CANP-WP-0002 T07: semver precedence and strict packaging
Two defects from the original review of the seed. Prerelease ordering was worse than first recorded. parse_semver returned (major, minor, patch, raw_string), so 1.0.0-rc1 and 1.0.0 tied on the numeric fields and then compared as strings — "1.0.0-rc1" > "1.0.0". A release candidate therefore shadowed its own release for `newest` and for `>=`, not just for the no-version case. parse_semver now returns a SemVer section 11 precedence key: numeric fields, a release/prerelease rank, then dot-separated prerelease identifiers with numeric ones compared numerically. Build metadata is ignored. Beyond ordering, prereleases are excluded from `any`, `newest` and `>=` entirely; only an exact pin selects one, so publishing a release candidate never changes what existing consumers resolve to. A package holding only prereleases now says so rather than reporting a bare not-found. Packaging copied the whole source directory, so a stray .git, virtualenv or scratch file landed in the catalog and registry. Section 2 already required otherwise — tools MUST ignore unknown non-reserved files unless a manifest field references them — so this is conformance rather than a new rule. What is new is that omissions are reported instead of silent: not packaged (not a reserved path, not referenced by the manifest): .git/, .venv/, notes.txt LICENSE joins the reserved paths. Strict packaging would otherwise drop a package's license text while faithfully copying its `license` field, which contradicts section 14's instruction to surface licensing on publish and install. Spec: 2 (LICENSE, packaging obligation, reporting), 17.1 new, 10.3 note. Reference CLI: parse_semver rewritten with is_prerelease; select_version and pick_version updated; copy_package and report_skipped replace copy_immutable. Tests 65 -> 78. examples/pqrst-estimate carries a LICENSE and a license field, exercising the new reserved path. Also fixes a leaked loop variable in package_members that would have reported a bad `template` path as an `evals` error. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
This commit is contained in:
parent
e885eb7b05
commit
95a8bb31d2
8 changed files with 306 additions and 34 deletions
16
README.md
16
README.md
|
|
@ -181,6 +181,22 @@ signing and trust scoring are explicit non-goals. Ownership lives with the
|
|||
registry rather than in the package, so no package carries an unverifiable
|
||||
assertion of authority.
|
||||
|
||||
## Packaging and versions
|
||||
|
||||
`add`, `publish` and `install` copy the reserved paths (`prompt.yaml`,
|
||||
`prompt.md`, `README.md`, `LICENSE`, `examples/`, `evals/`, `assets/`) plus
|
||||
anything a manifest field references — and nothing else, as § 2 requires. What
|
||||
was left behind is reported rather than silently dropped:
|
||||
|
||||
```text
|
||||
not packaged (not a reserved path, not referenced by the manifest): .git/, .venv/, notes.txt
|
||||
```
|
||||
|
||||
Version precedence follows SemVer, so `1.0.0` outranks `1.0.0-rc1`, and
|
||||
`any`, `newest` and `>= X.Y.Z` skip prereleases entirely. Publishing a release
|
||||
candidate never changes what existing consumers resolve to; name it exactly to
|
||||
use it.
|
||||
|
||||
## Deliberate limitations
|
||||
|
||||
This seed has no hosted registry, model execution, authentication, network access, dependency resolver, or social features. `publish` and `install` operate on a filesystem registry so that the package semantics can be tested before infrastructure is built around them.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue