Source: schemas/library_manifest.schema.json
Generated automatically from the published contract sources.
Source path: schemas/library_manifest.schema.json.
Schema fields
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | The shape of `manifest.json` at the root of a project's library folder (LC-07 in the library catalog contract; SPM-L0-50's `system/` row). It is the record of what one project holds — not a copy of the catalog, which is what a publish offers. The two share `name`, `version` and the closure hash on purpose, so the comparison `list_library` makes against a held set compares like with like. Only the turnzero-cloud command's `library take`, which the served installation and update skills direct, writes the manifest (PLD-L0-100). The registrar's `validate` MCP tool with library kind checks manifest form, listed-entry hashes, and unnamed entry folders. Coordinated file and hash edits can pass this local check; it does not authenticate version, source-commit, or fetch-time claims against a publication. Use `list_library` for the publication-currency comparison under LC-06. A test in the platform's suite holds this shape. $schema: https://json\-schema\.org/draft/2020\-12/schema version: 2026-10-03.1 title: Turn Zero Cloud — a project's library folder manifest Type: object Additional properties: false Required fields: ["manifest_version","entries"] |
| / |
The format's revision. An unknown revision is refused as malformed rather than read best-effort, on MAN-01's rule for the admission manifest — a reader that guesses at a format it does not know is a reader that silently drops what it did not understand. Required value: 1 |
| / |
One row per library entry the project holds. Holding none is the empty array rather than an absent member, so a folder that exists and holds nothing is distinguishable from one whose manifest was never written. Type: array uniqueItems: true |
| / |
Type: object Additional properties: false Required fields: ["name","version","closure_hash","source_commit","fetched_at"] |
| / |
The entry's stable name, as the catalog answers it: a package's folder name, `ui/<vocabulary>`, `fonts/<family>`, or `library/prd` for the library's own requirements entry. Type: string Minimum length: 1 |
| / |
The version held, on FTR-L0-62's front-matter spelling. Null on a font family, which carries no specification of its own and so no version of its own, and on the library's own requirements entry, whose two documents declare none — the closure hash is what a consumer compares for those. Type: ["string","null"] |
| / |
sha256 over the entry's whole closure, as the catalog computed it. This is what makes the folder checkable rather than merely present: `validate` rehashes each entry against this value and names any whose bytes have moved, detecting file changes against the locally recorded hash under SPM-L0-49. This checks local consistency; coordinated file and hash edits can pass. Type: string Pattern: ^[0-9a-f]{64}$ |
| / |
The library commit this entry was published from, so a holder can trace its bytes back to the source that produced them without the server's help. Type: string Minimum length: 7 |
| / |
When this entry was written into the folder, ISO 8601 in UTC. The publish's own date is the catalog's; this is the consumer's, and the two differ whenever a project takes a version some time after it was published. Spelled as a pattern rather than JSON Schema's `date-time` format, because the format vocabulary is an optional ajv package this project does not ship and an unrecognized format is silently ignored under strict mode — a check that passes anything. Type: string Pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(\.[0-9]+)?Z$ |
Complete source
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"version": "2026-10-03.1",
"title": "Turn Zero Cloud — a project's library folder manifest",
"description": "The shape of `manifest.json` at the root of a project's library folder (LC-07 in the library catalog contract; SPM-L0-50's `system/` row). It is the record of what one project holds — not a copy of the catalog, which is what a publish offers. The two share `name`, `version` and the closure hash on purpose, so the comparison `list_library` makes against a held set compares like with like. Only the turnzero-cloud command's `library take`, which the served installation and update skills direct, writes the manifest (PLD-L0-100). The registrar's `validate` MCP tool with library kind checks manifest form, listed-entry hashes, and unnamed entry folders. Coordinated file and hash edits can pass this local check; it does not authenticate version, source-commit, or fetch-time claims against a publication. Use `list_library` for the publication-currency comparison under LC-06. A test in the platform's suite holds this shape.",
"type": "object",
"additionalProperties": false,
"required": ["manifest_version", "entries"],
"properties": {
"manifest_version": {
"description": "The format's revision. An unknown revision is refused as malformed rather than read best-effort, on MAN-01's rule for the admission manifest — a reader that guesses at a format it does not know is a reader that silently drops what it did not understand.",
"const": 1
},
"entries": {
"description": "One row per library entry the project holds. Holding none is the empty array rather than an absent member, so a folder that exists and holds nothing is distinguishable from one whose manifest was never written.",
"type": "array",
"uniqueItems": true,
"items": {
"type": "object",
"additionalProperties": false,
"required": ["name", "version", "closure_hash", "source_commit", "fetched_at"],
"properties": {
"name": {
"description": "The entry's stable name, as the catalog answers it: a package's folder name, `ui/<vocabulary>`, `fonts/<family>`, or `library/prd` for the library's own requirements entry.",
"type": "string",
"minLength": 1
},
"version": {
"description": "The version held, on FTR-L0-62's front-matter spelling. Null on a font family, which carries no specification of its own and so no version of its own, and on the library's own requirements entry, whose two documents declare none — the closure hash is what a consumer compares for those.",
"type": ["string", "null"]
},
"closure_hash": {
"description": "sha256 over the entry's whole closure, as the catalog computed it. This is what makes the folder checkable rather than merely present: `validate` rehashes each entry against this value and names any whose bytes have moved, detecting file changes against the locally recorded hash under SPM-L0-49. This checks local consistency; coordinated file and hash edits can pass.",
"type": "string",
"pattern": "^[0-9a-f]{64}$"
},
"source_commit": {
"description": "The library commit this entry was published from, so a holder can trace its bytes back to the source that produced them without the server's help.",
"type": "string",
"minLength": 7
},
"fetched_at": {
"description": "When this entry was written into the folder, ISO 8601 in UTC. The publish's own date is the catalog's; this is the consumer's, and the two differ whenever a project takes a version some time after it was published. Spelled as a pattern rather than JSON Schema's `date-time` format, because the format vocabulary is an optional ajv package this project does not ship and an unrecognized format is silently ignored under strict mode — a check that passes anything.",
"type": "string",
"pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(\\.[0-9]+)?Z$"
}
}
}
}
}
}