spec(XLS-65): Update VaultCreate failure conditions and state changes - #549
spec(XLS-65): Update VaultCreate failure conditions and state changes#549Tapanito wants to merge 36 commits into
Conversation
…tion - Add Example JSON sections for Vault ledger entry and all transactions (VaultCreate, VaultSet, VaultDelete, VaultDeposit, VaultWithdraw, VaultClawback, Payment) with real transaction data - Add invariants for the Vault ledger entry (universal checks) and all transaction types derived from the ValidVault invariant checker - Restructure section 10 from "API" to "RPC: vault_info" matching the amendment template format with Request Fields, Response Fields, Failure Conditions, Example Request, and Example Response subsections - Update response fields table with missing fields (Data, Asset.mpt_issuance_id, shares.DomainID, shares.MPTokenMetadata) and correct Always Present values - Update response examples to use proper JSON format with response envelope - Add section 9.1 Fields for Payment transaction - Remove Index section and all Return to Index links Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Reorganize top-level sections: Abstract (1), Introduction (2), Specification (3), Rationale (4), Security Considerations (5), Appendix - Move all ledger entry, transaction, and RPC sections under "3. Specification" as subsections (3.1-3.9) - Remove "1.1 Overview" heading, merge content into Introduction body - Renumber Introduction subsections: Terminology (2.1), Actors (2.2), Connecting to the Vault (2.3) - Demote all specification headings by one level with new numbering - Add Rationale section explaining decoupled vault design - Rename FAQ section to "Appendix A: FAQ" with A.x numbering - Fix heading levels for Key Variables and Vault State Update Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Remove functional additions (invariants, example JSONs, error codes) added in this branch and retain only structural changes that bring the spec into conformance with AMENDMENT_TEMPLATE.md and XLS_TEMPLATE.md. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Convert failure conditions and state changes from numbered lists back to master's original nested bullet-point format. Keep the Data Verification / Protocol-Level Failures subsection headers as template compliance, but use master's original content and structure inside them. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Convert bullet points in Failure Conditions and State Changes sections to numbered lists with nested sub-numbering, per template requirements. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Mayukha Vadari <mvadari@gmail.com>
…-create # Conflicts: # XLS-0065-single-asset-vault/README.md
tyalymov
left a comment
There was a problem hiding this comment.
This PR syncs the spec with the current VaultCreate code, so I want to flag one thing. The order of the failure conditions in 3.2.5.2 differs from the evaluation order in VaultCreate.cpp, and that order is observable: when several conditions hold at once, the transactor returns the first one it hits.
Order in the code:
preclaim (checks run in this order):
- canAddHolding — can the vault's pseudo-account hold this asset at all:
IOU: terNO_ACCOUNT (issuer account missing),
then terNO_RIPPLE (issuer has no DefaultRipple)
MPT: tecOBJECT_NOT_FOUND (no MPTokenIssuance),
then tecNO_AUTH (token not transferable) - tecWRONG_ASSET (issuer is a pseudo-account)
- freeze/lock: tecFROZEN (IOU) / tecLOCKED (MPT)
- domain missing: tecOBJECT_NOT_FOUND
- terADDRESS_COLLISION
doApply (runs after all of preclaim):
6. tecINSUFFICIENT_RESERVE
Two places where the spec list disagrees:
tecWRONG_ASSET vs freeze/lock. The spec puts the freeze/lock checks (1.3 and 2.3) before tecWRONG_ASSET (item 3), but the code checks the pseudo-account issuer first. So for an asset whose issuer is a pseudo-account and is also frozen, the spec implies tecFROZEN/tecLOCKED while the code returns tecWRONG_ASSET.
tecINSUFFICIENT_RESERVE vs terADDRESS_COLLISION. The spec lists reserve (item 5) before address collision (item 6). In the code the collision check is in preclaim and the reserve check is in doApply, which runs later, so the order is reversed.
Is the numbered list meant to be the evaluation order? If so, can we move items 3 and 5/6 to match preclaim and doApply? If it is just a list of conditions with no order implied, a one-line note saying so would help, so nobody reads a precedence into it.
3.2.5.2 now follows the actual preclaim/doApply evaluation order: tecWRONG_ASSET is checked before freeze/lock, and terADDRESS_COLLISION (preclaim) before tecINSUFFICIENT_RESERVE (doApply, runs later). Addresses review feedback on PR #549.
|
Good catch, and yes — the list is meant to reflect evaluation order. Verified against |
| | `WithdrawalPolicy` | No | `number` | `UINT8` | `"FirstComeFirstServe"` | Indicates the withdrawal strategy used by the Vault. | | ||
| | `DomainID` | No | `string` | `HASH256` | | The `PermissionedDomain` object ID associated with the shares of this Vault. | | ||
| | `Scale` | No | `number` | `UINT8` | 6 | The `Scale` specifies the power of 10 ($10^{\text{scale}}$) to multiply an asset's value by when converting it into an integer-based number of shares. | | ||
| | `Scale` | No | `number` | `UINT8` | 6 | The `Scale` specifies the power of 10 ($10^{\text{scale}}$) to multiply an asset's value by when converting it into an integer-based number of shares. Ignored (fixed at `0`) when `Asset` is `XRP` or `MPT`; not stored on the `Vault` object in those cases. | |
There was a problem hiding this comment.
The Scale row says the field is ignored for XRP and MPT, but 3.2.5.1 item 7 in this same PR rejects it with temMALFORMED. VaultCreate.cpp:92-96 does the latter: if Scale is present and the asset is XRP or MPT, preflight fails. "Rejected" would be the accurate word here.
The "not stored on the Vault object" half is right: VaultCreate.cpp:243 only writes sfScale when the value is non-zero.
Syncs the VaultCreate spec section with the current implementation in
src/libxrpl/tx/transactors/vault/VaultCreate.cpp.Data Verification (3.2.5.1) — was
_TBD_, now populated:Protocol-Level Failures (3.2.5.2) — reorganised and extended:
terNO_ACCOUNT,terNO_RIPPLEfor IOU issuer checks (fromcanAddHolding)tecWRONG_ASSETfor pseudo-account issuerstecLOCKEDfor MPT lock (global or per-account, viaisFrozen)terADDRESS_COLLISIONfor pseudo-account address collisionState Changes (3.2.6) — extended:
tfVaultShareNonTransferableandtfVaultPrivate