forWriting decides which check: a caller that will only read takes a readable view, and one
that will write takes a writable one. A compiler that can see the body supplies it; a caller
writing this by hand says what it is about to do.
How many entities carry a component, and the one at an index among them; both reads, so both
checked. A script's ecs.count and ecs.at reach these, and a view without them made each
throw the moment a system called it.
Whether a handle names a live entity. It asks nothing of any component, so nothing is checked;
an entity this system destroyed is still alive until the system returns.