Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Generate local signatures with additional randomness - #2205

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata
Apr 20, 2023
Merged

Generate local signatures with additional randomness#2205
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
wpaulino:sign-ecdsa-with-noncedata

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Previously, our local signatures would always be deterministic, whether we'd grind for low R value signatures or not. For peers supporting SegWit, Bitcoin Core will generally use a transaction's witness-txid, as opposed to its txid, to advertise transactions. Therefore, to ensure a transaction has the best chance to propagate across node mempools in the network, each of its broadcast attempts should have a unique/distinct witness-txid, which we can achieve by introducing random nonce data when generating local signatures, such that they are no longer deterministic.

@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch 2 times, most recently from b8d85c9 to 099d875CompareApril 20, 2023 02:23
Comment threadlightning/src/chain/keysinterface.rs Outdated
/// because we are about to broadcast a holder transaction.
pub fn sign<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {
/// Signs the counterparty's commitment transaction.
pub fn sign_counterparty_commitment<T: secp256k1::Signing>(&self, funding_key: &SecretKey, funding_redeemscript: &Script, channel_value_satoshis: u64, secp_ctx: &Secp256k1<T>) -> Signature {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, this is fine, but is there a reason to break this out and treat them separately?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have a few test assertions that rely on the same commitment_signed being resent after a channel_reestablish. This is also the case for closing_signed signatures. We could remove those assertions I guess, since the protocol does allow you to retransmit a different signature after a reconnection.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, okay, yea, that's fine then, I think, I just wanted to check that there's some reason.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, fine as in we can remove the assertions or just leave them as is?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's leave it as-is.

@codecov-commenter

codecov-commenter commented Apr 20, 2023

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.06349% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 91.48%. Comparing base (8d50c91) to head (86531e5).
⚠️ Report is 6122 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/chain/keysinterface.rs92.68%3 Missing ⚠️
lightning/src/util/test_utils.rs0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #2205 +/- ##
==========================================
+ Coverage 91.38% 91.48% +0.10% 
==========================================
Files 102 104 +2 Lines 50832 51176 +344 Branches 50832 51176 +344 ==========================================
+ Hits 46451 46820 +369 + Misses 4381 4356 -25 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This allows the `InMemorySigner` to produce its own randomness, which we
plan to use when generating signatures in future work.
We can no longer derive `Clone` due to the `AtomicCounter`, so we opt to
implement it manually.
Previously, our local signatures would always be deterministic, whether
we'd grind for low R value signatures or not. For peers supporting
SegWit, Bitcoin Core will generally use a transaction's witness-txid, as
opposed to its txid, to advertise transactions. Therefore, to ensure a
transaction has the best chance to propagate across node mempools in the
network, each of its broadcast attempts should have a unique/distinct
witness-txid, which we can achieve by introducing random nonce data when
generating local signatures, such that they are no longer deterministic.
Gossip messages always use signatures in their compact form, so grinding
for low R signatures is unnecessary.
To match the local signatures found in test vectors, we must make sure
we don't use any additional randomess when generating signatures, as
we'll arrive at a different signature otherwise.
@wpaulino
wpaulinoforce-pushed the sign-ecdsa-with-noncedata branch from 099d875 to 86531e5CompareApril 20, 2023 19:14
@TheBlueMatt
TheBlueMatt merged commit 9d5adfc into lightningdevkit:mainApr 20, 2023
@wpaulino
wpaulino deleted the sign-ecdsa-with-noncedata branch April 20, 2023 22:18
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.115 - Apr 24, 2023 - "Rebroadcast the Bugfixes"
API Updates
===========
* The MSRV of the main LDK crates has been increased to 1.48 (lightningdevkit#2107).
* Attempting to claim an un-expired payment on a channel which has closed no
longer fails. The expiry time of payments is exposed via
`PaymentClaimable::claim_deadline` (lightningdevkit#2148).
* `payment_metadata` is now supported in `Invoice` deserialization, sending,
and receiving (via a new `RecipientOnionFields` struct) (lightningdevkit#2139, lightningdevkit#2127).
* `Event::PaymentFailed` now exposes a failure reason (lightningdevkit#2142).
* BOLT12 messages now support stateless generation and validation (lightningdevkit#1989).
* The `NetworkGraph` is now pruned of stale data after RGS processing (lightningdevkit#2161).
* Max inbound HTLCs in-flight can be changed in the handshake config (lightningdevkit#2138).
* `lightning-transaction-sync` feature `esplora-async-https` was added (lightningdevkit#2085).
* A `ChannelPending` event is now emitted after the initial handshake (lightningdevkit#2098).
* `PaymentForwarded::outbound_amount_forwarded_msat` was added (lightningdevkit#2136).
* `ChannelManager::list_channels_by_counterparty` was added (lightningdevkit#2079).
* `ChannelDetails::feerate_sat_per_1000_weight` was added (lightningdevkit#2094).
* `Invoice::fallback_addresses` was added to fetch `bitcoin` types (lightningdevkit#2023).
* The offer/refund description is now exposed in `Invoice{,Request}` (lightningdevkit#2206).
Backwards Compatibility
=======================
* Payments sent with the legacy `*_with_route` methods on LDK 0.0.115+ will no
longer be retryable via the LDK 0.0.114- `retry_payment` method (lightningdevkit#2139).
* `Event::PaymentPathFailed::retry` was removed and will always be `None` for
payments initiated on 0.0.115 which fail on an earlier version (lightningdevkit#2063).
* `Route`s and `PaymentParameters` with blinded path information will not be
readable on prior versions of LDK. Such objects are not currently constructed
by LDK, but may be when processing BOLT12 data in a coming release (lightningdevkit#2146).
* Providing `ChannelMonitorUpdate`s generated by LDK 0.0.115 to a
`ChannelMonitor` on 0.0.114 or before may panic (lightningdevkit#2059). Note that this is
in general unsupported, and included here only for completeness.
Bug Fixes
=========
* Fixed a case where `process_events_async` may `poll` a `Future` which has
already completed (lightningdevkit#2081).
* Fixed deserialization of `u16` arrays. This bug may have previously corrupted
the historical buckets in a `ProbabilisticScorer`. Users relying on the
historical buckets may wish to wipe their scorer on upgrade to remove corrupt
data rather than waiting on it to decay (lightningdevkit#2191).
* The `process_events_async` task is now `Send` and can thus be polled on a
multi-threaded runtime (lightningdevkit#2199).
* Fixed a missing macro export causing
`impl_writeable_tlv_based_enum{,_upgradable}` calls to not compile (lightningdevkit#2091).
* Fixed compilation of `lightning-invoice` with both `no-std` and serde (lightningdevkit#2187)
* Fix an issue where the `background-processor` would not wake when a
`ChannelMonitorUpdate` completed asynchronously, causing delays (lightningdevkit#2090).
* Fix an issue where `process_events_async` would exit immediately (lightningdevkit#2145).
* `Router` calls from the `ChannelManager` now call `find_route_with_id` rather
than `find_route`, as was intended and described in the API (lightningdevkit#2092).
* Ensure `process_events_async` always exits if any sleep future returns true,
not just if all sleep futures repeatedly return true (lightningdevkit#2145).
* `channel_update` messages no longer set the disable bit unless the peer has
been disconnected for some time. This should resolve cases where channels are
disabled for extended periods of time (lightningdevkit#2198).
* We no longer remove CLN nodes from the network graph for violating the BOLT
spec in some cases after failing to pay through them (lightningdevkit#2220).
* Fixed a debug assertion which may panic under heavy load (lightningdevkit#2172).
* `CounterpartyForceClosed::peer_msg` is now wrapped in UntrustedString (lightningdevkit#2114)
* Fixed a potential deadlock in `funding_transaction_generated` (lightningdevkit#2158).
Security
========
* Transaction re-broadcasting is now substantially more aggressive, including a
new regular rebroadcast feature called on a timer from the
`background-processor` or from `ChainMonitor::rebroadcast_pending_claims`.
This should substantially increase transaction confirmation reliability
without relying on downstream `TransactionBroadcaster` implementations for
rebroadcasting (lightningdevkit#2203, lightningdevkit#2205, lightningdevkit#2208).
* Implemented the changes from BOLT PRs lightningdevkit#1031, lightningdevkit#1032, and lightningdevkit#1040 which resolve a
privacy vulnerability which allows an intermediate node on the path to
discover the final destination for a payment (lightningdevkit#2062).
In total, this release features 110 files changed, 11928 insertions, 6368
deletions in 215 commits from 21 authors, in alphabetical order:
* Advait
* Alan Cohen
* Alec Chen
* Allan Douglas R. de Oliveira
* Arik Sosman
* Elias Rohrer
* Evan Feenstra
* Jeffrey Czyz
* John Cantrell
* Lucas Soriano del Pino
* Marc Tyndel
* Matt Corallo
* Paul Miller
* Steven
* Steven Williamson
* Steven Zhao
* Tony Giorgio
* Valentine Wallace
* Wilmer Paulino
* benthecarman
* munjesi
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@codecov-commenter@TheBlueMatt@arik-so