CredentialCreate::preclaim already rejects a pseudo-account Subject via a
separate amendment merged into develop while this branch was in review.
Drop the duplicate check added here and keep only the credential cleanup
this branch is actually for.
Adjust the Vault, LoanBroker, and AMM tests to build the pre-existing pin
with that other amendment disabled instead of this one, and drop the
now-redundant assertions that a new pin gets rejected -- that is covered
elsewhere now.
Add an overflow test for LoanBroker mirroring the existing Vault one,
exercising the tecINCOMPLETE branch a reviewer flagged as uncovered.
Fix an unrelated SeqProxy/namespace-rename mismatch in LoanBroker_test.cpp
introduced by the same develop merge, and rewrite comments across the
changed files to describe the rule rather than name the amendment or
ticket.
* upstream/release/3.3.x: (41 commits)
chore: Bump version to 3.3.0
chore: Bump version to 3.3.0-rc7
fix: Increase manifest protocol message size cap and fix manifests relay
fix: Cap untrusted manifests per message and drop oversized ones
chore: Bump version to 3.2.1
chore: Bump version to 3.2.1-rc1
fix: Cap untrusted manifests per message and drop oversized ones
fix: Reject oversized validator manifest before decoding
fix: Reduce untrusted manifest cache cap to 100
fix: Bound untrusted manifest cache
chore: Bump version to 3.3.0-rc6
feat: Package validator-keys inside rippled
chore: Bump version to 3.3.0-rc5
fix: Switch SponsorshipSet to use a delta for sfFeeAmount
fix: Re-revert "fix: Set request size limits and differential pricing for get-object-by-hash calls"
chore: Bump version to 3.3.0-rc4
fix: Revert "fix: Set request size limits and differential pricing for get-object-by-hash calls"
chore: Bump version to 3.3.0-rc3
fix: Reduce untrusted manifest cache cap to 100
fix: Revert "fix: Reject oversized SHAMap nodes in gotStaleData and fetch-pack path"
...
CredentialCreate accepted any existing Subject, including Vault, LoanBroker, and
AMM pseudo-accounts. A pseudo-account can't sign, so it can never accept or
delete a credential issued to it; the unaccepted credential stays pinned in the
pseudo-account's owner directory and blocks deletion of the owning object,
locking it and its owner reserve indefinitely.
Behind fixCleanup3_4_0:
- CredentialCreate::preclaim rejects a pseudo-account Subject with
tecPSEUDO_ACCOUNT.
- VaultDelete and LoanBrokerDelete remove any credentials pinned to the
pseudo-account before deleting it.
- isOnlyLiquidityProvider ignores credential entries and deleteAMMAccount removes
them, so an AMM pinned before the amendment can still be withdrawn and deleted.
This clears objects pinned before the amendment and prevents new pins after it.
Co-authored-by: xrplf-ai-reviewer[bot] <266832837+xrplf-ai-reviewer[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>