README.md
gno.land/r/moul/gnopm/registry/v0
An open, on-chain map from a deployed gno package path back to the source that produced it: repository, commit, directory.
The domain model lives in
gno.land/p/moul/gnopm/v0, which is also where the
reasoning is written down. This realm is the wiring: the routes, the authority
rule and the events.
It cannot promise, and does not pretend to
Nothing here is verified and nothing here can be. A realm cannot clone a repository, so it cannot check that the bytes at the claimed commit are the bytes deployed at the claimed path. What it stores is testimony under a signature: this address says this package came from that source.
That is still worth storing, for two reasons.
It is testimony in the shape a verifier needs. Path, repository, commit and
directory are precisely the four inputs to "hash the addpkg payload of that
directory and compare it with what the chain hands back", which
gnopm already does against a local tree
(gnopm verify -deployed). The realm does not answer the question; it makes the
question answerable by anything that can clone.
The chain knows who signed. A claim from the address that owns the package path's namespace comes from the party that controls the path. That is not proof the source matches, it is proof of who is speaking, and it is the strongest signal available without a chain-level feature.
Open, and tagged
Anyone may claim any path, including one they had nothing to do with. A claim from an address that does not own the namespace is not hidden: it renders under its own heading, below the owner's, and says so.
Suppressing it was the alternative and it is worse. A registry that only accepts self-registrations is empty on day one, when almost nothing has been registered by its own deployer, and an empty registry teaches nobody anything.
A claimant may always withdraw their own claim, and may never touch anyone else's.
Routes
| path | page |
|---|---|
/ |
every claimed package path, paginated with ?page=N |
/<package path> |
the claims about one package, owner first |
/help |
what this realm is and how to write to it |
A package path contains slashes, so it arrives at Render already split; the
routing is the rejoin.
Writing
1gnokey maketx call -pkgpath gno.land/r/moul/gnopm/registry/v0 \
2 -func Register \
3 -args "gno.land/p/moul/md/v1" \
4 -args "https://github.com/moul/gno-contracts" \
5 -args "<40 or 64 char lowercase hex commit>" \
6 -args "p/moul/md" \
7 -args "refs/tags/v1.0.0" \
8 -gas-fee 1000000ugnot -gas-wanted 5000000 \
9 -broadcast -chainid <chain> -remote <rpc> moul
dir is empty for a package at the repository root. ref is optional and is
never the thing verified: a ref moves, a commit does not. It is recorded so a
reader can tell a claim pinned to a released tag from one pinned to a commit on
nobody's branch, and so a verifier can report a commit since orphaned by a
force-push.
Calling Register again for the same path replaces your own claim and nobody
else's, which is how a claim moves to a new commit after a redeploy.
Withdraw takes it back.
Reading, from another realm or an indexer
1registry.HasClaims(pkgPath) // has anyone said anything
2repo, commit, dir, ok := registry.OwnerClaim(pkgPath) // the namespace holder's claim
3registry.PackageCount()
4registry.ClaimCount()
OwnerClaim is the only read that filters, and it filters on the one thing the
chain can prove. Ownership is recomputed on every call rather than stored,
because a name can be transferred.
Two events carry the same information to an indexer, which is how an explorer
follows the registry without polling: SourceClaimed (pkgpath, claimant,
repo, commit) and SourceWithdrawn (pkgpath, claimant).
Why private = true
Standard for a new realm here: it can be redeployed at this path by its creator
instead of burning a /v1. The cost is real and worth stating, because this
realm holds data other people wrote: a redeploy wipes every package-level
variable, so every claim in it goes with it. Claims are cheap to re-make and
each one is a signed statement its author can reissue, which is what makes the
trade acceptable here and would not make it acceptable for a realm holding
balances.
What is deliberately not here
- No verification, per the top of this file. The check that actually proves
something needs to clone a repository and hash a tree, which is a service, not
a realm. gnopm already holds the whole of that logic (
hashPayloadhashes exactly whataddpkgwould upload;gnomodnormhandles the fact that the chain rewritesgnomod.tomlon publish, appending an[addpkg]table, so a naive byte comparison reports every package as differing forever). - No curation, no voting. Whose claim to believe is a judgement that wants the deployer identity from chain history, which an explorer has and a realm does not.
- No compare-and-swap on update.
r/moul/forgetakes the expected previous object id when moving a ref, because two maintainers racing on a branch is a real lost-update. Here a claimant only ever overwrites their own claim, so there is nobody to race.
Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.
Dependency graph:

⚠️ Disclaimer: provided as-is, without warranty; not security-audited. Full disclaimer: DISCLAIMER.