Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Immediately unblock channels on duplicate claims by TheBlueMatt · Pull Request #2661 · lightningdevkit/rust-lightning · GitHub
Skip to content

Immediately unblock channels on duplicate claims - #2661

Merged
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang
Oct 19, 2023
Merged

Immediately unblock channels on duplicate claims#2661
TheBlueMatt merged 4 commits into
lightningdevkit:mainfrom
TheBlueMatt:2023-10-dup-claim-chan-hang

Conversation

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

When MonitorUpdateCompletionActions were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an if let rather than a
match, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
commitment_signed), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
MonitorUpdateCompletionAction.

The fix is simple - if we get back an
UpdateFulfillCommitFetch::DuplicateClaim when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new MonitorUpdateCompletionAction::FreeOtherChannelImmediately.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 13, 2023

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First high-level pass.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 1792bef to 9c487f4CompareOctober 16, 2023 15:25
@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 29 lines in your changes are missing coverage. Please review.

Comparison is base (6cafba9) 89.00% compared to head (5b71cd9) 89.63%.
Report is 22 commits behind head on main.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2661 +/- ##
==========================================
+ Coverage 89.00% 89.63% +0.63% 
==========================================
Files 112 112 Lines 87207 91365 +4158 Branches 87207 91365 +4158 ==========================================
+ Hits 77619 81897 +4278 + Misses 7353 7231 -122 - Partials 2235 2237 +2 
FilesCoverage Δ
lightning/src/ln/chanmon_update_fail_tests.rs97.71% <98.38%> (+0.01%)⬆️
lightning/src/ln/channelmanager.rs86.13% <83.62%> (+4.55%)⬆️

... and 20 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still going through a first pass

Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/chanmon_update_fail_tests.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Probably ready for a 2nd reviewer

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment on lines 5587 to 5590
let fee_earned_msat = if let Some(claimed_htlc_value) = htlc_claim_value_msat {
Some(claimed_htlc_value - forwarded_htlc_value)
} else { None };

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can move this to where the event is generated below. Can we also stop gating this whole thing on if let Some(forwarded_htlc_value) .. or add a comment for why we're doing so?

Copy link
Copy Markdown
CollaboratorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yea, its fine cause we only have None when claiming from a(n old) monitor, which we dont have to restore, but I'll move it, good idea.

@valentinewallace

Copy link
Copy Markdown
Contributor

Feel free to squash.

@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 6ab8b00 to 80792aaCompareOctober 18, 2023 19:02
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Pushed a number of further changes so didn't squash yet.

@valentinewallacevalentinewallace left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No real feedback, LGTM after a 2nd reviewer.

Comment threadlightning/src/ln/channelmanager.rs Outdated
Comment threadlightning/src/ln/channelmanager.rs Outdated
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 80792aa to a6d4676CompareOctober 18, 2023 20:33
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with one additional assertion and a comment fix:

$ git diff-tree -U3 80792aab a6d4676c
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index 217922ca5..b12fc3c86 100644
--- a/lightning/src/ln/channelmanager.rs+++ b/lightning/src/ln/channelmanager.rs@@ -5617,10 +5617,21 @@ where
// There should be a `BackgroundEvent` pending...
assert!(background_events.iter().any(|ev| {
match ev {
- // to apply a monitor update that blocked channel,+ // to apply a monitor update that blocked the claiming channel,
BackgroundEvent::MonitorUpdateRegeneratedOnStartup {
- funding_txo, ..- } => *funding_txo == claiming_chan_funding_outpoint,+ funding_txo, update, ..+ } => {+ if *funding_txo == claiming_chan_funding_outpoint {+ assert!(update.updates.iter().any(|upd|+ if let ChannelMonitorUpdateStep::PaymentPreimage {+ payment_preimage: update_preimage+ } = upd {+ payment_preimage == *update_preimage+ } else { false }+ ), "{:?}", update);+ true+ } else { false }+ },
// or the channel we'd unblock is already closed,
BackgroundEvent::ClosedMonitorUpdateRegeneratedOnStartup((funding_txo, ..))
=> *funding_txo == next_channel_outpoint,
$ 

Comment threadlightning/src/ln/channelmanager.rs

@tnulltnull left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, feel free to squash.

Comment threadlightning/src/ln/channelmanager.rs
Comment threadlightning/src/ln/channelmanager.rs Outdated
This may help in debugging blocking actions in the future.
While we'd previously avoided this, this is sadly now required in
the next commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we add the new variant, which we start generating in the next
commit.
When `MonitorUpdateCompletionAction`s were added, we didn't
consider the case of a duplicate claim during normal HTLC
processing (as the handling only had an `if let` rather than a
`match`, which made the branch easy to miss). This can lead to a
channel freezing indefinitely if an HTLC is claimed (without a
`commitment_signed`), the peer disconnects, and then the HTLC is
claimed again, leading to a never-completing
`MonitorUpdateCompletionAction`.
The fix is simple - if we get back an
`UpdateFulfillCommitFetch::DuplicateClaim` when claiming from the
inbound edge, immediately unlock the outbound edge channel with a
new `MonitorUpdateCompletionAction::FreeOtherChannelImmediately`.
Here we implement this fix by actually generating the new variant
when a claim is duplicative.
@TheBlueMatt
TheBlueMattforce-pushed the 2023-10-dup-claim-chan-hang branch from 5b71cd9 to f47270eCompareOctober 19, 2023 15:28
@TheBlueMatt

Copy link
Copy Markdown
CollaboratorAuthor

Squashed with a small wording tweak in the log:

$ git diff-tree -U1 5b71cd9a f47270e7
diff --git a/lightning/src/ln/channelmanager.rs b/lightning/src/ln/channelmanager.rs
index d66b6c478..1a4bdfbf6 100644
--- a/lightning/src/ln/channelmanager.rs
+++ b/lightning/src/ln/channelmanager.rs
@@ -6542,3 +6542,3 @@ where
log_trace!(self.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
msg.channel_id);
@@ -10130,3 +10130,3 @@ where
log_trace!(args.logger,
- "Holding the next revoke_and_ack from {} until the preimage is durably in the inbound edge's ChannelMonitor",
+ "Holding the next revoke_and_ack from {} until the preimage is durably persisted in the inbound edge's ChannelMonitor",
blocked_channel_outpoint.to_channel_id());
$ 

@TheBlueMatt
TheBlueMatt merged commit d7a6d0d into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@TheBlueMatt@codecov-commenter@valentinewallace@tnull