All notable changes to HOLOGRAM are documented in this file.
Format follows Keep a Changelog. Versioning follows Semantic Versioning.
- A TELA INDEX can be updated on the simulator again.
update-indexrefused every attempt with "Your wallet is not the owner of this INDEX", including from the wallet that had just installed it. The check compared the author string stored in the INDEX against the address the wallet renders — but those two strings come from two different renderers. The stored author is what the contract'saddress()returned, which is the DVM'sADDRESS_STRING, which builds it withrpc.NewAddressFromKeysand leavesMainnettrue; consensus cannot depend on which network a node thinks it is on, so a contract recordsdero1...on every chain, the simulator included. walletapi renders the same key through the wallet's network flag and saysdeto1...there. A DERO address is bech32 — the prefix names the network and the checksum is computed over it — so both halves differ and the compare read one wallet as two, always. Ownership is now decided on the decoded public key. The contract's own owner gate was never affected (it comparesaddress()toaddress()), and neither was mainnet, where both renderings agree. The same correction applies to the ownership flag reported by INDEX info, which readfalsefor the owner's own INDEX on the simulator.
A rebuilt consent model for dApps — connecting no longer asks for wallet access, and access that is remembered is remembered per wallet. Plus sender-attribution privacy, cold-wallet genesis, XSWD/Browser trust-boundary hardening, fund-safety guards on the hot send path, Linux launch fixes for WebKitGTK, TELA file-drop, name resolution, and a required consensus repin ahead of the DERO network's HF3 activation.
- Repinned the embedded
derodto theDHEBP/derohefork's HF3-ready state. Without this, HOLOGRAM's bundled node would have forked off the DERO network at block 7,504,640 — silently, with no error surfaced to the user. The fork carries the full set of transactions affected by the HF3 nonce-parity change and has been verified reaching chain tip with zero verification failures.
- Wallet: cold-wallet offline genesis — mine registration air-gapped, then broadcast a saved DCSP blob from inside HOLOGRAM (paste → fingerprint check → send).
- Wallet: sender-attribution controls on Send (anonymize / preferred decoys) with an approval modal that shows the effective ring and only promises a decoy when it holds.
- Send: Ring Members inline editor — build and name a decoy set without leaving the form.
- Linux: desktop installer in the release tarball (
install.sh/uninstall.sh/ icon /.desktop) so double-click and the app menu work without a bare binary. - Builds against the consensus-identical
DHEBP/derohefork (walletapi privacy patches only).
- dApp consent is now three doors. Connecting grants public blockchain data and nothing else — no checkboxes. Anything touching the wallet is asked for at the moment the app reaches for it, and that answer can be remembered. Spending is asked every time and can never be stored, enforced where grants are written rather than in the interface.
- Remembered access is scoped to the wallet that granted it. Approving an app under one wallet no longer covers the next wallet you open — that one is asked again. Grants made before this update cannot be attributed to a wallet and are dropped, so each app asks once more per wallet.
- Permission prompts list their three answers in a column, least commitment first, so a long label cannot squeeze them into unreadable chips.
- Smart contract writes report submitted, not saved. The call returns when the transaction is broadcast; the contract applies it when the transaction is mined and can still refuse.
- App state consolidated under
~/.dero/hologram(legacy CWD litter migrated best-effort). - Idle auto-lock: UI drops to the unlock screen on
wallet:autoLocked; docs claim an app-layer lock (spend refused), not in-memory secret scrub. - Browser session auth is parent-owned.
- Linux release folder ships binary + installer assets instead of a bare executable.
- Smart contract writes are paid for. A contract call is charged for what it stores, and the fee attached to the transaction is that budget — but the fee the wallet works out on its own covers less than the chain charges, so a write past a few hundred bytes was mined, charged, and stored nothing while the interface reported success. HOLOGRAM now measures what a call will store and, when the transaction it built does not carry enough, rebuilds it carrying the measured amount. It only ever raises the fee, and never above the chain's per-call ceiling, beyond which the extra would be spent without buying anything. On a test chain, writes of 500, 2,000 and 5,000 bytes were all lost before this change and all stored after it. This applies to the Explorer and Studio function caller and to contract calls arriving from dApps, which share one broadcast path; setting a variable from the Explorer and updating a TELA INDEX go through the TELA library, which already paid for its writes, and are unchanged.
- Smart contract writes that the chain cannot apply at any price are refused before broadcast, on the Explorer variable editor, the Explorer/Studio function caller, and INDEX updates. Above the storage ceiling a write is still mined and still charged while the contract stores nothing — HOLOGRAM checks the cost first and says how much to cut. When the cost cannot be measured the write proceeds as before rather than being blocked on a failed measurement. Calls from dApps are refused too: they arrive over a different route that skipped all three of those checks, so the refusal now also sits at the point every contract call passes through on its way out — which is why a fee the caller set itself no longer buys past it either, since nothing can.
- dApps can read the chain tip again:
DERO.GetHeightand the other no-argument daemon calls were rejected outright when a dApp sent an empty parameter object, which is ordinary JSON-RPC client behaviour. - A refused prompt reaches the dApp as the spec's own “permission denied” code instead of a generic failure, on every bridge — so an app can tell a refusal from a broken call.
- Permission prompts name the method that triggered them, show a full-length contract origin without clipping it mid-string, and no longer fragment their own explanatory text into columns.
- Browser: standing grants are read back from storage, so “remember this” survives a tab switch; grants key on the chain-resolved contract id after a session is restored, and a requested navigation wins over a restored one.
- TELA Rate from Discover Apps: submit no longer requires an Engram XSWD client connection — with the integrated wallet open (“Wallet Ready”) it invokes
Ratelocally. The sidebar XSWD light only meant HOLOGRAM’s server was up, so ratings failed with “Wallet not connected via XSWD” and no console trail. - About / version:
AppVersionis embedded from theVERSIONfile (kept in sync with CHANGELOG by CI) so About can no longer stick on a stale hardcoded release like 1.0.5. - XSWD: empty-origin sockets no longer skip permission checks; handshake requires a non-empty
url. - Browser: connect permissions are enforced on integrated-wallet reads; client
authStateis ignored (no forgeable'ok'). - Browser: srcdoc loads lock sandbox without
allow-same-originbefore content is assigned (closes a same-origin/window.gopivot race). - Approval modal shows every destination, token lines, and
sc_dero_deposit/sc_token_deposit— what you approve is what executes. - Native-DERO burn guard: junk
sc_rpcwithout a real entrypoint/SCACTIONno longer bypasses the block or labels destruction as a deposit. - Integrated-address invoice checks (amount + expiry) run on the hot
InternalWalletCallpath the Send UI actually uses. - XSWD anonymize clamps ring size to ≥16 so the decoy promise cannot ship at ring 2.
- TELA ratings: Rate arg is
"r"(was"rating"— ratings never recorded); non-functional Like/Dislike removed for Engram parity. - Browser: Discover Apps keeps polling until Gnomon’s first index finishes (~5 min), with a one-shot TOP RATED → ALL fallback on empty cold start.
- Wallet: empty-destination sends rejected; wrong-network destinations blocked on XSWD/token paths; unresolved destinations no longer misdiagnosed as “not registered.”
- Linux: WebKitGTK DMA-BUF hang on NVIDIA/Wayland — set
WEBKIT_DISABLE_DMABUF_RENDERER=1before the WebView starts. - TELA: dropping a file on an app no longer navigates the whole window away to that file. Fixed across all three bridges (proxy, srcdoc, and locally-served apps), which previously disagreed on drag-and-drop behavior.
- TELA: a dropped file is now identified by its real type instead of always reading as generic binary, so apps that filter by file type work correctly.
- Wallet: a registered name typed into the Send field or a Ring Members entry now resolves to its address live, with a status indicator, instead of reporting "Invalid DERO address."
- Wallet: a custom daemon endpoint is no longer silently overwritten when switching networks.
- XSWD:
DERO.GetSCstring values returned to dApps are no longer double-decoded, so contract data read through HOLOGRAM now matches what other XSWD-compliant wallets return. - Wallet: send-confirmation now clearly separates the ring breakdown (you + recipient + chosen + random) from the named decoy set, instead of running both together on one ambiguous line.
- Wallet: paying an address that requests a reply-back destination no longer spends funds against a request the wallet couldn't actually fulfil; sending to such a destination is refused up front. Reply-back payments are now supported when the paying wallet chooses to disclose its address, shown plainly in the send confirmation and the XSWD approval modal before it's sent.
- Fixed a crash where dividing by a zero-sized cache produced an unrepresentable number that the frontend bridge could not serialize, freezing the UI.
- Smart contract deployment (Explorer/Studio "install a new contract") now gets the same storage-gas measurement, refusal, and fee top-up as calling an existing contract. It had been broadcasting directly and, on the non-simulator path, with a fee of
0— the exact under-funding the rest of the storage-gas fix exists to prevent, just on the one path that was missed. - XSWD plain transfers (a dApp asking HOLOGRAM to send DERO, with no special parameters) now default to ring size 16, matching every other send path in the wallet. They had been defaulting to ring 2, silently stripping sender privacy for the ordinary case; contract-call paths (SC deployment,
scinvoke) are unaffected and correctly remain at ring 2, where a larger ring would break refundability.
Privacy Mode, automatic token discovery, clearer asset handling, hardened transfer validation, and Linux release binaries that run on current distros out of the box.
- Privacy Mode — seals HOLOGRAM's network connections behind your approval. Switch it on and the app blocks every outbound connection until you approve the destination, so nothing reaches the network without your say-so. Its armed state shows on the wallet anchor.
- Signal Dark — display masking for your address, balances, tokens, and avatar, now an independent control separate from Privacy Mode.
- Wallet: automatic token discovery via Gnomon — held tokens and NFAs are detected and added to the portfolio without manual SCID entry.
- Wallet: native DERO is managed as the base coin (Dashboard / Send), separate from the contract-token portfolio — which now lists contract assets only.
- Wallet: refreshed token portfolio rows with per-token actions (send, refresh metadata, remove) and an improved empty state.
- Wallet: hardened transfer validation so a native-DERO burn is consistently rejected across all send paths.
- Wallet: token transfers are credited via the amount field on the token's SCID, and per-token encrypted balances and metadata resolve correctly (including unindexed SCIDs).
- XSWD: canonical response shapes, correct SC deposit semantics, scid-aware balance reads for the TELA bridge, and a permission-tracking data-race fix.
- Linux: release binaries are built against
webkit2gtk-4.1(libsoup3) instead of the discontinued4.0, so they launch on Ubuntu 24.04+, Debian 13+, Fedora 40+, and Arch without a manual library symlink. CI now fails the release if a Linux binary links the old4.0runtime.
Payment URI workflow, unified storage controls, and XSWD bridge fixes.
- Wallet: smart-paste payment URI field with a 7-state input model
- Settings: Data & Storage section — a unified clear/reset surface
- Tightened the XSWD RPC surface and hardened CI checks
- XSWD: route
DERO.GetHeightthrough the daemon proxy and reclassify it as read-public-data - XSWD bridge: dispatch message events to
addEventListenerhandlers - Wallet:
CreatePaymentRequestuses the local wallet path; failures are surfaced instead of swallowed - Payment URI: dual-path integrated-address decode + address-aware OmniSearch
- Studio: accept
InitializePrivateas a valid SC entrypoint - Dev server: hot reload actually reloads, and real errors are surfaced
Wallet registration and expanded platform support.
- Manual PoW-based wallet registration — new wallets can register on-chain without waiting for incoming DERO
- Registration progress UI with hash count, elapsed time, and cancel option
- Blockchain confirmation polling after registration TX broadcast
- Linux ARM64 (aarch64) binary for Raspberry Pi and ARM servers
- PoW registration uses all available CPU cores (GOMAXPROCS-1) for faster completion
- Release artifacts renamed from
Hologram-*toHOLOGRAM-*for brand consistency
- Duplicate toast notifications when starting wallet registration
Cross-platform binaries and release automation.
- Pre-built binaries for Linux (amd64) and Windows (amd64) — closes the gap from v1.0.0 release notes
- GitHub Actions release workflow (
.github/workflows/release.yml) — tag-triggered cross-platform builds - Universal macOS binary (Intel + Apple Silicon in one file)
- SHA256 checksums for all release artifacts
- Added plain-language disclaimer section to README reinforcing MIT "AS IS" terms for wallet-adjacent software
1.0.0 - 2026-04-18
First public release
hologram-explorer-searchmessage handler — TELA apps can invoke Explorer searches- Privacy Mode enforcement for external link opens (https intercept + user prompt)
dero://deep link protocol registration and launch URL handling
- Network classification now uses daemon-reported field (fixes simulator edge cases)
- Recent search history scoped per-network
- SC deployment TXIDs auto-pivot to contract view in Explorer
- Gnomon corrupted cache recovery on startup
- Batch deploy budget gate and mainnet precheck hardening
- Simulator network switching and wallet state alignment
- EPOCH attribution and uptime overflow guards
- Favorite toggling and offline cache metadata display
- Active wallet filename kept in sync after operations
1.0.0-rc - 2026-04-01
Release candidate — full feature set for testing.
- Full TELA decentralized web browser — resolves INDEX and DOC contracts, reconstructs multi-shard apps, and renders them in an isolated webview
- Per-tab browser history with back/forward navigation and iframe caching
- Auto-start Gnomon on Browser page mount for immediate app discovery
- TELA icon rendering with V2 header support and SCID icon resolution
- TELA-STATIC text file rendering support
- Content filtering for Browser app list
- Download interceptor for dApp blob/local file downloads via JS bridge
- Batch Upload — scan a local folder, auto-infer app name/description/dURL from
package.json,index.html, andREADME.md, preview a preflight summary (file count, sizes, oversized warnings), and deploy as a TELA INDEX + DOC set - DocShard Manager — shard any file >18 KB into
.shardfragments and reconstruct from a shard folder; drag-and-drop file intake for both modes - Install DOC / Install INDEX — deploy individual contracts with DocType selector
- Version Control — file-based diff viewer with TELA version history and semantic labels
- Clone — clone an existing TELA app from chain
- Deploy SC — raw smart contract deployment with DVM validation, gas estimation, and safety guardrails
- Deploy SC Function Interactor — dynamic SC function call UI
- dURL auto-slug populated on folder scan; reactive warning when a shard batch is missing the
.tela.shardsdURL suffix - Preflight summary panel: file count, total size, oversized file detection with shard-manager hints
- Connect via XSWD protocol (Engram and compatible wallets)
- Send DERO and tokens with ringsize selection, fee display, and integrated address validation
- Receive with integrated address generation and payment URI support
- Transaction history with export, TXID caching, and semantic labels
- Hide balance / hide address privacy toggles (per-field eye icon, persisted across restarts)
- Privacy masking propagated to Sidebar (expanded, collapsed, and menu states), WalletModal, Recent Activity, and History
- Change wallet password
- Wallet recovery from backup
- Internal wallet polling with asset support
GetPublicKeyandDecryptPayloadfor Dead Drop encryption
- Gnomon-powered app discovery with fastsync and Time Machine (historical snapshot browser)
- OmniSearch — unified search across apps, smart contracts, transactions, and block numbers, with autocomplete and cross-tab support
- Tagging and content-class metadata on discovered apps
- Simple-Gnomon: historical queries and on-chain data allocation
- Resync UI with fastsync option; DB reset on height mismatch
- Built-in XSWD WebSocket server for dApp ↔ wallet communication
- Handles
DERO.*,Gnomon.*,EPOCH.*, andDeroAuth.*method namespaces - OAuth-style redirect flow for DeroAuth
- Per-app permission scoping with read-only app detection
telaHostAPI injected into XSWD bridge for cross-origin and local dev compatibility- XSWD bridge injection for local dev server HTML responses
- Full local simulator mode — runs an embedded DERO daemon and test wallets for offline development
- Pre-seeded test wallets UI on Wallet page
- Complete DVM deploy + invoke flow in simulator
- Simulator crash detection and notification
ReconnectSimulatorModefor app restart with an existing daemon- Automatic fallback to mainnet when simulator daemon is unreachable
- Settings persistence across restarts (daemon endpoint, network, privacy toggles, and more)
- Remote daemon endpoints persisted across restarts
- First-run wizard with node detection, LAN/external node option, and developer support screen
- LAN node connection support for power users
- SHA256 checksum verification for downloaded binaries
- EPOCH fair developer support address switching
- Battery detection for developer support (Windows via PowerShell/WMI)
- Villager identicon avatar system with 12 background patterns
derodandsimulatorbuilt from derohe source via Makefile (make all)- Build metadata (
version,commit,buildDate) injected at build time via-ldflags
SIGNER()returned empty string — was caused by hardcoded ringsize 16; now uses ringsize from params (default 2)transfers[].scidnot parsed — token transfers were brokenfeesalways hardcoded to 0sc_rpconly handled U/S/H types —I(int64) was silently droppedsc_dero_deposit/sc_token_depositnot parsed- SC deployment via XSWD (
scparam) not routed correctly DERO.*andGnomon.*methods not forwarded to WebSocket dAppsAttemptEPOCHWithAddrnot handledGetMaxHashesEPOCHresponse key mismatch- Null bytes in SCIDs causing key lookup failures — stripped in
sanitizeSCID()anddecodeHexString() - Hex-encoded string values in
GetAllSCIDVariableDetailsresponses not decoded GetDaemonendpoint format corrected to match Engram; simulator endpoint returned correctlyGetHeightnow populatesstableheightandtopoheight- Double approval modal on TELA app reconnect
- Missing XSWD methods, lowercase aliases, and permission mappings
- Test wallet showed 0 DERO balance
- Test wallets not loading on app restart
- Simulator daemon crashed on SC deploy
- Gnomon stale height after simulator restart
- Unreachable simulator now falls back to mainnet correctly
- SC deploy crash via disconnect-before-pause and post-tx settle delay
- WebSocket sequencing conflicts in batch upload
- Fund Wallet network mismatch and balance sync
- Fastsync disabled in simulator mode (was causing incorrect progress display)
- Shard
outputDirreported a phantom relative path (./datashards/shards/) instead of the actual output directory (filepath.Dir(filePath)) - GZIP compression toggle was not actually compressing before sharding
- Double extension when discovering compressed shard files (
.gz.gz) - Shard discovery and ordering in
ConstructFromShards - dURL tag detection aligned with backend (
.tela.shards,.tela.libsuffixes) - Drop-hijack bug: dropping a file into the app caused the webview to navigate to the file, rendering the app non-functional — fixed with
DisableWebViewDrop: truein Wails config and a global JSpreventDefaultguard
- Blob downloads not intercepted for local dev server — added blob cache interceptor
- TELA entry point ordering:
index.htmlnow deployed as DOC1 telaHostnot enabled for local files — fixed- New XSWD methods not matched due to case-sensitive string comparison
- Browser console auto-scroll fighting user scroll-up
- Double OmniSearch dropdown on load
- Normal transactions misclassified as smart contracts in Explorer
- Broadcast transactions to daemon after building (were not being sent)
- Amount rounding, integrated address validation, payment URI parsing
walletPathlost on wallet close, breaking re-open fallback- Reserved insufficient fees when sending max balance
- Ringsize selection missing from Transfer and TokenSend modals
- Non-blocking daemon connect, address prefix restore, file picker fixes
- TELA app reconnect shown double approval modal
- Daemon endpoint display and effective network label on startup
- Settings not persisted across restarts (daemon endpoint)
- Gnomon DB not reset when stored height exceeded daemon chain height
- Network mismatch detection on startup
- Gas estimation formula was ~100x too high
- OmniSearch dropdown opened automatically on load
- Scroll freezing in Wallet History and SyncManager
- Block number color, sidebar indicator navigation, search autocomplete
window.confirmreplaced with modal for destructive actions (Full Resync)- Design System v7.0 compliance pass (emojis removed from log/UI, colors, layout)
- Infinite log loop in production builds
- Console clear button not working
- Go module path is
github.com/DHEBP/HOLOGRAM - Testnet support removed — mainnet and simulator only
- Historical Timeline feature removed (superseded by Time Machine)
- Dead code, phantom mining, bookmark, and text-index bindings pruned
- README updated: Go requirement corrected to 1.24.0+, build instructions clarified
- Copyright year updated to 2026