RequantTESTNET
Requant documentation

Node operations

Running requantd for the long term: as a service, with signed self-updates, fast restarts and monitoring.

As a Linux service

The repository's deploy/install-node.sh installs a hardened systemd service from a static binary:

scp requantd deploy/install-node.sh root@HOST:/tmp/
ssh root@HOST 'bash /tmp/install-node.sh 2 193.187.93.29 193.32.188.248'   # threads, peers

It creates a requant service user, installs the binary in /opt/requant, keeps data in /var/lib/requant, caps memory at 1.5 GiB, lowers the priority, makes the system read-only for the service and opens port 19333 in ufw. Optional variables add services: EXPLORER_PORT=19380, POOL_PORT=19340 POOL_ARGS=…, AUTO_UPDATE=1.

On Windows, the deploy/windows scripts start a node, a miner or both and show the balance.

Signed releases and self-update

  • Every release has a manifest listing, per platform, the download URL and SHA-256 of the binary, signed with the project's release key (ed25519, strict verification). The public key is built into the node.
  • Nodes pass the newest verified manifest to their peers, so news of a release travels through the network itself. getinfo shows update_available.
  • With --auto-update the node waits a random delay of up to 30 minutes, downloads the binary, checks its SHA-256 and the version it reports, replaces itself and exits for its service manager (systemd, or start-node.bat on Windows) to restart it.
  • It never installs an older version. If a new version fails to start several times in a row, the previous binary is put back.
  • Without the flag nothing is downloaded.

Whoever holds the release key could update every node that opted in, so the key is kept offline. Verifying a manifest by hand: the manifest text is requant-release 1, then version X.Y.Z, then lines asset <platform> <sha256> <url>; the signature covers H("requant/release", text).

Fast restarts: the snapshot

  • The node keeps a snapshot, chainstate.bin, of its chain index, UTXO set, undo data, transaction index and block positions, checked by a SHA-256 trailer.
  • At start it loads the snapshot and replays only the blocks written after it. Any mismatch discards the snapshot and the node replays the whole chain.
  • The snapshot is rewritten every 10 minutes or 100 blocks when the tip has moved, through a temporary file and a rename, so a crash never leaves a broken one.

Clean shutdown

On SIGTERM, SIGINT or SIGHUP (Unix), a console close event (Windows) or the stop RPC (from localhost only), the node saves its address book, upload counter, mempool and snapshot, removes the RPC cookie and exits. A second signal on Unix exits at once.

Monitoring

Health. GET /health on the explorer port returns JSON, and HTTP 503 when the node has no peers, has seen no block for 20 minutes or is syncing.

Watchman. The node watches itself and the network and records events, readable through getevents, on the explorer's network page, or pushed with --notify-url (JSON POST) or --notify-telegram:

  • no block for 20 minutes;
  • no peers;
  • a reorganisation of 2 or more blocks;
  • the network rate tripling or falling to a third within an hour;
  • a block of the current epoch that no longer verifies when re-checked;
  • a failed supply audit.

Supply audit. The auditsupply RPC checks that the UTXO set holds no more coins than the emission schedule allows and returns a hash of the UTXO set, so operators can compare their state with each other.

Self-test. At start the node checks its TNet implementation against built-in vectors and refuses to verify blocks if they do not match.

Resource limits

  • --max-upload 50G caps upload per 30 days; once reached, only blocks within 100 of the tip are served.
  • On Linux the node steps back when its machine is busy, so it can share a server with other work.
  • Peers, inbound connections per IP, messages, orphans and the mempool (32 MiB, 72-hour expiry) are bounded.

Running public services

  • Explorer and API: --explorer 0.0.0.0:19380. The API is rate-limited per client.
  • Faucet: --faucet-key FILE; keep only a small balance on the key.
  • Pool: see the pool.
  • Keep the RPC port on localhost; use --rpc-cookie or --rpc-token-file when other users share the machine.