Decision
Content governance over origins has two symmetric authorities, both DAO-controlled:- Negative —
ContentBlacklist. Removes hashes and operators through a global (network-wide) path and a regional (jurisdiction-scoped) path. Standard governance entries carry a 24-hour compliance window; the emergency multisig path takes effect immediately with a 2-hour slash grace. - Positive —
OriginAssignment. Authorizes specific operators to act as origins for specific namespaces (content addressing).
pause(), which sunsets at 12 months, emergency blacklisting does not sunset, since unlawful-content removal is an ongoing legal-compliance duty. (Individual emergency entries still auto-expire unless ratified — see Entry types below.)
Why on-chain
The blacklist must be:- Non-repudiable. A compromised node operator cannot claim “I didn’t know” if the entry is publicly readable.
- Atomic per-node. Every node polls the same source of truth. No partial propagation.
- Auditable. Anyone can see what has been blacklisted and when.
Entry types
Emergency entries auto-expire unless ratified by governance before the deadline — preventing the multisig from maintaining a permanent de-facto blacklist without oversight. Expiry needs no transaction: the entry simply stops being enforceable, and anyone may then clean it out of storage permissionlessly.
The emergency path is deliberately one-way with respect to governance — it can always make enforcement stricter, never looser. Both compliance windows are governable within one set of hardcoded bounds: minimum 1 hour, maximum 7 days. The floor is what keeps the emergency path honest — governance cannot compress the window below a single poll cycle and slash nodes for entries they had no opportunity to learn about.
Why the 2-hour slash grace
The emergency path takes effect immediately in terms of “don’t serve this”, but the first 2 hours cannot result in a slash. This absorbs blacklist-poll lag and clock skew — a node that genuinely hasn’t seen the entry yet is given a realistic reaction window before liability attaches.Regional scoping
A regional entry applies only to nodes that advertise a matching region. The right to add regional entries is granted to regional governance bodies on a per-region basis; the emergency multisig can suspend a compromised body immediately. Governance must then ratify or reverse within 14 days, and silence lapses the suspension — the body resumes writing, exactly as an unratified emergency entry expires. Neither is a standing act of governance, and sustaining one on silence alone would let the multisig disable a jurisdiction permanently with no vote ever taken. Suspension also bounds only a body’s future authority: entries it already issued stay live. Scope follows the operator’s declared region — never the requester’s. A node serving a globally-blacklisted hash is always slashable. A node declaringDE is slashable for a DE-regional entry; a node declaring US is not slashable for a hash blacklisted only by the EU body, regardless of where its clients are — the requester’s location is not an input. A node cannot shed exposure by flipping regions after the fact either: slash eligibility is evaluated against the region in force when the bytes were served.
Sub-day removal orders
Some statutory regimes bind the operator that receives a removal order to a sub-day deadline — the EU Terrorist Content Online Regulation’s one-hour clock is the tightest. Such an order is discharged at the operator level, on the local denylist: it takes effect on the next reload, needs no governance round-trip, and binds exactly what the order binds — the recipient’s own serving. Network-wide removal on that clock goes through the emergency multisig.Origin assignment
The blacklist is the DAO’s authority to remove an origin.OriginAssignment is the symmetric authority to grant one, and it separates two planes:
- Vetting is governance’s job, done once per publisher wallet under a swappable vetting policy.
- Seating is the publisher’s job. A vetted publisher picks its own origin operators from the bonded set, per namespace, instantly and with no further governance action. Multiple operators may serve one namespace, so redundancy is a namespace-level property.