Search Apps Documentation Source Content File Folder Download Copy Actions Download State String Boolean Number Struct Map Slice Pointer Function Closure Reference Nil Package Type Interface Unknown

v0 source realm

untrusted-render: this realm stores no string of its own. The only two a caller supplies, a module path and its subpa...

Readme View source

gno.land/r/moul/pilot/v0

moul's realm-driven account. It holds the funds and the identity; moul's key pilots it; its powers arrive afterwards as separate realms this one never imports.

All behaviour is in p/moul/pilot, which explains the two grants and why Revoke takes back a purse but never an identity. This realm is the instance: a *pilot.Pilot, one-line crossing re-exports forwarding cur, and Render.

A power to try it with: r/moul/x/pilotdemo.

Claim is pinned to g1manfred47kzduec920z88wfr64ylksmdcedlf5 in the source. A deploy lands in one block and the claim is a second transaction, so taking the owner from whoever calls first is a race anyone on chain can win, and this path can never be redeployed to undo it.

1# once, and only this address can
2gnokey maketx call -pkgpath gno.land/r/moul/pilot/v0 -func Claim ... moul
3
4# authorise a path that does not have to exist yet
5gnokey maketx call -pkgpath gno.land/r/moul/pilot/v0 -func Approve \
6  -args gno.land/r/moul/x/pilotdemo/v0 -args payout -args false -args 1000 ... moul

Public on purpose. A module realm imports this one and persists objects it owns, both of which a private realm refuses, and a redeploy would wipe the owner, the roster and every budget while leaving the coins at the treasury address.


Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.

Dependency graph:

gno.land/r/moul/pilot/v0 dependency graph

⚠️ Disclaimer: provided as-is, without warranty; not security-audited. Full disclaimer: DISCLAIMER.

Overview

untrusted-render: this realm stores no string of its own. The only two a caller supplies, a module path and its subpath, are written solely by the owner through Approve and charset-validated there (p/moul/pilot assertPlain), which is what lets Render interpolate them. Package pilot is moul's realm-driven account: it holds the funds and the identity, moul's key pilots it, and its powers arrive afterwards as separate realms that this one never imports.

All behaviour is in gno.land/p/moul/pilot/v0; this realm is the instance. Demo of a power: r/moul/x/pilotdemo.

Functions 8

func Approve

crossing Action
1func Approve(cur realm, path, subpath string, identity bool, budget int64)
source

Approve authorises a package path to install itself later, under a named sub-identity, with a grant and a budget. The code need not exist yet.

func Claim

crossing Action
1func Claim(cur realm)
source

Claim arms the account. Once, and only by its owner.

func Exec

crossing Action
1func Exec(cur realm, path, args string) string
source

Exec drives an installed module.

func Fund

crossing Action
1func Fund(cur realm, path string, amount int64)
source

Fund moves coins from the main treasury into one module's sub-treasury.

func Handle

Action
1func Handle() *pilot.Account
source

Handle is how a module realm reaches this account. Its two methods key on the caller's own pkgpath, which no realm can forge for another.

func Revoke

crossing Action
1func Revoke(cur realm, path string)
source

Revoke stops a module. It cannot take back a granted identity.

func SetBudget

crossing Action
1func SetBudget(cur realm, path string, budget int64)
source

SetBudget changes what a module may still spend, including through a purse it already holds.

Imports 1

Source Files 4