Conversation
Hilt rotates a principal-bound key's delegations on every policy change and needs every revocation of one write sent together, so that the write waits on one round trip regardless of how many keys it touches. PublishBatch builds one self-signed /ucan/revoke invocation per revoked delegation and sends them in a single container through ucantone's ExecuteBatch, failing on the first refused receipt. ucantone is bumped to the version that exposes batch execution. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
RFC 30 (fil-one/RFC#30) has Hilt rotate a principal-bound key's delegations on every policy change and send every revocation produced by one write to Swarf in a single request, so a write waits on one round trip however many keys it touches. The client gains
PublishBatch, which builds one self-signed/ucan/revokeinvocation per revoked delegation and sends them in one container through ucantone'sExecuteBatch. Every receipt is checked; the first refused one fails the call. The service needs no change: a ucantone server already executes every invocation in a request container.Change log
pkg/client:PublishBatch(ctx, revoker, revoked []ucan.Delegation); the executor is the ucantone HTTP client so bothExecuteandExecuteBatchare available.go.mod: ucantone bumped tob59f1d1fcbb6forexecution/batch.TestPublishBatch(one request for two delegations, an empty batch publishes nothing, a refused revocation fails the call).🤖 Generated with Claude Code