Allows a confidential MPT holder to rotate or recover their ElGamal encryption key, or to cancel a pending recovery.
More...
|
| static bool | checkExtraFeatures (PreflightContext const &ctx) |
| static std::uint32_t | getFlagsMask (PreflightContext const &ctx) |
| static NotTEC | preflight (PreflightContext const &ctx) |
| static XRPAmount | calculateBaseFee (ReadView const &view, STTx const &tx) |
| static TER | preclaim (PreclaimContext const &ctx) |
| static NotTEC | checkSeqProxy (ReadView const &view, STTx const &tx, beast::Journal j) |
| static NotTEC | checkPriorTxAndLastLedger (PreclaimContext const &ctx) |
| static TER | checkFee (PreclaimContext const &ctx, XRPAmount baseFee) |
| static NotTEC | checkSign (PreclaimContext const &ctx) |
| static XRPAmount | calculateBaseFee (ReadView const &view, STTx const &tx, std::uint32_t extraBaseFeeMultiplier) |
| static FeePayer | getFeePayer (ReadView const &view, STTx const &tx) |
| template<class T> |
| static NotTEC | invokePreflight (PreflightContext const &ctx) |
| template<> |
| NotTEC | invokePreflight (PreflightContext const &ctx) |
| template<> |
| NotTEC | invokePreflight (PreflightContext const &ctx) |
| static NotTEC | checkGranularSemantics (ReadView const &view, STTx const &tx, std::unordered_set< GranularPermissionType > const &heldGranularPermissions) |
| | This function can be overridden to introduce additional semantic constraints beyond the granular template validation for granular permissions.
|
| template<class T> |
| static NotTEC | invokeCheckPermission (ReadView const &view, STTx const &tx) |
| | Checks whether the transaction is authorized to be executed by the delegated account.
|
| static NotTEC | checkSponsor (ReadView const &view, STTx const &tx) |
| static TER | ticketDelete (ApplyView &view, AccountID const &account, UInt256 const &ticketIndex, beast::Journal j) |
|
| static NotTEC | checkSign (ReadView const &view, ApplyFlags flags, std::optional< UInt256 const > const &parentBatchId, AccountID const &idAccount, STObject const &sigObject, beast::Journal const j, bool permitUncreatedAccount=false) |
| static XRPAmount | minimumFee (ServiceRegistry ®istry, XRPAmount baseFee, Fees const &fees, ApplyFlags flags) |
| | Compute the minimum fee required to process a transaction with a given baseFee based on the current server load.
|
| static XRPAmount | calculateOwnerReserveFee (ReadView const &view, STTx const &tx) |
| static NotTEC | preflightSigValidated (PreflightContext const &ctx) |
| static bool | validDataLength (std::optional< Slice > const &slice, std::size_t maxLength) |
| template<class T> |
| static bool | validNumericRange (std::optional< T > value, T max, T min=T{}) |
| template<class T, class Unit> |
| static bool | validNumericRange (std::optional< T > value, unit::ValueUnit< Unit, T > max, unit::ValueUnit< Unit, T > min=unit::ValueUnit< Unit, T >{}) |
| template<class T> |
| static bool | validNumericMinimum (std::optional< T > value, T min=T{}) |
| | Minimum will usually be zero.
|
| template<class T, class Unit> |
| static bool | validNumericMinimum (std::optional< T > value, unit::ValueUnit< Unit, T > min=unit::ValueUnit< Unit, T >{}) |
| | Minimum will usually be zero.
|
| static NotTEC | checkSingleSign (ReadView const &view, AccountID const &idSigner, AccountID const &idAccount, SLE::const_pointer sleAccount, beast::Journal const j) |
| static NotTEC | checkMultiSign (ReadView const &view, ApplyFlags flags, AccountID const &id, STObject const &sigObject, beast::Journal const j) |
|
| std::pair< TER, XRPAmount > | reset (XRPAmount fee) |
| | Reset the context, discarding any changes made and adjust the fee.
|
| TER | consumeSeqProxy (SLE::pointer const &sleAccount) |
| TER | payFee () |
| std::tuple< TER, XRPAmount, bool > | processPersistentChanges (TER result, XRPAmount fee) |
| void | trapTransaction (UInt256) const |
| void | visitEntry (bool isDelete, SLE::ConstRef before, SLE::ConstRef after) final |
| | Bridges the two-phase TxInvariantCheck interface to this transactor's visitInvariantEntry/finalizeInvariants hooks.
|
| bool | finalize (STTx const &tx, TER result, XRPAmount fee, ReadView const &view, beast::Journal const &j) final |
| | Called after all entries have been visited.
|
Allows a confidential MPT holder to rotate or recover their ElGamal encryption key, or to cancel a pending recovery.
Submitted by the holder. Exactly one of three modes must be selected via the transaction flags:
- Rotation (tfHolderKeyRotation): the holder still has their current ElGamal private key. They provide a new public key along with their current spending/inbox balances re-encrypted under that new key. The holder's encryption key and confidential balances are updated immediately.
- Recovery (tfHolderKeyRecovery): the holder has lost their current private key. They provide a new public key but cannot provide re-encrypted balances. The new key is recorded as a pending sfRecoveryKey; the confidential balances are left untouched. Completing the recovery (rewriting the balances) is done separately by the issuer via ConfidentialMPTRecoverBalance.
- Cancel (tfCancelRecovery): the holder revokes a pending recovery authorization created by a prior Recovery-mode transaction. No key, balances, or proof are carried; authorization is via the holder's ordinary XRPL signature. sfRecoveryKey is removed and everything else is left untouched. Fails if no recovery is pending.
- Note
- Zero-knowledge proof verification for Rotation and Recovery is deferred to a follow-up once the mpt-crypto constructions are finalized.
Definition at line 45 of file tx/transactors/token/ConfidentialMPTHolderKeyUpdate.h.
Which invariant layers to check.
Full runs the protocol invariants plus the transaction-specific check. This is always the scope of the initial pass, even when the tentative TER is a tec: a bug or exploit could still mutate ledger state, so transaction-specific invariants must run for failed transactions too.
ProtocolOnly runs only the protocol invariants and is used exclusively for the second invariant pass that follows a fee-claim reset — specifically, the reset that Transactor::operator() performs when the initial invariant pass returns tecINVARIANT_FAILED, rolling the transaction's effects back to a fee-claim-only state. In that reduced state the transaction-specific post-conditions no longer apply, but the protocol invariants must still hold against the fee claim itself. ProtocolOnly is not intended for other context discards (e.g. the reset used to handle tecOVERSIZE/tecKILLED/etc. in processPersistentChanges, or the ctx_.discard() done under TapFailHard); those paths do not re-run invariants at all.
| Enumerator |
|---|
| Full | |
| ProtocolOnly | |
Definition at line 217 of file Transactor.h.
Inspect a single ledger entry modified by this transaction.
Called once for every SLE created, modified, or deleted by the transaction, before finalizeInvariants. Implementations should accumulate whatever state they need to verify transaction-specific post-conditions.
- Parameters
-
| isDelete | true if the entry was erased from the ledger. |
| before | the entry's state before the transaction (nullptr for newly created entries). |
| after | the entry's state as supplied by the apply logic for this transaction. For deletions, this is the SLE being erased and is not guaranteed to be null; callers must use isDelete rather than after == nullptr to detect deletions. |
Implements xrpl::Transactor.
Definition at line 205 of file ConfidentialMPTHolderKeyUpdate.cpp.
Check transaction-specific post-conditions after all entries have been visited.
Called once after every modified ledger entry has been passed to visitInvariantEntry. Returns true if all transaction-specific invariants hold, or false to fail the transaction with tecINVARIANT_FAILED.
- Parameters
-
| tx | the transaction being applied. |
| result | the tentative TER result so far. |
| fee | the fee consumed by the transaction. |
| view | read-only view of the ledger after the transaction. |
| j | journal for logging invariant failures. |
- Returns
- true if all invariants pass; false otherwise.
Implements xrpl::Transactor.
Definition at line 210 of file ConfidentialMPTHolderKeyUpdate.cpp.
Checks whether the transaction is authorized to be executed by the delegated account.
This function enforces the strict permission check hierarchy. It is explicitly designed NOT to be overridden. Derived transactors must instead implement checkGranularSemantics to add custom validation logic for granular permissions.
The evaluation proceeds as follows:
- If transaction-level permission is granted, the function immediately returns tesSUCCESS.
- If transaction-level permission is not granted, the function checks whether the transaction matches the granular permission template defined in permissions.macro. If it does, it then calls checkGranularSemantics to perform any additional, fine-grained validation.
Definition at line 344 of file Transactor.h.