0c2054cf

A rule that sees a whole package

Stacked on #6. Review that first; this diff is against it.

Adds `HsGenValidInGenPackage` from `haskell-style.md`, the first rule that
cannot answer from one module, and with it the fact store that lets a rule see
further.

39 files, 1,182 lines. 255 tests.

## Why a database

What a rule above the module level does with facts is join them. One table per
fact, owned by the rule that writes it, so a rule brings its own schema the way
it brings its own check. The envelope never learns what is in that table, which
is why adding a rule adds no case to it: a package rule is a migration, what it
writes out of one module, and the query it answers with.

A fact is a row rather than a keyed entry. Two instances in one module are two
facts, and there is nothing to key them on that is not invented.

## The level

A rule's constructor is also its level, so nothing can disagree with it. Each
level judges exactly the suppressions naming its own rules, which is what keeps
unused-suppression detection sound without a global pass over the repository.

## Still not here

One process, so the store has nowhere to go and nothing crosses a process
boundary. Nothing reads what the compiler wrote down: the package check's
signature does not take the compiler's answers, because this rule has no use
for them.

weeder removed seven store queries on the way in that only a project rule would
want.

## Review loop

```
nix flake check
nix develop --command cabal test hopinion-test --test-options="--ai-executor"
```

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 2s 1s 1s 3s 2s
Eval 4s 11s 11s 15s 0s
Build 14s 0s 0s 14s 0s
Suite 2s 12s 13s 15s 2s

Timeline

0s10s