Running Hedgehog
This page takes you from a download to a running Hedgehog 0.0.8 node: where to get the program, how to check it, how to start and stop it, and where it keeps its data. A 0.0.8 node joins the peer-to-peer network, holds the signed network settings (Grid sporks) and serves the signed legacy chain snapshot. Gridnodes and network storage are not part of this release, see Network storage.
Download
Every file is on the 0.0.8 release page.
| Your computer | File | Needs |
|---|---|---|
| Linux, x86_64 | hedgehog-0.0.8-x86_64-linux-gnu.bin |
nothing else |
| macOS, Apple Silicon | hedgehog-0.0.8-osx-arm64.bin |
nothing else |
| Windows, x86_64 | hedgehog-0.0.8-win64.exe |
nothing else |
| Anything else, such as an Intel Mac | hedgehog-0.0.8-jar-with-dependencies.jar |
Java 25 or newer |
The executables carry their own Java runtime, see
Build, testing and native image. You do not download the legacy chain
snapshot yourself: a node fetches and checks it the first time it starts. On Linux and macOS, make the
executable runnable with chmod +x.
Check the download
Each release is signed by the Unigrid Foundation release key, whose public half is
release-key.asc in the
repository. Download SHA256SUMS and SHA256SUMS.asc from the release page next to your file, then run:
gpg --import release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum --check --ignore-missing SHA256SUMS
gpg reports a good signature, and warns that the key is not certified because you have not marked it as
trusted. That warning is expected. What matters is that the fingerprint it prints is
A1CB 0037 B3B9 2D59 5FA1 536C 95A9 8E88 8B0B A5D9
sha256sum then prints OK for your file. Every file also has its own .asc signature, so
gpg --verify <file>.asc <file> works as well. Where there is no sha256sum, compare the hash of your
file with its line in SHA256SUMS: shasum -a 256 <file> on macOS, and
certutil -hashfile <file> SHA256 on Windows.
Start a node
./hedgehog-0.0.8-x86_64-linux-gnu.bin daemon
With the jar, run java -jar hedgehog-0.0.8-jar-with-dependencies.jar daemon instead. The rest of this page
writes hedgehog for either form.
The first start of an executable unpacks its runtime into the data directory, which takes a moment. The node then:
- binds the peer-to-peer port and the REST port, see Open ports;
- dials the six seed nodes to find other peers, unless you pass
--no-seeds; - downloads and verifies the legacy chain snapshot in the background when it has none, about 314 MB, and
keeps serving everything else meanwhile.
GET /statusreportsdownloadingwith a percentage, thenrunning, see REST interface.
A node prints nothing by default. Add -v to see errors, and more of them for more detail:
| Flag | Shows |
|---|---|
| none | nothing |
-v |
errors |
-vv |
warnings as well |
-vvv |
progress messages as well, such as the snapshot download |
-vvvv |
debug output |
-vvvvv |
trace output |
Logging goes to the console only, there is no log file. Java may print a few WARNING lines about native
access when the node starts. They are harmless.
Stop a node
Stop a node with hedgehog cli stop. It asks the running node to shut down over REST, and works from the
same computer without any setup.
Use it for the executables in particular. About a minute after the start, the launcher loses its hold on the program it started, which keeps running on its own, so interrupting the launcher afterwards does not stop the node.
Open ports
| Port | Used for | What to do |
|---|---|---|
| 52883, UDP | Other nodes, over QUIC | Allow inbound traffic if you want others to connect to you |
| 52884, TCP | The REST interface | Leave it on localhost, the default |
The REST interface controls the node and its certificate is not verified by clients, so do not expose it
beyond the machine, see REST interface. Change the ports with --netport and --restport.
Options
These options go after the command, for example hedgehog daemon --no-seeds -vvv.
| Option | Default | Meaning |
|---|---|---|
-v, --verbose |
off | Raise the logging level, repeat for more |
-H, --nethost |
0.0.0.0 |
Address the peer-to-peer port binds to |
-p, --netport |
52883 |
Peer-to-peer port |
--no-seeds |
seeds on | Do not dial the seed nodes, --seeds turns them back on |
--network-keys |
the four board keys | Replace the built-in board keys, comma-separated |
--retired-network-keys |
three retired keys | Keys trusted only for reading old entries in the signature log |
-R, --resthost |
localhost |
Address the REST interface binds to |
-r, --restport |
52884 |
REST port |
--resttoken |
see below | Bearer token every REST request must carry |
--restmaxupload |
1 GiB | Largest upload accepted by the S3-compatible store, in bytes |
-s, --snapshot |
bootstrap.dat in the data directory |
Snapshot file, for the bootstrap commands |
-h, --help |
Show the options of a command | |
-V, --version |
Print the version |
The REST token is taken from --resttoken, then from the environment variable HEDGEHOG_REST_TOKEN, and
otherwise generated at each start into rest.token in the data directory. No configuration file is read.
The command line is the whole configuration.
Where the data lives
| System | Data directory |
|---|---|
| Linux | $XDG_DATA_HOME/hedgehog, by default ~/.local/share/hedgehog |
| macOS | ~/Library/Application Support/Hedgehog |
| Windows | %APPDATA%\Unigrid\Hedgehog |
| File or folder | Holds |
|---|---|
bootstrap.dat |
The legacy chain snapshot, about 556 MB |
spork.db |
The signed network settings the node has accepted |
rest.token |
The REST token, readable only by its owner |
s3data/ |
Buckets and objects of the local S3-compatible store |
| a folder named by a long hash | The unpacked runtime of an executable, safe to delete |
Deleting bootstrap.dat makes the next start download it again. On Linux, set XDG_DATA_HOME to keep the
data somewhere else.
Commands
A node is controlled with the same program. daemon runs it, and the commands below talk to a node that
is already running, or work on files.
| Command | What it does |
|---|---|
hedgehog cli stop |
Shut the node down |
hedgehog cli node-list, node-add <ip:port>, node-remove <ip:port> |
Show or change the peers the node knows, node-list prints JSON |
hedgehog cli gridspork-list, gridspork-log, gridspork-pending |
Read the sporks, their signature history, and the changes awaiting a second signature |
hedgehog cli gridspork-get mint-supply\|mint-storage |
Read one spork |
hedgehog bootstrap info |
Show what the snapshot contains |
hedgehog bootstrap balance <address> |
Show the coins held by a legacy address |
hedgehog bootstrap history <address> |
List its transactions, with --limit (100 by default), --offset and --json |
hedgehog bootstrap fetch |
Download, verify and install the published snapshot, --force replaces an existing one |
hedgehog util key-generate |
Create a key pair |
Changing a spork needs a board member’s private key: gridspork-set, gridspork-grow, gridspork-cosign
and gridspork-renew, together with util key-sign and key-validate, are for the board and are explained
in Grid sporks. bootstrap import and bootstrap sign make a snapshot and are used when a
release is prepared, see Legacy chain snapshot. Every cli command takes the
--resthost, --restport and --resttoken options, so it can reach a node on another machine given that
node’s token.
Running with Janus
Janus, the Unigrid desktop wallet, downloads and starts its own Hedgehog 0.0.8 and talks to it on port 52884 with a fresh token each time it runs, so it cannot use a node it did not start itself. Stop a node of your own before you open Janus, or Janus finds the port taken. The Janus troubleshooting page lists what it shows then.
Upgrading from 0.0.7
Nodes of 0.0.7 and earlier cannot talk to nodes of 0.0.8, because the wire protocols went from hedgehog/0.0.2
and gridspork/0.0.2 to hedgehog/0.0.4 and gridspork/0.0.4. The network keys were also replaced, with
one key per board member, so sporks signed with the old keys stop verifying until the board has re-signed
them, see Grid sporks. To upgrade, replace the program and start it again. The osx64.bin
executable for Intel Macs of earlier releases is gone: use the jar there.
Key facts
| Version | 0.0.8, “Howling Husky” |
| Java | 25 or newer, only for the jar |
| Linux executable | about 94 MB |
| Peer-to-peer | UDP 52883 |
| REST | HTTPS 52884, localhost, bearer token |
| Release signing key | A1CB 0037 B3B9 2D59 5FA1 536C 95A9 8E88 8B0B A5D9 |
In the source
application/src/main/java/org/unigrid/hedgehog/Hedgehog.javais the root command and the-voption.application/src/main/java/org/unigrid/hedgehog/command/holdsdaemon,cli,utilandbootstrapand their options.application/src/main/java/org/unigrid/hedgehog/command/option/defines the network, REST and snapshot options with their defaults.common/src/main/java/org/unigrid/hedgehog/common/model/ApplicationDirectory.javadecides the data directory.release.shandrelease-key.ascare how a release is signed.