Proposed XLS-0099 update changes key-rotation flags, proof size and failure rules
A pull request opened in the XRPL Standards repository on 7 October proposes changes to XLS-0099, the specification for rotating or recovering the encryption key that protects a holder's confidential multi-purpose token (MPT) balance. The transaction it describes, ConfidentialMPTHolderKeyUpdate, was merged into rippled's development branch on 2 October. The pull request is open, not merged.

What it changes.
- Flag values move. The three mode flags shift from the lowest bits to the upper half of the flags word:
tfHolderKeyRotationfrom 1 to 65536 (0x00010000),tfHolderKeyRecoveryfrom 2 to 131072,tfCancelRecoveryfrom 4 to 262144. Exactly one must still be set. - The rotation proof grows from 160 to 224 bytes; the recovery proof stays at 64. A proof of the wrong length is still rejected as malformed.
- A new error for a no-op. Submitting the key the holder already has now returns
tecDUPLICATEinstead oftecNO_PERMISSION. - Two preconditions are removed. The spec no longer requires the issuer key mirror, or the auditor's mirror and encrypted balance, to be migrated to the current epoch before a holder can rotate.
- Rotation clears a pending recovery. A successful rotation now also clears any
RecoveryKeyon the holder's token. The spec's reasoning: rotation proves the holder still has the old key, so a pending recovery authorisation is cancelled.
Why it matters to builders. Wallets and libraries that already encoded the draft flag values 1, 2 and 4 would send the wrong mode if this change lands. The pull request carries no description of its rationale beyond the diff itself.
Primary source
XRPL Standards
https://github.com/XRPLF/XRPL-Standards/pull/655Written by Serguey Asael Shinder / Serguey Shinder.