# Consumer contract
`kcode-k1-rust-package` owns canonical Rust package identities and validates the K1 invariants of one complete package without I/O or publication. `AuthorityId` wraps an authority transaction ID. `LibraryFamily` combines it with a 1–36 byte lowercase kebab-case name and derives `k1-<authority>-<name>`. `LibraryId` adds a stable semantic version. `SourceFile` retains one relative source path and arbitrary bytes. `SourcePackage::new` sorts complete source, validates K1-owned identity and containment invariants, and extracts canonically sorted `K1Dependency` values.
Source paths are slash-separated, relative, unique, free of file/ancestor collisions, and within Linux path/component bounds. Empty components, dot components, parent components, backslashes, NULs, and the root `Cargo.lock` are rejected. Root `Cargo.toml` and `Documentation.md` are required UTF-8 files.
The root manifest must be valid TOML with a literal package name and version exactly matching the K1 identity. K1 otherwise leaves ordinary Cargo package, target, workspace, feature, lint, profile, source, registry, and dependency policy to Cargo. For dependencies explicitly declaring `registry = "k1"`, K1 requires an authority-qualified package name and a stable Cargo semantic-version requirement so the coding service can resolve the public K1 dependency closure. Other dependency declarations are preserved without K1 validation and receive Cargo's own diagnostics during a check.
Failures return `PackageError`; no operation mutates source or external state.