Prostore::Diff::Validator
Validates the desired model state against the existing prostore_schema
state, enforcing the constraints from ADR-0003 (no in-place type
changes), ADR-0008 (reservation interlocks), and ADR-0011 (non-nullable
adds against non-empty tables require backfill:).
The validator runs before the planner. If validation fails, no DDL is planned or executed. The errors raised here are the user-facing failures of "your model is incompatible with the existing database state." All cross-checks here are static — they don't query the live DB.