# Consumer contract
`kcode-k1-rust-package` owns canonical Rust library identities and validates one complete package without I/O or publication. `AuthorityId` wraps an authority transaction ID. `LibraryFamily` combines it with a 1–36 byte lowercase kebab-case name and derives `k1-<authority>-<name>`. `LibraryId` adds a stable semantic version. `SourceFile` retains one canonical UTF-8 path and arbitrary bytes. `SourcePackage::new` sorts and validates complete source and extracts canonically sorted `K1Dependency` values.
Paths are slash-separated, relative, unique, free of file/ancestor collisions, and within Linux path/component bounds. Empty, dot, parent, backslash, NUL, `.cargo`, any leaf beginning `rust-toolchain`, root `Cargo.lock`, and nested `Cargo.toml` paths are rejected. Root `Cargo.toml` and `Documentation.md` are required UTF-8 files.
The manifest must exactly match the package identity and Rust 2024. It must set literal `autobins = false`, `autoexamples = false`, `autotests = false`, and `autobenches = false`, and declare `[lib]` or at least one `[[bin]]`; the library name maps the logical name from kebab case to snake case, and binary names are explicit, unique lowercase kebab case. Explicit and auto-discovered example, bench, and test targets are rejected. Package include/exclude, `publish = false`, patch/replace, path/Git/workspace dependencies, custom registries, workspace inheritance, and nested workspaces are rejected. A root workspace may contain only `resolver = "3"`. Normal, optional, build, development, and target dependencies are supported. Crates.io dependencies use ordinary requirements. K1 dependencies require registry `k1`, a canonical authority-prefixed package, and exact `=MAJOR.MINOR.PATCH`. Validation failures return `PackageError`; no operation mutates source or external state.