fix(tron): preserve vault observations across receipt failures

A TRON receipt lookup failure currently causes Bifrost to skip the transaction and advance its scanner cursor. This can lose a vault deposit or outbound observation, including gas accounting for failed outbounds. HTTP-200 responses containing an application error can also decode as empty receipts.

This MR retains the affected height and retries the block until the required vault receipts are valid. It also keeps scanner health and network-fee reporting consistent during failure and recovery.

Changes

  • Reject application-error and null receipt responses.
  • Require each relevant receipt to match the transaction ID and scanned block height. Matching receipts with zero fees remain valid.
  • Retry the entire block on receipt failure, without returning partial observations or advancing past the affected height.
  • Request successful TRX/USDT receipts only when the sender or decoded recipient is a known vault. Retiring and inactive vaults remain eligible; observer attribution is unchanged.
  • Clear cached scanner health during availability retries, then recompute health after a successful scan before initial or scheduled network-fee reporting.

Filtering unrelated transfers reduces RPC load and prevents their receipt failures from blocking vault observations. In the regression fixture containing 100 unrelated transfers and one vault transfer, receipt requests fall from 101 to one. Retries still repeat lookups for relevant vault transactions.

Origin and review evidence

Extracted from the production fixes developed during RDY/!5104 (merged):

These findings have local regression coverage. No failed CI job has been verified as demonstrating these specific scanner defects.

Scope and operational impact

This is a production Bifrost change targeting develop, with no XMR-series dependency. Mocknet configuration and simulation transaction-submission changes remain in RDY/!5104 (merged).

The shared scanner-health change affects all chains. A failed fetch pauses health-gated activity for at least the configured backoff plus lookup time, and longer if failures repeat. XMR’s production backoff is 30 seconds, during which signing and consolidation remain gated.

A persistent vault-receipt failure stops TRON scanning on the affected Bifrost instance. Repair or switch the RPC; scanning resumes automatically from the retained height. Do not skip that height, because doing so would discard the protected observations.

Vault filtering depends on timely refresh of the local vault list. Receipt ID/height validation does not provide block-hash binding.

Validation

Passed locally on the current implementation:

  • Full mocknet-tagged blockscanner and TRON/API/RPC package tests.
  • Targeted receipt, vault-filter, scanner-health and fee-recovery race tests, repeated three times.
  • Regression coverage for TRX/USDT inbound and outbound transfers, inactive vaults, request counts, partial-block rejection and successful retry.

Merge request reports

Loading
Loading