mirror of
https://github.com/logos-co/logos-cpp-sdk.git
synced 2026-08-31 01:31:10 +00:00
Completes the C1 codegen half. A3 declared this entry point in logos_module_impl.h and documented that the grant MUST cross the C ABI, but the generator never emitted it, so nothing could open a module's gates. The body forwards to lp_grant_host_services in the MODULE's own image, which is the entire point. Verified that premise on a real built module rather than taking it from the header comment: test_basic_module_cpp_plugin.dylib DEFINES 25 lp_* symbols and imports zero — logos-protocol is statically linked into each plugin, so the module's gate state really is its own, and a grant recorded only in the host would leave lp_token_keys() returning null forever. That failure is silent: null is indistinguishable from an empty token store. Emitted unconditionally rather than behind a codegen flag. Which modules are privileged is the host's decision — it pushes nothing to an ordinary module — and lp_grant_host_services validates the names and fails closed, so a per-module flag would only add a second place for declaration and capability to disagree. The comment states the boundary honestly: this is a declaration-and-audit mechanism, NOT a defence against a hostile module. The cdylib links logos-protocol, so its own code can call lp_grant_host_services() directly and self-grant. What the gate buys is that the privilege is explicit, greppable and off by default. Isolation between modules rests on process separation, the auth token, and the target's allowedCallers. Three tests, one per property that could regress independently: the export exists; its body actually forwards (a stub returning 0 would make every host push look successful while both gates stayed shut); and it is emitted for an ordinary module too, not only for privileged ones. Confirmed in the built artifact: nm on a real universal module lists _logos_module_grant_host_services alongside the other seven module-impl exports. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>