Authorize Work with durable grants - #34
Merged
Merged
Conversation
Add verified principals, pinned Offers, one provider grant journal and hierarchical accounting. Serve paid and grant channels through shared Work routing and bounded executor admission. Restore owner execution, expose local grant administration and contacts, and compose grant gateways and provider SDKs with strict HTTPS usage accounting.
This was referenced Oct 1, 2026
Hydra: runningHead 37 of 39 builds passed; awaiting the remaining results. |
Bound test runtimes to two workers, use a fixed grant clock, and give asynchronous fixtures one timeout budget. Test core-dump limits without installing the provider panic hook in the test process. (cherry picked from commit 6fc5c05)
georgewhewell
added a commit
that referenced
this pull request
Oct 2, 2026
Separate execution policy from payment terms and route Work by funding kind and channel. A sealed funding type and `JobBook<PaymentFunding>` share the job lifecycle while retaining payment-specific admission and settlement. Introduce V2 records, close descriptor v3 and journal format 7. Paid offers bind provider enrollment, and paid sessions require a pinned provider identity through the shared `WorkLink` authenticator. Grant record encodings are defined here; grant execution is added in the next layer. Validation: source checks and standalone CLI/chain feature lints pass. Wire vectors and transport tests cover canonical records, provider authentication, payment execution, wrong pins and missing Open. Depends on #32. Followed by #34.
georgewhewell
enabled auto-merge
October 2, 2026 02:06
georgewhewell
added a commit
that referenced
this pull request
Oct 2, 2026
Grant admission and shutdown previously allowed execution ownership to become optional or detached. A failed result reader could return before the worker finished, and shutdown could lose tasks after a failed journal write or a cancelled drain. This repair makes capacity and completion mandatory and keeps execution owned through cleanup. - Carry validated admission through the queue and worker; classify completion failures and preserve conservative grant accounting. - Give the grant service explicit runtime states and supervise its tasks. Share task supervision between gateways and return shutdown failures after cleanup. - Route grants and payment through an explicit `WorkRouter`. Share grant validation and journal preparation between SDK providers, CLI servers and local owner execution. - Remove the session facade, resolve grant transport once, keep gateway exports stable, and separate grant-only features from chain dependencies. - Replace core library `anyhow` and erased errors with typed causes. Remove unused scheduling metadata and production test hooks; use real integration tests and an isolated SDK feature matrix. Validation: 286 Work tests, 41 native executor tests, 54 SDK tests, 27 cloud tests, and 161 CLI tests pass, including all four grant HTTP/owner tests. All 243 RPC Work tests pass. Workspace Clippy, the cloud/node/gateway/evaluate/telemetry combination, the full SDK test/Clippy feature matrix, and formatting/dependency-order checks pass. Local basic and gateway VM tests and provider module evaluation pass. [GitHub CI](https://github.com/hellas-ai/hellas/actions/runs/37015374480) passes all 27 jobs. [Hydra evaluation 201972](https://hydra.hellas.ai/eval/201972) passes all 39 builds, including both required architecture gates. Compatibility: removes `GrantDef.weight` from encoded definitions. Older offers and grant journals require explicit migration; existing journals must not be discarded to reset allowances. Managed configurations now require their grant configuration path. SDK callers use concrete `PaidWorkSession` and `GrantSession` types. Follow-up to #34, which merged while this repair was in progress.
georgewhewell
added a commit
that referenced
this pull request
Oct 2, 2026
Make `hellas admin users` the interface for listing, adding, inspecting, updating and removing node users and exporting their offers. Owner, admin and work permissions share the grant journal as their authority, and removing a user revokes access on existing connections. Paid clients and providers share a process-owned Commonware chain node for verified execution, observation and settlement. ChainSync supplies replication; peer discovery and the CLI use the same node. The branch includes the merged Work foundation repair: explicit funding routing, mandatory admission and completion ownership, shared validated provider construction, typed errors and supervised shutdown. Journal write failures stop administrative authority while shutdown still waits for physical worker completion. Replace the top-level grant command and separate admin-peer policy; remove unused grant commands. Scope admin options to their commands, document every users flag, and use `--address` consistently for network endpoints. Validation: 163 CLI tests (including all four grant HTTP/owner tests), 54 SDK tests and 292 Work tests pass. Strict Clippy passes for CLI cloud/node/gateway/evaluate/telemetry, combined SDK funding features and Work, with all targets. Rust formatting, dependency order and TOML formatting pass. The grant-only SDK dependency graph excludes `hellas-chain`. All 153 chain tests pass with full-node, validator and work-watcher features. The full SDK test/Clippy matrix passes for combined, grant-only and all seven isolated feature sets. Hydra’s x86_64 required gate passes, including all VM tests. ARM checks and [GitHub CI](https://github.com/hellas-ai/hellas/actions/runs/37064595648) are pending. Includes #36 and incorporates the merged #34 and #37 foundation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Run authorized Work through durable grants with verified principals, signed offers and pinned provider identities. The grant journal owns policies, budgets, concurrency, expiry and usage accounting; client and provider sessions use the shared Work lifecycle.
Add HTTPS resource routes and metering, owner grants, contact and offer handling, grant administration, gateway backends and the Gate-facing SDK. Owner execution uses grants without constructing a chain node.
Validation: Source checks and standalone CLI/chain feature lints pass. SDK paid-work tests and lints pass. Grant HTTP tests and Clippy pass in both network and evaluation builds with loopback-only networking and a read-only home directory. Parallel CLI unit suites pass five consecutive runs in both feature sets.
Depends on #33. Followed by #35.