Packages and updates

Format

.iropkg is a zip read by the kernel’s own strict reader (stored/deflate, no zip64/encryption/links, ≤ 5,000 files, ≤ 100 MiB) with signature.json checked in memory before anything is written: Ed25519 over a canonical { id, version, files } list plus rotation chains. The first install pins the publisher’s key for updates. Every publisher follows the same signature, pin and consent checks.

Install sources

Install package…, drop on Iro’s window, or an iro://install?url=…&sha256=… link. Sources: file, https:// URL, github:owner/repo (latest release’s one .iropkg), or a catalog entry. Only the kernel downloads: https only, no cookies/credentials, ≤ 5 redirects, ≤ 100 MiB, and the bytes checked are the bytes unpacked. A link only ever opens the consent sheet, never over another sheet.

Updates and rollback

Iro checks URL/GitHub/catalog sources daily, on wake and on Check now. Only a newer version from the pinned key (or a rotation from it) is offered; another key is refused on the app’s page and tile. Update automatically (per app, off by default) applies only same-key updates that ask for nothing new; anything else waits for the update sheet on the old version.

Updates keep the replaced version; Roll back restores its files and only consented grants, keeps app data and the pin, and turns auto-update off. A version revoked by the install’s source catalog cannot be restored.

Catalogs and the Store

A catalog is static signed JSON (iro catalog init/add/verify/revoke). Stores choose what they list and verify catalog signatures; Iro independently checks each package’s signature and publisher pin. The Store installs through iro.install.request and hears only installed/cancelled.

A catalog’s revoked: [{ id, versions, reason }] list turns off versions installed from that catalog. Iro enforces this for connections, calls, services, jobs and rollback, and closes the app’s views. Data, grants, bindings and accounts stay. An update to a version not revoked, or the catalog removing the revocation, turns the app on again.