Skip to content

Type Work funding and authenticate paid providers - #33

Merged
georgewhewell merged 7 commits into
masterfrom
codex/funding-generic-work
Oct 2, 2026
Merged

georgewhewell merged 7 commits into
masterfrom
codex/funding-generic-work

Conversation

@georgewhewell

@georgewhewell georgewhewell commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Separate execution policy from payment terms and route Work by funding kind and channel. A sealed funding type and JobBook<PaymentFunding> share the job lifecycle while retaining payment-specific admission and settlement.

Introduce V2 records, close descriptor v3 and journal format 7. Paid offers bind provider enrollment, and paid sessions require a pinned provider identity through the shared WorkLink authenticator. Grant record encodings are defined here; grant execution is added in the next layer.

Validation: source checks and standalone CLI/chain feature lints pass. Wire vectors and transport tests cover canonical records, provider authentication, payment execution, wrong pins and missing Open.

Depends on #32. Followed by #34.

Separate execution policy from payment terms with V2 records, explicit funding and channel routes, version-3 close descriptors and format-7 journals. Use a sealed JobBook and typed paid session, share connection-bound Open authentication, and bind provider enrollment into signed paid offers. Paid gateways use the shared execution interface and select the configured Fetch manifest.
@hellasbot

hellasbot commented Oct 1, 2026 •

Copy link
Copy Markdown

Hydra: passed

Head eeea15a7612e · Evaluation #200434 · Hydra jobset

All 39 builds passed.

georgewhewell added a commit that referenced this pull request Oct 1, 2026
Remove Courtesy authorization, ticket RPCs, direct Fetch, CacheControl
and retained-artifact APIs. Internal worker events have their own type;
paid Work remains executable.

Owner-bound selection fails before side effects with
`OwnerGrantRequired`. The grant-funding layer restores owner execution
through grants.

Proxy-only NixOS gateways can omit native inference files. Native
gateways still require both the environment and tokenizer.

Validation: the full `nix run .#check` suite passes, including
standalone CLI feature checks, formatting, dependency sorting and Nix
checks. The proxy gateway VM test passes, including streaming and
credential checks. The discovery VM test passes three consecutive runs
with an isolated network.

Targets master after #31. Followed by #33.
Base automatically changed from codex/remove-courtesy to master October 1, 2026 22:58
@georgewhewell
georgewhewell merged commit 97c9c2e into master Oct 2, 2026
30 checks passed
@georgewhewell
georgewhewell deleted the codex/funding-generic-work branch October 2, 2026 01:06
georgewhewell added a commit that referenced this pull request Oct 2, 2026
Run authorized Work through durable grants with verified principals,
signed offers and pinned provider identities. The grant journal owns
policies, budgets, concurrency, expiry and usage accounting; client and
provider sessions use the shared Work lifecycle.

Add HTTPS resource routes and metering, owner grants, contact and offer
handling, grant administration, gateway backends and the Gate-facing
SDK. Owner execution uses grants without constructing a chain node.

Validation: Source checks and standalone CLI/chain feature lints pass.
SDK paid-work tests and lints pass. Grant HTTP tests and Clippy pass in
both network and evaluation builds with loopback-only networking and a
read-only home directory. Parallel CLI unit suites pass five consecutive
runs in both feature sets.

Depends on #33. Followed by #35.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants