Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Validate funding contributions reserves in splice_init and splice_ack handling - #4011

Merged
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check
Sep 3, 2025
Merged

Validate funding contributions reserves in splice_init and splice_ack handling#4011
TheBlueMatt merged 7 commits into
lightningdevkit:mainfrom
tankyleo:splice-reserve-check

Conversation

@tankyleo

@tankyleotankyleo commented Aug 14, 2025

Copy link
Copy Markdown
Contributor
 Check v2 reserves after `funding_contribution_satoshis` is applied
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.

@ldk-reviews-bot

ldk-reviews-bot commented Aug 14, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @wpaulino as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@tankyleotankyleo changed the title Validate negative funding contributions in splice_ack and splice_init messagesValidate negative funding contributions in splice_init and splice_ack messagesAug 14, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 6d6b07c to 93965c6CompareAugust 14, 2025 01:24
@tankyleo
tankyleo requested a review from wpaulinoAugust 14, 2025 01:25
@codecov

codecovBot commented Aug 14, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 38.09524% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 88.77%. Comparing base (bf87832) to head (85a02ca).
⚠️ Report is 8 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/sign/tx_builder.rs38.09%13 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4011 +/- ##
==========================================
+ Coverage 88.76% 88.77% +0.01% 
==========================================
Files 176 176 Lines 129345 129357 +12 Branches 129345 129357 +12 ==========================================
+ Hits 114812 114836 +24 + Misses 11925 11921 -4 + Partials 2608 2600 -8 
FlagCoverage Δ
fuzzing22.00% <23.80%> (-0.01%)⬇️
tests88.60% <38.09%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo self-assigned this Aug 14, 2025
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 2nd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@wpaulinowpaulino mentioned this pull request Aug 18, 2025
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

On hold until splice-out PR gets in.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 3rd Reminder

Hey @wpaulino! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

@tankyleo
tankyleo removed the request for review from wpaulinoAugust 20, 2025 01:37
@tankyleo
tankyleo marked this pull request as draft August 20, 2025 01:38
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 93965c6 to d0023e3CompareAugust 26, 2025 22:14
@tankyleo
tankyleo marked this pull request as ready for review August 26, 2025 22:14
@tankyleo
tankyleo requested review from wpaulino and removed request for valentinewallaceAugust 26, 2025 22:15
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/sign/tx_builder.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from d0023e3 to 835b67bCompareAugust 27, 2025 02:26
@tankyleo

tankyleo commented Aug 27, 2025

Copy link
Copy Markdown
ContributorAuthor

Rebase on merge-base (diff):

  • Always run the reserve check, not just when the funding contribution is negative.
  • Make sure that the funder of the channel can pay for an additional nondust HTLC after the contributions are applied.
  • Emit WarnAndDisconnect if the balance is exhausted.
  • Style improvements.

@tankyleo
tankyleo requested a review from wpaulinoAugust 27, 2025 02:37
@tankyleotankyleo changed the title Validate negative funding contributions in splice_init and splice_ack messagesValidate funding contributions reserves in splice_init and splice_ack handlingAug 27, 2025
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch from 835b67b to 453a211CompareAugust 27, 2025 05:51
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Amend: (diff)

  • Run the reserve check anytime the funding contribution is not zero.

Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo

Copy link
Copy Markdown
ContributorAuthor

Rebasing now to fix conflict...

@tankyleo
tankyleo requested review from TheBlueMatt and removed request for TheBlueMattAugust 31, 2025 22:04
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
@tankyleo
tankyleoforce-pushed the splice-reserve-check branch 2 times, most recently from 8b3004e to ce4161cCompareSeptember 1, 2025 07:38
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
let their_channel_balance = Amount::from_sat(self.funding.get_value_satoshis())
- Amount::from_sat(self.funding.get_value_to_self_msat() / 1000);
let post_channel_balance = AddSigned::checked_add_signed(
let adjusted_funding_contribution = if let Some((contribution, is_initiator, feerate)) =

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure this is right in the splice_ack case? In the splice_channel (initiate outbound splice) case, we pass the total contribution ignoring fees, which then mandates that we subtract the fee here. But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here. IMO we should pull this back out to the splice_channel method and keep this method strictly a symmetrical splice validation function that doesn't have any sender/recipient-specific logic at all. Once we make get_next_{local,remote}_commitment_stats fallible it'll just be a matter of calling that and checking the reserve, basically.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will look into it thank you

But then we go to test again in splice_ack and, AFAICT we pass the adjusted contribution at that point (which is what we send to our counterparty, or the their_funding_contribution used below), and then we shouldn't subtract the fee here.

When we receive splice_ack, we set this triple to None, and we don't subtract the fee here ?

I'll revisit this part in any case.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, sorry, duh, all the more confusing code tho :)

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Sep 1, 2025

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, thanks for rewriting this four times 😅. Feel free to squash (looks like the latest fixup needs to get moved back a bit), I think this LGTM. cc @wpaulino

@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Also sadly needs rebase.

@tankyleo

Copy link
Copy Markdown
ContributorAuthor

First rebase: no diff, squash fixups, reorganize commits.

As much as possible, we want to only mutate state once we are done with
input validation.
This also removes complaints when helper functions during validation
take a `&self`.
As in `splice_init`, this helps clearly delineate `splice_ack` message
validation from the subsequent state mutations.
This is a code-move.
`NextCommitmentStats` provides the commitment transaction fee as a
separate value to assist with applying a multiplier on it in
`can_accept_incoming_htlc`.
Nonetheless in most cases, we want the balances to include the
commitment transaction fee, so here we add a helper that gives us these
balances.
Also make the style of `tx_builder::subtract_addl_outputs` consistent
with `get_balances_including_fee`.
The reserve we should maintain on our own transaction should be greater
than our own dust limit.
We check this when validating `splice_init`, `splice_ack` messages, and
also when validating user-specified contributions.
From BOLT 2:
```
- If `funding_contribution_satoshis` is negative and its absolute value
is greater than the sending node's current channel balance:
- MUST send a `warning` and close the connection or send an `error`
and fail the channel.
```
and further down:
```
If a side does not meet the reserve requirements, that's OK: but if they
take funds out of the channel, they must ensure that they do meet them.
If your peer adds a massive amount to the channel, then you only have
to add more reserve if you want to contribute to the splice (and you
can use `tx_remove_output` and/or `tx_remove_input` part-way through if
this happens).
```
Therefore, we check the v2 reserve anytime
`funding_contribution_satoshis` is not equal to zero.
We allow parties to draw from their previous reserve, as long as they
satisfy their v2 reserve.
@tankyleo

tankyleo commented Sep 2, 2025

Copy link
Copy Markdown
ContributorAuthor

Second rebase: move base commit to bf87832 , use inline format arguments in some places.

Comment threadlightning/src/ln/channel.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question, otherwise LGTM

// New reserve values are based on the new channel value and are v2-specific
let counterparty_selected_channel_reserve_satoshis = Some(get_v2_channel_reserve_satoshis(
let counterparty_selected_channel_reserve_satoshis =
Some(get_v2_channel_reserve_satoshis(post_channel_value, MIN_CHAN_DUST_LIMIT_SATOSHIS));

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wait, I thin this is wrong (and also maybe reserves should be higher than both dust limits?). Not sure what the spec says, but the point of the reserve is to have something that we can be punished for when broadcasting our own stale transaction. Thus, the reserve we keep should really be higher than our own dust limit (which applies to our local commitment transactions that we can broadcast) so that if we broadcast a stale state we can be punished.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't that what we have here ?

MIN_CHAN_DUST_LIMIT_SATOSHIS: our own dust limit

counterparty_selected_channel_reserve_satoshis: we must keep at least these many sats "punishable" on our broadcastable transaction.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤦

@TheBlueMatt
TheBlueMatt merged commit 9ddd25b into lightningdevkit:mainSep 3, 2025
25 checks passed
@github-project-automationgithub-project-automationBot moved this from Goal: Merge to Done in Weekly GoalsSep 3, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants

@tankyleo@ldk-reviews-bot@TheBlueMatt@wpaulino