Skip to content

feat: replace dna_hashes/dna_modifiers with role-centric roles config - #18

Merged
zippy merged 4 commits into
mainfrom
feat/role-centric-network-config
Aug 21, 2026
Merged

zippy merged 4 commits into
mainfrom
feat/role-centric-network-config

Conversation

@zippy

@zippy zippy commented Aug 14, 2026

Copy link
Copy Markdown
Member

Fixes #14.

Config now mirrors Holochain's app model — each role carries its own DNA hash and modifiers:

"roles": {
  "main": {
    "dna_hash": "uhC0k...",
    "modifiers": { "network_seed": "...", "properties": { "progenitor_pubkey": "uhCAk..." } }
  }
}

This replaces dna_hashes and the global dna_modifiers outright — no compatibility layer. A config still containing the old keys fails at startup with an error pointing at roles.

  • dna_hash is required only when membrane proofs are enabled — it exists solely to bind proofs to a network. When present it is strictly validated (39-byte HoloHash, DnaHash prefix), so a role name can no longer masquerade as a hash. Configure the post-modifiers DNA hash, read from the conductor that installed the DNA (see DEPLOYMENT.md's "Obtaining the DNA hash") — the bundle's base hash produces proofs that never validate.
  • Provision response: per-role roles: { <role>: { membrane_proof?, dna_modifiers? } }, mirroring hc s call install-app --roles-settings. The old membrane_proofs map and top-level dna_modifiers are gone.
  • /v1/info: per-role dna_modifiers under roles (never DNA hashes or proofs); top-level dna_modifiers is gone.
  • CLI roles-settings YAML emits each role's own modifiers.

zippy added 4 commits August 13, 2026 14:02
dna_hash's sole purpose is binding a membrane proof to a network, so
roles that don't need a proof shouldn't need to carry one. Validation
now enforces dna_hash only when membrane_proof.enabled is true, while
still format-validating any dna_hash that is present regardless of
that setting. Provision generates proofs only for roles that have a
hash; hash-less roles keep their dna_modifiers with no membrane_proof.
…dance (#14)

Aligns the roles config reference with the now-optional dna_hash, and
explains why the hash must come from a running conductor: network_seed
and properties (including the progenitor) are hashed into the DNA, so
the bundle's base hash or a hand-computed value binds membrane proofs
to the wrong network and they will never validate.
@zippy
zippy requested a review from ThetaSinner August 14, 2026 14:30

@ThetaSinner ThetaSinner left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this structured the right way round? If I have the same role, over multiple networks, I require duplicate keys in a map.

Or is this change prior to handling multiple networks?

I'd expect the DNA hash to be the top level key perhaps?

@zippy

zippy commented Aug 17, 2026

Copy link
Copy Markdown
Member Author

Or is this change prior to handling multiple networks?

Yes, this is prior to handling multiple-networks, that's coming next, and things will be keyed by happ-id and this will no longer conflict. I wanted to just get the role shape in place first.

@zippy

zippy commented Aug 18, 2026

Copy link
Copy Markdown
Member Author

multi-network is in #19

@ThetaSinner ThetaSinner left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fine, happy with this as a stepping stone towards multi network support

@zippy
zippy merged commit c9f4ee9 into main Aug 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Properties layout assumes an app with a single role

2 participants