pub fn adapter_change_permitted(has_surface: bool) -> boolExpand description
Whether a runtime adapter change is allowed at all (ADR-0246): only on a context that has a surface.
The same guard super::tier::tier_change_permitted gives the tier, and
for the same reason: a surface-less context is the headless capture path,
where the adapter is part of what makes a capture a pure function of its
inputs (NFR 6) — a baseline is blessed on one rasterizer, and a public
mutator that could move a capture onto another mid-run would be the hole in
that guarantee. Expressed as a value rather than a branch so both
directions are assertable: a Renderer with a surface cannot be built
in CI, and a test that only observed the headless refusal would pass
against a set_adapter that did nothing at all.