RequantTESTNET
Requant documentation

Transactions and addresses

The byte-level formats a developer needs to build, sign and parse Requant transactions. The normative text is CHAIN.md; the reference code is the consensus crate.

Conventions

  • Integers are little-endian. varint is Bitcoin's CompactSize; only the shortest encoding is valid. bytes is varint(length) || data.
  • H(tag, x) = SHA256(tag || x) with an ASCII tag starting with requant/. Every hash in the protocol is domain-separated this way.
  • Amounts are unsigned 64-bit atoms: 1 RQT = 100,000,000 atoms.
  • Decoders reject trailing bytes, non-canonical encodings and values above the limits, so every transaction has exactly one valid encoding.
  • chain_id = H("requant/chain", network name) separates the networks: a signature for the test network is invalid on any other.

Addresses

An address is the bech32m encoding (BIP 350) of version 0 and a 32-byte key hash:

NetworkPrefixExample
Testtrq1trq1qvfkg4mygtgkcthzsnjdpgqdujda8vm92cg62vas08aylluhf5gqsezeems
Regtestrqrt1
Main (planned)rq1
  • For a plain key, the key hash is pkh = H("requant/pkh", ed25519 public key).
  • For a spending condition it is the hash of the condition (spending conditions); on the chain both look the same.
  • Many interfaces (RPC, the miner's --payee) take the key hash as 64 hex characters; validateaddress converts between the two forms.

Transaction format

tx       = LE32 version (= 1) || LE8 kind || body
coinbase (kind 0): LE64 height || bytes extra (≤ 64) || varint n_out || output*
transfer (kind 1): varint n_in || input* || varint n_out || output*
input    = prev_txid[32] || LE32 vout || pubkey[32] || signature[64]       (132 bytes)
output   = LE64 value || pkh[32]                                          (40 bytes)

Kind 2 is a transfer whose inputs use a spending condition, a time lock or the anyone-can-pay flag. Each of its inputs adds LE64 after_height || LE32 after_blocks || LE8 unlock || unlock data; the top bit of the unlock byte is anyone-can-pay. The templates and their unlocks are on spending conditions.

Identifiers and signatures

  • txid = H("requant/txid", tx with every signature omitted); wtxid = H("requant/wtxid", tx) covers everything. Outputs are referenced by (txid, vout), so a signature can never change a reference, and chains of pre-signed transactions work.
  • Input k is signed with ed25519 over sighash_k = H("requant/sighash", chain_id || txid || LE32 k), or, with the anyone-can-pay flag, over H("requant/sighash-acp", chain_id || LE32 version || that input without signatures || outputs).
  • Verification is strict RFC 8032 (as ed25519-dalek's verify_strict): S reduced, public key and R not of small order. H("requant/pkh", pubkey) must equal the pkh of the spent output.
  • Signatures do not cover input values. A signer that cannot see the chain must check the values against the parent transactions, as requant-wallet sign does.

Validity

  • At least one input and one output; no outpoint spent twice; every output at least 1 atom; sum(outputs) ≤ sum(inputs). The difference is the fee and goes to the miner.
  • Coinbase outputs are spendable 100 blocks after their block.
  • At most 10,000 inputs or outputs; a block is at most 1 MiB.

Fees and relay policy

These are node policy, not consensus:

  • Minimum relay fee rate 1 atom per byte; transactions up to 100,000 bytes.
  • The mempool holds 32 MiB; when full, higher-fee-rate transactions evict the lowest together with their descendants.
  • Up to 25 unconfirmed ancestors; transactions expire after 72 hours in the pool.
  • A kind-1 transfer is at most 11 + 132·inputs + 40·outputs bytes (the wallet's estimate). estimatefee suggests a rate from the current queue.
  • Blocks rank packages (child pays for parent), and a conflicting transaction can replace a pooled one by paying more (replace by fee); see chain rules.

Blocks

header (116 bytes) = LE32 version || LE64 height || prev_id[32] || tx_root[32] || LE64 time || target[32]
claim  (272 bytes) = LE64 nonce || LE32 i || LE32 c || piece[256]
block              = header || claim || varint n_tx || tx*
header_digest      = H("requant/header", chain_id || header)
block_id           = H("requant/block", header_digest || claim)
tx_root            = H("requant/txroot", LE32 n_tx || M(wtxid_0 … wtxid_{n−1}))      (RFC 6962 tree)

Building transactions

  • Simplest: let requant-wallet build and sign; use RPC or the public API to read the chain and send.
  • Rust: depend on the consensus crate for encoding, txids, sighashes, addresses and validation; its tests show transfers and conditions end to end.
  • Other languages: implement the formats above; check your encoder against decodetx on a regtest node (requantd without --network, with --mine for instant blocks).