Repository navigation
feat: replace dna_hashes/dna_modifiers with role-centric roles config - #18
Merged
Merged
Conversation
dna_hash's sole purpose is binding a membrane proof to a network, so roles that don't need a proof shouldn't need to carry one. Validation now enforces dna_hash only when membrane_proof.enabled is true, while still format-validating any dna_hash that is present regardless of that setting. Provision generates proofs only for roles that have a hash; hash-less roles keep their dna_modifiers with no membrane_proof.
…dance (#14) Aligns the roles config reference with the now-optional dna_hash, and explains why the hash must come from a running conductor: network_seed and properties (including the progenitor) are hashed into the DNA, so the bundle's base hash or a hand-computed value binds membrane proofs to the wrong network and they will never validate.
ThetaSinner
reviewed
Aug 17, 2026
ThetaSinner
left a comment
There was a problem hiding this comment.
Is this structured the right way round? If I have the same role, over multiple networks, I require duplicate keys in a map.
Or is this change prior to handling multiple networks?
I'd expect the DNA hash to be the top level key perhaps?
Member
Author
Yes, this is prior to handling multiple-networks, that's coming next, and things will be keyed by happ-id and this will no longer conflict. I wanted to just get the role shape in place first. |
Member
Author
|
multi-network is in #19 |
ThetaSinner
approved these changes
Aug 20, 2026
ThetaSinner
left a comment
There was a problem hiding this comment.
Fine, happy with this as a stepping stone towards multi network support
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #14.
Config now mirrors Holochain's app model — each role carries its own DNA hash and modifiers:
This replaces
dna_hashesand the globaldna_modifiersoutright — no compatibility layer. A config still containing the old keys fails at startup with an error pointing atroles.dna_hashis required only when membrane proofs are enabled — it exists solely to bind proofs to a network. When present it is strictly validated (39-byte HoloHash, DnaHash prefix), so a role name can no longer masquerade as a hash. Configure the post-modifiers DNA hash, read from the conductor that installed the DNA (see DEPLOYMENT.md's "Obtaining the DNA hash") — the bundle's base hash produces proofs that never validate.roles: { <role>: { membrane_proof?, dna_modifiers? } }, mirroringhc s call install-app --roles-settings. The oldmembrane_proofsmap and top-leveldna_modifiersare gone./v1/info: per-roledna_modifiersunderroles(never DNA hashes or proofs); top-leveldna_modifiersis gone.