Port Gate's local control and private state to Windows - #585
Merged
Merged
Conversation
Snapshot of uncommitted work that had been sitting in the working tree since
2026-09-02. Committed as-is on 2026-09-08 to get it into git rather than to
present a finished change -- rewrite or split it freely.
Three things are tangled together here because that is how they were found:
- src-tauri/: a Tauri desktop app (15 files) including the Apple App Attest
implementation, src-tauri/src/apple_app_attest.m and apple.rs. This is the
receiving end of the split; the hellas repo still carries the matching
deletion of crates/attestation/src/apple_app_attest.m and apple_macos.rs
as its own uncommitted change, so that side is not yet committed either.
- ui/ and macos/: the app's frontend and platform scaffolding.
- A large restructure: 386 deletions, mostly crates/chat-ui and the GitHub
workflow definitions. Intent not recorded anywhere; preserved verbatim.
Why this was committed now: the work existed only as untracked files on a
filesystem exported read-write to the whole LAN, in the directory adjacent to
/mnt/Home/src/hellas, which was emptied on 2026-09-05 by something still
unidentified. Untracked files have no git objects to recover from. Copies also
exist on the MacBook Air and at
/mnt/Home/Backups/gate-tauri-rescue/gate-untracked-20260908-1834.tgz.
Built against hellas-ai/hellas#27, which adds hellas-private, the Windows named-pipe local-control transport, and a cancel-safe mux frame reader. - host control: on Windows, serve HostControl through hellas's owner-authenticated named pipe (owner-only DACL, anti-squatting first instance, remote clients refused, peer process must run as this user), derived from the same gate.sock path so hellas-cli finds it. Unix keeps its socket and peer-uid check unchanged. - private data directory via hellas_private::restrict_directory: 0700 on Unix; on Windows an owner-only inheritable DACL, so identities, history and credentials written inside are private. - provider identity no longer needs Unix permission APIs to compile. - SQLite: Windows has none, so compile the amalgamation in with libsqlite3-sys (bundled) there; Unix still links the system library. - New test: host status is served over the local transport (Unix socket, or the named pipe on Windows). Verified: all of Gate, Tauri included, type-checks for x86_64-pc-windows-gnu; Gate's lib tests pass on Windows 10 (3 runs); Linux clippy -D warnings, fmt and the 18 workspace tests pass. The Windows build/bundle pipeline is not decided yet, so tauri.conf is unchanged.
Contributor
Author
|
Re-pinned |
Use contacts and pinned Offers for grant access, and signed paid offers for payment-funded sessions. Share the Work gateway backend across app runs and Responses serving; compose grant and paid provider routes, generic HTTPS resources and bond provisioning.
Use contacts and pinned Offers for grant access, and signed paid offers for payment-funded sessions. Share the Work gateway backend across app runs and Responses serving; compose grant and paid provider routes, generic HTTPS resources and bond provisioning.
georgewhewell
changed the base branch from
master
to
codex/shared-paid-gateway
October 3, 2026 02:34
georgewhewell
added a commit
that referenced
this pull request
Oct 3, 2026
Gate uses the merged Work foundation for authorized and paid requests. Imported contact Offers open grant sessions; paid pools use authenticated provider offers and one shared executing chain node. Providers serve both fundings through the SDK and preserve durable quotas and revocations across restarts. The gateway has explicit Responses and HTTP configurations. Responses uses the selected Work target; HTTP retains paid-pool routing, provider assurance and optional body archiving. Shutdown drains accepted work and surfaces SDK failures after closing providers and chain state. Pins Hellas `9c342ba1`, including hellas-ai/hellas#38 (finalized owner publication ordering) and hellas-ai/hellas#39 (current App Attest extensions and the Windows TLS fixture). Native archives use Xcode’s compiler and linker. The shell follows `xcode-select`, with `GATE_DEVELOPER_DIR` for provisioned SDK 27 builds; the signing guide documents the requirement. The release binary has the recursion limit needed by the chain transport futures. Validation: - Linux and native macOS `make check`: 25 tests, bindings, frontend, formatting and strict Clippy passed. - Native macOS release app built and passed bundle validation. - Developer ID signed, provisioned test bundle on `mbp`: Apple enrollment, pinned remote grant session, provider restart and a second session passed. The test uses the installed `ai.hellas.app-attest-spike` profile; production Gate keeps its own bundle ID. - SDK TLS Responses, quota exhaustion, restart and revocation passed on Linux, macOS and Windows. Merge the two Hellas fixes first. Windows support is isolated in #585, based on this PR.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Windows host control through an owner-authenticated named pipe, private-directory ACLs and bundled SQLite. Builds on the shared Work/SDK integration in #586.