Packages and manifests
Bind readable source to a profile, capability envelope, and immutable package commitment.
One logical manifest, two representations
The reference source tooling reads a sibling hybrid.toml file. The Core registry and published package view use a JSON manifest object. Both describe top-level profile, entrypoints, execution_limit, and capabilities. Do not use the older illustrative [contract] wrapper or an entrypoint mapping table for this profile.
profile = "hybridscript-0.1-preview"
entrypoints = ["accumulate"]
execution_limit = 50000
[capabilities]
state = ["private:read", "private:write"]
events = ["demo.*"]Required fields
| Field | Rule |
|---|---|
| profile | Must match the selected policy name. |
| entrypoints | Non-empty string list; its set must exactly match the decorated public functions. |
| execution_limit | Integer from 1 to 10,000,000; booleans are not integers here. |
| capabilities | Required table/object. state and events may be empty lists. |
| capabilities.state | Only private:read and private:write are admitted. |
| capabilities.events | Non-empty string entries; exact names or trailing-* prefixes. |
What the package commits to
The hybrid.contract-package.v0.1 descriptor binds the profile, source hash, manifest hash, policy hash, capability hash, resource schedule, normalized entrypoints, and execution limit. Its canonical hash is the package identifier. Editing source, manifest, policy, or budget can change the package identity.
The source hash is over the exact UTF-8 source bytes. The manifest hash is over the parsed canonical object, not the displayed JSON indentation or TOML whitespace. Preserve originals when checking commitments; do not hash shortened Explorer identifiers.
Publication is a separate operation
Source validation and package construction do not publish, deploy, or invoke anything. Follow the enabled Execution Studio API workflow for your workspace. A published package can have zero executions. An entry in a public registry does not grant callers access to invoke it.