Add full XMR support for the v3.20.4 soft launch (non-consensus-breaking)

DEPRECATED: v3.20.4 will not ship

Summary

This MR collects the XMR changes on develop for backporting into a non-consensus-breaking v3.20.4 soft-launch release, including deposits, swaps, liquidity provision and withdrawals.

This MR does not authorize XMR activation yet.

The bundle includes XMR keygen, signing, recovery and XMR-required simulation coverage. Itzamna will integrate the selected changes into the v3.20.4 release branch.

Release identity

Item Value
Intended release v3.20.4
Source branch zly/xmr-ncb-bundle
Target branch develop
Rebase base ca561d0c52
Bundle head fac0b51f95
Commit count above that base 25

This is a develop-targeted integration MR. The release version is set on the final v3.20.4 release branch.

Included scope

Private commits: No private-MR commits were selected.

This MR contains selected commits and adaptations from:

Item Source Included changes
S03A !5045 FROST stream ownership and DKG delivery
S29 !5121 (merged) Outbound-voter queries, authenticated spent-reference recovery, payout recovery after churn and restart, and XMR memo/change protection
S00 !5026 XMR keygen coordination, rollout gates, XMR-required simulation and the optional departed-signer refund scenario
S20A !5111 Unsupported destination handling and signer queue protection
S08c !5112 Scanner continuity and reorg reconciliation around churn rollback
S27 !5109 Preserve reorg history during vault catch-up

Historical members can provide authorized spend certificates for Active, Retiring and Inactive vaults. Pending certificates and late recovery observations are saved before processing continues, and observations remain retryable while the node's startup status is unknown.

Backport prerequisites

RDY (!5104 (merged)), outbound finality (!5055 (merged)), S18 (!5037 (merged)), the Bifrost keygen-warning change from !5083 (merged), and the signer-lock fix equivalent to !5113 (merged) are already present on develop. They are not separate additions in this MR's diff. The release owner must ensure equivalent changes are present in v3.20.4; cherry-picking this MR alone does not include them.

For S18, use the guarded external-query backport so contract-query behavior stays compatible with v3.20.4. The develop version must not be copied into the patch unchanged. Simulation harness adaptations may also be needed for the release branch.

Compatibility

Relative to develop, this MR adds no changes to production consensus handlers, keepers, managers, migrations or reward accounting. Its THORNode-side additions are guarded quote checks, the optional outbound TxVoters query field, two Mimir names read by Bifrost, and related generated bindings and tests.

S20A's new destination checks apply only to external API queries through the !isWasm guard. The branch inherits develop's existing S18 behavior; the patch backport must preserve contract-query compatibility as described above.

!5117 and S00's copy of the bond-reward rounding change are not selected for the v3.20.4 backport. Duplicate S29 changes and unrelated Zebra changes are not part of the selected XMR work.

Run Bifrost and THORNode from the same release so Bifrost's XMR recovery queries receive the expected responses.

XMR memoless outbounds remain disabled regardless of the global setting. Newly signed XMR payouts retain their semantic memo. Incoming payments carrying outbound memos, including vault payouts sent directly to another vault address, are ignored: they are neither credited nor refunded. Memoless inbounds remain supported.

Verification

The rebased bundle at fac0b51f95 passed the CI cluster simulation with XMR required. All 188 actors completed successfully. CI tested the merged result at 961fd0980c.

The local bundle at fac0b51f95, passed the full simulation with the explicit xmr-historical-refund stage. All 189 actors completed, covering:

  • Deposits, swaps and memoless-input flows.
  • Two XMR vault rotations and four migration transactions.
  • All 13 standard inactive-vault refund tests.
  • An extra refund that required a churned-out validator to sign, without counting its change as a deposit.
  • Spent-output tracking, solvency checks and Ragnarok.

All 16 XMR payouts and migrations finalized in that local run. The logs showed the change filter, spend-proof import and recovery replay, and the strict bond-accounting checks remained enabled. The extra departed-signer scenario was not part of the standard 188-actor CI run.

Related focused tests, simulation-harness tests, memo compatibility tests and production build checks also passed locally.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading