Skip to content

fix(zetaclient): keep signing when the keygen record is reset (backport v38) - #4627

Merged
kingpinXD merged 2 commits into
release/zetaclient/v38from
hotfix/zetaclient-ignore-blanked-keygen-v38
Aug 19, 2026
Merged

fix(zetaclient): keep signing when the keygen record is reset (backport v38)#4627
kingpinXD merged 2 commits into
release/zetaclient/v38from
hotfix/zetaclient-ignore-blanked-keygen-v38

Conversation

@kingpinXD

@kingpinXD kingpinXD commented Aug 14, 2026

Copy link
Copy Markdown
Member

Backport of #4618 to release/zetaclient/v38. Do not merge before #4618.

Summary

  • Whitelist p2p peers from TSS.TssParticipantList rather than the keygen record, which zetacore erases on any observer set change.
  • Skip the keygen ceremony when a TSS already exists, instead of waiting on a record scheduled for a block that never arrives.
  • Delete the keygen watcher that restarted every signer at once.
  • Retry every zetacore query on the startup path with a constant backoff, so a contended RPC during a mass restart does not kill startup.

Scope

Production code only, matching the drain backports (#4614 / #4615). Five files: zetaclient/tss/setup.go, service.go, zetaclient/maintenance/tss_listener.go and the two test files. The e2e harness, CI wiring and changelog stay on main — they conflict on this branch and carry no runtime behaviour.

Compatibility with the drain

No shared files, and no drain code reads the keygen record. Setup runs before startDrainIfArmed in cmd/zetaclientd/start.go, so a signer that died in Setup never reached the drain at all — this fix is a prerequisite for the drain rather than a conflict.

Verified on this branch: build clean, zetaclient/tss and zetaclient/maintenance green, and the drain suites still green under -tags drain.

This branch is what testnet signers run, and it already carries the testnet drain anchors, so a build cut from here carries both the drain and this fix.

For operators

While a finalized TSS exists, a keygen scheduled via MsgUpdateKeygen will not run. Rotating requires removing the current TSS first. Tracked in #4623.

Greptile Summary

This backport keeps existing signers operational after zetacore resets the keygen record.

  • Resolves the p2p whitelist from finalized TSS participants instead of erased keygen grantees.
  • Skips key generation when a finalized TSS already exists.
  • Removes keygen-record-triggered signer restarts.
  • Adds constant-backoff retries to zetacore queries on the startup path.
  • Adds focused coverage for whitelist selection and listener behavior.

Confidence Score: 5/5

The PR appears safe to merge, with no blocking failure remaining from the previously reviewed fallback behavior.

No blocking failure remains.

Important Files Changed

Filename Overview
zetaclient/tss/setup.go Selects peers from finalized TSS state, bypasses the obsolete keygen wait for existing keys, and retries startup queries.
zetaclient/tss/service.go Retries the metrics-related keygen query consistently with the rest of startup.
zetaclient/maintenance/tss_listener.go Removes keygen-record watching while retaining restart triggers for actual TSS changes.
zetaclient/tss/setup_test.go Covers finalized, blanked, imported, query-failure, and invalid-peer whitelist states.
zetaclient/maintenance/tss_listener_test.go Verifies keygen resets are ignored while TSS address and history changes still trigger shutdown.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Start zetaclient Setup] --> B[Retry keygen query]
    B --> C[Retry current TSS query]
    C --> D{Finalized TSS exists?}
    D -- Yes --> E[Whitelist TSS participants]
    E --> F[Skip keygen ceremony]
    D -- No --> G[Whitelist keygen grantees]
    G --> H[Run keygen ceremony]
    F --> I[Retry TSS history query]
    H --> I
    I --> J[Start signing service]
    K[TSS listener] --> L{TSS address or history changes?}
    L -- Yes --> M[Restart signer]
    L -- Keygen record only --> N[Keep signer running]
Loading

Reviews (2): Last reviewed commit: "Merge branch 'release/zetaclient/v38' in..." | Re-trigger Greptile

…rt v38)

Backport of #4618. Production code only, same scope as the drain
backports: the e2e harness, CI wiring and changelog stay on main.

zetacore blanks the keygen record on any observer set change, which took
every mainnet signer down on 2026-08-11 and stopped them restarting.
Three changes: the p2p whitelist now comes from TssParticipantList
instead of the erased grantee list, Setup skips the keygen ceremony when
a TSS already exists, and the keygen watcher that triggered the mass
restart is gone.

Every zetacore query on the startup path is retried with a constant
backoff, so a contended RPC during a mass restart does not kill startup.

Note for operators: while a finalized TSS exists, a keygen scheduled via
MsgUpdateKeygen will not run. Rotating requires removing the current TSS
first. Tracked in #4623.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Cd1ZRjpN5br7NRYA9sCp7G
@kingpinXD
kingpinXD requested a review from a team as a code owner August 14, 2026 03:32
@kingpinXD kingpinXD added the no-changelog Skip changelog CI check label Aug 14, 2026
@cursor

cursor Bot commented Aug 14, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

Comment thread zetaclient/tss/setup.go
@codecov

codecov Bot commented Aug 14, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.55102% with 11 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
zetaclient/tss/setup.go 80.85% 9 Missing ⚠️
zetaclient/tss/service.go 0.00% 2 Missing ⚠️

📢 Thoughts on this report? Let us know!

@ws4charlie ws4charlie left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — diffed this against #4618 and all five files are byte-identical, and the pre-patch baselines match across main/v37/v38 so the cherry-pick is clean. Built it and ran the tss + maintenance unit tests locally, both green.

@kingpinXD
kingpinXD marked this pull request as draft August 14, 2026 04:12
@kingpinXD
kingpinXD marked this pull request as ready for review August 19, 2026 04:40
@kingpinXD
kingpinXD merged commit 931e5c1 into release/zetaclient/v38 Aug 19, 2026
13 of 14 checks passed
@kingpinXD
kingpinXD deleted the hotfix/zetaclient-ignore-blanked-keygen-v38 branch August 19, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Skip changelog CI check

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants