Run authorized and paid Work through Gate's shared SDK - #586
Merged
Merged
Conversation
Snapshot of uncommitted work that had been sitting in the working tree since
2026-09-02. Committed as-is on 2026-09-08 to get it into git rather than to
present a finished change -- rewrite or split it freely.
Three things are tangled together here because that is how they were found:
- src-tauri/: a Tauri desktop app (15 files) including the Apple App Attest
implementation, src-tauri/src/apple_app_attest.m and apple.rs. This is the
receiving end of the split; the hellas repo still carries the matching
deletion of crates/attestation/src/apple_app_attest.m and apple_macos.rs
as its own uncommitted change, so that side is not yet committed either.
- ui/ and macos/: the app's frontend and platform scaffolding.
- A large restructure: 386 deletions, mostly crates/chat-ui and the GitHub
workflow definitions. Intent not recorded anywhere; preserved verbatim.
Why this was committed now: the work existed only as untracked files on a
filesystem exported read-write to the whole LAN, in the directory adjacent to
/mnt/Home/src/hellas, which was emptied on 2026-09-05 by something still
unidentified. Untracked files have no git objects to recover from. Copies also
exist on the MacBook Air and at
/mnt/Home/Backups/gate-tauri-rescue/gate-untracked-20260908-1834.tgz.
georgewhewell
added a commit
to hellas-ai/hellas
that referenced
this pull request
Sep 28, 2026
Extend Fetch to signed HTTPS exchanges and let native API clients use standard HTTP endpoints backed by funded work channels. The gateway selects an account from the requested model, preserves the upstream response, and completes payment through the existing channel protocol. ### Behavior - Add a shared Fetch work profile alongside Evaluate, with SDK sessions, provider admission, authenticated streaming and restart recovery. The reusable SDK paid pool serves both the CLI and Gate; client and provider features are separate, with typed configuration and errors. The provider invokes upstream only after accepting the signed job against its funded channel, credit and route policy. The HTTP gateway requires a paid pool; SDK Fetch providers configured for paid work advertise only Work and WorkSetup. - Carry HTTP methods, ordered queries, headers, encoded bodies, SSE and non-2xx responses through Fetch. Restrict provider-owned credentials by origin, path and method. Reuse upstream HTTPS and authenticated Work/WorkSetup connections, preserve streaming backpressure, and keep paid RPCs open through slow responses and idle connections. Accepted jobs queue under provider capacity pressure instead of becoming permanent failures. - Start transparent HTTP through dedicated `HttpGatewayOptions` with a required paid backend; tokenizer, inference-cache and Evaluate settings are absent. Route standard API paths by model across configured accounts. Pin existing sessions to their account, share capacity and cooldown for credential aliases, and direct new sessions toward available backends. - Archive gateway exchanges by default, with per-request or gateway-wide ZDR opt-out. Archive failures report telemetry while serving continues. Fetch payment journals retain accounting, hashes and signatures without payloads. Recovery pays verified deliveries from retained evidence, retransmits certificates idempotently, and skips lost payloads without re-executing them. Compressed requests receive the same ZDR retention checks as uncompressed requests. - Keep validator reads in independent channel observers. Provider connections verify the configured genesis before advancing payment state. Short journal locks order closes and new signatures; stale observations stop new exposure, while retained certificates remain retransmittable. Established-channel requests perform no consensus RPCs. ### Validation At `d9407a2d`, all local gates invoked by `nix run .#check` have passed across the aggregate runs and resumed checks: workspace and feature-specific strict Clippy, formatting and dependency checks, kernel/model, validator, RPC/work/client, SDK, HTTP/provider/storage, and WebAssembly builds. The SDK suite has 33 tests, the gateway 66, and the provider 70; the SDK client-only, provider-only and paid-gateway feature sets are also linted independently. The aggregate runs were not uninterrupted successes: one existing gateway local-control request timed out, and two existing filesystem tests exceeded their two-second limits. Their complete suites passed unchanged on rerun. The final checks also caught and fixed provider dependency ordering. A stale read-only zstd header in the local WebAssembly build cache needed its write permission restored; this required no source change. Gate's integration passed `nix develop --command make check` (bindings, TypeScript, frontend build, formatting, strict Clippy and 19 Rust tests); the final form edits also passed `make ui-build`. See hellas-ai/gate#586. These checks ran on Linux; production Apple enrollment was not exercised. `420f5e7e` fixes CLI tests that pinned superseded file-error wording and adds `check-cli` to the aggregate local gate. `nix run .#check-cli` passes all 179 tests, including the five that failed in the earlier hosted builds; formatting and Nix lint checks also pass. Hosted CI for the updated commit is queued: https://github.com/hellas-ai/hellas/actions/runs/36457595760. Regression coverage includes slow and idle paid streams, restart between verified delivery and payment, duplicate payment recovery, payload-free journals, paid-only protocol negotiation, genesis mismatch, bounded queues under saturation, observer stalls, and close/payment ordering. New coverage exercises the public HTTP entry point over a real socket, credential injection over local TLS, authenticated connection reuse and reconnect checks, and startup recovery without accidentally funding from counter files alone. CI explicitly runs the SDK feature combinations and HTTP/provider/storage suites. Earlier live devnet passes through Kimi Code, Codex and Claude Code completed their tool loops. Each pass produced six HTTP 200 exchanges and six units of acknowledged payment. Exported token counters matched response usage; all twelve established request traces contained zero validator RPCs. These were smoke tests, not latency benchmarks or final on-chain settlement tests. ### Review boundaries Paid Fetch changes Work/WorkSetup wire descriptors and the StreamResult schema. Gateways and providers must upgrade together; the on-chain payment certificate format is unchanged. Jobs within one funded channel finish in order. Generic HTTP streams remain open through EOF. WebSocket upgrades and streaming uploads are unsupported. ZDR controls application payload persistence; it does not attest OS swap/dump handling or upstream retention. Explicitly configured Courtesy HTTP routes still have no token-based spend accounting; paid channels charge their agreed fixed job price. This targets `master` independently of #29 (Runpod worker provisioning). No stacking is required. Configuration: [HTTP gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/http-gateway.md), [paid gateway](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/docs/paid-gateway.md), [HTTPS provider](https://github.com/hellas-ai/hellas/blob/codex/secure-fetch/crates/providers/HTTPS.md).
Use contacts and pinned Offers for grant access, and signed paid offers for payment-funded sessions. Share the Work gateway backend across app runs and Responses serving; compose grant and paid provider routes, generic HTTPS resources and bond provisioning.
georgewhewell
marked this pull request as ready for review
October 3, 2026 03:38
georgewhewell
added a commit
that referenced
this pull request
Oct 3, 2026
Ports Gate’s host control and private state to Windows on top of #586. The diff contains the Windows named-pipe listener, private-directory ACLs and bundled SQLite; shared Work/SDK integration lives in the base PR. The Windows diff is 7 files, 101 insertions and 14 deletions. Pins the same Hellas revision as #586, including hellas-ai/hellas#38 and hellas-ai/hellas#39. Published history is preserved with normal merges. Validation: - Linux `make check`: 26 tests, bindings, frontend, formatting and strict Clippy passed. - Windows GNU cross-compilation of the desktop app and test executable passed. - Native `win10` VM: all 9 core tests passed, including authenticated host status over a named pipe, private state, history and grant offer export. - Native SDK TLS Responses/quota/restart/revocation test passed. - Desktop executable with bundled frontend and WebView2 loader launched successfully. Merge #586 first.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Use the shared Work SDK for authorized and paid requests. Imported contact Offers open grant sessions; paid pools use authenticated provider offers and one shared executing chain node. Providers preserve durable quotas and revocations across restarts.
Keep explicit Responses and HTTP gateway configurations. Shutdown drains accepted work and reports failures after closing providers and chain state.
Pin the SDK fixes in hellas-ai/hellas#38 and hellas-ai/hellas#39. Use Xcode’s native compiler and linker, allow SDK selection through
GATE_DEVELOPER_DIR, and set the recursion limit required by the chain transport futures.