Search Apps Documentation Source Content File Folder Download Copy Actions Download State String Boolean Number Struct Map Slice Pointer Function Closure Reference Nil Package Type Interface Unknown

README.md

3.43 Kb · 80 lines

gno.land/p/moul/pilot/v0

A realm-driven account: one realm holds the funds and the identity, a key pilots it, and its powers arrive afterwards as separate realms it never imports. The gno answer to a Gnosis Safe with modules.

Live instance: r/moul/pilot. A power: r/moul/x/pilotdemo.

Why it is not just a multisig

gno has no dynamic call: a realm cannot invoke an arbitrary package path with runtime-built arguments. So an account can never execute arbitrary calldata the way a Safe does. Every outbound action has to be Go code in some realm.

The inversion that makes it work: the account is deployed once and stores Module values handed to it by realms that did not exist at the time. The power is the calldata, published as readable source, and installing one costs no redeploy of the account.

The two grants, and the only difference that matters

GrantPurse GrantIdentity
spends the main treasury, metered its own sub-treasury account#subpath
can act as the account toward other realms no yes
Revoke takes it back yes, immediately no, never

A Purse is a type this package declares, so every call on one re-enters this code and re-reads the live roster and budget. A module that stashed a purse and calls it a year later still goes through the check.

A sub-identity token is the opposite. The token itself cannot be persisted, but banker.NewBanker authorizes at construction and re-checks nothing ever again, so a module can mint one from the lent token and keep it. Revoke shuts the account's door and does not reach that banker. The blast radius is exactly what the sub-address was funded with, and it is permanent. Grant an identity only to code you have read, and note that you can read it: module source is on chain before you approve it.

Shape

 1// once, from the account realm
 2acct := pilot.New(0, cur)
 3
 4// the owner, through the account realm's crossing functions
 5acct.Approve(0, cur, "gno.land/r/you/somepower/v0", "power", pilot.GrantPurse, 1_000)
 6acct.Fund(0, cur, path, 500)
 7acct.SetBudget(0, cur, path, 2_000)
 8acct.Revoke(0, cur, path)
 9acct.Exec(0, cur, path, args)
10
11// the module realm, with its own cur: the account reads the path from the
12// runtime and never from an argument
13h := account.Handle()
14h.Register(0, cur, self)
15purse := h.PurseFor(0, cur)

Both realms in the pair must be public

A module's object is persisted in the account's roster, and a value of a type defined in a private realm cannot be persisted by anyone else. A private account realm cannot be imported at all, and a redeploy would wipe the owner, the roster and every budget while leaving the coins at the address. private = true is wrong for both halves, and each gnomod.toml says so.


Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.

Dependency graph:

gno.land/p/moul/pilot/v0 dependency graph

⚠️ Disclaimer: provided as-is, without warranty; not security-audited. Full disclaimer: DISCLAIMER.