Ripple pushes XRP Ledger node upgrade after manifest flood exposes flaw

Node operators running the XRP Ledger are being told to move fast. Ripple’s Director of Engineering, Vijay Khanna, urged infrastructure providers on Aug. 2 to complete an XRP Ledger node upgrade to xrpld version 3.2.1 after developers spotted a validator manifest flood hitting the network on July 31. The ledger kept producing blocks throughout the incident, but the episode exposed a resource-exhaustion weakness that Ripple has now moved to close with a targeted hotfix.
Key takeaways
- A validator manifest flood on July 31 pushed Ripple to release xrpld 3.2.1 as an emergency hotfix published Aug. 1.
- The XRP Ledger kept closing ledgers normally throughout the event, with no confirmed loss of funds, altered transactions, or consensus failure.
- Four new safeguards now cap manifest size, message batch sizes, cache growth for unknown validator keys, and outbound sharing of untrusted data.
- Operators must upgrade, confirm xrpld is running, then restart a second time to clear any manifests that persisted before the patch.
- Ripple rotated its package-signing GPG key on Feb. 18, so operators must trust the new key for the update to install correctly.
What triggered the XRP Ledger node upgrade
The flood centered on validator manifests, the cryptographically signed records that link a validator’s permanent master identity to the temporary key it uses for day-to-day validation traffic. When a validator rotates that temporary key, it broadcasts a new manifest signed by its master key so peers across the network can verify the change is legitimate.
… Continue reading the full article at the original source below.
