Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix long route failure attribution - #3709

Merged
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash
Apr 4, 2025
Merged

Fix long route failure attribution#3709
TheBlueMatt merged 1 commit into
lightningdevkit:mainfrom
joostjager:fix-attr-failure-crash

Conversation

@joostjager

Copy link
Copy Markdown
Contributor

An out of bound error could occur when attribution data was provided by the downstream hop for an exceptionally long route. The fix limits the verification of attribution data hmacs up to hop 20. If the sender chooses to use a longer route, failures in the final part of the route won't be attributable.

Fixes#3708

An out of bound error could occur when attribution data was provided by
the downstream hop for an exceptionally long route. The fix limits the
verification of attribution data hmacs up to hop 20. If the sender
chooses to use a longer route, failures in the final part of the route
won't be attributable.
@ldk-reviews-bot

ldk-reviews-bot commented Apr 4, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks. Gonna go ahead and land this because its basically trivial.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@joostjager

Copy link
Copy Markdown
ContributorAuthor

Well not completely trivial although the code change seems to be. I had to look twice at the fix myself. But hopefully the comments explain it well enough.

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Well the test is quite compelling :)

@TheBlueMatt
TheBlueMatt merged commit 42ab42a into lightningdevkit:mainApr 4, 2025

@carlaKCcarlaKC left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

post-merge review, lgtm!


// In the best case, paths can be up to 27 hops. But attribution data can only be conveyed back to the sender from
// the first 20 hops. Determine the number of hops to be used for attribution data.
let attributable_hop_count = usize::min(path.hops.len(), MAX_HOPS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still find myself wishing that the caller didn't need to concern itself with this level of detail about attributable faliures, but don't see an obvious way to improve it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

At the point of interpreting the failure message, there isn't much we can do about it. But one open question is whether we should limit pathfinding to 20 hops instead of 27 in pathfinding, so that we're sure every failure is attributable?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I doubt it's worth it. In the rare case that we are sending more than 20 hops it's probably because someone is doing something insane where they have a many-hop route hint, in which case it's not useful to get attribution data beyond the first handful.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OOB access in AttributionData::verify

4 participants

@joostjager@ldk-reviews-bot@TheBlueMatt@carlaKC