Search Apps Documentation Source Content File Folder Download Copy Actions Download State String Boolean Number Struct Map Slice Pointer Function Closure Reference Nil Package Type Interface Unknown

v0 source realm

Package facade is the permanent entry point of the "self-registering implementation" upgrade pattern (pattern E of th...

Readme View source

gno.land/r/moul/x/upgrade/selfreg/facade/v0

The permanent facade of pattern E. Holds an Impl interface value and forwards to it. Implementations register themselves from their own init, gated on an explicit path prefix (nestedpkg does not fit version-last paths).

See the pattern and the exploration.


Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.

Dependency graph:

gno.land/r/moul/x/upgrade/selfreg/facade/v0 dependency graph

🧪 Highly experimental — potentially vibe-coded. Not audited; may break, change, or be removed at any time. Do not use with anything of value. Full disclaimer: DISCLAIMER.

Overview

Package facade is the permanent entry point of the "self-registering implementation" upgrade pattern (pattern E of the exploration; see ../../README.md).

The path callers import never changes and holds no business logic: it holds an interface value. A new implementation realm takes over simply by being deployed, because it registers itself from its own init. Nobody has to send a transaction to switch, which is the pattern's whole appeal and also its whole risk: whoever can deploy under the guarded prefix can take the realm.

Constants 1

const StageOpen, StageSealed

1const (
2	StageOpen   = 0 // any realm under the prefix takes over by deploying
3	StageSealed = 1 // nothing may register again, the live implementation is final
4)
source

The stage ladder. Sui gates package upgrades with an UpgradeCap whose policy runs compatible, additive, dependency-only, immutable, and the rule that makes it worth copying is that a policy can only ever become MORE restrictive. CosmWasm and Solana land on the same primitive from different directions: a contract with no admin, a program whose upgrade authority is None. All three say the same thing, that the way out of "you are trusting the owner rather than the code" is an authority you can drop, permanently.

This pattern has no owner, so its ladder has two rungs rather than four: the only actor the facade already trusts is whichever implementation is live.

Functions 8

func Greet

Action
1func Greet(name string) string
source

Greet forwards to the live implementation.

func Live

Action
1func Live() string
source

Live is the package path currently serving, or "" before the first deploy.

func Register

crossing Action
1func Register(cur realm, impl Impl)
source

Register makes the calling realm the live implementation. Called from the implementation's own init, so deploying IS the upgrade.

func Seal

crossing Action
1func Seal(cur realm)
source

Seal ends this realm's upgradeability, forever. Callable only by the implementation currently serving, because with no owner that is the only actor the facade already trusts. It grants nothing new: whoever could deploy under the prefix could already take the realm over, and this only lets them make that the last word.

One-way, and there is no rung above it.

func Stage

Action
1func Stage() int
source

Stage is the rung this realm is on. It only ever goes up.

func Version

Action
1func Version() string
source

Version reports the live implementation's own version string.

Types 1

type Impl

interface
1type Impl interface {
2	Greet(name string) string
3	Version() string
4}
source

Impl is the contract an implementation realm must satisfy. This interface is the one thing here that can never change: it is compiled into every caller.

Imports 2

Source Files 5