Retain the bounded publisher-generation view independently, but dynamically hide candidate bindings whenever ordinary manifest state currently owns the same master or signing key. Main revocations also mask all candidate fields.
This preserves deterministic current-view provenance and fallback after ordinary untrusted eviction without shadow history, durable tombstones, or inferred graduation.
Keep publisher candidates in a bounded, generation-derived monitoring overlay rather than the ordinary untrusted manifest cache. Consensus membership and trust use candidate-free lookups, while monitoring can still resolve candidate signing keys.
Deliberately do not maintain shadow histories, infer candidate graduation, or promise historical key non-reuse. Manifests are dual-signed; current-view collisions are rejected only to keep inverse lookup unambiguous. Promotion requires the manifest to appear explicitly in the validators tier.
Pack listed manifests first, then use the remaining protobuf byte budget for bounded unlisted entries so a generated peer snapshot cannot be silently discarded by the receiver's TMManifests limit.
Invalidate cached snapshots when a retained manifest is promoted to trusted. Cover trusted entries beyond the untrusted count cap, byte-budget truncation, HashRouter skip-set intersection, and compressed and uncompressed frame guards.
Exercise the per-message untrusted limit through OverlayImpl, verify the sending peer is excluded from the coalesced relay, and confirm the retained manifests populate the initial peer snapshot.
Give a full untrusted manifest cache a local burst of ten eviction permits, refilling one permit per second. Novel untrusted admissions consume a permit only after validation; when none is available they are rejected before signature verification. Existing entries and uncapped protected manifests bypass the budget.
Use an injected steady clock to cover deterministic exhaustion and refill. Record that the global budget can be monopolized during a sustained flood, delaying novel untrusted validators while protected validators remain unaffected.
Evict a random dormant untrusted manifest when the 1000-entry cap is full, preferring to retain signing keys with current validations. Fall back to any untrusted victim when all retained validators are active. Entries admitted uncapped or later promoted remain protected.
Decouple relay novelty from cache admission with HashRouter so eviction cannot manufacture immediate relay novelty or echo a manifest to its source. Intersect suppression sets when relaying a multi-manifest bundle.
Document that eviction forgets untrusted high-water, revocation, and key-collision state. This is a buy-time retained-state bound: promotion is one-way, and unique valid identities can still consume verification, victim-selection, and relay resources.
Cover invalid-before-evict, protected and active retention, reverse-index cleanup, update-at-cap, all-active fallback, validation-key rotation, and freshness expiry.
Port the four manifest containment changes shipped in rippled 3.2.1 (587505ef18, 32a9cc4038, 0cce5a06d9, and 4bd1d1ca2f) to Xahau without additional behavioral changes.\n\nBound untrusted cache residency and per-message work, preserve trusted/configured/DB exemptions, reject oversized manifests before decoding, and soft-discard oversized manifest frames for compatibility.
Due to rounding, the LPTokenBalance of the last LP might not match the LP's trustline balance. This was fixed for `AMMWithdraw` in `fixAMMv1_1` by adjusting the LPTokenBalance to be the same as the trustline balance. Since `AMMClawback` is also performing a withdrawal, we need to adjust LPTokenBalance as well in `AMMClawback.`
This change includes:
1. Refactored `verifyAndAdjustLPTokenBalance` function in `AMMUtils`, which both`AMMWithdraw` and `AMMClawback` call to adjust LPTokenBalance.
2. Added the unit test `testLastHolderLPTokenBalance` to test the scenario.
3. Modify the existing unit tests for `fixAMMClawbackRounding`.
* Add AMM bid/create/deposit/swap/withdraw/vote invariants:
- Deposit, Withdrawal invariants: `sqrt(asset1Balance * asset2Balance) >= LPTokens`.
- Bid: `sqrt(asset1Balance * asset2Balance) > LPTokens` and the pool balances don't change.
- Create: `sqrt(asset1Balance * assetBalance2) == LPTokens`.
- Swap: `asset1BalanceAfter * asset2BalanceAfter >= asset1BalanceBefore * asset2BalanceBefore`
and `LPTokens` don't change.
- Vote: `LPTokens` and pool balances don't change.
- All AMM and swap transactions: amounts and tokens are greater than zero, except on withdrawal if all tokens
are withdrawn.
* Add AMM deposit and withdraw rounding to ensure AMM invariant:
- On deposit, tokens out are rounded downward and deposit amount is rounded upward.
- On withdrawal, tokens in are rounded upward and withdrawal amount is rounded downward.
* Add Order Book Offer invariant to verify consumed amounts. Consumed amounts are less than the offer.
* Fix Bid validation. `AuthAccount` can't have duplicate accounts or the submitter account.