v0.3.1
Core-library changes since v0.3.0, including the core changes from v0.3.1-mpt.0. The original pre-release notes remain available.
Added
address-codec
- Added
DecodeAddress()to resolve classic and X-addresses to their decoded AccountID, andIsZeroAccountID()to identify ACCOUNT_ZERO.
binary-codec
- Added XLS-96 confidential MPT fields and definitions for
ConfidentialMPTSend,ConfidentialMPTConvert,ConfidentialMPTConvertBack,ConfidentialMPTMergeInbox, andConfidentialMPTClawback.ConfidentialOutstandingAmountuses decimal-string serialization. - Added the
tecBAD_PROOF,tecNO_SPONSOR_PERMISSION,temBAD_CIPHERTEXT,tefBAD_PATH_COUNT,tefNO_DST_PARTIAL, andterNO_PERMISSIONtransaction result mappings. - Added single-sign and multisign encoders for counterparty and sponsor roles using the
fixCleanup3_4_0signing prefixes.
pkg/crypto
- Added
IsCompressedSECP256K1Point()to validate compressed secp256k1 curve points andCompressedSECP256K1PointByteLengthfor their encoded size.
pkg/hexutil
- Added
DecodeFixedHex()to decode hexadecimal values and enforce their decoded byte length.
pkg/mptsizes
- Added CGo-free XLS-96 wire-size constants shared by the transaction models and native bindings. The bindings check these constants against the vendored
mpt-cryptoheaders at compile time.
xrpl/flag
- Added
ContainsAnyto check whether any bits in a flag mask are set.
xrpl/hash
- Added
MPToken()andMPTokenIssuance()helpers for computing MPT ledger-entry keylet indexes.
xrpl/ledger-entry-types
- Added confidential balance and encryption-key fields to
MPTokenandMPTokenIssuance. - Added optional
VaultIDandLoanBrokerIDfields toAccountRoot, preserving pseudo-account links in typed ledger andaccount_inforesponses. - Added the
Sponsorshipledger model and factory support, sponsor fields on supported ledger entries, and sponsorship counters onAccountRoot. Optional budgets and counters preserve absent versus explicit zero values. Network use requires theSponsoramendment. - Added optional
LEVersion,VaultKind,SubscriptionDate, andRedemptionDatefields toVaultforLendingProtocolV1_1.
xrpl/queries
- Added
account_sponsoringmodels and RPC/WebSocket client methods. Requires a server supporting this method, identified as Clio-only by XRPL.js. - Added the optional
account_objects.sponsoredfilter, the sponsorship object type, andledger_entrysponsorship selectors by object ID or sponsor/sponsee pair.
xrpl/queries/vault
- Added
AssetScale,MaximumAmount,TransferFee,MPTokenMetadata,LockedAmount, andReferenceHoldingto typedvault_infoshare responses. - Added optional
LEVersion,VaultKind,SubscriptionDate, andRedemptionDatefields to typedvault_inforesponses.
xrpl/rpc, xrpl/websocket
- Added the required 10x base fee for confidential MPT transactions during autofill, including inner Batch transactions, plus the normal per-signer surcharge.
- Added X-address normalization for
Sponsor,Sponsee, andCounterpartySponsor, with embedded tags rejected. - Added
ValidateSponsorshipandValidateSponsorshipContextfor opt-in checks of sponsorship signature requirements and fee budgets against the current ledger. They reuse the transaction sponsorship rules without modifying the input.SponsorshipValidationreports the outcome, entry, and fee checked. OnlyentryNotFoundmeans an absent entry. Other lookup errors and mismatched entries are returned as errors. Autofill and submission remain unchanged by this optional check.
xrpl/transaction
- Added the five XLS-96 confidential MPT transaction models with amount, encryption-key, blinding-factor, ciphertext, commitment, and proof-size validation.
ConfidentialMPTSendsupportsDestinationTagand rejects duplicate tags in the destination X-address. - Added
IssuerEncryptionKeyandAuditorEncryptionKeytoMPTokenIssuanceSet. An auditor key requires an issuer key in the same transaction, and neither can be combined withHolder. - Added
IsMPTokenIssuer()to check whether an address is the issuer encoded in an MPT issuance ID. - Added
ErrZeroAccountID,ErrAccountZero,ErrDelegateZero,ErrDelegateTagNotAllowed,ErrSignerAccountZero, andErrSignerAccountTagNotAllowedfor field-specific address validation. Wrapped conditions remain matchable witherrors.Is. - Added
ErrAccountIDTagNotAllowedandErrDuplicateXAddressTagas aliases of the binary-codec sentinels, so validation and encoding share error identities. - Added
InspectSponsorFieldsfor non-mutating sponsorship validation before autofill, returning the typed sponsor signature while preserving field presence. - Added common sponsorship fields, fee and reserve flags, and sponsor signature validation, including Batch inner transaction checks. Pseudo-transactions reject sponsorship with
ErrPseudoTransactionSponsorship. Sponsor multisignatures require at most 32 signers in strict decoded AccountID order. Network use requires theSponsoramendment. - Added
SponsorshipSetandSponsorshipTransfertransactions with operation flags, signed budget deltas, and validation for counterparty, deletion, reserve sponsorship, and account-level sponsor authorization rules. Network use requires theSponsoramendment. - Added
LedgerStateFixTx,SponsorshipSetTx, andSponsorshipTransferTxtransaction type constants. - Added the Payment
TfSponsorCreatedAccountflag and setter, with validation for native XRP amounts and incompatible fields and flags. Network use requires theSponsoramendment. - Added
IsNonZeroDomainIDto check 64-character hexadecimal domain IDs excluding zero, without checking ledger existence or permissions.IsDomainIDstill accepts zero. - Added closed-ended VaultCreate fields with investment-period validation and top-level VaultDelete
MemoDataforLendingProtocolV1_1. - Added
CredentialIDsto VaultWithdraw and LoanBrokerCoverWithdraw. These fields requireCredentialsandfixCleanup3_4_0.
xrpl/wallet
- Added non-mutating
SignAsSponsorandCombineSponsorSignershelpers, with map/blob APIs and examples. Co-signing preserves account signatures and requires theSponsorandfixCleanup3_4_0amendments. - Added
AddPreFundedSponsorto attach sponsorship fields to an unsigned copy before autofill and account signing. It does not create or fund a ledger Sponsorship entry.
Changed
module
- Separated the confidential cryptography and builders introduced in
v0.3.1-mpt.0into the optionalgithub.com/Peersyst/xrpl-go/confidentialmodule, first released asv0.1.0. Core retains protocol models, codecs, clients, and wallet signing without a dependency on the native helpers. Core Go module downloads no longer include the confidential native bundles. Repository clones and GitHub source archives still contain both modules.
binary-codec
- Updated binary definitions to a rippled 3.4.0 development build (
21890d9d), including new protocol fields and removal of unused Hook field definitions. FeeAmountDeltanow accepts negative XRP strings and rejects non-string values, including IOU and MPT objects. Ordinary amount encoding is unchanged.
development
- Root
./...commands now check core only. Usemake workspaceand the separate confidential test and lint targets for paired development. Core and confidential CI and releases are scoped to the selected module.
xrpl/queries/transactions
- Deprecated
SimulateRequest.ValidateNetworkIDand the simulation input-validation error values, retaining them for source compatibility.ValidateandValidateNetworkIDnow only reject nil requests.
xrpl/rpc, xrpl/websocket
Simulatenow delegates request validation to the server, including input selection, signatures, blob syntax, andNetworkID. Removed simulation-specific network identity discovery. Nil-request protection and response validation remain enabled.ErrRawTransactionsFieldMissing,ErrRawTransactionFieldMissing,ErrCouldNotGetBaseFeeXrp,ErrCouldNotFetchOwnerReserve,ErrLoanBrokerIDRequired, andErrCouldNotFetchLoanBrokerOwnernow share values across both clients, soerrors.Ismatches an error raised by either client.- Deprecated
ErrFeeFieldMissing,ErrCounterpartyRequired, andErrFailedToParseFee. Fee calculation no longer returns them. - Autofill fetches the network fee once per transaction instead of once per inner Batch transaction, reducing repeated
server_inforequests.
xrpl/transaction
BaseTx.Validate()now rejects ACCOUNT_ZERO forAccountandDelegate, and rejects tagged X-addresses forDelegate. Consensus-generated pseudo-transactions remain exempt from the Account zero check.- Transaction multisigner validation now rejects more than 32 signers, duplicate accounts, and lists not ordered by decoded AccountID. Validation does not reorder signers.
ErrClawbackHolderTagNotAllowednow wrapsErrAccountIDTagNotAllowed, preserving consistenterrors.Ischecks and adding the wrapped reason to its message.
xrpl/wallet
- LoanSet counterparty signing now uses role-specific prefixes and requires
fixCleanup3_4_0on the target network. For networks without this amendment, use a previous library release.
Fixed
dependencies
- Raised the minimum Go version from 1.25.12 to 1.25.13 to fix the
net/urlquadratic path-resolution vulnerability (GO-2026-6218).
xrpl/ledger-entry-types
- Fixed
Check.SendMaxJSON decoding to select the concrete amount type and preserve all other fields. Failed decoding leaves the receiver unchanged. Successful object decoding replaces its contents, while top-levelnullremains a no-op. - Fixed JSON decoding to preserve
indexinOfferandNFTokenOffer. - Fixed failed JSON decoding to leave existing
Escrow,NFTokenOffer,Offer, andPriceDatavalues unchanged.
xrpl/rpc, xrpl/websocket
- Fixed fee calculation for transactions whose fee is a multiple of the base fee. Multipliers now apply to the exact load-adjusted network fee, and the total is rounded once. Batch inner fees are summed at the same precision.
- Fixed AccountDelete autofill to reject outstanding sponsorship obligations with
ErrAccountHasSponsorshipObligationsand a supplied destination that does not identify the account's sponsor withErrAccountDeleteSponsorMismatch.
xrpl/transaction
- Fixed failed JSON decoding to leave an existing
EscrowCreatevalue unchanged. - Reject zero
DomainIDreferences in Payment, OfferCreate, MPTokenIssuanceCreate, and VaultCreate. Preserve zero-domain clearing in MPTokenIssuanceSet and VaultSet. - Reject an empty
MPTokenIssuanceSet.DomainIDduring validation instead of failing later during binary encoding. Use 64 zero digits to request domain removal. - Compare decoded account identities in BaseTx Delegate checks and in DepositPreauth, NFTokenCreateOffer, SetRegularKey, DelegateSet, NFTokenMint, NFTokenModify, MPTokenAuthorize, and MPTokenIssuanceSet self-reference checks, so equivalent classic and X-addresses cannot bypass them. AMMClawback now accepts equivalent address forms in its asset issuer/account check.
- Reject tagged X-addresses and ACCOUNT_ZERO in
SignerswithErrSignerAccountTagNotAllowedandErrSignerAccountZero, respectively. - Reject
ConfidentialMPTConvertandSponsorshipTransferpermissions inDelegateSetbecause these transaction types are not delegatable. - Reject odd-length
VaultCreate.Datahex during validation instead of failing later during binary encoding.
xrpl/transaction/types
- Fixed
CredentialIDs.IsValid()to require one to eight distinct, nonzero 256-bit hexadecimal IDs. This tightens validation of previously accepted lists. Zero IDs are rejected offline without checkingfixCleanup3_4_0activation.