6288         window. Pin a value in 1ms..=1h (Learn You Some Erlang's `{{intensity, 5, 60}}` \
6289         worker-supervisor `Period = 60s` default, Elixir's `Supervisor` `max_seconds: 5` \
6290         default, OTP's `supervisor` callback module `MaxT = 5..=60` typical, Riak Core's \
6291         `MaxT ∈ 10s..=300s`, RabbitMQ broker-supervisor `MaxT = 5s` default — every Erlang/OTP \
6292         / Elixir production playbook sits in the 5s..=300s band; the longest documented \
6293         per-supervisor restart-window any pleme-io substrate playbook recommends maxes at \
6294         ~30m) or omit :restart-window to express `never reset` (the supervisor's restart \
6295         budget then becomes a strict lifetime counter by design, not a degenerate one — the \
6296         author surfaces the lifetime-counter semantic explicitly at the slot, rather than \
6297         hiding it behind a rolling-window declaration the cap arm rejects)"
6298    )]
6299    RestartWindowExceedsCap { window: Duration },
6300    #[error("child entry has empty :caixa name")]
6301    EmptyChildName,
6302    #[error(
6303        "child :caixa {caixa:?} is not a valid DNS-1123 label: {reason} \
6304         (the K8s apiserver enforces this rule on every `metadata.name` / Service \
6305         name / label value the child name lands in — the per-child \
6306         `wasm.pleme.io/v1alpha1/ComputeUnit.metadata.name`, the `LABEL_PROGRAM` \
6307         label value, and the future wasm-operator per-child Service `metadata.name` \
6308         — each apiserver-side schema rejects names that don't match; use a \
6309         lowercase alphanumeric + hyphen identifier like `\"worker\"` or `\"cache-v2\"`)"
6310    )]
6311    ChildCaixaInvalid { caixa: String, reason: String },
6312    #[error("child {caixa:?} has empty :versao constraint")]
6313    EmptyChildVersion { caixa: String },
6314    #[error(
6315        "child {caixa:?} :versao {versao:?} is not a valid semver requirement: \
6316         {reason} (use Cargo-shaped forms like `\"^0.1\"`, `\"~0.1.2\"`, \
6317         `\"0.1.0\"`, or `\"*\"` — the same shape `:deps :versao` and \
6318         `:membros :versao` carry; the lacre pipeline resolves all three \
6319         through the same parser)"
6320    )]
6321    ChildVersaoInvalid {
6322        caixa: String,
6323        versao: String,
6324        reason: String,
6325    },
6326    #[error(
6327        "child {caixa:?} appears more than once (Erlang/OTP requires unique \
6328         child_spec.id per supervisor; duplicate children materialize as duplicate \
6329         ComputeUnits in the rendered chart, one silently overwriting the other)"
6330    )]
6331    DuplicateChildCaixa { caixa: String },
6332    #[error(
6333        "supervisor {caixa:?} lists itself as a :children entry — a supervisor is \
6334         never its own child (the supervision tree is a DAG rooted at the supervisor; \
6335         OTP child specs reference distinct child processes). Since every :nome is a \
6336         globally-unique substrate identity, a child naming the supervisor's own :nome \
6337         is a one-node reconciliation cycle, not a coincidentally-named peer; drop the \
6338         self-referential :children entry or rename it to the actual child caixa."
6339    )]
6340    ChildSupervisesSelf { caixa: String },
6341}
6342
6343// Fold the three `SupervisorError::<Variant> { caixa: <&str>.to_string() }`
6344// caixa-only struct-variant wire-up sites at [`SupervisorSpec::validate_children`]
6345// and [`validate_no_self_supervision`] onto one substrate primitive per
6346// typed variant — the sibling on `SupervisorError` of the four uniform-shape
6347// `LayoutError`-envelope constructor families the peer
6348// [`crate::layout::layout_violation_ctors!`] macro closed (131ca0d, 16
6349// variants on `{ caixa, issue }`), the [`crate::layout::layout_slot_kind_ctors!`]
6350// macro closed (0419438, 4 variants on `{ caixa, kind, slots }`), the
6351// [`crate::LayoutError::missing_entry`] one-variant ctor closed (1b09f9d,
6352// on `{ kind, path }`), and the [`crate::layout::layout_nome_only_ctors!`]
6353// macro closed (3fe3dd7, 6 variants on `<Variant>(String)`), plus the
6354// [`crate::AplicacaoError::entrada_host_invalid`] one-variant ctor
6355// (17dd504, `{ host, reason }`), the [`crate::aplicacao::contrato_target_ctors!`]
6356// macro (14b81d5, 2 variants on `{ de, para, wit, expected }`), and the
6357// [`crate::aplicacao::contrato_empty_pair_ctors!`] macro (8580068, 4
6358// variants on `{ de, para }`) already at that discipline on the peer
6359// `AplicacaoError` envelopes.
6360//
6361// Each of the three wire-up sites on this shape (`EmptyChildVersion` at
6362// the per-`:children` semver-requirement empty-first arm, `DuplicateChildCaixa`
6363// at the per-`:children` dedup arm, `ChildSupervisesSelf` at the cross-slot
6364// self-supervision arm) opened the identical
6365// `SupervisorError::<Variant> { caixa: <&str>.to_string() }` struct-literal —
6366// the exact "same block re-inlined at every consumer" shape the PRIME
6367// DIRECTIVE names as a bug, on the same altitude the peer `LayoutError` /
6368// `AplicacaoError` families each closed on their sibling envelopes. The
6369// three variants share one `{ caixa: String }` shape, so the fold routes
6370// each wire-up site through one dispatch per typed variant.
6371//
6372// The macro below generates one static constructor per variant of shape
6373// `fn <slot>(caixa: &str) -> SupervisorError`, so every wire-up site
6374// collapses onto one dispatch:
6375// `SupervisorError::<slot>(<&str>)`, byte-equal to the pre-lift
6376// struct-literal on the same `&str` fixture. The uniform one-field
6377// construction (`caixa: caixa.to_string()`) is spelled once — inside the
6378// macro — rather than at every wire-up site. Every constructor is
6379// `#[must_use]` so a caller who mistakenly discards the constructed error
6380// trips a compile warning at the wire-up site.
6381//
6382// Every future consumer that wants to construct one of these three
6383// variants outside `SupervisorSpec::validate_children` /
6384// `validate_no_self_supervision` — a deferred
6385// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission
6386// webhook re-checking one added/renamed child, a future
6387// `feira validate --supervisor` per-caixa admission verb, a per-child
6388// dynamic-add re-validator on the `SimpleOneForOne` runtime-add path
6389// once dynamic-children graduate to a typed slot, a per-Supervisor
6390// overlay resolver rejecting a duplicate/self-supervising child against
6391// a cluster-local snapshot — now reaches each variant through one call
6392// rather than re-inlining the three-line struct-literal in lockstep
6393// with the three in-crate wire-up sites.
6394macro_rules! supervisor_caixa_only_ctors {
6395    ($($ctor:ident => $variant:ident),* $(,)?) => {
6396        impl SupervisorError {
6397            $(
6398                #[doc = concat!(
6399                    "Construct a [`SupervisorError::",
6400                    stringify!($variant),
6401                    "`] naming the offending `:children :caixa` (or ",
6402                    "supervisor `:nome`, on the self-supervision arm). ",
6403                    "Folds the uniform `Self::",
6404                    stringify!($variant),
6405                    " { caixa: caixa.to_string() }` one-field ",
6406                    "struct-literal onto one substrate primitive so ",
6407                    "every [`SupervisorSpec::validate_children`] / ",
6408                    "[`validate_no_self_supervision`] wire-up on this ",
6409                    "variant reads through one dispatch rather than the ",
6410                    "pre-lift open-coded struct-literal block."
6411                )]
6412                #[must_use]
6413                pub fn $ctor(caixa: &str) -> Self {
6414                    Self::$variant { caixa: caixa.to_string() }
6415                }
6416            )*
6417        }
6418    };
6419}
6420
6421supervisor_caixa_only_ctors! {
6422    empty_child_version => EmptyChildVersion,
6423    duplicate_child_caixa => DuplicateChildCaixa,
6424    child_supervises_self => ChildSupervisesSelf,
6425}
6426
6427// Fold the two `SupervisorError::{ChildCaixaInvalid, ChildVersaoInvalid}`
6428// struct-variant wire-up sites at [`SupervisorSpec::validate_children`] onto
6429// one substrate primitive per typed variant — the M2 supervisor-side siblings
6430// of the peer [`crate::AplicacaoError::membro_caixa_invalid`] two-slot ctor
6431// already lifted through the sibling
6432// [`crate::aplicacao::aplicacao_field_reason_ctors!`] macro (981060b) on the
6433// peer `AplicacaoError { caixa: String, reason: String }` envelope. The
6434// `ChildCaixaInvalid` variant carries the same `{ <name>: String, reason:
6435// String }` two-slot shape the peer seven-variant
6436// [`crate::aplicacao::aplicacao_field_reason_ctors!`] fold closed on the
6437// `AplicacaoError` envelope (`MembroCaixaInvalid`, `EntradaParaInvalid`,
6438// `EntradaHostInvalid`, `EntradaPathInvalid`, `PlacementClusterInvalid`,
6439// `PlacementAffinityInvalid`, `ShardKeyInvalid`); the `ChildVersaoInvalid`
6440// variant carries the `{ caixa: String, versao: String, reason: String }`
6441// three-slot shape the sibling `AplicacaoError::MembroVersaoInvalid` axis
6442// carries on the same `:versao` value-shape.
6443//
6444// Each of the two wire-up sites opened the same closure-shaped
6445// `|reason| SupervisorError::<Variant> { caixa: child.nome().to_string(),
6446// [versao: child.versao_requirement().to_string(),] reason }` block inside
6447// the paired [`crate::render::require_valid_dns_1123_label`] and
6448// [`crate::render::require_valid_versao_requirement`] callbacks — the exact
6449// "same block re-inlined at every consumer" shape the PRIME DIRECTIVE names
6450// as a bug, on the same altitude the peer `AplicacaoError` /
6451// `SupervisorError` / `LayoutError` / `DepError` / `LimitsError` ctor
6452// families already closed on their sibling envelopes.
6453//
6454// The two `#[must_use]` inherent constructors below fold each wire-up onto
6455// one dispatch: `SupervisorError::child_caixa_invalid(<name>, <reason>)`
6456// and `SupervisorError::child_versao_invalid(<name>, <versao>, <reason>)`,
6457// byte-equal to the pre-lift struct-literal on the same scalar fixtures.
6458// The uniform per-field `.to_string()` / `.into()` construction is spelled
6459// once — inside each ctor body — rather than at every wire-up site. The
6460// `reason: impl Into<String>` bound accepts both `&str` literals and
6461// `format!(…)` outputs verbatim so no wire-up site changes its per-arm
6462// diagnostic shape at the lift, matching the peer
6463// [`aplicacao_field_reason_ctors!`] and
6464// [`crate::aplicacao::contrato_pair_value_reason_ctors!`] bounds on the
6465// sibling envelopes.
6466//
6467// Every future consumer that wants to construct one of these two variants
6468// outside `SupervisorSpec::validate_children` — a deferred
6469// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission webhook
6470// re-checking one added/renamed child's `:caixa` or `:versao`, a future
6471// `feira validate --supervisor` per-caixa admission verb, a per-child
6472// dynamic-add re-validator on the `SimpleOneForOne` runtime-add path once
6473// dynamic-children graduate to a typed slot, a per-Supervisor overlay
6474// resolver rejecting a shape-invalid child `:caixa`/`:versao` against a
6475// cluster-local snapshot — now reaches each variant through one call rather
6476// than re-inlining the per-shape struct-literal block in lockstep with the
6477// two in-crate wire-up sites.
6478impl SupervisorError {
6479    /// Construct a [`SupervisorError::ChildCaixaInvalid`] naming the
6480    /// offending `:children :caixa` value under the given `reason`. Folds
6481    /// the uniform `Self::ChildCaixaInvalid { caixa: caixa.to_string(),
6482    /// reason: reason.into() }` two-slot struct-literal onto one substrate
6483    /// primitive so every wire-up on this variant reads through one
6484    /// dispatch, matching the peer
6485    /// [`crate::AplicacaoError::membro_caixa_invalid`] ctor's shape on the
6486    /// sibling `AplicacaoError { caixa: String, reason: String }`
6487    /// envelope. `reason` accepts both `&str` literals and `format!(…)`
6488    /// outputs through the `impl Into<String>` bound.
6489    #[must_use]
6490    pub fn child_caixa_invalid(caixa: &str, reason: impl Into<String>) -> Self {
6491        Self::ChildCaixaInvalid {
6492            caixa: caixa.to_string(),
6493            reason: reason.into(),
6494        }
6495    }
6496
6497    /// Construct a [`SupervisorError::ChildVersaoInvalid`] naming the
6498    /// offending `:children :caixa` and its `:versao` requirement under
6499    /// the given `reason`. Folds the uniform `Self::ChildVersaoInvalid {
6500    /// caixa: caixa.to_string(), versao: versao.to_string(), reason:
6501    /// reason.into() }` three-slot struct-literal onto one substrate
6502    /// primitive so every wire-up on this variant reads through one
6503    /// dispatch, matching the sibling `AplicacaoError::MembroVersaoInvalid
6504    /// { caixa, versao, reason }` three-slot axis on the peer
6505    /// `AplicacaoError` envelope. `reason` accepts both `&str` literals
6506    /// and `format!(…)` outputs through the `impl Into<String>` bound.
6507    #[must_use]
6508    pub fn child_versao_invalid(caixa: &str, versao: &str, reason: impl Into<String>) -> Self {
6509        Self::ChildVersaoInvalid {
6510            caixa: caixa.to_string(),
6511            versao: versao.to_string(),
6512            reason: reason.into(),
6513        }
6514    }
6515}
6516
6517// Fold the four `SupervisorError::<Variant> { <field>: <Copy> }` one-field
6518// Copy-scalar struct-variant wire-up sites at [`SupervisorSpec::validate`]'s
6519// three bracket-arms — one struct-literal at the `:children`-empty
6520// non-`SimpleOneForOne` refusal cascade (`NoChildren { estrategia }`) plus
6521// three `impl FnOnce(<ty>) -> SupervisorError` bracket-closures at the
6522// [`crate::render::require_positive_bounded_u32`] `:max-restarts` cap arm
6523// (`MaxRestartsExceedsCap { max_restarts }`) and the paired
6524// [`crate::render::require_positive_canonical_bounded_duration`]
6525// `:restart-window` canonical-form + cap arms (`RestartWindowNotCanonical
6526// { window }`, `RestartWindowExceedsCap { window }`) — onto one substrate
6527// primitive per typed variant, matching the sibling
6528// [`crate::aplicacao::aplicacao_policy_scalar_ctors!`] macro (7ef425e, 8
6529// variants on the same `{ <field>: Duration | u32 }` shape) at that
6530// discipline on the peer `AplicacaoError` envelope's per-`:politicas`
6531// scalar axis. Every variant is a one-field `Copy`-pass-through struct-
6532// literal — `RestartStrategy | u32 | Duration` — so the fold routes each
6533// wire-up site through one dispatch per typed variant without a runtime-
6534// work delta.
6535//
6536// Each of the four wire-up sites opened the identical
6537// `SupervisorError::<Variant> { <field>: <val> }` struct-literal — the
6538// exact "same block re-inlined at every consumer" shape the PRIME
6539// DIRECTIVE names as a bug, on the same altitude the peer
6540// `aplicacao_policy_scalar_ctors!` fold closed on the sibling
6541// `AplicacaoError` envelope's per-`:politicas` per-axis cap / canonical-
6542// form arms. The four variants share one `{ <field>: <Copy> }` shape, so
6543// the fold routes each wire-up site through one dispatch per typed
6544// variant.
6545//
6546// The macro below generates one static constructor per variant of shape
6547// `const fn <ctor>(<field>: <ty>) -> SupervisorError`, so every wire-up
6548// site collapses onto one dispatch: `SupervisorError::<ctor>(<val>)`,
6549// byte-equal to the pre-lift struct-literal on the same `Copy`-`<ty>`
6550// fixture — as a direct call at the [`SupervisorSpec::validate`]
6551// `:children`-empty refusal, or as a bare function pointer in the
6552// `impl FnOnce(<ty>) -> SupervisorError` bracket-closure slot every
6553// [`crate::render::require_positive_bounded_u32`] /
6554// [`crate::render::require_positive_canonical_bounded_duration`] gate
6555// carries — rather than the pre-lift open-coded one-line closure over
6556// the same one-field struct-literal. `const fn` preserves the `Copy`-
6557// pass-through's zero-runtime-work property verbatim. Every constructor
6558// is `#[must_use]` so a caller who mistakenly discards the constructed
6559// error trips a compile warning at the wire-up site.
6560//
6561// Every future consumer that wants to construct one of these four
6562// variants outside `SupervisorSpec::validate` — a deferred
6563// `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's admission
6564// webhook re-checking one edited `:estrategia` / `:max-restarts` /
6565// `:restart-window` slot against the cap + canonical-form cascade, a
6566// future `feira validate --supervisor` per-caixa admission verb re-
6567// running the shape gates on demand, a per-Supervisor overlay resolver
6568// rejecting an author-supplied slot against a cluster-local snapshot —
6569// now reaches each variant through one call rather than re-inlining the
6570// per-shape struct-literal block in lockstep with the four in-crate
6571// wire-up sites.
6572macro_rules! supervisor_scalar_ctors {
6573    ($($ctor:ident => $variant:ident { $field:ident: $ty:ty }),* $(,)?) => {
6574        impl SupervisorError {
6575            $(
6576                #[doc = concat!(
6577                    "Construct a [`SupervisorError::",
6578                    stringify!($variant),
6579                    "`] naming the offending per-`:supervisor` `",
6580                    stringify!($field),
6581                    "` scalar. Folds the uniform `Self::",
6582                    stringify!($variant),
6583                    " { ",
6584                    stringify!($field),
6585                    " }` one-field `Copy`-pass-through struct-literal onto ",
6586                    "one substrate primitive so every per-axis wire-up on ",
6587                    "this variant reads through one dispatch — as a direct ",
6588                    "call (`SupervisorError::",
6589                    stringify!($ctor),
6590                    "(<val>)`, byte-equal to the pre-lift struct-literal on ",
6591                    "the same `Copy`-`",
6592                    stringify!($ty),
6593                    "` fixture) or as a bare function pointer in the ",
6594                    "`impl FnOnce(",
6595                    stringify!($ty),
6596                    ") -> SupervisorError` bracket-closure slot every ",
6597                    "`crate::render::require_positive_bounded_*` / ",
6598                    "`crate::render::require_positive_canonical_bounded_*` ",
6599                    "gate carries — rather than the pre-lift open-coded ",
6600                    "one-line closure over the same one-field struct-",
6601                    "literal. `const fn` preserves the `Copy`-pass-through's ",
6602                    "zero-runtime-work property verbatim."
6603                )]
6604                #[must_use]
6605                pub const fn $ctor($field: $ty) -> Self {
6606                    Self::$variant { $field }
6607                }
6608            )*
6609        }
6610    };
6611}
6612
6613supervisor_scalar_ctors! {
6614    no_children => NoChildren { estrategia: RestartStrategy },
6615    max_restarts_exceeds_cap => MaxRestartsExceedsCap { max_restarts: u32 },
6616    restart_window_not_canonical => RestartWindowNotCanonical { window: Duration },
6617    restart_window_exceeds_cap => RestartWindowExceedsCap { window: Duration },
6618}
6619
6620/// Shared duration string codec for the typed slots that take a
6621/// duration (`restart_window`, `MeshPolicy::timeout`,
6622/// `CircuitBreaker::window`, …). Public so [`crate::aplicacao`] can
6623/// reuse it without duplicating the parser.
6624pub mod duration_codec {
6625    use super::Duration;
6626    use serde::{Deserializer, Serializer};
6627
6628    pub fn serialize<S: Serializer>(v: &Option<Duration>, s: S) -> Result<S::Ok, S::Error> {
6629        // Route through the canonical [`crate::render::serialize_option_via_str`]
6630        // — the substrate-side single-owner primitive for the forward
6631        // arm of the typed-magnitude codec family. See its docstring
6632        // for the full sibling roster.
6633        crate::render::serialize_option_via_str(v, s, render)
6634    }
6635
6636    pub fn deserialize<'de, D: Deserializer<'de>>(d: D) -> Result<Option<Duration>, D::Error> {
6637        // Route through the canonical [`crate::render::deserialize_option_via_str`]
6638        // — the substrate-side single-owner primitive for the reverse
6639        // arm of the typed-magnitude codec family. See its docstring
6640        // for the full sibling roster.
6641        crate::render::deserialize_option_via_str(d, parse)
6642    }
6643
6644    pub(crate) fn parse(s: &str) -> Result<Duration, String> {
6645        // Paired whitespace-rejection arm — same canonical-form
6646        // render-determinism discipline as the peer
6647        // `limits::parse_byte_size` / `limits::parse_duration` /
6648        // `limits::parse_millicores` /
6649        // `aplicacao::rate_limit_codec::parse` sites: the ASCII
6650        // byte-scan closes the WhatWG-conformant whitespace bytes
6651        // (`0x20`, `0x09`, `0x0A`, `0x0C`, `0x0D`), the non-ASCII
6652        // `char::is_whitespace` scan closes the strictly-complementary
6653        // Unicode `White_Space` class (NBSP `\u{00A0}`, LINE SEPARATOR
6654        // `\u{2028}`, EM-SPACE `\u{2003}`, and the peer typography
6655        // codepoints) that `str::trim` at parse entry silently strips.
6656        // Either drift class would round-trip through `render` to a
6657        // *different* canonical form on next emit — breaking the
6658        // THEORY.md Part V render-determinism contract on three typed-
6659        // duration slots at once (`:supervisor :restart-window`,
6660        // `:politicas :timeout`, `:politicas :circuit-breaker :window`)
6661        // via the shared codec.
6662        //
6663        // Routed through the lifted [`crate::render::reject_whitespace`]
6664        // primitive — the substrate-side single-owner paired-arm gate
6665        // every typed-magnitude codec in caixa-core shares.
6666        crate::render::reject_whitespace::<String, _, _>(
6667            s,
6668            |b| {
6669                format!(
6670                    "duration: value {s:?} contains whitespace byte 0x{b:02x} — the canonical \
6671                 authoring form for the typed duration slots routed through this shared codec \
6672                 (`:supervisor :restart-window`, `:politicas :timeout`, \
6673                 `:politicas :circuit-breaker :window`) is `<integer><unit>` (e.g. \
6674                 `\"30s\"`, `\"500ms\"`, `\"2m\"`, `\"1h\"`) with no whitespace bytes \
6675                 anywhere. A whitespace-carrying shape (`\" 30s\"`, `\"30s \"`, `\"30 s\"`, \
6676                 `\"\\t30s\"`, `\"30s\\n\"`) round-trips through `render` to a *different* \
6677                 canonical form (`\"30s\"`) on first serialize — breaking the THEORY.md \
6678                 Part V render-determinism contract every typed slot carries. Strip every \
6679                 whitespace byte (write `\"30s\"` verbatim)"
6680                )
6681            },
6682            |ch| {
6683                format!(
6684                    "duration: value {s:?} contains non-ASCII Unicode whitespace character \
6685                 {ch:?} (U+{cp:04X}) — the canonical authoring form for the typed \
6686                 duration slots routed through this shared codec (`:supervisor \
6687                 :restart-window`, `:politicas :timeout`, `:politicas :circuit-breaker \
6688                 :window`) is `<integer><unit>` (e.g. `\"30s\"`, `\"500ms\"`, `\"2m\"`, \
6689                 `\"1h\"`) with no whitespace characters anywhere (ASCII or Unicode). A \
6690                 non-ASCII-whitespace-carrying shape (`\"\\u{{00A0}}30s\"`, \
6691                 `\"30s\\u{{2028}}\"`, `\"30\\u{{2003}}s\"`) survives the ASCII byte-scan \
6692                 but `str::trim` (which uses `char::is_whitespace` — the Unicode \
6693                 `White_Space` property, strictly wider than the ASCII byte set) silently \
6694                 strips it at parse entry, and the value round-trips through `render` to \
6695                 a *different* canonical form (`\"30s\"`) on first serialize — breaking \
6696                 the THEORY.md Part V render-determinism contract every typed slot \
6697                 carries. Strip every non-ASCII whitespace character (write `\"30s\"` \
6698                 verbatim with only ASCII bytes)",
6699                    cp = ch as u32
6700                )
6701            },
6702        )?;
6703        let s = s.trim();
6704        // Routed through the lifted
6705        // [`crate::render::split_magnitude_and_alpha_unit`] primitive —
6706        // the single-owner split every ASCII-alphabetic-unit typed-
6707        // magnitude codec in caixa-core (`limits::parse_byte_size` /
6708        // `limits::parse_duration` / this shared duration codec) shares.
6709        // See its docstring for the full sibling roster on the same
6710        // primitive altitude.
6711        let (num_part, unit) = crate::render::split_magnitude_and_alpha_unit(s);
6712        let num_trim = num_part.trim();
6713        // The canonical authoring form for every typed slot routed
6714        // through this shared codec — `:supervisor :restart-window`,
6715        // `:politicas :timeout`, `:politicas :circuit-breaker :window`
6716        // — is `<integer><unit>`. Every magnitude [`render`] emits is a
6717        // non-negative integer with no decimal point and no leading
6718        // sign, so the parser's accepted set must match for
6719        // serialize/deserialize to round-trip without canonical-form
6720        // drift. Until this gate landed the parser accepted any
6721        // `f64`-shaped magnitude (`"1.5s"` → 1500ms, `"1.0s"` → 1s,
6722        // `"0.5m"` → 30s, `"+30s"` → 30s) and serde silently round-
6723        // tripped the value to a *different* canonical string on the
6724        // next emit (`"1.5s"` → 1500ms → `"1500ms"`, `"1.0s"` → 1s →
6725        // `"1s"`, `"0.5m"` → 30s → `"30s"`, `"+30s"` → 30s → `"30s"`)
6726        // — breaking the THEORY.md Part V render-determinism contract
6727        // on three typed slots at once. Same canonical-form discipline
6728        // `crate::limits::parse_duration` (818dd38, the immediate
6729        // predecessor on the peer `:limits :wall-clock` codec) applies;
6730        // this gate lifts the discipline onto the shared codec that
6731        // backs the remaining three typed-duration slots in caixa-core.
6732        //
6733        // Strict canonical form: every byte of the magnitude is an
6734        // ASCII digit (no `.`, no `+`, no `-`). On non-digit-only
6735        // inputs the gate distinguishes "non-canonical-but-numeric"
6736        // (parses as f64 or i64 — surfaced with a self-locating
6737        // diagnostic naming the canonical authoring form, the
6738        // round-trip drift each rejected shape would produce on first
6739        // serialize, and the canonical-form remediation) from
6740        // "garbage" (parses as neither — surfaced with the existing
6741        // narrower "bad duration magnitude" wording so its diagnostic
6742        // shape remains stable for the parser-shape footgun case).
6743        // The pre-existing `num < 0.0` arm is now unreachable — the
6744        // digit-only gate strictly precedes magnitude parsing, and a
6745        // leading `-` is not an ASCII digit, so `"-30s"` lands on the
6746        // non-canonical-but-numeric branch with the `-30` named
6747        // verbatim in the diagnostic rather than the prior
6748        // value-laundered "negative duration in \"-30s\"" wording.
6749        //
6750        // Routed through the lifted
6751        // [`crate::render::is_digit_only_magnitude`] predicate — the
6752        // same source of truth the four peer typed-magnitude codec
6753        // sites share.
6754        let digit_only = crate::render::is_digit_only_magnitude(num_trim);
6755        if !digit_only {
6756            let numeric = num_trim.parse::<f64>().is_ok() || num_trim.parse::<i64>().is_ok();
6757            if numeric {
6758                return Err(format!(
6759                    "duration: magnitude {num_trim:?} is not a non-negative integer — the \
6760                     canonical authoring form for the typed duration slots routed through \
6761                     this shared codec (`:supervisor :restart-window`, `:politicas :timeout`, \
6762                     `:politicas :circuit-breaker :window`) is `<integer><unit>` (e.g. \
6763                     `\"30s\"`, `\"500ms\"`, `\"2m\"`, `\"1h\"`) with no decimal point and \
6764                     no leading `+` / `-` sign. A fractional / decimal-shaped magnitude \
6765                     (`\"1.5s\"`, `\"1.0s\"`, `\"0.5m\"`, `\"+30s\"`, `\"-30s\"`) round-trips \
6766                     through `render` to a *different* canonical form (`\"1500ms\"`, `\"1s\"`, \
6767                     `\"30s\"`, `\"30s\"`, `\"30s\"`) on first serialize — breaking the \
6768                     THEORY.md Part V render-determinism contract every typed slot carries. \
6769                     Pick an integer magnitude in the unit that divides cleanly (write \
6770                     `\"1500ms\"` instead of `\"1.5s\"`; `\"30s\"` instead of `\"0.5m\"`)"
6771                ));
6772            }
6773            return Err(format!("bad duration magnitude in {s:?}"));
6774        }
6775        // Leading-zero arm — peer with the `rate_limit_codec` leading-
6776        // zero arm (4f46830) on the same canonical-form render-
6777        // determinism axis. The digit-only gate accepts `"030s"`,
6778        // `"00s"`, `"01h"`, `"0500ms"` as `u64::from_str` parses them
6779        // losslessly (= 30, 0, 1, 500), but `render` emits the leading-
6780        // zero-stripped form (`"30s"`, `"0s"`, `"1h"`, `"500ms"`) — a
6781        // *different* canonical string on the next emit, breaking the
6782        // THEORY.md Part V render-determinism contract the same way
6783        // `"+30s"` did before the leading-`+` arm landed. The single-
6784        // byte magnitude `"0"` (or `"0s"` / `"0ms"`) round-trips
6785        // losslessly through `render` (`render(Duration::ZERO)` emits
6786        // `"0s"`) — the downstream semantic-zero gates (e.g.
6787        // `SupervisorError::ZeroRestartWindow` on
6788        // `:supervisor :restart-window`,
6789        // `AplicacaoError::PolicyTimeoutZero` /
6790        // `PolicyCircuitBreakerWindowZero` on the typed `:politicas`
6791        // duration slots) refuse zero-magnitude authoring at the typed-
6792        // validate layer above, so the single-byte `"0"` stays in the
6793        // accepted set at this codec layer and the diagnostic
6794        // partitioning between canonical-form drift (this arm) and
6795        // semantic-zero (the downstream gates) remains stable.
6796        // Peer with the future leading-zero arms on the two remaining
6797        // typed-magnitude codecs the trajectory acknowledges:
6798        // `limits::parse_duration` backing `:limits :wall-clock`,
6799        // `limits::parse_byte_size` backing `:limits :memory` — each
6800        // carries the same canonical-form-drift class today; this
6801        // gate lands the discipline on the shared duration codec
6802        // first because the `rate_limit_codec` predecessor on the
6803        // same canonical-form-drift axis is the closest peer on the
6804        // trajectory.
6805        //
6806        // Routed through the lifted
6807        // [`crate::render::is_leading_zero_padded_magnitude`]
6808        // predicate — the same source of truth the four peer
6809        // typed-magnitude codec sites share.
6810        if crate::render::is_leading_zero_padded_magnitude(num_trim) {
6811            return Err(format!(
6812                "duration: magnitude {num_trim:?} has a non-canonical leading zero — the \
6813                 canonical authoring form for the typed duration slots routed through \
6814                 this shared codec (`:supervisor :restart-window`, `:politicas :timeout`, \
6815                 `:politicas :circuit-breaker :window`) is `<integer><unit>` (e.g. \
6816                 `\"30s\"`, `\"500ms\"`, `\"2m\"`, `\"1h\"`) with no leading-zero padding \
6817                 on the magnitude. A leading-zero magnitude (`\"030s\"`, `\"00s\"`, \
6818                 `\"01h\"`, `\"0500ms\"`) round-trips through `render` to a *different* \
6819                 canonical form (`\"30s\"`, `\"0s\"`, `\"1h\"`, `\"500ms\"`) on first \
6820                 serialize — breaking the THEORY.md Part V render-determinism contract \
6821                 every typed slot carries. Strip the leading zeros (write \
6822                 `\"30s\"` instead of `\"030s\"`)"
6823            ));
6824        }
6825        // The digit-only gate guarantees every byte is `[0-9]`, and
6826        // the leading-zero arm above guarantees the magnitude is
6827        // either the single byte `"0"` or starts with `[1-9]`, so
6828        // the only way `u64::from_str` can fail here is overflow (the
6829        // magnitude exceeds `u64::MAX`). Surface that with an
6830        // overflow-shaped wording so the diagnostic names the offending
6831        // magnitude verbatim rather than collapsing onto the
6832        // non-canonical arm. The codec now operates on `u64` end-to-end
6833        // — every accepted magnitude is integer-exact; no f64 mantissa
6834        // drift between author-supplied magnitude and the consumer's
6835        // `Duration` value. Same shape `crate::limits::parse_duration`
6836        // (818dd38) carries on the peer `:limits :wall-clock` axis.
6837        let num: u64 = num_trim.parse::<u64>().map_err(|_| {
6838            format!("bad duration magnitude in {s:?} (digit-only magnitude overflows u64)")
6839        })?;
6840        // Route the `{"ms" | "s" | "" | "m" | "h"} → Duration`
6841        // unit-arm dispatch through the canonical
6842        // [`crate::render::duration_from_integer_magnitude_and_unit`]
6843        // primitive — the substrate-side single-owner unit-dispatch
6844        // table every typed-duration codec in caixa-core routes
6845        // through (peer: `crate::limits::parse_duration` backing
6846        // `:limits :wall-clock`). Every unit conversion is integer-
6847        // exact for an integer magnitude; overflow surfaces via the
6848        // typed `DurationUnitError::Overflow { multiplier }`
6849        // discriminant so this arm reconstructs the pre-lift
6850        // `"duration <num><unit> overflows u64 (magnitude × 60 …)"`
6851        // wording verbatim from `num` / `unit_trim` / the returned
6852        // `multiplier`, and the unknown-unit arm reconstructs the
6853        // pre-lift `"unknown duration unit \"<other>\""` wording from
6854        // the caller-scoped `unit_trim`. Load-bearing pinned by
6855        // `crate::render::tests::duration_from_integer_magnitude_and_unit_matches_pre_lift_unit_dispatch_table`.
6856        let unit_trim = unit.trim();
6857        let dur = crate::render::duration_from_integer_magnitude_and_unit(num, unit_trim).map_err(
6858            |e| match e {
6859                crate::render::DurationUnitError::Overflow { multiplier } => format!(
6860                    "duration {num}{unit_trim} overflows u64 (magnitude × {multiplier} > 2^64-1)"
6861                ),
6862                crate::render::DurationUnitError::UnknownUnit => {
6863                    format!("unknown duration unit {unit_trim:?}")
6864                }
6865            },
6866        )?;
6867        Ok(dur)
6868    }
6869
6870    /// Render a [`Duration`] in the canonical pleme-io duration string
6871    /// form (`"30s"`, `"1m"`, `"1h"`, `"500ms"`). The same form every
6872    /// caixa typed-duration slot serializes to and the same form K8s
6873    /// Gateway API HTTPRoute `timeouts` / `backendRequest` and Cilium
6874    /// EnvoyConfig per-route timeouts both expect (an integer
6875    /// followed by `s`/`m`/`h`/`ms`, no fractional values, no leading
6876    /// `+`). Lifted to `pub` so caixa-side renderers
6877    /// (`caixa-mesh::gateway_routes`'s :politicas :timeout overlay,
6878    /// the future per-:politicas `CiliumClusterwideEnvoyConfig`
6879    /// emitter, the future caixa-otel collector pipeline emitter) can
6880    /// consume the same canonical formatter without re-inlining the
6881    /// magnitude/unit decision tree (and inheriting the same drift
6882    /// footguns: a subtly different `300ms` vs `0.3s` rendering breaks
6883    /// downstream apply-time parsing in non-obvious ways).
6884    pub fn render(d: Duration) -> String {
6885        let total_ms = d.as_millis();
6886        if total_ms == 0 {
6887            return "0s".into();
6888        }
6889        if total_ms.is_multiple_of(3600 * 1000) {
6890            return format!("{}h", total_ms / (3600 * 1000));
6891        }
6892        if total_ms.is_multiple_of(60 * 1000) {
6893            return format!("{}m", total_ms / (60 * 1000));
6894        }
6895        if total_ms.is_multiple_of(1000) {
6896            return format!("{}s", total_ms / 1000);
6897        }
6898        format!("{total_ms}ms")
6899    }
6900
6901    /// True iff `d` round-trips losslessly through [`render`] + [`parse`].
6902    ///
6903    /// [`render`] truncates a `Duration` to `as_millis()` before picking the
6904    /// largest divisor unit, so any sub-millisecond residue
6905    /// (`d.subsec_nanos() % 1_000_000 != 0`) silently breaks the THEORY.md
6906    /// §V.2.7 render-determinism contract:
6907    ///
6908    ///   - `Duration::from_micros(1500)` (= `1_500_000` ns) → `as_millis() == 1`
6909    ///     → renders `"1ms"` → parses back to `Duration::from_millis(1)` =
6910    ///     `1_000_000` ns ≠ original `1_500_000` ns;
6911    ///   - `Duration::from_nanos(1)` (= 1 ns) → `as_millis() == 0` →
6912    ///     renders the literal `"0s"`, which the per-axis zero-floor gate
6913    ///     on every typed-`Duration` slot then rejects on re-validate.
6914    ///
6915    /// Lifted to a `pub` predicate next to the [`render`] / [`parse`] pair so
6916    /// the codec's round-trippable accepted set lives in exactly one place —
6917    /// every typed-`Duration` slot that routes through this shared codec
6918    /// (`SupervisorSpec::restart_window` via [`super::duration_codec`],
6919    /// [`crate::MeshPolicy::timeout`] / [`crate::CircuitBreaker::window`] via
6920    /// `supervisor::duration_codec` + [`super::duration_codec_required`]) and
6921    /// every typed-`Duration` slot whose own codec shares the same
6922    /// `as_millis()`-truncation shape ([`crate::LimitsSpec::wall_clock`] via
6923    /// [`crate::limits`]'s in-module `parse_duration` / `render_duration`
6924    /// pair) calls this predicate from its `validate()` to bracket the
6925    /// accepted set against the codec's accepted set, structurally. Drift
6926    /// between the codec's granularity and any typed slot's accepted set is
6927    /// then a single-source-of-truth edit at this predicate rather than a
6928    /// silent round-trip break the next consumer discovers at apply time.
6929    ///
6930    /// Peer of [`crate::aplicacao::POLICY_RETRIES_MAX`] /
6931    /// [`crate::LIMITS_MEMORY_WASM32_MAX_BYTES`] and the
6932    /// `is_dns_1123_label` / `is_canonical_rate_limit_window` predicate
6933    /// family — same "typed-slot's valid set matches its codec's accepted
6934    /// set, structurally" discipline carried at the codec layer.
6935    #[must_use]
6936    pub fn is_integer_millisecond_duration(d: Duration) -> bool {
6937        d.subsec_nanos().is_multiple_of(1_000_000)
6938    }
6939}
6940
6941/// Required-Duration variant for fields that aren't Option<Duration>.
6942pub mod duration_codec_required {
6943    use super::Duration;
6944    use serde::{Deserialize, Deserializer, Serializer};
6945
6946    pub fn serialize<S: Serializer>(v: &Duration, s: S) -> Result<S::Ok, S::Error> {
6947        s.serialize_str(&super::duration_codec::render(*v))
6948    }
6949
6950    pub fn deserialize<'de, D: Deserializer<'de>>(d: D) -> Result<Duration, D::Error> {
6951        let s = String::deserialize(d)?;
6952        super::duration_codec::parse(&s).map_err(serde::de::Error::custom)
6953    }
6954}
6955
6956#[cfg(test)]
6957mod tests {
6958    use super::*;
6959
6960    fn child(name: &str, ver: &str, restart: RestartPolicy) -> ChildSpec {
6961        ChildSpec {
6962            caixa: name.into(),
6963            versao: ver.into(),
6964            restart,
6965        }
6966    }
6967
6968    #[test]
6969    fn child_spec_string_scalar_accessor_pair_is_const_fn() {
6970        // Fail-before-pass-after pin on [`ChildSpec::nome`] +
6971        // [`ChildSpec::versao_requirement`]'s `const`-eval-surface
6972        // posture. Each accessor projects the per-`:children :caixa`
6973        // / per-`:children :versao` [`String`] storage through the
6974        // `pub const fn` [`String::as_str`] (const-stable since Rust
6975        // 1.87, well within the workspace MSRV) — any future
6976        // accidental downgrade to non-`const` fails the corresponding
6977        // `<name>_via_const_fn` wrapper at caixa-core build time with
6978        // E0015 (`cannot call non-const method`), strictly stronger
6979        // than a runtime `assert!`. Sibling of the peer
6980        // per-M2/M3/universal-axis `String → &str` scalar-accessor
6981        // family pins on the sibling `const`-eval-surface passes
6982        // ([`crate::Caixa::nome`] / [`crate::Caixa::versao`] at the
6983        // top-level manifest, [`crate::CaixaVersion::as_str`] at the
6984        // typed-newtype wrapper, [`crate::aplicacao::Membro::nome`] /
6985        // [`crate::aplicacao::Membro::versao_requirement`] at the M3
6986        // membership axis, [`crate::aplicacao::Entrada::hostname`] /
6987        // [`crate::aplicacao::Entrada::destination`] at the M3
6988        // ingress axis,
6989        // [`crate::upgrade::UpgradeFromEntry::prior_versao`] at the
6990        // M2 upgrade axis, [`crate::dep::Dep::nome`] /
6991        // [`crate::dep::Dep::versao_requirement`] at the dep-graph
6992        // axis, and the per-`:contratos`
6993        // [`crate::aplicacao::WitContract::source`] /
6994        // [`crate::aplicacao::WitContract::destination`] /
6995        // [`crate::aplicacao::WitContract::world_ref`] trio the
6996        // sibling pin at 279823b already anchors).
6997        const fn nome_via_const_fn(c: &ChildSpec) -> &str {
6998            c.nome()
6999        }
7000        const fn versao_via_const_fn(c: &ChildSpec) -> &str {
7001            c.versao_requirement()
7002        }
7003        for (caixa, versao) in [
7004            ("worker-a", "^0.1"),
7005            ("worker-b", "~0.2.3"),
7006            ("collector", "*"),
7007        ] {
7008            let c = child(caixa, versao, RestartPolicy::Permanent);
7009            assert_eq!(nome_via_const_fn(&c), c.nome());
7010            assert_eq!(versao_via_const_fn(&c), c.versao_requirement());
7011            assert_eq!(c.nome(), caixa);
7012            assert_eq!(c.versao_requirement(), versao);
7013        }
7014    }
7015
7016    #[test]
7017    fn supervisor_children_slice_return_accessor_is_const_fn() {
7018        // Fail-before-pass-after pin on [`SupervisorSpec::children`]'s
7019        // `const`-eval-surface posture. The accessor destructures the
7020        // per-`:children` `Vec<ChildSpec>` storage through the
7021        // `pub const fn` [`Vec::as_slice`] (const-stable since Rust
7022        // 1.66, well within the workspace MSRV) — any future
7023        // accidental downgrade to non-`const` fails
7024        // `children_via_const_fn` at caixa-core build time with E0015
7025        // (`cannot call non-const method`), strictly stronger than a
7026        // runtime `assert!`. Sibling of the peer per-M3-mesh-slot
7027        // `Vec → &[T]` slice-return accessor family pin
7028        // [`crate::aplicacao::tests::m3_reference_return_accessor_family_is_const_fn`]
7029        // on the M3 mesh-slot per-`:clusters` / per-`:paths` /
7030        // per-`:membros` / per-`:contratos` slice-return axes, and of
7031        // the peer M2 upgrade-appup axis pin
7032        // [`crate::upgrade::tests::upgrade_from_entry_instructions_slice_return_accessor_is_const_fn`]
7033        // on the per-`:upgrade-from :instructions` slice-return axis.
7034        const fn children_via_const_fn(s: &SupervisorSpec) -> &[ChildSpec] {
7035            s.children()
7036        }
7037        // Sweep both the empty-children (leaf-supervisor with no
7038        // static children — the `SimpleOneForOne` dynamic-child
7039        // arm's canonical shape) and the populated-children
7040        // (`OneForOne` / `OneForAll` / `RestForOne` static-child
7041        // arm's canonical shape) axes so the accessor carries a
7042        // const-dispatch pin on both arms.
7043        let s_empty = SupervisorSpec {
7044            estrategia: RestartStrategy::SimpleOneForOne,
7045            max_restarts: SUPERVISOR_MAX_RESTARTS_DEFAULT,
7046            restart_window: Some(SUPERVISOR_RESTART_WINDOW_DEFAULT),
7047            children: vec![],
7048        };
7049        assert!(children_via_const_fn(&s_empty).is_empty());
7050        assert_eq!(children_via_const_fn(&s_empty), s_empty.children());
7051        let s_full = SupervisorSpec {
7052            estrategia: RestartStrategy::OneForOne,
7053            max_restarts: SUPERVISOR_MAX_RESTARTS_DEFAULT,
7054            restart_window: Some(SUPERVISOR_RESTART_WINDOW_DEFAULT),
7055            children: vec![
7056                child("worker-a", "^0.1", RestartPolicy::Permanent),
7057                child("worker-b", "~0.2.3", RestartPolicy::Transient),
7058                child("collector", "*", RestartPolicy::Temporary),
7059            ],
7060        };
7061        assert_eq!(children_via_const_fn(&s_full).len(), 3);
7062        assert_eq!(children_via_const_fn(&s_full), s_full.children());
7063    }
7064
7065    #[test]
7066    fn default_has_one_for_one_and_5_restarts_in_60s() {
7067        let s = SupervisorSpec::default();
7068        assert_eq!(s.estrategia, RestartStrategy::OneForOne);
7069        assert_eq!(s.max_restarts, 5);
7070        assert_eq!(s.restart_window, Some(Duration::from_secs(60)));
7071        assert!(s.children.is_empty());
7072    }
7073
7074    #[test]
7075    fn validate_one_for_one_requires_children() {
7076        // Explicit-empty via struct-update rather than `let mut s = default(); s.children = vec![];`
7077        // — the peer `validate_simple_one_for_one_forbids_static_children` below already uses
7078        // struct-update to name the axis under test at construction, and this shape matches
7079        // it. Also keeps the "empty children is the axis under test" intent visible at the
7080        // binding site rather than one line down, and side-steps `clippy::field_reassign_with_default`.
7081        let mut s = SupervisorSpec {
7082            children: vec![],
7083            ..SupervisorSpec::default()
7084        };
7085        assert!(matches!(
7086            s.validate().unwrap_err(),
7087            SupervisorError::NoChildren { .. }
7088        ));
7089        s.children = vec![child("worker", "^0.1", RestartPolicy::Permanent)];
7090        s.validate().unwrap();
7091    }
7092
7093    #[test]
7094    fn validate_simple_one_for_one_forbids_static_children() {
7095        let mut s = SupervisorSpec {
7096            estrategia: RestartStrategy::SimpleOneForOne,
7097            ..SupervisorSpec::default()
7098        };
7099        s.children
7100            .push(child("w", "^0.1", RestartPolicy::Permanent));
7101        assert_eq!(
7102            s.validate().unwrap_err(),
7103            SupervisorError::SimpleOneForOneWithStaticChildren
7104        );
7105        s.children.clear();
7106        s.validate().unwrap();
7107    }
7108
7109    #[test]
7110    fn validate_rejects_zero_max_restarts() {
7111        let s = SupervisorSpec {
7112            max_restarts: 0,
7113            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7114            ..SupervisorSpec::default()
7115        };
7116        assert_eq!(s.validate().unwrap_err(), SupervisorError::ZeroMaxRestarts);
7117    }
7118
7119    // ── upper-cap: SUPERVISOR_MAX_RESTARTS_MAX brackets the typed slot ─────
7120    //
7121    // The cap arm lifts the `:politicas :circuit-breaker :max-failures` /
7122    // `POLICY_BREAKER_MAX_FAILURES_MAX` (2b51ace) discipline onto the peer
7123    // `:supervisor :max-restarts` axis — both fields are "trip the
7124    // next-higher protection layer after N events in a rolling window"
7125    // counters with identical degenerate-at-the-high-end shape, so the
7126    // typed-slot's accepted set lies in `1..=1000` on the supervisor side
7127    // exactly as it lies in `1..=1000` on the breaker side.
7128
7129    #[test]
7130    fn validate_rejects_max_restarts_above_cap() {
7131        // The fail-before-pass-after pin: `SUPERVISOR_MAX_RESTARTS_MAX +
7132        // 1` is structurally one past the cap and silently passed
7133        // validate on every pre-gate codebase because the typed slot's
7134        // only check was the zero-floor arm. The no-op-supervisor vector
7135        // only surfaced at the runtime substrate (Erlang/OTP
7136        // MaxIntensity/Period ratio, the future wasm-operator's
7137        // per-supervisor restart-intensity counter) far from the source
7138        // caixa.lisp with no field naming the offending supervisor.
7139        let s = SupervisorSpec {
7140            max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
7141            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7142            ..SupervisorSpec::default()
7143        };
7144        assert_eq!(
7145            s.validate().unwrap_err(),
7146            SupervisorError::MaxRestartsExceedsCap {
7147                max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
7148            }
7149        );
7150    }
7151
7152    #[test]
7153    fn validate_rejects_max_restarts_far_above_cap() {
7154        // The `u32::MAX` worst case — the four-billion-restart
7155        // threshold a typo (`:max-restarts 4294967295`) or a
7156        // struct-literal copy-paste lands in the slot. Pin the cap
7157        // arm's coverage explicitly across the full `u32` overflow so
7158        // a future relaxation that drops the upper bound surfaces
7159        // here. Same shape every other typed-cap arm on this surface
7160        // carries (POLICY_BREAKER_MAX_FAILURES_MAX,
7161        // POLICY_RETRIES_MAX, POLICY_RATE_LIMIT_MAX).
7162        let s = SupervisorSpec {
7163            max_restarts: u32::MAX,
7164            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7165            ..SupervisorSpec::default()
7166        };
7167        assert_eq!(
7168            s.validate().unwrap_err(),
7169            SupervisorError::MaxRestartsExceedsCap {
7170                max_restarts: u32::MAX,
7171            }
7172        );
7173    }
7174
7175    #[test]
7176    fn validate_accepts_max_restarts_at_cap() {
7177        // The boundary value — exactly SUPERVISOR_MAX_RESTARTS_MAX —
7178        // must validate. The cap is inclusive on the top edge,
7179        // matching the POLICY_BREAKER_MAX_FAILURES_MAX /
7180        // POLICY_RETRIES_MAX / LIMITS_MEMORY_WASM32_MAX_BYTES
7181        // discipline on the sibling capped axes. Pin the boundary
7182        // explicitly so a future off-by-one tightening
7183        // (`>= SUPERVISOR_MAX_RESTARTS_MAX` instead of `>`) surfaces
7184        // here as a test failure rather than a silent contract
7185        // narrowing.
7186        let s = SupervisorSpec {
7187            max_restarts: SUPERVISOR_MAX_RESTARTS_MAX,
7188            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7189            ..SupervisorSpec::default()
7190        };
7191        s.validate()
7192            .expect("max_restarts == SUPERVISOR_MAX_RESTARTS_MAX must validate");
7193    }
7194
7195    #[test]
7196    fn validate_accepts_max_restarts_typical_values() {
7197        // The documented production-playbook band positive-control
7198        // sweep — every value Erlang/OTP / Elixir / Riak Core /
7199        // RabbitMQ recommend (1..=100) must pass, plus a sweep
7200        // through the hyperscale band (200, 500, 1000) the cap
7201        // accepts. Pin the inclusive validated set explicitly so a
7202        // future tightening of the ceiling surfaces here.
7203        for n in [1u32, 3, 5, 10, 20, 50, 100, 200, 500, 1000] {
7204            let s = SupervisorSpec {
7205                max_restarts: n,
7206                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7207                ..SupervisorSpec::default()
7208            };
7209            s.validate()
7210                .unwrap_or_else(|e| panic!("max_restarts={n} must validate; got {e:?}"));
7211        }
7212    }
7213
7214    #[test]
7215    fn zero_max_restarts_takes_precedence_over_cap() {
7216        // The cross-arm ordering pin: `0` is structurally outside
7217        // both `1..` (zero-floor) and `..=SUPERVISOR_MAX_RESTARTS_MAX`
7218        // (cap), but the zero-floor diagnostic is the more
7219        // self-locating one (it directly names the counter-axis
7220        // remediation), so the validate gate must fire on zero first.
7221        // Same shape every other zero-then-shape ordering on this
7222        // surface uses (PolicyRetriesZero then
7223        // PolicyRetriesExceedsCap; PolicyBreakerZeroFailures then
7224        // PolicyBreakerMaxFailuresExceedsCap).
7225        let s = SupervisorSpec {
7226            max_restarts: 0,
7227            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7228            ..SupervisorSpec::default()
7229        };
7230        assert_eq!(
7231            s.validate().unwrap_err(),
7232            SupervisorError::ZeroMaxRestarts,
7233            "max_restarts == 0 must surface the zero-floor diagnostic, not the cap diagnostic"
7234        );
7235    }
7236
7237    #[test]
7238    fn max_restarts_cap_takes_precedence_over_restart_window_gates() {
7239        // The cross-arm ordering pin between the cap and the sibling
7240        // `:restart-window` gates (zero-window, canonical-window). A
7241        // supervisor carrying both an over-cap `max_restarts` AND a
7242        // structurally invalid window (zero, sub-ms) must surface the
7243        // cap diagnostic first — the cap arm is wired immediately
7244        // after the zero-restart arm and strictly before the window
7245        // arms, so the offending value the diagnostic names matches
7246        // the order the author would discover the gates by reading
7247        // top-to-bottom through `SupervisorSpec::validate`. Pin the
7248        // order so a future refactor that reorders the arms surfaces
7249        // here as a test failure rather than a silent diagnostic
7250        // regression. Peer of
7251        // `circuit_breaker_max_failures_cap_takes_precedence_over_window_gates`
7252        // on the sibling `:politicas :circuit-breaker` slot.
7253        let s = SupervisorSpec {
7254            max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
7255            restart_window: Some(Duration::ZERO),
7256            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7257            ..SupervisorSpec::default()
7258        };
7259        assert_eq!(
7260            s.validate().unwrap_err(),
7261            SupervisorError::MaxRestartsExceedsCap {
7262                max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
7263            },
7264            "over-cap max_restarts must surface the cap diagnostic before any window-axis diagnostic"
7265        );
7266    }
7267
7268    #[test]
7269    fn max_restarts_cap_diagnostic_carries_offending_value() {
7270        // The diagnostic-shape pin: the offending `u32` is carried
7271        // verbatim into the `SupervisorError::MaxRestartsExceedsCap`
7272        // variant so the surfaced error message names the value the
7273        // author wrote (`":supervisor :max-restarts (50000) exceeds the
7274        // supervisor-policy ceiling …"`), not just the cap. Same
7275        // self-locating diagnostic shape every other typed-cap arm on
7276        // this surface carries
7277        // (`AplicacaoError::PolicyBreakerMaxFailuresExceedsCap` carries
7278        // the offending failure count verbatim,
7279        // `AplicacaoError::PolicyRetriesExceedsCap` carries the offending
7280        // retries count verbatim).
7281        let s = SupervisorSpec {
7282            max_restarts: 50_000,
7283            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
7284            ..SupervisorSpec::default()
7285        };
7286        let err = s.validate().unwrap_err();
7287        assert!(
7288            matches!(
7289                err,
7290                SupervisorError::MaxRestartsExceedsCap {
7291                    max_restarts: 50_000
7292                }
7293            ),
7294            "got {err:?}"
7295        );
7296        let msg = err.to_string();
7297        assert!(
7298            msg.contains("50000"),
7299            ":supervisor :max-restarts cap diagnostic must carry the offending value verbatim (got: {msg})"
7300        );
7301    }
7302
7303    #[test]
7304    fn supervisor_max_restarts_default_pins_otp_canonical_value() {
7305        // Pin [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] at `5` — the
7306        // Erlang/OTP-canonical `{intensity, 5, 60}` `MaxIntensity`
7307        // half of Learn You Some Erlang's worker-supervisor default,
7308        // sibling of the `60s` `Period` half that the paired
7309        // [`Default for SupervisorSpec`] impl already pins on the
7310        // sibling `restart_window` axis. Pinning the literal here
7311        // surfaces a future rebrand (a tightening to Elixir's `3`,
7312        // a widening to a per-cluster overlay the operator pins
7313        // through a future `:max-restarts-overrides` slot) as a
7314        // deliberate test edit, not a silent contract migration.
7315        // Peer of the sibling
7316        // [`supervisor_max_restarts_cap_pins_canonical_value`]
7317        // upper-bracket pin on the same axis.
7318        assert_eq!(SUPERVISOR_MAX_RESTARTS_DEFAULT, 5);
7319    }
7320
7321    #[test]
7322    fn default_max_restarts_helper_routes_through_lifted_default() {
7323        // Composition pin: the private `default_max_restarts()`
7324        // serde-`#[serde(default = "…")]` helper on
7325        // [`SupervisorSpec::max_restarts`] must route through the
7326        // substrate-canonical [`SUPERVISOR_MAX_RESTARTS_DEFAULT`]
7327        // typed `pub const` rather than a raw `5` literal. Prior to
7328        // the lift the helper carried an inline `5` with no compile-
7329        // time link back to the shared default, so the wire-format
7330        // author-omitted arm and the caixa-core
7331        // [`crate::manifest::Caixa::supervisor_view`] fold's `unwrap_or(5)`
7332        // arm could silently split on any future default rebrand.
7333        // Byte-parity against the lifted constant closes the split.
7334        assert_eq!(default_max_restarts(), SUPERVISOR_MAX_RESTARTS_DEFAULT);
7335    }
7336
7337    #[test]
7338    fn supervisor_spec_default_max_restarts_routes_through_lifted_default() {
7339        // Composition pin: the [`Default for SupervisorSpec`] impl's
7340        // struct-literal `max_restarts` field must route through the
7341        // substrate-canonical [`SUPERVISOR_MAX_RESTARTS_DEFAULT`]
7342        // typed `pub const` (via the private helper this test's
7343        // sibling `default_max_restarts_helper_routes_through_lifted_default`
7344        // already pins onto the constant). Structurally: every
7345        // `SupervisorSpec::default()` call must yield a
7346        // `max_restarts` field byte-equal to the lifted constant
7347        // (the two paired defaults — the serde-side wire-format arm
7348        // and the struct-literal default arm — cannot silently split
7349        // on any future default rebrand). Peer of the sibling
7350        // `default_has_one_for_one_and_5_restarts_in_60s` shape pin
7351        // — this pin closes the byte-parity arm on the two paired
7352        // altitude entry points onto the shared substrate constant.
7353        assert_eq!(
7354            SupervisorSpec::default().max_restarts(),
7355            SUPERVISOR_MAX_RESTARTS_DEFAULT,
7356        );
7357    }
7358
7359    #[test]
7360    fn supervisor_restart_window_default_pins_otp_canonical_value() {
7361        // Pin [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] at `60s` — the
7362        // Erlang/OTP-canonical `{intensity, 5, 60}` `Period` half of
7363        // Learn You Some Erlang's worker-supervisor default, paired
7364        // with the sibling `SUPERVISOR_MAX_RESTARTS_DEFAULT` `5`
7365        // `MaxIntensity` half this constant is the sliding-window
7366        // denominator of on the same `MaxIntensity / Period`
7367        // restart-intensity ratio. Pinning the literal here surfaces a
7368        // future coherent rebrand of the paired default (Elixir's
7369        // `{max_restarts: 3, max_seconds: 5}`, a per-cluster overlay
7370        // the operator pins through a future
7371        // `:restart-window-overrides` slot) as a deliberate test edit,
7372        // not a silent contract migration. Peer of the sibling
7373        // [`supervisor_max_restarts_default_pins_otp_canonical_value`]
7374        // paired-half pin on the same OTP-canonical default and the
7375        // [`supervisor_restart_window_cap_pins_canonical_value`]
7376        // upper-bracket pin on the same axis.
7377        assert_eq!(SUPERVISOR_RESTART_WINDOW_DEFAULT, Duration::from_secs(60),);
7378    }
7379
7380    #[test]
7381    fn supervisor_spec_default_restart_window_routes_through_lifted_default() {
7382        // Composition pin: the [`Default for SupervisorSpec`] impl's
7383        // struct-literal `restart_window` field must route through the
7384        // substrate-canonical [`SUPERVISOR_RESTART_WINDOW_DEFAULT`]
7385        // typed `pub const` rather than a raw
7386        // `Duration::from_secs(60)` literal. Prior to this lift the
7387        // paired `{intensity, 5, 60}` OTP-canonical default was split
7388        // across two altitudes with no compile-time link between the
7389        // halves — the `MaxIntensity` half rode through the lifted
7390        // [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] constant while the
7391        // `Period` half rode as an open-coded literal at the
7392        // composition site, so a future coherent rebrand of the paired
7393        // canonical would have had to migrate one half through the
7394        // constant and the other through a raw literal in lockstep.
7395        // Byte-parity against the lifted constant on the `Period` half
7396        // closes the split — the paired OTP-canonical default now
7397        // migrates as one unit on any future axis change. Peer of the
7398        // sibling
7399        // [`supervisor_spec_default_max_restarts_routes_through_lifted_default`]
7400        // byte-parity pin on the paired `MaxIntensity` half.
7401        assert_eq!(
7402            SupervisorSpec::default().restart_window(),
7403            Some(SUPERVISOR_RESTART_WINDOW_DEFAULT),
7404        );
7405    }
7406
7407    #[test]
7408    fn supervisor_estrategia_default_pins_otp_canonical_value() {
7409        // Pin [`SUPERVISOR_ESTRATEGIA_DEFAULT`] at [`RestartStrategy::OneForOne`]
7410        // — the Erlang/OTP-canonical `one_for_one` half of Learn You Some
7411        // Erlang's `{one_for_one, intensity, 5, 60}` worker-supervisor
7412        // canonical default, paired with the sibling
7413        // `SUPERVISOR_MAX_RESTARTS_DEFAULT` `5` `MaxIntensity` half and the
7414        // sibling `SUPERVISOR_RESTART_WINDOW_DEFAULT` `60s` `Period` half
7415        // this constant is the strategy discriminator of on the same
7416        // OTP-canonical worker-supervisor default. Pinning the arm here
7417        // surfaces a future coherent rebrand of the paired triple (Elixir's
7418        // `{:one_for_one, max_restarts: 3, max_seconds: 5}` on the sibling
7419        // intensity/period axes leaving this strategy arm untouched, an OTP
7420        // `rest_for_one` widening once the substrate discovers startup-
7421        // order-coupled child cohorts as the more common worker-supervisor
7422        // shape, a per-cluster overlay the operator pins through a future
7423        // `:estrategia-overrides` slot the MESH-COMPOSITION §III.2
7424        // supervision-canary roadmap acknowledges) as a deliberate test
7425        // edit, not a silent contract migration. Peer of the sibling
7426        // [`supervisor_max_restarts_default_pins_otp_canonical_value`] +
7427        // [`supervisor_restart_window_default_pins_otp_canonical_value`]
7428        // paired-half pins on the same OTP-canonical default.
7429        assert_eq!(SUPERVISOR_ESTRATEGIA_DEFAULT, RestartStrategy::OneForOne);
7430    }
7431
7432    #[test]
7433    fn restart_strategy_default_routes_through_lifted_default() {
7434        // Composition pin: the [`Default for RestartStrategy`] impl's
7435        // return arm must route through the substrate-canonical
7436        // [`SUPERVISOR_ESTRATEGIA_DEFAULT`] typed `pub const` rather than
7437        // a raw `Self::OneForOne` arm. Prior to the lift the impl carried
7438        // an inline `Self::OneForOne` with no compile-time link back to
7439        // the shared OTP-canonical `one_for_one` strategy the paired
7440        // [`Default for SupervisorSpec`] impl's struct-literal `estrategia`
7441        // field and the [`crate::manifest::Caixa::supervisor_view`] fold's
7442        // `.unwrap_or_default()` (now
7443        // `.unwrap_or(SUPERVISOR_ESTRATEGIA_DEFAULT)`) arm both key off —
7444        // so a future rebrand of the OTP-canonical strategy default (an
7445        // OTP `rest_for_one` widening once the substrate discovers
7446        // startup-order-coupled child cohorts as the more common worker-
7447        // supervisor shape, a per-cluster overlay the operator pins
7448        // through a future `:estrategia-overrides` slot) would have had to
7449        // be threaded through the `Default` impl and the two peer routes
7450        // in lockstep or the three consumers would silently split. Byte-
7451        // parity against the lifted constant closes the split. Peer of
7452        // the sibling
7453        // [`default_max_restarts_helper_routes_through_lifted_default`] +
7454        // [`supervisor_spec_default_restart_window_routes_through_lifted_default`]
7455        // composition pins on the paired `MaxIntensity` + `Period` halves.
7456        assert_eq!(RestartStrategy::default(), SUPERVISOR_ESTRATEGIA_DEFAULT,);
7457    }
7458
7459    #[test]
7460    fn supervisor_spec_default_estrategia_routes_through_lifted_default() {
7461        // Composition pin: the [`Default for SupervisorSpec`] impl's
7462        // struct-literal `estrategia` field must route through the
7463        // substrate-canonical [`SUPERVISOR_ESTRATEGIA_DEFAULT`] typed
7464        // `pub const` (either directly, or via the
7465        // [`RestartStrategy::default`] impl that the sibling
7466        // `restart_strategy_default_routes_through_lifted_default` pin
7467        // already routes onto the constant). Structurally: every
7468        // `SupervisorSpec::default()` call must yield an `estrategia`
7469        // field byte-equal to the lifted constant (the three paired
7470        // defaults — the [`Default for RestartStrategy`] impl arm, the
7471        // struct-literal default arm here, and the
7472        // [`crate::manifest::Caixa::supervisor_view`] fold arm — cannot
7473        // silently split on any future default rebrand). Peer of the
7474        // sibling
7475        // [`supervisor_spec_default_max_restarts_routes_through_lifted_default`]
7476        // + [`supervisor_spec_default_restart_window_routes_through_lifted_default`]
7477        // byte-parity pins on the paired `MaxIntensity` + `Period` halves
7478        // of the same `SupervisorSpec::default()` composed altitude.
7479        assert_eq!(
7480            SupervisorSpec::default().estrategia(),
7481            SUPERVISOR_ESTRATEGIA_DEFAULT,
7482        );
7483    }
7484
7485    #[test]
7486    fn supervisor_spec_default_routes_through_otp_canonical_ctor() {
7487        // Composition pin: the [`Default for SupervisorSpec`] impl must
7488        // route through the substrate-canonical
7489        // [`SupervisorSpec::otp_canonical`] `pub const fn` constructor
7490        // rather than a re-hand-authored struct-literal cascade. Sharpens
7491        // the sibling per-arm
7492        // `supervisor_spec_default_*_routes_through_lifted_default` pins
7493        // from a per-field lift into a whole-struct one-source-of-truth
7494        // pin — the derived-until-now [`Default::default`] and the
7495        // [`SupervisorSpec::otp_canonical`] constructor are byte-equal by
7496        // construction, not by coincidence.
7497        //
7498        // A future extension of the OTP-canonical baseline (a fifth
7499        // `restart_intensity` field the Erlang/OTP `#supervisor` record
7500        // grows, a per-child-cohort split of the `restart_window` /
7501        // `max_restarts` pair, an M4 `mesh.pleme.io/v1alpha1/Supervisor`
7502        // CR materializer's admission-time overlay pass) reaches both
7503        // paths through exactly one edit on
7504        // [`SupervisorSpec::otp_canonical`] — the derived path could
7505        // silently disagree with the constructor's shape on any new
7506        // field whose [`Default::default`] resolves to a different arm
7507        // than the OTP-canonical baseline the constructor names, while
7508        // this delegated impl reaches the constructor directly and
7509        // picks up every future extension by construction.
7510        //
7511        // Fourth peer on the M2 / M3 typed-slot-spec
7512        // [`Default`]-through-const-ctor fold family — sibling of the
7513        // [`crate::LimitsSpec`] [`Default`]-through-[`crate::LimitsSpec::empty`]
7514        // (abd52c2), [`crate::aplicacao::MeshPolicy`]
7515        // [`Default`]-through-[`crate::aplicacao::MeshPolicy::empty`]
7516        // (91641a4), and [`crate::BehaviorSpec`]
7517        // [`Default`]-through-[`crate::BehaviorSpec::empty`] (0c1752c)
7518        // per-`Option`-only-typed-slot folds — extended here onto the
7519        // M2 supervisor-slot [`SupervisorSpec`] whose canonical baseline
7520        // is not "everything `None`" but the Erlang/OTP-canonical
7521        // `{one_for_one, 5, 60}` worker-supervisor triple.
7522        assert_eq!(SupervisorSpec::default(), SupervisorSpec::otp_canonical());
7523    }
7524
7525    #[test]
7526    fn supervisor_spec_otp_canonical_byte_equals_default() {
7527        // Value pin: [`SupervisorSpec::otp_canonical`] must byte-equal
7528        // the hand-authored `{one_for_one, 5, 60, []}` OTP-canonical
7529        // baseline the sibling `default_has_one_for_one_and_5_restarts_in_60s`
7530        // pin already asserts against the [`Default::default`] path.
7531        // Sharpens the pair-invariant into a per-constructor pin so a
7532        // future extension of [`SupervisorSpec`] with a fifth field
7533        // whose OTP-canonical shape is non-`Default::default`-equivalent
7534        // trips at caixa-core test time rather than at a downstream
7535        // consumer that composed [`SupervisorSpec::otp_canonical`] with
7536        // [`SupervisorSpec::validate`] as its "canonical baseline
7537        // seed".
7538        let canonical = SupervisorSpec::otp_canonical();
7539        assert_eq!(canonical.estrategia, RestartStrategy::OneForOne);
7540        assert_eq!(canonical.max_restarts, 5);
7541        assert_eq!(canonical.restart_window, Some(Duration::from_secs(60)));
7542        assert!(canonical.children.is_empty());
7543    }
7544
7545    #[test]
7546    fn supervisor_spec_otp_canonical_is_usable_in_const_context() {
7547        // Const-context pin: [`SupervisorSpec::otp_canonical`] must
7548        // remain callable from a `const`-bound position so downstream
7549        // `const`-context callers wanting a canonical OTP-baseline seed
7550        // can construct one at compile time without runtime dispatch on
7551        // the derived [`Default::default`]. Peer of the sibling
7552        // `pub const fn` [`crate::LimitsSpec::empty`] /
7553        // [`crate::aplicacao::MeshPolicy::empty`] /
7554        // [`crate::BehaviorSpec::empty`] constructors on the sibling
7555        // typed-slot-spec `pub const fn` axis. If a future edit breaks
7556        // the `const`-eligibility of [`SupervisorSpec::otp_canonical`]
7557        // (a non-`const` field-default helper, a non-`const`-stable
7558        // container type promotion), this evaluation fails at
7559        // build time on this file rather than at a downstream
7560        // `const`-context call site.
7561        const CANONICAL: SupervisorSpec = SupervisorSpec::otp_canonical();
7562        assert_eq!(CANONICAL.estrategia, SUPERVISOR_ESTRATEGIA_DEFAULT);
7563        assert_eq!(CANONICAL.max_restarts, SUPERVISOR_MAX_RESTARTS_DEFAULT);
7564        assert_eq!(
7565            CANONICAL.restart_window,
7566            Some(SUPERVISOR_RESTART_WINDOW_DEFAULT),
7567        );
7568        assert!(CANONICAL.children.is_empty());
7569    }
7570
7571    #[test]
7572    fn supervisor_child_restart_default_pins_otp_canonical_value() {
7573        // Pin [`SUPERVISOR_CHILD_RESTART_DEFAULT`] at
7574        // [`RestartPolicy::Permanent`] — Erlang/OTP's `permanent`
7575        // worker-child restart type (`{ChildId, StartFunc, permanent, …}`
7576        // in a `supervisor`'s `init/1` child-spec tuple), the per-child
7577        // half of the same OTP-shape supervisor-tree default set whose
7578        // per-`:supervisor` halves the sibling
7579        // [`SUPERVISOR_ESTRATEGIA_DEFAULT`] /
7580        // [`SUPERVISOR_MAX_RESTARTS_DEFAULT`] /
7581        // [`SUPERVISOR_RESTART_WINDOW_DEFAULT`] constants pin. Pinning the
7582        // arm here surfaces a future rebrand of the per-child default (an
7583        // OTP-`transient` widening once the substrate discovers clean-
7584        // completion-aware children as the more common child shape, a
7585        // per-cluster overlay the operator pins through a future
7586        // `:restart-overrides` slot the MESH-COMPOSITION §III.2
7587        // supervision-canary roadmap acknowledges) as a deliberate test
7588        // edit, not a silent contract migration. Peer of the sibling
7589        // [`supervisor_estrategia_default_pins_otp_canonical_value`] /
7590        // [`supervisor_max_restarts_default_pins_otp_canonical_value`] /
7591        // [`supervisor_restart_window_default_pins_otp_canonical_value`]
7592        // value pins on the per-`:supervisor` halves.
7593        assert_eq!(SUPERVISOR_CHILD_RESTART_DEFAULT, RestartPolicy::Permanent);
7594    }
7595
7596    #[test]
7597    fn restart_policy_default_routes_through_lifted_default() {
7598        // Composition pin: the [`Default for RestartPolicy`] impl's return
7599        // arm must route through the substrate-canonical
7600        // [`SUPERVISOR_CHILD_RESTART_DEFAULT`] typed `pub const` rather
7601        // than a raw `Self::Permanent` arm. Prior to the lift the impl
7602        // carried an inline `Self::Permanent` with no compile-time link
7603        // back to the OTP-shape supervisor-tree default set whose three
7604        // per-`:supervisor` halves already rode through lifted constants
7605        // — so a future coherent rebrand of the set would have had to
7606        // migrate three halves through typed constants and this fourth
7607        // through a raw enum arm in lockstep or the supervisor-level and
7608        // child-level defaults would silently drift apart. Byte-parity
7609        // against the lifted constant closes the split. Peer of the
7610        // sibling
7611        // [`restart_strategy_default_routes_through_lifted_default`]
7612        // composition pin on the per-`:supervisor` `:estrategia` axis.
7613        assert_eq!(RestartPolicy::default(), SUPERVISOR_CHILD_RESTART_DEFAULT);
7614    }
7615
7616    #[test]
7617    fn child_spec_serde_default_restart_routes_through_lifted_default() {
7618        // Composition pin: the serde-side `#[serde(default)]` on
7619        // [`ChildSpec::restart`] — the wire-format author-omitted
7620        // `:children :restart` arm — must resolve onto the substrate-
7621        // canonical [`SUPERVISOR_CHILD_RESTART_DEFAULT`] typed `pub const`
7622        // (via the [`Default for RestartPolicy`] impl the sibling
7623        // `restart_policy_default_routes_through_lifted_default` pin
7624        // already routes onto the constant). Structurally: a `ChildSpec`
7625        // deserialized from a payload that omits the `restart` key must
7626        // yield a `restart` field byte-equal to the lifted constant, so
7627        // the wire-format author-omitted arm and the
7628        // [`RestartPolicy::default`] impl arm cannot silently split on any
7629        // future default rebrand. Peer of the sibling
7630        // [`supervisor_spec_default_estrategia_routes_through_lifted_default`]
7631        // / [`supervisor_spec_default_max_restarts_routes_through_lifted_default`]
7632        // / [`supervisor_spec_default_restart_window_routes_through_lifted_default`]
7633        // byte-parity pins on the per-`:supervisor` halves of the same
7634        // author-omitted-slot resolution surface.
7635        let omitted: ChildSpec = serde_json::from_str(r#"{"caixa":"worker","versao":"^0.1"}"#)
7636            .expect("ChildSpec must deserialize with the restart key omitted");
7637        assert_eq!(
7638            omitted.restart(),
7639            SUPERVISOR_CHILD_RESTART_DEFAULT,
7640            "an author-omitted :children :restart slot must degrade onto \
7641             the SUPERVISOR_CHILD_RESTART_DEFAULT typed pub const (got \
7642             {:?}, expected {:?})",
7643            omitted.restart(),
7644            SUPERVISOR_CHILD_RESTART_DEFAULT,
7645        );
7646    }
7647
7648    #[test]
7649    fn supervisor_max_restarts_cap_pins_canonical_value() {
7650        // The SUPERVISOR_MAX_RESTARTS_MAX constant pins the value at
7651        // 1000 — the same ceiling the peer
7652        // POLICY_BREAKER_MAX_FAILURES_MAX cap carries on the
7653        // `:politicas :circuit-breaker :max-failures` axis (both are
7654        // "trip the next-higher protection layer after N events in a
7655        // rolling window" counters with identical
7656        // degenerate-at-the-high-end shape; uniform top edge so the
7657        // M4 CR materializers and the wasm-operator reconciler reach
7658        // for either field knowing the value is in `1..=1000`). Two
7659        // orders of magnitude above every documented Erlang/OTP /
7660        // Elixir / Riak Core / RabbitMQ production-playbook
7661        // recommendation band and below the clearly-pathological
7662        // "effectively no escalation" floor (10_000, 100_000,
7663        // u32::MAX). Pinning the literal value here surfaces a future
7664        // drift (a relaxation to 10_000, a tightening to 100) as a
7665        // deliberate test edit, not a silent contract narrowing.
7666        assert_eq!(SUPERVISOR_MAX_RESTARTS_MAX, 1000);
7667    }
7668
7669    #[test]
7670    fn validate_rejects_empty_child_name() {
7671        let s = SupervisorSpec {
7672            children: vec![child("", "^0.1", RestartPolicy::Permanent)],
7673            ..SupervisorSpec::default()
7674        };
7675        assert_eq!(s.validate().unwrap_err(), SupervisorError::EmptyChildName);
7676    }
7677
7678    #[test]
7679    fn validate_rejects_empty_child_version() {
7680        let s = SupervisorSpec {
7681            children: vec![child("w", "", RestartPolicy::Permanent)],
7682            ..SupervisorSpec::default()
7683        };
7684        assert!(matches!(
7685            s.validate().unwrap_err(),
7686            SupervisorError::EmptyChildVersion { .. }
7687        ));
7688    }
7689
7690    // ── value-shape: parse-as-VersionReq on :children :versao ─────────────
7691
7692    #[test]
7693    fn validate_rejects_invalid_child_versao_requirement() {
7694        // The fail-before-pass-after pin: a non-empty but malformed
7695        // semver requirement (`"^bad-version"`) silently passed
7696        // `validate()` on every pre-gate codebase because the prior
7697        // shape only refused the empty string. The parse failure
7698        // surfaced far downstream at lacre-resolve time with a
7699        // `semver::Error` that didn't name which `:children` entry
7700        // carried the typo. The new gate moves the check to caixa-build
7701        // time at the source caixa.lisp — the third `:versao` typed
7702        // axis (`:children`) joins `:deps` and `:membros` (9888b13) at
7703        // structural parity.
7704        let s = SupervisorSpec {
7705            children: vec![
7706                child("worker", "^0.1", RestartPolicy::Permanent),
7707                child("cache", "^bad-version", RestartPolicy::Transient),
7708            ],
7709            ..SupervisorSpec::default()
7710        };
7711        let err = s.validate().unwrap_err();
7712        assert!(
7713            matches!(
7714                err,
7715                SupervisorError::ChildVersaoInvalid { ref caixa, ref versao, .. }
7716                    if caixa == "cache" && versao == "^bad-version"
7717            ),
7718            "got {err:?}"
7719        );
7720    }
7721
7722    #[test]
7723    fn validate_rejects_child_versao_with_double_caret_typo() {
7724        // `"^^0.1"` is the canonical doubled-caret typo — looks
7725        // Cargo-shaped on first glance but fails the parser because
7726        // semver doesn't accept stacked operators. Pin this
7727        // adjacent-shape footgun explicitly so a future relaxation that
7728        // accepts "looks-canonical-but-isn't" forms surfaces here.
7729        let s = SupervisorSpec {
7730            children: vec![child("worker", "^^0.1", RestartPolicy::Permanent)],
7731            ..SupervisorSpec::default()
7732        };
7733        let err = s.validate().unwrap_err();
7734        assert!(
7735            matches!(
7736                err,
7737                SupervisorError::ChildVersaoInvalid { ref caixa, ref versao, .. }
7738                    if caixa == "worker" && versao == "^^0.1"
7739            ),
7740            "got {err:?}"
7741        );
7742    }
7743
7744    #[test]
7745    fn validate_rejects_child_versao_with_v_prefixed_tag() {
7746        // `"v0.1"` is the canonical "git-tag-shape leaking into the
7747        // semver requirement slot" typo — an author copies the
7748        // publish-side git-tag string verbatim into `:versao`, but
7749        // Cargo's semver parser rejects the leading `v`. Same
7750        // adjacent-shape footgun pinned for `:membros :versao`
7751        // (9888b13).
7752        let s = SupervisorSpec {
7753            children: vec![child("worker", "v0.1", RestartPolicy::Permanent)],
7754            ..SupervisorSpec::default()
7755        };
7756        let err = s.validate().unwrap_err();
7757        assert!(
7758            matches!(
7759                err,
7760                SupervisorError::ChildVersaoInvalid { ref caixa, ref versao, .. }
7761                    if caixa == "worker" && versao == "v0.1"
7762            ),
7763            "got {err:?}"
7764        );
7765    }
7766
7767    #[test]
7768    fn validate_accepts_canonical_child_versao_forms() {
7769        // The Cargo-shaped requirement forms `:deps :versao` and
7770        // `:membros :versao` already accept via
7771        // `crate::parse_requirement` must pass the children gate
7772        // without re-validating at the resolver layer. Pin every leg so
7773        // a future tightening of the canonical set surfaces here as a
7774        // test failure.
7775        for form in [
7776            "^0.1",      // caret — minor-range pin (the most common shape)
7777            "~0.1.2",    // tilde — patch-range pin
7778            "0.1.0",     // exact — single-version pin
7779            "*",         // wildcard — any version (semver::VersionReq::STAR)
7780            ">=0.1, <2", // multi-range — comma-separated comparators
7781        ] {
7782            let s = SupervisorSpec {
7783                children: vec![child("worker", form, RestartPolicy::Permanent)],
7784                ..SupervisorSpec::default()
7785            };
7786            s.validate()
7787                .unwrap_or_else(|e| panic!("canonical form {form:?} must validate, got {e:?}"));
7788        }
7789    }
7790
7791    #[test]
7792    fn child_versao_empty_takes_precedence_over_invalid() {
7793        // Order pin: the existing `EmptyChildVersion` diagnostic (which
7794        // doesn't try to parse) fires before the new
7795        // `ChildVersaoInvalid` parse-side diagnostic, so an empty
7796        // `:versao` keeps its narrower error message —
7797        // `parse_requirement` would also reject `""`, but the
7798        // empty-string arm is the more self-locating diagnostic for the
7799        // author. Same ordering discipline as
7800        // `membro_versao_empty_takes_precedence_over_invalid` in
7801        // aplicacao.rs.
7802        let s = SupervisorSpec {
7803            children: vec![child("worker", "", RestartPolicy::Permanent)],
7804            ..SupervisorSpec::default()
7805        };
7806        let err = s.validate().unwrap_err();
7807        assert!(
7808            matches!(err, SupervisorError::EmptyChildVersion { ref caixa } if caixa == "worker"),
7809            "got {err:?}"
7810        );
7811    }
7812
7813    #[test]
7814    fn child_versao_invalid_fires_before_duplicate_check() {
7815        // Order pin: a malformed requirement on a non-duplicate entry
7816        // surfaces *its own* diagnostic (which names the offending
7817        // `:versao` string), even when a later entry would otherwise
7818        // collapse onto an earlier name. The per-entry shape gate runs
7819        // inline before the duplicate-key insert — parallel to
7820        // `membro_versao_invalid_fires_before_duplicate_check` in
7821        // aplicacao.rs and the b0c8389 / c4213a4 ordering discipline.
7822        let s = SupervisorSpec {
7823            children: vec![
7824                child("worker", "^bad", RestartPolicy::Permanent),
7825                child("cache", "^0.1", RestartPolicy::Transient),
7826                child("worker", "^0.2", RestartPolicy::Permanent), // would otherwise raise DuplicateChildCaixa
7827            ],
7828            ..SupervisorSpec::default()
7829        };
7830        let err = s.validate().unwrap_err();
7831        assert!(
7832            matches!(
7833                err,
7834                SupervisorError::ChildVersaoInvalid { ref caixa, .. } if caixa == "worker"
7835            ),
7836            "got {err:?}"
7837        );
7838    }
7839
7840    #[test]
7841    fn child_versao_invalid_diagnostic_carries_offending_versao() {
7842        // The diagnostic-shape pin: the error names the offending
7843        // `:versao` value verbatim so the author can grep their
7844        // caixa.lisp without re-running the build, and carries a
7845        // non-empty `reason` from `semver::VersionReq::parse` so the
7846        // parser's own wording flows through to the diagnostic.
7847        let s = SupervisorSpec {
7848            children: vec![child("worker", "not-a-req", RestartPolicy::Permanent)],
7849            ..SupervisorSpec::default()
7850        };
7851        let err = s.validate().unwrap_err();
7852        let SupervisorError::ChildVersaoInvalid {
7853            caixa,
7854            versao,
7855            reason,
7856        } = err
7857        else {
7858            panic!("expected ChildVersaoInvalid, got other variant");
7859        };
7860        assert_eq!(caixa, "worker");
7861        assert_eq!(versao, "not-a-req");
7862        assert!(
7863            !reason.is_empty(),
7864            "ChildVersaoInvalid `reason` must carry the parser's wording verbatim"
7865        );
7866    }
7867
7868    // ── value-shape: DNS-1123 label rule on :children :caixa ──────────────
7869
7870    #[test]
7871    fn validate_rejects_child_caixa_with_uppercase() {
7872        // The canonical "I copied the Servico's display name verbatim"
7873        // typo — child caixa names are lowercase per K8s DNS-1123 label
7874        // rule. The diagnostic names the offending name and suggests the
7875        // lower-cased fix in one edit, mirroring the
7876        // `rejects_membro_caixa_with_uppercase` gate's shape (3f9d7a0).
7877        let s = SupervisorSpec {
7878            children: vec![child("Worker", "^0.1", RestartPolicy::Permanent)],
7879            ..SupervisorSpec::default()
7880        };
7881        let err = s.validate().unwrap_err();
7882        let SupervisorError::ChildCaixaInvalid { caixa, reason } = err else {
7883            panic!("expected ChildCaixaInvalid, got other variant");
7884        };
7885        assert_eq!(caixa, "Worker");
7886        assert!(
7887            reason.contains("uppercase"),
7888            "diagnostic must name the violation as `uppercase` (got: {reason:?})"
7889        );
7890        assert!(
7891            reason.contains("\"worker\""),
7892            "diagnostic must suggest the lower-cased fix verbatim (got: {reason:?})"
7893        );
7894    }
7895
7896    #[test]
7897    fn validate_rejects_child_caixa_with_underscore() {
7898        // The canonical "I'm thinking of a Python module / Postgres
7899        // table" leak — `_` is forbidden by every DNS-1123 / DNS-1035
7900        // label schema. K8s rejects `metadata.name: my_worker` at
7901        // admission time with an opaque `field is invalid` (no source-
7902        // citing diagnostic). The gate moves it to caixa-build time.
7903        let s = SupervisorSpec {
7904            children: vec![child("my_worker", "^0.1", RestartPolicy::Permanent)],
7905            ..SupervisorSpec::default()
7906        };
7907        let err = s.validate().unwrap_err();
7908        assert!(
7909            matches!(
7910                err,
7911                SupervisorError::ChildCaixaInvalid { ref caixa, ref reason }
7912                    if caixa == "my_worker" && reason.contains('_')
7913            ),
7914            "got {err:?}"
7915        );
7916    }
7917
7918    #[test]
7919    fn validate_rejects_child_caixa_with_dot() {
7920        // A `:children :caixa` entry is a single DNS-1123 label, not a
7921        // subdomain. The K8s Service / ComputeUnit `metadata.name` rules
7922        // forbid dots. Same shape as `rejects_membro_caixa_with_dot`
7923        // (3f9d7a0) on the peer name axis.
7924        let s = SupervisorSpec {
7925            children: vec![child("team.worker", "^0.1", RestartPolicy::Permanent)],
7926            ..SupervisorSpec::default()
7927        };
7928        let err = s.validate().unwrap_err();
7929        assert!(
7930            matches!(
7931                err,
7932                SupervisorError::ChildCaixaInvalid { ref caixa, ref reason }
7933                    if caixa == "team.worker" && reason.contains('.')
7934            ),
7935            "got {err:?}"
7936        );
7937    }
7938
7939    #[test]
7940    fn validate_rejects_child_caixa_with_leading_hyphen() {
7941        // DNS-1123 / DNS-1035 boundary rule: labels must start and end
7942        // with an alphanumeric. The K8s apiserver rejects `-worker`
7943        // outright; the renderer would emit a `metadata.name: "-worker"`
7944        // that fails admission far from the source caixa.lisp.
7945        let s = SupervisorSpec {
7946            children: vec![child("-worker", "^0.1", RestartPolicy::Permanent)],
7947            ..SupervisorSpec::default()
7948        };
7949        let err = s.validate().unwrap_err();
7950        assert!(
7951            matches!(
7952                err,
7953                SupervisorError::ChildCaixaInvalid { ref caixa, ref reason }
7954                    if caixa == "-worker" && reason.contains("start and end")
7955            ),
7956            "got {err:?}"
7957        );
7958    }
7959
7960    #[test]
7961    fn validate_rejects_child_caixa_with_trailing_hyphen() {
7962        // The symmetric arm of the boundary rule. Pin separately so
7963        // both ends of the label are covered against a future relaxation
7964        // that only checks one boundary.
7965        let s = SupervisorSpec {
7966            children: vec![child("worker-", "^0.1", RestartPolicy::Permanent)],
7967            ..SupervisorSpec::default()
7968        };
7969        let err = s.validate().unwrap_err();
7970        assert!(
7971            matches!(
7972                err,
7973                SupervisorError::ChildCaixaInvalid { ref caixa, .. }
7974                    if caixa == "worker-"
7975            ),
7976            "got {err:?}"
7977        );
7978    }
7979
7980    #[test]
7981    fn validate_rejects_child_caixa_with_unicode() {
7982        // DNS-1123 is ASCII-only; IDN must be pre-encoded as Punycode
7983        // (`xn--…`) by the author before it reaches K8s. The byte-by-
7984        // byte ASCII validity check rejects multi-byte UTF-8 sequences
7985        // by the first byte that fails the `[a-z0-9-]` predicate.
7986        let s = SupervisorSpec {
7987            children: vec![child("café", "^0.1", RestartPolicy::Permanent)],
7988            ..SupervisorSpec::default()
7989        };
7990        let err = s.validate().unwrap_err();
7991        assert!(
7992            matches!(
7993                err,
7994                SupervisorError::ChildCaixaInvalid { ref caixa, .. }
7995                    if caixa == "café"
7996            ),
7997            "got {err:?}"
7998        );
7999    }
8000
8001    #[test]
8002    fn validate_rejects_child_caixa_with_whitespace() {
8003        // Whitespace is the canonical "I pasted from a sketch / doc"
8004        // footgun. The apiserver rejects every `metadata.name` value
8005        // carrying whitespace; pin the gate fires at the right boundary.
8006        let s = SupervisorSpec {
8007            children: vec![child("my worker", "^0.1", RestartPolicy::Permanent)],
8008            ..SupervisorSpec::default()
8009        };
8010        let err = s.validate().unwrap_err();
8011        assert!(
8012            matches!(
8013                err,
8014                SupervisorError::ChildCaixaInvalid { ref caixa, .. }
8015                    if caixa == "my worker"
8016            ),
8017            "got {err:?}"
8018        );
8019    }
8020
8021    #[test]
8022    fn validate_rejects_child_caixa_too_long() {
8023        // The 64-byte boundary pin. DNS-1123 / DNS-1035 cap labels at
8024        // 63 bytes; the K8s apiserver rejects every `metadata.name`
8025        // axis over the limit at admission time. The diagnostic names
8026        // both the cap and the actual length so the author can shorten
8027        // in one edit, mirroring `rejects_membro_caixa_too_long`
8028        // (3f9d7a0) and `rejects_placement_cluster_too_long` (6cbb900).
8029        let too_long = "a".repeat(64);
8030        let s = SupervisorSpec {
8031            children: vec![child(&too_long, "^0.1", RestartPolicy::Permanent)],
8032            ..SupervisorSpec::default()
8033        };
8034        let err = s.validate().unwrap_err();
8035        let SupervisorError::ChildCaixaInvalid { caixa, reason } = err else {
8036            panic!("expected ChildCaixaInvalid, got other variant");
8037        };
8038        assert_eq!(caixa, too_long);
8039        assert!(
8040            reason.contains("63"),
8041            "diagnostic must name the 63-byte cap (got: {reason:?})"
8042        );
8043        assert!(
8044            reason.contains("64"),
8045            "diagnostic must name the actual length (got: {reason:?})"
8046        );
8047    }
8048
8049    #[test]
8050    fn child_caixa_max_length_validates() {
8051        // The 63-byte boundary control pin — exactly-at-the-cap is
8052        // accepted, mirroring `membro_caixa_max_length_validates`
8053        // (3f9d7a0) and `placement_cluster_max_length_validates`
8054        // (6cbb900). Pinned separately so a future off-by-one tightening
8055        // surfaces here.
8056        let max_label = "a".repeat(63);
8057        let s = SupervisorSpec {
8058            children: vec![child(&max_label, "^0.1", RestartPolicy::Permanent)],
8059            ..SupervisorSpec::default()
8060        };
8061        s.validate().unwrap();
8062    }
8063
8064    #[test]
8065    fn validate_accepts_canonical_child_caixa_forms() {
8066        // The realistic shapes a supervised child's `:caixa` carries —
8067        // single-word `worker`, version-suffixed `cache-v2`, single-char
8068        // `a`, two-char `db`, digit-start `2-pool`, longer hyphen-joined
8069        // `payment-retry`, all-digit `0`. Pin every leg so a future
8070        // tightening (e.g. requiring a leading lowercase letter) surfaces
8071        // here as a test failure. Mirrors `accepts_canonical_membro_caixa_forms`
8072        // (3f9d7a0) and `accepts_canonical_placement_cluster_forms`
8073        // (6cbb900).
8074        for form in [
8075            "worker",
8076            "cache-v2",
8077            "a",
8078            "db",
8079            "2-pool",
8080            "payment-retry",
8081            "0",
8082        ] {
8083            let s = SupervisorSpec {
8084                children: vec![child(form, "^0.1", RestartPolicy::Permanent)],
8085                ..SupervisorSpec::default()
8086            };
8087            s.validate()
8088                .unwrap_or_else(|e| panic!("canonical form {form:?} must validate, got {e:?}"));
8089        }
8090    }
8091
8092    #[test]
8093    fn child_caixa_empty_takes_precedence_over_invalid() {
8094        // Order pin: the existing `EmptyChildName` diagnostic (which
8095        // doesn't try to parse the DNS-1123 shape) fires before the new
8096        // `ChildCaixaInvalid` per-axis gate, so an empty `:caixa` keeps
8097        // its narrower error message — `is_dns_1123_label` would reject
8098        // the empty string too (boundary check on the first byte), but
8099        // the empty-string arm is the more self-locating diagnostic for
8100        // the author. Same ordering discipline as
8101        // `membro_caixa_empty_takes_precedence_over_invalid` in
8102        // aplicacao.rs.
8103        let s = SupervisorSpec {
8104            children: vec![child("", "^0.1", RestartPolicy::Permanent)],
8105            ..SupervisorSpec::default()
8106        };
8107        let err = s.validate().unwrap_err();
8108        assert_eq!(err, SupervisorError::EmptyChildName);
8109    }
8110
8111    #[test]
8112    fn child_caixa_invalid_fires_before_versao_check() {
8113        // Order pin: the per-axis shape gate runs inline before the
8114        // per-entry versao check, so a malformed `:caixa` on an entry
8115        // whose `:versao` would also fail surfaces the more self-
8116        // locating name-axis diagnostic first. Parallel to
8117        // `membro_versao_invalid_fires_before_duplicate_check` (9888b13)
8118        // and `placement_cluster_invalid_fires_before_duplicate_check`
8119        // (6cbb900).
8120        let s = SupervisorSpec {
8121            children: vec![child("My_Worker", "", RestartPolicy::Permanent)],
8122            ..SupervisorSpec::default()
8123        };
8124        let err = s.validate().unwrap_err();
8125        assert!(
8126            matches!(
8127                err,
8128                SupervisorError::ChildCaixaInvalid { ref caixa, .. } if caixa == "My_Worker"
8129            ),
8130            "got {err:?}"
8131        );
8132    }
8133
8134    #[test]
8135    fn child_caixa_invalid_fires_before_duplicate_check() {
8136        // Order pin: a malformed name on a non-duplicate entry surfaces
8137        // its own diagnostic, even when a later entry would otherwise
8138        // collapse onto an earlier name. The per-entry shape gate runs
8139        // inline before the duplicate-key HashSet insert, mirroring
8140        // `placement_cluster_invalid_fires_before_duplicate_check`
8141        // (6cbb900).
8142        let s = SupervisorSpec {
8143            children: vec![
8144                child("Worker", "^0.1", RestartPolicy::Permanent),
8145                child("cache", "^0.1", RestartPolicy::Transient),
8146                child("worker", "^0.2", RestartPolicy::Permanent), // would otherwise raise DuplicateChildCaixa
8147            ],
8148            ..SupervisorSpec::default()
8149        };
8150        let err = s.validate().unwrap_err();
8151        assert!(
8152            matches!(
8153                err,
8154                SupervisorError::ChildCaixaInvalid { ref caixa, .. } if caixa == "Worker"
8155            ),
8156            "got {err:?}"
8157        );
8158    }
8159
8160    #[test]
8161    fn child_caixa_invalid_diagnostic_carries_offending_caixa() {
8162        // The diagnostic-shape pin: the error names the offending
8163        // `:caixa` verbatim plus a non-empty parser-shaped `reason` so
8164        // the author can grep their caixa.lisp without re-running the
8165        // build. Mirrors the diagnostic-shape sweep on every prior
8166        // value-shape gate (3f9d7a0, 6cbb900, c7d05ec).
8167        let s = SupervisorSpec {
8168            children: vec![child("My_Worker", "^0.1", RestartPolicy::Permanent)],
8169            ..SupervisorSpec::default()
8170        };
8171        let err = s.validate().unwrap_err();
8172        let SupervisorError::ChildCaixaInvalid { caixa, reason } = err else {
8173            panic!("expected ChildCaixaInvalid, got other variant");
8174        };
8175        assert_eq!(caixa, "My_Worker");
8176        assert!(
8177            !reason.is_empty(),
8178            "ChildCaixaInvalid `reason` must carry the parser's wording verbatim"
8179        );
8180    }
8181
8182    // ── value-shape: zero restart_window + duplicate child names ──────────
8183
8184    #[test]
8185    fn validate_accepts_none_restart_window() {
8186        // Omitted `:restart-window` is the "never reset" sentinel —
8187        // valid by design. Mirrors :limits axes where None = unbounded.
8188        let s = SupervisorSpec {
8189            restart_window: None,
8190            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8191            ..SupervisorSpec::default()
8192        };
8193        s.validate().unwrap();
8194    }
8195
8196    #[test]
8197    fn validate_rejects_zero_restart_window() {
8198        // Same "0 means the opposite of what you think" footgun closed
8199        // for :politicas :timeout (Envoy treats 0s as infinite) and
8200        // :limits :wall-clock (wasmtime traps before the call starts).
8201        // Erlang/OTP's MaxIntensity/Period requires Period > 0.
8202        let s = SupervisorSpec {
8203            restart_window: Some(Duration::ZERO),
8204            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8205            ..SupervisorSpec::default()
8206        };
8207        assert_eq!(
8208            s.validate().unwrap_err(),
8209            SupervisorError::RestartWindowZero
8210        );
8211    }
8212
8213    // ── value-shape: integer-ms canonical-form on :restart-window ─────────
8214    //
8215    // The fourth (and last) typed-`Duration` axis in caixa-core to get
8216    // the integer-millisecond canonical-form gate — peer with
8217    // `:limits :wall-clock` (82fc3ef), `:politicas :timeout` (a4ae535),
8218    // and `:politicas :circuit-breaker :window` (a4ae535). The serde
8219    // path is already gated at the shared codec layer (see
8220    // `restart_window_serde_rejects_fractional_seconds`); this arm
8221    // closes the programmatic-struct-literal path the codec gate can't
8222    // see.
8223
8224    #[test]
8225    fn validate_rejects_sub_millisecond_restart_window() {
8226        // The fail-before-pass-after pin: a programmatic
8227        // `Duration::from_micros(1500)` (= 1_500_000 ns) silently passed
8228        // `validate` on every pre-gate codebase, then truncated to
8229        // `as_millis() == 1` on first serialize — the shared codec
8230        // emits `"1ms"`, parses it back to `Duration::from_millis(1)` =
8231        // 1_000_000 ns, the typed `restart_window` no longer matches
8232        // its rendered form.
8233        let s = SupervisorSpec {
8234            restart_window: Some(Duration::from_micros(1500)),
8235            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8236            ..SupervisorSpec::default()
8237        };
8238        match s.validate().unwrap_err() {
8239            SupervisorError::RestartWindowNotCanonical { window } => {
8240                assert_eq!(window, Duration::from_micros(1500));
8241            }
8242            other => panic!("expected RestartWindowNotCanonical, got {other:?}"),
8243        }
8244    }
8245
8246    #[test]
8247    fn validate_rejects_one_nanosecond_restart_window() {
8248        // The far-sub-ms case: `Duration::from_nanos(1)` is non-zero
8249        // (so `RestartWindowZero` doesn't fire) but `as_millis() == 0`,
8250        // so the shared codec emits the literal `"0s"` — the next
8251        // serde round-trip would parse back to `Duration::ZERO`, which
8252        // the `RestartWindowZero` arm then rejects on re-validate. The
8253        // canonical-form gate at this layer surfaces a self-locating
8254        // diagnostic naming the offending Duration verbatim rather
8255        // than a downstream `RestartWindowZero` whose remediation
8256        // points at omitting the slot.
8257        let s = SupervisorSpec {
8258            restart_window: Some(Duration::from_nanos(1)),
8259            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8260            ..SupervisorSpec::default()
8261        };
8262        match s.validate().unwrap_err() {
8263            SupervisorError::RestartWindowNotCanonical { window } => {
8264                assert_eq!(window, Duration::from_nanos(1));
8265            }
8266            other => panic!("expected RestartWindowNotCanonical, got {other:?}"),
8267        }
8268    }
8269
8270    #[test]
8271    fn validate_rejects_nanosecond_past_canonical_boundary_restart_window() {
8272        // The 1-ns-past-1ms boundary case: a `Duration` carrying
8273        // 1_000_001 ns is structurally past the integer-ms granularity
8274        // floor — `subsec_nanos() % 1_000_000 == 1`. The codec round-
8275        // trip would truncate to `1ms` and the consumer would observe
8276        // a 1-ns drift on every emit. Same boundary the peer
8277        // `validate_rejects_nanosecond_past_canonical_boundary` test
8278        // in limits.rs pins for the `:limits :wall-clock` axis.
8279        let w = Duration::from_nanos(1_000_001);
8280        let s = SupervisorSpec {
8281            restart_window: Some(w),
8282            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8283            ..SupervisorSpec::default()
8284        };
8285        assert_eq!(
8286            s.validate().unwrap_err(),
8287            SupervisorError::RestartWindowNotCanonical { window: w }
8288        );
8289    }
8290
8291    #[test]
8292    fn validate_accepts_integer_millisecond_restart_window_values() {
8293        // The positive-control sweep: every `Duration` the shared
8294        // codec can round-trip losslessly — the canonical
8295        // `<integer>{ms,s,m,h}` set the codec's `render` / `parse`
8296        // pair emits and accepts — passes `validate` without
8297        // surfacing the new canonical-form arm. Mirrors
8298        // `validate_accepts_integer_millisecond_wall_clock_values` on
8299        // the sibling `:limits :wall-clock` axis.
8300        for w in [
8301            Duration::from_millis(1),
8302            Duration::from_millis(500),
8303            Duration::from_millis(1500),
8304            Duration::from_secs(1),
8305            Duration::from_secs(30),
8306            Duration::from_secs(60),
8307            Duration::from_secs(120),
8308            Duration::from_secs(3600),
8309        ] {
8310            let s = SupervisorSpec {
8311                restart_window: Some(w),
8312                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8313                ..SupervisorSpec::default()
8314            };
8315            s.validate()
8316                .unwrap_or_else(|e| panic!("integer-ms {w:?} must validate, got {e:?}"));
8317        }
8318    }
8319
8320    #[test]
8321    fn validate_restart_window_zero_takes_precedence_over_canonical_gate() {
8322        // Cross-arm ordering pin: `Duration::ZERO` has
8323        // `subsec_nanos() == 0` and would otherwise pass the
8324        // canonical-form arm — the zero-floor arm must fire first so
8325        // the more self-locating `RestartWindowZero` diagnostic (with
8326        // its omit-axis remediation directly named) leads. Same
8327        // posture every peer zero-then-shape gate uses
8328        // (`WallClockZero` → `WallClockNotCanonical`,
8329        // `PolicyTimeoutZero` → `PolicyTimeoutNotCanonical`,
8330        // `PolicyBreakerZeroWindow` → `PolicyBreakerWindowNotCanonical`).
8331        let s = SupervisorSpec {
8332            restart_window: Some(Duration::ZERO),
8333            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8334            ..SupervisorSpec::default()
8335        };
8336        assert_eq!(
8337            s.validate().unwrap_err(),
8338            SupervisorError::RestartWindowZero
8339        );
8340    }
8341
8342    #[test]
8343    fn restart_window_canonical_diagnostic_carries_offending_duration() {
8344        // Diagnostic-shape pin: the canonical-form arm names the
8345        // offending `Duration` verbatim so the author's grep lands on
8346        // the field's value, not a generic "duration not canonical"
8347        // message. Same shape every other typed-canonical-form arm
8348        // on this surface carries (`WallClockNotCanonical` carries
8349        // the offending `Duration` verbatim,
8350        // `PolicyTimeoutNotCanonical` carries the offending
8351        // `Duration` verbatim).
8352        let w = Duration::from_micros(500);
8353        let s = SupervisorSpec {
8354            restart_window: Some(w),
8355            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8356            ..SupervisorSpec::default()
8357        };
8358        let err = s.validate().unwrap_err();
8359        let msg = err.to_string();
8360        assert!(
8361            msg.contains("500"),
8362            "diagnostic must carry the offending magnitude verbatim (got {msg:?})"
8363        );
8364        assert!(
8365            msg.contains("sub-millisecond"),
8366            "diagnostic must name the sub-millisecond residue class (got {msg:?})"
8367        );
8368    }
8369
8370    #[test]
8371    fn restart_window_validated_value_round_trips_through_codec() {
8372        // The structural property the canonical-ms gate enforces:
8373        // every `SupervisorSpec::restart_window` past
8374        // `SupervisorSpec::validate` round-trips losslessly through
8375        // the shared duration codec (serialize → string →
8376        // deserialize → equal value). Pin this end-to-end so a future
8377        // change to either side (the validate gate's accepted
8378        // granularity, the codec's parse/render unit set) that breaks
8379        // the alignment surfaces here. Peer of
8380        // `wall_clock_validated_value_round_trips_through_codec` on
8381        // the sibling `:limits :wall-clock` axis.
8382        for w in [
8383            Duration::from_millis(1),
8384            Duration::from_millis(1500),
8385            Duration::from_secs(30),
8386            Duration::from_secs(3600),
8387        ] {
8388            let s = SupervisorSpec {
8389                restart_window: Some(w),
8390                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8391                ..SupervisorSpec::default()
8392            };
8393            s.validate().unwrap();
8394            let json = serde_json::to_string(&s).unwrap();
8395            let back: SupervisorSpec = serde_json::from_str(&json).unwrap();
8396            assert_eq!(back.restart_window, Some(w));
8397        }
8398    }
8399
8400    // ── value-shape: upper cap on :restart-window ─────────────────────────
8401    //
8402    // The fourth (and last) typed-`Duration` axis in caixa-core to get
8403    // the 1h upper cap — peer with `:limits :wall-clock` (51e0dbd),
8404    // `:politicas :timeout` (2e8ee7e), and `:politicas
8405    // :circuit-breaker :window` (379a814). Brackets the typed
8406    // `:restart-window` axis structurally: every validated value lies
8407    // in `1ms..=SUPERVISOR_RESTART_WINDOW_MAX`, integer-millisecond
8408    // granularity, closing the
8409    // rolling-window-degenerates-to-lifetime-counter footgun the prior
8410    // zero-floor-and-canonical-form-only checks left open.
8411
8412    #[test]
8413    fn validate_rejects_restart_window_above_cap() {
8414        // The fail-before-pass-after pin: 3601s = 1h + 1s is
8415        // structurally one canonical-tick past the
8416        // [`SUPERVISOR_RESTART_WINDOW_MAX`] ceiling (1h = 3600s) — an
8417        // integer-millisecond magnitude the canonical-form arm above
8418        // accepts cleanly, that the shared duration codec round-trips
8419        // losslessly as `"3601s"`, and that silently passed validate on
8420        // every pre-gate codebase because the typed slot's only checks
8421        // were the zero-floor and canonical-form arms. The runtime
8422        // substrate consuming the value (Erlang/OTP's MaxIntensity/
8423        // Period reconciler, the future wasm-operator's per-supervisor
8424        // restart-intensity counter) reaches for a `Duration` so long
8425        // no realistic restart-recovery pattern resets the counter,
8426        // far from the source caixa.lisp.
8427        let w = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_secs(1);
8428        let s = SupervisorSpec {
8429            restart_window: Some(w),
8430            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8431            ..SupervisorSpec::default()
8432        };
8433        assert_eq!(
8434            s.validate().unwrap_err(),
8435            SupervisorError::RestartWindowExceedsCap { window: w }
8436        );
8437    }
8438
8439    #[test]
8440    fn validate_rejects_restart_window_one_millisecond_above_cap() {
8441        // Boundary case: exactly 1ms past the cap (the granularity the
8442        // canonical-form gate enforces). Catches a future "strictly
8443        // less than" half-measure and pins the diagnostic to name the
8444        // offending `Duration` verbatim. Peer of
8445        // `validate_rejects_wall_clock_one_millisecond_above_cap` /
8446        // `rejects_policy_timeout_one_millisecond_above_cap` /
8447        // `rejects_circuit_breaker_window_one_millisecond_above_cap`
8448        // on the sibling typed-`Duration` axes' top edges.
8449        let w = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_millis(1);
8450        let s = SupervisorSpec {
8451            restart_window: Some(w),
8452            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8453            ..SupervisorSpec::default()
8454        };
8455        assert_eq!(
8456            s.validate().unwrap_err(),
8457            SupervisorError::RestartWindowExceedsCap { window: w }
8458        );
8459    }
8460
8461    #[test]
8462    fn validate_rejects_restart_window_far_above_cap() {
8463        // The "obvious authoring footgun" case: a `(:restart-window "24h")`,
8464        // `(:restart-window "7d")`, or any "I want a lifetime counter
8465        // but wrote a `<integer>h` magnitude anyway" typo — values the
8466        // canonical-form arm accepts as integer-millisecond magnitudes,
8467        // the codec round-trips losslessly through serde, but the
8468        // operator's `MaxIntensity / Period` reconciler cannot honor
8469        // as a meaningful rolling window. Until this gate landed
8470        // validate accepted them. Pin the common above-cap values (24h,
8471        // 7d, ~11.5d) so a future relaxation that drops the upper bound
8472        // surfaces here.
8473        for w in [
8474            Duration::from_secs(86_400),    // 24h
8475            Duration::from_secs(604_800),   // 7d
8476            Duration::from_secs(1_000_000), // ~11.5 days
8477        ] {
8478            let s = SupervisorSpec {
8479                restart_window: Some(w),
8480                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8481                ..SupervisorSpec::default()
8482            };
8483            assert_eq!(
8484                s.validate().unwrap_err(),
8485                SupervisorError::RestartWindowExceedsCap { window: w }
8486            );
8487        }
8488    }
8489
8490    #[test]
8491    fn validate_accepts_restart_window_at_cap() {
8492        // The boundary value — exactly [`SUPERVISOR_RESTART_WINDOW_MAX`]
8493        // (1h) — must validate. The cap is inclusive on the top edge,
8494        // matching the [`crate::LIMITS_WALL_CLOCK_MAX`] /
8495        // [`crate::POLICY_TIMEOUT_MAX`] /
8496        // [`crate::POLICY_BREAKER_WINDOW_MAX`] discipline on the sibling
8497        // capped axes. Pin the boundary explicitly so a future
8498        // off-by-one tightening (`>= SUPERVISOR_RESTART_WINDOW_MAX`
8499        // instead of `>`) surfaces here as a test failure rather than a
8500        // silent contract narrowing.
8501        let s = SupervisorSpec {
8502            restart_window: Some(SUPERVISOR_RESTART_WINDOW_MAX),
8503            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8504            ..SupervisorSpec::default()
8505        };
8506        s.validate()
8507            .expect("restart_window == SUPERVISOR_RESTART_WINDOW_MAX must validate");
8508    }
8509
8510    #[test]
8511    fn validate_accepts_restart_window_typical_values() {
8512        // The documented Erlang/OTP / Elixir / Riak Core / RabbitMQ
8513        // per-supervisor production-playbook band positive-control
8514        // sweep — every value Learn You Some Erlang's `{intensity, 5,
8515        // 60}` worker-supervisor `Period = 60s` default, Elixir's
8516        // `Supervisor` `max_seconds: 5` default, OTP's `supervisor`
8517        // callback module `MaxT = 5..=60` typical, Riak Core's `MaxT ∈
8518        // 10s..=300s`, and RabbitMQ broker-supervisor `MaxT = 5s`
8519        // default recommend (5s..=300s) must pass, plus a sweep
8520        // through the long-tail-flaky-pool band (5m, 15m, 30m, 1h) the
8521        // cap accepts. Mirrors `validate_accepts_wall_clock_typical_values`
8522        // on the sibling `:limits :wall-clock` axis.
8523        for w in [
8524            Duration::from_millis(1),
8525            Duration::from_millis(500),
8526            Duration::from_secs(1),
8527            Duration::from_secs(5),  // RabbitMQ broker-supervisor default
8528            Duration::from_secs(10), // Riak Core lower
8529            Duration::from_secs(30),
8530            Duration::from_secs(60),  // Learn You Some Erlang default
8531            Duration::from_secs(120), // OTP supervisor MaxT typical
8532            Duration::from_secs(300), // Riak Core upper
8533            Duration::from_secs(900), // 15m
8534            Duration::from_secs(1800),
8535            Duration::from_secs(3600), // exactly 1h, the cap
8536        ] {
8537            let s = SupervisorSpec {
8538                restart_window: Some(w),
8539                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8540                ..SupervisorSpec::default()
8541            };
8542            s.validate()
8543                .unwrap_or_else(|e| panic!("restart_window={w:?} must validate; got {e:?}"));
8544        }
8545    }
8546
8547    #[test]
8548    fn restart_window_zero_takes_precedence_over_cap() {
8549        // The cross-arm ordering pin: `Duration::ZERO` is structurally
8550        // outside both `>= 1ms` (zero-floor) and `<=
8551        // SUPERVISOR_RESTART_WINDOW_MAX` (cap), but the zero-floor
8552        // diagnostic is the more self-locating one (it directly names
8553        // the omit-axis remediation), so the validate gate must fire
8554        // on zero first. Same shape every other zero-then-cap ordering
8555        // on this surface uses (`WallClockZero` then
8556        // `WallClockExceedsCap`, `PolicyTimeoutZero` then
8557        // `PolicyTimeoutExceedsCap`, `PolicyBreakerZeroWindow` then
8558        // `PolicyBreakerWindowExceedsCap`).
8559        let s = SupervisorSpec {
8560            restart_window: Some(Duration::ZERO),
8561            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8562            ..SupervisorSpec::default()
8563        };
8564        assert_eq!(
8565            s.validate().unwrap_err(),
8566            SupervisorError::RestartWindowZero,
8567            "Duration::ZERO must surface the zero-floor diagnostic, not the cap diagnostic"
8568        );
8569    }
8570
8571    #[test]
8572    fn restart_window_canonical_takes_precedence_over_cap() {
8573        // The cross-arm ordering pin: a `Duration` that is *both*
8574        // sub-millisecond (non-canonical-form) and structurally above
8575        // the cap surfaces the canonical-form diagnostic first,
8576        // because the round-trip-shape break is the more fundamental
8577        // issue (the value can't even round-trip through the codec,
8578        // so the cap diagnostic naming `1ms..=1h` would be misleading
8579        // — there's no integer-ms form of the offending value). Pin
8580        // the order so a future refactor that reorders the arms
8581        // surfaces here as a test failure rather than a silent
8582        // diagnostic regression. Peer of
8583        // `wall_clock_canonical_takes_precedence_over_cap` /
8584        // `policy_timeout_canonical_takes_precedence_over_cap`.
8585        let w = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_nanos(1);
8586        let s = SupervisorSpec {
8587            restart_window: Some(w),
8588            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8589            ..SupervisorSpec::default()
8590        };
8591        assert_eq!(
8592            s.validate().unwrap_err(),
8593            SupervisorError::RestartWindowNotCanonical { window: w },
8594            "sub-ms above-cap value must surface the canonical-form diagnostic, not the cap diagnostic"
8595        );
8596    }
8597
8598    #[test]
8599    fn max_restarts_cap_takes_precedence_over_restart_window_cap() {
8600        // The cross-arm ordering pin between the `:max-restarts` cap
8601        // and the sibling `:restart-window` cap. A supervisor carrying
8602        // both an over-cap `max_restarts` AND an over-cap window must
8603        // surface the `MaxRestartsExceedsCap` diagnostic first — the
8604        // cap arm is wired immediately after the zero-restart arm and
8605        // strictly before every window-axis arm (zero / canonical /
8606        // cap), so the offending value the diagnostic names matches
8607        // the order the author would discover the gates by reading
8608        // top-to-bottom through `SupervisorSpec::validate`. Pin the
8609        // order so a future refactor that reorders the arms surfaces
8610        // here as a test failure rather than a silent diagnostic
8611        // regression. Peer of
8612        // `max_restarts_cap_takes_precedence_over_restart_window_gates`
8613        // on the sibling zero / canonical window arms.
8614        let w = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_secs(1);
8615        let s = SupervisorSpec {
8616            max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
8617            restart_window: Some(w),
8618            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8619            ..SupervisorSpec::default()
8620        };
8621        assert_eq!(
8622            s.validate().unwrap_err(),
8623            SupervisorError::MaxRestartsExceedsCap {
8624                max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
8625            },
8626            "over-cap max_restarts must surface the cap diagnostic before any window-axis diagnostic"
8627        );
8628    }
8629
8630    #[test]
8631    fn restart_window_cap_diagnostic_carries_offending_value() {
8632        // The diagnostic-shape pin: the offending `Duration` is
8633        // carried verbatim into the
8634        // [`SupervisorError::RestartWindowExceedsCap`] variant so the
8635        // surfaced error message names the value the author wrote,
8636        // not just the cap. Same self-locating diagnostic shape every
8637        // other typed-cap arm on this surface carries
8638        // (`WallClockExceedsCap` carries the offending `Duration`
8639        // verbatim, `PolicyTimeoutExceedsCap` carries the offending
8640        // `Duration` verbatim, `PolicyBreakerWindowExceedsCap` carries
8641        // the offending `Duration` verbatim).
8642        let w = Duration::from_secs(7200); // 2h
8643        let s = SupervisorSpec {
8644            restart_window: Some(w),
8645            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8646            ..SupervisorSpec::default()
8647        };
8648        let err = s.validate().unwrap_err();
8649        assert!(
8650            matches!(err, SupervisorError::RestartWindowExceedsCap { window } if window == w),
8651            "got {err:?}"
8652        );
8653        let msg = err.to_string();
8654        assert!(
8655            msg.contains("7200"),
8656            ":supervisor :restart-window cap diagnostic must carry the offending value verbatim (got: {msg})"
8657        );
8658    }
8659
8660    #[test]
8661    fn supervisor_restart_window_cap_pins_canonical_value() {
8662        // The SUPERVISOR_RESTART_WINDOW_MAX constant pins the value at
8663        // exactly 1 hour (3600s = 3_600_000ms) — the largest unit the
8664        // shared duration codec emits as a clean canonical string
8665        // (`"<n>h"`). Pinning the literal value here surfaces a future
8666        // drift (a relaxation to 24h, a tightening to 5m) as a
8667        // deliberate test edit, not a silent contract narrowing.
8668        //
8669        // The four typed-`Duration` caps on the validation surface
8670        // (`LIMITS_WALL_CLOCK_MAX` per-process, `POLICY_TIMEOUT_MAX`
8671        // per-edge, `POLICY_BREAKER_WINDOW_MAX` per-breaker,
8672        // `SUPERVISOR_RESTART_WINDOW_MAX` per-supervisor) share a
8673        // single uniform top edge at the codec's largest emitted unit
8674        // — a structural-property invariant the equality assertions
8675        // here enshrine, so a future drift on any of the four
8676        // surfaces as a deliberate test edit. Same shape every other
8677        // typed-cap value pin uses
8678        // (`wall_clock_cap_pins_canonical_value`,
8679        // `policy_timeout_cap_pins_canonical_value`,
8680        // `circuit_breaker_window_cap_pins_canonical_value`).
8681        assert_eq!(SUPERVISOR_RESTART_WINDOW_MAX, Duration::from_secs(3600));
8682        assert_eq!(SUPERVISOR_RESTART_WINDOW_MAX.as_millis(), 3_600_000);
8683        assert_eq!(SUPERVISOR_RESTART_WINDOW_MAX, crate::LIMITS_WALL_CLOCK_MAX);
8684        assert_eq!(SUPERVISOR_RESTART_WINDOW_MAX, crate::POLICY_TIMEOUT_MAX);
8685        assert_eq!(
8686            SUPERVISOR_RESTART_WINDOW_MAX,
8687            crate::POLICY_BREAKER_WINDOW_MAX
8688        );
8689    }
8690
8691    #[test]
8692    fn restart_window_cap_value_round_trips_through_codec() {
8693        // The codec round-trip property the cap arm preserves: the
8694        // [`SUPERVISOR_RESTART_WINDOW_MAX`] constant itself round-trips
8695        // through the shared duration codec — every value at the cap
8696        // serializes to the canonical `"1h"` form and parses back
8697        // identically. Pin the round-trip so a future change to the
8698        // codec's unit set or to the cap's magnitude that breaks the
8699        // round-trip property surfaces here. Peer of
8700        // `wall_clock_cap_value_round_trips_through_codec` on the
8701        // sibling `:limits :wall-clock` axis.
8702        let s = SupervisorSpec {
8703            restart_window: Some(SUPERVISOR_RESTART_WINDOW_MAX),
8704            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8705            ..SupervisorSpec::default()
8706        };
8707        s.validate().unwrap();
8708        let json = serde_json::to_string(&s).unwrap();
8709        assert!(
8710            json.contains("\"1h\""),
8711            "SUPERVISOR_RESTART_WINDOW_MAX must serialize to the canonical `\"1h\"` form (got {json})"
8712        );
8713        let back: SupervisorSpec = serde_json::from_str(&json).unwrap();
8714        assert_eq!(back.restart_window, Some(SUPERVISOR_RESTART_WINDOW_MAX));
8715    }
8716
8717    #[test]
8718    fn validate_rejects_duplicate_child_caixa() {
8719        // Two children with the same :caixa render to two ComputeUnits
8720        // with the same name in the cluster's HelmRelease values —
8721        // one silently overwrites the other. Erlang/OTP's child_spec.id
8722        // is required-unique per supervisor; same set-not-multiset
8723        // discipline applied here as for :membros / :placement
8724        // :clusters / :entrada :paths.
8725        let s = SupervisorSpec {
8726            children: vec![
8727                child("worker", "^0.1", RestartPolicy::Permanent),
8728                child("cache", "^0.1", RestartPolicy::Transient),
8729                child("worker", "^0.2", RestartPolicy::Permanent),
8730            ],
8731            ..SupervisorSpec::default()
8732        };
8733        let err = s.validate().unwrap_err();
8734        assert!(
8735            matches!(err, SupervisorError::DuplicateChildCaixa { ref caixa } if caixa == "worker"),
8736            "got {err:?}"
8737        );
8738    }
8739
8740    #[test]
8741    fn validate_duplicate_child_diagnostic_names_first_collision() {
8742        // Iteration walks the :children list in declaration order —
8743        // the diagnostic names the first repeat, deterministically,
8744        // even when multiple names duplicate.
8745        let s = SupervisorSpec {
8746            children: vec![
8747                child("a", "^0.1", RestartPolicy::Permanent),
8748                child("b", "^0.1", RestartPolicy::Permanent),
8749                child("a", "^0.1", RestartPolicy::Permanent),
8750                child("b", "^0.1", RestartPolicy::Permanent),
8751            ],
8752            ..SupervisorSpec::default()
8753        };
8754        let err = s.validate().unwrap_err();
8755        assert!(
8756            matches!(err, SupervisorError::DuplicateChildCaixa { ref caixa } if caixa == "a"),
8757            "got {err:?}"
8758        );
8759    }
8760
8761    // ── self-supervision cross-slot gate ──────────────────────────
8762
8763    #[test]
8764    fn validate_no_self_supervision_rejects_self_referential_child() {
8765        // A supervisor whose `:children` lists its own `:nome` is a
8766        // one-node reconciliation cycle — rejected, naming the parent.
8767        let children = vec![
8768            child("worker", "^0.1", RestartPolicy::Permanent),
8769            child("orquestra", "^0.1", RestartPolicy::Permanent),
8770        ];
8771        let err = validate_no_self_supervision(&children, "orquestra").unwrap_err();
8772        assert!(
8773            matches!(err, SupervisorError::ChildSupervisesSelf { ref caixa } if caixa == "orquestra"),
8774            "got {err:?}"
8775        );
8776    }
8777
8778    #[test]
8779    fn validate_no_self_supervision_accepts_distinct_children() {
8780        // Positive control: distinct child names (including a child that
8781        // is itself a supervisor — nested trees are valid OTP) pass.
8782        let children = vec![
8783            child("worker", "^0.1", RestartPolicy::Permanent),
8784            child("sub-tree", "^0.1", RestartPolicy::Permanent),
8785        ];
8786        validate_no_self_supervision(&children, "orquestra").unwrap();
8787    }
8788
8789    #[test]
8790    fn validate_no_self_supervision_empty_children_is_ok() {
8791        // SimpleOneForOne / no-static-children supervisors have nothing
8792        // to self-reference — the gate is vacuously satisfied.
8793        validate_no_self_supervision(&[], "orquestra").unwrap();
8794    }
8795
8796    #[test]
8797    fn validate_simple_one_for_one_skips_uniqueness_check() {
8798        // SimpleOneForOne supervisors carry no static children — the
8799        // duplicate-child loop never runs. A zero-window declaration
8800        // on a SimpleOneForOne supervisor still trips the window check
8801        // (window applies to dynamic children too).
8802        let s = SupervisorSpec {
8803            estrategia: RestartStrategy::SimpleOneForOne,
8804            restart_window: None,
8805            children: vec![],
8806            ..SupervisorSpec::default()
8807        };
8808        s.validate().unwrap();
8809        let s_zero = SupervisorSpec {
8810            estrategia: RestartStrategy::SimpleOneForOne,
8811            restart_window: Some(Duration::ZERO),
8812            children: vec![],
8813            ..SupervisorSpec::default()
8814        };
8815        assert_eq!(
8816            s_zero.validate().unwrap_err(),
8817            SupervisorError::RestartWindowZero
8818        );
8819    }
8820
8821    #[test]
8822    fn validate_zero_window_runs_after_max_restarts_check() {
8823        // Pin the order: max_restarts == 0 fires before
8824        // restart_window == 0s, so an author with both wrong sees the
8825        // counter-axis diagnostic first (matches the order in the
8826        // struct and in the doc comment).
8827        let s = SupervisorSpec {
8828            max_restarts: 0,
8829            restart_window: Some(Duration::ZERO),
8830            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8831            ..SupervisorSpec::default()
8832        };
8833        assert_eq!(s.validate().unwrap_err(), SupervisorError::ZeroMaxRestarts);
8834    }
8835
8836    #[test]
8837    fn round_trip_all_strategies() {
8838        for &strat in RestartStrategy::ALL {
8839            // Route the `SimpleOneForOne ↔ non-SimpleOneForOne` fixture-
8840            // shape partition through the [`gen_platform::IsVariant`]
8841            // derive-generated [`RestartStrategy::is_simple_one_for_one`]
8842            // predicate rather than the raw
8843            // `matches!(strat, RestartStrategy::SimpleOneForOne)`
8844            // open-coded pattern-match — same closed-set-typed-enum
8845            // arm-discriminator dispatch discipline the sibling
8846            // [`crate::upgrade::UpgradeInstruction::is_restart`] convergence
8847            // (915a934) extended onto its two paired positive / negated
8848            // `matches!` filter sites, and the sibling
8849            // [`crate::aplicacao::PlacementStrategy`] `IsVariant`-derived
8850            // predicate convergence (766ec63) extended onto the M3 mesh-
8851            // slot per-`:placement` distribution-strategy `matches!`
8852            // discriminator axis. See the sibling
8853            // `supervisor_spec_estrategia_returns_estrategia_verbatim_across_permutations`
8854            // fixture and the peer `manifest::tests::
8855            // caixa_estrategia_and_supervisor_view_reads_through_lifted_estrategia_accessor`
8856            // fixture — all three sites (the last unlifted
8857            // `matches!`-based arm-discriminator axis on the OTP-shape
8858            // supervisor sibling-restart-strategy closed-set typed enum,
8859            // acknowledged in 915a934's Prior-commits footnote as the
8860            // outstanding follow-up) now consult one typed dispatch on
8861            // the substrate primitive.
8862            let s = SupervisorSpec {
8863                estrategia: strat,
8864                children: if strat.is_simple_one_for_one() {
8865                    vec![]
8866                } else {
8867                    vec![child("w", "^0.1", RestartPolicy::Permanent)]
8868                },
8869                ..SupervisorSpec::default()
8870            };
8871            let json = serde_json::to_string(&s).unwrap();
8872            let back: SupervisorSpec = serde_json::from_str(&json).unwrap();
8873            assert_eq!(s, back);
8874        }
8875    }
8876
8877    #[test]
8878    fn round_trip_all_restart_policies() {
8879        for policy in [
8880            RestartPolicy::Permanent,
8881            RestartPolicy::Temporary,
8882            RestartPolicy::Transient,
8883        ] {
8884            let c = child("w", "^0.1", policy);
8885            let json = serde_json::to_string(&c).unwrap();
8886            let back: ChildSpec = serde_json::from_str(&json).unwrap();
8887            assert_eq!(c, back);
8888        }
8889    }
8890
8891    #[test]
8892    fn restart_strategy_is_simple_one_for_one_predicate_partitions_the_arm_set() {
8893        // The fail-before-pass-after pin on the `gen_platform::IsVariant`
8894        // derive's [`RestartStrategy::is_simple_one_for_one`] arm-
8895        // discriminator predicate: [`RestartStrategy::SimpleOneForOne`]
8896        // is the only variant that satisfies `.is_simple_one_for_one()`;
8897        // every static-children-bearing arm (`OneForOne` / `OneForAll`
8898        // / `RestForOne`) returns `false`. This pin makes the partition
8899        // invariant load-bearing at caixa-core test time so a future
8900        // derive regression (a hole that returns `false` for
8901        // `SimpleOneForOne` too, or a byte-collision that flips a second
8902        // variant to `true`) trips here rather than laundering the arm
8903        // at the three test-fixture builder sites (a hole flips the
8904        // `SimpleOneForOne` fixture to carry a non-empty children list
8905        // and the subsequent `SupervisorSpec::validate` would refuse the
8906        // fixture with [`SupervisorError::SimpleOneForOneWithStaticChildren`];
8907        // a collision flips a peer strategy's fixture to carry an empty
8908        // children list and the subsequent `validate` would refuse with
8909        // [`SupervisorError::NoChildren`] — either way, the pin fires
8910        // here, at the derive site, rather than at the fixture-refusal
8911        // site far away). Peer of the sibling
8912        // [`crate::upgrade::tests::upgrade_instruction_is_restart_predicate_partitions_the_arm_set`]
8913        // (915a934) pin on the M2 OTP-appup axis and the sibling
8914        // [`crate::kind::tests::caixa_kind_is_variant_predicates_partition_the_arm_set`]
8915        // pin on the M0 `:kind` axis.
8916        let cases: &[(RestartStrategy, bool)] = &[
8917            (RestartStrategy::OneForOne, false),
8918            (RestartStrategy::OneForAll, false),
8919            (RestartStrategy::RestForOne, false),
8920            (RestartStrategy::SimpleOneForOne, true),
8921        ];
8922        for (variant, expected) in cases {
8923            assert_eq!(
8924                variant.is_simple_one_for_one(),
8925                *expected,
8926                "RestartStrategy::{variant:?}.is_simple_one_for_one() must \
8927                 return {expected} (partition invariant on the \
8928                 IsVariant-derived arm-discriminator predicate — every \
8929                 test-fixture site that partitions the `:children` slot \
8930                 shape on `SimpleOneForOne ↔ non-SimpleOneForOne` keys \
8931                 off this typed dispatch, so a derive regression must \
8932                 surface here rather than at the fixture-refusal site)"
8933            );
8934        }
8935    }
8936
8937    #[test]
8938    fn restart_strategy_fixture_partition_routes_through_is_simple_one_for_one_predicate() {
8939        // Byte-identity pin on the `SimpleOneForOne ↔ non-SimpleOneForOne`
8940        // fixture-shape partition against the pre-lift
8941        // `matches!(strat, RestartStrategy::SimpleOneForOne)` open-coded
8942        // pattern-match every test-fixture builder site previously
8943        // coupled to inline. Asserts the two projections agree byte-for-
8944        // byte on every arm of the enum, so a future derive regression
8945        // that flipped either predicate's arm-set would surface here at
8946        // caixa-core test time rather than at the three fixture-builder
8947        // sites (`supervisor::tests::round_trip_all_strategies`,
8948        // `supervisor::tests::supervisor_spec_estrategia_returns_estrategia_verbatim_across_permutations`,
8949        // `manifest::tests::caixa_estrategia_and_supervisor_view_reads_through_lifted_estrategia_accessor`)
8950        // far from the derive site. Same peer-shape byte-identity pin
8951        // every sibling `IsVariant`-derive-routed convergence carries on
8952        // the substrate's closed-set typed-enum surface (peer of
8953        // [`crate::upgrade::tests::validate_restart_exclusive_routes_through_is_restart_predicate`]
8954        // on the M2 OTP-appup axis).
8955        for &strat in RestartStrategy::ALL {
8956            let via_predicate = strat.is_simple_one_for_one();
8957            let via_matches = matches!(strat, RestartStrategy::SimpleOneForOne);
8958            assert_eq!(
8959                via_predicate, via_matches,
8960                "RestartStrategy::{strat:?}: is_simple_one_for_one() must \
8961                 byte-equal matches!(_, RestartStrategy::SimpleOneForOne) — \
8962                 the pre-lift open-coded pattern and the \
8963                 IsVariant-derived predicate are the same axis, \
8964                 one typed dispatch"
8965            );
8966        }
8967    }
8968
8969    #[test]
8970    fn duration_codec_round_trip_canonical_units() {
8971        // Note the canonical-form rule: durations serialize to the
8972        // *largest* unit that divides cleanly, so 60s ↔ "1m" and not
8973        // "60s" — but the round-trip preserves the underlying Duration.
8974        let cases = [
8975            ("30s", Duration::from_secs(30)),
8976            ("5m", Duration::from_secs(300)),
8977            ("1h", Duration::from_secs(3600)),
8978            ("500ms", Duration::from_millis(500)),
8979        ];
8980        for (lit, dur) in cases {
8981            let s = SupervisorSpec {
8982                children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
8983                restart_window: Some(dur),
8984                ..SupervisorSpec::default()
8985            };
8986            let json = serde_json::to_string(&s).unwrap();
8987            assert!(
8988                json.contains(&format!("\"{lit}\"")),
8989                "expected \"{lit}\" in {json}"
8990            );
8991            let back: SupervisorSpec = serde_json::from_str(&json).unwrap();
8992            assert_eq!(back.restart_window, Some(dur));
8993        }
8994    }
8995
8996    #[test]
8997    fn duration_canonicalizes_to_largest_unit() {
8998        // 60 seconds → "1m" (largest cleanly-divisible unit), but the
8999        // typed Duration still equals 60s on the way back.
9000        let s = SupervisorSpec {
9001            children: vec![child("w", "^0.1", RestartPolicy::Permanent)],
9002            restart_window: Some(Duration::from_secs(60)),
9003            ..SupervisorSpec::default()
9004        };
9005        let json = serde_json::to_string(&s).unwrap();
9006        assert!(json.contains("\"1m\""), "{json}");
9007        let back: SupervisorSpec = serde_json::from_str(&json).unwrap();
9008        assert_eq!(back.restart_window, Some(Duration::from_secs(60)));
9009    }
9010
9011    #[test]
9012    fn three_child_one_for_one_validates() {
9013        let s = SupervisorSpec {
9014            estrategia: RestartStrategy::OneForOne,
9015            max_restarts: 5,
9016            restart_window: Some(Duration::from_secs(60)),
9017            children: vec![
9018                child("worker", "^0.1", RestartPolicy::Permanent),
9019                child("cache", "^0.1", RestartPolicy::Transient),
9020                child("scratch", "^0.1", RestartPolicy::Temporary),
9021            ],
9022        };
9023        s.validate().unwrap();
9024    }
9025
9026    #[test]
9027    fn json_uses_pascal_case_for_strategy_and_policy() {
9028        // Variant names are PascalCase by default in serde, matching
9029        // tatara-lisp's enum convention (`:estrategia OneForOne`).
9030        let c = child("w", "^0.1", RestartPolicy::Permanent);
9031        let json = serde_json::to_string(&c).unwrap();
9032        assert!(json.contains("\"Permanent\""));
9033        assert!(!json.contains("\"permanent\""));
9034
9035        let s = SupervisorSpec {
9036            estrategia: RestartStrategy::OneForOne,
9037            children: vec![c],
9038            ..SupervisorSpec::default()
9039        };
9040        let json = serde_json::to_string(&s).unwrap();
9041        assert!(json.contains("\"estrategia\":\"OneForOne\""));
9042    }
9043
9044    // ── shared duration codec: integer-magnitude canonical-form gate ──
9045    //
9046    // The gate lifts the discipline `crate::limits::parse_duration`
9047    // (818dd38) carries on the peer `:limits :wall-clock` codec onto
9048    // the shared codec backing the remaining three typed-duration
9049    // slots: `:supervisor :restart-window`, `:politicas :timeout`, and
9050    // `:politicas :circuit-breaker :window`. Every magnitude `render`
9051    // emits is a non-negative integer with no decimal point and no
9052    // leading sign, so the codec's accepted set must match for
9053    // serialize/deserialize to round-trip without canonical-form
9054    // drift.
9055
9056    #[test]
9057    fn parse_accepts_integer_canonical_units() {
9058        // Pin the happy-path: every canonical author shape `render`
9059        // ever emits parses to the same `Duration` value, so the
9060        // codec's accepted set is at least a superset of its emitted
9061        // set on the canonical-unit axis.
9062        for (lit, dur) in [
9063            ("30s", Duration::from_secs(30)),
9064            ("500ms", Duration::from_millis(500)),
9065            ("2m", Duration::from_secs(120)),
9066            ("1h", Duration::from_secs(3600)),
9067            ("0s", Duration::ZERO),
9068        ] {
9069            assert_eq!(
9070                duration_codec::parse(lit).unwrap(),
9071                dur,
9072                "parse({lit:?}) should be {dur:?}"
9073            );
9074        }
9075    }
9076
9077    #[test]
9078    fn parse_accepts_bare_integer_as_seconds() {
9079        // The `"s" | ""` arm: a bare integer with no unit is read as
9080        // seconds. Pin this so the unit-empty form keeps parsing (it
9081        // renders to `"<n>s"` on serialize — that's a unit-choice
9082        // drift the integer-magnitude gate does NOT close, matching
9083        // the `parse_byte_size` `"1024"` → `"1KiB"` scope decision in
9084        // the peer `:limits :memory` codec).
9085        assert_eq!(
9086            duration_codec::parse("30").unwrap(),
9087            Duration::from_secs(30)
9088        );
9089    }
9090
9091    #[test]
9092    fn parse_rejects_fractional_seconds_with_canonical_form_diagnostic() {
9093        // `"1.5s"` parses as f64 to 1.5 → renders back as `"1500ms"`
9094        // on first serialize — DRIFT. The integer-magnitude gate names
9095        // the offending `"1.5"` verbatim and points at the canonical
9096        // remediation `"1500ms"`.
9097        let err = duration_codec::parse("1.5s").unwrap_err();
9098        assert!(err.contains("\"1.5\""), "missing magnitude in {err:?}");
9099        assert!(
9100            err.contains("not a non-negative integer"),
9101            "missing canonical-form reason in {err:?}"
9102        );
9103        assert!(
9104            err.contains("\"1500ms\""),
9105            "missing canonical-form remediation in {err:?}"
9106        );
9107    }
9108
9109    #[test]
9110    fn parse_rejects_decimal_shaped_integer_seconds() {
9111        // `"1.0s"` is the trickiest drift class: numerically `1.0s` is
9112        // `1s` exactly, so the round-trip looks correct — but the
9113        // emitted canonical form is `"1s"`, not `"1.0s"`. Gate the
9114        // decimal-shape-with-integer-value form so author intent is
9115        // never silently rewritten.
9116        let err = duration_codec::parse("1.0s").unwrap_err();
9117        assert!(err.contains("\"1.0\""), "missing magnitude in {err:?}");
9118        assert!(
9119            err.contains("not a non-negative integer"),
9120            "missing canonical-form reason in {err:?}"
9121        );
9122    }
9123
9124    #[test]
9125    fn parse_rejects_half_unit_minute() {
9126        // `"0.5m"` is the unit-fraction footgun — author writes a
9127        // human-readable half-minute, serde silently rewrites to
9128        // `"30s"` on next emit. The gate names the offending
9129        // magnitude `"0.5"` and points at the integer-in-smaller-unit
9130        // form.
9131        let err = duration_codec::parse("0.5m").unwrap_err();
9132        assert!(err.contains("\"0.5\""), "missing magnitude in {err:?}");
9133        assert!(
9134            err.contains("\"30s\""),
9135            "missing canonical-form remediation in {err:?}"
9136        );
9137    }
9138
9139    #[test]
9140    fn parse_rejects_leading_plus_sign() {
9141        // `u64::from_str` rejects `"+30"` but `f64::from_str` accepts
9142        // it as `30.0` — the prior parser used f64 so `"+30s"` parsed
9143        // cleanly to 30s and round-tripped to `"30s"` on next emit
9144        // (DRIFT). The digit-only gate closes the leading-sign class
9145        // first; the diagnostic names `"+30"` verbatim.
9146        let err = duration_codec::parse("+30s").unwrap_err();
9147        assert!(err.contains("\"+30\""), "missing magnitude in {err:?}");
9148        assert!(
9149            err.contains("not a non-negative integer"),
9150            "missing canonical-form reason in {err:?}"
9151        );
9152    }
9153
9154    #[test]
9155    fn parse_rejects_leading_minus_sign() {
9156        // The former `num < 0.0` arm: `"-30s"` parsed as f64 to -30,
9157        // rejected with `"negative duration in \"-30s\""`. Under the
9158        // integer-magnitude gate the diagnostic is unified — `-30` is
9159        // non-digit-only, f64-numeric, and surfaces with the canonical-
9160        // form reason (no leading `+` / `-` sign) naming the offending
9161        // `"-30"` verbatim. Same diagnostic shape as every other
9162        // rejected non-integer magnitude.
9163        let err = duration_codec::parse("-30s").unwrap_err();
9164        assert!(err.contains("\"-30\""), "missing magnitude in {err:?}");
9165        assert!(
9166            err.contains("not a non-negative integer"),
9167            "missing canonical-form reason in {err:?}"
9168        );
9169    }
9170
9171    #[test]
9172    fn parse_garbage_still_falls_through_to_bad_magnitude() {
9173        // Non-digit-only AND non-numeric (`"--1s"`, `"abc"`) falls
9174        // through to the narrower "bad duration magnitude" arm — the
9175        // canonical-form diagnostic is reserved for the parser-shape
9176        // footgun case, not the "not a number at all" case. Same
9177        // shape `parse_byte_size`'s `BadByteMagnitude` arm carries on
9178        // the peer `:limits :memory` codec.
9179        let err = duration_codec::parse("--1s").unwrap_err();
9180        assert!(
9181            err.contains("bad duration magnitude"),
9182            "expected bad-magnitude wording in {err:?}"
9183        );
9184    }
9185
9186    #[test]
9187    fn parse_digit_only_magnitude_carries_zero_f64_drift() {
9188        // The accepted set is now closed under `u64`-exact integer
9189        // arithmetic: `"500ms"` → `Duration::from_millis(500)` exactly,
9190        // `"3600s"` → `Duration::from_secs(3600)` exactly, `"1h"` →
9191        // `Duration::from_secs(3600)` exactly, no f64 mantissa drift
9192        // possible. Pin the integer-exact arms across the four unit
9193        // suffixes so a future refactor that reaches back for f64
9194        // (`from_secs_f64`, `mul_f64`) surfaces here.
9195        assert_eq!(
9196            duration_codec::parse("3600s").unwrap(),
9197            Duration::from_secs(3600)
9198        );
9199        assert_eq!(
9200            duration_codec::parse("60m").unwrap(),
9201            Duration::from_secs(3600)
9202        );
9203        assert_eq!(
9204            duration_codec::parse("1h").unwrap(),
9205            Duration::from_secs(3600)
9206        );
9207        assert_eq!(
9208            duration_codec::parse("999ms").unwrap(),
9209            Duration::from_millis(999)
9210        );
9211    }
9212
9213    #[test]
9214    fn restart_window_serde_rejects_fractional_seconds() {
9215        // The shared codec backs `SupervisorSpec::restart_window`
9216        // (`with = "duration_codec"`) — so the gate applies on serde
9217        // deserialize for the typed Supervisor slot. A
9218        // `{"restartWindow":"1.5s"}` payload that previously round-
9219        // tripped to a different canonical string on next serialize
9220        // is now refused at deserialize with the integer-magnitude
9221        // diagnostic.
9222        let payload = r#"{"estrategia":"OneForOne","maxRestarts":5,
9223            "restartWindow":"1.5s",
9224            "children":[{"caixa":"w","versao":"^0.1","restart":"Permanent"}]}"#;
9225        let err = serde_json::from_str::<SupervisorSpec>(payload).unwrap_err();
9226        let msg = err.to_string();
9227        assert!(
9228            msg.contains("not a non-negative integer"),
9229            "expected integer-magnitude diagnostic in {msg:?}"
9230        );
9231        assert!(msg.contains("\"1.5\""), "missing magnitude in {msg:?}");
9232    }
9233
9234    #[test]
9235    fn restart_window_serde_rejects_leading_plus() {
9236        // The `u64::from_str` leading-`+` permissiveness gap that
9237        // motivated the digit-only gate (the `f64`-side accepted
9238        // `"+30"`, the prior parser silently round-tripped to `"30s"`)
9239        // is now closed on the shared codec — surfaces as a structured
9240        // diagnostic at the serde layer for every typed-duration slot.
9241        let payload = r#"{"estrategia":"OneForOne","maxRestarts":5,
9242            "restartWindow":"+30s",
9243            "children":[{"caixa":"w","versao":"^0.1","restart":"Permanent"}]}"#;
9244        let err = serde_json::from_str::<SupervisorSpec>(payload).unwrap_err();
9245        let msg = err.to_string();
9246        assert!(msg.contains("\"+30\""), "missing magnitude in {msg:?}");
9247        assert!(
9248            msg.contains("not a non-negative integer"),
9249            "missing canonical-form reason in {msg:?}"
9250        );
9251    }
9252
9253    #[test]
9254    fn parse_rejects_leading_zero_magnitude() {
9255        // `"030s"` is digit-only, so the existing non-digit-only / sign
9256        // / fractional arm doesn't catch it — `u64::from_str("030")`
9257        // returns `Ok(30)`, so before this gate `"030s"` parsed to
9258        // `Duration::from_secs(30)` and round-tripped through `render`
9259        // to `"30s"` — a *different* canonical string on the next emit,
9260        // breaking the THEORY.md Part V render-determinism contract
9261        // exactly the way `"+30s"` did before the leading-`+` arm
9262        // landed. Peer with the `rate_limit_codec` leading-zero arm
9263        // (4f46830) on the same canonical-form-drift axis.
9264        let err = duration_codec::parse("030s").unwrap_err();
9265        assert!(
9266            err.contains("non-canonical leading zero"),
9267            "expected leading-zero diagnostic in {err:?}"
9268        );
9269        assert!(err.contains("\"030\""), "missing magnitude in {err:?}");
9270        assert!(
9271            err.contains("\"30s\""),
9272            "missing canonical-form remediation in {err:?}"
9273        );
9274        assert!(
9275            err.contains("THEORY.md"),
9276            "missing render-determinism citation in {err:?}"
9277        );
9278    }
9279
9280    #[test]
9281    fn parse_rejects_multi_digit_zero_magnitude() {
9282        // `"00s"` and `"00ms"` are the all-zero leading-zero footgun —
9283        // digit-only, parse losslessly to `Duration::ZERO`, but render
9284        // back to `"0s"` (the single-byte canonical form) on the next
9285        // emit. The leading-zero arm refuses the drift class at the
9286        // codec layer; the semantic-zero gate downstream
9287        // (`SupervisorError::ZeroRestartWindow`, etc.) would refuse
9288        // the single-byte canonical form `"0s"` separately on the
9289        // typed-validate layer.
9290        let err = duration_codec::parse("00s").unwrap_err();
9291        assert!(
9292            err.contains("non-canonical leading zero"),
9293            "expected leading-zero diagnostic in {err:?}"
9294        );
9295        assert!(err.contains("\"00\""), "missing magnitude in {err:?}");
9296    }
9297
9298    #[test]
9299    fn parse_rejects_leading_zero_per_hour_window() {
9300        // `"01h"` is the per-hour-window footgun — multi-byte magnitude
9301        // starting with `0`, parses losslessly to `Duration::from_secs(3600)`,
9302        // renders to `"1h"` (DRIFT). The arm is unit-agnostic: every
9303        // canonical unit suffix the codec accepts (`ms` / `s` / `m` /
9304        // `h` / bare-integer-as-seconds) inherits the same gate.
9305        let err = duration_codec::parse("01h").unwrap_err();
9306        assert!(
9307            err.contains("non-canonical leading zero"),
9308            "expected leading-zero diagnostic in {err:?}"
9309        );
9310        assert!(err.contains("\"01\""), "missing magnitude in {err:?}");
9311    }
9312
9313    #[test]
9314    fn parse_rejects_leading_zero_bare_integer_as_seconds() {
9315        // The `parse_accepts_bare_integer_as_seconds` happy-path
9316        // (`"30"` → 30s) inherits the leading-zero arm: `"030"` is
9317        // multi-byte starts-with-`0`, parses losslessly to
9318        // `Duration::from_secs(30)`, renders to `"30s"` (DRIFT). The
9319        // bare-integer surface accepts permissive unit-empty
9320        // shorthand but still must reject leading-zero padding.
9321        let err = duration_codec::parse("030").unwrap_err();
9322        assert!(
9323            err.contains("non-canonical leading zero"),
9324            "expected leading-zero diagnostic in {err:?}"
9325        );
9326        assert!(err.contains("\"030\""), "missing magnitude in {err:?}");
9327    }
9328
9329    #[test]
9330    fn parse_accepts_single_zero_magnitude_at_codec_layer() {
9331        // The codec-layer / typed-validate-layer boundary: `"0s"` /
9332        // `"0ms"` / `"0"` are the single-byte canonical-zero forms —
9333        // each round-trips losslessly through `render`
9334        // (`render(Duration::ZERO)` → `"0s"`), so the codec layer
9335        // accepts them. The downstream semantic-zero gates
9336        // (`SupervisorError::ZeroRestartWindow`,
9337        // `AplicacaoError::PolicyTimeoutZero`,
9338        // `AplicacaoError::PolicyCircuitBreakerWindowZero`) refuse
9339        // zero-magnitude authoring at the typed-validate layer above,
9340        // peer with the `rate_limit_codec` codec-layer / typed-
9341        // validate-layer partition for `"0/s"`.
9342        assert_eq!(duration_codec::parse("0s").unwrap(), Duration::ZERO);
9343        assert_eq!(duration_codec::parse("0ms").unwrap(), Duration::ZERO);
9344        assert_eq!(duration_codec::parse("0").unwrap(), Duration::ZERO);
9345    }
9346
9347    #[test]
9348    fn parse_accepts_canonical_magnitude_with_leading_one() {
9349        // The complementary boundary: a future tightening cannot
9350        // drift into rejecting valid canonical magnitudes that
9351        // happen to start with `1` (or any digit `[1-9]`). Pin
9352        // every canonical-unit suffix so the leading-zero arm
9353        // remains strictly narrower than the digit-only arm.
9354        assert_eq!(
9355            duration_codec::parse("100ms").unwrap(),
9356            Duration::from_millis(100)
9357        );
9358        assert_eq!(
9359            duration_codec::parse("100s").unwrap(),
9360            Duration::from_secs(100)
9361        );
9362        assert_eq!(
9363            duration_codec::parse("10m").unwrap(),
9364            Duration::from_secs(600)
9365        );
9366        assert_eq!(
9367            duration_codec::parse("10h").unwrap(),
9368            Duration::from_secs(36_000)
9369        );
9370    }
9371
9372    #[test]
9373    fn restart_window_serde_rejects_leading_zero() {
9374        // The shared codec backs `SupervisorSpec::restart_window`
9375        // (`with = "duration_codec"`) — so the leading-zero arm
9376        // applies on serde deserialize for the typed Supervisor slot.
9377        // A `{"restartWindow":"030s"}` payload that previously round-
9378        // tripped to a different canonical string on next serialize
9379        // is now refused at deserialize with the leading-zero
9380        // diagnostic. Peer with `restart_window_serde_rejects_leading_plus`
9381        // / `restart_window_serde_rejects_fractional_seconds` on the
9382        // same canonical-form-drift axis.
9383        let payload = r#"{"estrategia":"OneForOne","maxRestarts":5,
9384            "restartWindow":"030s",
9385            "children":[{"caixa":"w","versao":"^0.1","restart":"Permanent"}]}"#;
9386        let err = serde_json::from_str::<SupervisorSpec>(payload).unwrap_err();
9387        let msg = err.to_string();
9388        assert!(
9389            msg.contains("non-canonical leading zero"),
9390            "expected leading-zero diagnostic in {msg:?}"
9391        );
9392        assert!(msg.contains("\"030\""), "missing magnitude in {msg:?}");
9393    }
9394
9395    #[test]
9396    fn parse_rejects_leading_whitespace() {
9397        // `" 30s"` — the canonical paste-from-aligned-doc /
9398        // paste-from-YAML-quoted-plain-scalar footgun. Before this
9399        // gate the top-level `s.trim()` at parse entry silently ate
9400        // the leading space and parsed the value to
9401        // `Duration::from_secs(30)`, which then round-tripped through
9402        // `render` to `"30s"` (a *different* canonical string on the
9403        // next emit) — the exact canonical-form-drift class the
9404        // leading-`+` / leading-zero arms already close, extended
9405        // to the whitespace-byte class. Peer with the sibling
9406        // `rate_limit_codec` whitespace-rejection arm (1ad7755) on
9407        // the M3 `:politicas` axis.
9408        let err = duration_codec::parse(" 30s").unwrap_err();
9409        assert!(
9410            err.contains("contains whitespace byte"),
9411            "expected whitespace diagnostic in {err:?}"
9412        );
9413        assert!(err.contains("0x20"), "missing offending byte in {err:?}");
9414        assert!(
9415            err.contains("THEORY.md"),
9416            "missing render-determinism contract citation in {err:?}"
9417        );
9418    }
9419
9420    #[test]
9421    fn parse_rejects_trailing_whitespace() {
9422        // `"30s "` — the canonical shell-history / trailing-space
9423        // paste footgun. Before this gate the top-level `s.trim()`
9424        // silently ate the trailing space and parsed to
9425        // `Duration::from_secs(30)`, round-tripping to `"30s"` on the
9426        // next emit — same canonical-form drift as the leading-space
9427        // sibling, closed on the same whitespace-byte arm.
9428        let err = duration_codec::parse("30s ").unwrap_err();
9429        assert!(
9430            err.contains("contains whitespace byte"),
9431            "expected whitespace diagnostic in {err:?}"
9432        );
9433        assert!(err.contains("0x20"), "missing offending byte in {err:?}");
9434    }
9435
9436    #[test]
9437    fn parse_rejects_internal_whitespace_between_magnitude_and_unit() {
9438        // `"30 s"` — the canonical typographically-spaced author
9439        // shape (the same idiom every prose reference to a duration
9440        // renders as, mistakenly retained when the value is pasted
9441        // into a codec-shaped slot). Before this gate the per-part
9442        // `num_part.trim()` / `unit.trim()` calls silently ate the
9443        // whitespace between the magnitude and the unit and parsed
9444        // the value to `Duration::from_secs(30)`, round-tripping to
9445        // `"30s"` — the codec's *internal* whitespace-tolerance
9446        // vector, orthogonal to the leading / trailing surface but
9447        // the same canonical-form-drift class. Pins the arm as
9448        // strictly stronger than the pre-existing top-level
9449        // `s.trim()` behavior: it fires on whitespace anywhere in
9450        // the value, not just at the string boundary.
9451        let err = duration_codec::parse("30 s").unwrap_err();
9452        assert!(
9453            err.contains("contains whitespace byte"),
9454            "expected whitespace diagnostic in {err:?}"
9455        );
9456        assert!(err.contains("0x20"), "missing offending byte in {err:?}");
9457    }
9458
9459    #[test]
9460    fn parse_rejects_tab_byte() {
9461        // `"\t30s"` — the canonical paste-from-indented-doc /
9462        // paste-from-YAML-block-scalar footgun where a tab byte leads
9463        // the magnitude. Pins that the gate covers tab (`0x09`) as
9464        // well as space (`0x20`) — both are `u8::is_ascii_whitespace`
9465        // members and both would be silently swallowed by `s.trim()`
9466        // pre-gate. The `is_ascii_whitespace` coverage extends beyond
9467        // space alone to the full ASCII-whitespace set (space `0x20`,
9468        // tab `0x09`, LF `0x0A`, FF `0x0C`, CR `0x0D`); this test pins
9469        // the tab arm as a representative of the non-space members.
9470        let err = duration_codec::parse("\t30s").unwrap_err();
9471        assert!(
9472            err.contains("contains whitespace byte"),
9473            "expected whitespace diagnostic in {err:?}"
9474        );
9475        assert!(
9476            err.contains("0x09"),
9477            "missing offending tab byte in {err:?}"
9478        );
9479    }
9480
9481    #[test]
9482    fn restart_window_serde_rejects_whitespace() {
9483        // The shared codec backs `SupervisorSpec::restart_window`
9484        // (`with = "duration_codec"`) — so the whitespace arm
9485        // applies on serde deserialize for the typed Supervisor slot.
9486        // A `{"restartWindow":" 30s"}` payload that previously round-
9487        // tripped to a different canonical string on next serialize
9488        // is now refused at deserialize with the whitespace-byte
9489        // diagnostic. Peer with `restart_window_serde_rejects_leading_zero`
9490        // / `restart_window_serde_rejects_leading_plus` /
9491        // `restart_window_serde_rejects_fractional_seconds` on the
9492        // same canonical-form-drift axis.
9493        let payload = r#"{"estrategia":"OneForOne","maxRestarts":5,
9494            "restartWindow":" 30s",
9495            "children":[{"caixa":"w","versao":"^0.1","restart":"Permanent"}]}"#;
9496        let err = serde_json::from_str::<SupervisorSpec>(payload).unwrap_err();
9497        let msg = err.to_string();
9498        assert!(
9499            msg.contains("contains whitespace byte"),
9500            "expected whitespace diagnostic in {msg:?}"
9501        );
9502        assert!(msg.contains("0x20"), "missing offending byte in {msg:?}");
9503    }
9504
9505    // ── canonical-form: non-ASCII Unicode `White_Space` duration gate ─────
9506    //
9507    // Successor to the ASCII-whitespace arm (a7ae622) on the shared
9508    // duration codec — closes the strictly-complementary class the
9509    // byte-scan cannot see, through the lifted
9510    // [`crate::render::find_non_ascii_whitespace_char`] predicate.
9511    // Applies to `:supervisor :restart-window`, `:politicas :timeout`,
9512    // and `:politicas :circuit-breaker :window` simultaneously via
9513    // this shared codec.
9514
9515    #[test]
9516    fn duration_codec_parse_rejects_leading_nbsp() {
9517        // NBSP prefix — the strictly-complementary drift class the
9518        // ASCII byte-scan cannot see. `str::trim` strips it silently
9519        // and the value drifts to `"30s"` on next serialize.
9520        let err = duration_codec::parse("\u{00A0}30s").unwrap_err();
9521        assert!(
9522            err.contains("non-ASCII Unicode whitespace character"),
9523            "expected non-ASCII whitespace diagnostic in {err:?}"
9524        );
9525        assert!(err.contains("U+00A0"), "missing codepoint in {err:?}");
9526    }
9527
9528    #[test]
9529    fn duration_codec_parse_rejects_trailing_line_separator() {
9530        // LINE SEPARATOR (`\u{2028}`) trailing — paste-from-web-doc
9531        // footgun.
9532        let err = duration_codec::parse("30s\u{2028}").unwrap_err();
9533        assert!(
9534            err.contains("non-ASCII Unicode whitespace character"),
9535            "expected non-ASCII whitespace diagnostic in {err:?}"
9536        );
9537        assert!(err.contains("U+2028"), "missing codepoint in {err:?}");
9538    }
9539
9540    #[test]
9541    fn duration_codec_parse_accepts_ascii_only_forms_after_unicode_arm() {
9542        // Positive-control pin: every ASCII-only canonical form the
9543        // renderer emits stays accepted through the new arm.
9544        assert_eq!(
9545            duration_codec::parse("30s").unwrap(),
9546            Duration::from_secs(30)
9547        );
9548        assert_eq!(
9549            duration_codec::parse("500ms").unwrap(),
9550            Duration::from_millis(500)
9551        );
9552        assert_eq!(
9553            duration_codec::parse("1h").unwrap(),
9554            Duration::from_secs(3600)
9555        );
9556    }
9557
9558    #[test]
9559    fn restart_window_serde_rejects_non_ascii_whitespace() {
9560        // The shared codec backs `SupervisorSpec::restart_window` — so
9561        // the new non-ASCII Unicode whitespace arm applies on serde
9562        // deserialize for the typed Supervisor slot. A
9563        // `{"restartWindow":" 30s"}` payload that previously
9564        // survived the ASCII byte-scan (only ASCII whitespace was
9565        // refused) is now refused at deserialize with the
9566        // non-ASCII-whitespace-and-codepoint diagnostic.
9567        let payload = "{\"estrategia\":\"OneForOne\",\"maxRestarts\":5,\
9568            \"restartWindow\":\"\u{00A0}30s\",\
9569            \"children\":[{\"caixa\":\"w\",\"versao\":\"^0.1\",\"restart\":\"Permanent\"}]}";
9570        let err = serde_json::from_str::<SupervisorSpec>(payload).unwrap_err();
9571        let msg = err.to_string();
9572        assert!(
9573            msg.contains("non-ASCII Unicode whitespace character"),
9574            "expected non-ASCII whitespace diagnostic in {msg:?}"
9575        );
9576        assert!(msg.contains("U+00A0"), "missing codepoint in {msg:?}");
9577    }
9578
9579    // ── drift-detection: serde-derive-to-SUPERVISOR_KEY_* identity ────────
9580
9581    #[test]
9582    fn supervisor_spec_serde_keys_match_lifted_supervisor_key_consts() {
9583        // Load-bearing invariant: the four `SUPERVISOR_KEY_*` consts
9584        // (`SUPERVISOR_KEY_ESTRATEGIA` / `SUPERVISOR_KEY_MAX_RESTARTS` /
9585        // `SUPERVISOR_KEY_RESTART_WINDOW` / `SUPERVISOR_KEY_CHILDREN`)
9586        // name the exact camelCase JSON keys the
9587        // `#[serde(rename_all = "camelCase")]` attribute on
9588        // `SupervisorSpec` emits. Serialize a fully-populated spec (each
9589        // field carries `Some(_)` / non-empty) and pin that each canonical
9590        // byte-sequence appears verbatim in the JSON — a future accidental
9591        // `rename_all = "snake_case"` / `"kebab-case"` / verbatim-field-
9592        // name flip at the derive attribute (any of which would silently
9593        // break every downstream JSON consumer that reaches for one of the
9594        // four consts via `Value::get(...)`) surfaces here as a build-time
9595        // test failure at `supervisor.rs`, not as an apply-time
9596        // `.get(<stale-canonical-const>)` returning `None` far from the
9597        // derive-attr drift's commit. Peer with the sibling
9598        // `limits_spec_serde_keys_match_lifted_m2_limits_key_consts`
9599        // (d8b8b4f) pin on the M2 `:limits` axis — same discipline the
9600        // M2 typed-slot family established, extended here to close the
9601        // top-level Supervisor axis.
9602        let spec = SupervisorSpec {
9603            estrategia: RestartStrategy::OneForOne,
9604            max_restarts: 5,
9605            restart_window: Some(Duration::from_secs(60)),
9606            children: vec![ChildSpec {
9607                caixa: "w".into(),
9608                versao: "^0.1".into(),
9609                restart: RestartPolicy::Permanent,
9610            }],
9611        };
9612        let json = serde_json::to_string(&spec).unwrap();
9613        for key in [
9614            crate::render::SUPERVISOR_KEY_ESTRATEGIA,
9615            crate::render::SUPERVISOR_KEY_MAX_RESTARTS,
9616            crate::render::SUPERVISOR_KEY_RESTART_WINDOW,
9617            crate::render::SUPERVISOR_KEY_CHILDREN,
9618        ] {
9619            let quoted = format!("\"{key}\"");
9620            assert!(
9621                json.contains(&quoted),
9622                "serialized SupervisorSpec must carry the lifted \
9623                 SUPERVISOR_KEY_* byte-sequence {quoted} verbatim in \
9624                 the JSON emission (got: {json})",
9625            );
9626        }
9627    }
9628
9629    #[test]
9630    fn supervisor_key_consts_are_pairwise_distinct() {
9631        // Cross-axis drift-detection pin: a future collapse of two
9632        // canonical top-level byte-strings onto the same value (e.g. an
9633        // accidental copy-paste flip of `SUPERVISOR_KEY_CHILDREN` to
9634        // also read `"estrategia"`) would silently reroute every
9635        // downstream probe on one axis onto the sibling axis's overlay
9636        // entry and pass every propagation-probe test that expected only
9637        // the stale axis's value. Peer of the sibling four-way distinct
9638        // pin on the `M2_LIMITS_KEY_*` tetrad (d8b8b4f).
9639        let all = [
9640            crate::render::SUPERVISOR_KEY_ESTRATEGIA,
9641            crate::render::SUPERVISOR_KEY_MAX_RESTARTS,
9642            crate::render::SUPERVISOR_KEY_RESTART_WINDOW,
9643            crate::render::SUPERVISOR_KEY_CHILDREN,
9644        ];
9645        for (i, a) in all.iter().enumerate() {
9646            for b in all.iter().skip(i + 1) {
9647                assert_ne!(
9648                    a, b,
9649                    "SUPERVISOR_KEY_* consts must be pairwise-distinct \
9650                     canonical byte-sequences — got `{a}` == `{b}`",
9651                );
9652            }
9653        }
9654    }
9655
9656    #[test]
9657    fn supervisor_key_consts_are_lower_camel_case_shape() {
9658        // Shape-pin: every `SUPERVISOR_KEY_*` const must be a
9659        // lowerCamelCase byte-sequence (no `snake_case` underscores, no
9660        // `kebab-case` hyphens, no leading colon, no `PascalCase` leading
9661        // capital, no whitespace / dots) — the canonical shape the
9662        // `#[serde(rename_all = "camelCase")]` derive produces on
9663        // `SupervisorSpec`. A future flip to a non-camelCase attribute
9664        // at the derive surfaces both here (this test fails on the
9665        // stale-constant shape) and at
9666        // `supervisor_spec_serde_keys_match_lifted_supervisor_key_consts`
9667        // (that test fails on the mismatch between const and derive).
9668        // Peer with `m2_limits_key_consts_are_lower_camel_case_shape`
9669        // (d8b8b4f) on the sibling M2 `:limits` axis.
9670        for key in [
9671            crate::render::SUPERVISOR_KEY_ESTRATEGIA,
9672            crate::render::SUPERVISOR_KEY_MAX_RESTARTS,
9673            crate::render::SUPERVISOR_KEY_RESTART_WINDOW,
9674            crate::render::SUPERVISOR_KEY_CHILDREN,
9675        ] {
9676            assert!(
9677                !key.is_empty(),
9678                "SUPERVISOR_KEY_* must be non-empty (got {key:?})"
9679            );
9680            let first = key.chars().next().unwrap();
9681            assert!(
9682                first.is_ascii_lowercase(),
9683                "SUPERVISOR_KEY_* must lead with an ASCII-lowercase byte \
9684                 (got {key:?}, leads with {first:?})",
9685            );
9686            assert!(
9687                key.chars().all(|c| c.is_ascii_alphanumeric()),
9688                "SUPERVISOR_KEY_* must be ASCII-alphanumeric only \
9689                 — no `_` / `-` / `:` / `.` / whitespace (got {key:?})",
9690            );
9691        }
9692    }
9693
9694    #[test]
9695    fn supervisor_key_consts_are_byte_distinct_from_supervisor_author_key_peers() {
9696        // Cross-axis drift pin: the four `SUPERVISOR_KEY_*` consts
9697        // (camelCase JSON keys, no leading colon) must never collide
9698        // byte-for-byte with the four peer `SUPERVISOR_AUTHOR_KEY_*`
9699        // consts (kebab-case author-facing labels with leading colon)
9700        // that sit next to them at `caixa_core::render`. Both families
9701        // cover the same four typed Supervisor slots on two distinct
9702        // axes (author-side kebab vs renderer-side camelCase);
9703        // collapsing either family onto the other's byte-shape would
9704        // silently reroute the render-side probe onto the author-facing
9705        // surface, or vice versa. Peer of the byte-distinctness
9706        // discipline the `M3_PLACEMENT_KEY_ESTRATEGIA` docstring names
9707        // against the peer `M3_AUTHOR_KEY_PLACEMENT`.
9708        let pairs = [
9709            (
9710                crate::render::SUPERVISOR_KEY_ESTRATEGIA,
9711                crate::render::SUPERVISOR_AUTHOR_KEY_ESTRATEGIA,
9712            ),
9713            (
9714                crate::render::SUPERVISOR_KEY_MAX_RESTARTS,
9715                crate::render::SUPERVISOR_AUTHOR_KEY_MAX_RESTARTS,
9716            ),
9717            (
9718                crate::render::SUPERVISOR_KEY_RESTART_WINDOW,
9719                crate::render::SUPERVISOR_AUTHOR_KEY_RESTART_WINDOW,
9720            ),
9721            (
9722                crate::render::SUPERVISOR_KEY_CHILDREN,
9723                crate::render::SUPERVISOR_AUTHOR_KEY_CHILDREN,
9724            ),
9725        ];
9726        for (json_key, author_key) in pairs {
9727            assert_ne!(
9728                json_key, author_key,
9729                "SUPERVISOR_KEY_* (JSON side) must differ byte-for-byte \
9730                 from the peer SUPERVISOR_AUTHOR_KEY_* (author side); \
9731                 got JSON `{json_key}` == author `{author_key}`",
9732            );
9733        }
9734    }
9735
9736    // ── drift-detection: serde-derive-to-SUPERVISOR_CHILD_KEY_* identity ──
9737
9738    #[test]
9739    fn child_spec_serde_keys_match_lifted_supervisor_child_key_consts() {
9740        // Load-bearing invariant: the three `SUPERVISOR_CHILD_KEY_*` consts
9741        // (`SUPERVISOR_CHILD_KEY_CAIXA` / `SUPERVISOR_CHILD_KEY_VERSAO` /
9742        // `SUPERVISOR_CHILD_KEY_RESTART`) name the exact camelCase JSON
9743        // keys the `#[serde(rename_all = "camelCase")]` attribute on
9744        // `ChildSpec` emits. Serialize a fully-populated `ChildSpec` and
9745        // pin that each canonical byte-sequence appears verbatim in the
9746        // JSON — a future accidental `rename_all = "snake_case"` /
9747        // `"kebab-case"` / verbatim-field-name flip at the derive
9748        // attribute (any of which would silently break every downstream
9749        // JSON consumer that reaches for one of the three consts via
9750        // `Value::get(...)`) surfaces here as a build-time test failure at
9751        // `supervisor.rs`, not as an apply-time
9752        // `.get(<stale-canonical-const>)` returning `None` far from the
9753        // derive-attr drift's commit. Peer with the enclosing
9754        // `supervisor_spec_serde_keys_match_lifted_supervisor_key_consts`
9755        // (40cc4e5) pin on the M2 supervision-tree top-level axis — same
9756        // discipline the SupervisorSpec top-level lift established,
9757        // extended here to the sibling per-`:children` entry `ChildSpec`
9758        // derive so the last M2 typed-struct sub-block
9759        // `#[serde(rename_all = "camelCase")]` axis on the Supervisor
9760        // surface without a lifted serde-key peer joins the substrate's
9761        // "one canonical byte-string per typed serialized-key axis"
9762        // discipline.
9763        let c = ChildSpec {
9764            caixa: "worker".into(),
9765            versao: "^0.1".into(),
9766            restart: RestartPolicy::Permanent,
9767        };
9768        let json = serde_json::to_string(&c).unwrap();
9769        for key in [
9770            crate::render::SUPERVISOR_CHILD_KEY_CAIXA,
9771            crate::render::SUPERVISOR_CHILD_KEY_VERSAO,
9772            crate::render::SUPERVISOR_CHILD_KEY_RESTART,
9773        ] {
9774            let quoted = format!("\"{key}\"");
9775            assert!(
9776                json.contains(&quoted),
9777                "serialized ChildSpec must carry the lifted \
9778                 SUPERVISOR_CHILD_KEY_* byte-sequence {quoted} verbatim \
9779                 in the JSON emission (got: {json})",
9780            );
9781        }
9782    }
9783
9784    #[test]
9785    fn supervisor_child_key_consts_are_pairwise_distinct() {
9786        // Cross-axis drift-detection pin: a future collapse of two
9787        // canonical `ChildSpec` per-entry byte-strings onto the same
9788        // value (e.g. an accidental copy-paste flip of
9789        // `SUPERVISOR_CHILD_KEY_RESTART` to also read `"caixa"`) would
9790        // silently reroute every downstream probe on one axis onto the
9791        // sibling axis's overlay entry and pass every propagation-probe
9792        // test that expected only the stale axis's value. Peer of the
9793        // sibling three-way distinct pin on the `CONTRATO_KEY_*` triad
9794        // (ca463a4) and the two-way distinct pin on the `MEMBRO_KEY_*`
9795        // pair (ce80ca0).
9796        let all = [
9797            crate::render::SUPERVISOR_CHILD_KEY_CAIXA,
9798            crate::render::SUPERVISOR_CHILD_KEY_VERSAO,
9799            crate::render::SUPERVISOR_CHILD_KEY_RESTART,
9800        ];
9801        for (i, a) in all.iter().enumerate() {
9802            for b in all.iter().skip(i + 1) {
9803                assert_ne!(
9804                    a, b,
9805                    "SUPERVISOR_CHILD_KEY_* consts must be pairwise-\
9806                     distinct canonical byte-sequences — got `{a}` == `{b}`",
9807                );
9808            }
9809        }
9810    }
9811
9812    #[test]
9813    fn supervisor_child_key_consts_are_lower_camel_case_shape() {
9814        // Shape-pin: every `SUPERVISOR_CHILD_KEY_*` const must be a
9815        // lowerCamelCase byte-sequence (no `snake_case` underscores, no
9816        // `kebab-case` hyphens, no leading colon, no `PascalCase` leading
9817        // capital, no whitespace / dots) — the canonical shape the
9818        // `#[serde(rename_all = "camelCase")]` derive produces on
9819        // `ChildSpec`. A future flip to a non-camelCase attribute at the
9820        // derive surfaces both here (this test fails on the
9821        // stale-constant shape) and at
9822        // `child_spec_serde_keys_match_lifted_supervisor_child_key_consts`
9823        // (that test fails on the mismatch between const and derive).
9824        // Peer with `supervisor_key_consts_are_lower_camel_case_shape`
9825        // (40cc4e5) on the sibling `SupervisorSpec` top-level axis.
9826        for key in [
9827            crate::render::SUPERVISOR_CHILD_KEY_CAIXA,
9828            crate::render::SUPERVISOR_CHILD_KEY_VERSAO,
9829            crate::render::SUPERVISOR_CHILD_KEY_RESTART,
9830        ] {
9831            assert!(
9832                !key.is_empty(),
9833                "SUPERVISOR_CHILD_KEY_* must be non-empty (got {key:?})"
9834            );
9835            let first = key.chars().next().unwrap();
9836            assert!(
9837                first.is_ascii_lowercase(),
9838                "SUPERVISOR_CHILD_KEY_* must lead with an ASCII-lowercase \
9839                 byte (got {key:?}, leads with {first:?})",
9840            );
9841            assert!(
9842                key.chars().all(|c| c.is_ascii_alphanumeric()),
9843                "SUPERVISOR_CHILD_KEY_* must be ASCII-alphanumeric only \
9844                 — no `_` / `-` / `:` / `.` / whitespace (got {key:?})",
9845            );
9846        }
9847    }
9848
9849    // ── drift-detection: serde-derive-to-SUPERVISOR_ESTRATEGIA_* identity ────
9850
9851    #[test]
9852    fn restart_strategy_variants_serialize_to_lifted_scalar_values() {
9853        // The fail-before-pass-after pin: pre-lift there was no
9854        // single-source binding between the [`RestartStrategy`] variant
9855        // name the un-`rename`d `Serialize` derive emits under
9856        // [`crate::render::SUPERVISOR_KEY_ESTRATEGIA`] and the byte-string
9857        // every downstream cluster-side dispatcher (the future
9858        // wasm-operator's per-supervisor sibling-restart branch, the
9859        // future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
9860        // admission-time enum-arm bind, the `caixa-operator`'s
9861        // hierarchical reconciliation scheduler's per-strategy fan-out)
9862        // probes verbatim. A future `#[serde(rename_all = "kebab-case")]`
9863        // attribute on the enum — or a per-variant `#[serde(rename = "…")]`
9864        // override, or a variant rename in the source — would silently
9865        // rebrand the emitted scalar under one spelling while every
9866        // downstream dispatcher still probed the other, with the failure
9867        // surfacing at the operator's reconcile posture (subtrees coming
9868        // up under the `default()` `OneForOne` arm rather than the typed
9869        // slot's declared strategy — a bad child would then only take
9870        // itself down instead of the sibling set the author intended, so
9871        // shared-state children fall out of sync) far from the source
9872        // rebrand commit and with no field naming the drift. Pinning the
9873        // two paths (the `Serialize` derive's serialized string AND the
9874        // [`RestartStrategy::as_str`] helper) to the same four lifted
9875        // [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE`] /
9876        // [`crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL`] /
9877        // [`crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`] /
9878        // [`crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE`]
9879        // byte-strings makes any future drift on either endpoint fail
9880        // here at caixa-core build time. Peer of the M3
9881        // `placement_strategy_variants_serialize_to_lifted_scalar_values`
9882        // (3f0e21c) on the sibling `PlacementStrategy` axis — same
9883        // three-path-convergence discipline, extended to close the
9884        // OTP-shaped per-supervisor sibling-restart axis.
9885        for (variant, expected) in [
9886            (
9887                RestartStrategy::OneForOne,
9888                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
9889            ),
9890            (
9891                RestartStrategy::OneForAll,
9892                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
9893            ),
9894            (
9895                RestartStrategy::RestForOne,
9896                crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
9897            ),
9898            (
9899                RestartStrategy::SimpleOneForOne,
9900                crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
9901            ),
9902        ] {
9903            let json = serde_json::to_string(&variant).unwrap();
9904            assert_eq!(
9905                json,
9906                format!("\"{expected}\""),
9907                "RestartStrategy::{variant:?} must serialize to {expected:?}"
9908            );
9909            assert_eq!(
9910                variant.as_str(),
9911                expected,
9912                "RestartStrategy::{variant:?}.as_str() must return the lifted \
9913                 SUPERVISOR_ESTRATEGIA_* constant"
9914            );
9915        }
9916    }
9917
9918    #[test]
9919    fn supervisor_estrategia_consts_are_pairwise_distinct() {
9920        // Cross-arm drift-detection pin: a future collapse of two
9921        // canonical variant byte-strings onto the same value (e.g. an
9922        // accidental copy-paste flip of `SUPERVISOR_ESTRATEGIA_REST_FOR_ONE`
9923        // to also read `"OneForOne"`) would silently reroute every
9924        // downstream operator's per-strategy dispatch onto the sibling
9925        // arm's reconcile branch and pass every propagation-probe test
9926        // that expected only the stale arm's value — the mis-strategied
9927        // subtree would come up with the wrong sibling-restart posture
9928        // on every subsequent failure. Peer of the sibling four-way
9929        // distinct pin `supervisor_key_consts_are_pairwise_distinct`
9930        // (40cc4e5) on the top-level `SUPERVISOR_KEY_*` axis.
9931        let all = [
9932            crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
9933            crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
9934            crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
9935            crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
9936        ];
9937        for (i, a) in all.iter().enumerate() {
9938            for (j, b) in all.iter().enumerate() {
9939                if i != j {
9940                    assert_ne!(
9941                        a, b,
9942                        "SUPERVISOR_ESTRATEGIA_* consts must be pairwise distinct \
9943                         — got duplicate {a:?} at indices {i} and {j}",
9944                    );
9945                }
9946            }
9947        }
9948    }
9949
9950    #[test]
9951    fn restart_strategy_display_routes_through_as_str_helper() {
9952        // The fail-before-pass-after pin on the first half of the
9953        // three-path convergence: pre-convergence the sibling
9954        // OTP-shape typed enum [`RestartStrategy`] carried a
9955        // [`std::fmt::Display`] surface via its
9956        // `#[discriminant(also_display)]` gen-platform derive route,
9957        // which arrived kebab-case as `"one-for-one"` /
9958        // `"one-for-all"` / `"rest-for-one"` /
9959        // `"simple-one-for-one"` while the wire format ran as
9960        // PascalCase `"OneForOne"` / `"OneForAll"` / `"RestForOne"` /
9961        // `"SimpleOneForOne"` through the un-`rename`d serde derive.
9962        // Every consumer reaching for a strategy byte-string past the
9963        // wire format had to pick between three paths
9964        // ([`RestartStrategy::as_str`], the `Serialize` derive's
9965        // serialized string, or `format!("{v}")` on the
9966        // discriminant-Display route), any two of which a future
9967        // variant rename or `#[serde(rename_all = "kebab-case")]`
9968        // attribute would silently desynchronize. Wiring
9969        // [`std::fmt::Display`] through [`RestartStrategy::as_str`]
9970        // closes the third path: every `format!("{v}")` call reaches
9971        // the same lifted [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
9972        // const the wire format and the [`RestartStrategy::as_str`]
9973        // helper already route through, so a future variant rename
9974        // lands at exactly one place. Pin the routing here so a future
9975        // `impl std::fmt::Display for RestartStrategy`
9976        // reimplementation that hand-rolls the arms instead of
9977        // delegating to [`RestartStrategy::as_str`] fails at
9978        // caixa-core build time. Peer of the M3
9979        // `placement_strategy_display_routes_through_as_str_helper`
9980        // (cc8f749) which the M3 axis converged first.
9981        for &variant in RestartStrategy::ALL {
9982            assert_eq!(
9983                variant.to_string(),
9984                variant.as_str(),
9985                "RestartStrategy::{variant:?} Display must route through \
9986                 RestartStrategy::as_str (single source of truth: the lifted \
9987                 SUPERVISOR_ESTRATEGIA_* const the wire format also emits)"
9988            );
9989        }
9990    }
9991
9992    #[test]
9993    fn restart_strategy_display_matches_serialized_wire_byte_string() {
9994        // The fail-before-pass-after pin on the second half of the
9995        // three-path convergence: `Display` (user-facing text) agrees
9996        // byte-for-byte with the `Serialize` derive's wire format
9997        // (canonical camelCase-schema `SUPERVISOR_KEY_ESTRATEGIA`
9998        // scalar) on every variant. Pre-convergence the two paths
9999        // were structurally independent — a future
10000        // `#[serde(rename_all = "kebab-case")]` attribute on the
10001        // enum would silently rebrand the emitted wire scalar
10002        // (`one-for-one`, `one-for-all`, `rest-for-one`,
10003        // `simple-one-for-one`) while every consumer that
10004        // pretty-prints the strategy (the future wasm-operator's
10005        // per-supervisor sibling-restart-strategy diagnostic line,
10006        // the future `feira app graph` per-supervisor strategy line,
10007        // the future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
10008        // materializer's admission-webhook rejection body) would
10009        // still emit the PascalCase form the `as_str` / `Display`
10010        // route returns, with the mismatch surfacing at consumer
10011        // parse time / operator dispatch time far from the source
10012        // rebrand commit. Pin the two paths byte-for-byte here so any
10013        // future serde-attribute or variant-rename drift is a
10014        // caixa-core-build-time test failure at this call, not a
10015        // silent per-consumer dispatch miss. Peer of the M3
10016        // `placement_strategy_display_matches_serialized_wire_byte_string`
10017        // (cc8f749) which the M3 axis converged first.
10018        for &variant in RestartStrategy::ALL {
10019            let wire = serde_json::to_string(&variant).unwrap();
10020            let unquoted = wire
10021                .strip_prefix('"')
10022                .and_then(|s| s.strip_suffix('"'))
10023                .expect("serialized RestartStrategy is a JSON string");
10024            assert_eq!(
10025                variant.to_string(),
10026                unquoted,
10027                "RestartStrategy::{variant:?} Display byte-string must match the \
10028                 Serialize derive's wire byte-string (three-path convergence: \
10029                 Display + as_str + Serialize all resolve to the same \
10030                 SUPERVISOR_ESTRATEGIA_* const)"
10031            );
10032        }
10033    }
10034
10035    #[test]
10036    fn restart_strategy_as_ref_str_routes_through_as_str_accessor() {
10037        // Fail-before-pass-after byte-parity pin on the lifted
10038        // `impl AsRef<str> for RestartStrategy` — asserts the
10039        // standard-library trait impl and the substrate-primitive
10040        // [`RestartStrategy::as_str`] `pub const fn` accessor resolve
10041        // to the same `&str` per instance across the four-arm
10042        // closed set, so any future silent detour that routes the
10043        // impl through a divergent projection (a per-arm inline
10044        // `match self { RestartStrategy::OneForOne => "OneForOne", … }`
10045        // re-inlining that opens a compile-time link to the un-lifted
10046        // arm-literal, a swap onto the kebab-case
10047        // [`gen_platform::Discriminant`] catalog identity that would
10048        // collide the wire axis with the dispatcher-catalog axis) trips
10049        // at caixa-core test time under `PartialEq` rather than at a
10050        // downstream `impl AsRef<str>`-bound consumer's silent split.
10051        // Sweeps every one of the four arms
10052        // [`RestartStrategy::ALL`] carries so no arm's projection is
10053        // covered only by the sibling wire-format `Serialize` derive
10054        // path. Peer of the sibling
10055        // [`crate::version::tests::caixa_version_as_ref_str_routes_through_as_str_accessor`]
10056        // (16d5c7e) `AsRef<str>`-byte-parity pin on the paired
10057        // top-level `:versao` typed newtype — the two pins together
10058        // cover the substrate primitive's `AsRef<str>` projection axis
10059        // on the paired newtype + closed-set-typed-enum surface.
10060        for &variant in RestartStrategy::ALL {
10061            assert_eq!(
10062                <RestartStrategy as AsRef<str>>::as_ref(&variant),
10063                variant.as_str(),
10064                "AsRef<str> impl on RestartStrategy::{variant:?} must \
10065                 byte-equal RestartStrategy::as_str on the same instance \
10066                 — divergence signals a silent detour off the substrate-\
10067                 primitive accessor"
10068            );
10069        }
10070    }
10071
10072    #[test]
10073    fn restart_strategy_as_ref_str_routes_through_display_via_shared_accessor() {
10074        // Fail-before-pass-after byte-parity pin on the three-path
10075        // convergence discipline the M2 sibling-restart primitive now
10076        // carries on the `&str`-projection axis:
10077        // `<RestartStrategy as AsRef<str>>::as_ref(&s)` (the newly
10078        // lifted impl), `format!("{s}")` (the pre-existing
10079        // [`fmt::Display`] impl), and `s.as_str()` (the substrate-
10080        // primitive `pub const fn` accessor both trait impls delegate
10081        // through) must resolve to the same byte-string on every
10082        // instance across the four-arm closed set. Refuses any future
10083        // divergence between the two trait impls (a stray
10084        // [`fmt::Display::fmt`] rewrite that hand-rolls the arms
10085        // rather than delegating through the shared accessor; a
10086        // hypothetical `AsRef<str>` rewrite that inlines a per-arm
10087        // literal cascade) that would silently split the two
10088        // projection paths of the same closed-set typed enum. Mirrors
10089        // the sibling three-path-convergence discipline the peer
10090        // [`crate::CaixaVersion`] typed newtype carries on its
10091        // `AsRef<str>` / `Display` / `as_str` triple
10092        // (version.rs pin
10093        // `caixa_version_as_ref_str_routes_through_display_via_shared_accessor`,
10094        // 16d5c7e).
10095        for &variant in RestartStrategy::ALL {
10096            let via_as_ref: &str = <RestartStrategy as AsRef<str>>::as_ref(&variant);
10097            let via_display: String = format!("{variant}");
10098            let via_accessor: &str = variant.as_str();
10099            assert_eq!(via_as_ref, via_accessor);
10100            assert_eq!(via_display, via_accessor);
10101            assert_eq!(via_as_ref, via_display.as_str());
10102        }
10103    }
10104
10105    #[test]
10106    fn restart_strategy_all_enumerates_every_variant_exactly_once() {
10107        // Fail-before-pass-after pin on the [`RestartStrategy::ALL`]
10108        // exhaustive-iteration surface: every variant appears exactly
10109        // once, and the slice length matches the arm count of the
10110        // closed set. Every consumer that walks the accepted-strategy
10111        // set (a future `feira supervisor --estrategia …` CLI-side
10112        // arg-parse's "did you mean" hint, a future M4 admission-
10113        // webhook's rejection body naming the accepted-`:estrategia`
10114        // list, the [`RestartStrategy::from_wire`] reverse-projection
10115        // consumers that iterate the accept-set for diagnostic
10116        // rendering) reads through this slice, so a future arm addition
10117        // that grows the enum but forgets to grow [`Self::ALL`]
10118        // silently truncates every downstream consumer's accept-set at
10119        // the same pre-addition boundary — this pin fails at caixa-core
10120        // build time on the pairwise-distinct + arm-count invariants.
10121        //
10122        // Peer of the sibling [`crate::CaixaKind::ALL`] (6b1f4fb) /
10123        // [`crate::aplicacao::PlacementStrategy::ALL`] (18c7342) /
10124        // [`crate::aplicacao::RateLimitUnit::ALL`] (6bce03d) /
10125        // [`crate::dep::DepList::ALL`] (45ee563) exhaustive-iteration
10126        // pins on the peer closed-set typed-enum axes.
10127        let all: &[RestartStrategy] = RestartStrategy::ALL;
10128        assert_eq!(
10129            all.len(),
10130            4,
10131            "RestartStrategy::ALL must enumerate every variant of the \
10132             four-arm closed set (OneForOne, OneForAll, RestForOne, \
10133             SimpleOneForOne); got {all:?}"
10134        );
10135        for (i, a) in all.iter().enumerate() {
10136            for (j, b) in all.iter().enumerate() {
10137                if i != j {
10138                    assert_ne!(
10139                        a, b,
10140                        "RestartStrategy::ALL must carry every variant exactly \
10141                         once — got duplicate {a:?} at indices {i} and {j}"
10142                    );
10143                }
10144            }
10145        }
10146        for variant in [
10147            RestartStrategy::OneForOne,
10148            RestartStrategy::OneForAll,
10149            RestartStrategy::RestForOne,
10150            RestartStrategy::SimpleOneForOne,
10151        ] {
10152            assert!(
10153                all.contains(&variant),
10154                "RestartStrategy::ALL must contain {variant:?} — a future arm \
10155                 addition that grows the enum but forgets to grow the ALL slice \
10156                 silently truncates every downstream consumer's accept-set at \
10157                 the pre-addition boundary"
10158            );
10159        }
10160    }
10161
10162    #[test]
10163    fn restart_strategy_wire_names_covers_every_arm() {
10164        // Load-bearing pin on the substrate-canonical
10165        // [`RestartStrategy::WIRE_NAMES`] exhaustive accept-set roster
10166        // on the `PascalCase` wire byte-string axis: every variant of
10167        // the sibling [`RestartStrategy::ALL`] exhaustive-iteration
10168        // surface must project through [`RestartStrategy::as_str`] onto
10169        // an entry the [`RestartStrategy::WIRE_NAMES`] roster carries,
10170        // and the roster's length must byte-equal
10171        // `RestartStrategy::ALL.len()` so a silent skew between the
10172        // [`RestartStrategy::as_str`] match's arm-set and the roster's
10173        // arm-set trips here at caixa-core test time rather than at a
10174        // downstream M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
10175        // admission-webhook rejection body's wire-form `:estrategia`
10176        // accepted-set enumeration miss / a `feira supervisor
10177        // --estrategia …` "did you mean" hint drift / a future
10178        // wasm-operator per-reconcile-step diagnostic log line's
10179        // accepted-wire-form enumeration miss. A future arm addition
10180        // (an OTP-`rest_for_all` arm the theory
10181        // [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
10182        // might reach for once the four canonical OTP strategies stop
10183        // covering the substrate's discovered load-shape) extends
10184        // [`RestartStrategy::ALL`] as a single edit and this pin
10185        // sweeps the new arm by iteration; the paired
10186        // [`RestartStrategy::WIRE_NAMES`] roster must grow in lockstep
10187        // or this assertion trips. Every entry is further pinned to
10188        // open with an ASCII uppercase byte so a silent collapse of
10189        // the wire-form axis with the peer kebab-case
10190        // dispatcher-catalog axis (an entry byte-identical to a
10191        // sibling [`Self::discriminant`] kebab byte-string that would
10192        // let a wire-axis consumer accept the dispatcher-catalog
10193        // vocabulary) trips here rather than at a downstream K8s-CR
10194        // round-trip miss.
10195        //
10196        // Peer of the sibling
10197        // [`crate::kind::tests::caixa_kind_wire_names_covers_every_arm`]
10198        // (bd708bd) pin on the top-level typed-kind discriminator's
10199        // `PascalCase` wire byte-string axis, and of the sibling
10200        // [`crate::upgrade::tests::upgrade_instruction_wire_forms_covers_every_arm`]
10201        // (cc42c0e) /
10202        // [`crate::upgrade::tests::upgrade_instruction_lisp_forms_covers_every_arm`]
10203        // (1898d77) pins on the OTP-appup discriminator's two-axis
10204        // roster split — the same closed-set exhaustive-roster
10205        // coverage discipline extended here onto the first M2
10206        // OTP-shape sibling-restart closed-set typed enum.
10207        //
10208        // Fail-before-pass-after locally verified by mutating one arm
10209        // of the paired [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
10210        // const family (e.g. dropping the trailing `e` from
10211        // `"OneForOne"` → `"OneForOn"`) — the length pin still passes
10212        // but the `contains` check fires on the mutated arm; and by
10213        // shortening the roster to three entries — the length pin
10214        // fires first.
10215        assert_eq!(
10216            RestartStrategy::WIRE_NAMES.len(),
10217            RestartStrategy::ALL.len(),
10218            "RestartStrategy::WIRE_NAMES.len() must byte-equal \
10219             RestartStrategy::ALL.len() — a mismatch means the roster \
10220             and the enum's arm-set have drifted; downstream consumers \
10221             that fan through both will silently disagree on the \
10222             accepted arm-set"
10223        );
10224        for &variant in RestartStrategy::ALL {
10225            let wire = variant.as_str();
10226            assert!(
10227                RestartStrategy::WIRE_NAMES.contains(&wire),
10228                "RestartStrategy::{variant:?}.as_str() = {wire:?} must \
10229                 be a member of RestartStrategy::WIRE_NAMES — the \
10230                 emitter and the roster have drifted out of lockstep"
10231            );
10232        }
10233        for tag in RestartStrategy::WIRE_NAMES {
10234            let first = tag.chars().next().unwrap_or_else(|| {
10235                panic!(
10236                    "RestartStrategy::WIRE_NAMES entry {tag:?} must be \
10237                     a non-empty PascalCase byte-string"
10238                )
10239            });
10240            assert!(
10241                first.is_ascii_uppercase(),
10242                "RestartStrategy::WIRE_NAMES entry {tag:?} must open \
10243                 with an ASCII uppercase byte (PascalCase wire form) — \
10244                 a lowercase entry would collide the wire-form axis \
10245                 with the peer kebab-case dispatcher-catalog axis \
10246                 [`RestartStrategy::discriminant`] serves"
10247            );
10248        }
10249    }
10250
10251    #[test]
10252    fn restart_strategy_from_wire_accepts_every_lifted_constant() {
10253        // Fail-before-pass-after pin on the forward accept-set of the
10254        // [`RestartStrategy::from_wire`] reverse projection: every
10255        // canonical [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
10256        // constant the [`RestartStrategy::as_str`] emitter walks parses
10257        // back to its paired variant. Any future arm addition that
10258        // grows the emitter's `as_str` match but forgets to grow the
10259        // parser's `from_wire` match silently splits the two halves of
10260        // the round-trip — the wire byte-string one non-serde consumer
10261        // parses from the one the emitter wrote — with the failure
10262        // surfacing at parse time far from the rebrand commit. Pinning
10263        // the four-arm accept-set here catches the drift at caixa-core
10264        // build time.
10265        //
10266        // Peer of the sibling [`crate::CaixaKind::from_wire`] (2aa6d23)
10267        // + [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342)
10268        // accept-set pins on the peer closed-set typed-enum `str → Self`
10269        // axes.
10270        for (wire, expected) in [
10271            (
10272                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
10273                RestartStrategy::OneForOne,
10274            ),
10275            (
10276                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
10277                RestartStrategy::OneForAll,
10278            ),
10279            (
10280                crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
10281                RestartStrategy::RestForOne,
10282            ),
10283            (
10284                crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
10285                RestartStrategy::SimpleOneForOne,
10286            ),
10287        ] {
10288            let parsed = RestartStrategy::from_wire(wire).unwrap_or_else(|| {
10289                panic!(
10290                    "RestartStrategy::from_wire({wire:?}) must accept every \
10291                     SUPERVISOR_ESTRATEGIA_* constant — got None for the \
10292                     lifted canonical byte-string that RestartStrategy::{expected:?} \
10293                     serializes as under SUPERVISOR_KEY_ESTRATEGIA"
10294                )
10295            });
10296            assert_eq!(
10297                parsed, expected,
10298                "RestartStrategy::from_wire({wire:?}) must return \
10299                 RestartStrategy::{expected:?}; got RestartStrategy::{parsed:?}"
10300            );
10301        }
10302    }
10303
10304    #[test]
10305    fn restart_strategy_from_wire_round_trips_through_as_str() {
10306        // Fail-before-pass-after pin on the closed round-trip between
10307        // the forward [`RestartStrategy::as_str`] emitter and the
10308        // reverse [`RestartStrategy::from_wire`] parser: for every
10309        // variant in [`RestartStrategy::ALL`], parsing the emitter's
10310        // output must return exactly the same variant. Any per-arm
10311        // divergence — a future arm added to `as_str` but not
10312        // `from_wire`, an accidental copy-paste flip in one but not
10313        // the other — silently splits the emit and parse halves and
10314        // the failure surfaces at consumer parse time far from the
10315        // drift site. The `ALL`-iterating shape means a future arm
10316        // addition picks up the coverage by construction.
10317        //
10318        // Peer of the sibling
10319        // [`crate::aplicacao::tests::placement_strategy_from_wire_round_trips_through_as_str`]
10320        // (18c7342) round-trip pin on
10321        // [`crate::aplicacao::PlacementStrategy::from_wire`] and
10322        // [`crate::kind::tests::caixa_kind_wire_round_trips_through_from_wire`]
10323        // (6b1f4fb) round-trip pin on [`crate::CaixaKind::from_wire`].
10324        for &variant in RestartStrategy::ALL {
10325            let wire = variant.as_str();
10326            let parsed = RestartStrategy::from_wire(wire).unwrap_or_else(|| {
10327                panic!(
10328                    "RestartStrategy::from_wire(RestartStrategy::{variant:?}.as_str()) \
10329                     must be Some({variant:?}) — the two halves of the round-trip \
10330                     dispatch on the same lifted SUPERVISOR_ESTRATEGIA_* consts; \
10331                     got None on wire byte-string {wire:?}"
10332                )
10333            });
10334            assert_eq!(
10335                parsed, variant,
10336                "RestartStrategy::from_wire(RestartStrategy::{variant:?}.as_str()) \
10337                 must round-trip to the same variant; got {parsed:?}"
10338            );
10339        }
10340    }
10341
10342    #[test]
10343    fn restart_strategy_from_wire_rejects_unknown_byte_strings() {
10344        // Fail-before-pass-after pin on the closed-set refusal
10345        // discipline of [`RestartStrategy::from_wire`]: every
10346        // byte-string outside the four-arm accept-set returns `None`
10347        // rather than silently collapsing onto the [`Default`]
10348        // (`OneForOne`) arm or an arbitrary neighbor. The refusal set
10349        // exercised here sweeps the load-bearing drift shapes: the
10350        // empty string (a stripped serde-attribute drift), all-
10351        // whitespace strings (the canonical text-editor accidental
10352        // padding shape), the kebab-case dispatcher-catalog identities
10353        // (`"one-for-one"` / `"one-for-all"` / `"rest-for-one"` /
10354        // `"simple-one-for-one"` — the [`gen_platform::FromStrKind`]-
10355        // derived [`std::str::FromStr`] accept-set, which parses the
10356        // *other* axis of this enum's two-axis split and must not leak
10357        // into the `from_wire` PascalCase-wire accept-set), the
10358        // lowercased single-word forms (`"oneforone"`), the padded
10359        // canonical scalar (`" OneForOne "`), the trailing-newline
10360        // shapes (`"OneForOne\n"`), and neighboring-but-unknown arms
10361        // (`"AllForOne"` — the canonical typo direction).
10362        //
10363        // Peer of the sibling
10364        // [`crate::kind::tests::caixa_kind_from_wire_rejects_unknown_byte_strings`]
10365        // (2aa6d23) +
10366        // [`crate::aplicacao::tests::placement_strategy_from_wire_rejects_unknown_byte_strings`]
10367        // (18c7342) refusal pins on the peer closed-set typed-enum
10368        // axes.
10369        for bad in [
10370            "",
10371            " ",
10372            "\n",
10373            "\t",
10374            "one-for-one",
10375            "one-for-all",
10376            "rest-for-one",
10377            "simple-one-for-one",
10378            "oneforone",
10379            "OneForOnes",
10380            "one_for_one",
10381            "one for one",
10382            "ONEFORONE",
10383            "OneForOne ",
10384            " OneForOne",
10385            " SimpleOneForOne ",
10386            "OneForOne\n",
10387            "restforone",
10388            "REST_FOR_ONE",
10389            "AllForOne",
10390            "Simple",
10391            "?",
10392        ] {
10393            assert!(
10394                RestartStrategy::from_wire(bad).is_none(),
10395                "RestartStrategy::from_wire({bad:?}) must return None — the \
10396                 parser's accept-set is exactly the four RestartStrategy::as_str \
10397                 outputs (OneForOne, OneForAll, RestForOne, SimpleOneForOne), \
10398                 and this byte-string is outside that closed set"
10399            );
10400        }
10401    }
10402
10403    #[test]
10404    fn restart_strategy_from_wire_matches_serialize_derive_wire_byte_string() {
10405        // Fail-before-pass-after pin on the fourth path of the four-path
10406        // convergence: `from_wire` (the reverse projection) inverts the
10407        // `Serialize` derive's wire byte-string on every variant.
10408        // Together with the pre-existing three-path convergence
10409        // (`Display` + `as_str` + `Serialize` all resolve to the same
10410        // lifted [`crate::render::SUPERVISOR_ESTRATEGIA_*`] const,
10411        // pinned by
10412        // [`restart_strategy_display_matches_serialized_wire_byte_string`])
10413        // this closes the round-trip: the wire byte-string the
10414        // `Serialize` derive emits parses back to the same variant
10415        // through `from_wire`, so any future serde-attribute or variant-
10416        // rename drift on the emit half now surfaces as a matched drift
10417        // on the parse half at caixa-core build time — the two halves
10418        // migrate as a unit through the lifted consts on any future
10419        // rename, and the round-trip cannot silently split.
10420        //
10421        // Peer of the sibling
10422        // [`crate::aplicacao::tests::placement_strategy_from_wire_matches_serialize_derive_wire_byte_string`]
10423        // (18c7342) wire-format pin on
10424        // [`crate::aplicacao::PlacementStrategy::from_wire`].
10425        for &variant in RestartStrategy::ALL {
10426            let wire = serde_json::to_string(&variant).unwrap();
10427            let unquoted = wire
10428                .strip_prefix('"')
10429                .and_then(|s| s.strip_suffix('"'))
10430                .expect("serialized RestartStrategy is a JSON string");
10431            let parsed = RestartStrategy::from_wire(unquoted).unwrap_or_else(|| {
10432                panic!(
10433                    "RestartStrategy::from_wire({unquoted:?}) must accept the \
10434                     Serialize derive's wire byte-string for \
10435                     RestartStrategy::{variant:?} — the four-path convergence \
10436                     (Display + as_str + Serialize + from_wire) resolves through \
10437                     the same lifted SUPERVISOR_ESTRATEGIA_* const; got None"
10438                )
10439            });
10440            assert_eq!(
10441                parsed, variant,
10442                "RestartStrategy::from_wire of the Serialize derive's wire \
10443                 byte-string for RestartStrategy::{variant:?} must round-trip \
10444                 to the same variant; got {parsed:?}"
10445            );
10446        }
10447    }
10448
10449    #[test]
10450    fn restart_strategy_try_from_str_routes_through_from_wire_accessor() {
10451        // Fail-before-pass-after byte-parity pin on the newly lifted
10452        // `impl TryFrom<&str> for RestartStrategy` — asserts the standard-
10453        // library trait impl and the substrate-primitive
10454        // [`RestartStrategy::from_wire`] `Option<Self>` accessor resolve to
10455        // the same four-arm accept-set across every arm the exhaustive
10456        // [`RestartStrategy::ALL`] slice enumerates. Any future silent
10457        // detour that routes the trait impl through a divergent projection
10458        // (a per-arm inline `match s { "OneForOne" => Ok(Self::OneForOne),
10459        // … }` re-inlining that opens a compile-time link to the un-
10460        // lifted arm-literal, a hypothetical `#[serde(rename_all = "…")]`
10461        // attribute drift that silently splits the wire byte-string from
10462        // every consumer that reaches for this typed dispatch, an
10463        // accidental swap onto the kebab-case dispatcher-catalog axis the
10464        // pre-existing [`std::str::FromStr`] impl parses through and which
10465        // would collide the two-axis wire/catalog split the sibling
10466        // [`RestartStrategy::from_wire`] doc block makes load-bearing)
10467        // trips at caixa-core test time under `assert_eq!` rather than at
10468        // a downstream `impl TryFrom<&str>`-bound consumer's silent split.
10469        // Sweeps every one of the four arms [`RestartStrategy::ALL`]
10470        // carries so no arm's projection is covered only by the sibling
10471        // method-named `from_wire` path. Peer of the sibling
10472        // [`crate::kind::tests::caixa_kind_try_from_str_routes_through_from_wire_accessor`]
10473        // (3c83606),
10474        // [`crate::dialeto::tests::caixa_dialeto_try_from_str_routes_through_from_wire_accessor`]
10475        // (bf33136), and the M3
10476        // [`crate::aplicacao::tests::placement_strategy_try_from_str_routes_through_from_wire_accessor`]
10477        // (6fd00cd) — extends the trait-idiomatic reverse-projection axis
10478        // onto the first M2-OTP-shape closed-set typed enum on the caixa
10479        // surface.
10480        for &variant in RestartStrategy::ALL {
10481            let wire = variant.as_str();
10482            assert_eq!(
10483                <RestartStrategy as TryFrom<&str>>::try_from(wire),
10484                Ok(variant),
10485                "TryFrom<&str> impl on RestartStrategy must round-trip \
10486                 RestartStrategy::{variant:?}.as_str() = {wire:?} back to \
10487                 Ok(RestartStrategy::{variant:?}) — divergence from \
10488                 RestartStrategy::from_wire signals a silent detour off \
10489                 the substrate-primitive accessor"
10490            );
10491            assert_eq!(
10492                <RestartStrategy as TryFrom<&str>>::try_from(wire).ok(),
10493                RestartStrategy::from_wire(wire),
10494                "TryFrom<&str> ok()-projection on {wire:?} must byte-equal \
10495                 RestartStrategy::from_wire on the same input"
10496            );
10497        }
10498    }
10499
10500    #[test]
10501    fn restart_strategy_try_from_str_rejects_unknown_byte_strings() {
10502        // Rejection witness on the `impl TryFrom<&str> for
10503        // RestartStrategy` — sweeps a candidate set of byte-strings
10504        // outside the four-arm PascalCase wire accept-set the sibling
10505        // [`RestartStrategy::as_str`] emits and asserts every one lands on
10506        // `Err(())`, so a future accidental widening of the trait impl's
10507        // accept-set (a stray additional
10508        // `_ if s.eq_ignore_ascii_case("OneForOne") => Ok(…)` case-fold
10509        // path, a silent inclusion of the kebab-case dispatcher-catalog
10510        // byte-string the pre-existing [`std::str::FromStr`] impl the
10511        // [`gen_platform::FromStrKind`] derive installs parses onto the
10512        // wire axis — which would collide the two-axis
10513        // wire/dispatcher-catalog split the sibling
10514        // [`RestartStrategy::from_wire`] doc block makes load-bearing —
10515        // an English-rebrand or plural-arm silent alias that would
10516        // widen the wire accept-set past the OTP-canonical four) trips at
10517        // caixa-core test time. The candidate set includes the empty
10518        // string, whitespace-only padding, the kebab-case dispatcher-
10519        // catalog byte-strings on the sibling axis (a caller who confuses
10520        // the two axes trips here rather than at a downstream consumer's
10521        // silent reject), a lowercase / uppercase / mixed-case fold of
10522        // each PascalCase arm (a caller who assumes case-fold acceptance
10523        // trips here), leading/trailing whitespace padding, the trailing-
10524        // newline shape, quote-wrapped candidates, and a residual set of
10525        // plausible-but-wrong English rebrand candidates. Peer of the
10526        // sibling
10527        // [`crate::kind::tests::caixa_kind_try_from_str_rejects_unknown_byte_strings`]
10528        // (3c83606) and
10529        // [`crate::aplicacao::tests::placement_strategy_try_from_str_rejects_unknown_byte_strings`]
10530        // (6fd00cd) rejection witnesses.
10531        let rejected: &[&str] = &[
10532            "",
10533            " ",
10534            "\n",
10535            "\t",
10536            "one-for-one",
10537            "one-for-all",
10538            "rest-for-one",
10539            "simple-one-for-one",
10540            "oneforone",
10541            "one_for_one",
10542            "OneForOnes",
10543            "ONEFORONE",
10544            "oneforall",
10545            "restforone",
10546            "simpleoneforone",
10547            "OneForOne ",
10548            " OneForOne",
10549            " OneForAll ",
10550            "OneForOne\n",
10551            "RestForOne\t",
10552            "OneForEach",
10553            "AllForOne",
10554            "one for one",
10555            "\"OneForOne\"",
10556            "?",
10557        ];
10558        for &input in rejected {
10559            assert_eq!(
10560                <RestartStrategy as TryFrom<&str>>::try_from(input),
10561                Err(()),
10562                "TryFrom<&str> impl on RestartStrategy must reject the \
10563                 non-wire byte-string {input:?} — silent acceptance signals \
10564                 an accept-set widening off the paired \
10565                 RestartStrategy::from_wire resolver"
10566            );
10567        }
10568    }
10569
10570    #[test]
10571    fn restart_strategy_try_from_str_and_from_wire_partition_the_accept_set() {
10572        // Cross-axis partition pin: the paired `TryFrom<&str>` and
10573        // `from_wire` reverse projections must resolve identically on
10574        // *every* input, not just the ones [`RestartStrategy::ALL`]
10575        // enumerates. Sweeps a mixed candidate set spanning accepted
10576        // (four-arm PascalCase wire byte-strings) and rejected (kebab-case
10577        // dispatcher-catalog byte-strings, empty, whitespace-padded,
10578        // quoted, English-rebrand candidates) inputs and asserts the
10579        // trait's `Result::ok()` projection byte-equals the method-named
10580        // resolver's `Option<Self>` return-shape on each, locking the two
10581        // paths together by construction so any future detour (a stray
10582        // `try_from` special-case that widens or narrows the accept-set
10583        // outside the paired `from_wire` resolver, an accidental swap
10584        // onto the kebab-case [`std::str::FromStr`] impl the
10585        // [`gen_platform::FromStrKind`] derive installs on the sibling
10586        // dispatcher-catalog axis) trips at caixa-core test time. Peer of
10587        // the sibling
10588        // [`crate::kind::tests::caixa_kind_try_from_str_and_from_wire_partition_the_accept_set`]
10589        // pin — extends the round-trip discipline onto the M2-OTP-shape
10590        // sibling-restart axis.
10591        let candidates: &[&str] = &[
10592            "OneForOne",
10593            "OneForAll",
10594            "RestForOne",
10595            "SimpleOneForOne",
10596            "",
10597            "one-for-one",
10598            "one-for-all",
10599            "rest-for-one",
10600            "simple-one-for-one",
10601            "oneforone",
10602            "unknown",
10603            "OneForOne ",
10604            " OneForOne",
10605            "\"OneForOne\"",
10606            "OneForEach",
10607            "?",
10608        ];
10609        for &input in candidates {
10610            let via_trait: Option<RestartStrategy> =
10611                <RestartStrategy as TryFrom<&str>>::try_from(input).ok();
10612            let via_method: Option<RestartStrategy> = RestartStrategy::from_wire(input);
10613            assert_eq!(
10614                via_trait, via_method,
10615                "TryFrom<&str> and from_wire must resolve identically on \
10616                 input {input:?} — divergence signals the two reverse-\
10617                 projection paths have drifted onto different accept-sets"
10618            );
10619        }
10620    }
10621
10622    #[test]
10623    fn restart_strategy_from_into_static_str_routes_through_as_str_accessor() {
10624        // Fail-before-pass-after byte-parity pin on the newly lifted
10625        // `impl From<RestartStrategy> for &'static str` — asserts the
10626        // standard-library trait impl and the substrate-primitive
10627        // [`RestartStrategy::as_str`] `pub const fn` accessor resolve to
10628        // the same four-arm emit-set across every arm the exhaustive
10629        // [`RestartStrategy::ALL`] slice enumerates. Any future silent
10630        // detour that routes the trait impl through a divergent
10631        // projection (a per-arm inline `match strategy { OneForOne =>
10632        // "OneForOne", … }` re-inlining that opens a compile-time link to
10633        // the un-lifted arm-literal, an accidental swap onto the sibling
10634        // kebab-case [`Self::discriminant`] dispatcher-catalog axis that
10635        // would collide the two-axis wire/catalog split the sibling
10636        // [`RestartStrategy::from_wire`] doc block makes load-bearing) trips
10637        // at caixa-core test time under `assert_eq!` rather than at a
10638        // downstream `impl Into<&'static str>`-bound consumer's silent
10639        // split. Sweeps every one of the four arms
10640        // [`RestartStrategy::ALL`] carries so no arm's projection is
10641        // covered only by the sibling method-named `as_str` /
10642        // [`std::fmt::Display`] / [`AsRef<str>`] paths. Materializes the
10643        // `<&'static str as From<RestartStrategy>>::from` output in a
10644        // `const`-shape binding to make the `'static` lifetime promise a
10645        // build-time invariant — a future accidental downgrade of any of
10646        // the four arms' [`crate::render::SUPERVISOR_ESTRATEGIA_*`]
10647        // constants to a non-`&'static str` (a `String::leak()`-produced
10648        // return, a `Box::leak`-cast) trips at caixa-core build time
10649        // rather than at a downstream `'static`-bound consumer.
10650        const ONE_FOR_ONE: &str = RestartStrategy::OneForOne.as_str();
10651        const ONE_FOR_ALL: &str = RestartStrategy::OneForAll.as_str();
10652        const REST_FOR_ONE: &str = RestartStrategy::RestForOne.as_str();
10653        const SIMPLE_ONE_FOR_ONE: &str = RestartStrategy::SimpleOneForOne.as_str();
10654        for &variant in RestartStrategy::ALL {
10655            let via_trait: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
10656            let via_method: &'static str = variant.as_str();
10657            assert_eq!(
10658                via_trait, via_method,
10659                "From<RestartStrategy> for &'static str impl must round-trip \
10660                 RestartStrategy::{variant:?} to the same lifted \
10661                 SUPERVISOR_ESTRATEGIA_* const RestartStrategy::as_str returns — \
10662                 divergence signals a silent detour off the substrate-primitive \
10663                 accessor"
10664            );
10665            let via_into: &'static str = variant.into();
10666            assert_eq!(
10667                via_into, via_method,
10668                "Into<&'static str>::into on RestartStrategy::{variant:?} must \
10669                 byte-equal RestartStrategy::as_str on the same input — the \
10670                 blanket-derived Into shape must resolve to the same as_str \
10671                 dispatch as the explicit From impl"
10672            );
10673        }
10674        assert_eq!(
10675            [ONE_FOR_ONE, ONE_FOR_ALL, REST_FOR_ONE, SIMPLE_ONE_FOR_ONE],
10676            [
10677                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
10678                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
10679                crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
10680                crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
10681            ],
10682            "const-context RestartStrategy::as_str must resolve to the four \
10683             lifted SUPERVISOR_ESTRATEGIA_* consts — a future accidental \
10684             downgrade of any arm to a non-const or non-static byte-string \
10685             breaks the `&'static str`-lifetime promise the paired \
10686             From<RestartStrategy> for &'static str impl carries by \
10687             construction"
10688        );
10689    }
10690
10691    #[test]
10692    fn restart_strategy_from_into_static_str_and_as_str_partition_the_emit_set() {
10693        // Cross-axis partition pin: the paired trait-idiomatic
10694        // `From<RestartStrategy> for &'static str` forward projection and
10695        // the method-named [`RestartStrategy::as_str`] forward projection
10696        // must resolve identically on *every* arm, not just the ones
10697        // named in the primary byte-parity pin above. Sweeps every
10698        // [`RestartStrategy::ALL`] arm and asserts the trait's `From::from`
10699        // output byte-equals the method-named accessor's return-value on
10700        // each, locking the two forward-projection paths together by
10701        // construction so any future detour (a stray `From` special-case
10702        // that lands on a divergent per-arm literal outside the paired
10703        // `as_str` dispatch, a hypothetical rebrand touching one axis
10704        // without the other) trips at caixa-core test time. Peer of the
10705        // sibling reverse-projection partition pin
10706        // [`restart_strategy_try_from_str_and_from_wire_partition_the_accept_set`]
10707        // — extends the round-trip discipline onto the trait-idiomatic
10708        // *forward* axis, closing the two-way `Self ↔ &'static str`
10709        // round-trip on the trait-idiomatic pair
10710        // (`From<Self> for &'static str` + `TryFrom<&str> for Self`) as
10711        // well as the pre-existing method-named pair
10712        // (`as_str` + `from_wire`).
10713        for &variant in RestartStrategy::ALL {
10714            let via_trait: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
10715            let via_method: &'static str = variant.as_str();
10716            assert_eq!(
10717                via_trait, via_method,
10718                "From<RestartStrategy> for &'static str and \
10719                 RestartStrategy::as_str must resolve identically on \
10720                 RestartStrategy::{variant:?} — divergence signals the \
10721                 two forward-projection paths have drifted onto different \
10722                 emit-sets"
10723            );
10724        }
10725        // Round-trip witness: every arm's forward `From` output re-parses
10726        // through the paired trait-idiomatic reverse `TryFrom<&str>` back
10727        // to the original variant. Closes the two-way `RestartStrategy ↔
10728        // &'static str` round-trip on the trait-idiomatic axis pair,
10729        // mirroring the pre-existing method-named `as_str` + `from_wire`
10730        // round-trip on the substrate-primitive axis pair.
10731        for &variant in RestartStrategy::ALL {
10732            let emitted: &'static str = variant.into();
10733            let re_parsed: Result<RestartStrategy, ()> =
10734                <RestartStrategy as TryFrom<&str>>::try_from(emitted);
10735            assert_eq!(
10736                re_parsed,
10737                Ok(variant),
10738                "trait-idiomatic axis pair must round-trip \
10739                 RestartStrategy::{variant:?} through `.into::<&'static \
10740                 str>()` and back through `TryFrom<&str>` — a break signals \
10741                 the forward-emit and reverse-parse axes have drifted onto \
10742                 different vocabularies"
10743            );
10744        }
10745    }
10746
10747    #[test]
10748    fn restart_strategy_from_borrowed_into_static_str_routes_through_as_str_accessor() {
10749        // Fail-before-pass-after byte-parity pin on the newly lifted
10750        // `impl From<&RestartStrategy> for &'static str` — asserts the
10751        // borrowed-input standard-library trait impl and the substrate-
10752        // primitive [`RestartStrategy::as_str`] `pub const fn` accessor
10753        // resolve to the same four-arm emit-set across every arm the
10754        // exhaustive [`RestartStrategy::ALL`] slice enumerates. Rust's
10755        // `From` trait does not auto-derive the borrowed-input sibling
10756        // from a paired owned-input impl (no `impl<T, U> From<&T> for U
10757        // where T: Copy, U: From<T>` blanket in `core`), so the
10758        // borrowed-input axis is a distinct trait-idiomatic surface
10759        // that a `.iter().map(Into::into)` shape over
10760        // [`RestartStrategy::ALL`] (whose iterator yields
10761        // `&RestartStrategy`, not `RestartStrategy`) reaches through
10762        // this impl and no other — the paired owned-input
10763        // [`From<RestartStrategy>`] impl requires an explicit
10764        // `.copied()` / dereference before the trait fires.
10765        // Materializes the `<&'static str as
10766        // From<&RestartStrategy>>::from` output in a `const`-shape
10767        // binding to make the `'static` lifetime promise a build-time
10768        // invariant.
10769        const ONE_FOR_ONE: &str = RestartStrategy::OneForOne.as_str();
10770        const ONE_FOR_ALL: &str = RestartStrategy::OneForAll.as_str();
10771        const REST_FOR_ONE: &str = RestartStrategy::RestForOne.as_str();
10772        const SIMPLE_ONE_FOR_ONE: &str = RestartStrategy::SimpleOneForOne.as_str();
10773        for variant in RestartStrategy::ALL {
10774            let via_trait: &'static str = <&'static str as From<&RestartStrategy>>::from(variant);
10775            let via_method: &'static str = variant.as_str();
10776            assert_eq!(
10777                via_trait, via_method,
10778                "From<&RestartStrategy> for &'static str impl must \
10779                 round-trip &RestartStrategy::{variant:?} to the same \
10780                 lifted SUPERVISOR_ESTRATEGIA_* const \
10781                 RestartStrategy::as_str returns — divergence signals a \
10782                 silent detour off the substrate-primitive accessor"
10783            );
10784            let via_into: &'static str = variant.into();
10785            assert_eq!(
10786                via_into, via_method,
10787                "Into<&'static str>::into on &RestartStrategy::{variant:?} \
10788                 must byte-equal RestartStrategy::as_str on the same input — \
10789                 the blanket-derived Into shape must resolve to the same \
10790                 as_str dispatch as the explicit From impl"
10791            );
10792        }
10793        assert_eq!(
10794            [ONE_FOR_ONE, ONE_FOR_ALL, REST_FOR_ONE, SIMPLE_ONE_FOR_ONE],
10795            [
10796                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ONE,
10797                crate::render::SUPERVISOR_ESTRATEGIA_ONE_FOR_ALL,
10798                crate::render::SUPERVISOR_ESTRATEGIA_REST_FOR_ONE,
10799                crate::render::SUPERVISOR_ESTRATEGIA_SIMPLE_ONE_FOR_ONE,
10800            ],
10801            "const-context RestartStrategy::as_str must resolve to the \
10802             four lifted SUPERVISOR_ESTRATEGIA_* consts — the borrowed-\
10803             input From<&RestartStrategy> for &'static str impl inherits \
10804             its `'static` lifetime promise from the same accessor the \
10805             owned-input sibling routes through"
10806        );
10807    }
10808
10809    #[test]
10810    fn restart_strategy_from_owned_and_borrowed_into_static_str_agree_on_every_arm() {
10811        // Cross-axis partition pin: the paired trait-idiomatic
10812        // owned-input `From<RestartStrategy> for &'static str` (523157d
10813        // campaign-shape) and borrowed-input `From<&RestartStrategy> for
10814        // &'static str` (this lift) forward projections must resolve
10815        // identically on every arm, locking the two input-shape paths
10816        // together so any future detour trips at caixa-core test time.
10817        // Then a witness that a `.iter().map(Into::into)` pipe over
10818        // [`RestartStrategy::ALL`] (whose iterator yields
10819        // `&RestartStrategy`) materializes the four-arm accept-set
10820        // through the borrowed-input axis alone — the exact shape a
10821        // future wasm-operator per-supervisor sibling-restart-strategy
10822        // diagnostic line, a future substrate-wide per-arm diagnostic
10823        // column, or a
10824        // `HashMap::<&'static str, RestartStrategy>::from_iter(
10825        //     RestartStrategy::ALL.iter().map(|s| (s.into(), *s)))`-style
10826        // per-strategy lookup reaches through — closing the two-way
10827        // owned/borrowed input-shape symmetry on the forward-projection
10828        // trait-idiomatic axis. Peer of the sibling
10829        // [`crate::dep::tests::dep_list_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
10830        // (64aa742) /
10831        // [`crate::kind::tests::caixa_kind_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
10832        // (5ab993a) /
10833        // [`crate::dialeto::tests::caixa_dialeto_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
10834        // (807b0b5) partition pins on the sibling closed-set typed-enum
10835        // discriminator axes — extends the borrowed-input axis
10836        // discipline onto the first M2 OTP-shape sibling-restart
10837        // closed-set typed enum on the caixa surface. Also closes the
10838        // direct two-way `&Self → &'static str → Self` round-trip via
10839        // the paired [`TryFrom<&str>`] axis — unlike the peer
10840        // [`crate::CaixaKind`] axis pair (whose forward `From` emits
10841        // lowercase Portuguese diagnostic bytes while the reverse
10842        // `TryFrom` parses `PascalCase` wire bytes, forcing the round-
10843        // trip through an intermediate wire-vocab hop), the
10844        // [`RestartStrategy::as_str`] emit and
10845        // [`RestartStrategy::from_wire`] parse share the same
10846        // `PascalCase` vocabulary by construction, so the borrowed-
10847        // input forward axis and the reverse axis compose directly.
10848        for &variant in RestartStrategy::ALL {
10849            let owned: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
10850            let borrowed: &'static str = <&'static str as From<&RestartStrategy>>::from(&variant);
10851            assert_eq!(
10852                owned, borrowed,
10853                "From<RestartStrategy> and From<&RestartStrategy> for \
10854                 &'static str must resolve identically on \
10855                 RestartStrategy::{variant:?} — divergence signals the \
10856                 owned-input and borrowed-input forward-projection paths \
10857                 have drifted onto different emit-sets"
10858            );
10859        }
10860        let via_iter: Vec<&'static str> = RestartStrategy::ALL.iter().map(Into::into).collect();
10861        let via_method: Vec<&'static str> =
10862            RestartStrategy::ALL.iter().map(|s| s.as_str()).collect();
10863        assert_eq!(
10864            via_iter, via_method,
10865            "`.iter().map(Into::into)` over RestartStrategy::ALL must \
10866             byte-equal `.iter().map(|s| s.as_str())` on every arm — the \
10867             borrowed-input `From<&RestartStrategy> for &'static str` \
10868             axis is what makes the `.iter().map(Into::into)` shape route \
10869             through the substrate-primitive `RestartStrategy::as_str` \
10870             accessor rather than through a per-call-site `.copied()` / \
10871             dereference detour"
10872        );
10873        for variant in RestartStrategy::ALL {
10874            let emitted: &'static str = variant.into();
10875            let re_parsed: Result<RestartStrategy, ()> =
10876                <RestartStrategy as TryFrom<&str>>::try_from(emitted);
10877            assert_eq!(
10878                re_parsed,
10879                Ok(*variant),
10880                "trait-idiomatic borrowed-input forward-projection + \
10881                 reverse-projection axis pair must round-trip \
10882                 &RestartStrategy::{variant:?} through `.into::<&'static \
10883                 str>()` (via the borrowed-input axis) and back through \
10884                 `TryFrom<&str>` — a break signals the borrowed-input \
10885                 forward-emit and reverse-parse axes have drifted onto \
10886                 different vocabularies"
10887            );
10888        }
10889    }
10890
10891    #[test]
10892    fn restart_strategy_from_into_owned_string_routes_through_as_str_accessor() {
10893        // Fail-before-pass-after byte-parity pin on the newly lifted
10894        // `impl From<RestartStrategy> for String` — asserts the
10895        // owned-`String`-returning standard-library trait impl and the
10896        // substrate-primitive [`RestartStrategy::as_str`] `pub const fn`
10897        // accessor resolve to the same four-arm emit-set across every
10898        // arm the exhaustive [`RestartStrategy::ALL`] slice enumerates.
10899        // Rust's standard library does not carry a blanket
10900        // `impl<T: AsRef<str>> From<T> for String` (nor an
10901        // `impl<T: fmt::Display> From<T> for String`), so the
10902        // owned-`String` forward-projection axis is a distinct
10903        // trait-idiomatic surface that a
10904        // `let key: String = strategy.into();`-shaped call site
10905        // reaches through this impl and no other — the paired sibling
10906        // `From<RestartStrategy> for &'static str` impl forces every
10907        // owned-`String` call site through an explicit
10908        // `.to_owned()` / `String::from` restatement.
10909        for &variant in RestartStrategy::ALL {
10910            let via_trait: String = <String as From<RestartStrategy>>::from(variant);
10911            let via_method: &'static str = variant.as_str();
10912            assert_eq!(
10913                via_trait.as_str(),
10914                via_method,
10915                "From<RestartStrategy> for String impl must round-trip \
10916                 RestartStrategy::{variant:?} to the same lifted \
10917                 SUPERVISOR_ESTRATEGIA_* const RestartStrategy::as_str \
10918                 returns — divergence signals a silent detour off the \
10919                 substrate-primitive accessor"
10920            );
10921            let via_into: String = variant.into();
10922            assert_eq!(
10923                via_into.as_str(),
10924                via_method,
10925                "Into<String>::into on RestartStrategy::{variant:?} must \
10926                 byte-equal RestartStrategy::as_str on the same input — the \
10927                 blanket-derived Into shape must resolve to the same as_str \
10928                 dispatch as the explicit From impl"
10929            );
10930        }
10931    }
10932
10933    #[test]
10934    fn restart_strategy_from_into_owned_string_and_static_str_agree_on_every_arm() {
10935        // Cross-axis partition pin: the paired trait-idiomatic
10936        // owned-`String` `From<RestartStrategy> for String` (this lift)
10937        // and owned-`&'static str` `From<RestartStrategy> for &'static
10938        // str` (523157d) forward projections must resolve identically
10939        // on every arm, locking the two return-type-shape paths
10940        // together so any future detour trips at caixa-core test time.
10941        // Also byte-parity witness against the sibling
10942        // [`ToString::to_string`] surface routed through
10943        // [`std::fmt::Display`] — the three owned-heap-string paths
10944        // (`.into::<String>()`, `String::from`, `.to_string()`) must
10945        // resolve identically on every arm so a future consumer that
10946        // picks any of the three lands on the same lifted
10947        // SUPERVISOR_ESTRATEGIA_* const. Then a direct round-trip
10948        // witness through the paired trait-idiomatic reverse
10949        // [`TryFrom<&str>`] axis on the owned-`String`'s
10950        // [`String::as_str`] borrow that closes the two-way
10951        // `Self → String → Self` round-trip on the trait-idiomatic
10952        // owned-`String` forward + reverse axis pair.
10953        for &variant in RestartStrategy::ALL {
10954            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
10955            let owned_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
10956            assert_eq!(
10957                owned_string.as_str(),
10958                owned_static,
10959                "From<RestartStrategy> for String and From<RestartStrategy> \
10960                 for &'static str must resolve identically on \
10961                 RestartStrategy::{variant:?} — divergence signals the \
10962                 owned-`String` and owned-`&'static str` forward-projection \
10963                 return-type-shape paths have drifted onto different \
10964                 emit-sets"
10965            );
10966            let via_to_string: String = variant.to_string();
10967            assert_eq!(
10968                owned_string, via_to_string,
10969                "From<RestartStrategy> for String must byte-equal \
10970                 RestartStrategy::to_string on RestartStrategy::{variant:?} — \
10971                 divergence signals the trait-idiomatic owned-`String` \
10972                 forward-projection axis and the ToString-through-Display \
10973                 axis have drifted onto different emit-sets"
10974            );
10975        }
10976        let via_iter: Vec<String> = RestartStrategy::ALL
10977            .iter()
10978            .copied()
10979            .map(String::from)
10980            .collect();
10981        let via_method: Vec<String> = RestartStrategy::ALL
10982            .iter()
10983            .map(|s| s.as_str().to_owned())
10984            .collect();
10985        assert_eq!(
10986            via_iter, via_method,
10987            "`.iter().copied().map(String::from)` over RestartStrategy::ALL \
10988             must byte-equal `.iter().map(|s| s.as_str().to_owned())` on \
10989             every arm — the owned-`String` `From<RestartStrategy> for \
10990             String` axis is what makes the `String::from` composition \
10991             route through the substrate-primitive `RestartStrategy::as_str` \
10992             accessor rather than through a per-call-site `.to_owned()` / \
10993             `String::from(strategy.as_str())` detour"
10994        );
10995        for &variant in RestartStrategy::ALL {
10996            let emitted: String = variant.into();
10997            let re_parsed: Result<RestartStrategy, ()> =
10998                <RestartStrategy as TryFrom<&str>>::try_from(emitted.as_str());
10999            assert_eq!(
11000                re_parsed,
11001                Ok(variant),
11002                "trait-idiomatic owned-`String` forward-projection + \
11003                 reverse-projection axis pair must round-trip \
11004                 RestartStrategy::{variant:?} through `.into::<String>()` \
11005                 and back through `TryFrom<&str>` on the owned-`String`'s \
11006                 String::as_str borrow — a break signals the owned-`String` \
11007                 forward-emit and reverse-parse axes have drifted onto \
11008                 different vocabularies"
11009            );
11010        }
11011    }
11012
11013    #[test]
11014    fn restart_strategy_from_into_borrowed_owned_string_routes_through_as_str_accessor() {
11015        // Fail-before-pass-after byte-parity pin on the newly lifted
11016        // `impl From<&RestartStrategy> for String` — asserts the
11017        // borrowed-input owned-`String`-returning standard-library trait
11018        // impl and the substrate-primitive [`RestartStrategy::as_str`]
11019        // `pub const fn` accessor resolve to the same four-arm emit-set
11020        // across every arm the exhaustive [`RestartStrategy::ALL`] slice
11021        // enumerates. Rust's standard library does not carry a blanket
11022        // `impl<T: AsRef<str>> From<&T> for String` (nor an
11023        // `impl<T: fmt::Display> From<&T> for String`), so the
11024        // borrowed-input owned-`String` forward-projection axis is a
11025        // distinct trait-idiomatic surface that a
11026        // `let key: String = (&strategy).into();`-shaped call site
11027        // reaches through this impl and no other — the paired sibling
11028        // `From<RestartStrategy> for String` impl forces every
11029        // borrowed-input call site through an explicit `Copy` deref
11030        // (`String::from(*strategy)`) or an `.as_str().to_owned()` /
11031        // `.to_string()` detour.
11032        for &variant in RestartStrategy::ALL {
11033            let via_trait: String = <String as From<&RestartStrategy>>::from(&variant);
11034            let via_method: &'static str = variant.as_str();
11035            assert_eq!(
11036                via_trait.as_str(),
11037                via_method,
11038                "From<&RestartStrategy> for String impl must round-trip \
11039                 &RestartStrategy::{variant:?} to the same lifted \
11040                 SUPERVISOR_ESTRATEGIA_* const RestartStrategy::as_str \
11041                 returns — divergence signals a silent detour off the \
11042                 substrate-primitive accessor"
11043            );
11044            let via_into: String = (&variant).into();
11045            assert_eq!(
11046                via_into.as_str(),
11047                via_method,
11048                "Into<String>::into on &RestartStrategy::{variant:?} must \
11049                 byte-equal RestartStrategy::as_str on the same input — the \
11050                 blanket-derived Into shape must resolve to the same as_str \
11051                 dispatch as the explicit From impl"
11052            );
11053        }
11054    }
11055
11056    #[test]
11057    fn restart_strategy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm() {
11058        // Cross-axis partition pin: the newly lifted trait-idiomatic
11059        // borrowed-input owned-`String` `From<&RestartStrategy> for
11060        // String` (this lift), the paired owned-input owned-`String`
11061        // `From<RestartStrategy> for String` (7baa18a), the paired
11062        // borrowed-input owned-`&'static str` `From<&RestartStrategy>
11063        // for &'static str` (e941836), and the paired owned-input
11064        // owned-`&'static str` `From<RestartStrategy> for &'static str`
11065        // (523157d) — every corner of the `{Self, &Self} × {&'static
11066        // str, String}` 2×2 trait-idiomatic projection family — must
11067        // resolve identically on every arm, locking the four
11068        // return-shape × input-shape paths together so any future
11069        // detour trips at caixa-core test time. Also byte-parity
11070        // witness against the sibling [`ToString::to_string`] surface
11071        // routed through [`std::fmt::Display`] and a direct round-trip
11072        // witness through the paired trait-idiomatic reverse
11073        // [`TryFrom<&str>`] axis on the owned-`String`'s
11074        // [`String::as_str`] borrow that closes the two-way
11075        // `&Self → String → Self` round-trip on the trait-idiomatic
11076        // borrowed-input owned-`String` forward + reverse axis pair.
11077        for &variant in RestartStrategy::ALL {
11078            let borrowed_string: String = <String as From<&RestartStrategy>>::from(&variant);
11079            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
11080            let borrowed_static: &'static str =
11081                <&'static str as From<&RestartStrategy>>::from(&variant);
11082            let owned_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
11083            assert_eq!(
11084                borrowed_string, owned_string,
11085                "From<&RestartStrategy> for String and From<RestartStrategy> \
11086                 for String must resolve identically on \
11087                 RestartStrategy::{variant:?} — divergence signals the \
11088                 borrowed-input and owned-input owned-`String` \
11089                 forward-projection input-shape paths have drifted onto \
11090                 different emit-sets"
11091            );
11092            assert_eq!(
11093                borrowed_string.as_str(),
11094                borrowed_static,
11095                "From<&RestartStrategy> for String and From<&RestartStrategy> \
11096                 for &'static str must resolve identically on \
11097                 RestartStrategy::{variant:?} — divergence signals the \
11098                 borrowed-input `&'static str` and owned-`String` \
11099                 return-shape paths have drifted onto different emit-sets"
11100            );
11101            assert_eq!(
11102                borrowed_string.as_str(),
11103                owned_static,
11104                "From<&RestartStrategy> for String and From<RestartStrategy> \
11105                 for &'static str must resolve identically on \
11106                 RestartStrategy::{variant:?} — divergence signals a break \
11107                 in the diagonal corner of the {{Self, &Self}} × \
11108                 {{&'static str, String}} 2×2 trait-idiomatic \
11109                 projection family"
11110            );
11111            let via_to_string: String = variant.to_string();
11112            assert_eq!(
11113                borrowed_string, via_to_string,
11114                "From<&RestartStrategy> for String must byte-equal \
11115                 RestartStrategy::to_string on RestartStrategy::{variant:?} — \
11116                 divergence signals the trait-idiomatic borrowed-input \
11117                 owned-`String` forward-projection axis and the \
11118                 ToString-through-Display axis have drifted onto different \
11119                 emit-sets"
11120            );
11121        }
11122        let via_iter: Vec<String> = RestartStrategy::ALL.iter().map(String::from).collect();
11123        let via_method: Vec<String> = RestartStrategy::ALL
11124            .iter()
11125            .map(|s| s.as_str().to_owned())
11126            .collect();
11127        assert_eq!(
11128            via_iter, via_method,
11129            "`.iter().map(String::from)` over RestartStrategy::ALL — a \
11130             call site whose iteration axis holds `&RestartStrategy` by \
11131             construction — must byte-equal `.iter().map(|s| \
11132             s.as_str().to_owned())` on every arm — the borrowed-input \
11133             owned-`String` `From<&RestartStrategy> for String` axis is \
11134             what makes the `String::from` composition route through the \
11135             substrate-primitive `RestartStrategy::as_str` accessor \
11136             without a spurious `Copy` deref (which would only be \
11137             reachable through the owned-input `From<RestartStrategy> for \
11138             String` axis by first calling `.copied()` on the iterator)"
11139        );
11140        for &variant in RestartStrategy::ALL {
11141            let emitted: String = (&variant).into();
11142            let re_parsed: Result<RestartStrategy, ()> =
11143                <RestartStrategy as TryFrom<&str>>::try_from(emitted.as_str());
11144            assert_eq!(
11145                re_parsed,
11146                Ok(variant),
11147                "trait-idiomatic borrowed-input owned-`String` \
11148                 forward-projection + reverse-projection axis pair must \
11149                 round-trip &RestartStrategy::{variant:?} through \
11150                 `.into::<String>()` on the borrowed-input surface and \
11151                 back through `TryFrom<&str>` on the owned-`String`'s \
11152                 String::as_str borrow — a break signals the \
11153                 borrowed-input owned-`String` forward-emit and \
11154                 reverse-parse axes have drifted onto different \
11155                 vocabularies"
11156            );
11157        }
11158    }
11159
11160    #[test]
11161    fn restart_strategy_from_into_static_cow_str_routes_through_as_str_accessor() {
11162        // Fail-before-pass-after byte-parity pin on the newly lifted
11163        // `impl From<RestartStrategy> for std::borrow::Cow<'static, str>` —
11164        // asserts the standard-library trait impl and the substrate-
11165        // primitive [`super::RestartStrategy::as_str`] `pub const fn`
11166        // accessor resolve to the same four-arm emit-set across every
11167        // arm the exhaustive [`super::RestartStrategy::ALL`] slice
11168        // enumerates. Rust's standard library does not carry a blanket
11169        // `impl<T: AsRef<str>> From<T> for Cow<'static, str>` (nor an
11170        // `impl<T: fmt::Display> From<T> for Cow<'static, str>`), so
11171        // the `Cow<'static, str>` forward-projection axis is a
11172        // distinct trait-idiomatic surface that a
11173        // `let key: Cow<'static, str> = strategy.into();`-shaped call
11174        // site reaches through this impl and no other — the paired
11175        // sibling `From<RestartStrategy> for &'static str` and
11176        // `From<RestartStrategy> for String` impls force every
11177        // `Cow<'static, str>`-parameterized call site through a
11178        // `Cow::Borrowed(strategy.as_str())` /
11179        // `Cow::Owned(strategy.to_string())` composition whose type
11180        // bounds have no compile-time link back to the substrate
11181        // primitive.
11182        //
11183        // Also asserts the projection lands on the zero-alloc
11184        // [`std::borrow::Cow::Borrowed`] arm (not the
11185        // [`std::borrow::Cow::Owned`] arm) — the substrate-primitive
11186        // [`super::RestartStrategy::as_str`] accessor's `&'static str`
11187        // return lifetime by construction makes the borrowed arm the
11188        // type-correct projection with no runtime allocation. Any
11189        // future silent detour that routes the impl through the owned
11190        // arm (an accidental `Cow::Owned(strategy.to_string())` rewrite
11191        // that would allocate on every call site where the
11192        // `&'static str` return of [`super::RestartStrategy::as_str`]
11193        // makes the zero-alloc borrowed projection type-correct) trips
11194        // at caixa-core test time under the
11195        // [`std::borrow::Cow::Borrowed`] discriminator witness rather
11196        // than at a downstream `Cow<'static, str>`-bound consumer's
11197        // silent allocation.
11198        //
11199        // First peer on the substrate-wide trait-idiomatic
11200        // [`std::borrow::Cow<'static, str>`] forward-projection family
11201        // to extend the axis off the top-level [`super::CaixaKind`]
11202        // enum (99c1735 owned-input, d45c409 borrowed-input) onto the
11203        // first M2 OTP-shape closed-set fieldless typed enum on the
11204        // caixa surface.
11205        for &variant in RestartStrategy::ALL {
11206            let via_trait: std::borrow::Cow<'static, str> =
11207                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
11208            let via_method: &'static str = variant.as_str();
11209            assert_eq!(
11210                via_trait.as_ref(),
11211                via_method,
11212                "From<RestartStrategy> for Cow<'static, str> impl must \
11213                 round-trip RestartStrategy::{variant:?} to the same \
11214                 lifted SUPERVISOR_ESTRATEGIA_* const \
11215                 RestartStrategy::as_str returns — divergence signals a \
11216                 silent detour off the substrate-primitive accessor"
11217            );
11218            assert!(
11219                matches!(via_trait, std::borrow::Cow::Borrowed(_)),
11220                "From<RestartStrategy> for Cow<'static, str> impl must \
11221                 land on the zero-alloc Cow::Borrowed arm on \
11222                 RestartStrategy::{variant:?} — a Cow::Owned outcome \
11223                 signals the projection has silently allocated where \
11224                 the substrate-primitive RestartStrategy::as_str \
11225                 `&'static str` return makes the borrowed arm the \
11226                 type-correct projection"
11227            );
11228            let via_into: std::borrow::Cow<'static, str> = variant.into();
11229            assert_eq!(
11230                via_into.as_ref(),
11231                via_method,
11232                "Into<Cow<'static, str>>::into on \
11233                 RestartStrategy::{variant:?} must byte-equal \
11234                 RestartStrategy::as_str on the same input — the \
11235                 blanket-derived Into shape must resolve to the same \
11236                 as_str dispatch as the explicit From impl"
11237            );
11238            assert!(
11239                matches!(via_into, std::borrow::Cow::Borrowed(_)),
11240                "Into<Cow<'static, str>>::into on \
11241                 RestartStrategy::{variant:?} must land on the \
11242                 zero-alloc Cow::Borrowed arm — the blanket-derived \
11243                 Into shape must resolve to the same Cow::Borrowed \
11244                 dispatch as the explicit From impl"
11245            );
11246        }
11247    }
11248
11249    #[test]
11250    fn restart_strategy_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm() {
11251        // Cross-axis partition pin: the newly lifted trait-idiomatic
11252        // `From<RestartStrategy> for std::borrow::Cow<'static, str>`
11253        // (this lift), the paired owned-input `From<RestartStrategy>
11254        // for &'static str` (523157d), and the paired owned-input
11255        // `From<RestartStrategy> for String` (7baa18a) forward
11256        // projections must resolve identically on every arm, locking
11257        // the three return-shape paths together by construction so any
11258        // future detour trips at caixa-core test time. Also byte-parity
11259        // witness against the sibling [`ToString::to_string`] surface
11260        // routed through [`std::fmt::Display`] — every owned-heap-
11261        // string path (the `Cow::Owned` promotion of this axis's
11262        // `.into_owned()`, `From<RestartStrategy> for String`, and
11263        // `.to_string()`) resolves to the same lifted
11264        // [`crate::render::SUPERVISOR_ESTRATEGIA_*`] const per arm.
11265        //
11266        // Then a `.iter().copied().map(std::borrow::Cow::from)` pipe
11267        // witness over [`super::RestartStrategy::ALL`] that
11268        // materializes the four-arm accept-set through the
11269        // [`std::borrow::Cow<'static, str>`] axis alone — the exact
11270        // shape a future `axum::response::IntoResponse` per-strategy
11271        // rejection-body composer, a future M4 admission-webhook
11272        // per-strategy rejection-reason emitter whose typing rules out
11273        // the sibling [`AsRef<str>`] borrowed return, or a future
11274        // substrate-wide per-strategy diagnostic surface that binds
11275        // through a [`Cow<'static, str>`] boundary reaches through.
11276        // The pipe witness also pins the zero-alloc discipline: every
11277        // element in the collected vector satisfies the
11278        // [`std::borrow::Cow::Borrowed`] arm predicate, so a future
11279        // accidental silent-allocation regression on the pipe's
11280        // iteration axis is a caixa-core-test-time failure.
11281        for &variant in RestartStrategy::ALL {
11282            let via_cow: std::borrow::Cow<'static, str> =
11283                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
11284            let via_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
11285            let via_string: String = <String as From<RestartStrategy>>::from(variant);
11286            assert_eq!(
11287                via_cow.as_ref(),
11288                via_static,
11289                "From<RestartStrategy> for Cow<'static, str> and \
11290                 From<RestartStrategy> for &'static str must resolve \
11291                 identically on RestartStrategy::{variant:?} — \
11292                 divergence signals the Cow<'static, str> and \
11293                 &'static str return-shape paths have drifted onto \
11294                 different emit-sets"
11295            );
11296            assert_eq!(
11297                via_cow.as_ref(),
11298                via_string.as_str(),
11299                "From<RestartStrategy> for Cow<'static, str> and \
11300                 From<RestartStrategy> for String must resolve \
11301                 identically on RestartStrategy::{variant:?} — \
11302                 divergence signals the Cow<'static, str> and String \
11303                 return-shape paths have drifted onto different \
11304                 emit-sets"
11305            );
11306            let via_to_string: String = variant.to_string();
11307            assert_eq!(
11308                via_cow.as_ref(),
11309                via_to_string.as_str(),
11310                "From<RestartStrategy> for Cow<'static, str> must \
11311                 byte-equal RestartStrategy::to_string on \
11312                 RestartStrategy::{variant:?} — divergence signals the \
11313                 trait-idiomatic Cow<'static, str> forward-projection \
11314                 axis and the ToString-through-Display axis have \
11315                 drifted onto different emit-sets"
11316            );
11317        }
11318        let via_iter: Vec<std::borrow::Cow<'static, str>> = RestartStrategy::ALL
11319            .iter()
11320            .copied()
11321            .map(std::borrow::Cow::from)
11322            .collect();
11323        let via_method: Vec<std::borrow::Cow<'static, str>> = RestartStrategy::ALL
11324            .iter()
11325            .map(|s| std::borrow::Cow::Borrowed(s.as_str()))
11326            .collect();
11327        assert_eq!(
11328            via_iter, via_method,
11329            "`.iter().copied().map(Cow::from)` over \
11330             RestartStrategy::ALL must byte-equal `.iter().map(|s| \
11331             Cow::Borrowed(s.as_str()))` on every arm — the \
11332             trait-idiomatic `From<RestartStrategy> for Cow<'static, \
11333             str>` axis is what makes the `Cow::from` composition \
11334             route through the substrate-primitive \
11335             `RestartStrategy::as_str` accessor with the zero-alloc \
11336             Cow::Borrowed arm by construction, rather than a \
11337             per-call-site `Cow::Owned(strategy.to_string())` \
11338             allocation"
11339        );
11340        for cow in &via_iter {
11341            assert!(
11342                matches!(cow, std::borrow::Cow::Borrowed(_)),
11343                "every element of the \
11344                 .iter().copied().map(Cow::from) pipe over \
11345                 RestartStrategy::ALL must land on the zero-alloc \
11346                 Cow::Borrowed arm — a Cow::Owned outcome on any arm \
11347                 signals the pipe's iteration axis has silently \
11348                 allocated where the substrate-primitive \
11349                 RestartStrategy::as_str `&'static str` return makes \
11350                 the borrowed arm the type-correct projection"
11351            );
11352        }
11353    }
11354
11355    #[test]
11356    fn restart_strategy_from_borrowed_into_static_cow_str_routes_through_as_str_accessor() {
11357        // Fail-before-pass-after byte-parity pin on the newly lifted
11358        // `impl From<&RestartStrategy> for std::borrow::Cow<'static, str>` —
11359        // asserts the borrowed-input standard-library trait impl and
11360        // the substrate-primitive [`super::RestartStrategy::as_str`]
11361        // `pub const fn` accessor resolve to the same four-arm emit-
11362        // set across every arm the exhaustive
11363        // [`super::RestartStrategy::ALL`] slice enumerates. Rust's
11364        // standard library does not carry a blanket
11365        // `impl<T: AsRef<str>> From<&T> for Cow<'static, str>` (nor a
11366        // `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`), so
11367        // the borrowed-input `Cow<'static, str>` forward-projection
11368        // axis is a distinct trait-idiomatic surface that a
11369        // `let key: Cow<'static, str> = (&strategy).into();`-shaped
11370        // call site or a
11371        // `RestartStrategy::ALL.iter().map(Cow::from)`-shaped pipe
11372        // reaches through this impl and no other — the paired owned-
11373        // input `From<RestartStrategy> for Cow<'static, str>` impl
11374        // (7dd28b3) forces every borrowed-input call site through an
11375        // explicit `Copy` deref (`Cow::from(*strategy)`) or a
11376        // `Cow::Borrowed(strategy.as_str())` open-code whose type
11377        // bounds have no compile-time link back to the substrate
11378        // primitive.
11379        //
11380        // Also asserts the projection lands on the zero-alloc
11381        // [`std::borrow::Cow::Borrowed`] arm (not the
11382        // [`std::borrow::Cow::Owned`] arm) — the substrate-primitive
11383        // [`super::RestartStrategy::as_str`] accessor's `&'static str`
11384        // return lifetime by construction makes the borrowed arm the
11385        // type-correct projection with no runtime allocation on the
11386        // borrowed-input surface just as on the paired owned-input
11387        // surface.
11388        //
11389        // Second peer on the substrate-wide trait-idiomatic
11390        // [`std::borrow::Cow<'static, str>`] forward-projection family
11391        // on this enum — closes the `{Self, &Self}` input-shape
11392        // corner of the [`Cow<'static, str>`] axis on the first M2
11393        // OTP-shape closed-set fieldless typed enum peer on the caixa
11394        // surface (`:supervisor :estrategia`), exactly as d45c409
11395        // closed it on the top-level [`super::CaixaKind`] one commit
11396        // after the owning half (99c1735) landed. Every future
11397        // closed-set fieldless typed enum peer on the substrate is a
11398        // future target of the campaign.
11399        for &variant in RestartStrategy::ALL {
11400            let via_trait: std::borrow::Cow<'static, str> =
11401                <std::borrow::Cow<'static, str> as From<&RestartStrategy>>::from(&variant);
11402            let via_method: &'static str = variant.as_str();
11403            assert_eq!(
11404                via_trait.as_ref(),
11405                via_method,
11406                "From<&RestartStrategy> for Cow<'static, str> impl must \
11407                 round-trip &RestartStrategy::{variant:?} to the same \
11408                 lifted SUPERVISOR_ESTRATEGIA_* const \
11409                 RestartStrategy::as_str returns — divergence signals a \
11410                 silent detour off the substrate-primitive accessor"
11411            );
11412            assert!(
11413                matches!(via_trait, std::borrow::Cow::Borrowed(_)),
11414                "From<&RestartStrategy> for Cow<'static, str> impl must \
11415                 land on the zero-alloc Cow::Borrowed arm on \
11416                 &RestartStrategy::{variant:?} — a Cow::Owned outcome \
11417                 signals the projection has silently allocated where \
11418                 the substrate-primitive RestartStrategy::as_str \
11419                 `&'static str` return makes the borrowed arm the \
11420                 type-correct projection"
11421            );
11422            let via_into: std::borrow::Cow<'static, str> = (&variant).into();
11423            assert_eq!(
11424                via_into.as_ref(),
11425                via_method,
11426                "Into<Cow<'static, str>>::into on \
11427                 &RestartStrategy::{variant:?} must byte-equal \
11428                 RestartStrategy::as_str on the same input — the \
11429                 blanket-derived Into shape must resolve to the same \
11430                 as_str dispatch as the explicit From impl"
11431            );
11432            assert!(
11433                matches!(via_into, std::borrow::Cow::Borrowed(_)),
11434                "Into<Cow<'static, str>>::into on \
11435                 &RestartStrategy::{variant:?} must land on the \
11436                 zero-alloc Cow::Borrowed arm — the blanket-derived \
11437                 Into shape must resolve to the same Cow::Borrowed \
11438                 dispatch as the explicit From impl"
11439            );
11440        }
11441    }
11442
11443    #[test]
11444    fn restart_strategy_from_borrowed_into_static_cow_str_agrees_with_paired_axes_on_every_arm() {
11445        // Cross-axis partition pin: the newly lifted trait-idiomatic
11446        // borrowed-input `From<&RestartStrategy> for
11447        // std::borrow::Cow<'static, str>` (this lift), the paired
11448        // owned-input `From<RestartStrategy> for
11449        // std::borrow::Cow<'static, str>` (7dd28b3), the paired
11450        // borrowed-input owned-`&'static str` `From<&RestartStrategy>
11451        // for &'static str`, and the paired borrowed-input owned-
11452        // `String` `From<&RestartStrategy> for String` must resolve
11453        // identically on every arm, locking the four
11454        // return-shape × input-shape paths together by construction so
11455        // any future detour trips at caixa-core test time. Also byte-
11456        // parity witness against the sibling [`ToString::to_string`]
11457        // surface routed through [`std::fmt::Display`] — every owned-
11458        // heap-string path (this axis's `.into_owned()` promotion, the
11459        // paired [`From<&RestartStrategy> for String`], and
11460        // `.to_string()`) resolves to the same lifted
11461        // [`crate::render::SUPERVISOR_ESTRATEGIA_*`] const per arm.
11462        //
11463        // Then a `.iter().map(std::borrow::Cow::from)` pipe witness
11464        // over [`super::RestartStrategy::ALL`] — whose iterator yields
11465        // `&RestartStrategy` by construction, so the borrowed-input
11466        // [`Cow<'static, str>`] axis is what routes the pipe through
11467        // the substrate-primitive [`super::RestartStrategy::as_str`]
11468        // accessor without a spurious [`Copy`] deref (which would only
11469        // be reachable through the owned-input
11470        // [`From<RestartStrategy> for Cow<'static, str>`] axis by
11471        // first calling `.copied()` on the iterator). The pipe witness
11472        // also pins the zero-alloc discipline: every element in the
11473        // collected vector satisfies the [`std::borrow::Cow::Borrowed`]
11474        // arm predicate, so a future accidental silent-allocation
11475        // regression on the pipe's iteration axis is a caixa-core-
11476        // test-time failure.
11477        for &strategy in RestartStrategy::ALL {
11478            let borrowed_cow: std::borrow::Cow<'static, str> =
11479                <std::borrow::Cow<'static, str> as From<&RestartStrategy>>::from(&strategy);
11480            let owned_cow: std::borrow::Cow<'static, str> =
11481                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(strategy);
11482            let borrowed_static: &'static str =
11483                <&'static str as From<&RestartStrategy>>::from(&strategy);
11484            let borrowed_string: String = <String as From<&RestartStrategy>>::from(&strategy);
11485            assert_eq!(
11486                borrowed_cow, owned_cow,
11487                "From<&RestartStrategy> for Cow<'static, str> and \
11488                 From<RestartStrategy> for Cow<'static, str> must \
11489                 resolve identically on RestartStrategy::{strategy:?} — \
11490                 divergence signals the borrowed-input and owned-input \
11491                 Cow<'static, str> forward-projection input-shape \
11492                 paths have drifted onto different emit-sets"
11493            );
11494            assert_eq!(
11495                borrowed_cow.as_ref(),
11496                borrowed_static,
11497                "From<&RestartStrategy> for Cow<'static, str> and \
11498                 From<&RestartStrategy> for &'static str must resolve \
11499                 identically on RestartStrategy::{strategy:?} — \
11500                 divergence signals the borrowed-input Cow<'static, \
11501                 str> and &'static str return-shape paths have drifted \
11502                 onto different emit-sets"
11503            );
11504            assert_eq!(
11505                borrowed_cow.as_ref(),
11506                borrowed_string.as_str(),
11507                "From<&RestartStrategy> for Cow<'static, str> and \
11508                 From<&RestartStrategy> for String must resolve \
11509                 identically on RestartStrategy::{strategy:?} — \
11510                 divergence signals the borrowed-input Cow<'static, \
11511                 str> and owned-`String` return-shape paths have \
11512                 drifted onto different emit-sets"
11513            );
11514            let via_to_string: String = strategy.to_string();
11515            assert_eq!(
11516                borrowed_cow.as_ref(),
11517                via_to_string.as_str(),
11518                "From<&RestartStrategy> for Cow<'static, str> must \
11519                 byte-equal RestartStrategy::to_string on \
11520                 RestartStrategy::{strategy:?} — divergence signals \
11521                 the trait-idiomatic borrowed-input Cow<'static, str> \
11522                 forward-projection axis and the ToString-through-\
11523                 Display axis have drifted onto different emit-sets"
11524            );
11525        }
11526        let via_iter: Vec<std::borrow::Cow<'static, str>> = RestartStrategy::ALL
11527            .iter()
11528            .map(std::borrow::Cow::from)
11529            .collect();
11530        let via_method: Vec<std::borrow::Cow<'static, str>> = RestartStrategy::ALL
11531            .iter()
11532            .map(|s| std::borrow::Cow::Borrowed(s.as_str()))
11533            .collect();
11534        assert_eq!(
11535            via_iter, via_method,
11536            "`.iter().map(Cow::from)` over RestartStrategy::ALL — a \
11537             call site whose iteration axis holds `&RestartStrategy` \
11538             by construction — must byte-equal `.iter().map(|s| \
11539             Cow::Borrowed(s.as_str()))` on every arm — the borrowed-\
11540             input Cow<'static, str> `From<&RestartStrategy> for \
11541             Cow<'static, str>` axis is what makes the `Cow::from` \
11542             composition route through the substrate-primitive \
11543             `RestartStrategy::as_str` accessor with the zero-alloc \
11544             Cow::Borrowed arm by construction and without a spurious \
11545             `Copy` deref (which would only be reachable through the \
11546             owned-input `From<RestartStrategy> for Cow<'static, str>` \
11547             axis by first calling `.copied()` on the iterator)"
11548        );
11549        for cow in &via_iter {
11550            assert!(
11551                matches!(cow, std::borrow::Cow::Borrowed(_)),
11552                "every element of the .iter().map(Cow::from) pipe \
11553                 over RestartStrategy::ALL must land on the zero-\
11554                 alloc Cow::Borrowed arm — a Cow::Owned outcome on \
11555                 any arm signals the pipe's iteration axis has \
11556                 silently allocated where the substrate-primitive \
11557                 RestartStrategy::as_str `&'static str` return makes \
11558                 the borrowed arm the type-correct projection"
11559            );
11560        }
11561    }
11562
11563    #[test]
11564    fn restart_strategy_from_into_box_str_routes_through_as_str_accessor() {
11565        // Fail-before-pass-after byte-parity pin on the newly lifted
11566        // `impl From<RestartStrategy> for Box<str>` — asserts the
11567        // owned-input standard-library trait impl and the
11568        // substrate-primitive [`super::RestartStrategy::as_str`]
11569        // `pub const fn` accessor resolve to the same four-arm emit-
11570        // set across every arm the exhaustive
11571        // [`super::RestartStrategy::ALL`] slice enumerates. Opens the
11572        // substrate-wide `Box<str>` forward-projection campaign tier
11573        // on the first M2 OTP-shape closed-set fieldless typed enum
11574        // peer on the caixa surface (`:supervisor :estrategia`),
11575        // immediately after the paired `Cow<'static, str>` axis
11576        // (7dd28b3 / ee577fd) closed the
11577        // `{Self, &Self} × {&'static str, String, Cow<'static, str>}`
11578        // 2×3 corner on this enum. Rust's standard library carries
11579        // `impl From<&str> for Box<str>` and
11580        // `impl From<String> for Box<str>` but no blanket
11581        // `impl<T: AsRef<str>> From<T> for Box<str>`, so this axis is
11582        // a distinct trait-idiomatic surface that a
11583        // `let key: Box<str> = strategy.into();`-shaped call site
11584        // reaches through this impl and no other — a paired
11585        // `Box::from(strategy.as_str())` open-code has no compile-
11586        // time link back to the substrate primitive.
11587        for &variant in RestartStrategy::ALL {
11588            let via_trait: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
11589            let via_method: &'static str = variant.as_str();
11590            assert_eq!(
11591                via_trait.as_ref(),
11592                via_method,
11593                "From<RestartStrategy> for Box<str> impl must round-\
11594                 trip RestartStrategy::{variant:?} to the same lifted \
11595                 SUPERVISOR_ESTRATEGIA_* const RestartStrategy::as_str \
11596                 returns — divergence signals a silent detour off the \
11597                 substrate-primitive accessor"
11598            );
11599            let via_into: Box<str> = variant.into();
11600            assert_eq!(
11601                via_into.as_ref(),
11602                via_method,
11603                "Into<Box<str>>::into on RestartStrategy::{variant:?} \
11604                 must byte-equal RestartStrategy::as_str on the same \
11605                 input — the blanket-derived Into shape must resolve \
11606                 to the same as_str dispatch as the explicit From impl"
11607            );
11608        }
11609    }
11610
11611    #[test]
11612    fn restart_strategy_from_borrowed_into_box_str_routes_through_as_str_accessor() {
11613        // Fail-before-pass-after byte-parity pin on the newly lifted
11614        // `impl From<&RestartStrategy> for Box<str>` — asserts the
11615        // borrowed-input standard-library trait impl and the
11616        // substrate-primitive [`super::RestartStrategy::as_str`]
11617        // `pub const fn` accessor resolve to the same four-arm emit-
11618        // set across every arm the exhaustive
11619        // [`super::RestartStrategy::ALL`] slice enumerates. Rust's
11620        // standard library does not carry a blanket
11621        // `impl<T: AsRef<str>> From<&T> for Box<str>` (nor a
11622        // `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`),
11623        // so the borrowed-input `Box<str>` forward-projection axis
11624        // is a distinct trait-idiomatic surface that a
11625        // `let key: Box<str> = (&strategy).into();`-shaped call site
11626        // or a `RestartStrategy::ALL.iter().map(Box::<str>::from)`-
11627        // shaped pipe reaches through this impl and no other — the
11628        // paired owned-input `From<RestartStrategy> for Box<str>`
11629        // impl (69ef45c) forces every borrowed-input call site
11630        // through an explicit `Copy` deref
11631        // (`Box::<str>::from((*strategy).as_str())`) or a
11632        // `Box::<str>::from(strategy.as_str())` open-code whose
11633        // type bounds have no compile-time link back to the
11634        // substrate primitive.
11635        //
11636        // Second peer on the substrate-wide trait-idiomatic
11637        // [`Box<str>`] forward-projection family on this enum —
11638        // closes the `{Self, &Self}` input-shape corner of the
11639        // [`Box<str>`] axis on the first M2 OTP-shape closed-set
11640        // fieldless typed enum peer on the caixa surface
11641        // (`:supervisor :estrategia`), exactly as ee577fd closed
11642        // the paired [`Cow<'static, str>`] axis one commit after
11643        // its owning half (7dd28b3) landed. Every future closed-
11644        // set fieldless typed enum peer on the substrate is a
11645        // future target of the campaign.
11646        //
11647        // Also byte-parity witness against the paired owned-input
11648        // [`From<RestartStrategy> for Box<str>`] and the sibling
11649        // borrowed-input [`From<&RestartStrategy> for &'static str`],
11650        // [`From<&RestartStrategy> for String`], and
11651        // [`From<&RestartStrategy> for Cow<'static, str>`]
11652        // return-shape axes — locking the four
11653        // return-shape × input-shape paths together by construction
11654        // so any future detour trips at caixa-core test time. Then a
11655        // `.iter().map(Box::<str>::from)` pipe witness over
11656        // [`super::RestartStrategy::ALL`] — whose iterator yields
11657        // `&RestartStrategy` by construction, so the borrowed-input
11658        // [`Box<str>`] axis is what routes the pipe through the
11659        // substrate-primitive [`super::RestartStrategy::as_str`]
11660        // accessor without a spurious [`Copy`] deref (which would
11661        // only be reachable through the owned-input
11662        // [`From<RestartStrategy> for Box<str>`] axis by first
11663        // calling `.copied()` on the iterator).
11664        for &variant in RestartStrategy::ALL {
11665            let via_trait: Box<str> = <Box<str> as From<&RestartStrategy>>::from(&variant);
11666            let via_method: &'static str = variant.as_str();
11667            assert_eq!(
11668                via_trait.as_ref(),
11669                via_method,
11670                "From<&RestartStrategy> for Box<str> impl must \
11671                 round-trip &RestartStrategy::{variant:?} to the same \
11672                 lifted SUPERVISOR_ESTRATEGIA_* const \
11673                 RestartStrategy::as_str returns — divergence signals \
11674                 a silent detour off the substrate-primitive accessor"
11675            );
11676            let via_into: Box<str> = (&variant).into();
11677            assert_eq!(
11678                via_into.as_ref(),
11679                via_method,
11680                "Into<Box<str>>::into on &RestartStrategy::{variant:?} \
11681                 must byte-equal RestartStrategy::as_str on the same \
11682                 input — the blanket-derived Into shape must resolve \
11683                 to the same as_str dispatch as the explicit From impl"
11684            );
11685            let owned_box: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
11686            assert_eq!(
11687                via_trait, owned_box,
11688                "From<&RestartStrategy> for Box<str> and \
11689                 From<RestartStrategy> for Box<str> must resolve \
11690                 identically on RestartStrategy::{variant:?} — \
11691                 divergence signals the borrowed-input and owned-input \
11692                 Box<str> forward-projection input-shape paths have \
11693                 drifted onto different emit-sets"
11694            );
11695            let borrowed_static: &'static str =
11696                <&'static str as From<&RestartStrategy>>::from(&variant);
11697            assert_eq!(
11698                via_trait.as_ref(),
11699                borrowed_static,
11700                "From<&RestartStrategy> for Box<str> and \
11701                 From<&RestartStrategy> for &'static str must resolve \
11702                 identically on RestartStrategy::{variant:?} — \
11703                 divergence signals the borrowed-input Box<str> and \
11704                 &'static str return-shape paths have drifted onto \
11705                 different emit-sets"
11706            );
11707            let borrowed_string: String = <String as From<&RestartStrategy>>::from(&variant);
11708            assert_eq!(
11709                via_trait.as_ref(),
11710                borrowed_string.as_str(),
11711                "From<&RestartStrategy> for Box<str> and \
11712                 From<&RestartStrategy> for String must resolve \
11713                 identically on RestartStrategy::{variant:?} — \
11714                 divergence signals the borrowed-input Box<str> and \
11715                 owned-`String` return-shape paths have drifted onto \
11716                 different emit-sets"
11717            );
11718            let borrowed_cow: std::borrow::Cow<'static, str> =
11719                <std::borrow::Cow<'static, str> as From<&RestartStrategy>>::from(&variant);
11720            assert_eq!(
11721                via_trait.as_ref(),
11722                borrowed_cow.as_ref(),
11723                "From<&RestartStrategy> for Box<str> and \
11724                 From<&RestartStrategy> for Cow<'static, str> must \
11725                 resolve identically on RestartStrategy::{variant:?} — \
11726                 divergence signals the borrowed-input Box<str> and \
11727                 Cow<'static, str> return-shape paths have drifted \
11728                 onto different emit-sets"
11729            );
11730        }
11731        let via_iter: Vec<Box<str>> = RestartStrategy::ALL.iter().map(Box::<str>::from).collect();
11732        let via_method: Vec<Box<str>> = RestartStrategy::ALL
11733            .iter()
11734            .map(|s| Box::<str>::from(s.as_str()))
11735            .collect();
11736        assert_eq!(
11737            via_iter, via_method,
11738            "`.iter().map(Box::<str>::from)` over \
11739             RestartStrategy::ALL — a call site whose iteration axis \
11740             holds `&RestartStrategy` by construction — must byte-\
11741             equal `.iter().map(|s| Box::<str>::from(s.as_str()))` \
11742             on every arm — the borrowed-input Box<str> \
11743             `From<&RestartStrategy> for Box<str>` axis is what \
11744             makes the `Box::<str>::from` composition route through \
11745             the substrate-primitive `RestartStrategy::as_str` \
11746             accessor without a spurious `Copy` deref (which would \
11747             only be reachable through the owned-input \
11748             `From<RestartStrategy> for Box<str>` axis by first \
11749             calling `.copied()` on the iterator)"
11750        );
11751    }
11752
11753    #[test]
11754    fn restart_strategy_from_into_arc_str_routes_through_as_str_accessor() {
11755        // Fail-before-pass-after byte-parity pin on the newly lifted
11756        // `impl From<RestartStrategy> for std::sync::Arc<str>` — asserts
11757        // the owned-input standard-library trait impl and the
11758        // substrate-primitive [`super::RestartStrategy::as_str`]
11759        // `pub const fn` accessor resolve to the same four-arm emit-
11760        // set across every arm the exhaustive
11761        // [`super::RestartStrategy::ALL`] slice enumerates. Opens the
11762        // substrate-wide [`std::sync::Arc<str>`] forward-projection
11763        // campaign tier on the first M2 OTP-shape closed-set fieldless
11764        // typed enum peer on the caixa surface
11765        // (`:supervisor :estrategia`), immediately after the paired
11766        // [`Box<str>`] axis (69ef45c / 59ae5dc) closed the
11767        // `{Self, &Self} × {&'static str, String, Cow<'static, str>,
11768        // Box<str>}` 2×4 corner on this enum. Rust's standard library
11769        // carries `impl From<&str> for std::sync::Arc<str>` and
11770        // `impl From<String> for std::sync::Arc<str>` but no blanket
11771        // `impl<T: AsRef<str>> From<T> for std::sync::Arc<str>` (nor
11772        // an `impl<T: fmt::Display> From<T> for std::sync::Arc<str>`),
11773        // so this axis is a distinct trait-idiomatic surface that a
11774        // `let key: std::sync::Arc<str> = strategy.into();`-shaped call
11775        // site reaches through this impl and no other — a paired
11776        // `std::sync::Arc::<str>::from(strategy.as_str())` open-code
11777        // has no compile-time link back to the substrate primitive,
11778        // and a two-step `std::sync::Arc::<str>::from(String::from(
11779        // strategy))` composition through the owned-`String` axis
11780        // allocates twice (once into the intermediate `String`, once
11781        // into the [`Arc<str>`] on the `From<String>` conversion)
11782        // where the single-step trait impl allocates once.
11783        //
11784        // Cross-axis byte-parity witness against the sibling owned-
11785        // input `{&'static str, String, Cow<'static, str>, Box<str>}`
11786        // return-shape axes — locking the five return-shape paths on
11787        // the owned-input surface together by construction so any
11788        // future detour off the substrate-primitive
11789        // [`super::RestartStrategy::as_str`] accessor trips at caixa-
11790        // core test time.
11791        for &variant in RestartStrategy::ALL {
11792            let via_trait: std::sync::Arc<str> =
11793                <std::sync::Arc<str> as From<RestartStrategy>>::from(variant);
11794            let via_method: &'static str = variant.as_str();
11795            assert_eq!(
11796                via_trait.as_ref(),
11797                via_method,
11798                "From<RestartStrategy> for std::sync::Arc<str> impl \
11799                 must round-trip RestartStrategy::{variant:?} to the \
11800                 same lifted SUPERVISOR_ESTRATEGIA_* const \
11801                 RestartStrategy::as_str returns — divergence signals \
11802                 a silent detour off the substrate-primitive accessor"
11803            );
11804            let via_into: std::sync::Arc<str> = variant.into();
11805            assert_eq!(
11806                via_into.as_ref(),
11807                via_method,
11808                "Into<std::sync::Arc<str>>::into on \
11809                 RestartStrategy::{variant:?} must byte-equal \
11810                 RestartStrategy::as_str on the same input — the \
11811                 blanket-derived Into shape must resolve to the same \
11812                 as_str dispatch as the explicit From impl"
11813            );
11814            let owned_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
11815            assert_eq!(
11816                via_trait.as_ref(),
11817                owned_static,
11818                "From<RestartStrategy> for std::sync::Arc<str> and \
11819                 From<RestartStrategy> for &'static str must resolve \
11820                 identically on RestartStrategy::{variant:?} — \
11821                 divergence signals the owned-input std::sync::Arc<str> \
11822                 and &'static str return-shape paths have drifted onto \
11823                 different emit-sets"
11824            );
11825            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
11826            assert_eq!(
11827                via_trait.as_ref(),
11828                owned_string.as_str(),
11829                "From<RestartStrategy> for std::sync::Arc<str> and \
11830                 From<RestartStrategy> for String must resolve \
11831                 identically on RestartStrategy::{variant:?} — \
11832                 divergence signals the owned-input std::sync::Arc<str> \
11833                 and owned-`String` return-shape paths have drifted \
11834                 onto different emit-sets"
11835            );
11836            let owned_cow: std::borrow::Cow<'static, str> =
11837                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
11838            assert_eq!(
11839                via_trait.as_ref(),
11840                owned_cow.as_ref(),
11841                "From<RestartStrategy> for std::sync::Arc<str> and \
11842                 From<RestartStrategy> for Cow<'static, str> must \
11843                 resolve identically on RestartStrategy::{variant:?} — \
11844                 divergence signals the owned-input std::sync::Arc<str> \
11845                 and Cow<'static, str> return-shape paths have drifted \
11846                 onto different emit-sets"
11847            );
11848            let owned_box: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
11849            assert_eq!(
11850                via_trait.as_ref(),
11851                owned_box.as_ref(),
11852                "From<RestartStrategy> for std::sync::Arc<str> and \
11853                 From<RestartStrategy> for Box<str> must resolve \
11854                 identically on RestartStrategy::{variant:?} — \
11855                 divergence signals the owned-input std::sync::Arc<str> \
11856                 and Box<str> return-shape paths have drifted onto \
11857                 different emit-sets"
11858            );
11859        }
11860    }
11861
11862    #[test]
11863    fn restart_strategy_from_borrowed_into_arc_str_routes_through_as_str_accessor() {
11864        // Fail-before-pass-after byte-parity pin on the newly lifted
11865        // `impl From<&RestartStrategy> for std::sync::Arc<str>` —
11866        // asserts the borrowed-input standard-library trait impl and
11867        // the substrate-primitive [`super::RestartStrategy::as_str`]
11868        // `pub const fn` accessor resolve to the same four-arm emit-
11869        // set across every arm the exhaustive
11870        // [`super::RestartStrategy::ALL`] slice enumerates. Rust's
11871        // standard library does not carry a blanket
11872        // `impl<T: AsRef<str>> From<&T> for std::sync::Arc<str>` (nor
11873        // a `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`),
11874        // so the borrowed-input [`std::sync::Arc<str>`] forward-
11875        // projection axis is a distinct trait-idiomatic surface that a
11876        // `let key: std::sync::Arc<str> = (&strategy).into();`-shaped
11877        // call site or a
11878        // `RestartStrategy::ALL.iter().map(std::sync::Arc::<str>::from)`-
11879        // shaped pipe reaches through this impl and no other — the
11880        // paired owned-input
11881        // `From<RestartStrategy> for std::sync::Arc<str>` impl
11882        // (bca2ec8) forces every borrowed-input call site through an
11883        // explicit `Copy` deref
11884        // (`std::sync::Arc::<str>::from((*strategy).as_str())`) or a
11885        // `std::sync::Arc::<str>::from(strategy.as_str())` open-code
11886        // whose type bounds have no compile-time link back to the
11887        // substrate primitive.
11888        //
11889        // Second peer on the substrate-wide trait-idiomatic
11890        // [`std::sync::Arc<str>`] forward-projection family on this
11891        // enum — closes the `{Self, &Self}` input-shape corner of
11892        // the [`std::sync::Arc<str>`] axis on the first M2 OTP-shape
11893        // closed-set fieldless typed enum peer on the caixa surface
11894        // (`:supervisor :estrategia`), exactly as 59ae5dc closed the
11895        // paired [`Box<str>`] axis one commit after its owning half
11896        // (69ef45c) landed. Every future closed-set fieldless typed
11897        // enum peer on the substrate is a future target of the
11898        // campaign.
11899        //
11900        // Also byte-parity witness against the paired owned-input
11901        // [`From<RestartStrategy> for std::sync::Arc<str>`] and the
11902        // sibling borrowed-input
11903        // [`From<&RestartStrategy> for &'static str`],
11904        // [`From<&RestartStrategy> for String`],
11905        // [`From<&RestartStrategy> for Cow<'static, str>`], and
11906        // [`From<&RestartStrategy> for Box<str>`] return-shape axes —
11907        // locking the five return-shape × input-shape paths together
11908        // by construction so any future detour trips at caixa-core
11909        // test time. Then a
11910        // `.iter().map(std::sync::Arc::<str>::from)` pipe witness over
11911        // [`super::RestartStrategy::ALL`] — whose iterator yields
11912        // `&RestartStrategy` by construction, so the borrowed-input
11913        // [`std::sync::Arc<str>`] axis is what routes the pipe
11914        // through the substrate-primitive
11915        // [`super::RestartStrategy::as_str`] accessor without a
11916        // spurious [`Copy`] deref (which would only be reachable
11917        // through the owned-input
11918        // [`From<RestartStrategy> for std::sync::Arc<str>`] axis by
11919        // first calling `.copied()` on the iterator).
11920        for &variant in RestartStrategy::ALL {
11921            let via_trait: std::sync::Arc<str> =
11922                <std::sync::Arc<str> as From<&RestartStrategy>>::from(&variant);
11923            let via_method: &'static str = variant.as_str();
11924            assert_eq!(
11925                via_trait.as_ref(),
11926                via_method,
11927                "From<&RestartStrategy> for std::sync::Arc<str> impl \
11928                 must round-trip &RestartStrategy::{variant:?} to the \
11929                 same lifted SUPERVISOR_ESTRATEGIA_* const \
11930                 RestartStrategy::as_str returns — divergence signals \
11931                 a silent detour off the substrate-primitive accessor"
11932            );
11933            let via_into: std::sync::Arc<str> = (&variant).into();
11934            assert_eq!(
11935                via_into.as_ref(),
11936                via_method,
11937                "Into<std::sync::Arc<str>>::into on \
11938                 &RestartStrategy::{variant:?} must byte-equal \
11939                 RestartStrategy::as_str on the same input — the \
11940                 blanket-derived Into shape must resolve to the same \
11941                 as_str dispatch as the explicit From impl"
11942            );
11943            let owned_arc: std::sync::Arc<str> =
11944                <std::sync::Arc<str> as From<RestartStrategy>>::from(variant);
11945            assert_eq!(
11946                via_trait, owned_arc,
11947                "From<&RestartStrategy> for std::sync::Arc<str> and \
11948                 From<RestartStrategy> for std::sync::Arc<str> must \
11949                 resolve identically on RestartStrategy::{variant:?} — \
11950                 divergence signals the borrowed-input and owned-input \
11951                 std::sync::Arc<str> forward-projection input-shape \
11952                 paths have drifted onto different emit-sets"
11953            );
11954            let borrowed_static: &'static str =
11955                <&'static str as From<&RestartStrategy>>::from(&variant);
11956            assert_eq!(
11957                via_trait.as_ref(),
11958                borrowed_static,
11959                "From<&RestartStrategy> for std::sync::Arc<str> and \
11960                 From<&RestartStrategy> for &'static str must resolve \
11961                 identically on RestartStrategy::{variant:?} — \
11962                 divergence signals the borrowed-input \
11963                 std::sync::Arc<str> and &'static str return-shape \
11964                 paths have drifted onto different emit-sets"
11965            );
11966            let borrowed_string: String = <String as From<&RestartStrategy>>::from(&variant);
11967            assert_eq!(
11968                via_trait.as_ref(),
11969                borrowed_string.as_str(),
11970                "From<&RestartStrategy> for std::sync::Arc<str> and \
11971                 From<&RestartStrategy> for String must resolve \
11972                 identically on RestartStrategy::{variant:?} — \
11973                 divergence signals the borrowed-input \
11974                 std::sync::Arc<str> and owned-`String` return-shape \
11975                 paths have drifted onto different emit-sets"
11976            );
11977            let borrowed_cow: std::borrow::Cow<'static, str> =
11978                <std::borrow::Cow<'static, str> as From<&RestartStrategy>>::from(&variant);
11979            assert_eq!(
11980                via_trait.as_ref(),
11981                borrowed_cow.as_ref(),
11982                "From<&RestartStrategy> for std::sync::Arc<str> and \
11983                 From<&RestartStrategy> for Cow<'static, str> must \
11984                 resolve identically on RestartStrategy::{variant:?} — \
11985                 divergence signals the borrowed-input \
11986                 std::sync::Arc<str> and Cow<'static, str> return-shape \
11987                 paths have drifted onto different emit-sets"
11988            );
11989            let borrowed_box: Box<str> = <Box<str> as From<&RestartStrategy>>::from(&variant);
11990            assert_eq!(
11991                via_trait.as_ref(),
11992                borrowed_box.as_ref(),
11993                "From<&RestartStrategy> for std::sync::Arc<str> and \
11994                 From<&RestartStrategy> for Box<str> must resolve \
11995                 identically on RestartStrategy::{variant:?} — \
11996                 divergence signals the borrowed-input \
11997                 std::sync::Arc<str> and Box<str> return-shape paths \
11998                 have drifted onto different emit-sets"
11999            );
12000        }
12001        let via_iter: Vec<std::sync::Arc<str>> = RestartStrategy::ALL
12002            .iter()
12003            .map(std::sync::Arc::<str>::from)
12004            .collect();
12005        let via_method: Vec<std::sync::Arc<str>> = RestartStrategy::ALL
12006            .iter()
12007            .map(|s| std::sync::Arc::<str>::from(s.as_str()))
12008            .collect();
12009        assert_eq!(
12010            via_iter, via_method,
12011            "`.iter().map(std::sync::Arc::<str>::from)` over \
12012             RestartStrategy::ALL — a call site whose iteration axis \
12013             holds `&RestartStrategy` by construction — must byte-\
12014             equal `.iter().map(|s| std::sync::Arc::<str>::from(s.as_str()))` \
12015             on every arm — the borrowed-input std::sync::Arc<str> \
12016             `From<&RestartStrategy> for std::sync::Arc<str>` axis is \
12017             what makes the `std::sync::Arc::<str>::from` composition \
12018             route through the substrate-primitive \
12019             `RestartStrategy::as_str` accessor without a spurious \
12020             `Copy` deref (which would only be reachable through the \
12021             owned-input `From<RestartStrategy> for std::sync::Arc<str>` \
12022             axis by first calling `.copied()` on the iterator)"
12023        );
12024    }
12025
12026    #[test]
12027    fn restart_strategy_from_into_rc_str_routes_through_as_str_accessor() {
12028        // Fail-before-pass-after byte-parity pin on the newly lifted
12029        // `impl From<RestartStrategy> for std::rc::Rc<str>` — asserts
12030        // the owned-input standard-library trait impl and the
12031        // substrate-primitive [`super::RestartStrategy::as_str`]
12032        // `pub const fn` accessor resolve to the same four-arm emit-
12033        // set across every arm the exhaustive
12034        // [`super::RestartStrategy::ALL`] slice enumerates, and cross-
12035        // witnesses against every sibling owned-input `{&'static str,
12036        // String, Cow<'static, str>, Box<str>, std::sync::Arc<str>}`
12037        // return-shape axis so the six return-shape paths on the
12038        // owned-input surface lock together by construction. Extends
12039        // the substrate-wide [`std::rc::Rc<str>`] forward-projection
12040        // campaign onto the first M2 OTP-shape closed-set fieldless
12041        // typed enum peer on the caixa surface
12042        // (`:supervisor :estrategia`).
12043        for &variant in RestartStrategy::ALL {
12044            let via_trait: std::rc::Rc<str> =
12045                <std::rc::Rc<str> as From<RestartStrategy>>::from(variant);
12046            let via_method: &'static str = variant.as_str();
12047            assert_eq!(
12048                via_trait.as_ref(),
12049                via_method,
12050                "From<RestartStrategy> for std::rc::Rc<str> impl must \
12051                 round-trip RestartStrategy::{variant:?} to the same \
12052                 lifted SUPERVISOR_ESTRATEGIA_* const \
12053                 RestartStrategy::as_str returns — divergence signals \
12054                 a silent detour off the substrate-primitive accessor"
12055            );
12056            let via_into: std::rc::Rc<str> = variant.into();
12057            assert_eq!(
12058                via_into.as_ref(),
12059                via_method,
12060                "Into<std::rc::Rc<str>>::into on \
12061                 RestartStrategy::{variant:?} must byte-equal \
12062                 RestartStrategy::as_str on the same input — the \
12063                 blanket-derived Into shape must resolve to the same \
12064                 as_str dispatch as the explicit From impl"
12065            );
12066            let owned_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
12067            assert_eq!(
12068                via_trait.as_ref(),
12069                owned_static,
12070                "From<RestartStrategy> for std::rc::Rc<str> and \
12071                 From<RestartStrategy> for &'static str must resolve \
12072                 identically on RestartStrategy::{variant:?}"
12073            );
12074            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
12075            assert_eq!(
12076                via_trait.as_ref(),
12077                owned_string.as_str(),
12078                "From<RestartStrategy> for std::rc::Rc<str> and \
12079                 From<RestartStrategy> for String must resolve \
12080                 identically on RestartStrategy::{variant:?}"
12081            );
12082            let owned_cow: std::borrow::Cow<'static, str> =
12083                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
12084            assert_eq!(
12085                via_trait.as_ref(),
12086                owned_cow.as_ref(),
12087                "From<RestartStrategy> for std::rc::Rc<str> and \
12088                 From<RestartStrategy> for Cow<'static, str> must \
12089                 resolve identically on RestartStrategy::{variant:?}"
12090            );
12091            let owned_box: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
12092            assert_eq!(
12093                via_trait.as_ref(),
12094                owned_box.as_ref(),
12095                "From<RestartStrategy> for std::rc::Rc<str> and \
12096                 From<RestartStrategy> for Box<str> must resolve \
12097                 identically on RestartStrategy::{variant:?}"
12098            );
12099            let owned_arc: std::sync::Arc<str> =
12100                <std::sync::Arc<str> as From<RestartStrategy>>::from(variant);
12101            assert_eq!(
12102                via_trait.as_ref(),
12103                owned_arc.as_ref(),
12104                "From<RestartStrategy> for std::rc::Rc<str> and \
12105                 From<RestartStrategy> for std::sync::Arc<str> must \
12106                 resolve identically on RestartStrategy::{variant:?}"
12107            );
12108        }
12109    }
12110
12111    #[test]
12112    fn restart_strategy_from_borrowed_into_rc_str_routes_through_as_str_accessor() {
12113        // Fail-before-pass-after byte-parity pin on the newly lifted
12114        // `impl From<&RestartStrategy> for std::rc::Rc<str>` — asserts
12115        // the borrowed-input standard-library trait impl and the
12116        // substrate-primitive [`super::RestartStrategy::as_str`]
12117        // `pub const fn` accessor resolve to the same four-arm emit-
12118        // set across every arm the exhaustive
12119        // [`super::RestartStrategy::ALL`] slice enumerates. Closes the
12120        // `{Self, &Self}` input-shape corner of the
12121        // [`std::rc::Rc<str>`] axis on this enum, cross-witnesses
12122        // against the paired owned-input axis and every sibling
12123        // borrowed-input return-shape axis, and locks the
12124        // `.iter().map(std::rc::Rc::<str>::from)` pipe over
12125        // [`super::RestartStrategy::ALL`] to the substrate-primitive
12126        // accessor without a spurious [`Copy`] deref (which would only
12127        // be reachable through the owned-input axis by first calling
12128        // `.copied()` on the iterator).
12129        for &variant in RestartStrategy::ALL {
12130            let via_trait: std::rc::Rc<str> =
12131                <std::rc::Rc<str> as From<&RestartStrategy>>::from(&variant);
12132            let via_method: &'static str = variant.as_str();
12133            assert_eq!(
12134                via_trait.as_ref(),
12135                via_method,
12136                "From<&RestartStrategy> for std::rc::Rc<str> impl must \
12137                 round-trip &RestartStrategy::{variant:?} to the same \
12138                 lifted SUPERVISOR_ESTRATEGIA_* const \
12139                 RestartStrategy::as_str returns"
12140            );
12141            let via_into: std::rc::Rc<str> = (&variant).into();
12142            assert_eq!(
12143                via_into.as_ref(),
12144                via_method,
12145                "Into<std::rc::Rc<str>>::into on \
12146                 &RestartStrategy::{variant:?} must byte-equal \
12147                 RestartStrategy::as_str on the same input"
12148            );
12149            let owned_rc: std::rc::Rc<str> =
12150                <std::rc::Rc<str> as From<RestartStrategy>>::from(variant);
12151            assert_eq!(
12152                via_trait, owned_rc,
12153                "From<&RestartStrategy> for std::rc::Rc<str> and \
12154                 From<RestartStrategy> for std::rc::Rc<str> must \
12155                 resolve identically on RestartStrategy::{variant:?}"
12156            );
12157            let borrowed_static: &'static str =
12158                <&'static str as From<&RestartStrategy>>::from(&variant);
12159            assert_eq!(
12160                via_trait.as_ref(),
12161                borrowed_static,
12162                "From<&RestartStrategy> for std::rc::Rc<str> and \
12163                 From<&RestartStrategy> for &'static str must resolve \
12164                 identically on RestartStrategy::{variant:?}"
12165            );
12166            let borrowed_string: String = <String as From<&RestartStrategy>>::from(&variant);
12167            assert_eq!(
12168                via_trait.as_ref(),
12169                borrowed_string.as_str(),
12170                "From<&RestartStrategy> for std::rc::Rc<str> and \
12171                 From<&RestartStrategy> for String must resolve \
12172                 identically on RestartStrategy::{variant:?}"
12173            );
12174            let borrowed_cow: std::borrow::Cow<'static, str> =
12175                <std::borrow::Cow<'static, str> as From<&RestartStrategy>>::from(&variant);
12176            assert_eq!(
12177                via_trait.as_ref(),
12178                borrowed_cow.as_ref(),
12179                "From<&RestartStrategy> for std::rc::Rc<str> and \
12180                 From<&RestartStrategy> for Cow<'static, str> must \
12181                 resolve identically on RestartStrategy::{variant:?}"
12182            );
12183            let borrowed_box: Box<str> = <Box<str> as From<&RestartStrategy>>::from(&variant);
12184            assert_eq!(
12185                via_trait.as_ref(),
12186                borrowed_box.as_ref(),
12187                "From<&RestartStrategy> for std::rc::Rc<str> and \
12188                 From<&RestartStrategy> for Box<str> must resolve \
12189                 identically on RestartStrategy::{variant:?}"
12190            );
12191            let borrowed_arc: std::sync::Arc<str> =
12192                <std::sync::Arc<str> as From<&RestartStrategy>>::from(&variant);
12193            assert_eq!(
12194                via_trait.as_ref(),
12195                borrowed_arc.as_ref(),
12196                "From<&RestartStrategy> for std::rc::Rc<str> and \
12197                 From<&RestartStrategy> for std::sync::Arc<str> must \
12198                 resolve identically on RestartStrategy::{variant:?}"
12199            );
12200        }
12201        let via_iter: Vec<std::rc::Rc<str>> = RestartStrategy::ALL
12202            .iter()
12203            .map(std::rc::Rc::<str>::from)
12204            .collect();
12205        let via_method: Vec<std::rc::Rc<str>> = RestartStrategy::ALL
12206            .iter()
12207            .map(|s| std::rc::Rc::<str>::from(s.as_str()))
12208            .collect();
12209        assert_eq!(
12210            via_iter, via_method,
12211            "`.iter().map(std::rc::Rc::<str>::from)` over \
12212             RestartStrategy::ALL — a call site whose iteration axis \
12213             holds `&RestartStrategy` by construction — must byte-\
12214             equal `.iter().map(|s| std::rc::Rc::<str>::from(s.as_str()))` \
12215             on every arm — the borrowed-input std::rc::Rc<str> \
12216             `From<&RestartStrategy> for std::rc::Rc<str>` axis is \
12217             what makes the `std::rc::Rc::<str>::from` composition \
12218             route through the substrate-primitive \
12219             `RestartStrategy::as_str` accessor without a spurious \
12220             `Copy` deref (which would only be reachable through the \
12221             owned-input `From<RestartStrategy> for std::rc::Rc<str>` \
12222             axis by first calling `.copied()` on the iterator)"
12223        );
12224    }
12225
12226    #[test]
12227    #[allow(
12228        clippy::too_many_lines,
12229        reason = "cross-axis partition pin folds the substrate-primitive \
12230                  as_str accessor's `.as_bytes()` byte-tail plus the \
12231                  paired str-view (AsRef<str>, Display, as_str) and \
12232                  reverse-projection ({&'static str, String, Cow<'static, \
12233                  str>, Box<str>, std::sync::Arc<str>}) return-shape \
12234                  axes' `.as_bytes()` byte-tails plus a <T: AsRef<[u8]>>\
12235                  -bound-consumer witness plus a blake3::Hasher::update-\
12236                  shape byte-input surface witness into one exhaustive \
12237                  round-trip over RestartStrategy::ALL — the accepted \
12238                  line-count cost of opening the byte-view axis keyed \
12239                  to the substrate-primitive as_str accessor at the \
12240                  same test-site"
12241    )]
12242    #[allow(
12243        clippy::needless_borrows_for_generic_args,
12244        reason = "the borrowed-input surface (&variant) is exercised \
12245                  deliberately: the `<T: AsRef<[u8]>>`-bound consumer \
12246                  and the `blake3::Hasher::update`-shape byte-input \
12247                  surface both accept either owned or borrowed input \
12248                  through the standard-library blanket \
12249                  `impl<T: ?Sized + AsRef<[u8]>> AsRef<[u8]> for &T`, \
12250                  and this pin round-trips both input shapes to lock \
12251                  the borrowed-input path load-bearing against a \
12252                  future silent regression"
12253    )]
12254    fn restart_strategy_as_ref_bytes_routes_through_as_str_accessor() {
12255        // `<T: AsRef<[u8]>>`-bound generic-consumer witness: a byte-input
12256        // function that binds its argument through the standard-library
12257        // [`AsRef<[u8]>`] trait bound accepts a [`super::RestartStrategy`]
12258        // directly, without the caller open-coding the two-hop
12259        // `estrategia.as_str().as_bytes()` composition. Lifted to the top
12260        // of the function per `clippy::items_after_statements`.
12261        fn generic_bytes_sink<T: AsRef<[u8]>>(t: T) -> Vec<u8> {
12262            t.as_ref().to_vec()
12263        }
12264        // `blake3::Hasher::update`-shape byte-input surface mock: mirrors
12265        // `blake3::Hasher::update` / `ring::digest::Context::update` /
12266        // `sha2::Sha256::update`'s `impl AsRef<[u8]>`-bound `update`
12267        // signature so a per-supervisor BLAKE3 content-address closure
12268        // that composes `hasher.update(estrategia)` on the
12269        // [`crate::Lacre`] closure builder reaches the substrate-primitive
12270        // `as_str` accessor through the [`super::RestartStrategy`]
12271        // `AsRef<[u8]>` axis and no other. Lifted to the top of the
12272        // function per `clippy::items_after_statements`.
12273        struct MockHasher(Vec<u8>);
12274        impl MockHasher {
12275            fn new() -> Self {
12276                Self(Vec::new())
12277            }
12278            fn update(&mut self, bytes: impl AsRef<[u8]>) -> &mut Self {
12279                self.0.extend_from_slice(bytes.as_ref());
12280                self
12281            }
12282            fn finalize(self) -> Vec<u8> {
12283                self.0
12284            }
12285        }
12286
12287        // Fail-before-pass-after byte-parity pin on the newly lifted
12288        // `impl AsRef<[u8]> for RestartStrategy` — asserts the trait-
12289        // idiomatic byte-view standard-library impl and the substrate-
12290        // primitive [`super::RestartStrategy::as_str`] `pub const fn`
12291        // accessor's `.as_bytes()` byte-tail resolve to the same four-arm
12292        // `PascalCase` wire byte-string emit-set across every arm the
12293        // exhaustive [`super::RestartStrategy::ALL`] slice enumerates.
12294        // Opens the trait-idiomatic byte-view axis onto the first M2
12295        // OTP-shape closed-set fieldless typed enum peer on the caixa
12296        // surface (`:supervisor :estrategia`), extending the substrate-
12297        // wide byte-view campaign the sibling
12298        // [`super::crate::CaixaKind`] first-mover (69d8d86) opened.
12299        //
12300        // Rust's standard library carries `impl AsRef<[u8]> for str` and
12301        // `impl AsRef<[u8]> for String`, so a two-hop composition
12302        // `estrategia.as_str().as_bytes()` (or the equally two-hop
12303        // `AsRef::<str>::as_ref(&estrategia).as_bytes()`) is reachable
12304        // through the pre-existing str-view axis alone. But that two-hop
12305        // shape has no compile-time link back to the byte-projection
12306        // axis, forces every downstream `<T: AsRef<[u8]>>`-bound
12307        // consumer to open-code the two-hop composition at every call
12308        // site, and admits a silent split whenever a future call site
12309        // takes a sibling reverse-projection axis whose `.as_bytes()`
12310        // byte-tail carries no compile-time byte-view surface. This
12311        // impl closes the byte-view axis at the substrate-primitive
12312        // [`super::RestartStrategy::as_str`] accessor so every future
12313        // `<T: AsRef<[u8]>>`-bound consumer reaches the same lifted
12314        // [`super::crate::render::SUPERVISOR_ESTRATEGIA_*`] const roster
12315        // the paired str-view axes already return through — through one
12316        // trait dispatch.
12317        for &variant in RestartStrategy::ALL {
12318            let via_trait: &[u8] = <RestartStrategy as AsRef<[u8]>>::as_ref(&variant);
12319            let via_method_bytes: &[u8] = variant.as_str().as_bytes();
12320            assert_eq!(
12321                via_trait, via_method_bytes,
12322                "AsRef<[u8]> for RestartStrategy impl must byte-equal \
12323                 RestartStrategy::as_str().as_bytes() on \
12324                 RestartStrategy::{variant:?} — divergence signals a \
12325                 silent detour off the substrate-primitive accessor"
12326            );
12327            // Cross-axis witness against the paired str-view axes'
12328            // `.as_bytes()` byte-tails: [`AsRef<str>`] /
12329            // [`std::fmt::Display`] / [`super::RestartStrategy::as_str`]
12330            // all resolve to the same lifted
12331            // [`super::crate::render::SUPERVISOR_ESTRATEGIA_*`] const
12332            // roster, and the byte-view axis must byte-equal each of
12333            // their `.as_bytes()` byte-tails by construction — locking
12334            // the str-view and byte-view axes together at the
12335            // substrate-primitive accessor.
12336            let str_view_ref: &str = <RestartStrategy as AsRef<str>>::as_ref(&variant);
12337            assert_eq!(
12338                via_trait,
12339                str_view_ref.as_bytes(),
12340                "AsRef<[u8]> for RestartStrategy and AsRef<str> for \
12341                 RestartStrategy must resolve to byte-equal byte-tails \
12342                 on RestartStrategy::{variant:?} — divergence signals \
12343                 the byte-view and str-view axes have drifted off the \
12344                 same substrate-primitive as_str accessor"
12345            );
12346            let display_bytes = variant.to_string();
12347            assert_eq!(
12348                via_trait,
12349                display_bytes.as_bytes(),
12350                "AsRef<[u8]> for RestartStrategy and \
12351                 <RestartStrategy as std::fmt::Display>::to_string must \
12352                 resolve to byte-equal byte-tails on \
12353                 RestartStrategy::{variant:?} — divergence signals the \
12354                 byte-view axis and the Display formatter axis have \
12355                 drifted off the same substrate-primitive as_str \
12356                 accessor"
12357            );
12358            // Cross-axis witness against the paired reverse-projection
12359            // axes' `.as_bytes()` byte-tails: every one of `{&'static
12360            // str, String, Cow<'static, str>, Box<str>,
12361            // std::sync::Arc<str>}` allocates (or borrows) the same
12362            // `PascalCase` wire byte-string the substrate-primitive
12363            // accessor emits, so the byte-view axis must byte-equal
12364            // each of their `.as_bytes()` byte-tails by construction.
12365            let owned_static: &'static str = <&'static str as From<RestartStrategy>>::from(variant);
12366            assert_eq!(
12367                via_trait,
12368                owned_static.as_bytes(),
12369                "AsRef<[u8]> for RestartStrategy and From<RestartStrategy> \
12370                 for &'static str must resolve to byte-equal byte-tails \
12371                 on RestartStrategy::{variant:?}"
12372            );
12373            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
12374            assert_eq!(
12375                via_trait,
12376                owned_string.as_bytes(),
12377                "AsRef<[u8]> for RestartStrategy and From<RestartStrategy> \
12378                 for String must resolve to byte-equal byte-tails on \
12379                 RestartStrategy::{variant:?}"
12380            );
12381            let owned_cow: std::borrow::Cow<'static, str> =
12382                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
12383            assert_eq!(
12384                via_trait,
12385                owned_cow.as_bytes(),
12386                "AsRef<[u8]> for RestartStrategy and From<RestartStrategy> \
12387                 for Cow<'static, str> must resolve to byte-equal byte-\
12388                 tails on RestartStrategy::{variant:?}"
12389            );
12390            let owned_box: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
12391            assert_eq!(
12392                via_trait,
12393                owned_box.as_bytes(),
12394                "AsRef<[u8]> for RestartStrategy and From<RestartStrategy> \
12395                 for Box<str> must resolve to byte-equal byte-tails on \
12396                 RestartStrategy::{variant:?}"
12397            );
12398            let owned_arc: std::sync::Arc<str> =
12399                <std::sync::Arc<str> as From<RestartStrategy>>::from(variant);
12400            assert_eq!(
12401                via_trait,
12402                owned_arc.as_bytes(),
12403                "AsRef<[u8]> for RestartStrategy and From<RestartStrategy> \
12404                 for std::sync::Arc<str> must resolve to byte-equal byte-\
12405                 tails on RestartStrategy::{variant:?}"
12406            );
12407        }
12408        // `<T: AsRef<[u8]>>`-bound-consumer witness: the generic byte-
12409        // input function `generic_bytes_sink` (lifted above per
12410        // `clippy::items_after_statements`) accepts a
12411        // [`super::RestartStrategy`] directly through the trait bound,
12412        // without the caller open-coding the two-hop
12413        // `estrategia.as_str().as_bytes()` composition. This is the
12414        // shape that reaches the caixa-lacre BLAKE3 content-address
12415        // closure's `blake3::Hasher::update(impl AsRef<[u8]>)` byte-
12416        // input surface through this impl and no other.
12417        for &variant in RestartStrategy::ALL {
12418            let via_generic = generic_bytes_sink(variant);
12419            let via_borrowed_generic = generic_bytes_sink(&variant);
12420            let via_method_bytes = variant.as_str().as_bytes().to_vec();
12421            assert_eq!(
12422                via_generic, via_method_bytes,
12423                "generic `<T: AsRef<[u8]>>`-bound consumer on \
12424                 RestartStrategy::{variant:?} must yield the same byte-\
12425                 tail RestartStrategy::as_str().as_bytes() returns — \
12426                 divergence signals the byte-view axis fails to bridge \
12427                 a generic byte-input trait bound to the substrate-\
12428                 primitive accessor"
12429            );
12430            assert_eq!(
12431                via_borrowed_generic, via_method_bytes,
12432                "generic `<T: AsRef<[u8]>>`-bound consumer on \
12433                 &RestartStrategy::{variant:?} must yield the same byte-\
12434                 tail RestartStrategy::as_str().as_bytes() returns — \
12435                 the borrowed-input surface must resolve to the same \
12436                 as_str dispatch"
12437            );
12438        }
12439        // `blake3::Hasher::update`-shape byte-input surface witness on
12440        // the caixa-lacre compounding target: the `MockHasher` (lifted
12441        // above per `clippy::items_after_statements`) mirrors
12442        // `blake3::Hasher::update` / `ring::digest::Context::update` /
12443        // `sha2::Sha256::update`'s `impl AsRef<[u8]>`-bound update
12444        // signature and accepts a [`super::RestartStrategy`] directly,
12445        // routing its byte-tail through the substrate-primitive
12446        // `as_str` accessor — the shape a future per-supervisor BLAKE3
12447        // content-address closure composes to fold an `:estrategia`
12448        // discriminator byte-tag into the [`crate::Lacre`] closure
12449        // body.
12450        for &variant in RestartStrategy::ALL {
12451            let mut owned_hasher = MockHasher::new();
12452            owned_hasher.update(variant);
12453            let owned_folded = owned_hasher.finalize();
12454            assert_eq!(
12455                owned_folded,
12456                variant.as_str().as_bytes(),
12457                "`hasher.update(estrategia)`-shape composition on \
12458                 RestartStrategy::{variant:?} must fold the same byte-\
12459                 tail RestartStrategy::as_str().as_bytes() returns — \
12460                 the shape a future per-supervisor BLAKE3 content-\
12461                 address closure composes to fold an `:estrategia` \
12462                 discriminator byte-tag into the Lacre closure body"
12463            );
12464            let mut borrowed_hasher = MockHasher::new();
12465            borrowed_hasher.update(&variant);
12466            let borrowed_folded = borrowed_hasher.finalize();
12467            assert_eq!(
12468                borrowed_folded,
12469                variant.as_str().as_bytes(),
12470                "`hasher.update(&estrategia)`-shape composition on \
12471                 &RestartStrategy::{variant:?} must fold the same byte-\
12472                 tail RestartStrategy::as_str().as_bytes() returns — \
12473                 the borrowed-input surface must resolve to the same \
12474                 as_str dispatch"
12475            );
12476        }
12477    }
12478
12479    #[test]
12480    #[expect(
12481        clippy::too_many_lines,
12482        reason = "the byte-owned reverse-projection axis is extended \
12483                  here onto the first M2-OTP-shape closed-set fieldless \
12484                  typed-enum peer, so the pin binds the new impl against \
12485                  every paired byte-view and str-owned axis on the same \
12486                  enum plus a generic <T: Into<Vec<u8>>>-bound consumer \
12487                  witness and a std::io::Write::write_all-shape owned-\
12488                  byte-sink surface witness on both owned and borrowed \
12489                  input shapes to lock the whole family against a future \
12490                  silent regression"
12491    )]
12492    fn restart_strategy_from_into_owned_vec_bytes_routes_through_as_str_accessor() {
12493        // `<T: Into<Vec<u8>>>`-bound-consumer witness helper: a generic
12494        // owned-byte-input function accepts a [`super::RestartStrategy`]
12495        // directly through the trait bound, without the caller open-
12496        // coding the three-hop `strategy.as_str().as_bytes().to_vec()`
12497        // composition. Lifted to the top of the function per
12498        // `clippy::items_after_statements`.
12499        fn generic_owned_bytes_sink<T: Into<Vec<u8>>>(t: T) -> Vec<u8> {
12500            t.into()
12501        }
12502        // `std::io::Write::write_all`-shape owned-byte-sink surface
12503        // mock: mirrors `std::io::Write::write_all` /
12504        // `bytes::BytesMut::extend_from_slice` / any per-arm audit-log
12505        // byte-sink that consumes a `Vec<u8>` payload via
12506        // `Into<Vec<u8>>`, so a future per-supervisor per-`:estrategia`
12507        // audit-log emit reaches the substrate-primitive `as_str`
12508        // accessor through the byte-owned reverse-projection axis and
12509        // no other. Lifted to the top of the function per
12510        // `clippy::items_after_statements`.
12511        struct MockOwnedByteSink(Vec<u8>);
12512        impl MockOwnedByteSink {
12513            fn new() -> Self {
12514                Self(Vec::new())
12515            }
12516            fn write_all(&mut self, bytes: impl Into<Vec<u8>>) -> &mut Self {
12517                self.0.extend_from_slice(&bytes.into());
12518                self
12519            }
12520            fn finalize(self) -> Vec<u8> {
12521                self.0
12522            }
12523        }
12524
12525        // Fail-before-pass-after byte-parity pin on the newly lifted
12526        // `impl From<RestartStrategy> for Vec<u8>` and
12527        // `impl From<&RestartStrategy> for Vec<u8>` — asserts the trait-
12528        // idiomatic byte-owned reverse-projection standard-library
12529        // impls and the substrate-primitive
12530        // [`super::RestartStrategy::as_str`] `pub const fn` accessor's
12531        // `.as_bytes().to_vec()` byte-tail resolve to the same four-arm
12532        // PascalCase wire byte-string emit-set across every arm the
12533        // exhaustive [`super::RestartStrategy::ALL`] slice enumerates.
12534        // Extends the substrate-wide trait-idiomatic byte-owned
12535        // reverse-projection axis onto the first M2-OTP-shape closed-
12536        // set fieldless typed-enum peer on the caixa surface
12537        // (`:supervisor :estrategia`), matching the trajectory the
12538        // first-mover [`super::crate::CaixaKind`] lift (b245fd6), the
12539        // second-mover [`super::crate::dialeto::CaixaDialeto`] lift
12540        // (4cceaf5), and the third-mover
12541        // [`super::crate::dep::DepList`] lift (e974ca2) established
12542        // across the caixa-core-internal tier.
12543        for &variant in RestartStrategy::ALL {
12544            let via_owned_from: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
12545            let via_borrowed_from: Vec<u8> = <Vec<u8> as From<&RestartStrategy>>::from(&variant);
12546            let via_method_bytes: Vec<u8> = variant.as_str().as_bytes().to_vec();
12547            assert_eq!(
12548                via_owned_from, via_method_bytes,
12549                "From<RestartStrategy> for Vec<u8> impl must byte-equal \
12550                 RestartStrategy::as_str().as_bytes().to_vec() on \
12551                 RestartStrategy::{variant:?} — divergence signals a \
12552                 silent detour off the substrate-primitive accessor"
12553            );
12554            assert_eq!(
12555                via_borrowed_from, via_method_bytes,
12556                "From<&RestartStrategy> for Vec<u8> impl must byte-\
12557                 equal RestartStrategy::as_str().as_bytes().to_vec() \
12558                 on RestartStrategy::{variant:?} — divergence signals \
12559                 a silent detour off the substrate-primitive accessor"
12560            );
12561            assert_eq!(
12562                via_owned_from, via_borrowed_from,
12563                "From<RestartStrategy> for Vec<u8> and \
12564                 From<&RestartStrategy> for Vec<u8> must byte-equal \
12565                 each other on RestartStrategy::{variant:?} — \
12566                 divergence signals the owned-input and borrowed-input \
12567                 paths have drifted off the same substrate-primitive \
12568                 as_str accessor"
12569            );
12570            // Cross-axis witness against the paired [`AsRef<[u8]>`]
12571            // borrowed byte-view axis (cd4c4e0): the byte-owned
12572            // reverse-projection axis must byte-equal the paired
12573            // borrowed byte-view axis by construction — locking the
12574            // byte-view and byte-owned axes together at the substrate-
12575            // primitive accessor.
12576            let borrowed_bytes: &[u8] = <RestartStrategy as AsRef<[u8]>>::as_ref(&variant);
12577            assert_eq!(
12578                via_owned_from,
12579                borrowed_bytes.to_vec(),
12580                "From<RestartStrategy> for Vec<u8> and AsRef<[u8]> \
12581                 for RestartStrategy must resolve to byte-equal byte-\
12582                 tails on RestartStrategy::{variant:?} — divergence \
12583                 signals the byte-owned and byte-view axes have \
12584                 drifted off the same substrate-primitive as_str \
12585                 accessor"
12586            );
12587            // Cross-axis witness against the str-owned reverse-
12588            // projection family's `.into_bytes()` / `.as_bytes().to_vec()`
12589            // byte-tails: every one of `{String, Cow<'static, str>,
12590            // Box<str>, std::sync::Arc<str>, std::rc::Rc<str>}`
12591            // allocates (or borrows) the same PascalCase wire byte-
12592            // string the substrate-primitive accessor emits, so the
12593            // byte-owned axis must byte-equal each of their owned
12594            // byte-tails by construction.
12595            let owned_string: String = <String as From<RestartStrategy>>::from(variant);
12596            assert_eq!(
12597                via_owned_from,
12598                owned_string.into_bytes(),
12599                "From<RestartStrategy> for Vec<u8> and \
12600                 String::from(strategy).into_bytes() must resolve to \
12601                 byte-equal byte-tails on RestartStrategy::{variant:?}"
12602            );
12603            let owned_cow: std::borrow::Cow<'static, str> =
12604                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
12605            assert_eq!(
12606                via_owned_from,
12607                owned_cow.as_bytes().to_vec(),
12608                "From<RestartStrategy> for Vec<u8> and \
12609                 From<RestartStrategy> for Cow<'static, str> must \
12610                 resolve to byte-equal byte-tails on \
12611                 RestartStrategy::{variant:?}"
12612            );
12613            let owned_box: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
12614            assert_eq!(
12615                via_owned_from,
12616                owned_box.as_bytes().to_vec(),
12617                "From<RestartStrategy> for Vec<u8> and \
12618                 From<RestartStrategy> for Box<str> must resolve to \
12619                 byte-equal byte-tails on RestartStrategy::{variant:?}"
12620            );
12621            let owned_arc: std::sync::Arc<str> =
12622                <std::sync::Arc<str> as From<RestartStrategy>>::from(variant);
12623            assert_eq!(
12624                via_owned_from,
12625                owned_arc.as_bytes().to_vec(),
12626                "From<RestartStrategy> for Vec<u8> and \
12627                 From<RestartStrategy> for std::sync::Arc<str> must \
12628                 resolve to byte-equal byte-tails on \
12629                 RestartStrategy::{variant:?}"
12630            );
12631        }
12632        // `<T: Into<Vec<u8>>>`-bound-consumer witness on both owned
12633        // and borrowed input shapes: the generic owned-byte-input
12634        // function `generic_owned_bytes_sink` (lifted above per
12635        // `clippy::items_after_statements`) accepts a
12636        // [`super::RestartStrategy`] and a `&RestartStrategy`
12637        // directly through the trait bound, without the caller open-
12638        // coding the three-hop `strategy.as_str().as_bytes().to_vec()`
12639        // composition.
12640        for &variant in RestartStrategy::ALL {
12641            let via_generic_owned = generic_owned_bytes_sink(variant);
12642            // Bind the borrowed-input path through an explicit
12643            // `&RestartStrategy` local so the generic-consumer witness
12644            // routes through `From<&RestartStrategy> for Vec<u8>` (T
12645            // binds to `&RestartStrategy`) rather than clippy-collapsing
12646            // the borrow onto the owned-input peer.
12647            let variant_ref: &RestartStrategy = &variant;
12648            let via_generic_borrowed = generic_owned_bytes_sink(variant_ref);
12649            let via_method_bytes = variant.as_str().as_bytes().to_vec();
12650            assert_eq!(
12651                via_generic_owned, via_method_bytes,
12652                "generic `<T: Into<Vec<u8>>>`-bound consumer on \
12653                 RestartStrategy::{variant:?} must yield the same byte-\
12654                 tail RestartStrategy::as_str().as_bytes() returns — \
12655                 divergence signals the byte-owned axis fails to bridge \
12656                 a generic owned-byte-input trait bound to the \
12657                 substrate-primitive accessor"
12658            );
12659            assert_eq!(
12660                via_generic_borrowed, via_method_bytes,
12661                "generic `<T: Into<Vec<u8>>>`-bound consumer on \
12662                 &RestartStrategy::{variant:?} must yield the same byte-\
12663                 tail RestartStrategy::as_str().as_bytes() returns — \
12664                 the borrowed-input surface must resolve to the same \
12665                 as_str dispatch"
12666            );
12667        }
12668        // `std::io::Write::write_all`-shape owned-byte-sink surface
12669        // witness: the `MockOwnedByteSink` (lifted above per
12670        // `clippy::items_after_statements`) mirrors
12671        // `std::io::Write::write_all` /
12672        // `bytes::BytesMut::extend_from_slice`'s `impl Into<Vec<u8>>`-
12673        // bound owned-byte input signature and accepts a
12674        // [`super::RestartStrategy`] directly on both owned and
12675        // borrowed input shapes, routing its byte-tail through the
12676        // substrate-primitive `as_str` accessor — the shape a future
12677        // per-supervisor per-`:estrategia` audit-log emit composes to
12678        // fold an `:estrategia` discriminator byte-tag into a
12679        // downstream owned-byte-sink surface.
12680        for &variant in RestartStrategy::ALL {
12681            let mut owned_sink = MockOwnedByteSink::new();
12682            owned_sink.write_all(variant);
12683            let owned_folded = owned_sink.finalize();
12684            assert_eq!(
12685                owned_folded,
12686                variant.as_str().as_bytes(),
12687                "`sink.write_all(strategy)`-shape composition on \
12688                 RestartStrategy::{variant:?} must fold the same byte-\
12689                 tail RestartStrategy::as_str().as_bytes() returns"
12690            );
12691            let mut borrowed_sink = MockOwnedByteSink::new();
12692            let variant_ref: &RestartStrategy = &variant;
12693            borrowed_sink.write_all(variant_ref);
12694            let borrowed_folded = borrowed_sink.finalize();
12695            assert_eq!(
12696                borrowed_folded,
12697                variant.as_str().as_bytes(),
12698                "`sink.write_all(&strategy)`-shape composition on \
12699                 &RestartStrategy::{variant:?} must fold the same byte-\
12700                 tail RestartStrategy::as_str().as_bytes() returns — \
12701                 the borrowed-input surface must resolve to the same \
12702                 as_str dispatch"
12703            );
12704        }
12705    }
12706
12707    #[test]
12708    fn restart_strategy_from_into_owned_cow_bytes_routes_through_as_str_accessor() {
12709        // Fail-before-pass-after byte-parity pin on the newly lifted
12710        // `impl From<RestartStrategy> for std::borrow::Cow<'static, [u8]>`
12711        // and `impl From<&RestartStrategy> for std::borrow::Cow<'static, [u8]>` —
12712        // asserts the trait-idiomatic byte-owned reverse-projection standard-
12713        // library impls and the substrate-primitive
12714        // [`super::RestartStrategy::as_str`] `pub const fn` accessor's
12715        // `.as_bytes()` byte-view resolve to the same four-arm PascalCase
12716        // wire byte-string emit-set across every arm the exhaustive
12717        // [`super::RestartStrategy::ALL`] slice enumerates. Additionally
12718        // asserts the returned `Cow<'static, [u8]>` binds the zero-alloc
12719        // `Cow::Borrowed` arm on both input shapes, because
12720        // `Self::as_str` returns `&'static str` and `.as_bytes()` on it
12721        // preserves the `&'static [u8]` lifetime by construction.
12722        //
12723        // Generic `<T: Into<Cow<'static, [u8]>>>`-bound consumer witness
12724        // helper: a future per-supervisor byte-writer that accepts a
12725        // `Cow<'static, [u8]>` composes on both owned and borrowed input
12726        // shapes without an open-coded three-hop
12727        // `Cow::Borrowed(strategy.as_str().as_bytes())` at every call
12728        // site. Lifted to the top of the function per
12729        // `clippy::items_after_statements`.
12730        fn generic_cow_bytes_sink<T: Into<std::borrow::Cow<'static, [u8]>>>(
12731            t: T,
12732        ) -> std::borrow::Cow<'static, [u8]> {
12733            t.into()
12734        }
12735        for &variant in RestartStrategy::ALL {
12736            let via_owned_from: std::borrow::Cow<'static, [u8]> =
12737                <std::borrow::Cow<'static, [u8]> as From<RestartStrategy>>::from(variant);
12738            let via_borrowed_from: std::borrow::Cow<'static, [u8]> =
12739                <std::borrow::Cow<'static, [u8]> as From<&RestartStrategy>>::from(&variant);
12740            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
12741            assert_eq!(
12742                via_owned_from.as_ref(),
12743                via_method_bytes,
12744                "From<RestartStrategy> for Cow<'static, [u8]> impl must \
12745                 byte-equal RestartStrategy::as_str().as_bytes() on \
12746                 RestartStrategy::{variant:?} — divergence signals a \
12747                 silent detour off the substrate-primitive accessor"
12748            );
12749            assert_eq!(
12750                via_borrowed_from.as_ref(),
12751                via_method_bytes,
12752                "From<&RestartStrategy> for Cow<'static, [u8]> impl must \
12753                 byte-equal RestartStrategy::as_str().as_bytes() on \
12754                 RestartStrategy::{variant:?} — divergence signals a \
12755                 silent detour off the substrate-primitive accessor"
12756            );
12757            assert!(
12758                matches!(via_owned_from, std::borrow::Cow::Borrowed(_)),
12759                "From<RestartStrategy> for Cow<'static, [u8]> must bind \
12760                 the zero-alloc Cow::Borrowed arm on \
12761                 RestartStrategy::{variant:?} — Self::as_str returns \
12762                 &'static str, so a Cow::Owned arm signals a silent \
12763                 allocation off the substrate primitive"
12764            );
12765            assert!(
12766                matches!(via_borrowed_from, std::borrow::Cow::Borrowed(_)),
12767                "From<&RestartStrategy> for Cow<'static, [u8]> must bind \
12768                 the zero-alloc Cow::Borrowed arm on \
12769                 &RestartStrategy::{variant:?} — Self::as_str returns \
12770                 &'static str, so a Cow::Owned arm signals a silent \
12771                 allocation off the substrate primitive"
12772            );
12773            // Cross-axis partition against the paired byte-owned
12774            // `Vec<u8>` reverse-projection axis (7cc10eb line 1579) on
12775            // the same enum — the two byte-owned reverse-projection
12776            // axes must byte-agree on every arm.
12777            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
12778            assert_eq!(
12779                via_owned_from.as_ref(),
12780                via_vec_bytes.as_slice(),
12781                "From<RestartStrategy> for Cow<'static, [u8]> and \
12782                 From<RestartStrategy> for Vec<u8> must byte-agree on \
12783                 RestartStrategy::{variant:?} — divergence signals the \
12784                 two byte-owned reverse-projection axes have drifted \
12785                 off the same substrate-primitive as_str accessor"
12786            );
12787            // Cross-axis partition against the paired str-side
12788            // `Cow<'static, str>` reverse-projection axis (7dd28b3) on
12789            // the same enum — the byte-side and str-side Cow<'static, _>
12790            // axes must both bind the Cow::Borrowed arm on every arm
12791            // (both route through Self::as_str's &'static return).
12792            let via_cow_str: std::borrow::Cow<'static, str> =
12793                <std::borrow::Cow<'static, str> as From<RestartStrategy>>::from(variant);
12794            assert_eq!(
12795                via_owned_from.as_ref(),
12796                via_cow_str.as_bytes(),
12797                "From<RestartStrategy> for Cow<'static, [u8]> and \
12798                 From<RestartStrategy> for Cow<'static, str> must \
12799                 byte-agree on RestartStrategy::{variant:?} — \
12800                 divergence signals a silent detour off the shared \
12801                 substrate-primitive as_str accessor"
12802            );
12803        }
12804        for &variant in RestartStrategy::ALL {
12805            let owned_via_generic = generic_cow_bytes_sink(variant);
12806            let variant_ref: &RestartStrategy = &variant;
12807            let borrowed_via_generic = generic_cow_bytes_sink(variant_ref);
12808            assert_eq!(
12809                owned_via_generic.as_ref(),
12810                variant.as_str().as_bytes(),
12811                "<T: Into<Cow<'static, [u8]>>>-bound composition on \
12812                 RestartStrategy::{variant:?} must fold the same byte-\
12813                 tail RestartStrategy::as_str().as_bytes() returns"
12814            );
12815            assert_eq!(
12816                borrowed_via_generic.as_ref(),
12817                variant.as_str().as_bytes(),
12818                "<T: Into<Cow<'static, [u8]>>>-bound composition on \
12819                 &RestartStrategy::{variant:?} must fold the same byte-\
12820                 tail RestartStrategy::as_str().as_bytes() returns"
12821            );
12822        }
12823    }
12824
12825    #[test]
12826    fn restart_policy_try_from_str_routes_through_from_wire_accessor() {
12827        // Fail-before-pass-after byte-parity pin on the newly lifted
12828        // `impl TryFrom<&str> for RestartPolicy` — asserts the standard-
12829        // library trait impl and the substrate-primitive
12830        // [`RestartPolicy::from_wire`] `Option<Self>` accessor resolve to
12831        // the same three-arm accept-set across every arm the exhaustive
12832        // [`RestartPolicy::ALL`] slice enumerates. Any future silent
12833        // detour that routes the trait impl through a divergent
12834        // projection (a per-arm inline `match s { "Permanent" =>
12835        // Ok(Self::Permanent), … }` re-inlining that opens a compile-time
12836        // link to the un-lifted arm-literal, a hypothetical
12837        // `#[serde(rename_all = "…")]` attribute drift that silently
12838        // splits the wire byte-string from every consumer that reaches
12839        // for this typed dispatch, an accidental swap onto the kebab-case
12840        // dispatcher-catalog axis the pre-existing [`std::str::FromStr`]
12841        // impl parses through and which would collide the two-axis
12842        // wire/catalog split the sibling [`RestartPolicy::from_wire`]
12843        // doc block makes load-bearing) trips at caixa-core test time
12844        // under `assert_eq!` rather than at a downstream
12845        // `impl TryFrom<&str>`-bound consumer's silent split. Sweeps
12846        // every one of the three arms [`RestartPolicy::ALL`] carries so
12847        // no arm's projection is covered only by the sibling method-
12848        // named `from_wire` path. Peer of the sibling
12849        // [`restart_strategy_try_from_str_routes_through_from_wire_accessor`]
12850        // (5b828ed) — extends the trait-idiomatic reverse-projection
12851        // axis onto the third and final M2-OTP-shape closed-set typed
12852        // enum on the caixa surface (the paired per-child restart-
12853        // decision-policy sibling on the same M2 `:supervisor` slot).
12854        for &variant in RestartPolicy::ALL {
12855            let wire = variant.as_str();
12856            assert_eq!(
12857                <RestartPolicy as TryFrom<&str>>::try_from(wire),
12858                Ok(variant),
12859                "TryFrom<&str> impl on RestartPolicy must round-trip \
12860                 RestartPolicy::{variant:?}.as_str() = {wire:?} back to \
12861                 Ok(RestartPolicy::{variant:?}) — divergence from \
12862                 RestartPolicy::from_wire signals a silent detour off \
12863                 the substrate-primitive accessor"
12864            );
12865            assert_eq!(
12866                <RestartPolicy as TryFrom<&str>>::try_from(wire).ok(),
12867                RestartPolicy::from_wire(wire),
12868                "TryFrom<&str> ok()-projection on {wire:?} must byte-\
12869                 equal RestartPolicy::from_wire on the same input"
12870            );
12871        }
12872    }
12873
12874    #[test]
12875    fn restart_policy_try_from_str_rejects_unknown_byte_strings() {
12876        // Rejection witness on the `impl TryFrom<&str> for
12877        // RestartPolicy` — sweeps a candidate set of byte-strings
12878        // outside the three-arm PascalCase wire accept-set the sibling
12879        // [`RestartPolicy::as_str`] emits and asserts every one lands on
12880        // `Err(())`, so a future accidental widening of the trait impl's
12881        // accept-set (a stray additional
12882        // `_ if s.eq_ignore_ascii_case("Permanent") => Ok(…)` case-fold
12883        // path, a silent inclusion of the kebab-case dispatcher-catalog
12884        // byte-string the pre-existing [`std::str::FromStr`] impl the
12885        // [`gen_platform::FromStrKind`] derive installs parses onto the
12886        // wire axis — which would collide the two-axis
12887        // wire/dispatcher-catalog split the sibling
12888        // [`RestartPolicy::from_wire`] doc block makes load-bearing —
12889        // an English-rebrand or plural-arm silent alias that would widen
12890        // the wire accept-set past the OTP-canonical three) trips at
12891        // caixa-core test time. The candidate set includes the empty
12892        // string, whitespace-only padding, the kebab-case dispatcher-
12893        // catalog byte-strings on the sibling axis (a caller who
12894        // confuses the two axes trips here rather than at a downstream
12895        // consumer's silent reject), a lowercase / uppercase / mixed-case
12896        // fold of each PascalCase arm (a caller who assumes case-fold
12897        // acceptance trips here), leading/trailing whitespace padding,
12898        // the trailing-newline shape, quote-wrapped candidates, and a
12899        // residual set of plausible-but-wrong English rebrand
12900        // candidates. Peer of the sibling
12901        // [`restart_strategy_try_from_str_rejects_unknown_byte_strings`]
12902        // (5b828ed) rejection witness.
12903        let rejected: &[&str] = &[
12904            "",
12905            " ",
12906            "\n",
12907            "\t",
12908            "permanent",
12909            "temporary",
12910            "transient",
12911            "PERMANENT",
12912            "TEMPORARY",
12913            "TRANSIENT",
12914            "Permanents",
12915            "Permanent ",
12916            " Permanent",
12917            " Temporary ",
12918            "Permanent\n",
12919            "Transient\t",
12920            "\"Permanent\"",
12921            "Ephemeral",
12922            "Always",
12923            "Never",
12924            "OnAbnormalExit",
12925            "intrinsic",
12926            "?",
12927        ];
12928        for &input in rejected {
12929            assert_eq!(
12930                <RestartPolicy as TryFrom<&str>>::try_from(input),
12931                Err(()),
12932                "TryFrom<&str> impl on RestartPolicy must reject the \
12933                 non-wire byte-string {input:?} — silent acceptance \
12934                 signals an accept-set widening off the paired \
12935                 RestartPolicy::from_wire resolver"
12936            );
12937        }
12938    }
12939
12940    #[test]
12941    fn restart_policy_try_from_str_and_from_wire_partition_the_accept_set() {
12942        // Cross-axis partition pin: the paired `TryFrom<&str>` and
12943        // `from_wire` reverse projections must resolve identically on
12944        // *every* input, not just the ones [`RestartPolicy::ALL`]
12945        // enumerates. Sweeps a mixed candidate set spanning accepted
12946        // (three-arm PascalCase wire byte-strings) and rejected (kebab-
12947        // case dispatcher-catalog byte-strings, empty, whitespace-
12948        // padded, quoted, English-rebrand candidates) inputs and asserts
12949        // the trait's `Result::ok()` projection byte-equals the method-
12950        // named resolver's `Option<Self>` return-shape on each, locking
12951        // the two paths together by construction so any future detour
12952        // (a stray `try_from` special-case that widens or narrows the
12953        // accept-set outside the paired `from_wire` resolver, an
12954        // accidental swap onto the kebab-case [`std::str::FromStr`]
12955        // impl the [`gen_platform::FromStrKind`] derive installs on the
12956        // sibling dispatcher-catalog axis) trips at caixa-core test
12957        // time. Peer of the sibling
12958        // [`restart_strategy_try_from_str_and_from_wire_partition_the_accept_set`]
12959        // pin — extends the round-trip discipline onto the M2-OTP-shape
12960        // per-child restart-policy axis.
12961        let candidates: &[&str] = &[
12962            "Permanent",
12963            "Temporary",
12964            "Transient",
12965            "",
12966            "permanent",
12967            "temporary",
12968            "transient",
12969            "PERMANENT",
12970            "unknown",
12971            "Permanent ",
12972            " Permanent",
12973            "\"Permanent\"",
12974            "Ephemeral",
12975            "OnAbnormalExit",
12976            "?",
12977        ];
12978        for &input in candidates {
12979            let via_trait: Option<RestartPolicy> =
12980                <RestartPolicy as TryFrom<&str>>::try_from(input).ok();
12981            let via_method: Option<RestartPolicy> = RestartPolicy::from_wire(input);
12982            assert_eq!(
12983                via_trait, via_method,
12984                "TryFrom<&str> and from_wire must resolve identically on \
12985                 input {input:?} — divergence signals the two reverse-\
12986                 projection paths have drifted onto different accept-sets"
12987            );
12988        }
12989    }
12990
12991    #[test]
12992    fn restart_policy_from_into_static_str_routes_through_as_str_accessor() {
12993        // Fail-before-pass-after byte-parity pin on the newly lifted
12994        // `impl From<RestartPolicy> for &'static str` — asserts the
12995        // standard-library trait impl and the substrate-primitive
12996        // [`RestartPolicy::as_str`] `pub const fn` accessor resolve to
12997        // the same three-arm emit-set across every arm the exhaustive
12998        // [`RestartPolicy::ALL`] slice enumerates. Any future silent
12999        // detour that routes the trait impl through a divergent
13000        // projection (a per-arm inline `match policy { Permanent =>
13001        // "Permanent", … }` re-inlining that opens a compile-time link
13002        // to the un-lifted arm-literal, an accidental swap onto the
13003        // sibling kebab-case [`Self::discriminant`] dispatcher-catalog
13004        // axis that would collide the two-axis wire/catalog split the
13005        // sibling [`RestartPolicy::from_wire`] doc block makes
13006        // load-bearing) trips at caixa-core test time under
13007        // `assert_eq!` rather than at a downstream
13008        // `impl Into<&'static str>`-bound consumer's silent split.
13009        // Sweeps every one of the three arms [`RestartPolicy::ALL`]
13010        // carries so no arm's projection is covered only by the sibling
13011        // method-named `as_str` / [`std::fmt::Display`] / [`AsRef<str>`]
13012        // paths. Materializes the `<&'static str as
13013        // From<RestartPolicy>>::from` output in a `const`-shape binding
13014        // to make the `'static` lifetime promise a build-time invariant
13015        // — a future accidental downgrade of any of the three arms'
13016        // [`crate::render::SUPERVISOR_CHILD_RESTART_*`] constants to a
13017        // non-`&'static str` (a `String::leak()`-produced return, a
13018        // `Box::leak`-cast) trips at caixa-core build time rather than
13019        // at a downstream `'static`-bound consumer. Peer of the sibling
13020        // [`restart_strategy_from_into_static_str_routes_through_as_str_accessor`]
13021        // (523157d) — extends the trait-idiomatic forward-projection
13022        // axis onto the second (and second-of-two-in-M2) closed-set
13023        // typed enum on the caixa surface (the paired per-child
13024        // restart-decision-policy sibling on the same M2 `:supervisor`
13025        // slot).
13026        const PERMANENT: &str = RestartPolicy::Permanent.as_str();
13027        const TEMPORARY: &str = RestartPolicy::Temporary.as_str();
13028        const TRANSIENT: &str = RestartPolicy::Transient.as_str();
13029        for &variant in RestartPolicy::ALL {
13030            let via_trait: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13031            let via_method: &'static str = variant.as_str();
13032            assert_eq!(
13033                via_trait, via_method,
13034                "From<RestartPolicy> for &'static str impl must round-trip \
13035                 RestartPolicy::{variant:?} to the same lifted \
13036                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str returns — \
13037                 divergence signals a silent detour off the substrate-primitive \
13038                 accessor"
13039            );
13040            let via_into: &'static str = variant.into();
13041            assert_eq!(
13042                via_into, via_method,
13043                "Into<&'static str>::into on RestartPolicy::{variant:?} must \
13044                 byte-equal RestartPolicy::as_str on the same input — the \
13045                 blanket-derived Into shape must resolve to the same as_str \
13046                 dispatch as the explicit From impl"
13047            );
13048        }
13049        assert_eq!(
13050            [PERMANENT, TEMPORARY, TRANSIENT],
13051            [
13052                crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
13053                crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
13054                crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
13055            ],
13056            "const-context RestartPolicy::as_str must resolve to the three \
13057             lifted SUPERVISOR_CHILD_RESTART_* consts — a future accidental \
13058             downgrade of any arm to a non-const or non-static byte-string \
13059             breaks the `&'static str`-lifetime promise the paired \
13060             From<RestartPolicy> for &'static str impl carries by \
13061             construction"
13062        );
13063    }
13064
13065    #[test]
13066    fn restart_policy_from_into_static_str_and_as_str_partition_the_emit_set() {
13067        // Cross-axis partition pin: the paired trait-idiomatic
13068        // `From<RestartPolicy> for &'static str` forward projection and
13069        // the method-named [`RestartPolicy::as_str`] forward projection
13070        // must resolve identically on *every* arm, not just the ones
13071        // named in the primary byte-parity pin above. Sweeps every
13072        // [`RestartPolicy::ALL`] arm and asserts the trait's `From::from`
13073        // output byte-equals the method-named accessor's return-value on
13074        // each, locking the two forward-projection paths together by
13075        // construction so any future detour (a stray `From` special-case
13076        // that lands on a divergent per-arm literal outside the paired
13077        // `as_str` dispatch, a hypothetical rebrand touching one axis
13078        // without the other) trips at caixa-core test time. Peer of the
13079        // sibling forward-projection partition pin
13080        // [`restart_strategy_from_into_static_str_and_as_str_partition_the_emit_set`]
13081        // (523157d) — extends the round-trip discipline onto the
13082        // second-of-two M2-OTP-shape closed-set typed enum on the caixa
13083        // surface, closing the two-way `Self ↔ &'static str` round-trip
13084        // on the trait-idiomatic pair (`From<Self> for &'static str` +
13085        // `TryFrom<&str> for Self`) as well as the pre-existing method-
13086        // named pair (`as_str` + `from_wire`).
13087        for &variant in RestartPolicy::ALL {
13088            let via_trait: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13089            let via_method: &'static str = variant.as_str();
13090            assert_eq!(
13091                via_trait, via_method,
13092                "From<RestartPolicy> for &'static str and \
13093                 RestartPolicy::as_str must resolve identically on \
13094                 RestartPolicy::{variant:?} — divergence signals the \
13095                 two forward-projection paths have drifted onto different \
13096                 emit-sets"
13097            );
13098        }
13099        // Round-trip witness: every arm's forward `From` output re-parses
13100        // through the paired trait-idiomatic reverse `TryFrom<&str>` back
13101        // to the original variant. Closes the two-way `RestartPolicy ↔
13102        // &'static str` round-trip on the trait-idiomatic axis pair,
13103        // mirroring the pre-existing method-named `as_str` + `from_wire`
13104        // round-trip on the substrate-primitive axis pair.
13105        for &variant in RestartPolicy::ALL {
13106            let emitted: &'static str = variant.into();
13107            let re_parsed: Result<RestartPolicy, ()> =
13108                <RestartPolicy as TryFrom<&str>>::try_from(emitted);
13109            assert_eq!(
13110                re_parsed,
13111                Ok(variant),
13112                "trait-idiomatic axis pair must round-trip \
13113                 RestartPolicy::{variant:?} through `.into::<&'static \
13114                 str>()` and back through `TryFrom<&str>` — a break signals \
13115                 the forward-emit and reverse-parse axes have drifted onto \
13116                 different vocabularies"
13117            );
13118        }
13119    }
13120
13121    #[test]
13122    fn restart_policy_from_borrowed_into_static_str_routes_through_as_str_accessor() {
13123        // Fail-before-pass-after byte-parity pin on the newly lifted
13124        // `impl From<&RestartPolicy> for &'static str` — asserts the
13125        // borrowed-input standard-library trait impl and the substrate-
13126        // primitive [`RestartPolicy::as_str`] `pub const fn` accessor
13127        // resolve to the same three-arm emit-set across every arm the
13128        // exhaustive [`RestartPolicy::ALL`] slice enumerates. Rust's
13129        // `From` trait does not auto-derive the borrowed-input sibling
13130        // from a paired owned-input impl (no `impl<T, U> From<&T> for U
13131        // where T: Copy, U: From<T>` blanket in `core`), so the
13132        // borrowed-input axis is a distinct trait-idiomatic surface
13133        // that a `.iter().map(Into::into)` shape over
13134        // [`RestartPolicy::ALL`] (whose iterator yields
13135        // `&RestartPolicy`, not `RestartPolicy`) reaches through this
13136        // impl and no other — the paired owned-input
13137        // [`From<RestartPolicy>`] impl requires an explicit `.copied()`
13138        // / dereference before the trait fires. Materializes the
13139        // `<&'static str as From<&RestartPolicy>>::from` output in a
13140        // `const`-shape binding to make the `'static` lifetime promise
13141        // a build-time invariant.
13142        const PERMANENT: &str = RestartPolicy::Permanent.as_str();
13143        const TEMPORARY: &str = RestartPolicy::Temporary.as_str();
13144        const TRANSIENT: &str = RestartPolicy::Transient.as_str();
13145        for variant in RestartPolicy::ALL {
13146            let via_trait: &'static str = <&'static str as From<&RestartPolicy>>::from(variant);
13147            let via_method: &'static str = variant.as_str();
13148            assert_eq!(
13149                via_trait, via_method,
13150                "From<&RestartPolicy> for &'static str impl must round-trip \
13151                 &RestartPolicy::{variant:?} to the same lifted \
13152                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str \
13153                 returns — divergence signals a silent detour off the \
13154                 substrate-primitive accessor"
13155            );
13156            let via_into: &'static str = variant.into();
13157            assert_eq!(
13158                via_into, via_method,
13159                "Into<&'static str>::into on &RestartPolicy::{variant:?} \
13160                 must byte-equal RestartPolicy::as_str on the same input — \
13161                 the blanket-derived Into shape must resolve to the same \
13162                 as_str dispatch as the explicit From impl"
13163            );
13164        }
13165        assert_eq!(
13166            [PERMANENT, TEMPORARY, TRANSIENT],
13167            [
13168                crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
13169                crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
13170                crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
13171            ],
13172            "const-context RestartPolicy::as_str must resolve to the three \
13173             lifted SUPERVISOR_CHILD_RESTART_* consts — the borrowed-input \
13174             From<&RestartPolicy> for &'static str impl inherits its \
13175             `'static` lifetime promise from the same accessor the \
13176             owned-input sibling routes through"
13177        );
13178    }
13179
13180    #[test]
13181    fn restart_policy_from_owned_and_borrowed_into_static_str_agree_on_every_arm() {
13182        // Cross-axis partition pin: the paired trait-idiomatic
13183        // owned-input `From<RestartPolicy> for &'static str` (9fb37d0
13184        // campaign-shape) and borrowed-input `From<&RestartPolicy> for
13185        // &'static str` (this lift) forward projections must resolve
13186        // identically on every arm, locking the two input-shape paths
13187        // together so any future detour trips at caixa-core test time.
13188        // Then a witness that a `.iter().map(Into::into)` pipe over
13189        // [`RestartPolicy::ALL`] (whose iterator yields
13190        // `&RestartPolicy`) materializes the three-arm accept-set
13191        // through the borrowed-input axis alone — the exact shape a
13192        // future wasm-operator per-child post-exit restart-decision
13193        // diagnostic line, a future substrate-wide per-arm diagnostic
13194        // column, or a
13195        // `HashMap::<&'static str, RestartPolicy>::from_iter(
13196        //     RestartPolicy::ALL.iter().map(|p| (p.into(), *p)))`-style
13197        // per-policy lookup reaches through — closing the two-way
13198        // owned/borrowed input-shape symmetry on the forward-projection
13199        // trait-idiomatic axis. Peer of the sibling
13200        // [`crate::dep::tests::dep_list_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
13201        // (64aa742) /
13202        // [`crate::kind::tests::caixa_kind_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
13203        // (5ab993a) /
13204        // [`crate::dialeto::tests::caixa_dialeto_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
13205        // (807b0b5) /
13206        // [`restart_strategy_from_owned_and_borrowed_into_static_str_agree_on_every_arm`]
13207        // (e941836) partition pins on the sibling closed-set typed-enum
13208        // discriminator axes — extends the borrowed-input axis
13209        // discipline onto the second-of-two M2 OTP-shape closed-set
13210        // typed enum on the caixa surface (per-child restart-decision
13211        // policy). Also closes the direct two-way `&Self → &'static
13212        // str → Self` round-trip via the paired [`TryFrom<&str>`] axis
13213        // — unlike the peer [`crate::CaixaKind`] axis pair (whose
13214        // forward `From` emits lowercase Portuguese diagnostic bytes
13215        // while the reverse `TryFrom` parses `PascalCase` wire bytes,
13216        // forcing the round-trip through an intermediate wire-vocab
13217        // hop), the [`RestartPolicy::as_str`] emit and
13218        // [`RestartPolicy::from_wire`] parse share the same
13219        // `PascalCase` vocabulary by construction, so the borrowed-
13220        // input forward axis and the reverse axis compose directly.
13221        for &variant in RestartPolicy::ALL {
13222            let owned: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13223            let borrowed: &'static str = <&'static str as From<&RestartPolicy>>::from(&variant);
13224            assert_eq!(
13225                owned, borrowed,
13226                "From<RestartPolicy> and From<&RestartPolicy> for \
13227                 &'static str must resolve identically on \
13228                 RestartPolicy::{variant:?} — divergence signals the \
13229                 owned-input and borrowed-input forward-projection paths \
13230                 have drifted onto different emit-sets"
13231            );
13232        }
13233        let via_iter: Vec<&'static str> = RestartPolicy::ALL.iter().map(Into::into).collect();
13234        let via_method: Vec<&'static str> = RestartPolicy::ALL.iter().map(|p| p.as_str()).collect();
13235        assert_eq!(
13236            via_iter, via_method,
13237            "`.iter().map(Into::into)` over RestartPolicy::ALL must \
13238             byte-equal `.iter().map(|p| p.as_str())` on every arm — the \
13239             borrowed-input `From<&RestartPolicy> for &'static str` axis \
13240             is what makes the `.iter().map(Into::into)` shape route \
13241             through the substrate-primitive `RestartPolicy::as_str` \
13242             accessor rather than through a per-call-site `.copied()` / \
13243             dereference detour"
13244        );
13245        for variant in RestartPolicy::ALL {
13246            let emitted: &'static str = variant.into();
13247            let re_parsed: Result<RestartPolicy, ()> =
13248                <RestartPolicy as TryFrom<&str>>::try_from(emitted);
13249            assert_eq!(
13250                re_parsed,
13251                Ok(*variant),
13252                "trait-idiomatic borrowed-input forward-projection + \
13253                 reverse-projection axis pair must round-trip \
13254                 &RestartPolicy::{variant:?} through `.into::<&'static \
13255                 str>()` (via the borrowed-input axis) and back through \
13256                 `TryFrom<&str>` — a break signals the borrowed-input \
13257                 forward-emit and reverse-parse axes have drifted onto \
13258                 different vocabularies"
13259            );
13260        }
13261    }
13262
13263    #[test]
13264    fn restart_policy_from_into_owned_string_routes_through_as_str_accessor() {
13265        // Fail-before-pass-after byte-parity pin on the newly lifted
13266        // `impl From<RestartPolicy> for String` — asserts the
13267        // owned-`String`-returning standard-library trait impl and the
13268        // substrate-primitive [`RestartPolicy::as_str`] `pub const fn`
13269        // accessor resolve to the same three-arm emit-set across every
13270        // arm the exhaustive [`RestartPolicy::ALL`] slice enumerates.
13271        // Rust's standard library does not carry a blanket
13272        // `impl<T: AsRef<str>> From<T> for String` (nor an
13273        // `impl<T: fmt::Display> From<T> for String`), so the
13274        // owned-`String` forward-projection axis is a distinct
13275        // trait-idiomatic surface that a `let key: String =
13276        // policy.into();`-shaped call site reaches through this impl
13277        // and no other — the paired sibling `From<RestartPolicy> for
13278        // &'static str` impl forces every owned-`String` call site
13279        // through an explicit `.to_owned()` / `String::from`
13280        // restatement. Peer of the first-mover
13281        // [`restart_strategy_from_into_owned_string_routes_through_as_str_accessor`]
13282        // (7baa18a) — extends the trait-idiomatic owned-`String`
13283        // forward-projection axis onto the second-of-two M2 OTP-shape
13284        // closed-set typed enums on the caixa surface (per-child
13285        // restart-decision-policy sibling on the same M2 `:supervisor`
13286        // slot).
13287        for &variant in RestartPolicy::ALL {
13288            let via_trait: String = <String as From<RestartPolicy>>::from(variant);
13289            let via_method: &'static str = variant.as_str();
13290            assert_eq!(
13291                via_trait.as_str(),
13292                via_method,
13293                "From<RestartPolicy> for String impl must round-trip \
13294                 RestartPolicy::{variant:?} to the same lifted \
13295                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str \
13296                 returns — divergence signals a silent detour off the \
13297                 substrate-primitive accessor"
13298            );
13299            let via_into: String = variant.into();
13300            assert_eq!(
13301                via_into.as_str(),
13302                via_method,
13303                "Into<String>::into on RestartPolicy::{variant:?} must \
13304                 byte-equal RestartPolicy::as_str on the same input — the \
13305                 blanket-derived Into shape must resolve to the same as_str \
13306                 dispatch as the explicit From impl"
13307            );
13308        }
13309    }
13310
13311    #[test]
13312    fn restart_policy_from_into_owned_string_and_static_str_agree_on_every_arm() {
13313        // Cross-axis partition pin: the paired trait-idiomatic
13314        // owned-`String` `From<RestartPolicy> for String` (this lift)
13315        // and owned-`&'static str` `From<RestartPolicy> for &'static
13316        // str` (9fb37d0) forward projections must resolve identically
13317        // on every arm, locking the two return-type-shape paths
13318        // together so any future detour trips at caixa-core test time.
13319        // Also byte-parity witness against the sibling
13320        // [`ToString::to_string`] surface routed through
13321        // [`std::fmt::Display`] — the three owned-heap-string paths
13322        // (`.into::<String>()`, `String::from`, `.to_string()`) must
13323        // resolve identically on every arm so a future consumer that
13324        // picks any of the three lands on the same lifted
13325        // SUPERVISOR_CHILD_RESTART_* const. Then a `.iter().copied()
13326        // .map(String::from)` pipe witness over [`RestartPolicy::ALL`]
13327        // that materializes the three-arm accept-set through the
13328        // owned-`String` axis alone — the exact shape a future
13329        // wasm-operator per-child post-exit restart-decision
13330        // diagnostic line composer or a
13331        // `HashMap::<String, RestartPolicy>::from_iter(
13332        //     RestartPolicy::ALL.iter().copied().map(|p| (p.into(), p)))`-style
13333        // owned-key per-policy lookup reaches through — closing the
13334        // owned-`String` forward-projection axis's iterator-pipe
13335        // shape. Then a direct round-trip witness through the paired
13336        // trait-idiomatic reverse [`TryFrom<&str>`] axis on the
13337        // owned-`String`'s [`String::as_str`] borrow that closes the
13338        // two-way `Self → String → Self` round-trip on the trait-
13339        // idiomatic owned-`String` forward + reverse axis pair —
13340        // unlike the peer [`crate::CaixaKind`] axis pair (whose
13341        // forward `From` emits lowercase Portuguese diagnostic bytes
13342        // while the reverse `TryFrom` parses `PascalCase` wire bytes,
13343        // forcing the round-trip through an intermediate wire-vocab
13344        // hop), the [`RestartPolicy::as_str`] emit and
13345        // [`RestartPolicy::from_wire`] parse share the same
13346        // `PascalCase` vocabulary by construction, so the owned-
13347        // `String` forward axis and the reverse axis compose directly.
13348        for &variant in RestartPolicy::ALL {
13349            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
13350            let owned_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13351            assert_eq!(
13352                owned_string.as_str(),
13353                owned_static,
13354                "From<RestartPolicy> for String and From<RestartPolicy> \
13355                 for &'static str must resolve identically on \
13356                 RestartPolicy::{variant:?} — divergence signals the \
13357                 owned-`String` and owned-`&'static str` forward-projection \
13358                 return-type-shape paths have drifted onto different \
13359                 emit-sets"
13360            );
13361            let via_to_string: String = variant.to_string();
13362            assert_eq!(
13363                owned_string, via_to_string,
13364                "From<RestartPolicy> for String must byte-equal \
13365                 RestartPolicy::to_string on RestartPolicy::{variant:?} — \
13366                 divergence signals the trait-idiomatic owned-`String` \
13367                 forward-projection axis and the ToString-through-Display \
13368                 axis have drifted onto different emit-sets"
13369            );
13370        }
13371        let via_iter: Vec<String> = RestartPolicy::ALL
13372            .iter()
13373            .copied()
13374            .map(String::from)
13375            .collect();
13376        let via_method: Vec<String> = RestartPolicy::ALL
13377            .iter()
13378            .map(|p| p.as_str().to_owned())
13379            .collect();
13380        assert_eq!(
13381            via_iter, via_method,
13382            "`.iter().copied().map(String::from)` over RestartPolicy::ALL \
13383             must byte-equal `.iter().map(|p| p.as_str().to_owned())` on \
13384             every arm — the owned-`String` `From<RestartPolicy> for \
13385             String` axis is what makes the `String::from` composition \
13386             route through the substrate-primitive `RestartPolicy::as_str` \
13387             accessor rather than through a per-call-site `.to_owned()` / \
13388             `String::from(policy.as_str())` detour"
13389        );
13390        for &variant in RestartPolicy::ALL {
13391            let emitted: String = variant.into();
13392            let re_parsed: Result<RestartPolicy, ()> =
13393                <RestartPolicy as TryFrom<&str>>::try_from(emitted.as_str());
13394            assert_eq!(
13395                re_parsed,
13396                Ok(variant),
13397                "trait-idiomatic owned-`String` forward-projection + \
13398                 reverse-projection axis pair must round-trip \
13399                 RestartPolicy::{variant:?} through `.into::<String>()` \
13400                 and back through `TryFrom<&str>` on the owned-`String`'s \
13401                 String::as_str borrow — a break signals the owned-`String` \
13402                 forward-emit and reverse-parse axes have drifted onto \
13403                 different vocabularies"
13404            );
13405        }
13406    }
13407
13408    #[test]
13409    fn restart_policy_from_into_borrowed_owned_string_routes_through_as_str_accessor() {
13410        // Fail-before-pass-after byte-parity pin on the newly lifted
13411        // `impl From<&RestartPolicy> for String` — asserts the
13412        // borrowed-input owned-`String`-returning standard-library
13413        // trait impl and the substrate-primitive
13414        // [`RestartPolicy::as_str`] `pub const fn` accessor resolve to
13415        // the same three-arm emit-set across every arm the exhaustive
13416        // [`RestartPolicy::ALL`] slice enumerates. Rust's standard
13417        // library does not carry a blanket `impl<T: AsRef<str>>
13418        // From<&T> for String` (nor an `impl<T: fmt::Display> From<&T>
13419        // for String`), so the borrowed-input owned-`String` forward-
13420        // projection axis is a distinct trait-idiomatic surface that a
13421        // `let key: String = (&policy).into();`-shaped call site
13422        // reaches through this impl and no other — the paired sibling
13423        // `From<RestartPolicy> for String` impl forces every borrowed-
13424        // input call site through an explicit `Copy` deref
13425        // (`String::from(*policy)`) or an `.as_str().to_owned()` /
13426        // `.to_string()` detour. Peer of the first-mover
13427        // [`restart_strategy_from_into_borrowed_owned_string_routes_through_as_str_accessor`]
13428        // (579385f) — extends the trait-idiomatic borrowed-input
13429        // owned-`String` forward-projection axis onto the second-of-
13430        // two M2 OTP-shape closed-set typed enums on the caixa surface
13431        // (per-child restart-decision-policy sibling on the same M2
13432        // `:supervisor` slot).
13433        for &variant in RestartPolicy::ALL {
13434            let via_trait: String = <String as From<&RestartPolicy>>::from(&variant);
13435            let via_method: &'static str = variant.as_str();
13436            assert_eq!(
13437                via_trait.as_str(),
13438                via_method,
13439                "From<&RestartPolicy> for String impl must round-trip \
13440                 &RestartPolicy::{variant:?} to the same lifted \
13441                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str \
13442                 returns — divergence signals a silent detour off the \
13443                 substrate-primitive accessor"
13444            );
13445            let via_into: String = (&variant).into();
13446            assert_eq!(
13447                via_into.as_str(),
13448                via_method,
13449                "Into<String>::into on &RestartPolicy::{variant:?} must \
13450                 byte-equal RestartPolicy::as_str on the same input — \
13451                 the blanket-derived Into shape must resolve to the \
13452                 same as_str dispatch as the explicit From impl"
13453            );
13454        }
13455    }
13456
13457    #[test]
13458    fn restart_policy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm() {
13459        // Cross-axis partition pin: the newly lifted trait-idiomatic
13460        // borrowed-input owned-`String` `From<&RestartPolicy> for
13461        // String` (this lift), the paired owned-input owned-`String`
13462        // `From<RestartPolicy> for String` (7851725), the paired
13463        // borrowed-input owned-`&'static str` `From<&RestartPolicy>
13464        // for &'static str` (842c7f3), and the paired owned-input
13465        // owned-`&'static str` `From<RestartPolicy> for &'static str`
13466        // (9fb37d0) — every corner of the `{Self, &Self} × {&'static
13467        // str, String}` 2×2 trait-idiomatic projection family — must
13468        // resolve identically on every arm, locking the four
13469        // return-shape × input-shape paths together so any future
13470        // detour trips at caixa-core test time. Also byte-parity
13471        // witness against the sibling [`ToString::to_string`] surface
13472        // routed through [`std::fmt::Display`] and a direct round-trip
13473        // witness through the paired trait-idiomatic reverse
13474        // [`TryFrom<&str>`] axis on the owned-`String`'s
13475        // [`String::as_str`] borrow that closes the two-way
13476        // `&Self → String → Self` round-trip on the trait-idiomatic
13477        // borrowed-input owned-`String` forward + reverse axis pair.
13478        // Peer of the first-mover
13479        // [`restart_strategy_from_into_borrowed_owned_string_agrees_with_paired_axes_on_every_arm`]
13480        // (579385f) — closes the whole `{Self, &Self} × {&'static str,
13481        // String}` 2×2 projection corner on both M2 OTP-shape sibling
13482        // peers.
13483        for &variant in RestartPolicy::ALL {
13484            let borrowed_string: String = <String as From<&RestartPolicy>>::from(&variant);
13485            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
13486            let borrowed_static: &'static str =
13487                <&'static str as From<&RestartPolicy>>::from(&variant);
13488            let owned_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13489            assert_eq!(
13490                borrowed_string, owned_string,
13491                "From<&RestartPolicy> for String and From<RestartPolicy> \
13492                 for String must resolve identically on \
13493                 RestartPolicy::{variant:?} — divergence signals the \
13494                 borrowed-input and owned-input owned-`String` \
13495                 forward-projection input-shape paths have drifted onto \
13496                 different emit-sets"
13497            );
13498            assert_eq!(
13499                borrowed_string.as_str(),
13500                borrowed_static,
13501                "From<&RestartPolicy> for String and From<&RestartPolicy> \
13502                 for &'static str must resolve identically on \
13503                 RestartPolicy::{variant:?} — divergence signals the \
13504                 borrowed-input `&'static str` and owned-`String` \
13505                 return-shape paths have drifted onto different \
13506                 emit-sets"
13507            );
13508            assert_eq!(
13509                borrowed_string.as_str(),
13510                owned_static,
13511                "From<&RestartPolicy> for String and From<RestartPolicy> \
13512                 for &'static str must resolve identically on \
13513                 RestartPolicy::{variant:?} — divergence signals a \
13514                 break in the diagonal corner of the {{Self, &Self}} × \
13515                 {{&'static str, String}} 2×2 trait-idiomatic \
13516                 projection family"
13517            );
13518            let via_to_string: String = variant.to_string();
13519            assert_eq!(
13520                borrowed_string, via_to_string,
13521                "From<&RestartPolicy> for String must byte-equal \
13522                 RestartPolicy::to_string on RestartPolicy::{variant:?} \
13523                 — divergence signals the trait-idiomatic borrowed-input \
13524                 owned-`String` forward-projection axis and the \
13525                 ToString-through-Display axis have drifted onto \
13526                 different emit-sets"
13527            );
13528        }
13529        let via_iter: Vec<String> = RestartPolicy::ALL.iter().map(String::from).collect();
13530        let via_method: Vec<String> = RestartPolicy::ALL
13531            .iter()
13532            .map(|p| p.as_str().to_owned())
13533            .collect();
13534        assert_eq!(
13535            via_iter, via_method,
13536            "`.iter().map(String::from)` over RestartPolicy::ALL — a \
13537             call site whose iteration axis holds `&RestartPolicy` by \
13538             construction — must byte-equal `.iter().map(|p| \
13539             p.as_str().to_owned())` on every arm — the borrowed-input \
13540             owned-`String` `From<&RestartPolicy> for String` axis is \
13541             what makes the `String::from` composition route through \
13542             the substrate-primitive `RestartPolicy::as_str` accessor \
13543             without a spurious `Copy` deref (which would only be \
13544             reachable through the owned-input `From<RestartPolicy> \
13545             for String` axis by first calling `.copied()` on the \
13546             iterator)"
13547        );
13548        for &variant in RestartPolicy::ALL {
13549            let emitted: String = (&variant).into();
13550            let re_parsed: Result<RestartPolicy, ()> =
13551                <RestartPolicy as TryFrom<&str>>::try_from(emitted.as_str());
13552            assert_eq!(
13553                re_parsed,
13554                Ok(variant),
13555                "trait-idiomatic borrowed-input owned-`String` \
13556                 forward-projection + reverse-projection axis pair must \
13557                 round-trip &RestartPolicy::{variant:?} through \
13558                 `.into::<String>()` on the borrowed-input surface and \
13559                 back through `TryFrom<&str>` on the owned-`String`'s \
13560                 String::as_str borrow — a break signals the \
13561                 borrowed-input owned-`String` forward-emit and \
13562                 reverse-parse axes have drifted onto different \
13563                 vocabularies"
13564            );
13565        }
13566    }
13567
13568    #[test]
13569    fn restart_policy_from_into_static_cow_str_routes_through_as_str_accessor() {
13570        // Fail-before-pass-after byte-parity pin on the newly lifted
13571        // `impl From<RestartPolicy> for std::borrow::Cow<'static, str>` —
13572        // asserts the standard-library trait impl and the substrate-
13573        // primitive [`super::RestartPolicy::as_str`] `pub const fn`
13574        // accessor resolve to the same three-arm emit-set across every
13575        // arm the exhaustive [`super::RestartPolicy::ALL`] slice
13576        // enumerates. Rust's standard library does not carry a blanket
13577        // `impl<T: AsRef<str>> From<T> for Cow<'static, str>` (nor an
13578        // `impl<T: fmt::Display> From<T> for Cow<'static, str>`), so
13579        // the `Cow<'static, str>` forward-projection axis is a
13580        // distinct trait-idiomatic surface that a
13581        // `let key: Cow<'static, str> = policy.into();`-shaped call
13582        // site reaches through this impl and no other — the paired
13583        // sibling `From<RestartPolicy> for &'static str` and
13584        // `From<RestartPolicy> for String` impls force every
13585        // `Cow<'static, str>`-parameterized call site through a
13586        // `Cow::Borrowed(policy.as_str())` /
13587        // `Cow::Owned(policy.to_string())` composition whose type
13588        // bounds have no compile-time link back to the substrate
13589        // primitive.
13590        //
13591        // Also asserts the projection lands on the zero-alloc
13592        // [`std::borrow::Cow::Borrowed`] arm (not the
13593        // [`std::borrow::Cow::Owned`] arm) — the substrate-primitive
13594        // [`super::RestartPolicy::as_str`] accessor's `&'static str`
13595        // return lifetime by construction makes the borrowed arm the
13596        // type-correct projection with no runtime allocation. Any
13597        // future silent detour that routes the impl through the owned
13598        // arm (an accidental `Cow::Owned(policy.to_string())` rewrite
13599        // that would allocate on every call site where the
13600        // `&'static str` return of [`super::RestartPolicy::as_str`]
13601        // makes the zero-alloc borrowed projection type-correct) trips
13602        // at caixa-core test time under the
13603        // [`std::borrow::Cow::Borrowed`] discriminator witness rather
13604        // than at a downstream `Cow<'static, str>`-bound consumer's
13605        // silent allocation.
13606        //
13607        // Second peer on the substrate-wide trait-idiomatic
13608        // [`std::borrow::Cow<'static, str>`] forward-projection family
13609        // to extend the axis off the top-level [`super::CaixaKind`]
13610        // enum (99c1735 owned-input, d45c409 borrowed-input) onto the
13611        // second (and second-of-two-in-M2) M2 OTP-shape closed-set
13612        // fieldless typed enum peer on the caixa surface — closes the
13613        // M2 OTP-shape tier of the campaign on the owned-input axis
13614        // (both sibling peers, `RestartStrategy` and `RestartPolicy`,
13615        // now carry the owned-input Cow<'static, str> forward
13616        // projection).
13617        for &variant in RestartPolicy::ALL {
13618            let via_trait: std::borrow::Cow<'static, str> =
13619                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
13620            let via_method: &'static str = variant.as_str();
13621            assert_eq!(
13622                via_trait.as_ref(),
13623                via_method,
13624                "From<RestartPolicy> for Cow<'static, str> impl must \
13625                 round-trip RestartPolicy::{variant:?} to the same \
13626                 lifted SUPERVISOR_CHILD_RESTART_* const \
13627                 RestartPolicy::as_str returns — divergence signals a \
13628                 silent detour off the substrate-primitive accessor"
13629            );
13630            assert!(
13631                matches!(via_trait, std::borrow::Cow::Borrowed(_)),
13632                "From<RestartPolicy> for Cow<'static, str> impl must \
13633                 land on the zero-alloc Cow::Borrowed arm on \
13634                 RestartPolicy::{variant:?} — a Cow::Owned outcome \
13635                 signals the projection has silently allocated where \
13636                 the substrate-primitive RestartPolicy::as_str \
13637                 `&'static str` return makes the borrowed arm the \
13638                 type-correct projection"
13639            );
13640            let via_into: std::borrow::Cow<'static, str> = variant.into();
13641            assert_eq!(
13642                via_into.as_ref(),
13643                via_method,
13644                "Into<Cow<'static, str>>::into on \
13645                 RestartPolicy::{variant:?} must byte-equal \
13646                 RestartPolicy::as_str on the same input — the \
13647                 blanket-derived Into shape must resolve to the same \
13648                 as_str dispatch as the explicit From impl"
13649            );
13650            assert!(
13651                matches!(via_into, std::borrow::Cow::Borrowed(_)),
13652                "Into<Cow<'static, str>>::into on \
13653                 RestartPolicy::{variant:?} must land on the \
13654                 zero-alloc Cow::Borrowed arm — the blanket-derived \
13655                 Into shape must resolve to the same Cow::Borrowed \
13656                 dispatch as the explicit From impl"
13657            );
13658        }
13659    }
13660
13661    #[test]
13662    fn restart_policy_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm() {
13663        // Cross-axis partition pin: the newly lifted trait-idiomatic
13664        // `From<RestartPolicy> for std::borrow::Cow<'static, str>`
13665        // (this lift), the paired owned-input `From<RestartPolicy>
13666        // for &'static str` (9fb37d0), and the paired owned-input
13667        // `From<RestartPolicy> for String` (7851725) forward
13668        // projections must resolve identically on every arm, locking
13669        // the three return-shape paths together by construction so any
13670        // future detour trips at caixa-core test time. Also byte-parity
13671        // witness against the sibling [`ToString::to_string`] surface
13672        // routed through [`std::fmt::Display`] — every owned-heap-
13673        // string path (the `Cow::Owned` promotion of this axis's
13674        // `.into_owned()`, `From<RestartPolicy> for String`, and
13675        // `.to_string()`) resolves to the same lifted
13676        // [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const per arm.
13677        //
13678        // Then a `.iter().copied().map(std::borrow::Cow::from)` pipe
13679        // witness over [`super::RestartPolicy::ALL`] that
13680        // materializes the three-arm accept-set through the
13681        // [`std::borrow::Cow<'static, str>`] axis alone — the exact
13682        // shape a future `axum::response::IntoResponse` per-policy
13683        // rejection-body composer, a future M4 admission-webhook
13684        // per-policy rejection-reason emitter whose typing rules out
13685        // the sibling [`AsRef<str>`] borrowed return, or a future
13686        // substrate-wide per-policy diagnostic surface that binds
13687        // through a [`Cow<'static, str>`] boundary reaches through.
13688        // The pipe witness also pins the zero-alloc discipline: every
13689        // element in the collected vector satisfies the
13690        // [`std::borrow::Cow::Borrowed`] arm predicate, so a future
13691        // accidental silent-allocation regression on the pipe's
13692        // iteration axis is a caixa-core-test-time failure. Peer of
13693        // the first-mover
13694        // [`restart_strategy_from_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
13695        // (7dd28b3) on the sibling M2 OTP-shape sibling-restart axis
13696        // — closes the whole owned-input `Cow<'static, str>` +
13697        // paired `{&'static str, String}` cross-axis-parity corner on
13698        // both M2 OTP-shape sibling peers.
13699        for &variant in RestartPolicy::ALL {
13700            let via_cow: std::borrow::Cow<'static, str> =
13701                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
13702            let via_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
13703            let via_string: String = <String as From<RestartPolicy>>::from(variant);
13704            assert_eq!(
13705                via_cow.as_ref(),
13706                via_static,
13707                "From<RestartPolicy> for Cow<'static, str> and \
13708                 From<RestartPolicy> for &'static str must resolve \
13709                 identically on RestartPolicy::{variant:?} — \
13710                 divergence signals the Cow<'static, str> and \
13711                 &'static str return-shape paths have drifted onto \
13712                 different emit-sets"
13713            );
13714            assert_eq!(
13715                via_cow.as_ref(),
13716                via_string.as_str(),
13717                "From<RestartPolicy> for Cow<'static, str> and \
13718                 From<RestartPolicy> for String must resolve \
13719                 identically on RestartPolicy::{variant:?} — \
13720                 divergence signals the Cow<'static, str> and String \
13721                 return-shape paths have drifted onto different \
13722                 emit-sets"
13723            );
13724            let via_to_string: String = variant.to_string();
13725            assert_eq!(
13726                via_cow.as_ref(),
13727                via_to_string.as_str(),
13728                "From<RestartPolicy> for Cow<'static, str> must \
13729                 byte-equal RestartPolicy::to_string on \
13730                 RestartPolicy::{variant:?} — divergence signals the \
13731                 trait-idiomatic Cow<'static, str> forward-projection \
13732                 axis and the ToString-through-Display axis have \
13733                 drifted onto different emit-sets"
13734            );
13735        }
13736        let via_iter: Vec<std::borrow::Cow<'static, str>> = RestartPolicy::ALL
13737            .iter()
13738            .copied()
13739            .map(std::borrow::Cow::from)
13740            .collect();
13741        let via_method: Vec<std::borrow::Cow<'static, str>> = RestartPolicy::ALL
13742            .iter()
13743            .map(|p| std::borrow::Cow::Borrowed(p.as_str()))
13744            .collect();
13745        assert_eq!(
13746            via_iter, via_method,
13747            "`.iter().copied().map(Cow::from)` over \
13748             RestartPolicy::ALL must byte-equal `.iter().map(|p| \
13749             Cow::Borrowed(p.as_str()))` on every arm — the \
13750             trait-idiomatic `From<RestartPolicy> for Cow<'static, \
13751             str>` axis is what makes the `Cow::from` composition \
13752             route through the substrate-primitive \
13753             `RestartPolicy::as_str` accessor with the zero-alloc \
13754             Cow::Borrowed arm by construction, rather than a \
13755             per-call-site `Cow::Owned(policy.to_string())` \
13756             allocation"
13757        );
13758        for cow in &via_iter {
13759            assert!(
13760                matches!(cow, std::borrow::Cow::Borrowed(_)),
13761                "every element of the \
13762                 .iter().copied().map(Cow::from) pipe over \
13763                 RestartPolicy::ALL must land on the zero-alloc \
13764                 Cow::Borrowed arm — a Cow::Owned outcome on any arm \
13765                 signals the pipe's iteration axis has silently \
13766                 allocated where the substrate-primitive \
13767                 RestartPolicy::as_str `&'static str` return makes \
13768                 the borrowed arm the type-correct projection"
13769            );
13770        }
13771    }
13772
13773    #[test]
13774    fn restart_policy_from_borrowed_into_static_cow_str_routes_through_as_str_accessor() {
13775        // Fail-before-pass-after byte-parity pin on the newly lifted
13776        // `impl From<&RestartPolicy> for std::borrow::Cow<'static, str>` —
13777        // asserts the borrowed-input standard-library trait impl and
13778        // the substrate-primitive [`super::RestartPolicy::as_str`]
13779        // `pub const fn` accessor resolve to the same three-arm emit-
13780        // set across every arm the exhaustive
13781        // [`super::RestartPolicy::ALL`] slice enumerates. Rust's
13782        // standard library does not carry a blanket
13783        // `impl<T: AsRef<str>> From<&T> for Cow<'static, str>` (nor a
13784        // `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`), so
13785        // the borrowed-input `Cow<'static, str>` forward-projection
13786        // axis is a distinct trait-idiomatic surface that a
13787        // `let key: Cow<'static, str> = (&policy).into();`-shaped
13788        // call site or a
13789        // `RestartPolicy::ALL.iter().map(Cow::from)`-shaped pipe
13790        // reaches through this impl and no other — the paired owned-
13791        // input `From<RestartPolicy> for Cow<'static, str>` impl
13792        // (0612398) forces every borrowed-input call site through an
13793        // explicit `Copy` deref (`Cow::from(*policy)`) or a
13794        // `Cow::Borrowed(policy.as_str())` open-code whose type
13795        // bounds have no compile-time link back to the substrate
13796        // primitive.
13797        //
13798        // Also asserts the projection lands on the zero-alloc
13799        // [`std::borrow::Cow::Borrowed`] arm (not the
13800        // [`std::borrow::Cow::Owned`] arm) — the substrate-primitive
13801        // [`super::RestartPolicy::as_str`] accessor's `&'static str`
13802        // return lifetime by construction makes the borrowed arm the
13803        // type-correct projection with no runtime allocation on the
13804        // borrowed-input surface just as on the paired owned-input
13805        // surface.
13806        //
13807        // Closes the `{Self, &Self}` input-shape corner on the M2
13808        // OTP-shape per-child-restart [`Cow<'static, str>`] axis on
13809        // the second-of-two-in-M2 closed-set fieldless typed enum peer
13810        // on the caixa surface (`:supervisor :children :restart`),
13811        // exactly as d45c409 closed it on the top-level
13812        // [`super::CaixaKind`] one commit after the owning half
13813        // (99c1735) landed and as 9b3e4b3 closed it on the sibling
13814        // M2 OTP-shape [`super::RestartStrategy`] one commit after
13815        // (7dd28b3) landed. This lift closes the whole M2 OTP-shape
13816        // tier of the substrate-wide Cow<'static, str> forward-
13817        // projection campaign on both input-shape corners
13818        // ({Self, &Self}) of both M2 OTP-shape sibling peers.
13819        for &variant in RestartPolicy::ALL {
13820            let via_trait: std::borrow::Cow<'static, str> =
13821                <std::borrow::Cow<'static, str> as From<&RestartPolicy>>::from(&variant);
13822            let via_method: &'static str = variant.as_str();
13823            assert_eq!(
13824                via_trait.as_ref(),
13825                via_method,
13826                "From<&RestartPolicy> for Cow<'static, str> impl must \
13827                 round-trip &RestartPolicy::{variant:?} to the same \
13828                 lifted SUPERVISOR_CHILD_RESTART_* const \
13829                 RestartPolicy::as_str returns — divergence signals a \
13830                 silent detour off the substrate-primitive accessor"
13831            );
13832            assert!(
13833                matches!(via_trait, std::borrow::Cow::Borrowed(_)),
13834                "From<&RestartPolicy> for Cow<'static, str> impl must \
13835                 land on the zero-alloc Cow::Borrowed arm on \
13836                 &RestartPolicy::{variant:?} — a Cow::Owned outcome \
13837                 signals the projection has silently allocated where \
13838                 the substrate-primitive RestartPolicy::as_str \
13839                 `&'static str` return makes the borrowed arm the \
13840                 type-correct projection"
13841            );
13842            let via_into: std::borrow::Cow<'static, str> = (&variant).into();
13843            assert_eq!(
13844                via_into.as_ref(),
13845                via_method,
13846                "Into<Cow<'static, str>>::into on \
13847                 &RestartPolicy::{variant:?} must byte-equal \
13848                 RestartPolicy::as_str on the same input — the \
13849                 blanket-derived Into shape must resolve to the same \
13850                 as_str dispatch as the explicit From impl"
13851            );
13852            assert!(
13853                matches!(via_into, std::borrow::Cow::Borrowed(_)),
13854                "Into<Cow<'static, str>>::into on \
13855                 &RestartPolicy::{variant:?} must land on the \
13856                 zero-alloc Cow::Borrowed arm — the blanket-derived \
13857                 Into shape must resolve to the same Cow::Borrowed \
13858                 dispatch as the explicit From impl"
13859            );
13860        }
13861    }
13862
13863    #[test]
13864    fn restart_policy_from_borrowed_into_static_cow_str_agrees_with_paired_axes_on_every_arm() {
13865        // Cross-axis partition pin: the newly lifted trait-idiomatic
13866        // borrowed-input `From<&RestartPolicy> for
13867        // std::borrow::Cow<'static, str>` (this lift), the paired
13868        // owned-input `From<RestartPolicy> for
13869        // std::borrow::Cow<'static, str>` (0612398), the paired
13870        // borrowed-input owned-`&'static str` `From<&RestartPolicy>
13871        // for &'static str`, and the paired borrowed-input owned-
13872        // `String` `From<&RestartPolicy> for String` must resolve
13873        // identically on every arm, locking the four
13874        // return-shape × input-shape paths together by construction so
13875        // any future detour trips at caixa-core test time. Also byte-
13876        // parity witness against the sibling [`ToString::to_string`]
13877        // surface routed through [`std::fmt::Display`] — every owned-
13878        // heap-string path (this axis's `.into_owned()` promotion, the
13879        // paired [`From<&RestartPolicy> for String`], and
13880        // `.to_string()`) resolves to the same lifted
13881        // [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const per arm.
13882        //
13883        // Then a `.iter().map(std::borrow::Cow::from)` pipe witness
13884        // over [`super::RestartPolicy::ALL`] — whose iterator yields
13885        // `&RestartPolicy` by construction, so the borrowed-input
13886        // [`Cow<'static, str>`] axis is what routes the pipe through
13887        // the substrate-primitive [`super::RestartPolicy::as_str`]
13888        // accessor without a spurious [`Copy`] deref (which would only
13889        // be reachable through the owned-input
13890        // [`From<RestartPolicy> for Cow<'static, str>`] axis by first
13891        // calling `.copied()` on the iterator). The pipe witness also
13892        // pins the zero-alloc discipline: every element in the
13893        // collected vector satisfies the [`std::borrow::Cow::Borrowed`]
13894        // arm predicate, so a future accidental silent-allocation
13895        // regression on the pipe's iteration axis is a caixa-core-
13896        // test-time failure. Peer of the sibling
13897        // [`restart_strategy_from_borrowed_into_static_cow_str_agrees_with_paired_axes_on_every_arm`]
13898        // (9b3e4b3) on the M2 OTP-shape sibling-restart axis — closes
13899        // the whole borrowed-input `Cow<'static, str>` +
13900        // paired `{&'static str, String}` cross-axis-parity corner on
13901        // both M2 OTP-shape sibling peers.
13902        for &policy in RestartPolicy::ALL {
13903            let borrowed_cow: std::borrow::Cow<'static, str> =
13904                <std::borrow::Cow<'static, str> as From<&RestartPolicy>>::from(&policy);
13905            let owned_cow: std::borrow::Cow<'static, str> =
13906                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(policy);
13907            let borrowed_static: &'static str =
13908                <&'static str as From<&RestartPolicy>>::from(&policy);
13909            let borrowed_string: String = <String as From<&RestartPolicy>>::from(&policy);
13910            assert_eq!(
13911                borrowed_cow, owned_cow,
13912                "From<&RestartPolicy> for Cow<'static, str> and \
13913                 From<RestartPolicy> for Cow<'static, str> must \
13914                 resolve identically on RestartPolicy::{policy:?} — \
13915                 divergence signals the borrowed-input and owned-input \
13916                 Cow<'static, str> forward-projection input-shape \
13917                 paths have drifted onto different emit-sets"
13918            );
13919            assert_eq!(
13920                borrowed_cow.as_ref(),
13921                borrowed_static,
13922                "From<&RestartPolicy> for Cow<'static, str> and \
13923                 From<&RestartPolicy> for &'static str must resolve \
13924                 identically on RestartPolicy::{policy:?} — \
13925                 divergence signals the borrowed-input Cow<'static, \
13926                 str> and &'static str return-shape paths have drifted \
13927                 onto different emit-sets"
13928            );
13929            assert_eq!(
13930                borrowed_cow.as_ref(),
13931                borrowed_string.as_str(),
13932                "From<&RestartPolicy> for Cow<'static, str> and \
13933                 From<&RestartPolicy> for String must resolve \
13934                 identically on RestartPolicy::{policy:?} — \
13935                 divergence signals the borrowed-input Cow<'static, \
13936                 str> and owned-`String` return-shape paths have \
13937                 drifted onto different emit-sets"
13938            );
13939            let via_to_string: String = policy.to_string();
13940            assert_eq!(
13941                borrowed_cow.as_ref(),
13942                via_to_string.as_str(),
13943                "From<&RestartPolicy> for Cow<'static, str> must \
13944                 byte-equal RestartPolicy::to_string on \
13945                 RestartPolicy::{policy:?} — divergence signals \
13946                 the trait-idiomatic borrowed-input Cow<'static, str> \
13947                 forward-projection axis and the ToString-through-\
13948                 Display axis have drifted onto different emit-sets"
13949            );
13950        }
13951        let via_iter: Vec<std::borrow::Cow<'static, str>> = RestartPolicy::ALL
13952            .iter()
13953            .map(std::borrow::Cow::from)
13954            .collect();
13955        let via_method: Vec<std::borrow::Cow<'static, str>> = RestartPolicy::ALL
13956            .iter()
13957            .map(|p| std::borrow::Cow::Borrowed(p.as_str()))
13958            .collect();
13959        assert_eq!(
13960            via_iter, via_method,
13961            "`.iter().map(Cow::from)` over RestartPolicy::ALL — a \
13962             call site whose iteration axis holds `&RestartPolicy` \
13963             by construction — must byte-equal `.iter().map(|p| \
13964             Cow::Borrowed(p.as_str()))` on every arm — the borrowed-\
13965             input Cow<'static, str> `From<&RestartPolicy> for \
13966             Cow<'static, str>` axis is what makes the `Cow::from` \
13967             composition route through the substrate-primitive \
13968             `RestartPolicy::as_str` accessor with the zero-alloc \
13969             Cow::Borrowed arm by construction and without a spurious \
13970             `Copy` deref (which would only be reachable through the \
13971             owned-input `From<RestartPolicy> for Cow<'static, str>` \
13972             axis by first calling `.copied()` on the iterator)"
13973        );
13974        for cow in &via_iter {
13975            assert!(
13976                matches!(cow, std::borrow::Cow::Borrowed(_)),
13977                "every element of the .iter().map(Cow::from) pipe \
13978                 over RestartPolicy::ALL must land on the zero-\
13979                 alloc Cow::Borrowed arm — a Cow::Owned outcome on \
13980                 any arm signals the pipe's iteration axis has \
13981                 silently allocated where the substrate-primitive \
13982                 RestartPolicy::as_str `&'static str` return makes \
13983                 the borrowed arm the type-correct projection"
13984            );
13985        }
13986    }
13987
13988    #[test]
13989    fn restart_policy_from_into_box_str_routes_through_as_str_accessor() {
13990        // Fail-before-pass-after byte-parity pin on the newly lifted
13991        // `impl From<RestartPolicy> for Box<str>` — asserts the
13992        // owned-input standard-library trait impl and the
13993        // substrate-primitive [`super::RestartPolicy::as_str`]
13994        // `pub const fn` accessor resolve to the same three-arm emit-
13995        // set across every arm the exhaustive
13996        // [`super::RestartPolicy::ALL`] slice enumerates. Extends the
13997        // substrate-wide `Box<str>` forward-projection campaign tier
13998        // opened one commit prior (69ef45c) on the paired sibling-
13999        // restart [`RestartStrategy`] onto the second (and third-and-
14000        // final) M2 OTP-shape closed-set fieldless typed enum peer on
14001        // the caixa surface (`:children :restart`), immediately after
14002        // the paired `Cow<'static, str>` axis (0612398 / b4dc55c)
14003        // closed the
14004        // `{Self, &Self} × {&'static str, String, Cow<'static, str>}`
14005        // 2×3 corner on this enum. Rust's standard library carries
14006        // `impl From<&str> for Box<str>` and
14007        // `impl From<String> for Box<str>` but no blanket
14008        // `impl<T: AsRef<str>> From<T> for Box<str>`, so this axis is
14009        // a distinct trait-idiomatic surface that a
14010        // `let key: Box<str> = policy.into();`-shaped call site
14011        // reaches through this impl and no other — a paired
14012        // `Box::from(policy.as_str())` open-code has no compile-time
14013        // link back to the substrate primitive. Peer of the sibling
14014        // [`restart_strategy_from_into_box_str_routes_through_as_str_accessor`]
14015        // (69ef45c) — extends the trait-idiomatic owned-input
14016        // [`Box<str>`] forward-projection axis onto the third and
14017        // final M2-OTP-shape closed-set typed enum on the caixa
14018        // surface.
14019        for &variant in RestartPolicy::ALL {
14020            let via_trait: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
14021            let via_method: &'static str = variant.as_str();
14022            assert_eq!(
14023                via_trait.as_ref(),
14024                via_method,
14025                "From<RestartPolicy> for Box<str> impl must round-\
14026                 trip RestartPolicy::{variant:?} to the same lifted \
14027                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str \
14028                 returns — divergence signals a silent detour off the \
14029                 substrate-primitive accessor"
14030            );
14031            let via_into: Box<str> = variant.into();
14032            assert_eq!(
14033                via_into.as_ref(),
14034                via_method,
14035                "Into<Box<str>>::into on RestartPolicy::{variant:?} \
14036                 must byte-equal RestartPolicy::as_str on the same \
14037                 input — the blanket-derived Into shape must resolve \
14038                 to the same as_str dispatch as the explicit From impl"
14039            );
14040        }
14041    }
14042
14043    #[test]
14044    fn restart_policy_from_borrowed_into_box_str_routes_through_as_str_accessor() {
14045        // Fail-before-pass-after byte-parity pin on the newly lifted
14046        // `impl From<&RestartPolicy> for Box<str>` — asserts the
14047        // borrowed-input standard-library trait impl and the
14048        // substrate-primitive [`super::RestartPolicy::as_str`]
14049        // `pub const fn` accessor resolve to the same three-arm emit-
14050        // set across every arm the exhaustive
14051        // [`super::RestartPolicy::ALL`] slice enumerates. Rust's
14052        // standard library does not carry a blanket
14053        // `impl<T: AsRef<str>> From<&T> for Box<str>` (nor a
14054        // `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`),
14055        // so the borrowed-input `Box<str>` forward-projection axis
14056        // is a distinct trait-idiomatic surface that a
14057        // `let key: Box<str> = (&policy).into();`-shaped call site
14058        // or a `RestartPolicy::ALL.iter().map(Box::<str>::from)`-
14059        // shaped pipe reaches through this impl and no other — the
14060        // paired owned-input `From<RestartPolicy> for Box<str>`
14061        // impl (0a1b313) forces every borrowed-input call site
14062        // through an explicit `Copy` deref
14063        // (`Box::<str>::from((*policy).as_str())`) or a
14064        // `Box::<str>::from(policy.as_str())` open-code whose
14065        // type bounds have no compile-time link back to the
14066        // substrate primitive.
14067        //
14068        // Fourth (and closing) peer on the substrate-wide trait-
14069        // idiomatic [`Box<str>`] forward-projection family on the
14070        // M2 OTP-shape tier — closes the `{Self, &Self}` input-
14071        // shape corner of the [`Box<str>`] axis on the second (and
14072        // third-and-final) M2 OTP-shape closed-set fieldless typed
14073        // enum peer on the caixa surface (`:children :restart`),
14074        // exactly as b4dc55c closed the paired [`Cow<'static, str>`]
14075        // axis one commit after its owning half (0612398) landed
14076        // on this enum. Every remaining closed-set fieldless typed
14077        // enum peer on the M3 mesh-shape / outside-M3 caixa-core /
14078        // render-side / outside-caixa-core tiers is a future
14079        // target of the campaign.
14080        //
14081        // Also byte-parity witness against the paired owned-input
14082        // [`From<RestartPolicy> for Box<str>`] and the sibling
14083        // borrowed-input [`From<&RestartPolicy> for &'static str`],
14084        // [`From<&RestartPolicy> for String`], and
14085        // [`From<&RestartPolicy> for Cow<'static, str>`]
14086        // return-shape axes — locking the four
14087        // return-shape × input-shape paths together by construction
14088        // so any future detour trips at caixa-core test time. Then a
14089        // `.iter().map(Box::<str>::from)` pipe witness over
14090        // [`super::RestartPolicy::ALL`] — whose iterator yields
14091        // `&RestartPolicy` by construction, so the borrowed-input
14092        // [`Box<str>`] axis is what routes the pipe through the
14093        // substrate-primitive [`super::RestartPolicy::as_str`]
14094        // accessor without a spurious [`Copy`] deref (which would
14095        // only be reachable through the owned-input
14096        // [`From<RestartPolicy> for Box<str>`] axis by first
14097        // calling `.copied()` on the iterator).
14098        for &variant in RestartPolicy::ALL {
14099            let via_trait: Box<str> = <Box<str> as From<&RestartPolicy>>::from(&variant);
14100            let via_method: &'static str = variant.as_str();
14101            assert_eq!(
14102                via_trait.as_ref(),
14103                via_method,
14104                "From<&RestartPolicy> for Box<str> impl must round-\
14105                 trip &RestartPolicy::{variant:?} to the same lifted \
14106                 SUPERVISOR_CHILD_RESTART_* const RestartPolicy::as_str \
14107                 returns — divergence signals a silent detour off the \
14108                 substrate-primitive accessor"
14109            );
14110            let via_into: Box<str> = (&variant).into();
14111            assert_eq!(
14112                via_into.as_ref(),
14113                via_method,
14114                "Into<Box<str>>::into on &RestartPolicy::{variant:?} \
14115                 must byte-equal RestartPolicy::as_str on the same \
14116                 input — the blanket-derived Into shape must resolve \
14117                 to the same as_str dispatch as the explicit From impl"
14118            );
14119            let owned_box: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
14120            assert_eq!(
14121                via_trait, owned_box,
14122                "From<&RestartPolicy> for Box<str> and \
14123                 From<RestartPolicy> for Box<str> must resolve \
14124                 identically on RestartPolicy::{variant:?} — \
14125                 divergence signals the borrowed-input and owned-input \
14126                 Box<str> forward-projection input-shape paths have \
14127                 drifted onto different emit-sets"
14128            );
14129            let borrowed_static: &'static str =
14130                <&'static str as From<&RestartPolicy>>::from(&variant);
14131            assert_eq!(
14132                via_trait.as_ref(),
14133                borrowed_static,
14134                "From<&RestartPolicy> for Box<str> and \
14135                 From<&RestartPolicy> for &'static str must resolve \
14136                 identically on RestartPolicy::{variant:?} — \
14137                 divergence signals the borrowed-input Box<str> and \
14138                 &'static str return-shape paths have drifted onto \
14139                 different emit-sets"
14140            );
14141            let borrowed_string: String = <String as From<&RestartPolicy>>::from(&variant);
14142            assert_eq!(
14143                via_trait.as_ref(),
14144                borrowed_string.as_str(),
14145                "From<&RestartPolicy> for Box<str> and \
14146                 From<&RestartPolicy> for String must resolve \
14147                 identically on RestartPolicy::{variant:?} — \
14148                 divergence signals the borrowed-input Box<str> and \
14149                 owned-`String` return-shape paths have drifted onto \
14150                 different emit-sets"
14151            );
14152            let borrowed_cow: std::borrow::Cow<'static, str> =
14153                <std::borrow::Cow<'static, str> as From<&RestartPolicy>>::from(&variant);
14154            assert_eq!(
14155                via_trait.as_ref(),
14156                borrowed_cow.as_ref(),
14157                "From<&RestartPolicy> for Box<str> and \
14158                 From<&RestartPolicy> for Cow<'static, str> must \
14159                 resolve identically on RestartPolicy::{variant:?} — \
14160                 divergence signals the borrowed-input Box<str> and \
14161                 Cow<'static, str> return-shape paths have drifted \
14162                 onto different emit-sets"
14163            );
14164        }
14165        let via_iter: Vec<Box<str>> = RestartPolicy::ALL.iter().map(Box::<str>::from).collect();
14166        let via_method: Vec<Box<str>> = RestartPolicy::ALL
14167            .iter()
14168            .map(|p| Box::<str>::from(p.as_str()))
14169            .collect();
14170        assert_eq!(
14171            via_iter, via_method,
14172            "`.iter().map(Box::<str>::from)` over \
14173             RestartPolicy::ALL — a call site whose iteration axis \
14174             holds `&RestartPolicy` by construction — must byte-\
14175             equal `.iter().map(|p| Box::<str>::from(p.as_str()))` \
14176             on every arm — the borrowed-input Box<str> \
14177             `From<&RestartPolicy> for Box<str>` axis is what \
14178             makes the `Box::<str>::from` composition route through \
14179             the substrate-primitive `RestartPolicy::as_str` \
14180             accessor without a spurious `Copy` deref (which would \
14181             only be reachable through the owned-input \
14182             `From<RestartPolicy> for Box<str>` axis by first \
14183             calling `.copied()` on the iterator)"
14184        );
14185    }
14186
14187    #[test]
14188    fn restart_policy_from_into_arc_str_routes_through_as_str_accessor() {
14189        // Fail-before-pass-after byte-parity pin on the newly lifted
14190        // `impl From<RestartPolicy> for std::sync::Arc<str>` — asserts
14191        // the owned-input standard-library trait impl and the
14192        // substrate-primitive [`super::RestartPolicy::as_str`]
14193        // `pub const fn` accessor resolve to the same three-arm emit-
14194        // set across every arm the exhaustive
14195        // [`super::RestartPolicy::ALL`] slice enumerates. Extends the
14196        // substrate-wide [`std::sync::Arc<str>`] forward-projection
14197        // campaign tier opened one projection tier prior (bca2ec8) on
14198        // the paired sibling-restart [`RestartStrategy`] owned-input
14199        // first-mover onto the second (and third-and-final) M2 OTP-
14200        // shape closed-set fieldless typed enum peer on the caixa
14201        // surface (`:children :restart`), immediately after the paired
14202        // [`Box<str>`] axis (0a1b313 / cb1d068) closed the
14203        // `{Self, &Self} × {&'static str, String, Cow<'static, str>,
14204        // Box<str>}` 2×4 corner on this enum. Rust's standard library
14205        // carries `impl From<&str> for std::sync::Arc<str>` and
14206        // `impl From<String> for std::sync::Arc<str>` but no blanket
14207        // `impl<T: AsRef<str>> From<T> for std::sync::Arc<str>` (nor
14208        // an `impl<T: fmt::Display> From<T> for std::sync::Arc<str>`),
14209        // so this axis is a distinct trait-idiomatic surface that a
14210        // `let key: std::sync::Arc<str> = policy.into();`-shaped call
14211        // site reaches through this impl and no other — a paired
14212        // `std::sync::Arc::<str>::from(policy.as_str())` open-code
14213        // has no compile-time link back to the substrate primitive,
14214        // and a two-step `std::sync::Arc::<str>::from(String::from(
14215        // policy))` composition through the owned-`String` axis
14216        // allocates twice (once into the intermediate `String`, once
14217        // into the [`Arc<str>`] on the `From<String>` conversion)
14218        // where the single-step trait impl allocates once.
14219        //
14220        // Cross-axis byte-parity witness against the sibling owned-
14221        // input `{&'static str, String, Cow<'static, str>, Box<str>}`
14222        // return-shape axes — locking the five return-shape paths on
14223        // the owned-input surface together by construction so any
14224        // future detour off the substrate-primitive
14225        // [`super::RestartPolicy::as_str`] accessor trips at caixa-
14226        // core test time.
14227        for &variant in RestartPolicy::ALL {
14228            let via_trait: std::sync::Arc<str> =
14229                <std::sync::Arc<str> as From<RestartPolicy>>::from(variant);
14230            let via_method: &'static str = variant.as_str();
14231            assert_eq!(
14232                via_trait.as_ref(),
14233                via_method,
14234                "From<RestartPolicy> for std::sync::Arc<str> impl \
14235                 must round-trip RestartPolicy::{variant:?} to the \
14236                 same lifted SUPERVISOR_CHILD_RESTART_* const \
14237                 RestartPolicy::as_str returns — divergence signals \
14238                 a silent detour off the substrate-primitive accessor"
14239            );
14240            let via_into: std::sync::Arc<str> = variant.into();
14241            assert_eq!(
14242                via_into.as_ref(),
14243                via_method,
14244                "Into<std::sync::Arc<str>>::into on \
14245                 RestartPolicy::{variant:?} must byte-equal \
14246                 RestartPolicy::as_str on the same input — the \
14247                 blanket-derived Into shape must resolve to the same \
14248                 as_str dispatch as the explicit From impl"
14249            );
14250            let owned_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
14251            assert_eq!(
14252                via_trait.as_ref(),
14253                owned_static,
14254                "From<RestartPolicy> for std::sync::Arc<str> and \
14255                 From<RestartPolicy> for &'static str must resolve \
14256                 identically on RestartPolicy::{variant:?} — \
14257                 divergence signals the owned-input std::sync::Arc<str> \
14258                 and &'static str return-shape paths have drifted onto \
14259                 different emit-sets"
14260            );
14261            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
14262            assert_eq!(
14263                via_trait.as_ref(),
14264                owned_string.as_str(),
14265                "From<RestartPolicy> for std::sync::Arc<str> and \
14266                 From<RestartPolicy> for String must resolve \
14267                 identically on RestartPolicy::{variant:?} — \
14268                 divergence signals the owned-input std::sync::Arc<str> \
14269                 and owned-`String` return-shape paths have drifted \
14270                 onto different emit-sets"
14271            );
14272            let owned_cow: std::borrow::Cow<'static, str> =
14273                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
14274            assert_eq!(
14275                via_trait.as_ref(),
14276                owned_cow.as_ref(),
14277                "From<RestartPolicy> for std::sync::Arc<str> and \
14278                 From<RestartPolicy> for Cow<'static, str> must \
14279                 resolve identically on RestartPolicy::{variant:?} — \
14280                 divergence signals the owned-input std::sync::Arc<str> \
14281                 and Cow<'static, str> return-shape paths have drifted \
14282                 onto different emit-sets"
14283            );
14284            let owned_box: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
14285            assert_eq!(
14286                via_trait.as_ref(),
14287                owned_box.as_ref(),
14288                "From<RestartPolicy> for std::sync::Arc<str> and \
14289                 From<RestartPolicy> for Box<str> must resolve \
14290                 identically on RestartPolicy::{variant:?} — \
14291                 divergence signals the owned-input std::sync::Arc<str> \
14292                 and Box<str> return-shape paths have drifted onto \
14293                 different emit-sets"
14294            );
14295        }
14296    }
14297
14298    #[test]
14299    fn restart_policy_from_borrowed_into_arc_str_routes_through_as_str_accessor() {
14300        // Fail-before-pass-after byte-parity pin on the newly lifted
14301        // `impl From<&RestartPolicy> for std::sync::Arc<str>` —
14302        // asserts the borrowed-input standard-library trait impl and
14303        // the substrate-primitive [`super::RestartPolicy::as_str`]
14304        // `pub const fn` accessor resolve to the same three-arm
14305        // emit-set across every arm the exhaustive
14306        // [`super::RestartPolicy::ALL`] slice enumerates. Rust's
14307        // standard library carries `impl From<&str> for
14308        // std::sync::Arc<str>` and `impl From<String> for
14309        // std::sync::Arc<str>` but no blanket
14310        // `impl<T: AsRef<str>> From<&T> for std::sync::Arc<str>` (nor
14311        // a `Copy`-based `impl<T: Copy, U: From<T>> From<&T> for U`),
14312        // so the borrowed-input [`std::sync::Arc<str>`] forward-
14313        // projection axis is a distinct trait-idiomatic surface that
14314        // a `let key: std::sync::Arc<str> = (&policy).into();`-shaped
14315        // call site or a
14316        // `RestartPolicy::ALL.iter().map(std::sync::Arc::<str>::from)`-
14317        // shaped pipe reaches through this impl and no other — the
14318        // paired owned-input [`From<RestartPolicy> for
14319        // std::sync::Arc<str>`] impl (b05724e) forces every borrowed-
14320        // input call site through an explicit [`Copy`] deref
14321        // (`std::sync::Arc::<str>::from((*policy).as_str())`) or a
14322        // `std::sync::Arc::<str>::from(policy.as_str())` open-code
14323        // whose type bounds have no compile-time link back to the
14324        // substrate primitive.
14325        //
14326        // Closes the `{Self, &Self}` input-shape corner of the
14327        // substrate-wide trait-idiomatic [`std::sync::Arc<str>`]
14328        // forward-projection family on the second (and third-and-
14329        // final) M2 OTP-shape closed-set fieldless typed enum peer
14330        // on the caixa surface (`:children :restart`), one commit
14331        // after b05724e opened the owned-input half — exactly as
14332        // b3e72d7 closed the paired [`std::sync::Arc<str>`] corner on
14333        // the sibling-restart [`RestartStrategy`] first-mover one
14334        // commit after its owning half (bca2ec8) landed, and as
14335        // cb1d068 closed the paired [`Box<str>`] corner on this
14336        // enum one commit after its owning half (0a1b313) landed.
14337        //
14338        // Also byte-parity witness against the paired owned-input
14339        // [`From<RestartPolicy> for std::sync::Arc<str>`] and the
14340        // sibling borrowed-input [`From<&RestartPolicy> for
14341        // &'static str`], [`From<&RestartPolicy> for String`],
14342        // [`From<&RestartPolicy> for Cow<'static, str>`], and
14343        // [`From<&RestartPolicy> for Box<str>`] return-shape axes —
14344        // locking the five return-shape × input-shape paths together
14345        // by construction so any future detour off the substrate-
14346        // primitive [`super::RestartPolicy::as_str`] accessor trips
14347        // at caixa-core test time. Then a
14348        // `.iter().map(std::sync::Arc::<str>::from)` pipe witness
14349        // over [`super::RestartPolicy::ALL`] — whose iterator yields
14350        // `&RestartPolicy` by construction, so the borrowed-input
14351        // [`std::sync::Arc<str>`] axis is what routes the pipe
14352        // through the substrate-primitive
14353        // [`super::RestartPolicy::as_str`] accessor without a
14354        // spurious [`Copy`] deref (which would only be reachable
14355        // through the owned-input
14356        // [`From<RestartPolicy> for std::sync::Arc<str>`] axis by
14357        // first calling `.copied()` on the iterator).
14358        for &variant in RestartPolicy::ALL {
14359            let via_trait: std::sync::Arc<str> =
14360                <std::sync::Arc<str> as From<&RestartPolicy>>::from(&variant);
14361            let via_method: &'static str = variant.as_str();
14362            assert_eq!(
14363                via_trait.as_ref(),
14364                via_method,
14365                "From<&RestartPolicy> for std::sync::Arc<str> impl \
14366                 must round-trip &RestartPolicy::{variant:?} to the \
14367                 same lifted SUPERVISOR_CHILD_RESTART_* const \
14368                 RestartPolicy::as_str returns — divergence signals \
14369                 a silent detour off the substrate-primitive accessor"
14370            );
14371            let via_into: std::sync::Arc<str> = (&variant).into();
14372            assert_eq!(
14373                via_into.as_ref(),
14374                via_method,
14375                "Into<std::sync::Arc<str>>::into on \
14376                 &RestartPolicy::{variant:?} must byte-equal \
14377                 RestartPolicy::as_str on the same input — the \
14378                 blanket-derived Into shape must resolve to the same \
14379                 as_str dispatch as the explicit From impl"
14380            );
14381            let owned_arc: std::sync::Arc<str> =
14382                <std::sync::Arc<str> as From<RestartPolicy>>::from(variant);
14383            assert_eq!(
14384                via_trait, owned_arc,
14385                "From<&RestartPolicy> for std::sync::Arc<str> and \
14386                 From<RestartPolicy> for std::sync::Arc<str> must \
14387                 resolve identically on RestartPolicy::{variant:?} — \
14388                 divergence signals the borrowed-input and owned-input \
14389                 std::sync::Arc<str> forward-projection input-shape \
14390                 paths have drifted onto different emit-sets"
14391            );
14392            let borrowed_static: &'static str =
14393                <&'static str as From<&RestartPolicy>>::from(&variant);
14394            assert_eq!(
14395                via_trait.as_ref(),
14396                borrowed_static,
14397                "From<&RestartPolicy> for std::sync::Arc<str> and \
14398                 From<&RestartPolicy> for &'static str must resolve \
14399                 identically on RestartPolicy::{variant:?} — \
14400                 divergence signals the borrowed-input std::sync::Arc<str> \
14401                 and &'static str return-shape paths have drifted onto \
14402                 different emit-sets"
14403            );
14404            let borrowed_string: String = <String as From<&RestartPolicy>>::from(&variant);
14405            assert_eq!(
14406                via_trait.as_ref(),
14407                borrowed_string.as_str(),
14408                "From<&RestartPolicy> for std::sync::Arc<str> and \
14409                 From<&RestartPolicy> for String must resolve \
14410                 identically on RestartPolicy::{variant:?} — \
14411                 divergence signals the borrowed-input std::sync::Arc<str> \
14412                 and owned-`String` return-shape paths have drifted \
14413                 onto different emit-sets"
14414            );
14415            let borrowed_cow: std::borrow::Cow<'static, str> =
14416                <std::borrow::Cow<'static, str> as From<&RestartPolicy>>::from(&variant);
14417            assert_eq!(
14418                via_trait.as_ref(),
14419                borrowed_cow.as_ref(),
14420                "From<&RestartPolicy> for std::sync::Arc<str> and \
14421                 From<&RestartPolicy> for Cow<'static, str> must \
14422                 resolve identically on RestartPolicy::{variant:?} — \
14423                 divergence signals the borrowed-input std::sync::Arc<str> \
14424                 and Cow<'static, str> return-shape paths have drifted \
14425                 onto different emit-sets"
14426            );
14427            let borrowed_box: Box<str> = <Box<str> as From<&RestartPolicy>>::from(&variant);
14428            assert_eq!(
14429                via_trait.as_ref(),
14430                borrowed_box.as_ref(),
14431                "From<&RestartPolicy> for std::sync::Arc<str> and \
14432                 From<&RestartPolicy> for Box<str> must resolve \
14433                 identically on RestartPolicy::{variant:?} — \
14434                 divergence signals the borrowed-input std::sync::Arc<str> \
14435                 and Box<str> return-shape paths have drifted onto \
14436                 different emit-sets"
14437            );
14438        }
14439        let via_iter: Vec<std::sync::Arc<str>> = RestartPolicy::ALL
14440            .iter()
14441            .map(std::sync::Arc::<str>::from)
14442            .collect();
14443        let via_method: Vec<std::sync::Arc<str>> = RestartPolicy::ALL
14444            .iter()
14445            .map(|p| std::sync::Arc::<str>::from(p.as_str()))
14446            .collect();
14447        assert_eq!(
14448            via_iter, via_method,
14449            "`.iter().map(std::sync::Arc::<str>::from)` over \
14450             RestartPolicy::ALL — a call site whose iteration axis \
14451             holds `&RestartPolicy` by construction — must byte-\
14452             equal `.iter().map(|p| std::sync::Arc::<str>::from(p.as_str()))` \
14453             on every arm — the borrowed-input std::sync::Arc<str> \
14454             `From<&RestartPolicy> for std::sync::Arc<str>` axis is \
14455             what makes the `std::sync::Arc::<str>::from` composition \
14456             route through the substrate-primitive \
14457             `RestartPolicy::as_str` accessor without a spurious \
14458             `Copy` deref (which would only be reachable through the \
14459             owned-input `From<RestartPolicy> for std::sync::Arc<str>` \
14460             axis by first calling `.copied()` on the iterator)"
14461        );
14462    }
14463
14464    #[test]
14465    fn restart_policy_from_into_rc_str_routes_through_as_str_accessor() {
14466        // Fail-before-pass-after byte-parity pin on the newly lifted
14467        // `impl From<RestartPolicy> for std::rc::Rc<str>` — asserts
14468        // the owned-input standard-library trait impl and the
14469        // substrate-primitive [`super::RestartPolicy::as_str`]
14470        // `pub const fn` accessor resolve to the same three-arm emit-
14471        // set across every arm the exhaustive
14472        // [`super::RestartPolicy::ALL`] slice enumerates, and cross-
14473        // witnesses against every sibling owned-input `{&'static str,
14474        // String, Cow<'static, str>, Box<str>, std::sync::Arc<str>}`
14475        // return-shape axis so the six return-shape paths on the
14476        // owned-input surface lock together by construction. Closes
14477        // the substrate-wide [`std::rc::Rc<str>`] forward-projection
14478        // campaign on the M2-OTP-shape `:supervisor :estrategia` +
14479        // `:children :restart` slot pair the sibling-restart
14480        // [`RestartStrategy`] first-mover (71ad8f4) opened one
14481        // projection tier prior on the paired sibling enum.
14482        for &variant in RestartPolicy::ALL {
14483            let via_trait: std::rc::Rc<str> =
14484                <std::rc::Rc<str> as From<RestartPolicy>>::from(variant);
14485            let via_method: &'static str = variant.as_str();
14486            assert_eq!(
14487                via_trait.as_ref(),
14488                via_method,
14489                "From<RestartPolicy> for std::rc::Rc<str> impl must \
14490                 round-trip RestartPolicy::{variant:?} to the same \
14491                 lifted SUPERVISOR_CHILD_RESTART_* const \
14492                 RestartPolicy::as_str returns — divergence signals \
14493                 a silent detour off the substrate-primitive accessor"
14494            );
14495            let via_into: std::rc::Rc<str> = variant.into();
14496            assert_eq!(
14497                via_into.as_ref(),
14498                via_method,
14499                "Into<std::rc::Rc<str>>::into on \
14500                 RestartPolicy::{variant:?} must byte-equal \
14501                 RestartPolicy::as_str on the same input — the \
14502                 blanket-derived Into shape must resolve to the same \
14503                 as_str dispatch as the explicit From impl"
14504            );
14505            let owned_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
14506            assert_eq!(
14507                via_trait.as_ref(),
14508                owned_static,
14509                "From<RestartPolicy> for std::rc::Rc<str> and \
14510                 From<RestartPolicy> for &'static str must resolve \
14511                 identically on RestartPolicy::{variant:?}"
14512            );
14513            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
14514            assert_eq!(
14515                via_trait.as_ref(),
14516                owned_string.as_str(),
14517                "From<RestartPolicy> for std::rc::Rc<str> and \
14518                 From<RestartPolicy> for String must resolve \
14519                 identically on RestartPolicy::{variant:?}"
14520            );
14521            let owned_cow: std::borrow::Cow<'static, str> =
14522                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
14523            assert_eq!(
14524                via_trait.as_ref(),
14525                owned_cow.as_ref(),
14526                "From<RestartPolicy> for std::rc::Rc<str> and \
14527                 From<RestartPolicy> for Cow<'static, str> must \
14528                 resolve identically on RestartPolicy::{variant:?}"
14529            );
14530            let owned_box: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
14531            assert_eq!(
14532                via_trait.as_ref(),
14533                owned_box.as_ref(),
14534                "From<RestartPolicy> for std::rc::Rc<str> and \
14535                 From<RestartPolicy> for Box<str> must resolve \
14536                 identically on RestartPolicy::{variant:?}"
14537            );
14538            let owned_arc: std::sync::Arc<str> =
14539                <std::sync::Arc<str> as From<RestartPolicy>>::from(variant);
14540            assert_eq!(
14541                via_trait.as_ref(),
14542                owned_arc.as_ref(),
14543                "From<RestartPolicy> for std::rc::Rc<str> and \
14544                 From<RestartPolicy> for std::sync::Arc<str> must \
14545                 resolve identically on RestartPolicy::{variant:?}"
14546            );
14547        }
14548    }
14549
14550    #[test]
14551    fn restart_policy_from_borrowed_into_rc_str_routes_through_as_str_accessor() {
14552        // Fail-before-pass-after byte-parity pin on the newly lifted
14553        // `impl From<&RestartPolicy> for std::rc::Rc<str>` — asserts
14554        // the borrowed-input standard-library trait impl and the
14555        // substrate-primitive [`super::RestartPolicy::as_str`]
14556        // `pub const fn` accessor resolve to the same three-arm emit-
14557        // set across every arm the exhaustive
14558        // [`super::RestartPolicy::ALL`] slice enumerates. Closes the
14559        // `{Self, &Self}` input-shape corner of the
14560        // [`std::rc::Rc<str>`] axis on this enum, cross-witnesses
14561        // against the paired owned-input axis and every sibling
14562        // borrowed-input return-shape axis, and locks the
14563        // `.iter().map(std::rc::Rc::<str>::from)` pipe over
14564        // [`super::RestartPolicy::ALL`] to the substrate-primitive
14565        // accessor without a spurious [`Copy`] deref (which would only
14566        // be reachable through the owned-input axis by first calling
14567        // `.copied()` on the iterator).
14568        for &variant in RestartPolicy::ALL {
14569            let via_trait: std::rc::Rc<str> =
14570                <std::rc::Rc<str> as From<&RestartPolicy>>::from(&variant);
14571            let via_method: &'static str = variant.as_str();
14572            assert_eq!(
14573                via_trait.as_ref(),
14574                via_method,
14575                "From<&RestartPolicy> for std::rc::Rc<str> impl must \
14576                 round-trip &RestartPolicy::{variant:?} to the same \
14577                 lifted SUPERVISOR_CHILD_RESTART_* const \
14578                 RestartPolicy::as_str returns"
14579            );
14580            let via_into: std::rc::Rc<str> = (&variant).into();
14581            assert_eq!(
14582                via_into.as_ref(),
14583                via_method,
14584                "Into<std::rc::Rc<str>>::into on \
14585                 &RestartPolicy::{variant:?} must byte-equal \
14586                 RestartPolicy::as_str on the same input"
14587            );
14588            let owned_rc: std::rc::Rc<str> =
14589                <std::rc::Rc<str> as From<RestartPolicy>>::from(variant);
14590            assert_eq!(
14591                via_trait, owned_rc,
14592                "From<&RestartPolicy> for std::rc::Rc<str> and \
14593                 From<RestartPolicy> for std::rc::Rc<str> must \
14594                 resolve identically on RestartPolicy::{variant:?}"
14595            );
14596            let borrowed_static: &'static str =
14597                <&'static str as From<&RestartPolicy>>::from(&variant);
14598            assert_eq!(
14599                via_trait.as_ref(),
14600                borrowed_static,
14601                "From<&RestartPolicy> for std::rc::Rc<str> and \
14602                 From<&RestartPolicy> for &'static str must resolve \
14603                 identically on RestartPolicy::{variant:?}"
14604            );
14605            let borrowed_string: String = <String as From<&RestartPolicy>>::from(&variant);
14606            assert_eq!(
14607                via_trait.as_ref(),
14608                borrowed_string.as_str(),
14609                "From<&RestartPolicy> for std::rc::Rc<str> and \
14610                 From<&RestartPolicy> for String must resolve \
14611                 identically on RestartPolicy::{variant:?}"
14612            );
14613            let borrowed_cow: std::borrow::Cow<'static, str> =
14614                <std::borrow::Cow<'static, str> as From<&RestartPolicy>>::from(&variant);
14615            assert_eq!(
14616                via_trait.as_ref(),
14617                borrowed_cow.as_ref(),
14618                "From<&RestartPolicy> for std::rc::Rc<str> and \
14619                 From<&RestartPolicy> for Cow<'static, str> must \
14620                 resolve identically on RestartPolicy::{variant:?}"
14621            );
14622            let borrowed_box: Box<str> = <Box<str> as From<&RestartPolicy>>::from(&variant);
14623            assert_eq!(
14624                via_trait.as_ref(),
14625                borrowed_box.as_ref(),
14626                "From<&RestartPolicy> for std::rc::Rc<str> and \
14627                 From<&RestartPolicy> for Box<str> must resolve \
14628                 identically on RestartPolicy::{variant:?}"
14629            );
14630            let borrowed_arc: std::sync::Arc<str> =
14631                <std::sync::Arc<str> as From<&RestartPolicy>>::from(&variant);
14632            assert_eq!(
14633                via_trait.as_ref(),
14634                borrowed_arc.as_ref(),
14635                "From<&RestartPolicy> for std::rc::Rc<str> and \
14636                 From<&RestartPolicy> for std::sync::Arc<str> must \
14637                 resolve identically on RestartPolicy::{variant:?}"
14638            );
14639        }
14640        let via_iter: Vec<std::rc::Rc<str>> = RestartPolicy::ALL
14641            .iter()
14642            .map(std::rc::Rc::<str>::from)
14643            .collect();
14644        let via_method: Vec<std::rc::Rc<str>> = RestartPolicy::ALL
14645            .iter()
14646            .map(|p| std::rc::Rc::<str>::from(p.as_str()))
14647            .collect();
14648        assert_eq!(
14649            via_iter, via_method,
14650            "`.iter().map(std::rc::Rc::<str>::from)` over \
14651             RestartPolicy::ALL — a call site whose iteration axis \
14652             holds `&RestartPolicy` by construction — must byte-\
14653             equal `.iter().map(|p| std::rc::Rc::<str>::from(p.as_str()))` \
14654             on every arm — the borrowed-input std::rc::Rc<str> \
14655             `From<&RestartPolicy> for std::rc::Rc<str>` axis is \
14656             what makes the `std::rc::Rc::<str>::from` composition \
14657             route through the substrate-primitive \
14658             `RestartPolicy::as_str` accessor without a spurious \
14659             `Copy` deref (which would only be reachable through the \
14660             owned-input `From<RestartPolicy> for std::rc::Rc<str>` \
14661             axis by first calling `.copied()` on the iterator)"
14662        );
14663    }
14664
14665    // ── drift-detection: serde-derive-to-SUPERVISOR_CHILD_RESTART_* identity ─
14666
14667    #[test]
14668    fn restart_policy_variants_serialize_to_lifted_scalar_values() {
14669        // The fail-before-pass-after pin: pre-lift there was no
14670        // single-source binding between the [`RestartPolicy`] variant
14671        // name the un-`rename`d `Serialize` derive emits under
14672        // [`crate::render::SUPERVISOR_CHILD_KEY_RESTART`] and the
14673        // byte-string every downstream cluster-side dispatcher (the
14674        // future wasm-operator's per-child post-exit restart-decision
14675        // branch, the future M4 `mesh.pleme.io/v1alpha1/Supervisor` CR
14676        // materializer's admission-time enum-arm bind, the
14677        // `caixa-operator`'s hierarchical reconciliation scheduler's
14678        // per-child-policy fan-out) probes verbatim. A future
14679        // `#[serde(rename_all = "kebab-case")]` attribute on the enum —
14680        // or a per-variant `#[serde(rename = "…")]` override, or a
14681        // variant rename in the source — would silently rebrand the
14682        // emitted scalar under one spelling while every downstream
14683        // dispatcher still probed the other, with the failure surfacing
14684        // at the operator's reconcile posture (children coming up under
14685        // the `default()` `Permanent` arm rather than the typed slot's
14686        // declared policy — a `:temporary` `oneShot` child would be
14687        // restarted on clean exit, treating the successful-completion
14688        // signal as failure and re-running the completion-terminal
14689        // one-shot indefinitely; a `:transient` child that clean-exited
14690        // would be restarted, masking the clean-completion contract)
14691        // far from the source rebrand commit and with no field naming
14692        // the drift. Pinning the two paths (the `Serialize` derive's
14693        // serialized string AND the [`RestartPolicy::as_str`] helper)
14694        // to the same three lifted
14695        // [`crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT`] /
14696        // [`crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY`] /
14697        // [`crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT`]
14698        // byte-strings makes any future drift on either endpoint fail
14699        // here at caixa-core build time. Peer of the sibling
14700        // [`restart_strategy_variants_serialize_to_lifted_scalar_values`]
14701        // (09ffb2d) on the per-supervisor sibling-restart-strategy axis
14702        // and the M3
14703        // `placement_strategy_variants_serialize_to_lifted_scalar_values`
14704        // (3f0e21c) on the per-Aplicacao distribution-strategy axis —
14705        // same three-path-convergence discipline, extended to close the
14706        // third OTP-shaped closed-enum discriminator axis on the caixa
14707        // typed surface (per-child restart-decision policy).
14708        for (variant, expected) in [
14709            (
14710                RestartPolicy::Permanent,
14711                crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
14712            ),
14713            (
14714                RestartPolicy::Temporary,
14715                crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
14716            ),
14717            (
14718                RestartPolicy::Transient,
14719                crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
14720            ),
14721        ] {
14722            let json = serde_json::to_string(&variant).unwrap();
14723            assert_eq!(
14724                json,
14725                format!("\"{expected}\""),
14726                "RestartPolicy::{variant:?} must serialize to {expected:?}"
14727            );
14728            assert_eq!(
14729                variant.as_str(),
14730                expected,
14731                "RestartPolicy::{variant:?}.as_str() must return the lifted \
14732                 SUPERVISOR_CHILD_RESTART_* constant"
14733            );
14734        }
14735    }
14736
14737    #[test]
14738    fn supervisor_child_restart_consts_are_pairwise_distinct() {
14739        // Cross-arm drift-detection pin: a future collapse of two
14740        // canonical variant byte-strings onto the same value (e.g. an
14741        // accidental copy-paste flip of `SUPERVISOR_CHILD_RESTART_TRANSIENT`
14742        // to also read `"Permanent"`) would silently reroute every
14743        // downstream operator's per-child-policy dispatch onto the
14744        // sibling arm's reconcile branch and pass every propagation-probe
14745        // test that expected only the stale arm's value — a `:transient`
14746        // child would come up under the `:permanent` restart-decision
14747        // posture on every subsequent clean exit, so a completion-terminal
14748        // child would be restarted indefinitely against its declared
14749        // policy. Peer of the sibling
14750        // [`supervisor_estrategia_consts_are_pairwise_distinct`]
14751        // (09ffb2d) on the per-supervisor sibling-restart-strategy axis
14752        // and the four-way distinct pin
14753        // `supervisor_key_consts_are_pairwise_distinct` (40cc4e5) on the
14754        // top-level `SUPERVISOR_KEY_*` axis.
14755        let all = [
14756            crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
14757            crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
14758            crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
14759        ];
14760        for (i, a) in all.iter().enumerate() {
14761            for (j, b) in all.iter().enumerate() {
14762                if i != j {
14763                    assert_ne!(
14764                        a, b,
14765                        "SUPERVISOR_CHILD_RESTART_* consts must be pairwise distinct \
14766                         — got duplicate {a:?} at indices {i} and {j}",
14767                    );
14768                }
14769            }
14770        }
14771    }
14772
14773    #[test]
14774    fn restart_policy_display_routes_through_as_str_helper() {
14775        // The fail-before-pass-after pin on the first half of the
14776        // three-path convergence: pre-convergence [`RestartPolicy`]
14777        // carried a [`std::fmt::Display`] surface via its
14778        // `#[discriminant(also_display)]` gen-platform derive route,
14779        // which arrived kebab-case as `"permanent"` / `"temporary"`
14780        // / `"transient"` on this three-arm enum (whose variant
14781        // names each collapse to their own lowercase form under the
14782        // kebab-case transform) while the wire format ran as
14783        // PascalCase `"Permanent"` / `"Temporary"` / `"Transient"`
14784        // through the un-`rename`d serde derive. Every consumer
14785        // reaching for a policy byte-string past the wire format had
14786        // to pick between three paths ([`RestartPolicy::as_str`],
14787        // the `Serialize` derive's serialized string, or
14788        // `format!("{v}")` on the discriminant-Display route), any
14789        // two of which a future variant rename or
14790        // `#[serde(rename_all = "kebab-case")]` attribute would
14791        // silently desynchronize. Wiring [`std::fmt::Display`]
14792        // through [`RestartPolicy::as_str`] closes the third path:
14793        // every `format!("{v}")` call reaches the same lifted
14794        // [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const the
14795        // wire format and the [`RestartPolicy::as_str`] helper
14796        // already route through, so a future variant rename lands at
14797        // exactly one place. Pin the routing here so a future
14798        // `impl std::fmt::Display for RestartPolicy`
14799        // reimplementation that hand-rolls the arms instead of
14800        // delegating to [`RestartPolicy::as_str`] fails at
14801        // caixa-core build time. Peer of the sibling
14802        // [`restart_strategy_display_routes_through_as_str_helper`]
14803        // on the per-supervisor sibling-restart-strategy axis and
14804        // the M3
14805        // `placement_strategy_display_routes_through_as_str_helper`
14806        // (cc8f749) — the third of three OTP-shape closed-enum
14807        // discriminator axes on the caixa typed surface now
14808        // converged onto the same three-path
14809        // (Display → as_str → lifted const) discipline.
14810        for variant in [
14811            RestartPolicy::Permanent,
14812            RestartPolicy::Temporary,
14813            RestartPolicy::Transient,
14814        ] {
14815            assert_eq!(
14816                variant.to_string(),
14817                variant.as_str(),
14818                "RestartPolicy::{variant:?} Display must route through \
14819                 RestartPolicy::as_str (single source of truth: the lifted \
14820                 SUPERVISOR_CHILD_RESTART_* const the wire format also emits)"
14821            );
14822        }
14823    }
14824
14825    #[test]
14826    fn restart_policy_display_matches_serialized_wire_byte_string() {
14827        // The fail-before-pass-after pin on the second half of the
14828        // three-path convergence: `Display` (user-facing text) agrees
14829        // byte-for-byte with the `Serialize` derive's wire format
14830        // (canonical camelCase-schema `SUPERVISOR_CHILD_KEY_RESTART`
14831        // scalar) on every variant. Pre-convergence the two paths
14832        // were structurally independent — a future
14833        // `#[serde(rename_all = "kebab-case")]` attribute on the
14834        // enum would silently rebrand the emitted wire scalar
14835        // (`permanent`, `temporary`, `transient`) while every
14836        // consumer that pretty-prints the policy (the future
14837        // wasm-operator's per-child post-exit restart-decision
14838        // diagnostic line, the future `feira app graph` per-child
14839        // restart column, the future M4
14840        // `mesh.pleme.io/v1alpha1/Supervisor` CR materializer's
14841        // per-child admission-webhook rejection body) would still
14842        // emit the PascalCase form the `as_str` / `Display` route
14843        // returns, with the mismatch surfacing at consumer parse
14844        // time / operator dispatch time far from the source rebrand
14845        // commit. Pin the two paths byte-for-byte here so any future
14846        // serde-attribute or variant-rename drift is a
14847        // caixa-core-build-time test failure at this call, not a
14848        // silent per-consumer dispatch miss. Peer of the sibling
14849        // [`restart_strategy_display_matches_serialized_wire_byte_string`]
14850        // on the per-supervisor sibling-restart-strategy axis and
14851        // the M3
14852        // `placement_strategy_display_matches_serialized_wire_byte_string`
14853        // (cc8f749).
14854        for variant in [
14855            RestartPolicy::Permanent,
14856            RestartPolicy::Temporary,
14857            RestartPolicy::Transient,
14858        ] {
14859            let wire = serde_json::to_string(&variant).unwrap();
14860            let unquoted = wire
14861                .strip_prefix('"')
14862                .and_then(|s| s.strip_suffix('"'))
14863                .expect("serialized RestartPolicy is a JSON string");
14864            assert_eq!(
14865                variant.to_string(),
14866                unquoted,
14867                "RestartPolicy::{variant:?} Display byte-string must match the \
14868                 Serialize derive's wire byte-string (three-path convergence: \
14869                 Display + as_str + Serialize all resolve to the same \
14870                 SUPERVISOR_CHILD_RESTART_* const)"
14871            );
14872        }
14873    }
14874
14875    #[test]
14876    fn restart_policy_as_ref_str_routes_through_as_str_accessor() {
14877        // Fail-before-pass-after byte-parity pin on the lifted
14878        // `impl AsRef<str> for RestartPolicy` — asserts the
14879        // standard-library trait impl and the substrate-primitive
14880        // [`RestartPolicy::as_str`] `pub const fn` accessor resolve
14881        // to the same `&str` per instance across the three-arm
14882        // closed set, so any future silent detour that routes the
14883        // impl through a divergent projection (a per-arm inline
14884        // `match self { RestartPolicy::Permanent => "Permanent", … }`
14885        // re-inlining that opens a compile-time link to the un-lifted
14886        // arm-literal, a swap onto the kebab-case
14887        // [`gen_platform::Discriminant`] catalog identity that would
14888        // collide the wire axis with the dispatcher-catalog axis) trips
14889        // at caixa-core test time under `PartialEq` rather than at a
14890        // downstream `impl AsRef<str>`-bound consumer's silent split.
14891        // Sweeps every one of the three arms
14892        // [`RestartPolicy::ALL`] carries so no arm's projection is
14893        // covered only by the sibling wire-format `Serialize` derive
14894        // path. Peer of the sibling
14895        // [`restart_strategy_as_ref_str_routes_through_as_str_accessor`]
14896        // (63eb1a4) on the paired per-supervisor sibling-restart-
14897        // strategy axis and the [`crate::CaixaVersion`]
14898        // `AsRef<str>`-byte-parity pin (16d5c7e) on the paired
14899        // top-level `:versao` typed newtype — the three pins together
14900        // cover the substrate primitive's `AsRef<str>` projection axis
14901        // on the paired newtype + M2 closed-set-typed-enum surface.
14902        for &variant in RestartPolicy::ALL {
14903            assert_eq!(
14904                <RestartPolicy as AsRef<str>>::as_ref(&variant),
14905                variant.as_str(),
14906                "AsRef<str> impl on RestartPolicy::{variant:?} must \
14907                 byte-equal RestartPolicy::as_str on the same instance \
14908                 — divergence signals a silent detour off the substrate-\
14909                 primitive accessor"
14910            );
14911        }
14912    }
14913
14914    #[test]
14915    fn restart_policy_as_ref_str_routes_through_display_via_shared_accessor() {
14916        // Fail-before-pass-after byte-parity pin on the three-path
14917        // convergence discipline the M2 per-child-restart-policy
14918        // primitive now carries on the `&str`-projection axis:
14919        // `<RestartPolicy as AsRef<str>>::as_ref(&v)` (the newly
14920        // lifted impl), `format!("{v}")` (the pre-existing
14921        // [`fmt::Display`] impl), and `v.as_str()` (the substrate-
14922        // primitive `pub const fn` accessor both trait impls delegate
14923        // through) must resolve to the same byte-string on every
14924        // instance across the three-arm closed set. Refuses any future
14925        // divergence between the two trait impls (a stray
14926        // [`fmt::Display::fmt`] rewrite that hand-rolls the arms
14927        // rather than delegating through the shared accessor; a
14928        // hypothetical `AsRef<str>` rewrite that inlines a per-arm
14929        // literal cascade) that would silently split the two
14930        // projection paths of the same closed-set typed enum. Mirrors
14931        // the sibling three-path-convergence discipline the peer
14932        // [`RestartStrategy`] typed enum carries on its
14933        // `AsRef<str>` / `Display` / `as_str` triple
14934        // (supervisor.rs pin
14935        // `restart_strategy_as_ref_str_routes_through_display_via_shared_accessor`,
14936        // 63eb1a4) and the [`crate::CaixaVersion`] typed newtype
14937        // carries on the same triple (version.rs pin
14938        // `caixa_version_as_ref_str_routes_through_display_via_shared_accessor`,
14939        // 16d5c7e).
14940        for &variant in RestartPolicy::ALL {
14941            let via_as_ref: &str = <RestartPolicy as AsRef<str>>::as_ref(&variant);
14942            let via_display: String = format!("{variant}");
14943            let via_accessor: &str = variant.as_str();
14944            assert_eq!(via_as_ref, via_accessor);
14945            assert_eq!(via_display, via_accessor);
14946            assert_eq!(via_as_ref, via_display.as_str());
14947        }
14948    }
14949
14950    // The `generic_bytes_sink(&variant)` and `borrowed_hasher.update(&variant)`
14951    // shapes below are the borrowed-input witness half of the by-value +
14952    // by-reference partition the paired witness pair carries: the pair proves
14953    // the trait bound accepts both owned (`variant`) and borrowed (`&variant`)
14954    // shapes through the same substrate-primitive `as_str` accessor, which is
14955    // the shape the caixa-lacre BLAKE3 content-address closure composes.
14956    // `clippy::needless_borrows_for_generic_args` would fold the borrowed half
14957    // into the owned half and collapse the by-value/by-reference partition
14958    // this test load-bears; the `#[allow]` documents that the partition is
14959    // deliberate, not an oversight.
14960    #[allow(clippy::needless_borrows_for_generic_args)]
14961    #[test]
14962    fn restart_policy_as_ref_bytes_routes_through_as_str_accessor() {
14963        // `<T: AsRef<[u8]>>`-bound generic-consumer witness: a byte-input
14964        // function that binds its argument through the standard-library
14965        // [`AsRef<[u8]>`] trait bound accepts a [`super::RestartPolicy`]
14966        // directly, without the caller open-coding the two-hop
14967        // `restart.as_str().as_bytes()` composition. Lifted to the top
14968        // of the function per `clippy::items_after_statements`.
14969        fn generic_bytes_sink<T: AsRef<[u8]>>(t: T) -> Vec<u8> {
14970            t.as_ref().to_vec()
14971        }
14972        // `blake3::Hasher::update`-shape byte-input surface mock: mirrors
14973        // `blake3::Hasher::update` / `ring::digest::Context::update` /
14974        // `sha2::Sha256::update`'s `impl AsRef<[u8]>`-bound `update`
14975        // signature so a per-child BLAKE3 content-address closure that
14976        // composes `hasher.update(restart)` on the [`crate::Lacre`]
14977        // closure builder reaches the substrate-primitive `as_str`
14978        // accessor through the [`super::RestartPolicy`] `AsRef<[u8]>`
14979        // axis and no other. Lifted to the top of the function per
14980        // `clippy::items_after_statements`.
14981        struct MockHasher(Vec<u8>);
14982        impl MockHasher {
14983            fn new() -> Self {
14984                Self(Vec::new())
14985            }
14986            fn update(&mut self, bytes: impl AsRef<[u8]>) -> &mut Self {
14987                self.0.extend_from_slice(bytes.as_ref());
14988                self
14989            }
14990            fn finalize(self) -> Vec<u8> {
14991                self.0
14992            }
14993        }
14994
14995        // Fail-before-pass-after byte-parity pin on the newly lifted
14996        // `impl AsRef<[u8]> for RestartPolicy` — asserts the trait-
14997        // idiomatic byte-view standard-library impl and the substrate-
14998        // primitive [`super::RestartPolicy::as_str`] `pub const fn`
14999        // accessor's `.as_bytes()` byte-tail resolve to the same three-
15000        // arm `PascalCase` wire byte-string emit-set across every arm
15001        // the exhaustive [`super::RestartPolicy::ALL`] slice enumerates.
15002        // Extends the trait-idiomatic byte-view axis onto the second
15003        // (and final) M2 OTP-shape closed-set fieldless typed enum peer
15004        // on the caixa surface (the paired per-child restart-decision
15005        // policy sibling on the same M2 `:supervisor` slot), closing
15006        // the byte-view axis across the `:supervisor :estrategia` +
15007        // `:children :restart` M2 slot pair the sibling
15008        // [`super::RestartStrategy`] first-mover (cd4c4e0) opened.
15009        //
15010        // Rust's standard library carries `impl AsRef<[u8]> for str` and
15011        // `impl AsRef<[u8]> for String`, so a two-hop composition
15012        // `restart.as_str().as_bytes()` (or the equally two-hop
15013        // `AsRef::<str>::as_ref(&restart).as_bytes()`) is reachable
15014        // through the pre-existing str-view axis alone. But that two-hop
15015        // shape has no compile-time link back to the byte-projection
15016        // axis, forces every downstream `<T: AsRef<[u8]>>`-bound
15017        // consumer to open-code the two-hop composition at every call
15018        // site, and admits a silent split whenever a future call site
15019        // takes a sibling reverse-projection axis whose `.as_bytes()`
15020        // byte-tail carries no compile-time byte-view surface. This
15021        // impl closes the byte-view axis at the substrate-primitive
15022        // [`super::RestartPolicy::as_str`] accessor so every future
15023        // `<T: AsRef<[u8]>>`-bound consumer reaches the same lifted
15024        // [`super::crate::render::SUPERVISOR_CHILD_RESTART_*`] const
15025        // roster the paired str-view axes already return through —
15026        // through one trait dispatch.
15027        for &variant in RestartPolicy::ALL {
15028            let via_trait: &[u8] = <RestartPolicy as AsRef<[u8]>>::as_ref(&variant);
15029            let via_method_bytes: &[u8] = variant.as_str().as_bytes();
15030            assert_eq!(
15031                via_trait, via_method_bytes,
15032                "AsRef<[u8]> for RestartPolicy impl must byte-equal \
15033                 RestartPolicy::as_str().as_bytes() on \
15034                 RestartPolicy::{variant:?} — divergence signals a \
15035                 silent detour off the substrate-primitive accessor"
15036            );
15037            // Cross-axis witness against the paired str-view axes'
15038            // `.as_bytes()` byte-tails: [`AsRef<str>`] /
15039            // [`std::fmt::Display`] / [`super::RestartPolicy::as_str`]
15040            // all resolve to the same lifted
15041            // [`super::crate::render::SUPERVISOR_CHILD_RESTART_*`] const
15042            // roster, and the byte-view axis must byte-equal each of
15043            // their `.as_bytes()` byte-tails by construction — locking
15044            // the str-view and byte-view axes together at the
15045            // substrate-primitive accessor.
15046            let str_view_ref: &str = <RestartPolicy as AsRef<str>>::as_ref(&variant);
15047            assert_eq!(
15048                via_trait,
15049                str_view_ref.as_bytes(),
15050                "AsRef<[u8]> for RestartPolicy and AsRef<str> for \
15051                 RestartPolicy must resolve to byte-equal byte-tails \
15052                 on RestartPolicy::{variant:?} — divergence signals \
15053                 the byte-view and str-view axes have drifted off the \
15054                 same substrate-primitive as_str accessor"
15055            );
15056            let display_bytes = variant.to_string();
15057            assert_eq!(
15058                via_trait,
15059                display_bytes.as_bytes(),
15060                "AsRef<[u8]> for RestartPolicy and \
15061                 <RestartPolicy as std::fmt::Display>::to_string must \
15062                 resolve to byte-equal byte-tails on \
15063                 RestartPolicy::{variant:?} — divergence signals the \
15064                 byte-view axis and the Display formatter axis have \
15065                 drifted off the same substrate-primitive as_str \
15066                 accessor"
15067            );
15068            // Cross-axis witness against the paired reverse-projection
15069            // axes' `.as_bytes()` byte-tails: every one of `{&'static
15070            // str, String, Cow<'static, str>, Box<str>,
15071            // std::sync::Arc<str>}` allocates (or borrows) the same
15072            // `PascalCase` wire byte-string the substrate-primitive
15073            // accessor emits, so the byte-view axis must byte-equal
15074            // each of their `.as_bytes()` byte-tails by construction.
15075            let owned_static: &'static str = <&'static str as From<RestartPolicy>>::from(variant);
15076            assert_eq!(
15077                via_trait,
15078                owned_static.as_bytes(),
15079                "AsRef<[u8]> for RestartPolicy and From<RestartPolicy> \
15080                 for &'static str must resolve to byte-equal byte-tails \
15081                 on RestartPolicy::{variant:?}"
15082            );
15083            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
15084            assert_eq!(
15085                via_trait,
15086                owned_string.as_bytes(),
15087                "AsRef<[u8]> for RestartPolicy and From<RestartPolicy> \
15088                 for String must resolve to byte-equal byte-tails on \
15089                 RestartPolicy::{variant:?}"
15090            );
15091            let owned_cow: std::borrow::Cow<'static, str> =
15092                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
15093            assert_eq!(
15094                via_trait,
15095                owned_cow.as_bytes(),
15096                "AsRef<[u8]> for RestartPolicy and From<RestartPolicy> \
15097                 for Cow<'static, str> must resolve to byte-equal byte-\
15098                 tails on RestartPolicy::{variant:?}"
15099            );
15100            let owned_box: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
15101            assert_eq!(
15102                via_trait,
15103                owned_box.as_bytes(),
15104                "AsRef<[u8]> for RestartPolicy and From<RestartPolicy> \
15105                 for Box<str> must resolve to byte-equal byte-tails on \
15106                 RestartPolicy::{variant:?}"
15107            );
15108            let owned_arc: std::sync::Arc<str> =
15109                <std::sync::Arc<str> as From<RestartPolicy>>::from(variant);
15110            assert_eq!(
15111                via_trait,
15112                owned_arc.as_bytes(),
15113                "AsRef<[u8]> for RestartPolicy and From<RestartPolicy> \
15114                 for std::sync::Arc<str> must resolve to byte-equal \
15115                 byte-tails on RestartPolicy::{variant:?}"
15116            );
15117        }
15118        // `<T: AsRef<[u8]>>`-bound-consumer witness: the generic byte-
15119        // input function `generic_bytes_sink` (lifted above per
15120        // `clippy::items_after_statements`) accepts a
15121        // [`super::RestartPolicy`] directly through the trait bound,
15122        // without the caller open-coding the two-hop
15123        // `restart.as_str().as_bytes()` composition. This is the shape
15124        // that reaches the caixa-lacre BLAKE3 content-address closure's
15125        // `blake3::Hasher::update(impl AsRef<[u8]>)` byte-input surface
15126        // through this impl and no other.
15127        for &variant in RestartPolicy::ALL {
15128            let via_generic = generic_bytes_sink(variant);
15129            let via_borrowed_generic = generic_bytes_sink(&variant);
15130            let via_method_bytes = variant.as_str().as_bytes().to_vec();
15131            assert_eq!(
15132                via_generic, via_method_bytes,
15133                "generic `<T: AsRef<[u8]>>`-bound consumer on \
15134                 RestartPolicy::{variant:?} must yield the same byte-\
15135                 tail RestartPolicy::as_str().as_bytes() returns — \
15136                 divergence signals the byte-view axis fails to bridge \
15137                 a generic byte-input trait bound to the substrate-\
15138                 primitive accessor"
15139            );
15140            assert_eq!(
15141                via_borrowed_generic, via_method_bytes,
15142                "generic `<T: AsRef<[u8]>>`-bound consumer on \
15143                 &RestartPolicy::{variant:?} must yield the same byte-\
15144                 tail RestartPolicy::as_str().as_bytes() returns — the \
15145                 borrowed-input surface must resolve to the same as_str \
15146                 dispatch"
15147            );
15148        }
15149        // `blake3::Hasher::update`-shape byte-input surface witness on
15150        // the caixa-lacre compounding target: the `MockHasher` (lifted
15151        // above per `clippy::items_after_statements`) mirrors
15152        // `blake3::Hasher::update` / `ring::digest::Context::update` /
15153        // `sha2::Sha256::update`'s `impl AsRef<[u8]>`-bound update
15154        // signature and accepts a [`super::RestartPolicy`] directly,
15155        // routing its byte-tail through the substrate-primitive
15156        // `as_str` accessor — the shape a future per-child BLAKE3
15157        // content-address closure composes to fold a `:restart`
15158        // discriminator byte-tag into the [`crate::Lacre`] closure
15159        // body.
15160        for &variant in RestartPolicy::ALL {
15161            let mut owned_hasher = MockHasher::new();
15162            owned_hasher.update(variant);
15163            let owned_folded = owned_hasher.finalize();
15164            assert_eq!(
15165                owned_folded,
15166                variant.as_str().as_bytes(),
15167                "`hasher.update(restart)`-shape composition on \
15168                 RestartPolicy::{variant:?} must fold the same byte-\
15169                 tail RestartPolicy::as_str().as_bytes() returns — the \
15170                 shape a future per-child BLAKE3 content-address \
15171                 closure composes to fold a `:restart` discriminator \
15172                 byte-tag into the Lacre closure body"
15173            );
15174            let mut borrowed_hasher = MockHasher::new();
15175            borrowed_hasher.update(&variant);
15176            let borrowed_folded = borrowed_hasher.finalize();
15177            assert_eq!(
15178                borrowed_folded,
15179                variant.as_str().as_bytes(),
15180                "`hasher.update(&restart)`-shape composition on \
15181                 &RestartPolicy::{variant:?} must fold the same byte-\
15182                 tail RestartPolicy::as_str().as_bytes() returns — the \
15183                 borrowed-input surface must resolve to the same as_str \
15184                 dispatch"
15185            );
15186        }
15187    }
15188
15189    #[test]
15190    #[expect(
15191        clippy::too_many_lines,
15192        reason = "the byte-owned reverse-projection axis is closed \
15193                  here across the M2-OTP-shape :supervisor slot pair by \
15194                  extending onto the second and final M2-OTP-shape \
15195                  closed-set fieldless typed-enum peer, so the pin \
15196                  binds the new impl against every paired byte-view \
15197                  and str-owned axis on the same enum plus a generic \
15198                  <T: Into<Vec<u8>>>-bound consumer witness and a \
15199                  std::io::Write::write_all-shape owned-byte-sink \
15200                  surface witness on both owned and borrowed input \
15201                  shapes to lock the whole family against a future \
15202                  silent regression"
15203    )]
15204    fn restart_policy_from_into_owned_vec_bytes_routes_through_as_str_accessor() {
15205        // `<T: Into<Vec<u8>>>`-bound-consumer witness helper: a generic
15206        // owned-byte-input function accepts a [`super::RestartPolicy`]
15207        // directly through the trait bound, without the caller open-
15208        // coding the three-hop `restart.as_str().as_bytes().to_vec()`
15209        // composition. Lifted to the top of the function per
15210        // `clippy::items_after_statements`.
15211        fn generic_owned_bytes_sink<T: Into<Vec<u8>>>(t: T) -> Vec<u8> {
15212            t.into()
15213        }
15214        // `std::io::Write::write_all`-shape owned-byte-sink surface
15215        // mock: mirrors `std::io::Write::write_all` /
15216        // `bytes::BytesMut::extend_from_slice` / any per-arm audit-log
15217        // byte-sink that consumes a `Vec<u8>` payload via
15218        // `Into<Vec<u8>>`, so a future per-child per-`:restart` audit-
15219        // log emit reaches the substrate-primitive `as_str` accessor
15220        // through the byte-owned reverse-projection axis and no
15221        // other. Lifted to the top of the function per
15222        // `clippy::items_after_statements`.
15223        struct MockOwnedByteSink(Vec<u8>);
15224        impl MockOwnedByteSink {
15225            fn new() -> Self {
15226                Self(Vec::new())
15227            }
15228            fn write_all(&mut self, bytes: impl Into<Vec<u8>>) -> &mut Self {
15229                self.0.extend(bytes.into());
15230                self
15231            }
15232            fn finalize(self) -> Vec<u8> {
15233                self.0
15234            }
15235        }
15236
15237        // Fail-before-pass-after byte-parity pin on the newly lifted
15238        // `impl From<RestartPolicy> for Vec<u8>` and
15239        // `impl From<&RestartPolicy> for Vec<u8>` — asserts the trait-
15240        // idiomatic byte-owned reverse-projection standard-library
15241        // impls and the substrate-primitive
15242        // [`super::RestartPolicy::as_str`] `pub const fn` accessor's
15243        // `.as_bytes().to_vec()` byte-tail resolve to the same three-
15244        // arm PascalCase wire byte-string emit-set across every arm
15245        // the exhaustive [`super::RestartPolicy::ALL`] slice
15246        // enumerates. Closes the substrate-wide trait-idiomatic byte-
15247        // owned reverse-projection axis on the M2-OTP-shape closed-
15248        // set typed-enum pair the sibling first-mover
15249        // [`super::RestartStrategy`] `From<{Self, &Self}> for Vec<u8>`
15250        // lift (63e5dd0) opened one commit prior, matching the
15251        // trajectory the paired [`AsRef<[u8]>`] borrowed byte-view
15252        // axis campaign already tracked across the same slot pair
15253        // (cd4c4e0 → 98b08fa).
15254        for &variant in RestartPolicy::ALL {
15255            let via_owned_from: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
15256            let via_borrowed_from: Vec<u8> = <Vec<u8> as From<&RestartPolicy>>::from(&variant);
15257            let via_method_bytes: Vec<u8> = variant.as_str().as_bytes().to_vec();
15258            assert_eq!(
15259                via_owned_from, via_method_bytes,
15260                "From<RestartPolicy> for Vec<u8> impl must byte-equal \
15261                 RestartPolicy::as_str().as_bytes().to_vec() on \
15262                 RestartPolicy::{variant:?} — divergence signals a \
15263                 silent detour off the substrate-primitive accessor"
15264            );
15265            assert_eq!(
15266                via_borrowed_from, via_method_bytes,
15267                "From<&RestartPolicy> for Vec<u8> impl must byte-\
15268                 equal RestartPolicy::as_str().as_bytes().to_vec() \
15269                 on RestartPolicy::{variant:?} — divergence signals \
15270                 a silent detour off the substrate-primitive accessor"
15271            );
15272            assert_eq!(
15273                via_owned_from, via_borrowed_from,
15274                "From<RestartPolicy> for Vec<u8> and \
15275                 From<&RestartPolicy> for Vec<u8> must byte-equal \
15276                 each other on RestartPolicy::{variant:?} — \
15277                 divergence signals the owned-input and borrowed-input \
15278                 paths have drifted off the same substrate-primitive \
15279                 as_str accessor"
15280            );
15281            // Cross-axis witness against the paired [`AsRef<[u8]>`]
15282            // borrowed byte-view axis (98b08fa): the byte-owned
15283            // reverse-projection axis must byte-equal the paired
15284            // borrowed byte-view axis by construction — locking the
15285            // byte-view and byte-owned axes together at the substrate-
15286            // primitive accessor.
15287            let borrowed_bytes: &[u8] = <RestartPolicy as AsRef<[u8]>>::as_ref(&variant);
15288            assert_eq!(
15289                via_owned_from,
15290                borrowed_bytes.to_vec(),
15291                "From<RestartPolicy> for Vec<u8> and AsRef<[u8]> for \
15292                 RestartPolicy must resolve to byte-equal byte-tails \
15293                 on RestartPolicy::{variant:?} — divergence signals \
15294                 the byte-owned and byte-view axes have drifted off \
15295                 the same substrate-primitive as_str accessor"
15296            );
15297            // Cross-axis witness against the str-owned reverse-
15298            // projection family's `.into_bytes()` / `.as_bytes().to_vec()`
15299            // byte-tails: every one of `{String, Cow<'static, str>,
15300            // Box<str>, std::sync::Arc<str>}` allocates (or borrows)
15301            // the same PascalCase wire byte-string the substrate-
15302            // primitive accessor emits, so the byte-owned axis must
15303            // byte-equal each of their owned byte-tails by
15304            // construction.
15305            let owned_string: String = <String as From<RestartPolicy>>::from(variant);
15306            assert_eq!(
15307                via_owned_from,
15308                owned_string.into_bytes(),
15309                "From<RestartPolicy> for Vec<u8> and \
15310                 String::from(policy).into_bytes() must resolve to \
15311                 byte-equal byte-tails on RestartPolicy::{variant:?}"
15312            );
15313            let owned_cow: std::borrow::Cow<'static, str> =
15314                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
15315            assert_eq!(
15316                via_owned_from,
15317                owned_cow.as_bytes().to_vec(),
15318                "From<RestartPolicy> for Vec<u8> and \
15319                 From<RestartPolicy> for Cow<'static, str> must \
15320                 resolve to byte-equal byte-tails on \
15321                 RestartPolicy::{variant:?}"
15322            );
15323            let owned_box: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
15324            assert_eq!(
15325                via_owned_from,
15326                owned_box.as_bytes().to_vec(),
15327                "From<RestartPolicy> for Vec<u8> and \
15328                 From<RestartPolicy> for Box<str> must resolve to \
15329                 byte-equal byte-tails on RestartPolicy::{variant:?}"
15330            );
15331            let owned_arc: std::sync::Arc<str> =
15332                <std::sync::Arc<str> as From<RestartPolicy>>::from(variant);
15333            assert_eq!(
15334                via_owned_from,
15335                owned_arc.as_bytes().to_vec(),
15336                "From<RestartPolicy> for Vec<u8> and \
15337                 From<RestartPolicy> for std::sync::Arc<str> must \
15338                 resolve to byte-equal byte-tails on \
15339                 RestartPolicy::{variant:?}"
15340            );
15341        }
15342        // `<T: Into<Vec<u8>>>`-bound-consumer witness on both owned
15343        // and borrowed input shapes: the generic owned-byte-input
15344        // function `generic_owned_bytes_sink` (lifted above per
15345        // `clippy::items_after_statements`) accepts a
15346        // [`super::RestartPolicy`] and a `&RestartPolicy` directly
15347        // through the trait bound, without the caller open-coding
15348        // the three-hop `restart.as_str().as_bytes().to_vec()`
15349        // composition.
15350        for &variant in RestartPolicy::ALL {
15351            let via_generic_owned = generic_owned_bytes_sink(variant);
15352            // Bind the borrowed-input path through an explicit
15353            // `&RestartPolicy` local so the generic-consumer witness
15354            // routes through `From<&RestartPolicy> for Vec<u8>` (T
15355            // binds to `&RestartPolicy`) rather than clippy-collapsing
15356            // the borrow onto the owned-input peer.
15357            let variant_ref: &RestartPolicy = &variant;
15358            let via_generic_borrowed = generic_owned_bytes_sink(variant_ref);
15359            let via_method_bytes = variant.as_str().as_bytes().to_vec();
15360            assert_eq!(
15361                via_generic_owned, via_method_bytes,
15362                "generic `<T: Into<Vec<u8>>>`-bound consumer on \
15363                 RestartPolicy::{variant:?} must yield the same byte-\
15364                 tail RestartPolicy::as_str().as_bytes() returns — \
15365                 divergence signals the byte-owned axis fails to bridge \
15366                 a generic owned-byte-input trait bound to the \
15367                 substrate-primitive accessor"
15368            );
15369            assert_eq!(
15370                via_generic_borrowed, via_method_bytes,
15371                "generic `<T: Into<Vec<u8>>>`-bound consumer on \
15372                 &RestartPolicy::{variant:?} must yield the same byte-\
15373                 tail RestartPolicy::as_str().as_bytes() returns — \
15374                 the borrowed-input surface must resolve to the same \
15375                 as_str dispatch"
15376            );
15377        }
15378        // `std::io::Write::write_all`-shape owned-byte-sink surface
15379        // witness: the `MockOwnedByteSink` (lifted above per
15380        // `clippy::items_after_statements`) mirrors
15381        // `std::io::Write::write_all` /
15382        // `bytes::BytesMut::extend_from_slice`'s `impl Into<Vec<u8>>`-
15383        // bound owned-byte input signature and accepts a
15384        // [`super::RestartPolicy`] directly on both owned and
15385        // borrowed input shapes, routing its byte-tail through the
15386        // substrate-primitive `as_str` accessor — the shape a future
15387        // per-child per-`:restart` audit-log emit composes to fold a
15388        // `:restart` discriminator byte-tag into a downstream owned-
15389        // byte-sink surface.
15390        for &variant in RestartPolicy::ALL {
15391            let mut owned_sink = MockOwnedByteSink::new();
15392            owned_sink.write_all(variant);
15393            let owned_folded = owned_sink.finalize();
15394            assert_eq!(
15395                owned_folded,
15396                variant.as_str().as_bytes(),
15397                "`sink.write_all(restart)`-shape composition on \
15398                 RestartPolicy::{variant:?} must fold the same byte-\
15399                 tail RestartPolicy::as_str().as_bytes() returns"
15400            );
15401            let mut borrowed_sink = MockOwnedByteSink::new();
15402            let variant_ref: &RestartPolicy = &variant;
15403            borrowed_sink.write_all(variant_ref);
15404            let borrowed_folded = borrowed_sink.finalize();
15405            assert_eq!(
15406                borrowed_folded,
15407                variant.as_str().as_bytes(),
15408                "`sink.write_all(&restart)`-shape composition on \
15409                 &RestartPolicy::{variant:?} must fold the same byte-\
15410                 tail RestartPolicy::as_str().as_bytes() returns — \
15411                 the borrowed-input surface must resolve to the same \
15412                 as_str dispatch"
15413            );
15414        }
15415    }
15416
15417    #[test]
15418    fn restart_policy_from_into_owned_cow_bytes_routes_through_as_str_accessor() {
15419        // Fail-before-pass-after byte-parity pin on the newly lifted
15420        // `impl From<RestartPolicy> for std::borrow::Cow<'static, [u8]>`
15421        // and `impl From<&RestartPolicy> for std::borrow::Cow<'static, [u8]>` —
15422        // asserts the trait-idiomatic byte-owned reverse-projection standard-
15423        // library impls and the substrate-primitive
15424        // [`super::RestartPolicy::as_str`] `pub const fn` accessor's
15425        // `.as_bytes()` byte-view resolve to the same three-arm PascalCase
15426        // wire byte-string emit-set across every arm the exhaustive
15427        // [`super::RestartPolicy::ALL`] slice enumerates. Additionally
15428        // asserts the returned `Cow<'static, [u8]>` binds the zero-alloc
15429        // `Cow::Borrowed` arm on both input shapes, because
15430        // `Self::as_str` returns `&'static str` and `.as_bytes()` on it
15431        // preserves the `&'static [u8]` lifetime by construction.
15432        //
15433        // Generic `<T: Into<Cow<'static, [u8]>>>`-bound consumer witness
15434        // helper: a future per-child byte-writer that accepts a
15435        // `Cow<'static, [u8]>` composes on both owned and borrowed input
15436        // shapes without an open-coded three-hop
15437        // `Cow::Borrowed(policy.as_str().as_bytes())` at every call
15438        // site. Lifted to the top of the function per
15439        // `clippy::items_after_statements`.
15440        fn generic_cow_bytes_sink<T: Into<std::borrow::Cow<'static, [u8]>>>(
15441            t: T,
15442        ) -> std::borrow::Cow<'static, [u8]> {
15443            t.into()
15444        }
15445        for &variant in RestartPolicy::ALL {
15446            let via_owned_from: std::borrow::Cow<'static, [u8]> =
15447                <std::borrow::Cow<'static, [u8]> as From<RestartPolicy>>::from(variant);
15448            let via_borrowed_from: std::borrow::Cow<'static, [u8]> =
15449                <std::borrow::Cow<'static, [u8]> as From<&RestartPolicy>>::from(&variant);
15450            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15451            assert_eq!(
15452                via_owned_from.as_ref(),
15453                via_method_bytes,
15454                "From<RestartPolicy> for Cow<'static, [u8]> impl must \
15455                 byte-equal RestartPolicy::as_str().as_bytes() on \
15456                 RestartPolicy::{variant:?} — divergence signals a \
15457                 silent detour off the substrate-primitive accessor"
15458            );
15459            assert_eq!(
15460                via_borrowed_from.as_ref(),
15461                via_method_bytes,
15462                "From<&RestartPolicy> for Cow<'static, [u8]> impl must \
15463                 byte-equal RestartPolicy::as_str().as_bytes() on \
15464                 RestartPolicy::{variant:?} — divergence signals a \
15465                 silent detour off the substrate-primitive accessor"
15466            );
15467            assert!(
15468                matches!(via_owned_from, std::borrow::Cow::Borrowed(_)),
15469                "From<RestartPolicy> for Cow<'static, [u8]> must bind \
15470                 the zero-alloc Cow::Borrowed arm on \
15471                 RestartPolicy::{variant:?} — Self::as_str returns \
15472                 &'static str, so a Cow::Owned arm signals a silent \
15473                 allocation off the substrate primitive"
15474            );
15475            assert!(
15476                matches!(via_borrowed_from, std::borrow::Cow::Borrowed(_)),
15477                "From<&RestartPolicy> for Cow<'static, [u8]> must bind \
15478                 the zero-alloc Cow::Borrowed arm on \
15479                 &RestartPolicy::{variant:?} — Self::as_str returns \
15480                 &'static str, so a Cow::Owned arm signals a silent \
15481                 allocation off the substrate primitive"
15482            );
15483            // Cross-axis partition against the paired byte-owned
15484            // `Vec<u8>` reverse-projection axis on the same enum — the
15485            // two byte-owned reverse-projection axes must byte-agree on
15486            // every arm.
15487            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
15488            assert_eq!(
15489                via_owned_from.as_ref(),
15490                via_vec_bytes.as_slice(),
15491                "From<RestartPolicy> for Cow<'static, [u8]> and \
15492                 From<RestartPolicy> for Vec<u8> must byte-agree on \
15493                 RestartPolicy::{variant:?} — divergence signals the \
15494                 two byte-owned reverse-projection axes have drifted \
15495                 off the same substrate-primitive as_str accessor"
15496            );
15497            // Cross-axis partition against the paired str-side
15498            // `Cow<'static, str>` reverse-projection axis on the same
15499            // enum — the byte-side and str-side Cow<'static, _> axes
15500            // must both bind the Cow::Borrowed arm on every arm (both
15501            // route through Self::as_str's &'static return).
15502            let via_cow_str: std::borrow::Cow<'static, str> =
15503                <std::borrow::Cow<'static, str> as From<RestartPolicy>>::from(variant);
15504            assert_eq!(
15505                via_owned_from.as_ref(),
15506                via_cow_str.as_bytes(),
15507                "From<RestartPolicy> for Cow<'static, [u8]> and \
15508                 From<RestartPolicy> for Cow<'static, str> must \
15509                 byte-agree on RestartPolicy::{variant:?} — \
15510                 divergence signals a silent detour off the shared \
15511                 substrate-primitive as_str accessor"
15512            );
15513        }
15514        for &variant in RestartPolicy::ALL {
15515            let owned_via_generic = generic_cow_bytes_sink(variant);
15516            let variant_ref: &RestartPolicy = &variant;
15517            let borrowed_via_generic = generic_cow_bytes_sink(variant_ref);
15518            assert_eq!(
15519                owned_via_generic.as_ref(),
15520                variant.as_str().as_bytes(),
15521                "<T: Into<Cow<'static, [u8]>>>-bound composition on \
15522                 RestartPolicy::{variant:?} must fold the same byte-\
15523                 tail RestartPolicy::as_str().as_bytes() returns"
15524            );
15525            assert_eq!(
15526                borrowed_via_generic.as_ref(),
15527                variant.as_str().as_bytes(),
15528                "<T: Into<Cow<'static, [u8]>>>-bound composition on \
15529                 &RestartPolicy::{variant:?} must fold the same byte-\
15530                 tail RestartPolicy::as_str().as_bytes() returns"
15531            );
15532        }
15533    }
15534
15535    #[test]
15536    fn restart_policy_from_into_owned_box_bytes_routes_through_as_str_accessor() {
15537        // Fail-before-pass-after byte-parity pin on the newly lifted
15538        // `impl From<RestartPolicy> for Box<[u8]>` — asserts the owned-
15539        // input byte-owned reverse projection routes through the
15540        // substrate-primitive [`super::RestartPolicy::as_str`]
15541        // `pub const fn` accessor's `.as_bytes()` byte-view via
15542        // [`Box::<[u8]>::from`] on the returned `&'static [u8]` and
15543        // resolves to the same three-arm PascalCase wire byte-string
15544        // emit-set across every arm the exhaustive
15545        // [`super::RestartPolicy::ALL`] slice enumerates. Refuses any
15546        // future silent detour that would swap
15547        // `Box::<[u8]>::from(policy.as_str().as_bytes())` for a
15548        // `Vec::<u8>::from(policy).into_boxed_slice()` double-hop, a
15549        // routing through the sibling `fmt::Display` emitter, or a stray
15550        // normalization step that would drop or rebrand a canonical
15551        // PascalCase arm ahead of the boxed byte-emit. Cross-axis
15552        // partition against the paired owned-input byte-owned reverse-
15553        // projection axes ([`Vec<u8>`], [`Cow<'static, [u8]>`]) and the
15554        // paired string-side [`Box<str>`] forward-projection axis on the
15555        // same primitive — all four routes must byte-agree on every arm,
15556        // otherwise the byte-owned reverse-projection matrix has drifted
15557        // off the shared substrate-primitive `as_str` accessor.
15558        for &variant in RestartPolicy::ALL {
15559            let via_owned_from: Box<[u8]> = <Box<[u8]> as From<RestartPolicy>>::from(variant);
15560            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15561            assert_eq!(
15562                via_owned_from.as_ref(),
15563                via_method_bytes,
15564                "From<RestartPolicy> for Box<[u8]> impl must byte-\
15565                 equal RestartPolicy::as_str().as_bytes() on \
15566                 RestartPolicy::{variant:?} — divergence signals a \
15567                 silent detour off the substrate-primitive accessor"
15568            );
15569            // Cross-axis partition against the paired owned-input
15570            // `Vec<u8>` and `Cow<'static, [u8]>` byte-owned reverse-
15571            // projection axes on the same enum — all three axes must
15572            // byte-agree on every arm.
15573            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
15574            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
15575                <std::borrow::Cow<'static, [u8]> as From<RestartPolicy>>::from(variant);
15576            assert_eq!(
15577                via_owned_from.as_ref(),
15578                via_vec_bytes.as_slice(),
15579                "From<RestartPolicy> for Box<[u8]> and \
15580                 From<RestartPolicy> for Vec<u8> must byte-agree on \
15581                 RestartPolicy::{variant:?} — divergence signals the \
15582                 owned-input byte-owned reverse-projection axes have \
15583                 drifted off the same substrate-primitive as_str \
15584                 accessor"
15585            );
15586            assert_eq!(
15587                via_owned_from.as_ref(),
15588                via_cow_bytes.as_ref(),
15589                "From<RestartPolicy> for Box<[u8]> and \
15590                 From<RestartPolicy> for Cow<'static, [u8]> must \
15591                 byte-agree on RestartPolicy::{variant:?} — \
15592                 divergence signals the owned-input byte-owned reverse-\
15593                 projection axes have drifted off the same substrate-\
15594                 primitive as_str accessor"
15595            );
15596            // Cross-axis partition against the paired string-side
15597            // `Box<str>` forward-projection axis on the same enum — the
15598            // byte-side and str-side `Box<_>` axes must byte-agree on
15599            // every arm (both route through Self::as_str's `&'static str`
15600            // return).
15601            let via_box_str: Box<str> = <Box<str> as From<RestartPolicy>>::from(variant);
15602            assert_eq!(
15603                via_owned_from.as_ref(),
15604                via_box_str.as_bytes(),
15605                "From<RestartPolicy> for Box<[u8]> and \
15606                 From<RestartPolicy> for Box<str> must byte-agree on \
15607                 RestartPolicy::{variant:?} — divergence signals a \
15608                 silent detour off the shared substrate-primitive \
15609                 as_str accessor"
15610            );
15611        }
15612    }
15613
15614    #[test]
15615    fn restart_policy_from_borrowed_into_owned_box_bytes_routes_through_as_str_accessor() {
15616        // Fail-before-pass-after byte-parity pin on the newly lifted
15617        // `impl From<&RestartPolicy> for Box<[u8]>` — asserts the
15618        // borrowed-input byte-owned reverse projection routes byte-for-
15619        // byte through the substrate-primitive
15620        // [`super::RestartPolicy::as_str`] `pub const fn` accessor's
15621        // `.as_bytes()` byte-view via [`Box::<[u8]>::from`] on the
15622        // returned `&'static [u8]` on every arm the exhaustive
15623        // [`super::RestartPolicy::ALL`] slice enumerates, preserving
15624        // the source [`super::RestartPolicy`] intact (no move-out).
15625        // Additionally asserts the paired owned-input and borrowed-input
15626        // corners byte-agree on the same arm, closing the
15627        // `{Self, &Self} → Box<[u8]>` byte-owned reverse-projection
15628        // family on this primitive.
15629        //
15630        // Generic `<T: Into<Box<[u8]>>>`-bound consumer witness helper:
15631        // a future per-child byte-writer that accepts a [`Box<[u8]>`]
15632        // composes on both owned and borrowed input shapes without an
15633        // open-coded `Box::<[u8]>::from(policy.as_str().as_bytes())` at
15634        // every call site. Lifted to the top of the function per
15635        // `clippy::items_after_statements`.
15636        fn generic_box_bytes_sink<T: Into<Box<[u8]>>>(t: T) -> Box<[u8]> {
15637            t.into()
15638        }
15639        for &variant in RestartPolicy::ALL {
15640            let via_borrowed_from: Box<[u8]> = <Box<[u8]> as From<&RestartPolicy>>::from(&variant);
15641            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15642            assert_eq!(
15643                via_borrowed_from.as_ref(),
15644                via_method_bytes,
15645                "From<&RestartPolicy> for Box<[u8]> impl must byte-\
15646                 equal RestartPolicy::as_str().as_bytes() on \
15647                 &RestartPolicy::{variant:?} — divergence signals a \
15648                 silent detour off the substrate-primitive accessor"
15649            );
15650            // The borrowed-input impl must not move out of the source —
15651            // the source RestartPolicy must survive the projection.
15652            let survivor: &'static str = variant.as_str();
15653            assert_eq!(
15654                survivor.as_bytes(),
15655                via_method_bytes,
15656                "source &RestartPolicy::{variant:?} must survive \
15657                 borrowed-input projection — a move-out here signals \
15658                 the impl silently dereferences past the borrowed \
15659                 handle"
15660            );
15661            // Cross-corner partition against the paired owned-input
15662            // `Box<[u8]>` axis on the same enum — the two corners must
15663            // byte-agree on every arm, closing the "owned-input move
15664            // vs. borrowed-input clone" bifurcation on the same wire
15665            // byte-string through the `Box<[u8]>` axis.
15666            let via_owned_from: Box<[u8]> = <Box<[u8]> as From<RestartPolicy>>::from(variant);
15667            assert_eq!(
15668                via_borrowed_from.as_ref(),
15669                via_owned_from.as_ref(),
15670                "From<&RestartPolicy> for Box<[u8]> and \
15671                 From<RestartPolicy> for Box<[u8]> must byte-agree on \
15672                 RestartPolicy::{variant:?} — divergence signals the \
15673                 paired owned-input and borrowed-input corners have \
15674                 drifted off the same substrate-primitive as_str \
15675                 accessor"
15676            );
15677            let owned_via_generic = generic_box_bytes_sink(variant);
15678            let variant_ref: &RestartPolicy = &variant;
15679            let borrowed_via_generic = generic_box_bytes_sink(variant_ref);
15680            assert_eq!(
15681                owned_via_generic.as_ref(),
15682                via_method_bytes,
15683                "<T: Into<Box<[u8]>>>-bound composition on \
15684                 RestartPolicy::{variant:?} must fold the same byte-\
15685                 tail RestartPolicy::as_str().as_bytes() returns"
15686            );
15687            assert_eq!(
15688                borrowed_via_generic.as_ref(),
15689                via_method_bytes,
15690                "<T: Into<Box<[u8]>>>-bound composition on \
15691                 &RestartPolicy::{variant:?} must fold the same byte-\
15692                 tail RestartPolicy::as_str().as_bytes() returns"
15693            );
15694        }
15695    }
15696
15697    #[test]
15698    fn restart_policy_from_into_owned_arc_bytes_routes_through_as_str_accessor() {
15699        // Fail-before-pass-after byte-parity pin on the newly lifted
15700        // `impl From<RestartPolicy> for std::sync::Arc<[u8]>` — asserts the
15701        // owned-input byte-owned reverse projection routes through the
15702        // substrate-primitive [`super::RestartPolicy::as_str`]
15703        // `pub const fn` accessor's `.as_bytes()` byte-view via
15704        // [`std::sync::Arc::<[u8]>::from`] on the returned `&'static [u8]`
15705        // and resolves to the same three-arm PascalCase wire byte-string
15706        // emit-set across every arm the exhaustive
15707        // [`super::RestartPolicy::ALL`] slice enumerates. Refuses any
15708        // future silent detour that would swap
15709        // `std::sync::Arc::<[u8]>::from(policy.as_str().as_bytes())` for a
15710        // `Box::<[u8]>::from(policy).into()` double-hop, a routing through
15711        // the sibling `fmt::Display` emitter, or a stray normalization step
15712        // that would drop or rebrand a canonical PascalCase arm ahead of
15713        // the atomic-refcounted byte-emit. Cross-axis partition against
15714        // the paired owned-input byte-owned reverse-projection axes
15715        // ([`Vec<u8>`], [`Cow<'static, [u8]>`], [`Box<[u8]>`]) on the same
15716        // primitive — all four routes must byte-agree on every arm.
15717        for &variant in RestartPolicy::ALL {
15718            let via_owned_from: std::sync::Arc<[u8]> =
15719                <std::sync::Arc<[u8]> as From<RestartPolicy>>::from(variant);
15720            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15721            assert_eq!(
15722                via_owned_from.as_ref(),
15723                via_method_bytes,
15724                "From<RestartPolicy> for Arc<[u8]> impl must byte-\
15725                 equal RestartPolicy::as_str().as_bytes() on \
15726                 RestartPolicy::{variant:?} — divergence signals a \
15727                 silent detour off the substrate-primitive accessor"
15728            );
15729            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
15730            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
15731                <std::borrow::Cow<'static, [u8]> as From<RestartPolicy>>::from(variant);
15732            let via_box_bytes: Box<[u8]> = <Box<[u8]> as From<RestartPolicy>>::from(variant);
15733            assert_eq!(
15734                via_owned_from.as_ref(),
15735                via_vec_bytes.as_slice(),
15736                "From<RestartPolicy> for Arc<[u8]> and \
15737                 From<RestartPolicy> for Vec<u8> must byte-agree on \
15738                 RestartPolicy::{variant:?} — divergence signals the \
15739                 owned-input byte-owned reverse-projection axes have \
15740                 drifted off the same substrate-primitive as_str \
15741                 accessor"
15742            );
15743            assert_eq!(
15744                via_owned_from.as_ref(),
15745                via_cow_bytes.as_ref(),
15746                "From<RestartPolicy> for Arc<[u8]> and \
15747                 From<RestartPolicy> for Cow<'static, [u8]> must byte-\
15748                 agree on RestartPolicy::{variant:?} — divergence \
15749                 signals the owned-input byte-owned reverse-projection \
15750                 axes have drifted off the same substrate-primitive \
15751                 as_str accessor"
15752            );
15753            assert_eq!(
15754                via_owned_from.as_ref(),
15755                via_box_bytes.as_ref(),
15756                "From<RestartPolicy> for Arc<[u8]> and \
15757                 From<RestartPolicy> for Box<[u8]> must byte-agree on \
15758                 RestartPolicy::{variant:?} — divergence signals the \
15759                 owned-input byte-owned reverse-projection axes have \
15760                 drifted off the same substrate-primitive as_str \
15761                 accessor"
15762            );
15763        }
15764    }
15765
15766    #[test]
15767    fn restart_policy_from_borrowed_into_owned_arc_bytes_routes_through_as_str_accessor() {
15768        // Fail-before-pass-after byte-parity pin on the newly lifted
15769        // `impl From<&RestartPolicy> for std::sync::Arc<[u8]>` — asserts
15770        // the borrowed-input byte-owned reverse projection routes byte-
15771        // for-byte through the substrate-primitive
15772        // [`super::RestartPolicy::as_str`] `pub const fn` accessor's
15773        // `.as_bytes()` byte-view via [`std::sync::Arc::<[u8]>::from`] on
15774        // the returned `&'static [u8]` on every arm the exhaustive
15775        // [`super::RestartPolicy::ALL`] slice enumerates, preserving the
15776        // source [`super::RestartPolicy`] intact (no move-out).
15777        // Additionally asserts the paired owned-input and borrowed-input
15778        // corners byte-agree on the same arm, closing the
15779        // `{Self, &Self} → std::sync::Arc<[u8]>` byte-owned reverse-
15780        // projection family on this primitive.
15781        fn generic_arc_bytes_sink<T: Into<std::sync::Arc<[u8]>>>(t: T) -> std::sync::Arc<[u8]> {
15782            t.into()
15783        }
15784        for &variant in RestartPolicy::ALL {
15785            let via_borrowed_from: std::sync::Arc<[u8]> =
15786                <std::sync::Arc<[u8]> as From<&RestartPolicy>>::from(&variant);
15787            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15788            assert_eq!(
15789                via_borrowed_from.as_ref(),
15790                via_method_bytes,
15791                "From<&RestartPolicy> for Arc<[u8]> impl must byte-\
15792                 equal RestartPolicy::as_str().as_bytes() on \
15793                 &RestartPolicy::{variant:?} — divergence signals a \
15794                 silent detour off the substrate-primitive accessor"
15795            );
15796            let survivor: &'static str = variant.as_str();
15797            assert_eq!(
15798                survivor.as_bytes(),
15799                via_method_bytes,
15800                "source &RestartPolicy::{variant:?} must survive \
15801                 borrowed-input projection — a move-out here signals \
15802                 the impl silently dereferences past the borrowed \
15803                 handle"
15804            );
15805            let via_owned_from: std::sync::Arc<[u8]> =
15806                <std::sync::Arc<[u8]> as From<RestartPolicy>>::from(variant);
15807            assert_eq!(
15808                via_borrowed_from.as_ref(),
15809                via_owned_from.as_ref(),
15810                "From<&RestartPolicy> for Arc<[u8]> and \
15811                 From<RestartPolicy> for Arc<[u8]> must byte-agree on \
15812                 RestartPolicy::{variant:?} — divergence signals the \
15813                 paired owned-input and borrowed-input corners have \
15814                 drifted off the same substrate-primitive as_str \
15815                 accessor"
15816            );
15817            let owned_via_generic = generic_arc_bytes_sink(variant);
15818            let variant_ref: &RestartPolicy = &variant;
15819            let borrowed_via_generic = generic_arc_bytes_sink(variant_ref);
15820            assert_eq!(
15821                owned_via_generic.as_ref(),
15822                via_method_bytes,
15823                "<T: Into<Arc<[u8]>>>-bound composition on \
15824                 RestartPolicy::{variant:?} must fold the same byte-\
15825                 tail RestartPolicy::as_str().as_bytes() returns"
15826            );
15827            assert_eq!(
15828                borrowed_via_generic.as_ref(),
15829                via_method_bytes,
15830                "<T: Into<Arc<[u8]>>>-bound composition on \
15831                 &RestartPolicy::{variant:?} must fold the same byte-\
15832                 tail RestartPolicy::as_str().as_bytes() returns"
15833            );
15834        }
15835    }
15836
15837    #[test]
15838    fn restart_policy_from_into_owned_rc_bytes_routes_through_as_str_accessor() {
15839        // Fail-before-pass-after byte-parity pin on the newly lifted
15840        // `impl From<RestartPolicy> for std::rc::Rc<[u8]>` — asserts the
15841        // owned-input byte-owned reverse projection routes through the
15842        // substrate-primitive [`super::RestartPolicy::as_str`]
15843        // `pub const fn` accessor's `.as_bytes()` byte-view via
15844        // [`std::rc::Rc::<[u8]>::from`] on the returned `&'static [u8]`
15845        // and resolves to the same three-arm PascalCase wire byte-string
15846        // emit-set across every arm the exhaustive
15847        // [`super::RestartPolicy::ALL`] slice enumerates. Refuses any
15848        // future silent detour that would swap the substrate-primitive
15849        // routing for a `Box::<[u8]>::from(policy).into()` /
15850        // `Rc::<[u8]>::from(Vec::<u8>::from(policy))` double-hop, a
15851        // routing through the sibling `fmt::Display` emitter, or a stray
15852        // normalization step that would drop or rebrand a canonical
15853        // PascalCase arm ahead of the single-threaded-refcounted byte-
15854        // emit. Cross-axis partition against the paired owned-input
15855        // byte-owned reverse-projection axes ([`Vec<u8>`],
15856        // [`Cow<'static, [u8]>`], [`Box<[u8]>`], and
15857        // [`std::sync::Arc<[u8]>`]) on the same primitive — all five
15858        // routes must byte-agree on every arm, otherwise the byte-owned
15859        // reverse-projection matrix has drifted off the shared substrate-
15860        // primitive `as_str` accessor.
15861        for &variant in RestartPolicy::ALL {
15862            let via_owned_from: std::rc::Rc<[u8]> =
15863                <std::rc::Rc<[u8]> as From<RestartPolicy>>::from(variant);
15864            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15865            assert_eq!(
15866                via_owned_from.as_ref(),
15867                via_method_bytes,
15868                "From<RestartPolicy> for Rc<[u8]> impl must byte-\
15869                 equal RestartPolicy::as_str().as_bytes() on \
15870                 RestartPolicy::{variant:?} — divergence signals a \
15871                 silent detour off the substrate-primitive accessor"
15872            );
15873            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
15874            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
15875                <std::borrow::Cow<'static, [u8]> as From<RestartPolicy>>::from(variant);
15876            let via_box_bytes: Box<[u8]> = <Box<[u8]> as From<RestartPolicy>>::from(variant);
15877            let via_arc_bytes: std::sync::Arc<[u8]> =
15878                <std::sync::Arc<[u8]> as From<RestartPolicy>>::from(variant);
15879            assert_eq!(
15880                via_owned_from.as_ref(),
15881                via_vec_bytes.as_slice(),
15882                "From<RestartPolicy> for Rc<[u8]> and \
15883                 From<RestartPolicy> for Vec<u8> must byte-agree on \
15884                 RestartPolicy::{variant:?} — divergence signals the \
15885                 owned-input byte-owned reverse-projection axes have \
15886                 drifted off the same substrate-primitive as_str \
15887                 accessor"
15888            );
15889            assert_eq!(
15890                via_owned_from.as_ref(),
15891                via_cow_bytes.as_ref(),
15892                "From<RestartPolicy> for Rc<[u8]> and \
15893                 From<RestartPolicy> for Cow<'static, [u8]> must byte-\
15894                 agree on RestartPolicy::{variant:?} — divergence \
15895                 signals the owned-input byte-owned reverse-projection \
15896                 axes have drifted off the same substrate-primitive \
15897                 as_str accessor"
15898            );
15899            assert_eq!(
15900                via_owned_from.as_ref(),
15901                via_box_bytes.as_ref(),
15902                "From<RestartPolicy> for Rc<[u8]> and \
15903                 From<RestartPolicy> for Box<[u8]> must byte-agree on \
15904                 RestartPolicy::{variant:?} — divergence signals the \
15905                 owned-input byte-owned reverse-projection axes have \
15906                 drifted off the same substrate-primitive as_str \
15907                 accessor"
15908            );
15909            assert_eq!(
15910                via_owned_from.as_ref(),
15911                via_arc_bytes.as_ref(),
15912                "From<RestartPolicy> for Rc<[u8]> and \
15913                 From<RestartPolicy> for Arc<[u8]> must byte-agree on \
15914                 RestartPolicy::{variant:?} — divergence signals the \
15915                 owned-input byte-owned reverse-projection axes have \
15916                 drifted off the same substrate-primitive as_str \
15917                 accessor"
15918            );
15919        }
15920    }
15921
15922    #[test]
15923    fn restart_policy_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor() {
15924        // Fail-before-pass-after byte-parity pin on the newly lifted
15925        // `impl From<&RestartPolicy> for std::rc::Rc<[u8]>` — asserts
15926        // the borrowed-input byte-owned reverse projection routes byte-
15927        // for-byte through the substrate-primitive
15928        // [`super::RestartPolicy::as_str`] `pub const fn` accessor's
15929        // `.as_bytes()` byte-view via [`std::rc::Rc::<[u8]>::from`] on the
15930        // returned `&'static [u8]` on every arm the exhaustive
15931        // [`super::RestartPolicy::ALL`] slice enumerates, preserving the
15932        // source [`super::RestartPolicy`] intact (no move-out).
15933        // Additionally asserts the paired owned-input and borrowed-input
15934        // corners byte-agree on the same arm, closing the
15935        // `{Self, &Self} → std::rc::Rc<[u8]>` byte-owned reverse-
15936        // projection family on this primitive.
15937        //
15938        // Generic `<T: Into<std::rc::Rc<[u8]>>>`-bound consumer witness
15939        // helper: a future per-child byte-writer that accepts a
15940        // [`std::rc::Rc<[u8]>`] composes on both owned and borrowed input
15941        // shapes without an open-coded
15942        // `std::rc::Rc::<[u8]>::from(policy.as_str().as_bytes())` at
15943        // every call site. Lifted to the top of the function per
15944        // `clippy::items_after_statements`.
15945        fn generic_rc_bytes_sink<T: Into<std::rc::Rc<[u8]>>>(t: T) -> std::rc::Rc<[u8]> {
15946            t.into()
15947        }
15948        for &variant in RestartPolicy::ALL {
15949            let via_borrowed_from: std::rc::Rc<[u8]> =
15950                <std::rc::Rc<[u8]> as From<&RestartPolicy>>::from(&variant);
15951            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
15952            assert_eq!(
15953                via_borrowed_from.as_ref(),
15954                via_method_bytes,
15955                "From<&RestartPolicy> for Rc<[u8]> impl must byte-\
15956                 equal RestartPolicy::as_str().as_bytes() on \
15957                 &RestartPolicy::{variant:?} — divergence signals a \
15958                 silent detour off the substrate-primitive accessor"
15959            );
15960            let survivor: &'static str = variant.as_str();
15961            assert_eq!(
15962                survivor.as_bytes(),
15963                via_method_bytes,
15964                "source &RestartPolicy::{variant:?} must survive \
15965                 borrowed-input projection — a move-out here signals \
15966                 the impl silently dereferences past the borrowed \
15967                 handle"
15968            );
15969            let via_owned_from: std::rc::Rc<[u8]> =
15970                <std::rc::Rc<[u8]> as From<RestartPolicy>>::from(variant);
15971            assert_eq!(
15972                via_borrowed_from.as_ref(),
15973                via_owned_from.as_ref(),
15974                "From<&RestartPolicy> for Rc<[u8]> and \
15975                 From<RestartPolicy> for Rc<[u8]> must byte-agree on \
15976                 RestartPolicy::{variant:?} — divergence signals the \
15977                 paired owned-input and borrowed-input corners have \
15978                 drifted off the same substrate-primitive as_str \
15979                 accessor"
15980            );
15981            let owned_via_generic = generic_rc_bytes_sink(variant);
15982            let variant_ref: &RestartPolicy = &variant;
15983            let borrowed_via_generic = generic_rc_bytes_sink(variant_ref);
15984            assert_eq!(
15985                owned_via_generic.as_ref(),
15986                via_method_bytes,
15987                "<T: Into<Rc<[u8]>>>-bound composition on \
15988                 RestartPolicy::{variant:?} must fold the same byte-\
15989                 tail RestartPolicy::as_str().as_bytes() returns"
15990            );
15991            assert_eq!(
15992                borrowed_via_generic.as_ref(),
15993                via_method_bytes,
15994                "<T: Into<Rc<[u8]>>>-bound composition on \
15995                 &RestartPolicy::{variant:?} must fold the same byte-\
15996                 tail RestartPolicy::as_str().as_bytes() returns"
15997            );
15998        }
15999    }
16000
16001    #[test]
16002    fn restart_policy_all_enumerates_every_variant_exactly_once() {
16003        // Fail-before-pass-after pin on the [`RestartPolicy::ALL`]
16004        // exhaustive-iteration surface: every variant appears exactly
16005        // once, and the slice length matches the arm count of the
16006        // closed set. Every consumer that walks the accepted-policy
16007        // set (a future `feira supervisor --restart …` CLI-side
16008        // arg-parse's "did you mean" hint, a future M4 admission-
16009        // webhook's per-child rejection body naming the accepted-
16010        // `:restart` list, the [`RestartPolicy::from_wire`] reverse-
16011        // projection consumers that iterate the accept-set for
16012        // diagnostic rendering) reads through this slice, so a future
16013        // arm addition that grows the enum but forgets to grow
16014        // [`Self::ALL`] silently truncates every downstream consumer's
16015        // accept-set at the same pre-addition boundary — this pin
16016        // fails at caixa-core build time on the pairwise-distinct +
16017        // arm-count invariants.
16018        //
16019        // Peer of the sibling [`RestartStrategy::ALL`] (4eec29c) /
16020        // [`crate::CaixaKind::ALL`] (6b1f4fb) /
16021        // [`crate::aplicacao::PlacementStrategy::ALL`] (18c7342) /
16022        // [`crate::aplicacao::RateLimitUnit::ALL`] (6bce03d) /
16023        // [`crate::dep::DepList::ALL`] (45ee563) exhaustive-iteration
16024        // pins on the peer closed-set typed-enum axes.
16025        let all: &[RestartPolicy] = RestartPolicy::ALL;
16026        assert_eq!(
16027            all.len(),
16028            3,
16029            "RestartPolicy::ALL must enumerate every variant of the \
16030             three-arm closed set (Permanent, Temporary, Transient); \
16031             got {all:?}"
16032        );
16033        for (i, a) in all.iter().enumerate() {
16034            for (j, b) in all.iter().enumerate() {
16035                if i != j {
16036                    assert_ne!(
16037                        a, b,
16038                        "RestartPolicy::ALL must carry every variant exactly \
16039                         once — got duplicate {a:?} at indices {i} and {j}"
16040                    );
16041                }
16042            }
16043        }
16044        for variant in [
16045            RestartPolicy::Permanent,
16046            RestartPolicy::Temporary,
16047            RestartPolicy::Transient,
16048        ] {
16049            assert!(
16050                all.contains(&variant),
16051                "RestartPolicy::ALL must contain {variant:?} — a future arm \
16052                 addition that grows the enum but forgets to grow the ALL slice \
16053                 silently truncates every downstream consumer's accept-set at \
16054                 the pre-addition boundary"
16055            );
16056        }
16057    }
16058
16059    #[test]
16060    fn restart_policy_wire_names_covers_every_arm() {
16061        // Load-bearing pin on the substrate-canonical
16062        // [`RestartPolicy::WIRE_NAMES`] exhaustive accept-set roster on
16063        // the `PascalCase` wire byte-string axis: every variant of the
16064        // sibling [`RestartPolicy::ALL`] exhaustive-iteration surface
16065        // must project through [`RestartPolicy::as_str`] onto an entry
16066        // the [`RestartPolicy::WIRE_NAMES`] roster carries, and the
16067        // roster's length must byte-equal `RestartPolicy::ALL.len()` so
16068        // a silent skew between the [`RestartPolicy::as_str`] match's
16069        // arm-set and the roster's arm-set trips here at caixa-core
16070        // test time rather than at a downstream M4
16071        // `mesh.pleme.io/v1alpha1/Supervisor` CR admission-webhook
16072        // rejection body's wire-form `:restart` accepted-set
16073        // enumeration miss / a `feira supervisor --restart …` "did you
16074        // mean" hint drift / a future wasm-operator per-reconcile-step
16075        // diagnostic log line's accepted-wire-form enumeration miss.
16076        // A future arm addition (an OTP-`intrinsic` fourth arm the
16077        // theory
16078        // [`ABSORPTION-ROADMAP`](https://github.com/pleme-io/theory/blob/main/ABSORPTION-ROADMAP.md)
16079        // might reach for once the three canonical OTP restart policies
16080        // stop covering the substrate's discovered load-shape) extends
16081        // [`RestartPolicy::ALL`] as a single edit and this pin sweeps
16082        // the new arm by iteration; the paired
16083        // [`RestartPolicy::WIRE_NAMES`] roster must grow in lockstep or
16084        // this assertion trips. Every entry is further pinned to open
16085        // with an ASCII uppercase byte so a silent collapse of the
16086        // wire-form axis with the peer kebab-case dispatcher-catalog
16087        // axis (an entry byte-identical to a sibling
16088        // [`RestartPolicy::discriminant`] kebab byte-string that would
16089        // let a wire-axis consumer accept the dispatcher-catalog
16090        // vocabulary) trips here rather than at a downstream K8s-CR
16091        // round-trip miss.
16092        //
16093        // Peer of the sibling
16094        // [`restart_strategy_wire_names_covers_every_arm`] (3033f45)
16095        // pin on the first M2 OTP-shape sibling-restart closed-set
16096        // typed enum, the sibling
16097        // [`crate::aplicacao::tests::placement_strategy_wire_names_covers_every_arm`]
16098        // (3e5b194) pin on the first M3 mesh-shape distribution-strategy
16099        // closed-set typed enum, the sibling
16100        // [`crate::kind::tests::caixa_kind_wire_names_covers_every_arm`]
16101        // (bd708bd) pin on the top-level typed-kind discriminator's
16102        // `PascalCase` wire byte-string axis, and the sibling
16103        // [`crate::upgrade::tests::upgrade_instruction_wire_forms_covers_every_arm`]
16104        // (cc42c0e) /
16105        // [`crate::upgrade::tests::upgrade_instruction_lisp_forms_covers_every_arm`]
16106        // (1898d77) pins on the OTP-appup discriminator's two-axis
16107        // roster split — the same closed-set exhaustive-roster coverage
16108        // discipline extended here onto the second and final M2
16109        // OTP-shape sibling-enum on the caixa surface, closing the
16110        // per-child restart-decision-policy axis paired with the peer
16111        // per-supervisor sibling-restart-strategy axis on the same M2
16112        // `:supervisor` slot.
16113        //
16114        // Fail-before-pass-after locally verified by mutating one arm
16115        // of the paired [`crate::render::SUPERVISOR_CHILD_RESTART_*`]
16116        // const family (e.g. dropping the trailing `t` from
16117        // `"Permanent"` → `"Permanen"`) — the length pin still passes
16118        // but the `contains` check fires on the mutated arm; and by
16119        // shortening the roster to two entries — the length pin fires
16120        // first.
16121        assert_eq!(
16122            RestartPolicy::WIRE_NAMES.len(),
16123            RestartPolicy::ALL.len(),
16124            "RestartPolicy::WIRE_NAMES.len() must byte-equal \
16125             RestartPolicy::ALL.len() — a mismatch means the roster \
16126             and the enum's arm-set have drifted; downstream consumers \
16127             that fan through both will silently disagree on the \
16128             accepted arm-set"
16129        );
16130        for &variant in RestartPolicy::ALL {
16131            let wire = variant.as_str();
16132            assert!(
16133                RestartPolicy::WIRE_NAMES.contains(&wire),
16134                "RestartPolicy::{variant:?}.as_str() = {wire:?} must \
16135                 be a member of RestartPolicy::WIRE_NAMES — the \
16136                 emitter and the roster have drifted out of lockstep"
16137            );
16138        }
16139        for tag in RestartPolicy::WIRE_NAMES {
16140            let first = tag.chars().next().unwrap_or_else(|| {
16141                panic!(
16142                    "RestartPolicy::WIRE_NAMES entry {tag:?} must be \
16143                     a non-empty PascalCase byte-string"
16144                )
16145            });
16146            assert!(
16147                first.is_ascii_uppercase(),
16148                "RestartPolicy::WIRE_NAMES entry {tag:?} must open \
16149                 with an ASCII uppercase byte (PascalCase wire form) — \
16150                 a lowercase entry would collide the wire-form axis \
16151                 with the peer kebab-case dispatcher-catalog axis \
16152                 [`RestartPolicy::discriminant`] serves"
16153            );
16154        }
16155    }
16156
16157    #[test]
16158    fn restart_policy_from_wire_accepts_every_lifted_constant() {
16159        // Fail-before-pass-after pin on the forward accept-set of the
16160        // [`RestartPolicy::from_wire`] reverse projection: every
16161        // canonical [`crate::render::SUPERVISOR_CHILD_RESTART_*`]
16162        // constant the [`RestartPolicy::as_str`] emitter walks parses
16163        // back to its paired variant. Any future arm addition that
16164        // grows the emitter's `as_str` match but forgets to grow the
16165        // parser's `from_wire` match silently splits the two halves of
16166        // the round-trip — the wire byte-string one non-serde consumer
16167        // parses from the one the emitter wrote — with the failure
16168        // surfacing at the operator's reconcile posture (a `:temporary`
16169        // `oneShot` child restarted on clean exit, a `:transient` child
16170        // restarted after clean completion) far from the rebrand
16171        // commit. Pinning the three-arm accept-set here catches the
16172        // drift at caixa-core build time.
16173        //
16174        // Peer of the sibling [`RestartStrategy::from_wire`] (4eec29c)
16175        // + [`crate::CaixaKind::from_wire`] (2aa6d23)
16176        // + [`crate::aplicacao::PlacementStrategy::from_wire`] (18c7342)
16177        // accept-set pins on the peer closed-set typed-enum `str → Self`
16178        // axes.
16179        for (wire, expected) in [
16180            (
16181                crate::render::SUPERVISOR_CHILD_RESTART_PERMANENT,
16182                RestartPolicy::Permanent,
16183            ),
16184            (
16185                crate::render::SUPERVISOR_CHILD_RESTART_TEMPORARY,
16186                RestartPolicy::Temporary,
16187            ),
16188            (
16189                crate::render::SUPERVISOR_CHILD_RESTART_TRANSIENT,
16190                RestartPolicy::Transient,
16191            ),
16192        ] {
16193            let parsed = RestartPolicy::from_wire(wire).unwrap_or_else(|| {
16194                panic!(
16195                    "RestartPolicy::from_wire({wire:?}) must accept every \
16196                     SUPERVISOR_CHILD_RESTART_* constant — got None for the \
16197                     lifted canonical byte-string that RestartPolicy::{expected:?} \
16198                     serializes as under SUPERVISOR_CHILD_KEY_RESTART"
16199                )
16200            });
16201            assert_eq!(
16202                parsed, expected,
16203                "RestartPolicy::from_wire({wire:?}) must return \
16204                 RestartPolicy::{expected:?}; got RestartPolicy::{parsed:?}"
16205            );
16206        }
16207    }
16208
16209    #[test]
16210    fn restart_policy_from_wire_round_trips_through_as_str() {
16211        // Fail-before-pass-after pin on the closed round-trip between
16212        // the forward [`RestartPolicy::as_str`] emitter and the
16213        // reverse [`RestartPolicy::from_wire`] parser: for every
16214        // variant in [`RestartPolicy::ALL`], parsing the emitter's
16215        // output must return exactly the same variant. Any per-arm
16216        // divergence — a future arm added to `as_str` but not
16217        // `from_wire`, an accidental copy-paste flip in one but not
16218        // the other — silently splits the emit and parse halves and
16219        // the failure surfaces at consumer parse time far from the
16220        // drift site. The `ALL`-iterating shape means a future arm
16221        // addition picks up the coverage by construction.
16222        //
16223        // Peer of the sibling
16224        // [`restart_strategy_from_wire_round_trips_through_as_str`]
16225        // (4eec29c) round-trip pin on
16226        // [`RestartStrategy::from_wire`] and the M3
16227        // [`crate::aplicacao::tests::placement_strategy_from_wire_round_trips_through_as_str`]
16228        // (18c7342) round-trip pin on
16229        // [`crate::aplicacao::PlacementStrategy::from_wire`].
16230        for &variant in RestartPolicy::ALL {
16231            let wire = variant.as_str();
16232            let parsed = RestartPolicy::from_wire(wire).unwrap_or_else(|| {
16233                panic!(
16234                    "RestartPolicy::from_wire(RestartPolicy::{variant:?}.as_str()) \
16235                     must be Some({variant:?}) — the two halves of the round-trip \
16236                     dispatch on the same lifted SUPERVISOR_CHILD_RESTART_* consts; \
16237                     got None on wire byte-string {wire:?}"
16238                )
16239            });
16240            assert_eq!(
16241                parsed, variant,
16242                "RestartPolicy::from_wire(RestartPolicy::{variant:?}.as_str()) \
16243                 must round-trip to the same variant; got {parsed:?}"
16244            );
16245        }
16246    }
16247
16248    #[test]
16249    fn restart_policy_from_wire_rejects_unknown_byte_strings() {
16250        // Fail-before-pass-after pin on the closed-set refusal
16251        // discipline of [`RestartPolicy::from_wire`]: every
16252        // byte-string outside the three-arm accept-set returns `None`
16253        // rather than silently collapsing onto the [`Default`]
16254        // (`Permanent`) arm or an arbitrary neighbor. The refusal set
16255        // exercised here sweeps the load-bearing drift shapes: the
16256        // empty string (a stripped serde-attribute drift), all-
16257        // whitespace strings (the canonical text-editor accidental
16258        // padding shape), the kebab-case dispatcher-catalog identities
16259        // (`"permanent"` / `"temporary"` / `"transient"` — the
16260        // [`gen_platform::FromStrKind`]-derived [`std::str::FromStr`]
16261        // accept-set, which parses the *other* axis of this enum's
16262        // two-axis split and must not leak into the `from_wire`
16263        // PascalCase-wire accept-set — a lowercase leak here would
16264        // silently accept the operator's kebab-case
16265        // dispatcher-catalog probe under the wire-axis parser and mis-
16266        // route a `:permanent` intent), the padded canonical scalar
16267        // (`" Permanent "`), the trailing-newline shapes
16268        // (`"Permanent\n"`), the uppercase-single-word forms
16269        // (`"PERMANENT"`), and neighboring-but-unknown arms
16270        // (`"Restart"` — the canonical typo direction toward the
16271        // sibling [`RestartStrategy`] enum's own wire-arm namespace).
16272        //
16273        // Peer of the sibling
16274        // [`restart_strategy_from_wire_rejects_unknown_byte_strings`]
16275        // (4eec29c) +
16276        // [`crate::kind::tests::caixa_kind_from_wire_rejects_unknown_byte_strings`]
16277        // (2aa6d23) +
16278        // [`crate::aplicacao::tests::placement_strategy_from_wire_rejects_unknown_byte_strings`]
16279        // (18c7342) refusal pins on the peer closed-set typed-enum
16280        // axes.
16281        for bad in [
16282            "",
16283            " ",
16284            "\n",
16285            "\t",
16286            "permanent",
16287            "temporary",
16288            "transient",
16289            "PERMANENT",
16290            "TEMPORARY",
16291            "TRANSIENT",
16292            "Permanents",
16293            "Permanent ",
16294            " Permanent",
16295            " Transient ",
16296            "Permanent\n",
16297            "perma",
16298            "Trans",
16299            "OneForOne",
16300            "Restart",
16301            "?",
16302        ] {
16303            assert!(
16304                RestartPolicy::from_wire(bad).is_none(),
16305                "RestartPolicy::from_wire({bad:?}) must return None — the \
16306                 parser's accept-set is exactly the three RestartPolicy::as_str \
16307                 outputs (Permanent, Temporary, Transient), and this \
16308                 byte-string is outside that closed set"
16309            );
16310        }
16311    }
16312
16313    #[test]
16314    fn restart_policy_from_wire_matches_serialize_derive_wire_byte_string() {
16315        // Fail-before-pass-after pin on the fourth path of the four-path
16316        // convergence: `from_wire` (the reverse projection) inverts the
16317        // `Serialize` derive's wire byte-string on every variant.
16318        // Together with the pre-existing three-path convergence
16319        // (`Display` + `as_str` + `Serialize` all resolve to the same
16320        // lifted [`crate::render::SUPERVISOR_CHILD_RESTART_*`] const,
16321        // pinned by
16322        // [`restart_policy_display_matches_serialized_wire_byte_string`])
16323        // this closes the round-trip: the wire byte-string the
16324        // `Serialize` derive emits parses back to the same variant
16325        // through `from_wire`, so any future serde-attribute or variant-
16326        // rename drift on the emit half now surfaces as a matched drift
16327        // on the parse half at caixa-core build time — the two halves
16328        // migrate as a unit through the lifted consts on any future
16329        // rename, and the round-trip cannot silently split.
16330        //
16331        // Peer of the sibling
16332        // [`restart_strategy_from_wire_matches_serialize_derive_wire_byte_string`]
16333        // (4eec29c) wire-format pin on
16334        // [`RestartStrategy::from_wire`] and the M3
16335        // [`crate::aplicacao::tests::placement_strategy_from_wire_matches_serialize_derive_wire_byte_string`]
16336        // (18c7342) wire-format pin on
16337        // [`crate::aplicacao::PlacementStrategy::from_wire`].
16338        for &variant in RestartPolicy::ALL {
16339            let wire = serde_json::to_string(&variant).unwrap();
16340            let unquoted = wire
16341                .strip_prefix('"')
16342                .and_then(|s| s.strip_suffix('"'))
16343                .expect("serialized RestartPolicy is a JSON string");
16344            let parsed = RestartPolicy::from_wire(unquoted).unwrap_or_else(|| {
16345                panic!(
16346                    "RestartPolicy::from_wire({unquoted:?}) must accept the \
16347                     Serialize derive's wire byte-string for \
16348                     RestartPolicy::{variant:?} — the four-path convergence \
16349                     (Display + as_str + Serialize + from_wire) resolves through \
16350                     the same lifted SUPERVISOR_CHILD_RESTART_* const; got None"
16351                )
16352            });
16353            assert_eq!(
16354                parsed, variant,
16355                "RestartPolicy::from_wire of the Serialize derive's wire \
16356                 byte-string for RestartPolicy::{variant:?} must round-trip \
16357                 to the same variant; got {parsed:?}"
16358            );
16359        }
16360    }
16361
16362    // ── drift-detection: ChildSpec::nome accessor pins ────────────────────
16363    //
16364    // The M2 supervisor-tree sibling of the M3 `Membro::nome` (4a32abf) pin
16365    // pair (`membro_nome_returns_caixa_byte_equal_across_permutations` +
16366    // `membro_nome_borrows_from_caixa_storage`) — extended here to the M2
16367    // per-`:children` child-caixa `:nome` axis, sibling to the first M2
16368    // slot scalar accessor `UpgradeFromEntry::prior_versao` (75d27a8) on
16369    // the peer per-`:upgrade-from :from` axis. The three pins jointly
16370    // brace the accessor against every future silent detour that would
16371    // desynchronize it from the raw `.caixa` field access every consumer
16372    // previously open-coded.
16373
16374    #[test]
16375    fn child_spec_nome_returns_caixa_byte_equal_across_permutations() {
16376        // The canonical per-`:children` child-caixa `:nome`-scalar pin:
16377        // [`ChildSpec::nome`] must return the `:children :caixa` field
16378        // byte-for-byte across every DNS-1123-label value the upstream
16379        // [`crate::render::require_valid_dns_1123_label`] gate at
16380        // `SupervisorSpec::validate` admits. Peer of the sibling
16381        // `membro_nome_returns_caixa_byte_equal_across_permutations`
16382        // (4a32abf) pin on the M3 per-`:membros` axis — same "the
16383        // substrate-primitive accessor must byte-equal the raw field
16384        // access verbatim across every author-declared value" discipline
16385        // extended to the M2 supervisor-tree per-`:children` arm. Pins
16386        // against a future silent detour that re-normalized the child
16387        // identity (an accidental `.to_lowercase()` — every `:children
16388        // :caixa` is validated as a DNS-1123 label upstream, so any
16389        // re-normalization is redundant + a drift surface between the
16390        // validator and the accessor), a namespace-prefix rewrite (an
16391        // accidental `format!("{namespace}/{caixa}")` per-CR
16392        // fully-qualified rewrite that didn't land on the peer axes), or
16393        // a per-cluster alias stamp the future wasm-operator's
16394        // hierarchical reconciliation scheduler authors on one consumer
16395        // without the others. Five values sweep the accept-set the
16396        // DNS-1123 gate upstream admits (short single-word / dashed /
16397        // v-suffixed / mixed-digit child names).
16398        for name in [
16399            "worker",
16400            "cache-server",
16401            "scratch-job",
16402            "orders-v2",
16403            "session-8080",
16404        ] {
16405            let c = ChildSpec {
16406                caixa: name.into(),
16407                versao: "^0.1".into(),
16408                restart: RestartPolicy::Permanent,
16409            };
16410            assert_eq!(
16411                c.nome(),
16412                name,
16413                "ChildSpec::nome must return :children :caixa verbatim \
16414                 (got {:?}, expected {name:?})",
16415                c.nome(),
16416            );
16417            assert_eq!(
16418                c.nome(),
16419                c.caixa.as_str(),
16420                "ChildSpec::nome must byte-equal the .caixa field access",
16421            );
16422        }
16423    }
16424
16425    #[test]
16426    fn child_spec_nome_borrows_from_caixa_storage() {
16427        // The borrow-not-copy pin: [`ChildSpec::nome`] must return a
16428        // `&str` slice that borrows from the typed slot's own [`String`]
16429        // storage — same-address invariant with `c.caixa.as_str()`. Pins
16430        // against a future silent detour that allocated a fresh `String`
16431        // (`self.caixa.clone()` in the body would type-check but silently
16432        // drop the borrow, and every downstream consumer that assumed
16433        // the returned slice outlives `&self` would break on a stale-
16434        // reference use-after-free — the [`crate::render::insert_first_seen`]
16435        // dedup key at [`SupervisorSpec::validate`], the
16436        // [`validate_no_self_supervision`] equality check against the
16437        // parent's `:nome` string slice, the DNS-1123 gate's `&str`
16438        // borrow — each would silently misbehave if this accessor
16439        // produced a detached copy). Peer of the sibling
16440        // `membro_nome_borrows_from_caixa_storage` (4a32abf) pin on the
16441        // M3 per-`:membros` axis and the
16442        // `prior_versao_borrows_from_from_storage` (75d27a8) pin on the
16443        // first M2 slot scalar accessor.
16444        let c = ChildSpec {
16445            caixa: "worker".into(),
16446            versao: "^0.1".into(),
16447            restart: RestartPolicy::Permanent,
16448        };
16449        let name = c.nome();
16450        let caixa_slice = c.caixa.as_str();
16451        assert_eq!(
16452            name.as_ptr(),
16453            caixa_slice.as_ptr(),
16454            "ChildSpec::nome must borrow from the .caixa String's backing \
16455             storage — a fresh allocation here means the accessor no \
16456             longer names the substrate-primitive typed dispatch and \
16457             every downstream consumer would silently carry a detached \
16458             copy",
16459        );
16460        assert_eq!(
16461            name.len(),
16462            caixa_slice.len(),
16463            "ChildSpec::nome and .caixa.as_str() must byte-equal in length \
16464             as well as in address",
16465        );
16466    }
16467
16468    #[test]
16469    fn validate_gates_child_nome_through_lifted_accessor() {
16470        // Bilateral coherence pin: every `:children :caixa` that
16471        // [`SupervisorSpec::validate`] accepts is one
16472        // [`crate::render::require_valid_dns_1123_label`] accepts on the
16473        // accessor-projected value, and vice versa on the reject side.
16474        // This closes the "the validator reads through the accessor"
16475        // contract structurally — a future silent detour that made the
16476        // accessor return a different byte-string than the validator
16477        // gates against would surface here as a coverage mismatch, not
16478        // as an apply-time DNS-1123 rejection at
16479        // `metadata.name: Invalid value` far from the caixa.lisp source.
16480        // Peer of the M2 sibling
16481        // `validate_parses_prior_versao_through_lifted_accessor`
16482        // (75d27a8) on the per-`:upgrade-from :from` axis and the M3
16483        // `validate_membros` peer discipline.
16484        //
16485        // Accept-set sweep: five DNS-1123-label values the upstream gate
16486        // admits.
16487        for ok_name in ["a", "worker", "cache-server", "orders-v2", "svc-8080"] {
16488            let s = SupervisorSpec {
16489                children: vec![ChildSpec {
16490                    caixa: ok_name.into(),
16491                    versao: "^0.1".into(),
16492                    restart: RestartPolicy::Permanent,
16493                }],
16494                ..SupervisorSpec::default()
16495            };
16496            s.validate().unwrap_or_else(|e| {
16497                panic!(
16498                    "SupervisorSpec::validate must accept :children :caixa {ok_name:?} \
16499                     (upstream DNS-1123 gate accepts it): got {e:?}",
16500                );
16501            });
16502            let c = ChildSpec {
16503                caixa: ok_name.into(),
16504                versao: "^0.1".into(),
16505                restart: RestartPolicy::Permanent,
16506            };
16507            crate::render::require_valid_dns_1123_label(c.nome(), || (), |_reason| ())
16508                .unwrap_or_else(|()| {
16509                    panic!(
16510                        "require_valid_dns_1123_label must accept the accessor-projected \
16511                     :children :caixa {ok_name:?}",
16512                    );
16513                });
16514        }
16515        // Reject-set sweep: five DNS-1123-label-violating shapes the
16516        // upstream gate refuses (empty / uppercase / underscore / dot /
16517        // leading-hyphen). Every rejection at the validator must
16518        // correspond to a rejection when the accessor's projected value
16519        // is fed back through the shared gate.
16520        for bad_name in ["", "Worker", "my_worker", "team.worker", "-worker"] {
16521            let s = SupervisorSpec {
16522                children: vec![ChildSpec {
16523                    caixa: bad_name.into(),
16524                    versao: "^0.1".into(),
16525                    restart: RestartPolicy::Permanent,
16526                }],
16527                ..SupervisorSpec::default()
16528            };
16529            let err = s.validate().unwrap_err();
16530            assert!(
16531                matches!(
16532                    err,
16533                    SupervisorError::EmptyChildName | SupervisorError::ChildCaixaInvalid { .. }
16534                ),
16535                "SupervisorSpec::validate must reject :children :caixa {bad_name:?} \
16536                 via the DNS-1123 gate: got {err:?}",
16537            );
16538            let c = ChildSpec {
16539                caixa: bad_name.into(),
16540                versao: "^0.1".into(),
16541                restart: RestartPolicy::Permanent,
16542            };
16543            assert!(
16544                crate::render::require_valid_dns_1123_label(c.nome(), || (), |_reason| (),)
16545                    .is_err(),
16546                "require_valid_dns_1123_label must reject the accessor-projected \
16547                 :children :caixa {bad_name:?}",
16548            );
16549        }
16550    }
16551
16552    // ── drift-detection: ChildSpec::versao_requirement accessor pins ──────
16553    //
16554    // Sibling of the peer per-`:membros` `membro_versao_requirement_*`
16555    // (a40b0e3) pin pair on the M3 mesh-slot surface — extended here to the
16556    // M2 supervisor-tree per-`:children` child-`:versao` axis, sibling to
16557    // the just-landed [`ChildSpec::nome`] (57c61d0) child-`:nome` pin
16558    // trio on the peer per-`:children` `String`-carry axis. The three pins
16559    // jointly brace the accessor against every future silent detour that
16560    // would desynchronize it from the raw `.versao` field access the
16561    // requirement gate + error carrier previously open-coded.
16562    //
16563    // Closes the last unlifted per-`:children` `String`-carry axis: the
16564    // pair (`nome`, `versao_requirement`) now jointly projects the
16565    // (`.caixa`, `.versao`) field pair every OTP-shape supervisor-tree
16566    // consumer that fans on per-child identity + version pin reads,
16567    // matching the peer M3 (`Membro::nome`, `Membro::versao_requirement`)
16568    // pair discipline verbatim.
16569    #[test]
16570    fn child_spec_versao_requirement_returns_versao_byte_equal_across_permutations() {
16571        // The canonical per-`:children` child-`:versao`-scalar pin:
16572        // [`ChildSpec::versao_requirement`] must return the `:children
16573        // :versao` field byte-for-byte across every Cargo-shaped semver
16574        // requirement value the upstream
16575        // [`crate::render::require_valid_versao_requirement`] gate admits.
16576        // Peer of the sibling
16577        // `membro_versao_requirement_returns_versao_byte_equal_across_permutations`
16578        // (a40b0e3) pin on the M3 per-`:membros` axis — same "the
16579        // substrate-primitive accessor must byte-equal the raw field
16580        // access verbatim across every author-declared value" discipline
16581        // extended to the M2 supervisor-tree per-`:children` arm. Pins
16582        // against a future silent detour that re-canonicalized the
16583        // requirement (an accidental `.to_string()` via
16584        // [`crate::version::parse_requirement`] → [`std::fmt::Display`]
16585        // round-trip that collapsed `"^0.1"` to `">=0.1, <0.2"` and
16586        // silently drifted the error carrier's quoted requirement away
16587        // from the source `caixa.lisp`, an accidental whitespace trim on
16588        // `"^ 0.1"` that no consumer ever produced from the field-access
16589        // side, an accidental per-cluster lacre-projected concrete-version
16590        // rewrite that didn't land on the peer requirement-gate call).
16591        // Five values sweep the accept-set the shared
16592        // [`crate::render::require_valid_versao_requirement`] gate admits
16593        // (caret / tilde / exact / wildcard / bare-major).
16594        for req in ["^0.1", "~0.1.2", "0.1.0", "*", "^1"] {
16595            let c = ChildSpec {
16596                caixa: "worker".into(),
16597                versao: req.into(),
16598                restart: RestartPolicy::Permanent,
16599            };
16600            assert_eq!(
16601                c.versao_requirement(),
16602                req,
16603                "ChildSpec::versao_requirement must return :children :versao \
16604                 verbatim (got {:?}, expected {req:?})",
16605                c.versao_requirement(),
16606            );
16607            assert_eq!(
16608                c.versao_requirement(),
16609                c.versao.as_str(),
16610                "ChildSpec::versao_requirement must byte-equal the .versao \
16611                 field access",
16612            );
16613        }
16614    }
16615
16616    #[test]
16617    fn child_spec_versao_requirement_borrows_from_versao_storage() {
16618        // The borrow-not-copy pin: [`ChildSpec::versao_requirement`] must
16619        // return a `&str` slice that borrows from the typed slot's own
16620        // [`String`] storage — same-address invariant with
16621        // `c.versao.as_str()`. Pins against a future silent detour that
16622        // allocated a fresh `String` (`self.versao.clone()` in the body
16623        // would type-check but silently drop the borrow, and every
16624        // downstream consumer that assumed the returned slice outlives
16625        // `&self` — the [`crate::render::require_valid_versao_requirement`]
16626        // gate's `&str` borrow, the [`SupervisorError::ChildVersaoInvalid`]
16627        // `.to_string()` carrier's byte-length assumption — would silently
16628        // misbehave if this accessor produced a detached copy). Peer of
16629        // the sibling `child_spec_nome_borrows_from_caixa_storage`
16630        // (57c61d0) pin on the per-`:children` `:nome` axis and the M3
16631        // `membro_versao_requirement_borrows_from_versao_storage` (a40b0e3)
16632        // pin on the peer per-`:membros` `:versao` axis.
16633        let c = ChildSpec {
16634            caixa: "worker".into(),
16635            versao: "^0.1".into(),
16636            restart: RestartPolicy::Permanent,
16637        };
16638        let req = c.versao_requirement();
16639        let versao_slice = c.versao.as_str();
16640        assert_eq!(
16641            req.as_ptr(),
16642            versao_slice.as_ptr(),
16643            "ChildSpec::versao_requirement must borrow from the .versao \
16644             String's backing storage — a fresh allocation here means the \
16645             accessor no longer names the substrate-primitive typed \
16646             dispatch and every downstream consumer would silently carry \
16647             a detached copy",
16648        );
16649        assert_eq!(
16650            req.len(),
16651            versao_slice.len(),
16652            "ChildSpec::versao_requirement and .versao.as_str() must \
16653             byte-equal in length as well as in address",
16654        );
16655    }
16656
16657    #[test]
16658    fn validate_gates_child_versao_through_lifted_accessor() {
16659        // Bilateral coherence pin: every `:children :versao` that
16660        // [`SupervisorSpec::validate`] accepts is one
16661        // [`crate::render::require_valid_versao_requirement`] accepts on
16662        // the accessor-projected value, and vice versa on the reject side.
16663        // This closes the "the validator reads through the accessor"
16664        // contract structurally — a future silent detour that made the
16665        // accessor return a different byte-string than the validator gates
16666        // against would surface here as a coverage mismatch, not as a
16667        // resolver-time semver-parse rejection at lacre-closure time far
16668        // from the caixa.lisp source. Peer of the sibling
16669        // `validate_gates_child_nome_through_lifted_accessor` (57c61d0) on
16670        // the per-`:children :caixa` axis and the M2
16671        // `validate_parses_prior_versao_through_lifted_accessor` (75d27a8)
16672        // on the peer per-`:upgrade-from :from` axis.
16673        //
16674        // Accept-set sweep: five Cargo-shaped semver requirement values
16675        // the upstream gate admits (caret / tilde / exact / wildcard /
16676        // bare-major).
16677        for ok_req in ["^0.1", "~0.1.2", "0.1.0", "*", "^1"] {
16678            let s = SupervisorSpec {
16679                children: vec![ChildSpec {
16680                    caixa: "worker".into(),
16681                    versao: ok_req.into(),
16682                    restart: RestartPolicy::Permanent,
16683                }],
16684                ..SupervisorSpec::default()
16685            };
16686            s.validate().unwrap_or_else(|e| {
16687                panic!(
16688                    "SupervisorSpec::validate must accept :children :versao {ok_req:?} \
16689                     (upstream versao-requirement gate accepts it): got {e:?}",
16690                );
16691            });
16692            let c = ChildSpec {
16693                caixa: "worker".into(),
16694                versao: ok_req.into(),
16695                restart: RestartPolicy::Permanent,
16696            };
16697            crate::render::require_valid_versao_requirement(
16698                c.versao_requirement(),
16699                || (),
16700                |_reason| (),
16701            )
16702            .unwrap_or_else(|()| {
16703                panic!(
16704                    "require_valid_versao_requirement must accept the accessor-projected \
16705                     :children :versao {ok_req:?}",
16706                );
16707            });
16708        }
16709        // Reject-set sweep: five requirement-violating shapes the upstream
16710        // gate refuses. The empty string closes the empty-first arm of the
16711        // shared [`crate::render::require_valid_versao_requirement`]
16712        // cascade; the four non-empty arms exercise distinct semver-parse
16713        // failure modes the M3 peer per-`:membros` reject-set already pins
16714        // (`rejects_invalid_membro_versao_requirement` on `^bad-version`,
16715        // `rejects_membro_versao_with_double_caret_typo` on `^^0.1`,
16716        // `rejects_membro_versao_with_v_prefixed_tag` on `v0.1`) — the
16717        // shared parser routing means the same reject-set must fail
16718        // identically at the M2 supervisor-tree per-`:children` accessor
16719        // arm here. Every rejection at the validator must correspond to a
16720        // rejection when the accessor's projected value is fed back
16721        // through the shared gate.
16722        //
16723        // (Bare partial magnitudes like `"0.1"` and bare identifiers like
16724        // `"not-a-semver"` are intentionally *not* in the reject-set: the
16725        // semver crate accepts `"0.1"` as an implicit `^0.1` requirement,
16726        // and the identifier-tail arm's grammar admits some non-canonical
16727        // shapes — matching what the M3 peer test suite already documents
16728        // as the shared parser's accept-set edges.)
16729        for bad_req in ["", "v0.1.0", "^bad-version", "^^0.1", "v0.1"] {
16730            let s = SupervisorSpec {
16731                children: vec![ChildSpec {
16732                    caixa: "worker".into(),
16733                    versao: bad_req.into(),
16734                    restart: RestartPolicy::Permanent,
16735                }],
16736                ..SupervisorSpec::default()
16737            };
16738            let err = s.validate().unwrap_err();
16739            assert!(
16740                matches!(
16741                    err,
16742                    SupervisorError::EmptyChildVersion { .. }
16743                        | SupervisorError::ChildVersaoInvalid { .. }
16744                ),
16745                "SupervisorSpec::validate must reject :children :versao {bad_req:?} \
16746                 via the versao-requirement gate: got {err:?}",
16747            );
16748            let c = ChildSpec {
16749                caixa: "worker".into(),
16750                versao: bad_req.into(),
16751                restart: RestartPolicy::Permanent,
16752            };
16753            assert!(
16754                crate::render::require_valid_versao_requirement(
16755                    c.versao_requirement(),
16756                    || (),
16757                    |_reason| (),
16758                )
16759                .is_err(),
16760                "require_valid_versao_requirement must reject the accessor-projected \
16761                 :children :versao {bad_req:?}",
16762            );
16763        }
16764    }
16765
16766    // ── per-`:children` `:restart` typed-accessor coherence pins ──────────
16767    //
16768    // The [`ChildSpec::restart`] accessor lift closes the last unlifted
16769    // per-`:children` axis (the pair `nome()` + `versao_requirement()`
16770    // already project the `String`-carry `(caixa, versao)` fields; the
16771    // `Copy`-composite-enum `restart` field is the third and final axis).
16772    // Peer of the sibling per-`:supervisor` [`SupervisorSpec::estrategia`]
16773    // (eafb619) `Copy`-return [`RestartStrategy`] sibling-restart-strategy
16774    // scalar accessor and the M3 mesh-slot [`crate::Placement::estrategia`]
16775    // (921fe1b) `Copy`-return [`crate::PlacementStrategy`] distribution-
16776    // strategy scalar accessor — same "one typed dispatch on the substrate
16777    // primitive, `Copy`-projected closed-set enum-arm discriminator" shape
16778    // extended onto the M2 supervisor-slot per-`:children` restart-decision
16779    // axis. The pin below covers the accessor's byte-equal projection
16780    // against the raw field access across every variant in the closed
16781    // accept-set (`Permanent`, `Transient`, `Temporary`).
16782
16783    #[test]
16784    fn child_spec_restart_returns_restart_verbatim_across_permutations() {
16785        // The canonical per-`:children` restart-decision-policy-scalar
16786        // pin: [`ChildSpec::restart`] must return the `:children :restart`
16787        // field verbatim as a [`RestartPolicy`], `Copy`-projected from the
16788        // typed slot's own [`RestartPolicy`] storage across every variant
16789        // in the closed accept-set (`Permanent`, `Transient`, `Temporary`).
16790        // Pins against a future silent detour that re-derived the policy
16791        // from a peer axis (an accidental fallback to
16792        // `if is_supervisor_child { Permanent } else { Temporary }` that
16793        // collapsed the child's kind axis into the restart discriminator),
16794        // a variant remap the operator authors on one consumer without the
16795        // other, or a stale-derive detour that substituted
16796        // [`RestartPolicy::default`] when the field held any explicit
16797        // variant (which would silently collapse the distinction between
16798        // "author explicitly declared `:restart Permanent`" and "author
16799        // omitted the slot and inherited the default" the future
16800        // per-cluster restart-decision override slot depends on).
16801        //
16802        // Peer of the sibling per-`:supervisor`
16803        // `supervisor_spec_estrategia_returns_estrategia_verbatim_across_permutations`
16804        // (eafb619) pin on the M2 supervisor-slot sibling-restart-strategy
16805        // axis and the M3
16806        // `placement_estrategia_returns_estrategia_verbatim_across_permutations`
16807        // (921fe1b) pin on the per-`:placement` distribution-strategy axis
16808        // — same "the substrate-primitive accessor must byte-equal the raw
16809        // field access verbatim across every author-declared value"
16810        // discipline extended onto the M2 supervisor-slot per-`:children`
16811        // restart-decision-policy axis, closing the last unlifted axis on
16812        // the per-`:children` [`ChildSpec`] type.
16813        for restart in [
16814            RestartPolicy::Permanent,
16815            RestartPolicy::Transient,
16816            RestartPolicy::Temporary,
16817        ] {
16818            let c = ChildSpec {
16819                caixa: "worker".into(),
16820                versao: "^0.1".into(),
16821                restart,
16822            };
16823            assert_eq!(
16824                c.restart(),
16825                restart,
16826                "ChildSpec::restart must return :children :restart \
16827                 verbatim (got {:?}, expected {restart:?})",
16828                c.restart(),
16829            );
16830            assert_eq!(
16831                c.restart(),
16832                c.restart,
16833                "ChildSpec::restart accessor and .restart field access \
16834                 must byte-equal — the accessor is the substrate-primitive \
16835                 typed dispatch every downstream per-child restart-\
16836                 decision consumer must route through",
16837            );
16838        }
16839    }
16840
16841    // ── per-`:supervisor` `:estrategia` typed-accessor coherence pins ─────
16842    //
16843    // The [`SupervisorSpec::estrategia`] accessor lift extends the peer M3
16844    // [`crate::Placement::estrategia`] (921fe1b) `Copy`-return
16845    // distribution-strategy accessor discipline onto the M2 supervisor-slot
16846    // per-`:supervisor` sibling-restart-strategy `Copy`-composite-enum
16847    // scalar axis. The two pins below cover (1) the accessor's byte-equal
16848    // projection against the raw field access across every variant in the
16849    // closed accept-set, and (2) the two-consumer coherence between the
16850    // [`SupervisorSpec::validate`] partition-dispatch `match` arm and the
16851    // non-`SimpleOneForOne`-arm [`SupervisorError::NoChildren`] error
16852    // carrier's `estrategia:` field — peer of the sibling M3
16853    // `placement_estrategia_returns_estrategia_verbatim_across_permutations`
16854    // / `validate_placement_reads_through_lifted_estrategia_accessor` pin
16855    // pair on the per-`:placement` distribution-strategy axis.
16856
16857    #[test]
16858    fn supervisor_spec_estrategia_returns_estrategia_verbatim_across_permutations() {
16859        // The canonical per-`:supervisor` sibling-restart-strategy-scalar
16860        // pin: [`SupervisorSpec::estrategia`] must return the
16861        // `:supervisor :estrategia` field verbatim as a
16862        // [`RestartStrategy`], `Copy`-projected from the typed slot's own
16863        // [`RestartStrategy`] storage across every variant in the closed
16864        // accept-set (`OneForOne`, `OneForAll`, `RestForOne`,
16865        // `SimpleOneForOne`). Pins against a future silent detour that
16866        // re-derived the strategy from a peer axis (an accidental
16867        // fallback to `if children.is_empty() { SimpleOneForOne } else {
16868        // OneForOne }` collapse that read the children-count axis into
16869        // the strategy discriminator), a variant remap the operator
16870        // authors on one consumer without the other, or a stale-derive
16871        // detour that substituted [`RestartStrategy::default`] when the
16872        // field held any explicit variant (which would silently collapse
16873        // the distinction between "author explicitly declared
16874        // `:estrategia OneForOne`" and "author omitted the slot and
16875        // inherited the default" the future per-cluster strategy override
16876        // slot depends on). Peer of the sibling M3
16877        // `placement_estrategia_returns_estrategia_verbatim_across_permutations`
16878        // (921fe1b) pin on the M3 mesh-slot `Copy`-composite-enum scalar
16879        // axis — same "the substrate-primitive accessor must byte-equal
16880        // the raw field access verbatim across every author-declared
16881        // value" discipline extended onto the M2 supervisor-slot
16882        // per-`:supervisor` sibling-restart-strategy axis.
16883        for &estrategia in RestartStrategy::ALL {
16884            // `SimpleOneForOne` requires `children.is_empty()`; the peer
16885            // three strategies require a non-empty static children list.
16886            // Build each shape coherently so the pin's fixture would
16887            // itself pass [`SupervisorSpec::validate`] once fed through
16888            // the sibling coherence pin below — the byte-equal projection
16889            // asserted here is a strictly weaker property (a `Copy` field
16890            // read) that does not depend on `validate` running, but
16891            // keeping the fixture validate-clean means a future extension
16892            // of the pin to exercise `validate` end-to-end does not have
16893            // to re-author the children shape.
16894            //
16895            // Route the `SimpleOneForOne ↔ non-SimpleOneForOne` fixture-
16896            // shape partition through the [`gen_platform::IsVariant`]
16897            // derive-generated
16898            // [`RestartStrategy::is_simple_one_for_one`] predicate rather
16899            // than the raw `matches!(estrategia, RestartStrategy::
16900            // SimpleOneForOne)` open-coded pattern-match — same closed-
16901            // set-typed-enum arm-discriminator dispatch discipline the
16902            // sibling [`crate::upgrade::UpgradeInstruction::is_restart`]
16903            // convergence (915a934) extended onto its two paired positive
16904            // / negated `matches!` sites and the peer
16905            // [`crate::aplicacao::PlacementStrategy`] `IsVariant`-derived
16906            // predicate convergence (766ec63) extended onto the M3 mesh-
16907            // slot per-`:placement` distribution-strategy discriminator
16908            // axis. See the sibling `round_trip_all_strategies` and the
16909            // peer `manifest::tests::
16910            // caixa_estrategia_and_supervisor_view_reads_through_lifted_estrategia_accessor`
16911            // fixture for the two peer sites the same lift closes on.
16912            let children = if estrategia.is_simple_one_for_one() {
16913                Vec::new()
16914            } else {
16915                vec![ChildSpec {
16916                    caixa: "worker".into(),
16917                    versao: "^0.1".into(),
16918                    restart: RestartPolicy::Permanent,
16919                }]
16920            };
16921            let s = SupervisorSpec {
16922                estrategia,
16923                children,
16924                ..SupervisorSpec::default()
16925            };
16926            assert_eq!(
16927                s.estrategia(),
16928                estrategia,
16929                "SupervisorSpec::estrategia must return :supervisor :estrategia \
16930                 verbatim (got {:?}, expected {estrategia:?})",
16931                s.estrategia(),
16932            );
16933            assert_eq!(
16934                s.estrategia(),
16935                s.estrategia,
16936                "SupervisorSpec::estrategia accessor and .estrategia field \
16937                 access must byte-equal — the accessor is the substrate-\
16938                 primitive typed dispatch every downstream sibling-restart-\
16939                 strategy consumer must route through",
16940            );
16941        }
16942    }
16943
16944    #[test]
16945    fn validate_reads_through_lifted_estrategia_accessor() {
16946        // Two-consumer coherence pin: the [`SupervisorSpec::validate`]
16947        // `SimpleOneForOne ↔ non-SimpleOneForOne` `match` partition
16948        // dispatch (which reads through [`SupervisorSpec::estrategia`]
16949        // to fan across the strategy-arm shape-gate cascades) and the
16950        // non-`SimpleOneForOne`-arm [`SupervisorError::NoChildren`]
16951        // error carrier's `estrategia:` field (which reads through
16952        // [`SupervisorSpec::estrategia`] to name the strategy the empty
16953        // `:children` list was declared against) must both key off the
16954        // lifted accessor, so any future rebrand on the typed slot's
16955        // reader shape lands at exactly one place. Pins the two-site
16956        // coherence by exercising the `NoChildren` error surface end-to-
16957        // end across every non-`SimpleOneForOne` variant and asserting
16958        // the surfaced `estrategia:` field byte-equals the accessor's
16959        // return. Peer of the sibling M3
16960        // `validate_placement_reads_through_lifted_estrategia_accessor`
16961        // (921fe1b) three-consumer coherence pin on the per-`:placement`
16962        // distribution-strategy axis.
16963        for estrategia in [
16964            RestartStrategy::OneForOne,
16965            RestartStrategy::OneForAll,
16966            RestartStrategy::RestForOne,
16967        ] {
16968            let s = SupervisorSpec {
16969                estrategia,
16970                children: Vec::new(),
16971                ..SupervisorSpec::default()
16972            };
16973            let err = s.validate().unwrap_err();
16974            match err {
16975                SupervisorError::NoChildren { estrategia: e } => {
16976                    assert_eq!(
16977                        e,
16978                        s.estrategia(),
16979                        "NoChildren.estrategia must byte-equal \
16980                         SupervisorSpec::estrategia() — the empty-`:children` \
16981                         refusal reads through the lifted accessor",
16982                    );
16983                    assert_eq!(
16984                        e, estrategia,
16985                        "NoChildren.estrategia must carry the author-declared \
16986                         :supervisor :estrategia variant verbatim (got {e:?}, \
16987                         expected {estrategia:?})",
16988                    );
16989                }
16990                other => panic!("expected NoChildren, got {other:?} for estrategia={estrategia:?}"),
16991            }
16992        }
16993    }
16994
16995    // ── per-`:supervisor` `:max-restarts` typed-accessor coherence pins ────
16996    //
16997    // The [`SupervisorSpec::max_restarts`] accessor lift extends the peer M3
16998    // [`crate::CircuitBreaker::max_failures`] (3a74062) `Copy`-return
16999    // required-`u32` scalar accessor discipline onto the M2 supervisor-slot
17000    // per-`:supervisor` restart-budget-count `Copy`-`u32` scalar axis.
17001    // The two pins below cover (1) the accessor's byte-equal projection
17002    // against the raw field access across every representative value in
17003    // the `u32` accept-set (`1` lower boundary, `SUPERVISOR_MAX_RESTARTS_MAX`
17004    // upper boundary, `0` past-the-guard zero sentinel, `u32::MAX`
17005    // past-the-guard cap sentinel), and (2) the [`SupervisorSpec::validate`]
17006    // zero-floor / cap composition — the validate gate and the accessor
17007    // must route through the same substrate-primitive typed dispatch, so
17008    // any future silent detour that had the accessor perform a
17009    // bounds-collapsing clamp would fail here at caixa-core build time.
17010    // Peer of the sibling M3
17011    // `circuit_breaker_max_failures_returns_max_failures_u32_byte_equal_across_permutations`
17012    // (3a74062) pin on the per-`CircuitBreaker :max-failures` axis.
17013
17014    #[test]
17015    fn supervisor_spec_max_restarts_returns_max_restarts_u32_byte_equal_across_permutations() {
17016        // The canonical per-`:supervisor` restart-budget-count scalar pin:
17017        // [`SupervisorSpec::max_restarts`] must return the `:supervisor
17018        // :max-restarts` typed `u32` verbatim, `Copy`-projected from the
17019        // typed slot's own `u32` storage, byte-equal to the raw field
17020        // access across every representative value in the accept-set —
17021        // `1` (the lower boundary of the `1..=SUPERVISOR_MAX_RESTARTS_MAX`
17022        // accept-set the surrounding [`SupervisorSpec::validate`] gate
17023        // carves out on the sibling `ZeroMaxRestarts` refusal),
17024        // `SUPERVISOR_MAX_RESTARTS_MAX` (the upper boundary the same gate
17025        // carves out on the sibling `MaxRestartsExceedsCap` refusal), `0`
17026        // (a past-the-guard sentinel that pins the accessor doesn't
17027        // perform a silent bounds-collapse into `1` on the zero arm —
17028        // validate rejects zero but the accessor must ship the raw slot
17029        // verbatim so a validate-time gate regression surfaces at the
17030        // emit boundary rather than being silently absorbed), `u32::MAX`
17031        // (a past-the-guard sentinel that pins the accessor doesn't
17032        // perform a silent bounds-collapse through
17033        // `SUPERVISOR_MAX_RESTARTS_MAX` at the return path).
17034        //
17035        // Peer of the sibling M3
17036        // `circuit_breaker_max_failures_returns_max_failures_u32_byte_equal_across_permutations`
17037        // (3a74062) pin on the M3 mesh-slot `Copy`-`u32` sub-struct
17038        // required-scalar axis — same "the substrate-primitive accessor
17039        // must byte-equal the raw field access verbatim across every
17040        // value in the `u32` accept-set" discipline extended onto the M2
17041        // supervisor-slot per-`:supervisor` restart-budget-count axis.
17042        for max_restarts in [1u32, SUPERVISOR_MAX_RESTARTS_MAX, 0, u32::MAX] {
17043            let s = SupervisorSpec {
17044                max_restarts,
17045                ..SupervisorSpec::default()
17046            };
17047            assert_eq!(
17048                s.max_restarts(),
17049                max_restarts,
17050                "SupervisorSpec::max_restarts must return :supervisor \
17051                 :max-restarts verbatim (got {}, expected {max_restarts})",
17052                s.max_restarts(),
17053            );
17054            assert_eq!(
17055                s.max_restarts(),
17056                s.max_restarts,
17057                "SupervisorSpec::max_restarts accessor and .max_restarts \
17058                 field access must byte-equal — the accessor is the \
17059                 substrate-primitive typed dispatch every downstream \
17060                 restart-budget-count consumer must route through",
17061            );
17062        }
17063    }
17064
17065    #[test]
17066    fn validate_max_restarts_zero_floor_and_cap_arms_route_through_accessor() {
17067        // Composition pin: [`SupervisorSpec::validate`]'s `:max-restarts`
17068        // zero-floor + upper-cap bracket must key off
17069        // [`SupervisorSpec::max_restarts`], not the raw `.max_restarts`
17070        // field access. Structurally: a `SupervisorSpec { max_restarts:
17071        // 0, .. }` must surface the `ZeroMaxRestarts` refusal exactly, a
17072        // `SupervisorSpec { max_restarts: SUPERVISOR_MAX_RESTARTS_MAX + 1,
17073        // .. }` must surface the `MaxRestartsExceedsCap` refusal exactly
17074        // (with the offending count carried verbatim from the accessor
17075        // return), and a `SupervisorSpec { max_restarts: 1, .. }` (the
17076        // lower boundary of the accept-set) plus a `SupervisorSpec {
17077        // max_restarts: SUPERVISOR_MAX_RESTARTS_MAX, .. }` (the upper
17078        // boundary) must pass validate. The four together jointly pin the
17079        // accessor + validate-gate composition: any future silent detour
17080        // that had the accessor return a fresh `1` on the zero arm (a
17081        // `.max_restarts().max(1)` collapse) would silently absorb the
17082        // `ZeroMaxRestarts` refusal at the accessor boundary and the
17083        // validate gate would accept a struct-literal `SupervisorSpec {
17084        // max_restarts: 0, .. }` — the composition pin catches that at
17085        // caixa-core build time.
17086        //
17087        // Peer of the sibling M3
17088        // `validate_politicas_max_failures_zero_floor_arm_routes_through_accessor`
17089        // (3a74062) pin on the sibling per-`CircuitBreaker :max-failures`
17090        // composition axis — same "the validate / shape-gate predicate
17091        // must route through the substrate-primitive typed dispatch"
17092        // discipline extended onto the peer M2 supervisor-slot
17093        // required-`u32` composition axis.
17094        let child = ChildSpec {
17095            caixa: "worker".into(),
17096            versao: "^0.1".into(),
17097            restart: RestartPolicy::Permanent,
17098        };
17099        // Zero-floor arm.
17100        let s = SupervisorSpec {
17101            max_restarts: 0,
17102            children: vec![child.clone()],
17103            ..SupervisorSpec::default()
17104        };
17105        assert_eq!(
17106            s.validate().unwrap_err(),
17107            SupervisorError::ZeroMaxRestarts,
17108            "validate must reject max_restarts == 0 with ZeroMaxRestarts \
17109             — the accessor and the validate gate must route through the \
17110             same substrate-primitive typed dispatch on the zero-floor arm",
17111        );
17112        // Cap arm — the surfaced `max_restarts:` field must byte-equal
17113        // the accessor's return so a future rebrand on the accessor
17114        // lands in the diagnostic without a coordinated rewrite.
17115        let over_cap = SUPERVISOR_MAX_RESTARTS_MAX + 1;
17116        let s = SupervisorSpec {
17117            max_restarts: over_cap,
17118            children: vec![child.clone()],
17119            ..SupervisorSpec::default()
17120        };
17121        match s.validate().unwrap_err() {
17122            SupervisorError::MaxRestartsExceedsCap { max_restarts } => {
17123                assert_eq!(
17124                    max_restarts,
17125                    s.max_restarts(),
17126                    "MaxRestartsExceedsCap.max_restarts must byte-equal \
17127                     SupervisorSpec::max_restarts() — the cap-arm refusal \
17128                     reads through the lifted accessor",
17129                );
17130                assert_eq!(
17131                    max_restarts, over_cap,
17132                    "MaxRestartsExceedsCap.max_restarts must carry the \
17133                     author-declared :supervisor :max-restarts value \
17134                     verbatim (got {max_restarts}, expected {over_cap})",
17135                );
17136            }
17137            other => panic!("expected MaxRestartsExceedsCap, got {other:?}"),
17138        }
17139        // Lower + upper accept-set boundaries.
17140        for max_restarts in [1u32, SUPERVISOR_MAX_RESTARTS_MAX] {
17141            let s = SupervisorSpec {
17142                max_restarts,
17143                children: vec![child.clone()],
17144                ..SupervisorSpec::default()
17145            };
17146            assert!(
17147                s.validate().is_ok(),
17148                "validate must accept max_restarts == {max_restarts} \
17149                 (an accept-set boundary of \
17150                 1..=SUPERVISOR_MAX_RESTARTS_MAX)",
17151            );
17152        }
17153    }
17154
17155    // ── per-`:supervisor` `:restart-window` typed-accessor coherence pins ─
17156    //
17157    // The [`SupervisorSpec::restart_window`] accessor lift extends the peer
17158    // M2 [`crate::LimitsSpec::wall_clock`] (8cb717b) `Option<Duration>`
17159    // accessor discipline and the peer M3 [`crate::MeshPolicy::timeout`]
17160    // (7073d0f) `Option<Duration>` accessor discipline onto the M2
17161    // supervisor-slot per-`:supervisor` restart-intensity-denominator
17162    // `Option<Duration>` scalar axis — third `Copy`-return accessor on the
17163    // M2 supervisor-slot `SupervisorSpec` type, closing the last unlifted
17164    // per-`:supervisor` scalar-value axis. The three pins below cover
17165    // (1) the accessor's byte-equal projection against the raw field
17166    // access across every representative value in the `Option<Duration>`
17167    // accept-set (`None` never-reset sentinel, `Some(Duration::from_millis(1))`
17168    // lower boundary, `Some(SUPERVISOR_RESTART_WINDOW_MAX)` upper boundary,
17169    // `Some(Duration::ZERO)` past-the-guard zero sentinel, `Some(Duration::MAX)`
17170    // past-the-guard above-cap sentinel), (2) the [`SupervisorSpec::validate`]
17171    // `if let Some(w) = self.restart_window() { … }` bracket-arm
17172    // composition — the validate gate and the accessor must route through
17173    // the same substrate-primitive typed dispatch, so any future silent
17174    // detour that had the accessor perform a bounds-collapsing clamp
17175    // would fail here at caixa-core build time, and (3) the accessor's
17176    // by-copy idempotence pin — the returned `Option<Duration>` must
17177    // outlive `&self` and two successive calls must return byte-equal
17178    // values. Peer of the sibling M2
17179    // `limits_wall_clock_returns_option_duration_byte_equal_across_permutations`
17180    // (8cb717b) pin on the per-`:limits :wall-clock` axis and the sibling
17181    // M3 `mesh_policy_timeout_returns_timeout_option_byte_equal_across_permutations`
17182    // (7073d0f) pin on the per-`:politicas :timeout` axis.
17183
17184    #[test]
17185    fn supervisor_spec_restart_window_returns_option_duration_byte_equal_across_permutations() {
17186        // The canonical per-`:supervisor` restart-intensity-denominator
17187        // scalar pin: [`SupervisorSpec::restart_window`] must return the
17188        // `:supervisor :restart-window` typed [`Duration`] verbatim as an
17189        // `Option<Duration>`, `Copy`-projected from the typed slot's own
17190        // `Option<Duration>` storage, byte-equal to the raw field access
17191        // across every representative value in the accept-set — `None`
17192        // (the "never reset — every restart across the supervisor's
17193        // lifetime counts against the sibling `:max-restarts` budget"
17194        // sentinel the field's own docstring names and the peer
17195        // `validate_accepts_none_restart_window` pin locks in on the
17196        // [`SupervisorSpec::validate`] entry-side),
17197        // `Some(Duration::from_millis(1))` (the structural minimum a
17198        // validated `:restart-window` may carry, the integer-millisecond
17199        // floor [`SupervisorError::RestartWindowNotCanonical`] rejects
17200        // everything sub-ms; `Duration::ZERO` is separately rejected by
17201        // [`SupervisorError::RestartWindowZero`]),
17202        // `Some(SUPERVISOR_RESTART_WINDOW_MAX)` (the upper boundary the
17203        // surrounding [`SupervisorSpec::validate`] gate carves out on the
17204        // sibling [`SupervisorError::RestartWindowExceedsCap`] refusal),
17205        // `Some(Duration::ZERO)` (a past-the-guard sentinel that pins the
17206        // accessor doesn't perform a silent bounds-collapse into `None` on
17207        // the zero-Duration arm — validate rejects zero but the accessor
17208        // must ship the raw slot verbatim so a validate-time gate
17209        // regression surfaces at the emit boundary rather than being
17210        // silently absorbed), and `Some(Duration::MAX)` (a past-the-guard
17211        // sentinel that pins the accessor doesn't perform a silent
17212        // bounds-collapse through [`SUPERVISOR_RESTART_WINDOW_MAX`] at the
17213        // return path).
17214        //
17215        // Peer of the sibling M2
17216        // `limits_wall_clock_returns_option_duration_byte_equal_across_permutations`
17217        // (8cb717b) pin on the per-`:limits :wall-clock` axis and the
17218        // sibling M3
17219        // `mesh_policy_timeout_returns_timeout_option_byte_equal_across_permutations`
17220        // (7073d0f) pin on the per-`:politicas :timeout` axis — same "the
17221        // substrate-primitive accessor must byte-equal the raw field
17222        // access verbatim across every value in the `Option<Duration>`
17223        // accept-set" discipline extended onto the M2 supervisor-slot
17224        // per-`:supervisor` `Option<Duration>` axis. Pins against a future
17225        // silent detour that re-derived the restart-window from a peer
17226        // axis (an accidental `.max_restarts.into()` collapse that read
17227        // the restart-budget-count as a duration — the two axes serve
17228        // different halves of the `MaxIntensity / Period` restart-
17229        // intensity ratio, and confusing them silently inverts the
17230        // ratio's numerator and denominator), a `None → Some(Duration::ZERO)`
17231        // "zero means never reset" collapse (the canonical
17232        // `Option<Duration>` → `Duration` collapse footgun the
17233        // [`SupervisorError::RestartWindowZero`] validate arm guards on
17234        // the peer zero-floor axis; a zero period either trips on the
17235        // first failure or never trips depending on operator
17236        // interpretation, neither of which is the author's "never reset"
17237        // intent that `None` expresses structurally), or a per-arm
17238        // variant swap that landed on one consumer without the other.
17239        for restart_window in [
17240            None,
17241            Some(Duration::from_millis(1)),
17242            Some(SUPERVISOR_RESTART_WINDOW_MAX),
17243            Some(Duration::ZERO),
17244            Some(Duration::MAX),
17245        ] {
17246            let s = SupervisorSpec {
17247                restart_window,
17248                ..SupervisorSpec::default()
17249            };
17250            assert_eq!(
17251                s.restart_window(),
17252                restart_window,
17253                "SupervisorSpec::restart_window must return :supervisor \
17254                 :restart-window verbatim (got {:?}, expected {restart_window:?})",
17255                s.restart_window(),
17256            );
17257            assert_eq!(
17258                s.restart_window(),
17259                s.restart_window,
17260                "SupervisorSpec::restart_window accessor and \
17261                 .restart_window field access must byte-equal — the \
17262                 accessor is the substrate-primitive typed dispatch every \
17263                 downstream restart-intensity-denominator consumer must \
17264                 route through",
17265            );
17266        }
17267    }
17268
17269    #[test]
17270    fn validate_restart_window_bracket_arm_routes_through_accessor() {
17271        // Composition pin: [`SupervisorSpec::validate`]'s
17272        // `:restart-window` `if let Some(w) = self.restart_window() { … }`
17273        // zero-floor + integer-millisecond canonical-form + upper-cap
17274        // bracket-arm must key off [`SupervisorSpec::restart_window`], not
17275        // the raw `.restart_window` field access. Structurally: a
17276        // `SupervisorSpec { restart_window: None, .. }` must pass the
17277        // arm gate structurally (the `if let Some(_)` shape returns
17278        // early on the `None` arm — the accessor and the validate gate
17279        // must agree on `None → skip the bracket cascade` so an authored
17280        // `:restart-window ()` structurally routes through the "never
17281        // reset" sentinel path), a `SupervisorSpec { restart_window:
17282        // Some(Duration::ZERO), .. }` must surface the `RestartWindowZero`
17283        // refusal exactly, a `SupervisorSpec { restart_window:
17284        // Some(Duration::from_micros(1500)), .. }` must surface the
17285        // `RestartWindowNotCanonical` refusal exactly (with the offending
17286        // duration carried verbatim from the accessor return), a
17287        // `SupervisorSpec { restart_window: Some(SUPERVISOR_RESTART_WINDOW_MAX
17288        // + Duration::from_millis(1)), .. }` must surface the
17289        // `RestartWindowExceedsCap` refusal exactly (with the offending
17290        // duration carried verbatim from the accessor return), and a
17291        // `SupervisorSpec { restart_window: Some(Duration::from_millis(1)),
17292        // .. }` (the lower boundary of the accept-set) plus a
17293        // `SupervisorSpec { restart_window: Some(SUPERVISOR_RESTART_WINDOW_MAX),
17294        // .. }` (the upper boundary) must pass validate. The six together
17295        // jointly pin the accessor + validate-gate composition: any future
17296        // silent detour that had the accessor return a fresh `None` on any
17297        // `Some` arm (a `.restart_window().filter(|w| !w.is_zero())`
17298        // collapse) would silently absorb the `RestartWindowZero` refusal
17299        // at the accessor boundary and the validate gate would accept a
17300        // struct-literal `SupervisorSpec { restart_window:
17301        // Some(Duration::ZERO), .. }` — the composition pin catches that
17302        // at caixa-core build time.
17303        //
17304        // Peer of the sibling M2 [`crate::LimitsSpec::wall_clock`]
17305        // (8cb717b) validate-arm-route pin on the per-`:limits :wall-clock`
17306        // axis and the peer M3 [`crate::MeshPolicy::timeout`] (7073d0f)
17307        // accessor-composition pin on the per-`:politicas :timeout` axis —
17308        // same "the validate / shape-gate predicate must route through
17309        // the substrate-primitive typed dispatch" discipline extended
17310        // onto the peer M2 supervisor-slot optional-`Duration` axis.
17311        let child = ChildSpec {
17312            caixa: "worker".into(),
17313            versao: "^0.1".into(),
17314            restart: RestartPolicy::Permanent,
17315        };
17316        // None arm — must not surface any :restart-window-shaped refusal;
17317        // the `if let Some(_)` bracket returns early on `None` structurally.
17318        let s = SupervisorSpec {
17319            restart_window: None,
17320            children: vec![child.clone()],
17321            ..SupervisorSpec::default()
17322        };
17323        assert!(
17324            s.validate().is_ok(),
17325            "validate must accept restart_window: None (the never-reset \
17326             sentinel) — the `if let Some(_)` bracket returns early on \
17327             the None arm and the accessor must agree",
17328        );
17329        // Zero-floor arm.
17330        let s = SupervisorSpec {
17331            restart_window: Some(Duration::ZERO),
17332            children: vec![child.clone()],
17333            ..SupervisorSpec::default()
17334        };
17335        assert_eq!(
17336            s.validate().unwrap_err(),
17337            SupervisorError::RestartWindowZero,
17338            "validate must reject restart_window == Some(Duration::ZERO) \
17339             with RestartWindowZero — the accessor and the validate gate \
17340             must route through the same substrate-primitive typed \
17341             dispatch on the zero-floor arm",
17342        );
17343        // Non-canonical (sub-ms) arm — the surfaced `window:` field must
17344        // byte-equal the accessor's return so a future rebrand on the
17345        // accessor lands in the diagnostic without a coordinated rewrite.
17346        let sub_ms = Duration::from_micros(1500);
17347        let s = SupervisorSpec {
17348            restart_window: Some(sub_ms),
17349            children: vec![child.clone()],
17350            ..SupervisorSpec::default()
17351        };
17352        match s.validate().unwrap_err() {
17353            SupervisorError::RestartWindowNotCanonical { window } => {
17354                assert_eq!(
17355                    Some(window),
17356                    s.restart_window(),
17357                    "RestartWindowNotCanonical.window must byte-equal \
17358                     SupervisorSpec::restart_window().unwrap() — the \
17359                     non-canonical-arm refusal reads through the lifted \
17360                     accessor",
17361                );
17362                assert_eq!(
17363                    window, sub_ms,
17364                    "RestartWindowNotCanonical.window must carry the \
17365                     author-declared :supervisor :restart-window value \
17366                     verbatim (got {window:?}, expected {sub_ms:?})",
17367                );
17368            }
17369            other => panic!("expected RestartWindowNotCanonical, got {other:?}"),
17370        }
17371        // Cap arm — the surfaced `window:` field must byte-equal the
17372        // accessor's return.
17373        let over_cap = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_millis(1);
17374        let s = SupervisorSpec {
17375            restart_window: Some(over_cap),
17376            children: vec![child.clone()],
17377            ..SupervisorSpec::default()
17378        };
17379        match s.validate().unwrap_err() {
17380            SupervisorError::RestartWindowExceedsCap { window } => {
17381                assert_eq!(
17382                    Some(window),
17383                    s.restart_window(),
17384                    "RestartWindowExceedsCap.window must byte-equal \
17385                     SupervisorSpec::restart_window().unwrap() — the \
17386                     cap-arm refusal reads through the lifted accessor",
17387                );
17388                assert_eq!(
17389                    window, over_cap,
17390                    "RestartWindowExceedsCap.window must carry the \
17391                     author-declared :supervisor :restart-window value \
17392                     verbatim (got {window:?}, expected {over_cap:?})",
17393                );
17394            }
17395            other => panic!("expected RestartWindowExceedsCap, got {other:?}"),
17396        }
17397        // Lower + upper accept-set boundaries.
17398        for restart_window in [Duration::from_millis(1), SUPERVISOR_RESTART_WINDOW_MAX] {
17399            let s = SupervisorSpec {
17400                restart_window: Some(restart_window),
17401                children: vec![child.clone()],
17402                ..SupervisorSpec::default()
17403            };
17404            assert!(
17405                s.validate().is_ok(),
17406                "validate must accept restart_window == Some({restart_window:?}) \
17407                 (an accept-set boundary of \
17408                 1ms..=SUPERVISOR_RESTART_WINDOW_MAX)",
17409            );
17410        }
17411    }
17412
17413    #[test]
17414    fn supervisor_spec_restart_window_projects_option_duration_by_copy() {
17415        // The by-copy pin: [`SupervisorSpec::restart_window`] returns
17416        // `Option<Duration>` by copy — `Duration` is `Copy` (so
17417        // `Option<Duration>` is `Copy`) and the accessor must return by
17418        // value, not by reference. Peer of the sibling M2
17419        // [`crate::LimitsSpec::wall_clock`] (8cb717b) by-copy pin on the
17420        // per-`:limits :wall-clock` axis and the sibling M3
17421        // [`crate::MeshPolicy::timeout`] (7073d0f) by-copy pin on the
17422        // per-`:politicas :timeout` axis, extended onto the peer M2
17423        // supervisor-slot `Option<Duration>` copy-invariant shape — the
17424        // accessor's returned `Option<Duration>` must outlive `&self`
17425        // (multiple calls must return equal values from a dropped-`&self`
17426        // copy, since the returned Option carries no borrow), and calling
17427        // the accessor twice on the same SupervisorSpec must yield the
17428        // same `Option<Duration>` verbatim (idempotent, no side effects
17429        // on `&self`).
17430        //
17431        // Pins against a future silent detour that returned
17432        // `Option<&Duration>` (which would type-check but silently break
17433        // every downstream caller — the future wasm-operator's
17434        // per-supervisor restart-intensity counter consumes `Duration` by
17435        // value and `&Duration` would fold to a detached copy at the call
17436        // site), an accidental `Option::as_ref()` projection
17437        // (`self.restart_window.as_ref()` would also type-check but
17438        // return `Option<&Duration>`), or a one-arm-only accessor that
17439        // reads `Some(*w)` in the Some arm but reads a fresh
17440        // `Default::default()` (which would collapse to `Duration::ZERO`,
17441        // not `None`) in the None arm — a footgun the
17442        // [`SupervisorError::RestartWindowZero`] validate arm explicitly
17443        // closes since Erlang/OTP's `MaxIntensity / Period` invariant
17444        // requires `Period > 0` and `None` structurally expresses "never
17445        // reset" instead.
17446        for restart_window in [
17447            None,
17448            Some(Duration::from_millis(1)),
17449            Some(Duration::from_secs(60)),
17450            Some(SUPERVISOR_RESTART_WINDOW_MAX),
17451        ] {
17452            let s = SupervisorSpec {
17453                restart_window,
17454                ..SupervisorSpec::default()
17455            };
17456            let first = s.restart_window();
17457            let second = s.restart_window();
17458            assert_eq!(
17459                first, second,
17460                "SupervisorSpec::restart_window must be idempotent — two \
17461                 successive calls on the same &self must return the \
17462                 same Option<Duration>",
17463            );
17464            assert_eq!(
17465                first, restart_window,
17466                "SupervisorSpec::restart_window must return :supervisor \
17467                 :restart-window verbatim by copy — got {first:?}, \
17468                 expected {restart_window:?}",
17469            );
17470        }
17471    }
17472
17473    // ── per-`:supervisor` `:children` typed-accessor coherence pins ─────────
17474    //
17475    // The [`SupervisorSpec::children`] accessor lift is the seed of the
17476    // slice-return (`&[T]`) accessor discipline on the substrate — the four
17477    // peer `Vec`-carry axes ([`crate::Placement::clusters`],
17478    // [`crate::AplicacaoSpec::membros`], [`crate::AplicacaoSpec::contratos`],
17479    // [`crate::UpgradeFromEntry::instructions`]) still key off the raw field
17480    // access at the time of this seed, and inherit this pin family's
17481    // discipline as future compounding runs migrate their consumers. The
17482    // three pins below cover (1) the accessor's byte-equal projection
17483    // against the raw field access across the empty / singleton / cohort
17484    // fixtures the [`SupervisorSpec::validate`] partition-dispatch fans
17485    // between, (2) the [`SupervisorSpec::validate`] `SimpleOneForOne ↔
17486    // non-SimpleOneForOne` partition dispatch's paired `.is_empty()`
17487    // consumer routing through the accessor on both arms, and (3) the
17488    // per-child validate loop's traversal reading the same slice-view the
17489    // accessor projects. Peer of the sibling M2
17490    // [`validate_reads_through_lifted_estrategia_accessor`] (eafb619)
17491    // two-consumer coherence pin on the per-`:supervisor`
17492    // sibling-restart-strategy `Copy`-composite-enum scalar axis, extended
17493    // onto the per-`:supervisor` static-child-list `Vec`-carry axis.
17494
17495    #[test]
17496    fn supervisor_spec_children_returns_children_slice_byte_equal_across_permutations() {
17497        // The canonical per-`:supervisor` static-child-list scalar-shape
17498        // pin: [`SupervisorSpec::children`] must return the `:supervisor
17499        // :children` typed `Vec<ChildSpec>` verbatim as a `&[ChildSpec]`
17500        // slice-view over the same backing buffer the raw
17501        // `self.children.as_slice()` field access borrows from, byte-
17502        // equal across every representative fixture in the accept-set —
17503        // the empty slice (the `SimpleOneForOne`-arm sentinel),
17504        // the singleton slice (the minimal non-`SimpleOneForOne` shape),
17505        // and a two-child cohort (a peer non-`SimpleOneForOne` shape
17506        // with the peer three restart-policy variants in play).
17507        //
17508        // Pins against a future silent detour that returned
17509        // `&Vec<ChildSpec>` (which would type-check but leak the
17510        // storage-side `Vec`'s grow/push/reserve surface no consumer of
17511        // the typed view reaches for), a fresh-allocated
17512        // `Vec<ChildSpec>` copy (which would type-check via a coercion
17513        // but silently break every downstream caller that relied on the
17514        // slice sharing the backing buffer's identity), or an
17515        // out-of-order or length-drifted projection (which would silently
17516        // split the per-child validate loop's traversal input from the
17517        // paired partition-dispatch `.is_empty()` probe's input).
17518        //
17519        // Peer of the sibling
17520        // `supervisor_spec_estrategia_returns_estrategia_verbatim_across_permutations`
17521        // (eafb619) `Copy`-composite-enum byte-equal pin on the
17522        // per-`:supervisor` sibling-restart-strategy axis, extended onto
17523        // the per-`:supervisor` static-child-list `Vec`-carry axis.
17524        let fixtures: Vec<Vec<ChildSpec>> = vec![
17525            Vec::new(),
17526            vec![child("worker", "^0.1", RestartPolicy::Permanent)],
17527            vec![
17528                child("worker", "^0.1", RestartPolicy::Permanent),
17529                child("cache-server", "^0.1", RestartPolicy::Transient),
17530            ],
17531            vec![
17532                child("worker", "^0.1", RestartPolicy::Permanent),
17533                child("cache-server", "^0.1", RestartPolicy::Transient),
17534                child("scratch-job", "^0.1", RestartPolicy::Temporary),
17535            ],
17536        ];
17537        for children in fixtures {
17538            let s = SupervisorSpec {
17539                children: children.clone(),
17540                ..SupervisorSpec::default()
17541            };
17542            assert_eq!(
17543                s.children(),
17544                children.as_slice(),
17545                "SupervisorSpec::children must return :supervisor \
17546                 :children verbatim (got {:?}, expected {:?})",
17547                s.children(),
17548                children.as_slice(),
17549            );
17550            assert_eq!(
17551                s.children(),
17552                s.children.as_slice(),
17553                "SupervisorSpec::children accessor and \
17554                 .children.as_slice() field access must byte-equal — \
17555                 the accessor is the substrate-primitive typed \
17556                 dispatch every downstream static-child-list consumer \
17557                 must route through",
17558            );
17559            assert_eq!(
17560                s.children().len(),
17561                s.children.len(),
17562                "SupervisorSpec::children().len() must byte-equal \
17563                 self.children.len() — a length-drift would silently \
17564                 split the paired partition-dispatch `.is_empty()` \
17565                 probe input from the per-child validate loop's \
17566                 traversal input",
17567            );
17568        }
17569    }
17570
17571    #[test]
17572    fn validate_reads_through_lifted_children_accessor() {
17573        // Three-consumer coherence pin: the [`SupervisorSpec::validate`]
17574        // `SimpleOneForOne`-arm `!self.children().is_empty()` refusal
17575        // probe (which must trip [`SupervisorError::SimpleOneForOneWithStaticChildren`]
17576        // when the accessor projects a non-empty slice under a
17577        // `SimpleOneForOne` estrategia), the peer non-`SimpleOneForOne`-arm
17578        // `self.children().is_empty()` refusal probe (which must trip
17579        // [`SupervisorError::NoChildren`] when the accessor projects the
17580        // empty slice under any peer estrategia), and the per-child
17581        // validate loop's `for child in self.children()` traversal
17582        // (which must reach every entry in the same order the accessor
17583        // projects) must all key off the lifted accessor, so any future
17584        // rebrand on the typed slot's reader shape lands at exactly one
17585        // place. Pins the three-site coherence by exercising each
17586        // production consumer end-to-end: (1) the
17587        // `SimpleOneForOneWithStaticChildren` refusal under a non-empty
17588        // slice + `SimpleOneForOne` estrategia, (2) the `NoChildren`
17589        // refusal under the empty slice + non-`SimpleOneForOne`
17590        // estrategia across every peer variant, and (3) the per-child
17591        // duplicate-detection surface fires on the second entry of a
17592        // two-child cohort that shares a `:caixa` name (which requires
17593        // the loop to reach both entries — a first-entry-only projection
17594        // would silently pass since the dedup HashSet has room for the
17595        // first insert).
17596        //
17597        // Peer of the sibling M2
17598        // [`validate_reads_through_lifted_estrategia_accessor`] (eafb619)
17599        // two-consumer coherence pin on the per-`:supervisor`
17600        // sibling-restart-strategy axis, extended onto the
17601        // per-`:supervisor` static-child-list `Vec`-carry axis.
17602
17603        // (1) `SimpleOneForOne`-arm probe: a non-empty slice under a
17604        // `SimpleOneForOne` estrategia must trip
17605        // `SimpleOneForOneWithStaticChildren`.
17606        let s = SupervisorSpec {
17607            estrategia: RestartStrategy::SimpleOneForOne,
17608            children: vec![child("worker", "^0.1", RestartPolicy::Permanent)],
17609            ..SupervisorSpec::default()
17610        };
17611        assert_eq!(
17612            s.validate().unwrap_err(),
17613            SupervisorError::SimpleOneForOneWithStaticChildren,
17614            "SimpleOneForOne + non-empty children must trip \
17615             SimpleOneForOneWithStaticChildren — the accessor projects \
17616             a non-empty slice, and the SimpleOneForOne-arm refusal \
17617             probe reads through the lifted accessor",
17618        );
17619        assert!(
17620            !s.children().is_empty(),
17621            "the SimpleOneForOne-arm refusal input must be a non-empty \
17622             slice per the accessor's projection",
17623        );
17624
17625        // (2) Peer non-`SimpleOneForOne`-arm probe: the empty slice
17626        // under any peer estrategia must trip `NoChildren`.
17627        for estrategia in [
17628            RestartStrategy::OneForOne,
17629            RestartStrategy::OneForAll,
17630            RestartStrategy::RestForOne,
17631        ] {
17632            let s = SupervisorSpec {
17633                estrategia,
17634                children: Vec::new(),
17635                ..SupervisorSpec::default()
17636            };
17637            match s.validate().unwrap_err() {
17638                SupervisorError::NoChildren { estrategia: e } => {
17639                    assert_eq!(
17640                        e, estrategia,
17641                        "NoChildren.estrategia must carry the author-\
17642                         declared :supervisor :estrategia variant \
17643                         verbatim (got {e:?}, expected {estrategia:?})",
17644                    );
17645                }
17646                other => panic!(
17647                    "expected NoChildren, got {other:?} for \
17648                     estrategia={estrategia:?}"
17649                ),
17650            }
17651            assert!(
17652                s.children().is_empty(),
17653                "the non-SimpleOneForOne-arm refusal input must be the \
17654                 empty slice per the accessor's projection",
17655            );
17656        }
17657
17658        // (3) Per-child validate loop: a two-child cohort that shares a
17659        // `:caixa` name must trip `DuplicateChildCaixa` — the loop must
17660        // reach both entries through the accessor.
17661        let s = SupervisorSpec {
17662            estrategia: RestartStrategy::OneForOne,
17663            children: vec![
17664                child("worker", "^0.1", RestartPolicy::Permanent),
17665                child("worker", "^0.2", RestartPolicy::Transient),
17666            ],
17667            ..SupervisorSpec::default()
17668        };
17669        match s.validate().unwrap_err() {
17670            SupervisorError::DuplicateChildCaixa { caixa } => {
17671                assert_eq!(
17672                    caixa, "worker",
17673                    "DuplicateChildCaixa.caixa must carry the shared \
17674                     child `:caixa` name verbatim",
17675                );
17676            }
17677            other => panic!("expected DuplicateChildCaixa, got {other:?}"),
17678        }
17679        assert_eq!(
17680            s.children().len(),
17681            2,
17682            "the per-child validate loop's traversal input must be a \
17683             two-element slice per the accessor's projection",
17684        );
17685    }
17686
17687    // Shared helper for the M2 per-`:children` per-slot-gate ≡
17688    // `validate` equivalence pins: builds an `OneForOne`-estrategia
17689    // one-cohort spec whose peer `:estrategia`↔`:children.is_empty()`
17690    // partition, `:max-restarts` zero-floor/cap, and `:restart-window`
17691    // bracket all pass cleanly so the sole failing surface is the
17692    // per-child cascade [`SupervisorSpec::validate_children`] owns, and
17693    // pins the two-altitude equivalence on the paired probe.
17694    fn assert_validate_children_matches_gate(children: Vec<ChildSpec>, expected: &SupervisorError) {
17695        let s = SupervisorSpec {
17696            estrategia: RestartStrategy::OneForOne,
17697            children,
17698            ..SupervisorSpec::default()
17699        };
17700        let via_gate = s.validate_children().unwrap_err();
17701        let via_validate = s.validate().unwrap_err();
17702        assert_eq!(&via_gate, expected, "validate_children direct dispatch",);
17703        assert_eq!(&via_validate, expected, "validate() end-to-end dispatch",);
17704        assert_eq!(
17705            via_gate, via_validate,
17706            "per-slot gate ≡ validate() must discriminate the same \
17707             refusal shape",
17708        );
17709    }
17710
17711    #[test]
17712    fn validate_children_matches_gate_on_per_axis_refusal_shapes() {
17713        // Fail-before-pass-after equivalence pin on the M2
17714        // per-`:children` per-slot gate ≡ [`SupervisorSpec::validate`]
17715        // convergence — sibling of the M3 mesh-slot
17716        // `validate_membros_*` / `validate_contratos_*` /
17717        // `validate_entrada_*` per-slot-gate ≡ `validate` pins on the
17718        // peer per-entry axes. Sweeps four of the five refusal shapes
17719        // the per-slot gate owns: (1) `EmptyChildName` on an empty-
17720        // `:caixa` child, (2) `ChildCaixaInvalid` on a structurally
17721        // invalid `:caixa` DNS-1123 label, (3) `EmptyChildVersion` on
17722        // an empty-`:versao` child, (4) `DuplicateChildCaixa` on a
17723        // duplicate-`:caixa` fan-out. Companion pin
17724        // `validate_children_matches_gate_on_versao_invalid_and_clean_pass`
17725        // covers `ChildVersaoInvalid` (whose parser-owned reason string
17726        // needs pattern-matching, not equality) and the clean-pass
17727        // canonical fixture; together the two pins guarantee the
17728        // per-slot gate and `validate` discriminate the same set on
17729        // every per-child-covered input.
17730        assert_validate_children_matches_gate(
17731            vec![child("", "^0.1", RestartPolicy::Permanent)],
17732            &SupervisorError::EmptyChildName,
17733        );
17734        assert_validate_children_matches_gate(
17735            vec![child("Worker", "^0.1", RestartPolicy::Permanent)],
17736            &SupervisorError::ChildCaixaInvalid {
17737                caixa: "Worker".into(),
17738                reason: "contains uppercase character 'W' (K8s DNS-1123 label names are lowercase-only; use \"worker\")".into(),
17739            },
17740        );
17741        assert_validate_children_matches_gate(
17742            vec![child("worker", "", RestartPolicy::Permanent)],
17743            &SupervisorError::EmptyChildVersion {
17744                caixa: "worker".into(),
17745            },
17746        );
17747        assert_validate_children_matches_gate(
17748            vec![
17749                child("worker", "^0.1", RestartPolicy::Permanent),
17750                child("worker", "^0.2", RestartPolicy::Transient),
17751            ],
17752            &SupervisorError::DuplicateChildCaixa {
17753                caixa: "worker".into(),
17754            },
17755        );
17756    }
17757
17758    #[test]
17759    fn validate_children_matches_gate_on_versao_invalid_and_clean_pass() {
17760        // Second half of the two-altitude equivalence pin — covers the
17761        // one refusal shape whose reason string is parser-owned
17762        // (`ChildVersaoInvalid`, whose reason comes from the shared
17763        // [`crate::version::parse_requirement`] impl and may drift) and
17764        // the clean-pass canonical fixture. Sibling pin
17765        // `validate_children_matches_gate_on_per_axis_refusal_shapes`
17766        // covers the four equality-comparable refusal shapes.
17767        let s_bad_versao = SupervisorSpec {
17768            estrategia: RestartStrategy::OneForOne,
17769            children: vec![child("worker", "not-a-req", RestartPolicy::Permanent)],
17770            ..SupervisorSpec::default()
17771        };
17772        let via_gate = s_bad_versao.validate_children().unwrap_err();
17773        let via_validate = s_bad_versao.validate().unwrap_err();
17774        match (&via_gate, &via_validate) {
17775            (
17776                SupervisorError::ChildVersaoInvalid {
17777                    caixa: cg,
17778                    versao: vg,
17779                    ..
17780                },
17781                SupervisorError::ChildVersaoInvalid {
17782                    caixa: cv,
17783                    versao: vv,
17784                    ..
17785                },
17786            ) => {
17787                assert_eq!(cg, "worker", "per-slot gate :caixa carrier");
17788                assert_eq!(vg, "not-a-req", "per-slot gate :versao carrier");
17789                assert_eq!(cv, "worker", "validate() :caixa carrier");
17790                assert_eq!(vv, "not-a-req", "validate() :versao carrier");
17791            }
17792            other => panic!("expected ChildVersaoInvalid on both altitudes, got {other:?}"),
17793        }
17794        assert_eq!(
17795            via_gate, via_validate,
17796            "per-slot gate ≡ validate() on ChildVersaoInvalid full envelope",
17797        );
17798
17799        let s_ok = SupervisorSpec {
17800            estrategia: RestartStrategy::OneForOne,
17801            children: vec![
17802                child("worker-a", "^0.1", RestartPolicy::Permanent),
17803                child("worker-b", "~0.2.3", RestartPolicy::Transient),
17804                child("collector", "*", RestartPolicy::Temporary),
17805            ],
17806            ..SupervisorSpec::default()
17807        };
17808        s_ok.validate_children()
17809            .expect("per-slot gate must accept the clean-pass fixture");
17810        s_ok.validate()
17811            .expect("validate() must accept the clean-pass fixture");
17812    }
17813
17814    #[test]
17815    fn validate_children_is_self_contained_on_children_slot() {
17816        // Self-containment pin: [`SupervisorSpec::validate_children`]
17817        // resolves the per-child cascade against `&self` alone, without
17818        // depending on the peer `:estrategia`/`:max-restarts`/
17819        // `:restart-window` gates having run first — same posture the M3
17820        // peer per-slot gates carry (`validate_membros`,
17821        // `validate_contratos`, `validate_entrada`, `validate_placement`,
17822        // routing through their own oracles rather than borrowing state
17823        // threaded down from `validate`). A future consumer that reaches
17824        // the per-slot gate directly on a spec whose peer slots would
17825        // fail `validate` still surfaces the per-child refusal, not the
17826        // peer refusal.
17827        //
17828        // Construct a spec whose `:max-restarts` is `0` (which would
17829        // trip [`SupervisorError::ZeroMaxRestarts`] at `validate` after
17830        // the partition-dispatch) and whose `:children` carries a
17831        // `DuplicateChildCaixa` shape: the per-slot gate called directly
17832        // must surface `DuplicateChildCaixa`, proving it does not depend
17833        // on the peer `:max-restarts` gate running first.
17834        let s = SupervisorSpec {
17835            estrategia: RestartStrategy::OneForOne,
17836            max_restarts: 0,
17837            restart_window: Some(Duration::from_secs(60)),
17838            children: vec![
17839                child("worker", "^0.1", RestartPolicy::Permanent),
17840                child("worker", "^0.2", RestartPolicy::Transient),
17841            ],
17842        };
17843        assert_eq!(
17844            s.validate_children().unwrap_err(),
17845            SupervisorError::DuplicateChildCaixa {
17846                caixa: "worker".into(),
17847            },
17848            "per-slot gate must resolve per-child refusal directly against \
17849             `&self` — a dependency on the peer `:max-restarts` gate \
17850             running first would surface ZeroMaxRestarts here instead",
17851        );
17852        // The peer gate is still the surface `validate` reaches — pin
17853        // the ordering to establish that `validate_children` truly runs
17854        // last in `validate`'s dispatch, so a direct call bypasses the
17855        // peer gates on any spec whose per-child cascade would fail.
17856        assert_eq!(
17857            s.validate().unwrap_err(),
17858            SupervisorError::ZeroMaxRestarts,
17859            "validate() must surface the peer `:max-restarts` gate before \
17860             reaching the per-child cascade — this pins the dispatch \
17861             ordering the per-slot gate's self-containment complements",
17862        );
17863    }
17864
17865    #[test]
17866    fn child_spec_restart_accessor_is_const_fn() {
17867        // The [`ChildSpec::restart`] per-`:children` restart-decision-
17868        // policy `Copy`-return scalar accessor is declared
17869        // `#[must_use] pub const fn` — matching the sibling M2
17870        // per-`:supervisor` [`SupervisorSpec::estrategia`] (pinned by
17871        // [`supervisor_spec_estrategia_accessor_is_const_fn`] below,
17872        // both converted in this commit), the sibling M2
17873        // per-`:supervisor` [`SupervisorSpec::max_restarts`] (b698ec0)
17874        // `Copy`-`u32` accessor already `pub const fn`, and the peer M3
17875        // mesh-slot per-`:entrada` [`crate::Entrada::port`] (bafa004) /
17876        // per-`:placement` [`crate::Placement::estrategia`] (bafa004)
17877        // `Copy`-return `pub const fn` scalar accessors on the sibling
17878        // M3 surface. Pin the `const`-eval posture here so a future
17879        // accidental downgrade to non-`const` (an added runtime helper
17880        // reachable only from a non-`const` context, an
17881        // `Option<RestartPolicy>`-shape migration on the per-child
17882        // restart-decision axis once heterogeneous per-cluster
17883        // restart-policy overlays land that would silently drop the
17884        // `const` qualifier, a manual hand-rolled shadow) trips at
17885        // caixa-core build time rather than surfacing as a downstream
17886        // `const`-context regression far from the declaration.
17887        //
17888        // Same shape as the sibling M3
17889        // [`crate::aplicacao::tests::placement_estrategia_accessor_is_const_fn`]
17890        // and [`crate::aplicacao::tests::entrada_port_accessor_is_const_fn`]
17891        // (bafa004) pins on the peer M3 mesh-slot `Copy`-return scalar
17892        // accessor axis — the load-bearing witness lives in the
17893        // module-scope `const fn` wrapper `restart_via_const_fn` below:
17894        // a body that calls [`ChildSpec::restart`] under a `const fn`
17895        // signature is well-formed only when the callee is itself
17896        // `const fn`, so any future accidental downgrade of
17897        // [`ChildSpec::restart`] to non-`const` fails at caixa-core
17898        // build time (const-eval E0015 `cannot call non-const method`),
17899        // strictly stronger than a runtime `assert!(CONST)` and
17900        // side-stepping the destructor-in-const restriction that
17901        // blocks direct `const _: RestartPolicy = FIXTURE.restart()`
17902        // items on `ChildSpec`'s `String` carriers.
17903        //
17904        // The runtime body sweeps every closed-set [`RestartPolicy`]
17905        // arm and asserts the wrapped and direct dispatches agree.
17906        const fn restart_via_const_fn(c: &ChildSpec) -> RestartPolicy {
17907            c.restart()
17908        }
17909        for restart in [
17910            RestartPolicy::Permanent,
17911            RestartPolicy::Transient,
17912            RestartPolicy::Temporary,
17913        ] {
17914            let c = ChildSpec {
17915                caixa: "worker".into(),
17916                versao: "^0.1".into(),
17917                restart,
17918            };
17919            assert_eq!(
17920                restart_via_const_fn(&c),
17921                c.restart(),
17922                "const-fn-wrapped and direct dispatch on \
17923                 ChildSpec::restart must agree for {restart:?}",
17924            );
17925            assert_eq!(
17926                c.restart(),
17927                restart,
17928                "ChildSpec::restart must return the storage-side \
17929                 RestartPolicy verbatim for {restart:?} (a violation \
17930                 means the accessor stopped being a raw field-return \
17931                 copy)",
17932            );
17933        }
17934    }
17935
17936    #[test]
17937    fn supervisor_spec_estrategia_accessor_is_const_fn() {
17938        // The [`SupervisorSpec::estrategia`] per-`:supervisor`
17939        // sibling-restart-strategy `Copy`-return scalar accessor is
17940        // declared `#[must_use] pub const fn` — matching the sibling M2
17941        // per-`:children` [`ChildSpec::restart`] (pinned by
17942        // [`child_spec_restart_accessor_is_const_fn`] above, both
17943        // converted in this commit), the sibling M2 per-`:supervisor`
17944        // [`SupervisorSpec::max_restarts`] (b698ec0) `Copy`-`u32`
17945        // accessor already `pub const fn`, and mirroring the peer M3
17946        // mesh-slot per-`:placement`
17947        // [`crate::Placement::estrategia`] (bafa004) `Copy`-return
17948        // `pub const fn` scalar accessor whose method-name discipline
17949        // the [`SupervisorSpec::estrategia`] method was authored to
17950        // match. Pin the `const`-eval posture here so a future
17951        // accidental downgrade to non-`const` (an added runtime helper
17952        // reachable only from a non-`const` context, an
17953        // `Option<RestartStrategy>`-shape migration once the substrate
17954        // grows per-cluster strategy overlays that would silently drop
17955        // the `const` qualifier, a manual hand-rolled shadow) trips at
17956        // caixa-core build time rather than surfacing as a downstream
17957        // `const`-context regression far from the declaration.
17958        //
17959        // Same shape as the sibling
17960        // [`child_spec_restart_accessor_is_const_fn`] pin above — the
17961        // load-bearing witness lives in the module-scope `const fn`
17962        // wrapper `estrategia_via_const_fn` below: a body that calls
17963        // [`SupervisorSpec::estrategia`] under a `const fn` signature
17964        // is well-formed only when the callee is itself `const fn`,
17965        // side-stepping the destructor-in-const restriction that would
17966        // otherwise block a direct
17967        // `const _: RestartStrategy = FIXTURE.estrategia()` item on
17968        // `SupervisorSpec`'s `Vec<ChildSpec>` / `Option<Duration>`
17969        // carriers.
17970        //
17971        // The runtime body sweeps every closed-set [`RestartStrategy`]
17972        // arm via [`RestartStrategy::ALL`] and asserts the wrapped and
17973        // direct dispatches agree.
17974        const fn estrategia_via_const_fn(s: &SupervisorSpec) -> RestartStrategy {
17975            s.estrategia()
17976        }
17977        for &estrategia in RestartStrategy::ALL {
17978            let s = SupervisorSpec {
17979                estrategia,
17980                max_restarts: 5,
17981                restart_window: Some(Duration::from_secs(60)),
17982                children: Vec::new(),
17983            };
17984            assert_eq!(
17985                estrategia_via_const_fn(&s),
17986                s.estrategia(),
17987                "const-fn-wrapped and direct dispatch on \
17988                 SupervisorSpec::estrategia must agree for {estrategia:?}",
17989            );
17990            assert_eq!(
17991                s.estrategia(),
17992                estrategia,
17993                "SupervisorSpec::estrategia must return the storage-side \
17994                 RestartStrategy verbatim for {estrategia:?} (a violation \
17995                 means the accessor stopped being a raw field-return \
17996                 copy)",
17997            );
17998        }
17999    }
18000
18001    // Per-variant equivalence pins for the [`supervisor_caixa_only_ctors!`]
18002    // macro definition (see the paired doc-block above the macro
18003    // definition) — every generated `<ctor>(caixa: &str) -> Self`
18004    // constructor folds the uniform `Self::<Variant> { caixa:
18005    // caixa.to_string() }` one-field struct-literal onto one substrate
18006    // primitive. The three per-variant equivalence pins below
18007    // (fail-before-pass-after by construction — a byte-mismatched macro
18008    // arm would trip its equivalence pin first) lock each generated
18009    // constructor to its struct-literal peer under `PartialEq`, so
18010    // every wire-up in [`SupervisorSpec::validate_children`] and
18011    // [`validate_no_self_supervision`] on that variant produces a
18012    // byte-equal `SupervisorError` to the pre-lift open-coded
18013    // struct-literal. The cross-axis pin that follows (non-default
18014    // caixa name) routes the sole constructor input axis through
18015    // `.to_string()`, so the fold does not silently collapse onto a
18016    // fixed name.
18017    //
18018    // Peer of the sibling `<slot>_ctor_matches_tuple_literal_wrap` /
18019    // `<slot>_violation_ctor_matches_struct_literal_wrap` /
18020    // `<slot>_slots_on_non_<owner>_ctor_matches_struct_literal_wrap` /
18021    // `missing_entry_ctor_matches_struct_literal_wrap` /
18022    // `entrada_host_invalid_ctor_matches_struct_literal_wrap` /
18023    // `contrato_wrong_target_ctor_matches_struct_literal_wrap` /
18024    // `contrato_missing_target_ctor_matches_struct_literal_wrap` /
18025    // `<variant>_ctor_matches_struct_literal_wrap` equivalence pins
18026    // on the six sibling ctor families the recent trajectory closed
18027    // on the peer `LayoutError` / `AplicacaoError` envelopes.
18028
18029    #[test]
18030    fn empty_child_version_ctor_matches_struct_literal_wrap() {
18031        assert_eq!(
18032            SupervisorError::empty_child_version("worker"),
18033            SupervisorError::EmptyChildVersion {
18034                caixa: "worker".to_string(),
18035            },
18036            "generated empty_child_version ctor must produce byte-equal \
18037             SupervisorError to the open-coded struct-literal wrap on the \
18038             same &str fixture",
18039        );
18040    }
18041
18042    #[test]
18043    fn duplicate_child_caixa_ctor_matches_struct_literal_wrap() {
18044        assert_eq!(
18045            SupervisorError::duplicate_child_caixa("worker"),
18046            SupervisorError::DuplicateChildCaixa {
18047                caixa: "worker".to_string(),
18048            },
18049            "generated duplicate_child_caixa ctor must produce byte-equal \
18050             SupervisorError to the open-coded struct-literal wrap on the \
18051             same &str fixture",
18052        );
18053    }
18054
18055    #[test]
18056    fn child_supervises_self_ctor_matches_struct_literal_wrap() {
18057        assert_eq!(
18058            SupervisorError::child_supervises_self("orquestra"),
18059            SupervisorError::ChildSupervisesSelf {
18060                caixa: "orquestra".to_string(),
18061            },
18062            "generated child_supervises_self ctor must produce byte-equal \
18063             SupervisorError to the open-coded struct-literal wrap on the \
18064             same &str fixture",
18065        );
18066    }
18067
18068    // Per-variant equivalence pins for the two lifted
18069    // [`SupervisorError::child_caixa_invalid`] /
18070    // [`SupervisorError::child_versao_invalid`] inherent constructors
18071    // (fail-before-pass-after by construction — a byte-mismatched ctor body
18072    // would trip its equivalence pin first). Each pins the ctor output to
18073    // its pre-lift struct-literal peer under `PartialEq`, so every wire-up
18074    // in [`SupervisorSpec::validate_children`] on the two variants
18075    // produces a byte-equal `SupervisorError` to the pre-lift open-coded
18076    // struct-literal on the same scalar fixtures. Peers of the sibling
18077    // `membro_caixa_invalid_ctor_matches_struct_literal_wrap` /
18078    // `entrada_para_invalid_ctor_matches_struct_literal_wrap` / … pins on
18079    // the peer `AplicacaoError` envelope's
18080    // [`crate::aplicacao::aplicacao_field_reason_ctors!`] fold.
18081
18082    #[test]
18083    fn child_caixa_invalid_ctor_matches_struct_literal_wrap() {
18084        let caixa = "Worker";
18085        let reason = "sample reason text";
18086        assert_eq!(
18087            SupervisorError::child_caixa_invalid(caixa, reason),
18088            SupervisorError::ChildCaixaInvalid {
18089                caixa: caixa.to_string(),
18090                reason: reason.to_string(),
18091            },
18092            "lifted child_caixa_invalid ctor must produce byte-equal \
18093             SupervisorError to the open-coded struct-literal wrap on the \
18094             same (&str, reason) fixture",
18095        );
18096    }
18097
18098    #[test]
18099    fn child_versao_invalid_ctor_matches_struct_literal_wrap() {
18100        let caixa = "worker";
18101        let versao = "not-a-req";
18102        let reason = "sample reason text";
18103        assert_eq!(
18104            SupervisorError::child_versao_invalid(caixa, versao, reason),
18105            SupervisorError::ChildVersaoInvalid {
18106                caixa: caixa.to_string(),
18107                versao: versao.to_string(),
18108                reason: reason.to_string(),
18109            },
18110            "lifted child_versao_invalid ctor must produce byte-equal \
18111             SupervisorError to the open-coded struct-literal wrap on the \
18112             same (&str, &str, reason) fixture",
18113        );
18114    }
18115
18116    #[test]
18117    fn supervisor_child_reason_ctors_route_reason_through_into_uniformly() {
18118        // Cross-axis pin: sweep the two lifted `{ …, reason }` ctors
18119        // against a `&str`-literal vs. `format!(…)` reason input to pin
18120        // both constructors accept the `impl Into<String>` bound
18121        // uniformly, so neither wire-up site drifts under a per-arm
18122        // wrapper transformation on the caller-side `reason` axis. Peer
18123        // of the sibling
18124        // `aplicacao_field_reason_ctors_route_reason_through_into_uniformly`
18125        // sweep on the peer `AplicacaoError` envelope.
18126        let via_literal = "literal reason text";
18127        let via_format = format!("{} reason text", "literal");
18128        assert_eq!(
18129            SupervisorError::child_caixa_invalid("Worker", via_literal),
18130            SupervisorError::child_caixa_invalid("Worker", via_format.clone()),
18131        );
18132        assert_eq!(
18133            SupervisorError::child_versao_invalid("worker", "not-a-req", via_literal),
18134            SupervisorError::child_versao_invalid("worker", "not-a-req", via_format),
18135        );
18136    }
18137
18138    #[test]
18139    fn supervisor_caixa_only_ctors_route_caixa_through_to_string() {
18140        // Cross-axis pin: sweep the sole constructor input axis (`caixa:
18141        // &str`) through a non-default fixture name against every
18142        // generated arm in the [`supervisor_caixa_only_ctors!`] macro,
18143        // so any wrapper-side lowercase / trim / truncate / re-order on
18144        // the `caixa.to_string()` sole-field construction surfaces
18145        // here rather than at a downstream diagnostic-shape mismatch.
18146        // Peer of the sibling `nome_only_ctor_routes_caixa_through_
18147        // nome_accessor` / `entrada_host_invalid_ctor_routes_host_
18148        // through_to_string` / `contrato_target_ctors_route_edge_
18149        // triple_through_verbatim` / `contrato_empty_pair_ctors_
18150        // route_edge_pair_through_verbatim` cross-axis routing pins on
18151        // the peer `LayoutError` / `AplicacaoError` envelopes; extended
18152        // here onto the `SupervisorError` `{ caixa: String }` envelope
18153        // so every substrate-primitive ctor family in caixa-core
18154        // guarantees the sole-field construction routes the caller's
18155        // `&str` through `.to_string()` verbatim.
18156        let name = "cache-v2";
18157        assert_eq!(
18158            SupervisorError::empty_child_version(name),
18159            SupervisorError::EmptyChildVersion {
18160                caixa: name.to_string(),
18161            },
18162        );
18163        assert_eq!(
18164            SupervisorError::duplicate_child_caixa(name),
18165            SupervisorError::DuplicateChildCaixa {
18166                caixa: name.to_string(),
18167            },
18168        );
18169        assert_eq!(
18170            SupervisorError::child_supervises_self(name),
18171            SupervisorError::ChildSupervisesSelf {
18172                caixa: name.to_string(),
18173            },
18174        );
18175    }
18176
18177    // ── supervisor_scalar_ctors! per-variant + cross-axis pins ──────────────
18178    //
18179    // Per-variant byte-equality pins guaranteeing every generated ctor arm in
18180    // the [`supervisor_scalar_ctors!`] macro produces a `SupervisorError`
18181    // structurally identical to the pre-lift `Self::<variant> { <field>: <val> }`
18182    // one-line struct-literal on the same `Copy`-`RestartStrategy | u32 |
18183    // Duration` fixture, plus one cross-axis sweep that routes each per-variant
18184    // `<field>: <ty>` scalar through the sole `$field:ident: $ty:ty` axis the
18185    // macro exposes so any wrapper-side truncation / re-order / silent `.into()`
18186    // / silent constant-substitution on any one variant surfaces here rather
18187    // than at a downstream per-`:supervisor` diagnostic-shape drift. Peer of the
18188    // sibling per-variant pins on `aplicacao_policy_scalar_ctors!` (7ef425e,
18189    // the 8-variant `AplicacaoError` `{ <field>: Duration | u32 }` fold on the
18190    // per-`:politicas` per-axis cap / canonical-form arms), plus the sibling
18191    // `supervisor_caixa_only_ctors!` (db09650), `SupervisorError::
18192    // {child_caixa_invalid,child_versao_invalid}` (d2ef2ec), and the peer
18193    // `DepError` / `AplicacaoError` / `LayoutError` / `LimitsError` /
18194    // `BehaviorError` / `UpgradeError` per-envelope ctor-macro pins.
18195    #[test]
18196    fn no_children_ctor_matches_struct_literal_wrap() {
18197        let estrategia = RestartStrategy::OneForAll;
18198        assert_eq!(
18199            SupervisorError::no_children(estrategia),
18200            SupervisorError::NoChildren { estrategia },
18201            "generated no_children ctor must produce byte-equal \
18202             `SupervisorError::NoChildren` to the pre-lift struct-literal wrap \
18203             on the same `Copy`-`RestartStrategy` fixture",
18204        );
18205    }
18206
18207    #[test]
18208    fn max_restarts_exceeds_cap_ctor_matches_struct_literal_wrap() {
18209        let max_restarts = SUPERVISOR_MAX_RESTARTS_MAX + 1;
18210        assert_eq!(
18211            SupervisorError::max_restarts_exceeds_cap(max_restarts),
18212            SupervisorError::MaxRestartsExceedsCap { max_restarts },
18213            "generated max_restarts_exceeds_cap ctor must produce byte-equal \
18214             `SupervisorError::MaxRestartsExceedsCap` to the pre-lift \
18215             struct-literal wrap on the same `Copy`-`u32` fixture",
18216        );
18217    }
18218
18219    #[test]
18220    fn restart_window_not_canonical_ctor_matches_struct_literal_wrap() {
18221        let window = Duration::from_micros(1_500);
18222        assert_eq!(
18223            SupervisorError::restart_window_not_canonical(window),
18224            SupervisorError::RestartWindowNotCanonical { window },
18225            "generated restart_window_not_canonical ctor must produce \
18226             byte-equal `SupervisorError::RestartWindowNotCanonical` to the \
18227             pre-lift struct-literal wrap on the same `Copy`-`Duration` fixture",
18228        );
18229    }
18230
18231    #[test]
18232    fn restart_window_exceeds_cap_ctor_matches_struct_literal_wrap() {
18233        let window = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_millis(1);
18234        assert_eq!(
18235            SupervisorError::restart_window_exceeds_cap(window),
18236            SupervisorError::RestartWindowExceedsCap { window },
18237            "generated restart_window_exceeds_cap ctor must produce \
18238             byte-equal `SupervisorError::RestartWindowExceedsCap` to the \
18239             pre-lift struct-literal wrap on the same `Copy`-`Duration` fixture",
18240        );
18241    }
18242
18243    #[test]
18244    fn supervisor_scalar_ctors_route_field_through_copy_uniformly() {
18245        // Cross-axis routing pin: sweep each generated `<field>: <ty>`
18246        // constructor input axis through a non-default `Copy` fixture against
18247        // every arm in the [`supervisor_scalar_ctors!`] macro, so any wrapper-
18248        // side silent `.into()` / silent constant-substitution / silent field
18249        // re-name away from the canonical `estrategia | max_restarts | window`
18250        // axes on any one variant, or a `RestartStrategy | u32 | Duration`
18251        // axis silently rerouted through some other `Copy` coercion, surfaces
18252        // here rather than at a downstream per-`:supervisor` diagnostic-shape
18253        // drift. Peer of the sibling
18254        // `aplicacao_policy_scalar_ctors_route_field_through_copy_uniformly`
18255        // (7ef425e) cross-axis routing pin on the peer `AplicacaoError`
18256        // envelope's per-`:politicas` per-axis ctor family, extended here onto
18257        // the last M2 per-`:supervisor` `Copy`-scalar `SupervisorError`
18258        // variant family folded onto a substrate primitive.
18259        //
18260        // Fixtures picked out of each variant's accept-set boundary rather
18261        // than the default value so a silent constant-substitution to a per-
18262        // variant sentinel surfaces here on the structural-equality assertion.
18263        // The `RestartStrategy` fixture picks `RestForOne` (a non-default arm
18264        // that isn't the `OneForOne` [`SUPERVISOR_ESTRATEGIA_DEFAULT`] and
18265        // isn't the `SimpleOneForOne` arm the sibling
18266        // `SimpleOneForOneWithStaticChildren` unit variant intercepts). The
18267        // `max_restarts` fixture picks an above-cap magnitude the cap arm
18268        // rejects; the two `Duration` fixtures pick the sub-millisecond and
18269        // above-cap ends of the `:restart-window` canonical-form + cap
18270        // bracket respectively.
18271        let estrategia = RestartStrategy::RestForOne;
18272        let above_cap_restarts = SUPERVISOR_MAX_RESTARTS_MAX + 137;
18273        let sub_ms = Duration::from_micros(1_500);
18274        let above_hour = SUPERVISOR_RESTART_WINDOW_MAX + Duration::from_secs(1);
18275        assert_eq!(
18276            SupervisorError::no_children(estrategia),
18277            SupervisorError::NoChildren { estrategia },
18278        );
18279        assert_eq!(
18280            SupervisorError::max_restarts_exceeds_cap(above_cap_restarts),
18281            SupervisorError::MaxRestartsExceedsCap {
18282                max_restarts: above_cap_restarts,
18283            },
18284        );
18285        assert_eq!(
18286            SupervisorError::restart_window_not_canonical(sub_ms),
18287            SupervisorError::RestartWindowNotCanonical { window: sub_ms },
18288        );
18289        assert_eq!(
18290            SupervisorError::restart_window_exceeds_cap(above_hour),
18291            SupervisorError::RestartWindowExceedsCap { window: above_hour },
18292        );
18293    }
18294
18295    #[test]
18296    fn restart_strategy_try_from_bytes_routes_through_from_wire_accessor() {
18297        // Fail-before-pass-after byte-parity pin on the newly lifted
18298        // `impl TryFrom<&[u8]> for RestartStrategy` — asserts the trait-
18299        // idiomatic byte-view reverse-projection standard-library impl
18300        // and the substrate-primitive [`RestartStrategy::from_wire`]
18301        // `Option<Self>` accessor resolve to the same four-arm
18302        // `PascalCase` wire accept-set across every arm the exhaustive
18303        // [`RestartStrategy::ALL`] slice enumerates. Extends the
18304        // substrate-wide trait-idiomatic byte-view reverse-projection
18305        // axis onto the first M2-OTP-shape supervisor-slot closed-set
18306        // fieldless typed enum peer — mirror of the paired
18307        // [`TryFrom<&str> for RestartStrategy`] str-view reverse-
18308        // projection axis on the same enum, and the byte-view companion
18309        // of the pre-existing byte-owned reverse-projection family
18310        // ([`AsRef<[u8]>`], [`From<RestartStrategy> for Vec<u8>`],
18311        // [`From<&RestartStrategy> for Vec<u8>`]) on this same enum.
18312        // Peer of the sibling
18313        // [`crate::kind::tests::caixa_kind_try_from_bytes_routes_through_from_wire_accessor`]
18314        // (18d1940),
18315        // [`crate::dialeto::tests::caixa_dialeto_try_from_bytes_routes_through_from_wire_accessor`]
18316        // (d102cb8), and
18317        // [`crate::dep::tests::dep_list_try_from_bytes_routes_through_from_wire_accessor`]
18318        // (b8f25d5) — tracks the "route through `from_wire` via
18319        // `std::str::from_utf8`" discipline the first-mover established.
18320        //
18321        // Rust's standard library carries no blanket
18322        // `impl<T: for<'a> TryFrom<&'a str>> TryFrom<&[u8]> for T`, so
18323        // a two-hop composition through [`std::str::from_utf8`] + the
18324        // paired [`TryFrom<&str>`] axis is reachable through the pre-
18325        // existing str-view reverse-projection axis alone. But that
18326        // two-hop shape has no compile-time link back to the byte-view
18327        // reverse-projection axis, forces every downstream
18328        // `<T: for<'a> TryFrom<&'a [u8]>>`-bound consumer to open-code
18329        // the composition at every call site, and admits a silent split
18330        // whenever a future call site takes a sibling byte-projection
18331        // axis whose parse arm-set carries no compile-time byte-view
18332        // surface. This impl closes the byte-view reverse-projection
18333        // axis at the substrate-primitive [`RestartStrategy::from_wire`]
18334        // accessor so every future `<T: for<'a> TryFrom<&'a [u8]>>`-
18335        // bound consumer reaches the same four-arm `PascalCase` wire
18336        // accept-set through one trait dispatch.
18337        for &variant in RestartStrategy::ALL {
18338            let wire_bytes: &[u8] = variant.as_str().as_bytes();
18339            assert_eq!(
18340                <RestartStrategy as TryFrom<&[u8]>>::try_from(wire_bytes),
18341                Ok(variant),
18342                "TryFrom<&[u8]> impl on RestartStrategy must round-trip \
18343                 RestartStrategy::{variant:?}.as_str().as_bytes() back to \
18344                 Ok(RestartStrategy::{variant:?}) — divergence from \
18345                 RestartStrategy::from_wire signals a silent detour off \
18346                 the substrate-primitive accessor"
18347            );
18348            assert_eq!(
18349                <RestartStrategy as TryFrom<&[u8]>>::try_from(wire_bytes).ok(),
18350                RestartStrategy::from_wire(variant.as_str()),
18351                "TryFrom<&[u8]> ok()-projection on \
18352                 RestartStrategy::{variant:?}.as_str().as_bytes() must \
18353                 byte-equal RestartStrategy::from_wire on the paired \
18354                 &str input"
18355            );
18356            // Cross-axis witness: the byte-view reverse-projection axis
18357            // must agree with the paired str-view reverse-projection
18358            // axis ([`TryFrom<&str>`]) on every accepted arm — the two
18359            // reverse paths share one `PascalCase` accept-set through
18360            // the substrate-primitive `from_wire` accessor.
18361            let via_str: Result<RestartStrategy, ()> =
18362                <RestartStrategy as TryFrom<&str>>::try_from(variant.as_str());
18363            let via_bytes: Result<RestartStrategy, ()> =
18364                <RestartStrategy as TryFrom<&[u8]>>::try_from(wire_bytes);
18365            assert_eq!(
18366                via_bytes, via_str,
18367                "TryFrom<&[u8]> and TryFrom<&str> reverse-projection \
18368                 axes on RestartStrategy must agree on \
18369                 RestartStrategy::{variant:?} — divergence signals the \
18370                 byte-view and str-view reverse paths have drifted off \
18371                 the same substrate-primitive from_wire accessor"
18372            );
18373            // Forward/reverse byte-view cross-axis witness: feed the
18374            // paired [`AsRef<[u8]>`] byte-tail back through the new
18375            // impl and assert it round-trips to the originating arm.
18376            let via_asref: &[u8] = <RestartStrategy as AsRef<[u8]>>::as_ref(&variant);
18377            assert_eq!(
18378                <RestartStrategy as TryFrom<&[u8]>>::try_from(via_asref),
18379                Ok(variant),
18380                "TryFrom<&[u8]> ∘ AsRef<[u8]> must round-trip \
18381                 RestartStrategy::{variant:?} — divergence signals the \
18382                 forward and reverse byte-view axes have drifted off \
18383                 the same substrate-primitive as_str/from_wire pair"
18384            );
18385        }
18386    }
18387
18388    #[test]
18389    fn restart_strategy_try_from_bytes_rejects_unknown_and_non_utf8_bytes() {
18390        // Rejection witness on the `impl TryFrom<&[u8]> for
18391        // RestartStrategy` — sweeps two rejection paths the byte-view
18392        // reverse-projection axis collapses onto the single unit-error
18393        // `Err(())` return: the invalid-UTF-8 rejection path
18394        // ([`std::str::from_utf8`] returns `Err` before
18395        // [`RestartStrategy::from_wire`] runs) and the valid-UTF-8-but-
18396        // unknown-wire rejection path ([`RestartStrategy::from_wire`]
18397        // returns `None` on a byte-string outside the four-arm
18398        // `PascalCase` accept-set). Both must reject, so a future
18399        // accidental widening of the trait impl's accept-set (a case-
18400        // fold path, a silent acceptance of the kebab-case dispatcher-
18401        // catalog byte-strings on this axis — which would collide the
18402        // two-axis wire/catalog split the sibling
18403        // [`RestartStrategy::from_wire`] doc block makes load-bearing —
18404        // a `#[serde(rename_all = "…")]` attribute drift that widens
18405        // the parse arm-set silently, a stray fallback that maps
18406        // invalid UTF-8 onto a default arm rather than the trait-
18407        // idiomatic `Err(())`) trips at caixa-core test time. Peer of
18408        // the sibling
18409        // [`crate::kind::tests::caixa_kind_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18410        // (18d1940),
18411        // [`crate::dialeto::tests::caixa_dialeto_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18412        // (d102cb8), and
18413        // [`crate::dep::tests::dep_list_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18414        // (b8f25d5) rejection witnesses.
18415        //
18416        // Non-UTF-8 candidates:
18417        //   - a lone 0xFF byte (never valid as a UTF-8 leading byte)
18418        //   - a lone 0x80 continuation byte with no leading byte
18419        //   - a truncated multi-byte sequence (0xC3 without its continuation)
18420        //   - a UTF-16 BOM-style byte pair the UTF-8 validator rejects
18421        //   - a UTF-16 surrogate half rejected by UTF-8
18422        let non_utf8_rejected: &[&[u8]] = &[
18423            &[0xFF],
18424            &[0x80],
18425            &[0xC3],
18426            &[0xFF, 0xFE],
18427            &[0xED, 0xA0, 0x80],
18428        ];
18429        for &input in non_utf8_rejected {
18430            assert_eq!(
18431                <RestartStrategy as TryFrom<&[u8]>>::try_from(input),
18432                Err(()),
18433                "TryFrom<&[u8]> impl on RestartStrategy must reject the \
18434                 non-UTF-8 byte-sequence {input:?} with Err(()) — \
18435                 silent acceptance signals the UTF-8 validation path \
18436                 collapsed onto a default arm rather than the trait-\
18437                 idiomatic unit-error"
18438            );
18439        }
18440        // Valid-UTF-8-but-unknown-wire candidates mirror the corpus
18441        // the sibling `restart_strategy_try_from_str_rejects_unknown_byte_strings`
18442        // (5b828ed) str-view rejection witness already pins on the
18443        // paired [`TryFrom<&str>`] axis: the empty byte-string,
18444        // whitespace-only padding, the kebab-case dispatcher-catalog
18445        // byte-strings on the sibling axis the pre-existing
18446        // [`std::str::FromStr`] impl the [`gen_platform::FromStrKind`]
18447        // derive installs parses onto (a caller who confuses the two
18448        // axes trips here rather than at a downstream K8s-CR round-
18449        // trip miss), lowercase / uppercase / mixed-case folds of each
18450        // `PascalCase` arm, whitespace-padded / trailing-newline /
18451        // quote-wrapped forms, and plausible-but-wrong English rebrand
18452        // candidates.
18453        let unknown_wire_rejected: &[&[u8]] = &[
18454            b"",
18455            b" ",
18456            b"\n",
18457            b"\t",
18458            b"one-for-one",
18459            b"one-for-all",
18460            b"rest-for-one",
18461            b"simple-one-for-one",
18462            b"oneforone",
18463            b"one_for_one",
18464            b"OneForOnes",
18465            b"ONEFORONE",
18466            b"oneforall",
18467            b"restforone",
18468            b"simpleoneforone",
18469            b"OneForOne ",
18470            b" OneForOne",
18471            b" OneForAll ",
18472            b"OneForOne\n",
18473            b"RestForOne\t",
18474            b"OneForEach",
18475            b"AllForOne",
18476            b"one for one",
18477            b"\"OneForOne\"",
18478            b"?",
18479        ];
18480        for &input in unknown_wire_rejected {
18481            assert_eq!(
18482                <RestartStrategy as TryFrom<&[u8]>>::try_from(input),
18483                Err(()),
18484                "TryFrom<&[u8]> impl on RestartStrategy must reject the \
18485                 valid-UTF-8-but-unknown-wire byte-string {input:?} \
18486                 with Err(()) — silent acceptance signals an accept-\
18487                 set widening off the paired RestartStrategy::from_wire \
18488                 resolver"
18489            );
18490            // Cross-axis witness: on a byte-string that is valid UTF-8,
18491            // the byte-view reverse-projection axis must agree with the
18492            // paired str-view reverse-projection axis
18493            // ([`TryFrom<&str>`]) — both route through the same
18494            // [`RestartStrategy::from_wire`] resolver, so the two
18495            // rejection paths align by construction.
18496            if let Ok(s) = std::str::from_utf8(input) {
18497                assert_eq!(
18498                    <RestartStrategy as TryFrom<&[u8]>>::try_from(input),
18499                    <RestartStrategy as TryFrom<&str>>::try_from(s),
18500                    "TryFrom<&[u8]> and TryFrom<&str> reverse-\
18501                     projection axes on RestartStrategy must agree on \
18502                     the valid-UTF-8 input {input:?} — divergence \
18503                     signals the two reverse paths have drifted off \
18504                     the same substrate-primitive from_wire accessor"
18505                );
18506            }
18507        }
18508    }
18509
18510    #[test]
18511    fn restart_strategy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis() {
18512        // Fail-before-pass-after byte-parity pin on the newly lifted
18513        // `impl TryFrom<Vec<u8>> for RestartStrategy` — asserts the trait-
18514        // idiomatic owned-byte-vec reverse-projection standard-library
18515        // impl and the sibling borrowed-input [`TryFrom<&[u8]>`] axis
18516        // resolve to the same four-arm `PascalCase` wire accept-set
18517        // across every arm the exhaustive [`RestartStrategy::ALL`] slice
18518        // enumerates. Extends the substrate-wide trait-idiomatic byte-
18519        // owned reverse-projection axis onto the first M2-OTP-shape
18520        // supervisor-slot closed-set fieldless typed enum peer — owned-
18521        // input mirror of the paired [`TryFrom<&[u8]>`] byte-view
18522        // reverse-projection axis (c699a83), and byte-owned reverse
18523        // companion of the pre-existing byte-owned *forward*-projection
18524        // pair ([`From<RestartStrategy> for Vec<u8>`],
18525        // [`From<&RestartStrategy> for Vec<u8>`]) on this same enum.
18526        // Peer of the sibling first-mover
18527        // [`crate::kind::tests::caixa_kind_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
18528        // (99c2849) on the [`crate::CaixaKind`] closed-set typed-enum
18529        // peer, the sibling second-mover
18530        // [`crate::dialeto::tests::caixa_dialeto_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
18531        // (83a1526) on the [`crate::CaixaDialeto`] peer, and the sibling
18532        // third-mover
18533        // [`crate::dep::tests::dep_list_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
18534        // (42091cb) on the [`crate::dep::DepList`] peer — tracks the
18535        // "delegate through `TryFrom<&[u8]>` on the `Vec<u8>::as_slice`
18536        // borrow" discipline the first-mover established.
18537        //
18538        // Rust's standard library carries no blanket
18539        // `impl<T: for<'a> TryFrom<&'a [u8]>> TryFrom<Vec<u8>> for T`,
18540        // so an owned-byte-vec caller otherwise picks between an open-
18541        // coded `<T as TryFrom<&[u8]>>::try_from(bytes.as_slice())` at
18542        // every call site whose type bounds have no compile-time link
18543        // back to the byte-owned reverse-projection axis, or a
18544        // `String::from_utf8(bytes)` two-hop shape whose error surface
18545        // leaks the standard-library `FromUtf8Error` type. This impl
18546        // closes the byte-owned reverse-projection axis at the
18547        // substrate-primitive [`RestartStrategy::from_wire`] accessor so
18548        // every future `<T: TryFrom<Vec<u8>>>`-bound owned-byte-vec
18549        // consumer reaches the same four-arm `PascalCase` wire accept-
18550        // set through one trait dispatch.
18551        for &variant in RestartStrategy::ALL {
18552            let wire_bytes: Vec<u8> = variant.as_str().as_bytes().to_vec();
18553            assert_eq!(
18554                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(wire_bytes.clone()),
18555                Ok(variant),
18556                "TryFrom<Vec<u8>> impl on RestartStrategy must round-trip \
18557                 RestartStrategy::{variant:?}.as_str().as_bytes().to_vec() \
18558                 back to Ok(RestartStrategy::{variant:?}) — divergence \
18559                 from the sibling TryFrom<&[u8]> axis signals a silent \
18560                 detour off the substrate-primitive from_wire accessor"
18561            );
18562            // Cross-axis witness: the owned-byte-vec reverse-projection
18563            // axis must agree with the borrowed byte-slice reverse-
18564            // projection axis on every accepted arm — the two axes share
18565            // one `PascalCase` wire vocabulary through the substrate-
18566            // primitive `from_wire` accessor, and the owned-input axis
18567            // delegates to the borrowed peer by design.
18568            let via_owned: Result<RestartStrategy, ()> =
18569                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(wire_bytes.clone());
18570            let via_borrowed: Result<RestartStrategy, ()> =
18571                <RestartStrategy as TryFrom<&[u8]>>::try_from(wire_bytes.as_slice());
18572            assert_eq!(
18573                via_owned, via_borrowed,
18574                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
18575                 axes on RestartStrategy must agree on \
18576                 RestartStrategy::{variant:?} — divergence signals the \
18577                 owned-input and borrowed-input byte-view reverse paths \
18578                 have drifted off the same substrate-primitive \
18579                 from_wire accessor"
18580            );
18581            // Cross-axis witness against the paired str-view reverse
18582            // axis ([`TryFrom<&str>`]) — the three reverse paths (str-
18583            // view, byte-view borrowed, byte-view owned) share one
18584            // substrate primitive.
18585            let via_str: Result<RestartStrategy, ()> =
18586                <RestartStrategy as TryFrom<&str>>::try_from(variant.as_str());
18587            assert_eq!(
18588                via_owned, via_str,
18589                "TryFrom<Vec<u8>> and TryFrom<&str> reverse-projection \
18590                 axes on RestartStrategy must agree on \
18591                 RestartStrategy::{variant:?} — divergence signals the \
18592                 byte-owned and str-view reverse paths have drifted off \
18593                 the same substrate-primitive from_wire accessor"
18594            );
18595            // Four-corner witness: because [`RestartStrategy`] carries
18596            // no wire-vs-diagnostic split (as_str and from_wire share
18597            // one `PascalCase` byte-vocabulary — unlike the sibling
18598            // [`crate::CaixaKind`] whose peer test deliberately declines
18599            // this witness), the byte-owned reverse-projection axis on
18600            // this enum *does* round-trip against the paired byte-owned
18601            // forward-projection pair. Pin every corner of the {owned-
18602            // input, borrowed-input} × {From<Self> → Vec<u8>,
18603            // From<&Self> → Vec<u8>} square onto the same Ok(variant)
18604            // return so a future accident that drops one corner off the
18605            // substrate-primitive accessor trips here.
18606            let owned_forward: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
18607            let borrowed_forward: Vec<u8> = <Vec<u8> as From<&RestartStrategy>>::from(&variant);
18608            assert_eq!(
18609                owned_forward, wire_bytes,
18610                "From<RestartStrategy> for Vec<u8> forward projection on \
18611                 RestartStrategy::{variant:?} must byte-equal \
18612                 variant.as_str().as_bytes().to_vec() — divergence \
18613                 signals the paired forward pair drifted off the \
18614                 substrate-primitive as_str accessor"
18615            );
18616            assert_eq!(
18617                borrowed_forward, wire_bytes,
18618                "From<&RestartStrategy> for Vec<u8> forward projection \
18619                 on &RestartStrategy::{variant:?} must byte-equal \
18620                 variant.as_str().as_bytes().to_vec() — divergence \
18621                 signals the paired forward pair drifted off the \
18622                 substrate-primitive as_str accessor"
18623            );
18624            assert_eq!(
18625                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(owned_forward.clone()),
18626                Ok(variant),
18627                "Four-corner round-trip on RestartStrategy::{variant:?} \
18628                 through From<RestartStrategy> for Vec<u8> then \
18629                 TryFrom<Vec<u8>> for RestartStrategy must return \
18630                 Ok(variant) — divergence signals the byte-owned \
18631                 forward pair and the byte-owned reverse axis have \
18632                 drifted apart"
18633            );
18634            assert_eq!(
18635                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(borrowed_forward),
18636                Ok(variant),
18637                "Four-corner round-trip on RestartStrategy::{variant:?} \
18638                 through From<&RestartStrategy> for Vec<u8> then \
18639                 TryFrom<Vec<u8>> for RestartStrategy must return \
18640                 Ok(variant) — divergence signals the borrowed-input \
18641                 forward corner and the owned-input reverse corner have \
18642                 drifted apart"
18643            );
18644        }
18645    }
18646
18647    #[test]
18648    fn restart_strategy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes() {
18649        // Rejection witness on the `impl TryFrom<Vec<u8>> for
18650        // RestartStrategy` — sweeps the same two rejection paths the
18651        // sibling borrowed `TryFrom<&[u8]>` axis collapses onto the
18652        // single unit-error return: the invalid-UTF-8 rejection path
18653        // (`std::str::from_utf8` on the underlying byte-slice returns
18654        // `Err` before [`RestartStrategy::from_wire`] runs) and the
18655        // valid-UTF-8-but-unknown-wire rejection path
18656        // ([`RestartStrategy::from_wire`] returns `None` on a byte-
18657        // string outside the four-arm `PascalCase` accept-set). Both
18658        // must reject so a future accidental widening of the trait
18659        // impl's accept-set (a case-fold path, a silent acceptance of
18660        // the kebab-case dispatcher-catalog byte-strings on this axis —
18661        // which would collide the two-axis wire/catalog split the
18662        // sibling [`RestartStrategy::from_wire`] doc block makes load-
18663        // bearing — a `#[serde(rename_all = "…")]` attribute drift that
18664        // widens the parse arm-set silently, a stray
18665        // `String::from_utf8_lossy` detour that widens the input
18666        // surface with the U+FFFD replacement character, an
18667        // `Option::unwrap_or_default`-shape fallback that maps invalid
18668        // UTF-8 onto a default arm rather than the trait-idiomatic
18669        // `Err(())`) trips at caixa-core test time. Peer of the sibling
18670        // first-mover
18671        // [`crate::kind::tests::caixa_kind_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
18672        // (99c2849) on the [`crate::CaixaKind`] peer, the sibling
18673        // second-mover
18674        // [`crate::dialeto::tests::caixa_dialeto_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
18675        // (83a1526) on the [`crate::CaixaDialeto`] peer, and the
18676        // sibling third-mover
18677        // [`crate::dep::tests::dep_list_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
18678        // (42091cb) on the [`crate::dep::DepList`] peer rejection
18679        // witnesses.
18680        let non_utf8_rejected: &[&[u8]] = &[
18681            &[0xFF],
18682            &[0x80],
18683            &[0xC3],
18684            &[0xFF, 0xFE],
18685            &[0xED, 0xA0, 0x80], // UTF-16 surrogate half — rejected by UTF-8
18686        ];
18687        for &input in non_utf8_rejected {
18688            let owned: Vec<u8> = input.to_vec();
18689            assert_eq!(
18690                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(owned),
18691                Err(()),
18692                "TryFrom<Vec<u8>> impl on RestartStrategy must reject \
18693                 the non-UTF-8 byte-sequence {input:?} with Err(()) — \
18694                 silent acceptance signals the UTF-8 validation path \
18695                 collapsed onto a default arm rather than the trait-\
18696                 idiomatic unit-error"
18697            );
18698            // Cross-axis witness: the owned-input axis must agree with
18699            // the borrowed-input axis on every rejected input.
18700            assert_eq!(
18701                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(input.to_vec()),
18702                <RestartStrategy as TryFrom<&[u8]>>::try_from(input),
18703                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
18704                 axes on RestartStrategy must agree on the non-UTF-8 \
18705                 input {input:?} — divergence signals the owned-input \
18706                 and borrowed-input byte-view reverse paths have drifted \
18707                 off the same substrate-primitive from_wire accessor"
18708            );
18709        }
18710        // Valid-UTF-8-but-unknown-wire candidates mirror the corpus the
18711        // sibling borrowed-input rejection witness
18712        // [`restart_strategy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18713        // (c699a83) already pins on the paired byte-view axis: the
18714        // empty byte-string, whitespace-only padding, the kebab-case
18715        // dispatcher-catalog byte-strings on the sibling axis the pre-
18716        // existing [`std::str::FromStr`] impl the
18717        // [`gen_platform::FromStrKind`] derive installs parses onto (a
18718        // caller who confuses the two axes trips here rather than at a
18719        // downstream K8s-CR round-trip miss), lowercase / uppercase /
18720        // mixed-case folds of each `PascalCase` arm, whitespace-padded
18721        // / trailing-newline / quote-wrapped forms, and plausible-but-
18722        // wrong English rebrand candidates.
18723        let unknown_wire_rejected: &[&[u8]] = &[
18724            b"",
18725            b" ",
18726            b"\n",
18727            b"\t",
18728            b"one-for-one",
18729            b"one-for-all",
18730            b"rest-for-one",
18731            b"simple-one-for-one",
18732            b"oneforone",
18733            b"one_for_one",
18734            b"OneForOnes",
18735            b"ONEFORONE",
18736            b"oneforall",
18737            b"restforone",
18738            b"simpleoneforone",
18739            b"OneForOne ",
18740            b" OneForOne",
18741            b" OneForAll ",
18742            b"OneForOne\n",
18743            b"RestForOne\t",
18744            b"OneForEach",
18745            b"AllForOne",
18746            b"one for one",
18747            b"\"OneForOne\"",
18748            b"?",
18749        ];
18750        for &input in unknown_wire_rejected {
18751            let owned: Vec<u8> = input.to_vec();
18752            assert_eq!(
18753                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(owned),
18754                Err(()),
18755                "TryFrom<Vec<u8>> impl on RestartStrategy must reject \
18756                 the valid-UTF-8-but-unknown-wire byte-string {input:?} \
18757                 with Err(()) — silent acceptance signals an accept-\
18758                 set widening off the paired RestartStrategy::from_wire \
18759                 resolver"
18760            );
18761            // Cross-axis witness against the borrowed byte-view axis:
18762            // the two paths must agree by construction, since the owned
18763            // axis delegates to the borrowed peer.
18764            assert_eq!(
18765                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(input.to_vec()),
18766                <RestartStrategy as TryFrom<&[u8]>>::try_from(input),
18767                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
18768                 axes on RestartStrategy must agree on the valid-UTF-8-\
18769                 but-unknown-wire input {input:?} — divergence signals \
18770                 the owned-input and borrowed-input byte-view reverse \
18771                 paths have drifted off the same substrate-primitive \
18772                 from_wire accessor"
18773            );
18774        }
18775    }
18776
18777    #[test]
18778    fn restart_policy_try_from_bytes_routes_through_from_wire_accessor() {
18779        // Fail-before-pass-after byte-parity pin on the newly lifted
18780        // `impl TryFrom<&[u8]> for RestartPolicy` — asserts the trait-
18781        // idiomatic byte-view reverse-projection standard-library impl
18782        // and the substrate-primitive [`RestartPolicy::from_wire`]
18783        // `Option<Self>` accessor resolve to the same three-arm
18784        // `PascalCase` wire accept-set across every arm the exhaustive
18785        // [`RestartPolicy::ALL`] slice enumerates. Closes the substrate-
18786        // wide trait-idiomatic byte-view reverse-projection axis on the
18787        // M2-OTP-shape `:supervisor :estrategia` + `:children :restart`
18788        // slot pair the sibling [`RestartStrategy`] first-mover
18789        // (c699a83) opened one commit prior — mirror of the paired
18790        // [`TryFrom<&str> for RestartPolicy`] str-view reverse-
18791        // projection axis on the same enum, and the byte-view companion
18792        // of the pre-existing byte-owned reverse-projection family
18793        // ([`AsRef<[u8]>`], [`From<RestartPolicy> for Vec<u8>`],
18794        // [`From<&RestartPolicy> for Vec<u8>`]) on this same enum. Peer
18795        // of the sibling
18796        // [`restart_strategy_try_from_bytes_routes_through_from_wire_accessor`]
18797        // (c699a83),
18798        // [`crate::kind::tests::caixa_kind_try_from_bytes_routes_through_from_wire_accessor`]
18799        // (18d1940),
18800        // [`crate::dialeto::tests::caixa_dialeto_try_from_bytes_routes_through_from_wire_accessor`]
18801        // (d102cb8), and
18802        // [`crate::dep::tests::dep_list_try_from_bytes_routes_through_from_wire_accessor`]
18803        // (b8f25d5) — tracks the "route through `from_wire` via
18804        // `std::str::from_utf8`" discipline the first-mover established.
18805        //
18806        // Rust's standard library carries no blanket
18807        // `impl<T: for<'a> TryFrom<&'a str>> TryFrom<&[u8]> for T`, so a
18808        // two-hop composition through [`std::str::from_utf8`] + the
18809        // paired [`TryFrom<&str>`] axis is reachable through the pre-
18810        // existing str-view reverse-projection axis alone. But that
18811        // two-hop shape has no compile-time link back to the byte-view
18812        // reverse-projection axis, forces every downstream
18813        // `<T: for<'a> TryFrom<&'a [u8]>>`-bound consumer to open-code
18814        // the composition at every call site, and admits a silent split
18815        // whenever a future call site takes a sibling byte-projection
18816        // axis whose parse arm-set carries no compile-time byte-view
18817        // surface. This impl closes the byte-view reverse-projection
18818        // axis at the substrate-primitive [`RestartPolicy::from_wire`]
18819        // accessor so every future `<T: for<'a> TryFrom<&'a [u8]>>`-
18820        // bound consumer reaches the same three-arm `PascalCase` wire
18821        // accept-set through one trait dispatch.
18822        for &variant in RestartPolicy::ALL {
18823            let wire_bytes: &[u8] = variant.as_str().as_bytes();
18824            assert_eq!(
18825                <RestartPolicy as TryFrom<&[u8]>>::try_from(wire_bytes),
18826                Ok(variant),
18827                "TryFrom<&[u8]> impl on RestartPolicy must round-trip \
18828                 RestartPolicy::{variant:?}.as_str().as_bytes() back to \
18829                 Ok(RestartPolicy::{variant:?}) — divergence from \
18830                 RestartPolicy::from_wire signals a silent detour off \
18831                 the substrate-primitive accessor"
18832            );
18833            assert_eq!(
18834                <RestartPolicy as TryFrom<&[u8]>>::try_from(wire_bytes).ok(),
18835                RestartPolicy::from_wire(variant.as_str()),
18836                "TryFrom<&[u8]> ok()-projection on \
18837                 RestartPolicy::{variant:?}.as_str().as_bytes() must \
18838                 byte-equal RestartPolicy::from_wire on the paired \
18839                 &str input"
18840            );
18841            // Cross-axis witness: the byte-view reverse-projection axis
18842            // must agree with the paired str-view reverse-projection
18843            // axis ([`TryFrom<&str>`]) on every accepted arm — the two
18844            // reverse paths share one `PascalCase` accept-set through
18845            // the substrate-primitive `from_wire` accessor.
18846            let via_str: Result<RestartPolicy, ()> =
18847                <RestartPolicy as TryFrom<&str>>::try_from(variant.as_str());
18848            let via_bytes: Result<RestartPolicy, ()> =
18849                <RestartPolicy as TryFrom<&[u8]>>::try_from(wire_bytes);
18850            assert_eq!(
18851                via_bytes, via_str,
18852                "TryFrom<&[u8]> and TryFrom<&str> reverse-projection \
18853                 axes on RestartPolicy must agree on \
18854                 RestartPolicy::{variant:?} — divergence signals the \
18855                 byte-view and str-view reverse paths have drifted off \
18856                 the same substrate-primitive from_wire accessor"
18857            );
18858            // Forward/reverse byte-view cross-axis witness: feed the
18859            // paired [`AsRef<[u8]>`] byte-tail back through the new
18860            // impl and assert it round-trips to the originating arm.
18861            let via_asref: &[u8] = <RestartPolicy as AsRef<[u8]>>::as_ref(&variant);
18862            assert_eq!(
18863                <RestartPolicy as TryFrom<&[u8]>>::try_from(via_asref),
18864                Ok(variant),
18865                "TryFrom<&[u8]> ∘ AsRef<[u8]> must round-trip \
18866                 RestartPolicy::{variant:?} — divergence signals the \
18867                 forward and reverse byte-view axes have drifted off \
18868                 the same substrate-primitive as_str/from_wire pair"
18869            );
18870        }
18871    }
18872
18873    #[test]
18874    fn restart_policy_try_from_bytes_rejects_unknown_and_non_utf8_bytes() {
18875        // Rejection witness on the `impl TryFrom<&[u8]> for RestartPolicy`
18876        // — sweeps two rejection paths the byte-view reverse-projection
18877        // axis collapses onto the single unit-error `Err(())` return: the
18878        // invalid-UTF-8 rejection path ([`std::str::from_utf8`] returns
18879        // `Err` before [`RestartPolicy::from_wire`] runs) and the
18880        // valid-UTF-8-but-unknown-wire rejection path
18881        // ([`RestartPolicy::from_wire`] returns `None` on a byte-string
18882        // outside the three-arm `PascalCase` accept-set). Both must
18883        // reject, so a future accidental widening of the trait impl's
18884        // accept-set (a case-fold path, a silent acceptance of the
18885        // kebab-case dispatcher-catalog byte-strings on this axis — which
18886        // would collide the two-axis wire/catalog split the sibling
18887        // [`RestartPolicy::from_wire`] doc block makes load-bearing — a
18888        // `#[serde(rename_all = "…")]` attribute drift that widens the
18889        // parse arm-set silently, a stray fallback that maps invalid
18890        // UTF-8 onto a default arm rather than the trait-idiomatic
18891        // `Err(())`) trips at caixa-core test time. Peer of the sibling
18892        // [`restart_strategy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18893        // (c699a83),
18894        // [`crate::kind::tests::caixa_kind_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18895        // (18d1940),
18896        // [`crate::dialeto::tests::caixa_dialeto_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18897        // (d102cb8), and
18898        // [`crate::dep::tests::dep_list_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
18899        // (b8f25d5) rejection witnesses.
18900        //
18901        // Non-UTF-8 candidates:
18902        //   - a lone 0xFF byte (never valid as a UTF-8 leading byte)
18903        //   - a lone 0x80 continuation byte with no leading byte
18904        //   - a truncated multi-byte sequence (0xC3 without its continuation)
18905        //   - a UTF-16 BOM-style byte pair the UTF-8 validator rejects
18906        //   - a UTF-16 surrogate half rejected by UTF-8
18907        let non_utf8_rejected: &[&[u8]] = &[
18908            &[0xFF],
18909            &[0x80],
18910            &[0xC3],
18911            &[0xFF, 0xFE],
18912            &[0xED, 0xA0, 0x80],
18913        ];
18914        for &input in non_utf8_rejected {
18915            assert_eq!(
18916                <RestartPolicy as TryFrom<&[u8]>>::try_from(input),
18917                Err(()),
18918                "TryFrom<&[u8]> impl on RestartPolicy must reject the \
18919                 non-UTF-8 byte-sequence {input:?} with Err(()) — \
18920                 silent acceptance signals the UTF-8 validation path \
18921                 collapsed onto a default arm rather than the trait-\
18922                 idiomatic unit-error"
18923            );
18924        }
18925        // Valid-UTF-8-but-unknown-wire candidates mirror the corpus the
18926        // sibling `restart_policy_try_from_str_rejects_unknown_byte_strings`
18927        // str-view rejection witness already pins on the paired
18928        // [`TryFrom<&str>`] axis: the empty byte-string, whitespace-only
18929        // padding, the kebab-case dispatcher-catalog byte-strings on the
18930        // sibling axis the pre-existing [`std::str::FromStr`] impl the
18931        // [`gen_platform::FromStrKind`] derive installs parses onto (a
18932        // caller who confuses the two axes trips here rather than at a
18933        // downstream K8s-CR round-trip miss), lowercase / uppercase /
18934        // mixed-case folds of each `PascalCase` arm, whitespace-padded /
18935        // trailing-newline / quote-wrapped forms, and plausible-but-wrong
18936        // English rebrand candidates (`Ephemeral`, `Always`, `Never`,
18937        // `OnAbnormalExit`, `intrinsic`).
18938        let unknown_wire_rejected: &[&[u8]] = &[
18939            b"",
18940            b" ",
18941            b"\n",
18942            b"\t",
18943            b"permanent",
18944            b"temporary",
18945            b"transient",
18946            b"PERMANENT",
18947            b"TEMPORARY",
18948            b"TRANSIENT",
18949            b"Permanents",
18950            b"Permanent ",
18951            b" Permanent",
18952            b" Temporary ",
18953            b"Permanent\n",
18954            b"Transient\t",
18955            b"\"Permanent\"",
18956            b"Ephemeral",
18957            b"Always",
18958            b"Never",
18959            b"OnAbnormalExit",
18960            b"intrinsic",
18961            b"?",
18962        ];
18963        for &input in unknown_wire_rejected {
18964            assert_eq!(
18965                <RestartPolicy as TryFrom<&[u8]>>::try_from(input),
18966                Err(()),
18967                "TryFrom<&[u8]> impl on RestartPolicy must reject the \
18968                 valid-UTF-8-but-unknown-wire byte-string {input:?} \
18969                 with Err(()) — silent acceptance signals an accept-\
18970                 set widening off the paired RestartPolicy::from_wire \
18971                 resolver"
18972            );
18973            // Cross-axis witness: on a byte-string that is valid UTF-8,
18974            // the byte-view reverse-projection axis must agree with the
18975            // paired str-view reverse-projection axis
18976            // ([`TryFrom<&str>`]) — both route through the same
18977            // [`RestartPolicy::from_wire`] resolver, so the two
18978            // rejection paths align by construction.
18979            if let Ok(s) = std::str::from_utf8(input) {
18980                assert_eq!(
18981                    <RestartPolicy as TryFrom<&[u8]>>::try_from(input),
18982                    <RestartPolicy as TryFrom<&str>>::try_from(s),
18983                    "TryFrom<&[u8]> and TryFrom<&str> reverse-\
18984                     projection axes on RestartPolicy must agree on \
18985                     the valid-UTF-8 input {input:?} — divergence \
18986                     signals the two reverse paths have drifted off \
18987                     the same substrate-primitive from_wire accessor"
18988                );
18989            }
18990        }
18991    }
18992
18993    #[test]
18994    fn supervisor_scalar_ctors_are_const_zero_runtime_work() {
18995        // Const-eval pin: the [`supervisor_scalar_ctors!`] macro spells every
18996        // generated ctor `const fn` so a caller can pin a `SupervisorError`
18997        // at compile time — the same zero-runtime-work property the pre-lift
18998        // `|<slot>| SupervisorError::<Variant> { <slot> }` closure carried on
18999        // its `Copy`-pass-through construction path (no `.to_string()` /
19000        // `.into()` allocation, no branching). If any future edit silently
19001        // drops the `const` qualifier from the macro body the per-arm `const`
19002        // bindings below fail to compile, which surfaces the regression at
19003        // the substrate-primitive definition rather than at some downstream
19004        // consumer that had come to rely on the `const`-constructibility.
19005        // Peer of the sibling
19006        // `aplicacao_policy_scalar_ctors_are_const_zero_runtime_work`
19007        // (7ef425e) const-eval pin on the peer `AplicacaoError` envelope's
19008        // per-`:politicas` per-axis ctor family.
19009        const NO_CHILDREN: SupervisorError =
19010            SupervisorError::no_children(RestartStrategy::OneForAll);
19011        const MAX_RESTARTS_CAP: SupervisorError = SupervisorError::max_restarts_exceeds_cap(1_337);
19012        const WINDOW_NC: SupervisorError =
19013            SupervisorError::restart_window_not_canonical(Duration::from_micros(1));
19014        const WINDOW_CAP: SupervisorError =
19015            SupervisorError::restart_window_exceeds_cap(Duration::from_secs(3_601));
19016        assert!(matches!(NO_CHILDREN, SupervisorError::NoChildren { .. }));
19017        assert!(matches!(
19018            MAX_RESTARTS_CAP,
19019            SupervisorError::MaxRestartsExceedsCap { .. }
19020        ));
19021        assert!(matches!(
19022            WINDOW_NC,
19023            SupervisorError::RestartWindowNotCanonical { .. }
19024        ));
19025        assert!(matches!(
19026            WINDOW_CAP,
19027            SupervisorError::RestartWindowExceedsCap { .. }
19028        ));
19029    }
19030
19031    #[test]
19032    fn restart_policy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis() {
19033        // Fail-before-pass-after byte-parity pin on the newly lifted
19034        // `impl TryFrom<Vec<u8>> for RestartPolicy` — asserts the trait-
19035        // idiomatic owned-byte-vec reverse-projection standard-library
19036        // impl and the sibling borrowed-input [`TryFrom<&[u8]>`] axis
19037        // resolve to the same three-arm `PascalCase` wire accept-set
19038        // across every arm the exhaustive [`RestartPolicy::ALL`] slice
19039        // enumerates. Closes the substrate-wide trait-idiomatic byte-
19040        // owned reverse-projection axis on the M2-OTP-shape
19041        // `:supervisor :estrategia` + `:children :restart` slot pair the
19042        // sibling [`RestartStrategy`] first-mover
19043        // [`restart_strategy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
19044        // (34951fe) opened one commit-window prior — owned-input mirror
19045        // of the paired [`TryFrom<&[u8]>`] byte-view reverse-projection
19046        // axis on this same enum (d9ef5f0), and byte-owned reverse
19047        // companion of the pre-existing byte-owned *forward*-projection
19048        // pair ([`From<RestartPolicy> for Vec<u8>`],
19049        // [`From<&RestartPolicy> for Vec<u8>`]) on this same enum. Peer
19050        // of the sibling first-mover
19051        // [`crate::kind::tests::caixa_kind_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
19052        // (99c2849) on the [`crate::CaixaKind`] closed-set typed-enum
19053        // peer, the sibling second-mover
19054        // [`crate::dialeto::tests::caixa_dialeto_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
19055        // (83a1526) on the [`crate::CaixaDialeto`] peer, the sibling
19056        // third-mover
19057        // [`crate::dep::tests::dep_list_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
19058        // (42091cb) on the [`crate::dep::DepList`] peer, and the sibling
19059        // fourth-mover
19060        // [`restart_strategy_try_from_vec_bytes_routes_through_borrowed_byte_view_axis`]
19061        // (34951fe) on the [`RestartStrategy`] peer — tracks the
19062        // "delegate through `TryFrom<&[u8]>` on the `Vec<u8>::as_slice`
19063        // borrow" discipline the first-mover established.
19064        //
19065        // Rust's standard library carries no blanket
19066        // `impl<T: for<'a> TryFrom<&'a [u8]>> TryFrom<Vec<u8>> for T`,
19067        // so an owned-byte-vec caller otherwise picks between an open-
19068        // coded `<T as TryFrom<&[u8]>>::try_from(bytes.as_slice())` at
19069        // every call site whose type bounds have no compile-time link
19070        // back to the byte-owned reverse-projection axis, or a
19071        // `String::from_utf8(bytes)` two-hop shape whose error surface
19072        // leaks the standard-library `FromUtf8Error` type. This impl
19073        // closes the byte-owned reverse-projection axis at the
19074        // substrate-primitive [`RestartPolicy::from_wire`] accessor so
19075        // every future `<T: TryFrom<Vec<u8>>>`-bound owned-byte-vec
19076        // consumer reaches the same three-arm `PascalCase` wire accept-
19077        // set through one trait dispatch.
19078        for &variant in RestartPolicy::ALL {
19079            let wire_bytes: Vec<u8> = variant.as_str().as_bytes().to_vec();
19080            assert_eq!(
19081                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(wire_bytes.clone()),
19082                Ok(variant),
19083                "TryFrom<Vec<u8>> impl on RestartPolicy must round-trip \
19084                 RestartPolicy::{variant:?}.as_str().as_bytes().to_vec() \
19085                 back to Ok(RestartPolicy::{variant:?}) — divergence \
19086                 from the sibling TryFrom<&[u8]> axis signals a silent \
19087                 detour off the substrate-primitive from_wire accessor"
19088            );
19089            // Cross-axis witness: the owned-byte-vec reverse-projection
19090            // axis must agree with the borrowed byte-slice reverse-
19091            // projection axis on every accepted arm — the two axes share
19092            // one `PascalCase` wire vocabulary through the substrate-
19093            // primitive `from_wire` accessor, and the owned-input axis
19094            // delegates to the borrowed peer by design.
19095            let via_owned: Result<RestartPolicy, ()> =
19096                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(wire_bytes.clone());
19097            let via_borrowed: Result<RestartPolicy, ()> =
19098                <RestartPolicy as TryFrom<&[u8]>>::try_from(wire_bytes.as_slice());
19099            assert_eq!(
19100                via_owned, via_borrowed,
19101                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
19102                 axes on RestartPolicy must agree on \
19103                 RestartPolicy::{variant:?} — divergence signals the \
19104                 owned-input and borrowed-input byte-view reverse paths \
19105                 have drifted off the same substrate-primitive \
19106                 from_wire accessor"
19107            );
19108            // Cross-axis witness against the paired str-view reverse
19109            // axis ([`TryFrom<&str>`]) — the three reverse paths (str-
19110            // view, byte-view borrowed, byte-view owned) share one
19111            // substrate primitive.
19112            let via_str: Result<RestartPolicy, ()> =
19113                <RestartPolicy as TryFrom<&str>>::try_from(variant.as_str());
19114            assert_eq!(
19115                via_owned, via_str,
19116                "TryFrom<Vec<u8>> and TryFrom<&str> reverse-projection \
19117                 axes on RestartPolicy must agree on \
19118                 RestartPolicy::{variant:?} — divergence signals the \
19119                 byte-owned and str-view reverse paths have drifted off \
19120                 the same substrate-primitive from_wire accessor"
19121            );
19122            // Four-corner witness: because [`RestartPolicy`] carries
19123            // no wire-vs-diagnostic split (as_str and from_wire share
19124            // one `PascalCase` byte-vocabulary — like the sibling
19125            // [`RestartStrategy`] and unlike the sibling
19126            // [`crate::CaixaKind`] whose peer test deliberately declines
19127            // this witness), the byte-owned reverse-projection axis on
19128            // this enum *does* round-trip against the paired byte-owned
19129            // forward-projection pair. Pin every corner of the {owned-
19130            // input, borrowed-input} × {From<Self> → Vec<u8>,
19131            // From<&Self> → Vec<u8>} square onto the same Ok(variant)
19132            // return so a future accident that drops one corner off the
19133            // substrate-primitive accessor trips here.
19134            let owned_forward: Vec<u8> = <Vec<u8> as From<RestartPolicy>>::from(variant);
19135            let borrowed_forward: Vec<u8> = <Vec<u8> as From<&RestartPolicy>>::from(&variant);
19136            assert_eq!(
19137                owned_forward, wire_bytes,
19138                "From<RestartPolicy> for Vec<u8> forward projection on \
19139                 RestartPolicy::{variant:?} must byte-equal \
19140                 variant.as_str().as_bytes().to_vec() — divergence \
19141                 signals the paired forward pair drifted off the \
19142                 substrate-primitive as_str accessor"
19143            );
19144            assert_eq!(
19145                borrowed_forward, wire_bytes,
19146                "From<&RestartPolicy> for Vec<u8> forward projection \
19147                 on &RestartPolicy::{variant:?} must byte-equal \
19148                 variant.as_str().as_bytes().to_vec() — divergence \
19149                 signals the paired forward pair drifted off the \
19150                 substrate-primitive as_str accessor"
19151            );
19152            assert_eq!(
19153                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(owned_forward.clone()),
19154                Ok(variant),
19155                "Four-corner round-trip on RestartPolicy::{variant:?} \
19156                 through From<RestartPolicy> for Vec<u8> then \
19157                 TryFrom<Vec<u8>> for RestartPolicy must return \
19158                 Ok(variant) — divergence signals the byte-owned \
19159                 forward pair and the byte-owned reverse axis have \
19160                 drifted apart"
19161            );
19162            assert_eq!(
19163                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(borrowed_forward),
19164                Ok(variant),
19165                "Four-corner round-trip on RestartPolicy::{variant:?} \
19166                 through From<&RestartPolicy> for Vec<u8> then \
19167                 TryFrom<Vec<u8>> for RestartPolicy must return \
19168                 Ok(variant) — divergence signals the borrowed-input \
19169                 forward corner and the owned-input reverse corner have \
19170                 drifted apart"
19171            );
19172        }
19173    }
19174
19175    #[test]
19176    fn restart_policy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes() {
19177        // Rejection witness on the `impl TryFrom<Vec<u8>> for
19178        // RestartPolicy` — sweeps the same two rejection paths the
19179        // sibling borrowed `TryFrom<&[u8]>` axis collapses onto the
19180        // single unit-error return: the invalid-UTF-8 rejection path
19181        // (`std::str::from_utf8` on the underlying byte-slice returns
19182        // `Err` before [`RestartPolicy::from_wire`] runs) and the
19183        // valid-UTF-8-but-unknown-wire rejection path
19184        // ([`RestartPolicy::from_wire`] returns `None` on a byte-
19185        // string outside the three-arm `PascalCase` accept-set). Both
19186        // must reject so a future accidental widening of the trait
19187        // impl's accept-set (a case-fold path, a silent acceptance of
19188        // the kebab-case dispatcher-catalog byte-strings on this axis —
19189        // which would collide the two-axis wire/catalog split the
19190        // sibling [`RestartPolicy::from_wire`] doc block makes load-
19191        // bearing — a `#[serde(rename_all = "…")]` attribute drift that
19192        // widens the parse arm-set silently, a stray
19193        // `String::from_utf8_lossy` detour that widens the input
19194        // surface with the U+FFFD replacement character, an
19195        // `Option::unwrap_or_default`-shape fallback that maps invalid
19196        // UTF-8 onto a default arm rather than the trait-idiomatic
19197        // `Err(())`) trips at caixa-core test time. Peer of the sibling
19198        // first-mover
19199        // [`crate::kind::tests::caixa_kind_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19200        // (99c2849) on the [`crate::CaixaKind`] peer, the sibling
19201        // second-mover
19202        // [`crate::dialeto::tests::caixa_dialeto_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19203        // (83a1526) on the [`crate::CaixaDialeto`] peer, the sibling
19204        // third-mover
19205        // [`crate::dep::tests::dep_list_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19206        // (42091cb) on the [`crate::dep::DepList`] peer, and the
19207        // sibling fourth-mover
19208        // [`restart_strategy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19209        // (34951fe) on the [`RestartStrategy`] peer rejection
19210        // witnesses.
19211        let non_utf8_rejected: &[&[u8]] = &[
19212            &[0xFF],
19213            &[0x80],
19214            &[0xC3],
19215            &[0xFF, 0xFE],
19216            &[0xED, 0xA0, 0x80], // UTF-16 surrogate half — rejected by UTF-8
19217        ];
19218        for &input in non_utf8_rejected {
19219            let owned: Vec<u8> = input.to_vec();
19220            assert_eq!(
19221                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(owned),
19222                Err(()),
19223                "TryFrom<Vec<u8>> impl on RestartPolicy must reject \
19224                 the non-UTF-8 byte-sequence {input:?} with Err(()) — \
19225                 silent acceptance signals the UTF-8 validation path \
19226                 collapsed onto a default arm rather than the trait-\
19227                 idiomatic unit-error"
19228            );
19229            // Cross-axis witness: the owned-input axis must agree with
19230            // the borrowed-input axis on every rejected input.
19231            assert_eq!(
19232                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(input.to_vec()),
19233                <RestartPolicy as TryFrom<&[u8]>>::try_from(input),
19234                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
19235                 axes on RestartPolicy must agree on the non-UTF-8 \
19236                 input {input:?} — divergence signals the owned-input \
19237                 and borrowed-input byte-view reverse paths have drifted \
19238                 off the same substrate-primitive from_wire accessor"
19239            );
19240        }
19241        // Valid-UTF-8-but-unknown-wire candidates mirror the corpus the
19242        // sibling borrowed-input rejection witness
19243        // [`restart_policy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
19244        // (d9ef5f0) already pins on the paired byte-view axis: the
19245        // empty byte-string, whitespace-only padding, the kebab-case
19246        // dispatcher-catalog byte-strings on the sibling axis the pre-
19247        // existing [`std::str::FromStr`] impl the
19248        // [`gen_platform::FromStrKind`] derive installs parses onto (a
19249        // caller who confuses the two axes trips here rather than at a
19250        // downstream K8s-CR round-trip miss), lowercase / uppercase /
19251        // mixed-case folds of each `PascalCase` arm, whitespace-padded /
19252        // trailing-newline / quote-wrapped forms, and plausible-but-
19253        // wrong English rebrand candidates (`Ephemeral`, `Always`,
19254        // `Never`, `OnAbnormalExit`, `intrinsic`).
19255        let unknown_wire_rejected: &[&[u8]] = &[
19256            b"",
19257            b" ",
19258            b"\n",
19259            b"\t",
19260            b"permanent",
19261            b"temporary",
19262            b"transient",
19263            b"PERMANENT",
19264            b"TEMPORARY",
19265            b"TRANSIENT",
19266            b"Permanents",
19267            b"Permanent ",
19268            b" Permanent",
19269            b" Temporary ",
19270            b"Permanent\n",
19271            b"Transient\t",
19272            b"\"Permanent\"",
19273            b"Ephemeral",
19274            b"Always",
19275            b"Never",
19276            b"OnAbnormalExit",
19277            b"intrinsic",
19278            b"?",
19279        ];
19280        for &input in unknown_wire_rejected {
19281            let owned: Vec<u8> = input.to_vec();
19282            assert_eq!(
19283                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(owned),
19284                Err(()),
19285                "TryFrom<Vec<u8>> impl on RestartPolicy must reject \
19286                 the valid-UTF-8-but-unknown-wire byte-string {input:?} \
19287                 with Err(()) — silent acceptance signals an accept-\
19288                 set widening off the paired RestartPolicy::from_wire \
19289                 resolver"
19290            );
19291            // Cross-axis witness against the borrowed byte-view axis:
19292            // the two paths must agree by construction, since the owned
19293            // axis delegates to the borrowed peer.
19294            assert_eq!(
19295                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(input.to_vec()),
19296                <RestartPolicy as TryFrom<&[u8]>>::try_from(input),
19297                "TryFrom<Vec<u8>> and TryFrom<&[u8]> reverse-projection \
19298                 axes on RestartPolicy must agree on the valid-UTF-8-\
19299                 but-unknown-wire input {input:?} — divergence signals \
19300                 the owned-input and borrowed-input byte-view reverse \
19301                 paths have drifted off the same substrate-primitive \
19302                 from_wire accessor"
19303            );
19304        }
19305    }
19306
19307    #[test]
19308    fn restart_strategy_try_from_owned_string_routes_through_borrowed_str_view_axis() {
19309        // Fail-before-pass-after byte-parity pin on the newly lifted
19310        // `impl TryFrom<String> for RestartStrategy` — asserts the
19311        // trait-idiomatic string-owned reverse-projection standard-
19312        // library impl and the sibling borrowed-input [`TryFrom<&str>`]
19313        // axis resolve to the same four-arm `PascalCase` wire accept-set
19314        // across every arm the exhaustive [`RestartStrategy::ALL`] slice
19315        // enumerates. Extends the substrate-wide trait-idiomatic string-
19316        // owned reverse-projection axis onto the first M2-OTP-shape
19317        // supervisor-slot closed-set fieldless typed-enum peer — owned-
19318        // input mirror of the paired [`TryFrom<&str>`] str-view reverse-
19319        // projection axis, and string-owned reverse companion of the
19320        // pre-existing string-owned *forward*-projection pair
19321        // ([`From<RestartStrategy> for String`],
19322        // [`From<&RestartStrategy> for String`]) on this same enum. Peer
19323        // of the sibling opener
19324        // [`crate::aplicacao::tests::rate_limit_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19325        // (a2e6f02) on the compound [`crate::aplicacao::RateLimit`]
19326        // primitive, the sibling first-mover
19327        // [`crate::aplicacao::tests::wit_shape_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19328        // (e6aac29) on the [`crate::aplicacao::WitShape`] closed-set peer,
19329        // the sibling second-mover
19330        // [`crate::aplicacao::tests::rate_limit_unit_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19331        // (94a9c5e) on the [`crate::aplicacao::RateLimitUnit`] peer, and
19332        // the sibling third-mover
19333        // [`crate::aplicacao::tests::placement_strategy_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19334        // (d81a70a) on the [`crate::aplicacao::PlacementStrategy`] peer —
19335        // tracks the "delegate through `TryFrom<&str>` on the
19336        // `String::as_str` borrow" discipline the compound-primitive
19337        // opener and closed-set-peer first-mover established.
19338        //
19339        // Rust's standard library carries no blanket
19340        // `impl<T: for<'a> TryFrom<&'a str>> TryFrom<String> for T`, so
19341        // an owned-`String` caller otherwise picks between an open-coded
19342        // `<T as TryFrom<&str>>::try_from(s.as_str())` at every call
19343        // site (whose type bounds have no compile-time link back to the
19344        // string-owned reverse-projection axis) or a `let s: &str = &s;
19345        // T::try_from(s)` two-step whose borrow arithmetic leaks a per-
19346        // call-site lifetime dance. This impl closes the string-owned
19347        // reverse-projection axis at the substrate-primitive
19348        // [`RestartStrategy::from_wire`] accessor so every future
19349        // `<T: TryFrom<String>>`-bound owned-string consumer reaches the
19350        // same four-arm `PascalCase` accept-set through one trait
19351        // dispatch.
19352        for &variant in RestartStrategy::ALL {
19353            let wire_string: String = variant.as_str().to_string();
19354            assert_eq!(
19355                <RestartStrategy as TryFrom<String>>::try_from(wire_string.clone()),
19356                Ok(variant),
19357                "TryFrom<String> impl on RestartStrategy must round-trip \
19358                 RestartStrategy::{variant:?}.as_str().to_string() back \
19359                 to Ok(RestartStrategy::{variant:?}) — divergence from \
19360                 the sibling TryFrom<&str> axis signals a silent detour \
19361                 off the substrate-primitive from_wire accessor"
19362            );
19363            // Cross-axis witness: the string-owned reverse-projection
19364            // axis must agree with the borrowed `&str` reverse-projection
19365            // axis on every accepted arm — the two axes share one
19366            // `PascalCase` wire vocabulary through the substrate-primitive
19367            // `from_wire` accessor, and the owned-input axis delegates to
19368            // the borrowed peer by design.
19369            let via_owned: Result<RestartStrategy, ()> =
19370                <RestartStrategy as TryFrom<String>>::try_from(wire_string.clone());
19371            let via_borrowed: Result<RestartStrategy, ()> =
19372                <RestartStrategy as TryFrom<&str>>::try_from(wire_string.as_str());
19373            assert_eq!(
19374                via_owned, via_borrowed,
19375                "TryFrom<String> and TryFrom<&str> reverse-projection \
19376                 axes on RestartStrategy must agree on \
19377                 RestartStrategy::{variant:?} — divergence signals the \
19378                 owned-`String` and borrowed-`&str` reverse paths have \
19379                 drifted off the same substrate-primitive from_wire \
19380                 accessor"
19381            );
19382            // Cross-axis witness against the paired byte-view and byte-
19383            // owned reverse axes — the four reverse paths (str-view
19384            // borrowed, string-owned, byte-view borrowed, byte-owned)
19385            // share one substrate primitive.
19386            let via_bytes_borrowed: Result<RestartStrategy, ()> =
19387                <RestartStrategy as TryFrom<&[u8]>>::try_from(wire_string.as_bytes());
19388            let via_bytes_owned: Result<RestartStrategy, ()> =
19389                <RestartStrategy as TryFrom<Vec<u8>>>::try_from(wire_string.as_bytes().to_vec());
19390            assert_eq!(
19391                via_owned, via_bytes_borrowed,
19392                "TryFrom<String> and TryFrom<&[u8]> reverse-projection \
19393                 axes on RestartStrategy must agree on \
19394                 RestartStrategy::{variant:?} — divergence signals the \
19395                 string-owned and byte-view reverse paths have drifted \
19396                 off the same substrate-primitive from_wire accessor"
19397            );
19398            assert_eq!(
19399                via_owned, via_bytes_owned,
19400                "TryFrom<String> and TryFrom<Vec<u8>> reverse-projection \
19401                 axes on RestartStrategy must agree on \
19402                 RestartStrategy::{variant:?} — divergence signals the \
19403                 string-owned and byte-owned reverse paths have drifted \
19404                 off the same substrate-primitive from_wire accessor"
19405            );
19406            // Closed-cycle witness against the paired string-owned
19407            // forward-projection pair: `Self → String → TryFrom<String>
19408            // → Self` round-trips to the originating arm on every
19409            // canonical `PascalCase` scalar. Both the owned-input
19410            // `From<RestartStrategy> for String` and the borrowed-input
19411            // `From<&RestartStrategy> for String` corners must feed back
19412            // through the new impl to `Ok(variant)`.
19413            let owned_forward: String = <String as From<RestartStrategy>>::from(variant);
19414            let borrowed_forward: String = <String as From<&RestartStrategy>>::from(&variant);
19415            assert_eq!(
19416                owned_forward, wire_string,
19417                "From<RestartStrategy> for String forward projection on \
19418                 RestartStrategy::{variant:?} must byte-equal \
19419                 variant.as_str().to_string() — divergence signals the \
19420                 paired forward pair drifted off the substrate-primitive \
19421                 as_str accessor"
19422            );
19423            assert_eq!(
19424                borrowed_forward, wire_string,
19425                "From<&RestartStrategy> for String forward projection on \
19426                 &RestartStrategy::{variant:?} must byte-equal \
19427                 variant.as_str().to_string() — divergence signals the \
19428                 paired forward pair drifted off the substrate-primitive \
19429                 as_str accessor"
19430            );
19431            assert_eq!(
19432                <RestartStrategy as TryFrom<String>>::try_from(owned_forward.clone()),
19433                Ok(variant),
19434                "Closed-cycle round-trip on RestartStrategy::{variant:?} \
19435                 through From<RestartStrategy> for String then \
19436                 TryFrom<String> for RestartStrategy must return \
19437                 Ok(variant) — divergence signals the string-owned \
19438                 forward pair and the string-owned reverse axis have \
19439                 drifted apart"
19440            );
19441            assert_eq!(
19442                <RestartStrategy as TryFrom<String>>::try_from(borrowed_forward),
19443                Ok(variant),
19444                "Closed-cycle round-trip on RestartStrategy::{variant:?} \
19445                 through From<&RestartStrategy> for String then \
19446                 TryFrom<String> for RestartStrategy must return \
19447                 Ok(variant) — divergence signals the borrowed-input \
19448                 forward corner and the owned-input string reverse \
19449                 corner have drifted apart"
19450            );
19451        }
19452    }
19453
19454    #[test]
19455    fn restart_strategy_try_from_owned_string_rejects_unknown_wire_strings() {
19456        // Rejection witness on the `impl TryFrom<String> for
19457        // RestartStrategy` — sweeps the corpus of valid-UTF-8-but-
19458        // unknown-wire byte-strings the sibling borrowed [`TryFrom<&str>`]
19459        // axis already rejects and asserts every one lands on `Err(())`,
19460        // so a future accidental widening of the trait impl's accept-set
19461        // (a case-fold path, a silent inclusion of the kebab-case
19462        // dispatcher-catalog byte-strings on the sibling axis that would
19463        // collide the two-axis wire/catalog split the sibling
19464        // [`RestartStrategy::from_wire`] doc block makes load-bearing, a
19465        // stray fallback that maps whitespace-padded canonical scalars
19466        // onto their unpadded arm rather than the trait-idiomatic
19467        // `Err(())`) trips at caixa-core test time. Peer of the sibling
19468        // borrowed-input rejection witness
19469        // [`restart_strategy_try_from_str_rejects_unknown_byte_strings`]
19470        // on the same enum, and the sibling byte-view / byte-owned
19471        // rejection witnesses
19472        // [`restart_strategy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
19473        // (c699a83) /
19474        // [`restart_strategy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19475        // (34951fe) on the same enum.
19476        let unknown_wire_rejected: &[&str] = &[
19477            "",
19478            " ",
19479            "\n",
19480            "\t",
19481            "one-for-one",
19482            "one-for-all",
19483            "rest-for-one",
19484            "simple-one-for-one",
19485            "oneforone",
19486            "one_for_one",
19487            "OneForOnes",
19488            "ONEFORONE",
19489            "oneforall",
19490            "restforone",
19491            "simpleoneforone",
19492            "OneForOne ",
19493            " OneForOne",
19494            " OneForAll ",
19495            "OneForOne\n",
19496            "RestForOne\t",
19497            "OneForEach",
19498            "AllForOne",
19499            "one for one",
19500            "\"OneForOne\"",
19501            "?",
19502        ];
19503        for &input in unknown_wire_rejected {
19504            let owned: String = input.to_string();
19505            assert_eq!(
19506                <RestartStrategy as TryFrom<String>>::try_from(owned),
19507                Err(()),
19508                "TryFrom<String> impl on RestartStrategy must reject the \
19509                 valid-UTF-8-but-unknown-wire byte-string {input:?} with \
19510                 Err(()) — silent acceptance signals an accept-set \
19511                 widening off the paired RestartStrategy::from_wire \
19512                 resolver"
19513            );
19514            // Cross-axis witness against the borrowed str-view axis:
19515            // the two paths must agree by construction, since the owned
19516            // axis delegates to the borrowed peer.
19517            assert_eq!(
19518                <RestartStrategy as TryFrom<String>>::try_from(input.to_string()),
19519                <RestartStrategy as TryFrom<&str>>::try_from(input),
19520                "TryFrom<String> and TryFrom<&str> reverse-projection \
19521                 axes on RestartStrategy must agree on the valid-UTF-8-\
19522                 but-unknown-wire input {input:?} — divergence signals \
19523                 the owned-`String` and borrowed-`&str` reverse paths \
19524                 have drifted off the same substrate-primitive from_wire \
19525                 accessor"
19526            );
19527        }
19528    }
19529
19530    #[test]
19531    fn restart_policy_try_from_owned_string_routes_through_borrowed_str_view_axis() {
19532        // Fail-before-pass-after byte-parity pin on the newly lifted
19533        // `impl TryFrom<String> for RestartPolicy` — asserts the trait-
19534        // idiomatic string-owned reverse-projection standard-library impl
19535        // and the sibling borrowed-input [`TryFrom<&str>`] axis resolve
19536        // to the same three-arm `PascalCase` wire accept-set across every
19537        // arm the exhaustive [`RestartPolicy::ALL`] slice enumerates.
19538        // Extends the substrate-wide trait-idiomatic string-owned reverse-
19539        // projection axis onto the second (and final) M2-OTP-shape
19540        // supervisor-slot closed-set fieldless typed-enum peer — owned-
19541        // input mirror of the paired [`TryFrom<&str>`] str-view reverse-
19542        // projection axis, and string-owned reverse companion of the
19543        // pre-existing string-owned *forward*-projection pair
19544        // ([`From<RestartPolicy> for String`],
19545        // [`From<&RestartPolicy> for String`]) on this same enum. Peer
19546        // of the sibling first-mover
19547        // [`crate::aplicacao::tests::rate_limit_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19548        // (a2e6f02) on the compound [`crate::aplicacao::RateLimit`]
19549        // primitive, and the sibling
19550        // [`restart_strategy_try_from_owned_string_routes_through_borrowed_str_view_axis`]
19551        // (78fe8c8) on the sibling first M2-OTP-shape supervisor-slot
19552        // [`RestartStrategy`] peer — tracks the "delegate through
19553        // `TryFrom<&str>` on the `String::as_str` borrow" discipline the
19554        // compound-primitive opener and closed-set-peer first-mover
19555        // established. This closes the string-owned reverse-projection
19556        // axis on the M2-OTP-shape `:supervisor :estrategia` +
19557        // `:children :restart` slot pair.
19558        for &variant in RestartPolicy::ALL {
19559            let wire_string: String = variant.as_str().to_string();
19560            assert_eq!(
19561                <RestartPolicy as TryFrom<String>>::try_from(wire_string.clone()),
19562                Ok(variant),
19563                "TryFrom<String> impl on RestartPolicy must round-trip \
19564                 RestartPolicy::{variant:?}.as_str().to_string() back \
19565                 to Ok(RestartPolicy::{variant:?}) — divergence from \
19566                 the sibling TryFrom<&str> axis signals a silent detour \
19567                 off the substrate-primitive from_wire accessor"
19568            );
19569            // Cross-axis witness: the string-owned reverse-projection
19570            // axis must agree with the borrowed `&str` reverse-projection
19571            // axis on every accepted arm — the two axes share one
19572            // `PascalCase` wire vocabulary through the substrate-
19573            // primitive `from_wire` accessor, and the owned-input axis
19574            // delegates to the borrowed peer by design.
19575            let via_owned: Result<RestartPolicy, ()> =
19576                <RestartPolicy as TryFrom<String>>::try_from(wire_string.clone());
19577            let via_borrowed: Result<RestartPolicy, ()> =
19578                <RestartPolicy as TryFrom<&str>>::try_from(wire_string.as_str());
19579            assert_eq!(
19580                via_owned, via_borrowed,
19581                "TryFrom<String> and TryFrom<&str> reverse-projection \
19582                 axes on RestartPolicy must agree on \
19583                 RestartPolicy::{variant:?} — divergence signals the \
19584                 owned-`String` and borrowed-`&str` reverse paths have \
19585                 drifted off the same substrate-primitive from_wire \
19586                 accessor"
19587            );
19588            // Cross-axis witness against the paired byte-view and byte-
19589            // owned reverse axes — the four reverse paths (str-view
19590            // borrowed, string-owned, byte-view borrowed, byte-owned)
19591            // share one substrate primitive.
19592            let via_bytes_borrowed: Result<RestartPolicy, ()> =
19593                <RestartPolicy as TryFrom<&[u8]>>::try_from(wire_string.as_bytes());
19594            let via_bytes_owned: Result<RestartPolicy, ()> =
19595                <RestartPolicy as TryFrom<Vec<u8>>>::try_from(wire_string.as_bytes().to_vec());
19596            assert_eq!(
19597                via_owned, via_bytes_borrowed,
19598                "TryFrom<String> and TryFrom<&[u8]> reverse-projection \
19599                 axes on RestartPolicy must agree on \
19600                 RestartPolicy::{variant:?} — divergence signals the \
19601                 string-owned and byte-view reverse paths have drifted \
19602                 off the same substrate-primitive from_wire accessor"
19603            );
19604            assert_eq!(
19605                via_owned, via_bytes_owned,
19606                "TryFrom<String> and TryFrom<Vec<u8>> reverse-projection \
19607                 axes on RestartPolicy must agree on \
19608                 RestartPolicy::{variant:?} — divergence signals the \
19609                 string-owned and byte-owned reverse paths have drifted \
19610                 off the same substrate-primitive from_wire accessor"
19611            );
19612            // Closed-cycle witness against the paired string-owned
19613            // forward-projection pair: `Self → String → TryFrom<String>
19614            // → Self` round-trips to the originating arm on every
19615            // canonical `PascalCase` scalar. Both the owned-input
19616            // `From<RestartPolicy> for String` and the borrowed-input
19617            // `From<&RestartPolicy> for String` corners must feed back
19618            // through the new impl to `Ok(variant)`.
19619            let owned_forward: String = <String as From<RestartPolicy>>::from(variant);
19620            let borrowed_forward: String = <String as From<&RestartPolicy>>::from(&variant);
19621            assert_eq!(
19622                owned_forward, wire_string,
19623                "From<RestartPolicy> for String forward projection on \
19624                 RestartPolicy::{variant:?} must byte-equal \
19625                 variant.as_str().to_string() — divergence signals the \
19626                 paired forward pair drifted off the substrate-primitive \
19627                 as_str accessor"
19628            );
19629            assert_eq!(
19630                borrowed_forward, wire_string,
19631                "From<&RestartPolicy> for String forward projection on \
19632                 &RestartPolicy::{variant:?} must byte-equal \
19633                 variant.as_str().to_string() — divergence signals the \
19634                 paired forward pair drifted off the substrate-primitive \
19635                 as_str accessor"
19636            );
19637            assert_eq!(
19638                <RestartPolicy as TryFrom<String>>::try_from(owned_forward.clone()),
19639                Ok(variant),
19640                "Closed-cycle round-trip on RestartPolicy::{variant:?} \
19641                 through From<RestartPolicy> for String then \
19642                 TryFrom<String> for RestartPolicy must return \
19643                 Ok(variant) — divergence signals the string-owned \
19644                 forward pair and the string-owned reverse axis have \
19645                 drifted apart"
19646            );
19647            assert_eq!(
19648                <RestartPolicy as TryFrom<String>>::try_from(borrowed_forward),
19649                Ok(variant),
19650                "Closed-cycle round-trip on RestartPolicy::{variant:?} \
19651                 through From<&RestartPolicy> for String then \
19652                 TryFrom<String> for RestartPolicy must return \
19653                 Ok(variant) — divergence signals the borrowed-input \
19654                 forward corner and the owned-input string reverse \
19655                 corner have drifted apart"
19656            );
19657        }
19658    }
19659
19660    #[test]
19661    fn restart_policy_try_from_owned_string_rejects_unknown_wire_strings() {
19662        // Rejection witness on the `impl TryFrom<String> for
19663        // RestartPolicy` — sweeps the corpus of valid-UTF-8-but-
19664        // unknown-wire byte-strings the sibling borrowed [`TryFrom<&str>`]
19665        // axis already rejects and asserts every one lands on `Err(())`,
19666        // so a future accidental widening of the trait impl's accept-set
19667        // (a case-fold path, a silent inclusion of the kebab-case
19668        // dispatcher-catalog byte-strings on the sibling axis that would
19669        // collide the two-axis wire/catalog split the sibling
19670        // [`RestartPolicy::from_wire`] doc block makes load-bearing, a
19671        // stray fallback that maps whitespace-padded canonical scalars
19672        // onto their unpadded arm rather than the trait-idiomatic
19673        // `Err(())`) trips at caixa-core test time. Peer of the sibling
19674        // borrowed-input rejection witness
19675        // [`restart_policy_try_from_str_rejects_unknown_byte_strings`]
19676        // on the same enum, and the sibling byte-view / byte-owned
19677        // rejection witnesses
19678        // [`restart_policy_try_from_bytes_rejects_unknown_and_non_utf8_bytes`]
19679        // (d9ef5f0) /
19680        // [`restart_policy_try_from_vec_bytes_rejects_unknown_and_non_utf8_bytes`]
19681        // (7592085) on the same enum.
19682        let unknown_wire_rejected: &[&str] = &[
19683            "",
19684            " ",
19685            "\n",
19686            "\t",
19687            "permanent",
19688            "temporary",
19689            "transient",
19690            "PERMANENT",
19691            "TEMPORARY",
19692            "TRANSIENT",
19693            "Permanents",
19694            "Permanent ",
19695            " Permanent",
19696            " Temporary ",
19697            "Permanent\n",
19698            "Transient\t",
19699            "\"Permanent\"",
19700            "Ephemeral",
19701            "Always",
19702            "Never",
19703            "OnAbnormalExit",
19704            "intrinsic",
19705            "?",
19706        ];
19707        for &input in unknown_wire_rejected {
19708            let owned: String = input.to_string();
19709            assert_eq!(
19710                <RestartPolicy as TryFrom<String>>::try_from(owned),
19711                Err(()),
19712                "TryFrom<String> impl on RestartPolicy must reject the \
19713                 valid-UTF-8-but-unknown-wire byte-string {input:?} with \
19714                 Err(()) — silent acceptance signals an accept-set \
19715                 widening off the paired RestartPolicy::from_wire \
19716                 resolver"
19717            );
19718            // Cross-axis witness against the borrowed str-view axis:
19719            // the two paths must agree by construction, since the owned
19720            // axis delegates to the borrowed peer.
19721            assert_eq!(
19722                <RestartPolicy as TryFrom<String>>::try_from(input.to_string()),
19723                <RestartPolicy as TryFrom<&str>>::try_from(input),
19724                "TryFrom<String> and TryFrom<&str> reverse-projection \
19725                 axes on RestartPolicy must agree on the valid-UTF-8-\
19726                 but-unknown-wire input {input:?} — divergence signals \
19727                 the owned-`String` and borrowed-`&str` reverse paths \
19728                 have drifted off the same substrate-primitive from_wire \
19729                 accessor"
19730            );
19731        }
19732    }
19733
19734    #[test]
19735    fn restart_strategy_from_into_owned_box_bytes_routes_through_as_str_accessor() {
19736        // Fail-before-pass-after byte-parity pin on the newly lifted
19737        // `impl From<RestartStrategy> for Box<[u8]>` — asserts the
19738        // owned-input byte-owned reverse projection routes through the
19739        // substrate-primitive [`super::RestartStrategy::as_str`]
19740        // `pub const fn` accessor's `.as_bytes()` byte-view via
19741        // [`Box::<[u8]>::from`] on the returned `&'static [u8]` and
19742        // resolves to the same four-arm PascalCase wire byte-string
19743        // emit-set across every arm the exhaustive
19744        // [`super::RestartStrategy::ALL`] slice enumerates. Refuses any
19745        // future silent detour that would swap
19746        // `Box::<[u8]>::from(strategy.as_str().as_bytes())` for a
19747        // `Vec::<u8>::from(strategy).into_boxed_slice()` double-hop, a
19748        // routing through the sibling `fmt::Display` emitter, or a stray
19749        // normalization step that would drop or rebrand a canonical
19750        // PascalCase arm ahead of the boxed byte-emit. Cross-axis
19751        // partition against the paired owned-input byte-owned reverse-
19752        // projection axes ([`Vec<u8>`], [`Cow<'static, [u8]>`]) and the
19753        // paired string-side [`Box<str>`] forward-projection axis on the
19754        // same primitive — all four routes must byte-agree on every arm,
19755        // otherwise the byte-owned reverse-projection matrix has drifted
19756        // off the shared substrate-primitive `as_str` accessor.
19757        for &variant in RestartStrategy::ALL {
19758            let via_owned_from: Box<[u8]> = <Box<[u8]> as From<RestartStrategy>>::from(variant);
19759            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
19760            assert_eq!(
19761                via_owned_from.as_ref(),
19762                via_method_bytes,
19763                "From<RestartStrategy> for Box<[u8]> impl must byte-\
19764                 equal RestartStrategy::as_str().as_bytes() on \
19765                 RestartStrategy::{variant:?} — divergence signals a \
19766                 silent detour off the substrate-primitive accessor"
19767            );
19768            // Cross-axis partition against the paired owned-input
19769            // `Vec<u8>` (98d38ed) and `Cow<'static, [u8]>` (7f81539)
19770            // byte-owned reverse-projection axes on the same enum — all
19771            // three axes must byte-agree on every arm.
19772            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
19773            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
19774                <std::borrow::Cow<'static, [u8]> as From<RestartStrategy>>::from(variant);
19775            assert_eq!(
19776                via_owned_from.as_ref(),
19777                via_vec_bytes.as_slice(),
19778                "From<RestartStrategy> for Box<[u8]> and \
19779                 From<RestartStrategy> for Vec<u8> must byte-agree on \
19780                 RestartStrategy::{variant:?} — divergence signals the \
19781                 owned-input byte-owned reverse-projection axes have \
19782                 drifted off the same substrate-primitive as_str \
19783                 accessor"
19784            );
19785            assert_eq!(
19786                via_owned_from.as_ref(),
19787                via_cow_bytes.as_ref(),
19788                "From<RestartStrategy> for Box<[u8]> and \
19789                 From<RestartStrategy> for Cow<'static, [u8]> must \
19790                 byte-agree on RestartStrategy::{variant:?} — \
19791                 divergence signals the owned-input byte-owned reverse-\
19792                 projection axes have drifted off the same substrate-\
19793                 primitive as_str accessor"
19794            );
19795            // Cross-axis partition against the paired string-side
19796            // `Box<str>` (69ef45c) forward-projection axis on the same
19797            // enum — the byte-side and str-side `Box<_>` axes must byte-
19798            // agree on every arm (both route through Self::as_str's
19799            // `&'static str` return).
19800            let via_box_str: Box<str> = <Box<str> as From<RestartStrategy>>::from(variant);
19801            assert_eq!(
19802                via_owned_from.as_ref(),
19803                via_box_str.as_bytes(),
19804                "From<RestartStrategy> for Box<[u8]> and \
19805                 From<RestartStrategy> for Box<str> must byte-agree on \
19806                 RestartStrategy::{variant:?} — divergence signals a \
19807                 silent detour off the shared substrate-primitive \
19808                 as_str accessor"
19809            );
19810        }
19811    }
19812
19813    #[test]
19814    fn restart_strategy_from_borrowed_into_owned_box_bytes_routes_through_as_str_accessor() {
19815        // Fail-before-pass-after byte-parity pin on the newly lifted
19816        // `impl From<&RestartStrategy> for Box<[u8]>` — asserts the
19817        // borrowed-input byte-owned reverse projection routes byte-for-
19818        // byte through the substrate-primitive
19819        // [`super::RestartStrategy::as_str`] `pub const fn` accessor's
19820        // `.as_bytes()` byte-view via [`Box::<[u8]>::from`] on the
19821        // returned `&'static [u8]` on every arm the exhaustive
19822        // [`super::RestartStrategy::ALL`] slice enumerates, preserving
19823        // the source [`super::RestartStrategy`] intact (no move-out).
19824        // Additionally asserts the paired owned-input and borrowed-input
19825        // corners byte-agree on the same arm, closing the
19826        // `{Self, &Self} → Box<[u8]>` byte-owned reverse-projection
19827        // family on this primitive.
19828        //
19829        // Generic `<T: Into<Box<[u8]>>>`-bound consumer witness helper:
19830        // a future per-supervisor byte-writer that accepts a
19831        // [`Box<[u8]>`] composes on both owned and borrowed input shapes
19832        // without an open-coded `Box::<[u8]>::from(strategy.as_str().
19833        // as_bytes())` at every call site. Lifted to the top of the
19834        // function per `clippy::items_after_statements`.
19835        fn generic_box_bytes_sink<T: Into<Box<[u8]>>>(t: T) -> Box<[u8]> {
19836            t.into()
19837        }
19838        for &variant in RestartStrategy::ALL {
19839            let via_borrowed_from: Box<[u8]> =
19840                <Box<[u8]> as From<&RestartStrategy>>::from(&variant);
19841            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
19842            assert_eq!(
19843                via_borrowed_from.as_ref(),
19844                via_method_bytes,
19845                "From<&RestartStrategy> for Box<[u8]> impl must byte-\
19846                 equal RestartStrategy::as_str().as_bytes() on \
19847                 &RestartStrategy::{variant:?} — divergence signals a \
19848                 silent detour off the substrate-primitive accessor"
19849            );
19850            // The borrowed-input impl must not move out of the source —
19851            // the source RestartStrategy must survive the projection.
19852            let survivor: &'static str = variant.as_str();
19853            assert_eq!(
19854                survivor.as_bytes(),
19855                via_method_bytes,
19856                "source &RestartStrategy::{variant:?} must survive \
19857                 borrowed-input projection — a move-out here signals \
19858                 the impl silently dereferences past the borrowed \
19859                 handle"
19860            );
19861            // Cross-corner partition against the paired owned-input
19862            // `Box<[u8]>` axis on the same enum — the two corners must
19863            // byte-agree on every arm, closing the "owned-input move
19864            // vs. borrowed-input clone" bifurcation on the same wire
19865            // byte-string through the `Box<[u8]>` axis.
19866            let via_owned_from: Box<[u8]> = <Box<[u8]> as From<RestartStrategy>>::from(variant);
19867            assert_eq!(
19868                via_borrowed_from.as_ref(),
19869                via_owned_from.as_ref(),
19870                "From<&RestartStrategy> for Box<[u8]> and \
19871                 From<RestartStrategy> for Box<[u8]> must byte-agree on \
19872                 RestartStrategy::{variant:?} — divergence signals the \
19873                 paired owned-input and borrowed-input corners have \
19874                 drifted off the same substrate-primitive as_str \
19875                 accessor"
19876            );
19877            let owned_via_generic = generic_box_bytes_sink(variant);
19878            let variant_ref: &RestartStrategy = &variant;
19879            let borrowed_via_generic = generic_box_bytes_sink(variant_ref);
19880            assert_eq!(
19881                owned_via_generic.as_ref(),
19882                via_method_bytes,
19883                "<T: Into<Box<[u8]>>>-bound composition on \
19884                 RestartStrategy::{variant:?} must fold the same byte-\
19885                 tail RestartStrategy::as_str().as_bytes() returns"
19886            );
19887            assert_eq!(
19888                borrowed_via_generic.as_ref(),
19889                via_method_bytes,
19890                "<T: Into<Box<[u8]>>>-bound composition on \
19891                 &RestartStrategy::{variant:?} must fold the same byte-\
19892                 tail RestartStrategy::as_str().as_bytes() returns"
19893            );
19894        }
19895    }
19896
19897    #[test]
19898    fn restart_strategy_from_into_owned_arc_bytes_routes_through_as_str_accessor() {
19899        // Fail-before-pass-after byte-parity pin on the newly lifted
19900        // `impl From<RestartStrategy> for std::sync::Arc<[u8]>` — asserts
19901        // the owned-input byte-owned reverse projection routes through the
19902        // substrate-primitive [`super::RestartStrategy::as_str`]
19903        // `pub const fn` accessor's `.as_bytes()` byte-view via
19904        // [`std::sync::Arc::<[u8]>::from`] on the returned `&'static [u8]`
19905        // and resolves to the same four-arm PascalCase wire byte-string
19906        // emit-set across every arm the exhaustive
19907        // [`super::RestartStrategy::ALL`] slice enumerates. Refuses any
19908        // future silent detour that would swap the substrate-primitive
19909        // routing for a `Box::<[u8]>::from(strategy).into()` double-hop,
19910        // a routing through the sibling `fmt::Display` emitter, or a stray
19911        // normalization step that would drop or rebrand a canonical
19912        // PascalCase arm ahead of the atomic-refcounted byte-emit. Cross-
19913        // axis partition against the paired owned-input byte-owned reverse-
19914        // projection axes ([`Vec<u8>`], [`Cow<'static, [u8]>`], and
19915        // [`Box<[u8]>`]) on the same primitive — all four routes must byte-
19916        // agree on every arm, otherwise the byte-owned reverse-projection
19917        // matrix has drifted off the shared substrate-primitive `as_str`
19918        // accessor.
19919        for &variant in RestartStrategy::ALL {
19920            let via_owned_from: std::sync::Arc<[u8]> =
19921                <std::sync::Arc<[u8]> as From<RestartStrategy>>::from(variant);
19922            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
19923            assert_eq!(
19924                via_owned_from.as_ref(),
19925                via_method_bytes,
19926                "From<RestartStrategy> for Arc<[u8]> impl must byte-\
19927                 equal RestartStrategy::as_str().as_bytes() on \
19928                 RestartStrategy::{variant:?} — divergence signals a \
19929                 silent detour off the substrate-primitive accessor"
19930            );
19931            // Cross-axis partition against the paired owned-input
19932            // `Vec<u8>`, `Cow<'static, [u8]>`, and `Box<[u8]>` byte-owned
19933            // reverse-projection axes on the same enum — all four axes
19934            // must byte-agree on every arm.
19935            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
19936            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
19937                <std::borrow::Cow<'static, [u8]> as From<RestartStrategy>>::from(variant);
19938            let via_box_bytes: Box<[u8]> = <Box<[u8]> as From<RestartStrategy>>::from(variant);
19939            assert_eq!(
19940                via_owned_from.as_ref(),
19941                via_vec_bytes.as_slice(),
19942                "From<RestartStrategy> for Arc<[u8]> and \
19943                 From<RestartStrategy> for Vec<u8> must byte-agree on \
19944                 RestartStrategy::{variant:?} — divergence signals the \
19945                 owned-input byte-owned reverse-projection axes have \
19946                 drifted off the same substrate-primitive as_str \
19947                 accessor"
19948            );
19949            assert_eq!(
19950                via_owned_from.as_ref(),
19951                via_cow_bytes.as_ref(),
19952                "From<RestartStrategy> for Arc<[u8]> and \
19953                 From<RestartStrategy> for Cow<'static, [u8]> must byte-\
19954                 agree on RestartStrategy::{variant:?} — divergence \
19955                 signals the owned-input byte-owned reverse-projection \
19956                 axes have drifted off the same substrate-primitive \
19957                 as_str accessor"
19958            );
19959            assert_eq!(
19960                via_owned_from.as_ref(),
19961                via_box_bytes.as_ref(),
19962                "From<RestartStrategy> for Arc<[u8]> and \
19963                 From<RestartStrategy> for Box<[u8]> must byte-agree on \
19964                 RestartStrategy::{variant:?} — divergence signals the \
19965                 owned-input byte-owned reverse-projection axes have \
19966                 drifted off the same substrate-primitive as_str \
19967                 accessor"
19968            );
19969        }
19970    }
19971
19972    #[test]
19973    fn restart_strategy_from_borrowed_into_owned_arc_bytes_routes_through_as_str_accessor() {
19974        // Fail-before-pass-after byte-parity pin on the newly lifted
19975        // `impl From<&RestartStrategy> for std::sync::Arc<[u8]>` — asserts
19976        // the borrowed-input byte-owned reverse projection routes byte-
19977        // for-byte through the substrate-primitive
19978        // [`super::RestartStrategy::as_str`] `pub const fn` accessor's
19979        // `.as_bytes()` byte-view via [`std::sync::Arc::<[u8]>::from`] on
19980        // the returned `&'static [u8]` on every arm the exhaustive
19981        // [`super::RestartStrategy::ALL`] slice enumerates, preserving
19982        // the source [`super::RestartStrategy`] intact (no move-out).
19983        // Additionally asserts the paired owned-input and borrowed-input
19984        // corners byte-agree on the same arm, closing the
19985        // `{Self, &Self} → std::sync::Arc<[u8]>` byte-owned reverse-
19986        // projection family on this primitive.
19987        //
19988        // Generic `<T: Into<std::sync::Arc<[u8]>>>`-bound consumer witness
19989        // helper: a future per-supervisor byte-writer that accepts a
19990        // [`std::sync::Arc<[u8]>`] composes on both owned and borrowed
19991        // input shapes without an open-coded
19992        // `std::sync::Arc::<[u8]>::from(strategy.as_str().as_bytes())` at
19993        // every call site. Lifted to the top of the function per
19994        // `clippy::items_after_statements`.
19995        fn generic_arc_bytes_sink<T: Into<std::sync::Arc<[u8]>>>(t: T) -> std::sync::Arc<[u8]> {
19996            t.into()
19997        }
19998        for &variant in RestartStrategy::ALL {
19999            let via_borrowed_from: std::sync::Arc<[u8]> =
20000                <std::sync::Arc<[u8]> as From<&RestartStrategy>>::from(&variant);
20001            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
20002            assert_eq!(
20003                via_borrowed_from.as_ref(),
20004                via_method_bytes,
20005                "From<&RestartStrategy> for Arc<[u8]> impl must byte-\
20006                 equal RestartStrategy::as_str().as_bytes() on \
20007                 &RestartStrategy::{variant:?} — divergence signals a \
20008                 silent detour off the substrate-primitive accessor"
20009            );
20010            // The borrowed-input impl must not move out of the source —
20011            // the source RestartStrategy must survive the projection.
20012            let survivor: &'static str = variant.as_str();
20013            assert_eq!(
20014                survivor.as_bytes(),
20015                via_method_bytes,
20016                "source &RestartStrategy::{variant:?} must survive \
20017                 borrowed-input projection — a move-out here signals \
20018                 the impl silently dereferences past the borrowed \
20019                 handle"
20020            );
20021            // Cross-corner partition against the paired owned-input
20022            // `Arc<[u8]>` axis on the same enum — the two corners must
20023            // byte-agree on every arm, closing the "owned-input move
20024            // vs. borrowed-input clone" bifurcation on the same wire
20025            // byte-string through the `Arc<[u8]>` axis.
20026            let via_owned_from: std::sync::Arc<[u8]> =
20027                <std::sync::Arc<[u8]> as From<RestartStrategy>>::from(variant);
20028            assert_eq!(
20029                via_borrowed_from.as_ref(),
20030                via_owned_from.as_ref(),
20031                "From<&RestartStrategy> for Arc<[u8]> and \
20032                 From<RestartStrategy> for Arc<[u8]> must byte-agree on \
20033                 RestartStrategy::{variant:?} — divergence signals the \
20034                 paired owned-input and borrowed-input corners have \
20035                 drifted off the same substrate-primitive as_str \
20036                 accessor"
20037            );
20038            let owned_via_generic = generic_arc_bytes_sink(variant);
20039            let variant_ref: &RestartStrategy = &variant;
20040            let borrowed_via_generic = generic_arc_bytes_sink(variant_ref);
20041            assert_eq!(
20042                owned_via_generic.as_ref(),
20043                via_method_bytes,
20044                "<T: Into<Arc<[u8]>>>-bound composition on \
20045                 RestartStrategy::{variant:?} must fold the same byte-\
20046                 tail RestartStrategy::as_str().as_bytes() returns"
20047            );
20048            assert_eq!(
20049                borrowed_via_generic.as_ref(),
20050                via_method_bytes,
20051                "<T: Into<Arc<[u8]>>>-bound composition on \
20052                 &RestartStrategy::{variant:?} must fold the same byte-\
20053                 tail RestartStrategy::as_str().as_bytes() returns"
20054            );
20055        }
20056    }
20057
20058    #[test]
20059    fn restart_strategy_from_into_owned_rc_bytes_routes_through_as_str_accessor() {
20060        // Fail-before-pass-after byte-parity pin on the newly lifted
20061        // `impl From<RestartStrategy> for std::rc::Rc<[u8]>` — asserts the
20062        // owned-input byte-owned reverse projection routes through the
20063        // substrate-primitive [`super::RestartStrategy::as_str`]
20064        // `pub const fn` accessor's `.as_bytes()` byte-view via
20065        // [`std::rc::Rc::<[u8]>::from`] on the returned `&'static [u8]`
20066        // and resolves to the same four-arm PascalCase wire byte-string
20067        // emit-set across every arm the exhaustive
20068        // [`super::RestartStrategy::ALL`] slice enumerates. Refuses any
20069        // future silent detour that would swap the substrate-primitive
20070        // routing for a `Box::<[u8]>::from(strategy).into()` /
20071        // `Rc::<[u8]>::from(Vec::<u8>::from(strategy))` double-hop, a
20072        // routing through the sibling `fmt::Display` emitter, or a stray
20073        // normalization step that would drop or rebrand a canonical
20074        // PascalCase arm ahead of the single-threaded-refcounted byte-
20075        // emit. Cross-axis partition against the paired owned-input
20076        // byte-owned reverse-projection axes ([`Vec<u8>`],
20077        // [`Cow<'static, [u8]>`], [`Box<[u8]>`], and
20078        // [`std::sync::Arc<[u8]>`]) on the same primitive — all five
20079        // routes must byte-agree on every arm, otherwise the byte-owned
20080        // reverse-projection matrix has drifted off the shared substrate-
20081        // primitive `as_str` accessor.
20082        for &variant in RestartStrategy::ALL {
20083            let via_owned_from: std::rc::Rc<[u8]> =
20084                <std::rc::Rc<[u8]> as From<RestartStrategy>>::from(variant);
20085            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
20086            assert_eq!(
20087                via_owned_from.as_ref(),
20088                via_method_bytes,
20089                "From<RestartStrategy> for Rc<[u8]> impl must byte-\
20090                 equal RestartStrategy::as_str().as_bytes() on \
20091                 RestartStrategy::{variant:?} — divergence signals a \
20092                 silent detour off the substrate-primitive accessor"
20093            );
20094            // Cross-axis partition against the paired owned-input
20095            // `Vec<u8>`, `Cow<'static, [u8]>`, `Box<[u8]>`, and
20096            // `Arc<[u8]>` byte-owned reverse-projection axes on the same
20097            // enum — all five axes must byte-agree on every arm, closing
20098            // the five-corner "owned-input into Vec/Cow/Box/Arc/Rc"
20099            // partition on the same wire byte-string.
20100            let via_vec_bytes: Vec<u8> = <Vec<u8> as From<RestartStrategy>>::from(variant);
20101            let via_cow_bytes: std::borrow::Cow<'static, [u8]> =
20102                <std::borrow::Cow<'static, [u8]> as From<RestartStrategy>>::from(variant);
20103            let via_box_bytes: Box<[u8]> = <Box<[u8]> as From<RestartStrategy>>::from(variant);
20104            let via_arc_bytes: std::sync::Arc<[u8]> =
20105                <std::sync::Arc<[u8]> as From<RestartStrategy>>::from(variant);
20106            assert_eq!(
20107                via_owned_from.as_ref(),
20108                via_vec_bytes.as_slice(),
20109                "From<RestartStrategy> for Rc<[u8]> and \
20110                 From<RestartStrategy> for Vec<u8> must byte-agree on \
20111                 RestartStrategy::{variant:?} — divergence signals the \
20112                 owned-input byte-owned reverse-projection axes have \
20113                 drifted off the same substrate-primitive as_str \
20114                 accessor"
20115            );
20116            assert_eq!(
20117                via_owned_from.as_ref(),
20118                via_cow_bytes.as_ref(),
20119                "From<RestartStrategy> for Rc<[u8]> and \
20120                 From<RestartStrategy> for Cow<'static, [u8]> must byte-\
20121                 agree on RestartStrategy::{variant:?} — divergence \
20122                 signals the owned-input byte-owned reverse-projection \
20123                 axes have drifted off the same substrate-primitive \
20124                 as_str accessor"
20125            );
20126            assert_eq!(
20127                via_owned_from.as_ref(),
20128                via_box_bytes.as_ref(),
20129                "From<RestartStrategy> for Rc<[u8]> and \
20130                 From<RestartStrategy> for Box<[u8]> must byte-agree on \
20131                 RestartStrategy::{variant:?} — divergence signals the \
20132                 owned-input byte-owned reverse-projection axes have \
20133                 drifted off the same substrate-primitive as_str \
20134                 accessor"
20135            );
20136            assert_eq!(
20137                via_owned_from.as_ref(),
20138                via_arc_bytes.as_ref(),
20139                "From<RestartStrategy> for Rc<[u8]> and \
20140                 From<RestartStrategy> for Arc<[u8]> must byte-agree on \
20141                 RestartStrategy::{variant:?} — divergence signals the \
20142                 owned-input byte-owned reverse-projection axes have \
20143                 drifted off the same substrate-primitive as_str \
20144                 accessor"
20145            );
20146        }
20147    }
20148
20149    #[test]
20150    fn restart_strategy_from_borrowed_into_owned_rc_bytes_routes_through_as_str_accessor() {
20151        // Fail-before-pass-after byte-parity pin on the newly lifted
20152        // `impl From<&RestartStrategy> for std::rc::Rc<[u8]>` — asserts
20153        // the borrowed-input byte-owned reverse projection routes byte-
20154        // for-byte through the substrate-primitive
20155        // [`super::RestartStrategy::as_str`] `pub const fn` accessor's
20156        // `.as_bytes()` byte-view via [`std::rc::Rc::<[u8]>::from`] on the
20157        // returned `&'static [u8]` on every arm the exhaustive
20158        // [`super::RestartStrategy::ALL`] slice enumerates, preserving the
20159        // source [`super::RestartStrategy`] intact (no move-out).
20160        // Additionally asserts the paired owned-input and borrowed-input
20161        // corners byte-agree on the same arm, closing the
20162        // `{Self, &Self} → std::rc::Rc<[u8]>` byte-owned reverse-
20163        // projection family on this primitive.
20164        //
20165        // Generic `<T: Into<std::rc::Rc<[u8]>>>`-bound consumer witness
20166        // helper: a future per-supervisor byte-writer that accepts a
20167        // [`std::rc::Rc<[u8]>`] composes on both owned and borrowed input
20168        // shapes without an open-coded
20169        // `std::rc::Rc::<[u8]>::from(strategy.as_str().as_bytes())` at
20170        // every call site. Lifted to the top of the function per
20171        // `clippy::items_after_statements`.
20172        fn generic_rc_bytes_sink<T: Into<std::rc::Rc<[u8]>>>(t: T) -> std::rc::Rc<[u8]> {
20173            t.into()
20174        }
20175        for &variant in RestartStrategy::ALL {
20176            let via_borrowed_from: std::rc::Rc<[u8]> =
20177                <std::rc::Rc<[u8]> as From<&RestartStrategy>>::from(&variant);
20178            let via_method_bytes: &'static [u8] = variant.as_str().as_bytes();
20179            assert_eq!(
20180                via_borrowed_from.as_ref(),
20181                via_method_bytes,
20182                "From<&RestartStrategy> for Rc<[u8]> impl must byte-\
20183                 equal RestartStrategy::as_str().as_bytes() on \
20184                 &RestartStrategy::{variant:?} — divergence signals a \
20185                 silent detour off the substrate-primitive accessor"
20186            );
20187            // The borrowed-input impl must not move out of the source —
20188            // the source RestartStrategy must survive the projection.
20189            let survivor: &'static str = variant.as_str();
20190            assert_eq!(
20191                survivor.as_bytes(),
20192                via_method_bytes,
20193                "source &RestartStrategy::{variant:?} must survive \
20194                 borrowed-input projection — a move-out here signals \
20195                 the impl silently dereferences past the borrowed \
20196                 handle"
20197            );
20198            // Cross-corner partition against the paired owned-input
20199            // `Rc<[u8]>` axis on the same enum — the two corners must
20200            // byte-agree on every arm, closing the "owned-input move
20201            // vs. borrowed-input clone" bifurcation on the same wire
20202            // byte-string through the `Rc<[u8]>` axis.
20203            let via_owned_from: std::rc::Rc<[u8]> =
20204                <std::rc::Rc<[u8]> as From<RestartStrategy>>::from(variant);
20205            assert_eq!(
20206                via_borrowed_from.as_ref(),
20207                via_owned_from.as_ref(),
20208                "From<&RestartStrategy> for Rc<[u8]> and \
20209                 From<RestartStrategy> for Rc<[u8]> must byte-agree on \
20210                 RestartStrategy::{variant:?} — divergence signals the \
20211                 paired owned-input and borrowed-input corners have \
20212                 drifted off the same substrate-primitive as_str \
20213                 accessor"
20214            );
20215            let owned_via_generic = generic_rc_bytes_sink(variant);
20216            let variant_ref: &RestartStrategy = &variant;
20217            let borrowed_via_generic = generic_rc_bytes_sink(variant_ref);
20218            assert_eq!(
20219                owned_via_generic.as_ref(),
20220                via_method_bytes,
20221                "<T: Into<Rc<[u8]>>>-bound composition on \
20222                 RestartStrategy::{variant:?} must fold the same byte-\
20223                 tail RestartStrategy::as_str().as_bytes() returns"
20224            );
20225            assert_eq!(
20226                borrowed_via_generic.as_ref(),
20227                via_method_bytes,
20228                "<T: Into<Rc<[u8]>>>-bound composition on \
20229                 &RestartStrategy::{variant:?} must fold the same byte-\
20230                 tail RestartStrategy::as_str().as_bytes() returns"
20231            );
20232        }
20233    }
20234}