ReadonlycapReadonlydefReadonlynameReadonlyoutReadonlyreceiverThe two index bounds, without growing: the schema count as validity
(INVALID) or, where the schema left the array open, the receiver cap as
capacity (LIMIT_EXCEEDED). Never both — §6.2.1 keeps a cap off a field the
schema already bounds, which is why one bound can stand for both.
Split out from reserve because a leaf element is bound-checked at its length word, before its payload has arrived and so before there is anything to place (StringSeq.begin).
What reserve does, then value written into the slot. A repeat
replaces (§7.4).
Written out rather than delegating to reserve: on the baseline tier a call is not free, and this is the per-element path. The check still precedes the growth, which is the property §7.2 item 8 asks for.
Bound-check id and grow out to id + 1, filling any gap — and the slot
itself — with the element default.
The check runs before the growth, which is the whole of §7.2 item 8's
"after a rejected id the container is not left partially extended": a
rejection leaves out exactly as it was, so a lower id delivered afterwards
still lands at its own index.
The slots of a wrapper-sequence array: the index rules of MESSAGE_SPEC §5.1 and the two bounds of CORELIB_PLAN §6.2.1, once, for any element type.
StringSeq and BlobSeq place leaf elements through it, and generated code places a framed element — a
struct/union/ nested row — through it directly: reserve at the element'ssequenceBegin, then build the child intoout[id]. The element kind changes which path arrives here and nothing else, which is the point — the bound is the index (§7.2 item 8).Param: out
The destination array; grown to
id + 1as elements arrive.Param: def
The element default, written into a gap and into a reserved slot.
Param: cap
The schema
countas an index capacity:id >= capisINVALID(§7.1) — a statement about validity. Pass UNBOUNDED (-1) for an array the schema left open, wherereceiverCapgoverns instead.Param: name
The schema field name, used only in a rejection message.
Param: receiverCap
The receiver-side index cap for a schema-unbounded array (§6.2.1):
id >= receiverCapisLIMIT_EXCEEDED, a policy rejection. There is no unlimited setting — a wrapper array announces no count, so the index is the only place a receiver can bound it. Required, with no default: the number is generated code's, and falling back toARRAY_MAXwould report a policy rejection against a format ceiling nobody configured (§6.2.1). A value that states no cap at all — negative,NaN,Infinity— isArgumentat construction, neverLIMIT_EXCEEDED(requireReceiverBound).