merge: bring develop forward from phase5-docs-deployment

This commit is contained in:
Pratik Mankawde
2026-09-03 17:33:52 +01:00
100 changed files with 5633 additions and 838 deletions

View File

@@ -14,7 +14,6 @@
#include <xrpl/protocol/STVector256.h>
#include <xrpl/protocol/TER.h>
#include <cstdint>
#include <memory>
#include <set>
#include <utility>
@@ -34,32 +33,6 @@ checkExpired(SLE const& sleCredential, NetClock::time_point const& closed);
[[nodiscard]] TER
deleteSLE(ApplyView& view, SLE::ref sleCredential, beast::Journal j);
/**
* @brief Remove credentials pinned to a pseudo-account's owner directory.
*
* Cleans up credentials that were linked to a pseudo-account (Vault, LoanBroker,
* AMM), which such an account can neither accept nor delete. Only credentials
* are removed; every other object is left in place. The walk visits at most
* @p maxNodesToDelete directory entries and charges the ones it leaves alone
* against that budget too, so a directory holding other objects yields fewer
* than @p maxNodesToDelete deletions. On reaching the bound the result is
* `tecINCOMPLETE` and the caller must propagate it so a later transaction
* resumes.
*
* @param view Mutable ledger view.
* @param pseudoAcct The pseudo-account whose directory is cleaned.
* @param maxNodesToDelete Upper bound on directory entries processed in one call.
* @param j Journal for diagnostics.
* @return tesSUCCESS once no credentials remain, tecINCOMPLETE if the bound was
* reached, or a deletion error.
*/
[[nodiscard]] TER
deletePseudoAccountCredentials(
ApplyView& view,
AccountID const& pseudoAcct,
std::uint16_t maxNodesToDelete,
beast::Journal j);
// Amendment and parameters checks for sfCredentialIDs field
NotTEC
checkFields(STTx const& tx, Rules const& rules, beast::Journal j);

View File

@@ -239,8 +239,13 @@ canTransfer(ReadView const& view, Issue const& issue, AccountID const& from, Acc
//------------------------------------------------------------------------------
/**
* Any transactors that call addEmptyHolding() in doApply must call
* canAddHolding() in preflight with the same View and Asset
* XRP and the issuer itself are always tesSUCCESS. Otherwise, after
* fixCleanup3_4_0, an existing trust line returns tecDUPLICATE without
* consulting issuer freeze or DefaultRipple; both still apply on the create
* path (DefaultRipple off is terNO_RIPPLE). canAddHolding() ignores existing
* holdings, so transactors that may create a holding in doApply should gate
* their preclaim call on it: after the amendment only when no holding
* exists, before it always.
*/
[[nodiscard]] TER
addEmptyHolding(

View File

@@ -38,6 +38,12 @@ enum class FreezeHandling { IgnoreFreeze, ZeroIfFrozen };
*/
enum class AuthHandling { IgnoreAuth, ZeroIfUnauthorized };
/**
* Controls whether the recipient owner-reserve check is enforced when
* auto-creating a trustline or MPToken during AMMWithdraw or AMMClawback.
*/
enum class ReserveHandling : bool { EnforceReserve, IgnoreReserve };
/**
* Controls whether to include the account's full spendable balance
*/
@@ -319,6 +325,12 @@ transferRate(ReadView const& view, STAmount const& amount);
[[nodiscard]] TER
canAddHolding(ReadView const& view, Asset const& asset);
/**
* True if the account already holds this asset (or is the issuer / XRP).
*/
[[nodiscard]] bool
holdingExists(ReadView const& view, AccountID const& account, Asset const& asset);
[[nodiscard]] TER
addEmptyHolding(
ApplyViewContext ctx,

View File

@@ -1,19 +0,0 @@
#pragma once
#include <xrpl/json/json_forwards.h>
#include <xrpl/protocol/STTx.h>
#include <xrpl/protocol/TxMeta.h>
#include <memory>
namespace xrpl::rpc {
/**
* Adds common synthetic fields to transaction-related JSON responses
*/
/** @{ */
void
insertNFTSyntheticInJson(json::Value&, std::shared_ptr<STTx const> const&, TxMeta const&);
/** @} */
} // namespace xrpl::rpc

View File

@@ -348,13 +348,24 @@ enum class VaultPhase : std::uint8_t {
Redemption,
};
/**
* Minimum gap between a closed-ended loan's final scheduled payment and the
* vault's RedemptionDate. LoanSet rejects a schedule whose final payment is
* fewer than this many seconds before RedemptionDate.
*/
constexpr std::uint32_t kLoanRedemptionBuffer = std::chrono::seconds{60}.count();
/**
* Bounds on the length of a closed-ended vault's Investment phase
* (RedemptionDate - SubscriptionDate). At vault creation the gap must satisfy
* kMinInvestmentPeriod <= gap < kMaxInvestmentPeriod.
*
* 180s is enough to originate a loan that uses the minimum payment interval
* and kLoanRedemptionBuffer after StartDate, which is strictly after
* SubscriptionDate. The interval and buffer need not be equal; only their
* sum plus one second must fit in this floor.
*/
constexpr std::uint32_t kMinInvestmentPeriod =
std::chrono::seconds{std::chrono::minutes{1}}.count();
constexpr std::uint32_t kMinInvestmentPeriod = std::chrono::seconds{180}.count();
// This is 946708560 seconds which 30 x 365.2425 days (the average length of a Gregorian year).
constexpr std::uint32_t kMaxInvestmentPeriod = std::chrono::seconds{std::chrono::years{30}}.count();
@@ -396,16 +407,6 @@ using TxID = uint256;
*/
constexpr std::uint16_t kMaxDeletableAmmTrustLines = 512;
/**
* The maximum number of owner-directory entries to walk when clearing
* credentials pinned to a pseudo-account, in a single transaction.
*
* The walk stops after this many entries whether or not each one turns out to
* be a credential, so a directory that also holds other objects yields fewer
* deletions per transaction.
*/
constexpr std::uint16_t kMaxDeletablePseudoAccountCredentials = 512;
/**
* The maximum length of a URI inside an Oracle
*/

View File

@@ -259,6 +259,13 @@ public:
static XRPAmount
calculateBaseFee(ReadView const& view, STTx const& tx, std::uint32_t extraBaseFeeMultiplier);
// Exposed for invariant checks (e.g. ValidVault) that need to know which
// ledger entry actually pays a transaction's fee, distinguishing an
// ordinary sender, a delegate, and pre-funded vs. co-signed fee
// sponsorship.
static FeePayer
getFeePayer(ReadView const& view, STTx const& tx);
/* Do NOT define an invokePreflight function in a derived class.
Instead, define:
@@ -525,9 +532,6 @@ private:
std::pair<TER, XRPAmount>
reset(XRPAmount fee);
static FeePayer
getFeePayer(ReadView const& view, STTx const& tx);
TER
consumeSeqProxy(SLE::pointer const& sleAccount);
TER

View File

@@ -19,6 +19,11 @@ namespace xrpl {
* 1. If `LoanBroker.OwnerCount = 0` the `DirectoryNode` will have at most one
* node (the root), which will only hold entries for `RippleState` or
* `MPToken` objects.
* 2. Under featureLendingProtocolV1_1, an `ltLOAN_BROKER` may only be deleted
* by a `ttLOAN_BROKER_DELETE` transaction, and only when its pre-state
* `OwnerCount` is zero and its pre-state `DebtTotal` rounds to zero at the
* vault's `AssetsTotal` scale, as `LoanBrokerDelete::preclaim` requires.
* 3. At most one `ltLOAN_BROKER` may be deleted in a single transaction.
*
*/
class ValidLoanBroker
@@ -36,6 +41,15 @@ class ValidLoanBroker
// pseudo-accounts. Key is the brokerID / index. It will be used to find the
// LoanBroker object if brokerBefore and brokerAfter are nullptr
std::map<uint256, BrokerInfo> brokers_;
// The broker whose ledger entry was deleted by this transaction, if any.
// Only ttLOAN_BROKER_DELETE removes a broker, and it removes exactly one.
// This is the pre-transaction state, which is what LoanBrokerDelete::preclaim
// reads when it decides whether the broker may be deleted, so the deletion invariants inspect
// the same DebtTotal and OwnerCount that the transactor did.
SLE::const_pointer deletedBroker_ = nullptr;
// Set if visitEntry observes more than one ltLOAN_BROKER deletion in the
// same transaction. Enforced as its own invariant in finalize.
bool multipleBrokerDeletions_ = false;
// Collect all the modified trust lines. Their high and low accounts will be
// loaded to look for LoanBroker pseudo-accounts.
std::vector<SLE::const_pointer> lines_;

View File

@@ -15,9 +15,33 @@ namespace xrpl {
/**
* @brief Invariants: Loans are internally consistent
*
* 1. If `Loan.PaymentRemaining = 0` then `Loan.PrincipalOutstanding = 0`
* 1. If `Loan.PaymentRemaining = 0` then `Loan.PrincipalOutstanding = 0`.
* 2. A newly-created Loan against a closed-ended vault must satisfy
* `StartDate + PaymentInterval * PaymentRemaining < Vault.RedemptionDate`.
* 3. An `ltLOAN` may only be created by a `ttLOAN_SET` transaction.
* 4. Prior to `featureLendingProtocolV1_1`, the `lsfLoanOverpayment` flag on a
* Loan must not change. From `featureLendingProtocolV1_1` onward the same
* rule is enforced by `NoModifiedUnmodifiableFields`.
* 5. Under `featureLendingProtocolV1_1`:
* a. An `ltLOAN` may only be deleted by a `ttLOAN_DELETE` transaction.
* b. If `Loan.PaymentRemaining = 0` then `Loan.NextPaymentDueDate = 0`.
* c. The `lsfLoanImpaired` flag may only change through a `ttLOAN_MANAGE`
* or `ttLOAN_PAY` transaction.
* d. The `lsfLoanDefault` flag may only change through a `ttLOAN_MANAGE`
* transaction. Combined with `NoModifiedUnmodifiableFields`, which
* rejects any clearing of `lsfLoanDefault`, this makes the flag
* write-once: `ttLOAN_MANAGE` may set it, and no transaction may
* clear it.
* e. Interest due, computed as `TotalValueOutstanding -
* PrincipalOutstanding - ManagementFeeOutstanding`, must not be
* negative.
* f. A Loan must reference a live `ltLOAN_BROKER`, and that broker must
* reference a live `ltVAULT`.
* g. Post-conditions for the Loan paid down by a successful `ttLOAN_PAY`:
* `PaymentRemaining > 0` after: `PrincipalOutstanding` and
* `PaymentRemaining` strictly decrease; `NextPaymentDueDate`
* advances by N * `PaymentInterval`, N > 0.
* `PaymentRemaining == 0` after: pinned by checks 1 and 5b.
*
*/
class ValidLoan
@@ -25,6 +49,9 @@ class ValidLoan
// Pair is <before, after>. After is used for most of the checks, except
// those that check changed values.
std::vector<std::pair<SLE::const_pointer, SLE::const_pointer>> loans_;
// Loans removed from the ledger, in the same <before, after> form as loans_.
// Note that `after` holds the erased entry, so it is not null.
std::vector<std::pair<SLE::const_pointer, SLE::const_pointer>> deletedLoans_;
public:
void

View File

@@ -215,6 +215,13 @@ class ValidMPTTransfer
// Deleted MPToken
// MPToken key: true if MPTAuthorized is set
hash_map<uint256, bool> deletedAuthorized_;
// Every touched AccountRoot (not only pseudos):
// AccountID -> whether it was a pseudo-account BEFORE this transaction
// applied. Needed because a transaction may erase a pseudo-account and
// move MPT out of it in the same transaction; by finalize() time the
// view no longer shows it as a pseudo-account (or as existing at all).
// False entries freeze the pre-tx classification for touched non-pseudos.
hash_map<AccountID, bool> pseudoAccountsBefore_;
public:
/**

View File

@@ -48,7 +48,10 @@ namespace xrpl {
* vault phase is Investment
*
* Immutability of VaultKind, SubscriptionDate and RedemptionDate is enforced
* by NoModifiedUnmodifiableFields (see InvariantCheck.cpp).
* by NoModifiedUnmodifiableFields (see InvariantCheck.cpp). From
* featureLendingProtocolV1_1 onwards, immutability of the vault's Asset,
* pseudo-account and ShareMPTID is likewise enforced by
* NoModifiedUnmodifiableFields; prior to that amendment it is checked here.
*/
class ValidVault
{
@@ -128,20 +131,57 @@ private:
deltaAssets(AccountID const& id) const;
/**
* @brief Return the vault-asset delta for the transaction's sending
* account, adjusted for the fee.
* @brief Return the AccountRoot whose XRP balance actually absorbed a
* transaction's fee, if any.
*
* Calls @c deltaAssets for @c tx[sfAccount] and, for non-delegated XRP
* transactions, adds the consumed fee back so the invariant sees the net
* asset movement rather than the fee-reduced balance change.
* Mirrors @c Transactor::getFeePayer, but resolves to @c std::nullopt for
* a pre-funded sponsorship: that fee is drawn from the @c ltSponsorship
* object's @c sfFeeAmount, never from the sponsor's own AccountRoot, so
* there is no balance to add back there.
*
* @param tx The transaction being applied.
* @param fee Fee charged by this transaction.
* @param view Read-only view of the ledger after the transaction.
* @param tx The transaction being applied.
* @return The fee-paying AccountRoot's id, or @c std::nullopt when the
* fee was not drawn from any AccountRoot balance.
*/
[[nodiscard]] static std::optional<AccountID>
feePayerAccountRoot(ReadView const& view, STTx const& tx);
/**
* @brief Return the vault-asset delta for a party inspected as a
* withdrawal/deposit counterparty, adjusted for the fee.
*
* Calls @c deltaAssets for @p id and, for XRP transactions, adds the
* consumed fee back only when @p id is the AccountRoot that actually
* paid it (per @c feePayerAccountRoot) -- so the invariant sees the net
* asset movement rather than a fee-reduced balance change, regardless of
* whether @p id is the sender, a distinct destination, a delegate, or a
* co-signed fee sponsor. Post-@c fixCleanup3_4_0, any resulting
* economically-zero delta is always normalized to absence.
*
* Pre-@c fixCleanup3_4_0 this replicates the legacy behaviour exactly:
* only @c tx[sfAccount] could ever receive a fee correction (and only
* when it was itself, per @c STTx::getFeePayerID, the fee payer). After
* that sender-only correction a zero delta is collapsed to absence; if
* the correction does not apply, a present-zero delta is kept as-is.
*
* @param view Read-only view of the ledger after the transaction.
* @param id Account being inspected as sender or destination.
* @param tx The transaction being applied.
* @param fee Fee charged by this transaction.
* @param fix340Enabled Whether @c fixCleanup3_4_0 is enabled, as already
* determined once by @c finalize.
* @return The fee-adjusted delta, or @c std::nullopt if the net delta is
* zero or the account entry was not touched.
* zero (always post-amendment; pre-amendment only after the
* sender-only fee correction) or the entry was not touched.
*/
[[nodiscard]] std::optional<DeltaInfo>
deltaAssetsTxAccount(STTx const& tx, XRPAmount fee) const;
deltaAssetsForParty(
ReadView const& view,
AccountID const& id,
STTx const& tx,
XRPAmount fee,
bool fix340Enabled) const;
/**
* @brief Return the vault-share balance-change delta for an account.
@@ -171,8 +211,8 @@ private:
*
* For a closed-ended vault, a loan may only be originated while the vault is in the Investment
* phase (strictly past @c SubscriptionDate and before @c RedemptionDate). Open-ended vaults (@c
* NoPhase) are unaffected. The complementary maturity bound (final payment strictly precedes @c
* RedemptionDate) is enforced by @c ValidLoan.
* NoPhase) are unaffected. The complementary maturity bound (final payment precedes @c
* RedemptionDate by at least @c kLoanRedemptionBuffer) is enforced by @c ValidLoan.
*/
[[nodiscard]] bool
finalizeLoanSet(ReadView const& view, beast::Journal const& j) const;

View File

@@ -109,6 +109,11 @@ public:
* @param lpTokens current LPT balance
* @param lpTokensWithdraw amount of tokens to withdraw
* @param tfee trading fee in basis points
* @param freezeHandling whether a frozen balance is reported as zero
* @param authHandling whether an unauthorized MPT balance is reported as
* zero
* @param reserveHandling whether the recipient owner-reserve check is
* enforced when a trustline or MPToken has to be auto-created
* @param withdrawAll if withdrawing all lptokens
* @param priorBalance balance before fees
* @return
@@ -128,6 +133,7 @@ public:
std::uint16_t tfee,
FreezeHandling freezeHandling,
AuthHandling authHandling,
ReserveHandling reserveHandling,
WithdrawAll withdrawAll,
XRPAmount const& priorBalance,
beast::Journal const& journal);
@@ -150,6 +156,11 @@ public:
* @param lpTokensAMMBalance current AMM LPT balance
* @param lpTokensWithdraw amount of lptokens to withdraw
* @param tfee trading fee in basis points
* @param freezeHandling whether a frozen balance is reported as zero
* @param authHandling whether an unauthorized MPT balance is reported as
* zero
* @param reserveHandling whether the recipient owner-reserve check is
* enforced when a trustline or MPToken has to be auto-created
* @param withdrawAll if withdraw all lptokens
* @param priorBalance balance before fees
* @return
@@ -169,6 +180,7 @@ public:
std::uint16_t tfee,
FreezeHandling freezeHandling,
AuthHandling authHandling,
ReserveHandling reserveHandling,
WithdrawAll withdrawAll,
XRPAmount const& priorBalance,
beast::Journal const& journal);