Commit Graph

14714 Commits

Author SHA1 Message Date
Nicholas Dudfield
1287cce0f7 fix(consensus): recycle member evidence cache 2026-07-12 09:27:16 +07:00
Nicholas Dudfield
25073d6cb1 fix(consensus): publish initial member revocations 2026-07-11 14:59:03 +07:00
Nicholas Dudfield
92c7839822 feat(consensus): publish UNL report member evidence 2026-07-11 14:50:53 +07:00
Nicholas Dudfield
ab30826c5c feat(consensus): add UNL report member registry 2026-07-11 14:17:47 +07:00
Nicholas Dudfield
dae0d64b3e feat(consensus): expose manifest binding identity 2026-07-11 13:48:28 +07:00
Nicholas Dudfield
0cdd7164f4 feat(consensus): consolidate UNL report amendment 2026-07-11 13:32:11 +07:00
Nicholas Dudfield
84d738ce8a docs(export): define bounded authority and committee path 2026-07-10 17:01:12 +07:00
Nicholas Dudfield
5e2cbf62fe docs(export): simplify submitter co-signer model 2026-07-10 16:24:35 +07:00
Nicholas Dudfield
75d08560d4 docs(export): describe optional executor gate 2026-07-10 16:21:03 +07:00
Nicholas Dudfield
b942a29fd8 docs(export): define quorum and cancellation contract 2026-07-10 16:14:29 +07:00
Nicholas Dudfield
3cb0583d0c style(export): match CI clang-format 2026-07-10 16:04:23 +07:00
Nicholas Dudfield
56bf9f2eed fix(export): align callback identity and signer authority 2026-07-10 15:50:39 +07:00
Nicholas Dudfield
3a865b5c0a style: apply clang-format 18 to nUNL cap fix + entropy pseudo ingress 2026-07-07 18:54:23 +07:00
Nicholas Dudfield
4e7996a86a docs(export): clarify nUNL cap proof denominator 2026-07-07 18:15:48 +07:00
Nicholas Dudfield
c558478337 docs(consensus): document nUNL cap amendment dependency 2026-07-07 18:13:13 +07:00
Nicholas Dudfield
7f6a29770c fix(consensus): align nUNL vote cap with active view 2026-07-07 18:09:50 +07:00
Nicholas Dudfield
7161937720 test(export): cover audit gaps 2026-07-07 17:42:41 +07:00
Nicholas Dudfield
f6e37bcc53 test(consensus): cover export pseudo acquired-set rejection 2026-07-07 17:32:32 +07:00
Nicholas Dudfield
4dd3882b30 fix(resource): strip inbound loopback ports from resource keys 2026-07-07 17:22:24 +07:00
Nicholas Dudfield
c7e5f54761 docs(consensus): anchor bounded extension waits 2026-07-07 16:45:05 +07:00
Nicholas Dudfield
990e15a468 docs(consensus): add walkthrough source anchors 2026-07-07 16:37:14 +07:00
Nicholas Dudfield
c03a92c5d2 fix(consensus): reject acquired CE pseudo transactions 2026-07-07 15:44:23 +07:00
Nicholas Dudfield
9bd964b7ff test(consensus): pin active NegativeUNL cap invariant 2026-07-07 15:31:50 +07:00
Nicholas Dudfield
96f84a1c15 fix(consensus): cap NegativeUNL shrink against UNLReport active view to preserve entropy intersection 2026-07-07 15:19:16 +07:00
Nicholas Dudfield
effead7b0d test(consensus): rolling-upgrade + CE-activation rollout scenario
.testnet/scenarios/rollout/: a 7-node localhost net (5 UNL validators quorum 4 +
2 non-UNL trackers) starts on @release, rolling-restarts the validators + 1
tracker to @export-rng (mesh-gated, quorum preserved), votes ConsensusEntropy,
activates at flag ledger 256, and asserts the upgraded tracker keeps tracking
while the @release straggler is amendment-blocked but not crashed. Requires
distinct loopback aliases (x-testnet setup-aliases).

Also drops the dead XAHAU_RESOURCE_PER_PORT env from the entropy/export/latency
suites (never read by the binary; the localhost mesh now comes from distinct-IP
fixed peers).
2026-07-07 11:52:51 +07:00
Nicholas Dudfield
dd678ee6ce docs(consensus): document the CE proposal wire-format rollout dependency
After featureConsensusEntropy activates, proposals may carry a serialized
ExtendedPosition in the legacy currenttxhash protobuf field, so pre-CE binaries
that require an exact 32-byte currenttxhash cannot participate as proposal peers;
disabling sidecar fetch/reconciliation does NOT restore compatibility (the
wire-format change is independent of the sidecar gate). Verified against the
implementation (RCLConsensus, ConsensusExtensions, PeerImp).
2026-07-07 11:52:36 +07:00
Nicholas Dudfield
3eaf7b9e3d feat(consensus): record entropy contributors 2026-07-03 19:21:10 +07:00
Nicholas Dudfield
02313caa00 fix(hooks): remove consensus entropy keylet 2026-07-03 12:27:52 +07:00
Nicholas Dudfield
7c5ddb06d8 feat(hooks): expose consensus entropy keylet 2026-07-03 07:23:07 +07:00
Nicholas Dudfield
e8d40472e9 feat(consensus): add validator full entropy tier 2026-07-02 21:08:37 +07:00
Nicholas Dudfield
ac659faec7 fix(consensus): refresh extension gates before round cleanup 2026-07-02 19:26:32 +07:00
Nicholas Dudfield
986646ec90 fix(consensus): refresh extension gates on round start 2026-07-02 18:35:29 +07:00
Nicholas Dudfield
e3e1d847a4 test(consensus): assert export quorum cohort sync 2026-07-02 18:34:44 +07:00
Nicholas Dudfield
fa876927a9 feat: record consensus entropy denominator 2026-07-02 17:38:40 +07:00
Nicholas Dudfield
9a99c2d400 chore: update levelization results 2026-07-02 16:56:02 +07:00
Nicholas Dudfield
e001aca8ae fix(consensus): trust accepted export signature roots 2026-07-02 16:09:29 +07:00
Nicholas Dudfield
777743792e docs(consensus): qualify entropy fallback boundary as lab-only 2026-07-02 14:53:21 +07:00
Nicholas Dudfield
3af3b33c07 docs(consensus): clarify entropy boundary after tx-set agreement 2026-07-02 14:39:40 +07:00
Nicholas Dudfield
030206d632 docs(consensus): document entropy fallback boundary 2026-07-02 14:33:43 +07:00
Nicholas Dudfield
9324bd59e5 fix(consensus): keep entropy selection rooted in accepted hash
Revert the local entropyFailed selector override introduced during sidecar reconciliation excision. ConsensusEntropy injection is ledger-defining, so accepted entropy roots remain authoritative; nodes without an accepted root still fall back through the normal missing-root path.

Update CSF parity, the focused onPreBuild regression, and the design intent note to capture that local timeout/diagnostic state must not override an accepted root.
2026-07-02 13:50:42 +07:00
Nicholas Dudfield
3c01901119 feat(consensus): excise sidecar reconciliation
Remove peer fetch/acquire/merge support for CE/export sidecar SHAMaps and keep them as local same-process snapshots only.

Harden generic transaction-set paths so sidecar maps are not advertised, served, acquired, or wrapped as RCLTxSet, and delete the stale fetch-positive .testnet suite.

Make entropy failure terminal at selection time and mirror that invariant in the CSF harness; keep Export witness materialization rooted in accepted exportSigSetHash rather than local timeout state.
2026-07-02 12:52:43 +07:00
Nicholas Dudfield
e8fa4e1154 fix(consensus): stop serving sidecars when reconciliation is off 2026-07-01 11:30:42 +07:00
Nicholas Dudfield
d4650441fb feat(consensus): default sidecar reconciliation off
Compile out sidecar acquisition and merge plumbing unless xahaud_sidecar_reconciliation is enabled, and move fetch-positive .testnet scenarios into an opt-in suite.

When reconciliation is enabled, gate eager fetches on current trusted root support so first-seen transient roots do not trigger network acquisition. This keeps the recovery path available for measurement without making it the default path.

Verified default OFF with x-format-changed, git diff --check, x-quick-check, cmake configure/build, and ./build/rippled --unittest=ConsensusExtensions. ON path syntax-checked; Claude is assigned the parallel ON build/test review in a separate worktree.
2026-06-30 16:10:50 +07:00
Nicholas Dudfield
67c2c44263 feat(consensus): gate sidecar reconciliation 2026-06-30 14:03:56 +07:00
Nicholas Dudfield
ee6c4ff31f test(consensus): measure entropy sidecar fetch yield 2026-06-30 12:07:33 +07:00
Nicholas Dudfield
63f99ad9d8 feat(consensus): salt tx ordering with entropy 2026-06-29 16:32:16 +07:00
Nicholas Dudfield
be649d5112 fix(export): bound retry window 2026-06-29 14:28:20 +07:00
Nicholas Dudfield
8c48e500e7 fix(consensus): domain-separate participant diagnostics 2026-06-29 11:49:26 +07:00
Nicholas Dudfield
5195fc64b3 fix(hooks): block callback from canceling current export latch 2026-06-29 10:54:31 +07:00
Nicholas Dudfield
f849b70a96 docs(export): clarify target network id guard 2026-06-29 10:18:53 +07:00