pilot.gno
2.80 Kb · 79 lines
1// untrusted-render: this realm stores no string of its own. The only two a
2// caller supplies, a module path and its subpath, are written solely by the
3// owner through Approve and charset-validated there (p/moul/pilot assertPlain),
4// which is what lets Render interpolate them.
5// Package pilot is moul's realm-driven account: it holds the funds and the
6// identity, moul's key pilots it, and its powers arrive afterwards as
7// separate realms that this one never imports.
8//
9// All behaviour is in gno.land/p/moul/pilot/v0; this realm is the instance.
10// Demo of a power: r/moul/x/pilotdemo.
11package pilot
12
13import "gno.land/p/moul/pilot/v0"
14
15// owner is pinned in the source rather than taken from whoever calls Claim
16// first. A deploy lands in its own block and the claim is a second
17// transaction, so an unpinned Claim is a race anyone on chain can win, and
18// this account can never be redeployed to undo it.
19const owner = "g1manfred47kzduec920z88wfr64ylksmdcedlf5"
20
21var acct *pilot.Pilot
22
23// Claim arms the account. Once, and only by its owner.
24func Claim(cur realm) {
25 if acct != nil {
26 panic("pilot: already claimed")
27 }
28 if cur.Previous().Address() != owner {
29 panic("pilot: only " + owner + " can claim this account")
30 }
31 acct = pilot.New(0, cur)
32}
33
34// Approve authorises a package path to install itself later, under a named
35// sub-identity, with a grant and a budget. The code need not exist yet.
36func Approve(cur realm, path, subpath string, identity bool, budget int64) {
37 grant := pilot.GrantPurse
38 if identity {
39 grant = pilot.GrantIdentity
40 }
41 must().Approve(0, cur, path, subpath, grant, budget)
42}
43
44// SetBudget changes what a module may still spend, including through a purse
45// it already holds.
46func SetBudget(cur realm, path string, budget int64) { must().SetBudget(0, cur, path, budget) }
47
48// Revoke stops a module. It cannot take back a granted identity.
49func Revoke(cur realm, path string) { must().Revoke(0, cur, path) }
50
51// Fund moves coins from the main treasury into one module's sub-treasury.
52func Fund(cur realm, path string, amount int64) { must().Fund(0, cur, path, amount) }
53
54// Exec drives an installed module.
55func Exec(cur realm, path, args string) string { return must().Exec(0, cur, path, args) }
56
57// Handle is how a module realm reaches this account. Its two methods key on
58// the caller's own pkgpath, which no realm can forge for another.
59func Handle() *pilot.Account { return must().Handle() }
60
61// Address is the main treasury.
62func Address() address { return must().Address() }
63
64// SubAddress is one module's treasury.
65func SubAddress(path string) address { return must().SubAddress(path) }
66
67func Render(path string) string {
68 if acct == nil {
69 return "# gno.land/r/moul/pilot\n\nUnclaimed.\n"
70 }
71 return acct.Render(path)
72}
73
74func must() *pilot.Pilot {
75 if acct == nil {
76 panic("pilot: unclaimed")
77 }
78 return acct
79}