const DELAY
DELAY is how long a ready release waits before it takes over. It is a constant so that it can never be shortened.
Package data keeps GnoRadio's state apart from its rules. It knows nothing of music: ordered collections of string ke...
Package data keeps GnoRadio's state apart from its rules. It knows nothing of music: ordered collections of string keys to string values, and a vault for the coins of promo budgets (vault.gno).
Each collection belongs to a role, the prefix of its name ("catalog/…"). Only that role's writer realm writes it; anyone reads. A release (new writers for one or more roles) takes over DELAY after every new realm said Ready, all at once, and no data moves. The owner proposes and cancels releases, pauses and resumes roles, passes the role on or renounces it, and can replace the guardian 2x DELAY after saying so. The guardian can only pause and cancel a release. This realm is never replaced: keep it small.
Batch applies up to 64 ops of four strings (store.Ops): "set" or "del", collection, key, value. It reads the strings and keeps nothing else of the caller's slice.
Cancel drops the release not yet in force. Owner or guardian. It never touches a guardian replacement.
Get returns the value at key ("" and false when absent).
GuardianOffer and GuardianAccept pass the guardian role in two steps; the guardian offers it. The owner's only call on the role is GuardianReplace.
GuardianRenounce gives the guardian role up. A replacement the owner already announced still takes over.
GuardianReplace is the owner's way out of a lost or stolen guardian key, which could otherwise cancel every release and pause after every resume for good: to becomes the guardian 2x DELAY (six days) later. The guardian cannot cancel it; the owner withdraws it with to = "" or announces another one, which restarts the clock. The wait outlasts a release's DELAY, so a stolen owner key that replaces the guardian is public for six days before its own release can even start its 72 hours. Owner only.
Index is the number of keys before key: Index(c, b) - Index(c, a) counts the keys in [a, b) without a counter. O(log² n).
IsGnoRadio reports whether addr is a GnoRadio realm: this one, the ticket NFT realm, or any current, proposed or past writer.
Make creates a collection under the caller's role (nothing if it exists): "<role>/<name>", name of a-z 0-9 _, at most 32 bytes in all, 32 per role.
Offer offers the owner role to an address (offering it to the owner cancels the offer); Accept takes it.
Page returns up to limit (1-100) rows with start <= key < end ("" no bound), lowest first or highest first when reverse, as store.Row strings (store.Rows decodes them).
PageAt returns up to limit (1-100) rows from the offset-th key, counted from the highest when reverse.
Pause stops a role's writes and vault operations at once ("" every role); reads and VaultWithdraw go on. on=false resumes the same writer. The owner pauses and resumes; the guardian only pauses, and only while there is an owner to resume.
Paused reports whether a role's writes are stopped now.
Propose adds a role's new writer to the next release. Any change restarts the clock. Owner only.
Ready is a proposed realm's own call (each rules realm exposes it): once every proposed realm said it, the release takes over DELAY later.
Remove deletes a key and reports whether it was there.
Renounce gives the owner role up: writers never change again and nothing can be paused. Refused while a role is paused, which could then never write again. It drops the release not yet in force.
Set writes value at key of a collection of the caller's role.
Size is the number of keys of a collection.
VaultCredit adds amt, which the writer has just sent to this realm, to an account funded by funder. A new funder needs an empty account (VaultRefund first).
VaultDay is the UTC day of the vault's clock, which stands still while any role is paused: a pause never makes a hold lapse, it lapses that much later. The clock lags real time by every past pause, so a hold made after one also lasts that much longer.
VaultHeld is the live hold of an account lapsing on day.
VaultHold reserves amt of the free balance until the end of day on the vault's clock (from VaultDay to 31 days from now).
VaultInfo is an account's funder, balance and free part (not held).
VaultPay pays amt from the live hold lapsing on day to an account outside GnoRadio.
VaultRefund pays the whole balance back to the funder and drops the holds (the profile changed hands). It returns the amount.
VaultRelease gives back up to amt of the hold lapsing on day and returns what it released (less when part of it lapsed or was refunded).
VaultTotal is every account's balance: what this realm holds for them.
VaultWithdraw pays the caller what is free in an account they funded. It works whoever the writer is, while paused and after Renounce.
Writer is the realm that writes a role's collections now.
Writers is the state of every role, as JSON: {"owner","pendingOwner", "guardian","pendingGuardian","nextGuardian","guardianAt","at","roles": {"catalog":{"writer","paused","proposed","ready"},…}}. at is the unix time a ready release takes over, guardianAt the time nextGuardian (the owner's GuardianReplace) does.