Skip to content
docs
Arxo ↗

Arxo registry publication descriptor 0.2

For LLMs11 sections

Descriptor of a RELEASE in the registry. The previous record p/<name>/<version>.json carried only a locked package and said nothing about what the release pulls in: a graph edge could be learned only by downloading the whole compiled file. Here dependencies and required resources are declared, so the graph and pin conflicts are visible BEFORE downloading. This is the publication contract, not the source of lockfile fields: only a subset flows into the closed locked-package form of the lockfile, and dependencies/resources/languageSemantics are not carried over there.

Accepted descriptorFormat: law.package-descriptor/0.2.

nametype-or-$refrequireddescription
descriptorFormat"law.package-descriptor/0.2"yesFormat version. Its absence means an old registry record (specVersion 0.1): it can still be read, but the new add/install/update orchestration rejects it because it does not declare exact dependencies.
name#/$defs/PackageNameyes—
version#/$defs/Versionyes—
namespacestringyes—
contentHash#/$defs/Sha256yessha256 of the canonical compiled (CLIR) bytes. Deliberately narrower than the general digest form: the bytes can only be checked with the algorithm they were computed with.
worldHash#/$defs/Sha256noOptional sha256 of the canonical bytes of the linked world of this release (root plus its pinned closure), published as p///world.lawir.json. The world is built by the engine link step only; SDKs verify these bytes and execute them, they never link. Absent on releases published before the field existed.
editorSourceMapHash#/$defs/Sha256noOptional sha256 of the raw editor source-map sidecar. A resolver copies it to the locked package, so the resolution hash covers the authored-location pin without changing the CLIR.
questionCatalogHash#/$defs/Sha256noOptional sha256 of the published questions catalog sidecar, installed as deps/.questions.json from the immutable registry version. It does not affect CLIR or evaluation semantics.
taskGuideCatalogHash#/$defs/Sha256noOptional sha256 of the published task-guides catalog sidecar, installed as deps/.task-guides.json from the immutable registry version. Task guides are metadata: they do not affect CLIR or evaluation semantics.
signatureobjectnoEd25519 signature over the canonical locked-package projection excluding the signature, domain-separated by application/vnd.arxo.locked-package+json.
registryId#/$defs/RegistryIdyes—
resolverUristringyesIdentity of the release, not a URL. The registry address lives in the consumer’s settings and changes with the mirror; identity does not.
featuresarrayyes—
languageSemanticsstringnoSemantics line of the release. A linked world is assembled from packages of ONE line; incompatibility is detected while preparing the operation, not by editing the semanticVersion of a downloaded file.
dependenciesarrayyesEXACT direct dependencies of the release. Must match the actual imports of the published CLIR — this is checked after download, because the descriptor is the publisher’s promise, and it is proved by the bytes.
resourcesarraynoRequired resources of the release, delivered as a blob keyed by contentHash. The first release supports only calendar datasets; an unknown kind is rejected rather than being placed “somewhere”.
locationvalues
properties/descriptorFormat"law.package-descriptor/0.2"
properties/signature/properties/algorithm"ed25519"
$defs/DescriptorResource/properties/kind"calendar-dataset"
$defs/DescriptorResource/properties/capability"law.calendar/0.1"
$defs/PackageVersions/properties/format"law.package-versions/0.1"

https://law.arxo.io/schema/package-descriptor.schema.json

Type: string.

Type: string.

Type: string.

Type: string.

Type: object. Required: name, version, namespace, registryId, contentHash.

nametype-or-$refdescription
name#/$defs/PackageName—
version#/$defs/Version—
namespacestring—
registryId#/$defs/RegistryId—
contentHash#/$defs/Sha256—

Type: object. Required: id, kind, capability, contentHash, file.

nametype-or-$refdescription
idstringLogical resource identifier — the same one as the calendar snapshot node and the law.lock entry. Two incompatible datasets under one id are a rejection citing both sources.
kind"calendar-dataset"—
capability"law.calendar/0.1"—
contentHash#/$defs/Sha256—
filestringFile name as A SINGLE segment: the in-project address is built by the consumer (resources/calendars//). The publisher’s path does not become a requirement on the user’s machine.

Index p/<name>/versions.json: without it the remote registry cannot name the latest stable version, and add NAME without a version would be unrunnable.

Type: object. Required: format, name, versions.

nametype-or-$refdescription
format"law.package-versions/0.1"—
name#/$defs/PackageName—
versionsarray—

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.