Skip to content

Unify node users and permissions in the grant journal - #35

Merged
georgewhewell merged 27 commits into
masterfrom
codex/admin-users
Oct 2, 2026
Merged

georgewhewell merged 27 commits into
masterfrom
codex/admin-users

Conversation

@georgewhewell

@georgewhewell georgewhewell commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Make hellas admin users the interface for listing, adding, inspecting, updating and removing node users and exporting their offers. Owner, admin and work permissions share the grant journal as their authority, and removing a user revokes access on existing connections.

Paid clients and providers share a process-owned Commonware chain node for verified execution, observation and settlement. ChainSync supplies replication; peer discovery and the CLI use the same node.

The branch includes the merged Work foundation repair: explicit funding routing, mandatory admission and completion ownership, shared validated provider construction, typed errors and supervised shutdown. Journal write failures stop administrative authority while shutdown still waits for physical worker completion.

Replace the top-level grant command and separate admin-peer policy; remove unused grant commands. Scope admin options to their commands, document every users flag, and use --address consistently for network endpoints.

Validation: 163 CLI tests (including all four grant HTTP/owner tests), 54 SDK tests and 292 Work tests pass. Strict Clippy passes for CLI cloud/node/gateway/evaluate/telemetry, combined SDK funding features and Work, with all targets. Rust formatting, dependency order and TOML formatting pass. The grant-only SDK dependency graph excludes hellas-chain. All 153 chain tests pass with full-node, validator and work-watcher features. The full SDK test/Clippy matrix passes for combined, grant-only and all seven isolated feature sets. Hydra’s x86_64 required gate passes, including all VM tests. ARM checks and GitHub CI are pending.

Includes #36 and incorporates the merged #34 and #37 foundation.

Share marshal archives and Stateful execution across validators, full nodes and indexers. Replicate certified blocks and QMDB operation proofs through bounded multi-peer ChainSync, with provisioned authority and caught-up local Work views.

Keep setup checkpoints compact and recover historical obligations through certified archive reads. Remove stateless and remote paid followers, duplicate archives and execution journals.
Bound test runtimes to two workers, use a fixed grant clock, and give asynchronous fixtures one timeout budget. Test core-dump limits without installing the provider panic hook in the test process.
@hellasbot

hellasbot commented Oct 1, 2026 •

Copy link
Copy Markdown

Hydra: passed

Head a98beabda095 · Evaluation #202823 · Hydra jobset

All 39 builds passed.

georgewhewell added a commit that referenced this pull request Oct 2, 2026
Run authorized Work through durable grants with verified principals,
signed offers and pinned provider identities. The grant journal owns
policies, budgets, concurrency, expiry and usage accounting; client and
provider sessions use the shared Work lifecycle.

Add HTTPS resource routes and metering, owner grants, contact and offer
handling, grant administration, gateway backends and the Gate-facing
SDK. Owner execution uses grants without constructing a chain node.

Validation: Source checks and standalone CLI/chain feature lints pass.
SDK paid-work tests and lints pass. Grant HTTP tests and Clippy pass in
both network and evaluation builds with loopback-only networking and a
read-only home directory. Parallel CLI unit suites pass five consecutive
runs in both feature sets.

Depends on #33. Followed by #35.
Base automatically changed from codex/grant-funding to master October 2, 2026 04:32
Paid clients and providers read finalized state from one local full
node. Validators and full nodes share marshal archives and execution;
grant-only and owner-only processes construct no node.

Backfill uses Commonware's opaque resolver over multi-peer `ChainSync`,
with verified finality, peer quarantine and bounded requests. QMDB state
sync starts ordinary nodes at a provisioned, verified anchor; indexers
replay history through the same execution pipeline. Remove the stateless
follower, remote paid-state reads, per-channel catch-up loops and
retained setup block histories.

Acquired history is retained by default. `--chain-archive-blocks` bounds
public history; older blocks needed for private obligations are fetched
and verified from peers. A missing source leaves the obligation
retryable. Indexers retain their separate read index.

Indexers accept explicit ChainSync peers with `--peer
ENDPOINT_ID@IP:PORT`; validators can set `chain_sync_bind` for a fixed
UDP listener. The chain VM tests provision trust from their validator
configuration and follow the chain without public discovery.

Validation: CLI and chain feature lints, all 146 validator tests,
formatting and Nix checks pass. The updated discovery,
validator/follower and settlement VMs pass. Grant HTTP tests and Clippy
pass in both network and evaluation builds with loopback-only networking
and a read-only home directory. Native CLI and evaluation packages also
build and test successfully in Nix.

Depends on #35.
@georgewhewell
georgewhewell merged commit 6742bdd into master Oct 2, 2026
30 checks passed
@georgewhewell
georgewhewell deleted the codex/admin-users branch October 2, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants