|
xrpld
|
The XRP Ledger has many and diverse stakeholders, and everyone deserves a chance to contribute meaningful changes to the code that runs the XRPL.
We assume you are familiar with the general practice of making contributions on GitHub. This file includes only special instructions specific to this project.
The following branches exist in the main project repository:
See RELEASING.md for how these branches are used.
The tip of each branch must be signed. In order for GitHub to sign a squashed commit that it builds from your pull request, GitHub must know your verifying key. Please set up signature verification.
In general, external contributions should be developed in your personal fork. Contributions from developers with write permissions should be done in the main repository in a branch with a permitted prefix. Permitted prefixes are:
Regardless of where the branch is created, please open a draft pull request as soon as possible after pushing the branch to Github, to increase visibility, and ease feedback during the development process.
If your contribution is a major feature or breaking change, then you must first write an XRP Ledger Standard (XLS) describing it. Go to XRPL-Standards, choose the next available standard number, and open a discussion with an appropriate title to propose your draft standard.
When you submit a pull request, please link the corresponding XLS in the description. An XLS still in Draft status is considered a work-in-progress and open for discussion. Please allow time for questions, suggestions, and changes to the XLS draft. It is the responsibility of the XLS author to update the draft to match the final implementation when its corresponding pull request is merged, unless the author delegates that responsibility to others.
Any amendment or major RPC change requires either a new XLS or an update to an existing XLS. Neither change will be released (in an amendment's case, marked as Supported::yes) until the corresponding XLS's status is Final.
AGENTS.md (and its CLAUDE.md symlink, for Claude Code) holds shared, checked-in guidance for AI coding agents working in this repository — build/test/lint commands and architecture notes. Additional AGENTS.md files may exist in subdirectories to give agents context specific to that part of the codebase; whenever you add one, also add a CLAUDE.md symlink pointing to it (ln -s AGENTS.md CLAUDE.md) so Claude Code picks it up too.
If you want to give an agent personal instructions that shouldn't be shared with other contributors (e.g. your own workflow preferences), those are gitignored, not checked in:
Likewise, .claude/settings.local.json is for personal, untracked Claude Code settings, while .claude/settings.json is shared.
(Or marking a draft pull request as ready.)
Changes that alter transaction processing must be guarded by an Amendment. All other changes that maintain the existing behavior do not need an Amendment.
Ensure that your code compiles according to the build instructions in BUILD.md.
Please write tests for your code. If your test can be run offline, in under 60 seconds, then it can be an automatic test run by xrpld --unittest. Otherwise, it must be a manual test.
If you create new source files, they must be organized as follows:
The source must be formatted according to the style guide below. The easiest way to satisfy this is to install the `pre-commit`pre-commit hooks, which format and lint your changes automatically on every commit.
Header includes must be levelized.
Changes should be usually squashed down into a single commit. Some larger or more complicated change sets make more sense, and are easier to review if organized into multiple logical commits. Either way, all commits should fit the following criteria:
. to explain a specific aspects of the change.
Refer to "How to Write a Git Commit Message" for general rules on writing a good commit message.
tl;dr
- Separate subject from body with a blank line.
- Limit the subject line to 50 characters.
- [...]shoot for 50 characters, but consider 72 the hard limit.
- Capitalize the subject line.
- Do not end the subject line with a period.
- Use the imperative mood in the subject line.
- A properly formed Git commit subject line should always be able to complete the following sentence: "If applied, this commit will _your subject line here_".
- Wrap the body at 72 characters.
- Use the body to explain what and why vs. how.
In general, pull requests use develop as the base branch.
The exceptions are fixes for an existing release line, which use that line's staging branch (e.g. staging/3.4.x) as the base.
If your changes are not quite ready, but you want to make it easily available for preliminary examination or review, you can create a "Draft" pull request. While a pull request is marked as a "Draft", you can rebase or reorganize the commits in the pull request as desired.
Github pull requests are created as "Ready" by default, or you can mark a "Draft" pull request as "Ready". Once a pull request is marked as "Ready", any changes must be added as new commits. Do not force-push to a branch in a pull request under review. (This includes rebasing your branch onto the updated base branch. Use a merge operation, instead or hit the "Update branch" button at the bottom of the Github PR page.) This preserves the ability for reviewers to filter changes since their last review.
A pull request must obtain approvals from at least two reviewers before it can be considered for merge by a Maintainer. Maintainers retain discretion to require more approvals if they feel the credibility of the existing approvals is insufficient.
Pull requests must be merged by squash-and-merge to preserve a linear history for the develop branch.
In addition to those guidelines, please start your PR title with one of the following:
First letter after the type prefix should be capitalized, and the type prefix should be followed by a colon and a space. e.g. feat: Add support for Borrowing Protocol.
A pull request should only have the "Ready to merge" label added when it meets a few criteria:
. (Exception: PRs that are deemed "trivial" only need one approval.)
.
The PR branch must be up to date with the base branch (usually develop). This is usually accomplished by merging the base branch into the feature branch, but if the other criteria are met, the changes can be squashed and rebased on top of the base branch.
Once the "Ready to merge" label is added, a maintainer may merge the PR at any time, so don't use it lightly.
This is a non-exhaustive list of recommended style guidelines. These are not always strictly enforced and serve as a way to keep the codebase coherent rather than a set of thou shalt not commandments.
We use the pre-commit framework to run the formatting and linting tools that keep the codebase consistent. pre-commit runs each tool configured in .pre-commit-config.yaml in its own isolated environment, so you don't need to install most of the individual tools yourself. The version of each hook sourced from an external repository (clang-format, gersemi, etc.) is pinned in that file, so running the hooks locally uses exactly the same versions as CI. A few local hooks — most notably clang-tidy and cargo fmt — run tools from your own environment; see Installing clang-tidyInstalling clang-tidy and Rust for how to get those.
To get started, install pre-commit and enable the git hook scripts:
Once installed, the hooks run automatically on your staged files every time you git commit. You can also run them on demand:
The hooks configured in this repository include, among others:
)
); opt in with TIDY=1
The same hooks run in CI on every pull request, so running them locally before you push helps you avoid CI failures.
All code must conform to clang-format, according to the settings in .clang-format, unless the result would be unreasonably difficult to read or maintain. The clang-format version is pinned in .pre-commit-config.yaml, so the `pre-commit`pre-commit hook always formats with the same version as CI. To demarcate lines that should be left as-is, surround them with comments like this:
The easiest way to format your changes is to let the pre-commit hook run automatically on commit, or to run it manually:
You can also format individual files in place by running clang-format -i <file>... from any directory within this project.
There is a Continuous Integration job that runs clang-format on pull requests. If the code doesn't comply, a patch file that corrects auto-fixable formatting issues is generated.
To download the patch file:
All code must pass clang-tidy checks according to the settings in .clang-tidy.
There is a Continuous Integration job that runs clang-tidy on pull requests. The CI will check:
This ensures that configuration changes don't introduce new warnings across the codebase.
See the environment setup guide for how to get clang-tidy.
Before running clang-tidy, you must generate the files it depends on (protobuf headers, and, when the project is configured with -Drust=ON, the cxxbridge headers from the Rust crates). Configure the project as described in BUILD.md, then build the tidy_prerequisites target, which generates all of them:
If you have already installed the `pre-commit`pre-commit hooks, you can run clang-tidy on your staged files using:
This runs clang-tidy locally with the same configuration/flags as CI, scoped to your staged C++ files. The TIDY=1 environment variable is required to opt in — without it the hook is skipped.
You can also have clang-tidy run automatically on every git commit by setting TIDY=1 in your shell environment:
With this set, the hook will run as part of git commit alongside the other pre-commit checks.
Then run clang-tidy on your local changes:
This will check all source files in the src, include and tests directories using the compile commands from your build directory. If you wish to automatically fix whatever clang-tidy finds and is capable of fixing, add -fix -format to the above command:
-format reformats the fixed code with .clang-format; without it the fixes are inserted in LLVM style and the clang-format hook rewrites them afterwards.
We are using Antithesis for continuous fuzzing, and keep a copy of Antithesis C++ SDK in external/antithesis-sdk. One of the aims of fuzzing is to identify bugs by finding external conditions which cause contracts violations inside xrpld. The contracts are expressed as XRPL_ASSERT or UNREACHABLE (defined in include/xrpl/beast/utility/instrumentation.h), which are effectively (outside of Antithesis) wrappers for assert(...) with added name. The purpose of name is to provide contracts with stable identity which does not rely on line numbers.
When xrpld is built with the Antithesis instrumentation enabled (using voidstar CMake option) and ran on the Antithesis platform, the contracts become test properties; otherwise they are just like a regular assert. To learn more about Antithesis, see How Antithesis Works and C++ SDK
We continue to use the old style assert or assert(false) in certain locations, where the reporting of contract violations on the Antithesis platform is either not possible or not useful.
For this reason:
To execute all unit tests:
xrpld --unittest --unittest-jobs=<number of cores>
(Note: Using multiple cores on a Mac M1 can cause spurious test failures. The cause is still under investigation. If you observe this problem, try specifying fewer jobs.)
To run a specific set of test suites:
Note: In this example, all tests with prefix TestSuiteName will be run, so if TestSuiteName1 and TestSuiteName2 both exist, then both tests will run. Alternatively, if the unit test name finds an exact match, it will stop doing partial matches, i.e. if a unit test with a title of TestSuiteName exists, then no other unit test will be executed, apart from TestSuiteName.
Maintainers are ecosystem participants with elevated access to the repository. They are able to push new code, make decisions on when a release should be made, etc.
New maintainers can be proposed by two existing maintainers, subject to a vote by a quorum of the existing maintainers. A minimum of 50% support and a 50% participation is required. In the event of a tie vote, the addition of the new maintainer will be rejected.
Existing maintainers can resign, or be subject to a vote for removal at the behest of two existing maintainers. A minimum of 60% agreement and 50% participation are required. The XRP Ledger Foundation will have the ability, for cause, to remove an existing maintainer without a vote.
Maintainers are users with maintain or admin access to the repo.
Code Reviewers are developers who have the ability to review, approve, and in some cases merge source code changes.
Developers not on this list are able and encouraged to submit feedback on pending code changes (open pull requests).
These instructions assume you have your git upstream remotes configured to avoid accidental pushes to the main repo, and a remote group specifying both of them. e.g.
You can use the setup-upstreams script to set this up.
It also assumes you have a default gpg signing key set up in git. e.g.
The maintainer should double-check that the PR has met all the necessary criteria, and can request additional information from the owner, or additional reviews, and can always feel free to remove the "Ready to merge" label if appropriate. The maintainer has final say on whether a PR gets merged, and are encouraged to communicate and issues or concerns to other maintainers.
Most pull requests don't need special handling, and can simply be merged using the "Squash and merge" button on the Github UI. Update the suggested commit message, or modify it as needed.
Some pull requests need to be pushed to their base branch (usually develop) as more than one commit. A PR author may request to merge as separate commits. They must justify why separate commits are needed, and specify how they would like the commits to be merged. If you disagree with the author, discuss it with them directly.
If the process is reasonable, follow it. The simplest option is to do a fast forward only merge (--ff-only) on the command line and push to the base branch.
Some examples of when separate commits are worthwhile are:
Either way, check that:
The "Create a merge commit" and "Rebase and merge" options should be disabled in the Github UI, but if you ever find them available Do not use them!
Releases, release branches, and merging releases back into develop are described in RELEASING.md.