Add full XMR support for the v3.20.4 soft launch (non-consensus-breaking)
DEPRECATED: v3.20.4 will not ship
Summary
This MR collects the XMR changes on develop for backporting into a non-consensus-breaking v3.20.4 soft-launch release, including deposits, swaps, liquidity provision and withdrawals.
This MR does not authorize XMR activation yet.
The bundle includes XMR keygen, signing, recovery and XMR-required simulation coverage. Itzamna will integrate the selected changes into the v3.20.4 release branch.
Release identity
| Item | Value |
|---|---|
| Intended release | v3.20.4 |
| Source branch | zly/xmr-ncb-bundle |
| Target branch | develop |
| Rebase base | ca561d0c52 |
| Bundle head | fac0b51f95 |
| Commit count above that base | 25 |
This is a develop-targeted integration MR. The release version is set on the final v3.20.4 release branch.
Included scope
Private commits: No private-MR commits were selected.
This MR contains selected commits and adaptations from:
| Item | Source | Included changes |
|---|---|---|
| S03A | !5045 | FROST stream ownership and DKG delivery |
| S29 | !5121 (merged) | Outbound-voter queries, authenticated spent-reference recovery, payout recovery after churn and restart, and XMR memo/change protection |
| S00 | !5026 | XMR keygen coordination, rollout gates, XMR-required simulation and the optional departed-signer refund scenario |
| S20A | !5111 | Unsupported destination handling and signer queue protection |
| S08c | !5112 | Scanner continuity and reorg reconciliation around churn rollback |
| S27 | !5109 | Preserve reorg history during vault catch-up |
Historical members can provide authorized spend certificates for Active, Retiring and Inactive vaults. Pending certificates and late recovery observations are saved before processing continues, and observations remain retryable while the node's startup status is unknown.
Backport prerequisites
RDY (!5104 (merged)), outbound finality (!5055 (merged)), S18 (!5037 (merged)), the Bifrost keygen-warning change from !5083 (merged), and the signer-lock fix equivalent to !5113 (merged) are already present on develop. They are not separate additions in this MR's diff. The release owner must ensure equivalent changes are present in v3.20.4; cherry-picking this MR alone does not include them.
For S18, use the guarded external-query backport so contract-query behavior stays compatible with v3.20.4. The develop version must not be copied into the patch unchanged. Simulation harness adaptations may also be needed for the release branch.
Compatibility
Relative to develop, this MR adds no changes to production consensus handlers, keepers, managers, migrations or reward accounting. Its THORNode-side additions are guarded quote checks, the optional outbound TxVoters query field, two Mimir names read by Bifrost, and related generated bindings and tests.
S20A's new destination checks apply only to external API queries through the !isWasm guard. The branch inherits develop's existing S18 behavior; the patch backport must preserve contract-query compatibility as described above.
!5117 and S00's copy of the bond-reward rounding change are not selected for the v3.20.4 backport. Duplicate S29 changes and unrelated Zebra changes are not part of the selected XMR work.
Run Bifrost and THORNode from the same release so Bifrost's XMR recovery queries receive the expected responses.
XMR memoless outbounds remain disabled regardless of the global setting. Newly signed XMR payouts retain their semantic memo. Incoming payments carrying outbound memos, including vault payouts sent directly to another vault address, are ignored: they are neither credited nor refunded. Memoless inbounds remain supported.
Verification
The rebased bundle at fac0b51f95 passed the CI cluster simulation with XMR required. All 188 actors completed successfully. CI tested the merged result at 961fd0980c.
The local bundle at fac0b51f95, passed the full simulation with the explicit xmr-historical-refund stage. All 189 actors completed, covering:
- Deposits, swaps and memoless-input flows.
- Two XMR vault rotations and four migration transactions.
- All 13 standard inactive-vault refund tests.
- An extra refund that required a churned-out validator to sign, without counting its change as a deposit.
- Spent-output tracking, solvency checks and Ragnarok.
All 16 XMR payouts and migrations finalized in that local run. The logs showed the change filter, spend-proof import and recovery replay, and the strict bond-accounting checks remained enabled. The extra departed-signer scenario was not part of the standard 188-actor CI run.
Related focused tests, simulation-harness tests, memo compatibility tests and production build checks also passed locally.