PathrockNetwork Gno Explorer
HomeBlocksTransactionsRealmsPackagesValidatorsAnalytics

PathrockNetwork Gno Explorer — an independent explorer for Gno.land Mainnet (gnoland-1), operated by PathrockNetwork. Not an official Gno.land service.

gnowebarchive RPC

gno.land/p/moul/x/daily/pullpayment/v0

Package
Open in gnoweb ↗

Overview

Kind
Pure package
Name
v0
Namespace
moul / x / daily / pullpayment
Files
3 (README)(gnomod.toml)
Exported functions
n/a — not supported for pure packages by the node (vm/qfuncs)
Module
gno.land/p/moul/x/daily/pullpayment/v0
gno
0.9

Files (3)

  • README.mdmarkdown
  • gnomod.tomltoml
  • pullpayment.gnogno
README.mdPreviewRaw
# `gno.land/p/moul/x/daily/pullpayment/v0`

**Pull-payment escrow ledger** — `New`, `Credit`, `CreditMany`, `Withdraw`,
`Forfeit`, `Balance`, `TotalOwed`, `TotalWithdrawn`, `Payees`, `Iterate`,
`Consistent`, `MaxPayees`.

```go
import "gno.land/p/moul/x/daily/pullpayment/v0"

l := pullpayment.New()
l.CreditMany([]string{"alice", "bob"}, []int64{500, 300})
l.TotalOwed()          // 800 — what the realm must keep in reserve

amt, err := l.Withdraw("bob")   // 300; the balance is ALREADY zeroed
// ...the caller transfers `amt` only now
```

The classic Solidity answer to reentrancy: never push value to an address,
credit it and let the recipient withdraw. A push hands control to the recipient
in the middle of your state transition, and a hostile recipient re-enters before
you have finished updating.

This package is the **bookkeeping half only** — it moves no coins. The realm
holding the funds transfers *after* calling `Withdraw`, which is exactly the
ordering the pattern demands: checks, effects, **then** interactions. The balance
is already deleted when control leaves, so a reentrant `Withdraw` returns
`ErrNothing` and `TotalWithdrawn` is not double-counted. That property has its own
test.

Other guarantees, each tested:

- **`CreditMany` is all-or-nothing.** A batch with one bad entry applies none of
  itself — a ledger half-agreeing with the funds it guards is worse than a
  rejected call.
- **Overflow is refused**, not wrapped, on both a single balance and the total.
- `Consistent()` is exported: `TotalOwed` always equals the sum of the balances.

`Payees` comes back **sorted**, never in map order, so a `Render` built from it
cannot differ between nodes.

**Live demo:** [`r/moul/x/daily/pullpaymentdemo`](https://github.com/moul/gno-contracts/tree/main/r/moul/x/daily/pullpaymentdemo/v0)
· render it at [`/r/moul/x/daily/pullpaymentdemo/v0`](https://gno.land/r/moul/x/daily/pullpaymentdemo/v0).

<!-- BEGIN GNOCONTRACTS FOOTER (generated by `make readmes`; do not edit below) -->

---

Part of **[moul/gno-contracts](https://github.com/moul/gno-contracts)** — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.

> 🧪 **Highly experimental — potentially vibe-coded.** Not audited; may break, change, or be removed at any time. Do not use with anything of value. Full disclaimer: [DISCLAIMER](https://github.com/moul/gno-contracts/blob/main/DISCLAIMER.md).

<!-- END GNOCONTRACTS FOOTER -->

Functions

not supported for pure packages by the node (vm/qfuncs)

Signatures reconstructed verbatim from vm/qfuncs — interface params keep their inline definitions.