A course-oriented B/S content platform combining browser-side cryptography, a P2P Mesh, and a Hyperledger Fabric permissioned blockchain for auditable governance.
Actinium Cast replaces traditional server-client models with three independent layers:
- BitTorrent DHT (BEP 44): Posts, comments, and votes are Ed25519-signed. Gateways keep verified messages in local SQLite and can publish them to the public DHT when the network permits.
- Gateway Mesh (BEP 5): Gateways can discover each other via BEP 5
announce_peeror use explicit static peers, then synchronize verified messages peer-to-peer. - Deterministic Local Mesh: Two isolated gateways can be linked with static peers and tested bidirectionally without public DHT, UPnP, or campus-network UDP access.
- Optional Public Traversal Experiments: UPnP and uTP/BEP 29 punching paths are implemented, but real-world reachability depends on NAT and network policy and is not a prerequisite for the course demo.
- Client-held keys: Private keys stay in the current browser/CLI environment. Ed25519 key generation, PoW computation, and signing happen locally; this is not a zero-knowledge proof system, and browser keys are not yet passphrase-encrypted.
- Hashcash Proof-of-Work: Every action requires a CPU-bound PoW solution. Gateways reject non-compliant packets, raising the cost of automated spam without claiming to eliminate Sybil attacks.
- Tombstone Governance: The current development network demonstrates auditable moderation using MSP/X.509 identities and Fabric endorsement policies. Gateways subscribe to chaincode events and purge banned content; this setup does not claim a production multi-organization threshold multisig.
- Gateway Reputation: Gateways can optionally register on-chain with an X.509 certificate, report uptime heartbeats, and build a verifiable reputation history. Any client can query the chain for reliable gateways.
- Content Provenance: The chaincode supports create/edit/delete provenance records; the current browser publishing path asynchronously registers the create record and exposes its status separately from local/P2P success.
- Zero Gas, Zero Token: Fabric is a permissioned blockchain — no cryptocurrency and no gas fee. The supplied course network is a single-organization, single-machine teaching setup.
| Component | Status |
|---|---|
| Core crypto (Ed25519, PoW, models) | Done |
| Gateway (HTTP API, SQLite cache, spam filter) | Done |
| DHT adapter (BEP 44, BEP 5) | Done |
| Gateway Mesh Sync | Done |
| Deterministic two-gateway local Mesh test | Done |
| Public NAT traversal (UPnP/uTP) | Implemented; not a campus-network acceptance gate |
| CLI client (post, comment, vote, smoke-test) | Done |
| Fabric chaincode (Go) | Done |
| Fabric gRPC client (Rust, tonic) | Done |
| Fabric network config (docker-compose, configtx) | Done |
| Fabric E2E: Tombstone governance + content provenance writes | Done; fresh four-service network and automated browser API flow verified |
| Wasm frontend (including Fabric status/provenance dashboard) | Done |
| Cross-NAT hole punching (UDP punch + uTP/BEP 29) | Implemented; public/symmetric-NAT reachability not sufficiently verified |
For the Windows course demo, run:
.\scripts\start-course-demo.ps1It starts two offline static-Mesh gateways, seeds posts/comments/votes, and opens the browser. If the Fabric development network is already running and the FABRIC_* variables are set, pass -WithFabric to enable real provenance writes; browser governance additionally requires the explicit -EnableGovernance demo flag.
# Clone with submodules
git clone --recurse-submodules https://github.com/AI1379/actinium-cast.git
cd actinium-cast
# 1. Start a gateway (offline mode — no blockchain needed)
cargo run -p gateway
# 2. In another terminal: generate an identity
cargo run -p client-cli -- identity generate
# 3. Post
cargo run -p client-cli -- post \
--title "Hello" --content "Decentralized world!" --difficulty 8
# 4. Read
cargo run -p client-cli -- list-posts
# 5. Run the full smoke test
cargo run -p client-cli -- smoke-test.\scripts\test-local-mesh.ps1The script stays offline and verifies bidirectional sync between two isolated gateways, idempotent deduplication, and invalid-input isolation. See docs/GUIDE.md §5 for manual configuration and optional public-network experiments.
cd contracts/fabric
bash scripts/generate-artifacts.sh # crypto material (first run)
docker compose up -d
docker exec actinium-cli bash -c "source /scripts/deploy.sh"
bash scripts/issue-gateway-cert.sh # → prints FABRIC_* env vars
# Start gateway with Fabric (use the env vars printed by the cert script)
cd ../..
env FABRIC_GATEWAY_ENDPOINT=grpcs://localhost:7051 \
FABRIC_CLIENT_CERT_PATH=$PWD/fabric/client.crt \
FABRIC_CLIENT_KEY_PATH=$PWD/fabric/client.key \
FABRIC_CA_CERT_PATH=$PWD/fabric/tlsca.crt \
FABRIC_TLS_SERVER_NAME=peer0.adminorg.example.com \
cargo run -p gatewayFull step-by-step verification (Tombstone ban/revoke, on-chain provenance):
see docs/GUIDE.md §6.
See docs/GUIDE.md for detailed testing procedures, docs/ARCHITECTURE.md for design decisions, and docs/ROADMAP.md for the implementation roadmap.
Course-deliverable source drafts for the introduction, slides, demo video, and contribution sheet are under deliverables/.