# Canister controller and cycle balance need to be public

**URL:** <https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591>\
**Category:** Developers\
**Created:** [June 30, 2021, 1:17am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591 "2021-06-30T01:17:18Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [June 30, 2021, 1:17am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/1 "2021-06-30T01:17:18Z")

</div>

I can’t think of any good reason why these 2 pieces of data are private. Canister controller is already public off-chain, so it should be public on-chain (through ic-management).

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [June 30, 2021, 12:31pm UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/2 "2021-06-30T12:31:34Z")

</div>

Followup:  
According to the [NNS AMA](https://www.reddit.com/r/dfinity/comments/o4zdy6/we_are_david_johan_nicolas_and_ryan_ask_us/h2okm5o?utm_source=share&utm_medium=web2x&context=3), the system doesn’t assume that Neuron info should be public.

I suppose we could debate this for a while, but how about this - I propose that these fields be public:

- `cached_neuron_stake_e8s` - we can already calculate to an accuracy of +/- 1 e8s from `voting_power`
- `maturity_e8s_equivalent` - no good way to calculate, nothing confidential here. also there are accounting usecases that would be simplified with this being available
- `followees` - maybe slightly more confidential, but needs to be public for transparency
- `neuron_fees_e8s` - nothing confidential

---

<div class="post-metadata">

**Author:** ![levi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/levi/32/22608_2.png) [@levi](https://forum.dfinity.org/u/levi)\
**Post date:** [July 1, 2021, 7:16pm UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/3 "2021-07-01T19:16:49Z")

</div>

What are your thoughts on why the cycle balance should be public?

---

<div class="post-metadata">

**Author:** ![Hazel](https://avatars.discourse-cdn.com/v4/letter/h/e56c9b/32.png) [@Hazel](https://forum.dfinity.org/u/Hazel)\
**Post date:** [July 1, 2021, 8:41pm UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/4 "2021-07-01T20:41:04Z")

</div>

Agree. I’d like to add the module hash should be public too.

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 2, 2021, 1:34am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/5 "2021-07-02T01:34:49Z")

</div>

If we’re interacting with a service, we should know how much runway it has left. If it’s a NFT canister that only has 1T left, I wouldn’t be comfortable storing long term assets in it.

Also, why should it be private?

---

<div class="post-metadata">

**Author:** ![stephenandrews](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/stephenandrews/32/1803_2.png) [@stephenandrews](https://forum.dfinity.org/u/stephenandrews)\
**Post date:** [July 2, 2021, 2:09am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/6 "2021-07-02T02:09:06Z")

</div>

If privacy is the concern, than at least give developers the ability to make cycle balance/controller available publicly.

I agree re: neurons too - cached stake not being available to non-controllers doesn’t seem smart as we can calculate manually as per @wang’s msg OR we can just lookup the neuron account and see the balance in the ledger.

Followees may be a privacy thing I guess, but at least allow users to specify if they can make this publicly available too.

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 2, 2021, 2:20am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/7 "2021-07-02T02:20:09Z")

</div>

I would prefer default public, optional private. Then, it’s up to developers to explain to their users why things are private.

---

<div class="post-metadata">

**Author:** ![stephenandrews](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/stephenandrews/32/1803_2.png) [@stephenandrews](https://forum.dfinity.org/u/stephenandrews)\
**Post date:** [July 2, 2021, 2:34am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/8 "2021-07-02T02:34:32Z")

</div>

Yup agree with that too

---

<div class="post-metadata">

**Author:** ![levi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/levi/32/22608_2.png) [@levi](https://forum.dfinity.org/u/levi)\
**Post date:** [July 4, 2021, 4:22am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/9 "2021-07-04T04:22:03Z")

</div>

If you want to feel comfortable storing an nft, the cycles balance isn’t enough you’d have to have the source code to make sure the cycles couldn’t be transferred out to someone and also you’d need to make sure that the contract can only be changed by a sufficient decentralized vote , or you’d have a set up where you spin up and fund your own nft canister once the standards come . So for those cases where the source is known to you there can be a public canister function that gives the current cycles balance and you can certify that it is , but the ic is not just a platform for open tokenized dapps, it’s the global-computer that’s meant to host the every kind of the software, not every business wants the world to know how much money they are making. wallets, cycles will be a stable coin, I want to keep my money-count with my self. the blockchain itself certifies the global cycles count if you are thinking bout that.

I do think there should be a way for a canister-controller to let non-controllers certify the canister-source with the hash and certify the controller but i think there might already be a way to do that with the legations.

Edit: controller and module\_hash are public, see below.

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 4, 2021, 5:07am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/10 "2021-07-04T05:07:05Z")

</div>

Agreed that cycle balance is just one of the many requirements for asset storage.

Using native cycles as a medium of exchange/unit of account is cumbersome, so I imagine wrapped cycles will fill that role. Whether these wrapped tokens have privacy features or not is a separate concern.

---

<div class="post-metadata">

**Author:** ![levi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/levi/32/22608_2.png) [@levi](https://forum.dfinity.org/u/levi)\
**Post date:** [July 6, 2021, 12:20am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/11 "2021-07-06T00:20:21Z")

</div>

the ic is meant for personal code systems as well. using native cycles as a medium of the change is the most straight-forward way to do it. there will be standards that catch on that let people send and get cycles from personal canisters with custom flows of some sort.

I am testing my self and I see the controllers and the module\_hash are public.

- Ledger canister:
  - module\_hash: 8e478353381b52ad3926601fc730982aa8886b78a089ddd6d184c9b5641d2d7a
  - controllers: [[0, 0, 0, 0, 0, 0, 0, 3, 1, 1]] // r7inp-6aaaa-aaaaa-aaabq-cai

- dscvr: h5aet-waaaa-aaaab-qaamq-cai:
  - module\_hash: 2664385b7ad001123d8cea1f7147fad005d012116139787d9054b2f3a62718ec
  - controllers: [[0, 0, 0, 0, 0, 48, 0, 20, 1, 1]] // g6mnv-cyaaa-aaaab-qaaka-cai

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 6, 2021, 2:09am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/12 "2021-07-06T02:09:38Z")

</div>

Summary of what data is available and how. Everything public off-chain should be public **on-chain** as well!

| Data | Public, off-chain | Public, on-chain | Controller, on-chain |
| --- | --- | --- | --- |
| Subnet | ✅ | 🚫 | 🚫 |
| Controller | ✅ | 🚫 | ✅ |
| Status | ✅ | 🚫 | ✅ |
| Module Hash | ✅ | 🚫 | ✅ |
| Cycle Balance | 🚫 | 🚫 | ✅ |
| CPU/Mem | 🚫 | 🚫 | ✅ |

---

<div class="post-metadata">

**Author:** ![levi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/levi/32/22608_2.png) [@levi](https://forum.dfinity.org/u/levi)\
**Post date:** [July 6, 2021, 3:34am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/13 "2021-07-06T03:34:13Z")

</div>

What do you mean that the controller and module hash are only public off-chain? The path: canister/canisterId/controlller in the system state tree which we can call and certify the sponse , gives the controller of a canister. ?

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 6, 2021, 4:19am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/14 "2021-07-06T04:19:41Z")

</div>

Is the state tree available within a canister? How do I access it with Motoko or Rust?

---

<div class="post-metadata">

**Author:** ![PaulLiu](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/paulliu/32/4701_2.png) [@PaulLiu](https://forum.dfinity.org/u/PaulLiu)\
**Post date:** [July 7, 2021, 2:45am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/15 "2021-07-07T02:45:38Z")

</div>

I think there can an easy opt-in solution to make canister status public, without modifying the current IC behavior:

1. Create a “blackhole” canister, with an exported interface `canister_status`.
2. The method just calls ic0.canister\_status to lookup status of a given canister id.
3. If anyone wants to make their canister status public, just add “blackhole” to the controller list.
4. But that wouldn’t be safe if “blackhole” can be changed. To make it safe, “blackhole” should have its controller field removed (or set to itself).

What do you think? @wang

---

<div class="post-metadata">

**Author:** ![PaulLiu](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/paulliu/32/4701_2.png) [@PaulLiu](https://forum.dfinity.org/u/PaulLiu)\
**Post date:** [July 7, 2021, 7:25am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/16 "2021-07-07T07:25:13Z")

</div>

@wang Check this out [GitHub - ninegua/ic-blackhole: Once a canister sets its only controller to a black hole, it becomes immutable and more!](https://github.com/ninegua/ic-blackhole)

With the blackhole canister, you can check the status of any canister that has set one of their controllers to the blackhole canister. For example to see the status of the blackhole canister itself:

```auto
dfx canister --network=ic --no-wallet call blackhole canister_status '(record { canister_id = principal "e3mmv-5qaaa-aaaah-aadma-cai"; })'
(
  record {
    status = variant { running };
    memory_size = 304_221;
    cycles = 2_126_143_362_964;
    settings = record {
      freezing_threshold = 2_592_000;
      controllers = vec { principal "e3mmv-5qaaa-aaaah-aadma-cai" };
      memory_allocation = 0;
      compute_allocation = 0;
    };
    module_hash = opt blob "!\0c\f9A\e5\caw\da\ac1J\91Qt\83\ac\17\12dR~=\0dq;\92\bb\95#\9d}\e0";
  },
)

```

---

<div class="post-metadata">

**Author:** ![wang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wang/32/446_2.png) [@wang](https://forum.dfinity.org/u/wang)\
**Post date:** [July 7, 2021, 7:57am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/17 "2021-07-07T07:57:32Z")

</div>

Thanks Paul. There is a need for a dead/unowned principal but having to remember `e3mmv-5qaaa-aaaah-aadma-cai` isn’t very ideal, I think `aaaaa-aa` would be better for that usecase.

I’m still in favor of public by default because I don’t think most devs will bother to opt-in, especially if the process for adding multiple controllers is complex.

Perhaps building this into dfx would be better? Add a flag to `dfx.json` like `public_status: true` which automatically adds the blackhole controller.

---

<div class="post-metadata">

**Author:** ![levi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/levi/32/22608_2.png) [@levi](https://forum.dfinity.org/u/levi)\
**Post date:** [July 7, 2021, 9:17pm UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/18 "2021-07-07T21:17:09Z")

</div>

hmmm, i see, i think controller and module\_hash should be able to be seen within another canister if it is public from the outside.

---

<div class="post-metadata">

**Author:** ![rossberg](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/rossberg/32/795_2.png) [@rossberg](https://forum.dfinity.org/u/rossberg)\
**Post date:** [December 2, 2021, 9:25am UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/19 "2021-12-02T09:25:38Z")

</div>

> [@wang](#):
>
> Everything public off-chain should be public **on-chain** as well!

I have to disagree with that premise. Making something accessible programmatically has a totally different quality, allows much easier abuse, and cannot be fixed later without breaking existing apps.

> [@wang](#):
>
> I would prefer default public, optional private.

That would be terrible, and would negate all lessons learnt from the unfixable privacy violation pandemic on the Web.

I already remarked this elsewhere: if we are at all serious about building Web 3.0, then we must avoid repeating the old Web’s mistakes, and make principles of least authority, data austerity, and explicit consent the guiding principles.

---

<div class="post-metadata">

**Author:** ![diegop](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/diegop/32/569_2.png) [@diegop](https://forum.dfinity.org/u/diegop)\
**Post date:** [December 2, 2021, 4:55pm UTC](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591/20 "2021-12-02T16:55:04Z")

</div>

> [@rossberg](#):
>
> I already remarked this elsewhere: if we are at all serious about building Web 3.0, then we must avoid repeating the old Web’s mistakes, and make principles of least authority, data austerity, and explicit consent the guiding principles.

I agree with @rossberg

[Next page](https://forum.dfinity.org/t/canister-controller-and-cycle-balance-need-to-be-public/5591.md?page=2)
