Skip to content

Run authorized and paid Work through Gate's shared SDK - #586

Merged
georgewhewell merged 17 commits into
masterfrom
codex/shared-paid-gateway
Oct 3, 2026
Merged

georgewhewell merged 17 commits into
masterfrom
codex/shared-paid-gateway

Conversation

@georgewhewell

@georgewhewell georgewhewell commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Use the shared Work SDK for authorized and paid requests. Imported contact Offers open grant sessions; paid pools use authenticated provider offers and one shared executing chain node. Providers preserve durable quotas and revocations across restarts.

Keep explicit Responses and HTTP gateway configurations. Shutdown drains accepted work and reports failures after closing providers and chain state.

Pin the SDK fixes in hellas-ai/hellas#38 and hellas-ai/hellas#39. Use Xcode’s native compiler and linker, allow SDK selection through GATE_DEVELOPER_DIR, and set the recursion limit required by the chain transport futures.

Snapshot of uncommitted work that had been sitting in the working tree since
2026-09-02. Committed as-is on 2026-09-08 to get it into git rather than to
present a finished change -- rewrite or split it freely.

Three things are tangled together here because that is how they were found:

  - src-tauri/: a Tauri desktop app (15 files) including the Apple App Attest
    implementation, src-tauri/src/apple_app_attest.m and apple.rs. This is the
    receiving end of the split; the hellas repo still carries the matching
    deletion of crates/attestation/src/apple_app_attest.m and apple_macos.rs
    as its own uncommitted change, so that side is not yet committed either.
  - ui/ and macos/: the app's frontend and platform scaffolding.
  - A large restructure: 386 deletions, mostly crates/chat-ui and the GitHub
    workflow definitions. Intent not recorded anywhere; preserved verbatim.

Why this was committed now: the work existed only as untracked files on a
filesystem exported read-write to the whole LAN, in the directory adjacent to
/mnt/Home/src/hellas, which was emptied on 2026-09-05 by something still
unidentified. Untracked files have no git objects to recover from. Copies also
exist on the MacBook Air and at
/mnt/Home/Backups/gate-tauri-rescue/gate-untracked-20260908-1834.tgz.
georgewhewell added a commit to hellas-ai/hellas that referenced this pull request Sep 28, 2026
Extend Fetch to signed HTTPS exchanges and let native API clients use
standard HTTP endpoints backed by funded work channels. The gateway
selects an account from the requested model, preserves the upstream
response, and completes payment through the existing channel protocol.

### Behavior

- Add a shared Fetch work profile alongside Evaluate, with SDK sessions,
provider admission, authenticated streaming and restart recovery. The
reusable SDK paid pool serves both the CLI and Gate; client and provider
features are separate, with typed configuration and errors. The provider
invokes upstream only after accepting the signed job against its funded
channel, credit and route policy. The HTTP gateway requires a paid pool;
SDK Fetch providers configured for paid work advertise only Work and
WorkSetup.
- Carry HTTP methods, ordered queries, headers, encoded bodies, SSE and
non-2xx responses through Fetch. Restrict provider-owned credentials by
origin, path and method. Reuse upstream HTTPS and authenticated
Work/WorkSetup connections, preserve streaming backpressure, and keep
paid RPCs open through slow responses and idle connections. Accepted
jobs queue under provider capacity pressure instead of becoming
permanent failures.
- Start transparent HTTP through dedicated `HttpGatewayOptions` with a
required paid backend; tokenizer, inference-cache and Evaluate settings
are absent. Route standard API paths by model across configured
accounts. Pin existing sessions to their account, share capacity and
cooldown for credential aliases, and direct new sessions toward
available backends.
- Archive gateway exchanges by default, with per-request or gateway-wide
ZDR opt-out. Archive failures report telemetry while serving continues.
Fetch payment journals retain accounting, hashes and signatures without
payloads. Recovery pays verified deliveries from retained evidence,
retransmits certificates idempotently, and skips lost payloads without
re-executing them. Compressed requests receive the same ZDR retention
checks as uncompressed requests.
- Keep validator reads in independent channel observers. Provider
connections verify the configured genesis before advancing payment
state. Short journal locks order closes and new signatures; stale
observations stop new exposure, while retained certificates remain
retransmittable. Established-channel requests perform no consensus RPCs.

### Validation

At `d9407a2d`, all local gates invoked by `nix run .#check` have passed
across the aggregate runs and resumed checks: workspace and
feature-specific strict Clippy, formatting and dependency checks,
kernel/model, validator, RPC/work/client, SDK, HTTP/provider/storage,
and WebAssembly builds. The SDK suite has 33 tests, the gateway 66, and
the provider 70; the SDK client-only, provider-only and paid-gateway
feature sets are also linted independently.

The aggregate runs were not uninterrupted successes: one existing
gateway local-control request timed out, and two existing filesystem
tests exceeded their two-second limits. Their complete suites passed
unchanged on rerun. The final checks also caught and fixed provider
dependency ordering. A stale read-only zstd header in the local
WebAssembly build cache needed its write permission restored; this
required no source change.

Gate's integration passed `nix develop --command make check` (bindings,
TypeScript, frontend build, formatting, strict Clippy and 19 Rust
tests); the final form edits also passed `make ui-build`. See
hellas-ai/gate#586. These checks ran on Linux;
production Apple enrollment was not exercised.

`420f5e7e` fixes CLI tests that pinned superseded file-error wording and
adds `check-cli` to the aggregate local gate. `nix run .#check-cli`
passes all 179 tests, including the five that failed in the earlier
hosted builds; formatting and Nix lint checks also pass.

Hosted CI for the updated commit is queued:
https://github.com/hellas-ai/hellas/actions/runs/36457595760.

Regression coverage includes slow and idle paid streams, restart between
verified delivery and payment, duplicate payment recovery, payload-free
journals, paid-only protocol negotiation, genesis mismatch, bounded
queues under saturation, observer stalls, and close/payment ordering.
New coverage exercises the public HTTP entry point over a real socket,
credential injection over local TLS, authenticated connection reuse and
reconnect checks, and startup recovery without accidentally funding from
counter files alone. CI explicitly runs the SDK feature combinations and
HTTP/provider/storage suites.

Earlier live devnet passes through Kimi Code, Codex and Claude Code
completed their tool loops. Each pass produced six HTTP 200 exchanges
and six units of acknowledged payment. Exported token counters matched
response usage; all twelve established request traces contained zero
validator RPCs. These were smoke tests, not latency benchmarks or final
on-chain settlement tests.

### Review boundaries

Paid Fetch changes Work/WorkSetup wire descriptors and the StreamResult
schema. Gateways and providers must upgrade together; the on-chain
payment certificate format is unchanged.

Jobs within one funded channel finish in order. Generic HTTP streams
remain open through EOF. WebSocket upgrades and streaming uploads are
unsupported. ZDR controls application payload persistence; it does not
attest OS swap/dump handling or upstream retention. Explicitly
configured Courtesy HTTP routes still have no token-based spend
accounting; paid channels charge their agreed fixed job price.

This targets `master` independently of #29 (Runpod worker provisioning).
No stacking is required.

Configuration: [HTTP
gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/http-gateway.md),
[paid
gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/paid-gateway.md),
[HTTPS
provider](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/crates/providers/HTTPS.md).
Use contacts and pinned Offers for grant access, and signed paid offers for payment-funded sessions. Share the Work gateway backend across app runs and Responses serving; compose grant and paid provider routes, generic HTTPS resources and bond provisioning.
@georgewhewell georgewhewell changed the title Use the SDK paid pool for Gate's HTTP gateway Run authorized and paid Work through Gate's shared SDK Oct 3, 2026
@georgewhewell
georgewhewell marked this pull request as ready for review October 3, 2026 03:38
@georgewhewell
georgewhewell merged commit bf10051 into master Oct 3, 2026
3 checks passed
@georgewhewell
georgewhewell deleted the codex/shared-paid-gateway branch October 3, 2026 03:38
georgewhewell added a commit that referenced this pull request Oct 3, 2026
Ports Gate’s host control and private state to Windows on top of #586.
The diff contains the Windows named-pipe listener, private-directory
ACLs and bundled SQLite; shared Work/SDK integration lives in the base
PR. The Windows diff is 7 files, 101 insertions and 14 deletions.

Pins the same Hellas revision as #586, including hellas-ai/hellas#38 and
hellas-ai/hellas#39. Published history is preserved with normal merges.

Validation:
- Linux `make check`: 26 tests, bindings, frontend, formatting and
strict Clippy passed.
- Windows GNU cross-compilation of the desktop app and test executable
passed.
- Native `win10` VM: all 9 core tests passed, including authenticated
host status over a named pipe, private state, history and grant offer
export.
- Native SDK TLS Responses/quota/restart/revocation test passed.
- Desktop executable with bundled frontend and WebView2 loader launched
successfully.

Merge #586 first.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant