Skip to main content

rudb_vector/
vector.rs

1//! The vector itself.
2//!
3//! `spec/07-execution.md` section 7.1 calls this the widest interface in the system, says every
4//! operator depends on it, and says changing it after twenty operators exist is expensive. So it
5//! is written before the first operator rather than after the fifth.
6//!
7//! A vector is a type, a length of at most [`VECTOR_SIZE`], a physical form, a validity
8//! representation and some data. Four of the forms are the ones in `spec/04-architecture.md`
9//! section 4.3: flat, constant, sequence and dictionary. Run length, bit packed and string view come
10//! after them, one at a time with the kernels that read them rather than all at once ahead of
11//! anything that can use them.
12//!
13//! Dictionary and run length are the pair worth understanding together, because they answer
14//! different questions about the same column. A dictionary says which distinct values there are, so
15//! it wins on low cardinality however the rows are ordered. Run length says where the values stop,
16//! so it wins on a clustered column however many distinct values it has. A column can want either
17//! one without wanting the other, and `hits` has columns of both kinds.
18//!
19//! String view is the odd one out, because it is not about making a column smaller. It is about who
20//! owns the bytes: the views are the vector's and the arena is shared, so cutting a chunk out of a
21//! page of strings moves sixteen bytes a row and copies none of the payload. Every other form here
22//! trades a little work per row for less memory, and that one trades nothing at all.
23//!
24//! The nested forms are the odd ones out in a different direction. The forms above are all ways of
25//! writing a column of scalars down more cheaply, and a nested value is not a scalar at all, so
26//! [`Form::List`] and [`Form::Struct`] are each the only form their column has rather than one of
27//! several it could be in. A list is a child vector of every element plus a start and a length per
28//! row. A struct is one child per field with no entries at all, because a struct row holds one value
29//! per field rather than a run of them. Either way the children are ordinary vectors and can be in any
30//! of the forms above, which is where a nested column gets made smaller.
31//!
32//! **What is not here yet.** Buffers are owned. Section 7.1 says a vector borrowed from a buffer
33//! managed page carries a pin, and there is no buffer manager until M2, so there is nothing to pin
34//! and pretending otherwise would be an interface built against an imaginary caller. `ARRAY` is not
35//! stored yet either, and it is a composition of what is here rather than a new shape: it is a list
36//! whose length is the type's rather than the row's, the way a `MAP` is a list whose child is a two
37//! field struct of keys and values. `UNION` is the one that is genuinely different, since it is one
38//! child per member plus a tag saying which member each row is in.
39
40use std::borrow::Cow;
41use std::cmp::Ordering;
42use std::sync::Arc;
43
44use rudb_common::{Cause, Error, Field, LogicalType, Result, Value, slow};
45
46use crate::buffer::Buffer;
47use crate::fsst::SymbolTable;
48use crate::string::{StringColumn, StringView};
49use crate::validity::Validity;
50
51/// How many values are in a full vector.
52///
53/// 8192, which is four times DuckDB's 2048 and eight times what this was. It started at 1024 for
54/// three reasons: the FastLanes unit is 1024, a validity mask comes out at exactly 16 `u64` words,
55/// and a vector of 16 byte string views is 16 KiB, which is small enough that several of them sit
56/// in L1 at once. The first two are still true of any multiple of 1024. The third was the argument
57/// and it was an argument about the wrong level, because it was also deciding how much of a table
58/// one zone map covered and how much work one call into the pipeline did, and those wanted a much
59/// larger number than L1 did.
60///
61/// #984 separated them: a table in memory is stored in row groups of 122,880 rows now and a chunk
62/// is a window into one, so the vector size is only the execution unit and is free to be chosen for
63/// what an operator costs per call. #480 measured it. On twenty million rows in memory, one thread,
64/// going from 1024 to 8192 takes `count(*)` with a filter from 14.0 milliseconds to 1.9, `sum(v)`
65/// with the same filter from 39.6 to 29.6 and `sum(k + v)` from 66.8 to 52.6. On ClickBench over
66/// Parquet, where the time is decode and hash aggregation rather than per call overhead, the same
67/// move is worth about eight percent on the total of the twenty nine queries that run.
68///
69/// 32768 was measured too and is not better: it wins another few percent on the full scans and
70/// loses on the load, on a needle that the chunk zone maps would otherwise prune, and on anything
71/// with a string column, where a vector of views is half a megabyte. 8192 is where the per call
72/// overhead has stopped mattering and the working set has not started to.
73pub const VECTOR_SIZE: usize = 8192;
74
75/// What the key field of a map's child struct is called.
76///
77/// A map is stored as a list of two field structs, and these are the two names. They are DuckDB's, and
78/// they are also the names the Parquet specification gives a map's repeated group, so a reader that
79/// builds one of these from a file finds the names already agreed rather than translated.
80pub const MAP_KEY: &str = "key";
81
82/// What the value field of a map's child struct is called. See [`MAP_KEY`].
83pub const MAP_VALUE: &str = "value";
84
85/// What [`Vector::map_parts`] hands back: one entry per row, then the keys and then the values.
86///
87/// A name rather than the triple written out, because the triple written out is over the complexity
88/// clippy allows and because a kernel that takes these as an argument should be able to say so in one
89/// word.
90pub type MapParts<'a> = (&'a [(u32, u32)], &'a Vector, &'a Vector);
91
92/// Which physical form a vector is in.
93///
94/// An operator asks this once per vector and then takes the path it wants, which is the one branch
95/// per vector that the whole design is willing to spend.
96///
97/// Not exhaustive, and that is a decision rather than an oversight. `Encoded` is the fifth form
98/// and it arrives at layer three with the specialization contract. If this enum were exhaustive,
99/// the day it lands is the day every kernel in the workspace stops compiling, and the pressure at
100/// that moment would be to add an arm to each of them in a hurry rather than to think about what
101/// each one should do with an encoded vector. A required fallback arm means each kernel already
102/// has a correct answer for a form it has never seen, and specializing it is then a change that
103/// can be made one kernel at a time with a benchmark next to it.
104#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
105#[non_exhaustive]
106pub enum Form {
107    /// One value per position.
108    Flat,
109    /// One value, repeated.
110    Constant,
111    /// A start and a step, computed rather than stored.
112    Sequence,
113    /// Codes into a smaller vector of distinct values.
114    Dictionary,
115    /// Integers stored in as many bits as the range of the column needs, offset from a base.
116    ///
117    /// The form a narrow integer column is in. A ClickBench `ResolutionWidth` is a `SMALLINT` whose
118    /// values live between 0 and 2560, which is twelve bits, so the column is three quarters of the
119    /// size it was and the pages behind it are three quarters of the reads. What it costs is a shift
120    /// and a mask per value, which is why this is worth it at storage and at rest and is not a form
121    /// anything should be building in the middle of a pipeline.
122    BitPacked,
123    /// Sixteen byte views over an arena the vector shares rather than owns.
124    ///
125    /// The form a varchar column is in once more than one vector is looking at the same page. A flat
126    /// varchar vector owns its arena, so cutting a chunk out of it copies every byte of every long
127    /// string in the range, and on ClickBench that is most of what reading `URL` costs. Sharing the
128    /// arena makes the cut the views and nothing else, the way a dictionary cut is the codes and
129    /// nothing else.
130    StringView,
131    /// Strings compressed against one symbol table, each row on its own.
132    ///
133    /// The form a text column is in at rest. FSST is about half the bytes on the ClickBench `URL`
134    /// and `Title` columns, and unlike a block compressor it keeps random access, so reading row
135    /// four million does not decompress the four million before it. What it costs is a decompression
136    /// per row read, which is why an equality filter over it is worth writing in code space: the
137    /// literal compresses once and the rows never decompress at all.
138    Fsst,
139    /// One value per run, with the row each run ends at.
140    ///
141    /// The form a clustered column is in. `hits` is written in time order, so `EventDate` is a few
142    /// hundred runs over a hundred million rows, and a sum over it is a few hundred multiplications
143    /// rather than a hundred million additions. Dictionary says which distinct values there are and
144    /// this says where they stop, and a column can want either one without wanting the other.
145    Rle,
146    /// A child vector of every element, and a start and a length per row.
147    ///
148    /// The form a `LIST` column is in, and the only form it has. The others are all ways of writing
149    /// down a column of scalars more cheaply and this is the shape a nested value has at all, so a
150    /// list vector reports this whether or not anything has tried to make it smaller. Making it
151    /// smaller happens in the child, which is an ordinary vector and can be any of the forms above.
152    ///
153    /// A `MAP` column reports this too, because a map is a list whose child is a two field struct and
154    /// the bytes really are a list's. This enum is about the physical layout, and the logical type is
155    /// what remembers the difference, which is the same division `LogicalType::physical` already makes.
156    List,
157    /// One child vector per field, each as long as the vector itself.
158    ///
159    /// The form a `STRUCT` column is in, and the only form it has, for the reason [`Form::List`] is
160    /// the only form a list has. A struct holds exactly one value per field per row rather than a run
161    /// of them, so there are no entries here and the children line up with the rows one to one, which
162    /// makes a cut a cut of every child and a gather a gather of every child. Each child is an
163    /// ordinary vector and can be in any of the forms above, so that is where a struct column gets
164    /// made smaller.
165    Struct,
166}
167
168/// The values of a flat vector, one Rust vector per physical type.
169///
170/// The variants are physical rather than logical, which is what lets `DATE` and `INTEGER` share
171/// storage and share a kernel. What a run of `i32` means is the vector's logical type's business.
172#[derive(Debug, Clone, PartialEq)]
173#[non_exhaustive]
174pub enum Data {
175    /// No values, for the type of an untyped `NULL`.
176    Empty,
177    /// One byte per value.
178    Bool(Buffer<bool>),
179    /// 8 bit signed.
180    Int8(Buffer<i8>),
181    /// 16 bit signed.
182    Int16(Buffer<i16>),
183    /// 32 bit signed.
184    Int32(Buffer<i32>),
185    /// 64 bit signed.
186    Int64(Buffer<i64>),
187    /// 128 bit signed.
188    Int128(Buffer<i128>),
189    /// 8 bit unsigned.
190    UInt8(Buffer<u8>),
191    /// 16 bit unsigned.
192    UInt16(Buffer<u16>),
193    /// 32 bit unsigned.
194    UInt32(Buffer<u32>),
195    /// 64 bit unsigned.
196    UInt64(Buffer<u64>),
197    /// 128 bit unsigned.
198    UInt128(Buffer<u128>),
199    /// IEEE 754 binary32.
200    Float32(Buffer<f32>),
201    /// IEEE 754 binary64.
202    Float64(Buffer<f64>),
203    /// The months, days and microseconds triple.
204    Interval(Buffer<(i32, i32, i64)>),
205    /// Strings, as 16 byte views plus the arena the long ones live in.
206    Varlen(StringColumn),
207}
208
209impl Data {
210    /// How many values are stored.
211    ///
212    /// The match below has no wildcard arm, and that is what makes this function the check that
213    /// keeps [`for_each_layout`](crate::for_each_layout) honest. A variant added to this enum
214    /// without being added to the `all` group fails to compile here, which is a line in a build log
215    /// rather than a layout quietly missing from six kernels.
216    #[must_use]
217    pub fn len(&self) -> usize {
218        macro_rules! lengths {
219            ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
220                match self {
221                    Self::Empty => 0,
222                    $(Self::$variant(values) => values.len(),)+
223                }
224            };
225        }
226        crate::for_each_layout!(all, lengths)
227    }
228
229    /// Whether there are no values.
230    #[must_use]
231    pub fn is_empty(&self) -> bool {
232        self.len() == 0
233    }
234
235    /// How many bytes of memory these values are holding.
236    ///
237    /// One arm per layout through the same macro as [`Data::len`], for the same reason: a layout
238    /// added without a size here is a layout the memory limit would charge nothing for, and a
239    /// buffer that is free is a buffer that can be grown until the process dies.
240    #[must_use]
241    pub fn footprint(&self) -> usize {
242        macro_rules! sizes {
243            ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
244                match self {
245                    Self::Empty => 0,
246                    $(Self::$variant(values) => values.footprint(),)+
247                }
248            };
249        }
250        crate::for_each_layout!(all, sizes)
251    }
252
253    /// These values held as a page, so that copying or cutting them does not copy the values.
254    ///
255    /// For a producer that is going to hand the same values out many times, which is what a stored
256    /// column is. It costs one `Arc` per layout and moves the run into it without touching a value,
257    /// and after it a write through any reader copies out rather than writing the page, which is
258    /// [`Buffer::to_mut`]. A run that is already a page comes back as it was.
259    #[must_use]
260    pub fn into_pages(self) -> Self {
261        macro_rules! paged {
262            ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
263                match self {
264                    Self::Empty => Self::Empty,
265                    $(Self::$variant(values) => Self::$variant(values.into_page()),)+
266                }
267            };
268        }
269        crate::for_each_layout!(all, paged)
270    }
271
272    /// An integer at `index`, widened, for any of the signed integer layouts.
273    ///
274    /// Used by the decimal path, which needs the unscaled value out of whichever width the width
275    /// and scale picked, and by anything else that would otherwise repeat the same five arms.
276    #[must_use]
277    pub fn signed_at(&self, index: usize) -> Option<i128> {
278        macro_rules! widened {
279            ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
280                match self {
281                    $(Self::$variant(v) => v.get(index).map(|&x| i128::from(x)),)+
282                    _ => None,
283                }
284            };
285        }
286        crate::for_each_layout!(signed, widened)
287    }
288
289    /// The first `len` signed integers, widened to `i64`, appended to `out`.
290    ///
291    /// The bulk form of [`Self::signed_at`]. Four of the five signed layouts, because the fifth is
292    /// 128 bits wide and does not fit what this hands back. `Int64` is a copy of the run and the
293    /// three narrower ones are a sign extension the compiler turns into one instruction per lane.
294    ///
295    /// `false`, leaving `out` as it found it, for the wide layout, for a run shorter than `len` and
296    /// for every layout that is not a signed integer.
297    #[must_use]
298    pub fn signed_block(&self, len: usize, out: &mut Vec<i64>) -> bool {
299        match self {
300            Self::Int8(v) => widen(v.as_slice(), len, out),
301            Self::Int16(v) => widen(v.as_slice(), len, out),
302            Self::Int32(v) => widen(v.as_slice(), len, out),
303            Self::Int64(v) => match v.as_slice().get(..len) {
304                Some(run) => {
305                    out.extend_from_slice(run);
306                    true
307                }
308                None => false,
309            },
310            _ => false,
311        }
312    }
313
314    /// An unsigned integer at `index`, widened.
315    #[must_use]
316    pub fn unsigned_at(&self, index: usize) -> Option<u128> {
317        macro_rules! widened {
318            ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
319                match self {
320                    $(Self::$variant(v) => v.get(index).map(|&x| u128::from(x)),)+
321                    _ => None,
322                }
323            };
324        }
325        crate::for_each_layout!(unsigned, widened)
326    }
327
328    /// The string at `index`, for a `Varlen`.
329    #[must_use]
330    pub fn str_at(&self, index: usize) -> Option<&str> {
331        match self {
332            Self::Varlen(column) => column.get(index),
333            _ => None,
334        }
335    }
336
337    /// The bytes at `index`, for a `Varlen`, whatever they are.
338    ///
339    /// What a `BLOB` reads through, since the bytes of one are not required to be text and
340    /// [`Self::str_at`] answers `None` for the ones that are not.
341    #[must_use]
342    pub fn bytes_at(&self, index: usize) -> Option<&[u8]> {
343        match self {
344            Self::Varlen(column) => column.bytes(index),
345            _ => None,
346        }
347    }
348}
349
350/// A type, a length, a validity representation and some data.
351#[derive(Debug, Clone, PartialEq)]
352pub struct Vector {
353    ty: LogicalType,
354    len: usize,
355    validity: Validity,
356    body: Body,
357}
358
359/// What the vector holds, which is what its form is decided by.
360#[derive(Debug, Clone, PartialEq)]
361enum Body {
362    Flat(Data),
363    Constant(Box<Value>),
364    Sequence {
365        start: i64,
366        step: i64,
367    },
368    /// The values are behind an `Arc` rather than a `Box` because slicing shares them.
369    ///
370    /// A dictionary vector is cut once per chunk and the dictionary itself is the same dictionary
371    /// every time, so a `Box` meant a copy of every value in it per cut. On the ClickBench columns
372    /// that are dictionary encoded the dictionary is larger than the chunk of codes pointing into
373    /// it, and copying it was ten percent of the cycles of reading the file.
374    ///
375    /// Nothing here mutates a dictionary in place, so sharing one is only ever a read, and the one
376    /// place that wants an owned copy of the values is [`compose`], which asks for one.
377    Dictionary {
378        codes: Vec<u32>,
379        values: Arc<Vector>,
380        stable: bool,
381    },
382    /// Integer codes of `width` bits each, packed end to end, each one an offset from `base`.
383    ///
384    /// Row `r` is the `width` bits starting at bit `(offset + r) * width`, read little end first, so
385    /// a code that straddles a word boundary has its low bits in the earlier word. `offset` is what
386    /// lets a cut of a packed column be free: the bits are not byte aligned, so a slice either
387    /// repacks or remembers where it starts, and remembering is one addition per read.
388    ///
389    /// The words are behind an `Arc` for the reason the dictionary's values are. A page is packed
390    /// once and cut into chunk sized pieces, and copying the words per cut would undo most of what
391    /// the packing saved.
392    Packed {
393        words: Arc<Vec<u64>>,
394        width: u32,
395        base: i128,
396        offset: usize,
397    },
398    /// The views of a string column, over an arena that other vectors are reading at the same time.
399    ///
400    /// The views are owned because a cut is a different run of views, and the arena is shared
401    /// because a cut is the same bytes. That split is the whole form: sixteen bytes a row move and
402    /// the payload does not, however many cuts a page is taken in.
403    ///
404    /// A row's bytes are found the same way [`StringColumn`] finds them, through
405    /// [`StringView::bytes_in`], so a short string never reads the arena at all and the two ways of
406    /// holding strings cannot answer a row differently.
407    Views {
408        views: Vec<StringView>,
409        arena: Arc<Buffer<u8>>,
410    },
411    /// Text owned by a storage source and fetched by position.
412    ExternalText {
413        source: Arc<dyn TextSource>,
414    },
415    /// The FSST codes of every row, end to end, with one symbol table over all of them.
416    ///
417    /// A span rather than a run of offsets, because a gather keeps this form and a gather puts the
418    /// rows in an order the codes are not in. Eight bytes a row either way, and the span is the one
419    /// that survives being permuted.
420    ///
421    /// The codes and the table are shared for the reason a dictionary's values are: one table is
422    /// trained per page and every chunk cut out of it points at the same one. A table is sixty five
423    /// thousand hash slots, so a table per chunk would cost more than the compression saves.
424    Coded {
425        codes: Arc<Vec<u8>>,
426        spans: Vec<(u32, u32)>,
427        table: Arc<SymbolTable>,
428    },
429    /// One value per run, with the row each run ends at, exclusive and increasing.
430    ///
431    /// Ends rather than lengths, because every reader of this wants to know which run holds a row
432    /// and ends answer that with a binary search while lengths answer it with a running total. The
433    /// two are the same information and only one of them is the one that gets asked for.
434    ///
435    /// The values are behind an `Arc` for the reason the dictionary's are: a page is cut into chunk
436    /// sized pieces and the values are the same values every time.
437    Runs {
438        ends: Vec<u32>,
439        values: Arc<Vector>,
440    },
441    /// One child vector holding every element of every row, and a start and a length per row.
442    ///
443    /// Start and length rather than the run of offsets Arrow carries, because offsets say where a
444    /// row ends by saying where the next one begins, and that is only true while the rows are in
445    /// order and none is skipped. A gather permutes the rows and a filter drops them, both of which
446    /// this form has to survive without copying the child, so each row says where its own elements
447    /// are and nothing is implied about its neighbour.
448    ///
449    /// The child is behind an `Arc` for the reason a dictionary's values are. A cut of a list column
450    /// is the entries and nothing else, so a page of lists taken in chunk sized pieces holds one
451    /// child however many pieces it is read in, and the elements outside the cut stay reachable but
452    /// unreferenced rather than being copied out.
453    ///
454    /// A null list and an empty list are different rows and this is where the difference lives. A
455    /// null is the validity mask at this level being false, the same as for any other type, and its
456    /// entry is `(start, 0)` and never read. An empty list is a valid row whose entry is `(start, 0)`
457    /// as well. So the entry alone does not say which one a row is, the mask does, which is the same
458    /// division of labour every other form here uses.
459    ///
460    /// A `MAP` is stored here too, with a [`Body::Fields`] child of `key` and `value`. Everything above
461    /// is true of it unchanged, which is the point of storing it this way: the cut, the gather and the
462    /// null rule are written once and a map inherits all three.
463    Nested {
464        entries: Vec<(u32, u32)>,
465        child: Arc<Vector>,
466    },
467    /// One child vector per field, in the order the type names them, each as long as this vector.
468    ///
469    /// No entries, which is the whole difference from [`Body::Nested`]. A list row is a run of
470    /// elements so it needs to say where its run is, and a struct row is one value per field so row
471    /// `r` of field `f` is position `r` of child `f` and there is nothing to record. That makes a cut
472    /// a cut of every child and a gather a gather of every child, both at the same positions, rather
473    /// than a rewrite of an index.
474    ///
475    /// The children are behind an `Arc` for the reason a dictionary's values are, and it pays off less
476    /// often here. A cut of a list column shares its child untouched because the entries carry the
477    /// range, and a cut of a struct column has to cut each child, so the sharing only survives the
478    /// cases where nothing moves. It is still worth having, because a struct of a hundred fields
479    /// handed between operators is a hundred pointers rather than a hundred columns.
480    ///
481    /// A null struct is the validity mask at this level being false and says nothing about the
482    /// children, which still hold whatever was put in them at that row. That is DuckDB's behaviour and
483    /// it is the reason this form cannot decide a row is null by looking down: the mask is the answer,
484    /// the same as it is for a list.
485    Fields {
486        children: Vec<Arc<Vector>>,
487    },
488}
489
490/// Random access to immutable text kept by a storage reader.
491pub trait TextSource: std::fmt::Debug + Send + Sync {
492    /// Number of values available.
493    fn len(&self) -> usize;
494    /// Whether this source has no values.
495    fn is_empty(&self) -> bool {
496        self.len() == 0
497    }
498    /// Bytes at one position, or no value when the position is outside the source.
499    fn bytes_at(&self, index: usize) -> Result<Option<&[u8]>>;
500    /// Byte length at one position without requiring the payload when the source has an index.
501    fn bytes_len_at(&self, index: usize) -> Result<Option<usize>> {
502        Ok(self.bytes_at(index)?.map(<[u8]>::len))
503    }
504    /// Hands `body` the values from `first` up to at most `limit`, and answers where it stopped.
505    ///
506    /// The point of it is what it does not do, which is keep what it read.
507    /// [`bytes_at`](Self::bytes_at) hands back a borrow, so a source that decodes a block to answer
508    /// it has to hold that block for as long as the source lives, and a reader that walks the whole
509    /// source therefore ends up holding the whole thing decoded. On the ClickBench `URL` dictionary
510    /// that is 4.2 GB resident to answer one `LIKE`, and none of it is read twice.
511    ///
512    /// A caller that means to walk a stretch of values once calls this instead and gets the bytes
513    /// on loan for the length of the call. The source decides how much it hands over at a time,
514    /// which for a blocked payload is the rest of the block it had to decode anyway, and answers
515    /// with one past the last value it visited so the caller can come back for the next stretch.
516    /// The answer is always above `first` where `first` is a value this source has, so a loop on it
517    /// finishes.
518    ///
519    /// The default hands over one value through `bytes_at` and is correct for every source. It is
520    /// also pointless for a source that keeps everything anyway, which is every source built in
521    /// memory, and that is the right default for exactly that reason.
522    fn sweep(
523        &self,
524        first: usize,
525        limit: usize,
526        body: &mut dyn FnMut(usize, &[u8]) -> Result<()>,
527    ) -> Result<usize> {
528        if first >= limit.min(self.len()) {
529            return Ok(first);
530        }
531        body(first, self.bytes_at(first)?.unwrap_or_default())?;
532        Ok(first + 1)
533    }
534    /// Resident bytes retained by this source.
535    fn footprint(&self) -> usize;
536    /// How many ranks this source's sorted value order has, when it has one.
537    ///
538    /// A rank is a position in the values sorted by their bytes, so rank zero is the smallest value
539    /// and rank `ranks() - 1` is the largest. A storage format that keeps a dictionary for a whole
540    /// column can afford to sort the distinct values once when it writes the file, and what that
541    /// buys is a binary search where a reader that only knows the values are distinct has to ask
542    /// every one of them whether it matches.
543    ///
544    /// `None` means the source does not know its order, which is the honest answer for anything
545    /// built in memory and for a file written before its format stored one. Nothing is allowed to
546    /// depend on this for correctness, only for speed.
547    ///
548    /// A source that answers with `Some` promises the ranks cover every value it has, and that
549    /// [`compare_rank`](Self::compare_rank) is consistent with an ordering in which the values are
550    /// strictly increasing. Strictly, which is to say the values are distinct, because what reads
551    /// this searches it, and a search of a run of equal values finds one of them rather than all of
552    /// them. A source that holds the same value twice must answer `None` here even though it could
553    /// sort itself perfectly well.
554    fn ranks(&self) -> Option<usize> {
555        None
556    }
557    /// How the value at `rank` compares against `wanted`.
558    ///
559    /// This is a method rather than a slice of positions the caller indexes because the answer is
560    /// the only thing a search wants, and a source that knows that can answer most probes without
561    /// reading a value at all. A file that stores the first few bytes of each value in rank order
562    /// settles every probe from those bytes except the ones where two values start the same way,
563    /// and the payload stays untouched. A caller handed positions instead would have to read a
564    /// value per probe, which for a dictionary of half a million entries spread over thirty
565    /// megabytes is a fresh block of the file every time.
566    ///
567    /// Only called for a rank below [`ranks`](Self::ranks), so the default is the error a source
568    /// that has no order should never be asked to produce.
569    fn compare_rank(&self, rank: usize, wanted: &[u8]) -> Result<Ordering> {
570        let _ = (rank, wanted);
571        Err(Error::internal("a text source without a sorted order was asked to compare a rank"))
572    }
573    /// How many values sort before `wanted`, and whether one of them is `wanted`.
574    ///
575    /// The whole search rather than a probe of it, so that a source which can answer the same
576    /// question twice without repeating the work is allowed to. The default runs the search through
577    /// [`compare_rank`](Self::compare_rank) and remembers nothing, which is right for a source whose
578    /// probes are cheap.
579    ///
580    /// The reason it is on the trait at all is the top N. `ORDER BY <varchar> LIMIT 10` asks once a
581    /// chunk whether anything left can beat the worst candidate, and the worst candidate stops
582    /// changing long before the chunks run out, so nearly every one of those searches is the one
583    /// before it asked again. A probe of a file backed dictionary is not cheap: it settles on the
584    /// stored head where it can and reads a value where it cannot, and reading a value means
585    /// decoding the payload block it sits in. On ClickBench 25 that search was 29 percent of the
586    /// query's instructions and the block decoding under it another 40.
587    ///
588    /// Only called when [`ranks`](Self::ranks) is `Some`, and `ranks` is what it answered.
589    fn below(&self, ranks: usize, wanted: &[u8]) -> Result<(usize, bool)> {
590        search_below(self, ranks, wanted)
591    }
592    /// The position of the value at `rank`, which is what a search returns once it has found one.
593    ///
594    /// Called about once per search rather than once per probe, so unlike
595    /// [`compare_rank`](Self::compare_rank) it is free to be the expensive one.
596    fn code_at_rank(&self, rank: usize) -> Result<u32> {
597        let _ = rank;
598        Err(Error::internal("a text source without a sorted order was asked for a rank"))
599    }
600    /// The rank of every value, in position order, when the source can hand the whole map over.
601    ///
602    /// This is [`code_at_rank`](Self::code_at_rank) turned round, and it is a separate method
603    /// because the two are wanted by opposite kinds of reader. A search wants one code out of a
604    /// rank and probes a handful of times, so it reads the order a block at a time and leaves the
605    /// rest alone. A min or a max over a grouped column wants a rank out of a code once per row,
606    /// and a walk of the order per row costs far more than reading the order once and turning it
607    /// round. What that buys is a comparison of two integers where the alternative is a fetch of
608    /// two strings out of a payload the size of the column.
609    ///
610    /// The slice is indexed by position and is as long as [`len`](Self::len), so a caller holding a
611    /// dictionary code indexes it directly.
612    ///
613    /// `None` from a source with no order, and from one with an order it would rather not invert.
614    /// Nothing depends on this for correctness, only for speed.
615    fn code_ranks(&self) -> Option<&[u32]> {
616        None
617    }
618    /// Whether another source presents the same values.
619    fn equal(&self, other: &dyn TextSource) -> bool {
620        self.len() == other.len()
621            && (0..self.len()).all(|index| {
622                matches!(
623                    (self.bytes_at(index), other.bytes_at(index)),
624                    (Ok(left), Ok(right)) if left == right
625                )
626            })
627    }
628}
629
630impl PartialEq for dyn TextSource {
631    fn eq(&self, other: &Self) -> bool {
632        self.equal(other)
633    }
634}
635
636/// The binary search behind [`TextSource::below`], written once so an override can still use it.
637///
638/// A source that remembers its answers overrides `below` to look in what it remembers first, and
639/// then it still has to do the search when it does not find one. This is that search. It carries on
640/// past an equal probe to the first rank holding the value, so what it returns is a boundary rather
641/// than wherever the halving happened to touch down, and the values are distinct so there is exactly
642/// one such rank.
643///
644/// # Errors
645///
646/// Whatever [`TextSource::compare_rank`] gives for a probe.
647pub fn search_below<S>(source: &S, ranks: usize, wanted: &[u8]) -> Result<(usize, bool)>
648where
649    S: TextSource + ?Sized,
650{
651    let mut low = 0;
652    let mut high = ranks;
653    let mut equal = false;
654    while low < high {
655        let middle = low + (high - low) / 2;
656        match source.compare_rank(middle, wanted)? {
657            Ordering::Less => low = middle + 1,
658            Ordering::Greater => high = middle,
659            Ordering::Equal => {
660                equal = true;
661                high = middle;
662            }
663        }
664    }
665    Ok((low, equal))
666}
667
668impl Vector {
669    /// A flat vector of `data`, all valid.
670    ///
671    /// # Errors
672    ///
673    /// If the data's physical layout is not the one the type calls for. That check is here rather
674    /// than left to the caller because a vector whose type and layout disagree is a wrong answer
675    /// waiting to be read out, and it costs one comparison at construction to prevent.
676    pub fn flat(ty: LogicalType, data: Data) -> Result<Self> {
677        let len = data.len();
678        if !matches!(data, Data::Empty) && layout_of(&data) != ty.physical() {
679            return Err(Error::internal(format!(
680                "a {ty} vector cannot hold {:?} data",
681                layout_of(&data)
682            )));
683        }
684        Ok(Self { ty, len, validity: Validity::AllValid, body: Body::Flat(data) })
685    }
686
687    /// A flat vector built from single values, with the nulls among them turning into validity.
688    ///
689    /// The slow way in, and the only way in that anything outside this crate has. It is what an
690    /// `INSERT`, a `VALUES` clause and a test build a column with, all of which arrive holding
691    /// values rather than a run of `i32`. Nothing on a scan path calls it: a scan produces a run of
692    /// data directly and hands it to [`Self::flat`].
693    ///
694    /// # Errors
695    ///
696    /// If a value is not one the type can hold, or if the type is one there is no vector for yet,
697    /// which today means `ARRAY` and `UNION`. A `LIST`, a `STRUCT` and a `MAP` are routed to their own
698    /// builders and come back built.
699    pub fn from_values(ty: LogicalType, values: &[Value]) -> Result<Self> {
700        match &ty {
701            LogicalType::List(element) => {
702                return Self::list_from_values(element.as_ref().clone(), values);
703            }
704            LogicalType::Struct(fields) => return Self::struct_from_values(fields, values),
705            LogicalType::Map(key, value) => {
706                return Self::map_from_values(key.as_ref().clone(), value.as_ref().clone(), values);
707            }
708            _ => {}
709        }
710        let mut data = empty_data_for(&ty)?;
711        for value in values {
712            push_value(&mut data, value)?;
713        }
714        let validity = Validity::from_iter(values.len(), |index| !values[index].is_null());
715        Ok(Self { ty, len: values.len(), validity, body: Body::Flat(data) })
716    }
717
718    /// A list vector of `element`, built from one [`Value::List`] per row.
719    ///
720    /// The elements of every row go into one child vector end to end, so a row's elements are a
721    /// contiguous range of it and a row is a start and a length into it. That is what makes a cut of
722    /// this form the entries and nothing else.
723    ///
724    /// A null row contributes no elements and gets an entry of length zero, which is the same entry
725    /// an empty list gets. The two are told apart by the validity mask rather than by the entry, for
726    /// the reason written on [`Body::Nested`].
727    fn list_from_values(element: LogicalType, values: &[Value]) -> Result<Self> {
728        let mut flat = Vec::new();
729        let mut entries = Vec::with_capacity(values.len());
730        for value in values {
731            let start = u32::try_from(flat.len())
732                .map_err(|_| Error::internal("a list column with more than u32 elements in it"))?;
733            match value {
734                Value::Null => entries.push((start, 0)),
735                Value::List { values: held, .. } => {
736                    let len = u32::try_from(held.len())
737                        .map_err(|_| Error::internal("a list longer than u32"))?;
738                    flat.extend_from_slice(held);
739                    entries.push((start, len));
740                }
741                other => {
742                    return Err(Error::internal(format!(
743                        "{other:?} does not belong in a list vector"
744                    )));
745                }
746            }
747        }
748        // The element type is the column's rather than any one value's. A `Value::List` carries what
749        // it thinks it is empty of, and a column built from a row of `INTEGER[]` and a row of
750        // `[]::NULL[]` would otherwise take its type from whichever row came first.
751        let child = Self::from_values(element, &flat)?;
752        let validity = Validity::from_iter(values.len(), |index| !values[index].is_null());
753        Ok(Self {
754            ty: LogicalType::list(child.ty.clone()),
755            len: values.len(),
756            validity,
757            body: Body::Nested { entries, child: Arc::new(child) },
758        })
759    }
760
761    /// A list vector over a child that already exists, one entry per row.
762    ///
763    /// What a scan and a list returning kernel build, both of which produce the elements in bulk and
764    /// then say which row each range belongs to. Every row is valid, since a caller with nulls to
765    /// record adds them with [`Self::with_validity`].
766    ///
767    /// # Errors
768    ///
769    /// If an entry runs past the end of the child, which would be a row that reads elements belonging
770    /// to nobody and is the one mistake this form makes easy.
771    pub fn list(entries: Vec<(u32, u32)>, child: Vector) -> Result<Self> {
772        let reach = child.len();
773        for &(start, len) in &entries {
774            if start as usize + len as usize > reach {
775                return Err(Error::internal(format!(
776                    "a list entry of {len} at {start} in a child of {reach}"
777                )));
778            }
779        }
780        Ok(Self {
781            ty: LogicalType::list(child.ty.clone()),
782            len: entries.len(),
783            validity: Validity::AllValid,
784            body: Body::Nested { entries, child: Arc::new(child) },
785        })
786    }
787
788    /// A struct vector of `fields`, built from one [`Value::Struct`] per row.
789    ///
790    /// One pass per field rather than one pass per row, because each field becomes its own child
791    /// vector and a child is built from a run of values of one type. So a struct of three fields over
792    /// a thousand rows is three calls to [`Self::from_values`] and not a thousand.
793    ///
794    /// The fields are matched by name and not by position. A `Value::Struct` carries its names, and a
795    /// caller that built one in a different order from the type's would otherwise get the values
796    /// silently transposed into the wrong columns, which is the kind of wrong answer that reads as
797    /// right. A row missing a field the type names is an error rather than a null for the same reason.
798    ///
799    /// A null row is a null in every child as well as a false bit in the mask here. [`Body::Fields`]
800    /// says a null struct is allowed to have readable children and that is about a struct built out of
801    /// children that already exist, where whatever is underneath is the caller's. Built from values
802    /// there is nothing underneath to keep, so the children get the null.
803    fn struct_from_values(fields: &[Field], values: &[Value]) -> Result<Self> {
804        let mut children = Vec::with_capacity(fields.len());
805        for field in fields {
806            let mut column = Vec::with_capacity(values.len());
807            for value in values {
808                column.push(match value {
809                    Value::Null => Value::Null,
810                    Value::Struct(held) => held
811                        .iter()
812                        .find(|(name, _)| *name == field.name)
813                        .map(|(_, held)| held.clone())
814                        .ok_or_else(|| {
815                            Error::internal(format!(
816                                "a struct row with no {} field in it",
817                                field.name
818                            ))
819                        })?,
820                    other => {
821                        return Err(Error::internal(format!(
822                            "{other:?} does not belong in a struct vector"
823                        )));
824                    }
825                });
826            }
827            children.push(Arc::new(Self::from_values(field.ty.clone(), &column)?));
828        }
829        let validity = Validity::from_iter(values.len(), |index| !values[index].is_null());
830        Ok(Self {
831            ty: LogicalType::Struct(fields.to_vec()),
832            len: values.len(),
833            validity,
834            body: Body::Fields { children },
835        })
836    }
837
838    /// A struct vector over children that already exist, one per field.
839    ///
840    /// What a scan and a struct returning kernel build, both of which produce each field as a column
841    /// and then put them side by side. Every row is valid, since a caller with nulls to record adds
842    /// them with [`Self::with_validity`].
843    ///
844    /// # Errors
845    ///
846    /// If there are no fields, or if the children are not all the same length. The first is not a
847    /// fussy restriction: a struct vector with no children has no child to take its length from, so a
848    /// zero field struct column would be a length with nothing to check it against, and a caller that
849    /// wants a column of empty structs wants a constant vector of one.
850    pub fn structure(children: Vec<(String, Vector)>) -> Result<Self> {
851        let Some((_, first)) = children.first() else {
852            return Err(Error::internal("a struct vector of no fields, which has no length"));
853        };
854        let len = first.len();
855        for (name, child) in &children {
856            if child.len() != len {
857                return Err(Error::internal(format!(
858                    "a {} field of {} rows beside a struct of {len}",
859                    name,
860                    child.len()
861                )));
862            }
863        }
864        let fields = children
865            .iter()
866            .map(|(name, child)| Field::new(name.clone(), child.ty.clone()))
867            .collect();
868        let children = children.into_iter().map(|(_, child)| Arc::new(child)).collect();
869        Ok(Self {
870            ty: LogicalType::Struct(fields),
871            len,
872            validity: Validity::AllValid,
873            body: Body::Fields { children },
874        })
875    }
876
877    /// The children, for a struct vector, and `None` for any other form.
878    ///
879    /// The accessor a kernel over a struct column reads, and the reason field extraction is free:
880    /// picking one field out of a struct is picking one of these, so a projection of `s.a` hands back
881    /// a vector that already exists rather than reading a row at a time and rebuilding a column.
882    #[must_use]
883    pub fn struct_parts(&self) -> Option<&[Arc<Self>]> {
884        match &self.body {
885            Body::Fields { children } => Some(children),
886            _ => None,
887        }
888    }
889
890    /// A map vector, built from one [`Value::Map`] per row.
891    ///
892    /// A map is a list whose child is a two field struct of keys and values, which is what DuckDB
893    /// stores and what Arrow and Parquet store, so this is the list builder and the struct builder
894    /// composed rather than a third layout. The keys of every row go into one column end to end, the
895    /// values into another beside it, and a row is a start and a length into the pair.
896    ///
897    /// The field names are [`MAP_KEY`] and [`MAP_VALUE`] because those are the names DuckDB gives them
898    /// and the names anything reading a Parquet map field will expect to find.
899    ///
900    /// A null row and an empty map are both an entry of length zero, told apart by the validity mask,
901    /// for the reason written on [`Body::Nested`].
902    fn map_from_values(key: LogicalType, value: LogicalType, values: &[Value]) -> Result<Self> {
903        let mut keys = Vec::new();
904        let mut held = Vec::new();
905        let mut entries = Vec::with_capacity(values.len());
906        for row in values {
907            let start = u32::try_from(keys.len())
908                .map_err(|_| Error::internal("a map column with more than u32 entries in it"))?;
909            match row {
910                Value::Null => entries.push((start, 0)),
911                Value::Map { entries: pairs, .. } => {
912                    let len = u32::try_from(pairs.len())
913                        .map_err(|_| Error::internal("a map with more than u32 entries"))?;
914                    for (one, other) in pairs {
915                        keys.push(one.clone());
916                        held.push(other.clone());
917                    }
918                    entries.push((start, len));
919                }
920                other => {
921                    return Err(Error::internal(format!(
922                        "{other:?} does not belong in a map vector"
923                    )));
924                }
925            }
926        }
927        // The two types are the column's rather than any one row's, for the reason the list builder
928        // takes the element type from the column: a row that is the empty map carries whatever it was
929        // built as being empty of, and the column is not entitled to take its type from that.
930        let child = Self::structure(vec![
931            (MAP_KEY.to_string(), Self::from_values(key, &keys)?),
932            (MAP_VALUE.to_string(), Self::from_values(value, &held)?),
933        ])?;
934        let ty = LogicalType::map(
935            fields_of(&child.ty)[0].ty.clone(),
936            fields_of(&child.ty)[1].ty.clone(),
937        );
938        let validity = Validity::from_iter(values.len(), |index| !values[index].is_null());
939        Ok(Self {
940            ty,
941            len: values.len(),
942            validity,
943            body: Body::Nested { entries, child: Arc::new(child) },
944        })
945    }
946
947    /// A map vector over a pair of columns that already exist, one entry per row.
948    ///
949    /// What a scan and a map returning kernel build. The keys and the values are two columns of the
950    /// same length, and each row of the map is the same range of both. Every row is valid, since a
951    /// caller with nulls to record adds them with [`Self::with_validity`].
952    ///
953    /// # Errors
954    ///
955    /// If the two columns are different lengths, or if an entry runs past the end of them.
956    pub fn map(entries: Vec<(u32, u32)>, keys: Vector, values: Vector) -> Result<Self> {
957        let key = keys.ty.clone();
958        let value = values.ty.clone();
959        let child =
960            Self::structure(vec![(MAP_KEY.to_string(), keys), (MAP_VALUE.to_string(), values)])?;
961        let mut vector = Self::list(entries, child)?;
962        vector.ty = LogicalType::map(key, value);
963        Ok(vector)
964    }
965
966    /// The entries and the two columns, for a map vector, and `None` for anything else.
967    ///
968    /// Reaches through the struct child that a map is stored as, so that a kernel over a map column
969    /// reads the keys and the values as the two columns they are rather than having to know that the
970    /// pair is spelled as a struct underneath.
971    #[must_use]
972    pub fn map_parts(&self) -> Option<MapParts<'_>> {
973        if !matches!(self.ty, LogicalType::Map(_, _)) {
974            return None;
975        }
976        let (entries, child) = self.list_parts()?;
977        let [keys, values] = child.struct_parts()? else { return None };
978        Some((entries, keys, values))
979    }
980
981    /// The entries and the child, for a list vector, and `None` for any other form.
982    ///
983    /// The accessor a kernel over a list column reads, for the reason
984    /// [`Self::dictionary_parts`] exists: `unnest` over 1024 rows wants the child once and the
985    /// entries once, and reading it through [`Self::value_at`] would build a `Value::List` per row
986    /// and then throw every one of them away.
987    ///
988    /// A map answers here as well, with the struct child it is stored as, because this is a question
989    /// about the layout and a map's layout is a list's. A caller that wants the keys and the values as
990    /// two columns wants [`Self::map_parts`], which reaches through that child.
991    #[must_use]
992    pub fn list_parts(&self) -> Option<(&[(u32, u32)], &Self)> {
993        match &self.body {
994            Body::Nested { entries, child } => Some((entries, child)),
995            _ => None,
996        }
997    }
998
999    /// A vector of `len` copies of one value.
1000    ///
1001    /// Costs one value regardless of the length, which is what makes a literal in a predicate free
1002    /// and what makes a projection of a constant free.
1003    #[must_use]
1004    pub fn constant(ty: LogicalType, value: Value, len: usize) -> Self {
1005        let validity = if value.is_null() { Validity::AllInvalid } else { Validity::AllValid };
1006        Self { ty, len, validity, body: Body::Constant(Box::new(value)) }
1007    }
1008
1009    /// A vector of `len` values starting at `start` and stepping by `step`.
1010    ///
1011    /// This is what a row identifier column is, and it costs sixteen bytes rather than eight
1012    /// kilobytes. A scan that produces row ids for a later fetch produces one of these.
1013    #[must_use]
1014    pub fn sequence(start: i64, step: i64, len: usize) -> Self {
1015        Self {
1016            ty: LogicalType::BigInt,
1017            len,
1018            validity: Validity::AllValid,
1019            body: Body::Sequence { start, step },
1020        }
1021    }
1022
1023    /// A vector of codes into a smaller vector of distinct values.
1024    ///
1025    /// The form the whole M3 thesis rests on. A dictionary vector handed to a group by is an
1026    /// integer column, and an aggregate over one is an aggregate over integers no matter what the
1027    /// logical type says.
1028    ///
1029    /// A dictionary over a dictionary is composed into one level here rather than left as two, so
1030    /// the form has a depth of one always and a kernel that reads [`Self::dictionary_parts`] is
1031    /// reading the values rather than another layer of codes. Two filters over the same chunk build
1032    /// the second case and four conjuncts pushed down separately build four of it.
1033    ///
1034    /// The cost of leaving them stacked turned out to be a cliff rather than a slope. Every loop in
1035    /// `rudb-kernels` reaches for the values behind the codes with [`Self::data`], a dictionary
1036    /// pointing at a dictionary has no data to hand back, so the second level does not make the
1037    /// kernels slower, it turns them off and drops the work onto the row at a time path that exists
1038    /// to be correct rather than fast. Measured on server3 over a chunk of two numeric columns and a
1039    /// consumer of two vectorized passes, one level reads at 3.5 nanoseconds a row and two levels at
1040    /// 104, and the third and fourth levels cost almost nothing more because the first one had
1041    /// already given up everything there was to give. Composing is one pass over the outer codes,
1042    /// which the range check above is already making.
1043    ///
1044    /// The one dictionary that is not composed past is one carrying a validity of its own. A
1045    /// dictionary is built all valid and only [`Self::with_validity`] can change that, so such a
1046    /// vector is saying that its nulls are at this level rather than in the values it points at, and
1047    /// composing past it would drop them.
1048    ///
1049    /// # Errors
1050    ///
1051    /// If any code is past the end of the value vector.
1052    pub fn dictionary(codes: Vec<u32>, values: Vector) -> Result<Self> {
1053        Self::dictionary_over(codes, Arc::new(values))
1054    }
1055
1056    /// The same, over a set of values somebody else is holding too.
1057    ///
1058    /// The body holds its values in an `Arc` either way, so a caller that already has one has
1059    /// nothing to hand over but a pointer. The caller this is for is a Parquet chunk: one dictionary
1060    /// page serves every data page of the chunk, and going through [`Self::dictionary`] meant
1061    /// copying the whole dictionary into each page's vector on the way to putting it in an `Arc`
1062    /// that then had a single holder. On a ClickBench scan that copy was sixteen percent of the
1063    /// instructions the query ran.
1064    ///
1065    /// Composing a dictionary over a dictionary keeps the handle too. The leaf of the stack is what
1066    /// the composed dictionary points at and neither its values nor anything about it changes, so
1067    /// there is nothing to own and the new dictionary shares the same leaf the old one did.
1068    ///
1069    /// The range check takes the highest code rather than stopping at the first bad one. Stopping
1070    /// early sounds cheaper and is not, because a loop that can exit anywhere cannot be vectorized
1071    /// and a running maximum can, and the only run that would have exited early is the one about to
1072    /// fail the query anyway. Every other run reads the whole of `codes` either way. It was 5.2
1073    /// percent of a ClickBench scan as a `find`.
1074    ///
1075    /// # Errors
1076    ///
1077    /// If any code is past the end of the value vector.
1078    pub fn dictionary_over(codes: Vec<u32>, values: Arc<Vector>) -> Result<Self> {
1079        let highest = codes.iter().copied().fold(0, u32::max);
1080        if !codes.is_empty() && highest as usize >= values.len() {
1081            return Err(Error::internal(format!(
1082                "dictionary code {highest} is past the end of a {} value dictionary",
1083                values.len()
1084            )));
1085        }
1086        let (codes, values) = compose(codes, values);
1087        Ok(Self {
1088            ty: values.ty.clone(),
1089            len: codes.len(),
1090            validity: Validity::AllValid,
1091            body: Body::Dictionary { codes, values, stable: false },
1092        })
1093    }
1094
1095    /// A dictionary whose codes keep the same meaning across every page of its source.
1096    pub fn stable_dictionary(codes: Vec<u32>, values: Arc<Vector>) -> Result<Self> {
1097        let mut vector = Self::dictionary_over(codes, values)?;
1098        if let Body::Dictionary { stable, .. } = &mut vector.body {
1099            *stable = true;
1100        }
1101        Ok(vector)
1102    }
1103
1104    /// A stable dictionary whose caller already found the largest code while decoding it.
1105    pub fn stable_dictionary_validated(
1106        codes: Vec<u32>,
1107        values: Arc<Vector>,
1108        highest: Option<u32>,
1109    ) -> Result<Self> {
1110        if highest.is_some_and(|code| code as usize >= values.len()) {
1111            return Err(Error::internal("a stable dictionary code is past its value dictionary"));
1112        }
1113        Ok(Self {
1114            ty: values.ty.clone(),
1115            len: codes.len(),
1116            validity: Validity::AllValid,
1117            body: Body::Dictionary { codes, values, stable: true },
1118        })
1119    }
1120
1121    /// A vector of runs, one value each, with the row each run ends at.
1122    ///
1123    /// `ends` is exclusive and strictly increasing, so run `i` covers the rows from `ends[i - 1]` to
1124    /// `ends[i]` and run zero starts at nothing. The length of the vector is the last end.
1125    ///
1126    /// The depth is one, the same way a dictionary's is, and for a sharper reason. Every kernel that
1127    /// wants runs wants the value of a run without another search, and a run length vector over a
1128    /// run length vector turns one search into two and then into three. Rather than compose, this
1129    /// refuses: nothing in the engine builds a stacked one, because [`Self::run_encoded`] only ever
1130    /// reads a flat body, so a stacked one is a caller doing something by hand and the useful answer
1131    /// is to say so rather than to quietly do a pass of work they did not ask for.
1132    ///
1133    /// A run over a dictionary is fine and is not that case. The two forms answer different
1134    /// questions and a column that is both clustered and low cardinality genuinely wants both.
1135    ///
1136    /// # Errors
1137    ///
1138    /// If there is not exactly one value per run, if the ends do not increase, or if the values are
1139    /// themselves run length encoded.
1140    pub fn runs(ends: Vec<u32>, values: Vector) -> Result<Self> {
1141        if matches!(values.body, Body::Runs { .. }) {
1142            return Err(Error::internal("runs of runs, which is two searches to read one row"));
1143        }
1144        if ends.len() != values.len() {
1145            return Err(Error::internal(format!(
1146                "{} runs and {} values to put in them",
1147                ends.len(),
1148                values.len()
1149            )));
1150        }
1151        if ends.windows(2).any(|pair| pair[0] >= pair[1]) || ends.first() == Some(&0) {
1152            return Err(Error::internal("run ends that do not increase"));
1153        }
1154        let len = ends.last().copied().unwrap_or(0) as usize;
1155        Ok(Self {
1156            ty: values.ty.clone(),
1157            len,
1158            validity: Validity::AllValid,
1159            body: Body::Runs { ends, values: Arc::new(values) },
1160        })
1161    }
1162
1163    /// The same values as runs, when there are few enough runs for that to be smaller.
1164    ///
1165    /// Costs one pass over the column to find out, which is why this is a call somebody makes rather
1166    /// than something a constructor does. The decision is the same arithmetic every time: a row in
1167    /// flat form costs one value, a run costs one value plus the four bytes of its end, so runs are
1168    /// smaller once there are fewer than about half as many runs as rows, and the narrower the
1169    /// column the more runs it takes. `RUNS_PAY_AT` is that ratio, written down rather than spelt
1170    /// into an `if`, because it is the number a sweep will want to move.
1171    ///
1172    /// Only a flat body is looked at. A constant and a sequence are already one value and two
1173    /// numbers, so there is nothing to win, and a dictionary that is also clustered is a real case
1174    /// that wants its codes run length encoded rather than its values, which is a different function
1175    /// and not this one.
1176    ///
1177    /// Two adjacent nulls are one run. Two adjacent equal values with a null between them are three,
1178    /// because the null is a value of the column as far as anything reading it is concerned.
1179    ///
1180    /// # Errors
1181    ///
1182    /// From the gather this does at the end, and nowhere else. A body that is not flat comes back
1183    /// unchanged rather than as an error, so a nested vector never reaches the part that can fail.
1184    pub fn run_encoded(&self) -> Result<Self> {
1185        let Body::Flat(data) = &self.body else {
1186            return Ok(self.clone());
1187        };
1188        let ends = boundaries(data, &self.validity, self.len);
1189        if ends.len().saturating_mul(RUNS_PAY_AT) >= self.len {
1190            return Ok(self.clone());
1191        }
1192        let starts: Vec<u32> =
1193            std::iter::once(0).chain(ends.iter().copied()).take(ends.len()).collect();
1194        Self::runs(ends, self.gather(&starts)?)
1195    }
1196
1197    /// A vector of `len` integers packed `width` bits each, every one an offset from `base`.
1198    ///
1199    /// The way in for a reader that already has the packed bits, which is what a column file holds
1200    /// and what a network frame carries. Nothing unpacks on the way in, so a scan of a packed column
1201    /// hands the bits straight to the chunk and the cost of the form is paid by whoever reads a
1202    /// value rather than by the scan.
1203    ///
1204    /// The range check is on the two ends rather than on every code, which is the whole check. A
1205    /// code is between zero and `2^width - 1` by construction, so if `base` and `base + 2^width - 1`
1206    /// both fit the column's layout then every value does, and that is two comparisons instead of
1207    /// one per row.
1208    ///
1209    /// # Errors
1210    ///
1211    /// If the type is not one of the integer layouts, if the width is not between one and
1212    /// [`PACKED_WIDTH_MAX`], if there are not enough words for the length, or if either end of the
1213    /// range would not fit the type.
1214    pub fn packed(
1215        ty: LogicalType,
1216        words: Vec<u64>,
1217        width: u32,
1218        base: i128,
1219        len: usize,
1220    ) -> Result<Self> {
1221        let Some((low, high)) = layout_range(&ty) else {
1222            return Err(Error::internal(format!("a {ty} vector has no integer layout to pack")));
1223        };
1224        if width == 0 || width > PACKED_WIDTH_MAX {
1225            return Err(Error::internal(format!(
1226                "a packed width of {width}, which is outside 1 to {PACKED_WIDTH_MAX}"
1227            )));
1228        }
1229        let needed = words_for(len, width);
1230        if words.len() < needed {
1231            return Err(Error::internal(format!(
1232                "{} words for {len} values of {width} bits, which needs {needed}",
1233                words.len()
1234            )));
1235        }
1236        let top = base + i128::from(u64::MAX >> (64 - width));
1237        if base < low || top > high {
1238            return Err(Error::internal(format!(
1239                "packed values from {base} to {top}, which a {ty} cannot hold"
1240            )));
1241        }
1242        Ok(Self {
1243            ty,
1244            len,
1245            validity: Validity::AllValid,
1246            body: Body::Packed { words: Arc::new(words), width, base, offset: 0 },
1247        })
1248    }
1249
1250    /// The same values bit packed, when the range of the column makes that smaller.
1251    ///
1252    /// Costs one pass to find the range and one to write the bits, which is why this is a call
1253    /// somebody makes rather than something a constructor does. It is the counterpart of
1254    /// [`Self::run_encoded`] and the decision has the same shape: a row flat costs the width of its
1255    /// layout, a row packed costs the bits the column's range needs, and the form is worth having
1256    /// only when the second is a good deal smaller than the first. [`PACKING_PAYS_AT`] is that
1257    /// ratio, written down rather than spelt into an `if`, because it is the number a sweep will
1258    /// want to move.
1259    ///
1260    /// Only a flat integer body is looked at. A constant and a sequence are already smaller than any
1261    /// packing of them, a dictionary's codes are the thing that would want packing rather than its
1262    /// values, and a float has no range to pack into since the bits of an `f64` are not an integer
1263    /// that arithmetic on the column agrees with.
1264    ///
1265    /// The range is taken over every slot including the null ones, which hold a zero. A column of
1266    /// large values with one null in it therefore packs a range that reaches down to zero and comes
1267    /// out wider than it needed to be. The alternative is a pass that consults the validity per slot
1268    /// to find the range and a second rule for what to write into a null slot, and this form exists
1269    /// to make reads cheap rather than to squeeze the last bit out of a sparse column.
1270    ///
1271    /// A column whose values are all the same packs to nothing at all, and rather than invent a zero
1272    /// bit code this declines and leaves it to [`Self::run_encoded`], which turns that column into
1273    /// one run and is smaller than any packing of it.
1274    ///
1275    /// # Errors
1276    ///
1277    /// If the packed bits and the length disagree, which would be a bug here rather than a caller
1278    /// doing something wrong.
1279    pub fn bit_packed(&self) -> Result<Self> {
1280        let Body::Flat(data) = &self.body else {
1281            return Ok(self.clone());
1282        };
1283        let Some((low, high)) = span_of(data, self.len) else {
1284            return Ok(self.clone());
1285        };
1286        let Some(range) = high.checked_sub(low).and_then(|range| u64::try_from(range).ok()) else {
1287            return Ok(self.clone());
1288        };
1289        let width = u64::BITS - range.leading_zeros();
1290        if width == 0 || width > PACKED_WIDTH_MAX {
1291            return Ok(self.clone());
1292        }
1293        if words_for(self.len, width) * size_of::<u64>() * PACKING_PAYS_AT > data.footprint() {
1294            return Ok(self.clone());
1295        }
1296        let words = pack(data, self.len, low, width);
1297        let packed = Self::packed(self.ty.clone(), words, width, low, self.len)?;
1298        Ok(packed.with_validity(self.validity.clone()))
1299    }
1300
1301    /// A vector of string views over an arena somebody else is holding too.
1302    ///
1303    /// The way in for a scan that has a page of strings and wants several chunks over it. Each chunk
1304    /// gets its own run of views and they all share the one arena, so the bytes are read where the
1305    /// page put them and nothing copies them.
1306    ///
1307    /// Every view is checked against the arena here rather than when a row is read. That is a pass
1308    /// over the views at construction, which is the same pass the caller just did to build them, and
1309    /// what it buys is that a row of this form cannot resolve to bytes that are not there. The check
1310    /// is on the offsets and not on the bytes, so it says nothing about whether the payload is text,
1311    /// which is the same promise a `BLOB` column makes.
1312    ///
1313    /// # Errors
1314    ///
1315    /// If the type is not one stored as views, or if a view points past the end of the arena.
1316    pub fn string_views(
1317        ty: LogicalType,
1318        views: Vec<StringView>,
1319        arena: Arc<Buffer<u8>>,
1320    ) -> Result<Self> {
1321        if ty.physical() != rudb_common::PhysicalType::Varlen {
1322            return Err(Error::internal(format!("a {ty} vector cannot hold string views")));
1323        }
1324        if views.iter().any(|view| view.bytes_in(&arena).is_none()) {
1325            return Err(Error::internal("a string view points past the end of its arena"));
1326        }
1327        let len = views.len();
1328        Ok(Self { ty, len, validity: Validity::AllValid, body: Body::Views { views, arena } })
1329    }
1330
1331    /// A text vector whose values remain in a storage source until they are read.
1332    pub fn external_text(ty: LogicalType, source: Arc<dyn TextSource>) -> Result<Self> {
1333        if ty.physical() != rudb_common::PhysicalType::Varlen {
1334            return Err(Error::internal(format!(
1335                "a {ty} vector cannot use an external text source"
1336            )));
1337        }
1338        let len = source.len();
1339        Ok(Self { ty, len, validity: Validity::AllValid, body: Body::ExternalText { source } })
1340    }
1341
1342    /// The same strings, in a form where a cut of them does not copy the bytes.
1343    ///
1344    /// The counterpart of [`Self::run_encoded`] and [`Self::bit_packed`] for a string column, and
1345    /// the only one of the three that takes `self` by value. It has to: what it does is move the
1346    /// arena into an `Arc` so nothing copies it again, and a version taking `&self` would start by
1347    /// copying the arena once to have one to move.
1348    ///
1349    /// Anything that is not a flat string column comes back as it was, which includes a column that
1350    /// is already in this form.
1351    ///
1352    /// # Errors
1353    ///
1354    /// Nothing here fails today. The result is a `Result` because the check inside
1355    /// [`Self::string_views`] is worth running on the views this builds rather than trusting that
1356    /// this function built them right.
1357    pub fn shared_text(self) -> Result<Self> {
1358        let Body::Flat(Data::Varlen(column)) = self.body else {
1359            return Ok(self);
1360        };
1361        let (views, arena) = column.into_parts();
1362        let shared = Self::string_views(self.ty, views, Arc::new(arena))?;
1363        Ok(shared.with_validity(self.validity))
1364    }
1365
1366    /// A vector of FSST codes against a table somebody else trained.
1367    ///
1368    /// The way in for a reader that has a page of compressed strings and the table that goes with
1369    /// it. The codes are not copied and the table is not retrained, so laying several chunks over
1370    /// one page costs the spans and nothing else.
1371    ///
1372    /// # Errors
1373    ///
1374    /// If the type is not one stored as text, or if a span runs past the end of the codes.
1375    pub fn coded(
1376        ty: LogicalType,
1377        codes: Arc<Vec<u8>>,
1378        spans: Vec<(u32, u32)>,
1379        table: Arc<SymbolTable>,
1380    ) -> Result<Self> {
1381        if ty.physical() != rudb_common::PhysicalType::Varlen {
1382            return Err(Error::internal(format!("a {ty} vector cannot hold FSST codes")));
1383        }
1384        let end = u32::try_from(codes.len()).unwrap_or(u32::MAX);
1385        if spans.iter().any(|&(from, to)| from > to || to > end) {
1386            return Err(Error::internal("an FSST span runs past the end of the codes"));
1387        }
1388        let len = spans.len();
1389        Ok(Self {
1390            ty,
1391            len,
1392            validity: Validity::AllValid,
1393            body: Body::Coded { codes, spans, table },
1394        })
1395    }
1396
1397    /// The same strings, compressed against a table trained on them.
1398    ///
1399    /// The counterpart of [`Self::run_encoded`] and [`Self::bit_packed`] for a text column, and it
1400    /// takes `self` by value for the reason [`Self::shared_text`] does.
1401    ///
1402    /// The table is trained on every row rather than on a sample. A vector is at most 1024 rows, so
1403    /// the sample would be most of the column anyway, and the systematic sampling
1404    /// `spec/06-compression.md` section 6.3 asks for is a decision about a page and belongs to
1405    /// whoever is holding one.
1406    ///
1407    /// It declines unless the codes are at most half the bytes the strings are. FSST gets about that
1408    /// on text and rather less on anything already short or already random, and below that the
1409    /// decompression per row read is not bought back. A column it declines on comes back as it was.
1410    ///
1411    /// # Errors
1412    ///
1413    /// Nothing here fails today. The result is a `Result` because the checks inside [`Self::coded`]
1414    /// are worth running on what this builds rather than trusting that this built it right.
1415    pub fn compressed(self) -> Result<Self> {
1416        let Body::Flat(Data::Varlen(column)) = &self.body else {
1417            return Ok(self);
1418        };
1419        let rows: Vec<&[u8]> = (0..self.len).filter_map(|row| column.bytes(row)).collect();
1420        if rows.len() != self.len {
1421            return Ok(self);
1422        }
1423        let plain: usize = rows.iter().map(|row| row.len()).sum();
1424        let table = SymbolTable::train(&rows);
1425        let mut codes = Vec::with_capacity(plain);
1426        let mut spans = Vec::with_capacity(self.len);
1427        for row in &rows {
1428            let from = u32::try_from(codes.len()).unwrap_or(u32::MAX);
1429            table.compress(row, &mut codes);
1430            spans.push((from, u32::try_from(codes.len()).unwrap_or(u32::MAX)));
1431        }
1432        if codes.len() * FSST_PAYS_AT > plain {
1433            return Ok(self);
1434        }
1435        let coded = Self::coded(self.ty.clone(), Arc::new(codes), spans, Arc::new(table))?;
1436        Ok(coded.with_validity(self.validity.clone()))
1437    }
1438
1439    /// The same values under a wider decimal type that stores them the same way.
1440    ///
1441    /// A decimal is kept as its unscaled integer, so two decimal types with one scale and one
1442    /// storage width describe the same bits, and going from the narrower of them to the wider is a
1443    /// relabelling rather than a conversion. The binder writes three of those into
1444    /// `l_extendedprice * (1 - l_discount)`, because a product's operands are given the answer's
1445    /// width and the answer's width is eighteen while both columns are fifteen, and each one was a
1446    /// pass over six million rows that wrote back the bytes it had just read.
1447    ///
1448    /// A flat run only, and deliberately. The general cast flattens whatever it is given, so a
1449    /// dictionary column came out of a width change as a run of values, and a relabelling that kept
1450    /// the dictionary would hand the arithmetic above two columns it has to read through a code per
1451    /// row instead of two it can read end to end. That was measured and it is the worse of the two:
1452    /// on `sum(l_extendedprice * l_discount)` under the filter q6 puts on it, where the rows left
1453    /// are few and scattered and the indirection is a cache miss each, keeping the dictionary cost
1454    /// half again as much as the flattening it saved. The flat case has no such question, since
1455    /// what it hands on is exactly what the pass would have built.
1456    ///
1457    /// Only widening, because a narrower width is a range every value has to be checked against and
1458    /// checking it is the pass this exists to avoid. `None` for anything else, including a narrower
1459    /// width, a changed scale, a changed storage width and any form but the flat one.
1460    #[must_use]
1461    pub fn as_wider_decimal(&self, target: &LogicalType) -> Option<Self> {
1462        let (
1463            LogicalType::Decimal { width: from, scale: held },
1464            LogicalType::Decimal { width: into, scale },
1465        ) = (&self.ty, target)
1466        else {
1467            return None;
1468        };
1469        if held != scale || from > into || self.ty.decimal_storage() != target.decimal_storage() {
1470            return None;
1471        }
1472        // Nothing in a flat run says what its numbers mean, so the relabelling is the type and
1473        // nothing else, and the buffer underneath is shared rather than copied.
1474        if !matches!(self.body, Body::Flat(_)) {
1475            return None;
1476        }
1477        Some(Self {
1478            ty: target.clone(),
1479            len: self.len,
1480            validity: self.validity.clone(),
1481            body: self.body.clone(),
1482        })
1483    }
1484
1485    /// The same vector with a different validity.
1486    #[must_use]
1487    pub fn with_validity(mut self, validity: Validity) -> Self {
1488        self.validity = validity;
1489        self
1490    }
1491
1492    /// What kind of values these are.
1493    #[must_use]
1494    pub fn logical_type(&self) -> &LogicalType {
1495        &self.ty
1496    }
1497
1498    /// How many values there are.
1499    #[must_use]
1500    pub fn len(&self) -> usize {
1501        self.len
1502    }
1503
1504    /// Whether there are no values.
1505    #[must_use]
1506    pub fn is_empty(&self) -> bool {
1507        self.len == 0
1508    }
1509
1510    /// How many bytes of memory this vector is holding.
1511    ///
1512    /// What the memory limit charges for it. A constant and a sequence hold one value and two
1513    /// numbers however long they are, which is the point of both forms, so the number here is the
1514    /// form's cost and not the column's width times its length.
1515    ///
1516    /// A part that is behind an `Arc` counts as one holder's share of it, which is
1517    /// [`Buffer::footprint`]'s rule for a shared page applied to the other shared parts. A
1518    /// dictionary counted in full in every vector sharing it is not a conservative over count, it is
1519    /// a number with the chunk count in it: an aggregate that emits nineteen thousand chunks of
1520    /// groups out of one stable dictionary reported that dictionary nineteen thousand times and
1521    /// refused itself a budget of twenty five gigabytes while the process held one. Dividing by the
1522    /// holders makes the sum over everything sharing the part come to about the part, which is what
1523    /// the number is supposed to mean, and it errs high rather than low whenever the holders arrive
1524    /// one after another, because each of them counts what it sees at the time it asks.
1525    #[must_use]
1526    pub fn footprint(&self) -> usize {
1527        let body = match &self.body {
1528            Body::Flat(data) => data.footprint(),
1529            Body::Constant(value) => value.footprint(),
1530            Body::Sequence { .. } => 0,
1531            Body::Dictionary { codes, values, .. } => {
1532                codes.capacity() * size_of::<u32>() + share(values.footprint(), values)
1533            }
1534            Body::Packed { words, .. } => share(words.capacity() * size_of::<u64>(), words),
1535            Body::Views { views, arena } => {
1536                views.capacity() * size_of::<StringView>() + share(arena.footprint(), arena)
1537            }
1538            Body::ExternalText { source } => share(source.footprint(), source),
1539            Body::Coded { codes, spans, table } => {
1540                share(codes.capacity(), codes)
1541                    + spans.capacity() * size_of::<(u32, u32)>()
1542                    + share(table.footprint(), table)
1543            }
1544            Body::Runs { ends, values } => {
1545                ends.capacity() * size_of::<u32>() + share(values.footprint(), values)
1546            }
1547            Body::Nested { entries, child } => {
1548                entries.capacity() * size_of::<(u32, u32)>() + share(child.footprint(), child)
1549            }
1550            // A struct is as wide as its fields are, so this is the one body whose cost is a sum
1551            // over children rather than one number, and a struct of a hundred narrow fields costs
1552            // what the hundred columns cost.
1553            Body::Fields { children } => {
1554                children.capacity() * size_of::<Arc<Self>>()
1555                    + children.iter().map(|child| share(child.footprint(), child)).sum::<usize>()
1556            }
1557        };
1558        size_of::<Self>() + self.validity.footprint() + body
1559    }
1560
1561    /// Which of the values are not null, at this level and no deeper.
1562    ///
1563    /// This is not the same question as [`Self::is_null_at`] and the difference has already cost
1564    /// one wrong answer. A dictionary and a run length vector keep their nulls in the values they
1565    /// point at rather than in a mask of their own, so both are built with every row marked present
1566    /// here and a row whose value is null reads as valid. A caller that wants to know whether a row
1567    /// is null wants the other one. A caller that wants the mask of a flat column, to copy it or to
1568    /// count it, wants this one.
1569    #[must_use]
1570    pub fn validity(&self) -> &Validity {
1571        &self.validity
1572    }
1573
1574    /// Whether the row at `index` is null, in whichever form the vector is in.
1575    ///
1576    /// Reads through a dictionary or a run to the value it stands for, which is where those two
1577    /// forms keep their nulls, and answers from the mask for every other form. A row past the end
1578    /// is null, the same answer [`Self::value_at`] gives it.
1579    #[must_use]
1580    pub fn is_null_at(&self, index: usize) -> bool {
1581        if index >= self.len || !self.validity.is_valid(index) {
1582            return true;
1583        }
1584        match &self.body {
1585            Body::Dictionary { codes, values, .. } => match codes.get(index) {
1586                Some(&code) => values.is_null_at(code as usize),
1587                None => true,
1588            },
1589            Body::Runs { ends, values } => match run_holding(ends, index) {
1590                Some(run) => values.is_null_at(run),
1591                None => true,
1592            },
1593            _ => false,
1594        }
1595    }
1596
1597    /// Which physical form this vector is in.
1598    #[must_use]
1599    pub fn form(&self) -> Form {
1600        match self.body {
1601            Body::Flat(_) => Form::Flat,
1602            Body::Constant(_) => Form::Constant,
1603            Body::Sequence { .. } => Form::Sequence,
1604            Body::Dictionary { .. } => Form::Dictionary,
1605            Body::Packed { .. } => Form::BitPacked,
1606            Body::Views { .. } => Form::StringView,
1607            Body::ExternalText { .. } => Form::StringView,
1608            Body::Coded { .. } => Form::Fsst,
1609            Body::Runs { .. } => Form::Rle,
1610            Body::Nested { .. } => Form::List,
1611            Body::Fields { .. } => Form::Struct,
1612        }
1613    }
1614
1615    /// The data, for a flat vector, and `None` for any other form.
1616    ///
1617    /// A kernel that wants a slice asks for it and takes the flat path if it gets one. A kernel
1618    /// that can do better on a constant or a dictionary checks [`Self::form`] first.
1619    #[must_use]
1620    pub fn data(&self) -> Option<&Data> {
1621        match &self.body {
1622            Body::Flat(data) => Some(data),
1623            _ => None,
1624        }
1625    }
1626
1627    /// The one value, for a constant vector, and `None` for any other form.
1628    ///
1629    /// A kernel comparing a column against a literal wants the literal once rather than 1024
1630    /// times, and [`Self::value_at`] on a constant clones it on every call because it has to be
1631    /// able to hand back a `Value` for any form. This is the accessor that lets the specialized
1632    /// path hoist the clone out of the loop.
1633    #[must_use]
1634    pub fn constant_value(&self) -> Option<&Value> {
1635        match &self.body {
1636            Body::Constant(value) => Some(value.as_ref()),
1637            _ => None,
1638        }
1639    }
1640
1641    /// The codes and the values, for a dictionary vector, and `None` for any other form.
1642    ///
1643    /// The reason a kernel needs this rather than reading the dictionary through
1644    /// [`Self::value_at`] is the entire argument for the form existing. A filter against a
1645    /// dictionary column of 1024 rows and 40 distinct values is 40 comparisons and 1024 lookups,
1646    /// not 1024 comparisons, and there is no way to write that loop without seeing the codes.
1647    ///
1648    /// Note what the validity of the returned vector means. A dictionary keeps its nulls in the
1649    /// vector it points at, and the dictionary's own validity says nothing about them, so a caller
1650    /// deciding whether row `i` is null has to ask the value vector about `codes[i]` rather than
1651    /// asking this vector about `i`. [`Self::flatten`] has the same note on it for the same
1652    /// reason, because getting this wrong is a null that survives being selected and comes out as
1653    /// a zero.
1654    #[must_use]
1655    pub fn dictionary_parts(&self) -> Option<(&[u32], &Self)> {
1656        match &self.body {
1657            Body::Dictionary { codes, values, .. } => Some((codes, values.as_ref())),
1658            _ => None,
1659        }
1660    }
1661
1662    /// The codes and the shared dictionary handle for a dictionary vector.
1663    ///
1664    /// Storage readers use the identity of this handle to prove that codes from separate pages
1665    /// belong to one table-wide dictionary. Kernels that only read values should continue to use
1666    /// [`Self::dictionary_parts`].
1667    #[must_use]
1668    pub fn shared_dictionary_parts(&self) -> Option<(&[u32], &Arc<Self>)> {
1669        match &self.body {
1670            Body::Dictionary { codes, values, .. } => Some((codes, values)),
1671            _ => None,
1672        }
1673    }
1674
1675    /// Stable codes and their shared values, when storage guarantees one code space across pages.
1676    #[must_use]
1677    pub fn stable_dictionary_parts(&self) -> Option<(&[u32], &Arc<Self>)> {
1678        match &self.body {
1679            Body::Dictionary { codes, values, stable: true } => Some((codes, values)),
1680            _ => None,
1681        }
1682    }
1683
1684    /// The run ends and the run values, for a run length vector, and `None` for any other form.
1685    ///
1686    /// The ends are exclusive and increasing, and there is exactly one value per run, so a kernel
1687    /// that wants to walk this walks the pairs and never asks which run a row is in. That is the
1688    /// whole argument for the form: an aggregate over a clustered column is one multiply per run
1689    /// instead of one add per row, and there is no way to write that loop without seeing the ends.
1690    ///
1691    /// The nulls are in the values, the way a dictionary's are, so a caller deciding whether row `i`
1692    /// is null asks the value vector about the run rather than asking this vector about `i`.
1693    #[must_use]
1694    pub fn run_parts(&self) -> Option<(&[u32], &Self)> {
1695        match &self.body {
1696            Body::Runs { ends, values } => Some((ends, values.as_ref())),
1697            _ => None,
1698        }
1699    }
1700
1701    /// Where each row's value is, for the two forms that keep their values somewhere else.
1702    ///
1703    /// A dictionary and a run length vector are the same shape seen from a kernel: a run of
1704    /// positions and a vector to read them out of. The difference is that a dictionary stores the
1705    /// positions and a run length vector works them out, and a kernel writing `values[at[row]]` does
1706    /// not care which. So every specialization written against [`Self::dictionary_parts`] covers
1707    /// both forms by asking this instead, and the day a third form with an indirection arrives it
1708    /// covers that one too without any of those kernels being reopened.
1709    ///
1710    /// The run length side costs an allocation of one position per row and a pass to fill it, which
1711    /// is the same four bytes a row a dictionary was already carrying and is paid once per kernel
1712    /// call rather than once per row. That is the price of this being one accessor rather than a
1713    /// second arm in eighteen kernels, and it is not the last word: a kernel that wants a run at a
1714    /// time reads [`Self::run_parts`] and pays nothing, which is the specialization this makes it
1715    /// possible to skip writing until a sweep says it is worth it.
1716    #[must_use]
1717    pub fn positions(&self) -> Option<(Cow<'_, [u32]>, &Self)> {
1718        match &self.body {
1719            Body::Dictionary { codes, values, .. } => Some((Cow::Borrowed(codes), values.as_ref())),
1720            Body::Runs { ends, values } => {
1721                let mut at = Vec::with_capacity(self.len);
1722                for (run, &stop) in ends.iter().enumerate() {
1723                    let run = u32::try_from(run).unwrap_or(u32::MAX);
1724                    at.resize(stop as usize, run);
1725                }
1726                Some((Cow::Owned(at), values.as_ref()))
1727            }
1728            _ => None,
1729        }
1730    }
1731
1732    /// The bits and what they mean, for a bit packed vector, and `None` for any other form.
1733    ///
1734    /// What a kernel needs to stay in code space. A comparison against a literal is the case that
1735    /// pays: `column > 900` over a column packed from a base of 40 is `code > 860`, which is the
1736    /// same shift and mask the read was going to do anyway and no unpacking at all, and a literal
1737    /// outside the packed range answers the whole vector without reading a bit of it. None of that
1738    /// can be written without seeing the width and the base.
1739    #[must_use]
1740    pub fn packed_parts(&self) -> Option<Packed<'_>> {
1741        match &self.body {
1742            Body::Packed { words, width, base, offset } => {
1743                Some(Packed { words, width: *width, base: *base, offset: *offset })
1744            }
1745            _ => None,
1746        }
1747    }
1748
1749    /// The views and the arena, for either form that stores strings, and `None` for the rest.
1750    ///
1751    /// This is to the two string forms what [`Self::positions`] is to the two forms that point
1752    /// somewhere else. A flat varchar column owns its arena and a string view column shares one, and
1753    /// a kernel reading a row wants the view and the bytes either way, so every specialization
1754    /// written against this covers both forms and neither has to be reopened when a third way of
1755    /// holding an arena arrives.
1756    ///
1757    /// The arena is whatever the long strings live in, which for a column over a page is the page,
1758    /// including the parts of it no view points at. Only the views say which bytes are a row.
1759    #[must_use]
1760    pub fn text_parts(&self) -> Option<(&[StringView], &[u8])> {
1761        match &self.body {
1762            Body::Flat(Data::Varlen(column)) => Some((column.views(), column.arena())),
1763            Body::Views { views, arena } => Some((views, arena)),
1764            _ => None,
1765        }
1766    }
1767
1768    /// The codes and the table, for an FSST vector, and `None` for any other form.
1769    ///
1770    /// What a kernel needs to stay in code space. An equality filter is the case that pays, and it
1771    /// pays completely: the literal is compressed once against the same table and after that a row
1772    /// matches exactly when its code bytes match, because compressing is a function and so is
1773    /// decompressing. No row is decompressed at all. An ordering comparison cannot do that, since a
1774    /// symbol code says nothing about where its symbol sorts, so those decompress and say so.
1775    #[must_use]
1776    pub fn coded_parts(&self) -> Option<Coded<'_>> {
1777        match &self.body {
1778            Body::Coded { codes, spans, table } => Some(Coded { codes, spans, table }),
1779            _ => None,
1780        }
1781    }
1782
1783    /// The start and the step, for a sequence vector, and `None` for any other form.
1784    #[must_use]
1785    pub fn sequence_parts(&self) -> Option<(i64, i64)> {
1786        match self.body {
1787            Body::Sequence { start, step } => Some((start, step)),
1788            _ => None,
1789        }
1790    }
1791
1792    /// The value at `index`, as a single value.
1793    ///
1794    /// This is the slow path on purpose. It is what a result set is read out with and what a test
1795    /// asserts on, and an operator that calls it per row is an operator that has already lost the
1796    /// argument the vector interface exists to win.
1797    #[must_use]
1798    pub fn value_at(&self, index: usize) -> Value {
1799        if index >= self.len || !self.validity.is_valid(index) {
1800            return Value::Null;
1801        }
1802        match &self.body {
1803            Body::Constant(value) => value.as_ref().clone(),
1804            Body::Sequence { start, step } => Value::BigInt(start + step * index as i64),
1805            Body::Dictionary { codes, values, .. } => match codes.get(index) {
1806                Some(&code) => values.value_at(code as usize),
1807                None => Value::Null,
1808            },
1809            Body::Runs { ends, values } => match run_holding(ends, index) {
1810                Some(run) => values.value_at(run),
1811                None => Value::Null,
1812            },
1813            // One value unpacked into a run of one, so that what a packed value means is decided in
1814            // the same place a flat one is rather than in a second copy of the type mapping that
1815            // could drift from it. It allocates, which this path is allowed to do and the typed
1816            // unpack in `copied` is not, and it is the reason anything about to read a packed
1817            // column a row at a time should flatten it once instead.
1818            Body::Packed { words, width, base, offset } => {
1819                unpack(&self.ty, words, *offset, *width, *base, &[index])
1820                    .map_or(Value::Null, |data| value_from(&self.ty, &data, 0))
1821            }
1822            // The bytes are where the arena has them, and what they are read as is the logical
1823            // type's business, so this hands the row to the same reader a flat column goes through
1824            // rather than deciding here that a `BLOB` is a string.
1825            Body::Views { views, arena } => {
1826                match views.get(index).and_then(|v| v.bytes_in(arena)) {
1827                    Some(bytes) => bytes_as(&self.ty, bytes),
1828                    None => Value::Null,
1829                }
1830            }
1831            Body::ExternalText { source } => source
1832                .bytes_at(index)
1833                .ok()
1834                .flatten()
1835                .map_or(Value::Null, |bytes| bytes_as(&self.ty, bytes)),
1836            // One row decompressed on its own, which is the property the form is chosen for. It
1837            // allocates, which this path is allowed to do, and it is the reason anything about to
1838            // read a compressed column a row at a time should flatten it once instead.
1839            Body::Coded { codes, spans, table } => {
1840                match spans.get(index).and_then(|&(from, to)| {
1841                    let mut out = Vec::new();
1842                    table.decompress(codes.get(from as usize..to as usize)?, &mut out).ok()?;
1843                    Some(out)
1844                }) {
1845                    Some(bytes) => bytes_as(&self.ty, &bytes),
1846                    None => Value::Null,
1847                }
1848            }
1849            // A row's elements are read out of the child one at a time, which is the slow path this
1850            // whole function is and is why a kernel over a list column reads `list_parts` instead.
1851            // The element type comes from the child rather than from this vector's type, so a list
1852            // whose child was built narrower than the column claims still hands back what is in it.
1853            //
1854            // A map is stored in this body too, so which value comes out is decided by the logical
1855            // type rather than by the body. That is the one place the composition shows: the bytes of
1856            // a map really are the bytes of a list of two field structs, and the only thing that
1857            // remembers it is a map is the type.
1858            Body::Nested { entries, child } => match (entries.get(index), &self.ty) {
1859                (Some(&(start, len)), LogicalType::Map(key, value)) => {
1860                    let pairs = child.struct_parts().unwrap_or_default();
1861                    Value::map(
1862                        key.as_ref().clone(),
1863                        value.as_ref().clone(),
1864                        (start..start + len)
1865                            .filter_map(|at| {
1866                                let [keys, values] = pairs else { return None };
1867                                Some((keys.value_at(at as usize), values.value_at(at as usize)))
1868                            })
1869                            .collect(),
1870                    )
1871                }
1872                (Some(&(start, len)), _) => Value::List {
1873                    element: child.ty.clone(),
1874                    values: (start..start + len).map(|at| child.value_at(at as usize)).collect(),
1875                },
1876                (None, _) => Value::Null,
1877            },
1878            // One value read out of each child at the same position, which is the slow path this whole
1879            // function is and is why a kernel over a struct column reads `struct_parts` instead. The
1880            // names come from this vector's type rather than from the children, because a child is a
1881            // vector and a vector has no name, and the type is where the field order is written down.
1882            Body::Fields { children } => Value::Struct(
1883                fields_of(&self.ty)
1884                    .iter()
1885                    .zip(children)
1886                    .map(|(field, child)| (field.name.clone(), child.value_at(index)))
1887                    .collect(),
1888            ),
1889            Body::Flat(data) => value_from(&self.ty, data, index),
1890        }
1891    }
1892
1893    /// One value of this vector's type, built out of bytes the caller already holds.
1894    ///
1895    /// [`try_value_at`](Self::try_value_at) finds the bytes itself, which over a dictionary that
1896    /// keeps its payload in a file means a read. A caller that swept the values out has the bytes in
1897    /// hand already and wants nothing from here but the type.
1898    pub fn value_of(&self, bytes: &[u8]) -> Value {
1899        bytes_as(&self.ty, bytes)
1900    }
1901
1902    /// The value at `index`, preserving storage read and validation failures.
1903    pub fn try_value_at(&self, index: usize) -> Result<Value> {
1904        if index >= self.len || !self.validity.is_valid(index) {
1905            return Ok(Value::Null);
1906        }
1907        match &self.body {
1908            Body::ExternalText { source } => {
1909                Ok(source.bytes_at(index)?.map_or(Value::Null, |bytes| bytes_as(&self.ty, bytes)))
1910            }
1911            Body::Dictionary { codes, values, .. } => match codes.get(index) {
1912                Some(&code) => values.try_value_at(code as usize),
1913                None => Ok(Value::Null),
1914            },
1915            Body::Runs { ends, values } => match run_holding(ends, index) {
1916                Some(run) => values.try_value_at(run),
1917                None => Ok(Value::Null),
1918            },
1919            Body::Nested { entries, child } => match (entries.get(index), &self.ty) {
1920                (Some(&(start, len)), LogicalType::Map(key, value)) => {
1921                    let pairs = child.struct_parts().unwrap_or_default();
1922                    let [keys, values] = pairs else { return Ok(Value::Null) };
1923                    let mut entries = Vec::with_capacity(len as usize);
1924                    for at in start..start + len {
1925                        entries.push((
1926                            keys.try_value_at(at as usize)?,
1927                            values.try_value_at(at as usize)?,
1928                        ));
1929                    }
1930                    Ok(Value::map(key.as_ref().clone(), value.as_ref().clone(), entries))
1931                }
1932                (Some(&(start, len)), _) => {
1933                    let mut values = Vec::with_capacity(len as usize);
1934                    for at in start..start + len {
1935                        values.push(child.try_value_at(at as usize)?);
1936                    }
1937                    Ok(Value::List { element: child.ty.clone(), values })
1938                }
1939                (None, _) => Ok(Value::Null),
1940            },
1941            Body::Fields { children } => {
1942                let mut values = Vec::with_capacity(children.len());
1943                for (field, child) in fields_of(&self.ty).iter().zip(children) {
1944                    values.push((field.name.clone(), child.try_value_at(index)?));
1945                }
1946                Ok(Value::Struct(values))
1947            }
1948            _ => Ok(self.value_at(index)),
1949        }
1950    }
1951
1952    /// The text at `index`, borrowed rather than copied.
1953    ///
1954    /// [`Self::value_at`] on a `VARCHAR` column allocates a `String` per call, and a group by that
1955    /// reads a string column keys on one string per input row. This hands back the bytes where they
1956    /// already are, so a caller with somewhere to put them does not go to the allocator at all.
1957    ///
1958    /// `None` for a null, for an index past the end, for a column that is not `VARCHAR`, and for the
1959    /// constant and sequence forms, whose values are not stored per position. A caller that gets
1960    /// `None` has to fall back to [`Self::value_at`], which is correct for all of those.
1961    #[must_use]
1962    pub fn text_at(&self, index: usize) -> Option<&str> {
1963        if self.ty != LogicalType::Varchar || index >= self.len || !self.validity.is_valid(index) {
1964            return None;
1965        }
1966        match &self.body {
1967            Body::Flat(data) => data.str_at(index),
1968            Body::Dictionary { codes, values, .. } => {
1969                values.text_at(usize::try_from(*codes.get(index)?).ok()?)
1970            }
1971            Body::Runs { ends, values } => values.text_at(run_holding(ends, index)?),
1972            Body::Views { views, arena } => {
1973                std::str::from_utf8(views.get(index)?.bytes_in(arena)?).ok()
1974            }
1975            Body::ExternalText { source } => {
1976                std::str::from_utf8(source.bytes_at(index).ok().flatten()?).ok()
1977            }
1978            _ => None,
1979        }
1980    }
1981
1982    /// The variable length bytes at `index`, borrowed without validating or copying them.
1983    ///
1984    /// String data is validated when it enters a vector. Hashing and equality only need its bytes,
1985    /// so those kernels should not pay for UTF-8 validation again on every read.
1986    #[must_use]
1987    pub fn bytes_at(&self, index: usize) -> Option<&[u8]> {
1988        if index >= self.len || !self.validity.is_valid(index) {
1989            return None;
1990        }
1991        match &self.body {
1992            Body::Constant(value) => match value.as_ref() {
1993                Value::Varchar(text) => Some(text.as_bytes()),
1994                Value::Blob(bytes) => Some(bytes),
1995                _ => None,
1996            },
1997            Body::Dictionary { codes, values, .. } => {
1998                values.bytes_at(usize::try_from(*codes.get(index)?).ok()?)
1999            }
2000            Body::Runs { ends, values } => values.bytes_at(run_holding(ends, index)?),
2001            Body::Views { views, arena } => views.get(index)?.bytes_in(arena),
2002            Body::ExternalText { source } => source.bytes_at(index).ok().flatten(),
2003            Body::Flat(data) => data.bytes_at(index),
2004            // The same `None` [`Self::text_at`] gives, for the same reason. A compressed row is not
2005            // anywhere in its plain bytes, so there is nothing here to hand back a borrow of, and a
2006            // caller that gets `None` goes to `value_at` and gets the row decompressed into a value.
2007            // A list row is `None` for a nearer reason: it is not bytes at all, and a caller wanting
2008            // its elements wants [`Self::list_parts`] rather than a borrow of one row.
2009            Body::Coded { .. }
2010            | Body::Sequence { .. }
2011            | Body::Packed { .. }
2012            | Body::Nested { .. }
2013            | Body::Fields { .. } => None,
2014        }
2015    }
2016
2017    /// Variable length bytes at `index`, preserving storage read and validation failures.
2018    pub fn try_bytes_at(&self, index: usize) -> Result<Option<&[u8]>> {
2019        if index >= self.len || !self.validity.is_valid(index) {
2020            return Ok(None);
2021        }
2022        match &self.body {
2023            Body::Constant(value) => Ok(match value.as_ref() {
2024                Value::Varchar(text) => Some(text.as_bytes()),
2025                Value::Blob(bytes) => Some(bytes.as_slice()),
2026                _ => None,
2027            }),
2028            Body::Dictionary { codes, values, .. } => match codes.get(index) {
2029                Some(&code) => values.try_bytes_at(code as usize),
2030                None => Ok(None),
2031            },
2032            Body::Runs { ends, values } => match run_holding(ends, index) {
2033                Some(run) => values.try_bytes_at(run),
2034                None => Ok(None),
2035            },
2036            Body::Views { views, arena } => {
2037                Ok(views.get(index).and_then(|view| view.bytes_in(arena)))
2038            }
2039            Body::ExternalText { source } => source.bytes_at(index),
2040            Body::Flat(data) => Ok(data.bytes_at(index)),
2041            Body::Coded { .. }
2042            | Body::Sequence { .. }
2043            | Body::Packed { .. }
2044            | Body::Nested { .. }
2045            | Body::Fields { .. } => Ok(None),
2046        }
2047    }
2048
2049    /// Walks the values from `first` up to at most `limit`, without keeping what it read.
2050    ///
2051    /// [`TextSource::sweep`] is what this is for and what the doc on it explains. Everything else
2052    /// here is the honest fallback: a vector that is not reading text out of a file has its values
2053    /// already, so there is nothing to avoid keeping, and it hands over one value and lets the
2054    /// caller come back. The answer is one past the last value visited either way, so the loop that
2055    /// calls this is the same loop whichever form it got.
2056    ///
2057    /// Nulls go the slow way. A source that reads a file holds no validity of its own, so the
2058    /// vector's own mask is the only thing that knows, and rather than teach the sweep about it the
2059    /// one form that can have both hands over a value at a time through the reader that checks.
2060    ///
2061    /// # Errors
2062    ///
2063    /// Whatever reading a value raises, and whatever `body` raises.
2064    pub fn sweep_text(
2065        &self,
2066        first: usize,
2067        limit: usize,
2068        body: &mut dyn FnMut(usize, &[u8]) -> Result<()>,
2069    ) -> Result<usize> {
2070        let limit = limit.min(self.len);
2071        if first >= limit {
2072            return Ok(first);
2073        }
2074        if let Body::ExternalText { source } = &self.body {
2075            if matches!(self.validity, Validity::AllValid) {
2076                return source.sweep(first, limit, body);
2077            }
2078        }
2079        body(first, self.try_bytes_at(first)?.unwrap_or_default())?;
2080        Ok(first + 1)
2081    }
2082
2083    /// Variable length byte count at `index`, preserving storage failures.
2084    pub fn try_bytes_len_at(&self, index: usize) -> Result<Option<usize>> {
2085        if index >= self.len || !self.validity.is_valid(index) {
2086            return Ok(None);
2087        }
2088        match &self.body {
2089            Body::Dictionary { codes, values, .. } => match codes.get(index) {
2090                Some(&code) => values.try_bytes_len_at(code as usize),
2091                None => Ok(None),
2092            },
2093            Body::Runs { ends, values } => match run_holding(ends, index) {
2094                Some(run) => values.try_bytes_len_at(run),
2095                None => Ok(None),
2096            },
2097            Body::ExternalText { source } => source.bytes_len_at(index),
2098            _ => Ok(self.bytes_at(index).map(<[u8]>::len)),
2099        }
2100    }
2101
2102    /// How many ranks this vector's values have in sorted order, when whatever holds them knows.
2103    ///
2104    /// See [`TextSource::ranks`] for what a rank is and what a source promises by answering with
2105    /// one. Only a vector whose values come from storage can answer, because only storage is in a
2106    /// position to have sorted them once and written the answer down.
2107    #[must_use]
2108    pub fn ranks(&self) -> Option<usize> {
2109        match &self.body {
2110            Body::ExternalText { source } => source.ranks(),
2111            _ => None,
2112        }
2113    }
2114
2115    /// How the value at `rank` compares against `wanted`. See [`TextSource::compare_rank`].
2116    pub fn compare_rank(&self, rank: usize, wanted: &[u8]) -> Result<Ordering> {
2117        match &self.body {
2118            Body::ExternalText { source } => source.compare_rank(rank, wanted),
2119            _ => {
2120                Err(Error::internal("a vector without a sorted order was asked to compare a rank"))
2121            }
2122        }
2123    }
2124
2125    /// Where `wanted` would go in the sorted order. See [`TextSource::below`].
2126    ///
2127    /// # Errors
2128    ///
2129    /// If this vector has no sorted order, or if a probe of it fails.
2130    pub fn below(&self, ranks: usize, wanted: &[u8]) -> Result<(usize, bool)> {
2131        match &self.body {
2132            Body::ExternalText { source } => source.below(ranks, wanted),
2133            _ => Err(Error::internal("a vector without a sorted order was asked for a boundary")),
2134        }
2135    }
2136
2137    /// The position of the value at `rank`. See [`TextSource::code_at_rank`].
2138    pub fn code_at_rank(&self, rank: usize) -> Result<u32> {
2139        match &self.body {
2140            Body::ExternalText { source } => source.code_at_rank(rank),
2141            _ => Err(Error::internal("a vector without a sorted order was asked for a rank")),
2142        }
2143    }
2144
2145    /// The rank of every value, indexed by position. See [`TextSource::code_ranks`].
2146    #[must_use]
2147    pub fn code_ranks(&self) -> Option<&[u32]> {
2148        match &self.body {
2149            Body::ExternalText { source } => source.code_ranks(),
2150            _ => None,
2151        }
2152    }
2153
2154    /// Text at `index`, preserving storage read, validation and UTF-8 failures.
2155    pub fn try_text_at(&self, index: usize) -> Result<Option<&str>> {
2156        if self.ty != LogicalType::Varchar {
2157            return Ok(None);
2158        }
2159        self.try_bytes_at(index)?
2160            .map(|bytes| {
2161                std::str::from_utf8(bytes).map_err(|error| {
2162                    Error::conversion(format!("invalid UTF-8 in VARCHAR: {error}"))
2163                })
2164            })
2165            .transpose()
2166    }
2167
2168    /// Read every storage-backed value reachable through this vector.
2169    pub fn validate_external(&self) -> Result<()> {
2170        match &self.body {
2171            Body::ExternalText { source } => {
2172                for index in 0..source.len() {
2173                    source.bytes_at(index)?;
2174                }
2175            }
2176            Body::Dictionary { codes, values, .. } => {
2177                for &code in codes {
2178                    values.try_bytes_at(code as usize)?;
2179                }
2180            }
2181            Body::Runs { values, .. } => values.validate_external()?,
2182            Body::Nested { child, .. } => child.validate_external()?,
2183            Body::Fields { children } => {
2184                for child in children {
2185                    child.validate_external()?;
2186                }
2187            }
2188            _ => {}
2189        }
2190        Ok(())
2191    }
2192
2193    /// The signed integer at `index`, widened, read without building a [`Value`].
2194    ///
2195    /// The integer sibling of [`Self::bytes_at`], and it is here for the same caller. A group by on
2196    /// an integer column compares one key per input row against the group it probed, and doing that
2197    /// through [`Self::value_at`] built and dropped a sixty four byte value a row at a time for a
2198    /// number that was already sitting in the column.
2199    ///
2200    /// Widened to `i128` because that is what [`Data::signed_at`] hands back underneath, and one
2201    /// method that covers every signed width is worth more than five that do not. A caller that
2202    /// wants a narrower type narrows it, which is a range check against a value in a register.
2203    ///
2204    /// The types this answers for are the ones whose flat data is read through `signed_at`, so the
2205    /// five signed integer widths and the decimal, date, time and timestamp types that are stored
2206    /// in them. A decimal answers with its unscaled value, which is the number the column holds.
2207    ///
2208    /// `None` for a null, for an index past the end, for a column of any other type, and for the
2209    /// compressed form. Packed integers stay in code space and answer `base + code` directly. A
2210    /// caller that gets `None` falls back to [`Self::value_at`], which is correct for the remaining
2211    /// forms.
2212    #[must_use]
2213    pub fn signed_at(&self, index: usize) -> Option<i128> {
2214        if index >= self.len || !self.validity.is_valid(index) {
2215            return None;
2216        }
2217        match &self.body {
2218            Body::Flat(data) => data.signed_at(index),
2219            Body::Constant(value) => match value.as_ref() {
2220                Value::TinyInt(x) => Some(i128::from(*x)),
2221                Value::SmallInt(x) => Some(i128::from(*x)),
2222                Value::Integer(x) | Value::Date(x) => Some(i128::from(*x)),
2223                Value::BigInt(x) | Value::Time(x) | Value::Timestamp(x) => Some(i128::from(*x)),
2224                Value::HugeInt(x) | Value::Decimal { unscaled: x, .. } => Some(*x),
2225                _ => None,
2226            },
2227            // The same arithmetic [`Self::value_at`] does on a sequence, so the two agree about a
2228            // sequence that runs off the end of the width it is stored in.
2229            Body::Sequence { start, step } => {
2230                Some(i128::from(start.wrapping_add(step.wrapping_mul(index as i64))))
2231            }
2232            Body::Dictionary { codes, values, .. } => {
2233                values.signed_at(usize::try_from(*codes.get(index)?).ok()?)
2234            }
2235            Body::Runs { ends, values } => values.signed_at(run_holding(ends, index)?),
2236            Body::Packed { words, width, base, offset } => Some(
2237                *base + i128::from(code_at(words, (*offset + index) * *width as usize, *width)),
2238            ),
2239            // The same `None` [`Self::bytes_at`] gives, for the same reason. A compressed row is not
2240            // an integer anywhere until it has been unpacked, and a caller that gets
2241            // `None` goes to `value_at` and gets the row unpacked into a value. A list row is not an
2242            // integer in any form, however many integers are in it, and a struct row is not one even
2243            // when it has exactly one integer field, since the row is the struct and not the field.
2244            Body::Coded { .. }
2245            | Body::Views { .. }
2246            | Body::ExternalText { .. }
2247            | Body::Nested { .. }
2248            | Body::Fields { .. } => None,
2249        }
2250    }
2251
2252    /// Every signed value in order, widened to `i64`, written into `out`.
2253    ///
2254    /// The bulk form of [`Self::signed_at`], for a caller that is going to read the whole vector
2255    /// anyway. A group by on two integer columns called `signed_at` once per column per row, and
2256    /// every one of those matched on the body, called into the data and matched again on the
2257    /// layout, which is about sixty five instructions to read a number that was already sitting in
2258    /// a slice. It was a fifth of ClickBench 32 on its own.
2259    ///
2260    /// A null writes whatever the body holds under it, which is the zero a flat column keeps behind
2261    /// its mask. Nulls are a separate question and the caller asks it separately, from
2262    /// [`Self::none_null`] once for the vector when that answers and a row at a time when it does
2263    /// not.
2264    ///
2265    /// `false`, with `out` left empty, for a vector this cannot hand over as a block: `HUGEINT` and
2266    /// the wide decimals, whose values do not fit an `i64`, the string and nested forms, the
2267    /// compressed form, and the dictionary and run forms, which are a gather rather than a copy and
2268    /// are left until something wants them. A caller that gets `false` reads the vector the way it
2269    /// read it before, with [`Self::signed_at`].
2270    #[must_use]
2271    pub fn signed_block(&self, out: &mut Vec<i64>) -> bool {
2272        out.clear();
2273        match &self.body {
2274            Body::Flat(data) => data.signed_block(self.len, out),
2275            Body::Constant(value) => {
2276                let held = match value.as_ref() {
2277                    Value::TinyInt(x) => i64::from(*x),
2278                    Value::SmallInt(x) => i64::from(*x),
2279                    Value::Integer(x) | Value::Date(x) => i64::from(*x),
2280                    Value::BigInt(x) | Value::Time(x) | Value::Timestamp(x) => *x,
2281                    _ => return false,
2282                };
2283                out.resize(self.len, held);
2284                true
2285            }
2286            // The same arithmetic [`Self::signed_at`] does on a sequence, once per row rather than
2287            // once per call, and it wraps where that one wraps.
2288            Body::Sequence { start, step } => {
2289                out.extend(
2290                    (0..self.len).map(|index| start.wrapping_add(step.wrapping_mul(index as i64))),
2291                );
2292                true
2293            }
2294            Body::Packed { words, width, base, offset } => match i64::try_from(*base) {
2295                Ok(base) => {
2296                    out.extend((0..self.len).map(|index| {
2297                        base.wrapping_add(code_at(
2298                            words,
2299                            (*offset + index) * *width as usize,
2300                            *width,
2301                        ) as i64)
2302                    }));
2303                    true
2304                }
2305                Err(_) => false,
2306            },
2307            Body::Dictionary { .. }
2308            | Body::Runs { .. }
2309            | Body::Coded { .. }
2310            | Body::Views { .. }
2311            | Body::ExternalText { .. }
2312            | Body::Nested { .. }
2313            | Body::Fields { .. } => false,
2314        }
2315    }
2316
2317    /// Whether the vector holds no nulls at all, asked once rather than a row at a time.
2318    ///
2319    /// The bulk form of [`Self::is_null_at`], and it answers the same question that one does, so a
2320    /// dictionary and a run are read through to the values behind them where those two keep their
2321    /// nulls. A dictionary that holds a null no code points at answers `false` here and `false` at
2322    /// every row, which is the safe direction and is the only place the two can differ.
2323    ///
2324    /// A caller that gets `false` goes back to asking a row at a time.
2325    #[must_use]
2326    pub fn none_null(&self) -> bool {
2327        if self.validity.has_nulls(self.len) {
2328            return false;
2329        }
2330        match &self.body {
2331            Body::Dictionary { values, .. } | Body::Runs { values, .. } => values.none_null(),
2332            _ => true,
2333        }
2334    }
2335
2336    /// Every value in order, as single values.
2337    pub fn iter(&self) -> impl Iterator<Item = Value> + '_ {
2338        (0..self.len).map(|index| self.value_at(index))
2339    }
2340
2341    /// This vector with its payload held as a page, so that copying or cutting it is free.
2342    ///
2343    /// For a producer that means to hand the same values out many times, which is what a stored
2344    /// column is. A flat body is the form this changes, because it is the only one that owns a run
2345    /// of values a copy would have to copy. Every other form already shares what is expensive and
2346    /// owns only what a cut has to rewrite, so it comes back as it was: a dictionary shares its
2347    /// values, a packed body shares its words, a string body shares its arena, an FSST body shares
2348    /// its codes and its table, and a constant and a sequence have nothing to share.
2349    ///
2350    /// Not recursive into a nested column's children, because a `LIST` or a `STRUCT` holds its
2351    /// children behind an `Arc` already.
2352    #[must_use]
2353    pub fn into_pages(self) -> Self {
2354        let body = match self.body {
2355            Body::Flat(data) => Body::Flat(data.into_pages()),
2356            other => other,
2357        };
2358        Self { body, ..self }
2359    }
2360
2361    /// A contiguous run of the values, in the form they are already in.
2362    ///
2363    /// This is the cut [`Self::gather`] cannot do. A gather walks a dictionary to its leaf and
2364    /// copies, so gathering a piece of a dictionary encoded column hands back a flat one, and a
2365    /// caller that only wanted the first thousand rows of a page has silently paid for a copy and
2366    /// thrown the dictionary away. A group by over a dictionary encoded column is the case that
2367    /// cares, and it is most of ClickBench.
2368    ///
2369    /// So each form is cut as itself. A dictionary keeps its dictionary and slices its codes, a
2370    /// sequence stays arithmetic with its start moved along, a constant stays a shorter constant,
2371    /// and a flat body is a window into its page when it has one and a copy of its range when it
2372    /// does not, which [`Self::into_pages`] is how a producer decides.
2373    ///
2374    /// The dictionary itself is shared rather than copied, so a cut is the codes and nothing else.
2375    /// It used to be copied, and on a read of a ClickBench partition that copy was ten percent of
2376    /// the cycles: a page holds one dictionary and is cut into chunk sized pieces, so the whole
2377    /// dictionary was copied once per chunk to be read the same way each time.
2378    ///
2379    /// # Errors
2380    ///
2381    /// If the range runs past the end of the vector, or if the type has no flat layout and the
2382    /// body is one that has to be copied.
2383    pub fn slice(&self, at: usize, len: usize) -> Result<Self> {
2384        let end = at.checked_add(len).ok_or_else(|| Error::internal("a slice that wraps"))?;
2385        if end > self.len {
2386            return Err(Error::internal(format!("rows {at} to {end} of a vector of {}", self.len)));
2387        }
2388        if at == 0 && len == self.len {
2389            return Ok(self.clone());
2390        }
2391        let validity = self.validity.slice(at, len);
2392        let body = match &self.body {
2393            Body::Constant(value) => Body::Constant(value.clone()),
2394            Body::Sequence { start, step } => {
2395                Body::Sequence { start: start + step * at as i64, step: *step }
2396            }
2397            Body::Dictionary { codes, values, stable } => Body::Dictionary {
2398                codes: codes[at..end].to_vec(),
2399                values: Arc::clone(values),
2400                stable: *stable,
2401            },
2402            // The bits are not byte aligned, so a cut either repacks them or moves the row the
2403            // reading starts at. Moving it is one addition and repacking is a pass, and a page is
2404            // cut into chunk sized pieces often enough that the difference is the form.
2405            Body::Packed { words, width, base, offset } => Body::Packed {
2406                words: Arc::clone(words),
2407                width: *width,
2408                base: *base,
2409                offset: offset + at,
2410            },
2411            // The cut a flat string column cannot do. Sixteen bytes a row move and the payload stays
2412            // where the page put it, so taking a chunk out of a column of long strings costs the
2413            // same as taking one out of a column of integers. A flat varchar body copies every byte
2414            // of every long string in the range instead, which is the measurement written down in
2415            // `Chunk::compact`: compaction loses on a varchar column, and this is the half of the
2416            // reason that is about cutting rather than about selecting.
2417            Body::Views { views, arena } => {
2418                Body::Views { views: views[at..end].to_vec(), arena: Arc::clone(arena) }
2419            }
2420            // The spans are absolute positions in the shared codes, so a cut is a run of them and
2421            // nothing has to be rebased. One page of compressed strings, one table, and as many
2422            // chunks over it as the reader wants.
2423            Body::Coded { codes, spans, table } => Body::Coded {
2424                codes: Arc::clone(codes),
2425                spans: spans[at..end].to_vec(),
2426                table: Arc::clone(table),
2427            },
2428            // Only the runs the range touches survive, the first and last of them cut back to where
2429            // the range starts and stops, and every end moved to be relative to the new row zero. A
2430            // cut of a hundred rows out of a column of a hundred million is a handful of runs, which
2431            // is the reason this form is worth cutting as itself rather than copying out.
2432            Body::Runs { ends, values } if len > 0 => {
2433                let first = run_holding(ends, at).unwrap_or(0);
2434                let last = run_holding(ends, end - 1).unwrap_or(first);
2435                let cut: Vec<u32> = ends[first..=last]
2436                    .iter()
2437                    .map(|&stop| stop.min(end as u32) - at as u32)
2438                    .collect();
2439                let values = values.slice(first, last - first + 1)?;
2440                Body::Runs { ends: cut, values: Arc::new(values) }
2441            }
2442            // An empty cut has no run to point at and an empty run length body would be a vector of
2443            // no runs claiming a length, so it comes back as the empty flat vector instead.
2444            Body::Runs { .. } => return self.gather(&[]),
2445            // The entries are absolute positions in the shared child, so a cut is a run of them and
2446            // nothing has to be rebased, the same as a cut of FSST spans. The elements outside the
2447            // range stay in the child unreferenced, which is the trade this form makes: a chunk cut
2448            // out of a page of lists moves eight bytes a row and copies no elements at all.
2449            Body::Nested { entries, child } => {
2450                Body::Nested { entries: entries[at..end].to_vec(), child: Arc::clone(child) }
2451            }
2452            // Every child cut at the same place, because a struct row is one value per field at the
2453            // same position in each and there is no entry standing between the row and the child to
2454            // rewrite instead. So this is the one nested form whose cut is not free, and what it costs
2455            // is whatever cutting each field costs, which for a field of string views is sixteen bytes
2456            // a row and for a field of packed integers is one addition.
2457            Body::Fields { children } => Body::Fields {
2458                children: children
2459                    .iter()
2460                    .map(|child| child.slice(at, len).map(Arc::new))
2461                    .collect::<Result<Vec<_>>>()?,
2462            },
2463            Body::ExternalText { source } => {
2464                let mut out = StringColumn::with_capacity(len);
2465                for index in at..end {
2466                    out.push_bytes(source.bytes_at(index)?.unwrap_or_default());
2467                }
2468                Body::Flat(Data::Varlen(out))
2469            }
2470            // The one form with nowhere to point, so its range is copied out. A run and not a
2471            // gather: this used to build a vector of the positions `at..end` and hand it to
2472            // `gather`, which then built a vector of `usize` from it, a vector of `bool` beside
2473            // that, and read the values back one bounds checked index at a time. That is five
2474            // passes and three allocations to say `memcpy`, and on a scan it was the largest thing
2475            // in the program after the aggregation itself, because every chunk of every column of
2476            // every page comes through here.
2477            Body::Flat(data) => Body::Flat(run_of(data, at, end)),
2478        };
2479        Ok(Self { ty: self.ty.clone(), len, validity, body })
2480    }
2481
2482    /// The same values in flat form.
2483    ///
2484    /// Flattening a vector that is already flat is free. Flattening any other form costs a copy,
2485    /// which is exactly why the other forms exist and why nothing on the hot path should call
2486    /// this. It is here for the operators that genuinely cannot do better and for the tests that
2487    /// check the other forms against it.
2488    ///
2489    /// A call that copies counts itself against [`Cause::Flatten`], because a flatten on a hot path
2490    /// is the most expensive thing in this crate and the only way to find one is to have the number.
2491    /// A call on a vector that is already flat does not count, since it neither copies nor gives
2492    /// anything up.
2493    ///
2494    /// # Errors
2495    ///
2496    /// If the type is one there is no vector for yet, which today means `ARRAY` and `UNION`. A `LIST`
2497    /// and a `MAP` flatten to themselves and a `STRUCT` to a struct of flattened fields, since none of
2498    /// the three has a data slice in any form and there is nothing flatter to become.
2499    pub fn flatten(&self) -> Result<Self> {
2500        if let Body::Flat(_) = self.body {
2501            return Ok(self.clone());
2502        }
2503        slow::took(Cause::Flatten);
2504        self.copied((0..self.len).collect(), false)
2505    }
2506
2507    /// The values at the given positions, copied, in a form that does not point back at this vector.
2508    ///
2509    /// This is the copying counterpart to [`Self::dictionary`], and the two are the two halves of
2510    /// the decision `spec/07-execution.md` section 7.1 describes. Which half is right is measured
2511    /// rather than argued, and [`Chunk::compact`](crate::Chunk::compact) is where the measurement
2512    /// is written down.
2513    ///
2514    /// A dictionary chain is walked to its leaf first and the codes composed on the way down, so the
2515    /// copy runs once over the data rather than once per level, and a position that is null at any
2516    /// level comes out null here. The copy is a typed loop per physical layout rather than a `Value`
2517    /// per row, which is the whole point of it and is what [`Self::flatten`] now goes through too.
2518    ///
2519    /// # Errors
2520    ///
2521    /// If the type is one there is no vector for yet, which today means `ARRAY` and `UNION`. A `LIST`
2522    /// and a `MAP` gather by permuting their entries and a `STRUCT` by gathering every field.
2523    pub fn gather(&self, indices: &[u32]) -> Result<Self> {
2524        self.copied(indices.iter().map(|&index| index as usize).collect(), true)
2525    }
2526
2527    /// The copy both [`Self::gather`] and [`Self::flatten`] are.
2528    ///
2529    /// `forms_stay` is the one thing the two want differently. A gather of a constant is a shorter
2530    /// constant and copying it out would be a thousand writes of the same value for nothing, and a
2531    /// gather of string views is a shorter run of views over the same arena rather than a copy of
2532    /// the bytes. Flattening promises flat form to a caller that is about to read the data slice, so
2533    /// for that one both of them have to be written out.
2534    fn copied(&self, at: Vec<usize>, forms_stay: bool) -> Result<Self> {
2535        let rows = at.len();
2536        if forms_stay {
2537            if let Body::Dictionary { codes, values, stable: true } = &self.body {
2538                let validity = Validity::from_iter(rows, |row| {
2539                    at.get(row).is_some_and(|&index| index < self.len && !self.is_null_at(index))
2540                });
2541                let gathered =
2542                    at.iter().map(|&index| codes.get(index).copied().unwrap_or(0)).collect();
2543                return Ok(
2544                    Self::stable_dictionary(gathered, Arc::clone(values))?.with_validity(validity)
2545                );
2546            }
2547        }
2548        let (at, leaf) = self.resolve(at);
2549        let live: Vec<bool> = at.iter().map(|&index| index != NOWHERE).collect();
2550        let validity = Validity::from_run(&live);
2551        let body = match &leaf.body {
2552            // The same gather the arm below is, for a type that has no flat layout to be written out
2553            // into. It goes through the nested builders rather than through a run of data, because they
2554            // are the one place that knows a row of a list column is a range of a child and a row of a
2555            // struct column is one position in each of several, and a second copy of that here would
2556            // be a second thing to keep in step with them.
2557            Body::Constant(value)
2558                if matches!(
2559                    self.ty,
2560                    LogicalType::List(_) | LogicalType::Struct(_) | LogicalType::Map(_, _)
2561                ) =>
2562            {
2563                if forms_stay && matches!(validity, Validity::AllValid) {
2564                    return Ok(Self::constant(self.ty.clone(), value.as_ref().clone(), rows));
2565                }
2566                let rows: Vec<Value> = at
2567                    .iter()
2568                    .map(
2569                        |&index| {
2570                            if index == NOWHERE { Value::Null } else { value.as_ref().clone() }
2571                        },
2572                    )
2573                    .collect();
2574                return Self::from_values(self.ty.clone(), &rows);
2575            }
2576            // Every position holds the same value, so the only thing the gather can change is the
2577            // length and which positions are null. A gather with no null in it is still a constant.
2578            Body::Constant(value) => {
2579                if forms_stay && matches!(validity, Validity::AllValid) {
2580                    return Ok(Self::constant(self.ty.clone(), value.as_ref().clone(), rows));
2581                }
2582                let mut data = empty_data_for(&self.ty)?;
2583                for &index in &at {
2584                    push_value(&mut data, if index == NOWHERE { &Value::Null } else { value })?;
2585                }
2586                Body::Flat(data)
2587            }
2588            // A sequence is arithmetic rather than storage, so the gather is the arithmetic done at
2589            // the positions asked for, and a null writes the zero every other layout writes.
2590            Body::Sequence { start, step } => Body::Flat(Data::Int64(
2591                at.iter()
2592                    .map(|&index| if index == NOWHERE { 0 } else { start + step * index as i64 })
2593                    .collect(),
2594            )),
2595            // A flat body with no values is the untyped null, so every position asked for is null
2596            // whatever was asked for. Going through the copy would build a run of no values and
2597            // call it `rows` long, which is a vector whose length and data disagree.
2598            Body::Flat(Data::Empty) => {
2599                return Ok(Self::constant(self.ty.clone(), Value::Null, rows));
2600            }
2601            Body::Flat(data) => Body::Flat(copy_of(data, &at)),
2602            // The one form whose copy is arithmetic rather than a move of bytes. It goes through a
2603            // typed loop per layout the way the flat copy does, because the alternative is a `Value`
2604            // per row and this is the path a flatten of a scanned column takes.
2605            Body::Packed { words, width, base, offset } => {
2606                Body::Flat(unpack(&self.ty, words, *offset, *width, *base, &at)?)
2607            }
2608            // A gather keeps the form, which is what makes selecting rows out of a string column
2609            // cost sixteen bytes a row instead of the bytes of the strings. The arena it shares is
2610            // the whole arena and not the part the kept rows point at, so a selection that throws
2611            // most of a page away goes on holding the page. That is the trade the form is: a cut and
2612            // a filter are cheap and the memory comes back when the last vector over the page goes,
2613            // and a caller that wants the bytes narrowed asks for a flatten.
2614            Body::Views { views, arena } if forms_stay => Body::Views {
2615                views: at
2616                    .iter()
2617                    .map(|&index| views.get(index).copied().unwrap_or_else(StringView::empty))
2618                    .collect(),
2619                arena: Arc::clone(arena),
2620            },
2621            // Flattening promises a data slice, so the bytes are copied out into an arena of their
2622            // own and the shared one is let go of. The total is known before any of it is copied,
2623            // the way the flat copy works it out, so the new arena is one allocation.
2624            Body::Views { views, arena } => {
2625                let mut out = StringColumn::with_capacity(at.len());
2626                out.reserve_bytes(
2627                    at.iter()
2628                        .filter_map(|&index| views.get(index))
2629                        .filter(|view| !view.is_inline())
2630                        .map(StringView::len)
2631                        .sum(),
2632                );
2633                for &index in &at {
2634                    let bytes = views.get(index).and_then(|view| view.bytes_in(arena));
2635                    out.push_bytes(bytes.unwrap_or_default());
2636                }
2637                Body::Flat(Data::Varlen(out))
2638            }
2639            Body::ExternalText { source } => {
2640                let mut out = StringColumn::with_capacity(at.len());
2641                for &index in &at {
2642                    out.push_bytes(source.bytes_at(index)?.unwrap_or_default());
2643                }
2644                Body::Flat(Data::Varlen(out))
2645            }
2646            // A gather keeps the form, because the codes do not move and a span survives being put
2647            // in an order the codes are not in. A position that resolved to nowhere gets the empty
2648            // span, which decompresses to no bytes, which is the zero every other layout writes.
2649            Body::Coded { codes, spans, table } if forms_stay => Body::Coded {
2650                codes: Arc::clone(codes),
2651                spans: at
2652                    .iter()
2653                    .map(|&index| spans.get(index).copied().unwrap_or((0, 0)))
2654                    .collect(),
2655                table: Arc::clone(table),
2656            },
2657            // Flattening decompresses, which is the price of the data slice it promises. The scratch
2658            // buffer is reused across rows, so this is one allocation for the whole column rather
2659            // than one per row the way reading it a value at a time would be.
2660            Body::Coded { codes, spans, table } => {
2661                let mut out = StringColumn::with_capacity(at.len());
2662                let mut scratch = Vec::new();
2663                for &index in &at {
2664                    scratch.clear();
2665                    let span = spans
2666                        .get(index)
2667                        .and_then(|&(from, to)| codes.get(from as usize..to as usize));
2668                    if let Some(span) = span {
2669                        table.decompress(span, &mut scratch)?;
2670                    }
2671                    out.push_bytes(&scratch);
2672                }
2673                Body::Flat(Data::Varlen(out))
2674            }
2675            // The entries move and the child does not, which is the same trade the string forms
2676            // make and is why a gather of a list column costs eight bytes a row however long the
2677            // lists are. A position that resolved to nowhere gets a zero length entry, and the mask
2678            // already says it is null, so the entry is never read.
2679            //
2680            // This arm ignores `forms_stay`, unlike every arm above it, because there is nothing
2681            // flatter for a list to become. The other forms are all cheaper ways of writing down a
2682            // column of scalars and flattening gives up the saving to hand back a data slice, and a
2683            // list has no data slice in any form, so a flatten of one is this and a caller reading it
2684            // goes through `list_parts` either way.
2685            Body::Nested { entries, child } => Body::Nested {
2686                entries: at
2687                    .iter()
2688                    .map(|&index| entries.get(index).copied().unwrap_or((0, 0)))
2689                    .collect(),
2690                child: Arc::clone(child),
2691            },
2692            // Every child gathered at the same positions, for the reason the cut cuts every child:
2693            // there are no entries to permute instead, so the permutation happens once per field. The
2694            // positions handed down are the resolved ones, sentinel and all, so a row that resolved to
2695            // nowhere comes back null in each field as well as null here.
2696            //
2697            // `forms_stay` is passed straight through rather than ignored, which is the opposite of
2698            // what the list arm does, and the difference is real. There is nothing flatter for a list
2699            // to become, and a struct is only as flat as its fields are, so a flatten of a struct
2700            // column is a flatten of each field and a caller that asked for data slices gets them.
2701            Body::Fields { children } => Body::Fields {
2702                children: children
2703                    .iter()
2704                    .map(|child| child.copied(at.clone(), forms_stay).map(Arc::new))
2705                    .collect::<Result<Vec<_>>>()?,
2706            },
2707            // Unreachable, because `resolve` walks past both of the forms that point at another
2708            // vector and stops at the first body that does not.
2709            Body::Dictionary { .. } | Body::Runs { .. } => {
2710                return Err(Error::internal(
2711                    "a form that points somewhere survived being resolved",
2712                ));
2713            }
2714        };
2715        Ok(Self { ty: self.ty.clone(), len: rows, validity, body })
2716    }
2717
2718    /// Where each wanted position lives in the first body that is not a dictionary, and that body.
2719    ///
2720    /// A position that is null anywhere on the way down, or past the end of anything on the way
2721    /// down, comes back as [`NOWHERE`]. That single sentinel is what keeps the copy loop from
2722    /// carrying a validity mask alongside the positions it is already walking.
2723    fn resolve(&self, mut at: Vec<usize>) -> (Vec<usize>, &Self) {
2724        let mut source = self;
2725        loop {
2726            for slot in &mut at {
2727                if *slot >= source.len || !source.validity.is_valid(*slot) {
2728                    *slot = NOWHERE;
2729                }
2730            }
2731            source = match &source.body {
2732                Body::Dictionary { codes, values, .. } => {
2733                    for slot in &mut at {
2734                        *slot = match codes.get(*slot) {
2735                            Some(&code) => code as usize,
2736                            None => NOWHERE,
2737                        };
2738                    }
2739                    values.as_ref()
2740                }
2741                // A run length body is a dictionary whose code is worked out from the position
2742                // rather than stored, so the walk down is the same walk with a search where the
2743                // lookup was. `NOWHERE` searches for nothing and stays `NOWHERE`.
2744                Body::Runs { ends, values } => {
2745                    for slot in &mut at {
2746                        *slot = run_holding(ends, *slot).unwrap_or(NOWHERE);
2747                    }
2748                    values.as_ref()
2749                }
2750                _ => return (at, source),
2751            };
2752        }
2753    }
2754}
2755
2756/// So that a kernel can take its operands as either a list of vectors or a list of references.
2757///
2758/// A caller that built a `Vec<Vector>` and a caller whose operands are already somewhere else, in a
2759/// chunk or in an evaluator's scratch, want the same kernel. Without this the second kind has to
2760/// clone every operand into a `Vec` to satisfy the signature, and a clone of a vector is a copy of
2761/// the whole column, so the type would be charging real memory traffic for nothing.
2762impl AsRef<Vector> for Vector {
2763    fn as_ref(&self) -> &Vector {
2764        self
2765    }
2766}
2767
2768/// The bits of a packed vector and what they mean, for a kernel that wants to stay in code space.
2769///
2770/// Borrowed from the vector rather than owning anything, so getting one costs nothing and a kernel
2771/// that finds it cannot use them has given up nothing by asking.
2772#[derive(Debug, Clone, Copy)]
2773pub struct Packed<'a> {
2774    words: &'a [u64],
2775    width: u32,
2776    base: i128,
2777    offset: usize,
2778}
2779
2780impl Packed<'_> {
2781    /// Packed words. A persisted vector also records [`Self::offset`].
2782    #[must_use]
2783    pub fn words(&self) -> &[u64] {
2784        self.words
2785    }
2786
2787    /// Bit offset, in rows, of the first value.
2788    #[must_use]
2789    pub fn offset(&self) -> usize {
2790        self.offset
2791    }
2792
2793    /// How many bits one code takes, between one and [`PACKED_WIDTH_MAX`].
2794    #[must_use]
2795    pub fn width(&self) -> u32 {
2796        self.width
2797    }
2798
2799    /// What zero means, so that the value of a row is the base plus its code.
2800    #[must_use]
2801    pub fn base(&self) -> i128 {
2802        self.base
2803    }
2804
2805    /// The largest value this vector can be holding, whatever it is actually holding.
2806    ///
2807    /// With [`Self::base`] this is the pair a comparison kernel wants first. A literal outside the
2808    /// two answers every row of the vector the same way, which is a whole chunk decided without a
2809    /// bit being read, and that is the case a zone map would have caught if there were one here.
2810    #[must_use]
2811    pub fn ceiling(&self) -> i128 {
2812        self.base + i128::from(u64::MAX >> (u64::BITS - self.width))
2813    }
2814
2815    /// The code of row `row`, which is its value minus [`Self::base`].
2816    ///
2817    /// Out of range rows read as zero rather than panicking, the way every other accessor in this
2818    /// file answers for a row that is not there.
2819    #[must_use]
2820    pub fn code(&self, row: usize) -> u64 {
2821        code_at(self.words, (self.offset + row) * self.width as usize, self.width)
2822    }
2823
2824    /// Which code a value would have, and `None` for a value this vector cannot be holding.
2825    ///
2826    /// The translation a comparison does once per vector so that it does not have to unpack once per
2827    /// row. `None` is the useful answer rather than a failure: it says the literal is outside the
2828    /// packed range, so every row compares against it the same way.
2829    #[must_use]
2830    pub fn code_of(&self, value: i128) -> Option<u64> {
2831        u64::try_from(value.checked_sub(self.base)?).ok().filter(|&code| code <= self.mask())
2832    }
2833
2834    /// The largest code the width allows.
2835    fn mask(&self) -> u64 {
2836        u64::MAX >> (u64::BITS - self.width)
2837    }
2838}
2839
2840/// The widest a packed code is allowed to be.
2841///
2842/// Sixty three rather than sixty four so that a mask is `u64::MAX >> (64 - width)` with no shift of
2843/// a whole word in it, and reading a code is one branch on whether it straddles rather than two. A
2844/// sixty four bit code saves nothing anyway, since it is the layout it came from.
2845pub const PACKED_WIDTH_MAX: u32 = 63;
2846
2847/// How much smaller packing has to be before it is worth the shift and the mask on every read.
2848///
2849/// Two, so a column packs when the bits come to half the flat size or less. A column that would save
2850/// a tenth stays flat, because a tenth of a column is not worth turning every read of it into
2851/// arithmetic, and the whole argument for the form is that a narrow column saves most of itself.
2852pub const PACKING_PAYS_AT: usize = 2;
2853
2854/// How much smaller compressing has to be before it is worth a decompression on every read.
2855///
2856/// Two, the same rule packing follows and for the same reason. FSST gets about that on text, so a
2857/// column of English or of URLs compresses and a column of short codes or of random bytes does not,
2858/// which is the right answer for both.
2859pub const FSST_PAYS_AT: usize = 2;
2860
2861/// The codes of a compressed column and the table they are against.
2862///
2863/// Handed out by [`Vector::coded_parts`] so a kernel can work in code space. Nothing here
2864/// decompresses, which is the point: [`Self::encode`] puts the literal into the same space the rows
2865/// are already in, and after that an equality test is a byte slice comparison.
2866#[derive(Debug, Clone, Copy)]
2867pub struct Coded<'a> {
2868    codes: &'a [u8],
2869    spans: &'a [(u32, u32)],
2870    table: &'a SymbolTable,
2871}
2872
2873impl Coded<'_> {
2874    /// The table every row in this vector is compressed against.
2875    #[must_use]
2876    pub fn table(&self) -> &SymbolTable {
2877        self.table
2878    }
2879
2880    /// The code bytes of one row, still compressed.
2881    #[must_use]
2882    pub fn row(&self, row: usize) -> Option<&[u8]> {
2883        let &(from, to) = self.spans.get(row)?;
2884        self.codes.get(from as usize..to as usize)
2885    }
2886
2887    /// Some bytes in the code space this vector is in.
2888    ///
2889    /// The literal side of an equality filter. Compressing is a function of the table and the bytes,
2890    /// so two strings compress to the same codes exactly when they are the same string, and an
2891    /// equality test on the codes is an equality test on the strings with no decompression in it.
2892    #[must_use]
2893    pub fn encode(&self, bytes: &[u8]) -> Vec<u8> {
2894        let mut out = Vec::with_capacity(bytes.len());
2895        self.table.compress(bytes, &mut out);
2896        out
2897    }
2898}
2899
2900/// The first `len` of a run of some narrower signed width, sign extended into `out`.
2901///
2902/// Written once and called from the three narrow arms of [`Data::signed_block`], so that the sign
2903/// extension is one loop the compiler can widen rather than three written out by hand.
2904fn widen<T: Copy + Into<i64>>(run: &[T], len: usize, out: &mut Vec<i64>) -> bool {
2905    match run.get(..len) {
2906        Some(run) => {
2907            out.extend(run.iter().map(|&x| x.into()));
2908            true
2909        }
2910        None => false,
2911    }
2912}
2913
2914/// One holder's share of a part that several vectors are reading at the same time.
2915///
2916/// The rule [`Buffer::footprint`] already uses for a shared page. Everything holding the part asks
2917/// this, so what they say between them comes to about what the part costs rather than to the part
2918/// times the number of them, and the answer is never zero for a part that costs anything, because a
2919/// caller with a reference is at least one holder.
2920fn share<T: ?Sized>(bytes: usize, held: &Arc<T>) -> usize {
2921    bytes / Arc::strong_count(held).max(1)
2922}
2923
2924/// How many words hold `len` codes of `width` bits.
2925fn words_for(len: usize, width: u32) -> usize {
2926    (len * width as usize).div_ceil(u64::BITS as usize)
2927}
2928
2929/// The lowest and highest value a type's layout can hold, and `None` for a type with no integer one.
2930///
2931/// This is also the test of whether a type can be packed at all, and it is the only one, so the
2932/// layouts listed here and the layouts [`pack`] and [`unpack`] know how to walk are the same list
2933/// from the same macro and cannot drift apart.
2934fn layout_range(ty: &LogicalType) -> Option<(i128, i128)> {
2935    use rudb_common::PhysicalType as P;
2936    macro_rules! ranges {
2937        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
2938            match ty.physical() {
2939                $(P::$variant => Some((i128::from(<$native>::MIN), i128::from(<$native>::MAX))),)+
2940                _ => None,
2941            }
2942        };
2943    }
2944    crate::for_each_layout!(exact, ranges)
2945}
2946
2947/// The lowest and highest value in the first `len` slots of a run of integer data.
2948///
2949/// `None` for data that is not integers, which is what says a column cannot be packed. The null
2950/// slots are in the span, holding whatever zero was written into them, which
2951/// [`Vector::bit_packed`] says more about.
2952fn span_of(data: &Data, len: usize) -> Option<(i128, i128)> {
2953    macro_rules! spans {
2954        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
2955            match data {
2956                $(Data::$variant(values) => {
2957                    let mut low = i128::MAX;
2958                    let mut high = i128::MIN;
2959                    for &value in values.as_slice().iter().take(len) {
2960                        let value = i128::from(value);
2961                        low = low.min(value);
2962                        high = high.max(value);
2963                    }
2964                    (low <= high).then_some((low, high))
2965                })+
2966                _ => None,
2967            }
2968        };
2969    }
2970    crate::for_each_layout!(exact, spans)
2971}
2972
2973/// The first `len` values of a run of integer data, written out as codes of `width` bits from `base`.
2974fn pack(data: &Data, len: usize, base: i128, width: u32) -> Vec<u64> {
2975    let mut words = vec![0u64; words_for(len, width)];
2976    macro_rules! packing {
2977        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
2978            match data {
2979                $(Data::$variant(values) => {
2980                    for (row, &value) in values.as_slice().iter().take(len).enumerate() {
2981                        // In range because `base` and `width` came from the span of this same run.
2982                        let code = u64::try_from(i128::from(value) - base).unwrap_or(0);
2983                        write_code(&mut words, row * width as usize, width, code);
2984                    }
2985                })+
2986                _ => {}
2987            }
2988        };
2989    }
2990    crate::for_each_layout!(exact, packing);
2991    words
2992}
2993
2994/// The codes at the given rows, unpacked into the flat layout the type calls for.
2995///
2996/// A row of [`NOWHERE`] writes the layout's zero, which is the rule [`copy_of`] follows for the same
2997/// reason: every layout here is a parallel array to a validity mask, so a null takes a slot.
2998///
2999/// # Errors
3000///
3001/// If the type has no flat layout, which a packed vector cannot have and which is checked when one
3002/// is built, so an error here is a bug rather than a caller mistake.
3003fn unpack(
3004    ty: &LogicalType,
3005    words: &[u64],
3006    offset: usize,
3007    width: u32,
3008    base: i128,
3009    at: &[usize],
3010) -> Result<Data> {
3011    let mut out = empty_data_for(ty)?;
3012    let value_of = |row: usize| {
3013        if row == NOWHERE {
3014            return None;
3015        }
3016        Some(base + i128::from(code_at(words, (offset + row) * width as usize, width)))
3017    };
3018    macro_rules! unpacking {
3019        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3020            match &mut out {
3021                $(Data::$variant(values) => {
3022                    values.reserve(at.len());
3023                    for &row in at {
3024                        // In range because both ends of it were checked when the vector was built.
3025                        let value = value_of(row)
3026                            .and_then(|value| <$native>::try_from(value).ok())
3027                            .unwrap_or($zero);
3028                        values.push(value);
3029                    }
3030                })+
3031                _ => {
3032                    return Err(Error::internal(format!(
3033                        "a {ty} vector was packed, which no integer layout allows"
3034                    )));
3035                }
3036            }
3037        };
3038    }
3039    crate::for_each_layout!(exact, unpacking);
3040    Ok(out)
3041}
3042
3043/// The `width` bits starting at `bit`, low end first.
3044///
3045/// Zero for bits past the end of the words, which keeps a read of a row that is not there from
3046/// panicking and matches what every other accessor here does with one.
3047fn code_at(words: &[u64], bit: usize, width: u32) -> u64 {
3048    let word = bit / u64::BITS as usize;
3049    let shift = (bit % u64::BITS as usize) as u32;
3050    let mask = u64::MAX >> (u64::BITS - width);
3051    let low = words.get(word).copied().unwrap_or(0) >> shift;
3052    let taken = u64::BITS - shift;
3053    if taken >= width {
3054        return low & mask;
3055    }
3056    // The code straddles two words, and `taken` is under the width here so it is under sixty four,
3057    // which is what makes the shift below one the hardware will do rather than one it refuses.
3058    let high = words.get(word + 1).copied().unwrap_or(0) << taken;
3059    (low | high) & mask
3060}
3061
3062/// Writes `width` bits of `code` starting at `bit`, over words that started out zero.
3063fn write_code(words: &mut [u64], bit: usize, width: u32, code: u64) {
3064    let word = bit / u64::BITS as usize;
3065    let shift = (bit % u64::BITS as usize) as u32;
3066    words[word] |= code << shift;
3067    let taken = u64::BITS - shift;
3068    if taken < width {
3069        words[word + 1] |= code >> taken;
3070    }
3071}
3072
3073/// One level of dictionary out of however many levels were handed to [`Vector::dictionary`].
3074///
3075/// Every dictionary in the system is built through that constructor and every one of them comes
3076/// through here first, so the invariant this maintains is that the vector a dictionary points at is
3077/// never itself a dictionary that could have been composed away. That makes the work a single `if`
3078/// rather than a loop: the inner vector was already composed when it was built, so composing the
3079/// outer codes through it leaves the result no deeper than the inner vector already was.
3080///
3081/// The codes are indexed rather than fetched with `get`, because the caller has already walked the
3082/// whole outer array to check that every code is in range and the inner array is exactly as long as
3083/// the vector those codes were checked against.
3084fn compose(codes: Vec<u32>, values: Arc<Vector>) -> (Vec<u32>, Arc<Vector>) {
3085    // A dictionary carrying a validity of its own is one whose nulls live at this level rather than
3086    // in the values, which is the one thing composition cannot carry down with it.
3087    if !matches!(values.validity, Validity::AllValid) {
3088        return (codes, values);
3089    }
3090    let Body::Dictionary { codes: inner, values: leaf, .. } = &values.body else {
3091        return (codes, values);
3092    };
3093    debug_assert!(
3094        !matches!(leaf.body, Body::Dictionary { .. })
3095            || !matches!(leaf.validity, Validity::AllValid),
3096        "a dictionary was stacked on a dictionary without going through the constructor"
3097    );
3098    // The leaf is handed on as the handle it already is. Nothing here reads it and nothing here
3099    // changes it, so the composed dictionary points at the same values the stacked one did and
3100    // whoever else is holding them keeps holding them. This used to take them out of the `Arc`,
3101    // which copied the whole leaf whenever anybody else was still reading it, and a scan selecting
3102    // rows out of a chunk whose column came from a shared page dictionary is exactly that: the page
3103    // holds the leaf, every chunk cut from the page composes through it, and every one of those
3104    // cuts copied the page's dictionary. TPC-H q21 does it once per thousand rows of `lineitem`.
3105    let composed = codes.iter().map(|&code| inner[code as usize]).collect();
3106    (composed, Arc::clone(leaf))
3107}
3108
3109/// How many rows a run has to cover on average before run length encoding is smaller.
3110///
3111/// A run costs its value plus the four bytes of its end, so on a four byte column a run of two rows
3112/// breaks even and a run of three wins. Wider columns win sooner and narrower ones later, and this
3113/// is the one ratio for all of them because a threshold per width is a table that has to be right
3114/// nine times rather than once. It is a constant with a name so that the sweep that eventually moves
3115/// it has something to move.
3116const RUNS_PAY_AT: usize = 2;
3117
3118/// Which run holds `row`, given ends that are exclusive and increasing.
3119///
3120/// A binary search rather than a scan, because the callers that ask this are the ones that are not
3121/// walking the runs in order: a single value read out of a result set, or a gather at scattered
3122/// positions. Anything walking in order should be reading [`Vector::run_parts`] instead, which is
3123/// what the form is for.
3124fn run_holding(ends: &[u32], row: usize) -> Option<usize> {
3125    let row = u32::try_from(row).ok()?;
3126    let run = match ends.binary_search(&row) {
3127        // The ends are exclusive, so landing exactly on one means the row is the first of the next.
3128        Ok(at) => at + 1,
3129        Err(at) => at,
3130    };
3131    (run < ends.len()).then_some(run)
3132}
3133
3134/// The row each run ends at, for a flat body read alongside the validity that goes with it.
3135///
3136/// Two adjacent nulls are one run, because a reader of either gets a null and cannot tell them
3137/// apart. A null between two equal values is three runs for the same reason, since the null is a
3138/// value of the column as far as anything reading it is concerned.
3139///
3140/// The comparison is per layout rather than per `Value`, which is the whole reason this is a macro.
3141/// A `Value` a row would allocate a string per row on a `VARCHAR` column and would be the exact
3142/// defect `cargo xtask rowloop` exists to fail the build on.
3143fn boundaries(data: &Data, validity: &Validity, len: usize) -> Vec<u32> {
3144    if len == 0 {
3145        return Vec::new();
3146    }
3147    let breaks = |ends: &mut Vec<u32>, mut differs: Box<dyn FnMut(usize, usize) -> bool + '_>| {
3148        for row in 1..len {
3149            let same = match (validity.is_valid(row), validity.is_valid(row - 1)) {
3150                (false, false) => true,
3151                (true, true) => !differs(row, row - 1),
3152                _ => false,
3153            };
3154            if !same {
3155                ends.push(u32::try_from(row).unwrap_or(u32::MAX));
3156            }
3157        }
3158        ends.push(u32::try_from(len).unwrap_or(u32::MAX));
3159    };
3160    let mut ends = Vec::new();
3161    macro_rules! walked {
3162        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3163            match data {
3164                // No values at all, so every row is the same null and the column is one run.
3165                Data::Empty => ends.push(u32::try_from(len).unwrap_or(u32::MAX)),
3166                $(Data::$variant(values) => {
3167                    breaks(&mut ends, Box::new(|a, b| values.get(a) != values.get(b)));
3168                })+
3169                Data::Varlen(values) => {
3170                    breaks(&mut ends, Box::new(|a, b| values.bytes(a) != values.bytes(b)));
3171                }
3172            }
3173        };
3174    }
3175    crate::for_each_layout!(fixed, walked);
3176    ends
3177}
3178
3179/// The position of a value that is not anywhere, because it is null or out of range.
3180///
3181/// `usize::MAX` rather than an `Option<usize>`, because the copy loop's bounds check rejects it for
3182/// free and an `Option` would put a second branch next to the one already there.
3183pub(crate) const NOWHERE: usize = usize::MAX;
3184
3185/// A run of data copied at the given positions, with a zero wherever the position is [`NOWHERE`].
3186///
3187/// A zero and not a skip, because every layout here is a parallel array to a validity mask and a
3188/// short one would put every value after the first null at the wrong index. It is the same rule
3189/// [`push_value`] follows for a null.
3190/// A contiguous run of a flat body, copied out.
3191///
3192/// The counterpart to [`copy_of`] for the one case that is a range rather than a set of positions,
3193/// which is what [`Vector::slice`] asks for. Every fixed width layout is one `memcpy` and the
3194/// string layout is a run of views and their bytes, where `copy_of` is a bounds checked index and a
3195/// null test per row.
3196///
3197/// The caller has already checked that `end` is inside the vector, and a body whose data is shorter
3198/// than its vector claims is a bug elsewhere, so a short run is clamped rather than reported.
3199///
3200/// A fixed width run over a buffer that is a window into a page does not copy anything, because
3201/// [`Buffer::slice`] moves the offset instead. That is the case a scan over stored memory is in, and
3202/// it is why the flat body is no longer the one form of a vector whose cut costs an allocation.
3203fn run_of(data: &Data, at: usize, end: usize) -> Data {
3204    macro_rules! run {
3205        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3206            match data {
3207                Data::Empty => Data::Empty,
3208                $(Data::$variant(values) => {
3209                    let held = values.len();
3210                    let from = at.min(held);
3211                    let to = end.max(from).min(held);
3212                    if to == end {
3213                        // The whole run is there, so this is a window on a shared page and a copy on
3214                        // an owned one, decided inside the buffer rather than here.
3215                        Data::$variant(values.slice(from, end - from))
3216                    } else {
3217                        let values = values.as_slice();
3218                        let mut out = Buffer::with_capacity(end - at);
3219                        out.extend_from_slice(&values[from..to]);
3220                        // A body shorter than the rows asked for pads with the zero every layout
3221                        // uses for a null, which is the answer `copy_of` gives for a position past
3222                        // the end.
3223                        // row at a time: never runs on a vector whose data matches its length.
3224                        for _ in to..end {
3225                            out.push($zero);
3226                        }
3227                        Data::$variant(out)
3228                    }
3229                })+
3230                // A view says where its bytes are, so a run of rows is not a run of bytes and this
3231                // is the one layout whose cut is still a loop. The total is known before any of it
3232                // is copied, so the arena is one allocation.
3233                Data::Varlen(values) => {
3234                    let views = values.views();
3235                    let mut out = StringColumn::with_capacity(end - at);
3236                    out.reserve_bytes(
3237                        views
3238                            .get(at.min(views.len())..end.min(views.len()))
3239                            .unwrap_or(&[])
3240                            .iter()
3241                            .filter(|view| !view.is_inline())
3242                            .map(StringView::len)
3243                            .sum(),
3244                    );
3245                    // row at a time: see above, the bytes of consecutive rows need not be next to
3246                    // each other.
3247                    for index in at..end {
3248                        out.push_from(values, index);
3249                    }
3250                    Data::Varlen(out)
3251                }
3252            }
3253        };
3254    }
3255    crate::for_each_layout!(fixed, run)
3256}
3257
3258pub(crate) fn copy_of(data: &Data, at: &[usize]) -> Data {
3259    macro_rules! copied {
3260        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3261            match data {
3262                Data::Empty => Data::Empty,
3263                $(Data::$variant(values) => {
3264                    let mut out = Buffer::with_capacity(at.len());
3265                    for &index in at {
3266                        // One bounds check rather than a null test and a bounds check, because
3267                        // `NOWHERE` is past the end of every slice there can be.
3268                        out.push(values.get(index).copied().unwrap_or($zero));
3269                    }
3270                    Data::$variant(out)
3271                })+
3272                // The one layout where a gather is a copy of bytes rather than a copy of fixed
3273                // width slots, and the reason compaction is a decision rather than a default on a
3274                // string column.
3275                Data::Varlen(values) => {
3276                    let mut out = StringColumn::with_capacity(at.len());
3277                    // The bytes are known before any of them are copied, because a view carries its
3278                    // length and the wanted positions are already in hand, so the arena is one
3279                    // allocation rather than a run of doublings that each copy what the last one
3280                    // copied.
3281                    let views = values.views();
3282                    out.reserve_bytes(
3283                        at.iter()
3284                            .filter_map(|&index| views.get(index))
3285                            .filter(|view| !view.is_inline())
3286                            .map(StringView::len)
3287                            .sum(),
3288                    );
3289                    for &index in at {
3290                        out.push_from(values, index);
3291                    }
3292                    Data::Varlen(out)
3293                }
3294            }
3295        };
3296    }
3297    crate::for_each_layout!(fixed, copied)
3298}
3299
3300/// The physical layout a run of data is in, for the check that it matches its type.
3301///
3302/// The two enums name their variants the same way on purpose, so this is one generated arm rather
3303/// than sixteen chances to pair the wrong two up.
3304pub(crate) fn layout_of(data: &Data) -> rudb_common::PhysicalType {
3305    use rudb_common::PhysicalType as P;
3306    macro_rules! layouts {
3307        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3308            match data {
3309                Data::Empty => P::Empty,
3310                $(Data::$variant(_) => P::$variant,)+
3311            }
3312        };
3313    }
3314    crate::for_each_layout!(all, layouts)
3315}
3316
3317/// One value out of a run of data, given what the run means.
3318///
3319/// The match is on the logical type rather than on the data, because the data cannot tell a `DATE`
3320/// from an `INTEGER` and that is the whole reason the two are kept apart.
3321fn value_from(ty: &LogicalType, data: &Data, index: usize) -> Value {
3322    let signed = || data.signed_at(index);
3323    let unsigned = || data.unsigned_at(index);
3324    let value = match ty {
3325        LogicalType::Boolean => match data {
3326            Data::Bool(v) => v.get(index).map(|&x| Value::Boolean(x)),
3327            _ => None,
3328        },
3329        LogicalType::TinyInt => signed().and_then(|x| i8::try_from(x).ok()).map(Value::TinyInt),
3330        LogicalType::SmallInt => signed().and_then(|x| i16::try_from(x).ok()).map(Value::SmallInt),
3331        LogicalType::Integer => signed().and_then(|x| i32::try_from(x).ok()).map(Value::Integer),
3332        LogicalType::BigInt => signed().and_then(|x| i64::try_from(x).ok()).map(Value::BigInt),
3333        LogicalType::HugeInt => signed().map(Value::HugeInt),
3334        LogicalType::UTinyInt => unsigned().and_then(|x| u8::try_from(x).ok()).map(Value::UTinyInt),
3335        LogicalType::USmallInt => {
3336            unsigned().and_then(|x| u16::try_from(x).ok()).map(Value::USmallInt)
3337        }
3338        LogicalType::UInteger => {
3339            unsigned().and_then(|x| u32::try_from(x).ok()).map(Value::UInteger)
3340        }
3341        LogicalType::UBigInt => unsigned().and_then(|x| u64::try_from(x).ok()).map(Value::UBigInt),
3342        LogicalType::UHugeInt => unsigned().map(Value::UHugeInt),
3343        LogicalType::Float => match data {
3344            Data::Float32(v) => v.get(index).map(|&x| Value::Float(x)),
3345            _ => None,
3346        },
3347        LogicalType::Double => match data {
3348            Data::Float64(v) => v.get(index).map(|&x| Value::Double(x)),
3349            _ => None,
3350        },
3351        LogicalType::Decimal { width, scale } => {
3352            signed().map(|unscaled| Value::Decimal { unscaled, width: *width, scale: *scale })
3353        }
3354        LogicalType::Varchar | LogicalType::Blob | LogicalType::Bit => {
3355            data.bytes_at(index).map(|bytes| bytes_as(ty, bytes))
3356        }
3357        LogicalType::Date => signed().and_then(|x| i32::try_from(x).ok()).map(Value::Date),
3358        LogicalType::Time => signed().and_then(|x| i64::try_from(x).ok()).map(Value::Time),
3359        LogicalType::TimeTz => signed().and_then(|x| i64::try_from(x).ok()).map(Value::TimeTz),
3360        LogicalType::Timestamp
3361        | LogicalType::TimestampS
3362        | LogicalType::TimestampMs
3363        | LogicalType::TimestampNs => {
3364            signed().and_then(|x| i64::try_from(x).ok()).map(Value::Timestamp)
3365        }
3366        LogicalType::TimestampTz => {
3367            signed().and_then(|x| i64::try_from(x).ok()).map(Value::TimestampTz)
3368        }
3369        LogicalType::Interval => match data {
3370            Data::Interval(v) => {
3371                v.get(index).map(|&(months, days, micros)| Value::Interval { months, days, micros })
3372            }
3373            _ => None,
3374        },
3375        _ => None,
3376    };
3377    value.unwrap_or(Value::Null)
3378}
3379
3380/// The fields a struct type names, and nothing for any other type.
3381///
3382/// Only a `STRUCT` vector has a [`Body::Fields`] body, and the two are built together, so in practice
3383/// the empty slice is unreachable and is here so that reading a field name is not a panic if that ever
3384/// stops being true. A struct vector whose type has fewer fields than it has children answers about
3385/// the fields it can name, because the zip stops at the shorter of the two.
3386fn fields_of(ty: &LogicalType) -> &[Field] {
3387    match ty {
3388        LogicalType::Struct(fields) => fields,
3389        _ => &[],
3390    }
3391}
3392
3393/// One row of a string column as a value, given what its bytes are meant to be read as.
3394///
3395/// Both forms that hold strings come through here, so a row that is a `BLOB` in a flat column is a
3396/// `BLOB` in a string view column too. Bytes that are not text in a `VARCHAR` column are a null
3397/// rather than a panic, since everything that got in went in as a string and a column that has
3398/// something else in it is a bug somewhere earlier that a read should not turn into a crash.
3399fn bytes_as(ty: &LogicalType, bytes: &[u8]) -> Value {
3400    match ty {
3401        LogicalType::Varchar => {
3402            std::str::from_utf8(bytes).map_or(Value::Null, |text| Value::Varchar(text.to_owned()))
3403        }
3404        LogicalType::Blob | LogicalType::Bit => Value::Blob(bytes.to_vec()),
3405        _ => Value::Null,
3406    }
3407}
3408
3409/// An empty run of data of the right layout for a type.
3410pub(crate) fn empty_data_for(ty: &LogicalType) -> Result<Data> {
3411    use rudb_common::PhysicalType as P;
3412    macro_rules! empties {
3413        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3414            match ty.physical() {
3415                P::Empty => Data::Empty,
3416                $(P::$variant => Data::$variant(Buffer::new()),)+
3417                P::Varlen => Data::Varlen(StringColumn::new()),
3418                other => {
3419                    return Err(Error::not_implemented(format!(
3420                        "a flat vector of {other:?} data, which arrives with the storage layer"
3421                    )));
3422                }
3423            }
3424        };
3425    }
3426    Ok(crate::for_each_layout!(fixed, empties))
3427}
3428
3429/// An empty run of the type's layout with room for `rows` values already taken.
3430///
3431/// For a caller that knows how many values are going in before the first one does, which is a
3432/// producer laying pieces end to end. Growing from empty instead reallocates once per doubling and
3433/// finishes holding a run rounded up to the next power of two, and on a row group of 122,880 values
3434/// that rounding is the last 8,192 of them carried for the life of the table.
3435///
3436/// Bytes are not reserved for a varlen run, because how many of them there are is not the number of
3437/// rows and the caller appending them is the one that can work it out.
3438///
3439/// # Errors
3440///
3441/// If the type has no flat layout, the same as [`empty_data_for`].
3442pub(crate) fn data_for(ty: &LogicalType, rows: usize) -> Result<Data> {
3443    let mut data = empty_data_for(ty)?;
3444    macro_rules! reserved {
3445        ($(($variant:ident, $native:ty, $zero:expr)),+ $(,)?) => {
3446            match &mut data {
3447                Data::Empty => {}
3448                $(Data::$variant(values) => values.reserve(rows),)+
3449                Data::Varlen(values) => values.reserve_views(rows),
3450            }
3451        };
3452    }
3453    crate::for_each_layout!(fixed, reserved);
3454    Ok(data)
3455}
3456
3457/// Appends one value to a run of data, or a zero of the right shape when it is null.
3458///
3459/// The zero matters. A null still occupies a position, the validity mask is what says it is null,
3460/// and a run of data with a hole in it would put every value after the hole in the wrong place.
3461fn push_value(data: &mut Data, value: &Value) -> Result<()> {
3462    macro_rules! push {
3463        ($vec:expr, $variant:path, $zero:expr) => {
3464            match value {
3465                Value::Null => $vec.push($zero),
3466                $variant(x) => $vec.push(*x),
3467                other => {
3468                    return Err(Error::internal(format!(
3469                        "{other:?} does not belong in this vector"
3470                    )));
3471                }
3472            }
3473        };
3474    }
3475    // A decimal is stored as its unscaled integer in whatever width its precision needs, which
3476    // `LogicalType::physical` decides and which is why the same `Value::Decimal` is at home in four
3477    // different runs. The narrowing cannot fail for a value the binder produced, because the width
3478    // that chose the run is the width in the value, but it is checked rather than assumed because
3479    // an unchecked cast here would silently store a different number.
3480    macro_rules! decimal {
3481        ($vec:expr, $ty:ty, $unscaled:expr) => {
3482            match <$ty>::try_from(*$unscaled) {
3483                Ok(x) => $vec.push(x),
3484                Err(_) => {
3485                    return Err(Error::internal(format!(
3486                        "an unscaled decimal of {} does not fit the run its precision chose",
3487                        $unscaled
3488                    )));
3489                }
3490            }
3491        };
3492    }
3493    match data {
3494        Data::Empty => {}
3495        Data::Bool(v) => push!(v, Value::Boolean, false),
3496        Data::Int8(v) => push!(v, Value::TinyInt, 0),
3497        Data::Int16(v) => match value {
3498            Value::Null => v.push(0),
3499            Value::SmallInt(x) => v.push(*x),
3500            Value::Decimal { unscaled, .. } => decimal!(v, i16, unscaled),
3501            other => return Err(Error::internal(format!("{other:?} is not a 16 bit value"))),
3502        },
3503        Data::Int32(v) => match value {
3504            Value::Null => v.push(0),
3505            Value::Integer(x) | Value::Date(x) => v.push(*x),
3506            Value::Decimal { unscaled, .. } => decimal!(v, i32, unscaled),
3507            other => return Err(Error::internal(format!("{other:?} is not a 32 bit value"))),
3508        },
3509        Data::Int64(v) => match value {
3510            Value::Null => v.push(0),
3511            Value::BigInt(x)
3512            | Value::Time(x)
3513            | Value::TimeTz(x)
3514            | Value::Timestamp(x)
3515            | Value::TimestampTz(x) => v.push(*x),
3516            Value::Decimal { unscaled, .. } => decimal!(v, i64, unscaled),
3517            other => return Err(Error::internal(format!("{other:?} is not a 64 bit value"))),
3518        },
3519        Data::Int128(v) => match value {
3520            Value::Null => v.push(0),
3521            Value::HugeInt(x) => v.push(*x),
3522            Value::Decimal { unscaled, .. } => v.push(*unscaled),
3523            other => return Err(Error::internal(format!("{other:?} is not a 128 bit value"))),
3524        },
3525        Data::UInt8(v) => push!(v, Value::UTinyInt, 0),
3526        Data::UInt16(v) => push!(v, Value::USmallInt, 0),
3527        Data::UInt32(v) => push!(v, Value::UInteger, 0),
3528        Data::UInt64(v) => push!(v, Value::UBigInt, 0),
3529        Data::UInt128(v) => push!(v, Value::UHugeInt, 0),
3530        Data::Float32(v) => push!(v, Value::Float, 0.0),
3531        Data::Float64(v) => push!(v, Value::Double, 0.0),
3532        Data::Interval(v) => match value {
3533            Value::Null => v.push((0, 0, 0)),
3534            Value::Interval { months, days, micros } => v.push((*months, *days, *micros)),
3535            other => return Err(Error::internal(format!("{other:?} is not an interval"))),
3536        },
3537        Data::Varlen(column) => match value {
3538            Value::Null => {
3539                column.push("");
3540            }
3541            Value::Varchar(text) => {
3542                column.push(text);
3543            }
3544            // A blob goes in as the bytes it is. The column stores a length and some bytes either
3545            // way, so text is the reading of one rather than a different column, and a blob that
3546            // is not UTF-8 is stored exactly like one that happens to be.
3547            Value::Blob(bytes) => {
3548                column.push_bytes(bytes);
3549            }
3550            other => return Err(Error::internal(format!("{other:?} is not a string"))),
3551        },
3552    }
3553    Ok(())
3554}
3555
3556#[cfg(test)]
3557mod tests {
3558    use std::sync::Arc;
3559
3560    use rudb_common::{Field, LogicalType, Value};
3561
3562    use super::{Body, Data, FSST_PAYS_AT, Form, MAP_KEY, MAP_VALUE, VECTOR_SIZE, Vector};
3563    use crate::buffer::Buffer;
3564    use crate::fsst::SymbolTable;
3565    use crate::string::{StringColumn, StringView};
3566    use crate::validity::Validity;
3567
3568    fn integers(values: &[i32]) -> Vector {
3569        Vector::flat(LogicalType::Integer, Data::Int32(values.to_vec().into())).unwrap()
3570    }
3571
3572    /// A `Value::List` of integers, which is what a row of a list column arrives as.
3573    fn list(values: &[i32]) -> Value {
3574        Value::List {
3575            element: LogicalType::Integer,
3576            values: values.iter().map(|&v| Value::Integer(v)).collect(),
3577        }
3578    }
3579
3580    fn list_column(rows: &[Value]) -> Vector {
3581        Vector::from_values(LogicalType::list(LogicalType::Integer), rows).unwrap()
3582    }
3583
3584    #[test]
3585    fn a_list_column_is_one_child_and_a_range_per_row() {
3586        let rows = vec![list(&[1, 2, 3]), list(&[]), Value::Null, list(&[4])];
3587        let column = list_column(&rows);
3588        assert_eq!(column.form(), Form::List);
3589        assert_eq!(column.len(), 4);
3590        assert_eq!(column.logical_type(), &LogicalType::list(LogicalType::Integer));
3591        // Four rows and four elements, because a null and an empty list both contribute none.
3592        let (entries, child) = column.list_parts().expect("a list");
3593        assert_eq!(entries, [(0, 3), (3, 0), (3, 0), (3, 1)]);
3594        assert_eq!(child.len(), 4);
3595        assert_eq!(column.iter().collect::<Vec<_>>(), rows);
3596    }
3597
3598    /// The one thing the entries cannot say on their own, so it has to be checked that the mask says
3599    /// it. An empty list is a row that is there and holds nothing, a null is a row that is not there,
3600    /// and both of them have an entry of length zero.
3601    #[test]
3602    fn an_empty_list_and_a_null_list_have_the_same_entry_and_are_different_rows() {
3603        let column = list_column(&[list(&[]), Value::Null]);
3604        let (entries, _) = column.list_parts().expect("a list");
3605        assert_eq!(entries[0].1, entries[1].1, "both entries are empty");
3606        assert!(!column.is_null_at(0), "an empty list is not null");
3607        assert!(column.is_null_at(1), "a null list is null");
3608        assert_eq!(column.value_at(0), list(&[]));
3609        assert_eq!(column.value_at(1), Value::Null);
3610    }
3611
3612    #[test]
3613    fn slicing_a_list_column_shares_the_child_rather_than_copying_it() {
3614        let rows: Vec<Value> = (0..64).map(|row| list(&[row, row + 1, row + 2])).collect();
3615        let column = list_column(&rows);
3616        let cut = column.slice(8, 4).unwrap();
3617        assert_eq!(cut.form(), Form::List);
3618        assert_eq!(cut.iter().collect::<Vec<_>>(), rows[8..12]);
3619        // The entries are absolute positions in a child that was not cut, which is what makes the
3620        // cut eight bytes a row however long the lists are. The elements outside the range are still
3621        // there and nothing points at them.
3622        let (entries, child) = cut.list_parts().expect("a list");
3623        assert_eq!(entries[0], (24, 3));
3624        assert_eq!(child.len(), 192);
3625    }
3626
3627    #[test]
3628    fn gathering_a_list_column_permutes_the_entries_and_leaves_the_child_alone() {
3629        let rows = vec![list(&[1]), list(&[2, 2]), list(&[3, 3, 3])];
3630        let column = list_column(&rows);
3631        let picked = column.gather(&[2, 0, 2]).unwrap();
3632        assert_eq!(
3633            picked.iter().collect::<Vec<_>>(),
3634            [list(&[3, 3, 3]), list(&[1]), list(&[3, 3, 3])]
3635        );
3636        // Two of the three rows are the same row, which is the case a run of offsets cannot write
3637        // down and a start and a length can. That is the whole reason this form carries both.
3638        assert_eq!(picked.list_parts().expect("a list").1.len(), 6);
3639    }
3640
3641    #[test]
3642    fn a_gather_past_the_end_of_a_list_column_is_null_rather_than_somebody_elses_elements() {
3643        let column = list_column(&[list(&[1, 2]), list(&[3])]);
3644        let picked = column.gather(&[1, 9]).unwrap();
3645        assert_eq!(picked.value_at(0), list(&[3]));
3646        assert_eq!(picked.value_at(1), Value::Null);
3647    }
3648
3649    #[test]
3650    fn a_list_of_lists_nests_as_far_as_it_is_written() {
3651        let outer = Value::List {
3652            element: LogicalType::list(LogicalType::Integer),
3653            values: vec![list(&[1, 2]), list(&[3])],
3654        };
3655        let column = Vector::from_values(
3656            LogicalType::list(LogicalType::list(LogicalType::Integer)),
3657            std::slice::from_ref(&outer),
3658        )
3659        .unwrap();
3660        assert_eq!(column.value_at(0), outer);
3661        assert_eq!(column.list_parts().expect("a list").1.form(), Form::List);
3662    }
3663
3664    /// A list row is not bytes and not an integer, and a caller that asks for either gets nothing
3665    /// rather than the first element or a length. Both of those would be a wrong answer that a
3666    /// group by or a hash would read without complaining.
3667    #[test]
3668    fn the_scalar_readers_decline_a_list_instead_of_answering_about_its_elements() {
3669        let column = list_column(&[list(&[7])]);
3670        assert_eq!(column.signed_at(0), None);
3671        assert_eq!(column.bytes_at(0), None);
3672        assert_eq!(column.data(), None);
3673    }
3674
3675    fn pair(a: i32, b: &str) -> Value {
3676        Value::Struct(vec![
3677            ("a".to_string(), Value::Integer(a)),
3678            ("b".to_string(), Value::Varchar(b.to_string())),
3679        ])
3680    }
3681
3682    fn pair_type() -> LogicalType {
3683        LogicalType::Struct(vec![
3684            Field::new("a", LogicalType::Integer),
3685            Field::new("b", LogicalType::Varchar),
3686        ])
3687    }
3688
3689    fn pair_column(rows: &[Value]) -> Vector {
3690        Vector::from_values(pair_type(), rows).unwrap()
3691    }
3692
3693    #[test]
3694    fn a_struct_column_is_one_child_per_field_as_long_as_the_column() {
3695        let rows = vec![pair(1, "x"), pair(2, "y"), pair(3, "z")];
3696        let column = pair_column(&rows);
3697        assert_eq!(column.form(), Form::Struct);
3698        assert_eq!(column.len(), 3);
3699        assert_eq!(column.logical_type(), &pair_type());
3700        // Two children rather than two entries and a child, and both of them as long as the column,
3701        // which is the whole difference between this form and the list one.
3702        let children = column.struct_parts().expect("a struct");
3703        assert_eq!(children.len(), 2);
3704        assert_eq!(children[0].len(), 3);
3705        assert_eq!(children[1].len(), 3);
3706        assert_eq!(children[0].logical_type(), &LogicalType::Integer);
3707        assert_eq!(children[1].logical_type(), &LogicalType::Varchar);
3708        assert_eq!(column.iter().collect::<Vec<_>>(), rows);
3709    }
3710
3711    /// Picking one field out of a struct is picking one child, which is the reason this accessor is
3712    /// public. A projection of `s.a` hands back a vector that already exists, so it costs a pointer
3713    /// rather than a pass over the rows, and that is only true while the children are full length.
3714    #[test]
3715    fn one_field_of_a_struct_column_is_a_column_that_is_already_there() {
3716        let column = pair_column(&[pair(10, "x"), pair(20, "y")]);
3717        let field = &column.struct_parts().expect("a struct")[0];
3718        assert_eq!(field.iter().collect::<Vec<_>>(), [Value::Integer(10), Value::Integer(20)]);
3719        assert_eq!(field.signed_at(1), Some(20), "the field is a scalar column and reads like one");
3720    }
3721
3722    /// A null struct is a bit in the mask at the top and nothing deeper, which is how every other type
3723    /// records a null and is what DuckDB does. The row reads as a single null rather than as a struct of
3724    /// nulls, and the fields underneath are still their own columns.
3725    #[test]
3726    fn a_null_struct_is_the_mask_at_the_top_and_not_a_struct_full_of_nulls() {
3727        let column = pair_column(&[pair(1, "x"), Value::Null]);
3728        assert!(!column.is_null_at(0));
3729        assert!(column.is_null_at(1));
3730        assert_eq!(column.value_at(1), Value::Null);
3731        // A struct row whose every field happens to be null is a different row, and it is not null.
3732        let all_null = pair_column(&[Value::Struct(vec![
3733            ("a".to_string(), Value::Null),
3734            ("b".to_string(), Value::Null),
3735        ])]);
3736        assert!(!all_null.is_null_at(0), "a struct of nulls is a row that is there");
3737        assert_ne!(all_null.value_at(0), Value::Null);
3738    }
3739
3740    #[test]
3741    fn slicing_a_struct_column_cuts_every_field_at_the_same_place() {
3742        let rows: Vec<Value> = (0..64).map(|row| pair(row, "s")).collect();
3743        let column = pair_column(&rows);
3744        let cut = column.slice(8, 4).unwrap();
3745        assert_eq!(cut.form(), Form::Struct);
3746        assert_eq!(cut.iter().collect::<Vec<_>>(), rows[8..12]);
3747        // The cut a list column does not have to do. A list shares its child untouched because the
3748        // entries carry the range, and a struct has no entry standing between the row and the child,
3749        // so every child is four rows long here rather than sixty four.
3750        for child in cut.struct_parts().expect("a struct") {
3751            assert_eq!(child.len(), 4);
3752        }
3753    }
3754
3755    #[test]
3756    fn gathering_a_struct_column_gathers_every_field_at_the_same_positions() {
3757        let column = pair_column(&[pair(1, "x"), pair(2, "y"), pair(3, "z")]);
3758        let picked = column.gather(&[2, 0, 2]).unwrap();
3759        assert_eq!(picked.iter().collect::<Vec<_>>(), [pair(3, "z"), pair(1, "x"), pair(3, "z")]);
3760        for child in picked.struct_parts().expect("a struct") {
3761            assert_eq!(child.len(), 3, "a field is as long as the gather, not as the source");
3762        }
3763    }
3764
3765    #[test]
3766    fn a_gather_past_the_end_of_a_struct_column_is_null_in_every_field_and_at_the_top() {
3767        let column = pair_column(&[pair(1, "x"), pair(2, "y")]);
3768        let picked = column.gather(&[1, 9]).unwrap();
3769        assert_eq!(picked.value_at(0), pair(2, "y"));
3770        assert_eq!(picked.value_at(1), Value::Null);
3771        for child in picked.struct_parts().expect("a struct") {
3772            assert!(child.is_null_at(1), "a row that came from nowhere has no field value either");
3773        }
3774    }
3775
3776    /// The names are matched and not counted, because a caller holding a struct value built in a
3777    /// different order from the type's would otherwise get its columns transposed, and that is a wrong
3778    /// answer that reads as a right one.
3779    #[test]
3780    fn the_fields_of_a_struct_value_go_in_by_name_rather_than_by_position() {
3781        let swapped = Value::Struct(vec![
3782            ("b".to_string(), Value::Varchar("x".to_string())),
3783            ("a".to_string(), Value::Integer(1)),
3784        ]);
3785        let column = pair_column(&[swapped]);
3786        assert_eq!(column.value_at(0), pair(1, "x"));
3787        let wrong = Value::Struct(vec![
3788            ("a".to_string(), Value::Integer(1)),
3789            ("c".to_string(), Value::Varchar("x".to_string())),
3790        ]);
3791        let failed = Vector::from_values(pair_type(), &[wrong]);
3792        assert!(failed.is_err(), "a row with no b field is an error rather than a null b");
3793    }
3794
3795    #[test]
3796    fn a_struct_built_from_children_takes_its_field_names_from_the_caller() {
3797        let column = Vector::structure(vec![
3798            ("a".to_string(), integers(&[1, 2, 3])),
3799            ("b".to_string(), integers(&[4, 5, 6])),
3800        ])
3801        .expect("two columns of three");
3802        assert_eq!(column.len(), 3);
3803        assert_eq!(
3804            column.logical_type(),
3805            &LogicalType::Struct(vec![
3806                Field::new("a", LogicalType::Integer),
3807                Field::new("b", LogicalType::Integer),
3808            ])
3809        );
3810        assert_eq!(
3811            column.value_at(1),
3812            Value::Struct(vec![
3813                ("a".to_string(), Value::Integer(2)),
3814                ("b".to_string(), Value::Integer(5)),
3815            ])
3816        );
3817    }
3818
3819    /// The two mistakes this constructor makes easy, both refused rather than stored. A short field is
3820    /// the one that matters: it would be a struct that reads past the end of one of its own children,
3821    /// which is the same mistake `Vector::list` checks for at the other end.
3822    #[test]
3823    fn a_struct_of_uneven_children_or_of_no_children_is_refused() {
3824        let uneven = Vector::structure(vec![
3825            ("a".to_string(), integers(&[1, 2, 3])),
3826            ("b".to_string(), integers(&[4, 5])),
3827        ]);
3828        assert!(uneven.is_err(), "a field shorter than the struct");
3829        assert!(Vector::structure(vec![]).is_err(), "no field to take a length from");
3830    }
3831
3832    #[test]
3833    fn a_struct_of_lists_and_a_list_of_structs_both_nest() {
3834        let ty =
3835            LogicalType::Struct(vec![Field::new("a", LogicalType::list(LogicalType::Integer))]);
3836        let row = Value::Struct(vec![("a".to_string(), list(&[1, 2]))]);
3837        let column = Vector::from_values(ty, std::slice::from_ref(&row)).unwrap();
3838        assert_eq!(column.value_at(0), row);
3839        assert_eq!(column.struct_parts().expect("a struct")[0].form(), Form::List);
3840
3841        let outer = Value::List { element: pair_type(), values: vec![pair(1, "x"), pair(2, "y")] };
3842        let lists =
3843            Vector::from_values(LogicalType::list(pair_type()), std::slice::from_ref(&outer))
3844                .unwrap();
3845        assert_eq!(lists.value_at(0), outer);
3846        assert_eq!(lists.list_parts().expect("a list").1.form(), Form::Struct);
3847    }
3848
3849    fn tags(pairs: &[(&str, &str)]) -> Value {
3850        Value::map(
3851            LogicalType::Varchar,
3852            LogicalType::Varchar,
3853            pairs
3854                .iter()
3855                .map(|&(key, value)| {
3856                    (Value::Varchar(key.to_string()), Value::Varchar(value.to_string()))
3857                })
3858                .collect(),
3859        )
3860    }
3861
3862    fn tag_column(rows: &[Value]) -> Vector {
3863        Vector::from_values(LogicalType::map(LogicalType::Varchar, LogicalType::Varchar), rows)
3864            .unwrap()
3865    }
3866
3867    /// A map is a list of two field structs, which is the whole design, so the test that says so is
3868    /// the one that reaches through both layers and finds the pieces where each of them puts them.
3869    #[test]
3870    fn a_map_column_is_a_list_whose_child_is_a_struct_of_keys_and_values() {
3871        let rows =
3872            vec![tags(&[("a", "b"), ("c", "d")]), tags(&[]), Value::Null, tags(&[("e", "f")])];
3873        let column = tag_column(&rows);
3874        assert_eq!(column.len(), 4);
3875        assert_eq!(
3876            column.logical_type(),
3877            &LogicalType::map(LogicalType::Varchar, LogicalType::Varchar)
3878        );
3879        // The physical form is a list's, because the bytes are a list's. The logical type is what
3880        // remembers it is a map, which is the same split `LogicalType::physical` already makes.
3881        assert_eq!(column.form(), Form::List);
3882        let (entries, child) = column.list_parts().expect("the layout of a list");
3883        assert_eq!(entries, [(0, 2), (2, 0), (2, 0), (2, 1)]);
3884        assert_eq!(child.form(), Form::Struct);
3885        assert_eq!(
3886            child.logical_type(),
3887            &LogicalType::Struct(vec![
3888                Field::new(MAP_KEY, LogicalType::Varchar),
3889                Field::new(MAP_VALUE, LogicalType::Varchar),
3890            ])
3891        );
3892        // And the accessor that reaches through it hands back the two columns rather than the struct.
3893        let (entries, keys, values) = column.map_parts().expect("a map");
3894        assert_eq!(entries.len(), 4);
3895        assert_eq!(keys.text_at(0), Some("a"));
3896        assert_eq!(values.text_at(0), Some("b"));
3897        assert_eq!(column.iter().collect::<Vec<_>>(), rows);
3898    }
3899
3900    /// The same distinction a list has, checked again here rather than assumed from the composition,
3901    /// because the empty map is the one every catalog table in D2 is full of and a null map is what a
3902    /// column with no tags at all would be.
3903    #[test]
3904    fn an_empty_map_and_a_null_map_are_different_rows() {
3905        let column = tag_column(&[tags(&[]), Value::Null]);
3906        assert!(!column.is_null_at(0), "an empty map is a row that is there");
3907        assert!(column.is_null_at(1));
3908        assert_eq!(column.value_at(0), tags(&[]));
3909        assert_eq!(column.value_at(1), Value::Null);
3910        assert_eq!(column.value_at(0).to_string(), "{}");
3911        assert_eq!(column.value_at(1).to_string(), "NULL");
3912    }
3913
3914    /// A map prints `{a=b}` and a struct prints `{'a': b}`, both measured off the pin. They share a
3915    /// layout and they cannot share a printer, which is the one thing about this composition that does
3916    /// not fall out of it.
3917    #[test]
3918    fn a_map_prints_with_equals_signs_and_a_struct_prints_with_quoted_names() {
3919        assert_eq!(tags(&[("a", "b"), ("c", "d")]).to_string(), "{a=b, c=d}");
3920        assert_eq!(pair(1, "x").to_string(), "{'a': 1, 'b': x}");
3921        let numbers = Value::map(
3922            LogicalType::Integer,
3923            LogicalType::Integer,
3924            vec![(Value::Integer(1), Value::Integer(3)), (Value::Integer(2), Value::Integer(4))],
3925        );
3926        assert_eq!(numbers.to_string(), "{1=3, 2=4}");
3927        let null_value = Value::map(
3928            LogicalType::Varchar,
3929            LogicalType::Varchar,
3930            vec![(Value::Varchar("x".to_string()), Value::Null)],
3931        );
3932        assert_eq!(null_value.to_string(), "{x=NULL}");
3933    }
3934
3935    /// A map inherits the list's cut and the list's gather, which is the payoff for storing it as one.
3936    /// Neither of these is code written for maps and both of them are worth a test that says the
3937    /// inheritance works, since the type is rewritten on the way through and a form that came back as a
3938    /// list would still read.
3939    #[test]
3940    fn cutting_and_gathering_a_map_keeps_it_a_map() {
3941        let rows: Vec<Value> =
3942            (0..16).map(|row| tags(&[("k", if row % 2 == 0 { "e" } else { "o" })])).collect();
3943        let column = tag_column(&rows);
3944
3945        let cut = column.slice(4, 3).unwrap();
3946        assert!(matches!(cut.logical_type(), LogicalType::Map(_, _)), "still a map after a cut");
3947        assert_eq!(cut.iter().collect::<Vec<_>>(), rows[4..7]);
3948        // The child was not cut, the same as for a list, which is what makes the cut eight bytes a row.
3949        assert_eq!(cut.map_parts().expect("a map").1.len(), 16);
3950
3951        let picked = column.gather(&[3, 0, 3]).unwrap();
3952        assert!(matches!(picked.logical_type(), LogicalType::Map(_, _)));
3953        assert_eq!(
3954            picked.iter().collect::<Vec<_>>(),
3955            [rows[3].clone(), rows[0].clone(), rows[3].clone()]
3956        );
3957        let past = column.gather(&[0, 99]).unwrap();
3958        assert_eq!(past.value_at(1), Value::Null);
3959    }
3960
3961    #[test]
3962    fn a_map_built_from_two_columns_pairs_them_by_position() {
3963        let keys = Vector::from_values(
3964            LogicalType::Varchar,
3965            &[Value::Varchar("a".to_string()), Value::Varchar("c".to_string())],
3966        )
3967        .unwrap();
3968        let values = Vector::from_values(
3969            LogicalType::Varchar,
3970            &[Value::Varchar("b".to_string()), Value::Varchar("d".to_string())],
3971        )
3972        .unwrap();
3973        let column = Vector::map(vec![(0, 2), (2, 0)], keys, values).expect("two rows");
3974        assert_eq!(column.len(), 2);
3975        assert_eq!(
3976            column.logical_type(),
3977            &LogicalType::map(LogicalType::Varchar, LogicalType::Varchar)
3978        );
3979        assert_eq!(column.value_at(0), tags(&[("a", "b"), ("c", "d")]));
3980        assert_eq!(column.value_at(1), tags(&[]));
3981        // The entry check the list constructor does is the one a map gets, so an entry past the end of
3982        // the pair of columns is refused here too rather than read as somebody else's keys.
3983        let short =
3984            Vector::from_values(LogicalType::Varchar, &[Value::Varchar("a".to_string())]).unwrap();
3985        let other =
3986            Vector::from_values(LogicalType::Varchar, &[Value::Varchar("b".to_string())]).unwrap();
3987        assert!(Vector::map(vec![(0, 9)], short, other).is_err(), "an entry past the end");
3988    }
3989
3990    /// `map_parts` is about the logical type and `list_parts` is about the layout, so a list has to
3991    /// decline the first and a map has to answer the second. Getting that backwards would let a kernel
3992    /// written for maps read a list of two field structs as if it were one.
3993    #[test]
3994    fn a_list_is_not_a_map_however_much_its_child_looks_like_one() {
3995        let pairs = Value::List { element: pair_type(), values: vec![pair(1, "x")] };
3996        let column =
3997            Vector::from_values(LogicalType::list(pair_type()), std::slice::from_ref(&pairs))
3998                .unwrap();
3999        assert!(column.map_parts().is_none(), "a list of structs is a list");
4000        assert!(column.list_parts().is_some());
4001        let map = tag_column(&[tags(&[("a", "b")])]);
4002        assert!(map.map_parts().is_some());
4003        assert!(map.list_parts().is_some(), "a map has a list's layout and says so");
4004    }
4005
4006    /// A struct row is not bytes and not an integer, and it stays that way when it has exactly one
4007    /// integer field, which is the case where answering about the field would look reasonable and would
4008    /// be a hash keyed on the wrong thing.
4009    #[test]
4010    fn the_scalar_readers_decline_a_struct_of_one_integer_field() {
4011        let ty = LogicalType::Struct(vec![Field::new("a", LogicalType::Integer)]);
4012        let row = Value::Struct(vec![("a".to_string(), Value::Integer(7))]);
4013        let column = Vector::from_values(ty, &[row]).unwrap();
4014        assert_eq!(column.signed_at(0), None);
4015        assert_eq!(column.bytes_at(0), None);
4016        assert_eq!(column.data(), None);
4017    }
4018
4019    #[test]
4020    fn a_clustered_column_becomes_runs_and_reads_back_the_same() {
4021        let mut values = Vec::new();
4022        for (value, times) in [(7, 400), (8, 300), (7, 324)] {
4023            values.extend(std::iter::repeat_n(value, times));
4024        }
4025        let flat = integers(&values);
4026        let runs = flat.run_encoded().unwrap();
4027        assert_eq!(runs.form(), Form::Rle);
4028        assert_eq!(runs.run_parts().expect("runs").0, [400, 700, 1024]);
4029        assert_eq!(runs.len(), flat.len());
4030        assert_eq!(runs.iter().collect::<Vec<_>>(), flat.iter().collect::<Vec<_>>());
4031        assert!(
4032            runs.footprint() * 10 < flat.footprint(),
4033            "three runs against a thousand rows: {} against {}",
4034            runs.footprint(),
4035            flat.footprint()
4036        );
4037    }
4038
4039    /// The check is worth having in both directions. A form that is only ever bigger than what it
4040    /// replaced is a form that costs a pass over the column to decide not to use.
4041    #[test]
4042    fn a_column_that_does_not_repeat_is_left_flat() {
4043        let flat = integers(&(0..1024).collect::<Vec<i32>>());
4044        assert_eq!(flat.run_encoded().unwrap().form(), Form::Flat);
4045        // Two runs over four rows is exactly break even on a four byte column, and break even is
4046        // not a reason to change form.
4047        assert_eq!(integers(&[1, 1, 2, 2]).run_encoded().unwrap().form(), Form::Flat);
4048        assert_eq!(integers(&[1, 1, 1, 2, 2]).run_encoded().unwrap().form(), Form::Rle);
4049    }
4050
4051    #[test]
4052    fn two_nulls_beside_each_other_are_one_run_and_a_null_between_two_equals_is_a_break() {
4053        let mut values = vec![Value::Integer(4), Value::Integer(4)];
4054        values.extend([Value::Null, Value::Null, Value::Null]);
4055        values.extend(std::iter::repeat_n(Value::Integer(4), 5));
4056        let flat = Vector::from_values(LogicalType::Integer, &values).unwrap();
4057        let runs = flat.run_encoded().unwrap();
4058        assert_eq!(runs.run_parts().expect("runs").0, [2, 5, 10]);
4059        assert_eq!(runs.iter().collect::<Vec<_>>(), values);
4060    }
4061
4062    #[test]
4063    fn slicing_runs_keeps_them_runs_and_cuts_the_first_and_last_one_back() {
4064        let flat = integers(&[1, 1, 1, 1, 2, 2, 2, 2, 3, 3, 3, 3]);
4065        let runs = flat.run_encoded().unwrap();
4066        let piece = runs.slice(3, 6).unwrap();
4067        assert_eq!(piece.form(), Form::Rle, "the form is the whole point");
4068        assert_eq!(piece.run_parts().expect("runs").0, [1, 5, 6]);
4069        assert_eq!(
4070            piece.iter().collect::<Vec<_>>(),
4071            flat.slice(3, 6).unwrap().iter().collect::<Vec<_>>()
4072        );
4073        assert_eq!(runs.slice(0, 0).unwrap().len(), 0);
4074        assert_eq!(runs.slice(0, 12).unwrap().form(), Form::Rle);
4075    }
4076
4077    #[test]
4078    fn gathering_out_of_runs_walks_to_the_values_the_way_it_walks_a_dictionary() {
4079        let mut values = vec![Value::Varchar("red".into()); 4];
4080        values.extend([Value::Null, Value::Null, Value::Null]);
4081        values.extend(vec![Value::Varchar("blue".into()); 4]);
4082        let runs =
4083            Vector::from_values(LogicalType::Varchar, &values).unwrap().run_encoded().unwrap();
4084        assert_eq!(runs.form(), Form::Rle);
4085        let picked = runs.gather(&[8, 0, 5, 2]).unwrap();
4086        assert_eq!(picked.form(), Form::Flat, "a gather copies, whatever it gathered from");
4087        assert_eq!(
4088            picked.iter().collect::<Vec<_>>(),
4089            [values[8].clone(), values[0].clone(), Value::Null, values[2].clone()]
4090        );
4091        assert_eq!(runs.text_at(1), Some("red"));
4092        assert_eq!(runs.text_at(5), None, "a null has no text");
4093        assert_eq!(runs.flatten().unwrap().iter().collect::<Vec<_>>(), values);
4094    }
4095
4096    /// A run length vector over a run length vector turns one search per row into two, and there is
4097    /// nothing in the engine that builds one, so it is refused rather than composed.
4098    #[test]
4099    fn runs_of_runs_are_refused_and_runs_of_a_dictionary_are_not() {
4100        let inner = integers(&[1, 1, 1, 1, 2]).run_encoded().unwrap();
4101        assert_eq!(inner.form(), Form::Rle);
4102        let error = Vector::runs(vec![2, 8], inner).unwrap_err();
4103        assert!(error.to_string().contains("runs of runs"), "{error}");
4104
4105        let words = Vector::from_values(
4106            LogicalType::Varchar,
4107            &[Value::Varchar("red".into()), Value::Varchar("blue".into())],
4108        )
4109        .unwrap();
4110        let dictionary = Vector::dictionary(vec![1, 0], words).unwrap();
4111        let stacked = Vector::runs(vec![4, 9], dictionary).unwrap();
4112        assert_eq!(stacked.len(), 9);
4113        assert_eq!(stacked.value_at(3), Value::Varchar("blue".into()));
4114        assert_eq!(stacked.value_at(4), Value::Varchar("red".into()));
4115    }
4116
4117    #[test]
4118    fn run_ends_have_to_increase_and_there_is_one_value_for_each_of_them() {
4119        let values = integers(&[1, 2]);
4120        assert!(Vector::runs(vec![4], values.clone()).is_err(), "two values and one run");
4121        assert!(Vector::runs(vec![4, 4], values.clone()).is_err(), "an end that repeats");
4122        assert!(Vector::runs(vec![4, 2], values.clone()).is_err(), "an end that goes backwards");
4123        assert!(Vector::runs(vec![0, 2], values.clone()).is_err(), "a first run holding no rows");
4124        assert_eq!(Vector::runs(vec![4, 9], values).unwrap().len(), 9);
4125    }
4126
4127    #[test]
4128    fn a_form_that_is_already_compact_is_left_where_it_is() {
4129        let constant = Vector::constant(LogicalType::Integer, Value::Integer(1), 1000);
4130        assert_eq!(constant.run_encoded().unwrap().form(), Form::Constant);
4131        assert_eq!(Vector::sequence(0, 1, 1000).run_encoded().unwrap().form(), Form::Sequence);
4132    }
4133
4134    /// What makes one accessor cover both forms. A dictionary hands back the codes it stores and a
4135    /// run length vector works the same numbers out, and a kernel writing `values[at[row]]` reads
4136    /// the same rows out of either.
4137    #[test]
4138    fn both_forms_that_point_somewhere_hand_back_a_position_per_row() {
4139        let words = Vector::from_values(
4140            LogicalType::Varchar,
4141            &[Value::Varchar("red".into()), Value::Varchar("blue".into())],
4142        )
4143        .unwrap();
4144        let runs = Vector::runs(vec![3, 5], words.clone()).unwrap();
4145        let (at, values) = runs.positions().expect("runs point somewhere");
4146        assert_eq!(at.as_ref(), [0, 0, 0, 1, 1]);
4147        assert_eq!(values.value_at(at[3] as usize), runs.value_at(3));
4148
4149        let dictionary = Vector::dictionary(vec![1, 0, 1], words).unwrap();
4150        let (at, values) = dictionary.positions().expect("a dictionary points somewhere");
4151        assert_eq!(at.as_ref(), [1, 0, 1]);
4152        assert_eq!(values.value_at(at[0] as usize), dictionary.value_at(0));
4153
4154        assert!(integers(&[1, 2, 3]).positions().is_none(), "a flat vector points at itself");
4155        assert!(Vector::sequence(0, 1, 4).positions().is_none(), "a sequence stores nothing");
4156    }
4157
4158    #[test]
4159    fn slicing_a_dictionary_keeps_it_a_dictionary_where_gathering_would_not() {
4160        let values = Vector::from_values(
4161            LogicalType::Varchar,
4162            &[Value::Varchar("red".into()), Value::Varchar("blue".into())],
4163        )
4164        .unwrap();
4165        let vector = Vector::dictionary(vec![0, 1, 1, 0, 1], values).unwrap();
4166
4167        let piece = vector.slice(1, 3).unwrap();
4168        assert_eq!(piece.form(), Form::Dictionary, "the form is the whole point");
4169        assert_eq!(piece.len(), 3);
4170        assert_eq!(
4171            piece.iter().collect::<Vec<_>>(),
4172            [
4173                Value::Varchar("blue".into()),
4174                Value::Varchar("blue".into()),
4175                Value::Varchar("red".into())
4176            ]
4177        );
4178        assert_eq!(vector.gather(&[1, 2, 3]).unwrap().form(), Form::Flat, "which a gather loses");
4179    }
4180
4181    #[test]
4182    fn slicing_a_dictionary_shares_the_dictionary_rather_than_copying_it() {
4183        // The assertion is about the address and not about the values, because the values were
4184        // right when the dictionary was copied too. A page holds one dictionary and is cut into a
4185        // chunk of codes at a time, so copying the dictionary here is a copy of every string in it
4186        // per chunk, and on a read of a ClickBench partition it was ten percent of the cycles.
4187        let values = Vector::from_values(
4188            LogicalType::Varchar,
4189            &[Value::Varchar("red".into()), Value::Varchar("blue".into())],
4190        )
4191        .unwrap();
4192        let vector = Vector::dictionary(vec![0, 1, 1, 0, 1], values).unwrap();
4193        let Body::Dictionary { values: whole, .. } = &vector.body else {
4194            panic!("a dictionary vector holds a dictionary");
4195        };
4196
4197        let piece = vector.slice(1, 3).unwrap();
4198        let Body::Dictionary { codes, values: cut, .. } = &piece.body else {
4199            panic!("a slice of a dictionary is a dictionary");
4200        };
4201        assert!(Arc::ptr_eq(whole, cut), "the cut copied the dictionary");
4202        assert_eq!(codes, &[1, 1, 0], "the codes are the part that is cut");
4203
4204        // And a cut of a cut shares it too, since that is what a scan does to a page it reads twice.
4205        let again = piece.slice(1, 2).unwrap();
4206        let Body::Dictionary { values: cut, .. } = &again.body else {
4207            panic!("a slice of a slice of a dictionary is a dictionary");
4208        };
4209        assert!(Arc::ptr_eq(whole, cut), "the second cut copied the dictionary");
4210        assert_eq!(
4211            again.iter().collect::<Vec<_>>(),
4212            [Value::Varchar("blue".into()), Value::Varchar("red".into())]
4213        );
4214    }
4215
4216    #[test]
4217    fn a_slice_carries_the_nulls_that_were_in_its_range_and_not_the_others() {
4218        let vector =
4219            integers(&[1, 2, 3, 4]).with_validity(Validity::from_run(&[false, true, false, true]));
4220        let piece = vector.slice(1, 2).unwrap();
4221        assert!(piece.validity().is_valid(0));
4222        assert!(!piece.validity().is_valid(1));
4223        assert_eq!(piece.value_at(1), Value::Null);
4224    }
4225
4226    #[test]
4227    fn slicing_a_sequence_moves_its_start_rather_than_writing_the_values_out() {
4228        let vector = Vector::sequence(100, 5, 10);
4229        let piece = vector.slice(3, 4).unwrap();
4230        assert_eq!(piece.form(), Form::Sequence);
4231        assert_eq!(
4232            piece.iter().collect::<Vec<_>>(),
4233            [Value::BigInt(115), Value::BigInt(120), Value::BigInt(125), Value::BigInt(130)]
4234        );
4235    }
4236
4237    #[test]
4238    fn slicing_a_constant_is_a_shorter_constant() {
4239        let vector = Vector::constant(LogicalType::Integer, Value::Integer(9), 8);
4240        let piece = vector.slice(2, 3).unwrap();
4241        assert_eq!(piece.form(), Form::Constant);
4242        assert_eq!(piece.len(), 3);
4243        assert_eq!(piece.value_at(2), Value::Integer(9));
4244    }
4245
4246    #[test]
4247    fn slicing_the_whole_vector_hands_it_back_as_it_was() {
4248        let vector = integers(&[1, 2, 3]);
4249        assert_eq!(
4250            vector.slice(0, 3).unwrap().iter().collect::<Vec<_>>(),
4251            [Value::Integer(1), Value::Integer(2), Value::Integer(3)]
4252        );
4253    }
4254
4255    #[test]
4256    fn cutting_a_flat_body_answers_what_gathering_the_same_rows_answers() {
4257        // The cut of a flat body used to be written as a gather over the positions in the range,
4258        // and it is now a run copied out, so the two have to keep saying the same thing. Every
4259        // start and every length, with nulls in the range and out of it, since the validity is the
4260        // half of this that changed shape.
4261        let rows: Vec<i32> = (0..70).collect();
4262        let valid: Vec<bool> = (0..70).map(|row| row % 7 != 0 && row % 11 != 3).collect();
4263        let vector = integers(&rows).with_validity(Validity::from_run(&valid));
4264        for at in 0..70usize {
4265            for len in 0..=(70 - at) {
4266                let cut = vector.slice(at, len).unwrap();
4267                let positions: Vec<u32> = (at..at + len).map(|row| row as u32).collect();
4268                let gathered = vector.gather(&positions).unwrap();
4269                assert_eq!(cut.len(), len, "rows {at} to {}", at + len);
4270                assert_eq!(
4271                    cut.iter().collect::<Vec<_>>(),
4272                    gathered.iter().collect::<Vec<_>>(),
4273                    "rows {at} to {}",
4274                    at + len
4275                );
4276            }
4277        }
4278    }
4279
4280    /// The flat body used to be the one form of a vector whose cut cost an allocation and a copy,
4281    /// and it is not any more when its buffer is a run inside a page. Asserted on the address,
4282    /// because the values are the same either way and the address is the whole claim.
4283    #[test]
4284    fn cutting_a_flat_body_over_a_page_does_not_copy_it() {
4285        let page = Arc::new((0i64..64).collect::<Vec<_>>());
4286        let address = page.as_ptr() as usize;
4287        let data = Data::Int64(Buffer::from_arc(Arc::clone(&page)));
4288        let vector = Vector::flat(LogicalType::BigInt, data).unwrap();
4289        let cut = vector.slice(16, 8).unwrap();
4290        assert_eq!(cut.form(), Form::Flat);
4291        assert_eq!(cut.len(), 8);
4292        let Some(Data::Int64(run)) = cut.data() else {
4293            panic!("the layout changed under the test")
4294        };
4295        assert!(run.is_shared(), "the cut copied the run out of the page");
4296        assert_eq!(run.as_slice().as_ptr() as usize, address + 16 * 8);
4297        assert_eq!(run.as_slice(), &(16i64..24).collect::<Vec<_>>()[..]);
4298        assert_eq!(cut.value_at(0), Value::BigInt(16));
4299        // And the same cut of an owned run says the same thing, by copying it.
4300        let owned = Vector::flat(LogicalType::BigInt, Data::Int64((0i64..64).collect())).unwrap();
4301        let copied = owned.slice(16, 8).unwrap();
4302        let Some(Data::Int64(run)) = copied.data() else {
4303            panic!("the layout changed under the test")
4304        };
4305        assert!(!run.is_shared());
4306        assert_eq!(run.as_slice(), &(16i64..24).collect::<Vec<_>>()[..]);
4307    }
4308
4309    /// `into_pages` is how a producer says its values will be handed out many times. A flat body is
4310    /// the form it changes, and after it a copy of the vector is a reference count bump.
4311    #[test]
4312    fn a_vector_over_pages_is_copied_and_cut_without_its_values_moving() {
4313        let vector = integers(&[1, 2, 3, 4, 5, 6, 7, 8]).into_pages();
4314        let address = |vector: &Vector| match vector.data() {
4315            Some(Data::Int32(values)) => values.as_slice().as_ptr() as usize,
4316            _ => panic!("the layout changed under the test"),
4317        };
4318        let stored = address(&vector);
4319        assert_eq!(address(&vector.clone()), stored, "a copy moved the values");
4320        assert_eq!(address(&vector.slice(2, 4).unwrap()), stored + 2 * 4, "a cut moved the values");
4321        assert_eq!(
4322            vector.slice(2, 4).unwrap().iter().collect::<Vec<_>>(),
4323            [Value::Integer(3), Value::Integer(4), Value::Integer(5), Value::Integer(6)]
4324        );
4325        // Twice is not two pages.
4326        assert_eq!(address(&vector.clone().into_pages()), stored);
4327    }
4328
4329    /// Every form that is not flat already shares what is expensive, so this is a no op on them and
4330    /// in particular does not flatten anything. A form that came back flat would be a column that
4331    /// lost its encoding on the way into a table.
4332    #[test]
4333    fn putting_a_vector_on_pages_does_not_change_any_other_form() {
4334        let dictionary = Vector::dictionary(
4335            vec![0, 1, 0, 1],
4336            Vector::from_values(
4337                LogicalType::Varchar,
4338                &[Value::Varchar("a".into()), Value::Varchar("b".into())],
4339            )
4340            .unwrap(),
4341        )
4342        .unwrap();
4343        let cases = [
4344            Vector::constant(LogicalType::Integer, Value::Integer(9), 4),
4345            Vector::sequence(4, 0, 1),
4346            dictionary,
4347        ];
4348        for vector in cases {
4349            let form = vector.form();
4350            let paged = vector.clone().into_pages();
4351            assert_eq!(paged.form(), form, "{form:?} changed form");
4352            assert_eq!(paged.iter().collect::<Vec<_>>(), vector.iter().collect::<Vec<_>>());
4353        }
4354    }
4355
4356    #[test]
4357    fn cutting_a_flat_string_column_answers_what_gathering_it_answers() {
4358        // The string layout is the one whose cut is still a loop, and it is also the one where a
4359        // row is a view into an arena rather than a slot, so it gets the same treatment separately.
4360        // Both inline and out of line strings, since they are copied by different paths.
4361        let rows: Vec<String> =
4362            (0..40).map(|row| "x".repeat(row % 30) + &row.to_string()).collect();
4363        let values: Vec<Value> = rows.iter().map(|row| Value::Varchar(row.clone())).collect();
4364        let vector = Vector::from_values(LogicalType::Varchar, &values).unwrap().flatten().unwrap();
4365        assert_eq!(vector.form(), Form::Flat, "the cut under test is the flat one");
4366        for at in 0..40usize {
4367            for len in 0..=(40 - at) {
4368                let cut = vector.slice(at, len).unwrap();
4369                let positions: Vec<u32> = (at..at + len).map(|row| row as u32).collect();
4370                let gathered = vector.gather(&positions).unwrap();
4371                assert_eq!(
4372                    cut.iter().collect::<Vec<_>>(),
4373                    gathered.iter().collect::<Vec<_>>(),
4374                    "rows {at} to {}",
4375                    at + len
4376                );
4377            }
4378        }
4379    }
4380
4381    #[test]
4382    fn a_slice_past_the_end_is_an_error_rather_than_a_short_vector() {
4383        let error = integers(&[1, 2, 3]).slice(2, 2).unwrap_err();
4384        assert!(error.to_string().contains("of a vector of 3"), "{error}");
4385    }
4386
4387    #[test]
4388    fn the_vector_size_is_the_one_the_design_is_built_around() {
4389        // 8192, which is four times DuckDB's 2048, measured in #480 against 1024, 2048, 4096 and
4390        // 32768. What the rest of the code assumes about it is not the value but the shape: a
4391        // multiple of 1024, which is the FastLanes unit and is what makes a validity mask a whole
4392        // number of u64 words with none of them half used.
4393        assert_eq!(VECTOR_SIZE, 8192);
4394        assert_eq!(VECTOR_SIZE % 1024, 0);
4395        assert_eq!(VECTOR_SIZE % 64, 0);
4396        assert_eq!(VECTOR_SIZE / 64, 128, "the words in a validity mask");
4397    }
4398
4399    #[test]
4400    fn a_flat_vector_reads_back_what_was_put_in_it() {
4401        let vector = integers(&[1, 2, 3]);
4402        assert_eq!(vector.form(), Form::Flat);
4403        assert_eq!(vector.len(), 3);
4404        assert_eq!(vector.value_at(1), Value::Integer(2));
4405        assert_eq!(
4406            vector.iter().collect::<Vec<_>>(),
4407            vec![Value::Integer(1), Value::Integer(2), Value::Integer(3)]
4408        );
4409    }
4410
4411    #[test]
4412    fn a_vector_built_from_values_reads_the_same_values_back() {
4413        let vector = Vector::from_values(
4414            LogicalType::Varchar,
4415            &[
4416                Value::Varchar("a".to_string()),
4417                Value::Null,
4418                Value::Varchar("a string too long to sit inside a view".to_string()),
4419            ],
4420        )
4421        .expect("strings and a null");
4422        assert_eq!(vector.len(), 3);
4423        assert_eq!(vector.value_at(0), Value::Varchar("a".to_string()));
4424        assert_eq!(vector.value_at(1), Value::Null);
4425        assert_eq!(
4426            vector.value_at(2),
4427            Value::Varchar("a string too long to sit inside a view".to_string())
4428        );
4429    }
4430
4431    /// A null still occupies a position. If it did not then every value after it would read back
4432    /// one place to the left, which is the kind of bug that looks like a storage bug for a week.
4433    #[test]
4434    fn a_null_in_the_middle_does_not_move_the_values_after_it() {
4435        let vector = Vector::from_values(
4436            LogicalType::Integer,
4437            &[Value::Integer(1), Value::Null, Value::Integer(3)],
4438        )
4439        .expect("integers and a null");
4440        assert_eq!(vector.value_at(2), Value::Integer(3));
4441        assert!(vector.validity().has_nulls(3), "the middle one is null");
4442    }
4443
4444    #[test]
4445    fn a_value_the_type_cannot_hold_is_refused() {
4446        let wrong = Vector::from_values(LogicalType::Integer, &[Value::Varchar("x".to_string())]);
4447        assert!(wrong.is_err(), "a string is not an integer");
4448    }
4449
4450    #[test]
4451    fn a_type_that_does_not_match_its_layout_is_refused_at_construction() {
4452        // One comparison here against a wrong answer read out three layers later.
4453        let wrong = Vector::flat(LogicalType::Varchar, Data::Int32(vec![1].into()));
4454        assert!(wrong.is_err());
4455        let right = Vector::flat(LogicalType::Date, Data::Int32(vec![1].into()));
4456        assert!(right.is_ok(), "a date is stored in an i32 and that has to be allowed");
4457    }
4458
4459    #[test]
4460    fn a_constant_vector_costs_one_value_whatever_its_length() {
4461        let vector = Vector::constant(LogicalType::Integer, Value::Integer(7), VECTOR_SIZE);
4462        assert_eq!(vector.form(), Form::Constant);
4463        assert_eq!(vector.len(), VECTOR_SIZE);
4464        assert_eq!(vector.value_at(0), Value::Integer(7));
4465        assert_eq!(vector.value_at(VECTOR_SIZE - 1), Value::Integer(7));
4466        assert_eq!(vector.value_at(VECTOR_SIZE), Value::Null, "past the end is null, not a panic");
4467    }
4468
4469    #[test]
4470    fn a_constant_null_is_all_invalid_without_being_told() {
4471        let vector = Vector::constant(LogicalType::Integer, Value::Null, 8);
4472        assert_eq!(vector.validity(), &Validity::AllInvalid);
4473        assert_eq!(vector.value_at(3), Value::Null);
4474    }
4475
4476    #[test]
4477    fn a_sequence_vector_is_sixteen_bytes_of_row_identifiers() {
4478        let vector = Vector::sequence(100, 1, VECTOR_SIZE);
4479        assert_eq!(vector.form(), Form::Sequence);
4480        assert_eq!(vector.value_at(0), Value::BigInt(100));
4481        assert_eq!(vector.value_at(923), Value::BigInt(1023));
4482        let stepped = Vector::sequence(0, 5, 4);
4483        assert_eq!(
4484            stepped.iter().collect::<Vec<_>>(),
4485            vec![Value::BigInt(0), Value::BigInt(5), Value::BigInt(10), Value::BigInt(15)]
4486        );
4487    }
4488
4489    #[test]
4490    fn a_dictionary_vector_reads_through_its_codes() {
4491        let mut column = StringColumn::new();
4492        column.push("red");
4493        column.push("green");
4494        let values = Vector::flat(LogicalType::Varchar, Data::Varlen(column)).unwrap();
4495        let vector = Vector::dictionary(vec![0, 1, 1, 0], values).unwrap();
4496        assert_eq!(vector.form(), Form::Dictionary);
4497        assert_eq!(vector.logical_type(), &LogicalType::Varchar);
4498        assert_eq!(vector.value_at(2), Value::Varchar("green".into()));
4499        assert_eq!(vector.len(), 4);
4500    }
4501
4502    /// The accessor a group by keys a string column through, which has to agree with `value_at` on
4503    /// every position or two rows holding one string end up in two groups.
4504    #[test]
4505    fn text_is_read_where_it_already_is_for_the_forms_that_store_it() {
4506        let mut column = StringColumn::new();
4507        column.push("red");
4508        column.push("green");
4509        column.push("");
4510        let flat = Vector::flat(LogicalType::Varchar, Data::Varlen(column)).unwrap();
4511        for index in 0..flat.len() {
4512            assert_eq!(flat.text_at(index).map(str::to_string), text_of(&flat.value_at(index)));
4513        }
4514        let dictionary = Vector::dictionary(vec![1, 0, 1, 2], flat).unwrap();
4515        for index in 0..dictionary.len() {
4516            assert_eq!(
4517                dictionary.text_at(index).map(str::to_string),
4518                text_of(&dictionary.value_at(index))
4519            );
4520        }
4521        assert_eq!(dictionary.text_at(4), None, "past the end");
4522    }
4523
4524    /// The forms and types that have no text to hand back, which a caller answers by falling back
4525    /// to `value_at`. A blob is the one that would be a correctness bug rather than a slow path,
4526    /// since its bytes are not required to be text and it is not a `VARCHAR` either way.
4527    #[test]
4528    fn text_is_refused_where_it_is_not_stored_as_itself() {
4529        let nulls =
4530            Vector::from_values(LogicalType::Varchar, &[Value::Varchar("red".into()), Value::Null])
4531                .unwrap();
4532        assert_eq!(nulls.text_at(0), Some("red"));
4533        assert_eq!(nulls.text_at(1), None, "a null has no text");
4534        let constant = Vector::constant(LogicalType::Varchar, Value::Varchar("red".into()), 3);
4535        assert_eq!(constant.text_at(0), None, "a constant is not stored per position");
4536        assert_eq!(integers(&[1, 2]).text_at(0), None, "an integer is not text");
4537        let mut bytes = StringColumn::new();
4538        bytes.push("red");
4539        let blob = Vector::flat(LogicalType::Blob, Data::Varlen(bytes)).unwrap();
4540        assert_eq!(blob.text_at(0), None, "a blob is not a varchar");
4541    }
4542
4543    /// The accessor a group by keys an integer column through, which has to agree with `value_at`
4544    /// on every position or two rows holding one number end up in two groups.
4545    #[test]
4546    fn a_signed_integer_is_read_where_it_already_is_for_the_forms_that_store_it() {
4547        let flat = integers(&[7, -3, 0, 2]);
4548        for index in 0..flat.len() {
4549            assert_eq!(flat.signed_at(index), signed_of(&flat.value_at(index)), "flat {index}");
4550        }
4551        let dictionary = Vector::dictionary(vec![1, 0, 3, 2], flat).unwrap();
4552        for index in 0..dictionary.len() {
4553            assert_eq!(
4554                dictionary.signed_at(index),
4555                signed_of(&dictionary.value_at(index)),
4556                "dictionary {index}"
4557            );
4558        }
4559        assert_eq!(dictionary.signed_at(4), None, "past the end");
4560
4561        let runs = Vector::runs(vec![2, 5], integers(&[4, 9])).unwrap();
4562        for index in 0..runs.len() {
4563            assert_eq!(runs.signed_at(index), signed_of(&runs.value_at(index)), "run {index}");
4564        }
4565        let constant = Vector::constant(LogicalType::BigInt, Value::BigInt(11), 3);
4566        assert_eq!(constant.signed_at(2), Some(11));
4567        let sequence = Vector::sequence(100, 5, 4);
4568        for index in 0..sequence.len() {
4569            assert_eq!(
4570                sequence.signed_at(index),
4571                signed_of(&sequence.value_at(index)),
4572                "sequence {index}"
4573            );
4574        }
4575    }
4576
4577    /// The forms and types that have no integer to hand back, which a caller answers by falling
4578    /// back to `value_at`.
4579    #[test]
4580    fn a_signed_integer_is_refused_where_it_is_not_stored_as_itself() {
4581        let nulls =
4582            Vector::from_values(LogicalType::BigInt, &[Value::BigInt(4), Value::Null]).unwrap();
4583        assert_eq!(nulls.signed_at(0), Some(4));
4584        assert_eq!(nulls.signed_at(1), None, "a null is not a number");
4585        let packed = integers(&[1, 2, 3, 1]).bit_packed().unwrap();
4586        assert_eq!(packed.signed_at(0), Some(1), "a packed integer is read in code space");
4587        let mut bytes = StringColumn::new();
4588        bytes.push("red");
4589        let text = Vector::flat(LogicalType::Varchar, Data::Varlen(bytes)).unwrap();
4590        assert_eq!(text.signed_at(0), None, "a string is not a number");
4591        let double = Vector::flat(LogicalType::Double, Data::Float64(vec![1.5].into())).unwrap();
4592        assert_eq!(double.signed_at(0), None, "a double is not a signed integer");
4593    }
4594
4595    /// The block form has to agree with the row at a time form on every position of every shape it
4596    /// answers for, because a caller picks one of the two and a group by that read two different
4597    /// numbers for one row would put that row in two groups.
4598    #[test]
4599    fn a_block_of_signed_integers_holds_what_the_row_at_a_time_accessor_hands_back() {
4600        let mut out = Vec::new();
4601        let shapes = [
4602            integers(&[7, -3, 0, 2]),
4603            Vector::flat(LogicalType::Integer, Data::Int32(vec![5, -6, 7].into())).unwrap(),
4604            Vector::flat(LogicalType::SmallInt, Data::Int16(vec![1, -2].into())).unwrap(),
4605            Vector::flat(LogicalType::TinyInt, Data::Int8(vec![-128, 127].into())).unwrap(),
4606            Vector::constant(LogicalType::BigInt, Value::BigInt(11), 3),
4607            Vector::sequence(100, 5, 4),
4608            integers(&[1, 2, 3, 1]).bit_packed().unwrap(),
4609        ];
4610        for column in &shapes {
4611            assert!(column.signed_block(&mut out), "{:?} hands over a block", column.form());
4612            assert_eq!(out.len(), column.len(), "{:?} filled the whole chunk", column.form());
4613            for (index, &held) in out.iter().enumerate() {
4614                assert_eq!(
4615                    Some(i128::from(held)),
4616                    column.signed_at(index),
4617                    "{:?} at {index}",
4618                    column.form()
4619                );
4620            }
4621        }
4622    }
4623
4624    /// What the block form will not answer for, where the caller reads the vector a row at a time
4625    /// instead. A null is not one of them: it writes whatever sits under it and the caller reads the
4626    /// null from the column.
4627    #[test]
4628    fn a_block_is_refused_for_the_shapes_it_would_have_to_gather_or_widen() {
4629        let mut out = Vec::new();
4630        let flat = integers(&[7, -3, 0, 2]);
4631        assert!(!Vector::dictionary(vec![1, 0], flat.clone()).unwrap().signed_block(&mut out));
4632        assert!(!Vector::runs(vec![2, 5], integers(&[4, 9])).unwrap().signed_block(&mut out));
4633        let wide = Vector::flat(LogicalType::HugeInt, Data::Int128(vec![1, 2].into())).unwrap();
4634        assert!(!wide.signed_block(&mut out), "a hugeint does not fit sixty four bits");
4635        let double = Vector::flat(LogicalType::Double, Data::Float64(vec![1.5].into())).unwrap();
4636        assert!(!double.signed_block(&mut out), "a double is not a signed integer");
4637        assert!(out.is_empty(), "a refusal leaves the buffer empty");
4638
4639        let nulls =
4640            Vector::from_values(LogicalType::BigInt, &[Value::BigInt(4), Value::Null]).unwrap();
4641        assert!(nulls.signed_block(&mut out), "a flat column with nulls still hands over");
4642        assert_eq!(out[0], 4);
4643    }
4644
4645    /// Asked once for a chunk, and it has to agree with `is_null_at` asked for every row of it.
4646    #[test]
4647    fn a_vector_says_whether_it_holds_any_null_at_all() {
4648        let flat = integers(&[7, -3, 0, 2]);
4649        assert!(flat.none_null());
4650        let nulls =
4651            Vector::from_values(LogicalType::BigInt, &[Value::BigInt(4), Value::Null]).unwrap();
4652        assert!(!nulls.none_null());
4653        assert!(Vector::dictionary(vec![1, 0], flat.clone()).unwrap().none_null());
4654        // The null is in the dictionary rather than in the mask, which is the case the row at a time
4655        // form reads through for and the reason this one does too.
4656        let holed = Vector::dictionary(vec![0, 0], nulls.clone()).unwrap();
4657        assert!(!holed.none_null(), "a dictionary is read through to its values");
4658        assert!(!holed.is_null_at(0), "and no code points at the null it holds");
4659        assert!(Vector::runs(vec![2, 5], integers(&[4, 9])).unwrap().none_null());
4660        assert!(!Vector::runs(vec![1, 2], nulls).unwrap().none_null());
4661        assert!(Vector::constant(LogicalType::BigInt, Value::BigInt(11), 3).none_null());
4662        assert!(!Vector::constant(LogicalType::BigInt, Value::Null, 3).none_null());
4663    }
4664
4665    /// The integer of a value, for comparing `signed_at` against `value_at` position by position.
4666    fn signed_of(value: &Value) -> Option<i128> {
4667        match value {
4668            Value::TinyInt(x) => Some(i128::from(*x)),
4669            Value::SmallInt(x) => Some(i128::from(*x)),
4670            Value::Integer(x) | Value::Date(x) => Some(i128::from(*x)),
4671            Value::BigInt(x) | Value::Time(x) | Value::Timestamp(x) => Some(i128::from(*x)),
4672            Value::HugeInt(x) | Value::Decimal { unscaled: x, .. } => Some(*x),
4673            _ => None,
4674        }
4675    }
4676
4677    /// The text of a value, for comparing `text_at` against `value_at` position by position.
4678    fn text_of(value: &Value) -> Option<String> {
4679        match value {
4680            Value::Varchar(text) => Some(text.clone()),
4681            _ => None,
4682        }
4683    }
4684
4685    #[test]
4686    fn a_dictionary_code_past_the_end_is_refused() {
4687        // The alternative is a silent read of the wrong value, which is the failure mode the
4688        // entire M3 design has to be careful about.
4689        let values = integers(&[1, 2]);
4690        assert!(Vector::dictionary(vec![0, 2], values).is_err());
4691        // The check runs on the highest code rather than the first bad one, so it has to say that
4692        // no codes at all is fine even when there are no values for them to point at either.
4693        let empty = Vector::dictionary(Vec::new(), integers(&[])).expect("no codes, no values");
4694        assert_eq!(empty.len(), 0);
4695        // And a code of zero against an empty dictionary is still past the end.
4696        assert!(Vector::dictionary(vec![0], integers(&[])).is_err());
4697    }
4698
4699    #[test]
4700    fn every_form_flattens_to_the_same_values_it_reads_out() {
4701        // This is the shape of the equivalence testing in spec/16-testing.md section 16.2, in
4702        // miniature and long before there is an encoded kernel to point it at. A form that reads
4703        // out one way and flattens another is the exact bug that testing exists to catch.
4704        let mut column = StringColumn::new();
4705        column.push("alpha");
4706        column.push("beta");
4707        let dictionary = Vector::dictionary(
4708            vec![1, 0, 1],
4709            Vector::flat(LogicalType::Varchar, Data::Varlen(column)).unwrap(),
4710        )
4711        .unwrap();
4712        let cases = [
4713            Vector::constant(LogicalType::Integer, Value::Integer(3), 5),
4714            Vector::sequence(7, -2, 5),
4715            dictionary,
4716        ];
4717        for vector in cases {
4718            let flat = vector.flatten().unwrap();
4719            assert_eq!(flat.form(), Form::Flat);
4720            assert_eq!(flat.len(), vector.len());
4721            for index in 0..vector.len() {
4722                assert_eq!(flat.value_at(index), vector.value_at(index), "at {index}");
4723            }
4724        }
4725    }
4726
4727    #[test]
4728    fn a_null_still_occupies_a_position_after_flattening() {
4729        // The reason push_value writes a zero for a null rather than skipping it. A run of data
4730        // with a hole in it puts every value after the hole in the wrong place, and the validity
4731        // mask is what says the position is null.
4732        let vector = Vector::sequence(0, 1, 4).with_validity(Validity::from_iter(4, |i| i != 1));
4733        let flat = vector.flatten().unwrap();
4734        assert_eq!(flat.value_at(0), Value::BigInt(0));
4735        assert_eq!(flat.value_at(1), Value::Null);
4736        assert_eq!(flat.value_at(2), Value::BigInt(2));
4737        assert_eq!(flat.value_at(3), Value::BigInt(3));
4738    }
4739
4740    /// A dictionary holds its nulls in the vector it points at, so its own validity is all valid
4741    /// and reading that instead of the values turns a null into whatever zero means for the type.
4742    /// A filter over a nullable column produces exactly this vector, so the bug reaches a result
4743    /// set as `LEFT JOIN` padding that comes back as zeros.
4744    #[test]
4745    fn a_null_behind_a_dictionary_survives_flattening() {
4746        let values =
4747            Vector::from_values(LogicalType::Integer, &[Value::Integer(3), Value::Null]).unwrap();
4748        let dictionary = Vector::dictionary(vec![1, 0, 1], values).unwrap();
4749        let flat = dictionary.flatten().unwrap();
4750        assert_eq!(flat.value_at(0), Value::Null);
4751        assert_eq!(flat.value_at(1), Value::Integer(3));
4752        assert_eq!(flat.value_at(2), Value::Null);
4753    }
4754
4755    /// The property that makes `gather` usable at all: it has to be the same function as reading the
4756    /// wanted positions one at a time, over every form, or compaction changes answers.
4757    #[test]
4758    fn gathering_reads_what_reading_one_position_at_a_time_reads() {
4759        let mut column = StringColumn::new();
4760        column.push("alpha");
4761        column.push("beta");
4762        column.push("gamma");
4763        let cases = [
4764            integers(&[10, 20, 30, 40]),
4765            integers(&[10, 20, 30, 40]).with_validity(Validity::from_iter(4, |i| i != 2)),
4766            Vector::constant(LogicalType::Integer, Value::Integer(9), 4),
4767            Vector::sequence(100, -7, 4),
4768            Vector::sequence(100, -7, 4).with_validity(Validity::from_iter(4, |i| i % 2 == 0)),
4769            Vector::dictionary(
4770                vec![2, 0, 1, 2],
4771                Vector::flat(LogicalType::Varchar, Data::Varlen(column)).unwrap(),
4772            )
4773            .unwrap(),
4774            Vector::dictionary(
4775                vec![1, 0, 1, 0],
4776                Vector::from_values(LogicalType::Integer, &[Value::Integer(5), Value::Null])
4777                    .unwrap(),
4778            )
4779            .unwrap(),
4780        ];
4781        let wanted = [3_u32, 0, 2, 2, 1];
4782        for vector in cases {
4783            let gathered = vector.gather(&wanted).unwrap();
4784            assert_eq!(gathered.len(), wanted.len());
4785            assert_eq!(gathered.logical_type(), vector.logical_type());
4786            for (slot, &index) in wanted.iter().enumerate() {
4787                assert_eq!(
4788                    gathered.value_at(slot),
4789                    vector.value_at(index as usize),
4790                    "slot {slot} of {:?}",
4791                    vector.form()
4792                );
4793            }
4794        }
4795    }
4796
4797    /// A gather past the end is not an error, because the selection that produced the indices is
4798    /// checked by its caller and the one thing that must not happen here is a read of the wrong
4799    /// value. An index nothing answers is null, which is what an outer join pad needs anyway.
4800    #[test]
4801    fn gathering_a_position_that_is_not_there_is_a_null_and_not_a_wrong_value() {
4802        let vector = integers(&[1, 2, 3]);
4803        let gathered = vector.gather(&[2, 9]).unwrap();
4804        assert_eq!(gathered.value_at(0), Value::Integer(3));
4805        assert_eq!(gathered.value_at(1), Value::Null);
4806    }
4807
4808    /// The vector with nothing in it at all, which is what an untyped `NULL` is stored as. Every
4809    /// position asked for is past its end, so the answer is nulls and the length has to be the
4810    /// length that was asked for rather than the length that was there.
4811    #[test]
4812    fn gathering_from_a_vector_of_no_values_is_that_many_nulls() {
4813        let vector = Vector::flat(LogicalType::Null, Data::Empty).unwrap();
4814        let gathered = vector.gather(&[0, 1, 2]).unwrap();
4815        assert_eq!(gathered.len(), 3);
4816        assert_eq!(gathered.value_at(0), Value::Null);
4817        assert_eq!(gathered.value_at(2), Value::Null);
4818    }
4819
4820    /// Every position holds the same value, so a gather with no hole in it has nothing to copy and
4821    /// the result is the constant again rather than a run of a thousand copies of it.
4822    #[test]
4823    fn gathering_a_constant_stays_a_constant() {
4824        let vector = Vector::constant(LogicalType::Integer, Value::Integer(4), 100);
4825        let gathered = vector.gather(&[7, 7, 99]).unwrap();
4826        assert_eq!(gathered.form(), Form::Constant);
4827        assert_eq!(gathered.len(), 3);
4828        assert_eq!(gathered.value_at(2), Value::Integer(4));
4829    }
4830
4831    /// A dictionary over a dictionary is what a second filter over an already filtered chunk builds,
4832    /// and the gather has to walk to the bottom of that chain rather than one step down it. The
4833    /// constructor composes the ordinary chain away, so the one built here is the kind it cannot,
4834    /// which is a level holding nulls of its own.
4835    #[test]
4836    fn gathering_walks_a_dictionary_over_a_dictionary_to_the_values() {
4837        let inner = Vector::dictionary(vec![2, 1, 0], integers(&[7, 8, 9]))
4838            .unwrap()
4839            .with_validity(Validity::from_iter(3, |index| index != 2));
4840        let outer = Vector::dictionary(vec![1, 2], inner).unwrap();
4841        let gathered = outer.gather(&[0, 1]).unwrap();
4842        assert_eq!(gathered.form(), Form::Flat);
4843        assert_eq!(gathered.value_at(0), Value::Integer(8));
4844        assert_eq!(gathered.value_at(1), Value::Null);
4845    }
4846
4847    /// Two filters over one chunk build a dictionary over a dictionary, four conjuncts pushed down
4848    /// separately build four levels of it, and every level is a dependent load on every later read
4849    /// of every row plus a code array that cannot be freed. Composing at construction is one pass
4850    /// over the codes the range check was walking anyway.
4851    #[test]
4852    fn a_dictionary_over_a_dictionary_is_composed_into_one_level() {
4853        let inner = Vector::dictionary(vec![2, 1, 0], integers(&[7, 8, 9])).unwrap();
4854        let outer = Vector::dictionary(vec![1, 2], inner).unwrap();
4855        let (codes, values) = outer.dictionary_parts().unwrap();
4856        assert_eq!(codes, [1, 0]);
4857        assert_eq!(values.form(), Form::Flat);
4858        assert_eq!(outer.value_at(0), Value::Integer(8));
4859        assert_eq!(outer.value_at(1), Value::Integer(7));
4860    }
4861
4862    /// The invariant stated as the thing it is there for, which is that the depth does not grow with
4863    /// the number of filters. Four levels stacked one at a time are one level at the end of it.
4864    #[test]
4865    fn stacking_dictionaries_does_not_make_them_deeper() {
4866        let mut vector = integers(&[10, 20, 30, 40]);
4867        for _ in 0..4 {
4868            vector = Vector::dictionary(vec![3, 2, 1, 0], vector).unwrap();
4869        }
4870        let (codes, values) = vector.dictionary_parts().unwrap();
4871        assert_eq!(values.form(), Form::Flat);
4872        assert_eq!(codes, [0, 1, 2, 3]);
4873        assert_eq!(
4874            vector.iter().collect::<Vec<_>>(),
4875            integers(&[10, 20, 30, 40]).iter().collect::<Vec<_>>()
4876        );
4877    }
4878
4879    /// Composing has to carry the nulls down with it. The values hold them, the codes point at them,
4880    /// and a composed code that lands on a null position is still a null.
4881    #[test]
4882    fn composing_a_dictionary_keeps_the_nulls_its_values_hold() {
4883        let values =
4884            Vector::from_values(LogicalType::Integer, &[Value::Integer(3), Value::Null]).unwrap();
4885        let inner = Vector::dictionary(vec![1, 0, 1], values).unwrap();
4886        let outer = Vector::dictionary(vec![0, 1], inner).unwrap();
4887        assert_eq!(outer.dictionary_parts().unwrap().1.form(), Form::Flat);
4888        assert_eq!(outer.value_at(0), Value::Null);
4889        assert_eq!(outer.value_at(1), Value::Integer(3));
4890    }
4891
4892    /// The one level composition cannot go past. A dictionary that was given a validity of its own is
4893    /// saying its nulls are at that level rather than in the values, and pointing the outer codes
4894    /// straight at the values would read through the holes instead of stopping at them.
4895    #[test]
4896    fn a_dictionary_holding_its_own_nulls_is_not_composed_past() {
4897        let inner = Vector::dictionary(vec![0, 1, 2], integers(&[1, 2, 3]))
4898            .unwrap()
4899            .with_validity(Validity::from_iter(3, |index| index != 1));
4900        let outer = Vector::dictionary(vec![1, 2, 0], inner).unwrap();
4901        assert_eq!(outer.dictionary_parts().unwrap().1.form(), Form::Dictionary);
4902        assert_eq!(outer.value_at(0), Value::Null);
4903        assert_eq!(outer.value_at(1), Value::Integer(3));
4904        assert_eq!(outer.value_at(2), Value::Integer(1));
4905    }
4906
4907    /// The difference between the two questions about nulls, which a group by got wrong. A filtered
4908    /// chunk is dictionary vectors, those are built with every row marked present at their own
4909    /// level, and the nulls are down in the values. So the mask says the row has a value and the
4910    /// row does not.
4911    #[test]
4912    fn a_null_behind_a_dictionary_reads_as_null_even_though_the_mask_says_otherwise() {
4913        let values = Vector::flat(LogicalType::Integer, Data::Int32(vec![0, 7].into()))
4914            .unwrap()
4915            .with_validity(Validity::from_iter(2, |index| index != 0));
4916        let vector = Vector::dictionary(vec![0, 1, 0], values).unwrap();
4917        assert!(vector.validity().is_valid(0), "the mask at this level says present");
4918        assert!(vector.is_null_at(0));
4919        assert!(!vector.is_null_at(1));
4920        assert!(vector.is_null_at(2));
4921        assert!(vector.is_null_at(3), "a row past the end is null");
4922    }
4923
4924    /// The same for runs, which are built the same way and keep their nulls in the same place.
4925    #[test]
4926    fn a_null_inside_a_run_reads_as_null_even_though_the_mask_says_otherwise() {
4927        let values = Vector::flat(LogicalType::Integer, Data::Int32(vec![0, 7].into()))
4928            .unwrap()
4929            .with_validity(Validity::from_iter(2, |index| index != 0));
4930        let vector = Vector::runs(vec![2, 3], values).unwrap();
4931        assert!(vector.validity().is_valid(0));
4932        assert!(vector.is_null_at(0));
4933        assert!(vector.is_null_at(1));
4934        assert!(!vector.is_null_at(2));
4935    }
4936
4937    /// Every other form keeps its nulls in its own mask, so the two answers agree there.
4938    #[test]
4939    fn the_forms_that_hold_their_own_nulls_answer_the_same_either_way() {
4940        let flat = Vector::flat(LogicalType::Integer, Data::Int32(vec![0, 7].into()))
4941            .unwrap()
4942            .with_validity(Validity::from_iter(2, |index| index != 0));
4943        let constant = Vector::constant(LogicalType::Integer, Value::Null, 2);
4944        let sequence = Vector::sequence(10, 2, 2);
4945        for vector in [flat, constant, sequence] {
4946            for row in 0..vector.len() {
4947                assert_eq!(vector.is_null_at(row), !vector.validity().is_valid(row));
4948            }
4949        }
4950    }
4951
4952    #[test]
4953    fn flattening_a_flat_vector_is_the_same_vector() {
4954        let vector = integers(&[1, 2, 3]);
4955        assert_eq!(vector.flatten().unwrap(), vector);
4956    }
4957
4958    #[test]
4959    fn a_decimal_reads_its_width_and_scale_from_the_type_and_not_the_data() {
4960        let ty = LogicalType::decimal(9, 2).unwrap();
4961        let vector = Vector::flat(ty, Data::Int32(vec![1234].into())).unwrap();
4962        assert_eq!(vector.value_at(0), Value::Decimal { unscaled: 1234, width: 9, scale: 2 });
4963        assert_eq!(vector.value_at(0).to_string(), "12.34");
4964    }
4965
4966    #[test]
4967    fn a_decimal_writes_into_whichever_of_the_four_runs_its_precision_chose() {
4968        // The read path worked at every width and the write path only accepted the 128 bit run, so
4969        // `SELECT 2.5` produced a value nothing could store. All four widths round trip now.
4970        for (width, scale, unscaled) in
4971            [(4u8, 1u8, 25i128), (9, 2, 1234), (18, 3, 123_456), (38, 4, 1_234_567)]
4972        {
4973            let ty = LogicalType::decimal(width, scale).unwrap();
4974            let value = Value::Decimal { unscaled, width, scale };
4975            let vector = Vector::from_values(ty, &[value.clone(), Value::Null]).unwrap();
4976            assert_eq!(vector.value_at(0), value, "a decimal of width {width}");
4977            assert_eq!(vector.value_at(1), Value::Null, "a null decimal of width {width}");
4978        }
4979    }
4980
4981    /// The bytes a blob holds are not required to be text, and a vector of them used to refuse the
4982    /// ones that were not. A byte array column in a Parquet file that nothing annotated is a blob,
4983    /// which is what ClickHouse writes and what ten of the ClickBench queries compare against, so
4984    /// this is the path those take rather than a corner of the type system.
4985    #[test]
4986    fn a_blob_holds_bytes_that_are_not_text() {
4987        let bytes = |raw: &[u8]| Value::Blob(raw.to_vec());
4988        let values = [
4989            bytes(b"a\xffb"),
4990            bytes(b"\x00\x01\x02"),
4991            Value::Null,
4992            bytes(b"\xed\xa0\x80 and long enough to leave the view"),
4993            bytes(b""),
4994        ];
4995        let vector = Vector::from_values(LogicalType::Blob, &values).unwrap();
4996        for (index, value) in values.iter().enumerate() {
4997            assert_eq!(&vector.value_at(index), value, "row {index}");
4998        }
4999    }
5000
5001    #[test]
5002    fn a_decimal_too_wide_for_the_run_its_type_chose_is_an_error_and_not_a_wrong_number() {
5003        // Only reachable by hand, since a value's width is what picked the run. Truncating here
5004        // would store a different number and say nothing about it.
5005        let ty = LogicalType::decimal(4, 1).unwrap();
5006        let value = Value::Decimal { unscaled: 1_000_000, width: 4, scale: 1 };
5007        let error = Vector::from_values(ty, &[value]).unwrap_err();
5008        assert!(error.to_string().contains("does not fit"), "{error}");
5009    }
5010
5011    #[test]
5012    fn a_flat_vector_costs_its_values_and_a_constant_costs_one() {
5013        let flat = integers(&[1; 1000]);
5014        assert!(
5015            flat.footprint() >= 4000,
5016            "a thousand i32 are four thousand bytes: {}",
5017            flat.footprint()
5018        );
5019        // The forms that compute their values rather than storing them cost nothing per value,
5020        // which is the point of having them and is what the memory limit should see.
5021        let constant = Vector::constant(LogicalType::Integer, Value::Integer(1), 1_000_000);
5022        assert!(constant.footprint() < 200, "a constant is one value: {}", constant.footprint());
5023        let sequence = Vector::sequence(0, 1, 1_000_000);
5024        assert!(sequence.footprint() < 200, "a sequence is two numbers: {}", sequence.footprint());
5025    }
5026
5027    #[test]
5028    fn a_dictionary_read_by_many_cuts_is_counted_about_once_between_them() {
5029        let strings: Vec<Value> = (0..2000)
5030            .map(|at| Value::Varchar(format!("a value well past the inline limit, number {at}")))
5031            .collect();
5032        let values = Arc::new(Vector::from_values(LogicalType::Varchar, &strings).unwrap());
5033        let dictionary = values.footprint();
5034        let cuts: Vec<Vector> = (0..500)
5035            .map(|_| Vector::stable_dictionary(vec![0; 8], Arc::clone(&values)).unwrap())
5036            .collect();
5037        let together: usize = cuts.iter().map(Vector::footprint).sum();
5038        // Five hundred chunks cut out of one page hold one dictionary, and what they say they hold
5039        // has to be about one dictionary. Before this it was five hundred of them, which is a
5040        // reading that grows with the answer and refuses a query holding a gigabyte a budget of
5041        // twenty five.
5042        assert!(
5043            together < dictionary * 2,
5044            "five hundred cuts are not five hundred dictionaries: {together} against {dictionary}"
5045        );
5046        assert!(
5047            together > dictionary / 2,
5048            "the dictionary is still counted: {together} against {dictionary}"
5049        );
5050    }
5051
5052    #[test]
5053    fn a_string_vector_costs_the_bytes_of_its_long_strings() {
5054        let short =
5055            Vector::from_values(LogicalType::Varchar, &[Value::Varchar("red".into())]).unwrap();
5056        let long = "a string well past the sixteen bytes a view holds inline".to_string();
5057        let spilled =
5058            Vector::from_values(LogicalType::Varchar, &[Value::Varchar(long.clone())]).unwrap();
5059        assert!(
5060            spilled.footprint() >= short.footprint() + long.len(),
5061            "the arena is counted: {} against {}",
5062            spilled.footprint(),
5063            short.footprint()
5064        );
5065    }
5066
5067    /// The cases worth checking are the widths where a code straddles a word boundary, which is
5068    /// every width that does not divide sixty four, and the two ends of the range.
5069    #[test]
5070    fn a_narrow_column_packs_and_reads_back_the_same_at_every_width() {
5071        for width in 1..=20u32 {
5072            let span = (1i64 << width) - 1;
5073            let values: Vec<i64> =
5074                (0..1000).map(|row| 1_000_000 + (row * 7919) % (span + 1)).collect();
5075            let flat =
5076                Vector::flat(LogicalType::BigInt, Data::Int64(values.clone().into())).unwrap();
5077            let packed = flat.bit_packed().unwrap();
5078            assert_eq!(packed.len(), flat.len());
5079            assert_eq!(
5080                packed.iter().collect::<Vec<_>>(),
5081                flat.iter().collect::<Vec<_>>(),
5082                "width {width} read back differently"
5083            );
5084        }
5085    }
5086
5087    #[test]
5088    fn the_width_is_the_bits_the_range_needs_and_not_the_bits_the_type_has() {
5089        let values: Vec<i32> = (0..1024).map(|row| 40 + (row * 2560) / 1023).collect();
5090        let flat = Vector::flat(LogicalType::Integer, Data::Int32(values.into())).unwrap();
5091        let packed = flat.bit_packed().unwrap();
5092        assert_eq!(packed.form(), Form::BitPacked);
5093        let parts = packed.packed_parts().expect("packed");
5094        assert_eq!(parts.width(), 12, "0 to 2560 is twelve bits");
5095        assert_eq!(parts.base(), 40);
5096        assert!(
5097            packed.footprint() * 2 < flat.footprint(),
5098            "twelve bits against thirty two: {} against {}",
5099            packed.footprint(),
5100            flat.footprint()
5101        );
5102    }
5103
5104    /// The check is worth having in both directions, the way the run length one is. A form that is
5105    /// only ever bigger than what it replaced costs a pass over the column to decide not to use.
5106    #[test]
5107    fn a_column_that_uses_its_whole_type_is_left_flat() {
5108        let values: Vec<i32> = (0..1024).map(|row| row * 2_000_000 - 1_000_000_000).collect();
5109        let flat = Vector::flat(LogicalType::Integer, Data::Int32(values.into())).unwrap();
5110        assert_eq!(flat.bit_packed().unwrap().form(), Form::Flat);
5111    }
5112
5113    /// A column of one value would pack to no bits at all, and one run is smaller than any packing
5114    /// of it, so the two forms do not fight over that column.
5115    #[test]
5116    fn a_column_of_one_value_is_left_to_the_run_length_form() {
5117        let flat = integers(&[9; 1024]);
5118        assert_eq!(flat.bit_packed().unwrap().form(), Form::Flat);
5119        assert_eq!(flat.run_encoded().unwrap().form(), Form::Rle);
5120    }
5121
5122    #[test]
5123    fn a_string_column_has_no_range_to_pack() {
5124        let text = Vector::from_values(
5125            LogicalType::Varchar,
5126            &[Value::Varchar("red".into()), Value::Varchar("blue".into())],
5127        )
5128        .unwrap();
5129        assert_eq!(text.bit_packed().unwrap().form(), Form::Flat);
5130    }
5131
5132    /// The cut is the reason the form carries a row to start reading at. It stays packed, it shares
5133    /// the same words, and it reads the rows the range asked for.
5134    #[test]
5135    fn a_cut_of_a_packed_column_stays_packed_and_shares_its_bits() {
5136        let values: Vec<i32> = (0..1024).map(|row| 100 + row % 300).collect();
5137        let flat = Vector::flat(LogicalType::Integer, Data::Int32(values.into())).unwrap();
5138        let packed = flat.bit_packed().unwrap();
5139        let cut = packed.slice(500, 24).unwrap();
5140        assert_eq!(cut.form(), Form::BitPacked);
5141        assert_eq!(cut.len(), 24);
5142        assert_eq!(
5143            cut.iter().collect::<Vec<_>>(),
5144            flat.slice(500, 24).unwrap().iter().collect::<Vec<_>>()
5145        );
5146        assert!(
5147            cut.footprint() >= packed.footprint(),
5148            "a cut shares the words rather than copying a piece of them"
5149        );
5150    }
5151
5152    #[test]
5153    fn a_gather_of_a_packed_column_comes_out_flat_and_keeps_the_nulls() {
5154        let values: Vec<i32> = (0..64).map(|row| 10 + row).collect();
5155        let flat = Vector::flat(LogicalType::Integer, Data::Int32(values.into())).unwrap();
5156        let packed =
5157            flat.bit_packed().unwrap().with_validity(Validity::from_iter(64, |row| row % 3 != 0));
5158        let taken = packed.gather(&[0, 1, 2, 3, 62]).unwrap();
5159        assert_eq!(taken.form(), Form::Flat);
5160        assert_eq!(
5161            taken.iter().collect::<Vec<_>>(),
5162            vec![
5163                Value::Null,
5164                Value::Integer(11),
5165                Value::Integer(12),
5166                Value::Null,
5167                Value::Integer(72)
5168            ]
5169        );
5170    }
5171
5172    /// The pair a comparison kernel asks for before it reads a bit. A literal inside the range has a
5173    /// code and a literal outside it does not, which answers the whole vector at once.
5174    #[test]
5175    fn a_literal_outside_the_packed_range_has_no_code() {
5176        let values: Vec<i32> = (0..256).map(|row| 1000 + row).collect();
5177        let flat = Vector::flat(LogicalType::Integer, Data::Int32(values.into())).unwrap();
5178        let packed = flat.bit_packed().unwrap();
5179        let parts = packed.packed_parts().expect("packed");
5180        assert_eq!(parts.code_of(1000), Some(0));
5181        assert_eq!(parts.code_of(1100), Some(100));
5182        assert_eq!(parts.code_of(999), None);
5183        assert!(parts.ceiling() >= 1255);
5184        assert_eq!(parts.code_of(parts.ceiling() + 1), None);
5185    }
5186
5187    /// The bits arriving from a file rather than from a flat vector, which is what the form is for.
5188    #[test]
5189    fn packed_bits_can_be_handed_in_without_a_flat_vector_to_start_from() {
5190        let packed = Vector::packed(LogicalType::SmallInt, vec![0x0000_0000_0000_4321], 4, 7, 4)
5191            .expect("four codes of four bits");
5192        assert_eq!(
5193            packed.iter().collect::<Vec<_>>(),
5194            vec![Value::SmallInt(8), Value::SmallInt(9), Value::SmallInt(10), Value::SmallInt(11)]
5195        );
5196    }
5197
5198    #[test]
5199    fn packed_bits_that_could_not_hold_what_they_claim_are_refused() {
5200        assert!(Vector::packed(LogicalType::Varchar, vec![0], 4, 0, 4).is_err(), "not an integer");
5201        assert!(Vector::packed(LogicalType::Integer, vec![0], 0, 0, 4).is_err(), "no width");
5202        assert!(Vector::packed(LogicalType::Integer, vec![0], 64, 0, 4).is_err(), "too wide");
5203        assert!(Vector::packed(LogicalType::Integer, vec![0], 8, 0, 9).is_err(), "too few words");
5204        assert!(Vector::packed(LogicalType::TinyInt, vec![0], 8, 100, 8).is_err(), "would not fit");
5205    }
5206
5207    /// A column of strings long enough that the payload is in the arena rather than in the views.
5208    fn long_strings(count: usize) -> Vector {
5209        let values: Vec<Value> = (0..count)
5210            .map(|row| {
5211                Value::Varchar(format!("a string too long to sit inside a view, number {row}"))
5212            })
5213            .collect();
5214        Vector::from_values(LogicalType::Varchar, &values).unwrap()
5215    }
5216
5217    #[test]
5218    fn a_string_column_in_view_form_reads_back_the_same_strings() {
5219        let flat = long_strings(40);
5220        let shared = flat.clone().shared_text().unwrap();
5221        assert_eq!(shared.form(), Form::StringView);
5222        assert_eq!(shared.len(), 40);
5223        for row in 0..40 {
5224            assert_eq!(shared.value_at(row), flat.value_at(row), "row {row}");
5225            assert_eq!(shared.text_at(row), flat.text_at(row), "row {row}");
5226        }
5227    }
5228
5229    #[test]
5230    fn a_short_string_is_read_out_of_its_view_and_never_out_of_the_arena() {
5231        let flat = Vector::from_values(
5232            LogicalType::Varchar,
5233            &[Value::Varchar("red".into()), Value::Varchar("green".into()), Value::Null],
5234        )
5235        .unwrap();
5236        let shared = flat.shared_text().unwrap();
5237        // Nothing went to the arena, so the whole column resolves with an empty one.
5238        let (views, arena) = shared.text_parts().unwrap();
5239        assert!(arena.is_empty(), "three short strings need no arena");
5240        assert_eq!(views[0].bytes_in(arena), Some(&b"red"[..]));
5241        assert_eq!(shared.value_at(1), Value::Varchar("green".into()));
5242        assert_eq!(shared.value_at(2), Value::Null, "the validity came across");
5243    }
5244
5245    #[test]
5246    fn a_cut_of_a_view_column_shares_the_arena_rather_than_copying_the_bytes() {
5247        let shared = long_strings(64).shared_text().unwrap();
5248        let cut = shared.slice(16, 8).unwrap();
5249        assert_eq!(cut.form(), Form::StringView, "a cut of views is views");
5250        assert_eq!(cut.len(), 8);
5251        assert_eq!(cut.value_at(0), shared.value_at(16));
5252        assert_eq!(cut.value_at(7), shared.value_at(23));
5253        // The arena is the same bytes at the same address, which is the whole point of the form.
5254        let (_, whole) = shared.text_parts().unwrap();
5255        let (_, piece) = cut.text_parts().unwrap();
5256        assert_eq!(piece.as_ptr(), whole.as_ptr(), "the cut shares the page");
5257        assert_eq!(piece.len(), whole.len());
5258    }
5259
5260    #[test]
5261    fn a_flat_string_column_has_to_copy_the_bytes_its_cut_keeps() {
5262        let flat = long_strings(64);
5263        let cut = flat.slice(16, 8).unwrap();
5264        assert_eq!(cut.form(), Form::Flat);
5265        let (_, whole) = flat.text_parts().unwrap();
5266        let (_, piece) = cut.text_parts().unwrap();
5267        assert!(piece.len() < whole.len(), "the flat cut carries only what it kept");
5268    }
5269
5270    #[test]
5271    fn a_gather_of_a_view_column_keeps_the_form_and_a_flatten_copies_out_of_it() {
5272        let shared = long_strings(32).shared_text().unwrap();
5273        let picked: Vec<u32> = (0..32).step_by(3).collect();
5274        let gathered = shared.gather(&picked).unwrap();
5275        assert_eq!(gathered.form(), Form::StringView, "selecting rows moves views, not bytes");
5276        assert_eq!(gathered.len(), picked.len());
5277        for (row, &from) in picked.iter().enumerate() {
5278            assert_eq!(gathered.value_at(row), shared.value_at(from as usize), "row {row}");
5279        }
5280        let flattened = gathered.flatten().unwrap();
5281        assert_eq!(flattened.form(), Form::Flat);
5282        assert_eq!(flattened.iter().collect::<Vec<_>>(), gathered.iter().collect::<Vec<_>>());
5283        // The flatten is what narrows the bytes, so the arena it built holds only the rows it kept.
5284        let (_, narrowed) = flattened.text_parts().unwrap();
5285        let (_, whole) = shared.text_parts().unwrap();
5286        assert!(narrowed.len() < whole.len(), "flattening lets the page go");
5287    }
5288
5289    #[test]
5290    fn a_null_in_a_view_column_survives_being_gathered_and_flattened() {
5291        let shared = long_strings(8)
5292            .with_validity(Validity::from_iter(8, |row| row % 3 != 0))
5293            .shared_text()
5294            .unwrap();
5295        let gathered = shared.gather(&[0, 1, 2, 3, 4]).unwrap();
5296        let expected =
5297            [Value::Null, shared.value_at(1), shared.value_at(2), Value::Null, shared.value_at(4)];
5298        assert_eq!(gathered.iter().collect::<Vec<_>>(), expected);
5299        assert_eq!(gathered.flatten().unwrap().iter().collect::<Vec<_>>(), expected);
5300    }
5301
5302    #[test]
5303    fn both_string_forms_hand_a_kernel_the_same_views_and_the_same_bytes() {
5304        let flat = long_strings(6);
5305        let shared = flat.clone().shared_text().unwrap();
5306        let (flat_views, flat_arena) = flat.text_parts().unwrap();
5307        let (shared_views, shared_arena) = shared.text_parts().unwrap();
5308        assert_eq!(flat_views.len(), shared_views.len());
5309        for row in 0..6 {
5310            assert_eq!(
5311                flat_views[row].bytes_in(flat_arena),
5312                shared_views[row].bytes_in(shared_arena),
5313                "row {row}"
5314            );
5315        }
5316        // Nothing else answers this, which is what keeps a kernel from taking it for a string column.
5317        assert!(Vector::sequence(0, 1, 4).text_parts().is_none());
5318        assert!(integers(&[1, 2, 3]).text_parts().is_none());
5319    }
5320
5321    #[test]
5322    fn a_column_that_is_not_strings_cannot_be_held_as_views() {
5323        let views = vec![StringView::inline("red")];
5324        let arena = Arc::new(Buffer::new());
5325        let wrong = Vector::string_views(LogicalType::Integer, views, arena);
5326        assert!(wrong.is_err(), "an integer column has no views");
5327        assert_eq!(integers(&[1, 2]).shared_text().unwrap().form(), Form::Flat, "left alone");
5328    }
5329
5330    /// A column with enough repeated structure for a symbol table to find something, which is what
5331    /// a real text column has and a column of random bytes does not.
5332    fn sentences(count: usize) -> Vector {
5333        let values: Vec<Value> = (0..count)
5334            .map(|row| {
5335                Value::Varchar(format!(
5336                    "http://example.test/catalogue/section/{}/item/{row}",
5337                    row % 7
5338                ))
5339            })
5340            .collect();
5341        Vector::from_values(LogicalType::Varchar, &values).unwrap()
5342    }
5343
5344    #[test]
5345    fn a_compressed_column_reads_back_the_strings_that_went_into_it() {
5346        let flat = sentences(64);
5347        let coded = flat.clone().compressed().unwrap();
5348        assert_eq!(coded.form(), Form::Fsst, "a text column compresses");
5349        assert_eq!(coded.len(), 64);
5350        for row in 0..64 {
5351            assert_eq!(coded.value_at(row), flat.value_at(row), "row {row}");
5352        }
5353        assert_eq!(coded.flatten().unwrap(), flat, "flattening is the column it came from");
5354    }
5355
5356    #[test]
5357    fn compressing_halves_the_bytes_or_the_column_is_left_flat() {
5358        let flat = sentences(200);
5359        let coded = flat.clone().compressed().unwrap();
5360        let parts = coded.coded_parts().expect("compressed");
5361        // Read through the flat column, because the compressed one has no bytes to hand back where
5362        // they are and answers `None` to `text_at` rather than decompressing into a borrow.
5363        assert_eq!(coded.text_at(0), None, "nothing to borrow until it is flattened");
5364        let plain: usize = (0..200).map(|row| flat.text_at(row).map_or(0, str::len)).sum();
5365        let codes: usize = (0..200).map(|row| parts.row(row).map_or(0, <[u8]>::len)).sum();
5366        assert!(codes * FSST_PAYS_AT <= plain, "{codes} codes against {plain} bytes");
5367        // Text with no repeated structure in it gives a table nothing longer than a byte to find,
5368        // so the codes are the bytes and the column stays where it is rather than paying a
5369        // decompression per read to save nothing.
5370        let mut seed = 0x2545_f491_4f6c_dd1du64;
5371        let values: Vec<Value> = (0..256)
5372            .map(|_| {
5373                let mut text = String::new();
5374                while text.len() < 12 {
5375                    seed = seed.wrapping_mul(6_364_136_223_846_793_005).wrapping_add(1);
5376                    text.push(char::from(b'!' + ((seed >> 33) % 90) as u8));
5377                }
5378                Value::Varchar(text)
5379            })
5380            .collect();
5381        let noise = Vector::from_values(LogicalType::Varchar, &values).unwrap();
5382        assert_eq!(noise.compressed().unwrap().form(), Form::Flat);
5383    }
5384
5385    #[test]
5386    fn a_cut_of_a_compressed_column_shares_the_codes_and_the_table() {
5387        let coded = sentences(64).compressed().unwrap();
5388        let cut = coded.slice(8, 16).unwrap();
5389        assert_eq!(cut.form(), Form::Fsst);
5390        assert_eq!(cut.len(), 16);
5391        for row in 0..16 {
5392            assert_eq!(cut.value_at(row), coded.value_at(8 + row), "row {row}");
5393        }
5394        let (whole, piece) = (coded.coded_parts().unwrap(), cut.coded_parts().unwrap());
5395        assert_eq!(piece.row(0), whole.row(8), "the spans point into the same codes");
5396    }
5397
5398    #[test]
5399    fn a_gather_of_a_compressed_column_stays_compressed_and_keeps_the_nulls() {
5400        let coded = sentences(32)
5401            .with_validity(Validity::from_iter(32, |row| row % 5 != 2))
5402            .compressed()
5403            .unwrap();
5404        let picked: Vec<u32> = (0..32).step_by(2).collect();
5405        let gathered = coded.gather(&picked).unwrap();
5406        assert_eq!(gathered.form(), Form::Fsst, "selecting rows moves spans, not bytes");
5407        for (row, &from) in picked.iter().enumerate() {
5408            assert_eq!(gathered.value_at(row), coded.value_at(from as usize), "row {row}");
5409        }
5410        assert_eq!(
5411            gathered.flatten().unwrap().iter().collect::<Vec<_>>(),
5412            gathered.iter().collect::<Vec<_>>()
5413        );
5414    }
5415
5416    #[test]
5417    fn a_literal_lands_in_the_same_codes_the_row_holding_it_does() {
5418        let coded = sentences(40).compressed().unwrap();
5419        let parts = coded.coded_parts().expect("compressed");
5420        let text = coded.value_at(11);
5421        let Value::Varchar(text) = text else { panic!("a string column reads back strings") };
5422        assert_eq!(parts.encode(text.as_bytes()), parts.row(11).expect("row 11"));
5423        assert_ne!(parts.encode(b"something else entirely"), parts.row(11).unwrap());
5424    }
5425
5426    #[test]
5427    fn codes_that_run_past_what_is_there_are_refused() {
5428        let table = Arc::new(SymbolTable::empty());
5429        let codes = Arc::new(vec![1u8, 2, 3, 4]);
5430        let good = vec![(0u32, 2u32), (2, 4)];
5431        assert!(
5432            Vector::coded(LogicalType::Varchar, Arc::clone(&codes), good, Arc::clone(&table))
5433                .is_ok()
5434        );
5435        let past = vec![(0u32, 9u32)];
5436        assert!(
5437            Vector::coded(LogicalType::Varchar, Arc::clone(&codes), past, Arc::clone(&table))
5438                .is_err(),
5439            "a span past the end of the codes"
5440        );
5441        let backwards = vec![(3u32, 1u32)];
5442        assert!(
5443            Vector::coded(LogicalType::Varchar, Arc::clone(&codes), backwards, Arc::clone(&table))
5444                .is_err(),
5445            "a span that ends before it starts"
5446        );
5447        let wrong = vec![(0u32, 2u32)];
5448        assert!(
5449            Vector::coded(LogicalType::Integer, codes, wrong, table).is_err(),
5450            "an integer column has no codes"
5451        );
5452    }
5453
5454    #[test]
5455    fn a_view_pointing_past_its_arena_is_refused_at_construction() {
5456        let long = "a string too long to sit inside a view";
5457        let arena: Arc<Buffer<u8>> = Arc::new(long.as_bytes().to_vec().into());
5458        let good = vec![StringView::over(long.as_bytes(), 0)];
5459        assert!(Vector::string_views(LogicalType::Varchar, good, Arc::clone(&arena)).is_ok());
5460        let bad = vec![StringView::over(long.as_bytes(), 4)];
5461        assert!(
5462            Vector::string_views(LogicalType::Varchar, bad, arena).is_err(),
5463            "four bytes short of what the view claims"
5464        );
5465    }
5466}