func Approve
crossing ActionApprove authorises a package path to install itself later, under a named sub-identity, with a grant and a budget. The code need not exist yet.
untrusted-render: this realm stores no string of its own. The only two a caller supplies, a module path and its subpa...
gno.land/r/moul/pilot/v0moul's realm-driven account. It holds the funds and the identity; moul's key pilots it; its powers arrive afterwards as separate realms this one never imports.
All behaviour is in p/moul/pilot, which explains the two grants
and why Revoke takes back a purse but never an identity. This realm is the instance: a
*pilot.Pilot, one-line crossing re-exports forwarding cur, and Render.
A power to try it with: r/moul/x/pilotdemo.
Claim is pinned to g1manfred47kzduec920z88wfr64ylksmdcedlf5 in the source. A deploy
lands in one block and the claim is a second transaction, so taking the owner from whoever
calls first is a race anyone on chain can win, and this path can never be redeployed to undo
it.
1# once, and only this address can
2gnokey maketx call -pkgpath gno.land/r/moul/pilot/v0 -func Claim ... moul
3
4# authorise a path that does not have to exist yet
5gnokey maketx call -pkgpath gno.land/r/moul/pilot/v0 -func Approve \
6 -args gno.land/r/moul/x/pilotdemo/v0 -args payout -args false -args 1000 ... moul
Public on purpose. A module realm imports this one and persists objects it owns, both of which a private realm refuses, and a redeploy would wipe the owner, the roster and every budget while leaving the coins at the treasury address.
Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.
Dependency graph:

⚠️ Disclaimer: provided as-is, without warranty; not security-audited. Full disclaimer: DISCLAIMER.
untrusted-render: this realm stores no string of its own. The only two a caller supplies, a module path and its subpath, are written solely by the owner through Approve and charset-validated there (p/moul/pilot assertPlain), which is what lets Render interpolate them. Package pilot is moul's realm-driven account: it holds the funds and the identity, moul's key pilots it, and its powers arrive afterwards as separate realms that this one never imports.
All behaviour is in gno.land/p/moul/pilot/v0; this realm is the instance. Demo of a power: r/moul/x/pilotdemo.
Approve authorises a package path to install itself later, under a named sub-identity, with a grant and a budget. The code need not exist yet.
Claim arms the account. Once, and only by its owner.
Exec drives an installed module.
Fund moves coins from the main treasury into one module's sub-treasury.
Handle is how a module realm reaches this account. Its two methods key on the caller's own pkgpath, which no realm can forge for another.
Revoke stops a module. It cannot take back a granted identity.
SetBudget changes what a module may still spend, including through a purse it already holds.