vole-document 0.1.0-alpha.20

Persistent procedural document runtime: byte-exact reconstruction plus a content-addressed procedural seed DAG, queryable observations with provenance, and selective late materialization.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
//! Phase 12.8 court: cross-document procedural state under exact content identity.
//!
//! Two documents of **different formats** (a DOCX and an EPUB) that embed the
//! byte-identical resource resolve to **one** content-addressed
//! [`ResourceBlob`](vole_document::field::node::NodeKind::ResourceBlob) — one
//! node id, one persisted blob — so the second ingest writes strictly fewer seed
//! bytes and the shared decoded state is reused across a document boundary. A
//! no-sharing control (a structurally identical document embedding *different*
//! bytes) shares nothing.
//!
//! Sharing is scoped to the formats that actually extract embedded resources:
//! the package adapters (DOCX/EPUB). The Phase-11 PDF adapter does **not**
//! extract embedded images as resource blobs, so a PDF carrying the same bytes
//! joins the store but shares no resource node (asserted as a reported zero);
//! PDF↔DOCX resource sharing is therefore out of scope in Phase 12, and a
//! genuine cross-format share is demonstrated DOCX↔EPUB instead.
//!
//! Exactness is asserted for every root: `materialize_exact(root) == source`.
//! The whole file is gated on the features it needs so `--no-default-features`
//! builds an empty, compiling target.

#![cfg(all(
    feature = "field",
    feature = "package",
    feature = "docx",
    feature = "epub"
))]

use std::path::PathBuf;

use vole_document::adapter::package::{crc32_iso_hdlc, scan};
use vole_document::container::{Descriptor, ObjectSource};
use vole_document::dra::{Op, Program};
use vole_document::field::cache::DerivedCache;
use vole_document::field::dag::{
    EvalBudget, InverseWork, load_node, materialize_node_cached, retained_inverse_work_fraction,
};
use vole_document::field::index::{FsIndexStore, SEL_PACKAGE_MEMBER_DECODED, SelectorKey, lookup};
use vole_document::field::ingest::ingest;
use vole_document::field::observe::{
    ObserveRequest, ObserveStats, Representation, Selector, observe,
};
use vole_document::field::provenance::AnswerValue;
use vole_document::field::resource::{is_shareable_resource, resource_blob_node};
use vole_document::field::{Field, FieldStore};
use vole_document::limits::Limits;

/// The resource embedded verbatim in the shared cohort.
const SHARED_PNG: &[u8] = b"\x89PNG\r\n\x1a\nSHARED-RESOURCE-PAYLOAD-0123456789";
/// A control resource of **identical length** but different bytes.
const CONTROL_PNG: &[u8] = b"\x89PNG\r\n\x1a\nCONTROL-RESOURCE-PAYLOAD-012345678";

// ---------------------------------------------------------------------------
// Dependency-free ZIP / PDF writers (test ground truth)
// ---------------------------------------------------------------------------

fn put_u16(out: &mut Vec<u8>, v: u16) {
    out.extend_from_slice(&v.to_le_bytes());
}
fn put_u32(out: &mut Vec<u8>, v: u32) {
    out.extend_from_slice(&v.to_le_bytes());
}

/// Build a ZIP with stored members (order preserved), UTF-8 flag set.
fn build_zip(entries: &[(String, Vec<u8>)]) -> Vec<u8> {
    const UTF8_FLAG: u16 = 0x0800;
    let mut out: Vec<u8> = Vec::new();
    let mut offsets: Vec<u32> = Vec::new();
    let mut crcs: Vec<u32> = Vec::new();
    for (name, content) in entries {
        offsets.push(out.len() as u32);
        crcs.push(crc32_iso_hdlc(content));
        put_u32(&mut out, 0x0403_4b50);
        put_u16(&mut out, 20);
        put_u16(&mut out, UTF8_FLAG);
        put_u16(&mut out, 0); // stored
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u32(&mut out, *crcs.last().unwrap());
        put_u32(&mut out, content.len() as u32);
        put_u32(&mut out, content.len() as u32);
        put_u16(&mut out, name.len() as u16);
        put_u16(&mut out, 0);
        out.extend_from_slice(name.as_bytes());
        out.extend_from_slice(content);
    }
    let cd_start = out.len() as u32;
    for (i, (name, content)) in entries.iter().enumerate() {
        put_u32(&mut out, 0x0201_4b50);
        put_u16(&mut out, 20);
        put_u16(&mut out, 20);
        put_u16(&mut out, UTF8_FLAG);
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u32(&mut out, crcs[i]);
        put_u32(&mut out, content.len() as u32);
        put_u32(&mut out, content.len() as u32);
        put_u16(&mut out, name.len() as u16);
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u16(&mut out, 0);
        put_u32(&mut out, 0);
        put_u32(&mut out, offsets[i]);
        out.extend_from_slice(name.as_bytes());
    }
    let cd_end = out.len() as u32;
    put_u32(&mut out, 0x0605_4b50);
    put_u16(&mut out, 0);
    put_u16(&mut out, 0);
    put_u16(&mut out, entries.len() as u16);
    put_u16(&mut out, entries.len() as u16);
    put_u32(&mut out, cd_end - cd_start);
    put_u32(&mut out, cd_start);
    put_u16(&mut out, 0);
    out
}

/// A minimal OPC DOCX embedding `png` at `word/media/image1.png`.
fn build_docx(png: &[u8]) -> Vec<u8> {
    let content_types = br#"<?xml version="1.0" encoding="UTF-8"?><Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types"><Default Extension="rels" ContentType="application/vnd.openxmlformats-package.relationships+xml"/><Default Extension="xml" ContentType="application/xml"/><Default Extension="png" ContentType="image/png"/><Override PartName="/word/document.xml" ContentType="application/vnd.openxmlformats-officedocument.wordprocessingml.document.main+xml"/></Types>"#.to_vec();
    let rels = br#"<?xml version="1.0" encoding="UTF-8"?><Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"><Relationship Id="rId1" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument" Target="word/document.xml"/></Relationships>"#.to_vec();
    let document = br#"<?xml version="1.0" encoding="UTF-8"?><w:document xmlns:w="http://schemas.openxmlformats.org/wordprocessingml/2006/main"><w:body><w:p><w:r><w:t>Cross-document resource court</w:t></w:r></w:p></w:body></w:document>"#.to_vec();
    build_zip(&[
        ("[Content_Types].xml".to_string(), content_types),
        ("_rels/.rels".to_string(), rels),
        ("word/document.xml".to_string(), document),
        ("word/media/image1.png".to_string(), png.to_vec()),
    ])
}

/// A minimal OCF EPUB embedding `png` at `OEBPS/images/shared.png`.
fn build_epub(png: &[u8]) -> Vec<u8> {
    let container = br#"<?xml version="1.0" encoding="UTF-8"?><container version="1.0" xmlns="urn:oasis:names:tc:opendocument:xmlns:container"><rootfiles><rootfile full-path="OEBPS/package.opf" media-type="application/oebps-package+xml"/></rootfiles></container>"#.to_vec();
    let opf = br#"<?xml version="1.0" encoding="UTF-8"?><package xmlns="http://www.idpf.org/2007/opf" version="3.0" unique-identifier="id"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:identifier id="id">urn:uuid:court</dc:identifier><dc:title>Resource Court</dc:title><dc:language>en</dc:language></metadata><manifest><item id="c1" href="chapter.xhtml" media-type="application/xhtml+xml"/><item id="img" href="images/shared.png" media-type="image/png"/></manifest><spine><itemref idref="c1"/></spine></package>"#.to_vec();
    let chapter = br#"<?xml version="1.0" encoding="UTF-8"?><html xmlns="http://www.w3.org/1999/xhtml"><head><title>c</title></head><body><p>cross-document resource</p></body></html>"#.to_vec();
    build_zip(&[
        ("mimetype".to_string(), b"application/epub+zip".to_vec()),
        ("META-INF/container.xml".to_string(), container),
        ("OEBPS/package.opf".to_string(), opf),
        ("OEBPS/chapter.xhtml".to_string(), chapter),
        ("OEBPS/images/shared.png".to_string(), png.to_vec()),
    ])
}

/// A classic-xref PDF whose object 5 is an **unfiltered** image XObject carrying
/// `png` verbatim. The PDF adapter extracts no resource blob from it, so this is
/// an exactness-only participant.
fn build_pdf(png: &[u8]) -> Vec<u8> {
    let mut buf: Vec<u8> = Vec::new();
    let mut offsets: Vec<(u64, u64)> = Vec::new();
    let obj = |buf: &mut Vec<u8>, offsets: &mut Vec<(u64, u64)>, n: u64, body: &[u8]| {
        offsets.push((n, buf.len() as u64));
        buf.extend_from_slice(format!("{n} 0 obj\n").as_bytes());
        buf.extend_from_slice(body);
    };
    buf.extend_from_slice(b"%PDF-1.5\n");
    obj(
        &mut buf,
        &mut offsets,
        1,
        b"<< /Type /Catalog /Pages 2 0 R >>",
    );
    buf.extend_from_slice(b"\nendobj\n");
    obj(
        &mut buf,
        &mut offsets,
        2,
        b"<< /Type /Pages /Kids [3 0 R] /Count 1 >>",
    );
    buf.extend_from_slice(b"\nendobj\n");
    obj(
        &mut buf,
        &mut offsets,
        3,
        b"<< /Type /Page /Parent 2 0 R /MediaBox [0 0 612 792] /Resources << /XObject << /Im0 5 0 R >> >> /Contents 4 0 R >>",
    );
    buf.extend_from_slice(b"\nendobj\n");
    // An unfiltered content stream (its bytes are not a resource signature).
    let content = b"q 1 0 0 1 0 0 cm /Im0 Do Q";
    obj(
        &mut buf,
        &mut offsets,
        4,
        format!("<< /Length {} >>\nstream\n", content.len()).as_bytes(),
    );
    buf.extend_from_slice(content);
    buf.extend_from_slice(b"\nendstream\nendobj\n");
    // The image XObject: uncompressed, so its encoded bytes are `png` exactly.
    obj(
        &mut buf,
        &mut offsets,
        5,
        format!(
            "<< /Type /XObject /Subtype /Image /Width 4 /Height 4 /ColorSpace /DeviceRGB /BitsPerComponent 8 /Length {} >>\nstream\n",
            png.len()
        )
        .as_bytes(),
    );
    buf.extend_from_slice(png);
    buf.extend_from_slice(b"\nendstream\nendobj\n");
    // Classic xref trailer.
    let xref = buf.len() as u64;
    buf.extend_from_slice(b"xref\n0 6\n0000000000 65535 f \n");
    for n in 1..6u64 {
        let off = offsets.iter().find(|&&(num, _)| num == n).unwrap().1;
        buf.extend_from_slice(format!("{off:010} 00000 n \n").as_bytes());
    }
    buf.extend_from_slice(
        format!("trailer\n<< /Size 6 /Root 1 0 R >>\nstartxref\n{xref}\n%%EOF\n").as_bytes(),
    );
    buf
}

fn opaque_descriptor(source: &[u8]) -> Vec<u8> {
    let d = Descriptor {
        universe: vole_document::container::UNIVERSE.to_string(),
        source_format: vole_document::SOURCE_FORMAT_OPAQUE,
        format_basis: "opaque:phase12-share".to_string(),
        models: vec![],
        channels: vec![],
        objects: vec![ObjectSource::Inline(source.to_vec())],
        program: Program::new(vec![Op::EmitObject { object_id: 0 }]),
        observation_index: None,
        seek_directory: false,
        checkpoints: None,
        source_sha256: vole_document::integrity::sha256(source),
        source_len: source.len() as u64,
    };
    d.serialize().unwrap().0
}

fn temp_dir(label: &str) -> PathBuf {
    let mut p = std::env::temp_dir();
    p.push(format!(
        "vole-xdoc-{label}-{}-{}",
        std::process::id(),
        std::time::SystemTime::now()
            .duration_since(std::time::UNIX_EPOCH)
            .unwrap()
            .as_nanos()
    ));
    std::fs::create_dir_all(&p).unwrap();
    p
}

fn answer_bytes(answer: &vole_document::field::provenance::FieldAnswer) -> Vec<u8> {
    match &answer.value {
        AnswerValue::Bytes(b) => b.clone(),
        other => panic!("expected bytes, got {other:?}"),
    }
}

/// The content id of the shared resource blob, from the library itself.
fn shared_blob_id() -> vole_document::store::NodeId {
    resource_blob_node(SHARED_PNG).content_id()
}

// ---------------------------------------------------------------------------
// Cross-document sharing
// ---------------------------------------------------------------------------

#[test]
fn cross_document_shared_resource_is_one_content_addressed_blob() {
    let limits = Limits::DEFAULT;
    let shared_dir = temp_dir("identity-shared");
    let control_dir = temp_dir("identity-control");

    let docx_src = build_docx(SHARED_PNG);
    let epub_src = build_epub(SHARED_PNG);
    let control_src = build_epub(CONTROL_PNG);
    // A PDF carrying the same bytes verbatim participates in exactness only: the
    // Phase-11 PDF adapter extracts no embedded resource blob.
    let pdf_src = build_pdf(SHARED_PNG);

    assert!(is_shareable_resource(SHARED_PNG));
    assert!(is_shareable_resource(CONTROL_PNG));

    // Store A: a DOCX and an EPUB embedding the *same* resource bytes. DOCX first:
    // it pays the blob's byte cost; the EPUB then shares it by content id.
    let mut store = FieldStore::open(&shared_dir).unwrap();
    let docx = match ingest(&mut store, &opaque_descriptor(&docx_src), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };
    let epub = match ingest(&mut store, &opaque_descriptor(&epub_src), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };
    let pdf = match ingest(&mut store, &opaque_descriptor(&pdf_src), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Pdf(r) => r,
        other => panic!("expected PDF, got {other:?}"),
    };

    // Store B: the same DOCX, and a structurally identical EPUB whose only
    // difference is the resource bytes (the no-sharing control).
    let mut control_store = FieldStore::open(&control_dir).unwrap();
    let _control_docx =
        match ingest(&mut control_store, &opaque_descriptor(&docx_src), limits).unwrap() {
            vole_document::field::ingest::IngestOutcome::Package(r) => r,
            other => panic!("expected package, got {other:?}"),
        };
    let control =
        match ingest(&mut control_store, &opaque_descriptor(&control_src), limits).unwrap() {
            vole_document::field::ingest::IngestOutcome::Package(r) => r,
            other => panic!("expected package, got {other:?}"),
        };

    // One content id, one physically stored blob, shared across the DOCX/EPUB
    // boundary by exact byte identity (not by format or member name).
    let blob = shared_blob_id();
    assert!(
        store.seeds().contains_node(&blob).unwrap(),
        "the shared resource blob must be in the store"
    );

    // The DOCX writes the blob; the EPUB shares it by content id and writes zero
    // bytes for it, and shares the content-addressed decoded member node too.
    assert_eq!(
        docx.resource_blob_nodes, 1,
        "DOCX registers one blob: {docx:?}"
    );
    assert_eq!(
        docx.shared_resource_ids, 0,
        "DOCX pays for the blob: {docx:?}"
    );
    assert_eq!(docx.shared_resource_bytes, 0, "DOCX pays: {docx:?}");
    assert_eq!(
        epub.resource_blob_nodes, 1,
        "EPUB registers one blob: {epub:?}"
    );
    assert_eq!(
        epub.shared_resource_ids, 1,
        "EPUB must share the DOCX's resource blob: {epub:?}"
    );
    assert_eq!(
        epub.shared_resource_bytes,
        SHARED_PNG.len() as u64,
        "EPUB deduplicates exactly the resource bytes: {epub:?}"
    );
    // Two id-shared nodes: the resource blob and the decoded member for it.
    assert_eq!(
        epub.nodes_id_shared, 2,
        "EPUB shares blob + decoded: {epub:?}"
    );

    // The no-sharing control (different bytes) shares no resource, and deduplicated
    // zero resource bytes.
    assert_eq!(control.resource_blob_nodes, 1, "control: {control:?}");
    assert_eq!(
        control.shared_resource_ids, 0,
        "control shares no resource: {control:?}"
    );
    assert_eq!(control.shared_resource_bytes, 0, "control: {control:?}");
    // The control's only difference from the sharing EPUB is the resource bytes;
    // in its own store it shares no node id at all (a true zero-reuse control).
    assert_eq!(
        control.nodes_id_shared, 0,
        "control shares no node id: {control:?}"
    );

    // Same container structure and same DOCX baseline in both stores; the only
    // difference is the resource bytes, so the sharing EPUB writes strictly fewer
    // seed bytes than the control.
    assert!(
        epub.seed_bytes_written < control.seed_bytes_written,
        "shared EPUB seed bytes {} must be < control {}",
        epub.seed_bytes_written,
        control.seed_bytes_written
    );

    // The PDF adapter extracts no embedded resource blob (Phase-11 limitation),
    // so PDF↔DOCX resource sharing does not exist and is a reported zero.
    assert_eq!(
        pdf.resource_blob_nodes, 0,
        "PDF extracts no resource: {pdf:?}"
    );
    assert_eq!(
        pdf.shared_resource_ids, 0,
        "PDF shares no resource: {pdf:?}"
    );

    // Exactness holds for every root, independent of any sharing.
    for (s, id, src) in [
        (&store, docx.field, docx_src.as_slice()),
        (&store, epub.field, epub_src.as_slice()),
        (&store, pdf.field, pdf_src.as_slice()),
        (&control_store, control.field, control_src.as_slice()),
    ] {
        let field = Field::open(s, &id, limits).unwrap();
        assert_eq!(field.materialize_exact(limits).unwrap(), src);
    }

    std::fs::remove_dir_all(&shared_dir).ok();
    std::fs::remove_dir_all(&control_dir).ok();
}

#[test]
fn shared_decoded_state_is_reused_across_documents() {
    let dir = temp_dir("reuse");
    let mut store = FieldStore::open(&dir).unwrap();
    let limits = Limits::DEFAULT;

    let docx_src = build_docx(SHARED_PNG);
    let epub_src = build_epub(SHARED_PNG);

    let docx = match ingest(&mut store, &opaque_descriptor(&docx_src), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };
    let epub = match ingest(&mut store, &opaque_descriptor(&epub_src), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };

    // The DOCX and EPUB decoded-member nodes for the resource are the *same* node:
    // content identity, not per-source coordinates.
    let docx_png_ordinal = png_ordinal(&docx_src);
    let docx_decoded = decoded_node_id(&store, &docx.field, docx_png_ordinal);
    let epub_png_ordinal = png_ordinal(&epub_src);
    let epub_decoded = decoded_node_id(&store, &epub.field, epub_png_ordinal);
    assert_eq!(
        docx_decoded, epub_decoded,
        "the shared resource must decode to one content-addressed node"
    );

    // Materialize the shared node through the *DOCX* field, warming the persisted
    // derived cache for that content id.
    warm_shared_node(&store, &docx.field, &docx_decoded, limits);

    // Observe the EPUB's resource decoded bytes: the cold run re-executes, the warm
    // run is served from the state the DOCX materialization persisted.
    let selector = Selector::EpubResource("OEBPS/images/shared.png".to_string());
    let cold = observe_stats(&mut store, &epub.field, &selector, false, limits);
    assert_eq!(
        cold.seed_nodes_reused, 0,
        "a cold run cannot reuse: {cold:?}"
    );
    assert!(cold.seed_nodes_executed > 0, "cold run executes: {cold:?}");

    let (warm_answer, warm) = observe_answer(&mut store, &epub.field, &selector, true, limits);
    assert_eq!(
        answer_bytes(&warm_answer),
        SHARED_PNG,
        "shared bytes must be exact"
    );
    assert!(
        warm.seed_nodes_reused >= 1,
        "the shared decoded state must be reused across documents: {warm:?}"
    );

    // The retained-inverse-work fraction, from receipted integers only.
    let cold_work = InverseWork::new(cold.seed_nodes_executed, cold.bytes_read);
    let warm_work = InverseWork::new(warm.seed_nodes_executed, warm.bytes_read);
    let fraction = retained_inverse_work_fraction(cold_work, warm_work);
    assert!(
        fraction > 0.0 && fraction <= 1.0,
        "fraction {fraction} must be in (0,1]; cold={cold_work:?} warm={warm_work:?}"
    );
    // Consistency: the fraction is exactly the receipted reuse over cold work.
    let expected = warm_work_reused(cold_work, warm_work) as f64 / cold_work.units() as f64;
    assert!((fraction - expected).abs() < 1e-12);

    // `nodes_id_shared` (representation) is reported and distinct from
    // `nodes_reused` (work): it comes from the manifest, not this observation.
    assert!(
        warm.nodes_id_shared >= 1,
        "ingest recorded content-id sharing: {warm:?}"
    );

    // Exactness for both roots after all sharing and reuse.
    for (id, src) in [
        (docx.field, docx_src.as_slice()),
        (epub.field, epub_src.as_slice()),
    ] {
        let field = Field::open(&store, &id, limits).unwrap();
        assert_eq!(field.materialize_exact(limits).unwrap(), src);
    }

    std::fs::remove_dir_all(&dir).ok();
}

#[test]
fn different_resource_bytes_never_share() {
    let dir = temp_dir("control");
    let mut store = FieldStore::open(&dir).unwrap();
    let limits = Limits::DEFAULT;

    let a = build_epub(SHARED_PNG);
    let b = build_epub(CONTROL_PNG);
    let ra = match ingest(&mut store, &opaque_descriptor(&a), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };
    let rb = match ingest(&mut store, &opaque_descriptor(&b), limits).unwrap() {
        vole_document::field::ingest::IngestOutcome::Package(r) => r,
        other => panic!("expected package, got {other:?}"),
    };

    assert_eq!(ra.shared_resource_ids, 0);
    assert_eq!(rb.shared_resource_ids, 0, "different bytes must not share");
    assert_eq!(rb.shared_resource_bytes, 0);
    // The two decoded-member nodes are distinct content ids.
    assert_ne!(
        decoded_node_id(&store, &ra.field, png_ordinal(&a)),
        decoded_node_id(&store, &rb.field, png_ordinal(&b)),
    );

    std::fs::remove_dir_all(&dir).ok();
}

// ---------------------------------------------------------------------------
// helpers
// ---------------------------------------------------------------------------

fn png_ordinal(source: &[u8]) -> u32 {
    let physical = scan(source, Limits::DEFAULT).unwrap();
    physical
        .members
        .iter()
        .find(|m| m.name.ends_with(b".png"))
        .expect("a .png member")
        .id
        .ordinal
}

fn decoded_node_id(
    store: &FieldStore,
    field: &vole_document::field::FieldId,
    ordinal: u32,
) -> vole_document::store::NodeId {
    let manifest = store.get_field(field).unwrap();
    let istore = FsIndexStore::open(store.root()).unwrap();
    let root = vole_document::store::NodeId::from_bytes(manifest.index_root);
    lookup(
        &istore,
        &root,
        &SelectorKey::new(SEL_PACKAGE_MEMBER_DECODED, ordinal),
    )
    .unwrap()
    .first()
    .expect("decoded member entry")
    .node_id
}

/// Materialize a node through a field's source and the persisted derived cache,
/// so the shared content id is warm for a later observation of another document.
fn warm_shared_node(
    store: &FieldStore,
    field: &vole_document::field::FieldId,
    id: &vole_document::store::NodeId,
    limits: Limits,
) {
    let opened = Field::open(store, field, limits).unwrap();
    let node = load_node(store.seeds(), id).unwrap();
    let mut cache = DerivedCache::open(store.root().join("cache")).unwrap();
    let mut budget = EvalBudget::default();
    let mut reuse = vole_document::field::dag::ReuseStats::default();
    let out = materialize_node_cached(
        opened.parsed(),
        store.seeds(),
        &mut cache,
        &node,
        limits,
        &mut budget,
        node.limits.max_depth,
        &mut reuse,
    )
    .unwrap();
    assert_eq!(out, SHARED_PNG);
}

fn observe_answer(
    store: &mut FieldStore,
    field: &vole_document::field::FieldId,
    selector: &Selector,
    use_cache: bool,
    limits: Limits,
) -> (vole_document::field::provenance::FieldAnswer, ObserveStats) {
    let mut req = ObserveRequest::new(selector.clone(), Representation::DecodedBytes);
    req.use_cache = use_cache;
    let (answer, stats, _) = observe(store, field, &req, limits).unwrap();
    (answer, stats)
}

fn observe_stats(
    store: &mut FieldStore,
    field: &vole_document::field::FieldId,
    selector: &Selector,
    use_cache: bool,
    limits: Limits,
) -> ObserveStats {
    observe_answer(store, field, selector, use_cache, limits).1
}

fn warm_work_reused(cold: InverseWork, warm: InverseWork) -> u64 {
    cold.node_executions
        .saturating_sub(warm.node_executions)
        .saturating_add(cold.input_bytes.saturating_sub(warm.input_bytes))
}