Architecture

Core node package map, block validation pipeline, and startup sequence.


The core node is written in Go. It uses libp2p for peer-to-peer networking, BadgerDB for persistent storage, blake2b for proof-of-work, and ed25519 for signatures.

Package Map

xe/
├── cmd/
│   └── xe/         Single binary — node daemon, wallet, send/receive, leases, ssh, chat
├── core/           Domain logic — ledger, crypto, encoding, PoW, voting, quorum, supply
├── store/          Pluggable storage — MemStore (testing), BadgerStore (production)
├── net/            libp2p networking — gossip, sync, DHT discovery, netcheck, messaging, tunnel
├── node/           Orchestration — ties all packages together into a running node
├── api/            HTTP REST + SSE API — handler, routes, CORS, rate limits, /health /ready
├── statechain/     Deterministic state machine — DAO governance, KV store, activations, sync
├── vm/             VM abstraction — Lima and QEMU managers, mock, credentials
├── perf/           Performance certificates — PoW-chain + memory benchmark, price multiplier
├── web/            Embedded web UI — HTML + ES modules + CSS, served by xe node --ui
├── client/         HTTP client shared by CLI subcommands
├── directory/      P2P account directory — registration, verification, gossip
├── chat/           P2P messaging — envelope format, PoW, chat store
├── logging/        Levelled, optionally JSON, size-rotated logs
├── metrics/        Prometheus registry for the operator listener
├── genesis/        Published genesis bundles, one directory per network
├── deploy/         systemd unit, pm2 ecosystem, Dockerfile, monitoring stack
└── scripts/ci/     Build and release helpers

This is the source the testnet runs, with the development test suites and internal operational tooling removed; development happens in a private repository and this tree is its published release.

Core Package Files

FilePurpose
types.goBlock, Vote, Conflict, Lease (+ renewal segments), PendingSend structs; BlockType and LeaseState constants
ledger.goLedger struct — validates/adds blocks, per-account locking, delegation tracking, lease cost formula, genesis-driven lease timing
lease_renew.golease_renew validation — consumer-only, attested before effective expiry, cumulative duration cap
address.gosha256("xe/account/v1" ‖ pubkey) address derivation and payload-key checks
amount.goPer-asset decimal precision; micro-unit amount parsing and formatting
crypto.goKeyPair, GenerateKeyPair, HashBlock (SHA-256), SignBlock, VerifyBlock (ed25519), network-ID binding
encoding.goMarshalBlockCanonical (binary encoding), MarshalBlockAux, MarshalBlock, UnmarshalBlock; vote encoding
pow.goblake2b PoW — ComputePoW, ComputePoWConcurrent, ComputePoWWithContext, ValidatePoW
vote.goVoteManager — casts and validates votes for conflict resolution
quorum.goQuorumManager — tallies votes, finalizes/rejects blocks at 67% weight
finalization.goTwo-phase finalization voting — the central consensus mechanism
conflict.goConflict detection — equivocation checks
cascade_commit.goConflict-promotion overlay — atomically commits a winning fork's cascade
rollback.goCascading cross-account rollback of rejected forks
spendable.goSpendable-balance computation — settlement surfaces honor finalization
supply.goPer-asset supply auditor behind GET /supply — both sides of the conservation identity
genesis.goGenesis loading and validation — embedded placeholder or --genesis-dir bundle
activations.gosys.activations feature registry and block-type gating
repeligibility.gosys.representatives allowlist — which delegated weight counts toward quorum
mint.goAuthorized XUSD mint validation — sys.minter accounts only
memo.goOn-chain memo size and validation rules
multisig.goMultisig address derivation, keyset validation, threshold signatures
recovery_phrase.go24-word recovery phrases for wallet seeds
reputation.goDeterministic per-account reputation from on-chain lease activity
retryable.goClassifies errors that may resolve on retry (missing dependencies)
attestation.goTimekeeper attestation validation for lease blocks
store.goStore interface and optional interfaces

Block Validation Pipeline

AddBlock(b *Block)
  │
  ├── 1. Normalize hex fields (lowercase)
  ├── 2. VerifyBlock — recompute hash + check ed25519 signature
  ├── 3. ValidatePoW — blake2b(nonce || hash) >= difficulty
  ├── 4. Timestamp check — within ±1 hour of local time
  ├── 5. Duplicate check — block hash not already in store
  ├── 6. Conflict detection — check if Previous hash is shared
  │     ├── No conflict → continue on main chain
  │     └── Conflict → stage block, fire callback, return
  │
  ├── 6b. Opening-key check — previous == "0" requires pub_key deriving the account; any later block must omit it
  │
  ├── 7. Type-specific validation (per-account lock held)
  │     ├── send     → balance sufficient, frontier matches, amount > 0
  │     ├── receive  → pending send exists, destination matches
  │     ├── mint     → XUSD only, account in sys.minter, no source/destination/memo, amount > 0
  │     ├── burn     → XE only, no source/destination, amount > 0, balance sufficient
  │     ├── lease    → XUSD only, cost formula correct against the provider certificate, balance sufficient
  │     ├── lease_accept → lease exists, valid certificate, emission params locked, attestations valid (no stake)
  │     ├── lease_renew  → consumer only, lease accepted, attested before effective expiry, cost at current certificate
  │     ├── lease_settle → lease expired within settle grace, XE emission formula summed over segments
  │     ├── lease_cancel → consumer only, source lease exists and is cancellable
  │     ├── lease_force_settle → consumer only, after grace + gap, before escrow expiry
  │     └── multisig_open/update → keyset valid; open derives the account address, update rotates the keyset
  │
  ├── 8. Update in-memory state (asset balances, delegation weights)
  └── 9. Write to store (atomic commit via AtomicBlockStore)

Startup Sequence

  1. Load the genesis pair (--genesis-dir bundle or the embedded placeholder), set the network ID and apply its lease timing
  2. Open or create key pair (loads {dataDir}/node.key or generates new); refuse a data directory that belongs to another network
  3. Open store (BadgerStore at {dataDir}/ledger)
  4. Create libp2p host (TCP, noise encryption, yamux, per-IP connection caps)
  5. Setup pubsub (GossipSub)
  6. Create gossip layers (block, vote, marketplace, directory, state chain, certificates)
  7. Setup mDNS (unless --disable-mdns)
  8. Create ledger (wraps store with validation)
  9. Wire voting (VoteManager + QuorumManager)
  10. Setup frontier sync
  11. Setup DHT (Kademlia) and ambient discovery (unless --no-discovery)
  12. Create messenger
  13. Initialize state chain
  14. Wire timekeeper config
  15. Register gossip handlers and the netcheck admission handshake
  16. Dial bootstrap peers
  17. Start the API listener, the operator listener (/metrics, /health, /ready) and background goroutines