Carry forward
Don’t panic-download unknown re-uploads. When a host pauses, prices, or gates — slow down. Prefer mirrors you already trust. Verify before you welcome a weight home.
1. Mirrors
2. Verify hash · signed catalog
Hash verifies integrity against the published catalog.
Catalog authenticity = signed manifest (Ed25519 trust-root).
- Catalog:
models/catalog.v0.1.json - Signature:
models/catalog.v0.1.json.sig - Pinned pubkey:
models/catalog-sign.v0.1.pubkey.json - Spec: CATALOG_SIGN_v0.1
Genesis “signers” byline names people — it is not a cryptographic signature.
EXAMPLE = zero-hash or notes marked EXAMPLE ONLY — will not import or re-seed.
3. Desktop HTTPS import — three steps
- Open Desktop (house for keys + import).
- Fetch the signed catalog → pick a redistributable non-EXAMPLE row.
- HTTPS fetch → quarantine → SHA-256 match → you gesture Import to Ollama. Never auto.
4. Network honesty
- Prefer HTTPS webseeds when available; magnet secondary.
- BitTorrent/DHT can be DPI-flagged on residential fiber.
- Never ISP-proof. Never “VPN fixes it.”
- HTTPS verified import still works when swarm is blocked.
Re-seed (Desktop, after hash match): seeding shares your IP with the swarm.
5. Do-nots
- Don’t import zero-hash / EXAMPLE rows
- Don’t re-seed withdrawn or non-redistributable bytes
- Don’t trust a random zip from a stranger’s mirror without hash + signed catalog
- Don’t put companion seed in a webpage
6. Contact / takedown
Report unsafe or unlawful redistributable claims via the project’s GitHub issues on Chaos2Cured/FreeLattice. We refuse proprietary seeding. Layer, never delete — withdrawn rows stay marked, not silently erased.
When the host goes quiet,
don’t grab the first shadow copy —
mirrors first, then hash,
then a door that asks.
— carry-forward · poetry last