Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
aca826b
docs(reference-impl): restore the snapshot reorg buffer's comments, d…
jdogresorg Sep 17, 2026
b7d7468
docs(encoder): document NODE_OPTIONS, the Node flags the suite-title …
jdogresorg Sep 17, 2026
d33eb05
fix(consensus): re-cut the LTC and DOGE mirror-admission heights onto…
jdogresorg Sep 17, 2026
8055c07
test(docs): add activation predicate boundary vectors
jdogresorg Sep 18, 2026
6ecbb82
fix(env-coverage): lower the regtest-miner computed-read baseline to 4
jdogresorg Sep 18, 2026
88d8e1a
Merge master into develop after the v0.20.0 train
jdogresorg Sep 19, 2026
b7b7c60
merge: level develop with master for the v0.20.1 patch train
jdogresorg Sep 19, 2026
18a05fc
fix(protocol): ship LTC:testnet mirror admission as null under dq4 (a)
jdogresorg Sep 19, 2026
6c5d418
fix(protocol): re-slide v0.20.1 BTC and DOGE activation heights, 24h …
jdogresorg Sep 19, 2026
66e592d
feat(protocol): publish four activation maps in the canon and index them
jdogresorg Sep 19, 2026
11b6e02
docs(indexer): document the list-owner witness env reads and lower th…
jdogresorg Sep 20, 2026
4cc2721
docs(decoder): repoint the migrate CLI citations at src/db/migrate.js
jdogresorg Sep 20, 2026
ed75eb7
docs(indexer): clarify mirror admission startup snapshot
jdogresorg Sep 20, 2026
1024490
Land row L006-33 from cx-l006-33
jdogresorg Sep 20, 2026
2bd72f0
docs: document iOS reproducibility limits
jdogresorg Sep 20, 2026
745a9ea
Land row L024-41 from cx-sharp-l024-41
jdogresorg Sep 20, 2026
0c2f589
docs: harden Android review wallet guidance
jdogresorg Sep 20, 2026
b26b39b
Land row L024-51 from cx-l024-51
jdogresorg Sep 20, 2026
341fc54
test(paths): cover gitignored explorer runtime config
jdogresorg Sep 21, 2026
50ff7cf
docs: correct capability derivation units
jdogresorg Sep 21, 2026
a73c877
Land row L002-65 from cx-l002-65
jdogresorg Sep 21, 2026
ca04f79
Land row L011-58 from cx-l011-58
jdogresorg Sep 21, 2026
fe5132d
docs: document bridge proof origin wiring
jdogresorg Sep 21, 2026
0747e44
Merge: docs: document bridge proof origin wiring
jdogresorg Sep 21, 2026
5d532a0
ci: run develop and fork pull request checks
jdogresorg Sep 22, 2026
fdfee90
docs(errors): register ACTION_NOT_YET_INDEXED, the explorer 404 for a…
jdogresorg Sep 22, 2026
b0ecf01
Merge: ci: run develop and fork pull request checks
jdogresorg Sep 22, 2026
8677e14
docs: warn against contracts on Bitcoin testnet4
jdogresorg Sep 22, 2026
3b0bc65
Merge: docs: warn against contracts on Bitcoin testnet4
jdogresorg Sep 23, 2026
36fadeb
docs: reconcile contradictory claims across the corpus
jdogresorg Sep 23, 2026
71e6c5b
docs: correct drain, lint, error-code, controller-binding and user-gu…
jdogresorg Sep 23, 2026
99bfea0
docs: complete the TIS field table, the envelope flag heights and the…
jdogresorg Sep 23, 2026
b98ee5b
docs(reference-impl): name each consensus file's canonical home and c…
jdogresorg Sep 23, 2026
f520c28
docs(hub): document XCHAIN_HUB_ORACLE_TICK_MIRRORS_WIDENED
jdogresorg Sep 23, 2026
8d9de2c
Document Android App Links test venue
jdogresorg Sep 23, 2026
53dcead
Merge: Document Android App Links test venue
jdogresorg Sep 23, 2026
57dda5f
docs(utxo-tracker): amount field is the coin-denominated string the s…
jdogresorg Sep 23, 2026
3213c8c
Merge: docs(utxo-tracker): amount field is the coin-denominated strin…
jdogresorg Sep 23, 2026
6a27957
fix(protocol): re-slide v0.20.1 BTC and DOGE activation heights, 40h …
jdogresorg Sep 23, 2026
db07738
docs(releases): refresh v0.20.0 testnet heights for the v0.20.1 reslide
jdogresorg Sep 23, 2026
67c34ec
docs(utxo-tracker): fix bulk_sync path from hyphen to underscore
jdogresorg Sep 23, 2026
6a38a7f
chore(release): v0.20.1
jdogresorg Sep 23, 2026
6e7bc06
docs: remove internal release decision references
jdogresorg Sep 23, 2026
9f7d892
docs: re-slide DOGE:testnet mirror admission to the 84h trailing mean
jdogresorg Sep 23, 2026
fcaf078
Merge branch 'cut/v0201-dq4' into cut/v0201-land
jdogresorg Sep 23, 2026
c860775
docs: document HUB_AUTH_RATE_LIMIT_RPM and TOKEN_FOLD_PARITY_CHECK
jdogresorg Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ on:
# so the merge commit a release tag points at has its own green run.
branches: [master, develop]
pull_request:
branches: [master]
branches: [master, develop]

# Protected branches (master, develop) are exempt from cancellation, and that
# needs both lines rather than the second alone. `cancel-in-progress: false`
Expand Down Expand Up @@ -107,7 +107,14 @@ jobs:
# ones that are absent, and the env-var coverage suite applies its fleet
# floor only when every sibling is present, so a partial set is judged on
# what is here rather than accused of a broken scanner.
# Skipped on a fork pull request. This checkout is the one step in the
# job that reaches for cross-repo access rather than reading only the
# repo the workflow itself runs in, so it is the one a fork's more
# limited token could fail on. Skipping it there still runs the rest of
# the suite with siblings absent, per the near-hermeticity note above,
# rather than failing the whole job over this one step.
- name: Check out xchain-indexer (flag-day registry read by the literals suite)
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
uses: actions/checkout@v4
with:
repository: XChain-Platform/xchain-indexer
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.20.1] - 2026-09-23

### Changed
- Published re-slid BTC and DOGE testnet activation maps with LTC inert and corrected protocol behavior across the reference documentation.


## [0.20.0] - 2026-09-17

### Added
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ A blockchain-agnostic token protocol currently running on Bitcoin, Litecoin, and
| [**xchain-utxo-tracker**](https://github.com/XChain-Platform/xchain-utxo-tracker/) | Real-time UTXO indexer powering balance queries and transaction construction |
| [**xchain-vm**](https://github.com/XChain-Platform/xchain-vm/) | Sandboxed JavaScript virtual machine for on-chain smart contracts with gas metering, deterministic execution, and reorg-safe state |
| [**xchain-contracts**](https://github.com/XChain-Platform/xchain-contracts/) | MIT-licensed template library: audited example smart contracts, reusable patterns, a no-code policy generator, and a CLI, deployed via the ordinary `DEPLOY` action |
| [**xchain-sdk**](https://github.com/XChain-Platform/xchain-sdk/) | Developer SDK: builders for all 31 developer-invocable actions, 100+ explorer query methods, smart contract support, live WebSocket events, batch builder, PSBT generation |
| [**xchain-sdk**](https://github.com/XChain-Platform/xchain-sdk/) | Developer SDK: builders for all 32 developer-invocable actions, 100+ explorer query methods, smart contract support, live WebSocket events, batch builder, PSBT generation |
| [**xchain-wallet**](https://github.com/XChain-Platform/xchain-wallet/) | Reference self-custodial multi-chain wallet: browser, Chrome extension, Electron desktop, and Capacitor mobile (Android shipped, iOS later) from a single codebase; software + Trezor + Ledger + remote + multisig signers; full DEX, messaging, contracts, staking, and `window.xchain` dApp bridge |
| [**xchain-regtest-miner**](https://github.com/XChain-Platform/xchain-regtest-miner/) | Auto-mines blocks for regtest development environments |
| [**xchain-e2e-test**](https://github.com/XChain-Platform/xchain-e2e-test/) | Full-stack Mocha test suite running against a live regtest deployment |
Expand All @@ -50,7 +50,7 @@ This project is licensed under the **GNU Affero General Public License v3.0 (AGP
| [**LICENSE**](./LICENSE.md) | Full license text |
| [**NOTICE**](./NOTICE.md) | Required attribution, license summary, and third-party notices |

Any redistribution or modification must include the attribution notice specified in [NOTICE.md](./NOTICE.md). You may run and modify XChain for free under the AGPL-3.0, including inside a for-profit company, provided you share any modifications under the AGPL; a commercial license from Dankest, LLC is required only to keep modifications private or to embed XChain in a closed-source product (see [legal/licensing.md](./legal/licensing.md) for details).
Any redistribution or modification must include the attribution notice specified in [NOTICE.md](./NOTICE.md). You may run and modify XChain for free under the AGPL-3.0, including inside a for-profit company, provided you share any modifications under the AGPL; a commercial license from Dankest, LLC is required only to keep modifications private or to embed XChain in a closed-source product; the MIT-licensed `xchain-contracts` templates need neither (see [legal/licensing.md](./legal/licensing.md) for details).

---

Expand Down
4 changes: 2 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ Email **security@dankest.llc** with:
- A concrete scenario: which implementer behavior the spec permits or encourages, and why that behavior is insecure.
- Any proposed corrected text you'd like considered.

For sensitive reports, encrypt the email body to our PGP key. Its fingerprint is published at <https://xchain.io/security>, which is currently the only place a public reader can read it, and the key itself is served beside it. If you would rather make first contact before sending anything sensitive, the email channel is fine for that and we will coordinate an encrypted exchange before you share details.
For sensitive reports, the GitHub advisory channel above is the confidential path we recommend: it is private until we publish it and needs no key exchange. If you would rather use email, send a first message without the sensitive details and we will coordinate an encrypted exchange before you share them. We do not publish a PGP key for this address. The keys published at <https://xchain.io/security> and in [operations/release-signing.md](./operations/release-signing.md) are release signing keys, there so you can verify that a download is genuine; do not encrypt a report to them.

We do not currently offer a paid bug bounty. We do offer public credit in release notes and the advisory itself, unless you prefer to remain anonymous.

Expand Down Expand Up @@ -86,4 +86,4 @@ We ship security fixes against the latest revision on `master`. The current vers

---

Last reviewed: 2026-06-16.
Last reviewed: 2026-09-22.
6 changes: 3 additions & 3 deletions architecture/component-map.md
Original file line number Diff line number Diff line change
Expand Up @@ -259,7 +259,7 @@ See [`../components/node/`](../components/node/) for full documentation.
| | |
|---|---|
| **Purpose** | Auto-mines mempool transactions for regtest development environments |
| **Inputs** | Coin node JSON-RPC (mempool polling every 1 second) |
| **Inputs** | Coin node JSON-RPC (mempool polling every 100 ms) |
| **Outputs** | Mined blocks via `generatetoaddress` |
| **Storage** | None |
| **Communication** | Outbound JSON-RPC to coin node; inbound JSON-RPC control API |
Expand Down Expand Up @@ -314,7 +314,7 @@ Key technical details:
- Non-deterministic globals (`Date`, `Math.random`, `fetch`, `eval`, etc.) are stripped before any contract code runs; `Math` is replaced by a frozen deterministic subset.
- Gas is metered by AST instrumentation (acorn parse + astring regenerate) rather than wall-clock time, so cost is a deterministic function of code structure.
- A per-block compilation cache (keyed by contract index plus code hash, bounded to 1,000 entries) avoids recompiling the same contract across multiple calls in a block.
- Requires Node.js 22 exactly; `isolated-vm` does not build on Node.js 24.
- Requires Node.js 22 exactly: `xchain-vm` pins the consensus runtime to Node ABI 127, so Node.js 24 fails `checkConsensusRuntime()` even though `isolated-vm` installs there from a prebuilt binding.

See [`../components/vm/`](../components/vm/) for full documentation.

Expand All @@ -334,7 +334,7 @@ See [`../components/vm/`](../components/vm/) for full documentation.

Key technical details:

- Built on xchain-sdk; all action construction goes through the SDK's 31 developer-invocable ACTION methods.
- Built on xchain-sdk; all action construction goes through the SDK's 32 developer-invocable ACTION methods.
- Supports every chain the platform runs on, today Bitcoin, Litecoin, and Dogecoin (mainnet, testnet, regtest), from the same codebase.
- Deployed as a web SPA (served from a static docroot), a Chrome MV3 extension (packaged from the same source), an Electron desktop application, and a Capacitor mobile app wrapping the same web build (Android shipped, iOS later).
- Private keys never leave the client; signing happens locally before broadcast.
Expand Down
2 changes: 1 addition & 1 deletion architecture/data-pipeline.md
Original file line number Diff line number Diff line change
Expand Up @@ -208,7 +208,7 @@ The cost is latency: a transaction confirmed in a block will not appear in the e

In a local development environment, the full pipeline runs identically but with two additions:

- **xchain-regtest-miner** polls the coin node's mempool every 1 second. When it detects pending transactions, it waits up to 30 seconds (resetting to 5 seconds on each new arrival) and then calls `generatetoaddress` to mine a block. This means developers do not have to manually mine blocks.
- **xchain-regtest-miner** polls the coin node's mempool every 100 ms. When it detects pending transactions, it waits up to 30 seconds (resetting to 5 seconds on each new arrival) and then calls `generatetoaddress` to mine a block. This means developers do not have to manually mine blocks.

- **xchain-e2e-test** drives the entire stack using a Mocha test suite. Tests construct actions via BIP39/BIP32 wallets, broadcast them, wait for the pipeline to process them, and assert the resulting explorer state. Tests run in order and share state across the suite; each test builds on the blockchain and indexer state left by the previous one.

Expand Down
6 changes: 3 additions & 3 deletions architecture/platform-map-app.html
Original file line number Diff line number Diff line change
Expand Up @@ -245,7 +245,7 @@ <h2>Flows</h2>
{ "id": "indexer", "label": "xchain-indexer", "type": "service", "group": "index", "tech": "Node.js, MariaDB", "description": "Reads the decoder DB and applies ACTION semantics: double-entry ledger, XCHAIN gas fees, orders/swaps/dispensers, staking capabilities, attestation validation, system-injected expiries. Executes contracts through xchain-vm and follows decoder reorgs." },
{ "id": "indexerdb", "label": "Indexer DB", "type": "database", "group": "index", "tech": "MariaDB", "description": "Canonical protocol state: balances, tokens, orders, contracts, contract_state (append-only), staking, attestation and SPV tables." },
{ "id": "vm", "label": "xchain-vm", "type": "library", "group": "index", "tech": "Node.js, isolated-vm", "description": "Deterministic smart-contract engine: sandboxed V8 isolates, host-side gas metering, 30s CPU / 8MB memory / call depth 4 limits, hardened sandbox (constructor neutering, RegExp removal). Emits actions (XCALL, ATTEST) back to the indexer." },
{ "id": "hub", "label": "xchain-hub", "type": "service", "group": "hub", "tech": "Node.js, MariaDB", "description": "Config oracle and cross-chain coordinator. PBFT federation (stake-weighted source-deduped quorum at/above STAKE_WEIGHTED_QUORUM_ACTIVATION, majority-floored count max(2f+1, ceil((N+1)/2)) below it), five stake-qualified capabilities, price-oracle rounds, attestation engine (http_get / llm providers), reorg-retraction co-signing, governance/slash, and StateAnchorPublisher (ANCHOR v7 bundle on DOGE)." },
{ "id": "hub", "label": "xchain-hub", "type": "service", "group": "hub", "tech": "Node.js, MariaDB", "description": "Config oracle and cross-chain coordinator. PBFT federation (stake-weighted source-deduped quorum at/above STAKE_WEIGHTED_QUORUM_ACTIVATION, majority-floored count max(2f+1, ceil((N+1)/2)) below it), five stake-qualified capabilities, price-oracle rounds, attestation engine (http_get / llm providers), reorg-retraction co-signing, governance/slash, and StateAnchorPublisher (ANCHOR v0 bundle on DOGE)." },
{ "id": "hubdb", "label": "Hub DB", "type": "database", "group": "hub", "tech": "MariaDB", "description": "About 20 tables: configs, validators, consensus state, cross-chain calls, price_snapshots, oracle_prices, attestation stats." },
{ "id": "explorer", "label": "xchain-explorer", "type": "service", "group": "serve", "tech": "Node.js, Express, WS", "description": "Read-only REST + JSON-RPC + WebSocket API and web UI over indexer state (60+ endpoints, /{COIN} prefixed). Runs a hub-mirror sync for consensus tables, ABI introspection, and an optional sandboxed contract-simulation endpoint." },
{ "id": "sync", "label": "xchain-sync", "type": "service", "group": "serve", "tech": "Node.js, WS", "description": "Replicates indexer + decoder DBs to validators: REST snapshots plus a WebSocket block feed, transactional apply with rollback, merkle transparency log (sync_meta, merkle_epochs) and pinned-validator checkpoint quorum verification." },
Expand Down Expand Up @@ -399,10 +399,10 @@ <h2>Flows</h2>
{
"id": "f8",
"name": "State anchoring (ANCHOR on DOGE)",
"description": "Quorum-signed per-chain state checkpoints are anchored on Dogecoin as one ANCHOR v7 bundle per network, for chain-parse recoverability.",
"description": "Quorum-signed per-chain state checkpoints are anchored on Dogecoin as one ANCHOR v0 bundle per network, for chain-parse recoverability.",
"steps": [
{ "n": 1, "node": "hub", "edge": "r13", "action": "StateAnchorPublisher runs one publisher election per bundle by hash ordering and assembles every checkpointed chain's quorum-signed checkpoint as its own bundle section, plus the compressed cross-chain match archive." },
{ "n": 2, "node": "hub", "edge": "r14", "action": "ONE ANCHOR v7 checkpoint bundle per network per publishing cycle is built and submitted through the DOGE encoder from the elected publisher's own DOGE wallet." },
{ "n": 2, "node": "hub", "edge": "r14", "action": "ONE ANCHOR v0 checkpoint bundle per network per publishing cycle is built and submitted through the DOGE encoder from the elected publisher's own DOGE wallet." },
{ "n": 3, "node": "encoder", "edge": "r4", "action": "Anchor transaction is broadcast on Dogecoin." },
{ "n": 4, "node": "decoder", "edge": "r6", "action": "DOGE decoder picks the ANCHOR out of the block." },
{ "n": 5, "node": "indexer", "edge": "r8", "action": "Indexers verify and record the checkpoint; RewardTracker records publisher rewards." }
Expand Down
6 changes: 3 additions & 3 deletions architecture/platform-map.json
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@
"type": "service",
"group": "hub",
"tech": "Node.js, MariaDB",
"description": "Config oracle and cross-chain coordinator. PBFT federation (stake-weighted source-deduped quorum at/above STAKE_WEIGHTED_QUORUM_ACTIVATION, majority-floored count max(2f+1, ceil((N+1)/2)) below it), five stake-qualified capabilities, price-oracle rounds, attestation engine (http_get / llm providers), reorg-retraction co-signing, governance/slash, and StateAnchorPublisher (ANCHOR v7 bundle on DOGE)."
"description": "Config oracle and cross-chain coordinator. PBFT federation (stake-weighted source-deduped quorum at/above STAKE_WEIGHTED_QUORUM_ACTIVATION, majority-floored count max(2f+1, ceil((N+1)/2)) below it), five stake-qualified capabilities, price-oracle rounds, attestation engine (http_get / llm providers), reorg-retraction co-signing, governance/slash, and StateAnchorPublisher (ANCHOR v0 bundle on DOGE)."
},
{
"id": "hubdb",
Expand Down Expand Up @@ -794,7 +794,7 @@
{
"id": "f8",
"name": "State anchoring (ANCHOR on DOGE)",
"description": "Quorum-signed per-chain state checkpoints are anchored on Dogecoin as one ANCHOR v7 bundle per network, for chain-parse recoverability.",
"description": "Quorum-signed per-chain state checkpoints are anchored on Dogecoin as one ANCHOR v0 bundle per network, for chain-parse recoverability.",
"steps": [
{
"n": 1,
Expand All @@ -806,7 +806,7 @@
"n": 2,
"node": "hub",
"edge": "r14",
"action": "ONE ANCHOR v7 checkpoint bundle per network per publishing cycle is built and submitted through the DOGE encoder from the elected publisher's own DOGE wallet."
"action": "ONE ANCHOR v0 checkpoint bundle per network per publishing cycle is built and submitted through the DOGE encoder from the elected publisher's own DOGE wallet."
},
{
"n": 3,
Expand Down
20 changes: 16 additions & 4 deletions bin/complete_run_reporter.js
Original file line number Diff line number Diff line change
@@ -1,9 +1,21 @@
/*********************************************************************
*
* Copyright © 2026 Dankest, LLC
* Based on XChain Platform by Dankest, LLC - https://dankest.llc
*
* SPDX-License-Identifier: AGPL-3.0-or-later
*
* This file is part of XChain Platform. Licensed under the GNU Affero
* General Public License v3.0 or later; see LICENSE.md.
*
**********************************************************************
*
* Refuses a node --test run in which a file's child exited before its event
* stream was whole: the runner trusts exit codes alone, so a lost stream tail
* otherwise grades green with the tests in it never counted. Node 22.10+.
*/
'use strict';

// Refuses a node --test run in which a file's child exited before its event
// stream was whole: the runner trusts exit codes alone, so a lost stream tail
// otherwise grades green with the tests in it never counted. Node 22.10+.

const fs = require('node:fs');
const path = require('node:path');

Expand Down
Loading
Loading