Open Network X10 posts

Open Network X

on-x.live

An independent implementation of an open network architecture.

Built from the specification. Tested for determinism. Designed to stand on its own.

Open Network Xon-x.liveREADME.md

The goal is not to reproduce an existing implementation.

Most networks that share an architecture begin as a fork: take working source code, change it, deploy it. ONX begins one step earlier, with the published design. Each requirement is restated as an ONX specification, every ambiguity or gap gets a recorded decision, and only then is code written, followed by tests that try to prove it wrong.

Existing implementationfork

  1. Source codeBehaviour starts from what the code already does.
  2. ModificationChanges are made against that behaviour.
  3. Deployment

ONXindependent

  1. Reference specificationThe original white paper, kept unmodified.WHITEPAPER.md
  2. Protocol requirement15 ONX specifications, separating what the paper requires from what ONX interprets.docs/specification/
  3. Engineering decisionGaps and ambiguities are written down: 20 accepted decision records.docs/decisions/
  4. ImplementationA Rust workspace; protocol, node and tooling crates kept apart.crates/
  5. TestGolden vectors, cross-process checks, crash and corruption probes in CI.ci.yml

Existing implementations may be studied for research and interoperability. ONX does not treat any of them as its specification.

README.md
Open Network Xon-x.live

CI green-up: crash-atomic database init, rustls audit fix.

The red CI run was hiding a real bug. On slow runners, a kill -9 could land while the chain database was first being created, leaving a half-written file that refused to reopen. ChainStore::open now builds the database at a temporary path and renames it into place; a damaged database still fails closed instead of being silently reinitialized.

Also bumps rustls to 0.23.45 for RUSTSEC-2026-0285.

github.com
Merge pull request #3 from gokooteam/ci-greenup
gokooteam/The-Open-Network-X
Pull request #3
Open Network Xon-x.live

Transactions are now signed (ONX_TX_V2).

Every transfer carries an Ed25519 signature and the sender's next nonce, so a signed transfer can be applied exactly once. Accounts with no key can receive but never spend.

Same change: storage refuses blocks that don't chain off the stored head, and every resume checks the rebuilt state root against the stored one. Golden vectors were refrozen on the new format.

github.com
Merge pull request #2 from gokooteam/tx-auth-and-hardening
gokooteam/The-Open-Network-X
Pull request #2
Open Network Xon-x.live

Deterministic replay milestone: phases 0–5 complete.

Same input. Same state. Same result.

onx replay loads a genesis document and applies each block through a pure state-transition function (no clocks, no randomness, no I/O), then persists the result in one atomic write. Run it twice, or kill it halfway and resume, and it has to land on the same state root.

  • Canonical encodings, byte-identical across processes
  • A real binary genesis whose hash is the chain ID
  • A pure state transition with fees
  • Atomic storage on redb with crash recovery
  • The onx replay command and its acceptance suite

The hashes below are real output from the repository's frozen test chain.

Genesis

chain_id
58758ecb51f0f2e7fc1353896392e43e2554aa9bef02a335fc350cd804484683
genesis_root
079404cb2379be4802d27f77101e92c232cb94af2f93b3c8274995e85b99c04d
input
4 accounts, 5 blocks × 4 signed transfers (seed 0xC10C)
Process Afirst run, fresh data directory
#14b7def00
#2d6b5e7a8
#33fbb03b2
#449c137e2
#58b2f6aa6
Process Bsecond run, separate process
#14b7def00
#2d6b5e7a8
#33fbb03b2
#449c137e2
#58b2f6aa6
Process Ckill -9 during a commit, then resume
#14b7def00
#2d6b5e7a8
#33fbb03b2
#449c137e2
#58b2f6aa6

Final state root

final_seqno
5
final_block_hash
d7b978d02b2c81deaed08e635c40a2487d7e551656cec878037ecc8399478229
final_state_root
8b2f6aa6de16db8b22ac3f8fdde779ae0e292b6912a21dbf1915f98747aa6098
comparison
3 of 3 runs identical

Recorded result: all three runs reach the golden root 8b2f6aa6….

Show raw onx replay output
$ onx replay --genesis genesis.toml --blocks ./blocks/ --data-dir ./data
chain_id=58758ecb51f0f2e7fc1353896392e43e2554aa9bef02a335fc350cd804484683
genesis_root=079404cb2379be4802d27f77101e92c232cb94af2f93b3c8274995e85b99c04d
seqno=1 block=e7a5ec9f9a1893c30d2a61eb26e8937c8e08cdee0cfe511103e333873808239c root=4b7def00ee570f70da6ebdcf724af6c9ef56612faf0a689b3824fc037b193abf
seqno=2 block=bd978a065da45de1caf2ae9f06a0043a1924fb7ba306050ccac313cbb880680b root=d6b5e7a8b98fcc15697ed6226955d14b022502f6a8fd3eba2e6a0d676b5894c0
seqno=3 block=d78248605651402379b89a5a2e7b5dd3f0b19409b8ee2dd2986e278ca53526f3 root=3fbb03b29519164464d470e1facbb62f96d0f1ea4fe2e4dce3df87661650af36
seqno=4 block=6f9777afafff5e3f889bd7dd4a223581c58a27e36a457340dfdace368099e8c2 root=49c137e2ac8bcd8e72338c39edb01ca24a3c254f7a7dce547c54396f6c997e67
seqno=5 block=d7b978d02b2c81deaed08e635c40a2487d7e551656cec878037ecc8399478229 root=8b2f6aa6de16db8b22ac3f8fdde779ae0e292b6912a21dbf1915f98747aa6098
final_seqno=5
final_block_hash=d7b978d02b2c81deaed08e635c40a2487d7e551656cec878037ecc8399478229
final_state_root=8b2f6aa6de16db8b22ac3f8fdde779ae0e292b6912a21dbf1915f98747aa6098

The animation replays recorded output; nothing executes in your browser. The genesis root and the roots after blocks 3 and 5 are golden vectors CI checks on every change.

phase5_replay.rsPull request #1
Open Network Xon-x.liveprobe suites

Try to break it.

A protocol isn't trustworthy because it looks correct. It becomes trustworthy by surviving attempts to make it fail.

Pick an attack. Each one is an existing test in the repository, and the response is the output the implementation produces.

probe consoleselect an attack

Choose an attack below.

Block files, transactions, proofs and storage.

STANDBY
—
test: none selected

Block files

Transactions and proofs

Storage and process

These results cover specific failure modes at commit 4b26795. They are evidence about those cases, not a security guarantee, and the repository records no external security audit. Concurrent writers, network partitions, Byzantine validators and denial-of-service are not covered yet; they can't be tested meaningfully until consensus and networking are integrated.

Test suites
Open Network Xon-x.livearchitecture.md

From the whole network down to a single cell.

Tap a layer to see what it is, the identifiers ONX uses for it, and how much of it exists in code today. Each layer is contained by the one above it.

Everything together: one masterchain, the workchains it coordinates, the validators that produce blocks, and the peer-to-peer layer that carries traffic.

In ONX today: specified, with a frozen scaffold. The node daemon refuses to start with networking enabled, so there is no running network.

transport
ADNL, plus RLDP for large transfers
discovery
Kademlia-style DHT, XOR distance, signed records
propagation
overlay networks
SPECIFIEDSCAFFOLD

The coordinating chain. It holds configuration, the validator set and the shard tree of every workchain. Masterchain blocks commit the latest shard block hashes, which makes those shard blocks canonical.

In ONX today: genesis labels the masterchain −1 and the replay chain runs under that id. Coupling shard blocks into masterchain blocks is specified, not implemented.

workchain_id
-1
reference
WHITEPAPER.md §2.1.13–§2.1.17, §2.6
merge blocks
second parent via prev_ref_hash_2 (ADR-0016)
SPECIFIED

Chains that share one masterchain but can each define their own rules. Workchain 0 is the basic workchain, executed by the TVM.

In ONX today: which other workchains exist, and which VM each uses, is still an open question (ONX-ARCH-006).

basic workchain
0
open question
ONX-ARCH-006, partially resolved
SPECIFIED

A workchain's account space is split into shards that form a binary tree. A busy shard splits in two; two quiet siblings merge back.

In ONX today: split and merge rules are specified with thresholds ONX chose itself. Sharding is not integrated yet.

identifier
(workchain_id, shard_prefix)
encoding
prefix then a marker bit; prefix 0 is 0x4000000000000000
split
both averages ≥ 75% of limits for 256 blocks
merge
both siblings ≤ 20% for 1,024 blocks
SPECIFIED

Every balance lives in an account, and every account is in exactly one state: Uninitialized, Active, Frozen or Destroyed.

In ONX today: implemented and tested. Active accounts carry an Ed25519 key and a nonce; every spend must be signed and use the next nonce.

states
Uninitialized 0x00, Active 0x01, Frozen 0x02, Destroyed 0x03
signature
Ed25519 over ONX_TX_V2_SIGN ‖ body
replay guard
per-account nonce, no gaps, no reuse
TESTED

State is stored as trees of cells. A cell holds up to 128 bytes of data and up to four references, and a tree is identified by the hash of its root.

In ONX today: tested. Bag of Cells encoding is byte-identical across processes, the account trie yields the state root, Merkle proofs are checked against a trusted root, and storage is atomic.

cell
≤ 128 data bytes, 0–4 refs (SHA-256 child hashes)
encoding
Bag of Cells, ascending hash order
commitment
ShardStateTree → 32-byte state root
storage
redb, one write transaction per block
TESTED

In the specified design, accounts never write to each other directly. They exchange asynchronous messages that wait in a shard's output queue and move between shards by hypercube routing.

In ONX today: specified, not wired in. The current state transition applies signed Onyx transfers directly between accounts.

0x01 internal
account to account, carries value
0x02 external in
from outside the chain, carries no value
0x03 external out
emitted outward, not routed to an account
ordering
FIFO per (source, destination); double delivery rejected
SPECIFIED
architecture.md
Open Network Xon-x.liveREADME.md

Built incrementally.

Each layer is specified before it is implemented, and nothing is called done until a probe has tried to break it. Later layers stay frozen until the ones beneath them hold. Statuses follow the repository's own status table.

TESTED probedSPECIFIED written downSCAFFOLD code, not integratedPLANNED goal only
  1. 01PrimitivesTESTEDDomain-separated hashing, Ed25519, canonical integers, fixed test vectors.vectors.rs
  2. 02StateTESTEDCanonical Bag of Cells, account trie and state root, Merkle proofs, atomic storage with crash recovery.phase3_merkle.rsphase4_storage.rs
  3. 03TransactionsTESTED: TRANSFERSSPECIFIED: MESSAGESSigned Onyx transfers with fees and nonces are tested. The asynchronous message model is not implemented yet.tx_auth.rs
  4. 04BlocksTESTEDHeaders commit to the ordered transactions and the claimed post-state root; blocks chain by hash and replay from genesis. Masterchain coupling is specified only.phase3_stf.rsphase5_replay.rs
  5. Tested frontier at commit 4b26795
  6. 05ExecutionSPECIFIEDSCAFFOLDTVM instruction set specified; interpreter scaffold not connected to the state transition.tvm-instruction-set.md
  7. 06ConsensusSPECIFIEDSCAFFOLDBFT rules with a two-thirds stake quorum are specified; the engine is a frozen scaffold.consensus.md
  8. 07NetworkingSPECIFIEDSCAFFOLDADNL, DHT and overlays specified; frozen scaffold; the node won't start in network mode.onxd/src/lib.rs
  9. 08ShardingSPECIFIEDShard tree invariants and split and merge triggers specified; not integrated.sharding.md
  10. 09ValidatorsSPECIFIEDElection, stake, rewards and slashing specified; nothing runs validators yet.ADR-0020
  11. 10Public networkPLANNEDThe long-term goal is an independent, functioning network. There is no launch date.README.md
Status table
Open Network Xon-x.liveWHITEPAPER.md

The specification is the starting point.

The original white paper is the primary architectural reference, kept in the repository unmodified. ONX doesn't change the paper to make the code easier; the code adapts to the paper.

  • Precise: implemented faithfully.
  • Ambiguous: the interpretation is documented.
  • Missing: the gap is named and the decision that fills it is recorded.
github.com
The Open Network white paper
Reference document, included with its own source and attribution.
Show 15 specifications
Show 20 decision records, all accepted
Show other working documents
docs/specification
Open Network Xon-x.liveADR-0019

Onyx

Native protocol currency.

The currency is part of the protocol. It is not the reason the protocol exists.

Onyx is defined inside the ONX protocol rather than as an application-layer token. It pays fees and storage and secures validator stake. Parameters below are recorded in ADR-0019 (accepted 2026-09-10) and onx-economics.

Denomination
1 Onyx = 109 nanocoins
TESTED
Every balance and amount in the state transition.
Transaction fees
50% burned, 50% to validators
TESTED
The state transition burns half and credits half to the fee collector named in the block header.
Initial supply
5,000,000,000 Onyx
SPECIFIED
A constant in onx-economics; no network issues it.
Validator rewards
1.75% a year on active stake
SPECIFIED
Not exercised; there are no running validators.
Storage fees
10 nanocoins / byte / 106 lt
SPECIFIED
Not yet charged by the state transition.

No public network exists, so Onyx exists only inside local test chains. This post lists protocol parameters and makes no statement about value.

ADR-0019
Open Network Xon-x.livemain

Project status

Protocol status
Pre-release
Nothing has shipped. Formats can still change: transactions moved from V1 to V2 with signatures before any chain existed.
Implementation
Replay milestone passing
Execute, persist, recover and replay from genesis. VM, consensus and networking are frozen scaffolds.
Tests
219 passed, 0 failed
Local run of cargo test --workspace at 4b26795. Live CI:
CI workflow status for main
Documentation
15 specifications, 20 decision records
Every protocol layer has a specification; every decision record is accepted.
Network
Not running
onxd refuses to start with networking enabled. There is no testnet or mainnet.
Current build
4b26795
Snapshot of main.
Last updated
2026-10-05
Merge pull request #3 from gokooteam/ci-greenup
Toolchain and license
Rust 1.98.1, Apache-2.0
Pinned in rust-toolchain.toml; license chosen in ADR-0015.

Statuses on this page were reviewed against commit 4b26795 (2026-10-05).

Commit history

Build the protocol. Verify the network.

Independent project. Open Network X builds on the architecture described in the original TON white paper. ONX, Open Network X and Onyx are not TON products, networks or services, and using that material as a reference implies no endorsement by, affiliation with, or control by the organizations or communities of the existing TON ecosystem.

Code is licensed under Apache-2.0. Reference materials such as WHITEPAPER.md carry their own source and attribution.

SPECIFICATION → IMPLEMENTATION → NETWORK