fix(bifrost): S15 - honor cancellation during state sync

When state sync times out, the network transfer stops, but processing can still be waiting for a lock or a THORNode query. This change makes processing, query waits and HTTP retries stop when the transfer is cancelled.

Series context

S15 is part of the series replacing the superseded XMR MR !4983 (closed). The full roadmap is tracked there.

  • Scope: cancellation during Bifrost state sync and shared THORNode queries. This applies beyond XMR.
  • Depends on: S14(!5107). This MR targets that S14(!5107) and should target develop after S14(!5107) merges.
  • Already included through S14(!5107): transfer limits, the separate state-sync timeout and the uneven-snapshot test previously planned for S16.
  • Related work: S11(!5067) covers XMR spent-reference recovery and errata ordering. Its authorization changes need to be combined with this cancellation support during integration.

Changes

  • Carry cancellation through opening the stream, collecting the snapshot and processing all five attestation types.
  • Allow processing to stop while waiting for observer locks, without adding worker goroutines.
  • Make vault, keysign and observed-voter queries cancellable, including waits for shared results, HTTP requests and retries.
  • Keep existing blocking query methods and cache timing. Calls for the same URL still share results. Only query responses are cached; authorization and quorum decisions are checked separately.
  • Release pending spent-reference reservations if cancellation happens before an import starts, so a later attempt can proceed.
  • Keep delayed sends for price feeds already accepted, and release the delay latch on cancellation so future sends are not blocked.

The wire format, consensus rules and S14 transfer limits do not change.

Trade-offs and integration

Cancellable lock waits try again every 10 ms. They use one timer per waiting caller and do not join the normal mutex queue. Under sustained contention, a transfer may keep losing the race for the lock until it times out. Failed transfers are not automatically retried; startup retries remain separate work.

The production bridge supports cancellable queries. Test bridges that exercise XMR spent-reference imports through state sync must support them too when integrating S11.

Verification

  • Focused state-sync and query-cancellation tests in normal and mocknet builds, repeated three times.
  • Relevant race tests, repeated three times.
  • Full observer and thorclient package tests under mocknet.

No full cluster simulation was run.

Merge request reports

Loading
Loading