fix(xmr): S11 - recover spent references with exact wire identity and errata ordering

Recover committed XMR spent references using the exact scheduled outbound and its original wire memo. An OUT/REFUND observation can carry a semantic memo while the transaction itself is memoless; using the observation memo for sidecar verification prevents recovery.

Series context

This is S11 part of the S series tracked in the XMR v3.21.0 launch plan.

  • Scope: exact spent-reference recovery and ordering against errata cleanup.
  • Depends on: !5065 / S10 — canonical mined-height identity, including S09’s local errata admission.
  • Related work: !5068 / S12 — terminal errata outcomes and retries; S13 — observer readiness and reconciliation.

This MR is stacked on !5056 (zly/s10-xmr-mined-height-identity). Retarget to develop after !5056 / S10 merges. S12 remains a separate sibling MR.

Changes

  • Resolve committed OUT/REFUND plans through an opt-in query requiring exact OutHash, inbound commitment and matching outbound provenance. Reject ambiguous records.
  • Preserve semantic observation and certificate memos while passing the exact wire bytes, including an empty memo, to the sidecar.
  • Share recovery between direct committed events and periodic catch-up. Revalidate fresh committed-voter state before using a bounded positive cache.
  • Guard each import attempt, migration replay and successful outcome callback against durable errata admission. Release the guard between retries.
  • Replace per-height HTTP recovery requests with one query, with regenerated protobuf/OpenAPI outputs and no consensus-state writes. Historical store scans remain on cache misses.

Verification

Regressions cover exact-hash precedence, ambiguous plans, wire memos, missing/reversed commitment, delayed scheduling, retry/restart, cache behavior, cancellation and import-versus-cleanup ordering.

Affected mocknet tests, focused normal tests, repeated race checks, generation, affected-package vet and formatting checks passed during implementation. Focused mocknet tests and gofumpt were rechecked on the current rebased head.

Rollout

This belongs to the XMR integration series. Economic activity remains disabled until the required series is reviewed, integrated and deployed.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading