Realm

v0

gno.land/r/moul/x/provable/v0

Render

provable

What gno.land can and cannot prove about itself, demonstrated rather than asserted.

The log

An append-only Merkle mountain range. Appending costs O(log n) hashes and never rebuilds.

FieldValue
Entries3 / 512
Stored hashes4
Peaks2
Rootc9d22dd237c668944fde619edb56cc1bee0e988b03ac08694f6d3aba440c0776

This root is also the Tendermint simple-tree root over the same entries, so any Tendermint verifier accepts it. Verify and VerifyFixed check the two proof encodings against it.

What the chain can prove

gno.land/pkg/gnoland/app.go mounts exactly two stores. One is IAVL and merkleized, the other is a plain dbadapter whose Commit is documented as "Always returns a zero commitID, as dbadapter store doesn't merkleize".

DataStoreProvable against the app hash
Package sourceiavlyes
Account balancesiavlyes
Escaped object hashes (cross-realm)iavlyes, the hash only
Realm objects, types, realm metadatabaseno
This logbaseno

What that means here

A proof from this realm says this entry is consistent with the root this realm published. It cannot say this root is the chain's own, for two independent reasons:

  1. Realm state is not merkleized, so there is no state proof to produce.
  2. chain/runtime exposes ChainID, ChainDomain, ChainHeight and GetSessionInfo and nothing else. No app hash, no block hash, no header. A realm has no trusted root to check anything against.

Anything built on Merkle proofs in a gno realm is trust-minimised relative to a committed root, never trustless. Saying otherwise would be the interesting-sounding half of a true story.

Entries

#Entry
0genesis of this log
1a second commitment
2a third commitment

Transactions

HashBlockTimeMsgCallerStatus
9097984460…2095B9A8272,69217d agoEnablePkg—ok
DD24EF909B…43A4E4E7272,41217d agoAddPackage—ok

Calls, deploys, and child packages in indexed history.

Call function

Source (qfile)