mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-29 08:18:01 +00:00
sfAssetsTotal is stored on a coarser STAmount grid than sfAssetsAvailable and the vault's trust line, so adding the same amount to all three quantizes differently on each and leaves the vault's books disagreeing with its actual holdings by a sub-ULP amount. Fix by clamping the credited/withdrawn amount to what sfAssetsTotal can represent before applying it to the other rails, via a shared clampToAssetsTotalScale helper used by all three transactors. - Deposit: clamp assetsDeposited downward to the assetsTotal grid, then re-derive shares from the clamped amount so the depositor cannot receive shares worth more than they paid. Return tecPRECISION_LOSS if the clamp rounds the deposit to zero. - Withdraw: clamp assetsWithdrawn upward (i.e. the vault pays out slightly less) so it never pays out more than it can account for. Shares are not re-derived, so the withdrawer receives slightly less per share, favouring remaining holders. - Clawback: same pattern as withdraw, guarded on assetsRecovered > 0 and placed after the existing clamp-to-available. Gated on fixCleanup3_4_0.