-- The Cover splits into two facts. `cover` keeps the third-party address the -- bytes come from, which is what the refetch path dedupes on; `cover_address` -- is the content address of the bytes once they are actually stored, and is -- what the wire's absolute URL is built from. -- -- Empty `cover_address` therefore means "no Cover yet" rather than "a Cover -- that 404s", which is the distinction the API and the UI both depend on. -- -- The content address was originally the hex SHA-256 of the source URL -- (ADR-0007). Since ADR-0014 it is the hex SHA-256 of the bytes themselves, -- so a re-art behind the same URL is a new address. Rows written before -- ADR-0014 keep their URL-derived addresses; they are never rehashed and heal -- into byte addressing on their first forced replacement. Both derivations -- share the 64-hex-digit shape, so the serving guard is unchanged. ALTER TABLE series ADD COLUMN cover_address text NOT NULL DEFAULT '';