Commit Graph

10305 Commits

Author SHA1 Message Date
Nicholas Dudfield
d5feb23d04 fix: close candidate resolver races 2026-08-11 09:09:00 +07:00
Nicholas Dudfield
34042f998b fix: stabilize monitoring identity snapshots 2026-08-11 09:03:51 +07:00
Nicholas Dudfield
79fa1ee4f5 fix: isolate malformed candidate extensions 2026-08-11 08:58:58 +07:00
Nicholas Dudfield
b9892da0a7 refactor: isolate publisher candidate manifests 2026-08-11 08:55:26 +07:00
Nicholas Dudfield
d3264e16c5 fix(validators): mask candidates behind current state
Retain the bounded publisher-generation view independently, but dynamically hide candidate bindings whenever ordinary manifest state currently owns the same master or signing key. Main revocations also mask all candidate fields.

This preserves deterministic current-view provenance and fallback after ordinary untrusted eviction without shadow history, durable tombstones, or inferred graduation.
2026-08-10 20:59:57 +07:00
Nicholas Dudfield
6da9ab90ae fix(validators): separate publisher candidate state
Keep publisher candidates in a bounded, generation-derived monitoring overlay rather than the ordinary untrusted manifest cache. Consensus membership and trust use candidate-free lookups, while monitoring can still resolve candidate signing keys.

Deliberately do not maintain shadow histories, infer candidate graduation, or promise historical key non-reuse. Manifests are dual-signed; current-view collisions are rejected only to keep inverse lookup unambiguous. Promotion requires the manifest to appear explicitly in the validators tier.
2026-08-10 17:15:08 +07:00
Nicholas Dudfield
84edc16a92 fix(validators): isolate published candidates 2026-08-10 16:24:39 +07:00
Nicholas Dudfield
fd8fedbeca feat(validators): ingest publisher candidate manifests 2026-08-10 15:22:11 +07:00
Nicholas Dudfield
d31f9fe421 fix(overlay): bound manifest work and refresh snapshots
Bound total TMManifests entries independently of the wire-byte and valid-untrusted limits so tiny malformed entries cannot multiply per-entry parsing and logging work.

Track listed-key membership separately from retained manifest state. Rebuild cached peer snapshots after listing changes, promote config-listed entries, and reconcile capped admissions atomically so listing and eviction cannot leave a listed manifest absent or evictable.

Cover high-cardinality malformed envelopes, list-only snapshot invalidation, config promotion, eviction-induced reaccept relay suppression, and singleton eviction-victim selection.
2026-08-06 19:50:10 +07:00
Nicholas Dudfield
1ea905a0d3 style(overlay): apply clang-format 18 wrapping 2026-08-06 18:58:12 +07:00
Nicholas Dudfield
a0ea133c5c test(overlay): preserve levelization boundary
Use the validator section name directly in the overlay fixture so the regression does not introduce a test.overlay dependency on xrpld.core.
2026-08-06 18:52:37 +07:00
Nicholas Dudfield
9462bafa49 fix(overlay): align manifest snapshots with receive limits
Pack listed manifests first, then use the remaining protobuf byte budget for bounded unlisted entries so a generated peer snapshot cannot be silently discarded by the receiver's TMManifests limit.

Invalidate cached snapshots when a retained manifest is promoted to trusted. Cover trusted entries beyond the untrusted count cap, byte-budget truncation, HashRouter skip-set intersection, and compressed and uncompressed frame guards.
2026-08-06 18:49:49 +07:00
Nicholas Dudfield
8696eeb454 test(overlay): cover manifest relay containment
Exercise the per-message untrusted limit through OverlayImpl, verify the sending peer is excluded from the coalesced relay, and confirm the retained manifests populate the initial peer snapshot.
2026-08-06 16:59:51 +07:00
Nicholas Dudfield
9cc426b3fb fix(manifest): rate-limit cache eviction
Give a full untrusted manifest cache a local burst of ten eviction permits, refilling one permit per second. Novel untrusted admissions consume a permit only after validation; when none is available they are rejected before signature verification. Existing entries and uncapped protected manifests bypass the budget.

Use an injected steady clock to cover deterministic exhaustion and refill. Record that the global budget can be monopolized during a sustained flood, delaying novel untrusted validators while protected validators remain unaffected.
2026-08-05 09:03:40 +07:00
Nicholas Dudfield
6426a11058 fix(manifest): keep bounded gossip cache moving
Evict a random dormant untrusted manifest when the 1000-entry cap is full, preferring to retain signing keys with current validations. Fall back to any untrusted victim when all retained validators are active. Entries admitted uncapped or later promoted remain protected.

Decouple relay novelty from cache admission with HashRouter so eviction cannot manufacture immediate relay novelty or echo a manifest to its source. Intersect suppression sets when relaying a multi-manifest bundle.

Document that eviction forgets untrusted high-water, revocation, and key-collision state. This is a buy-time retained-state bound: promotion is one-way, and unique valid identities can still consume verification, victim-selection, and relay resources.

Cover invalid-before-evict, protected and active retention, reverse-index cleanup, update-at-cap, all-active fallback, validation-key rotation, and freshness expiry.
2026-08-05 08:48:16 +07:00
Nicholas Dudfield
ad84ef5a9a fix(manifest): port rippled 3.2.1 containment
Port the four manifest containment changes shipped in rippled 3.2.1 (587505ef18, 32a9cc4038, 0cce5a06d9, and 4bd1d1ca2f) to Xahau without additional behavioral changes.\n\nBound untrusted cache residency and per-message work, preserve trusted/configured/DB exemptions, reject oversized manifests before decoding, and soft-discard oversized manifest frames for compatibility.
2026-08-05 08:12:50 +07:00
Richard Holland
639ea34377 Fixhookmap (#756) 2026-06-16 17:06:25 +10:00
tequ
089c0dc3fe Fix ammLPHolds logic to include escrowed cases (#757) 2026-06-16 15:26:29 +10:00
tequ
607a7fdf98 Change AMM to Supported::no (#758) 2026-06-16 13:56:58 +10:00
tequ
c55420bcd8 Fix duplicate and incorrect fields in server_definitions (#753) 2026-05-27 07:58:13 +10:00
tequ
90333b6fd0 Fix HookAPI Expected and Refactor Enum classes (#729) 2026-05-26 11:02:17 +10:00
tequ
7f9a9364b0 fix: Ensures canonical order for PriceDataSeries upon PriceOracle creation (#5485) (#744) 2026-05-25 11:34:24 +10:00
tequ
663ed4edb8 Named Hook (#718) 2026-05-19 12:00:25 +10:00
tequ
586c78e812 fix: Replace badCurrency() checks with isBadCurrency() for improved clarity (#742) 2026-05-18 11:57:25 +10:00
Niq Dudfield
9b50b68d39 perf(ledger): optimize catalogue loading memory usage and performance (#548) 2026-05-06 17:29:44 +10:00
tequ
5e8d26f67a refactor: Calculate numFeatures automatically (#5324) (#739)
Co-authored-by: Ed Hennis <ed@ripple.com>
2026-04-30 18:17:50 +10:00
tequ
a6186d7855 IOURewardClaim (#500) 2026-04-30 15:27:51 +10:00
tequ
b449599408 Add --definitions CLI flag to output static server definitions without starting server (#708) 2026-04-30 12:42:42 +10:00
tequ
49fd0c33b5 fixIOULockedBalanceInvariant Amendment (#732) 2026-04-29 17:05:18 +10:00
tequ
0ffb6e8c21 Replace vendored magic_enum header with Conan package dependency (#727) 2026-04-29 17:00:25 +10:00
tequ
61138058a6 Delete unused sfHookDefinition (#715) 2026-04-29 16:45:35 +10:00
Fomo
dd9e6053a0 fix: Expand the pathing tables and lower weight on sabbxd, also return up … (#723) 2026-04-29 14:28:00 +10:00
tequ
8c1be39f70 Fix LedgerNameSpace to ensure uniqueness (#710) 2026-04-29 12:01:57 +10:00
tequ
61d1d6e441 Add test for rejected Remit to AMM account (#698) 2026-04-29 11:20:13 +10:00
tequ
788ba43266 Refactor getFieldU16(sfTransactionType) with getTxnType() (#711) 2026-04-29 11:17:49 +10:00
tequ
55710c4baf Disallow setting a AMM account as Issuer/Destination/Inform (#709) 2026-04-29 11:00:25 +10:00
tequ
7bf5bcaf20 Add new TSH tests (#704) 2026-04-29 10:40:50 +10:00
Niq Dudfield
9f2160f42e fix: resolve switch fall-through in util_keylet unimplemented cases (#701) 2026-04-29 10:37:17 +10:00
tequ
ef7a03ec10 fix owner count assertion at XahauGenesis_test (#688) 2026-04-29 10:32:43 +10:00
tequ
ea92477d21 Test: hint build_test_hooks.sh when hook wasm is empty in hso() 2026-04-28 18:23:32 +10:00
tequ
6aabbc940b fix: typo SignersListSet 2026-04-28 18:23:31 +10:00
tequ
3111ecea52 Update util_keylet fee test 2026-04-28 18:23:31 +10:00
tequ
1008508c9b Updated tests to align with the changes merged into the dev branch. 2026-04-28 18:23:31 +10:00
tequ
58e278289b Add tests for Hooks fee 2026-04-28 18:23:31 +10:00
tequ
d3d24f781b Merge fixAMMClawbackRounding amendment into featureAMMClawback amendment 2026-04-28 18:23:31 +10:00
yinyiqian1
131d659032 fixAMMClawbackRounding: adjust last holder's LPToken balance (#5513)
Due to rounding, the LPTokenBalance of the last LP might not match the LP's trustline balance. This was fixed for `AMMWithdraw` in `fixAMMv1_1` by adjusting the LPTokenBalance to be the same as the trustline balance. Since `AMMClawback` is also performing a withdrawal, we need to adjust LPTokenBalance as well in `AMMClawback.`

This change includes:
1. Refactored `verifyAndAdjustLPTokenBalance` function in `AMMUtils`, which both`AMMWithdraw` and `AMMClawback` call to adjust LPTokenBalance.
2. Added the unit test `testLastHolderLPTokenBalance` to test the scenario.
3. Modify the existing unit tests for `fixAMMClawbackRounding`.
2026-04-28 18:23:31 +10:00
tequ
503dee619a Merge fixAMMv1_3 amendment into featureAMM amendment 2026-04-28 18:23:31 +10:00
Gregory Tsipenyuk
1703d96a48 fix: Add AMMv1_3 amendment (#5203)
* Add AMM bid/create/deposit/swap/withdraw/vote invariants:
  - Deposit, Withdrawal invariants: `sqrt(asset1Balance * asset2Balance) >= LPTokens`.
  - Bid: `sqrt(asset1Balance * asset2Balance) > LPTokens` and the pool balances don't change.
  - Create: `sqrt(asset1Balance * assetBalance2) == LPTokens`.
  - Swap: `asset1BalanceAfter * asset2BalanceAfter >= asset1BalanceBefore * asset2BalanceBefore`
     and `LPTokens` don't change.
  - Vote: `LPTokens` and pool balances don't change.
  - All AMM and swap transactions: amounts and tokens are greater than zero, except on withdrawal if all tokens
    are withdrawn.
* Add AMM deposit and withdraw rounding to ensure AMM invariant:
  - On deposit, tokens out are rounded downward and deposit amount is rounded upward.
  - On withdrawal, tokens in are rounded upward and withdrawal amount is rounded downward.
* Add Order Book Offer invariant to verify consumed amounts. Consumed amounts are less than the offer.
* Fix Bid validation. `AuthAccount` can't have duplicate accounts or the submitter account.
2026-04-28 18:23:31 +10:00
Nicholas Dudfield
fff46e3dd0 chore: clang-format 2026-02-20 08:22:49 +09:00
Nicholas Dudfield
52369f3ebb fix: resolve merge issues from dev sync
- Add missing getHookOn declaration and implementation (build blocker)
- Add else branches for HookOnOutgoing/HookOnIncoming in hsoUPDATE path
- Guard unprotected optional dereferences in hsoINSTALL path
- Reorder features.macro per review (HookOnV2/HooksUpdate2 before fixHookAPI20251128)
2026-02-20 08:22:15 +09:00