1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
//! Coverage audit: record which entity types are actually constructed.
//!
//! Off unless the `authored-dump` feature is on *and* `AUTHORED_DUMP`
//! names a directory, so an `--all-features` build pays one relaxed
//! atomic load per entity and nothing else.
//!
//! # Why this exists
//!
//! Static scanning of writer call sites cannot answer "is this entity
//! authorable". A type name reaches [`crate::Entity::new`] through a
//! const, a catalogue row, or a match arm returning it into a tuple, so
//! a scan both misses real writers and counts names that are only
//! mentioned. Recording what is built during a test run answers it
//! directly.
//!
//! # Origins
//!
//! Three call sites, because "an entity of this type exists" and "a
//! writer can produce one" are different claims:
//!
//! - `create`: [`crate::Transaction::create`], the authoring path. The
//! only origin that proves a writer exists.
//! - `insert`: [`crate::Model::insert`], where every entity actually
//! lands -- committed transactions, [`crate::Model::push`], and codec
//! loads all funnel through it. The chokepoint, so nothing enters a
//! model unseen.
//! - `retype`: `Model::retype`, which changes a type name in place and
//! can therefore produce a type no writer ever constructed.
//!
//! An earlier version hooked `create` and `push` only. That missed
//! `Transaction::stage(Edit::Create { .. })`, which builds an entity
//! without going through `create`, and missed `retype` entirely.
//!
//! # Usage
//!
//! ```text
//! AUTHORED_DUMP=/tmp/dump \
//! cargo test --workspace --all-features --features ifc-model/authored-dump
//! python3 scripts/authored-coverage.py /tmp/dump
//! ```
use BTreeSet;
use ;
use ;
/// Where records accumulate until the process exits.
/// Tri-state cache of the `AUTHORED_DUMP` lookup: 0 unknown, 1 off, 2 on.
///
/// The variable is read once. Without this every constructed entity pays
/// an environment lookup and a `String` allocation, which is a real cost
/// on a full `--all-features` run where the feature is on but the
/// variable is unset.
static STATE: AtomicU8 = new;
/// The directory named by `AUTHORED_DUMP`, resolved once.
/// Whether recording is on, reading the environment at most once.
///
/// Public so a test can assert the hook stays inert when the feature
/// is compiled in but `AUTHORED_DUMP` is unset -- the configuration
/// every `--all-features` build runs in. Asserting on an absent output
/// directory would pass even if this returned `true`, since the writer
/// has no directory to write to either way.
/// Record one type name against the path that produced it.
///
/// `origin` is `"create"`, `"insert"` or `"retype"`; see the module
/// docs for what each proves. Names are upper-cased because the crates
/// disagree on the casing they store and the audit compares against the
/// schema.
/// Write the accumulated set to a per-process file.
///
/// Per-process because cargo runs test binaries in parallel and a single
/// shared path would have them overwrite each other. The reader unions
/// every file in the directory.
///
/// Failures are ignored: this is an audit aid, and a full disk or a
/// missing directory must not fail the run it is observing.