|
xrpld
|
Runtime interface for a transaction-specific invariant check. More...
#include <InvariantRunner.h>

Public Member Functions | |
| virtual | ~TxInvariantCheck ()=default |
| virtual void | visitEntry (bool isDelete, SLE::ConstRef before, SLE::ConstRef after)=0 |
| Called for each ledger entry modified by the transaction. | |
| virtual bool | finalize (STTx const &tx, TER result, XRPAmount fee, ReadView const &view, beast::Journal const &j)=0 |
| Called after all entries have been visited. | |
Runtime interface for a transaction-specific invariant check.
The free checkInvariants runner drives two layers of checks over a single walk of the modified ledger entries:
Both layers honour the same two-phase protocol:
Phase 1 — state collection (visitEntry). Called once for each ledger entry created, modified, or deleted by the transaction. Implementations accumulate whatever state they need to evaluate their post-conditions. Must not throw.
Phase 2 — condition evaluation (finalize). Called once after every modified entry has been visited. Returns true if all post-conditions hold, false to fail the transaction.
Rule: invariants must run regardless of transaction result. finalize MUST perform meaningful checks even when the transaction has failed (when result is not tesSUCCESS). A bug or exploit could cause a failed transaction to mutate ledger state in unexpected ways; invariants are the last line of defense.
The typical pattern: an invariant that expects a domain-specific state change (e.g. a Vault being created) should expect that change only when the transaction succeeded. A failed VaultCreate must not have created a Vault.
Rule: privilege-gated checks apply to failed transactions too. Failed transactions carry no privileges. Any privilege-gated assertion must therefore also be enforced for failed transactions.
Definition at line 61 of file InvariantRunner.h.
|
virtualdefault |
|
pure virtual |
Called for each ledger entry modified by the transaction.
| isDelete | true if the SLE is being deleted. |
| before | the entry's state before the transaction (nullptr for newly created entries). |
| after | the entry's state after the transaction. For deletions this is the SLE being erased; use isDelete rather than a null after to detect deletions. after is never null. |
Implemented in xrpl::Transactor.
|
nodiscardpure virtual |
Called after all entries have been visited.
| tx | the transaction being applied. |
| result | the tentative TER result of the transaction. |
| fee | the fee consumed by the transaction. |
| view | read-only view of the ledger after the transaction. |
| j | journal for logging invariant failures. |
Implemented in xrpl::Transactor.