fix(xmr): S10 - preserve canonical mined-height observation identity

Preserve the original XMR mining height through finalization, voting, errata cleanup and observation completion. A transaction mined at height 100 but reported at height 110 must still match an errata tombstone for height 100.

Series context

This is S10 part of the S series tracked in the XMR v3.21.0 launch plan.

  • Scope: canonical mined-height identity and independent observation quorum.
  • Depends on: !5066 / S09 - XMR errata ordering and bounded attestation delivery.
  • Follow-ups: !5067 / S11 - spent-reference recovery and import ordering; S12 - terminal errata outcomes and retries.

This MR targets the S09(!5066) branch because it builds on S09(!5066)’s cleanup and ordering changes. The two MRs remain separate for review but will land in develop together. After completing the existing-voter compatibility fix and validation, merge this MR into the S09 branch. Then merge the combined S09 MR (!5066) into develop.

Changes

  • Carry xmr_mined_height through observation payloads, finalization, queries and CLI reconstruction, with regenerated protobuf and OpenAPI outputs.
  • Include mined height in XMR equality, gossip identity and signed payloads, so different mining locations require independent quorum.
  • Reject missing or invalid mined heights for inbound observations before voter or slash-accounting writes.
  • Use canonical mined height for tombstone admission, queued cleanup and persisted observation replay.
  • Prevent delayed completion for an orphaned mining location from modifying or removing a replacement observation sharing the same finalization height.

Legitimate pre-mining outbound observations retain zero mined height. Repeated-generation economic policy remains assigned to S10b; spent-reference ordering and terminal outcomes remain assigned to S11/S12.

Verification

Regression coverage includes independent 64-of-95 quorum, both inbound handler entrypoints, malformed metadata, admission and cleanup, storage restart, stale completion with durable-state and callback assertions, query/CLI round trips, and pre-mining/non-XMR controls.

Affected mocknet packages, focused normal tests, repeated observer race tests, generation, vet and formatting checks passed. The full untagged THORNode suite has 25 failures also reproduced against the S09 / !5066 baseline.

Rollout

The consensus-visible identity changes ship through the scheduled version upgrade. XMR economic activity remains disabled until the required series is reviewed, integrated and deployed.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading