|
| static bool | checkExtraFeatures (PreflightContext const &ctx) |
| static NotTEC | preflight (PreflightContext const &ctx) |
| static XRPAmount | calculateBaseFee (ReadView const &view, STTx const &tx) |
| static TER | preclaim (PreclaimContext const &ctx) |
| static NotTEC | checkSeqProxy (ReadView const &view, STTx const &tx, beast::Journal j) |
| static NotTEC | checkPriorTxAndLastLedger (PreclaimContext const &ctx) |
| static TER | checkFee (PreclaimContext const &ctx, XRPAmount baseFee) |
| static NotTEC | checkSign (PreclaimContext const &ctx) |
| static XRPAmount | calculateBaseFee (ReadView const &view, STTx const &tx, std::uint32_t extraBaseFeeMultiplier) |
| static FeePayer | getFeePayer (ReadView const &view, STTx const &tx) |
| template<class T> |
| static NotTEC | invokePreflight (PreflightContext const &ctx) |
| template<> |
| NotTEC | invokePreflight (PreflightContext const &ctx) |
| template<> |
| NotTEC | invokePreflight (PreflightContext const &ctx) |
| static NotTEC | checkGranularSemantics (ReadView const &view, STTx const &tx, std::unordered_set< GranularPermissionType > const &heldGranularPermissions) |
| | This function can be overridden to introduce additional semantic constraints beyond the granular template validation for granular permissions.
|
| template<class T> |
| static NotTEC | invokeCheckPermission (ReadView const &view, STTx const &tx) |
| | Checks whether the transaction is authorized to be executed by the delegated account.
|
| static NotTEC | checkSponsor (ReadView const &view, STTx const &tx) |
| static TER | ticketDelete (ApplyView &view, AccountID const &account, UInt256 const &ticketIndex, beast::Journal j) |
|
| static NotTEC | checkSign (ReadView const &view, ApplyFlags flags, std::optional< UInt256 const > const &parentBatchId, AccountID const &idAccount, STObject const &sigObject, beast::Journal const j, bool permitUncreatedAccount=false) |
| static XRPAmount | minimumFee (ServiceRegistry ®istry, XRPAmount baseFee, Fees const &fees, ApplyFlags flags) |
| | Compute the minimum fee required to process a transaction with a given baseFee based on the current server load.
|
| static XRPAmount | calculateOwnerReserveFee (ReadView const &view, STTx const &tx) |
| static std::uint32_t | getFlagsMask (PreflightContext const &ctx) |
| static NotTEC | preflightSigValidated (PreflightContext const &ctx) |
| static bool | validDataLength (std::optional< Slice > const &slice, std::size_t maxLength) |
| template<class T> |
| static bool | validNumericRange (std::optional< T > value, T max, T min=T{}) |
| template<class T, class Unit> |
| static bool | validNumericRange (std::optional< T > value, unit::ValueUnit< Unit, T > max, unit::ValueUnit< Unit, T > min=unit::ValueUnit< Unit, T >{}) |
| template<class T> |
| static bool | validNumericMinimum (std::optional< T > value, T min=T{}) |
| | Minimum will usually be zero.
|
| template<class T, class Unit> |
| static bool | validNumericMinimum (std::optional< T > value, unit::ValueUnit< Unit, T > min=unit::ValueUnit< Unit, T >{}) |
| | Minimum will usually be zero.
|
| static NotTEC | checkSingleSign (ReadView const &view, AccountID const &idSigner, AccountID const &idAccount, SLE::const_pointer sleAccount, beast::Journal const j) |
| static NotTEC | checkMultiSign (ReadView const &view, ApplyFlags flags, AccountID const &id, STObject const &sigObject, beast::Journal const j) |
|
| std::pair< TER, XRPAmount > | reset (XRPAmount fee) |
| | Reset the context, discarding any changes made and adjust the fee.
|
| TER | consumeSeqProxy (SLE::pointer const &sleAccount) |
| TER | payFee () |
| std::tuple< TER, XRPAmount, bool > | processPersistentChanges (TER result, XRPAmount fee) |
| void | trapTransaction (UInt256) const |
| void | visitEntry (bool isDelete, SLE::ConstRef before, SLE::ConstRef after) final |
| | Bridges the two-phase TxInvariantCheck interface to this transactor's visitInvariantEntry/finalizeInvariants hooks.
|
| bool | finalize (STTx const &tx, TER result, XRPAmount fee, ReadView const &view, beast::Journal const &j) final |
| | Called after all entries have been visited.
|
Updates the encrypted mirror balances of a Confidential MPToken.
This transaction updates a single holder's mirrored confidential balances (sfIssuerEncryptedBalance and/or sfAuditorEncryptedBalance) with the latest ElGamal public keys defined on the MPTokenIssuance.
It supports both issuer and holder self-migration modes, each mode supports multiple flows:
- Issuer mode: Submitted by the issuer.
- Issuer Key Rotation Migration: Re-encrypts the holder's sfIssuerEncryptedBalance under the issuer's new ElGamal public key.
- Auditor Key Rotation Migration: Re-encrypts the holder's sfAuditorEncryptedBalance under the auditor's new ElGamal public key.
- Simultaneous Rotation Migration: Updates both the issuer and auditor encrypted balances in a single transaction to optimize network throughput.
- Auditor Late-Registration Migration: When the issuer ElGamal public key is already registered on the MPTokenIssuance object, the issuer can register an auditor key at a later time through MPTokenIssuanceSet. Then the issuer uses this flow to set the holder's initial sfAuditorEncryptedBalance on MPToken object.
- Holder self-migration mode: Submitted by the holder. The holder decrypts their own sfConfidentialBalanceSpending with holder's private key to recover the balance and re-encrypts it under the relevant new ElGamal public key(s). This mode is always available to the holder and is not conditioned on the issuer being unable to migrate them: the ledger cannot verify whether an issuer has really lost its private key. That loss is only the expected motivation, since an issuer that still holds its key can migrate holders itself in issuer mode.
- Note
- All holder migration flows strictly require the holder's sfConfidentialBalanceInbox to be canonically zero; the holder must run ConfidentialMPTMergeInbox first so the spending balance reflects the full balance.
- Holder Issuer-Mirror Migration: Re-encrypts the holder's sfIssuerEncryptedBalance under the issuer's new ElGamal public key.
- Holder Auditor-Mirror Migration: Re-encrypts the holder's sfAuditorEncryptedBalance under the auditor's new ElGamal public key, or sets it for the first time when the auditor key was late-registered. This is the holder-driven counterpart to flows 2 and 4, for when the issuer does not migrate the holder itself.
- Simultaneous Holder Self-Migration: Updates both the issuer and auditor encrypted balances in a single transaction (both keys have rotated).
Definition at line 62 of file tx/transactors/token/ConfidentialMPTMirrorUpdate.h.
Which invariant layers to check.
Full runs the protocol invariants plus the transaction-specific check. This is always the scope of the initial pass, even when the tentative TER is a tec: a bug or exploit could still mutate ledger state, so transaction-specific invariants must run for failed transactions too.
ProtocolOnly runs only the protocol invariants and is used exclusively for the second invariant pass that follows a fee-claim reset — specifically, the reset that Transactor::operator() performs when the initial invariant pass returns tecINVARIANT_FAILED, rolling the transaction's effects back to a fee-claim-only state. In that reduced state the transaction-specific post-conditions no longer apply, but the protocol invariants must still hold against the fee claim itself. ProtocolOnly is not intended for other context discards (e.g. the reset used to handle tecOVERSIZE/tecKILLED/etc. in processPersistentChanges, or the ctx_.discard() done under TapFailHard); those paths do not re-run invariants at all.
| Enumerator |
|---|
| Full | |
| ProtocolOnly | |
Definition at line 217 of file Transactor.h.
Inspect a single ledger entry modified by this transaction.
Called once for every SLE created, modified, or deleted by the transaction, before finalizeInvariants. Implementations should accumulate whatever state they need to verify transaction-specific post-conditions.
- Parameters
-
| isDelete | true if the entry was erased from the ledger. |
| before | the entry's state before the transaction (nullptr for newly created entries). |
| after | the entry's state as supplied by the apply logic for this transaction. For deletions, this is the SLE being erased and is not guaranteed to be null; callers must use isDelete rather than after == nullptr to detect deletions. |
Implements xrpl::Transactor.
Definition at line 258 of file ConfidentialMPTMirrorUpdate.cpp.
Check transaction-specific post-conditions after all entries have been visited.
Called once after every modified ledger entry has been passed to visitInvariantEntry. Returns true if all transaction-specific invariants hold, or false to fail the transaction with tecINVARIANT_FAILED.
- Parameters
-
| tx | the transaction being applied. |
| result | the tentative TER result so far. |
| fee | the fee consumed by the transaction. |
| view | read-only view of the ledger after the transaction. |
| j | journal for logging invariant failures. |
- Returns
- true if all invariants pass; false otherwise.
Implements xrpl::Transactor.
Definition at line 263 of file ConfidentialMPTMirrorUpdate.cpp.
Checks whether the transaction is authorized to be executed by the delegated account.
This function enforces the strict permission check hierarchy. It is explicitly designed NOT to be overridden. Derived transactors must instead implement checkGranularSemantics to add custom validation logic for granular permissions.
The evaluation proceeds as follows:
- If transaction-level permission is granted, the function immediately returns tesSUCCESS.
- If transaction-level permission is not granted, the function checks whether the transaction matches the granular permission template defined in permissions.macro. If it does, it then calls checkGranularSemantics to perform any additional, fine-grained validation.
Definition at line 344 of file Transactor.h.