Networking

libp2p host, peer admission, GossipSub topics, frontier sync, DHT, and request-response messaging.


Fully peer-to-peer using libp2p. No central servers.

Components

ComponentPurposeProtocol
HostTCP transport, connection managementlibp2p core
NetcheckPeer admission — network-ID + version handshake/xe/netcheck/1
GossipSubBroadcast blocks, votes, marketplace, statechain, directorylibp2p GossipSub
SyncFrontier-based block synchronization/xe/sync/1.0.0
Statechain syncState-chain block synchronization/xe/statechain-sync/1.0.0
MessagingRequest-response over streams/xe/msg/1.0.0
TunnelSSH-over-network tunnels to leased VMs/xe/tunnel/2.0.0
DHTKademlia routing + rendezvous discovery/xe prefix; namespace xe/discovery/1/<network_id>

Discovery Mechanisms

  1. Bootstrap peers — explicit via --dial; a watchdog re-dials disconnected bootstraps every 30s (10s timeout per dial). This is the only way a fresh node learns of the network, so configure more than one.
  2. Ambient DHT discovery — once connected, the node advertises itself under xe/discovery/1/<network_id> and, every 60s while below the target peer count (default 24, --discovery-peers), looks up and dials up to 8 peers found there (15s dial timeout, 5 min backoff). --no-discovery disables it, leaving the node peered only with its --dial list.
  3. mDNS — LAN discovery; --disable-mdns turns it off on shared networks.

GossipSub Topics

TopicData Type
xe/blocksBlock
xe/votesVote
xe/marketplaceMarketplaceMsg
xe/statechainStateChainBlock
xe/directoryRegistration
xe/certificatesCertificate

Max gossip message size: 256 KB.

Sync Protocol

  • Frontier-based: exchange account → latest block hash
  • Paginated responses (default 64 blocks/page, max 256)
  • Max 10,000 blocks per sync session
  • 5-second per-peer cooldown
  • Periodic re-sync every 10 seconds (with dirty flag optimization)
  • Cross-account dependency retry passes, with early exit when a pass makes no progress
  • Block quarantine for permanently invalid blocks

Messaging Protocol

  • Request-response semantics
  • 30-second stream deadline
  • 64 KB max request/response
  • Message types: vm_credentials, vm_status, account_chat, attest_timestamp, block_request, vote_request, cert_request
  • block_request, vote_request, and cert_request are targeted sync-repair RPCs — a node missing a block body, an election's votes, or a lease certificate asks a peer for it directly
  • DHT-based peer discovery fallback

Security

  • Peer admission: on connect, peers exchange network ID, protocol version and advertised features over /xe/netcheck/1 (1 KB handshake, 5s timeout); a network-ID mismatch disconnects the peer with a 10-minute ban, a protocol-version mismatch (beyond two minor versions, or below sys.min_protocol_version) with a 1-hour ban. After a testnet wipe, this is why a node started with the old genesis logs CANNOT JOIN NETWORK rather than syncing.
  • Inbound connections are capped per source IP (default 8, --max-conns-per-ip) and in total (default 256, --max-inbound-conns), reserving the rest of the connection budget for peers this node dials
  • Transport encryption (Noise or TLS 1.3)
  • Persistent Ed25519 identity
  • GossipSub pre-validates field lengths
  • Sync rate limiting (5s per peer)
  • Max message sizes enforced

Host Configuration

  • TCP on all interfaces, configurable port
  • Connection manager: low=100, high=400, grace=1min
  • Persistent identity at {dataDir}/host.key
  • Optional relay + hole-punching support