1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
//! **The reply codec's field readers** — rung 1 of [`super`]'s policy, in one
//! place so "shape refuses" is a property of the vocabulary rather than a
//! habit each decoder is trusted to keep.
//!
//! Every reader **names the field it refused on**. That is not politeness: a
//! seat's reader is the only party that can say which key of which answer was
//! wrong, and a bare "malformed reply" would send an operator to read the
//! engine's source.
//!
//! They are `pub(crate)`, not `pub`. Two take a reader function, which is a
//! trait bound, and a bound on a `pub` item forces monomorphisation onto every
//! consumer (`rules/no-pub-generic-bounds.yml`); the honest demotion is the
//! remedy the rule names, and nothing outside this crate reads a raw field.
//!
//! The key is always a parameter and the map never is a second borrow, so no
//! signature here needs a named lifetime: every reader takes borrows and hands
//! back an owned value, which is the house rule's *"borrow on the way in, own
//! on the way out"* with nothing to think about.
use ;
/// The key every listing hangs its elements off. One spelling, read by every
/// listing, because a second would be a second protocol.
const ROWS: &str = "rows";
/// A required string field.
pub
/// A required boolean field.
pub
/// A required signed-integer field — an age, which may be negative under clock
/// skew and is therefore not a count.
pub
/// A required count — a rollup, a rank, an indent, a counter value.
///
/// **It keeps the wire's own width and is never narrowed to a `usize`.** The
/// narrowing would be free everywhere this crate is built and its failure arm
/// therefore unreachable, and an unreachable arm under a 100% floor is a line
/// no test can honestly cover — so the choice is a branch that lies about
/// being checked, or the width the answer was written in. A count is a count
/// at any width; the one place a narrowing is a real check is [`exit`], where
/// the type is the thing rather than a container for it.
pub
/// The captured run's exit status, narrowed the same way. Its own reader
/// rather than a call to [`secs`], because the narrowing is the strictness: a
/// status no `i32` holds is an engine saying something this seat has no way to
/// paint.
pub
/// An **optional** string field: absent and `null` are both `None`, and a
/// value of the wrong type still refuses.
///
/// Absence is a reading here, never a malformed envelope — the reply surface
/// spells a fact's absence by leaving the key out precisely so a reader need
/// not tell "not stated" from "stated as empty". `None` and `Some("")` are two
/// different claims and this keeps them two.
pub
/// An **optional** exit status: absent and `null` are both `None`, a value of
/// the wrong type refuses, and one no `i32` holds refuses too.
///
/// [`exit`]'s narrowing over [`opt_text`]'s absence, and it is a reader rather
/// than the two composed at the call site because the two failures have to name
/// one field between them: a sign-in that has not settled and one that settled
/// on a status this seat cannot paint are different claims (`super::login`).
pub
/// A boolean whose **absence is `false`**, and whose `null` is a refusal.
///
/// It is not [`opt_text`]'s shape one type over, and the difference is the
/// point: an optional string spells *not stated* by absence OR by `null`
/// because the reply surface uses both, while REMOTE §5.1's consent flag
/// *"absent reads false, rides only when true, and a mistyped value refuses at
/// the read"* — and upstream's own decoder refuses a `null` there. Two ends
/// disagreeing about what an absence is would be a consent read one way and
/// enforced the other.
pub
/// An **optional** signed integer: absent and `null` are both `None`, and a
/// value of the wrong type still refuses.
///
/// [`opt_text`]'s reading one type over, and it exists for the same reason: a
/// bound that is not stated and a bound of zero are two different claims about
/// what a control will accept (`super::config`).
pub
/// A listing's elements, each read by `read`.
///
/// One element that will not read fails the whole listing rather than
/// shortening it. A shorter list is a lie a window paints silently, which is
/// the one outcome [`super`]'s policy exists to exclude.
pub
/// The same, for an array under a key of its own.
pub