Registry
Registry is the living public world around software. It is not a second factory and not an App Store grid.
Discover
Section titled “Discover”Discover is a deterministic public timeline with a closed event set:
shot.shipped— the one birth of a public Shot;shot.updated— each later public release;shot.forked— an exact parent-release relationship;claim.edition_closed— a finite or timed edition reached its boundary.
Events are ordered from canonical receipt and block facts, with idempotent reorg handling. Individual Claims do not flood the timeline; counts and closure summarize them.
Following
Section titled “Following”Following filters public events using exact BuilderIDs held as a private preference in the encrypted Mac/Companion relationship. Follow and Unfollow are idempotent, durable while either peer is offline, and survive handle changes.
There is no public follow graph, follower count, leaderboard, popularity score, token, or server-owned social identity.
Updates
Section titled “Updates”Updates is a private high-signal inbox for facts that directly involve the person: a claimed app changed, preparation is ready, a fork of their Shot shipped, their edition closed, an alias changed, publication needs approval, or a private evolution completed. Stable IDs and paired-device reconciliation prevent restart spam.
Generic Discover traffic and individual Claims do not enter Updates.
Verification boundary
Section titled “Verification boundary”The service database is an index. A security-sensitive client independently checks the signed activation, active chain and contract, current Builder authority, canonical transaction receipt, current Registry head, Companion-signed catalog, public checkpoint digest, and exact source bytes.
Catalog reachability is not labeled chain verification. A card can be visible before the client has enough evidence to install it; the decisive verification runs when a person chooses Claim, Install, or Fork.
Blob durability boundary
Section titled “Blob durability boundary”The public catalog remains on the Registry’s durable local volume. Only its immutable source and icon bytes may use private Cloudflare R2, selected by the server. Final objects are keyed by the signed SHA-256 digest, written create-only, and streamed back through digest and length verification before a catalog record becomes visible. ETags are not content evidence.
Public clients continue to use the Registry route, not an R2 hostname. The
route supports full reads, HEAD, and one byte range. A missing object is
404; storage unavailability is 503 and is never disguised as absence.
See current status for which public reads and writes are actually activated now.