Coin Brief ENDE

rippled adds an invariant that MPT issuance flags can never be cleared

The XRP Ledger server rippled merged pull request #8152, "fix: Enforce that MPT issuance flags are never cleared", on 6 October. The author is tyalymov.

Where it came from. An external review of the lending code flagged that LoanPay moves a broker fee in a multi-purpose token (MPT) from the borrower to the broker owner without checking lsfMPTCanTransfer, the flag that marks a token as transferable. Triage found the dangerous state unreachable: the transferability flag can be turned on after creation but never off, and VaultCreate has refused non-transferable assets since the first vault commit, so no vault, and therefore no loan, can hold such a token.

rippled adds an invariant that MPT issuance flags can never be cleared
rippled adds an invariant that MPT issuance flags can never be cleared — Coin Brief

The catch. That conclusion rests on one assumption: issuance flags never revert. Until now only the code of MPTokenIssuanceSet upheld it, by construction, since it only ever adds flags.

The fix. Instead of adding a transferability check to LoanPay (earlier commits on the branch did that and were reverted), the pull request adds the assumption itself to the ValidMPTIssuance invariant: no transaction may clear a flag on an MPTokenIssuance. The one exception is lsfMPTLocked, which tfMPTUnlock clears legitimately. A transaction that breaks the rule fails with tecINVARIANT_FAILED.

What changes for users. Nothing today. The check is gated on the fixCleanup3_5_0 amendment and, in the authors' words, "only fires if a future bug introduces" a path that clears a flag. It turns an assumption that held by accident of how one function was written into a rule the ledger enforces.

Primary source
rippled repository
https://github.com/XRPLF/rippled/pull/8152
Written by Victoria Shinder.