func Echo
crossing ActionEcho reports who called it. A crossing call shifts the previous-realm stack even into the same realm, so this is what the module's borrowed identity looks like from the outside.
Package pilotdemo is a power for a realm-driven account: a payout module installed into gno.land/p/moul/pilot/v0 afte...
gno.land/r/moul/x/pilotdemo/v0A power for a realm-driven account: a payout module installed into
r/moul/pilot after that account was already deployed. Demo of
p/moul/pilot.
It shows both delegation modes in one realm, which is the point of the pair:
Pay goes through the account's revocable purse. Revoke stops it on the next call even
though this realm still holds the purse object.gno.land/r/moul/pilot/v0#payout toward another realm,
and spends the sub-treasury through a banker it mints and keeps. That is deliberate:
it is what makes the test TestIdentityGrantOutlivesRevoke pass, and what an identity
grant costs.InstallInto takes the account handle as a value rather than importing one account, so a
module is not bound to a single instance. gno has no dynamic call, so a gnokey maketx run
script is what passes the handle; MsgCall cannot.
Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.
Dependency graph:

🧪 Highly experimental — potentially vibe-coded. Not audited; may break, change, or be removed at any time. Do not use with anything of value. Full disclaimer: DISCLAIMER.
Package pilotdemo is a power for a realm-driven account: a payout module installed into gno.land/p/moul/pilot/v0 after the account was deployed.
It shows both delegation modes side by side:
Demo of gno.land/p/moul/pilot/v0. Account instance: r/moul/pilot.
Echo reports who called it. A crossing call shifts the previous-realm stack even into the same realm, so this is what the module's borrowed identity looks like from the outside.
Install wires this module into moul's account.
InstallInto wires it into ANY account: a module is not bound to one instance. gno has no dynamic call, so the handle has to be passed as a value, which a `gnokey maketx run` script can do and a MsgCall cannot.
Paid is what this module has moved in total.
Payout spends the sub-treasury with the retained banker, reaching the bank without re-entering the account. This is the demonstration that an identity grant cannot be revoked: it keeps working after Revoke.