From bfefe4eb5eb8bdde7d99b2946498ab7d02653d5c Mon Sep 17 00:00:00 2001 From: Nicholas Dudfield Date: Mon, 31 Aug 2026 14:35:33 +0700 Subject: [PATCH] docs(manifest): describe thin signing index --- src/xrpld/app/consensus/RCLValidations.cpp | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/src/xrpld/app/consensus/RCLValidations.cpp b/src/xrpld/app/consensus/RCLValidations.cpp index 4cc77393d4..bbaa3a93ee 100644 --- a/src/xrpld/app/consensus/RCLValidations.cpp +++ b/src/xrpld/app/consensus/RCLValidations.cpp @@ -180,10 +180,13 @@ handleNewValidation( auto const seq = val->getFieldU32(sfLedgerSequence); // A validator that rotated its ephemeral key while this node was not - // listening signs with a key no held manifest mentions, which is - // indistinguishable from a validator this node has never heard of. Every - // manifest published on-chain is written at its ephemeral keylet as well - // as its master one, so that binding is recoverable in a single read. + // listening may sign with a key absent from every manifest held here. That + // is indistinguishable from a validator this node has never heard of. Every + // manifest published on-chain has a thin signing-key index pointing to its + // canonical master-key object, so that binding takes two bounded reads. + // This is a rare cold-cache fallback: manifest gossip and canonical-wrapper + // harvesting normally populate the mapping first. It is mainly needed at + // startup, after missed propagation, or after local cache loss. // // Done here rather than left to the next consensus round, because // ManifestCache::applyLedger() runs there against the master keys already