Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Make ChannelSigner solely responsible for validating commitment sigs - #3878

Closed
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates
Closed

Make ChannelSigner solely responsible for validating commitment sigs#3878
tankyleo wants to merge 2 commits into
lightningdevkit:mainfrom
tankyleo:signer-alone-validates

Conversation

@tankyleo

Copy link
Copy Markdown
Contributor

As part of the custom transactions project, we want to make channel generic over any funding, htlc, and revokeable scripts used on-chain.

Hence, this commit removes the validation of holder commitment signatures from channel, as it requires building the funding, htlc, and revokeable scripts to create the expected sighash.

This signature validation is now the sole responsibility of ChannelSigner::validate_holder_commitment.

This commit updates InMemorySigner to honor this new API contract.

As part of the custom transactions project, we want to make channel
generic over any funding, htlc, and revokeable scripts used on-chain.
Hence, this commit removes the validation of holder commitment
signatures from channel, as it requires building the funding, htlc, and
revokeable scripts to create the expected sighash.
This signature validation is now the sole responsibility of
`ChannelSigner::validate_holder_commitment`.
This commit updates `InMemorySigner` to honor this new API contract.
@ldk-reviews-bot

ldk-reviews-bot commented Jun 21, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we add a logger here ? This would add a generic on the ChannelSigner trait as far as I see.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@tankyleotankyleo mentioned this pull request May 21, 2025
24 tasks
Comment on lines +1390 to +1417
let htlc_tx = chan_utils::build_htlc_transaction(
&bitcoin_tx.txid,
holder_tx.feerate_per_kw(),
channel_parameters.as_holder_broadcastable().contest_delay(),
&htlc,
&channel_parameters.channel_type_features,
&holder_keys.broadcaster_delayed_payment_key,
&holder_keys.revocation_key,
);
let htlc_redeemscript = chan_utils::get_htlc_redeemscript(
&htlc,
&channel_parameters.channel_type_features,
&holder_keys,
);
let htlc_sighashtype =
if channel_parameters.channel_type_features.supports_anchors_zero_fee_htlc_tx() {
EcdsaSighashType::SinglePlusAnyoneCanPay
} else {
EcdsaSighashType::All
};
let htlc_sighash = hash_to_message!(
&sighash::SighashCache::new(&htlc_tx)
.p2wsh_signature_hash(
0,
&htlc_redeemscript,
htlc.to_bitcoin_amount(),
htlc_sighashtype
)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For code moves, please move the code as-is first (with only indentation changes) and then run rustfmt in a separate commit. That way git show --color-moved --color-moved-ws=ignore-space-change highlights it as a clean move.

nodes[1].node.handle_funding_created(node_c_id, &funding_created_msg);
get_err_msg(&nodes[1], &node_c_id);
let err = "Invalid funding_created signature from peer".to_owned();
let err = "Failed to validate our commitment".to_owned();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, the old error was more descriptive :)

Comment on lines 765 to 769
fn validate_holder_commitment(
&self, holder_tx: &HolderCommitmentTransaction,
outbound_htlc_preimages: Vec<PaymentPreimage>,
&self, channel_parameters: &ChannelTransactionParameters,
holder_tx: &HolderCommitmentTransaction, outbound_htlc_preimages: Vec<PaymentPreimage>,
secp_ctx: &Secp256k1<secp256k1::All>,
) -> Result<(), ()>;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logging is great, but we shouldn't add it to the trait, rather store a logger in the InMemorySigner directly.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

Hi @tankyleo,

Thanks for your contributions to rust-lightning!

After too many struggles with bugs, outages, contributor bans, and, finally, a multi-week CI ban, the rust-lightning project is moving off of GitHub for day-to-day development.

You can still file issues and access the git tree here, but PRs will now take place exclusively at https://git.rust-bitcoin.org/. As such, this PR has been migrated to https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/3878

If you log in using GitHub (or otherwise link your GitHub account from https://git.rust-bitcoin.org/user/settings/security), ownership of your PRs, issues, and comments will automatically transfer. To push updates to this PR, you'll need to use git push git@gitea-ssh.bitcoin.ninja:lightningdevkit/rust-lightning YOUR_LOCAL_COMMIT_OR_BRANCH:tankyleo/signer-alone-validates. This may require a permissions change - if it doesn't work initially just leave a comment and we'll get you access.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt