XE extends the block lattice with an on-chain compute marketplace. Consumers lease virtual machines from providers, paying XUSD. Providers earn XE emission rewards upon settlement.
[!NOTE] Live on testnet-0005 — with two caveats Providers are online (
GET /providerslists them) and leases are being accepted, renewed and settled on the live network. Two things stop a newcomer from exercising it: leases are priced in XUSD, which only the operators'sys.minteraccounts issue and which the faucet does not hand out; and provider availability is not guaranteed — check the live list before assuming a counterparty exists. GPU leasing is not implemented at all.
Lifecycle
- Consumer creates
leaseblock — escrows XUSD for the full cost, specifying vCPUs, memory, disk, and duration - Provider creates
lease_acceptblock — locks the emission rate, provisions the VM, gets timekeeper attestations - Consumer optionally creates
lease_renewblocks — each one escrows more XUSD at the provider's current rate and extends the same lease in place; the SDK does this a minute at a time - Provider creates
lease_settleblock — mints XE emission, burns the escrow, tears down the VM
Two blocks cover the paths where that does not happen — the consumer's escrow is recoverable on both:
lease_cancel— the consumer withdraws a lease no provider accepted; the escrow is refunded in fulllease_settlenever arrives — once the provider has abandoned the lease, the consumer submitslease_force_settle: full escrow refund
A lease ends in one of six states: created, accepted, settled, cancelled, unfulfilled (force-settled), or expired (neither party acted; escrow burned after the refund window closes).
Timing windows are a network parameter
The settle and force-settle windows are set in the ledger genesis and reported by every node under GET /node → lease_timing, so read them from the network rather than assuming the binary defaults. Relative to the lease's effective expiry (start + base duration + every renewal):
| Window | Binary default | testnet-0005 | Meaning |
|---|---|---|---|
min_duration_secs | 60 s | 5 s | Smallest legal lease or renewal |
settle_grace_ns | 1 h | 120 s | Provider may lease_settle until expiry + grace |
force_settle_gap_ns | 25 min | 300 s | Dead zone after the grace; consumer may lease_force_settle from expiry + grace + gap |
escrow_expiry_ns | 365 d | 1 h | Refund window closes at expiry + escrow expiry; the escrow is then burnt |
archive_gap_ns | 1 h | 10 min | After expiry + escrow expiry + this gap, the node archives the lease out of its working set |
max_attestation_skew_ns | 10 min | 60 s | Tolerance between timekeeper timestamps on one block |
Cost Model
All amounts are micro-units. Rates are quoted per hour; billing granularity is one minute:
perHourMicro = vCPUs × 20_000 + ceil(memMB / 1024) × 10_000 + diskGB × 1_000
minutes = ceil(duration / 60)
cost = max(1, ceil(ceil(perHourMicro × minutes / 60) × multiplierMilli / 1000))
XE emission = max(1, ceil(cost × R_capped / 1000)) // µXE, rate locked at accept (and per renewal)Every validator re-derives cost from the block's own fields (core.LeaseCost) and hard-rejects a mismatch. Provider PriceMultiplierMilli range: 500 (0.5×) to 10000 (10×), default 1000 (1×) — the binary flags non-default values as a simulation feature pending anti-cheat gates. Duration limits: min_duration_secs (see above) to 31,536,000 s (365 days), cumulative across renewals. Resource caps per lease: 4,096 vCPUs, 64 TiB memory, 1 PiB disk.
There is no provider stake on the current network: LeaseStakeDivisor is 0, LeaseStake() returns 0, and every lease record reports "stake": 0. Force-settle refunds the consumer; there is nothing of the provider's to burn.
Renewal
lease_renew is consumer-signed and references the lease by hash in source. It carries amount (the additional XUSD, priced by the same formula at the provider's current certificate), duration (additional seconds), certificate_hash, the emission parameters locked from the epoch at the attested renewal time, and timekeeper attestations proving the renewal happened while the lease was still live. Renewals grow the single escrow in place; settlement sums emission over the base term plus every renewal segment, each at its own locked R. Lease records expose them under renewals[].
The renewal must be attested before the lease's effective expiry, so a client renewing "a minute at a time" needs to gather attestations ahead of each boundary — this is what the SDK's holdLease does. Operators can also renew from the node's own wallet with POST /lease/{hash}/renew (admin token required).
Attestations
- Signed timestamps from trusted timekeeper nodes
- Timekeeper keys stored in state chain under
sys.timekeepers - SHA-256(leaseHash || timestamp) signed with ed25519
- Max skew between attestations:
max_attestation_skew_ns(60 s ontestnet-0005) - Median of valid timestamps used as canonical time
- Max 20 attestations per block
- Rate limited: one attestation per lease per client (IP over HTTP, peer ID over p2p) every 15 s; a request rejected by validation does not consume the window
VM Management
- Lima (QEMU-based) VMs with KVM acceleration; a QEMU-direct manager also exists for hosts without Lima
- Ubuntu 24.04 cloud images (
ubuntu-24.04-server-cloudimg-amd64.img, downloaded on first use) - Cloud-init for SSH key injection
- VMs named
xe-{leaseHash[:12]} - Manager interface: Provision, Teardown, DialSSH, Get, List
- VM access is SSH-only, through the tunnel — there is no exec API
SSH Gateway & Tunnel
- Protocol:
/xe/tunnel/2.0.0 - SSH gateway authenticates via lease's
AccessPubKey - ProxyJump for end-to-end encryption
- HTTP tunnel endpoint:
POST /tunnel/{leaseHash}/tcp(headerX-Signature: ed25519 signature of the lease hash by the access key) - Max 100 concurrent SSH connections
- Public gateway:
ldn.test.network:2222(XE_SSH_HOST/XE_SSH_PORT)
Economics
- XUSD is escrowed at lease creation (and grown by each renewal), burned at settle, and refunded in full on cancel or force-settle
- XE is inflationary — minted on lease settlement: emission = ceil(cost × R_capped / 1000) µXE per segment, with the rate locked at accept and at each renewal (live
epoch.0:r_effective2000 ⇒ 2× cost) - Provider price multiplier range: 500 (0.5×) to 10000 (10×), default 1000 (1×)
- No stake: an abandoned lease is recoverable via
lease_force_settle, which refunds the consumer's escrow GET /supplyreports both sides of the conservation identity per asset, including escrow burnt and emission minted
Provider Policy
Providers can filter incoming leases before expensive attestation/VM-provision gates run. Five flags:
--min-lease-duration— Go duration string (e.g.5m)--max-lease-duration— Go duration string (e.g.720h)--min-lease-cost— minimum cost in whole XUSD (uint64)--max-lease-cost— maximum cost in whole XUSD (uint64)--max-concurrent-leases— max active leases (uint64)
All default to zero/empty (fully permissive). The gate runs in autoAcceptLease immediately after the idempotency check. Defined in node/policy.go. The live providers advertise max_concurrent_leases: 5.
Performance Certificates
- Benchmark on startup, workload version 4
- Phase 1 (CPU): 1,024 chained proof-of-work puzzles at 19 difficulty bits, each seeded by the last — the solving nonces are the witness served by
GET /certificate/nonces/{hash} - Phase 2 (memory): 256 MB table (8,388,608 × 32-byte entries) + 10,000,000 random reads
- Score = 1.0 / elapsed_seconds
- 7-day validity; expired certificates stay retrievable by hash (
GET /certificate/hash/{hash}) because historical lease blocks pin them - Required for
lease_acceptandlease_renewblocks;GET /node→certificate.validsays whether this node can currently be leased from - Broadcast via
xe/certificatesgossip topic