Requant documentation
Transactions and addresses
The byte-level formats a developer needs to build, sign and parse Requant transactions. The normative text is CHAIN.md; the reference code is the consensus crate.
Conventions
- Integers are little-endian.
varintis Bitcoin's CompactSize; only the shortest encoding is valid.bytesisvarint(length) || data. H(tag, x) = SHA256(tag || x)with an ASCII tag starting withrequant/. Every hash in the protocol is domain-separated this way.- Amounts are unsigned 64-bit atoms: 1 RQT = 100,000,000 atoms.
- Decoders reject trailing bytes, non-canonical encodings and values above the limits, so every transaction has exactly one valid encoding.
chain_id = H("requant/chain", network name)separates the networks: a signature for the test network is invalid on any other.
Addresses
An address is the bech32m encoding (BIP 350) of version 0 and a 32-byte key hash:
| Network | Prefix | Example |
|---|---|---|
| Test | trq1 | trq1qvfkg4mygtgkcthzsnjdpgqdujda8vm92cg62vas08aylluhf5gqsezeems |
| Regtest | rqrt1 | |
| Main (planned) | rq1 |
- For a plain key, the key hash is
pkh = H("requant/pkh", ed25519 public key). - For a spending condition it is the hash of the condition (spending conditions); on the chain both look the same.
- Many interfaces (RPC, the miner's
--payee) take the key hash as 64 hex characters;validateaddressconverts between the two forms.
Transaction format
tx = LE32 version (= 1) || LE8 kind || body
coinbase (kind 0): LE64 height || bytes extra (≤ 64) || varint n_out || output*
transfer (kind 1): varint n_in || input* || varint n_out || output*
input = prev_txid[32] || LE32 vout || pubkey[32] || signature[64] (132 bytes)
output = LE64 value || pkh[32] (40 bytes)
Kind 2 is a transfer whose inputs use a spending condition, a time lock or the anyone-can-pay flag. Each of its inputs adds LE64 after_height || LE32 after_blocks || LE8 unlock || unlock data; the top bit of the unlock byte is anyone-can-pay. The templates and their unlocks are on spending conditions.
Identifiers and signatures
txid = H("requant/txid", tx with every signature omitted);wtxid = H("requant/wtxid", tx)covers everything. Outputs are referenced by(txid, vout), so a signature can never change a reference, and chains of pre-signed transactions work.- Input
kis signed with ed25519 oversighash_k = H("requant/sighash", chain_id || txid || LE32 k), or, with the anyone-can-pay flag, overH("requant/sighash-acp", chain_id || LE32 version || that input without signatures || outputs). - Verification is strict RFC 8032 (as ed25519-dalek's
verify_strict):Sreduced, public key andRnot of small order.H("requant/pkh", pubkey)must equal thepkhof the spent output. - Signatures do not cover input values. A signer that cannot see the chain must check the values against the parent transactions, as
requant-wallet signdoes.
Validity
- At least one input and one output; no outpoint spent twice; every output at least 1 atom;
sum(outputs) ≤ sum(inputs). The difference is the fee and goes to the miner. - Coinbase outputs are spendable 100 blocks after their block.
- At most 10,000 inputs or outputs; a block is at most 1 MiB.
Fees and relay policy
These are node policy, not consensus:
- Minimum relay fee rate 1 atom per byte; transactions up to 100,000 bytes.
- The mempool holds 32 MiB; when full, higher-fee-rate transactions evict the lowest together with their descendants.
- Up to 25 unconfirmed ancestors; transactions expire after 72 hours in the pool.
- A kind-1 transfer is at most
11 + 132·inputs + 40·outputsbytes (the wallet's estimate).estimatefeesuggests a rate from the current queue. - Blocks rank packages (child pays for parent), and a conflicting transaction can replace a pooled one by paying more (replace by fee); see chain rules.
Blocks
header (116 bytes) = LE32 version || LE64 height || prev_id[32] || tx_root[32] || LE64 time || target[32]
claim (272 bytes) = LE64 nonce || LE32 i || LE32 c || piece[256]
block = header || claim || varint n_tx || tx*
header_digest = H("requant/header", chain_id || header)
block_id = H("requant/block", header_digest || claim)
tx_root = H("requant/txroot", LE32 n_tx || M(wtxid_0 … wtxid_{n−1})) (RFC 6962 tree)
Building transactions
- Simplest: let
requant-walletbuild and sign; use RPC or the public API to read the chain and send. - Rust: depend on the consensus crate for encoding, txids, sighashes, addresses and validation; its tests show transfers and conditions end to end.
- Other languages: implement the formats above; check your encoder against
decodetxon a regtest node (requantdwithout--network, with--minefor instant blocks).