Running Hedgehog

This page takes you from a download to a running Hedgehog 0.0.8 node: where to get the program, how to check it, how to start and stop it, and where it keeps its data. A 0.0.8 node joins the peer-to-peer network, holds the signed network settings (Grid sporks) and serves the signed legacy chain snapshot. Gridnodes and network storage are not part of this release, see Network storage.

Download

Every file is on the 0.0.8 release page.

Your computer File Needs
Linux, x86_64 hedgehog-0.0.8-x86_64-linux-gnu.bin nothing else
macOS, Apple Silicon hedgehog-0.0.8-osx-arm64.bin nothing else
Windows, x86_64 hedgehog-0.0.8-win64.exe nothing else
Anything else, such as an Intel Mac hedgehog-0.0.8-jar-with-dependencies.jar Java 25 or newer

The executables carry their own Java runtime, see Build, testing and native image. You do not download the legacy chain snapshot yourself: a node fetches and checks it the first time it starts. On Linux and macOS, make the executable runnable with chmod +x.

Check the download

Each release is signed by the Unigrid Foundation release key, whose public half is release-key.asc in the repository. Download SHA256SUMS and SHA256SUMS.asc from the release page next to your file, then run:

gpg --import release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum --check --ignore-missing SHA256SUMS

gpg reports a good signature, and warns that the key is not certified because you have not marked it as trusted. That warning is expected. What matters is that the fingerprint it prints is

A1CB 0037 B3B9 2D59 5FA1 536C 95A9 8E88 8B0B A5D9

sha256sum then prints OK for your file. Every file also has its own .asc signature, so gpg --verify <file>.asc <file> works as well. Where there is no sha256sum, compare the hash of your file with its line in SHA256SUMS: shasum -a 256 <file> on macOS, and certutil -hashfile <file> SHA256 on Windows.

Start a node

./hedgehog-0.0.8-x86_64-linux-gnu.bin daemon

With the jar, run java -jar hedgehog-0.0.8-jar-with-dependencies.jar daemon instead. The rest of this page writes hedgehog for either form.

The first start of an executable unpacks its runtime into the data directory, which takes a moment. The node then:

  • binds the peer-to-peer port and the REST port, see Open ports;
  • dials the six seed nodes to find other peers, unless you pass --no-seeds;
  • downloads and verifies the legacy chain snapshot in the background when it has none, about 314 MB, and keeps serving everything else meanwhile. GET /status reports downloading with a percentage, then running, see REST interface.

A node prints nothing by default. Add -v to see errors, and more of them for more detail:

Flag Shows
none nothing
-v errors
-vv warnings as well
-vvv progress messages as well, such as the snapshot download
-vvvv debug output
-vvvvv trace output

Logging goes to the console only, there is no log file. Java may print a few WARNING lines about native access when the node starts. They are harmless.

Stop a node

Stop a node with hedgehog cli stop. It asks the running node to shut down over REST, and works from the same computer without any setup.

Use it for the executables in particular. About a minute after the start, the launcher loses its hold on the program it started, which keeps running on its own, so interrupting the launcher afterwards does not stop the node.

Open ports

Port Used for What to do
52883, UDP Other nodes, over QUIC Allow inbound traffic if you want others to connect to you
52884, TCP The REST interface Leave it on localhost, the default

The REST interface controls the node and its certificate is not verified by clients, so do not expose it beyond the machine, see REST interface. Change the ports with --netport and --restport.

Options

These options go after the command, for example hedgehog daemon --no-seeds -vvv.

Option Default Meaning
-v, --verbose off Raise the logging level, repeat for more
-H, --nethost 0.0.0.0 Address the peer-to-peer port binds to
-p, --netport 52883 Peer-to-peer port
--no-seeds seeds on Do not dial the seed nodes, --seeds turns them back on
--network-keys the four board keys Replace the built-in board keys, comma-separated
--retired-network-keys three retired keys Keys trusted only for reading old entries in the signature log
-R, --resthost localhost Address the REST interface binds to
-r, --restport 52884 REST port
--resttoken see below Bearer token every REST request must carry
--restmaxupload 1 GiB Largest upload accepted by the S3-compatible store, in bytes
-s, --snapshot bootstrap.dat in the data directory Snapshot file, for the bootstrap commands
-h, --help   Show the options of a command
-V, --version   Print the version

The REST token is taken from --resttoken, then from the environment variable HEDGEHOG_REST_TOKEN, and otherwise generated at each start into rest.token in the data directory. No configuration file is read. The command line is the whole configuration.

Where the data lives

System Data directory
Linux $XDG_DATA_HOME/hedgehog, by default ~/.local/share/hedgehog
macOS ~/Library/Application Support/Hedgehog
Windows %APPDATA%\Unigrid\Hedgehog
File or folder Holds
bootstrap.dat The legacy chain snapshot, about 556 MB
spork.db The signed network settings the node has accepted
rest.token The REST token, readable only by its owner
s3data/ Buckets and objects of the local S3-compatible store
a folder named by a long hash The unpacked runtime of an executable, safe to delete

Deleting bootstrap.dat makes the next start download it again. On Linux, set XDG_DATA_HOME to keep the data somewhere else.

Commands

A node is controlled with the same program. daemon runs it, and the commands below talk to a node that is already running, or work on files.

Command What it does
hedgehog cli stop Shut the node down
hedgehog cli node-list, node-add <ip:port>, node-remove <ip:port> Show or change the peers the node knows, node-list prints JSON
hedgehog cli gridspork-list, gridspork-log, gridspork-pending Read the sporks, their signature history, and the changes awaiting a second signature
hedgehog cli gridspork-get mint-supply\|mint-storage Read one spork
hedgehog bootstrap info Show what the snapshot contains
hedgehog bootstrap balance <address> Show the coins held by a legacy address
hedgehog bootstrap history <address> List its transactions, with --limit (100 by default), --offset and --json
hedgehog bootstrap fetch Download, verify and install the published snapshot, --force replaces an existing one
hedgehog util key-generate Create a key pair

Changing a spork needs a board member’s private key: gridspork-set, gridspork-grow, gridspork-cosign and gridspork-renew, together with util key-sign and key-validate, are for the board and are explained in Grid sporks. bootstrap import and bootstrap sign make a snapshot and are used when a release is prepared, see Legacy chain snapshot. Every cli command takes the --resthost, --restport and --resttoken options, so it can reach a node on another machine given that node’s token.

Running with Janus

Janus, the Unigrid desktop wallet, downloads and starts its own Hedgehog 0.0.8 and talks to it on port 52884 with a fresh token each time it runs, so it cannot use a node it did not start itself. Stop a node of your own before you open Janus, or Janus finds the port taken. The Janus troubleshooting page lists what it shows then.

Upgrading from 0.0.7

Nodes of 0.0.7 and earlier cannot talk to nodes of 0.0.8, because the wire protocols went from hedgehog/0.0.2 and gridspork/0.0.2 to hedgehog/0.0.4 and gridspork/0.0.4. The network keys were also replaced, with one key per board member, so sporks signed with the old keys stop verifying until the board has re-signed them, see Grid sporks. To upgrade, replace the program and start it again. The osx64.bin executable for Intel Macs of earlier releases is gone: use the jar there.

Key facts

   
Version 0.0.8, “Howling Husky”
Java 25 or newer, only for the jar
Linux executable about 94 MB
Peer-to-peer UDP 52883
REST HTTPS 52884, localhost, bearer token
Release signing key A1CB 0037 B3B9 2D59 5FA1 536C 95A9 8E88 8B0B A5D9

In the source

  • application/src/main/java/org/unigrid/hedgehog/Hedgehog.java is the root command and the -v option.
  • application/src/main/java/org/unigrid/hedgehog/command/ holds daemon, cli, util and bootstrap and their options.
  • application/src/main/java/org/unigrid/hedgehog/command/option/ defines the network, REST and snapshot options with their defaults.
  • common/src/main/java/org/unigrid/hedgehog/common/model/ApplicationDirectory.java decides the data directory.
  • release.sh and release-key.asc are how a release is signed.