From 5866b2db94308c02c56c6b4d2e907713513e4980 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 9 Oct 2026 13:51:54 +0200 Subject: [PATCH] =?UTF-8?q?Hold=20a=20private=20kind's=20holder=20to=20an?= =?UTF-8?q?=20account=20of=20its=20own,=20as=20a=20verified=20one=20is=20(?= =?UTF-8?q?hq=20ADR=200259=20=C2=A77,=20=C2=A78)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A private kind is where the router shows a link's code, and the code makes an account the operator's. Registration refused a verified-sender holder on the machine's runtime and let a private one stand; it now refuses both (the confirmation review of 2026-10-09, low). --- internal/catalogue/kinded_test.go | 7 +++++++ internal/catalogue/seats_declared.go | 9 +++++++-- 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/internal/catalogue/kinded_test.go b/internal/catalogue/kinded_test.go index 15b15201..896a87f3 100644 --- a/internal/catalogue/kinded_test.go +++ b/internal/catalogue/kinded_test.go @@ -134,6 +134,13 @@ func TestATrustedHolderMustRunAsAnAccountOfItsOwn(t *testing.T) { if got := problemsFor(t, Shelf{"messenger": router(), "desk-channel": desk}); got != "" { t.Errorf("a channel proving nothing was held to it: %s", got) } + // A kind that is `private` shows a link's code, which links an account as the operator: its holder is + // trusted with it, so it runs as its own account too (the confirmation review of 2026-10-09). + private := aChannel("desk-channel", "desktop") + private.Claims[0].Capabilities = []string{"choice", "private"} + if got := problemsFor(t, Shelf{"messenger": router(), "desk-channel": private}); !strings.Contains(got, "desk-channel must run as an account of its own") { + t.Errorf("a private channel on the machine's runtime stood: %s", got) + } } func TestRunsAsIsAnAccountOfTheModulesOwn(t *testing.T) { diff --git a/internal/catalogue/seats_declared.go b/internal/catalogue/seats_declared.go index 1728a9bb..972eabf7 100644 --- a/internal/catalogue/seats_declared.go +++ b/internal/catalogue/seats_declared.go @@ -466,7 +466,8 @@ func RunsAsProblems(m Manifest) []string { // TrustedHolding is why a module must run as its own account (novox/hq ADR 0259 ยง8), or "": it holds a seat // whose events it says to one caller each (a warrant), or speaks for a kind of a kinded bench that proves -// its sender. Neither may be carried by the machine's runtime, which runs as the operator's account. +// its sender, or is private (a link's code is shown there). None may be carried by the machine's runtime, which +// runs as the operator's account. func TrustedHolding(m Manifest, declared map[string]SeatDeclaration) string { for _, c := range m.Claims { s, ok := declared[c.Name] @@ -480,8 +481,12 @@ func TrustedHolding(m Manifest, declared map[string]SeatDeclaration) string { } if s.Kinded { for _, capability := range c.Capabilities { - if capability == "verified-sender" { + switch capability { + case "verified-sender": return fmt.Sprintf("it holds %s of kind %s, which proves its sender", c.Name, c.Kind) + case "private": + // A private kind is shown a link's code, which makes an account the operator's. + return fmt.Sprintf("it holds %s of kind %s, which is private: a link's code is shown there", c.Name, c.Kind) } } }