Skip to main content
waiOS · Private registries

Private registries, inside the organisation's own infrastructure.

Some organisations cannot fetch decoder modules and parameter sets from outside. waiOS will run private registries of those artifacts in the organisation's own infrastructure, under the organisation's own key log, on the HTTP serving rules WAI is building.

Roadmap Not yet operating. Each open component below is labelled with where it stands on the WAI status page.

The three labels

In the standard
The open component is in the main branch of the WAI open standard. Its link goes to its row on the dated WAI status page, and its notes are that row's.
Building
The open component is in active development, as the WAI status page lists it.
Roadmap
Planned: a WAI roadmap item, or a waiOS service. Every waiOS service is on the roadmap; none is operating yet.

Attested, in WAI, means signed by the party that did the work and measured it: a reader can check the signature, not re-measure the figure. It is not hardware attestation.

01 · The service

What waiOS will run inside the organisation.

  • Copies of the decoder modules and parameter sets the organisation uses, held by digest, so a runtime never reaches outside to decode.
  • Private entries for in-house decoders and parameter sets, under the organisation's own key log.
  • On-premises operation, where runtimes confirm receipts and grants offline.
  • Replication between sites, each artifact checked by digest on arrival.
02 · Builds on

Open components, each with its WAI label.

  • In the standard

    The normative parameter-set pin. A sink verifies it before decoding and decodes only from the bytes it verified.

    Notes A pin that does not resolve makes its capability unsupported for that envelope: dispatch continues at the fallback, and selection at the next rendition.

  • In the standard

    A key log at a web origin the signer names. Verifiers confirm receipts, claims and module grants against it offline.

  • In the standard

    Decoder and reconstruct modules, and pinned parameter sets, authorised by digest and revoked by digest.

    Notes A runtime host that loads signed modules is on the roadmap.

  • In the standard

    The wire forms a pinned prior may declare, the NNC bitstream among them.

    Notes A replicate whose prior declares a wire form the sink cannot read is refused.

  • In the standard

    The WAI capability registry's machine-readable export, generated from one table and checked for drift in CI, so a private registry names capabilities by their registered strings.

03 · Being built

In active development in the standard.

  • Building

    Parameter sets, key statuses and grants served over HTTP and checked on every fetch path.

04 · Roadmap

Planned, in the standard and in the service.

  • Roadmap· waiOS

    Private and on-premises registries, with replication between sites.

  • Roadmap· WAI

    A host that runs signed, revocable modules.

05 · Limits

What this page does not claim.

  • No public registry of decoder modules or parameter sets exists today. The standard defines how such an artifact is pinned, authorised and revoked; serving artifacts over HTTP is being built.
  • No WAI runtime loads decoder modules yet: a runtime host that loads signed modules is on the WAI roadmap.
  • A copied artifact keeps its licence class and its licence.