Prevent unfair TRON solvency observation slashing and add fragmentation monitoring

Title: Prevent unfair TRON solvency observation slashing and add fragmentation monitoring

Summary

Mitigates #3098 by removing ordinary TRON solvency observation penalties and refunds while preserving the existing duplicate-message penalty. Adds TRON-specific telemetry and a four-validator regression simulation.

Why

TRON balance queries currently read latest state rather than state pinned to the reported height. Honest validators can therefore report different balances for the same solvency round.

This fragmentation can penalize minority-payload signers. Additionally, non-signers can be penalized even when the resulting consensus is subsequently discarded as stale.

Changes

  • Introduce Chain.SupportsSolvencyObservationSlashing() to express the chain-specific policy.
  • Disable ordinary observation charges, consensus refunds, non-signer penalties, and late-attestation refunds for TRON.
  • Preserve the existing duplicate-message penalty and other chains’ accounting.
  • Add TRON-only metrics for payload fragmentation, round outcomes, attestation counts, and stale-report discards.
  • Add regression coverage and a dedicated four-validator simulation target.
  • After verifying the churn-out payout, the BondYield simulation now waits for the validator to rejoin and vault migration to finish, restoring the original validator set before subsequent stages such as TRON solvency fragmentation run.

Consensus thresholds, stale-report rejection, and insolvency decisions remain unchanged. Previously accumulated slash points are not refunded.

Scope and trade-offs

This resolves the unfair-slashing symptoms of #3098, not the underlying balance fragmentation. Solvency reports can still split across different payloads.

A root-cause fix would require reliable historical state queries for both TRX and supported TRC-20 assets, or a validated historical snapshot/reconstruction mechanism. Ensuring complete, height-consistent data across validators adds significant implementation and operational complexity.

The compromise removes the ordinary TRON solvency participation incentive and per-payload observation cost. The duplicate-message penalty remains, but does not prevent distinct-payload spam.

Simulation test

Run:

make test-simulation-tron-solvency

This rebuilds and resets the local four-node mocknet cluster, then runs:

seed -> bootstrap -> churn -> tron-solvency-fragmentation

The test requires four active validators and fails immediately with setup guidance if activation is missing. It submits differing TRX/USDT payloads at the same stale report height and verifies:

  • Ordinary solvency observations leave all four validators’ slash points unchanged.
  • Consensus is discarded as stale.
  • Repeating an already-signed payload still applies the duplicate penalty.

This exercises on-chain handler accounting, not historical TRON RPC reads or Bifrost gossip/quorum dispatch.

Verification

  • The four-node simulation completed successfully, including zero ordinary slash-point deltas and the expected duplicate penalty.

Relationship to the unified solvency reporter MR !4597

This MR delivers the mitigation independently of the unified reporter. Equivalent changes are also present on zoly/bifrost-unify-solvency (MR !4597).

Either MR may land first. If the unified reporter (!4597) lands first, this standalone MR can be closed as superseded.

Closes #3098 for the unfair-slashing behavior. Deterministic historical TRON balances remain outside this MR’s scope.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading