From 67e991ed2da37f08b6cb7a8ad57c2b3d4b4dad3b Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 16:03:49 +0100 Subject: [PATCH] feat(uuid-v7): exempt registry-assigned Julia dependency UUIDs Julia names every dependency by the UUID the General registry assigned it, so a Julia repository cannot pass check-uuid-v7.sh however it is written. The standard already says external identifiers are preserved and typed explicitly; Project.toml dependency tables are such a typed context. The checker now skips the [deps], [weakdeps] and [extras] tables of Project.toml / JuliaProject.toml, and Julia Manifests. A package's own top-level `uuid =` is still checked, so new Julia packages mint v7 before registration. Scanned text is a subset of before: nothing that passed fails. Five new cases in uuid-v7-test.sh (16/16 pass). Mutants: the main checker fails exactly the two acceptance cases; a whole-file Project.toml exemption fails exactly the two narrowness cases. Standard revised to v1.1. Owner decision 2026-10-02 (selection UI): dependency tables only. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj --- docs/UUID-V7-ESTATE-STANDARD.adoc | 12 ++++++++++++ scripts/check-uuid-v7.sh | 21 ++++++++++++++++++++- scripts/tests/uuid-v7-test.sh | 18 ++++++++++++++++++ 3 files changed, 50 insertions(+), 1 deletion(-) diff --git a/docs/UUID-V7-ESTATE-STANDARD.adoc b/docs/UUID-V7-ESTATE-STANDARD.adoc index 331bb7c4c..69c1b52cd 100644 --- a/docs/UUID-V7-ESTATE-STANDARD.adoc +++ b/docs/UUID-V7-ESTATE-STANDARD.adoc @@ -135,6 +135,14 @@ and can be run against a repository or a list of files. It is intentionally a supplement to type-aware tests: absence of a literal does not prove that a runtime generator is compliant. +Julia project files are the one typed external-identifier context the checker +recognises by itself. The General registry assigns every Julia package its UUID +and Julia does not let a dependant change it, so the `[deps]`, `[weakdeps]` and +`[extras]` tables of `Project.toml` / `JuliaProject.toml`, and every +`Manifest*.toml` / `JuliaManifest*.toml`, are not scanned. A package's own +top-level `uuid =` is still checked: a new estate Julia package MUST mint it as +v7 before it is first registered, because the registry fixes it from then on. + == References and ownership The specification is RFC 9562, *Universally Unique IDentifiers (UUIDs)*, @@ -146,3 +154,7 @@ Revision history: * 2026-09-29 — v1.0: UUID v7 made the sole estate UUID standard; migration and enforcement requirements established. +* 2026-10-02 — v1.1: the checker no longer scans registry-assigned Julia + dependency UUIDs (Project.toml dependency tables, Manifests). Migration + impact: no repository that passed before fails now; Julia repositories whose + only findings were dependency UUIDs now pass. Package-own UUIDs stay governed. diff --git a/scripts/check-uuid-v7.sh b/scripts/check-uuid-v7.sh index 0b93e069e..ff07c5b46 100755 --- a/scripts/check-uuid-v7.sh +++ b/scripts/check-uuid-v7.sh @@ -7,6 +7,25 @@ if [ "$#" -eq 0 ]; then set -- . fi +# Print the text of a file that is subject to the v7 rule. +# +# Julia project files name each dependency by the UUID the General registry +# assigned it. Those are external identifiers (the standard: preserve and type +# explicitly), so the [deps], [weakdeps] and [extras] tables of a +# Project.toml / JuliaProject.toml are not scanned, and neither is a Manifest +# (every entry is a resolved dependency). Everything else in a project file, +# including the package's own top-level `uuid =`, is still checked. +scannable_text() { + case "${1##*/}" in + Manifest.toml|Manifest-v*.toml|JuliaManifest.toml|JuliaManifest-v*.toml) ;; + Project.toml|JuliaProject.toml) + awk '/^[[:space:]]*\[/ { t = $0; gsub(/[[:space:]]/, "", t); sub(/#.*/, "", t) + skip = (t == "[deps]" || t == "[weakdeps]" || t == "[extras]") } + !skip' "$1" ;; + *) cat "$1" ;; + esac +} + # A UUID literal is v7 only when the version nibble is 7 and the variant nibble # is 8, 9, a, or b. Keep this POSIX so it can run in every estate checkout. status=0 @@ -28,7 +47,7 @@ while IFS= read -r file; do *) printf '%s: non-v7 UUID literal (%s)\n' "$file" "$uuid" >&2; status=1 ;; esac done < "$WORK/t/blob.bin" expect 0 "a v4 inside a binary file is ignored" +# Julia project files: registry-assigned dependency UUIDs are external IDs. +fresh; printf 'name = "P"\nuuid = "%s"\n\n[deps]\nX = "%s"\n\n[weakdeps]\nY = "%s"\n\n[extras]\nZ = "%s"\n' \ + "$V7_8" "$V4" "$V4" "$V4" > "$WORK/t/Project.toml" +expect 0 "v4 dependency UUIDs in Project.toml [deps]/[weakdeps]/[extras] are accepted" + +fresh; printf 'name = "P"\nuuid = "%s"\n\n[deps]\nX = "%s"\n' "$V4" "$V7_8" > "$WORK/t/Project.toml" +expect 1 "a v4 package's own uuid in Project.toml is rejected" + +fresh; printf 'uuid = "%s"\n[ deps ] # comment\nX = "%s"\n\n[compat]\n\n[sources]\nY = "%s"\n' \ + "$V7_8" "$V4" "$V4" > "$WORK/t/JuliaProject.toml" +expect 1 "the exemption ends at the next table header" + +fresh; printf '[deps]\nX = "%s"\n' "$V4" > "$WORK/t/deps.toml" +expect 1 "a [deps] table outside a Julia project file is not exempt" + +fresh; mkdir -p "$WORK/t/docs"; printf '[[deps.X]]\nuuid = "%s"\n' "$V4" > "$WORK/t/docs/Manifest-v1.12.toml" +expect 0 "a v4 in a Julia Manifest is accepted" + echo "PASS=$pass FAIL=$fail" [ "$fail" -eq 0 ]