Search Apps Documentation Source Content File Folder Download Copy Actions Download State String Boolean Number Struct Map Slice Pointer Function Closure Reference Nil Package Type Interface Unknown

v0 source realm

Package pilotdemo is a power for a realm-driven account: a payout module installed into gno.land/p/moul/pilot/v0 afte...

Readme View source

gno.land/r/moul/x/pilotdemo/v0

A power for a realm-driven account: a payout module installed into r/moul/pilot after that account was already deployed. Demo of p/moul/pilot.

It shows both delegation modes in one realm, which is the point of the pair:

  • Pay goes through the account's revocable purse. Revoke stops it on the next call even though this realm still holds the purse object.
  • Under an identity grant it acts as gno.land/r/moul/pilot/v0#payout toward another realm, and spends the sub-treasury through a banker it mints and keeps. That is deliberate: it is what makes the test TestIdentityGrantOutlivesRevoke pass, and what an identity grant costs.

InstallInto takes the account handle as a value rather than importing one account, so a module is not bound to a single instance. gno has no dynamic call, so a gnokey maketx run script is what passes the handle; MsgCall cannot.


Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.

Dependency graph:

gno.land/r/moul/x/pilotdemo/v0 dependency graph

🧪 Highly experimental — potentially vibe-coded. Not audited; may break, change, or be removed at any time. Do not use with anything of value. Full disclaimer: DISCLAIMER.

Overview

Package pilotdemo is a power for a realm-driven account: a payout module installed into gno.land/p/moul/pilot/v0 after the account was deployed.

It shows both delegation modes side by side:

  • Pay goes through the account's revocable pilot.Purse. Revoking the module stops it on the next call, even though this realm still holds the purse object.
  • Act is only reachable under an identity grant: the account lends its sub-identity, this realm acts as "<account>#<subpath>" toward another realm, and spends the sub-treasury through a banker it mints. That banker is KEPT on purpose, which is what makes an identity grant permanent: revoking stops Exec, not this.

Demo of gno.land/p/moul/pilot/v0. Account instance: r/moul/pilot.

Functions 6

func Echo

crossing Action
1func Echo(cur realm) string
source

Echo reports who called it. A crossing call shifts the previous-realm stack even into the same realm, so this is what the module's borrowed identity looks like from the outside.

func Install

crossing Action
1func Install(cur realm, dest address)
source

Install wires this module into moul's account.

func InstallInto

crossing Action
1func InstallInto(cur realm, acct *pilot.Account, dest address)
source

InstallInto wires it into ANY account: a module is not bound to one instance. gno has no dynamic call, so the handle has to be passed as a value, which a `gnokey maketx run` script can do and a MsgCall cannot.

func Payout

crossing Action
1func Payout(cur realm, to address, amount int64)
source

Payout spends the sub-treasury with the retained banker, reaching the bank without re-entering the account. This is the demonstration that an identity grant cannot be revoked: it keeps working after Revoke.

Imports 5

Source Files 4