Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Allow counterparty tx_abort before handling initial commitment signed by wpaulino · Pull Request #4204 · lightningdevkit/rust-lightning · GitHub
Skip to content

Allow counterparty tx_abort before handling initial commitment signed - #4204

Merged
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig
Nov 9, 2025
Merged

Allow counterparty tx_abort before handling initial commitment signed#4204
TheBlueMatt merged 2 commits into
lightningdevkit:mainfrom
wpaulino:splice-counterparty-tx-abort-before-commit-sig

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

Upon processing the counterparty's initial commitment_signed for a splice, we queue a monitor update with the new commitment transactions spending the new funding transaction. Once handled, funding transaction signatures can be exchanged and we must start monitoring the chain for a possible commitment transaction broadcast spending the new funding transaction. Aborting the splice negotiation then would therefore be unsafe, hence why we currently force close in such cases. However, there is no reason to force close prior to receiving their initial commitment_signed, as this would imply the funding transaction signatures have yet to be exchanged, thus making a commitment broadcast spending said transaction impossible allowing us to abort the splice negotiation safely.

Upon processing the counterparty's initial `commitment_signed` for a
splice, we queue a monitor update with the new commitment transactions
spending the new funding transaction. Once handled, funding transaction
signatures can be exchanged and we must start monitoring the chain for a
possible commitment transaction broadcast spending the new funding
transaction. Aborting the splice negotiation then would therefore be
unsafe, hence why we currently force close in such cases. However, there
is no reason to force close prior to receiving their initial
`commitment_signed`, as this would imply the funding transaction
signatures have yet to be exchanged, thus making a commitment broadcast
spending said transaction impossible allowing us to abort the splice
negotiation safely.
@wpaulino
wpaulino requested a review from jkczyzNovember 3, 2025 21:44
@wpaulinowpaulino self-assigned this Nov 3, 2025
@ldk-reviews-bot

ldk-reviews-bot commented Nov 3, 2025

Copy link
Copy Markdown

👋 Thanks for assigning @jkczyz as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Nov 4, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.66102% with 36 lines in your changes missing coverage. Please review.
✅ Project coverage is 89.30%. Comparing base (3f96d12) to head (d282a47).
⚠️ Report is 20 commits behind head on main.

Files with missing linesPatch %Lines
lightning/src/ln/interactivetxs.rs0.00%30 Missing ⚠️
lightning/src/ln/functional_test_utils.rs66.66%3 Missing and 1 partial ⚠️
lightning/src/ln/splicing_tests.rs97.05%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #4204 +/- ##
==========================================
+ Coverage 89.28% 89.30% +0.02% 
==========================================
Files 180 180 Lines 137913 138055 +142 Branches 137913 138055 +142 ==========================================
+ Hits 123134 123293 +159 + Misses 12163 12150 -13 + Partials 2616 2612 -4 
FlagCoverage Δ
fuzzing32.58% <5.10%> (+0.96%)⬆️
tests88.71% <79.66%> (+0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only kinda skimmed the test changes, but code diff lgtm. One thing we should probably make sure to do is add splicing logic to chanmon_consistency and have a hard-coded seed for doing a splice in full_stack. That should give us somewhat-okay coverage of the debug assertions and test accidental force-closes (not that either would have caught this, just a general note).

@ldk-reviews-bot

Copy link
Copy Markdown

🔔 1st Reminder

Hey @jkczyz! This PR has been waiting for your review.
Please take a look when you have a chance. If you're unable to review, please let us know so we can find another reviewer.

funding_negotiation,
FundingNegotiation::AwaitingSignatures { .. }
);
if counterparty_aborted {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we condition on counterparty_aborted? Would it be a problem if always do the new check?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't, then we would always reset the splice state when we haven't received their initial commitment_signed.

.expect("We have a pending splice awaiting signatures")
.has_received_commitment_signed()
{
// We only force close once the counterparty tries to abort after committing to

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This implies that this is somehow a limitation in LDK, but it isn't, its a rather fundamental limitation of the protocol - if we have received the CS, the peer cannot know whether we have provided them with funding signatures, at which point cancelling the splice would be unsafe no matter the implementation in LDK.

@TheBlueMattTheBlueMatt added this to the 0.2 milestone Nov 9, 2025
@TheBlueMatt
TheBlueMatt merged commit e42e74e into lightningdevkit:mainNov 9, 2025
23 of 25 checks passed
@wpaulino
wpaulino deleted the splice-counterparty-tx-abort-before-commit-sig branch November 10, 2025 21:02
@TheBlueMattTheBlueMatt mentioned this pull request Nov 12, 2025
@TheBlueMatt

Copy link
Copy Markdown
Collaborator

Backported in #4221

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@jkczyz