diff --git a/internal/catalogue/kinded_test.go b/internal/catalogue/kinded_test.go index 15b15201..896a87f3 100644 --- a/internal/catalogue/kinded_test.go +++ b/internal/catalogue/kinded_test.go @@ -134,6 +134,13 @@ func TestATrustedHolderMustRunAsAnAccountOfItsOwn(t *testing.T) { if got := problemsFor(t, Shelf{"messenger": router(), "desk-channel": desk}); got != "" { t.Errorf("a channel proving nothing was held to it: %s", got) } + // A kind that is `private` shows a link's code, which links an account as the operator: its holder is + // trusted with it, so it runs as its own account too (the confirmation review of 2026-10-09). + private := aChannel("desk-channel", "desktop") + private.Claims[0].Capabilities = []string{"choice", "private"} + if got := problemsFor(t, Shelf{"messenger": router(), "desk-channel": private}); !strings.Contains(got, "desk-channel must run as an account of its own") { + t.Errorf("a private channel on the machine's runtime stood: %s", got) + } } func TestRunsAsIsAnAccountOfTheModulesOwn(t *testing.T) { diff --git a/internal/catalogue/seats_declared.go b/internal/catalogue/seats_declared.go index 1728a9bb..972eabf7 100644 --- a/internal/catalogue/seats_declared.go +++ b/internal/catalogue/seats_declared.go @@ -466,7 +466,8 @@ func RunsAsProblems(m Manifest) []string { // TrustedHolding is why a module must run as its own account (novox/hq ADR 0259 ยง8), or "": it holds a seat // whose events it says to one caller each (a warrant), or speaks for a kind of a kinded bench that proves -// its sender. Neither may be carried by the machine's runtime, which runs as the operator's account. +// its sender, or is private (a link's code is shown there). None may be carried by the machine's runtime, which +// runs as the operator's account. func TrustedHolding(m Manifest, declared map[string]SeatDeclaration) string { for _, c := range m.Claims { s, ok := declared[c.Name] @@ -480,8 +481,12 @@ func TrustedHolding(m Manifest, declared map[string]SeatDeclaration) string { } if s.Kinded { for _, capability := range c.Capabilities { - if capability == "verified-sender" { + switch capability { + case "verified-sender": return fmt.Sprintf("it holds %s of kind %s, which proves its sender", c.Name, c.Kind) + case "private": + // A private kind is shown a link's code, which makes an account the operator's. + return fmt.Sprintf("it holds %s of kind %s, which is private: a link's code is shown there", c.Name, c.Kind) } } }