Derive credits from the Downward-rounded posterior total so an off-grid
sfAssetsTotal cannot over-credit the depositor's payment, and round
debits down at that same posterior scale so decade-boundary amounts
that are representable after the tx succeed in full.
Mirrors the equivalent guard already applied to VaultWithdraw: wrap
the dust check in try/catch so a sufficiently abused sfScale pushing
assetsTotal/assetsAvailable out of STAmount's representable range
returns tecPATH_DRY instead of surfacing as a raw overflow_error.
Also address other outstanding review nits: fix
VaultTransactorPrecision_test's suite module (tx -> app, matching
every other Vault suite), replace the "PR 2" comment in
VaultPrecisionFixture.h with a stable description, and tighten the
clampToAssetsTotalScale docstring in VaultHelpers.h.
The clamp block added in VaultWithdraw::doApply unconditionally returned
tecPRECISION_LOSS when the clamped payout was zero. That undid the
develop-side guard that deliberately permits fixed-share zero-asset
withdrawals in a fully-impaired vault (assetsTotalForWithdrawal == 0),
causing xrpl.tx.LoanRounding to fail on all three build-test configs
(linux-clang, linux-gcc-coverage, windows). Skip the clamp when
assetsWithdrawn is already zero, and also on the final-withdrawal path
where the value is overwritten with sfAssetsAvailable a few lines later.
Also addresses review feedback:
- Correct clampToAssetsTotalScale docstring to reflect that it returns a
non-negative magnitude; the caller applies the sign.
- Add XRPL_ASSERT precondition matching sibling helpers, and canonicalize
totalBefore/totalAfter under a single NumberRoundModeGuard so the
returned delta reflects only `delta`, not a rounding difference between
the two endpoints.
- Move VaultPrecisionFixture.h and VaultTransactorPrecision_test.cpp
from src/test/app/lending/ to src/test/app/vault/ so vault tests live
alongside the other vault-specific suites.
- Simplify inline commentary across VaultDeposit/VaultWithdraw/
VaultClawback.
sfAssetsTotal is stored on a coarser STAmount grid than sfAssetsAvailable
and the vault's trust line, so adding the same amount to all three
quantizes differently on each and leaves the vault's books disagreeing
with its actual holdings by a sub-ULP amount. Fix by clamping the
credited/withdrawn amount to what sfAssetsTotal can represent before
applying it to the other rails, via a shared clampToAssetsTotalScale
helper used by all three transactors.
- Deposit: clamp assetsDeposited downward to the assetsTotal grid, then
re-derive shares from the clamped amount so the depositor cannot
receive shares worth more than they paid. Return tecPRECISION_LOSS if
the clamp rounds the deposit to zero.
- Withdraw: clamp assetsWithdrawn upward (i.e. the vault pays out
slightly less) so it never pays out more than it can account for.
Shares are not re-derived, so the withdrawer receives slightly less
per share, favouring remaining holders.
- Clawback: same pattern as withdraw, guarded on assetsRecovered > 0 and
placed after the existing clamp-to-available.
Gated on fixCleanup3_4_0.
* upstream/release/3.3.x: (41 commits)
chore: Bump version to 3.3.0
chore: Bump version to 3.3.0-rc7
fix: Increase manifest protocol message size cap and fix manifests relay
fix: Cap untrusted manifests per message and drop oversized ones
chore: Bump version to 3.2.1
chore: Bump version to 3.2.1-rc1
fix: Cap untrusted manifests per message and drop oversized ones
fix: Reject oversized validator manifest before decoding
fix: Reduce untrusted manifest cache cap to 100
fix: Bound untrusted manifest cache
chore: Bump version to 3.3.0-rc6
feat: Package validator-keys inside rippled
chore: Bump version to 3.3.0-rc5
fix: Switch SponsorshipSet to use a delta for sfFeeAmount
fix: Re-revert "fix: Set request size limits and differential pricing for get-object-by-hash calls"
chore: Bump version to 3.3.0-rc4
fix: Revert "fix: Set request size limits and differential pricing for get-object-by-hash calls"
chore: Bump version to 3.3.0-rc3
fix: Reduce untrusted manifest cache cap to 100
fix: Revert "fix: Reject oversized SHAMap nodes in gotStaleData and fetch-pack path"
...