Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Fix minor miscellaneous splicing issues by wpaulino · Pull Request #4060 · lightningdevkit/rust-lightning · GitHub
Skip to content

Fix minor miscellaneous splicing issues - #4060

Merged
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes
Sep 9, 2025
Merged

Fix minor miscellaneous splicing issues#4060
TheBlueMatt merged 10 commits into
lightningdevkit:mainfrom
wpaulino:splice-misc-fixes

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

This was pulled out of #4054 to ease review. It fixes an assortment of issues I ran into while writing the tests there.

@wpaulinowpaulino added this to the 0.2 milestone Sep 5, 2025
@wpaulinowpaulino self-assigned this Sep 5, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Sep 5, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

1 similar comment
@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @TheBlueMatt@jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

}
}
}
removed_fulfilled_htlcs = true;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we just run the loop below at this point and return rather than needing this variable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's just a small optimization to not remove HTLCs that have already been removed since we have duplicate data across FundingScopes. The loop below does need to run for every FundingScope though.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, but that is already inside the closure, which is called on each FundingScope.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, nevermind. Didn't see that removed_fulfilled_htlcs is used across all calls.

{
Some(interactive_tx_constructor)
} else {
None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this also unreachable?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we actually don't want any unreachables since they can be triggered by a buggy/malicious counterparty.

ChannelPhase::UnfundedOutboundV1(_) => unreachable!(),
ChannelPhase::UnfundedInboundV1(_) => unreachable!(),
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can't recall if we eventually want to use FundingNegotiation here, too. Can wait, of course, but we may be able avoid these unreachables if we can take that at the call sites below.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not quite using that yet for dual funding so I'd rather delay it until we do.

Comment threadlightning/src/ln/interactivetxs.rs

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Basically LGTM

pub fn funding_tx_constructed<L: Deref>(
&mut self, logger: &L,
) -> Result<msgs::CommitmentSigned, msgs::TxAbort>
) -> Result<msgs::CommitmentSigned, AbortReason>

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wanna make these methods non-pub now? Makes the logic more readable.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, I think it was just funding_tx_constructed and interactive_tx_constructor_mut?

@wpaulino
wpaulinoforce-pushed the splice-misc-fixes branch 2 times, most recently from b1d97a1 to 9540edeCompareSeptember 8, 2025 19:14
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/chain/channelmonitor.rs
Otherwise we'll hit an assert that we do not already have an alternative
funding confirmation when reprocessing the transaction.
…cked
The `ChannelMonitor` now tracks its own set of channel parameters, but
in the event they change after a splice, we want to ensure they are
updated accordingly at the `OnchainTxHandler` level as well in case the
user downgrades after a locked splice has already occurred.
We only need to track the HTLC sources for the previous and current
counterparty commitments.
This commit reworks all interactive transaction construction methods to
mark the negotiation as failed upon a local/remote `TxAbort`, ensuring
the `InteractiveTxConstructor` is consumed. Along the way, we refactor
the handling of `tx_complete` such that we only have a single call into
the `Channel` from the `ChannelManager`.
The splice shared input weight should always be composed of the base
input weight (prevout & sequence), an empty `script_sig` weight, and the
multisig channel-type specific witness weight.
Although a splice out doesn't include inputs to sign, users still need
to call back with `funding_transaction_signed` to sign the shared splice
input.
Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test is using the wrong variable in the handle_tx_complete call. It captures the latest tx_complete message as _tx_complete_msg (with an underscore), but then passes the earlier tx_complete_msg from line 244 to the handler. This could lead to incorrect behavior since it's processing the wrong message. The variable names should be consistent, and the latest message should be used in the handler call.

Spotted by Diamond

Fix in Graphite


Is this helpful? React 👍 or 👎 to let us know.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah this test is getting removed completely in #4054 anyway.

Comment on lines 268 to 273
let events = initiator_node.node.get_and_clear_pending_msg_events();
assert_eq!(events.len(), 2);
assert_eq!(events.len(), 1);
match events[0] {
MessageSendEvent::SendTxComplete { .. } => {},
_ => panic!("Unexpected event {:?}", events[0]),
}
match events[1] {
MessageSendEvent::SendTxAbort { .. } => {},
_ => panic!("Unexpected event {:?}", events[1]),
_ => panic!("Unexpected event {:?}", events[0]),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks to predate the PR, but shouldn't affect behavior given tx_complete only contains a channel id.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gonna land this but think we need to fix the dual-funding failure handling.

ChannelPhase::Undefined => unreachable!(),
ChannelPhase::UnfundedOutboundV1(_) | ChannelPhase::UnfundedInboundV1(_) => None,
ChannelPhase::UnfundedV2(pending_v2_channel) => {
pending_v2_channel.interactive_tx_constructor.take()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we really just blindly take this? Its set up in new for inbound channels, so we probably should be outright failing the channel here, not resetting the signing session?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same applies further down.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dual funding hasn't been updated to use the new interactive tx path, it shouldn't even have an interactive tx constructor in new yet without calling FundingNegotiationContext::into_interactive_tx_constructor.

@TheBlueMatt
TheBlueMatt merged commit 3324799 into lightningdevkit:mainSep 9, 2025
22 of 23 checks passed
@wpaulino
wpaulino deleted the splice-misc-fixes branch September 9, 2025 19:57
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz