From 8180336145d00a3a36f28d4f27326697674e12ce Mon Sep 17 00:00:00 2001 From: Nicholas Dudfield Date: Thu, 16 Jul 2026 19:11:21 +0700 Subject: [PATCH] docs(export): separate admission and publication clocks --- src/xrpld/app/consensus/ExportIntent.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/src/xrpld/app/consensus/ExportIntent.md b/src/xrpld/app/consensus/ExportIntent.md index 0cb4ebbb3..989cf5d43 100644 --- a/src/xrpld/app/consensus/ExportIntent.md +++ b/src/xrpld/app/consensus/ExportIntent.md @@ -22,6 +22,10 @@ account, destination TicketSequence, reserved origin Memo, and bounded timing fields. Successful apply creates a durable origin-keyed latch. It does not claim that signatures or a witness already exist. +The outer transaction's mandatory `sfLastLedgerSequence` bounds only intent +admission. Successful admission starts a separate publication lifetime on the +new latch; queue delay before admission never consumes that publication window. + *Anti-pattern:* treating provisional open-ledger execution or source transaction-set agreement as authorization to release destination signatures. @@ -46,6 +50,12 @@ deletion guard and witness apply's committee lookup are one load-bearing invariant: do not weaken the guard to pending-only while latches retain only a committee digest. +A live Export latch is itself a non-deletable account obligation: an account +owning any latch cannot be deleted. The committee SLE is otherwise a deletable +owned entry. Its required survival while latches exist comes from the explicit +committee-deletion guard together with the account-level latch obligation, not +from making the committee intrinsically non-deletable. + **INV-3 - qC and qV answer different questions.** qC is the content threshold for one account-selected committee: `ceil(0.8 * committeeSize)`. The intent cannot lower it. Committee positions @@ -208,6 +218,17 @@ window after ordinary transaction-set convergence, but timeout always permits base consensus to continue. Below-qC or unaligned work remains pending until witness, cancellation, explicit erase, or publication expiry. +The admission and publication clocks are distinct. The outer +`sfLastLedgerSequence` follows ordinary inclusive transaction admission and may +be at most `maxAdmissionWindowLedgers` beyond the ledger evaluating the intent. +On successful apply, the latch stores an independent inclusive publication +deadline of `admittingLedger + maxPublicationLedgers`; it never copies the +outer deadline. That final candidate ledger may still publish and materialize a +witness. After it, no new witness material is eligible. Later paid Export work +deterministically but lazily removes the expired pending-work link. Expiry does +not revoke released signatures or erase the latch: owner reserve and callback +readiness remain until symmetric completion or explicit erase. + **INV-13 - Return callbacks remain owner-authorized Imports.** An XPOP whose proven target transaction carries `sfTicketSequence` takes the Export callback path only while both Import and Export are enabled. The outer