mirror of
https://github.com/XRPLF/rippled.git
synced 2026-04-29 15:37:57 +00:00
Merge remote-tracking branch 'mywork/ximinez/lending-number' into ximinez/lending-XLS-66
* mywork/ximinez/lending-number: Add a distinction between a "valid" and a "representable" Number chore: Point xrpld symlink to rippled (6012) Catch up the consequences of Number changes Fix build error - avoid copy Add integer enforcement when converting to XRP/MPTAmount to Number Make all STNumber fields "soeDEFAULT" Add optional enforcement of valid integer range to Number
This commit is contained in:
@@ -227,6 +227,8 @@ Number::checkInteger(char const* what) const
|
||||
{
|
||||
if (enforceInteger_ == strong && !valid())
|
||||
throw std::overflow_error(what);
|
||||
if (enforceInteger_ == weak && !representable())
|
||||
throw std::overflow_error(what);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -273,7 +275,20 @@ Number::normalize()
|
||||
bool
|
||||
Number::valid() const noexcept
|
||||
{
|
||||
if (enforceInteger_ != none)
|
||||
return valid(enforceInteger_);
|
||||
}
|
||||
|
||||
bool
|
||||
Number::valid(EnforceInteger enforce)
|
||||
{
|
||||
setIntegerEnforcement(enforce);
|
||||
return valid();
|
||||
}
|
||||
|
||||
bool
|
||||
Number::valid(EnforceInteger enforce) const
|
||||
{
|
||||
if (enforce != none)
|
||||
{
|
||||
static Number const max = maxIntValue;
|
||||
static Number const maxNeg = -maxIntValue;
|
||||
@@ -285,6 +300,21 @@ Number::valid() const noexcept
|
||||
return true;
|
||||
}
|
||||
|
||||
bool
|
||||
Number::representable() const noexcept
|
||||
{
|
||||
if (enforceInteger_ != none)
|
||||
{
|
||||
static Number const max = maxMantissa;
|
||||
static Number const maxNeg = -maxMantissa;
|
||||
// Avoid making a copy
|
||||
if (mantissa_ < 0)
|
||||
return *this >= maxNeg;
|
||||
return *this <= max;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
Number&
|
||||
Number::operator+=(Number const& y)
|
||||
{
|
||||
|
||||
@@ -3481,6 +3481,8 @@ assetsToSharesDeposit(
|
||||
|
||||
Number const assetTotal = vault->at(sfAssetsTotal);
|
||||
STAmount shares{vault->at(sfShareMPTID)};
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
shares.setIntegerEnforcement(Number::weak);
|
||||
if (assetTotal == 0)
|
||||
return STAmount{
|
||||
@@ -3513,6 +3515,8 @@ sharesToAssetsDeposit(
|
||||
|
||||
Number const assetTotal = vault->at(sfAssetsTotal);
|
||||
STAmount assets{vault->at(sfAsset)};
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
assets.setIntegerEnforcement(Number::weak);
|
||||
if (assetTotal == 0)
|
||||
return STAmount{
|
||||
@@ -3547,6 +3551,8 @@ assetsToSharesWithdraw(
|
||||
Number assetTotal = vault->at(sfAssetsTotal);
|
||||
assetTotal -= vault->at(sfLossUnrealized);
|
||||
STAmount shares{vault->at(sfShareMPTID)};
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
shares.setIntegerEnforcement(Number::weak);
|
||||
if (assetTotal == 0)
|
||||
return shares;
|
||||
@@ -3578,6 +3584,8 @@ sharesToAssetsWithdraw(
|
||||
Number assetTotal = vault->at(sfAssetsTotal);
|
||||
assetTotal -= vault->at(sfLossUnrealized);
|
||||
STAmount assets{vault->at(sfAsset)};
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
assets.setIntegerEnforcement(Number::weak);
|
||||
if (assetTotal == 0)
|
||||
return assets;
|
||||
|
||||
@@ -270,7 +270,9 @@ STAmount::integerEnforcement() const noexcept
|
||||
bool
|
||||
STAmount::validNumber() const noexcept
|
||||
{
|
||||
Number n = toNumber(Number::EnforceInteger::weak);
|
||||
// compatible will not throw. IOUs will ignore the flag, and will
|
||||
// always be valid.
|
||||
Number n = toNumber(Number::EnforceInteger::compatible);
|
||||
return n.valid();
|
||||
}
|
||||
|
||||
|
||||
@@ -3646,7 +3646,7 @@ class Vault_test : public beast::unit_test::suite
|
||||
}
|
||||
});
|
||||
|
||||
testCase(14, [&, this](Env& env, Data d) {
|
||||
testCase(13, [&, this](Env& env, Data d) {
|
||||
testcase("MPT scale deposit overflow on first deposit");
|
||||
auto tx = d.vault.deposit(
|
||||
{.depositor = d.depositor,
|
||||
@@ -3656,7 +3656,7 @@ class Vault_test : public beast::unit_test::suite
|
||||
env.close();
|
||||
});
|
||||
|
||||
testCase(14, [&, this](Env& env, Data d) {
|
||||
testCase(13, [&, this](Env& env, Data d) {
|
||||
testcase("MPT scale deposit overflow on second deposit");
|
||||
|
||||
{
|
||||
@@ -3678,7 +3678,7 @@ class Vault_test : public beast::unit_test::suite
|
||||
}
|
||||
});
|
||||
|
||||
testCase(14, [&, this](Env& env, Data d) {
|
||||
testCase(13, [&, this](Env& env, Data d) {
|
||||
testcase("No MPT scale deposit overflow on total shares");
|
||||
|
||||
{
|
||||
@@ -3998,7 +3998,7 @@ class Vault_test : public beast::unit_test::suite
|
||||
}
|
||||
});
|
||||
|
||||
testCase(14, [&, this](Env& env, Data d) {
|
||||
testCase(13, [&, this](Env& env, Data d) {
|
||||
testcase("MPT scale withdraw overflow");
|
||||
|
||||
{
|
||||
@@ -4239,7 +4239,7 @@ class Vault_test : public beast::unit_test::suite
|
||||
}
|
||||
});
|
||||
|
||||
testCase(14, [&, this](Env& env, Data d) {
|
||||
testCase(13, [&, this](Env& env, Data d) {
|
||||
testcase("MPT Scale clawback overflow");
|
||||
|
||||
{
|
||||
|
||||
@@ -846,28 +846,87 @@ public:
|
||||
Number a{100};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::none);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{1, 30};
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = -100;
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
{
|
||||
Number a{100, Number::compatible};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::compatible);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{1, 15};
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{1, 30, Number::none};
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
a = -100;
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::compatible);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{5, Number::weak};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::weak);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{5, Number::strong};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::strong);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
{
|
||||
Number a{100, Number::weak};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::weak);
|
||||
BEAST_EXPECT(a.valid());
|
||||
a = Number{1, 30, Number::none};
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{1, 15};
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
try
|
||||
{
|
||||
a = Number{1, 30, Number::compatible};
|
||||
BEAST_EXPECT(false);
|
||||
}
|
||||
catch (std::overflow_error const& e)
|
||||
{
|
||||
BEAST_EXPECT(e.what() == "Number::operator= integer overflow"s);
|
||||
// The throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT((a == Number{1, 30}));
|
||||
}
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::weak);
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
a = -100;
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::weak);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
a = Number{5, Number::strong};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::strong);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
{
|
||||
Number a{100, Number::strong};
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::strong);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
try
|
||||
{
|
||||
a = Number{1, 15, Number::compatible};
|
||||
BEAST_EXPECT(false);
|
||||
}
|
||||
catch (std::overflow_error const& e)
|
||||
{
|
||||
BEAST_EXPECT(e.what() == "Number::operator= integer overflow"s);
|
||||
// The throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT((a == Number{1, 15}));
|
||||
}
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
try
|
||||
{
|
||||
a = Number{1, 30};
|
||||
@@ -880,15 +939,19 @@ public:
|
||||
BEAST_EXPECT((a == Number{1, 30}));
|
||||
}
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
a = -100;
|
||||
BEAST_EXPECT(a.integerEnforcement() == Number::strong);
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
{
|
||||
Number a{INITIAL_XRP.drops(), Number::weak};
|
||||
Number a{INITIAL_XRP.drops(), Number::compatible};
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
a = -a;
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
|
||||
try
|
||||
{
|
||||
@@ -904,6 +967,7 @@ public:
|
||||
// assigned to the Number
|
||||
BEAST_EXPECT(a == -INITIAL_XRP);
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
}
|
||||
try
|
||||
{
|
||||
@@ -917,6 +981,7 @@ public:
|
||||
// assigned to the Number
|
||||
BEAST_EXPECT(a == -INITIAL_XRP);
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
}
|
||||
a = Number::maxIntValue;
|
||||
try
|
||||
@@ -930,6 +995,7 @@ public:
|
||||
// This time, the throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT(a == Number::maxIntValue + 1);
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
a = -Number::maxIntValue;
|
||||
try
|
||||
@@ -943,6 +1009,7 @@ public:
|
||||
// This time, the throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT(a == -Number::maxIntValue - 1);
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
a = Number(1, 10);
|
||||
try
|
||||
@@ -957,6 +1024,7 @@ public:
|
||||
// The throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT((a == Number{1, 20}));
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
}
|
||||
try
|
||||
{
|
||||
@@ -969,6 +1037,7 @@ public:
|
||||
// The throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT((a == Number::maxIntValue * 2));
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
try
|
||||
{
|
||||
@@ -981,6 +1050,7 @@ public:
|
||||
// The Number doesn't get updated because the ctor throws
|
||||
BEAST_EXPECT((a == Number::maxIntValue * 2));
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
a = Number(1, 10);
|
||||
try
|
||||
@@ -994,10 +1064,12 @@ public:
|
||||
// The throw is done _after_ the number is updated.
|
||||
BEAST_EXPECT((a == Number{1, 20}));
|
||||
BEAST_EXPECT(!a.valid());
|
||||
BEAST_EXPECT(!a.representable());
|
||||
}
|
||||
a /= Number(1, 15);
|
||||
BEAST_EXPECT((a == Number{1, 5}));
|
||||
BEAST_EXPECT(a.valid());
|
||||
BEAST_EXPECT(a.representable());
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -2532,6 +2532,13 @@ ValidVault::Vault::make(SLE const& from)
|
||||
self.assetsAvailable = from.at(sfAssetsAvailable);
|
||||
self.assetsMaximum = from.at(sfAssetsMaximum);
|
||||
self.lossUnrealized = from.at(sfLossUnrealized);
|
||||
if (self.asset.integral())
|
||||
{
|
||||
self.assetsTotal.setIntegerEnforcement(Number::compatible);
|
||||
self.assetsAvailable.setIntegerEnforcement(Number::compatible);
|
||||
self.assetsMaximum.setIntegerEnforcement(Number::compatible);
|
||||
self.lossUnrealized.setIntegerEnforcement(Number::compatible);
|
||||
}
|
||||
return self;
|
||||
}
|
||||
|
||||
@@ -2766,6 +2773,19 @@ ValidVault::finalize(
|
||||
beforeVault_.empty() || beforeVault_[0].key == afterVault.key,
|
||||
"ripple::ValidVault::finalize : single vault operation");
|
||||
|
||||
if (!afterVault.assetsTotal.representable() ||
|
||||
!afterVault.assetsAvailable.representable() ||
|
||||
!afterVault.assetsMaximum.representable() ||
|
||||
!afterVault.lossUnrealized.representable())
|
||||
{
|
||||
JLOG(j.fatal()) << "Invariant failed: vault overflowed maximum current "
|
||||
"representable integer value";
|
||||
XRPL_ASSERT(
|
||||
enforce,
|
||||
"ripple::ValidVault::finalize : vault integer limit invariant");
|
||||
return !enforce; // That's all we can do here
|
||||
}
|
||||
|
||||
auto const updatedShares = [&]() -> std::optional<Shares> {
|
||||
// At this moment we only know that a vault is being updated and there
|
||||
// might be some MPTokenIssuance objects which are also updated in the
|
||||
|
||||
@@ -150,8 +150,11 @@ VaultClawback::doApply()
|
||||
amount.asset() == vaultAsset,
|
||||
"ripple::VaultClawback::doApply : matching asset");
|
||||
|
||||
// Both of these values are going to be decreased in this transaction,
|
||||
// so the limit doesn't really matter.
|
||||
auto assetsAvailable = vault->at(sfAssetsAvailable);
|
||||
auto assetsTotal = vault->at(sfAssetsTotal);
|
||||
|
||||
[[maybe_unused]] auto const lossUnrealized = vault->at(sfLossUnrealized);
|
||||
XRPL_ASSERT(
|
||||
lossUnrealized <= (assetsTotal - assetsAvailable),
|
||||
@@ -161,6 +164,8 @@ VaultClawback::doApply()
|
||||
MPTIssue const share{mptIssuanceID};
|
||||
STAmount sharesDestroyed = {share};
|
||||
STAmount assetsRecovered;
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
assetsRecovered.setIntegerEnforcement(Number::weak);
|
||||
sharesDestroyed.setIntegerEnforcement(Number::weak);
|
||||
try
|
||||
|
||||
@@ -213,6 +213,13 @@ VaultCreate::doApply()
|
||||
vault->at(sfWithdrawalPolicy) = vaultStrategyFirstComeFirstServe;
|
||||
if (scale)
|
||||
vault->at(sfScale) = scale;
|
||||
if (asset.integral())
|
||||
{
|
||||
// Only the Maximum can be a non-zero value, so only it needs to be
|
||||
// checked.
|
||||
if (!vault->at(sfAssetsMaximum).value().valid(Number::compatible))
|
||||
return tecLIMIT_EXCEEDED;
|
||||
}
|
||||
view().insert(vault);
|
||||
|
||||
// Explicitly create MPToken for the vault owner
|
||||
|
||||
@@ -220,6 +220,8 @@ VaultDeposit::doApply()
|
||||
}
|
||||
|
||||
STAmount sharesCreated = {vault->at(sfShareMPTID)}, assetsDeposited;
|
||||
// STAmount will ignore enforcement for IOUs, so we can set it regardless of
|
||||
// type.
|
||||
sharesCreated.setIntegerEnforcement(Number::weak);
|
||||
try
|
||||
{
|
||||
|
||||
@@ -147,6 +147,11 @@ VaultSet::doApply()
|
||||
tx[sfAssetsMaximum] < *vault->at(sfAssetsTotal))
|
||||
return tecLIMIT_EXCEEDED;
|
||||
vault->at(sfAssetsMaximum) = tx[sfAssetsMaximum];
|
||||
if (vault->at(sfAsset).value().integral())
|
||||
{
|
||||
if (!vault->at(sfAssetsMaximum).value().valid(Number::compatible))
|
||||
return tecLIMIT_EXCEEDED;
|
||||
}
|
||||
}
|
||||
|
||||
if (auto const domainId = tx[~sfDomainID]; domainId)
|
||||
|
||||
@@ -207,6 +207,8 @@ VaultWithdraw::doApply()
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
}
|
||||
|
||||
// These values are only going to decrease, and can't be less than 0, so
|
||||
// there's no need for integer range enforcement.
|
||||
auto assetsAvailable = vault->at(sfAssetsAvailable);
|
||||
auto assetsTotal = vault->at(sfAssetsTotal);
|
||||
[[maybe_unused]] auto const lossUnrealized = vault->at(sfLossUnrealized);
|
||||
|
||||
Reference in New Issue
Block a user