On this page
One system. Composable layers.

Start with the execution contract

The Programs workspace contains the deterministic WebAssembly execution surface for the LayerX kernel domain of Paxeer X. Applications deploy artifacts and interfaces, execute under explicit capabilities, and express monetary effects as authenticated native transfer sets. Read Programs before choosing entrypoints, account seeds, and spending grants.

Rust workspace packages use edition 2021 and Rust 1.91.1. Cargo resolves dependencies from the checked-in vendor tree in offline mode, and the interpreter is pinned to wasmi = 0.31.2. Run Cargo from inside programs/ so its local configuration applies. Lockfiles, source checksums, and frozen ABI vectors make builds and byte contracts reproducible.

Choose the right package

Workspace areaResponsibility
crates/layerx-programs-runtimeValidation, budgets, metering, host imports, storage, cross-program calls, transfer authorization, occupancy, replay, and kernel FFI.
crates/layerx-programs-registryReceipt-bound deployment journals, interfaces, program account bindings, account proofs, and lifecycle exits.
crates/layerx-programs-protocol-adapterVerified program-state reads across the C and Rust boundary.
crates/layerx-programs-interpreterBounded deterministic scripts with canonical input validation before effects.
crates/layerx-programs-marketCompute leases, usage claims, challenge windows, provider stake, attesters, and bisection disputes.
crates/layerx-programs-arbiterSandbox trace replay and disputed single-step adjudication.
crates/layerx-programs-sandboxBounded lease lifecycle, isolated execution, snapshots, and restore.
sdk/ and porting/Rust, C, and AssemblyScript guests; migration guides and reference guests for EVM, Solana, and CosmWasm developers.
fixtures/, tests/, fuzz/, benches/Canonical artifacts, cross-implementation vectors, hostile guests, fuzz corpora, and interpreter comparisons.

Build a guest application

  1. Choose a guest SDK and a reference application close to your use case.
  2. Define canonical calldata and responses, entrypoint bounds, storage scopes, and required grants. Select the guest ABI that supplies those host imports.
  3. Keep state transitions deterministic. Consume admitted oracle or web evidence through host calls rather than adding a network client to execution.
  4. Compile a WASM artifact, generate its canonical interface, and retain the artifact hash and interface together.
  5. Deploy with the chosen upgrade policy, verify the receipt, register any program-owned accounts, and fund them through native transfers.
  6. Simulate a bounded call, submit the signed activity, and verify committed terminal evidence.

Rust examples cover escrow, naming, LXT-721, merchant payments, constant-product swaps, LXT-20, vaults, and web readers. C and AssemblyScript provide paid-counter guests. A reference application is an executable contract: preserve its documented selectors and authorization requirements when adapting it.

# From the repository root
cd programs
cargo build --locked --manifest-path sdk/rust/examples/token-lxt20/Cargo.toml \
  --target wasm32-unknown-unknown --release

Build and validate the workspace

The repository Makefile coordinates Rust and native C checks. Run these commands from the repository root; they enter the Programs directory where required.

make programs-build
make programs-lint
make programs-abi-drift
make programs-test
GateWhat it establishes
programs-buildBuilds the locked workspace and sandbox host FFI used by native integration.
programs-lintChecks runtime module boundaries, Clippy, dependency and vendoring policy, advisories, sources, and dependency bans.
programs-abi-driftChecks frozen vectors and the runtime linker against the canonical guest import contract.
programs-core-testExercises native registration, lifecycle, calls, monetary invariants, occupancy, fees, accounts, and wind-down.
programs-adversarialChecks guest isolation, composition, and monetary-law refusal paths.
programs-fuzz-smokeReplays validation, instantiation, and execution corpora.
programs-differentialChecks deterministic replay and serial versus parallel execution behavior.
programs-interpreter-conformanceBuilds the interpreter WASM and exercises it through the runtime.
programs-testCombines protocol, native, guest SDK, porting, adversarial, fuzz, ABI, and differential checks.

Preserve ABI compatibility

Frozen guest ABI versions 1 through 5 have independently pinned vector checksums in programs/abi-frozen.sha256. The ABI gate compares generated canonical bytes, manifests, validator allowlists, and SDK declarations with those baselines. An existing frozen import contract is immutable; add a new ABI version for a new surface.

Do not treat vector regeneration as a fix for incompatible behavior. A missing frozen vector, changed checksum, or changed generated surface fails the drift check. Review interface generators and clients alongside a new ABI allocation so deployment, calls, and response decoding agree.

Maintain runtime boundaries

Host-function families register through their own modules and access execution state through RuntimeState. The boundary gate rejects forbidden sibling dependencies, legacy monolithic modules, and production paths into qualification-only helpers. The workspace denies unsafe code by default; explicitly bounded FFI adapters carry the reviewed boundary work.

Dependency policy excludes entropy, clocks, arbitrary networking, dynamic registration, database engines, and alternate execution engines from the deterministic boundary. It verifies vendored checksums, the exact interpreter revision, approved licenses, and integer-only consensus-adjacent code. Workspace linting also rejects unchecked unwraps, expects, and float arithmetic.

Canonical fixtures and release evidence

Lifecycle, capability, executed-receipt, and reference-program fixtures keep native encoders and SDKs aligned. Use the check targets when validating existing output; generation targets intentionally write new fixtures.

make programs-check-capability-fixture
make programs-check-native-lifecycle-fixtures
make programs-check-executed-fixture

# Rebuild reference artifacts when intentionally changing their source
make programs-reference-fixtures

Retain the artifact hash, interface, chosen ABI, test results, and receipt-verification behavior for each release. Local checks establish the behavior they exercise; the qualification runner adds its own release evidence. Applications still verify live deployment and execution receipts before relying on a program outcome.

Continue with bounded storage scans and sandbox execution.

Technical references: Programs workspace guide, Cargo manifest and configuration, Makefile Programs targets, frozen ABI baselines, dependency policy, and runtime boundary checks.
Paxeer X · System documentationBack to top ↑

Ask Paxeer X Docs

Answers from the documentation.

What would you like to know?

Ask a question, find a guide, or get help with your next step.

Enter to send · Shift+Enter for a new line