Deterministic, universe-lane Layer-1 engineering focused on low-hardware scaling, policy-governed authority, fail-closed validation, and evidence-driven operations.
Status Notice (Pre-Release)
This repository is under active development. Runtime behavior, command surfaces, and governance policy may change between commits. Treat all workflows as pre-release unless an explicit release artifact and evidence bundle declares otherwise.
AOXChain is an experimental Layer-1 blockchain program built around a strict principle: protocol truth is enforced by deterministic kernel behavior and governance-managed cryptographic policy, not by operator discretion.
- Deterministic state transitions across nodes.
- Fail-closed validation before execution.
- Explicit authority separation across account, validator, governance, and recovery domains.
- Cryptographic agility through profile-driven migration controls.
- Reproducible evidence for audits, release readiness, and operational traceability.
Primary top-level surfaces:
crates/β Rust workspace crates (protocol, consensus, execution, networking, CLI, tooling).configs/β Runtime profiles, policy inputs, and environment configuration.docs/β Architecture, operations, and implementation references.scripts/β Automation and evidence-generation helpers.tests/β Integration and cross-component validation suites.artifacts/β Generated outputs for verification and audit trails.models/β Machine-readable readiness and governance metadata.contracts/β Contract-facing references and integration surfaces.
For engineering and review decisions, read these in order:
READ.mdβ Normative technical contract and invariants.SCOPE.mdβ Scope boundaries, exclusions, and sensitive change classes.ARCHITECTURE.mdβ Component topology, trust boundaries, and dependency direction.TESTING.mdβ Validation obligations and readiness expectations.SECURITY.mdβ Security posture and disclosure handling.VERSIONING.mdβ Compatibility and release governance.CONTRIBUTING.mdβ Contribution and review protocol.docs/ENERGY_AND_CULTURAL_NETWORK_DESIGN.mdβ Proposed bounded treasury emission, energy-evidence, and cultural archive model.
README.md is the operational entrypoint; READ.md is the normative contract.
AOXChain follows a policy-first admission pipeline:
- Ingress is treated as untrusted input.
- Validation runs before execution (actor identity, scheme profile, policy root, proof bundle, replay protection).
- Consensus-owned truth is enforced by kernel rules.
- Deterministic execution proceeds only after admission succeeds.
- State updates and audit evidence are persisted.
Normative authority chain:
actor -> scheme_id -> policy_root -> proof_bundle -> replay_check -> execute
Operational implication: correctness depends on validation and policy gates, not ad-hoc operator override.
aoxc(crates/aoxcmd) β Primary operator CLI.aoxchub(crates/aoxchub) β Hub/service entrypoint.aoxckit(crates/aoxckit) β Companion operational toolkit.crates/kernel/β Core consensus and canonical protocol logic.
Minimum local environment:
- Rust toolchain compatible with
Cargo.toml/Cargo.lock. - POSIX shell.
- GNU
make.
Optional:
- Docker or Podman for containerized runtime workflows.
make help
make build
make test
make qualityUse make help first to inspect host-specific targets before selecting a workflow.
make build
make build-release
make build-release-allmake fmt
make check
make test
make clippy
make audit
make qualitymake production-full
make phase1-full
make quantum-readiness-gate
make aoxcvm-production-closure-gate
make quantum-full
make testnet-gate
make testnet-readiness-gatemake runtime-source-check
make runtime-install
make runtime-verify
make runtime-activate
make runtime-status
make runtime-doctorRecommended sequence:
runtime-source-checkruntime-installruntime-verifyruntime-activateruntime-statusruntime-doctor
make chain-help
make chain-init AOXC_BOOTSTRAP_PROFILE=validation AOXC_VALIDATOR_NAME=validator-01 AOXC_VALIDATOR_PASSWORD='StrongPass#2026'
make chain-add-account AOXC_NEW_ACCOUNT_ID=AOXC_USER_0001 AOXC_NEW_ACCOUNT_BALANCE=1000000 AOXC_NEW_ACCOUNT_ROLE=user
make chain-add-validator AOXC_VALIDATOR_ID=aoxc-val-custom-001 AOXC_CONSENSUS_PUBLIC_KEY=<hex> AOXC_NETWORK_PUBLIC_KEY=<hex> AOXC_VALIDATOR_BALANCE=50000000
make chain-start-persistentmake demo
make localnet
make devnet
make testnet
make doctor
make audit-chain
make resetPersistent multi-node testnet supervisor (/mnt/xdbx/aoxc default):
make aoxc-q-up AOXC_Q_MODE=local AOXC_Q_ENV=testnet AOXC_Q_PROFILE=testnet AOXC_Q_NODES=7 AOXC_Q_FORCE=1
make aoxc-q-status AOXC_Q_MODE=local AOXC_Q_ENV=testnet AOXC_Q_NODES=7Operational note: aoxc-q provisions identity-side genesis.json, validators.json, bootnodes.json, and certificate.json per node so genesis-validate --strict and genesis-production-gate can be evaluated directly with --home <node-home>.
make package-bin
make package-all-bin
make package-versioned-bin
make package-versioned-archive
make publish-releaseSigned release support:
make repo-release-keygen
make repo-release-signed
make repo-release-signed-verify
make repo-release-prepare
make repo-release-validateA minimal readiness evaluation should include:
make build
make test
make quality
make audit
make testnet-gate
make testnet-readiness-gateIf required gates fail, or are skipped without an approved exception, treat the system as NOT_READY.
The repository is versioned as 0.2.0-alpha.4. Production readiness requires only evidence-backed closure of the remaining operational gates below:
- Replace all production-facing placeholder keys, certificates, bootnodes, and validator records with governed real values.
- Run and retain full release evidence for formatting, clippy, workspace tests, audit, quantum readiness, testnet readiness, and production closure gates.
- Publish a signed release package with SBOM, provenance, checksums, and certificate artifacts.
- Complete operator runbooks for key rotation, validator recovery, quantum-profile cutover, rollback, and incident response.
- Reconcile mainnet environment hashes after final genesis, validator, and topology files are sealed.
No item above is a decorative roadmap entry; each item blocks a production-ready mainnet declaration until evidence is retained.
The next meaningful beta path is the universe-lane model: independent low-hardware execution lanes validate local activity and submit bounded anchor commitments to AOXC instead of pushing every local transaction onto one global chain. A beta label should wait until lane registry persistence, anchor commitment admission, dispute evidence, multi-lane localnet supervision, and lane-load metrics are implemented and evidenced.
The first operator-facing preview is:
aoxc universe status --profile low-hardware --format jsonThis command reports the current universe-lane foundation, low-hardware policy envelope, mandatory roots, and beta blockers without claiming production finality.
AOXChain is distributed under the MIT License and provided on an "AS IS" basis, without warranty.
For security classes, disclosure process, and operational posture, see SECURITY.md.