realmURL
untyped stringrealmURL is this realm as gnoweb serves it. Absolute, because the path ends in /v0 and a relative link would resolve against the parent directory. Not derived at runtime: a Render has no cur, and CurrentRealm there is the caller. TestRealmURLMatchesTheModule pins it to the module line.
Value
"/r/moul/zones/v0"
pkgPath
untyped stringpkgPath is this realm's package path, for the action links.
Value
"gno.land/r/moul/zones/v0"
action
func(title string, fn string, args []string) stringaction is a call link to a function of THIS realm, named explicitly. Not ui.Action: that resolves its target through unsafe.CurrentRealm, which in a borrowed Render is the caller, so a realm embedding this page would get links that call its own functions. filetests/z\_borrowed\_render\_filetest.gno pins it from a caller realm, the only place the difference shows.
- OID
- 07b342…f101:3
action details
PageSize
untyped bigintPageSize is how many rows any table here shows at once. Every list is paginated and every page reads only its own records, because vm/qrender is gas-metered (3B per query) and a Render that outgrows it stops answering instead of slowing down. At the caps a page reads its 25 records, one lookup per URL it may mark flagged (each row's main RPC on the index; the zone's RPC and gnoweb on its page), the zone serving this chain for the printed command, the curators, and a few index nodes. Escaping free text is what dominates: about 97k gas a character on a node, so a page of full-length fields costs on the order of a billion, still under the ceiling.
Value
(25 <untyped> bigint)
Render
func(path string) stringRender is the whole public surface, three pages: the zone list (official, or retired with ?status=retired), one zone (?kind= narrows its endpoints), and the proposals (pending, or rejected with ?status=rejected). Every list takes ?page=.
- OID
- 07b342…f101:5
Render details
renderIndex
func(req *v0.Request) string- OID
- 07b342…f101:6
renderIndex details
zoneTable
func(status v0.Status, req *v0.Request, empty string) (string, int)zoneTable renders one page of the zones with that status, and returns how many pages there are.
- OID
- 07b342…f101:7
zoneTable details
renderZone
func(slug string, req *v0.Request) string- OID
- 07b342…f101:8
renderZone details
renderProposals
func(req *v0.Request) string- OID
- 07b342…f101:9
renderProposals details
pageCount
func(n int) intpageCount is how many pages n rows make, at least one.
- OID
- 07b342…f101:10
pageCount details
pageNum
func(req *v0.Request, pages int) intpageNum reads ?page= and clamps it into 1..pages: it is a reader's input, and ?page=-1 must not render a footer saying "page -1 of 2".
- OID
- 07b342…f101:11
pageNum details
pager
func(path string, query string, page int, pages int) stringpager links the neighbouring pages of a list, keeping the list's other query parameters (query ends in "&" when not empty). One page needs no pager.
- OID
- 07b342…f101:12
pager details
kindLink
func(label string, url string, n int, current bool) string- OID
- 07b342…f101:13
kindLink details
notFound
func(msg string) string- OID
- 07b342…f101:14
notFound details
queryCommand
func(call string) stringqueryCommand is the gnokey line that evaluates call against this realm. The remote is looked up in the registry itself, by the chain id this realm is running on, so the command a reader copies points at the chain they are reading. A chain the registry does not list gets no -remote, rather than a guessed one, and so does a chain id two approved zones share (every gnodev is "dev"): picking one would be the same guess. A reader pastes this into a shell, so the remote must never carry shell syntax. Two layers make sure: the main RPC is validated down to \<scheme>://\<host>\[:\<port>], host \[A-Za-z0-9.-] and port digits, which leaves nothing a shell reads as syntax; and it is single-quoted anyway, a quote being the one character no URL here can contain, so a later, wider validator does not reopen it. The call is built from charset-checked slugs and literals.
- OID
- 07b342…f101:15
queryCommand details
exampleSlug
func() stringexampleSlug is the zone the index's example asks for peers of: the one serving the chain this page is read on, when there is exactly one and it lists a peer, else onyx (one zone and an index count read).
- OID
- 07b342…f101:16
exampleSlug details
para
func(s string) stringpara is one paragraph as a Join part. Not md.Paragraph, whose trailing blank line plus Join's separator makes two in a row, which an example cannot pin.
- OID
- 07b342…f101:17
para details
zoneLink
func(z v0.Zone) stringzoneLink is a zone's title linking to its page, for a TABLE cell. Built by hand rather than with md.Link, whose text escape is for prose and leaves a pipe literal, so a title like "Alice|official" would open a column in every zone table. ui.Cell escapes the pipe too; the destination is a constant plus a slug checked to \[a-z0-9-] at write time.
- OID
- 07b342…f101:18
zoneLink details
urlFact
func(z v0.Zone, kind v0.EndpointKind, url string) stringurlFact shows a zone's URL as its own text, never behind a label, so a reader sees where it goes: a proposal's "genesis.json" link could otherwise open anything, a pre-filled transaction form included, right under the Approve button. Only an approved zone's URLs are links; a proposal's are code, to copy and check, not to click. A URL the zone also lists, under the kind it is shown as, as a flagged endpoint is code and marked, never a link: the page does not offer what its own endpoint table says not to use. kind is what the URL is shown as, "" for the genesis URL, which no endpoint kind lists (flaggedAs).
- OID
- 07b342…f101:19
urlFact details
prose
func(s string) stringprose and cell escape a caller's free text for a sentence and a table cell, plus what ui.Inline and ui.Cell leave alone: gnoweb turns an @name, and a bare g1 address after a space or at the start, into a user-profile link with an icon, so "run by @gnocore" or "run by g1…" would vouch for an account the registrant chose.
- OID
- 07b342…f101:20
prose details
cell
func(s string) string- OID
- 07b342…f101:21
cell details
escapeMentions
func(s string) stringescapeMentions backslash-escapes every @, and writes the 1 of every g1 as a character reference. It runs after ui.Inline or ui.Cell, which escape every & the caller typed, so the only reference in the output is this one; goldmark decodes it back to "1" after the mention parser has looked and not matched. One pass, and none at all when there is nothing to escape: it runs on every free-text field of every page.
- OID
- 07b342…f101:22
escapeMentions details
rpcFlag
func(z v0.Zone) stringrpcFlag marks a zone's main RPC when the endpoint table flags it, so the table, the zone page and the printed command never disagree.
- OID
- 07b342…f101:23
rpcFlag details
rpcFlagged
func(z v0.Zone) bool- OID
- 07b342…f101:24
rpcFlagged details
flaggedAs
func(z v0.Zone, shown v0.EndpointKind, url string) boolflaggedAs reports whether a URL the page shows as a kind (the main RPC as rpc, the gnoweb URL as gnoweb) is listed under that kind and flagged. Only that kind's verdict counts. A listing under another kind is anybody's to make on an approved zone, so letting its flag mark the zone's own URL would let a stranger's mis-kinded entry, flagged as mis-kinded, mark an official URL; a curator who means the zone's URL flags it under its own kind. The lookup compares in Canonical form, which reads an rpc tcp:// as the http:// gnokey dials, so either spelling finds the other.
- OID
- 07b342…f101:25
flaggedAs details
revStr
func(z v0.Zone) string- OID
- 07b342…f101:26
revStr details
isKind
func(k v0.EndpointKind) bool- OID
- 07b342…f101:27
isKind details
statusBadge
func(s v0.Status) string- OID
- 07b342…f101:28
statusBadge details
endpointStatus
func(e v0.Endpoint) string- OID
- 07b342…f101:29
endpointStatus details
reviewText
func(by .uverse.address, at int64, reason string) string- OID
- 07b342…f101:30
reviewText details
curatorList
func() string- OID
- 07b342…f101:31
curatorList details
seedReason
untyped stringseedReason is the review every seeded zone and endpoint carries, so a reader can tell a deploy-time entry from one a curator reviewed later, and knows how old the check is.
Value
"seeded at deploy; probed 2026-10-01"
seedZone
typeseedZone is one zone the realm starts with, approved, plus the endpoints it starts with. Every seeded endpoint carries the probe's verdict, which is per zone: verified with seedReason when the zone's endpoints answered, flagged with failed, the observed failure, when they did not. Flagged rather than left unverified, because "probed and down" and "nobody looked" are different facts and only a review can say which.
Value
v0.seedZone
seeds
func() []v0.seedZoneseeds are the four zones this registry opens with. Every address below was probed on 2026-10-01: each RPC's /status answered with the chain id given here, except staging, whose RPC answered "temporarily unavailable" and whose gnoweb answered 503, which is why its endpoints are seeded flagged with that. The peers are the persistent\_peers each network's VALIDATOR.md publishes in the gnolang/gno monorepo, under misc/deployments. A function, not a package-level var: a realm's package variables are its database, so a var here would keep every seed stored a second time, forever, beside the registry copy seed() makes of it.
- OID
- 07b342…f101:32
seeds details
seed
func()seed files every seed through the same Registry methods a caller's transaction goes through (the gated ones, so a seeded endpoint is not Exempt; each is ruled on at once, so none is clearable), so a seed that would fail validation fails the deploy instead of shipping a zone no later edit could reproduce.
- OID
- 07b342…f101:34
seed details
Admin
.uverse.addressValue
<gnolang.StringValue>
ReviewWindow
untyped bigintReviewWindow is how many blocks must pass before the author of a change may change it again, a rate bound rather than a review deadline (100 blocks is minutes): after a zone was proposed or last edited (by anybody) before its proposer may edit or withdraw it, and after an endpoint was registered before its registrant may withdraw it. Every edit bumps the revision a curator's decision must name, and a withdrawal plus a fresh proposal or registration does the same with a new revision or id, so without a wait a proposer or a registrant acting every block would keep their entry out of every curator's reach. Curators are not limited.
Value
(100 <untyped> bigint)
MaxCurators
untyped bigintMaxCurators bounds curators and open invitations together. The curator list renders on the index page, and only curators can grow it, but a bound costs nothing and an unbounded list on a public page is a page someone can break.
Value
(16 <untyped> bigint)
reg
*v0.Registry- OID
- 07b342…f101:36
reg details
curators
v1.Set- OID
- 07b342…f101:89
curators details
invited
v1.Set// invited by a curator, not yet accepted
- OID
- 07b342…f101:92
invited details
inviter
map[.uverse.address].uverse.address// invitee -> the curator who invited them; lookups only
- OID
- 07b342…f101:95
inviter details
init.42
func()- OID
- 07b342…f101:96
init.42 details
ProposeZone
func(slug string, chainID string, title string, description string, kind string, gnowebURL string, rpcURL string, genesisURL string)ProposeZone files a new zone for review. Anybody may; it is listed as a proposal until a curator approves or rejects it. The review queue's caps (zones.MaxPending, zones.MaxPendingPerProposer) do not stop a curator, who also has the registry's last zones.ReservedForReviewers places, so neither a flood nor a full registry locks out the people who clear it. kind is mainnet, testnet, devnet or local. gnowebURL and genesisURL may be empty; rpcURL may not, and is \<scheme>://\<host>\[:\<port>] with no path, which is what gnokey -remote takes.
- OID
- 07b342…f101:98
ProposeZone details
EditZone
func(slug string, revision int64, chainID string, title string, description string, kind string, gnowebURL string, rpcURL string, genesisURL string, reason string)EditZone replaces a zone's Info, every field but its slug and status. A curator may edit any pending or approved zone; the proposer may edit their own while it is pending. revision is the zone's Revision the edit was written against: it fails if the zone changed in between, its content or its status. Every edit bumps the revision, so a decision prepared against the old one fails too. A proposer edits only ReviewWindow blocks after the zone was proposed or last edited, and an edit that changes nothing is refused. On a pending zone the reason must be empty; on an approved one it is required and replaces the review on record, so the page names who changed the values, and why. A new chain id sends the zone's verified endpoints back to unverified. Leaving the local kind drops every endpoint on a private host, and is refused while one carries a curator's ruling (a verified one its registrant may withdraw first); the proposer's edit only drops endpoints that are theirs and that they could withdraw on their own (RemoveEndpoint), as for RemoveZone. A new main RPC or gnoweb a stranger (on an approved zone, its proposer too) already lists under its kind would make that listing the zone's own: on a curator's edit it is dropped if nobody ruled on it, and refuses the edit if a curator did; a proposer's edit refuses rather than drop what is not theirs; and a flagged listing refuses the edit whoever holds it. The registry validates the edit before it drops or resets anything, and a refusal reverts the edit with it. A rejected or retired zone cannot be edited.
- OID
- 07b342…f101:99
EditZone details
ApproveZone
func(slug string, revision int64, reason string)ApproveZone makes a zone official. revision is the zone's Revision as you read it (the zone page's Approve link carries it): if the zone changed since, its content or its status, the approval fails and you read it again. The reason is optional.
- OID
- 07b342…f101:100
ApproveZone details
RejectZone
func(slug string, revision int64, reason string)RejectZone turns a proposal down. The reason is required, and public. revision is the zone's Revision you read, as for ApproveZone.
- OID
- 07b342…f101:101
RejectZone details
RetireZone
func(slug string, revision int64, reason string)RetireZone marks an official zone as no longer running, and sends its verified endpoints back to unverified. The reason is required: it is what an operator still holding the chain id will read. revision is the zone's Revision you read.
- OID
- 07b342…f101:102
RetireZone details
RemoveZone
func(slug string, revision int64)RemoveZone deletes a pending or rejected zone and its endpoints. revision is the zone's Revision you read: a removal meant for one proposal fails on another proposed again under the same slug. A curator may remove any pending or rejected zone. The proposer may withdraw their own only while it is pending, ReviewWindow blocks after it was proposed or last edited (so withdrawing and proposing again cannot dodge the edit wait), while every endpoint on it is theirs (the deposit is refunded to whoever signs the removal, so removing somebody else's endpoints would collect what they paid) and each one is one they could withdraw on its own (RemoveEndpoint): removing the zone must not wipe a curator's flag or unverify, or skip an endpoint's own wait. A rejected zone is the curators' record: only a curator removes it, or newer rejections push it out, and the rejection's deposit, paid by the curator, is not the proposer's to collect. A zone that was ever official is never removed this way: an approved one is retired, and a retired one is kept until newer retirements push it out.
- OID
- 07b342…f101:103
RemoveZone details
RegisterEndpoint
func(slug string, kind string, addr string, label string) int64RegisterEndpoint lists an endpoint on a zone and returns its id. On an approved zone anybody may, except the zone's own main RPC under rpc and gnoweb under gnoweb, which only a curator lists (or the proposer while the zone is pending: every proposer right ends at approval); on a pending one only the proposer or a curator, so a stranger cannot pin a proposal the proposer then cannot withdraw. It shows as unverified until a curator checks it. A curator also registers past the review queue's caps and into the zones.ReservedForReviewers places a gated registration may not take, never past zones.MaxEndpointsPerZone. kind is rpc, gnoweb, seed, peer, indexer, faucet or explorer. addr is a URL, or \<node id>@\<host>:\<port> for a seed or a peer. label is optional: who runs it, in your words.
- OID
- 07b342…f101:104
RegisterEndpoint details
VerifyEndpoint
func(id int64, zoneRevision int64, revision int64, reason string)VerifyEndpoint marks an endpoint as checked against its zone. revision is the endpoint's revision as read (the endpoint table's revision column), and zoneRevision the zone's (the zone page shows it): the verdict fails if either changed since, another curator's verdict on the endpoint, or any edit or status change of the zone (what is verified is that it answers for this zone's chain id). The reason is optional. Each verdict may be given again with a new reason, to restate it.
- OID
- 07b342…f101:105
VerifyEndpoint details
FlagEndpoint
func(id int64, revision int64, reason string)FlagEndpoint tells readers not to use an endpoint. The reason is required. revision is the endpoint's, as for VerifyEndpoint; a flag is not bound to the zone, so editing the zone cannot hold off a warning.
- OID
- 07b342…f101:106
FlagEndpoint details
UnverifyEndpoint
func(id int64, revision int64, reason string)UnverifyEndpoint puts an endpoint back to unverified, for one that changed hands or needs checking again. revision is as for FlagEndpoint.
- OID
- 07b342…f101:107
UnverifyEndpoint details
RemoveEndpoint
func(id int64, revision int64)RemoveEndpoint deletes an endpoint. revision is its revision as read: the removal fails if a verdict landed since, rather than delete one nobody saw. A curator may remove any. Its registrant may remove it unless a curator flagged or unverified it (a flag is a warning, an unverify carries why, and removing and registering it again would wipe either; a verified one the registrant may take down, since listing it again starts it unverified, and so one a reset sent back to unverified, since the reset says the zone changed, not it), only while its zone is pending or approved (a rejected or retired zone is a record, endpoints and all), and only ReviewWindow blocks after registering it (removing and registering again every block would give it a new id faster than a curator could flag the old one).
- OID
- 07b342…f101:108
RemoveEndpoint details
ClearUnreviewed
func(slug string, throughRevision int64) intClearUnreviewed removes, in one call, every endpoint on a zone that is zones.Endpoint.Clearable (nobody ruled on it, and no reviewer registered it past the caps), and returns how many. There are never more than zones.MaxUnverifiedPerZone: clearable endpoints are a part of the review queue its gate holds there, and no reset makes one. It is the answer to a flood that cycles: registrants who withdraw and register again each review window keep the queue full, and one removal per transaction lets them refill it before a curator is done. throughRevision bounds it to what the curator read: an endpoint registered after it (a later Revision) is kept. The deposits go to the curator who signs. At most zones.MaxEndpointsPerZone are read.
- OID
- 07b342…f101:109
ClearUnreviewed details
assertWithdrawable
func(e v0.Endpoint)assertWithdrawable refuses a non-curator's withdrawal of an endpoint a curator flagged or unverified, or one registered less than ReviewWindow blocks ago. Shared by RemoveEndpoint, the proposer's RemoveZone and the proposer's edit off local, so none can do what another refuses.
- OID
- 07b342…f101:110
assertWithdrawable details
AddCurator
func(addr .uverse.address)AddCurator invites another address to curate. Only a curator may. The address becomes a curator when it calls AcceptCurator itself. Two steps, deliberately: a curator set is the one thing a mistake here can lose for good. With a one-step add, a sole curator who invites a mistyped address and then steps down leaves a registry nobody controls; accepting is the proof that somebody holds the key. An invitation dies with its inviter: removing a curator withdraws every invitation they sent.
- OID
- 07b342…f101:111
AddCurator details
AcceptCurator
func()AcceptCurator makes the caller a curator, if a curator invited it.
- OID
- 07b342…f101:112
AcceptCurator details
RemoveCurator
func(addr .uverse.address)RemoveCurator revokes a curator, along with every invitation they sent, or withdraws one invitation. Only a curator may, and the last curator cannot be removed: a registry nobody can curate can never retire a dead zone. Curators are equals: any one may remove any other, the admin included. That is the trust a curator set is, and it is why there are few of them.
- OID
- 07b342…f101:113
RemoveCurator details
GetZone
func(slug string) (v0.Zone, bool)GetZone returns the zone under slug, and whether there is one.
- OID
- 07b342…f101:114
GetZone details
ListZones
func(status string, kind string) []v0.ZoneListZones returns the zones with that status and kind, in the order they were proposed. "" matches any; "approved" is the official list.
- OID
- 07b342…f101:115
ListZones details
GetEndpoint
func(id int64) (v0.Endpoint, bool)GetEndpoint returns the endpoint with that id, and whether there is one.
- OID
- 07b342…f101:116
GetEndpoint details
ListEndpoints
func(slug string, kind string, status string) []v0.EndpointListEndpoints returns a zone's endpoints of that kind and verification, oldest first. "" matches any kind or verdict, so ("onyx", "", "") is everything on onyx and ("onyx", "peer", "verified") is what a cautious node should dial. The zone is required: one zone is at most MaxEndpointsPerZone rows, every zone together is a response no node should be asked for.
- OID
- 07b342…f101:117
ListEndpoints details
ListAddresses
func(slug string, kind string, status string) []stringListAddresses is ListEndpoints reduced to the addresses, which is what a config file wants: ListAddresses("onyx", "peer", "verified").
- OID
- 07b342…f101:118
ListAddresses details
IsInvited
func(addr .uverse.address) boolIsInvited reports whether addr holds a curator invitation it has not accepted yet.
- OID
- 07b342…f101:119
IsInvited details
IsCurator
func(addr .uverse.address) boolIsCurator reports whether addr may curate.
- OID
- 07b342…f101:120
IsCurator details
Curators
func() [].uverse.address- OID
- 07b342…f101:121
Curators details
Invited
func() [].uverse.address- OID
- 07b342…f101:122
Invited details
members
func(set *v1.Set) [].uverse.address- OID
- 07b342…f101:123
members details
review
func(slug string, to v0.Status, revision int64, reason string)- OID
- 07b342…f101:124
review details
reviewEndpoint
func(id int64, to v0.Verification, zoneRevision int64, revision int64, reason string)- OID
- 07b342…f101:125
reviewEndpoint details
endpointFilter
func(slug string, kind string, status string) v0.EndpointFilter- OID
- 07b342…f101:126
endpointFilter details
info
func(chainID string, title string, description string, kind string, gnowebURL string, rpcURL string, genesisURL string) v0.Info- OID
- 07b342…f101:127
info details
caller
func() .uverse.address- OID
- 07b342…f101:128
caller details
assertReviewWindow
func(slug string, z v0.Zone)assertReviewWindow refuses a proposer's edit or withdrawal of a pending zone sooner than ReviewWindow blocks after it was proposed or last edited, by anybody.
- OID
- 07b342…f101:129
assertReviewWindow details
assertCurator
func(who .uverse.address)- OID
- 07b342…f101:130
assertCurator details
mustZone
func(slug string) v0.Zone- OID
- 07b342…f101:131
mustZone details
must
func(err .uverse.error)- OID
- 07b342…f101:132