The only crate that may contain unsafe (contract §0). It turns
Postgres's C surface into safe types: the single-threaded executor
whose reactor is a WaitEventSet (§2), the HTTP/2 client it drives,
and the batch scan that evaluates the extension's functions (§1).
Every unsafe block names the Postgres invariant it relies on.
A failure outside an HTTP exchange (those are jev_client's
TransportErrors), which the caller reports as a Postgres ERROR.