icydb-core 0.264.4

IcyDB — A schema-first typed query engine and persistence runtime for Internet Computer canisters
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
//! Module: db::executor::pipeline::runtime::grouped
//! Defines grouped row runtime and fold-stage carriers.
//! Does not own: grouped route-stage DTOs or planner semantics.
//! Boundary: keeps grouped row decoding and fold-stage runtime state out of contracts.

use crate::{
    db::{
        data::{
            CanonicalSlotReader, DecodedDataStoreKey, RawRow, decode_structural_value_storage_bytes,
        },
        executor::{
            ExecutionPreparation, PreparedGroupedRuntimeResidents,
            aggregate::field::{
                AggregateFieldValueError, FieldSlot, extract_orderable_field_value_with_slot_reader,
            },
            budget::{
                charge_current_execution_budget, charge_decoded_row, charge_materialized_data_row,
            },
            pipeline::contracts::ResolvedExecutionKeyStream,
            projection::{
                eval_effective_runtime_filter_program_with_value_cow_reader, resolve_path_segments,
                resolve_value_field_path,
            },
            terminal::{RetainedSlotLayout, RetainedSlotRow, RowDecoder, RowLayout},
        },
        predicate::MissingRowPolicy,
        query::plan::{
            EffectiveRuntimeFilterProgram, FieldSlot as PlannedFieldSlot, GroupFieldSet,
            GroupedAggregateExecutionSpec, GroupedDistinctExecutionStrategy, ScalarGroupPath,
            expr::{CompiledExprValueReader, ProjectionEvalError},
        },
        registry::StoreHandle,
    },
    error::InternalError,
    value::Value,
};
use icydb_diagnostic_code::DiagnosticExecutionBudgetResource;
use std::{borrow::Cow, rc::Rc};

///
/// RowView
///
/// Structural grouped row view used inside grouped runtime loops.
/// Rows carry slot-indexed values only, so grouped execution can remain
/// monomorphic after typed decode happens at the row-runtime boundary.
///

pub(in crate::db::executor) struct RowView {
    storage: RowViewStorage,
}

// Compile one grouped ingest slot layout from the planner-owned grouped
// runtime shape plus the already selected predicate program.
pub(in crate::db::executor) fn compile_grouped_row_slot_layout_from_inputs(
    row_layout: RowLayout,
    group_fields: &GroupFieldSet,
    grouped_aggregate_execution_specs: &[GroupedAggregateExecutionSpec],
    grouped_distinct_execution_strategy: &GroupedDistinctExecutionStrategy,
    effective_runtime_filter_program: Option<&EffectiveRuntimeFilterProgram>,
) -> RetainedSlotLayout {
    let field_count = row_layout.field_count();
    let mut required_slots = vec![false; field_count];

    // Phase 1: every grouped path needs the group key slots themselves.
    for field in group_fields.iter() {
        if let Some(required_slot) = required_slots.get_mut(field.root_slot()) {
            *required_slot = true;
        }
    }

    // Phase 2: residual filter semantics still run on grouped row views.
    if let Some(effective_runtime_filter_program) = effective_runtime_filter_program {
        effective_runtime_filter_program.mark_referenced_slots(&mut required_slots);
    }

    // Phase 3: grouped reducer state needs every row slot referenced by either
    // one direct field-target aggregate or one widened aggregate-input scalar
    // expression carried into grouped fold runtime.
    for aggregate in grouped_aggregate_execution_specs {
        if let Some(target_slot) = aggregate.target_slot()
            && let Some(required_slot) = required_slots.get_mut(target_slot.index())
        {
            *required_slot = true;
        }

        if let Some(compiled_input_expr) = aggregate.compiled_input_expr() {
            compiled_input_expr.mark_referenced_slots(&mut required_slots);
        }

        if let Some(compiled_filter_expr) = aggregate.compiled_filter_expr() {
            compiled_filter_expr.mark_referenced_slots(&mut required_slots);
        }
    }

    // Phase 4: the dedicated grouped DISTINCT path still reads its target
    // field from the shared grouped row view when active.
    if let Some(target_field) = grouped_distinct_execution_strategy.global_distinct_target_slot()
        && let Some(required_slot) = required_slots.get_mut(target_field.index())
    {
        *required_slot = true;
    }

    RetainedSlotLayout::compile(
        field_count,
        required_slots
            .into_iter()
            .enumerate()
            .filter_map(|(slot, required)| required.then_some(slot))
            .collect(),
    )
}

// Grouped row views keep one compact single-slot value, one predecoded scalar
// path leaf, or one retained slot row. The retained row shape decodes each
// required field once at the row-runtime boundary so filter, grouping, and
// aggregate evaluation can reuse borrowed slot values.
enum RowViewStorage {
    Single { slot: usize, value: Value },
    SinglePath { value: Value },
    Retained(RetainedSlotRow),
}

impl RowView {
    /// Build one retained row fixture from slot-indexed values.
    #[must_use]
    #[cfg(test)]
    pub(in crate::db::executor) fn new(slots: Vec<Option<Value>>) -> Self {
        // Keep fixture field indices while storing only populated values under
        // the same layout used by grouped ingest.
        let required_slots = slots
            .iter()
            .enumerate()
            .filter_map(|(slot, value)| value.as_ref().map(|_| slot))
            .collect();
        let layout = RetainedSlotLayout::compile(slots.len(), required_slots);
        let values = slots.into_iter().flatten().map(Some).collect();

        Self::from_retained_slots(RetainedSlotRow::from_indexed_values(&layout, values))
    }

    /// Build one grouped row view over already decoded retained slot values.
    #[must_use]
    pub(in crate::db::executor) const fn from_retained_slots(row: RetainedSlotRow) -> Self {
        Self {
            storage: RowViewStorage::Retained(row),
        }
    }

    /// Build one compact grouped row view for the common single-slot grouped
    /// shape without cloning the shared retained-slot layout or allocating a
    /// one-element retained-values vector.
    #[must_use]
    pub(in crate::db::executor) const fn from_single_value(slot: usize, value: Value) -> Self {
        Self {
            storage: RowViewStorage::Single { slot, value },
        }
    }

    /// Borrow one slot by index without cloning decoded grouped row values.
    pub(in crate::db::executor) fn slot_value_ref(&self, index: usize) -> Option<&Value> {
        match &self.storage {
            RowViewStorage::Single { slot, value } => (*slot == index).then_some(value),
            RowViewStorage::SinglePath { .. } => None,
            RowViewStorage::Retained(row) => row.slot_ref(index),
        }
    }

    /// Read one required slot and fail closed when it is missing.
    pub(in crate::db::executor) fn require_slot_value(
        &self,
        index: usize,
    ) -> Result<&Value, InternalError> {
        self.slot_value_ref(index)
            .ok_or_else(InternalError::query_executor_invariant)
    }

    /// Consume this row view and move out one required slot value without
    /// cloning. Use this only at callsites that no longer need any other row
    /// slots after extracting the selected value.
    pub(in crate::db::executor) fn into_required_slot_value(
        self,
        index: usize,
    ) -> Result<Value, InternalError> {
        match self.storage {
            RowViewStorage::Single { slot, value } => {
                if slot == index {
                    return Ok(value);
                }

                Err(InternalError::query_executor_invariant())
            }
            RowViewStorage::SinglePath { .. } => Err(InternalError::query_executor_invariant()),
            RowViewStorage::Retained(mut row) => row
                .take_slot(index)
                .ok_or_else(InternalError::query_executor_invariant),
        }
    }

    /// Decode one required slot into an owned value.
    pub(in crate::db::executor) fn require_slot_owned(
        &self,
        index: usize,
    ) -> Result<Value, InternalError> {
        self.require_slot_value(index).cloned()
    }

    /// Run one closure with a required slot value borrowed from row-view storage.
    pub(in crate::db::executor) fn with_required_slot<R>(
        &self,
        index: usize,
        f: impl FnOnce(&Value) -> Result<R, InternalError>,
    ) -> Result<R, InternalError> {
        f(self.require_slot_value(index)?)
    }

    /// Borrow the scalar leaf produced by the prepared single-path row decoder.
    #[must_use]
    pub(in crate::db::executor) const fn predecoded_single_group_path_value(
        &self,
    ) -> Option<&Value> {
        match &self.storage {
            RowViewStorage::SinglePath { value } => Some(value),
            RowViewStorage::Single { .. } | RowViewStorage::Retained(_) => None,
        }
    }

    /// Evaluate one compiled residual filter program against this structural row.
    pub(in crate::db::executor) fn eval_filter_program(
        &self,
        effective_runtime_filter_program: &EffectiveRuntimeFilterProgram,
    ) -> Result<bool, InternalError> {
        eval_effective_runtime_filter_program_with_value_cow_reader(
            effective_runtime_filter_program,
            &mut |slot| self.slot_value_ref(slot).map(Cow::Borrowed),
        )
    }

    /// Extract one validated aggregate field value from this structural row.
    pub(in crate::db::executor) fn extract_orderable_field_value(
        &self,
        field_slot: FieldSlot,
    ) -> Result<Value, InternalError> {
        let mut value = Some(self.require_slot_owned(field_slot.index)?);

        extract_orderable_field_value_with_slot_reader(field_slot, &mut |_| value.take())
            .map_err(AggregateFieldValueError::into_internal_error)
    }

    /// Collect one grouped key payload from planned group field slots.
    pub(in crate::db::executor) fn group_values(
        &self,
        group_fields: &[PlannedFieldSlot],
    ) -> Result<Vec<Value>, InternalError> {
        let mut values = Vec::with_capacity(group_fields.len());

        for field in group_fields {
            let value = self.require_slot_owned(field.index())?;
            values.push(value);
        }

        Ok(values)
    }
}

impl CompiledExprValueReader for RowView {
    fn read_slot(&self, slot: usize) -> Option<Cow<'_, Value>> {
        self.slot_value_ref(slot).map(Cow::Borrowed)
    }

    fn read_group_key(&self, _offset: usize) -> Option<Cow<'_, Value>> {
        None
    }

    fn read_aggregate(&self, _index: usize) -> Option<Cow<'_, Value>> {
        None
    }

    fn read_field_path(
        &self,
        root_slot: usize,
        segments: &[String],
        _segment_bytes: &[Box<[u8]>],
    ) -> Result<Option<Cow<'_, Value>>, ProjectionEvalError> {
        let Some(root) = self.slot_value_ref(root_slot) else {
            return Ok(None);
        };
        let value = resolve_value_field_path(root, segments)?;

        Ok(Some(value.map_or(Cow::Owned(Value::Null), Cow::Borrowed)))
    }
}

///
/// SingleGroupedSlotDecode
///
/// SingleGroupedSlotDecode freezes the one-slot grouped row path selected for
/// this runtime.
/// The data-layer sparse decoder uses the frozen accepted row contract, so
/// the grouped runtime only keeps the required slot selected by route staging.
///

struct SingleGroupedSlotDecode {
    slot: usize,
}

/// Prepared raw-row decoder for the common one-scalar-path grouped shape.
struct SingleGroupedPathDecode {
    root_slot: usize,
    segment_bytes: Box<[Box<[u8]>]>,
}

impl SingleGroupedPathDecode {
    fn new(path: &ScalarGroupPath) -> Self {
        Self {
            root_slot: path.root_slot(),
            segment_bytes: path
                .path()
                .segments()
                .iter()
                .map(|segment| segment.as_bytes().to_vec().into_boxed_slice())
                .collect::<Vec<_>>()
                .into_boxed_slice(),
        }
    }
}

/// One mutually exclusive single-value row decode selected at preparation.
enum SingleGroupedDecode {
    Path(SingleGroupedPathDecode),
    Slot(SingleGroupedSlotDecode),
}

///
/// StructuralGroupedRowRuntime
///
/// StructuralGroupedRowRuntime keeps grouped row reads on store-handle and
/// structural decode metadata only.
/// Grouped fold/runtime code receives slot-indexed `RowView` payloads without
/// carrying `Context<'_, E>` or any entity-typed row adapter in production.
///

pub(in crate::db::executor) struct StructuralGroupedRowRuntime {
    store: StoreHandle,
    row_layout: RowLayout,
    grouped_slot_layout: RetainedSlotLayout,
    single_grouped_decode: Option<SingleGroupedDecode>,
}

impl StructuralGroupedRowRuntime {
    /// Build one grouped row runtime from structural store authority and one
    /// precomputed row-decode layout.
    #[must_use]
    pub(in crate::db::executor) fn new(
        store: StoreHandle,
        row_layout: RowLayout,
        grouped_slot_layout: RetainedSlotLayout,
        single_grouped_path: Option<&ScalarGroupPath>,
    ) -> Self {
        let single_grouped_decode = single_grouped_path
            .map(SingleGroupedPathDecode::new)
            .map(SingleGroupedDecode::Path)
            .or_else(|| match grouped_slot_layout.required_slots() {
                [required_slot] => Some(SingleGroupedDecode::Slot(SingleGroupedSlotDecode {
                    slot: *required_slot,
                })),
                _ => None,
            });

        Self {
            store,
            row_layout,
            grouped_slot_layout,
            single_grouped_decode,
        }
    }

    // Decode one persisted data row straight into the structural slot view
    // consumed by grouped fold/runtime stages without building a full kernel row.
    fn row_view_from_data_row(
        &self,
        key: &DecodedDataStoreKey,
        row: RawRow,
    ) -> Result<RowView, InternalError> {
        match self.single_grouped_decode.as_ref() {
            Some(SingleGroupedDecode::Path(single_grouped_path_decode)) => {
                self.single_path_row_view_from_data_row(key, row, single_grouped_path_decode)
            }
            Some(SingleGroupedDecode::Slot(single_grouped_slot_decode)) => {
                self.single_slot_row_view_from_data_row(key, row, single_grouped_slot_decode)
            }
            None => {
                charge_decoded_row(row.len(), self.grouped_slot_layout.required_slots().len())?;
                let retained_slots = RowDecoder::decode_retained_slots_from_data_key(
                    &self.row_layout,
                    key,
                    &row,
                    &self.grouped_slot_layout,
                )?;

                Ok(RowView::from_retained_slots(retained_slots))
            }
        }
    }

    fn single_path_row_view_from_data_row(
        &self,
        key: &DecodedDataStoreKey,
        row: RawRow,
        path: &SingleGroupedPathDecode,
    ) -> Result<RowView, InternalError> {
        charge_decoded_row(row.len(), path.segment_bytes.len())?;
        let row_fields = self.row_layout.open_raw_row_with_contract(&row)?;
        row_fields.validate_primary_key(key)?;
        let root_bytes = row_fields.required_bytes(path.root_slot)?;
        let leaf_bytes = resolve_path_segments(root_bytes, path.segment_bytes.as_ref())
            .map_err(|_| InternalError::persisted_row_decode_corruption())?;
        let value = match leaf_bytes {
            Some(leaf_bytes) => decode_structural_value_storage_bytes(leaf_bytes)
                .map_err(|_| InternalError::persisted_row_decode_corruption())?,
            None => Value::Null,
        };

        Ok(RowView {
            storage: RowViewStorage::SinglePath { value },
        })
    }

    // Decode one grouped row view for the common single-slot shape without
    // allocating the shared indexed row-view wrapper.
    fn single_slot_row_view_from_data_row(
        &self,
        key: &DecodedDataStoreKey,
        row: RawRow,
        single_grouped_slot_decode: &SingleGroupedSlotDecode,
    ) -> Result<RowView, InternalError> {
        let value = self.decode_single_grouped_slot_value_from_raw_row(
            key,
            &row,
            single_grouped_slot_decode,
        )?;

        Ok(RowView::from_single_value(
            single_grouped_slot_decode.slot,
            value,
        ))
    }

    // Decode the caller-frozen single grouped slot directly from one raw row.
    // Both the single-slot row-view path and the direct grouped slot read path
    // share the same data-layer sparse required-slot decoder.
    fn decode_single_grouped_slot_value_from_raw_row(
        &self,
        key: &DecodedDataStoreKey,
        row: &RawRow,
        single_grouped_slot_decode: &SingleGroupedSlotDecode,
    ) -> Result<Value, InternalError> {
        charge_decoded_row(row.len(), 1)?;
        RowLayout::decode_required_value_from_data_key(
            &self.row_layout,
            row,
            key,
            single_grouped_slot_decode.slot,
        )
    }

    // Return the single-slot decode contract only when the caller-selected
    // required slot matches the runtime-frozen single grouped slot path.
    const fn matching_single_grouped_slot_decode(
        &self,
        required_slot: usize,
    ) -> Option<&SingleGroupedSlotDecode> {
        match self.single_grouped_decode.as_ref() {
            Some(SingleGroupedDecode::Slot(single_grouped_slot_decode))
                if single_grouped_slot_decode.slot == required_slot =>
            {
                Some(single_grouped_slot_decode)
            }
            Some(SingleGroupedDecode::Path(_) | SingleGroupedDecode::Slot(_)) | None => None,
        }
    }

    // Read one persisted row under the grouped consistency contract while
    // preserving fail-closed executor corruption handling.
    fn read_data_row(
        &self,
        consistency: MissingRowPolicy,
        key: &DecodedDataStoreKey,
    ) -> Result<Option<RawRow>, InternalError> {
        let raw_key = key.to_raw()?;
        let row = self.store.with_data(|store| store.get(&raw_key));
        charge_current_execution_budget(DiagnosticExecutionBudgetResource::RowsVisited, 1)?;
        if let Some(row) = row.as_ref() {
            charge_materialized_data_row!(row)?;
        }

        match (consistency, row) {
            (MissingRowPolicy::Ignore, None) => Ok(None),
            (MissingRowPolicy::Ignore | MissingRowPolicy::Error, Some(row)) => Ok(Some(row)),
            (MissingRowPolicy::Error, None) => Err(InternalError::store_corruption()),
        }
    }

    /// Read one data row and decode one caller-selected grouped slot value
    /// directly when the grouped runtime already carries the matching one-slot
    /// decode metadata.
    pub(in crate::db::executor) fn read_single_group_value(
        &self,
        consistency: MissingRowPolicy,
        key: &DecodedDataStoreKey,
        required_slot: usize,
    ) -> Result<Option<Value>, InternalError> {
        let Some(row) = self.read_data_row(consistency, key)? else {
            return Ok(None);
        };

        if let Some(single_grouped_slot_decode) =
            self.matching_single_grouped_slot_decode(required_slot)
        {
            return self
                .decode_single_grouped_slot_value_from_raw_row(
                    key,
                    &row,
                    single_grouped_slot_decode,
                )
                .map(Some);
        }

        let row_view = self.row_view_from_data_row(key, row)?;

        row_view.into_required_slot_value(required_slot).map(Some)
    }

    /// Read one data row and project it into one structural grouped row view.
    pub(in crate::db::executor) fn read_row_view(
        &self,
        consistency: MissingRowPolicy,
        key: &DecodedDataStoreKey,
    ) -> Result<Option<RowView>, InternalError> {
        self.read_data_row(consistency, key)?
            .map(|row| self.row_view_from_data_row(key, row))
            .transpose()
    }
}

///
/// GroupedStreamStage
///
/// Stream-construction stage payload for grouped execution.
/// Owns recovered context, execution preparation, and resolved grouped key
/// stream for fold-phase consumption.
///

pub(in crate::db::executor) struct GroupedStreamStage {
    row_runtime: StructuralGroupedRowRuntime,
    prepared_residents: Rc<PreparedGroupedRuntimeResidents>,
    resolved: ResolvedExecutionKeyStream,
}

impl GroupedStreamStage {
    // Build one grouped stream stage from recovered context, execution preparation,
    // and resolved grouped key stream payload.
    pub(in crate::db::executor) const fn new(
        row_runtime: StructuralGroupedRowRuntime,
        prepared_residents: Rc<PreparedGroupedRuntimeResidents>,
        resolved: ResolvedExecutionKeyStream,
    ) -> Self {
        Self {
            row_runtime,
            prepared_residents,
            resolved,
        }
    }

    // Borrow grouped fold inputs together so callers can combine immutable and
    // mutable borrows safely.
    pub(in crate::db::executor) fn fold_inputs_mut(
        &mut self,
    ) -> (
        &StructuralGroupedRowRuntime,
        &ExecutionPreparation,
        &mut ResolvedExecutionKeyStream,
    ) {
        (
            &self.row_runtime,
            self.prepared_residents.execution_preparation(),
            &mut self.resolved,
        )
    }
}

///
/// TESTS
///

#[cfg(test)]
mod tests {
    use crate::{
        db::executor::{
            pipeline::runtime::RowView,
            terminal::{RetainedSlotLayout, RetainedSlotRow},
        },
        value::Value,
    };

    #[test]
    fn retained_row_view_resolves_noncontiguous_slots() {
        let row_view = RowView::new(vec![
            None,
            Some(Value::Nat64(7)),
            None,
            None,
            Some(Value::Text("group".to_string())),
            None,
        ]);

        assert_eq!(row_view.slot_value_ref(1), Some(&Value::Nat64(7)));
        assert_eq!(
            row_view.slot_value_ref(4),
            Some(&Value::Text("group".to_string()))
        );
        assert_eq!(row_view.slot_value_ref(0), None);
        assert_eq!(row_view.slot_value_ref(5), None);
        assert_eq!(row_view.slot_value_ref(6), None);
        assert_eq!(
            row_view.into_required_slot_value(4).unwrap(),
            Value::Text("group".to_string())
        );
    }

    #[test]
    fn single_slot_row_view_resolves_only_its_declared_slot() {
        let row_view = RowView::from_single_value(4, Value::Text("group".to_string()));

        assert_eq!(
            row_view.slot_value_ref(4),
            Some(&Value::Text("group".to_string()))
        );
        assert_eq!(row_view.slot_value_ref(1), None);
    }

    #[test]
    fn retained_row_view_slot_reads_are_repeatable_borrows() {
        let layout = RetainedSlotLayout::compile(5, vec![1, 4]);
        let retained = RetainedSlotRow::from_indexed_values(
            &layout,
            vec![
                Some(Value::Nat64(7)),
                Some(Value::Text("group".to_string())),
            ],
        );
        let row_view = RowView::from_retained_slots(retained);

        assert_eq!(
            row_view.slot_value_ref(1),
            Some(&Value::Nat64(7)),
            "first retained slot read should borrow the decoded value",
        );
        assert_eq!(
            row_view.slot_value_ref(1),
            Some(&Value::Nat64(7)),
            "second retained slot read must see the same decoded value",
        );
        assert_eq!(
            row_view.slot_value_ref(4),
            Some(&Value::Text("group".to_string())),
            "reading another retained slot must not invalidate earlier slots",
        );
    }
}