Came out of reviewing #102, which paired each workspace-root candidate name with the kind that reads it (root_names: &[(&'static str, ManifestKind)], replacing a single root_kind over the whole list) and made workspace_declarations take the root's kind rather than the member's.
That change exists to make a heterogeneous descriptor safe — one where a candidate's paired kind is not the kind that went looking, e.g. a JavaScript member rooting at either pnpm-workspace.yaml or the workspace root's own package.json. No such descriptor reaches the code paths that would actually exercise it.
What is covered
a_candidate_is_read_with_the_kind_it_is_paired_with and an_unrecognised_candidate_does_not_hide_a_later_one (crates/dependable-fetch/src/discover.rs) do test heterogeneity, but they call the private root_in_dir directly and stage a fake pairing (("package.json", ManifestKind::CargoToml)).
What is not covered
Nothing exercises a descriptor where root_kind != kind through:
The debug_assert! in workspace_root_of guarding the self_governing invariant ("a self-governing kind must appear among its own root_names kinds") has no test that trips it.
The traps #102 exists to close therefore reopen at exactly the layer with no coverage, the day a second ecosystem's descriptor lands — and #84 (pom.xml) and #85 (Swift) are both open.
Why it could not be fixed in #102
WorkspaceRoots is #[non_exhaustive] with no constructor, so a synthetic descriptor cannot be built from dependable-fetch. ManifestKind::workspace_roots returns Some only for CargoToml, so no real descriptor is heterogeneous yet.
Suggested fix
A #[doc(hidden)] or cfg(test)-gated test descriptor in dependable-core — either a constructor for WorkspaceRoots or a hidden ManifestKind whose workspace_roots() is deliberately heterogeneous — so dependable-fetch can drive the public walk, the self branch, and the cache key with root_kind != kind, and can trip the debug_assert!.
Came out of reviewing #102, which paired each workspace-root candidate name with the kind that reads it (
root_names: &[(&'static str, ManifestKind)], replacing a singleroot_kindover the whole list) and madeworkspace_declarationstake the root's kind rather than the member's.That change exists to make a heterogeneous descriptor safe — one where a candidate's paired kind is not the kind that went looking, e.g. a JavaScript member rooting at either
pnpm-workspace.yamlor the workspace root's ownpackage.json. No such descriptor reaches the code paths that would actually exercise it.What is covered
a_candidate_is_read_with_the_kind_it_is_paired_withandan_unrecognised_candidate_does_not_hide_a_later_one(crates/dependable-fetch/src/discover.rs) do test heterogeneity, but they call the privateroot_in_dirdirectly and stage a fake pairing (("package.json", ManifestKind::CargoToml)).What is not covered
Nothing exercises a descriptor where
root_kind != kindthrough:nearest_workspace_root— the public walk;workspace_root_of's self-governing branch;Checker::workspace_source's cache key, which refactor!: harden the workspace-root descriptor before a second ecosystem uses it #102 widened to(PathBuf, ManifestKind)precisely so two kinds reading one path do not collide.The
debug_assert!inworkspace_root_ofguarding theself_governinginvariant ("a self-governing kind must appear among its ownroot_nameskinds") has no test that trips it.The traps #102 exists to close therefore reopen at exactly the layer with no coverage, the day a second ecosystem's descriptor lands — and #84 (pom.xml) and #85 (Swift) are both open.
Why it could not be fixed in #102
WorkspaceRootsis#[non_exhaustive]with no constructor, so a synthetic descriptor cannot be built fromdependable-fetch.ManifestKind::workspace_rootsreturnsSomeonly forCargoToml, so no real descriptor is heterogeneous yet.Suggested fix
A
#[doc(hidden)]orcfg(test)-gated test descriptor independable-core— either a constructor forWorkspaceRootsor a hiddenManifestKindwhoseworkspace_roots()is deliberately heterogeneous — sodependable-fetchcan drive the public walk, the self branch, and the cache key withroot_kind != kind, and can trip thedebug_assert!.