14266 Commits

Author SHA1 Message Date
onledger.net
22a94c4429 fix(base58): Read characters as unsigned char in b58_to_b256_be (#868) 2026-10-08 23:08:47 +10:00
Alphonse N. Mousse
42a33a224d Fix handling of emitted transactions: (#731) 2026-10-08 18:30:35 +10:00
Fomo
ee33d825fc fix: NULL RWDB and mutex locks (#728) 2026-10-08 16:39:29 +10:00
onledger.net
9ef66a65b8 fix: ReportFeeChange data race, no-subscriber queuing, and LoadManager loop (#785) 2026-10-07 18:26:53 +10:00
Richard Holland
98fdaa4afa UNLReport Fix (#872) 2026-10-07 17:12:19 +10:00
tequ
d9cc66afe9 ci: always run fixed 3-config matrix in nix workflow (#873) 2026-10-07 14:36:37 +10:00
Richard Holland
b260b445e9 Foreign Hook State Touch (#859) 2026-10-06 11:05:49 +10:00
Richard Holland
4e0e108654 On Chain Manifest Canonical Envelope (port from 854) (#862)
Co-authored-by: Niq Dudfield <ndudfield@gmail.com>
2026-10-05 17:05:21 +10:00
tequ
919d817edc Restrict slot_set to keylets (#863) 2026-10-05 15:56:18 +10:00
Richard Holland
0373045bff re-enable ocm (#864) 2026-10-05 15:53:59 +10:00
tequ
2baa23d14b Fix/string plus int warning (#857) 2026-10-05 15:03:40 +10:00
tequ
de9d5e53f1 test: cover BuildInfo::getVersionString (#856)
Add a unit test for getVersionString() / getFullVersionString() so the
generated "<year>.<month>.<day>-CustomBuild" version string is checked
for strict semver round-trip and sane date ranges before touching the
__DATE__ parsing code.
2026-10-05 14:39:12 +10:00
tequ
80c70ec03d Add fix20261005 Amendment placeholder (#860) 2026-10-05 14:08:57 +10:00
Richard Holland
2566bcf6fa EscrowDestinationCancel (#858) 2026-10-04 10:51:15 +10:00
tequ
7f37aeac39 Fix compiler warnings in gcc CI builds and Boost 1.91 deprecation (#855) 2026-10-02 14:41:57 +10:00
Niq Dudfield
21fab66a17 build: bump boost to 1.91.0 and fix beast/asio timeout bugs (#812)
Cherry-picking XRPLF/rippled 1506e65558

Co-authored-by: Alex Kremer <akremer@ripple.com>
2026-10-01 15:32:18 +10:00
Richard Holland
0f3258d235 import exploit fixes (#9)
Co-authored-by: Nicholas Dudfield <ndudfield@gmail.com>
2026-09-29 18:07:37 +10:00
tequ
3fbeb130f8 fix20261001 to fix20260929 (#14) 2026-09-29 17:58:39 +10:00
Richard Holland
58efea062c Offer create exploit fix (#10)
Co-authored-by: tequ <git@tequ.dev>
Co-authored-by: Nicholas Dudfield <ndudfield@gmail.com>
2026-09-29 17:57:50 +10:00
Niq Dudfield
43d90b8549 ci: run the codecov upload and docker release builder only from xahau/xahaud (#13)
* ci: upload coverage to codecov only from xahau/xahaud

* ci: run the docker release builder only from xahau/xahaud
2026-09-29 15:23:04 +10:00
Niq Dudfield
a3bd76fdc9 fix(test): mark skipped SetHookTSH manifest case (#12) 2026-09-29 12:22:47 +10:00
Richard Holland
4de217a2c6 mint exploit fix (#8) 2026-09-29 08:26:29 +10:00
Richard Holland
5e49dc8474 Disable ocm tests (#847) clang
clang
2026-09-29 07:22:32 +10:00
Richard Holland
77e309fff5 disable ocm tests (#846) 2026-09-29 07:15:33 +10:00
Niq Dudfield
79319aaf96 fix(ci): skip docker cleanup when the run has no checkout path (#841) 2026-09-29 05:40:39 +10:00
tequ
a5163eeb50 Extract Transactor::finishApply from Transactor::operator() (#843)
Pure move of the post-apply pipeline (tec handling, invariants,
balance rewards, weak hooks, commit) into a helper so it can be
invoked more than once. No behaviour change.
2026-09-29 05:39:57 +10:00
Richard Holland
3bc435864f disable onchainmanifests for this release (#845) 2026-09-29 05:35:30 +10:00
tequ
4d08a9e603 etxn_fee_base: compute the fee against the applied view (fix20261001) (#842) 2026-09-29 05:02:37 +10:00
Niq Dudfield
f155556017 test(jtx): reconnect the JSON-RPC client when the server closed it (#840) 2026-09-29 04:59:03 +10:00
tequ
c4570a699f Move isValidUTF8 to xrpl/basics and its unit test to test/basics (#834) 2026-09-28 11:50:07 +10:00
tequ
426ff27e42 Merge fixHookNameValidation into fix20261001 (#837) 2026-09-28 11:48:50 +10:00
tequ
e6bdd55803 Merge fixHookExitOutOfBounds into fix20261001 (#836) 2026-09-28 11:48:05 +10:00
tequ
9dd103fad4 Merge fixHookAPISType into fix20261001 (#835) 2026-09-28 11:46:59 +10:00
Richard Holland
a7f9c683c4 fix keylet api (#833) 2026-09-26 14:24:00 +10:00
tequ
48a94af13d Add HookName validation to ClaimReward hookCan process (#786)
* Add HookName validation to ClaimReward hookCan process

* fixHookNameValidation Amendment (#776)

* Add fix20261001 Amendment placeholder (#831)

* address review

* use Slice instead Blob for canHook helper
2026-09-26 13:25:19 +10:00
Richard Holland
1ddda79c34 utf8 patch (#832) 2026-09-26 13:11:53 +10:00
tequ
76b7111098 Add fix20261001 Amendment placeholder (#831) 2026-09-26 11:07:18 +10:00
tequ
20f2b7f456 fixHookNameValidation Amendment (#776) 2026-09-26 10:45:24 +10:00
tequ
c6a292ca55 fix AMMCreate::calculateBaseFee to include hook fee (and base fee, multisign fee, ...) (#828) 2026-09-25 20:29:36 +10:00
tequ
1ae3fb3f57 fix: record rollback when accept()/rollback() reason is out of bounds (#803)
When a hook calls accept() or rollback() with a reason string pointer
outside of wasm memory, HOOK_EXIT returned OUT_OF_BOUNDS and let the hook
keep running. If the hook then returned normally, the execution ended
with exitType UNSET and the HookExecution metadata carried no useful
information about what happened.

Behind the new fixHookExitOutOfBounds amendment, HOOK_EXIT now terminates
the hook as a ROLLBACK with exitCode OUT_OF_BOUNDS (mirroring the guard
violation path), so HookResult and HookReturnCode in the transaction
metadata make the failure visible to hook developers.

Adds a SetHook test covering accept() and rollback() with an out of
bounds reason, with and without the amendment.

Fixes #767
2026-09-25 20:26:59 +10:00
Niq Dudfield
1ea6b76853 fix(server): preserve idle JSON-RPC keep-alives (#797) 2026-09-25 20:24:06 +10:00
tequ
8f4569a63c fixHookAPISType Amendment (#778) 2026-09-25 20:20:40 +10:00
Niq Dudfield
b775f3c3c2 ci: add -Dcoverage_tool=gcov|llvm option, wire native llvm-cov in matrix (#740)
* ci: add -Dcoverage_tool=gcov|llvm option, wire native llvm-cov in matrix

introduces native llvm source-based coverage as an alternative to the
existing gcov + gcovr pipeline. driven by a new -Dcoverage_tool cache
variable (default 'gcov' for backwards compat; 'llvm' enables
-fprofile-instr-generate / -fcoverage-mapping + llvm-profdata + llvm-cov).

cmake:
- RippledSettings.cmake: add coverage_tool with validation
- RippledInterface.cmake: split coverage compile/link flags by tool
- RippledCov.cmake: dispatch to the new helper when tool=llvm
- CodeCoverageLLVM.cmake (new): setup_target_for_coverage_llvm() driving
  profraw -> profdata -> export with format-aware output (lcov/json/txt/html)

ci:
- new clang-20 llvm-cov coverage matrix row (apt.llvm.org bootstrap for
  clang >= 19 since 24.04 default repos cap at clang-18)
- conditional install of llvm-N vs gcovr based on coverage_tool
- artifact + codecov upload generalised to coverage.lcov | coverage.xml
- coverage cmake-args switched to *_FLAGS_DEBUG so the build action's
  stdlib flag isn't clobbered

temp (revert before merging to dev):
- matrix narrowed to just the llvm-cov row on non-main refs so we can
  iterate without burning runners
- 'coverage-llm' added to push trigger for direct-push CI runs

* ci: drop coverage-llm from push triggers, PR trigger covers it

* ci: actually narrow matrix to just the llvm-cov row

prior guard checked base_ref against ['dev','candidate','release'] which
excluded the very PR we're iterating on. drop the guard - this branch
is for iteration only and must be reverted before merging anyway.

* ci(deps): apply Wno-missing-template-arg-list workaround to Linux clang

grpc 1.50.1 hits -Werror=missing-template-arg-list-after-template-kw on
clang-19+. macOS clang already had this workaround in the conan profile;
mirror it to the Linux branch, gated on compiler==clang.

* ci(temp): disable all workflows except Nix GA on this branch

renames every non-nix workflow to .yml.disabled so they stop firing on
PR pushes while we iterate on the llvm-cov coverage row. MUST be
reverted before merging to dev.

* fix(cov): use absolute binary path in llvm-cov run command

bare 'rippled' wasn't on PATH and the build dir isn't '.', so the
profile-collection step failed with 'No such file or directory'.
splice the resolved absolute path back into Cov_EXECUTABLE before
the run command consumes it.

* ci(deps): replace hardcoded grpc workaround with matrix-driven conan_deps_cxxflags

new dependencies action input `conan_deps_cxxflags` (json list, default
'[]') drives `tools.build:cxxflags` in the conan profile. clearly named
to indicate the flags only apply to conan dependency builds, not the
rippled build itself.

removes the per-os/per-compiler hardcoded workaround (linux clang
conditional + unconditional macOS block) that used to set the same flag
in two places kept-in-sync by hand.

call sites:
- xahau-ga-nix.yml: clang-20 coverage row gets the
  -Wno-missing-template-arg-list-after-template-kw workaround for grpc 1.50.1
- xahau-ga-macos.yml.disabled: same flag plumbed through (preserves
  prior behaviour when re-enabled)

drop the workaround entries when grpc is bumped past the fix.

* fix(cov): tighten coverage_tool=llvm validation + macOS tool discovery

two bugs caught in review:

- RippledSettings.cmake: the clang-only guard for coverage_tool=llvm ran
  before coverage_test could auto-enable coverage. so
  '-Dcoverage_tool=llvm -Dcoverage_test=Foo' on a gcc build slipped past
  the guard and produced an instrumentation/tool mismatch. move the
  guard after the auto-enable block.

- CodeCoverageLLVM.cmake: _find_llvm_cov_tools unconditionally
  preferred xcrun's tools on APPLE, which on a homebrew clang-N build
  would pair the user's clang with xcode's llvm-cov - exactly the
  version mismatch the helper is trying to avoid. gate the xcrun branch
  on CMAKE_CXX_COMPILER_ID == AppleClang.

* chore(cov): drop dead BASE_DIRECTORY arg + revert .disabled file edit

- CodeCoverageLLVM.cmake: BASE_DIRECTORY was parsed but never used
  (no analog to gcovr's -r in the llvm-cov commands we emit). dead arg.
- xahau-ga-macos.yml.disabled: revert the conan_deps_cxxflags addition.
  the file is disabled so the edit was bit-rotting in unreachable code.
  whoever revives the macOS workflow can wire up the field then.

* Revert "chore(cov): drop ... .disabled file edit" (partial)

restore the conan_deps_cxxflags addition to xahau-ga-macos.yml.disabled.
prior commit framed it as dead code, but the .disabled rename is itself
a TEMP measure being reverted before merge - the field is needed for the
macOS workflow to keep building grpc 1.50.1 once it's re-enabled, since
the unconditional workaround was removed from the dependencies action.

* fix(ci): restore conan_deps_cxxflags on macOS workflow

reverts part of f8a30c528d - removing this line dropped the apple-clang
grpc workaround that the dependencies action used to apply
unconditionally before the matrix-driven refactor. the .disabled rename
is itself a TEMP measure being reverted before merge, so the field needs
to be in place when the macOS workflow comes back.

* ci: restore matrix-row comments explaining clang-20 + grpc workaround

* ci: dedupe conan_deps_cxxflags in macOS workflow row

prior turn-of-events created two identical conan_deps_cxxflags entries
in the same matrix row from overlapping restore commits. keep one.

* ci: undisable workflows, drop gcc-13 coverage row, keep clang-20 llvm-cov as sole codecov reporter

- restore the 8 .yml.disabled workflows back to .yml
- drop the gcc-13 gcov coverage matrix row; native clang-20 llvm-cov is
  now the only codecov reporter
- update minimal_matrix indices to match
- remove the TEMP narrowing block that filtered to just the llvm-cov row
- log line says '7 configs (build x6 + clang-20 llvm-cov coverage)' to
  reflect the new shape

* fix(ci): scope conan_deps_cxxflags per Conan package pattern

prior shape (bare json list -> 'tools.build:cxxflags=[...]') leaked into
the consumer/rippled build via the conan-generated toolchain
(CMAKE_CXX_FLAGS_INIT). on macOS, where the build action doesn't
override CMAKE_CXX_FLAGS, this would silently apply the workaround flag
to rippled itself.

reshape the input to a json object keyed by Conan package pattern:
  {"grpc/*":["-Wno-..."]}

action emits package-pattern scoped lines:
  grpc/*:tools.build:cxxflags=["-Wno-..."]

flags only apply while building the matching dependency. consumer
toolchain stays clean. python validator rejects the consumer pattern
('&') and malformed shapes.

* ci: bump apt retries to 5 to handle ppa.launchpadcontent.net flakes

* ci: relax patch coverage for PeerImp
2026-09-25 19:55:54 +10:00
tequ
03d75df295 Reduce MagicEnum usage in server definitions (#775) 2026-09-25 19:47:54 +10:00
tequ
c2e253b365 refactor new account seqno (#772)
When creating accounts in GenesisLedger, we previously set the account Sequence to 0. However, since this conflicts with the PseudoAccount requirements, we are changing it to 1.
There will be no impact on networks that are already running, and for future networks, there won't be any impact unless you create accounts via GenesisLedger.
This specifically addresses an issue that comes up during unittests.
2026-09-25 13:10:18 +10:00
tequ
ba130f8363 AMMClawback supported::no (#827)
Co-authored-by: Richard Holland <richard.holland@starstone.co.nz>
2026-09-25 12:36:31 +10:00
tequ
e87eabd8be HookOnV2_1 Amendment (#766) 2026-09-25 11:17:12 +10:00
Niq Dudfield
2e32b5c6bb feat(server_definitions): distinguish config-forced from ledger-enabled amendments (#765) 2026-09-23 15:33:43 +10:00
tequ
902ed9b492 Use normal consequences factory for standard transactions (#774)
Replace redundant custom consequence factories that returned normal consequences with the built-in Normal factory.
2026-09-21 21:12:15 +10:00
tequ
c208a40ce8 remove WASM: $COUNTER from SetHook_wasm.h (#804) 2026-09-09 15:31:11 +10:00