mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-27 15:28:03 +00:00
`NodePathStack`'s position and depth checks were `XRPL_ASSERT_IF`s, which are stripped under `NDEBUG`, so a release build walked on with a node sitting where it did not belong. Each is now a live test that refuses the push and lets the caller stop, and each reports `SOMETIMES` rather than `UNREACHABLE`: a node resolved from the local store reaches a walk through `descend(parent, branch)`, which fetches by the parent's recorded child hash and judges neither position nor type, so external data can reach either case and neither may abort a build. Every path that does know the position now judges a node before hooking it: the two filter descents and the deferred-read hook, each marking the map invalid the way `addKnownNode` already did. `getMissingNodes` no longer calls `clearSynching()` on a map it has condemned, at either of its two returns, since that would move the state to `Modifying` and erase the verdict. `gmnProcessDeferredReads` became non-static so it can record one. `boundHelper` now throws where it used to answer `end()`. An empty map still leaves its root on the path, so an empty path means only that a node was refused, while `end()` is the positive claim that no key lies on the requested side of the key asked for. New `SHAMapMisplacedLeaf` tests build a tree whose hashes agree but whose leaf sits under the wrong branch, drive it in through both acquisition routes, and check that iteration and both bounds refuse it.