IsEnabled
Command
gnokey query vm/qeval -remote "https://rpc.topaz.testnets.gno.land" -data "gno.land/r/sys/names.IsEnabled()"
Result
Package names enforces namespace permissions for package deployment.
Two namespace shapes grant deploy authority when enforcement is enabled:
PA (personal-address) namespaces — gno.land/{r,p}/<addr>/* — the deployer's address string equals the namespace literal. Anyone can deploy under their own address.
Registered-name namespaces — gno.land/{r,p}/<name>/* — r/sys/users has a (name → addr) mapping where the resolved address equals the deployer AND the name is the user's CURRENT name (not a historical alias from a rename chain). This is the bridge that lets r/sys/namereg/v1 (or any other DAO-whitelisted controller) grant deploy authority via name registration.
Authority is unscoped: a registered name owns BOTH r/<name>/* and p/<name>/* paths. There is no sub-prefix isolation (e.g. r/u/<name>/*).
The realm exposes an emergency-halt switch via SetPaused. When paused, the verifier rejects EVERY namespace check — PA included — until unpaused. This is the "true emergency" semantic; the narrow alternative (pause registered-name only, preserve PA) was considered and rejected because the threats most likely to justify pausing this realm (verifier bug, compromised controller, signature-layer incident) do not reliably exempt PA from the same blast radius.
gnokey query vm/qeval -remote "https://rpc.topaz.testnets.gno.land" -data "gno.land/r/sys/names.IsEnabled()"