[POST-3.20 ONLY] fix(xmr-signer): harden post-3.20 recovery contracts

Summary

Post-3.20 follow-up for the XMR signer.

This MR:

  • requires imported outbound memos to match the memo authenticated from Monero transaction Extra
  • rejects malformed, ambiguous, oversized, or non-UTF-8 Extra data
  • retains the earliest valid birthday when an existing vault is re-enrolled
  • returns the retained effective_birthday to Bifrost
  • atomically clears stale checkpoints and rewinds scanner continuity when an earlier bounded birthday is accepted
  • reports daemon-derived Monero nettype and genesis hash through /v1/monero/info
  • advertises the monero-network-identity-v1 capability and fails the request when daemon identity is unavailable or unsupported

Why

THORNode keeps two memo representations for memoless XMR outbounds:

  • the wire memo included in the Monero transaction;
  • the semantic OriginalMemo used for THORChain attribution.

The post-3.20 THORNode changes pass the exact wire memo and transaction key to the signer while keeping the semantic memo in THORNode. This lets the signer reject mismatched metadata without losing THORChain attribution.

The birthday change handles recovery where a vault was initially registered near its DKG height but later requires an earlier safe starting height. Exact, later, and omitted-birthday retries remain idempotent. Earlier birthdays are accepted only within the bounded rewind window.

The daemon-identity change prevents a deployment label from hiding a signer connected to the wrong Monero network. Bifrost can now verify both the reported nettype and block-zero genesis hash.

Dependencies

It is the signer companion for:

Do not pair this branch with unmodified THORNode 3.20. It requires the post-3.20 wire-memo, effective-birthday, and daemon-identity handling.

Release images must be built from a reviewed commit and pinned by immutable digest.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading