1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
//! Every public type of the runner.
//!
//! Constructors and readers are this file's own child, `type_guard.rs`, so an invocation is born in one place and nothing reaches in afterwards.
//!
//! The descriptor home declares its table and its attachment over two type parameters, because it sits below the record vocabulary and may not import a record type.
//! This home sees both, so the parameters are pinned here once: the facts are [`Invocation`] and the conclusion is [`TrialConclusion`].
use crateHarnessClock;
use crate;
use crate;
use BTreeSet;
/// What one run stands on: the budgets a check reads, the host facts it was told, the site its reports are written at, and the caller's clock.
///
/// The engine reads this value and its other parameters and nothing else: no argument vector, no environment, no clock of its own, no output stream.
/// The site states where the invocation was written, not where a row was authored.
/// The budgets are the check's to honour, so a bound that was exceeded is a conclusion the check states rather than one the engine infers from a measurement.
/// What one invocation chooses from the complete world.
///
/// Every arm is a set over a shape a row already carries, so a selection joins on the table itself and no second index exists to disagree with it.
/// A selection narrows a run and never the denominator: the report is stated over every row of the world, however few of them this invocation named.
/// What a run expects that choice to match is [`SelectionPlan`]'s, because two runs can choose identically and expect differently.
/// What one selection says about one row of the denominator.
pub
/// A selection joined to what the run expects that selection to match.
///
/// The engine takes this rather than a bare [`Selection`], so every run states its anti-vacuity posture and no run is missing one.
/// [`SelectionPlan::allowing_empty`] is the only road that admits zero, and admitting it admits exactly that: no arm of it says a trial passed, because no trial ran.
/// Why a host-authored trial record was not admitted as evidence.
///
/// Each arm names the first relation that did not hold between the record and the binding, table, and selection it was joined to.
/// The callable one executable attachment carries, at the types this engine runs.
///
/// A capture-free function pointer, which excludes captured state and establishes neither semantic purity nor termination.
pub type TrialCall = fn ;
/// One row married to its callable, at the types this engine runs.
pub type TrialBinding = ;
/// The complete authored world, at the types this engine runs.
pub type TrialTable = ;
/// The sealed read surface an authored table and a staged view both present, at the types this engine runs.
pub type TrialTableView<'view> = ;
/// The typed cause every caught subject panic is cited under.
///
/// The pair is this home's own, so a fingerprint over a subject panic names the boundary that caught it rather than any of the panic's own words.
/// The family is qualified with the harness's own name, like every sibling family, so a consumer's bare `runner` family cannot alias it.
pub const SUBJECT_PANIC_CAUSE: FindingCause =
named;
/// What one selected trial did instead of concluding lawfully.
///
/// A satisfied check has no arm here, so "this is why the seat refused" is unsayable about a trial that passed.
/// Every arm carries a typed value lifted out of the record the run wrote, so a seat describes a failure by carrying it rather than by rendering it.
/// One selected trial that did not conclude lawfully: both identity rails, and what it did instead.
///
/// Neither rail stands in for the other — the semantic identity is the name this failure keeps across a refactor, and the site is the spelling a person filters on and jumps to.
/// What one aggregate seat's reading found when it did not refuse.
///
/// The two arms are two different facts, and naming them apart is what keeps a run that deliberately exercised nothing from being read as a run that exercised everything.
/// Nothing here spells "passed": the satisfied arm says every selected trial concluded lawfully, and says nothing at all about the rows the selection passed over.
/// The seats' one refusal type: everything a stamped test function answers with instead of passing.
///
/// A construction refusal enters unchanged through this type's [`From`] road over [`TrialTableRefusal`], and the run's own verdict supplies the other arms.
/// That is the whole road in, which is what makes `?` the entire ceremony at a seat.
/// `Debug` is the rendering surface, deliberately: a `Display` written here would be a second vocabulary for facts the typed fields already carry.