diff --git a/src/xrpld/app/consensus/RCLValidations.cpp b/src/xrpld/app/consensus/RCLValidations.cpp index 4cc77393d4..bbaa3a93ee 100644 --- a/src/xrpld/app/consensus/RCLValidations.cpp +++ b/src/xrpld/app/consensus/RCLValidations.cpp @@ -180,10 +180,13 @@ handleNewValidation( auto const seq = val->getFieldU32(sfLedgerSequence); // A validator that rotated its ephemeral key while this node was not - // listening signs with a key no held manifest mentions, which is - // indistinguishable from a validator this node has never heard of. Every - // manifest published on-chain is written at its ephemeral keylet as well - // as its master one, so that binding is recoverable in a single read. + // listening may sign with a key absent from every manifest held here. That + // is indistinguishable from a validator this node has never heard of. Every + // manifest published on-chain has a thin signing-key index pointing to its + // canonical master-key object, so that binding takes two bounded reads. + // This is a rare cold-cache fallback: manifest gossip and canonical-wrapper + // harvesting normally populate the mapping first. It is mainly needed at + // startup, after missed propagation, or after local cache loss. // // Done here rather than left to the next consensus round, because // ManifestCache::applyLedger() runs there against the master keys already