# Consumer contract
`kcode-k1-rust-transaction` owns the version 1 canonical publication wire format for a validated `SourcePackage`.
`WIRE_VERSION` is `1`. `encode(&SourcePackage)` emits one canonical byte representation. `decode(&[u8])` accepts only that representation and reconstructs a validated `SourcePackage`. Failures return `TransactionError`; `message()` and its `Display` implementation expose the diagnostic.
The layout is a one-byte wire version, 12 raw authority transaction-ID bytes, a one-byte logical-name byte length followed by its UTF-8 bytes, and stable semantic-version major, minor, and patch values as three big-endian `u64` values. A big-endian `u64` file count follows. Each file, in strictly increasing canonical path order, contains a big-endian `u16` UTF-8 path-byte length, path bytes, a big-endian `u64` content length, and exact arbitrary content bytes.
There is no source digest or policy size limit. Representational overflow and allocation failure are errors. Decoding rejects unknown versions, truncation, invalid UTF-8 names or paths, overflow, non-increasing file paths, trailing bytes, and every package invariant rejected by `kcode-k1-rust-package`.
Encoding and decoding perform no I/O, publication, mutation of caller data, network access, deployment, or other external effect.