func ClaimCount
ActionClaimCount is the total number of claims across every path.
Package registry is an open, on-chain map from a deployed gno package path back to the source that produced it: repos...
gno.land/r/moul/gnopm/registry/v0An open, on-chain map from a deployed gno package path back to the source that produced it: repository, commit, directory.
The domain model lives in
gno.land/p/moul/gnopm/v0, which is also where the
reasoning is written down. This realm is the wiring: the routes, the authority
rule and the events.
Nothing here is verified and nothing here can be. A realm cannot clone a repository, so it cannot check that the bytes at the claimed commit are the bytes deployed at the claimed path. What it stores is testimony under a signature: this address says this package came from that source.
That is still worth storing, for two reasons.
It is testimony in the shape a verifier needs. Path, repository, commit and
directory are precisely the four inputs to "hash the addpkg payload of that
directory and compare it with what the chain hands back", which
gnopm already does against a local tree
(gnopm verify -deployed). The realm does not answer the question; it makes the
question answerable by anything that can clone.
The chain knows who signed. A claim from the address that owns the package path's namespace comes from the party that controls the path. That is not proof the source matches, it is proof of who is speaking, and it is the strongest signal available without a chain-level feature.
Anyone may claim any path, including one they had nothing to do with. A claim from an address that does not own the namespace is not hidden: it renders under its own heading, below the owner's, and says so.
Suppressing it was the alternative and it is worse. A registry that only accepts self-registrations is empty on day one, when almost nothing has been registered by its own deployer, and an empty registry teaches nobody anything.
A claimant may always withdraw their own claim, and may never touch anyone else's.
| path | page |
|---|---|
/ |
every claimed package path, paginated with ?page=N |
/<package path> |
the claims about one package, owner first |
/help |
what this realm is and how to write to it |
A package path contains slashes, so it arrives at Render already split; the
routing is the rejoin.
1gnokey maketx call -pkgpath gno.land/r/moul/gnopm/registry/v0 \
2 -func Register \
3 -args "gno.land/p/moul/md/v1" \
4 -args "https://github.com/moul/gno-contracts" \
5 -args "<40 or 64 char lowercase hex commit>" \
6 -args "p/moul/md" \
7 -args "refs/tags/v1.0.0" \
8 -gas-fee 1000000ugnot -gas-wanted 5000000 \
9 -broadcast -chainid <chain> -remote <rpc> moul
dir is empty for a package at the repository root. ref is optional and is
never the thing verified: a ref moves, a commit does not. It is recorded so a
reader can tell a claim pinned to a released tag from one pinned to a commit on
nobody's branch, and so a verifier can report a commit since orphaned by a
force-push.
Calling Register again for the same path replaces your own claim and nobody
else's, which is how a claim moves to a new commit after a redeploy.
Withdraw takes it back.
1registry.HasClaims(pkgPath) // has anyone said anything
2repo, commit, dir, ok := registry.OwnerClaim(pkgPath) // the namespace holder's claim
3registry.PackageCount()
4registry.ClaimCount()
OwnerClaim is the only read that filters, and it filters on the one thing the
chain can prove. Ownership is recomputed on every call rather than stored,
because a name can be transferred.
Two events carry the same information to an indexer, which is how an explorer
follows the registry without polling: SourceClaimed (pkgpath, claimant,
repo, commit) and SourceWithdrawn (pkgpath, claimant).
private = trueStandard for a new realm here: it can be redeployed at this path by its creator
instead of burning a /v1. The cost is real and worth stating, because this
realm holds data other people wrote: a redeploy wipes every package-level
variable, so every claim in it goes with it. Claims are cheap to re-make and
each one is a signed statement its author can reissue, which is what makes the
trade acceptable here and would not make it acceptable for a realm holding
balances.
hashPayload hashes
exactly what addpkg would upload; gnomodnorm handles the fact that the
chain rewrites gnomod.toml on publish, appending an [addpkg] table, so
a naive byte comparison reports every package as differing forever).r/moul/forge takes the expected previous
object id when moving a ref, because two maintainers racing on a branch is a
real lost-update. Here a claimant only ever overwrites their own claim, so
there is nobody to race.Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.
Dependency graph:

⚠️ Disclaimer: provided as-is, without warranty; not security-audited. Full disclaimer: DISCLAIMER.
Package registry is an open, on-chain map from a deployed gno package path back to the source that produced it: repository, commit, directory.
It is the realm half of gno.land/p/moul/gnopm/v0, which holds the domain model and the whole of the reasoning; this file is wiring. Every exported mutation is a crossing function that resolves the caller, forwards to the library, aborts on error (the only way to revert state in gno) and emits an event for indexers.
Nothing here is verified and nothing here can be. A realm cannot clone a repository, so it cannot check that the bytes at the claimed commit are the bytes deployed at the claimed path. What it stores is testimony under a signature: this address says this package came from that source.
That is still worth storing, for two reasons.
First, it is testimony in the exact shape a verifier needs. Path, repository, commit and directory are precisely the four inputs to "hash the addpkg payload of that directory and compare it with what the chain hands back", which gnopm already does against a local tree (`gnopm verify -deployed`). The registry does not answer the question; it makes the question answerable by anything that can clone.
Second, the chain knows who signed. A claim from the address that owns the package path's namespace comes from the party that controls the path, and OwnedBy reports that. It is computed on every read, never stored, because a name can be transferred and a stored answer would rot into exactly the kind of stale claim this realm exists to distinguish from a live one.
Anyone may claim any path, including one they had nothing to do with. That is deliberate: gating registration on namespace ownership would leave the map empty on day one, when almost nothing has been registered by its own deployer, and an empty registry teaches nobody anything. A stranger's claim is not suppressed, it is labelled and ranked below the owner's, and Render never presents an unverified claim as a fact.
A claimant may always withdraw their own claim, and may never touch anyone else's.
ClaimCount is the total number of claims across every path.
HasClaims reports whether anything has been said about pkgPath. Cheap enough for another realm or an indexer to ask per package.
OwnerClaim returns the repository, commit and directory claimed by the party that owns pkgPath's namespace, and whether such a claim exists.
This is the only read that filters, and it filters on the one signal the chain can actually prove. Everything else a caller wants is in Render or in the events.
PackageCount is how many package paths carry at least one claim.
Register records that pkgPath was built from dir of repo at commit.
Calling it again for the same path replaces the caller's own claim and nobody else's, so moving a claim to a new commit after a redeploy is one call with no read first.
ref is optional and is never the thing verified: a ref moves, a commit does not. It is recorded so a reader can tell a claim pinned to a released tag from one pinned to a commit on nobody's branch, and so a verifier can report a commit that has since been orphaned by a force-push.
dir is empty when the package sits at the repository root.
Withdraw removes the caller's own claim about pkgPath.