CANP-WP-0002 T02: registry-scoped identity and namespace ownership
Section 17 already defined what a registry does when the same id@version is republished; nothing defined what a *consumer* does. That is where namespace conflict actually bites — in the catalog, after installing from two registries. Identity is now registry-scoped: an id names a package within a registry, the way a path names a file within a repository. A local-first format with no signing, no federation and no central authority cannot enforce global uniqueness, and an unenforceable guarantee is worse than none — it invites consumers to conflate two packages that merely share a name. A qualified `<registry>:<id>` reference distinguishes them, and `:` is now barred from ids so the separator stays available. Installing the same id from two registries is therefore not a conflict. The catalog is namespaced by registry and keeps both. Ownership is registry policy, not package data. An optional `registry.yaml` names a registry and records namespace claims. Those claims are explicitly descriptive — a filesystem registry cannot authenticate a publisher, and `publish` says so rather than implying it checked. Keeping the claim out of packages leaves artifacts free of unverifiable assertions of authority, and means package semantics do not change when a hosted registry appears later. Spec: 3.2 (registry-scoped identity, qualified references), 17 (immutability scoped to a registry), 20.1 and 20.2 (new), 18 (registry-manifest validation), 21 (qualified references, reserved `local` name). Reference CLI: parse_reference, check_registry_name, read_registry_manifest, registry_name, namespace_policy; registry_package_path and catalog_package_path split; resolve_installed reports ambiguity and returns the source registry; iter_catalog; `add --as`; closed-namespace warning on publish. Tests 11 -> 21. The catalog layout changed. An existing catalog is detected and reported with instructions rather than failing as "package not found". Signing, trust scoring and federation remain non-goals and were not touched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM Assistant: claude-code Assistant-Model: opus Assistant-Process: 388925@bnt-lap001 Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
This commit is contained in:
parent
4a8422e1aa
commit
ea70a59610
6 changed files with 533 additions and 45 deletions
|
|
@ -30,18 +30,35 @@ Default locations:
|
|||
~/.canned-prompts/registry
|
||||
```
|
||||
|
||||
Catalog and registry both store packages as:
|
||||
A **registry** stores packages flat, because an id is unambiguous within one
|
||||
registry:
|
||||
|
||||
```text
|
||||
<store>/<id path>/<version>/...
|
||||
<registry>/<id path>/<version>/...
|
||||
```
|
||||
|
||||
A **catalog** is namespaced by registry, because identity is registry-scoped
|
||||
(§ 3.2) and the same id may be installed from more than one place:
|
||||
|
||||
```text
|
||||
<catalog>/<registry name>/<id path>/<version>/...
|
||||
```
|
||||
|
||||
For example:
|
||||
|
||||
```text
|
||||
~/.canned-prompts/catalog/practice/pqrst-estimate/0.1.0/
|
||||
~/.canned-prompts/catalog/house/practice/pqrst-estimate/0.1.0/
|
||||
~/.canned-prompts/catalog/local/practice/pqrst-estimate/0.1.0/
|
||||
```
|
||||
|
||||
A registry's name comes from its optional `registry.yaml`, and otherwise from
|
||||
its directory basename. `add` takes a package from a path rather than a
|
||||
registry, so it files it under `local` (override with `--as`).
|
||||
|
||||
Commands that take an ID accept a bare id or a qualified `<registry>:<id>`.
|
||||
A bare id installed from more than one registry is reported as ambiguous
|
||||
rather than resolved by guessing.
|
||||
|
||||
## Design choices
|
||||
|
||||
- YAML manifest via PyYAML.
|
||||
|
|
@ -50,7 +67,11 @@ For example:
|
|||
- Published versions are immutable by default.
|
||||
- `install` copies from registry to catalog.
|
||||
- `add` copies a package directly to catalog.
|
||||
- `search`, `show`, `resolve`, and `render` operate on catalog packages.
|
||||
- `search`, `show`, `resolve`, and `render` operate on catalog packages, and
|
||||
print qualified `<registry>:<id>` references.
|
||||
- An optional `registry.yaml` names a registry and records namespace claims.
|
||||
`publish` warns when a namespace is declared `closed` — it cannot
|
||||
authenticate a publisher, and says so rather than implying it checked.
|
||||
- Static input defaults are applied; **derived** defaults (§ 6.1) are not. This
|
||||
tool never calls a model, so a derived default is satisfied only by its
|
||||
static fallback `value`. Without one, `resolve` reports the input as
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue