The core node is written in Go. It uses libp2p for peer-to-peer networking, BadgerDB for persistent storage, blake2b for proof-of-work, and ed25519 for signatures.
Package Map
xe/
├── cmd/
│ └── xe/ Single binary — node daemon, wallet, send/receive, leases, ssh, chat
├── core/ Domain logic — ledger, crypto, encoding, PoW, voting, quorum, supply
├── store/ Pluggable storage — MemStore (testing), BadgerStore (production)
├── net/ libp2p networking — gossip, sync, DHT discovery, netcheck, messaging, tunnel
├── node/ Orchestration — ties all packages together into a running node
├── api/ HTTP REST + SSE API — handler, routes, CORS, rate limits, /health /ready
├── statechain/ Deterministic state machine — DAO governance, KV store, activations, sync
├── vm/ VM abstraction — Lima and QEMU managers, mock, credentials
├── perf/ Performance certificates — PoW-chain + memory benchmark, price multiplier
├── web/ Embedded web UI — HTML + ES modules + CSS, served by xe node --ui
├── client/ HTTP client shared by CLI subcommands
├── directory/ P2P account directory — registration, verification, gossip
├── chat/ P2P messaging — envelope format, PoW, chat store
├── logging/ Levelled, optionally JSON, size-rotated logs
├── metrics/ Prometheus registry for the operator listener
├── genesis/ Published genesis bundles, one directory per network
├── deploy/ systemd unit, pm2 ecosystem, Dockerfile, monitoring stack
└── scripts/ci/ Build and release helpersThis is the source the testnet runs, with the development test suites and internal operational tooling removed; development happens in a private repository and this tree is its published release.
Core Package Files
| File | Purpose |
|---|---|
types.go | Block, Vote, Conflict, Lease (+ renewal segments), PendingSend structs; BlockType and LeaseState constants |
ledger.go | Ledger struct — validates/adds blocks, per-account locking, delegation tracking, lease cost formula, genesis-driven lease timing |
lease_renew.go | lease_renew validation — consumer-only, attested before effective expiry, cumulative duration cap |
address.go | sha256("xe/account/v1" ‖ pubkey) address derivation and payload-key checks |
amount.go | Per-asset decimal precision; micro-unit amount parsing and formatting |
crypto.go | KeyPair, GenerateKeyPair, HashBlock (SHA-256), SignBlock, VerifyBlock (ed25519), network-ID binding |
encoding.go | MarshalBlockCanonical (binary encoding), MarshalBlockAux, MarshalBlock, UnmarshalBlock; vote encoding |
pow.go | blake2b PoW — ComputePoW, ComputePoWConcurrent, ComputePoWWithContext, ValidatePoW |
vote.go | VoteManager — casts and validates votes for conflict resolution |
quorum.go | QuorumManager — tallies votes, finalizes/rejects blocks at 67% weight |
finalization.go | Two-phase finalization voting — the central consensus mechanism |
conflict.go | Conflict detection — equivocation checks |
cascade_commit.go | Conflict-promotion overlay — atomically commits a winning fork's cascade |
rollback.go | Cascading cross-account rollback of rejected forks |
spendable.go | Spendable-balance computation — settlement surfaces honor finalization |
supply.go | Per-asset supply auditor behind GET /supply — both sides of the conservation identity |
genesis.go | Genesis loading and validation — embedded placeholder or --genesis-dir bundle |
activations.go | sys.activations feature registry and block-type gating |
repeligibility.go | sys.representatives allowlist — which delegated weight counts toward quorum |
mint.go | Authorized XUSD mint validation — sys.minter accounts only |
memo.go | On-chain memo size and validation rules |
multisig.go | Multisig address derivation, keyset validation, threshold signatures |
recovery_phrase.go | 24-word recovery phrases for wallet seeds |
reputation.go | Deterministic per-account reputation from on-chain lease activity |
retryable.go | Classifies errors that may resolve on retry (missing dependencies) |
attestation.go | Timekeeper attestation validation for lease blocks |
store.go | Store interface and optional interfaces |
Block Validation Pipeline
AddBlock(b *Block)
│
├── 1. Normalize hex fields (lowercase)
├── 2. VerifyBlock — recompute hash + check ed25519 signature
├── 3. ValidatePoW — blake2b(nonce || hash) >= difficulty
├── 4. Timestamp check — within ±1 hour of local time
├── 5. Duplicate check — block hash not already in store
├── 6. Conflict detection — check if Previous hash is shared
│ ├── No conflict → continue on main chain
│ └── Conflict → stage block, fire callback, return
│
├── 6b. Opening-key check — previous == "0" requires pub_key deriving the account; any later block must omit it
│
├── 7. Type-specific validation (per-account lock held)
│ ├── send → balance sufficient, frontier matches, amount > 0
│ ├── receive → pending send exists, destination matches
│ ├── mint → XUSD only, account in sys.minter, no source/destination/memo, amount > 0
│ ├── burn → XE only, no source/destination, amount > 0, balance sufficient
│ ├── lease → XUSD only, cost formula correct against the provider certificate, balance sufficient
│ ├── lease_accept → lease exists, valid certificate, emission params locked, attestations valid (no stake)
│ ├── lease_renew → consumer only, lease accepted, attested before effective expiry, cost at current certificate
│ ├── lease_settle → lease expired within settle grace, XE emission formula summed over segments
│ ├── lease_cancel → consumer only, source lease exists and is cancellable
│ ├── lease_force_settle → consumer only, after grace + gap, before escrow expiry
│ └── multisig_open/update → keyset valid; open derives the account address, update rotates the keyset
│
├── 8. Update in-memory state (asset balances, delegation weights)
└── 9. Write to store (atomic commit via AtomicBlockStore)Startup Sequence
- Load the genesis pair (
--genesis-dirbundle or the embedded placeholder), set the network ID and apply its lease timing - Open or create key pair (loads
{dataDir}/node.keyor generates new); refuse a data directory that belongs to another network - Open store (BadgerStore at
{dataDir}/ledger) - Create libp2p host (TCP, noise encryption, yamux, per-IP connection caps)
- Setup pubsub (GossipSub)
- Create gossip layers (block, vote, marketplace, directory, state chain, certificates)
- Setup mDNS (unless
--disable-mdns) - Create ledger (wraps store with validation)
- Wire voting (VoteManager + QuorumManager)
- Setup frontier sync
- Setup DHT (Kademlia) and ambient discovery (unless
--no-discovery) - Create messenger
- Initialize state chain
- Wire timekeeper config
- Register gossip handlers and the netcheck admission handshake
- Dial bootstrap peers
- Start the API listener, the operator listener (
/metrics,/health,/ready) and background goroutines