fn ensure_single_row(array: &ArrayRef, what: &str) -> Result<()>
The runtime is external input: reject an array of the wrong length so that datum_at(0) at the call sites is in bounds.
datum_at(0)