ICPWatch
Get alerts
Protocol canisters

Upgrade the Registry Canister to Commit 98c898f

#144199 · Open · 4 d left · proposed Oct 2, 2026

Yes 94.7%0.7% of voting power has votedNo 5.3%
tally read NNS governance canister, list_proposals
Action
Install Code
Proposer neuron
51
Created
Voting ends
Oct 6, 2026 (in 4 d)

Summary

Upgrade the Registry Canister to Commit 98c898f

__Proposer__: daniel.wong at dfinity.org

__Source code__: [98c898f8de068a1fc0e97ebc805f9fa7f315d862][new-commit]

[new-commit]: https://github.com/dfinity/ic/tree/98c898f8de068a1fc0e97ebc805f9fa7f315d862

Features & Fixes

Added

  • A subnet-split request will now fail if a concurrent call modified the StandardEngineReplicaVersionRecord

while the fresh key material was being generated for the splitting subnet.

  • A subnet-split request whose source subnet is a cloud engine that derives its replica version from the

StandardEngineReplicaVersionRecord will now be rejected while a deployment of a new replica version is in progress. This guarantees that both subnets run the same replica version after the split.

  • Invariant requiring that every elected GuestOS and HostOS version ID is well-formed, i.e. that it consists

only of alphanumeric characters, dots, dashes and underscores. Such IDs are what ReplicaVersion and HostosVersion accept, so until now, it was possible to elect a version that consumers could not read back out of the Registry.

  • secp256r1 as a variant of EcdsaCurve, so a chain key config may now name a NIST P-256

ECDSA key. It is reachable through create_subnet and update_subnet, and a subnet accepting it still needs the key itself to be generated and enabled by separate proposals.

  • merge_subnets endpoint, callable through a MergeSubnets proposal. It merges a subnet into

another subnet: in the routing table, reassigns all canister ranges hosted by the source subnet to the destination subnet. Only the routing table is updated: neither subnet record is modified and the source subnet is not deleted.

  • Newly created CatchUpPackageContents records with CUP type CupType::Genesis will not contain a height

field anymore. You can (and should) assume that the height for Genesis CUPs is always 0.

  • Invariant requiring that every subnet's CatchUpPackageContents record has a cup_type set.
  • One-time post-upgrade migration backfilling cup_type on every CatchUpPackageContents record

that has none. A record whose legacy height, time and state_hash fields are all unset is stamped as CupType::Genesis. Any other record is stamped as CupType::Recovery, which keeps those legacy values.

Changed

  • The maximum size of a single atomic registry mutation (MAX_CHUNKABLE_ATOMIC_MUTATION_LEN) is raised from

10 MiB to 13 MiB. Many Registry data migrations (one-time mutations during post_upgrade) piled up, due to a slower than usual upgrade cadence, and together they amount to a single mutation of about 12 MB on mainnet state.

  • update_subnet now also lets the engine controller canister set cooling_down on a cloud engine

subnet. The engine controller's scope is thus subnet_admins, is_halted and cooling_down; every other field remains rejected for that caller.

  • UpdateStandardEngineReplicaVersion can now start a new deployment after the previous one has been

fully rolled back (deployment_progress == 0.0), not just after it has been fully rolled forward (deployment_progress == 1.0).

New Commits

$ git log --format="%C(auto) %h %s" 237a41f0f03801f24d6eda835248bcb5ce189f0e..98c898f8de068a1fc0e97ebc805f9fa7f315d862 --  ./rs/registry/canister
 98c898f8de fix(registry): raise MAX_CHUNKABLE_ATOMIC_MUTATION_LEN to 13 MiB (#11746)
 edcce4f4f9 chore(registry): [CON-1671] backfill `cup_type`s of `CatchUpPackageContents ` records + invariant ensuring their presence (#11578)
 89dd01c3bd feat(registry): Let the engine controller make a cloud engine cool down (#11519)
 cf4331ee55 chore(registry): [CON-1671] remove `height` field in Genesis CUPs (#11577)
 621f646bcf test(subnet-splitting): enable subnet splitting in test releases (#11649)
 48b6f629d7 feat(crypto): add secp256r1 variant to EcdsaCurve (#11573)
 279f3a6fe8 feat(registry): add merge_subnets endpoint (#11366)
 5b49fd2520 feat(registry): Allow advancing standard engine replica version after a roll back. (#11403)
 037a7f09ed docs(governance): Changelogs for 2026-08-28 upgrade proposals (#11372)
 0990a520d6 feat(registry): ensure all elected versions can be parsed (#11249)
 1509403599 feat(registry): ensure no version deployment is in progress when splitting a cloud engine + that the record was not changed (#11242)

Current Version

__Current git hash__: 237a41f0f03801f24d6eda835248bcb5ce189f0e

__Current wasm hash__: fbe290283a2c2d01401df42f8481e6f95512324eb5aad9568d71ba982939b823

Verification

See the general instructions on [how to verify] proposals like this. A "quick start" guide is provided here.

[how to verify]: https://github.com/dfinity/ic/tree/98c898f8de068a1fc0e97ebc805f9fa7f315d862/rs/nervous_system/docs/proposal_verification.md

WASM Verification

See ["Building the code"][prereqs] for prerequisites.

[prereqs]: https://github.com/dfinity/ic/tree/98c898f8de068a1fc0e97ebc805f9fa7f315d862/README.adoc#building-the-code

# 1. Get a copy of the code.
git clone git@github.com:dfinity/ic.git
cd ic
# Or, if you already have a copy of the ic repo,
git fetch
git checkout 98c898f8de068a1fc0e97ebc805f9fa7f315d862

# 2. Build canisters.
./ci/container/build-ic.sh -c

# 3. Fingerprint the result.
sha256sum ./artifacts/canisters/registry-canister.wasm.gz

This should match wasm_module_hash field of this proposal.

Official view: dashboard.internetcomputer.org/proposal/144199