fix: Return objectNotFound for a non-existent book_offers domain - #7963
Draft
SoubeDev wants to merge 2 commits into
Draft
fix: Return objectNotFound for a non-existent book_offers domain#7963SoubeDev wants to merge 2 commits into
SoubeDev wants to merge 2 commits into
Conversation
The book_offers RPC validated the domain parameter for hex format but never checked that the PermissionedDomain existed in the ledger. The domain is folded into the order-book directory index by getBookBase(), so a typo'd or deleted domain ID hashed to a directory that was not there and the caller received an empty offers array, indistinguishable from a real domain with no offers. Look the domain up in the ledger and return objectNotFound when it is absent, consistent with amm_info (actNotFound), ledger_entry (entryNotFound), and nft_buy_offers/nft_sell_offers, which already return objectNotFound for a missing directory. Use read() rather than exists(): the caller supplies the raw ledger key, and Ledger::exists(Keylet) does not check the entry type, so the index of any unrelated object would otherwise pass and still yield an empty result. Reject the all-zero key up front, since Ledger::read treats a zero key as UNREACHABLE. Fixes XRPLF#6589
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The book_offers RPC validated the domain parameter for hex format but never checked that the PermissionedDomain existed in the ledger. The domain is folded into the order-book directory index by getBookBase(), so a typo'd or deleted domain ID hashed to a directory that was not there and the caller received an empty offers array, indistinguishable from a real domain with no offers.
Look the domain up in the ledger and return objectNotFound when it is absent, consistent with amm_info (actNotFound), ledger_entry (entryNotFound), and nft_buy_offers/nft_sell_offers, which already return objectNotFound for a missing directory.
Use read() rather than exists(): the caller supplies the raw ledger key, and Ledger::exists(Keylet) does not check the entry type, so the index of any unrelated object would otherwise pass and still yield an empty result. Reject the all-zero key up front, since Ledger::read treats a zero key as UNREACHABLE.
Fixes #6589
High Level Overview of Change
Context of Change
API Impact
libxrplchange (any change that may affectlibxrplor dependents oflibxrpl)