How nodes find and reach one another
The peer network uses discovery hints, a peerbook, expiring peer announcements, and minimum/maximum peer policies. Framed hello, header/block exchange, gossip, and anti-entropy synchronization have development evidence. The exercised framed carrier is HTTP; final internal TCP+TLS transport parity is not established.
Bootstrap and endpoint management
Nodes accept configured bootstrap peers and a chain-specific seed registry supplied by configuration. Invalid or duplicate peers are handled explicitly; a configured seed is not proof of a connection. No built-in public seed fleet is established. Endpoint management separates loopback, LAN, observed public addresses, and verified mapping candidates.
NAT mapping and relay foundations
UPnP and NAT-PMP mapping code includes renewal, withdrawal, and restart handling. Public advertisement requires suitable endpoint verification; merely observing an external address is insufficient. The latest real-router test did not create a public mapping, and independent remote acceptance was not performed. Router and network compatibility remain practical limits.
Framed relay envelopes, quota controls, and handshake fallback have local test evidence. Route diagnostics distinguish direct LAN, direct public, and relayed attempts. This is a relay foundation, not a proven public relay fleet or a guarantee of connectivity behind every NAT or CGNAT.
Identity, authentication, and delegated access
Transport NodeID is separate from producer/wallet identity. The current peer handshake checks identity consistency but does not prove possession of the advertised transport key: connected routes remain identity-claim-only, not authenticated peers. Transport encryption and public-network security must not be inferred from connectivity or TLS configuration labels.
Canonical capabilities support signed grants, revocation, and delegation with narrower actions, scope, and depth. Reputation is bounded and derived from canonical events. Peer scoring, rate limits, content verification, and reorganization guards provide implemented hardening; they do not close the full production security model.
Applications, services, and hosting
Application and service registries bind identity, namespace, runtime-package, and schema references. Hosting foundations add publication revisions, object/chunk asset bindings, provider capability checks, freshness, and replica-fallback plans, audit traces, and operator readiness gates. Registering a service does not execute it; these contracts do not prove live multi-provider publishing, retrieval, or replication.
Hash-addressed objects and application/service namespaces provide addressing foundations. Hosting route identities are modeled, but public DNS and zero-configuration public hosting are not complete. Predictive cache/prefetch/routing evidence is deterministic and fixture-backed, not production adaptive AI routing.
Diagnostics and the role of ENT
Node diagnostics expose configuration, peers, bootstrap, reachability, NAT/relay limits, and transport state through CLI and query interfaces. The explorer rebuilds read models from canonical state and events; its views are not independent authority.
ENT is the network fuel/token terminology. Contribution records and accounting foundations model reserves, fee debits, and reward credits. This does not establish complete token economics, production reward correctness, exchange functionality, or an available public token service.