---
source: crates/ridl-backend-rust/src/tests.rs
expression: rust_for(decls)
---
/// Vehicle speed over ground
///
/// Quantization (`step`) is not checked by `new`.
#[derive(Debug, Clone, Copy, PartialEq, PartialOrd)]
#[repr(transparent)]
pub struct Speed(f64);
impl Speed {
/// Constructs the value, enforcing its typl constraints.
pub fn new(
value: f64,
) -> ::core::result::Result<Self, ::ridl_rt::payload::Violation> {
Self::check(&value)?;
::core::result::Result::Ok(Self::new_unchecked(value))
}
/// Checks `value` against this type's typl constraints, without
/// constructing it. `pub(crate)` rather than `pub`: a caller
/// outside `new` is a function generated into this crate — since
/// driftsys/ridl#467 that includes the codec of *another* package
/// of the same build, which reaches this type through the module
/// tree and so cannot see a private item here. The emitted crate
/// is one crate per build, so `pub(crate)` reaches every such
/// caller while adding nothing to the crate's public surface.
/// Whether this becomes `pub` is Epic 10's call, still open.
/// `new` is the composition of this and `new_unchecked`.
pub(crate) fn check(
value: &f64,
) -> ::core::result::Result<(), ::ridl_rt::payload::Violation> {
let value = *value;
if value < 0.0 {
return ::core::result::Result::Err(::ridl_rt::payload::Violation {
type_name: "Speed",
rule: ::ridl_rt::payload::Rule::Range,
});
}
if value > 250.0 {
return ::core::result::Result::Err(::ridl_rt::payload::Violation {
type_name: "Speed",
rule: ::ridl_rt::payload::Rule::Range,
});
}
::core::result::Result::Ok(())
}
/// Constructs the value without checking its constraints.
///
/// Safe: nothing here relies on the invariant for memory
/// soundness. Use it only for a value already known to satisfy
/// the contract.
pub const fn new_unchecked(value: f64) -> Self {
Self(value)
}
pub const fn get(self) -> f64 {
self.0
}
}
impl ::core::convert::TryFrom<f64> for Speed {
type Error = ::ridl_rt::payload::Violation;
fn try_from(value: f64) -> ::core::result::Result<Self, Self::Error> {
Self::new(value)
}
}
impl ::core::convert::From<Speed> for f64 {
fn from(value: Speed) -> Self {
value.0
}
}
impl Default for Speed {
fn default() -> Self {
Speed::new_unchecked(0.0)
}
}
#[derive(Debug, Clone, PartialEq)]
pub struct Samples {
pub readings: [Speed; 8],
pub history: Vec<Speed>,
}
impl Default for Samples {
fn default() -> Self {
Samples {
readings: ::core::array::from_fn(|_| Speed::default()),
history: (0..2).map(|_| Speed::default()).collect(),
}
}
}
/// An accessor over FlatBuffers bytes `Speed`'s `verify` accepted.
///
/// The buffer's root is the box table ADR-0019 decision 8
/// gives this declaration: one required `value` field. A
/// buffer carrying no slot for it is `MissingRequired`.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
#[allow(deprecated)]
pub struct SpeedFbView<'a> {
pub(crate) buf: &'a [u8],
pub(crate) table: usize,
}
#[allow(deprecated)]
impl<'a> SpeedFbView<'a> {
/// The verified bytes this view reads.
pub fn bytes(&self) -> &'a [u8] {
self.buf
}
/// The value the box carries. `Speed` is one value, so this decodes it rather than borrowing it, which costs one read.
pub fn value(&self) -> Speed {
__ridl_fb_decode_speed(self.buf, self.table)
}
}
/// Writes `Speed` as its box table and returns its position (ADR-0019 decision 8).
#[allow(deprecated)]
pub(crate) fn __ridl_fb_encode_speed(
value: &Speed,
builder: &mut ::ridl_rt::flatbuffers::Builder<'_>,
) -> ::core::result::Result<
::ridl_rt::flatbuffers::Pos,
::ridl_rt::payload::EncodeError,
> {
::core::result::Result::Ok({
let __box = [
::ridl_rt::flatbuffers::TableField {
slot: 0u16,
offset: 4u16,
value: {
let __s = *value;
::ridl_rt::flatbuffers::Field::F32(__s.get() as f32)
},
},
];
builder.push_table(8usize, 4usize, 1u16, &__box)?
})
}
#[allow(deprecated)]
pub(crate) fn __ridl_fb_verify_speed(
buf: &[u8],
table: usize,
) -> ::core::result::Result<(), ::ridl_rt::payload::VerifyError> {
match ::ridl_rt::flatbuffers::field(buf, table, 0u16, 4usize)
.map_err(::ridl_rt::payload::VerifyError::Structure)?
{
::core::option::Option::Some(__p) => {
let __raw = ::ridl_rt::flatbuffers::read_f32(buf, __p)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
Speed::check(&(f64::from(__raw)))
.map_err(::ridl_rt::payload::VerifyError::Contract)?;
}
::core::option::Option::None => {
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Structure(
::ridl_rt::payload::Malformed::MissingRequired,
),
);
}
}
::core::result::Result::Ok(())
}
#[allow(deprecated)]
pub(crate) fn __ridl_fb_decode_speed(buf: &[u8], table: usize) -> Speed {
{
let __p = ::ridl_rt::flatbuffers::field(buf, table, 0u16, 4usize)
.unwrap_or(::core::option::Option::None)
.unwrap_or(0usize);
Speed::new_unchecked(
f64::from(::ridl_rt::flatbuffers::read_f32(buf, __p).unwrap_or(0.0f32)),
)
}
}
#[allow(deprecated)]
impl ::ridl_rt::payload::Payload<::ridl_rt::encoding::FlatBuffers> for Speed {
/// The largest FlatBuffers buffer any legal `Speed` encodes to: 46 bytes.
///
/// `ridl_ir::projection::flatbuffers::max_size` computed it,
/// which is the one implementation of the bound (design note
/// D-6): each table is charged its `soffset`, its inline
/// fields, its vtable and one alignment event per slot; a
/// string four bytes per declared character plus a
/// terminator; a collection its declared maximum. It is a
/// literal rather than an expression over the field types
/// because that slack is not expressible in Rust's type
/// system.
const MAX_SIZE: usize = 46usize;
type View<'a> = SpeedFbView<'a>;
fn encode<'o>(
&self,
out: &'o mut [u8],
) -> ::core::result::Result<
::ridl_rt::payload::Encoded<'o, Self::View<'o>>,
::ridl_rt::payload::EncodeError,
> {
let mut builder = ::ridl_rt::flatbuffers::Builder::new(out);
let __root = __ridl_fb_encode_speed(self, &mut builder)?;
let bytes = builder.finish(__root, 8usize)?;
let table = ::ridl_rt::flatbuffers::root(bytes).unwrap_or(0usize);
::core::result::Result::Ok(::ridl_rt::payload::Encoded {
bytes,
view: SpeedFbView { buf: bytes, table },
})
}
fn verify(
buf: &[u8],
) -> ::core::result::Result<Self::View<'_>, ::ridl_rt::payload::VerifyError> {
if buf.len()
> <Self as ::ridl_rt::payload::Payload<
::ridl_rt::encoding::FlatBuffers,
>>::MAX_SIZE
{
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Structure(
::ridl_rt::payload::Malformed::TooLarge,
),
);
}
let table = ::ridl_rt::flatbuffers::root(buf)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
__ridl_fb_verify_speed(buf, table)?;
::core::result::Result::Ok(SpeedFbView { buf, table })
}
fn decode(
r: ::ridl_rt::payload::Ref<'_, Self, ::ridl_rt::encoding::FlatBuffers>,
) -> Self {
let __view = r.view();
__ridl_fb_decode_speed(__view.buf, __view.table)
}
}
/// A zero-copy accessor over FlatBuffers bytes `Samples`'s `verify` accepted.
///
/// A scalar, a string, a byte sequence and a nested table are
/// read in place and allocate nothing. A union and a collection
/// are decoded on access instead: a union's arms and a
/// collection's elements have no one view type to hand back.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
#[allow(deprecated)]
pub struct SamplesFbView<'a> {
pub(crate) buf: &'a [u8],
pub(crate) table: usize,
}
#[allow(deprecated)]
impl<'a> SamplesFbView<'a> {
/// The verified bytes this view reads.
pub fn bytes(&self) -> &'a [u8] {
self.buf
}
/// Reads `Samples`'s `readings` field in place.
pub fn readings(&self) -> [Speed; 8] {
let __p = ::ridl_rt::flatbuffers::field(self.buf, self.table, 0u16, 4usize)
.unwrap_or(::core::option::Option::None)
.unwrap_or(0usize);
{
let __v = ::ridl_rt::flatbuffers::vector(self.buf, __p, 4usize)
.unwrap_or(::ridl_rt::flatbuffers::Vector {
len: 0,
first: 0,
});
::core::array::from_fn(|__i| {
let __at = __v.element(__i, 4usize);
Speed::new_unchecked(
f64::from(
::ridl_rt::flatbuffers::read_f32(self.buf, __at)
.unwrap_or(0.0f32),
),
)
})
}
}
/// Reads `Samples`'s `history` field in place.
pub fn history(&self) -> Vec<Speed> {
let __p = ::ridl_rt::flatbuffers::field(self.buf, self.table, 1u16, 4usize)
.unwrap_or(::core::option::Option::None)
.unwrap_or(0usize);
{
let __v = ::ridl_rt::flatbuffers::vector(self.buf, __p, 4usize)
.unwrap_or(::ridl_rt::flatbuffers::Vector {
len: 0,
first: 0,
});
let mut __out = Vec::with_capacity(__v.len);
for __i in 0..__v.len {
let __at = __v.element(__i, 4usize);
__out
.push(
Speed::new_unchecked(
f64::from(
::ridl_rt::flatbuffers::read_f32(self.buf, __at)
.unwrap_or(0.0f32),
),
),
);
}
__out
}
}
}
/// Writes `Samples` as a FlatBuffers table and returns its position.
#[allow(deprecated)]
pub(crate) fn __ridl_fb_encode_samples(
value: &Samples,
builder: &mut ::ridl_rt::flatbuffers::Builder<'_>,
) -> ::core::result::Result<
::ridl_rt::flatbuffers::Pos,
::ridl_rt::payload::EncodeError,
> {
let mut __fields = [::ridl_rt::flatbuffers::TableField {
slot: 0u16,
offset: 4u16,
value: ::ridl_rt::flatbuffers::Field::Bool(false),
}; 2usize];
let mut __n = 0usize;
__fields[__n] = ::ridl_rt::flatbuffers::TableField {
slot: 0u16,
offset: 4u16,
value: ::ridl_rt::flatbuffers::Field::Offset({
let __c = &value.readings;
let mut __bytes: Vec<u8> = Vec::with_capacity(__c.len() * 4usize);
for __e in __c.iter() {
let __s = *__e;
let __r = __s.get() as f32;
__bytes.extend_from_slice(&__r.to_le_bytes());
}
builder.push_vector(&__bytes, 4usize)?
}),
};
__n += 1;
__fields[__n] = ::ridl_rt::flatbuffers::TableField {
slot: 1u16,
offset: 8u16,
value: ::ridl_rt::flatbuffers::Field::Offset({
let __c = &value.history;
let mut __bytes: Vec<u8> = Vec::with_capacity(__c.len() * 4usize);
for __e in __c.iter() {
let __s = *__e;
let __r = __s.get() as f32;
__bytes.extend_from_slice(&__r.to_le_bytes());
}
builder.push_vector(&__bytes, 4usize)?
}),
};
__n += 1;
builder.push_table(12usize, 4usize, 2u16, &__fields[..__n])
}
/// Checks the FlatBuffers table at `table` against `Samples`'s shape.
///
/// A total walk of the type's own shape: the structure in full,
/// an enum and an enum-set discriminant, a collection's declared
/// element count, and every **named** scalar's own declared
/// range, length and pattern, checked over a borrow (`check`,
/// beside `new` on the type itself) against its declared range,
/// length and pattern.
///
/// This does not make every value `decode` builds satisfy every
/// typl constraint. Three gaps:
///
/// - a `step` constraint is checked nowhere — not by `new`, by
/// `check`, or here (driftsys/ridl#469);
/// - the pattern check is behind the `validate-pattern` feature,
/// so a value violating a `match` pattern passes when that
/// feature is off;
/// - an anonymous inline constraint (a field's own `[..]` or
/// `match` written at the field, not through a named scalar)
/// is not checked here at all (driftsys/ridl#469).
#[allow(deprecated)]
pub(crate) fn __ridl_fb_verify_samples(
buf: &[u8],
table: usize,
) -> ::core::result::Result<(), ::ridl_rt::payload::VerifyError> {
match ::ridl_rt::flatbuffers::field(buf, table, 0u16, 4usize)
.map_err(::ridl_rt::payload::VerifyError::Structure)?
{
::core::option::Option::Some(__p) => {
let __v = ::ridl_rt::flatbuffers::vector(buf, __p, 4usize)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
if __v.len != 8usize {
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Contract(::ridl_rt::payload::Violation {
type_name: "Samples",
rule: ::ridl_rt::payload::Rule::Length,
}),
);
}
for __i in 0..__v.len {
let __at = __v.element(__i, 4usize);
let __raw = ::ridl_rt::flatbuffers::read_f32(buf, __at)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
Speed::check(&(f64::from(__raw)))
.map_err(::ridl_rt::payload::VerifyError::Contract)?;
}
}
::core::option::Option::None => {
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Structure(
::ridl_rt::payload::Malformed::MissingRequired,
),
);
}
}
match ::ridl_rt::flatbuffers::field(buf, table, 1u16, 4usize)
.map_err(::ridl_rt::payload::VerifyError::Structure)?
{
::core::option::Option::Some(__p) => {
let __v = ::ridl_rt::flatbuffers::vector(buf, __p, 4usize)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
if __v.len < 2usize || __v.len > 8usize {
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Contract(::ridl_rt::payload::Violation {
type_name: "Samples",
rule: ::ridl_rt::payload::Rule::Length,
}),
);
}
for __i in 0..__v.len {
let __at = __v.element(__i, 4usize);
let __raw = ::ridl_rt::flatbuffers::read_f32(buf, __at)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
Speed::check(&(f64::from(__raw)))
.map_err(::ridl_rt::payload::VerifyError::Contract)?;
}
}
::core::option::Option::None => {
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Structure(
::ridl_rt::payload::Malformed::MissingRequired,
),
);
}
}
::core::result::Result::Ok(())
}
/// Builds `Samples` from the FlatBuffers table at `table`.
///
/// It cannot fail. A read that could is discharged with the
/// neutral value of its own type — zero, the empty string or
/// collection, the first declared enum variant — and `verify` is
/// what makes those branches unreachable. A named scalar is
/// built with its unchecked constructor (`new_unchecked`) over a
/// value `verify` has already range-checked (`check`), so this
/// never re-checks and never fails.
#[allow(deprecated)]
pub(crate) fn __ridl_fb_decode_samples(buf: &[u8], table: usize) -> Samples {
Samples {
readings: {
let __p = ::ridl_rt::flatbuffers::field(buf, table, 0u16, 4usize)
.unwrap_or(::core::option::Option::None)
.unwrap_or(0usize);
{
let __v = ::ridl_rt::flatbuffers::vector(buf, __p, 4usize)
.unwrap_or(::ridl_rt::flatbuffers::Vector {
len: 0,
first: 0,
});
::core::array::from_fn(|__i| {
let __at = __v.element(__i, 4usize);
Speed::new_unchecked(
f64::from(
::ridl_rt::flatbuffers::read_f32(buf, __at).unwrap_or(0.0f32),
),
)
})
}
},
history: {
let __p = ::ridl_rt::flatbuffers::field(buf, table, 1u16, 4usize)
.unwrap_or(::core::option::Option::None)
.unwrap_or(0usize);
{
let __v = ::ridl_rt::flatbuffers::vector(buf, __p, 4usize)
.unwrap_or(::ridl_rt::flatbuffers::Vector {
len: 0,
first: 0,
});
let mut __out = Vec::with_capacity(__v.len);
for __i in 0..__v.len {
let __at = __v.element(__i, 4usize);
__out
.push(
Speed::new_unchecked(
f64::from(
::ridl_rt::flatbuffers::read_f32(buf, __at)
.unwrap_or(0.0f32),
),
),
);
}
__out
}
},
}
}
#[allow(deprecated)]
impl ::ridl_rt::payload::Payload<::ridl_rt::encoding::FlatBuffers> for Samples {
/// The largest FlatBuffers buffer any legal `Samples` encodes to: 145 bytes.
///
/// `ridl_ir::projection::flatbuffers::max_size` computed it,
/// which is the one implementation of the bound (design note
/// D-6): each table is charged its `soffset`, its inline
/// fields, its vtable and one alignment event per slot; a
/// string four bytes per declared character plus a
/// terminator; a collection its declared maximum. It is a
/// literal rather than an expression over the field types
/// because that slack is not expressible in Rust's type
/// system.
const MAX_SIZE: usize = 145usize;
type View<'a> = SamplesFbView<'a>;
fn encode<'o>(
&self,
out: &'o mut [u8],
) -> ::core::result::Result<
::ridl_rt::payload::Encoded<'o, Self::View<'o>>,
::ridl_rt::payload::EncodeError,
> {
let mut builder = ::ridl_rt::flatbuffers::Builder::new(out);
let __root = __ridl_fb_encode_samples(self, &mut builder)?;
let bytes = builder.finish(__root, 8usize)?;
let table = ::ridl_rt::flatbuffers::root(bytes).unwrap_or(0usize);
::core::result::Result::Ok(::ridl_rt::payload::Encoded {
bytes,
view: SamplesFbView { buf: bytes, table },
})
}
fn verify(
buf: &[u8],
) -> ::core::result::Result<Self::View<'_>, ::ridl_rt::payload::VerifyError> {
if buf.len()
> <Self as ::ridl_rt::payload::Payload<
::ridl_rt::encoding::FlatBuffers,
>>::MAX_SIZE
{
return ::core::result::Result::Err(
::ridl_rt::payload::VerifyError::Structure(
::ridl_rt::payload::Malformed::TooLarge,
),
);
}
let table = ::ridl_rt::flatbuffers::root(buf)
.map_err(::ridl_rt::payload::VerifyError::Structure)?;
__ridl_fb_verify_samples(buf, table)?;
::core::result::Result::Ok(SamplesFbView { buf, table })
}
fn decode(
r: ::ridl_rt::payload::Ref<'_, Self, ::ridl_rt::encoding::FlatBuffers>,
) -> Self {
let __view = r.view();
__ridl_fb_decode_samples(__view.buf, __view.table)
}
}