Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Avoid applying onion's channel updates in an observable way by tnull · Pull Request #2666 · lightningdevkit/rust-lightning · GitHub
Skip to content

Avoid applying onion's channel updates in an observable way - #2666

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update
Oct 19, 2023
Merged

Avoid applying onion's channel updates in an observable way#2666
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
tnull:2023-10-observable-update

Conversation

@tnull

@tnulltnull commented Oct 16, 2023

Copy link
Copy Markdown
Contributor

Fixes#2598.

If we receive a channel update from an intermediary via a failure onion we shouldn't apply them in a persisted and network-observable way to our network graph, as this might introduce a privacy leak.

Here, we therefore avoid applying such updates to our network graph.

@tnull
tnull marked this pull request as draft October 16, 2023 11:36
@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Currently in draft until the approach is clarified. I already started some commits including the ChannelUpdate in PaymentParameters::previously_failed_channels, but don't think this is necessary if we don't reuse any previously failed channels anyways.

@codecov-commenter

codecov-commenter commented Oct 16, 2023

Copy link
Copy Markdown

Codecov Report

Attention: 13 lines in your changes are missing coverage. Please review.

Comparison is base (1852715) 88.98% compared to head (e64a293) 88.94%.

❗ Current head e64a293 differs from pull request most recent head 1c35255. Consider uploading reports for the commit 1c35255 to get more accurate results

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@ Coverage Diff @@## main #2666 +/- ##
==========================================
- Coverage 88.98% 88.94% -0.04% 
==========================================
Files 112 112 Lines 87632 87663 +31 Branches 87632 87663 +31 ==========================================
- Hits 77978 77975 -3 - Misses 7421 7441 +20 - Partials 2233 2247 +14 
FilesCoverage Δ
lightning/src/ln/onion_utils.rs91.52% <100.00%> (+0.01%)⬆️
lightning/src/ln/functional_test_utils.rs90.46% <0.00%> (-0.59%)⬇️
lightning/src/routing/gossip.rs85.89% <61.29%> (-0.40%)⬇️

... and 6 files with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@tnull
tnullforce-pushed the 2023-10-observable-update branch from e6ed6af to 5485d1bCompareOctober 16, 2023 12:24
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

Yea, this makes sense to me. Lets just remove the network_update field in PathFailure::OnPath entirely?

Mh, not sure if we want to keep the ability to manually apply updates to a graph around for users knowing what they doing? But if we want to remove it, I think it may make sense to also drop NetworkGraph::handle_network_update and the entire NetworkUpdate type?

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data. I'm a bit torn on applying the "perm fail" case still, because while it exhibits a similar issue, the cost to attack is much higher (you lose out on a lot of fees going forward cause we never route through you now) and its nice to remove graph entries optimistically (we don't currently look at the chain, so the only other reason we remove entries is if they aren't getting any more updates).

@tnull

tnull commented Oct 16, 2023

Copy link
Copy Markdown
ContributorAuthor

I mean, I think (a) we think its a terrible idea to apply the update, and would be a lot of work to do so safely (you'd probably have to keep a second copy of the network graph), and (b) we expect to receive the update via the normal gossip network soon anyway, so its not like we're missing out for too long, and (c) we score the channel negatively cause the payment failed (I hope, need to double-check that?) so we shouldn't be retrying over the same channel soon even for a new payment, and (d) probably the network updates will go away in the spec cause its such a bad issue anyway....

I don't really think its worth keeping a bunch of code around for such a rarely-useful case, much better to have less code :)

Alright, makes sense.

I do think we should keep NetworkGraph::handle_network_update just cause who knows where people are getting their gossip data.

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Hum, but they'd likely receive gossip data as NodeAnnouncements/ChannelAnnouncements/ChannelUpdates anyways, not NetworkUpdate, which really is only a, to quote its docs, "Update to the NetworkGraph based on payment failure information conveyed via the Onion return packet by a node along the route.", and handle_network_update "Handles any network updates originating from Events."?

Oh, duh, yea.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Given that it's really just a wrapper type used for the one purpose we're about to drop, it's really tempting to drop all that associated code.

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

@tnull

Copy link
Copy Markdown
ContributorAuthor

Yea, I'm just a bit torn on removing from perm failures - it does seem like something worth doing given we don't currently look at the chain to remove after the funding outpoint is spent (and rely on timeouts of the channel_updates). The timeouts are after a week or two, though.

Mh, will think about that once more, but currently have no strong opinion on it. I now pushed a commit removing the failure field and dependants. If we're positive we want to go this way, I may look into also removing NetworkUpdate etc.

@TheBlueMattTheBlueMatt added this to the 0.0.118 milestone Oct 18, 2023
@TheBlueMattTheBlueMatt self-assigned this Oct 18, 2023
@tnull
tnull marked this pull request as ready for review October 18, 2023 18:05
Comment threadlightning/src/events/mod.rs
We introduce a new `NetworkGraph::verify_channel_update` method that
allows to check whether an update would be applied by `update_channel`.
@tnull
tnullforce-pushed the 2023-10-observable-update branch 2 times, most recently from e64a293 to 8d7aa35CompareOctober 19, 2023 15:01
If we receive a channel update from an intermediary via a failure onion
we shouldn't apply them in a persisted and network-observable way to our
network graph, as this might introduce a privacy leak. Here, we
therefore avoid applying such updates to our network graph.
@tnull
tnullforce-pushed the 2023-10-observable-update branch from 8d7aa35 to 1c35255CompareOctober 19, 2023 15:03
@tnull

Copy link
Copy Markdown
ContributorAuthor

Alright, after more and more backpedaling I now pushed an MVP that just skips application of the NetworkUpdate::ChannelUpdateMessages. I think we should see how to remove them entirely eventually, but this will be a much larger change that requires more coordination beforehand to not lose too much test coverage and not break compatibilty.

@TheBlueMatt
TheBlueMatt merged commit 6fff3e5 into lightningdevkit:mainOct 19, 2023
PXplod pushed a commit to bitlightlabs/rust-lightning that referenced this pull request Sep 30, 2024
0.0.118 - Oct 23, 2023 - "Just the Twelve Sinks"
API Updates
===========
* BOLT12 sending and receiving is now supported as an alpha feature. You may
run into unexpected issues and will need to have a direct connection with
the offer's blinded path introduction points as messages are not yet routed.
We are seeking feedback from early testers (lightningdevkit#2578, lightningdevkit#2039).
* `ConfirmationTarget` has been rewritten to provide information about the
specific use LDK needs the feerate estimate for, rather than the generic
low-, medium-, and high-priority estimates. This allows LDK users to more
accurately target their feerate estimates (lightningdevkit#2660). For those wishing to
retain their existing behavior, see the table below for conversion.
* `ChainHash` is now used in place of `BlockHash` where it represents the
genesis block (lightningdevkit#2662).
* `lightning-invoice` payment utilities now take a `Deref` to
`AChannelManager` (lightningdevkit#2652).
* `peel_onion` is provided to statelessly decode an `OnionMessage` (lightningdevkit#2599).
* `ToSocketAddrs` + `Display` are now impl'd for `SocketAddress` (lightningdevkit#2636, lightningdevkit#2670)
* `Display` is now implemented for `OutPoint` (lightningdevkit#2649).
* `Features::from_be_bytes` is now provided (lightningdevkit#2640).
For those moving to the new `ConfirmationTarget`, the new variants in terms of
the old mempool/low/medium/high priorities are as follows:
* `OnChainSweep` = `HighPriority`
* `MaxAllowedNonAnchorChannelRemoteFee` = `max(25 * 250, HighPriority * 10)`
* `MinAllowedAnchorChannelRemoteFee` = `MempoolMinimum`
* `MinAllowedNonAnchorChannelRemoteFee` = `Background - 250`
* `AnchorChannelFee` = `Background`
* `NonAnchorChannelFee` = `Normal`
* `ChannelCloseMinimum` = `Background`
Bug Fixes
=========
* Calling `ChannelManager::close_channel[_with_feerate_and_script]` on a
channel which did not exist would immediately hang holding several key
`ChannelManager`-internal locks (lightningdevkit#2657).
* Channel information updates received from a failing HTLC are no longer
applied to our `NetworkGraph`. This prevents a node which we attempted to
route a payment through from being able to learn the sender of the payment.
In some rare cases, this may result in marginally reduced payment success
rates (lightningdevkit#2666).
* Anchor outputs are now properly considered when calculating the amount
available to send in HTLCs. This can prevent force-closes in anchor channels
when sending payments which overflow the available balance (lightningdevkit#2674).
* A peer that sends an `update_fulfill_htlc` message for a forwarded HTLC,
then reconnects prior to sending a `commitment_signed` (thus retransmitting
their `update_fulfill_htlc`) may result in the channel stalling and being
unable to make progress (lightningdevkit#2661).
* In exceedingly rare circumstances, messages intended to be sent to a peer
prior to reconnection can be sent after reconnection. This could result in
undefined channel state and force-closes (lightningdevkit#2663).
Backwards Compatibility
=======================
* Creating a blinded path to receive a payment then downgrading to LDK prior to
0.0.117 may result in failure to receive the payment (lightningdevkit#2413).
* Calling `ChannelManager::pay_for_offer` or
`ChannelManager::create_refund_builder` may prevent downgrading to LDK prior
to 0.0.118 until the payment times out and has been removed (lightningdevkit#2039).
Node Compatibility
==================
* LDK now sends a bogus `channel_reestablish` message to peers when they ask to
resume an unknown channel. This should cause LND nodes to force-close and
broadcast the latest channel state to the chain. In order to trigger this
when we wish to force-close a channel, LDK now disconnects immediately after
sending a channel-closing `error` message. This should result in cooperative
peers also working to confirm the latest commitment transaction when we wish
to force-close (lightningdevkit#2658).
Security
========
0.0.118 expands mitigations against transaction cycling attacks to non-anchor
channels, though note that no mitigations which exist today are considered robust
to prevent the class of attacks.
* In order to mitigate against transaction cycling attacks, non-anchor HTLC
transactions are now properly re-signed before broadcasting (lightningdevkit#2667).
In total, this release features 61 files changed, 3470 insertions, 1503
deletions in 85 commits from 12 authors, in alphabetical order:
* Antonio Yang
* Elias Rohrer
* Evan Feenstra
* Fedeparma74
* Gursharan Singh
* Jeffrey Czyz
* Matt Corallo
* Sergi Delgado Segura
* Vladimir Fomene
* Wilmer Paulino
* benthecarman
* slanesuke
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dont apply NetworkUpdate::ChannelUpdate in an observable way

4 participants

@tnull@codecov-commenter@TheBlueMatt@wpaulino