SOURCE / PINNED RELEASE
Made of little things.
Powder Tool V600Billion
- Release
- 142767edcab8…
- Author-recorded commit
- 6d92971effd0…
- License
- LICENSE
- Author’s source reference
- nostr://npub1fllw8kw0thjj55wds0uugcnp5kej2nfxd36eruq39d56wwz8r44q5q78wj/wss%3A%2F%2Fgit.napplet.soy%2F/powder-toy
Archive hash verified: ed7d6a8ea7083197…. The source-to-build association is the author’s claim; it has not been independently rebuilt.
# Publishing on napplet.soy
napplet.soy publishes a project folder with their `soyli` CLI (their `docs/PUBLISHING.md`,
`docs/CLI.md`, in [zeSchlausKwab/napplet-soy](https://github.com/zeSchlausKwab/napplet-soy)):
its own Git repository, pushed to `git.napplet.soy`; the playable HTML (at most 10 MiB) to
their Blossom; a kind 35129 manifest to their relays. At most 128 files and 40 MiB of
source, a nonempty LICENSE, and a browser startup check in their runtime before anything
is signed. The key is a napplet.soy creator key, made with `soyli`, separate from the
Nappelin release key (nappelin.com `docs/POWDER-TOY-PUBLISH.md` §3).
Checked on 2026-09-27 with the first build of the page: `soyli check` (soyLI 0.23.4,
runtime profile `space-playback-4`) on the project `npm run soy` writes ends with
`status: checked`; `soyli screenshot` shows the game running. The page rebuilt for
reproducible pins (2026-09-28, docs/FORK.md) passed the same harness checks in napplet.soy's
player (`npm run smoke`, `npm run e2e`); run `soyli check` again before publishing.
## The public source
This repository is private. napplet.soy's Git is where the public gets the source:
https://git.napplet.soy/npub1fllw8kw0thjj55wds0uugcnp5kej2nfxd36eruq39d56wwz8r44q5q78wj/powder-toy.git (a page in a browser, `git clone` for the files). Every release there
carries this repository, as it was committed, as `source/`, which builds exactly the
release's `index.html`. The page's About dialog, the Hangar's card and `provenance.json`
point there, so **the Hangar only docks a page that napplet.soy has published**: publish
the release first, check that its `index.html` is the page you dock
(`git show HEAD:index.html | sha256sum` in a fresh clone), then `npm run dock`.
## Releases
| Date | Title | Creator | Artifact (sha256) | Source |
|---|---|---|---|---|
| 2026-09-28 | Powder Tool V600Billion | `npub1fllw8kw0thjj55wds0uugcnp5kej2nfxd36eruq39d56wwz8r44q5q78wj` | `22e797478ae608313db53613c72b373e78bd93e52527916708e21a8dc9836e66` | this repository at `6f19e46`, as `source/` of project commit `d8859eb` |
| 2026-09-28 | Powder Tool V600Billion: its own controls and nine scenes | the same | `ca4cb8946181652881bc459c21382fe4903551f8452a3ccdc692aed519fca4a2` | this repository at `d24ebb1`, as `source/` of project commit `bd3aa94`; the listing picture from `scripts/soy-preview.mjs` |
[The napplet on napplet.soy](https://napplet.soy/n/naddr1qvzqqqyf8ypzqnl7u0vu7h099fgumqlec33xrfdny4xjvmr4j8cpz2mf5uuyw8t2qyv8wumn8ghj7un9d3shjtnwv9c8qmr9wsh8xmme9uqsuamnwvaz7tmwdaejumr0dshsz9mhwden5te0wfjkccte9ec8y6tdv9kzumn9wshszyrhwden5te0dehhxarj9ekk7mf0qyd8wumn8ghj7un9d3shjtnsda3kket5wd68ytnrdakj7qq2wphhwer9wgkhgmmeveyk6g)
(identifier `powder-toy`, kind 35129; snapshot `4087cfb9…26f4` for the first release, `92e3a1ca…e32c`
for the second). Published with soyLI 0.23.4 from WSL Ubuntu 24.04: `soyli check` status `checked`,
profile `space-playback-4`. The optional relay copies are best effort; nos.lol and
relay.pocketstr.com timed out on the second release, `soyli publish` again with the same source
repairs them. The creator key is
the napplet's own, in soyLI's file vault there (WSL has no Secret Service); its backup is kept
privately. The project folder with `.git` and `.napplet-space/` is the release journal.
**On WSL:** soyLI's check browser needs NSS and NSPR. Without root they can be unpacked from
Ubuntu's own packages into the home directory (`apt-get download libnss3 libnspr4`, then
`dpkg-deb -x`) and handed over with `LD_LIBRARY_PATH`; with root, `sudo apt-get install libnss3`.
The file vault needs `SOYLI_DANGEROUS_PLAINTEXT_KEYS=1` for every soyLI command.
## What players get there
The game plays; local saves, stamps and settings are kept in their storage (1 MiB in
all). The online browser reads saves others shared from Nappelin (if their relays carry
them). Publishing a save, voting and commenting are not possible: their host signs only
records in its own `soy.app-data/1` format (their `docs/SHARED-DATA.md`) and announces
that at the handshake; the game reads that and says so in its message of the day and
when Publish is pressed, instead of failing later. Carrying shared saves in their format
(the save through their upload domain to Blossom, a `soy.app-data/1` record pointing at
it, votes through `common.react`) is possible and would be its own piece of work.
## Steps, on your machine
1. **soyLI**, once: `curl -fsSL https://napplet.soy/install.sh | sh`, then `soyli doctor`.
2. **Creator key**, once: `soyli account create --new`. It creates a local key in the
OS keystore and prints where it saved the nsec backup (outside any Git project).
Keep a private copy; never paste the nsec anywhere. Alternatively a NIP-46 signer:
`soyli account pair` or `soyli account connect`.
3. **The project**, in this repository after a build, from a committed tree:
`npm run soy` writes `soy/` (or pass a folder: `npm run soy -- <dir>`). It holds
`index.html` (the built page, byte for byte the one the Hangar pins), `napplet.json`,
`LICENSE`, `README.md` and `source/` (this repository as committed, with the patches
and the wasm build script: what GPL-3.0 asks for). The script checks their limits.
Run it again after every build; it keeps `napplet.json`'s `previewId` and
`identifier` and soyLI's `.napplet-space/`.
4. In that folder, the first time: `git init -b main`.
5. A listing picture: `node scripts/soy-preview.mjs <dir>` takes one of the napplet in
napplet.soy's player (dark, 960 × 600, a scene running, fireworks unless you name
another) and names it in `napplet.json`; without one, soyLI takes its own picture of
the page as it starts, an empty sandbox (`soyli screenshot preview.png` shows it).
6. `soyli checkpoint "Powder Toy 100.1.400"` (commits the folder).
7. `soyli check`: must end with `status: checked`.
8. `soyli publish --dry-run`: shows the files, the creator, the identifier `powder-toy`,
the artifact hash and the destinations. Everything in `source/` becomes public.
9. `soyli publish`, then `soyli status`. Keep the folder with `.git` and
`.napplet-space/`: it is the release journal; `soyli publish --resume` finishes an
interrupted release.
## If something is off
| Symptom | Cause | Fix |
|---|---|---|
| "This host publishes only its own kind of records …" | napplet.soy (or a host like it) | Expected there; save without Publish |
| "This host did not keep …, its storage may be full" | The host's storage is full (napplet.soy: 1 MiB) | Delete old local saves or stamps; the file stays for the session |
| `soy-project.mjs`: "dist/.nip5a-manifest.json does not pin dist/index.html" | Not rebuilt | `npm run build` |
| `soy-project.mjs`: "the working tree has changes" | Uncommitted changes would make `source/` differ from the page's source | Commit first |
