fix(xmr-signer): prepare minimal safe launch image

Summary

Minimal signer launch candidate on develop e7bb429a17b979f7100e5034086a16ea5807d7fe, retaining this existing MR as the review owner. Three separate commits:

  • d2f8fef8: reject additionally timelocked outputs and miner rewards before scanner persistence, inbound credit or balance accounting; add production-path scanner regressions and use cargo build --locked in the image.
  • 034f3287: update rustls 0.23.35 to 0.23.45 and its webpki patch dependency for RUSTSEC-2026-0285. Monero/FROST source revisions are unchanged.
  • a3cb3e5f: allow the process health listener to start during an anonymous-daemon outage. Authentication, database safety, operational readiness and daemon-backed signing checks remain fail-closed. Add a real-executable startup regression.

Compared with the previous MR head, this deliberately omits the additional sign-time retained-payload guard, following the minimal scanner-only launch scope. It does not claim to repair old credited outputs. No signing ownership, reservations, cryptographic protocol or wire schema is changed.

Validation

Rust 1.90: fmt, locked all-target Clippy with warnings denied, 341 unit tests plus the executable startup regression, modular-FROST Ed25519 vector tests, and cargo-deny advisories/bans/sources passed locally.

Built Linux/amd64 from the exact source commit with VERSION/VCS_REF. Offline container smoke passes with public dummy credentials: health 200, readiness 503/daemon unreachable, unauthenticated keys 401, authenticated keys 200, and network identity 503 until the daemon is available. Non-root UID 10001, read-only root, no exposed ports and OCI revision are checked. A complete daemon/fleet or Kubernetes launch rehearsal was explicitly deferred by the user; these checks do not replace it.

Org pipeline 2871154533 passed all five jobs (fmt, Clippy, advisories and both test jobs). The exact candidate is published as registry.gitlab.com/thorchain/devops/serai/xmr-frost-signer:a3cb3e5f@sha256:ca11b703898d1ecd20d6d2383b6583e1116d140db46a268cce5896196af4b3f5 (Linux/amd64), pulled by digest and OCI source identity verified. It is a manually published commit-specific candidate, not the protected-branch image job. Protected release tags and integration branches are unchanged.

Release constraints

Fresh prelaunch accounting is required. Upgrading a schema-4 store with previously credited unsupported deposits does not repair balances. Never delete live signing claims/keyshares to work around this. Unsupported custom-lock/miner deposits do not enter normal swap/refund flows.

The prepared launcher supports anonymous in-cluster Monero RPC. Credentialed RPC URLs still perform the upstream constructor's initial digest-auth exchange before the listener starts; the launcher rejects them rather than silently promising bootstrap-safe liveness.

This candidate includes merged !70 (merged)'s identity/recovery contract. No production deployment, keygen enablement, XMR trading activation or consensus change is included. Image publication and deployment pins will be recorded in follow-up notes.

Edited by Boone W

Merge request reports

Loading
Loading