Skip to content

Authorize Work with durable grants - #34

Merged
georgewhewell merged 12 commits into
masterfrom
codex/grant-funding
Oct 2, 2026
Merged

georgewhewell merged 12 commits into
masterfrom
codex/grant-funding

Conversation

@georgewhewell

@georgewhewell georgewhewell commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Run authorized Work through durable grants with verified principals, signed offers and pinned provider identities. The grant journal owns policies, budgets, concurrency, expiry and usage accounting; client and provider sessions use the shared Work lifecycle.

Add HTTPS resource routes and metering, owner grants, contact and offer handling, grant administration, gateway backends and the Gate-facing SDK. Owner execution uses grants without constructing a chain node.

Validation: Source checks and standalone CLI/chain feature lints pass. SDK paid-work tests and lints pass. Grant HTTP tests and Clippy pass in both network and evaluation builds with loopback-only networking and a read-only home directory. Parallel CLI unit suites pass five consecutive runs in both feature sets.

Depends on #33. Followed by #35.

Add verified principals, pinned Offers, one provider grant journal and hierarchical accounting. Serve paid and grant channels through shared Work routing and bounded executor admission. Restore owner execution, expose local grant administration and contacts, and compose grant gateways and provider SDKs with strict HTTPS usage accounting.
@hellasbot

hellasbot commented Oct 1, 2026 •

Copy link
Copy Markdown

Hydra: running

Head fb159ee0edf5 · Evaluation #200612 · Hydra jobset

37 of 39 builds passed; awaiting the remaining results.

Base automatically changed from codex/funding-generic-work to master October 2, 2026 01:06
georgewhewell added a commit that referenced this pull request Oct 2, 2026
Separate execution policy from payment terms and route Work by funding
kind and channel. A sealed funding type and `JobBook<PaymentFunding>`
share the job lifecycle while retaining payment-specific admission and
settlement.

Introduce V2 records, close descriptor v3 and journal format 7. Paid
offers bind provider enrollment, and paid sessions require a pinned
provider identity through the shared `WorkLink` authenticator. Grant
record encodings are defined here; grant execution is added in the next
layer.

Validation: source checks and standalone CLI/chain feature lints pass.
Wire vectors and transport tests cover canonical records, provider
authentication, payment execution, wrong pins and missing Open.

Depends on #32. Followed by #34.
@georgewhewell
georgewhewell merged commit e61383a into master Oct 2, 2026
30 checks passed
@georgewhewell
georgewhewell deleted the codex/grant-funding branch October 2, 2026 04:32
georgewhewell added a commit that referenced this pull request Oct 2, 2026
Grant admission and shutdown previously allowed execution ownership to
become optional or detached. A failed result reader could return before
the worker finished, and shutdown could lose tasks after a failed
journal write or a cancelled drain. This repair makes capacity and
completion mandatory and keeps execution owned through cleanup.

- Carry validated admission through the queue and worker; classify
completion failures and preserve conservative grant accounting.
- Give the grant service explicit runtime states and supervise its
tasks. Share task supervision between gateways and return shutdown
failures after cleanup.
- Route grants and payment through an explicit `WorkRouter`. Share grant
validation and journal preparation between SDK providers, CLI servers
and local owner execution.
- Remove the session facade, resolve grant transport once, keep gateway
exports stable, and separate grant-only features from chain
dependencies.
- Replace core library `anyhow` and erased errors with typed causes.
Remove unused scheduling metadata and production test hooks; use real
integration tests and an isolated SDK feature matrix.

Validation: 286 Work tests, 41 native executor tests, 54 SDK tests, 27
cloud tests, and 161 CLI tests pass, including all four grant HTTP/owner
tests. All 243 RPC Work tests pass. Workspace Clippy, the
cloud/node/gateway/evaluate/telemetry combination, the full SDK
test/Clippy feature matrix, and formatting/dependency-order checks pass.
Local basic and gateway VM tests and provider module evaluation pass.
[GitHub
CI](https://github.com/hellas-ai/hellas/actions/runs/37015374480) passes
all 27 jobs. [Hydra evaluation
201972](https://hydra.hellas.ai/eval/201972) passes all 39 builds,
including both required architecture gates.

Compatibility: removes `GrantDef.weight` from encoded definitions. Older
offers and grant journals require explicit migration; existing journals
must not be discarded to reset allowances. Managed configurations now
require their grant configuration path. SDK callers use concrete
`PaidWorkSession` and `GrantSession` types.

Follow-up to #34, which merged while this repair was in progress.
georgewhewell added a commit that referenced this pull request Oct 2, 2026
Make `hellas admin users` the interface for listing, adding, inspecting,
updating and removing node users and exporting their offers. Owner,
admin and work permissions share the grant journal as their authority,
and removing a user revokes access on existing connections.

Paid clients and providers share a process-owned Commonware chain node
for verified execution, observation and settlement. ChainSync supplies
replication; peer discovery and the CLI use the same node.

The branch includes the merged Work foundation repair: explicit funding
routing, mandatory admission and completion ownership, shared validated
provider construction, typed errors and supervised shutdown. Journal
write failures stop administrative authority while shutdown still waits
for physical worker completion.

Replace the top-level grant command and separate admin-peer policy;
remove unused grant commands. Scope admin options to their commands,
document every users flag, and use `--address` consistently for network
endpoints.

Validation: 163 CLI tests (including all four grant HTTP/owner tests),
54 SDK tests and 292 Work tests pass. Strict Clippy passes for CLI
cloud/node/gateway/evaluate/telemetry, combined SDK funding features and
Work, with all targets. Rust formatting, dependency order and TOML
formatting pass. The grant-only SDK dependency graph excludes
`hellas-chain`. All 153 chain tests pass with full-node, validator and
work-watcher features. The full SDK test/Clippy matrix passes for
combined, grant-only and all seven isolated feature sets. Hydra’s x86_64
required gate passes, including all VM tests. ARM checks and [GitHub
CI](https://github.com/hellas-ai/hellas/actions/runs/37064595648) are
pending.

Includes #36 and incorporates the merged #34 and #37 foundation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants